[{"data":1,"prerenderedAt":68396},["ShallowReactive",2],{"application-flags":3,"navbar":7,"always-visible-banner":36,"navbar-about-highlight":108,"navbar-resource-highlight":182,"blog-topics":226,"trust-badges":656,"solution-nav":677,"fa-icon-solid-faUserSecret":800,"fa-icon-sharp-regular-faLaptopCode":804,"fa-icon-solid-faPlugCircleXmark":806,"fa-icon-sharp-regular-faPuzzlePiece":808,"fa-icon-solid-faFileCircleXmark":810,"fa-icon-solid-faGhost":813,"fa-icon-solid-faQrcode":816,"fa-icon-solid-faCookieBite":818,"fa-icon-sharp-regular-faFishingRod":820,"fa-icon-sharp-regular-faUserSecret":822,"fa-icon-sharp-regular-faRadar":824,"fa-icon-sharp-regular-faSatelliteDish":826,"fa-icon-sharp-regular-faShieldCheck":828,"fa-icon-sharp-regular-faBrainCircuit":830,"fa-icon-solid-faMobileScreenButton":832,"fa-icon-brands-faChrome":834,"fa-icon-solid-faDisplay":836,"fa-icon-solid-faFilter":838,"fa-icon-solid-faCloudArrowUp":840,"blog-topic-edr":842},[4],{"name":5,"enabled":6},"maintenanceMode",false,[8],{"createdDate":9,"id":10,"name":11,"modelId":12,"published":13,"meta":14,"query":22,"data":23,"variations":28,"lastUpdated":29,"firstPublished":30,"testRatio":31,"createdBy":32,"lastUpdatedBy":33,"folders":34,"rev":35},1742208588866,"1c7a4e423bf54ac1a328bb4063459ef2","Banner","1c6207a5f24948ab82d4a0b17f251193","published",{"breakpoints":15,"hasAutosaves":19,"kind":20,"lastPreviewUrl":21},{"medium":16,"small":17,"xsmall":18},768,640,320,true,"data","",[],{"link":24,"text":25,"type":26,"url":27},{},"Get our latest report analyzing browser attack techniques in 2026","web-banner","https://pushsecurity.com/resources/browser-attacks-report",{},1774258294825,1742208637545,1,"CydmZnOWU1XuAaLhEDCoYNM4Z8W2","jKjF9r5jcvXU8tzZEfFQm31Iyvr2",[],"j7ew2tin4q",{"createdBy":37,"createdDate":38,"data":39,"folders":94,"id":95,"lastUpdated":96,"lastUpdatedBy":97,"meta":98,"modelId":102,"name":103,"published":13,"query":104,"testRatio":31,"variations":105,"firstPublished":106,"stageModifiedSincePublish":6,"rev":107},"ST0tXQM8slWpFrmioqKHmENB2qe2",1774965361051,{"ctaText":40,"text":41,"url":21,"blocks":42,"state":90},"ewrererw","testrfesssssssssss",[43,70,78],{"@type":44,"@version":45,"id":46,"component":47,"responsiveStyles":60},"@builder.io/sdk:Element",2,"builder-ca12c06a52de41d7b8743da53118cd38",{"name":48,"tag":48,"options":49,"isRSC":59},"TopBannerContent",{"text":50,"ctaText":51,"url":52,"mainText":53,"cta":56},"New Webinar Series: Join John Hammond, Troy Hunt, and Matt Johansen for the State of Browser Attacks","Save Your Spot","https://pushsecurity.com/webinar/state-of-browser-security",{"content":54,"fontSize":55},"\u003Cp class=\"\">Do you know how much AI is in your workforce? Find out August 20th.\u003C/p>","text-base",{"content":57,"fontSize":55,"url":58},"\u003Cp class=\"\">Save your seat →\u003C/p>","https://pushsecurity.com/webinar/shadow-ai",null,{"large":61},{"display":62,"flexDirection":63,"position":64,"flexShrink":65,"boxSizing":66,"marginTop":67,"marginBottom":67,"fontSize":68,"fontWeight":69},"flex","column","relative","0","border-box",".56rem","1.125rem","700",{"@type":44,"@version":45,"id":71,"component":72,"responsiveStyles":76},"builder-a2e1f4b9f30b464bb814d7f5de5b0aa7",{"name":73,"options":74,"isRSC":59},"Custom Code",{"code":75,"scriptsClientOnly":6},"\u003Cstyle>\n  .top-banner.bg-web-orange{background:rgb(114, 79, 255);}\n\u003C/style>\n",{"large":77},{"display":62,"flexDirection":63,"position":64,"flexShrink":65,"boxSizing":66},{"id":79,"@type":44,"tagName":80,"properties":81,"responsiveStyles":85},"builder-pixel-k74nkzlquog","img",{"src":82,"aria-hidden":83,"alt":21,"role":84,"width":65,"height":65},"https://cdn.builder.io/api/v1/pixel?apiKey=f3a1111ff5be48cdbb123cd9f5795a05","true","presentation",{"large":86},{"height":65,"width":65,"display":87,"opacity":65,"overflow":88,"pointerEvents":89},"block","hidden","none",{"deviceSize":91,"location":92},"large",{"path":21,"query":93},{},[],"fd266d0172cc47429be7ad10f48c99ad",1786155414606,"kYgMv6WsbvfmlOUYqR2SFwGzw6e2",{"breakpoints":99,"hasAutosaves":6,"hasErrors":6,"hasLinks":6,"kind":100,"lastPreviewUrl":101},{"medium":16,"small":17,"xsmall":18},"component","https://pushsecurity.com/?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CcreateProjects%2CsendPullRequests%2CfusionHostingPublish&builder.user.role.name=Designer&builder.user.role.id=creator&builder.cachebust=true&builder.preview=always-visible-banner&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.always-visible-banner=fd266d0172cc47429be7ad10f48c99ad&builder.overrides.fd266d0172cc47429be7ad10f48c99ad=fd266d0172cc47429be7ad10f48c99ad&builder.options.locale=Default","0678d178ec8b41efb8a23c09dba7874d","always visible banner",[],{},1774968080803,"1lcyl36j3gz",[109,145],{"createdBy":32,"createdDate":110,"data":111,"folders":134,"id":135,"lastUpdated":136,"lastUpdatedBy":32,"meta":137,"modelId":139,"name":140,"published":13,"query":141,"stageModifiedSincePublish":6,"testRatio":31,"variations":142,"firstPublished":143,"rev":144},1776247359804,{"link":112,"testimonial":113,"testimonialLink":133,"type":116},{},{"@type":114,"id":115,"model":116,"value":117},"@builder.io/core:Reference","f028f2b685bb47cd8bf9e82a26dd5a79","testimonial",{"query":118,"folders":119,"createdDate":120,"id":115,"name":121,"modelId":122,"published":13,"data":123,"variations":127,"lastUpdated":128,"firstPublished":129,"testRatio":31,"createdBy":37,"lastUpdatedBy":37,"meta":130,"rev":132},[],[],1735823466309,"We found Push to be more accurate when compared to competitors and the browser agent offered features that others couldn’t match.","42035571a56940ac98bff4544aa79aa5",{"author":124,"jobTitle":125,"quote":121,"image":126},"Jason Waits","\u003Cp>CISO at Inductive Automation\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Ff04c0c0689ce4a89ac0f0708d78c0a07",{},1735910703862,1735823501152,{"kind":20,"lastPreviewUrl":21,"breakpoints":131,"hasAutosaves":19},{"small":17,"medium":16},"xal7chkxmdh","/customer-stories/inductive-automation",[],"9136a8f18b3b4a6ba29b8653a99372b1",1776247404986,{"breakpoints":138,"hasAutosaves":6,"kind":20,"lastPreviewUrl":21},{"medium":16,"small":17,"xsmall":18},"20d9eaa352304613b3d1a794b400703d","testimonial-inductive-automation",[],{},1776247404973,"5mqgwlt47hs",{"createdBy":32,"createdDate":146,"data":147,"folders":174,"id":175,"lastUpdated":176,"lastUpdatedBy":32,"meta":177,"modelId":139,"name":172,"published":13,"query":179,"stageModifiedSincePublish":6,"testRatio":31,"variations":180,"firstPublished":181,"rev":144},1776255761419,{"description":148,"image":149,"link":150,"testimonial":153,"title":172,"type":173},"Learn about the latest techniques being used in the wild.","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F7b4a5ebf81d64e8c9d7fc35f6c96c4a9",{"text":151,"url":152},"Download now","/resources/browser-attacks-report",{"@type":114,"id":154,"model":116,"value":155},"192acbb1f9ca4cac918c0ec435a8bae3",{"query":156,"folders":157,"createdDate":158,"id":154,"name":159,"modelId":122,"published":13,"data":160,"variations":166,"lastUpdated":167,"firstPublished":168,"testRatio":31,"createdBy":37,"lastUpdatedBy":32,"meta":169,"rev":171},[],[],1728981467463,"Push does for identity what CrowdStrike did for the endpoint",{"video":161,"jobTitle":162,"author":163,"qoute":21,"quote":164,"image":165},"https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F8b30e8ca50064058bbaef0f3c6164575%2Fcompressed?apiKey=f3a1111ff5be48cdbb123cd9f5795a05&token=8b30e8ca50064058bbaef0f3c6164575&alt=media&optimized=true","\u003Cp>Deputy CISO at Microsoft\u003C/p>\u003Cp>Former LinkedIn, Slack, Palantir\u003C/p>","Geoff Belknap","Push does for identity what CrowdStrike did for the endpoint.","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F748f0ad0a5064a00a13f4721fcc8dea1",{},1742902158597,1728981782923,{"kind":20,"lastPreviewUrl":21,"breakpoints":170,"hasAutosaves":19},{"small":17,"medium":16},"kg131t0jkvo","Report: 2026 Browser Attack Techniques","resource",[],"05a9322735fc427db12e2740e4302300",1776255810913,{"breakpoints":178,"hasAutosaves":6,"kind":20,"lastPreviewUrl":21},{"medium":16,"small":17,"xsmall":18},[],{},1776255810900,[183,205],{"createdBy":32,"createdDate":184,"data":185,"folders":195,"id":196,"lastUpdated":197,"lastUpdatedBy":32,"meta":198,"modelId":200,"name":172,"published":13,"query":201,"stageModifiedSincePublish":6,"testRatio":31,"variations":202,"firstPublished":203,"rev":204},1776256900280,{"description":148,"image":149,"link":186,"testimonial":187,"title":172,"type":173},{"text":151,"url":152},{"@type":114,"id":154,"model":116,"value":188},{"query":189,"folders":190,"createdDate":158,"id":154,"name":159,"modelId":122,"published":13,"data":191,"variations":192,"lastUpdated":167,"firstPublished":168,"testRatio":31,"createdBy":37,"lastUpdatedBy":32,"meta":193,"rev":171},[],[],{"video":161,"jobTitle":162,"author":163,"qoute":21,"quote":164,"image":165},{},{"kind":20,"lastPreviewUrl":21,"breakpoints":194,"hasAutosaves":19},{"small":17,"medium":16},[],"1f429607996e4e5fae8fe3f9b9610e55",1776256937553,{"breakpoints":199,"hasAutosaves":6,"kind":20,"lastPreviewUrl":21},{"medium":16,"small":17,"xsmall":18},"4829faa81e7c4ee8bd2d000e160e8d3c",[],{},1776256937540,"470xio0yv7r",{"createdBy":32,"createdDate":206,"data":207,"folders":217,"id":218,"lastUpdated":219,"lastUpdatedBy":32,"meta":220,"modelId":200,"name":222,"published":13,"query":223,"stageModifiedSincePublish":6,"testRatio":31,"variations":224,"firstPublished":225,"rev":204},1776256949234,{"link":208,"testimonial":209,"testimonialLink":133,"type":116},{},{"@type":114,"id":115,"model":116,"value":210},{"query":211,"folders":212,"createdDate":120,"id":115,"name":121,"modelId":122,"published":13,"data":213,"variations":214,"lastUpdated":128,"firstPublished":129,"testRatio":31,"createdBy":37,"lastUpdatedBy":37,"meta":215,"rev":132},[],[],{"author":124,"jobTitle":125,"quote":121,"image":126},{},{"kind":20,"lastPreviewUrl":21,"breakpoints":216,"hasAutosaves":19},{"small":17,"medium":16},[],"ce043785b71b4ece98eac811ecf4ba10",1776256974140,{"breakpoints":221,"hasAutosaves":6,"kind":20,"lastPreviewUrl":21},{"medium":16,"small":17,"xsmall":18},"inductive-automation",[],{},1776256974130,{"id":227,"extension":228,"items":229,"meta":653,"stem":654,"__hash__":655},"blogTopics/blogtopics.json","json",[230,239,247,256,265,274,283,292,301,310,319,328,337,346,355,363,372,381,390,399,408,417,426,435,443,452,461,470,479,488,497,506,514,523,532,540,549,558,566,575,584,593,602,611,619,628,637,645],{"sys":231,"faqItemsCollection":233,"name":235,"slug":236,"tier":31,"intro":237,"faqTitle":59,"postCount":238,"hasPage":19},{"id":232},"topic-ai",{"items":234},[],"AI","ai","AI is reshaping both sides of the security equation: employees adopt AI tools faster than security teams can track them, while attackers use AI to scale and automate campaigns. Shadow AI adoption may now outpace wider shadow SaaS, and attackers are already turning AI chatbot platforms into malware delivery channels. Push has researched the offensive potential of computer-using agents and now applies AI agents to its own threat hunting. This hub covers AI as risk, target, and defensive tool.",22,{"sys":240,"faqItemsCollection":242,"name":244,"slug":245,"tier":45,"intro":246,"faqTitle":59,"postCount":238,"hasPage":19},{"id":241},"topic-ai-attacks",{"items":243},[],"AI attacks","ai-attacks","AI attacks run in both directions: attackers using AI to scale phishing, malware delivery, and identity attacks, and AI platforms themselves becoming the attack surface. Push has researched how computer-using agents can automate identity attacks, and has seen the poisoned tenant technique it coined used against its own employees in the wild.",{"sys":248,"faqItemsCollection":250,"name":252,"slug":253,"tier":45,"intro":254,"faqTitle":59,"postCount":255,"hasPage":19},{"id":249},"topic-ai-governance",{"items":251},[],"AI governance","ai-governance","AI governance is how organizations set and enforce rules for workplace AI use — which tools are allowed, what data can enter them, and how to evidence it to regulators. With US, EU, and UK AI regulations converging on obligations most organizations can’t yet meet, Push’s research makes the case that enforcement starts in the browser, where AI tools are actually used.",9,{"sys":257,"faqItemsCollection":259,"name":261,"slug":262,"tier":45,"intro":263,"faqTitle":59,"postCount":264,"hasPage":19},{"id":258},"topic-aitm",{"items":260},[],"AiTM phishing","aitm","Adversary-in-the-middle (AiTM) phishing proxies a real login page through an attacker-controlled site, capturing credentials, MFA codes, and session tokens in real time to bypass multi-factor authentication. Push’s research into kits like Evilginx and Sneaky2FA documents how they evade URL- and signature-based detection — and why analyzing toolkit behavior in the browser catches attacks that blocklists miss.",77,{"sys":266,"faqItemsCollection":268,"name":270,"slug":271,"tier":45,"intro":272,"faqTitle":59,"postCount":273,"hasPage":6},{"id":267},"topic-bec",{"items":269},[],"BEC","bec","Business email compromise (BEC) turns a hijacked mailbox into a fraud tool: attackers use mail rules, auto-forwarding, and payment redirection to steal money while staying invisible to the account owner. Alongside a first-hand case study of a BEC attack that nearly cost an engineering firm millions, Push breaks down these mailbox persistence tricks and how to detect them.",3,{"sys":275,"faqItemsCollection":277,"name":279,"slug":280,"tier":31,"intro":281,"faqTitle":59,"postCount":282,"hasPage":19},{"id":276},"topic-browser-attacks",{"items":278},[],"Browser attacks","browser-attacks","Browser attacks target users through the web pages, sessions, and extensions they rely on every day — bypassing endpoint and network defenses that never see inside the browser. Techniques like AiTM phishing kits, ClickFix-style copy-paste attacks, OAuth consent abuse, malvertising, and browser sync abuse have become a leading path to account takeover. Push researchers analyze these attacks in the wild, from infiltrating criminal phishing panels to dissecting toolkits like ConsentFix and Sneaky2FA. Use this hub to track how the techniques evolve and how to defend against them.",118,{"sys":284,"faqItemsCollection":286,"name":288,"slug":289,"tier":45,"intro":290,"faqTitle":59,"postCount":291,"hasPage":19},{"id":285},"topic-browser-extensions",{"items":287},[],"Browser extensions","browser-extensions","Browser extensions cut both ways for security teams: malicious or compromised extensions are a growing attack vector, while an extension is also the lightest-weight way to deploy security controls into the browsers employees already use. These posts cover both sides — extension-borne risks like browser sync attacks and the limits of risk scoring, and how Push uses its extension to detect threats and block risky extensions.",30,{"sys":293,"faqItemsCollection":295,"name":297,"slug":298,"tier":31,"intro":299,"faqTitle":59,"postCount":300,"hasPage":19},{"id":294},"topic-browser-security",{"items":296},[],"Browser security","browser-security","Work now happens in the browser, making browser security — visibility and control at the point where users meet the web — a core layer of enterprise defense. Endpoint, network, and email tools miss attacks that unfold inside the browser session, from AiTM phishing to risky extensions and shadow SaaS. Push has published extensively on choosing between enterprise browsers and browser extensions, using browser telemetry, and making the business case for browser security. Start here for both strategy and hands-on guidance.",127,{"sys":302,"faqItemsCollection":304,"name":306,"slug":307,"tier":45,"intro":308,"faqTitle":59,"postCount":309,"hasPage":19},{"id":303},"topic-casb",{"items":305},[],"CASB","casb","Cloud access security brokers (CASBs) govern cloud app usage through API integrations and network proxies — an approach that works for sanctioned apps but struggles with the long tail of shadow SaaS employees adopt on their own. Because every SaaS signup happens in a browser, Push captures that adoption in real time at the point of login, and these posts cover what proxy-based discovery misses.",12,{"sys":311,"faqItemsCollection":313,"name":315,"slug":316,"tier":45,"intro":317,"faqTitle":59,"postCount":318,"hasPage":19},{"id":312},"topic-clickfix",{"items":314},[],"ClickFix","clickfix","ClickFix attacks trick users into copying and running malicious commands themselves — typically through fake CAPTCHA, error, or fix-it prompts — so malware executes without a download for security tools to scan. Push researchers track the technique’s evolution in the wild and identified the ConsentFix and InstallFix variants, which extend it to OAuth consent grants and fake install guides.",39,{"sys":320,"faqItemsCollection":322,"name":324,"slug":325,"tier":45,"intro":326,"faqTitle":59,"postCount":327,"hasPage":19},{"id":321},"topic-credential-phishing",{"items":323},[],"Credential phishing","credential-phishing","Credential phishing steals usernames and passwords through fake login pages impersonating the services employees use, handing attackers direct access to corporate accounts. Attackers don’t hack in — they log in. Push’s browser extension analyzes login pages as users actually see them, blocking cloned pages and stopping employees from entering company passwords on lookalike sites.",89,{"sys":329,"faqItemsCollection":331,"name":333,"slug":334,"tier":45,"intro":335,"faqTitle":59,"postCount":336,"hasPage":19},{"id":330},"topic-credential-stuffing",{"items":332},[],"Credential stuffing","credential-stuffing","Credential stuffing is an attack where criminals replay username-password pairs stolen from one breach against other services, exploiting password reuse to take over accounts. Major breaches have shown how far a single set of stolen credentials can travel. Push detects verified stolen credentials by comparing employee passwords against breach datasets and dark-web threat intelligence, eliminating false positives.",64,{"sys":338,"faqItemsCollection":340,"name":342,"slug":343,"tier":31,"intro":344,"faqTitle":59,"postCount":345,"hasPage":19},{"id":339},"topic-detection-and-response",{"items":341},[],"Detection & response","detection-and-response","Detection and response is being reshaped as attacks move into the browser, where EDR, SIEM, and network tools have limited visibility. Modern phishing kits evade signature-based detection, and most malicious pages have never been seen before — so technique-level, in-browser detection matters more than known-bad indicators. Push’s work here spans high-fidelity browser telemetry, session token theft detection, and agentic threat hunting, plus practical IR guidance for compromised SaaS accounts and malicious OAuth apps. These posts cover both the philosophy and the workflows.",101,{"sys":347,"faqItemsCollection":349,"name":351,"slug":352,"tier":45,"intro":353,"faqTitle":59,"postCount":354,"hasPage":19},{"id":348},"topic-detection-engineering",{"items":350},[],"Detection engineering","detection-engineering","Detection engineering turns threat research into reliable, high-fidelity detections — and as AI accelerates the churn of attacker infrastructure, indicator-based detection is collapsing in favor of technique-level approaches. Here you’ll find teardowns of AiTM kits, ClickFix pages, and malvertising campaigns, alongside Push’s own account of building an agentic threat hunting pipeline that turns hunts into shipped detections.",42,{"sys":356,"faqItemsCollection":358,"name":360,"slug":361,"tier":45,"intro":362,"faqTitle":59,"postCount":238,"hasPage":19},{"id":357},"topic-device-code-phishing",{"items":359},[],"Device code phishing","device-code-phishing","Device code phishing abuses the OAuth device authorization flow: attackers generate a legitimate sign-in code, trick the victim into entering it on the vendor’s real login page, and walk away with access tokens — no fake site or password capture required. Push research tracked a sharp spike in adoption during 2026 as attackers use the technique to sidestep standard access controls.",{"sys":364,"faqItemsCollection":366,"name":368,"slug":369,"tier":45,"intro":370,"faqTitle":59,"postCount":371,"hasPage":19},{"id":365},"topic-dlp",{"items":367},[],"DLP","dlp","Data loss prevention (DLP) is the practice of stopping sensitive data from leaving your control — a problem that has shifted from email and endpoints to the browser, where employees move data into SaaS and AI tools. Push applies controls at that point of use, from keeping corporate credentials out of personal password managers to governing what flows into unsanctioned apps.",15,{"sys":373,"faqItemsCollection":375,"name":377,"slug":378,"tier":45,"intro":379,"faqTitle":59,"postCount":380,"hasPage":19},{"id":374},"topic-edr",{"items":376},[],"EDR","edr","Endpoint detection and response (EDR) watches processes, files, and memory on the device — a vantage point that never sees the phishing pages, stolen sessions, and identity attacks playing out inside the browser. That’s not an EDR failure; attackers have simply moved where it can’t follow. These posts map that gap and show how Push pairs browser-level detection and response with endpoint security to close it.",24,{"sys":382,"faqItemsCollection":384,"name":386,"slug":387,"tier":45,"intro":388,"faqTitle":59,"postCount":389,"hasPage":19},{"id":383},"topic-enterprise-browser",{"items":385},[],"Enterprise browser","enterprise-browser","An enterprise browser is a standalone, security-hardened browser that organizations deploy in place of Chrome, Edge, or other defaults. The real buying question is whether replacing the browser beats securing the browsers employees already use — a trade-off these posts examine directly, alongside analysis of Omdia’s secure enterprise browser market report and Push’s framework for weighing full browsers against extension-based deployment.",6,{"sys":391,"faqItemsCollection":393,"name":395,"slug":396,"tier":45,"intro":397,"faqTitle":59,"postCount":398,"hasPage":19},{"id":392},"topic-ghost-logins",{"items":394},[],"Ghost logins","ghost-logins","Ghost logins are overlooked authentication routes into an account — like a password login lingering behind SSO, or a forgotten secondary auth method — that attackers exploit for account takeover and persistence. Push coined the term after research showing how these forgotten login paths let attackers sidestep the MFA and SSO controls guarding an account’s primary sign-in method.",48,{"sys":400,"faqItemsCollection":402,"name":404,"slug":405,"tier":45,"intro":406,"faqTitle":59,"postCount":407,"hasPage":19},{"id":401},"topic-identity-attacks",{"items":403},[],"Identity attacks","identity-attacks","Identity attacks target user accounts rather than infrastructure — phishing credentials, stealing sessions, abusing OAuth grants — because logging in is easier than hacking in. Identity-based techniques are now the leading cause of breaches. Push’s offensive research maps these techniques continuously, coining attacks like SAMLjacking and the poisoned tenant before they appeared in the wild.",56,{"sys":409,"faqItemsCollection":411,"name":413,"slug":414,"tier":31,"intro":415,"faqTitle":59,"postCount":416,"hasPage":19},{"id":410},"topic-identity-security",{"items":412},[],"Identity security","identity-security","Identity security is the practice of protecting workforce accounts, credentials, and sessions — the primary route attackers now use to breach organizations. Instead of hacking in, attackers log in: through phished credentials, stolen session tokens, MFA bypass, and forgotten ghost logins. Push’s research team documents these techniques continuously, from cross-IdP impersonation and SAMLjacking to analyses of major identity-driven breaches. This hub collects that research alongside practical guidance on MFA, SSO, and stopping account takeover.",154,{"sys":418,"faqItemsCollection":420,"name":422,"slug":423,"tier":45,"intro":424,"faqTitle":59,"postCount":425,"hasPage":19},{"id":419},"topic-infostealer",{"items":421},[],"Infostealer","infostealer","Infostealers are malware built to harvest saved passwords, cookies, and session tokens from infected devices, supplying the stolen credentials behind some of the most consequential breaches of recent years. Push traces the ecosystem trading this data and checks employee passwords against threat intel feeds, flagging verified stolen credentials before attackers can log in with them.",52,{"sys":427,"faqItemsCollection":429,"name":431,"slug":432,"tier":45,"intro":433,"faqTitle":59,"postCount":434,"hasPage":19},{"id":428},"topic-legitimate-service-abuse",{"items":430},[],"Legitimate service abuse","legitimate-service-abuse","Legitimate service abuse means staging attacks on trusted platforms — Google Ads, AI chatbot share pages, office.com links, Slack, SaaS tenants — so malicious content inherits the reputation of the service hosting it. Push research has documented the pattern repeatedly, from malvertising run through hijacked Google Ad Manager accounts to phishing links generated by Active Directory Federation Services.",28,{"sys":436,"faqItemsCollection":438,"name":440,"slug":441,"tier":45,"intro":442,"faqTitle":59,"postCount":291,"hasPage":19},{"id":437},"topic-malvertising",{"items":439},[],"Malvertising","malvertising","Malvertising uses paid search and display ads to put phishing pages and malware in front of users, often by impersonating trusted brands at the top of Google results. Push tracks these campaigns continuously — intercepting live attacks spoofing well-known brands — and has documented how criminals hijack Google Ads accounts to fund and run them.",{"sys":444,"faqItemsCollection":446,"name":448,"slug":449,"tier":45,"intro":450,"faqTitle":59,"postCount":451,"hasPage":19},{"id":445},"topic-malware-delivery",{"items":447},[],"Malware delivery","malware-delivery","Malware delivery has moved into the browser: rather than email attachments, attackers now rely on malvertising, fake install guides, and ClickFix-style copy-paste lures to get code running on endpoints. Push research on techniques like InstallFix maps the playbook, and in-browser detection of malicious copy and paste blocks these attacks before commands reach the endpoint.",13,{"sys":453,"faqItemsCollection":455,"name":457,"slug":458,"tier":45,"intro":459,"faqTitle":59,"postCount":460,"hasPage":19},{"id":454},"topic-mfa",{"items":456},[],"MFA","mfa","Multi-factor authentication (MFA) requires a second proof of identity beyond a password, and it remains one of the most effective controls against account takeover. Regulators from Cyber Essentials to NYDFS now mandate it across cloud services. Push enforces MFA in the browser on third-party apps — even those with no native enforcement option — and shows security teams where coverage gaps remain.",83,{"sys":462,"faqItemsCollection":464,"name":466,"slug":467,"tier":45,"intro":468,"faqTitle":59,"postCount":469,"hasPage":19},{"id":463},"topic-mfa-bypass",{"items":465},[],"MFA bypass","mfa-bypass","MFA bypass covers the techniques attackers use to defeat multi-factor authentication — AiTM phishing kits, consent phishing, device code phishing, and MFA downgrade attacks among them. None of these break the second factor; they route around it. Push researchers regularly get hands-on with phishing kits like Evilginx and Sneaky2FA, analyzing how these attacks work in the wild and how they evolve.",58,{"sys":471,"faqItemsCollection":473,"name":475,"slug":476,"tier":45,"intro":477,"faqTitle":59,"postCount":478,"hasPage":19},{"id":472},"topic-non-email-phishing",{"items":474},[],"Non-email phishing","non-email-phishing","Non-email phishing delivers malicious links through channels your secure email gateway never sees — social media messages, IM apps like Slack and Teams, search ads, and SMS. Push has intercepted live campaigns arriving via LinkedIn DMs, malvertising, and messaging platforms, which is why it detects phishing pages in the browser at the point of click, regardless of delivery channel.",51,{"sys":480,"faqItemsCollection":482,"name":484,"slug":485,"tier":45,"intro":486,"faqTitle":59,"postCount":487,"hasPage":19},{"id":481},"topic-oauth-abuse",{"items":483},[],"OAuth abuse","oauth-abuse","OAuth abuse is attackers exploiting app-to-app authorization — consent phishing, malicious OAuth apps, stolen tokens, and device code flows — to gain persistent access to cloud tenants without touching a password or MFA prompt. Push tracks these techniques continuously and discovered ConsentFix, a browser-native attack in the wild that pairs OAuth consent phishing with a ClickFix-style prompt.",70,{"sys":489,"faqItemsCollection":491,"name":493,"slug":494,"tier":45,"intro":495,"faqTitle":59,"postCount":496,"hasPage":19},{"id":490},"topic-passkeys",{"items":492},[],"Passkeys","passkeys","Passkeys are phishing-resistant credentials that replace passwords with cryptographic key pairs bound to a user’s device. They defeat conventional credential phishing, but attackers adapt: Push research has documented MFA downgrade, app-specific password phishing, and device code phishing being used in the wild to route around passkey-protected accounts. Deploying passkeys is step one; closing those fallback paths is step two.",21,{"sys":498,"faqItemsCollection":500,"name":502,"slug":503,"tier":45,"intro":504,"faqTitle":59,"postCount":505,"hasPage":19},{"id":499},"topic-password-security",{"items":501},[],"Password security","password-security","Password security is the practice of keeping workforce credentials strong, unique, and out of attackers’ hands — still a frontline defense while most SaaS logins depend on passwords. Expiration policies don’t fix weak or reused passwords; visibility does. Push observes real logins in the browser to flag weak, reused, and breached passwords and guide employees to reset them on any app.",79,{"sys":507,"faqItemsCollection":509,"name":511,"slug":512,"tier":45,"intro":513,"faqTitle":59,"postCount":318,"hasPage":19},{"id":508},"topic-phaas",{"items":510},[],"PhaaS","phaas","Phishing-as-a-service (PhaaS) platforms sell ready-made phishing kits, hosted infrastructure, and management panels on subscription, letting low-skill criminals run MFA-bypassing campaigns at scale. Kits like Evilginx, Tycoon2FA, Sneaky2FA, FlowerStorm, and EvilTokens each add their own evasion and session-theft capabilities, and new entrants appear regularly. Push researchers continuously get hands-on with these tools — investigating attacks in the wild, reverse-engineering kit behavior, and turning that research into detections.",{"sys":515,"faqItemsCollection":517,"name":519,"slug":520,"tier":31,"intro":521,"faqTitle":59,"postCount":522,"hasPage":19},{"id":516},"topic-phishing",{"items":518},[],"Phishing","phishing","Phishing remains the most common way attackers compromise business accounts — and it has moved far beyond suspicious emails. Modern campaigns use AiTM toolkits that bypass MFA, consent phishing against OAuth, device code phishing, and lures delivered through malvertising, LinkedIn, and Slack. Push detects and blocks these attacks in the browser, and its researchers publish teardowns of live campaigns and kits like Evilginx and Sneaky2FA. Read on for how phishing actually works today and what stops it.",91,{"sys":524,"faqItemsCollection":526,"name":528,"slug":529,"tier":45,"intro":530,"faqTitle":59,"postCount":531,"hasPage":19},{"id":525},"topic-public-breach",{"items":527},[],"Public breach","public-breach","Public breaches are the disclosed incidents that show how attacks actually unfold once the headlines fade. Push’s breach analyses keep finding identity at the entry point: stolen credentials, OAuth abuse, and missing MFA recur across the incidents analyzed here.",29,{"sys":533,"faqItemsCollection":535,"name":537,"slug":538,"tier":45,"intro":539,"faqTitle":59,"postCount":451,"hasPage":19},{"id":534},"topic-ransomware",{"items":536},[],"Ransomware","ransomware","Ransomware attacks increasingly begin with an identity, not an exploit: stolen credentials, MFA bypass, and help desk scams give operators their initial foothold. The analysis here follows that front end of the kill chain — how identity compromise leads to ransomware deployment, and the breaches driving regulators toward tighter MFA requirements.",{"sys":541,"faqItemsCollection":543,"name":545,"slug":546,"tier":31,"intro":547,"faqTitle":59,"postCount":548,"hasPage":19},{"id":542},"topic-saas-security",{"items":544},[],"SaaS security","saas-security","SaaS security means protecting the sprawl of cloud apps, accounts, and integrations your employees adopt — often without IT ever knowing. Shadow SaaS, risky OAuth grants, ghost logins, and unmanaged third-party access create attack paths traditional controls can’t see, as recent high-profile breaches have demonstrated. Building on the original SaaS attack matrix, Push continues to map SaaS-native attack techniques alongside practical guides for discovering and securing unsanctioned apps, and this hub gathers all of it.",96,{"sys":550,"faqItemsCollection":552,"name":554,"slug":555,"tier":45,"intro":556,"faqTitle":59,"postCount":557,"hasPage":6},{"id":551},"topic-security-training",{"items":553},[],"Security training","security-training","Security training aims to teach employees to recognize and avoid attacks — yet modern phishing routinely fools even seasoned security professionals. Push argues that training budgets work harder as real-time, in-browser intervention: guardrails and warnings at the moment of risk, rather than lessons employees must recall under pressure.",4,{"sys":559,"faqItemsCollection":561,"name":563,"slug":564,"tier":45,"intro":565,"faqTitle":59,"postCount":389,"hasPage":19},{"id":560},"topic-seo-poisoning",{"items":562},[],"SEO poisoning","seo-poisoning","SEO poisoning manipulates search engine results so malicious pages rank prominently for the software, tools, or services users are actively searching for, turning a routine search into an infection vector. It often pairs with malvertising and ClickFix-style payloads — Push has documented attackers abusing shared pages on legitimate AI chatbot domains to deliver malware from trusted infrastructure.",{"sys":567,"faqItemsCollection":569,"name":571,"slug":572,"tier":45,"intro":573,"faqTitle":59,"postCount":574,"hasPage":19},{"id":568},"topic-session-hijacking",{"items":570},[],"Session hijacking","session-hijacking","Session hijacking is the theft of an authenticated session — usually via stolen session cookies or tokens — letting attackers walk past passwords and MFA into a live account. AiTM phishing kits and infostealers have made it a mainstream attack technique across both criminal and targeted intrusions. Push’s browser agent detects session token theft by adding telemetry to the user agent string, creating a high-fidelity signal for security teams.",74,{"sys":576,"faqItemsCollection":578,"name":580,"slug":581,"tier":45,"intro":582,"faqTitle":59,"postCount":583,"hasPage":19},{"id":577},"topic-shadow-ai",{"items":579},[],"Shadow AI","shadow-ai","Shadow AI is employees’ unsanctioned use of AI tools at work, putting corporate data into chatbots and assistants that security teams never approved and can’t see. Push’s own browser telemetry shows AI adoption acting as a force multiplier for shadow IT — potentially now outscaling shadow SaaS — and this hub tracks that research, real-world breach examples, and practical controls.",20,{"sys":585,"faqItemsCollection":587,"name":589,"slug":590,"tier":45,"intro":591,"faqTitle":59,"postCount":592,"hasPage":19},{"id":586},"topic-shadow-saas",{"items":588},[],"Shadow SaaS","shadow-saas","Shadow SaaS is the cloud applications employees adopt for work without IT approval, each one creating unmanaged accounts, identities, and data outside your security controls. Push covers the problem end to end — from browser-based SaaS discovery to in-browser app banners and MFA enforcement — alongside breach analyses that show where unmanaged accounts lead.",75,{"sys":594,"faqItemsCollection":596,"name":598,"slug":599,"tier":45,"intro":600,"faqTitle":59,"postCount":601,"hasPage":19},{"id":595},"topic-siem",{"items":597},[],"SIEM","siem","A SIEM is only as good as the telemetry feeding it, and most log sources never see what happens inside the browser — where phishing, session token theft, and account takeover actually play out. Push streams browser-level detections and identity telemetry into SIEMs, and these posts show how that data improves detection fidelity and cuts alert fatigue.",19,{"sys":603,"faqItemsCollection":605,"name":607,"slug":608,"tier":45,"intro":609,"faqTitle":59,"postCount":610,"hasPage":19},{"id":604},"topic-social-engineering",{"items":606},[],"Social engineering","social-engineering","Social engineering is the manipulation of people — through phishing pages, help desk impersonation, vishing calls, and poisoned tenant invites — into handing over access that no exploit could take. Coverage here tracks how threat actors run these plays — drawing on Push’s ongoing investigation of live phishing infrastructure and criminal tooling.",59,{"sys":612,"faqItemsCollection":614,"name":616,"slug":617,"tier":31,"intro":618,"faqTitle":59,"postCount":557,"hasPage":6},{"id":613},"topic-supply-chain-security",{"items":615},[],"Supply chain security","supply-chain-security","Supply chain security extends beyond your own perimeter to the vendors, platforms, and browser extensions your organization depends on. A compromised third party can hand attackers legitimate access — as recent campaigns against SaaS providers have shown. Push’s research examines the browser-extension supply chain in particular: why extension risk scores fail to predict compromise, and how developers can harden extensions against takeover. These posts frame supply chain risk through a browser and identity lens.",{"sys":620,"faqItemsCollection":622,"name":624,"slug":625,"tier":45,"intro":626,"faqTitle":59,"postCount":627,"hasPage":19},{"id":621},"topic-swg",{"items":623},[],"SWG","swg","A secure web gateway (SWG) filters and inspects web traffic in transit, sitting in the network path between users and the internet. That position shows you the packet but not the session: Push’s research on AitM phishing kits documents how attackers break the signatures proxies rely on, and these posts explain why phishing detection is moving from the network path into the browser itself.",17,{"sys":629,"faqItemsCollection":631,"name":633,"slug":634,"tier":45,"intro":635,"faqTitle":59,"postCount":636,"hasPage":19},{"id":630},"topic-third-party-risk",{"items":632},[],"Third-party risk","third-party-risk","Third-party risk is the exposure your organization inherits from vendors, SaaS providers, and integrations that hold your data or access your tenants — a chain now extended one employee sign-up at a time. This hub collects Push’s breach analyses and guides for assessing OAuth integrations, managing browser extensions, and responding when a supplier is compromised.",44,{"sys":638,"faqItemsCollection":640,"name":642,"slug":643,"tier":31,"intro":644,"faqTitle":59,"postCount":398,"hasPage":19},{"id":639},"topic-threat-landscape",{"items":641},[],"Threat landscape","threat-landscape","The enterprise threat landscape is now defined by identity attacks: criminals log in with phished, stolen, or stuffed credentials rather than breaking infrastructure. Threat actors keep proving how effective help desk scams, MFA bypass, and session theft are against well-defended organizations. Drawing on breach analyses, annual phishing trend reviews, and in-the-wild campaign tracking, Push documents how attacker TTPs are shifting. This hub is where to follow those changes.",{"sys":646,"faqItemsCollection":648,"name":650,"slug":651,"tier":45,"intro":652,"faqTitle":59,"postCount":371,"hasPage":19},{"id":647},"topic-vishing",{"items":649},[],"Vishing","vishing","Vishing — voice phishing — uses phone calls to impersonate IT support, help desks, or employees, talking targets into password resets, MFA approvals, or opening attacker-controlled pages. Threat actors now routinely pair calls with AiTM phishing to hijack SSO accounts, a chain Push has analyzed across campaigns targeting hundreds of organizations.",{},"blogtopics","w0ITersBlkytyrxHNkTEFmGsSW5X9NfdbmeXV1u8bAo",[657,661,665,669,673],{"title":658,"logo":659,"createdDate":660},"SOC2","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fb6727a5e00004d6e9e69fc3068b8b64c",1784291539953,{"title":662,"logo":663,"createdDate":664},"GDPR","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Ffe49f53211674deaa5a6640d929cdf42?format=webp",1784291672535,{"title":666,"logo":667,"createdDate":668},"Cyber essentials","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F53558c1045a342a7a28def960cd54ae7?format=webp",1784291702710,{"title":670,"logo":671,"createdDate":672},"ISO IEC 27001","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F578a404a61cf45db951a41fe3554d12d",1784291766222,{"title":674,"logo":675,"createdDate":676},"ISO IEC 27701","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fbe219844b13242fbba531959579a753c",1784291858848,[678,730,775],{"id":679,"label":680,"text":21,"navIcon":681,"items":682},"stop-browser-based-attacks","Stop browser-based attacks","solid:faShieldHalved",[683,688,693,698,703,708,712,717,721,725],{"title":684,"text":685,"url":686,"navIcon":687},"Adversary-in-the-Middle","Detect and block AiTM proxies stealing session tokens.","/solution/stop-browser-based-attacks/adversary-in-the-middle-attacks","solid:faUserSecret",{"title":689,"text":690,"url":691,"navIcon":692},"ClickFix (+Fix variants)","Block attacks that trick users into running malicious code.","/solution/stop-browser-based-attacks/clickfix-fix-variants","sharp-regular:faLaptopCode",{"title":694,"text":695,"url":696,"navIcon":697},"Malicious OAuth integrations","Detect suspicious OAuth consent flows and stop persistent access.","/solution/stop-browser-based-attacks/malicious-oauth-integrations","solid:faPlugCircleXmark",{"title":699,"text":700,"url":701,"navIcon":702},"Malicious browser extensions","Shine a light on risky browser extensions.","/solution/stop-browser-based-attacks/malicious-browser-extensions","sharp-regular:faPuzzlePiece",{"title":704,"text":705,"url":706,"navIcon":707},"Malicious file downloads","Gain visibility into browser downloads and block malicious files.","/solution/stop-browser-based-attacks/malicious-file-downloads","solid:faFileCircleXmark",{"title":395,"text":709,"url":710,"navIcon":711},"Surface hidden login paths that bypass SSO and expose accounts.","/solution/stop-browser-based-attacks/ghost-logins","solid:faGhost",{"title":713,"text":714,"url":715,"navIcon":716},"Mobile phishing (QR & SMS)","Detect phishing links delivered via SMS and QR codes.","/solution/stop-browser-based-attacks/mobile-phishing-qr-code-sms","solid:faQrcode",{"title":333,"text":718,"url":719,"navIcon":720},"Identify reused and compromised credentials across SaaS logins.","/solution/stop-browser-based-attacks/credential-stuffing","custom:credentialStuffing",{"title":571,"text":722,"url":723,"navIcon":724},"Detect and block stolen session tokens before attackers get access.","/solution/stop-browser-based-attacks/session-hijacking","solid:faCookieBite",{"title":726,"text":727,"url":728,"navIcon":729},"Zero-day phishing","Detect phishing TTPs directly in the browser and stop credential theft.","/solution/stop-browser-based-attacks/zero-day-phishing","sharp-regular:faFishingRod",{"id":731,"label":732,"text":21,"navIcon":733,"items":734},"achieve-security-outcomes","Achieve security outcomes","solid:faCheckToSlot",[735,740,745,750,755,760,765,770],{"title":736,"text":737,"url":738,"navIcon":739},"Stop account takeover","Stop ATO with stolen credential and compromised token detection.","/solution/achieve-security-outcomes/stop-account-takeover","sharp-regular:faUserSecret",{"title":741,"text":742,"url":743,"navIcon":744},"Harden unmanaged identities","Harden access paths with visibility, detection, and guardrails.","/solution/achieve-security-outcomes/harden-unmanaged-identities","sharp-regular:faRadar",{"title":746,"text":747,"url":748,"navIcon":749},"Investigate browser-related incidents","Investigate and respond faster with unique browser telemetry.","/solution/achieve-security-outcomes/investigate-browser-related-incidents","sharp-regular:faSatelliteDish",{"title":751,"text":752,"url":753,"navIcon":754},"Secure shadow SaaS","See and control shadow SaaS in the browser.","/solution/achieve-security-outcomes/secure-shadow-saas","sharp-regular:faShieldCheck",{"title":756,"text":757,"url":758,"navIcon":759},"Secure AI","See and control AI apps in the browser.","/solution/achieve-security-outcomes/secure-ai","sharp-regular:faBrainCircuit",{"title":761,"text":762,"url":763,"navIcon":764},"Secure BYOD","Extend consistent browser-based protection to unmanaged devices.","/solution/achieve-security-outcomes/secure-bring-your-own-device","solid:faMobileScreenButton",{"title":766,"text":767,"url":768,"navIcon":769},"Secure Chromebooks","Secure browser activity on Chromebooks without endpoint agents.","/solution/achieve-security-outcomes/secure-chromebooks","brands:faChrome",{"title":771,"text":772,"url":773,"navIcon":774},"Investigate and stop data loss","Detect and prevent data loss across AI tools, apps, and sessions.","/solution/achieve-security-outcomes/investigate-and-stop-data-loss","custom:investigateAndStopDataLoss",{"id":776,"label":777,"text":21,"navIcon":778,"items":779},"tool-replacements","Tool replacements","solid:faScrewdriverWrench",[780,785,790,795],{"title":781,"text":782,"url":783,"navIcon":784},"Remote browser isolation","Detect attacks that look like normal browsing.","/solution/tool-replacements/remote-browser-isolation","solid:faDisplay",{"title":786,"text":787,"url":788,"navIcon":789},"Secure web gateways","Detect attacks inside the browser after SWGs allowed the connection.","/solution/tool-replacements/secure-web-gateways","solid:faFilter",{"title":791,"text":792,"url":793,"navIcon":794},"Cloud access security broker","Catch browser-based identity threats in real time, not after the fact.","/solution/tool-replacements/cloud-access-security-broker","solid:faCloudArrowUp",{"title":796,"text":797,"url":798,"navIcon":799},"Security awareness training","Block real phishing instead of training users on simulations.","/solution/tool-replacements/security-awareness-training","custom:securityAwareness",{"w":801,"h":802,"d":803},448,512,"M171-16c-36.4 0-57.8 58.3-68.3 112L72 96c-13.3 0-24 10.7-24 24s10.7 24 24 24l24 0 0 32c0 17 3.3 33.2 9.3 48l-9.3 0 0 0-20.5 0c-15.2 0-27.5 12.3-27.5 27.5 0 3 .5 5.9 1.4 8.7l28.9 86.6C40.2 379.6 16 428.1 16 482.3 16 498.7 29.3 512 45.7 512l356.6 0c16.4 0 29.7-13.3 29.7-29.7 0-54.2-24.2-102.7-62.3-135.4l28.9-86.6c.9-2.8 1.4-5.7 1.4-8.7 0-15.2-12.3-27.5-27.5-27.5l-20.5 0 0 0-9.3 0c6-14.8 9.3-31 9.3-48l0-32 24 0c13.3 0 24-10.7 24-24s-10.7-24-24-24l-30.7 0c-10.4-53.7-31.9-112-68.3-112-9.6 0-19 3.9-27.5 8.2-8.2 4.1-18.4 7.8-25.5 7.8s-17.3-3.7-25.5-7.8C190-12.1 180.6-16 171-16zm93.7 484.4l-24.8-70.9 27.9-32.5c2.7-3.2 4.2-7.2 4.2-11.4 0-9.7-7.8-17.5-17.5-17.5l-61 0c-9.7 0-17.5 7.8-17.5 17.5 0 4.2 1.5 8.2 4.2 11.4l27.9 32.5-24.8 70.9-57-180.4 35.7 0c18.4 10.2 39.5 16 62 16s43.6-5.8 62-16l35.7 0-57 180.4zM224 256c-34.7 0-64.2-22.1-75.3-53 5.7 3.2 12.3 5 19.3 5l12.4 0c16.5 0 31.1-10.6 36.3-26.2 2.3-7 12.2-7 14.5 0 5.2 15.6 19.9 26.2 36.3 26.2l12.4 0c7 0 13.6-1.8 19.3-5-11.1 30.9-40.6 53-75.3 53z",{"w":17,"h":802,"d":805},"M112 80l416 0 0 224 48 0 0-272-512 0 0 272 48 0 0-224zM48 404.1l0-4.1 544 0 0 4.1-27.9 27.9-488.2 0-27.9-27.9zM592 352l-592 0 0 72 56 56 528 0 56-56 0-72-48 0zM281 169l17-17-33.9-33.9c-6.1 6.1-27.8 27.8-65 65l-17 17c6.1 6.1 27.8 27.8 65 65l17 17 33.9-33.9c-9-9-25-25-48-48l31-31zM393 135l-17-17-33.9 33.9c9 9 25 25 48 48-23 23-39 39-48 48L376 281.9c6.1-6.1 27.8-27.8 65-65l17-17c-6.1-6.1-27.8-27.8-65-65z",{"w":17,"h":802,"d":807},"M192-32c17.7 0 32 14.3 32 32l0 96 128 0 0-96c0-17.7 14.3-32 32-32s32 14.3 32 32l0 96 64 0c17.7 0 32 14.3 32 32s-14.3 32-32 32l0 48.7c-98.6 8.1-176 90.7-176 191.3 0 27.3 5.7 53.3 16 76.9l0 3.1c0 17.7-14.3 32-32 32s-32-14.3-32-32l0-66.7C165.2 398.1 96 319.1 96 224l0-64c-17.7 0-32-14.3-32-32S78.3 96 96 96l64 0 0-96c0-17.7 14.3-32 32-32zM496 256a144 144 0 1 1 0 288 144 144 0 1 1 0-288zm59.3 107.3c6.2-6.2 6.2-16.4 0-22.6s-16.4-6.2-22.6 0l-36.7 36.7-36.7-36.7c-6.2-6.2-16.4-6.2-22.6 0s-6.2 16.4 0 22.6l36.7 36.7-36.7 36.7c-6.2 6.2-6.2 16.4 0 22.6s16.4 6.2 22.6 0l36.7-36.7 36.7 36.7c6.2 6.2 16.4 6.2 22.6 0s6.2-16.4 0-22.6l-36.7-36.7 36.7-36.7z",{"w":802,"h":802,"d":809},"M201.1 57.3c-7 5.3-9.1 10.7-9.1 14.7 0 4.5 2.8 11.2 12.4 16.9l11.6 7 0 48.1-168 0 0 60.5c7.4-2.9 15.5-4.5 24-4.5 43.1 0 72 39.4 72 80s-28.9 80-72 80c-8.5 0-16.6-1.6-24-4.5l0 108.5 108.5 0c-2.9-7.4-4.5-15.5-4.5-24 0-43.1 39.4-72 80-72s80 28.9 80 72c0 8.5-1.6 16.6-4.5 24l60.5 0 0-168 48.1 0 7 11.6c5.8 9.6 12.4 12.4 16.9 12.4 4 0 9.5-2.1 14.7-9.1s9.3-17.9 9.3-30.9-4-23.8-9.3-30.9-10.7-9.1-14.7-9.1c-4.5 0-11.2 2.8-16.9 12.4l-7 11.6-48.1 0 0-120-120 0 0-48.1 11.6-7c9.6-5.8 12.4-12.4 12.4-16.9 0-4-2.1-9.5-9.1-14.7S245 48 232 48 208.2 52 201.1 57.3zM172.3 18.9C188.5 6.8 209.6 0 232 0S275.5 6.8 291.7 18.9 320 49.5 320 72c0 8.6-1.8 16.7-4.9 24l100.9 0 0 100.9c7.3-3.1 15.4-4.9 24-4.9 22.5 0 41 12.2 53.1 28.3s18.9 37.3 18.9 59.7-6.8 43.5-18.9 59.7-30.6 28.3-53.1 28.3c-8.6 0-16.7-1.8-24-4.9l0 148.9-168 0 0-49.3 8.2-7.2c5.4-4.7 7.8-10.3 7.8-15.5 0-9.9-10.7-24-32-24s-32 14.1-32 24c0 5.3 2.4 10.8 7.8 15.5l8.2 7.2 0 49.3-216 0 0-216 49.3 0 7.2 8.2c4.7 5.4 10.3 7.8 15.5 7.8 9.9 0 24-10.7 24-32s-14.1-32-24-32c-5.3 0-10.8 2.4-15.5 7.8L49.3 264 0 264 0 96 148.9 96c-3.1-7.3-4.9-15.4-4.9-24 0-22.5 12.2-41 28.3-53.1z",{"w":811,"h":802,"d":812},576,"M96 0C60.7 0 32 28.7 32 64l0 384c0 35.3 28.7 64 64 64l180 0c-22.7-31.5-36-70.2-36-112 0-100.6 77.4-183.2 176-191.3l0-38.1c0-17-6.7-33.3-18.7-45.3L290.7 18.7C278.7 6.7 262.5 0 245.5 0L96 0zM357.5 176L264 176c-13.3 0-24-10.7-24-24L240 58.5 357.5 176zM432 544a144 144 0 1 0 0-288 144 144 0 1 0 0 288zm59.3-180.7l-36.7 36.7 36.7 36.7c6.2 6.2 6.2 16.4 0 22.6s-16.4 6.2-22.6 0l-36.7-36.7-36.7 36.7c-6.2 6.2-16.4 6.2-22.6 0s-6.2-16.4 0-22.6l36.7-36.7-36.7-36.7c-6.2-6.2-6.2-16.4 0-22.6s16.4-6.2 22.6 0l36.7 36.7 36.7-36.7c6.2-6.2 16.4-6.2 22.6 0s6.2 16.4 0 22.6z",{"w":814,"h":802,"d":815},384,"M40.1 467.1l-11.2 9C25.7 478.6 21.8 480 17.8 480 8 480 0 472 0 462.2L0 192C0 86 86 0 192 0S384 86 384 192l0 270.2c0 9.8-8 17.8-17.8 17.8-4 0-7.9-1.4-11.1-3.9l-11.2-9c-13.4-10.7-32.8-9-44.1 3.9L269.3 506c-3.3 3.8-8.2 6-13.3 6s-9.9-2.2-13.3-6l-26.6-30.5c-12.7-14.6-35.4-14.6-48.2 0L141.3 506c-3.3 3.8-8.2 6-13.3 6s-9.9-2.2-13.3-6L84.2 471c-11.3-12.9-30.7-14.6-44.1-3.9zM160 192a32 32 0 1 0 -64 0 32 32 0 1 0 64 0zm96 32a32 32 0 1 0 0-64 32 32 0 1 0 0 64z",{"w":801,"h":802,"d":817},"M64 160l64 0 0-64-64 0 0 64zM0 80C0 53.5 21.5 32 48 32l96 0c26.5 0 48 21.5 48 48l0 96c0 26.5-21.5 48-48 48l-96 0c-26.5 0-48-21.5-48-48L0 80zM64 416l64 0 0-64-64 0 0 64zM0 336c0-26.5 21.5-48 48-48l96 0c26.5 0 48 21.5 48 48l0 96c0 26.5-21.5 48-48 48l-96 0c-26.5 0-48-21.5-48-48l0-96zM320 96l0 64 64 0 0-64-64 0zM304 32l96 0c26.5 0 48 21.5 48 48l0 96c0 26.5-21.5 48-48 48l-96 0c-26.5 0-48-21.5-48-48l0-96c0-26.5 21.5-48 48-48zM288 352a32 32 0 1 1 0-64 32 32 0 1 1 0 64zm0 64c17.7 0 32 14.3 32 32s-14.3 32-32 32-32-14.3-32-32 14.3-32 32-32zm96 32c0-17.7 14.3-32 32-32s32 14.3 32 32-14.3 32-32 32-32-14.3-32-32zm32-96a32 32 0 1 1 0-64 32 32 0 1 1 0 64zm-32 32a32 32 0 1 1 -64 0 32 32 0 1 1 64 0z",{"w":802,"h":802,"d":819},"M257.5 27.6c-.8-5.4-4.9-9.8-10.3-10.6-22.1-3.1-44.6 .9-64.4 11.4l-74 39.5C89.1 78.4 73.2 94.9 63.4 115L26.7 190.6c-9.8 20.1-13 42.9-9.1 64.9l14.5 82.8c3.9 22.1 14.6 42.3 30.7 57.9l60.3 58.4c16.1 15.6 36.6 25.6 58.7 28.7l83 11.7c22.1 3.1 44.6-.9 64.4-11.4l74-39.5c19.7-10.5 35.6-27 45.4-47.2l36.7-75.5c9.8-20.1 13-42.9 9.1-64.9-.9-5.3-5.3-9.3-10.6-10.1-51.5-8.2-92.8-47.1-104.5-97.4-1.8-7.6-8-13.4-15.7-14.6-54.6-8.7-97.7-52-106.2-106.8zM208 144a32 32 0 1 1 0 64 32 32 0 1 1 0-64zM144 336a32 32 0 1 1 64 0 32 32 0 1 1 -64 0zm224-64a32 32 0 1 1 0 64 32 32 0 1 1 0-64z",{"w":801,"h":802,"d":821},"M284.6 0l91.4 0 0 160-48 0 0-112-36.6 0-203.4 58.1 0 181.9 40 0 0 224-128 0 0-224 40 0 0-218.1 17.4-5 224-64 3.2-.9zM80 336l-32 0 0 128 32 0 0-128zm176 8c0-76.8 64-136 96-152 32 16 96 75.2 96 152 0 32-16 80-64 112l32 40 0 16-128 0 0-16 32-40c-48-32-64-80-64-112zm128-32a24 24 0 1 0 -48 0 24 24 0 1 0 48 0z",{"w":801,"h":802,"d":823},"M144-16l-48 112-48 0 0 48 48 0 0 32c0 17 3.3 33.2 9.3 48l-73.3 0 0 32 5.3 16 26.7 80-64 160 51.7 0 56.9-142.2 6.5-16.3c-1-3.1-10.1-30.3-27.2-81.5l51.4 0c22.6 19.9 52.2 32 84.7 32s62.1-12.1 84.7-32l51.4 0c-17.1 51.2-26.1 78.4-27.2 81.5l6.5 16.3 56.9 142.2 51.7 0-64-160 26.7-80 5.3-16 0-32-73.3 0c6-14.8 9.3-31 9.3-48l0-32 48 0 0-48-48 0-48-112-32 0-48 32-48-32-32 0zm80 272c-32.8 0-61-19.7-73.3-48l57.3 0 16-40 16 40 57.3 0c-12.3 28.3-40.5 48-73.3 48zm17.5 139.6l30.5-35.6 0-24-96 0 0 24 30.5 35.6-46.5 116.4 128 0-46.5-116.4z",{"w":802,"h":802,"d":825},"M497.4 49l17-17-33.9-33.9C473.6 4.9 453.3 25.2 419.7 58.8 375.4 22.1 318.5 0 256.4 0 115.1 0 .4 114.6 .4 256s114.6 256 256 256 256-114.6 256-256l-48 0c0 114.9-93.1 208-208 208s-208-93.1-208-208 93.1-208 208-208c48.8 0 93.7 16.8 129.1 44.9l-45.7 45.7c-23.5-16.8-52.3-26.6-83.4-26.6-79.5 0-144 64.5-144 144s64.5 144 144 144 144-64.5 144-144l-48 0c0 53-43 96-96 96s-96-43-96-96 43-96 96-96c17.8 0 34.5 4.8 48.8 13.3-52 52-79.5 79.5-82.7 82.7l33.9 33.9 17-17 224-224z",{"w":802,"h":802,"d":827},"M208 0l24 0C386.6 0 512 125.4 512 280l0 24-48 0 0-24C464 151.9 360.1 48 232 48l-24 0 0-48zm24 96c101.6 0 184 82.4 184 184l0 24-48 0 0-24c0-75.1-60.9-136-136-136l-24 0 0-48 24 0zM48 256c0 114.9 93.1 208 208 208 22.9 0 45-3.7 65.6-10.5l-263-263C51.7 211 48 233.1 48 256zM0 256c0-36.5 7.6-71.3 21.4-102.7 6.7-15.3 14.9-29.9 24.4-43.5 7.7 7.7 61.5 61.5 161.2 161.2 30.5-30.5 49.5-49.5 57-57L297.9 248c-7.5 7.5-26.5 26.5-57 57 99.7 99.7 153.5 153.5 161.2 161.2-13.6 9.5-28.2 17.7-43.5 24.4-31.4 13.8-66.2 21.4-102.7 21.4-141.4 0-256-114.6-256-256z",{"w":802,"h":802,"d":829},"M267.6 4.5l207.5 80.5 19.2 7.4 1.2 20.5c2.9 50-4.9 126.3-37.3 200.9-32.7 75.2-91.1 150-189.4 192.5l-12.7 5.5-12.7-5.5C144.9 463.9 86.6 389.2 53.9 313.9 21.5 239.3 13.7 162.9 16.6 113L17.8 92.5 37 85 244.5 4.5 256 0 267.6 4.5zM64.1 126C63.1 169.5 71 232.9 97.9 294.8 126.1 359.7 175 422.4 256 459.6 337.1 422.4 385.9 359.7 414.2 294.8 441 232.9 449 169.5 448 126L256 51.5 64.1 126zm302.3 44.7L352.3 190.1 249.8 330.9 233 354c-8.8-9.1-30.9-32-66.2-68.6l-16.7-17.3 34.5-33.3c9.5 9.8 23.9 24.7 43.2 44.7l85.6-117.7 14.1-19.4 38.8 28.2z",{"w":802,"h":802,"d":831},"M192 48l40 0 0 108-12.4 0c-7.6-16.5-24.3-28-43.6-28-26.5 0-48 21.5-48 48s21.5 48 48 48c19.4 0 36.1-11.5 43.6-28l12.4 0 0 56-92 0 0 56.4c-16.5 7.6-28 24.3-28 43.6 0 26.5 21.5 48 48 48s48-21.5 48-48c0-19.4-11.5-36.1-28-43.6l0-16.4 52 0 0 172-40 0c-16.8 0-31.2-10.3-37.1-25.1l-6.4-16-17.2 1c-1.1 .1-2.2 .1-3.2 .1-30.9 0-56-25.1-56-56 0-9.5 2.4-18.5 6.5-26.3l8.7-16.2-13.4-12.6c-11-10.2-17.8-24.8-17.8-40.9 0-21.6 12.2-40.4 30.3-49.8l22.6-11.7-13.1-21.9c-5-8.4-7.9-18.1-7.9-28.6 0-30.9 25.1-56 56-56l24 0 0-32c0-13.3 10.7-24 24-24zm88 148l12.4 0c7.6 16.5 24.3 28 43.6 28 26.5 0 48-21.5 48-48s-21.5-48-48-48c-19.4 0-36.1 11.5-43.6 28l-12.4 0 0-108 40 0c13.3 0 24 10.7 24 24l0 32 24 0c30.9 0 56 25.1 56 56 0 10.5-2.9 20.3-7.9 28.6l-13.1 21.9 22.6 11.7c18 9.3 30.3 28.1 30.3 49.8 0 16.1-6.8 30.7-17.8 40.9l-13.4 12.6 8.7 16.2c4.2 7.8 6.5 16.7 6.5 26.3 0 30.9-25.1 56-56 56-1.1 0-2.2 0-3.2-.1l-17.2-1-6.4 16C351.2 453.7 336.8 464 320 464l-40 0 0-76 92 0 0-56.4c16.5-7.6 28-24.3 28-43.6 0-26.5-21.5-48-48-48s-48 21.5-48 48c0 19.4 11.5 36.1 28 43.6l0 16.4-52 0 0-152zM192 512l128 0c31.1 0 58.4-16.2 74.1-40.5 52.7-5.1 93.9-49.5 93.9-103.5 0-11.5-1.9-22.5-5.3-32.9 13.4-17.5 21.3-39.4 21.3-63.1 0-32-14.5-60.6-37.1-79.7 3.3-10.2 5.1-21.1 5.1-32.3 0-49.6-34.8-91.1-81.3-101.5-6.3-33.3-35.6-58.5-70.7-58.5L192 0c-35.1 0-64.4 25.2-70.7 58.5-46.5 10.4-81.3 51.9-81.3 101.5 0 11.3 1.8 22.2 5.1 32.3-22.7 19.1-37.1 47.7-37.1 79.7 0 23.7 8 45.6 21.3 63.1-3.5 10.4-5.3 21.4-5.3 32.9 0 54 41.2 98.5 93.9 103.5 15.6 24.3 42.9 40.5 74.1 40.5zM336 192a16 16 0 1 1 0-32 16 16 0 1 1 0 32zm32 96a16 16 0 1 1 -32 0 16 16 0 1 1 32 0zM176 352a16 16 0 1 1 -32 0 16 16 0 1 1 32 0zm16-176a16 16 0 1 1 -32 0 16 16 0 1 1 32 0z",{"w":814,"h":802,"d":833},"M16 64C16 28.7 44.7 0 80 0L304 0c35.3 0 64 28.7 64 64l0 384c0 35.3-28.7 64-64 64L80 512c-35.3 0-64-28.7-64-64L16 64zm64 0l0 304 224 0 0-304-224 0zM192 472c17.7 0 32-14.3 32-32s-14.3-32-32-32-32 14.3-32 32 14.3 32 32 32z",{"w":802,"h":802,"d":835},"M0 256c0-46.6 12.5-90.4 34.3-128.9L144.1 318.3c21.9 39.2 63.8 65.7 111.9 65.7 14.3 0 27.1-2.3 40.8-6.6L220.5 509.6C95.9 492.3 0 385.3 0 256zm365.1 65.6c12.3-19.2 18.9-42.5 18.9-65.6 0-38.2-16.8-72.5-43.3-96l152.7 0c12 29.6 18.6 62.1 18.6 96 0 141.4-114.6 255.1-256 256L365.1 321.6zM477.8 128L256 128c-62.9 0-113.7 44.1-125.5 102.7L54.2 98.5C101 38.5 174 0 256 0 350.8 0 433.5 51.5 477.8 128zM344 256a88 88 0 1 1 -176 0 88 88 0 1 1 176 0z",{"w":802,"h":802,"d":837},"M448 96l0 256-384 0 0-256 384 0zM64 32C28.7 32 0 60.7 0 96L0 352c0 35.3 28.7 64 64 64l144 0-16 48-72 0c-13.3 0-24 10.7-24 24s10.7 24 24 24l272 0c13.3 0 24-10.7 24-24s-10.7-24-24-24l-72 0-16-48 144 0c35.3 0 64-28.7 64-64l0-256c0-35.3-28.7-64-64-64L64 32z",{"w":802,"h":802,"d":839},"M32 64C19.1 64 7.4 71.8 2.4 83.8S.2 109.5 9.4 118.6L192 301.3 192 416c0 8.5 3.4 16.6 9.4 22.6l64 64c9.2 9.2 22.9 11.9 34.9 6.9S320 492.9 320 480l0-178.7 182.6-182.6c9.2-9.2 11.9-22.9 6.9-34.9S492.9 64 480 64L32 64z",{"w":811,"h":802,"d":841},"M144 480c-79.5 0-144-64.5-144-144 0-63.4 41-117.2 97.9-136.5-1.3-7.7-1.9-15.5-1.9-23.5 0-79.5 64.5-144 144-144 55.4 0 103.5 31.3 127.6 77.1 14.2-8.3 30.8-13.1 48.4-13.1 53 0 96 43 96 96 0 15.7-3.8 30.6-10.5 43.7 44 20.3 74.5 64.7 74.5 116.3 0 70.7-57.3 128-128 128l-304 0zM305 191c-9.4-9.4-24.6-9.4-33.9 0l-72 72c-9.4 9.4-9.4 24.6 0 33.9s24.6 9.4 33.9 0l31-31 0 102.1c0 13.3 10.7 24 24 24s24-10.7 24-24l0-102.1 31 31c9.4 9.4 24.6 9.4 33.9 0s9.4-24.6 0-33.9l-72-72z",[843,4083,7995,11119,16634,19716,21067,23661,25816,28672,31293,33177,35571,37658,39284,43195,45464,48557,50417,56276,57974,60257,62185,66978],{"id":844,"title":845,"authorsCollection":846,"content":854,"extension":228,"faqItemsCollection":1763,"faqTitle":59,"featured":6,"hashTags":59,"meta":1765,"metaTitle":1766,"ogImage":59,"postType":1767,"publishedDate":1768,"relatedBlogPostsCollection":1769,"slug":4027,"stem":4028,"subtitle":59,"summary":4029,"synopsis":4040,"sys":4041,"tagsCollection":4044,"topicsCollection":4050,"__hash__":4082},"blog/blog/why-modern-browser-attacks-evade-edr.json","Your EDR is working exactly as intended. Attackers are getting around it anyway.",{"items":847},[848],{"fullName":849,"firstName":850,"jobTitle":851,"socialLinks":59,"profilePicture":852},"Peyton Padfield","Peyton","Product Team",{"url":853},"https://images.ctfassets.net/y1cdw1ablpvd/1GU01HXElmc07nwi89qP3b/3188050420106c62e9df2ed4e4893b7f/1677005177901__1_.jpeg",{"json":855,"links":1681},{"data":856,"content":857,"nodeType":1680},{},[858,869,877,884,891,898,920,939,943,951,958,977,986,1005,1012,1015,1023,1030,1037,1044,1051,1059,1077,1084,1101,1108,1125,1132,1149,1156,1187,1193,1196,1204,1211,1219,1250,1258,1265,1272,1280,1321,1327,1330,1338,1345,1353,1360,1367,1375,1382,1390,1397,1405,1412,1440,1446,1449,1457,1464,1472,1479,1486,1494,1501,1508,1515,1523,1530,1537,1543,1546,1554,1561,1630,1638,1658,1661],{"data":859,"content":860,"nodeType":868},{},[861],{"data":862,"marks":863,"value":866,"nodeType":867},{},[864],{"type":865},"bold","Why endpoint security has a blind spot in the browser ","text","heading-1",{"data":870,"content":871,"nodeType":876},{},[872],{"data":873,"marks":874,"value":875,"nodeType":867},{},[],"Modern EDR makes compromising the OS hard. Process execution, memory behavior, file system changes: all of it under real-time scrutiny from an agent that never sleeps. Getting in through the endpoint is expensive, noisy, and increasingly not worth the effort.","paragraph",{"data":878,"content":879,"nodeType":876},{},[880],{"data":881,"marks":882,"value":883,"nodeType":867},{},[],"So attackers expanded their focus. ",{"data":885,"content":886,"nodeType":876},{},[887],{"data":888,"marks":889,"value":890,"nodeType":867},{},[],"The browser is the logical target. It's where work happens now. Authentication, data access, application administration, sensitive file handling — all of it inside a browser tab, with no real security instrumentation, no behavioral detection, and no one paying attention. ",{"data":892,"content":893,"nodeType":876},{},[894],{"data":895,"marks":896,"value":897,"nodeType":867},{},[],"The endpoint got Falcon, Defender, Singularity, Cortex, etc. The browser didn't. And the economics made the choice obvious: a PhaaS kit that proxies credentials and steals session tokens costs about $1k a year, a credential list off a dark web marketplace runs $15, and an admin-level account from an initial access broker goes for a few thousand dollars. None of those require getting past an endpoint agent.",{"data":899,"content":900,"nodeType":876},{},[901,905,916],{"data":902,"marks":903,"value":904,"nodeType":867},{},[],"We've written before about ",{"data":906,"content":908,"nodeType":915},{"uri":907},"https://pushsecurity.com/blog/push-plus-endpoint-security",[909],{"data":910,"marks":911,"value":914,"nodeType":867},{},[912],{"type":913},"underline","how Push and endpoint security fit together","hyperlink",{"data":917,"marks":918,"value":919,"nodeType":867},{},[]," and how the two layers complement each other. This post goes further into why succeeding at securing the endpoint isn't enough on its own, and why the gap between what EDR sees and what actually happens in the browser is exactly where attackers have built their playbook.",{"data":921,"content":922,"nodeType":876},{},[923,926,935],{"data":924,"marks":925,"value":21,"nodeType":867},{},[],{"data":927,"content":929,"nodeType":915},{"uri":928},"https://www.crowdstrike.com/explore/2026-global-threat-report",[930],{"data":931,"marks":932,"value":934,"nodeType":867},{},[933],{"type":913},"82% of attack detections are now malware-free",{"data":936,"marks":937,"value":938,"nodeType":867},{},[],", according to CrowdStrike's 2026 Global Threat Report, and that's not because attackers got more sophisticated. If anything, the barrier to entry is considerably lower now. It's because they got smarter about where to target their efforts.",{"data":940,"content":941,"nodeType":942},{},[],"hr",{"data":944,"content":945,"nodeType":868},{},[946],{"data":947,"marks":948,"value":950,"nodeType":867},{},[949],{"type":865},"What EDR actually sees",{"data":952,"content":953,"nodeType":876},{},[954],{"data":955,"marks":956,"value":957,"nodeType":867},{},[],"Before behavioral detection, defense meant chasing known-bad indicators: a malicious hash was identified, it got blocked, the attacker changed the hash, and the cycle repeated indefinitely. EDR broke that dynamic by running an agent inside the operating system and watching what actually happened on the host — process execution, file system changes, memory behavior, registry modifications.",{"data":959,"content":960,"nodeType":876},{},[961,965,973],{"data":962,"marks":963,"value":964,"nodeType":867},{},[],"The ",{"data":966,"content":968,"nodeType":915},{"uri":967},"https://pushsecurity.com/blog/our-design-philosophy-detecting-what-matters/",[969],{"data":970,"marks":971,"value":972,"nodeType":867},{},[],"Pyramid of Pain",{"data":974,"marks":975,"value":976,"nodeType":867},{},[]," explains why this worked. Tools and indicators at the bottom of the pyramid are trivially easy for attackers to rotate, while behavioral TTPs at the top are expensive to change. EDR moved detection up the pyramid, which is why fileless attacks, living-off-the-land techniques, and lateral movement started getting caught. It's also why attackers shifted their focus away from the OS.",{"data":978,"content":984,"nodeType":985},{"target":979},{"sys":980},{"id":981,"type":982,"linkType":983},"2N04ycJ6RKGfHdX5X1TwU3","Link","Entry",[],"embedded-entry-block",{"data":987,"content":988,"nodeType":876},{},[989,993,1001],{"data":990,"marks":991,"value":992,"nodeType":867},{},[],"All of that visibility ends at the browser boundary. From the EDR agent's perspective, Chrome is a well-behaved process. It opens, connects to the internet, does browser things. The agent can see the process, but it can't see which tab is open, what the page is rendering, what scripts are executing, or whether the login form the user just submitted was real or a convincing ",{"data":994,"content":996,"nodeType":915},{"uri":995},"https://pushsecurity.com/blog/2025-top-phishing-trends/",[997],{"data":998,"marks":999,"value":1000,"nodeType":867},{},[],"cloned page",{"data":1002,"marks":1003,"value":1004,"nodeType":867},{},[],". It doesn't know whether the session token that just got issued is about to leave the organization.",{"data":1006,"content":1007,"nodeType":876},{},[1008],{"data":1009,"marks":1010,"value":1011,"nodeType":867},{},[],"For browser-based attacks, EDR registers nothing unusual, because nothing unusual happened at the OS layer. EDR worked — but the attackers worked around it.",{"data":1013,"content":1014,"nodeType":942},{},[],{"data":1016,"content":1017,"nodeType":868},{},[1018],{"data":1019,"marks":1020,"value":1022,"nodeType":867},{},[1021],{"type":865},"The attack surface has moved beyond the endpoint",{"data":1024,"content":1025,"nodeType":876},{},[1026],{"data":1027,"marks":1028,"value":1029,"nodeType":867},{},[],"Attackers didn't stumble into the browser. They moved there deliberately, and the tooling reflects it.",{"data":1031,"content":1032,"nodeType":876},{},[1033],{"data":1034,"marks":1035,"value":1036,"nodeType":867},{},[],"The numbers tell the story. PhaaS-driven account compromise surged 389% year-over-year according to eSentire. Fake CAPTCHA lures used in ClickFix attacks increased 563% in 2025, according to CrowdStrike, and ClickFix is now the most common initial access vector observed by Microsoft, accounting for 47% of attacks. ",{"data":1038,"content":1039,"nodeType":876},{},[1040],{"data":1041,"marks":1042,"value":1043,"nodeType":867},{},[],"We see it too; in a single 30-day proof-of-value deployment at a financial services organization, Push detected 6 ClickFix attacks and 10 AiTM phishing attempts that were invisible to the existing security stack.",{"data":1045,"content":1046,"nodeType":876},{},[1047],{"data":1048,"marks":1049,"value":1050,"nodeType":867},{},[],"These aren't niche techniques. They're the dominant playbook, and none of them need to touch the endpoint to succeed, or for an attacker to achieve their goals.",{"data":1052,"content":1053,"nodeType":1058},{},[1054],{"data":1055,"marks":1056,"value":261,"nodeType":867},{},[1057],{"type":865},"heading-2",{"data":1060,"content":1061,"nodeType":876},{},[1062,1065,1073],{"data":1063,"marks":1064,"value":21,"nodeType":867},{},[],{"data":1066,"content":1068,"nodeType":915},{"uri":1067},"https://pushsecurity.com/solution/stop-browser-based-attacks/adversary-in-the-middle-attacks",[1069],{"data":1070,"marks":1071,"value":1072,"nodeType":867},{},[],"AiTM phishing kits",{"data":1074,"marks":1075,"value":1076,"nodeType":867},{},[]," render a convincing login page inside the browser, proxy the authentication in real time, and lift the session token as it passes through. The user completes what feels like a normal login; the attacker gets a valid session. The OS saw a browser connecting to a website.",{"data":1078,"content":1079,"nodeType":1058},{},[1080],{"data":1081,"marks":1082,"value":571,"nodeType":867},{},[1083],{"type":865},{"data":1085,"content":1086,"nodeType":876},{},[1087,1090,1097],{"data":1088,"marks":1089,"value":21,"nodeType":867},{},[],{"data":1091,"content":1093,"nodeType":915},{"uri":1092},"https://pushsecurity.com/solution/stop-browser-based-attacks/session-hijacking",[1094],{"data":1095,"marks":1096,"value":571,"nodeType":867},{},[],{"data":1098,"marks":1099,"value":1100,"nodeType":867},{},[]," skips authentication entirely by targeting an existing session. By stealing and replaying a token acquired by an infostealer, or a malicious browser extension, they can import the session into their own browser and continue using it — there's no password prompt, no MFA challenge, no re-authentication. The session blends into normal browser activity and generates nothing an endpoint agent was built to catch.",{"data":1102,"content":1103,"nodeType":1058},{},[1104],{"data":1105,"marks":1106,"value":360,"nodeType":867},{},[1107],{"type":865},{"data":1109,"content":1110,"nodeType":876},{},[1111,1114,1121],{"data":1112,"marks":1113,"value":21,"nodeType":867},{},[],{"data":1115,"content":1117,"nodeType":915},{"uri":1116},"https://pushsecurity.com/blog/device-code-phishing/",[1118],{"data":1119,"marks":1120,"value":360,"nodeType":867},{},[],{"data":1122,"marks":1123,"value":1124,"nodeType":867},{},[]," is harder to spot, because the user authenticates on a legitimate identity provider page. The attacker initiates a device authorization flow and tricks the user into entering a code on the real Microsoft (or Google or GitHub) login page. The IdP issues a valid token. The phishing happened before the authentication page even loaded, and the session token goes straight to the attacker. Push has documented a 37x increase in device code phishing attacks this year, with 12+ unique kits now offering the technique.",{"data":1126,"content":1127,"nodeType":1058},{},[1128],{"data":1129,"marks":1130,"value":315,"nodeType":867},{},[1131],{"type":865},{"data":1133,"content":1134,"nodeType":876},{},[1135,1138,1145],{"data":1136,"marks":1137,"value":21,"nodeType":867},{},[],{"data":1139,"content":1141,"nodeType":915},{"uri":1140},"https://pushsecurity.com/solution/stop-browser-based-attacks/clickfix-fix-variants",[1142],{"data":1143,"marks":1144,"value":315,"nodeType":867},{},[],{"data":1146,"marks":1147,"value":1148,"nodeType":867},{},[]," takes a different approach: the lure tricks the user into copying a malicious payload to their clipboard and running it themselves, framed as a verification step or a fix for a page that won't load. It's social engineering dressed up as a CAPTCHA. Unlike the attacks above, ClickFix is a hybrid — the delivery and lure happen in the browser, but the payload executes on the endpoint. That split is important when we get to how the detection layers divide.",{"data":1150,"content":1151,"nodeType":876},{},[1152],{"data":1153,"marks":1154,"value":1155,"nodeType":867},{},[],"The attacks look different on the surface, but the design principle is the same: stay out of the OS, stay inside the browser, and stay invisible to every tool that's watching the endpoint.",{"data":1157,"content":1158,"nodeType":876},{},[1159,1163,1171,1175,1183],{"data":1160,"marks":1161,"value":1162,"nodeType":867},{},[],"Once access to an app is established via a compromised identity, attackers can also achieve their goals without touching the endpoint. Most of the time, this involves data theft and extortion, but adversaries like ",{"data":1164,"content":1166,"nodeType":915},{"uri":1165},"https://pushsecurity.com/blog/analyzing-the-instructure-breach/",[1167],{"data":1168,"marks":1169,"value":1170,"nodeType":867},{},[],"ShinyHunters",{"data":1172,"marks":1173,"value":1174,"nodeType":867},{},[]," and ",{"data":1176,"content":1178,"nodeType":915},{"uri":1177},"https://pushsecurity.com/blog/scattered-lapsus-hunters/",[1179],{"data":1180,"marks":1181,"value":1182,"nodeType":867},{},[],"Scattered Spider",{"data":1184,"marks":1185,"value":1186,"nodeType":867},{},[]," are also experts in cloud-based disruption and destruction techniques — with no ransomware binary dropped to user endpoints for an EDR agent to intercept. ",{"data":1188,"content":1192,"nodeType":985},{"target":1189},{"sys":1190},{"id":1191,"type":982,"linkType":983},"4eZcjfuT34oQoKIZAsZCr4",[],{"data":1194,"content":1195,"nodeType":942},{},[],{"data":1197,"content":1198,"nodeType":868},{},[1199],{"data":1200,"marks":1201,"value":1203,"nodeType":867},{},[1202],{"type":865},"The EDR you're using doesn't change the result",{"data":1205,"content":1206,"nodeType":876},{},[1207],{"data":1208,"marks":1209,"value":1210,"nodeType":867},{},[],"The constraint isn't vendor-specific. Every EDR's observation model stops at the OS layer because that's where the agent sits. What happens inside a browser session is outside that model by design. A better EDR doesn't close the gap; a different layer does.",{"data":1212,"content":1213,"nodeType":1058},{},[1214],{"data":1215,"marks":1216,"value":1218,"nodeType":867},{},[1217],{"type":865},"Reputation-based filtering falls short too",{"data":1220,"content":1221,"nodeType":876},{},[1222,1226,1234,1238,1246],{"data":1223,"marks":1224,"value":1225,"nodeType":867},{},[],"Some platforms add URL filtering or domain reputation checks at the browser boundary, and that narrows the surface somewhat. But reputation-based filtering hits the same wall against PhaaS infrastructure engineered to rotate domains before reputation databases catch up. ",{"data":1227,"content":1229,"nodeType":915},{"uri":1228},"https://www.spamhaus.com/resource-center/supporting-researchers-with-passive-dns/",[1230],{"data":1231,"marks":1232,"value":1233,"nodeType":867},{},[],"89% of phishing domains are active for fewer than two days",{"data":1235,"marks":1236,"value":1237,"nodeType":867},{},[],". A reputation engine can't flag infrastructure it hasn't seen, and ",{"data":1239,"content":1241,"nodeType":915},{"uri":1240},"https://pushsecurity.com/blog/phishing-detection-evasion-launch/",[1242],{"data":1243,"marks":1244,"value":1245,"nodeType":867},{},[],"modern phishing operations",{"data":1247,"marks":1248,"value":1249,"nodeType":867},{},[]," are designed around that window.",{"data":1251,"content":1252,"nodeType":1058},{},[1253],{"data":1254,"marks":1255,"value":1257,"nodeType":867},{},[1256],{"type":865},"Some vendors recognize the problem",{"data":1259,"content":1260,"nodeType":876},{},[1261],{"data":1262,"marks":1263,"value":1264,"nodeType":867},{},[],"The market has started to acknowledge this. CrowdStrike's acquisition of Seraphic is a direct signal that endpoint vendors see the browser gap and want to close it, and it validates what we've been building here at Push since day one. That's a good thing for defenders — the more coverage at this layer, the better.",{"data":1266,"content":1267,"nodeType":876},{},[1268],{"data":1269,"marks":1270,"value":1271,"nodeType":867},{},[],"But endpoint vendors see the world through the endpoint. Their platforms, their telemetry models, and their detection logic are all structured around what happens at the OS layer. When they acquire browser capability, it gets pulled into that orbit. Seraphic was built to detect browser exploits by injecting into the browser's JavaScript runtime from the OS. ",{"data":1273,"content":1274,"nodeType":1058},{},[1275],{"data":1276,"marks":1277,"value":1279,"nodeType":867},{},[1278],{"type":865},"Attacks in vs. on the browser: why this distinction matters",{"data":1281,"content":1282,"nodeType":876},{},[1283,1287,1295,1299,1305,1309,1317],{"data":1284,"marks":1285,"value":1286,"nodeType":867},{},[],"In other words, ",{"data":1288,"content":1290,"nodeType":915},{"uri":1289},"https://pushsecurity.com/blog/how-to-avoid-the-browser-security-buyers-trap/",[1291],{"data":1292,"marks":1293,"value":1294,"nodeType":867},{},[],"their focus is on attacks on the browser itself",{"data":1296,"marks":1297,"value":1298,"nodeType":867},{},[],", rather than those happening ",{"data":1300,"marks":1301,"value":1304,"nodeType":867},{},[1302],{"type":1303},"italic","inside",{"data":1306,"marks":1307,"value":1308,"nodeType":867},{},[]," the browser session. That's a meaningful capability, but it's a different problem from detecting the identity attacks that dominate the threat landscape today — AiTM phishing, session hijacking, OAuth consent abuse, ClickFix — where the attacker never triggers an exploit and the browser works exactly as designed. We've written in detail aboutwhy that ",{"data":1310,"content":1311,"nodeType":915},{"uri":1289},[1312],{"data":1313,"marks":1314,"value":1316,"nodeType":867},{},[1315],{"type":913},"architectural distinction matters",{"data":1318,"marks":1319,"value":1320,"nodeType":867},{},[]," for buyers evaluating the category.",{"data":1322,"content":1326,"nodeType":985},{"target":1323},{"sys":1324},{"id":1325,"type":982,"linkType":983},"37815BxUTO55avL4molrA5",[],{"data":1328,"content":1329,"nodeType":942},{},[],{"data":1331,"content":1332,"nodeType":868},{},[1333],{"data":1334,"marks":1335,"value":1337,"nodeType":867},{},[1336],{"type":865},"What browser-native detection actually looks like",{"data":1339,"content":1340,"nodeType":876},{},[1341],{"data":1342,"marks":1343,"value":1344,"nodeType":867},{},[],"Network tools and reputation engines see where a user went and whether the destination had a known-bad reputation. What they can't see is what happened on the page once the user got there — whether the login form was real or a proxied clone, whether a session token was issued and where it went next.",{"data":1346,"content":1347,"nodeType":1058},{},[1348],{"data":1349,"marks":1350,"value":1352,"nodeType":867},{},[1351],{"type":865},"Why network-layer detection can't keep up",{"data":1354,"content":1355,"nodeType":876},{},[1356],{"data":1357,"marks":1358,"value":1359,"nodeType":867},{},[],"At the network layer, a brand-new domain hosting a pixel-perfect Microsoft login page is indistinguishable from the real thing. There's no signal to act on — the domain is in good standing, the TLS cert is valid, and the traffic looks normal.",{"data":1361,"content":1362,"nodeType":876},{},[1363],{"data":1364,"marks":1365,"value":1366,"nodeType":867},{},[],"But it's not as simple as looking at the page itself. The phishing pages attackers are building now don't look like the clone-and-paste jobs of a few years ago. Attackers are vibe-coding imitations where the AI has constructed the page from scratch — visually identical to the real login page, but with a completely different underlying structure. They look the same to the user and to any tool doing a surface-level comparison. You need to understand how credential-harvesting mechanics actually work, how authentication relay is structured, and what behavioral fingerprints phishing kits leave behind regardless of how the page was built.",{"data":1368,"content":1369,"nodeType":1058},{},[1370],{"data":1371,"marks":1372,"value":1374,"nodeType":867},{},[1373],{"type":865},"How Push detects what others miss",{"data":1376,"content":1377,"nodeType":876},{},[1378],{"data":1379,"marks":1380,"value":1381,"nodeType":867},{},[],"That's where Push's visibility and expertise intersect. Running inside the browser, Push sees DOM structure, script behavior, how credential forms are constructed, and how authentication is being relayed. Phishing attacks leave consistent behavioral fingerprints at this level regardless of what domain they're hosted on, which kit family they belong to, or whether the page was hand-coded or vibe-coded in minutes. Push catches attacks built on infrastructure that's never appeared on any blocklist, because it isn't looking at the infrastructure. It's looking at what the page is doing.",{"data":1383,"content":1384,"nodeType":1058},{},[1385],{"data":1386,"marks":1387,"value":1389,"nodeType":867},{},[1388],{"type":865},"Where the detection layers divide",{"data":1391,"content":1392,"nodeType":876},{},[1393],{"data":1394,"marks":1395,"value":1396,"nodeType":867},{},[],"ClickFix illustrates how the layers split. Push identifies the page behavior delivering the lure and analyzes the clipboard payload before the user runs it — two detection points, both inside the browser, both before anything reaches the endpoint. EDR's window opens after execution. Push and EDR are watching the same attack from opposite ends of the kill chain.",{"data":1398,"content":1399,"nodeType":1058},{},[1400],{"data":1401,"marks":1402,"value":1404,"nodeType":867},{},[1403],{"type":865},"Keeping pace with AI-accelerated attacks",{"data":1406,"content":1407,"nodeType":876},{},[1408],{"data":1409,"marks":1410,"value":1411,"nodeType":867},{},[],"That detection model has to keep pace with an attack surface that's evolving at machine speed. Attackers are using AI to vibe-code phishing kits, generate convincing cloned pages, and rotate infrastructure faster than any human team can track.",{"data":1413,"content":1414,"nodeType":876},{},[1415,1419,1427,1431,1436],{"data":1416,"marks":1417,"value":1418,"nodeType":867},{},[],"Push matches that pace with an ",{"data":1420,"content":1422,"nodeType":915},{"uri":1421},"https://pushsecurity.com/blog/can-ai-replace-a-threat-researcher-what-we-learned-building-an-agentic-threat-hunting-pipeline/",[1423],{"data":1424,"marks":1425,"value":1426,"nodeType":867},{},[],"agentic threat hunting pipeline",{"data":1428,"marks":1429,"value":1430,"nodeType":867},{},[],": autonomous agents hunt continuously across browser telemetry from over ",{"data":1432,"marks":1433,"value":1435,"nodeType":867},{},[1434],{"type":865},"3 million browsers worldwide",{"data":1437,"marks":1438,"value":1439,"nodeType":867},{},[],", develop hypotheses, analyze traces, and write detection rules without waiting for human initiation. Push's in-house threat researchers feed the agents the context they need — years of accumulated knowledge about how browser-based attacks actually work. The agents operationalize that expertise at a scale and speed no human team could sustain alone.",{"data":1441,"content":1445,"nodeType":985},{"target":1442},{"sys":1443},{"id":1444,"type":982,"linkType":983},"27crXZtdoKOl08wDzLFnBO",[],{"data":1447,"content":1448,"nodeType":942},{},[],{"data":1450,"content":1451,"nodeType":868},{},[1452],{"data":1453,"marks":1454,"value":1456,"nodeType":867},{},[1455],{"type":865},"Two layers that fit together",{"data":1458,"content":1459,"nodeType":876},{},[1460],{"data":1461,"marks":1462,"value":1463,"nodeType":867},{},[],"Browser detection and endpoint detection cover different surfaces. Together they close the gap.",{"data":1465,"content":1466,"nodeType":1058},{},[1467],{"data":1468,"marks":1469,"value":1471,"nodeType":867},{},[1470],{"type":865},"Response at the speed of the attack",{"data":1473,"content":1474,"nodeType":876},{},[1475],{"data":1476,"marks":1477,"value":1478,"nodeType":867},{},[],"Push doesn't just detect — the detection comes with response built in. Phishing pages are blocked before credentials are submitted. Malicious clipboard payloads are intercepted before the user can run them. Suspicious OAuth consent grants are flagged or blocked in real time, before the authorization completes. These aren't after-the-fact alerts that require an analyst to act; they're inline controls that operate at the speed of the attack.",{"data":1480,"content":1481,"nodeType":876},{},[1482],{"data":1483,"marks":1484,"value":1485,"nodeType":867},{},[],"For purely browser-based attacks like AiTM phishing, device code phishing, and OAuth consent abuse, Push is both the detection and the response layer. For ClickFix, the coverage divides: Push catches the delivery and the clipboard payload, and if the user runs it and something lands on the OS, EDR picks up what happens next.",{"data":1487,"content":1488,"nodeType":1058},{},[1489],{"data":1490,"marks":1491,"value":1493,"nodeType":867},{},[1492],{"type":865},"The telemetry bridge",{"data":1495,"content":1496,"nodeType":876},{},[1497],{"data":1498,"marks":1499,"value":1500,"nodeType":867},{},[],"The integration with endpoint tooling is straightforward. Push feeds browser telemetry into the same SIEM and XDR workflows endpoint data already flows into.",{"data":1502,"content":1503,"nodeType":876},{},[1504],{"data":1505,"marks":1506,"value":1507,"nodeType":867},{},[],"EDR tells you what happened on the host. Push tells you what happened in the session before the host was involved — which login page loaded, how it behaved, whether a session token left the organization. That's the causal link most investigation timelines are missing: the bridge between \"a user visited a URL\" and \"credentials were submitted to a phishing page that proxied authentication and captured the session token.\"",{"data":1509,"content":1510,"nodeType":876},{},[1511],{"data":1512,"marks":1513,"value":1514,"nodeType":867},{},[],"Without browser-layer telemetry, that chain of events is invisible — the EDR sees normal endpoint processes and the SIEM sees a successful login. An alert from either layer is more useful with context from the other, and the range of problems you can solve from inside the browser extends well beyond threat detection.",{"data":1516,"content":1517,"nodeType":1058},{},[1518],{"data":1519,"marks":1520,"value":1522,"nodeType":867},{},[1521],{"type":865},"Deployment without disruption",{"data":1524,"content":1525,"nodeType":876},{},[1526],{"data":1527,"marks":1528,"value":1529,"nodeType":867},{},[],"Operationally, adding the browser layer doesn't mean adding complexity. Push deploys as a browser extension — no network changes, no TLS inspection, no browser replacement, and no impact on page load times or browsing performance.",{"data":1531,"content":1532,"nodeType":876},{},[1533],{"data":1534,"marks":1535,"value":1536,"nodeType":867},{},[],"Unlike approaches that route traffic through a proxy or render pages remotely, Push operates natively inside the browser session, which means there's no latency penalty and no disruption to how employees work. ",{"data":1538,"content":1542,"nodeType":985},{"target":1539},{"sys":1540},{"id":1541,"type":982,"linkType":983},"3w1g0UvGN28HBOTxeZlIfc",[],{"data":1544,"content":1545,"nodeType":942},{},[],{"data":1547,"content":1548,"nodeType":868},{},[1549],{"data":1550,"marks":1551,"value":1553,"nodeType":867},{},[1552],{"type":865},"A quick check on your coverage",{"data":1555,"content":1556,"nodeType":876},{},[1557],{"data":1558,"marks":1559,"value":1560,"nodeType":867},{},[],"If you're running EDR and assume the browser is covered, these are worth thinking through. ",{"data":1562,"content":1563,"nodeType":1629},{},[1564,1587,1609,1619],{"data":1565,"content":1566,"nodeType":1586},{},[1567],{"data":1568,"content":1569,"nodeType":876},{},[1570,1574,1582],{"data":1571,"marks":1572,"value":1573,"nodeType":867},{},[],"Can you identify which browser extensions across your fleet have the ",{"data":1575,"content":1577,"nodeType":915},{"uri":1576},"https://pushsecurity.com/blog/why-browser-extension-risk-scoring-wont-predict-your-next-breach/",[1578],{"data":1579,"marks":1580,"value":1581,"nodeType":867},{},[],"permissions needed for account takeover",{"data":1583,"marks":1584,"value":1585,"nodeType":867},{},[],"? ","list-item",{"data":1588,"content":1589,"nodeType":1586},{},[1590],{"data":1591,"content":1592,"nodeType":876},{},[1593,1597,1605],{"data":1594,"marks":1595,"value":1596,"nodeType":867},{},[],"Would anything stop a ",{"data":1598,"content":1600,"nodeType":915},{"uri":1599},"https://pushsecurity.com/blog/introducing-malicious-copy-paste-detection/",[1601],{"data":1602,"marks":1603,"value":1604,"nodeType":867},{},[],"ClickFix payload",{"data":1606,"marks":1607,"value":1608,"nodeType":867},{},[]," before your user ran it? ",{"data":1610,"content":1611,"nodeType":1586},{},[1612],{"data":1613,"content":1614,"nodeType":876},{},[1615],{"data":1616,"marks":1617,"value":1618,"nodeType":867},{},[],"Do you have visibility into every account your employees have created outside of SSO, and whether those accounts are protected by MFA or using weak, breached, or reused passwords? ",{"data":1620,"content":1621,"nodeType":1586},{},[1622],{"data":1623,"content":1624,"nodeType":876},{},[1625],{"data":1626,"marks":1627,"value":1628,"nodeType":867},{},[],"When a session token gets stolen, do you have any signal when the attacker starts using it?","unordered-list",{"data":1631,"content":1632,"nodeType":876},{},[1633],{"data":1634,"marks":1635,"value":1637,"nodeType":867},{},[1636],{"type":865},"Push surfaces answers to all of them — across every browser session.",{"data":1639,"content":1640,"nodeType":876},{},[1641,1645,1654],{"data":1642,"marks":1643,"value":1644,"nodeType":867},{},[],"Defenders secured the endpoint. Attackers took note, and they've had the browser to themselves ever since. The attacker tooling that followed was built for an environment where the endpoint is watched and the session layer isn't. That's been a reasonable assumption for the better part of a decade. Endpoint vendors are starting to move toward the browser, but there's a case for ",{"data":1646,"content":1648,"nodeType":915},{"uri":1647},"https://pushsecurity.com/blog/the-case-for-best-of-breed-browser-security/",[1649],{"data":1650,"marks":1651,"value":1653,"nodeType":867},{},[1652],{"type":913},"purpose-built browser security",{"data":1655,"marks":1656,"value":1657,"nodeType":867},{},[]," rather than bolted-on features from platforms designed for a different layer. The endpoint is covered. The browser is where the work is now.",{"data":1659,"content":1660,"nodeType":942},{},[],{"data":1662,"content":1663,"nodeType":876},{},[1664,1668,1676],{"data":1665,"marks":1666,"value":1667,"nodeType":867},{},[],"Push Security is the most powerful AI-native security tool in the browser. Think EDR, but for the browser — high-fidelity telemetry and real-time control across every session, on every device, with no browser migration required. ",{"data":1669,"content":1671,"nodeType":915},{"uri":1670},"https://pushsecurity.com/book-demo/",[1672],{"data":1673,"marks":1674,"value":1675,"nodeType":867},{},[],"Book a live demo to learn more",{"data":1677,"marks":1678,"value":1679,"nodeType":867},{},[],".","document",{"entries":1682},{"hyperlink":1683,"inline":1684,"block":1685},[],[],[1686,1695,1703,1723,1749],{"sys":1687,"__typename":1688,"title":1689,"caption":1690,"layoutMode":59,"file":1691},{"id":981},"Image","Pyramid of Pain for internet-based attacks","The Pyramid of Pain reworked for internet-based attacks.",{"url":1692,"width":1693,"height":1694},"https://images.ctfassets.net/y1cdw1ablpvd/2KJMvUn55yStIIB5jIcy0n/c64a1d128567ed1189821b8160f81fe7/image6.png",1999,1149,{"sys":1696,"__typename":1697,"type":1698,"ctaText":1699,"buttonLabel":1700,"buttonColour":1701,"buttonUrl":1702},{"id":1191},"CtaWidget","Custom","Read our browser attack techniques report for more information on these attack techniques and how attackers are leveraging them in browser-native breaches that don't touch the endpoint detection surface.","Download now (no gates!)","sunny orange","https://pushsecurity.com/thank-you/browser-attacks-report",{"sys":1704,"__typename":1705,"content":1706,"name":1722,"title":59},{"id":1325},"InsightTextBlockComponent",{"json":1707},{"nodeType":1680,"data":1708,"content":1709},{},[1710],{"nodeType":876,"data":1711,"content":1712},{},[1713,1717],{"nodeType":867,"value":1714,"marks":1715,"data":1716},"Push was built for the browser from the start, for exactly these attacks. The detection engine runs inside the session. The response actions operate at the session layer, blocking phishing pages, intercepting malicious clipboard payloads, and warning on suspicious OAuth consent grants, because that's where the attack is happening. ",[],{},{"nodeType":867,"value":1718,"marks":1719,"data":1721},"That's not a philosophical matter. It determines what you can catch and how fast you can stop it.",[1720],{"type":865},{},"EDR blog IB1",{"sys":1724,"__typename":1705,"content":1725,"name":1748,"title":59},{"id":1444},{"json":1726},{"nodeType":1680,"data":1727,"content":1728},{},[1729],{"nodeType":876,"data":1730,"content":1731},{},[1732,1736,1744],{"nodeType":867,"value":1733,"marks":1734,"data":1735},"Since deploying the pipeline, we've 3x'ed our detection output (but with ",[],{},{"nodeType":915,"data":1737,"content":1739},{"uri":1738},"https://pushsecurity.com/blog/the-pyramid-of-pain-in-the-ai-era/",[1740],{"nodeType":867,"value":1741,"marks":1742,"data":1743},"broad technique-level detections, not just IoC noise",[],{},{"nodeType":867,"value":1745,"marks":1746,"data":1747},"). New detections move from discovery to customer protection in minutes rather than the days or weeks a manual process required.",[],{},"EDR blog IB2",{"sys":1750,"__typename":1705,"content":1751,"name":1762,"title":59},{"id":1541},{"json":1752},{"nodeType":1680,"data":1753,"content":1754},{},[1755],{"nodeType":876,"data":1756,"content":1757},{},[1758],{"nodeType":867,"value":1759,"marks":1760,"data":1761},"Push has been deployed to 100,000 users in under an hour during normal business hours with zero downtime, and it sits alongside whatever endpoint and network tooling is already in place.",[],{},"EDR blog IB3",{"items":1764},[],{},"How attackers get around endpoint security controls like EDR","thought-leadership","2026-06-02T00:00:00.000Z",{"items":1770},[1771,2718,3249],{"__typename":1772,"sys":1773,"content":1775,"title":2699,"synopsis":2700,"hashTags":59,"publishedDate":1768,"slug":2701,"tagsCollection":2702,"authorsCollection":2711},"BlogPosts",{"id":1774},"I5SoVIYsYVgutpLIzZRpC",{"json":1776},{"data":1777,"content":1778,"nodeType":1680},{},[1779,1786,1793,1814,1821,1828,1831,1839,1846,1853,1876,1883,1890,1896,1899,1907,1914,1920,1927,1935,1967,1986,1992,2000,2007,2013,2033,2041,2048,2080,2086,2101,2104,2112,2119,2125,2142,2149,2156,2168,2188,2195,2202,2210,2217,2236,2242,2249,2255,2261,2264,2272,2279,2286,2349,2356,2363,2370,2377,2393,2400,2407,2414,2421,2428,2435,2442,2449,2456,2463,2470,2477,2484,2487,2495,2502,2514,2521,2528,2535,2542,2665,2671,2677,2680],{"data":1780,"content":1781,"nodeType":876},{},[1782],{"data":1783,"marks":1784,"value":1785,"nodeType":867},{},[],"When is a fork not a fork? When it's a browser security platform built to solve both problems of the AI era.",{"data":1787,"content":1788,"nodeType":876},{},[1789],{"data":1790,"marks":1791,"value":1792,"nodeType":867},{},[],"Many security leaders are rightly worried about two big problems in the age of AI: AI-enabled attacks targeting their employees via the browser; and employees introducing the risk of data loss through their use of AI tools.",{"data":1794,"content":1795,"nodeType":876},{},[1796,1801,1805,1810],{"data":1797,"marks":1798,"value":1800,"nodeType":867},{},[1799],{"type":865},"For security teams researching browser-based solutions to these challenges, the decision at first looks like a fork in the road: ",{"data":1802,"marks":1803,"value":1804,"nodeType":867},{},[],"Choose a solution that's purpose-built to detect and respond to modern browser-based attacks like AI-enabled phish kits, ClickFix and other *Fix-style attacks, malicious browser extensions, device code phishing, and others; ",{"data":1806,"marks":1807,"value":1809,"nodeType":867},{},[1808],{"type":1303},"or",{"data":1811,"marks":1812,"value":1813,"nodeType":867},{},[]," select an AI governance tool to enforce sensible policies for sensitive data in the browser.",{"data":1815,"content":1816,"nodeType":876},{},[1817],{"data":1818,"marks":1819,"value":1820,"nodeType":867},{},[],"Push solves both of these problems. One platform, one SKU.",{"data":1822,"content":1823,"nodeType":876},{},[1824],{"data":1825,"marks":1826,"value":1827,"nodeType":867},{},[],"In this article, we'll take a look at the two big AI security and data governance problems that security teams are facing and outline how Push solves them in a single solution. We’ll cover what questions to ask as you evaluate browser security solutions, and describe Push's focus on providing foundational telemetry, detections, and controls that allow you to answer the question “What actually happened here?” not just “What policy was violated?”",{"data":1829,"content":1830,"nodeType":942},{},[],{"data":1832,"content":1833,"nodeType":868},{},[1834],{"data":1835,"marks":1836,"value":1838,"nodeType":867},{},[1837],{"type":865},"The AI risks every security team is now responsible for",{"data":1840,"content":1841,"nodeType":876},{},[1842],{"data":1843,"marks":1844,"value":1845,"nodeType":867},{},[],"AI is an amplifier, for adversaries and for your employees. Whatever they could do before, they can now do faster, more powerfully, and at scale.",{"data":1847,"content":1848,"nodeType":876},{},[1849],{"data":1850,"marks":1851,"value":1852,"nodeType":867},{},[],"The two risks that every security team now must manage: ",{"data":1854,"content":1855,"nodeType":1629},{},[1856,1866],{"data":1857,"content":1858,"nodeType":1586},{},[1859],{"data":1860,"content":1861,"nodeType":876},{},[1862],{"data":1863,"marks":1864,"value":1865,"nodeType":867},{},[],"AI is making browser-based attacks faster, cheaper, and harder to detect.",{"data":1867,"content":1868,"nodeType":1586},{},[1869],{"data":1870,"content":1871,"nodeType":876},{},[1872],{"data":1873,"marks":1874,"value":1875,"nodeType":867},{},[],"Employee AI adoption is creating data exposure faster than security teams can respond.",{"data":1877,"content":1878,"nodeType":876},{},[1879],{"data":1880,"marks":1881,"value":1882,"nodeType":867},{},[],"Both of these challenges intersect in the same place: The browser. It's the place where adversaries target employees with modern attacks designed to accomplish account takeover and data exfiltration. It's also the place where workers discover and use new AI-enabled apps and introduce risk into the business in the form of data loss, shadow apps, risky browser extensions, and shadow integrations.",{"data":1884,"content":1885,"nodeType":876},{},[1886],{"data":1887,"marks":1888,"value":1889,"nodeType":867},{},[],"To address both problems, security teams need visibility and control in the browser.",{"data":1891,"content":1895,"nodeType":985},{"target":1892},{"sys":1893},{"id":1894,"type":982,"linkType":983},"1U2Hmn4XrFpdcxyjxY3aCc",[],{"data":1897,"content":1898,"nodeType":942},{},[],{"data":1900,"content":1901,"nodeType":868},{},[1902],{"data":1903,"marks":1904,"value":1906,"nodeType":867},{},[1905],{"type":865},"How AI is transforming attacks",{"data":1908,"content":1909,"nodeType":876},{},[1910],{"data":1911,"marks":1912,"value":1913,"nodeType":867},{},[],"On the adversary side of the equation, adversaries are using AI tooling to rapidly iterate on new attack types or new iterations of existing browser-based TTPs that target employees to achieve account or endpoint compromise — usually with the end goal of harvesting valuable corporate identities in order to exfiltrate data or hold it for ransom.",{"data":1915,"content":1919,"nodeType":985},{"target":1916},{"sys":1917},{"id":1918,"type":982,"linkType":983},"G8xv1seFz1wJnY5HpfV6z",[],{"data":1921,"content":1922,"nodeType":876},{},[1923],{"data":1924,"marks":1925,"value":1926,"nodeType":867},{},[],"AI is changing attacks in three key ways.",{"data":1928,"content":1929,"nodeType":1058},{},[1930],{"data":1931,"marks":1932,"value":1934,"nodeType":867},{},[1933],{"type":865},"AI has supercharged the iteration and evolution of adversary tools and techniques",{"data":1936,"content":1937,"nodeType":876},{},[1938,1942,1951,1955,1963],{"data":1939,"marks":1940,"value":1941,"nodeType":867},{},[],"Attackers are using the same AI capabilities as any other engineer who wants to multiply their output. That translates to an array of new attack techniques: multiple increasingly sophisticated variations of the ",{"data":1943,"content":1945,"nodeType":915},{"uri":1944},"https://pushsecurity.com/blog/consentfix-v3-analyzing-a-new-toolkit/",[1946],{"data":1947,"marks":1948,"value":1950,"nodeType":867},{},[1949],{"type":913},"ClickFix-style attacks",{"data":1952,"marks":1953,"value":1954,"nodeType":867},{},[]," that use social engineering techniques to get users to unknowingly install malware via malicious scripts; as well as creative ",{"data":1956,"content":1957,"nodeType":915},{"uri":1116},[1958],{"data":1959,"marks":1960,"value":1962,"nodeType":867},{},[1961],{"type":913},"exploitation of device codes",{"data":1964,"marks":1965,"value":1966,"nodeType":867},{},[],", a legitimate authentication mechanism, that allows attackers to phish access post-authentication.",{"data":1968,"content":1969,"nodeType":876},{},[1970,1974,1982],{"data":1971,"marks":1972,"value":1973,"nodeType":867},{},[],"Device code phishing in particular demonstrates the rapid growth of new techniques, with early documented appearances of the TTP occurring in 2024, and by early the next year, the method had been packaged as a PhaaS offering with GPT-enhanced spear-phishing and customized landing pages. The ",{"data":1975,"content":1977,"nodeType":915},{"uri":1976},"https://www.huntress.com/blog/device-code-phishing-ai-mfa-bypass",[1978],{"data":1979,"marks":1980,"value":1981,"nodeType":867},{},[],"campaign",{"data":1983,"marks":1984,"value":1985,"nodeType":867},{},[]," targeted more than 340 organizations across five countries in March 2026, using personalized AI-generated lures at a scale that would have been impractical to produce manually.",{"data":1987,"content":1991,"nodeType":985},{"target":1988},{"sys":1989},{"id":1990,"type":982,"linkType":983},"eNUpU2GtGOcXRrHBKHnLN",[],{"data":1993,"content":1994,"nodeType":1058},{},[1995],{"data":1996,"marks":1997,"value":1999,"nodeType":867},{},[1998],{"type":865},"Infrastructure-based detections are increasingly degraded by AI-enabled approaches",{"data":2001,"content":2002,"nodeType":876},{},[2003],{"data":2004,"marks":2005,"value":2006,"nodeType":867},{},[],"AI has also collapsed the cost and time it takes to build convincing phishing infrastructure: Attackers can vibecode a convincing phishing page in minutes, burn the domain, and regenerate another one before any blocklist updates. ",{"data":2008,"content":2012,"nodeType":985},{"target":2009},{"sys":2010},{"id":2011,"type":982,"linkType":983},"2obvOhMWjy64h94tEIbx04",[],{"data":2014,"content":2015,"nodeType":876},{},[2016,2020,2029],{"data":2017,"marks":2018,"value":2019,"nodeType":867},{},[],"The impact on IOC-based detections that rely on infrastructure elements is severe: When elements constantly change, every phishing attack is essentially a zero-day. Complicating the picture further is the increasing use of legitimate cloud platforms like ",{"data":2021,"content":2023,"nodeType":915},{"uri":2022},"https://www.huntress.com/blog/railway-paas-m365-token-replay-campaign",[2024],{"data":2025,"marks":2026,"value":2028,"nodeType":867},{},[2027],{"type":913},"Railway",{"data":2030,"marks":2031,"value":2032,"nodeType":867},{},[],", Cloudflare Workers, and Vercel, which attackers use to host and dynamically rotate attack infrastructure.",{"data":2034,"content":2035,"nodeType":1058},{},[2036],{"data":2037,"marks":2038,"value":2040,"nodeType":867},{},[2039],{"type":865},"AI is making it easier to build and run omni-channel campaigns",{"data":2042,"content":2043,"nodeType":876},{},[2044],{"data":2045,"marks":2046,"value":2047,"nodeType":867},{},[],"Push researchers have written extensively over the last year about malvertising campaigns that serve malicious pages to users via search engine results, enticing them to visit sites designed to steal credentials or deliver malware. ",{"data":2049,"content":2050,"nodeType":876},{},[2051,2055,2064,2068,2076],{"data":2052,"marks":2053,"value":2054,"nodeType":867},{},[],"We've tracked ",{"data":2056,"content":2058,"nodeType":915},{"uri":2057},"https://pushsecurity.com/blog/cyber-criminal-ecosystem-analysis/",[2059],{"data":2060,"marks":2061,"value":2063,"nodeType":867},{},[2062],{"type":913},"sustained campaigns",{"data":2065,"marks":2066,"value":2067,"nodeType":867},{},[]," impersonating Onfido, TradingView, Ahrefs, Semrush, and others. These campaigns are part of a self-reinforcing criminal ecosystem: Malvertising campaigns paid for by stolen ad accounts, with credential theft that funds the next round of credential theft. And the recent ",{"data":2069,"content":2071,"nodeType":915},{"uri":2070},"https://pushsecurity.com/blog/llmshare-malvertising-campaign/",[2072],{"data":2073,"marks":2074,"value":2075,"nodeType":867},{},[],"LLMShare",{"data":2077,"marks":2078,"value":2079,"nodeType":867},{},[]," campaign identified by Push shows how attackers are combining their abuse of AI tools of AI-assisted phishing page creation with malvertising, helping them to spin up lookalike pages quickly and cheaply to serve as convincing lures.",{"data":2081,"content":2085,"nodeType":985},{"target":2082},{"sys":2083},{"id":2084,"type":982,"linkType":983},"2Gwj25KBjClQ5u8uiEYuYR",[],{"data":2087,"content":2088,"nodeType":876},{},[2089,2093,2098],{"data":2090,"marks":2091,"value":2092,"nodeType":867},{},[],"These are just a few examples of how phishing has moved beyond the inbox, targeting users through malvertising, SEO poisoning, and social media DMs. Over the last year, Push researchers found that ",{"data":2094,"marks":2095,"value":2097,"nodeType":867},{},[2096],{"type":865},"1 in 3 payloads intercepted by the platform were sent outside of email",{"data":2099,"marks":2100,"value":1679,"nodeType":867},{},[],{"data":2102,"content":2103,"nodeType":942},{},[],{"data":2105,"content":2106,"nodeType":868},{},[2107],{"data":2108,"marks":2109,"value":2111,"nodeType":867},{},[2110],{"type":865},"How AI is creating risky employee behaviors ",{"data":2113,"content":2114,"nodeType":876},{},[2115],{"data":2116,"marks":2117,"value":2118,"nodeType":867},{},[],"Meanwhile, on the employee side of the equation, there are three other key concerns that security teams should be paying attention to when it comes to the risks associated with AI use.",{"data":2120,"content":2124,"nodeType":985},{"target":2121},{"sys":2122},{"id":2123,"type":982,"linkType":983},"2hsKQ9DEspflhmtR0bE7QY",[],{"data":2126,"content":2127,"nodeType":1058},{},[2128,2133,2137],{"data":2129,"marks":2130,"value":2132,"nodeType":867},{},[2131],{"type":865},"Data leaving the business via shadow AI",{"data":2134,"marks":2135,"value":2136,"nodeType":867},{},[]," ",{"data":2138,"marks":2139,"value":2141,"nodeType":867},{},[2140],{"type":865},"and AI extensions",{"data":2143,"content":2144,"nodeType":876},{},[2145],{"data":2146,"marks":2147,"value":2148,"nodeType":867},{},[],"Employees are signing up to AI tools directly, beyond the bounds of procurement or security review. That means security teams can't see sensitive data going into LLMs — clipboard pastes of API keys, file uploads to coding assistants, customer data in uploaded spreadsheets, etc.",{"data":2150,"content":2151,"nodeType":876},{},[2152],{"data":2153,"marks":2154,"value":2155,"nodeType":867},{},[],"Most teams also don't have visibility of AI browser extensions, another avenue for data to leave the business. Extensions are also an attack surface in their own right, as previously benign extensions can be compromised by threat actors through account takeover of the extension developer.",{"data":2157,"content":2158,"nodeType":1058},{},[2159,2164],{"data":2160,"marks":2161,"value":2163,"nodeType":867},{},[2162],{"type":865},"Employees using personal accounts on corporate AI app tenants",{"data":2165,"marks":2166,"value":2167,"nodeType":867},{},[]," ",{"data":2169,"content":2170,"nodeType":876},{},[2171,2175,2184],{"data":2172,"marks":2173,"value":2174,"nodeType":867},{},[],"The 2026 ",{"data":2176,"content":2178,"nodeType":915},{"uri":2177},"https://www.verizon.com/business/resources/reports/dbir/",[2179],{"data":2180,"marks":2181,"value":2183,"nodeType":867},{},[2182],{"type":913},"Verizon DBIR",{"data":2185,"marks":2186,"value":2187,"nodeType":867},{},[]," found that 67% of GenAI users on corporate devices are using non-corporate accounts, and our own data shows that 38% of file uploads to AI tools are made from shadow accounts rather than approved organizational ones.",{"data":2189,"content":2190,"nodeType":876},{},[2191],{"data":2192,"marks":2193,"value":2194,"nodeType":867},{},[],"That means a large number of employees in most organizations are using AI apps with personal accounts, outside of organizational data governance, retention policies, access controls, or basic security oversight. ",{"data":2196,"content":2197,"nodeType":876},{},[2198],{"data":2199,"marks":2200,"value":2201,"nodeType":867},{},[],"The compounding risk is that personal accounts are typically protected by weaker passwords, inconsistent MFA, and credential reuse from other personal services — meaning a compromise of the personal account could give an attacker access to corporate data and tools.",{"data":2203,"content":2204,"nodeType":1058},{},[2205],{"data":2206,"marks":2207,"value":2209,"nodeType":867},{},[2208],{"type":865},"Shadow integrations between AI tools and corporate systems",{"data":2211,"content":2212,"nodeType":876},{},[2213],{"data":2214,"marks":2215,"value":2216,"nodeType":867},{},[],"App-to-app connections accomplished through OAuth are also proliferating faster than most teams can observe and review them. For the average organization, Push sees 17 unique AI app OAuth integrations connected just to Microsoft and Google corporate tenants.",{"data":2218,"content":2219,"nodeType":876},{},[2220,2223,2232],{"data":2221,"marks":2222,"value":964,"nodeType":867},{},[],{"data":2224,"content":2226,"nodeType":915},{"uri":2225},"https://pushsecurity.com/blog/unpacking-the-vercel-breach/",[2227],{"data":2228,"marks":2229,"value":2231,"nodeType":867},{},[2230],{"type":913},"recent Vercel breach",{"data":2233,"marks":2234,"value":2235,"nodeType":867},{},[]," illustrates the risks of even a single OAuth connection from a compromised third-party AI SaaS provider. This isn't really a new AI threat so much as a shadow SaaS problem that's accelerating alongside AI adoption, given that AI apps are specifically designed to pull data from one system, analyze it in another, and present it in a third — with MCP connections now creating the same kind of persistent, permissioned access through an authentication protocol (OAuth) that most organizations have no process to review.",{"data":2237,"content":2241,"nodeType":985},{"target":2238},{"sys":2239},{"id":2240,"type":982,"linkType":983},"1t2jn4fLxMlH0adMyQqkXk",[],{"data":2243,"content":2244,"nodeType":876},{},[2245],{"data":2246,"marks":2247,"value":2248,"nodeType":867},{},[],"This is the same web of OAuth-connected apps that is being exposed at scale through AI tool integrations. For many organizations, AI tools are now the hub of modern activity that orchestrates and automates across the mesh of cloud apps, which adds a useful perspective on what's changed. ",{"data":2250,"content":2254,"nodeType":985},{"target":2251},{"sys":2252},{"id":2253,"type":982,"linkType":983},"6cRnPkGdwWXRWcct6LfMzo",[],{"data":2256,"content":2260,"nodeType":985},{"target":2257},{"sys":2258},{"id":2259,"type":982,"linkType":983},"5WQZNpnPETWeys1VqubVW",[],{"data":2262,"content":2263,"nodeType":942},{},[],{"data":2265,"content":2266,"nodeType":868},{},[2267],{"data":2268,"marks":2269,"value":2271,"nodeType":867},{},[2270],{"type":865},"What to ask when evaluating browser-based AI visibility and control solutions",{"data":2273,"content":2274,"nodeType":876},{},[2275],{"data":2276,"marks":2277,"value":2278,"nodeType":867},{},[],"When you're evaluating AI visibility and control platforms that operate in the browser, there are two lines of questioning that can be useful to unpack.",{"data":2280,"content":2281,"nodeType":876},{},[2282],{"data":2283,"marks":2284,"value":2285,"nodeType":867},{},[],"The first is the tactical basics: What use cases does the product cover, and how quickly will you see value? In this category, you'll likely be looking for:",{"data":2287,"content":2288,"nodeType":1629},{},[2289,2304,2319,2334],{"data":2290,"content":2291,"nodeType":1586},{},[2292],{"data":2293,"content":2294,"nodeType":876},{},[2295,2300],{"data":2296,"marks":2297,"value":2299,"nodeType":867},{},[2298],{"type":865},"Depth of visibility:",{"data":2301,"marks":2302,"value":2303,"nodeType":867},{},[]," Can the solution observe both corporate and personal account usage of AI apps? Does the solution work with all major browsers, including emerging AI browsers? Does the solution automatically classify AI apps and automatically discover shadow AI?",{"data":2305,"content":2306,"nodeType":1586},{},[2307],{"data":2308,"content":2309,"nodeType":876},{},[2310,2315],{"data":2311,"marks":2312,"value":2314,"nodeType":867},{},[2313],{"type":865},"Granularity of controls:",{"data":2316,"marks":2317,"value":2318,"nodeType":867},{},[]," Does the solution support visibility and control over clipboard interactions, allowing you to identify sensitive data strings like personal access tokens (PATs) or API keys? Does the solution allow you to set multiple enforcement modes (monitor, warn, block) and carve out exceptions for tools, teams and individuals where necessary? ",{"data":2320,"content":2321,"nodeType":1586},{},[2322],{"data":2323,"content":2324,"nodeType":876},{},[2325,2330],{"data":2326,"marks":2327,"value":2329,"nodeType":867},{},[2328],{"type":865},"Ease of deployment:",{"data":2331,"marks":2332,"value":2333,"nodeType":867},{},[]," How is the solution deployed? Browser extension-based solutions like Push can be deployed at scale in an hour. Solutions that require an endpoint agent or a complete browser replacement will be a heavier lift.",{"data":2335,"content":2336,"nodeType":1586},{},[2337],{"data":2338,"content":2339,"nodeType":876},{},[2340,2345],{"data":2341,"marks":2342,"value":2344,"nodeType":867},{},[2343],{"type":865},"Scope of coverage:",{"data":2346,"marks":2347,"value":2348,"nodeType":867},{},[]," Does the solution only enforce policy around AI usage, or does it also prevent AI-enabled attacks in the browser? ",{"data":2350,"content":2351,"nodeType":876},{},[2352],{"data":2353,"marks":2354,"value":2355,"nodeType":867},{},[],"The second set of questions is more about the underlying architectural choices a product has made, and how those translate into actionable intelligence for security teams — or where there may be blind spots. In this category, you will want to ask:",{"data":2357,"content":2358,"nodeType":1058},{},[2359],{"data":2360,"marks":2361,"value":2362,"nodeType":867},{},[],"Does the tool capture AI interactions that didn’t trigger a policy violation — or only the ones it blocked?",{"data":2364,"content":2365,"nodeType":876},{},[2366],{"data":2367,"marks":2368,"value":2369,"nodeType":867},{},[],"This is the most useful diagnostic if you're focused on understanding the wider security meaning and impact of an AI interaction, not just whether it violated a policy. ",{"data":2371,"content":2372,"nodeType":876},{},[2373],{"data":2374,"marks":2375,"value":2376,"nodeType":867},{},[],"Enforcement-first tools record what they stopped: blocked uploads, attempted usage of unapproved apps, flagged file names, etc. ",{"data":2378,"content":2379,"nodeType":876},{},[2380,2384,2389],{"data":2381,"marks":2382,"value":2383,"nodeType":867},{},[],"That's useful for compliance reporting but incomplete for security investigation, because ",{"data":2385,"marks":2386,"value":2388,"nodeType":867},{},[2387],{"type":865},"the most significant events are often the ones that looked normal at the time",{"data":2390,"marks":2391,"value":2392,"nodeType":867},{},[],": A user whose behavior shifted gradually over weeks before a resignation. An approved AI browser extension that updates its permissions, putting it in risky territory. An OAuth consent grant that was technically permitted but shouldn't have been.",{"data":2394,"content":2395,"nodeType":876},{},[2396],{"data":2397,"marks":2398,"value":2399,"nodeType":867},{},[],"Ask whether the tool can collect user behavior telemetry, file upload and download activity, and AI usage logs for permitted events — not just policy violations — and whether that telemetry can be forwarded to your SIEM. ",{"data":2401,"content":2402,"nodeType":876},{},[2403],{"data":2404,"marks":2405,"value":2406,"nodeType":867},{},[],"One approach gives you an investigation tool. The other gives you compliance alerts without deeper context.",{"data":2408,"content":2409,"nodeType":1058},{},[2410],{"data":2411,"marks":2412,"value":2413,"nodeType":867},{},[],"When an AI agent requests OAuth permissions to access your organization's data, does the tool capture the consent flow — what scopes were requested on which app, which user initiated the consent, and what was the outcome?",{"data":2415,"content":2416,"nodeType":876},{},[2417],{"data":2418,"marks":2419,"value":2420,"nodeType":867},{},[],"Most enforcement-first tools treat OAuth as a binary: approved app or blocked app. That was a reasonable model when OAuth grants were primarily app-to-app integrations managed by IT. It isn't sufficient for agentic AI.",{"data":2422,"content":2423,"nodeType":876},{},[2424],{"data":2425,"marks":2426,"value":2427,"nodeType":867},{},[],"AI agents request OAuth permissions to access organizational data on behalf of users. These are user-initiated consent grants that happen inside browser sessions, often with broad scopes, and frequently without security team awareness. The right tool needs to capture the consent event itself: what permissions were requested, what scopes were granted, who approved them, and what application received them. ",{"data":2429,"content":2430,"nodeType":876},{},[2431],{"data":2432,"marks":2433,"value":2434,"nodeType":867},{},[],"Ask whether the tool monitors OAuth consent flows across authorization servers, whether it can warn or block consent grants in real time based on policy, and whether that coverage extends to AI-enabled apps and MCP connections.",{"data":2436,"content":2437,"nodeType":1058},{},[2438],{"data":2439,"marks":2440,"value":2441,"nodeType":867},{},[],"When a new browser attack technique emerges that no tool has a signature for, how long does it take the platform to detect it — and can you show a specific example?",{"data":2443,"content":2444,"nodeType":876},{},[2445],{"data":2446,"marks":2447,"value":2448,"nodeType":867},{},[],"Attackers are rotating infrastructure in hours and using AI to generate new lures and phishing pages at scale. A detection model built on blocklists, reputation feeds, and known-bad indicators is architecturally behind any novel technique because by the time the indicator appears on a feed, the attacker has already moved on.",{"data":2450,"content":2451,"nodeType":876},{},[2452],{"data":2453,"marks":2454,"value":2455,"nodeType":867},{},[],"Ask vendors to show you a specific detection that fired on a novel technique before the infrastructure appeared on any threat feed.",{"data":2457,"content":2458,"nodeType":1058},{},[2459],{"data":2460,"marks":2461,"value":2462,"nodeType":867},{},[],"What browser telemetry reaches your SIEM — just alerts, or the underlying session data that makes those alerts investigable?",{"data":2464,"content":2465,"nodeType":876},{},[2466],{"data":2467,"marks":2468,"value":2469,"nodeType":867},{},[],"Ask to see a sample SIEM event from a real detection. Many browser security tools integrate with SIEMs, but the depth of what they forward varies a lot. ",{"data":2471,"content":2472,"nodeType":876},{},[2473],{"data":2474,"marks":2475,"value":2476,"nodeType":867},{},[],"Some send alert metadata that captures policy violations, timestamps, and involved users. Others forward a broader set of telemetry for deeper context — credential reuse, app logins, newly installed extensions, detected phishing kits, file uploads, clipboard activity, OAuth consent flows, file downloads, etc. ",{"data":2478,"content":2479,"nodeType":876},{},[2480],{"data":2481,"marks":2482,"value":2483,"nodeType":867},{},[],"The difference determines whether your SOC team can easily correlate signals from the browser-based tool with other layers of their stack and begin an investigation from the SIEM event itself — or whether they need to pivot back into the vendor's console for the actual evidence.",{"data":2485,"content":2486,"nodeType":942},{},[],{"data":2488,"content":2489,"nodeType":868},{},[2490],{"data":2491,"marks":2492,"value":2494,"nodeType":867},{},[2493],{"type":865},"AI visibility and control is a feature of the right browser security platform, not a separate purchase",{"data":2496,"content":2497,"nodeType":876},{},[2498],{"data":2499,"marks":2500,"value":2501,"nodeType":867},{},[],"Ultimately, the choice of browser platform for solving the two big problems of the AI era comes down to whether you need broader attack coverage and telemetry context in order to secure your organization, or whether a policy-based approach is enough. ",{"data":2503,"content":2504,"nodeType":876},{},[2505,2509],{"data":2506,"marks":2507,"value":2508,"nodeType":867},{},[],"Push treats the challenges of stopping AI-enabled attacks and providing visibility and control over AI usage as features that extend naturally from the platform's underlying architectural model: Rich browser-layer telemetry in ",{"data":2510,"marks":2511,"value":2513,"nodeType":867},{},[2512],{"type":865},"a single tool that helps security teams answer the question “What actually happened here?” not just “What policy was violated?”",{"data":2515,"content":2516,"nodeType":876},{},[2517],{"data":2518,"marks":2519,"value":2520,"nodeType":867},{},[],"This unified architecture matters because the AI control problem and the browser threat detection problem share a root cause: Security-relevant activity is happening inside browser sessions that most tools can't see. ",{"data":2522,"content":2523,"nodeType":876},{},[2524],{"data":2525,"marks":2526,"value":2527,"nodeType":867},{},[],"A standalone AI governance tool can tell you which AI apps are in use and whether employees violated a usage policy. It can't tell you whether the OAuth grant an AI agent just received was part of a broader pattern that includes credential entry on an unfamiliar domain, a clipboard paste from an internal document, and a login to a shadow SaaS app — all in the same session, all visible in the same telemetry stream. ",{"data":2529,"content":2530,"nodeType":876},{},[2531],{"data":2532,"marks":2533,"value":2534,"nodeType":867},{},[],"Separating AI governance from browser security means maintaining two tools that each only see half the picture. ",{"data":2536,"content":2537,"nodeType":1058},{},[2538],{"data":2539,"marks":2540,"value":2541,"nodeType":867},{},[],"How Push can help",{"data":2543,"content":2544,"nodeType":1629},{},[2545,2568,2590,2612,2622,2632,2642],{"data":2546,"content":2547,"nodeType":1586},{},[2548],{"data":2549,"content":2550,"nodeType":876},{},[2551,2555,2564],{"data":2552,"marks":2553,"value":2554,"nodeType":867},{},[],"Block emerging ",{"data":2556,"content":2558,"nodeType":915},{"uri":2557},"https://pushsecurity.com/blog/introducing-the-browser-and-identity-attacks-matrix/",[2559],{"data":2560,"marks":2561,"value":2563,"nodeType":867},{},[2562],{"type":913},"browser-based attack techniques",{"data":2565,"marks":2566,"value":2567,"nodeType":867},{},[],", including AI-enabled phishing and quickly evolving *Fix-style attacks.",{"data":2569,"content":2570,"nodeType":1586},{},[2571],{"data":2572,"content":2573,"nodeType":876},{},[2574,2578,2586],{"data":2575,"marks":2576,"value":2577,"nodeType":867},{},[],"Benefit from Push's ",{"data":2579,"content":2580,"nodeType":915},{"uri":1421},[2581],{"data":2582,"marks":2583,"value":2585,"nodeType":867},{},[2584],{"type":913},"agentic detection pipeline",{"data":2587,"marks":2588,"value":2589,"nodeType":867},{},[],", which continuously hunts across customer environments to identify emerging threats and ship new detections.",{"data":2591,"content":2592,"nodeType":1586},{},[2593],{"data":2594,"content":2595,"nodeType":876},{},[2596,2599,2608],{"data":2597,"marks":2598,"value":21,"nodeType":867},{},[],{"data":2600,"content":2602,"nodeType":915},{"uri":2601},"https://pushsecurity.com/help/audience/engineering/rest-v1",[2603],{"data":2604,"marks":2605,"value":2607,"nodeType":867},{},[2606],{"type":913},"Stream telemetry",{"data":2609,"marks":2610,"value":2611,"nodeType":867},{},[]," to your SIEM for a wide variety of events, including attack detections; newly installed browser extensions or newly adopted apps; updates to extension permissions; file uploads and downloads; clipboard pastes; app logins; credential reuse; OAuth consents; and more.",{"data":2613,"content":2614,"nodeType":1586},{},[2615],{"data":2616,"content":2617,"nodeType":876},{},[2618],{"data":2619,"marks":2620,"value":2621,"nodeType":867},{},[],"Block file uploads and downloads.",{"data":2623,"content":2624,"nodeType":1586},{},[2625],{"data":2626,"content":2627,"nodeType":876},{},[2628],{"data":2629,"marks":2630,"value":2631,"nodeType":867},{},[],"Block clipboard pastes of sensitive data, with regex-based patterns you can define.",{"data":2633,"content":2634,"nodeType":1586},{},[2635],{"data":2636,"content":2637,"nodeType":876},{},[2638],{"data":2639,"marks":2640,"value":2641,"nodeType":867},{},[],"Monitor for or block unauthorized MCP connections.",{"data":2643,"content":2644,"nodeType":1586},{},[2645],{"data":2646,"content":2647,"nodeType":876},{},[2648,2652,2661],{"data":2649,"marks":2650,"value":2651,"nodeType":867},{},[],"Write your own ",{"data":2653,"content":2655,"nodeType":915},{"uri":2654},"https://pushsecurity.com/help/audience/engineering/resources/custom-detections",[2656],{"data":2657,"marks":2658,"value":2660,"nodeType":867},{},[2659],{"type":913},"custom YAML rules",{"data":2662,"marks":2663,"value":2664,"nodeType":867},{},[]," targeting specific elements of the page DOM, web requests and responses, HTTP headers such as cookies, and a lot more.",{"data":2666,"content":2667,"nodeType":876},{},[2668],{"data":2669,"marks":2670,"value":21,"nodeType":867},{},[],{"data":2672,"content":2676,"nodeType":985},{"target":2673},{"sys":2674},{"id":2675,"type":982,"linkType":983},"7AwQv7bLbARq6mdAgv7uGq",[],{"data":2678,"content":2679,"nodeType":942},{},[],{"data":2681,"content":2682,"nodeType":876},{},[2683,2687,2696],{"data":2684,"marks":2685,"value":2686,"nodeType":867},{},[],"If you'd like to learn more about Push, ",{"data":2688,"content":2690,"nodeType":915},{"uri":2689},"https://pushsecurity.com/demo",[2691],{"data":2692,"marks":2693,"value":2695,"nodeType":867},{},[2694],{"type":913},"book a live demo",{"data":2697,"marks":2698,"value":1679,"nodeType":867},{},[],"Why you can't control AI without being in the browser","Why the right browser security tool makes a separate AI visibility and control purchase unnecessary — and how to decide what you actually need.","why-you-cant-control-ai-without-being-in-the-browser",{"items":2703},[2704,2707],{"sys":2705,"name":297},{"id":2706},"3pjES4THCIfSAwhGdNwBcy",{"sys":2708,"name":2710},{"id":2709},"1gZi8NrRy2v9OqPV7C4dwD","Risk management",{"items":2712},[2713],{"fullName":2714,"firstName":2715,"jobTitle":851,"profilePicture":2716},"Kelly Davenport","Kelly",{"url":2717},"https://images.ctfassets.net/y1cdw1ablpvd/1hi8bEuVfn5sF57LivAq6d/9a3b82426c697d765e2e450e33a18424/kelly_profile_pic.jpeg",{"__typename":1772,"sys":2719,"content":2721,"title":3230,"synopsis":3231,"hashTags":59,"publishedDate":3232,"slug":3233,"tagsCollection":3234,"authorsCollection":3241},{"id":2720},"2MWicW07sNEBp59wxYtAiC",{"json":2722},{"data":2723,"content":2724,"nodeType":1680},{},[2725,2733,2764,2770,2777,2796,2811,2814,2822,2837,2856,2881,2887,2903,2934,2940,2946,2962,2965,2973,2980,2988,3006,3022,3029,3054,3061,3069,3099,3106,3114,3121,3127,3130,3138,3145,3153,3159,3162,3170,3177,3184,3191,3203,3206,3212],{"data":2726,"content":2727,"nodeType":868},{},[2728],{"data":2729,"marks":2730,"value":2732,"nodeType":867},{},[2731],{"type":865},"The quantification problem nobody talks about",{"data":2734,"content":2735,"nodeType":876},{},[2736,2740,2748,2752,2760],{"data":2737,"marks":2738,"value":2739,"nodeType":867},{},[],"I was recently teaching ",{"data":2741,"content":2743,"nodeType":915},{"uri":2742},"https://www.sans.org/cyber-security-courses/cybersecurity-leaders/",[2744],{"data":2745,"marks":2746,"value":2747,"nodeType":867},{},[],"SANS LDR551",{"data":2749,"marks":2750,"value":2751,"nodeType":867},{},[],", where we cover some of the flawed approaches used in risk measurement and prioritization — for example, presenting ordinal data in a risk matrix as ratio data, implying that the matrix represents quantitative analysis when it’s more of a best guess. We then look at modeling using ",{"data":2753,"content":2755,"nodeType":915},{"uri":2754},"https://en.wikipedia.org/wiki/Loss_exceedance_curve",[2756],{"data":2757,"marks":2758,"value":2759,"nodeType":867},{},[],"Loss Exceedance Curves",{"data":2761,"marks":2762,"value":2763,"nodeType":867},{},[]," as a more accurate, if much more difficult, approach to quantitative risk assessment.",{"data":2765,"content":2769,"nodeType":985},{"target":2766},{"sys":2767},{"id":2768,"type":982,"linkType":983},"4S1wJUm6E1qvyZzwrl2DL",[],{"data":2771,"content":2772,"nodeType":876},{},[2773],{"data":2774,"marks":2775,"value":2776,"nodeType":867},{},[],"The only problem is, we rarely have the time or the data to construct such models. Ask a CISO how they measure risk for credential compromise and other account takeover attacks, and the answer will probably include one or more of the following: a risk assessment, a whiteboard, and a room full of smart people making educated guesses about attack frequency and control strength. ",{"data":2778,"content":2779,"nodeType":876},{},[2780,2784,2792],{"data":2781,"marks":2782,"value":2783,"nodeType":867},{},[],"That isn't a criticism — for most risk scenarios, expert elicitation is the best (and most convenient) available method. Breach cost data is sparse, threat actor behavior is unpredictable, and internal incident history is (ideally!) a limited sample. Quantitative risk frameworks like ",{"data":2785,"content":2787,"nodeType":915},{"uri":2786},"https://www.fairinstitute.org/",[2788],{"data":2789,"marks":2790,"value":2791,"nodeType":867},{},[],"FAIR",{"data":2793,"marks":2794,"value":2795,"nodeType":867},{},[]," give structure to that uncertainty, but they can't conjure data that just doesn't exist.",{"data":2797,"content":2798,"nodeType":876},{},[2799,2803,2808],{"data":2800,"marks":2801,"value":2802,"nodeType":867},{},[],"The results are usually estimates with wide confidence intervals and loss distributions that appear precise, but are hard to defend to a CFO or a board. Finance leaders have seen Monte Carlo simulations before; the capable ones will challenge the quality of the outputs if they doubt the quality of the inputs. ",{"data":2804,"marks":2805,"value":2807,"nodeType":867},{},[2806],{"type":865},"But with the right telemetry, we can get both",{"data":2809,"marks":2810,"value":1679,"nodeType":867},{},[],{"data":2812,"content":2813,"nodeType":942},{},[],{"data":2815,"content":2816,"nodeType":868},{},[2817],{"data":2818,"marks":2819,"value":2821,"nodeType":867},{},[2820],{"type":865},"Why the identity attack surface is uniquely measurable",{"data":2823,"content":2824,"nodeType":876},{},[2825,2829,2834],{"data":2826,"marks":2827,"value":2828,"nodeType":867},{},[],"We've written extensively about the shift to identity as a primary attack vector — and the evidence continues to stack up. Credential phishing, device code phishing, ClickFix, adversary-in-the-middle attacks, session hijacking, and SaaS account compromise now account for the majority of breach entry points in most enterprise environments. But the silver lining here is that this shift has created something valuable for risk quantification: ",{"data":2830,"marks":2831,"value":2833,"nodeType":867},{},[2832],{"type":1303},"a highly observable threat surface",{"data":2835,"marks":2836,"value":1679,"nodeType":867},{},[],{"data":2838,"content":2839,"nodeType":876},{},[2840,2844,2852],{"data":2841,"marks":2842,"value":2843,"nodeType":867},{},[],"Identity attacks execute ",{"data":2845,"content":2846,"nodeType":915},{"uri":2557},[2847],{"data":2848,"marks":2849,"value":2851,"nodeType":867},{},[2850],{"type":913},"in the browser",{"data":2853,"marks":2854,"value":2855,"nodeType":867},{},[],". They leave traces in authentication flows, login behaviors, OAuth integrations, extension activity, and SaaS access patterns — all of which are captured in real time by the Push extension. Unlike network or endpoint attacks, where the signal is often binary and retroactive, browser-based identity threats generate continuous, high-frequency telemetry that maps directly onto the inputs that drive quantitative risk models.",{"data":2857,"content":2858,"nodeType":876},{},[2859,2863,2868,2872,2877],{"data":2860,"marks":2861,"value":2862,"nodeType":867},{},[],"This telemetry directly informs the hardest inputs in any quantitative risk model. One is ",{"data":2864,"marks":2865,"value":2867,"nodeType":867},{},[2866],{"type":865},"Threat Event Frequency (TEF)",{"data":2869,"marks":2870,"value":2871,"nodeType":867},{},[],": how often a threat agent acts against an asset in a given period. For identity risks, this can be answered in how many credential phishing attempts reached your users across all delivery channels (social media, email, malvertising, etc.), or how frequently your users authorize malicious or compromised SaaS apps. Browser-level telemetry can answer these questions with ",{"data":2873,"marks":2874,"value":2876,"nodeType":867},{},[2875],{"type":1303},"observed",{"data":2878,"marks":2879,"value":2880,"nodeType":867},{},[]," data rather than industry lookups and general benchmarks. ",{"data":2882,"content":2886,"nodeType":985},{"target":2883},{"sys":2884},{"id":2885,"type":982,"linkType":983},"EvjT68MCWW7nz5q86xe8S",[],{"data":2888,"content":2889,"nodeType":876},{},[2890,2894,2899],{"data":2891,"marks":2892,"value":2893,"nodeType":867},{},[],"The other input to risk modeling that's difficult to express in concrete terms is ",{"data":2895,"marks":2896,"value":2898,"nodeType":867},{},[2897],{"type":865},"vulnerability",{"data":2900,"marks":2901,"value":2902,"nodeType":867},{},[],": the probability a threat becomes a loss event or, more specifically, how likely it is that your controls will fail. ",{"data":2904,"content":2905,"nodeType":876},{},[2906,2910,2918,2922,2930],{"data":2907,"marks":2908,"value":2909,"nodeType":867},{},[],"This is where browser telemetry gets especially concrete. ",{"data":2911,"content":2913,"nodeType":915},{"uri":2912},"https://pushsecurity.com/blog/how-many-vulnerable-identities-do-you-have/",[2914],{"data":2915,"marks":2916,"value":2917,"nodeType":867},{},[],"Analysis of login telemetry across Push-monitored environments",{"data":2919,"marks":2920,"value":2921,"nodeType":867},{},[]," shows that 1 in 4 logins are still password-only (not SSO), 2 in 5 are not protected by MFA, and 1 in 5 use a weak, breached, or reused password. Many of these logins occur outside the visibility of a central IdP platform like Microsoft, Google or Okta — the result of downstream ",{"data":2923,"content":2925,"nodeType":915},{"uri":2924},"https://pushsecurity.com/blog/ghost-logins-when-forgotten-identities-come-back-to-haunt-you/",[2926],{"data":2927,"marks":2928,"value":2929,"nodeType":867},{},[],"ghost logins",{"data":2931,"marks":2932,"value":2933,"nodeType":867},{},[],". ",{"data":2935,"content":2939,"nodeType":985},{"target":2936},{"sys":2937},{"id":2938,"type":982,"linkType":983},"5GctExdVGjHRwKifiP00Fp",[],{"data":2941,"content":2945,"nodeType":985},{"target":2942},{"sys":2943},{"id":2944,"type":982,"linkType":983},"2mWToHCJcuB9FMwxxzd67F",[],{"data":2947,"content":2948,"nodeType":876},{},[2949,2953,2958],{"data":2950,"marks":2951,"value":2952,"nodeType":867},{},[],"In a FAIR-based model, TEF and vulnerability together determine ",{"data":2954,"marks":2955,"value":2957,"nodeType":867},{},[2956],{"type":865},"loss event frequency",{"data":2959,"marks":2960,"value":2961,"nodeType":867},{},[],": the foundational driver of the entire risk calculation. Using telemetry from your own environment as the basis for these calculations makes them far more accurate, and more likely to stand up to scrutiny.",{"data":2963,"content":2964,"nodeType":942},{},[],{"data":2966,"content":2967,"nodeType":868},{},[2968],{"data":2969,"marks":2970,"value":2972,"nodeType":867},{},[2971],{"type":865},"The attack surface is bigger than most models assume",{"data":2974,"content":2975,"nodeType":876},{},[2976],{"data":2977,"marks":2978,"value":2979,"nodeType":867},{},[],"One of the consistent failures in identity risk modeling is the tendency to model risks defenders can see, and leave the rest off the balance sheet. These omissions create a systematic understatement of exposure that browser-based telemetry can offset.",{"data":2981,"content":2982,"nodeType":1058},{},[2983],{"data":2984,"marks":2985,"value":2987,"nodeType":867},{},[2986],{"type":865},"Shadow AI and OAuth sprawl",{"data":2989,"content":2990,"nodeType":876},{},[2991,2994,3002],{"data":2992,"marks":2993,"value":21,"nodeType":867},{},[],{"data":2995,"content":2996,"nodeType":915},{"uri":2225},[2997],{"data":2998,"marks":2999,"value":3001,"nodeType":867},{},[3000],{"type":913},"The Vercel breach in April 2026",{"data":3003,"marks":3004,"value":3005,"nodeType":867},{},[]," was the result of an OAuth connection to a third-party AI SaaS tool a developer connected into the organization's Google Workspace tenant (without admin approval). When the AI vendor was compromised, the attacker leveraged stored OAuth tokens to access downstream accounts, ultimately reaching internal dashboards, API keys, and source code. ",{"data":3007,"content":3008,"nodeType":876},{},[3009,3013,3018],{"data":3010,"marks":3011,"value":3012,"nodeType":867},{},[],"Push telemetry across customer environments shows an average of ",{"data":3014,"marks":3015,"value":3017,"nodeType":867},{},[3016],{"type":865},"17 unique AI app integrations per organization in Microsoft and Google alone",{"data":3019,"marks":3020,"value":3021,"nodeType":867},{},[],", most of which security teams would describe as unapproved. These generally don't appear in a conventional risk model that isn't looking for them.",{"data":3023,"content":3024,"nodeType":1058},{},[3025],{"data":3026,"marks":3027,"value":288,"nodeType":867},{},[3028],{"type":865},{"data":3030,"content":3031,"nodeType":876},{},[3032,3036,3045,3050],{"data":3033,"marks":3034,"value":21,"nodeType":867},{},[3035],{"type":865},{"data":3037,"content":3038,"nodeType":915},{"uri":1576},[3039],{"data":3040,"marks":3041,"value":3044,"nodeType":867},{},[3042,3043],{"type":913},{"type":865},"Analysis of 20,000 unique extensions deployed across Push customer environments",{"data":3046,"marks":3047,"value":3049,"nodeType":867},{},[3048],{"type":865}," found that 46.76% have the permission combinations required for account takeover without user interaction. ",{"data":3051,"marks":3052,"value":3053,"nodeType":867},{},[],"The extensions carrying these permissions aren't flagged by risk scoring systems because the same permissions are used by ad blockers, password managers, and translation tools (the downside of relying on tools that rely on dubious scoring to assess extensions, but I digress). ",{"data":3055,"content":3056,"nodeType":876},{},[3057],{"data":3058,"marks":3059,"value":3060,"nodeType":867},{},[],"What matters for risk quantification isn't the permission set or an arbitrary score assigned by a vendor; it's whether the monitoring exists to detect when a previously-clean extension changes ownership, escalates permissions, or behaves anomalously. Without that monitoring, the exposure is real but unquantified.",{"data":3062,"content":3063,"nodeType":1058},{},[3064],{"data":3065,"marks":3066,"value":3068,"nodeType":867},{},[3067],{"type":865},"ClickFix and non-email delivery channels",{"data":3070,"content":3071,"nodeType":876},{},[3072,3076,3084,3088,3095],{"data":3073,"marks":3074,"value":3075,"nodeType":867},{},[],"ClickFix — where a malicious page silently writes a PowerShell or mshta command into the victim's clipboard and instructs them to paste it — was ",{"data":3077,"content":3079,"nodeType":915},{"uri":3078},"https://cdn-dynmedia-1.microsoft.com/is/content/microsoftcorp/microsoft/msc/documents/presentations/CSR/Microsoft-Digital-Defense-Report-2025.pdf",[3080],{"data":3081,"marks":3082,"value":3083,"nodeType":867},{},[],"the most common initial access vector observed by Microsoft in 2025",{"data":3085,"marks":3086,"value":3087,"nodeType":867},{},[],", and CrowdStrike reported a",{"data":3089,"content":3090,"nodeType":915},{"uri":928},[3091],{"data":3092,"marks":3093,"value":3094,"nodeType":867},{},[]," 563% increase in fake CAPTCHA lures",{"data":3096,"marks":3097,"value":3098,"nodeType":867},{},[]," (one of the most common ClickFix styles in which the user has to \"verify they're human\" by running a command on their machine). ",{"data":3100,"content":3101,"nodeType":876},{},[3102],{"data":3103,"marks":3104,"value":3105,"nodeType":867},{},[],"What makes this particularly relevant for risk quantification is the delivery channel: 4 in 5 ClickFix payloads intercepted by Push arrive via search engines, not email. A risk model that estimates threat event frequency from email-based phishing telemetry alone is structurally blind to an entire category of attack that has become one of the most prevalent initial access methods in the landscape.",{"data":3107,"content":3108,"nodeType":1058},{},[3109],{"data":3110,"marks":3111,"value":3113,"nodeType":867},{},[3112],{"type":865},"Authorization attacks",{"data":3115,"content":3116,"nodeType":876},{},[3117],{"data":3118,"marks":3119,"value":3120,"nodeType":867},{},[],"Device code phishing and OAuth consent abuse represent a slightly separate category of identity attack that most risk models don't account for because they operate after the authentication flow has already completed — meaning password strength, MFA coverage, and SSO adoption are irrelevant to whether the attack succeeds. ",{"data":3122,"content":3126,"nodeType":985},{"target":3123},{"sys":3124},{"id":3125,"type":982,"linkType":983},"7qtHmxCzBm5664jD6HsCwN",[],{"data":3128,"content":3129,"nodeType":942},{},[],{"data":3131,"content":3132,"nodeType":868},{},[3133],{"data":3134,"marks":3135,"value":3137,"nodeType":867},{},[3136],{"type":865},"The key lesson for CISOs",{"data":3139,"content":3140,"nodeType":876},{},[3141],{"data":3142,"marks":3143,"value":3144,"nodeType":867},{},[],"A risk model that measures identity vulnerability purely in terms of authentication hygiene at the IdP layer — how many accounts have MFA, how many use SSO — will correctly quantify one dimension of exposure while completely missing another that is growing faster and is structurally immune to the controls being measured.",{"data":3146,"content":3147,"nodeType":876},{},[3148],{"data":3149,"marks":3150,"value":3152,"nodeType":867},{},[3151],{"type":865},"For a CISO building a risk model, these aren't edge cases. They represent a real attack surface that doesn't show up in models built on conventional network, endpoint, and cloud telemetry. We aren't just talking about better inputs to risk modeling — we're talking about entirely new risk scenarios that aren't being modeled at all, supported by live data.",{"data":3154,"content":3158,"nodeType":985},{"target":3155},{"sys":3156},{"id":3157,"type":982,"linkType":983},"2ObEcO1gqz8lrOLCZzfpNw",[],{"data":3160,"content":3161,"nodeType":942},{},[],{"data":3163,"content":3164,"nodeType":1058},{},[3165],{"data":3166,"marks":3167,"value":3169,"nodeType":867},{},[3168],{"type":865},"Browser telemetry makes a CISO's life easier",{"data":3171,"content":3172,"nodeType":876},{},[3173],{"data":3174,"marks":3175,"value":3176,"nodeType":867},{},[],"Browser-based telemetry changes the conversation a CISO can have with a CFO or board. Instead of \"industry benchmarks suggest our expected annual loss from account compromise is somewhere in this range,\" the answer is, \"We can see how often these attacks are attempted against our users, and we can measure what percentage of our accounts have the controls in place to stop them,\" or \"We know how many shadow AI apps our users self-provision and share data with each month.\" ",{"data":3178,"content":3179,"nodeType":876},{},[3180],{"data":3181,"marks":3182,"value":3183,"nodeType":867},{},[],"Identity risk is only a piece of the quantification problem. Loss magnitude, regulatory exposure, and reputational impact are still extremely hard to estimate regardless of how good your frequency inputs are. ",{"data":3185,"content":3186,"nodeType":876},{},[3187],{"data":3188,"marks":3189,"value":3190,"nodeType":867},{},[],"But the identity attack surface is one of the few areas in security where measurement is genuinely achievable right now, and the gap between what most organizations are modeling and what's actually observable is significant. Shadow SaaS integrations, unapproved AI connections, browser extensions with excessive privileges — these are enumerable risks that don't appear in models built on network, endpoint, and cloud access telemetry alone. ",{"data":3192,"content":3193,"nodeType":876},{},[3194,3199],{"data":3195,"marks":3196,"value":3198,"nodeType":867},{},[3197],{"type":865},"The lesson for CISOs serious about quantitative risk management is this: the frameworks exist, the talent is available, and the bottleneck is almost always data quality. ",{"data":3200,"marks":3201,"value":3202,"nodeType":867},{},[],"Browser telemetry is a good example of the kind of high-fidelity, environment-specific measurement that closes that gap.",{"data":3204,"content":3205,"nodeType":942},{},[],{"data":3207,"content":3208,"nodeType":876},{},[3209],{"data":3210,"marks":3211,"value":1667,"nodeType":867},{},[],{"data":3213,"content":3214,"nodeType":876},{},[3215,3219,3226],{"data":3216,"marks":3217,"value":3218,"nodeType":867},{},[],"Security teams use Push to detect and stop advanced browser-based attacks like AiTM phishing, ClickFix, and session hijacking; gain visibility and control over AI tool usage across their workforce; harden identities by surfacing credential reuse, SSO gaps, and shadow IT; and support data loss and insider investigations with browser-layer telemetry that other tools can't see. ",{"data":3220,"content":3221,"nodeType":915},{"uri":1670},[3222],{"data":3223,"marks":3224,"value":3225,"nodeType":867},{},[],"Book a live demo",{"data":3227,"marks":3228,"value":3229,"nodeType":867},{},[]," to learn more.","The CISO's data problem (and how browser telemetry can help)","How CISOs can use browser telemetry to support cyber risk quantification in areas where traditional data points fall short. ","2026-05-11T00:00:00.000Z","the-cisos-data-problem-and-how-browser-telemetry-can-help",{"items":3235},[3236,3238],{"sys":3237,"name":2710},{"id":2709},{"sys":3239,"name":342},{"id":3240},"4ksQNCFeBf8H4QIORqpRLw",{"items":3242},[3243],{"fullName":3244,"firstName":3245,"jobTitle":3246,"profilePicture":3247},"Mark Orlando","Mark","Field CTO",{"url":3248},"https://images.ctfassets.net/y1cdw1ablpvd/592PMwIQQFaa24k5SKBEKF/a33090d0ad95d1e3081f5d16a46ba826/image__68_.png",{"__typename":1772,"sys":3250,"content":3252,"title":4007,"synopsis":4008,"hashTags":59,"publishedDate":4009,"slug":4010,"tagsCollection":4011,"authorsCollection":4019},{"id":3251},"5RDOpmzJolwT1hk0fNIxzf",{"json":3253},{"data":3254,"content":3255,"nodeType":1680},{},[3256,3274,3280,3287,3294,3297,3305,3323,3342,3349,3354,3361,3367,3374,3382,3389,3407,3436,3442,3448,3456,3463,3481,3511,3543,3550,3556,3564,3571,3582,3589,3628,3634,3674,3713,3719,3722,3730,3737,3743,3750,3757,3763,3770,3777,3805,3808,3816,3823,3831,3838,3845,3864,3871,3877,3884,3892,3899,3916,3923,3942,3945,3953,3960,3967,3974,3977,3984,3991],{"data":3257,"content":3258,"nodeType":876},{},[3259,3263,3270],{"data":3260,"marks":3261,"value":3262,"nodeType":867},{},[],"Back in 2024, we wrote about ",{"data":3264,"content":3265,"nodeType":915},{"uri":967},[3266],{"data":3267,"marks":3268,"value":3269,"nodeType":867},{},[],"how the Pyramid of Pain shapes Push's detection philosophy",{"data":3271,"marks":3272,"value":3273,"nodeType":867},{},[]," — detections targeting indicators that are easy for attackers to change deliver diminishing returns, while detections targeting attacker techniques impose a cost that's hard to absorb. Two years on, every force that made IoC-based detection fragile has intensified.",{"data":3275,"content":3279,"nodeType":985},{"target":3276},{"sys":3277},{"id":3278,"type":982,"linkType":983},"1iuLYxwI8T1wDUIFSom0G0",[],{"data":3281,"content":3282,"nodeType":876},{},[3283],{"data":3284,"marks":3285,"value":3286,"nodeType":867},{},[],"AI hasn't introduced a new problem so much as it's compressed the timelines on an existing one — attackers can generate infrastructure, iterate on tooling, and industrialize newly discovered techniques faster than before. The bottom layers of the Pyramid are collapsing under the weight of machine-speed operations, and the middle layers are starting to buckle too.",{"data":3288,"content":3289,"nodeType":876},{},[3290],{"data":3291,"marks":3292,"value":3293,"nodeType":867},{},[],"These changes mean that technique-level detection is more important than ever. In this article, we’ll dig into how the Pyramid is changing, and what this means for our detection philosophy at Push (TL;DR — it reinforces the path we’re already on: building detections at the top of the Pyramid by harnessing browser visibility). ",{"data":3295,"content":3296,"nodeType":942},{},[],{"data":3298,"content":3299,"nodeType":868},{},[3300],{"data":3301,"marks":3302,"value":3304,"nodeType":867},{},[3303],{"type":865},"The bottom of the Pyramid was already crumbling",{"data":3306,"content":3307,"nodeType":876},{},[3308,3312,3319],{"data":3309,"marks":3310,"value":3311,"nodeType":867},{},[],"The case against indicator-based detection didn't need AI to be compelling. ",{"data":3313,"content":3315,"nodeType":915},{"uri":3314},"https://www.spamhaus.org/",[3316],{"data":3317,"marks":3318,"value":1233,"nodeType":867},{},[],{"data":3320,"marks":3321,"value":3322,"nodeType":867},{},[],", with just 6.5% surviving past 15 days — by the time a domain makes it onto a blocklist, the campaign has moved on.",{"data":3324,"content":3325,"nodeType":876},{},[3326,3330,3338],{"data":3327,"marks":3328,"value":3329,"nodeType":867},{},[],"We've ",{"data":3331,"content":3333,"nodeType":915},{"uri":3332},"https://pushsecurity.com/blog/why-most-phishing-attacks-feel-like-a-zero-day/",[3334],{"data":3335,"marks":3336,"value":3337,"nodeType":867},{},[],"written before",{"data":3339,"marks":3340,"value":3341,"nodeType":867},{},[]," about how this makes every phishing attack effectively a zero-day for organizations relying on known-bad detection. The phishing kit's behavior — its page structure, script signatures, malicious payload mechanics — is the only detection target that outlasts a single campaign.",{"data":3343,"content":3344,"nodeType":876},{},[3345],{"data":3346,"marks":3347,"value":3348,"nodeType":867},{},[],"When we blogged about the Pyramid of Pain for modern attacks that happen predominantly over the internet, with minimal (or zero) endpoint contact, it first looked like this: ",{"data":3350,"content":3353,"nodeType":985},{"target":3351},{"sys":3352},{"id":981,"type":982,"linkType":983},[],{"data":3355,"content":3356,"nodeType":876},{},[3357],{"data":3358,"marks":3359,"value":3360,"nodeType":867},{},[],"Now, it looks more like this:",{"data":3362,"content":3366,"nodeType":985},{"target":3363},{"sys":3364},{"id":3365,"type":982,"linkType":983},"mfhP4WToOQkrHnVkXU0tX",[],{"data":3368,"content":3369,"nodeType":876},{},[3370],{"data":3371,"marks":3372,"value":3373,"nodeType":867},{},[],"Let’s explore why. ",{"data":3375,"content":3376,"nodeType":1058},{},[3377],{"data":3378,"marks":3379,"value":3381,"nodeType":867},{},[3380],{"type":865},"AI is accelerating phishing rotation and delivery",{"data":3383,"content":3384,"nodeType":876},{},[3385],{"data":3386,"marks":3387,"value":3388,"nodeType":867},{},[],"Attackers are harnessing AI at every stage, speeding up the process of creating, rotating, and replacing phishing infrastructure at every level, as well as capitalizing on AI adoption itself to enhance their lures. The operational signature is more domains, shorter lifespans, more variation, and fewer of the reuse patterns that blocklists depend on.",{"data":3390,"content":3391,"nodeType":876},{},[3392,3396,3403],{"data":3393,"marks":3394,"value":3395,"nodeType":867},{},[],"Attackers can ",{"data":3397,"content":3398,"nodeType":915},{"uri":1421},[3399],{"data":3400,"marks":3401,"value":3402,"nodeType":867},{},[],"vibe-code entire phishing pages in minutes",{"data":3404,"marks":3405,"value":3406,"nodeType":867},{},[]," — not just cloning legitimate login pages but vibe-cloning them, feeding an AI a screenshot and having it rebuild a convincing frontend with a completely unique backend. ",{"data":3408,"content":3409,"nodeType":876},{},[3410,3414,3422,3426,3432],{"data":3411,"marks":3412,"value":3413,"nodeType":867},{},[],"We've seen attackers clone free SaaS tools like background removers and PDF converters, then inject phishing components or ClickFix payloads into what looks like a functional utility. We’ve even seen attackers distributing malware using AI-generated pages shared using ",{"data":3415,"content":3416,"nodeType":915},{"uri":2070},[3417],{"data":3418,"marks":3419,"value":3421,"nodeType":867},{},[3420],{"type":913},"LLM tool sharing functionality",{"data":3423,"marks":3424,"value":3425,"nodeType":867},{},[],", resulting in phishing delivery pages hosted on real claude.ai and chatgpt.com. And legitimate cloud platforms like ",{"data":3427,"content":3428,"nodeType":915},{"uri":2022},[3429],{"data":3430,"marks":3431,"value":2028,"nodeType":867},{},[],{"data":3433,"marks":3434,"value":3435,"nodeType":867},{},[],", Cloudflare Workers, and Vercel host and dynamically rotate attack infrastructure, so the domains feeding into blocklists often belong to reputable services that can't simply be blocked. ",{"data":3437,"content":3441,"nodeType":985},{"target":3438},{"sys":3439},{"id":3440,"type":982,"linkType":983},"5yoLmqysyQazfzLITCUTfc",[],{"data":3443,"content":3447,"nodeType":985},{"target":3444},{"sys":3445},{"id":3446,"type":982,"linkType":983},"5XK5qZMQU19xlA8L2T5y0Z",[],{"data":3449,"content":3450,"nodeType":1058},{},[3451],{"data":3452,"marks":3453,"value":3455,"nodeType":867},{},[3454],{"type":865},"The kit ecosystem is fragmenting faster than anyone can track",{"data":3457,"content":3458,"nodeType":876},{},[3459],{"data":3460,"marks":3461,"value":3462,"nodeType":867},{},[],"What we see across our install base is a huge and growing variation in phishing kits — new kits, derivative kits of known platforms, derivatives of those derivatives — appearing on a weekly basis.",{"data":3464,"content":3465,"nodeType":876},{},[3466,3470,3477],{"data":3467,"marks":3468,"value":3469,"nodeType":867},{},[],"As we reported in our ",{"data":3471,"content":3472,"nodeType":915},{"uri":1702},[3473],{"data":3474,"marks":3475,"value":3476,"nodeType":867},{},[],"Browser Attacks Report",{"data":3478,"marks":3479,"value":3480,"nodeType":867},{},[],", the most common AiTM kits we detected over the last year were Tycoon 2FA (59% of detections), followed by Sneaky 2FA, FlowerStorm, Evilginx (nominally a red team tool, but widely abused by attackers), NakedPages, Gabagool, and dozens more — but those established names are just the visible layer.",{"data":3482,"content":3483,"nodeType":876},{},[3484,3488,3496,3500,3507],{"data":3485,"marks":3486,"value":3487,"nodeType":867},{},[],"Code is forked, modified, and redeployed across kits in a pattern that ",{"data":3489,"content":3491,"nodeType":915},{"uri":3490},"https://blog.barracuda.com/2026/04/16/threat-spotlight-tycoon-2fa-scattered-everywhere",[3492],{"data":3493,"marks":3494,"value":3495,"nodeType":867},{},[],"resembles open-source development",{"data":3497,"marks":3498,"value":3499,"nodeType":867},{},[]," more than traditional criminal enterprise, and the rate at which new variants appear is accelerating. The ",{"data":3501,"content":3502,"nodeType":915},{"uri":1116},[3503],{"data":3504,"marks":3505,"value":3506,"nodeType":867},{},[],"Venom kit",{"data":3508,"marks":3509,"value":3510,"nodeType":867},{},[]," reuses Sneaky 2FA's AiTM infrastructure but carries different branding and adds device code phishing — whether it's the same developers, stolen code, or a deliberate fork is unclear.",{"data":3512,"content":3513,"nodeType":876},{},[3514,3518,3526,3530,3539],{"data":3515,"marks":3516,"value":3517,"nodeType":867},{},[],"Tycoon 2FA illustrates the scale of the evolution. The kit evolves continuously, addingnew capabilities, new evasion techniques, and hybridizing with other platforms. Even when Sekoia and Microsoft seized 330+ Tycoon domains in March 2026, the techniques it popularized were already embedded across competitors, and the slack was taken up by rival platforms within days. And in any case, Tycoon was back to ",{"data":3519,"content":3521,"nodeType":915},{"uri":3520},"https://www.crowdstrike.com/en-us/blog/tycoon2fa-phishing-as-a-service-platform-persists-following-takedown/",[3522],{"data":3523,"marks":3524,"value":3525,"nodeType":867},{},[],"normal levels of operation",{"data":3527,"marks":3528,"value":3529,"nodeType":867},{},[]," shortly after. It has also been observed ",{"data":3531,"content":3533,"nodeType":915},{"uri":3532},"https://www.okta.com/en-nl/blog/threat-intelligence/tycoon_2fa_phishing_actors_scatter/",[3534],{"data":3535,"marks":3536,"value":3538,"nodeType":867},{},[3537],{"type":913},"pivoting to add new device code phishing capabilities",{"data":3540,"marks":3541,"value":3542,"nodeType":867},{},[]," (more on that below). ",{"data":3544,"content":3545,"nodeType":876},{},[3546],{"data":3547,"marks":3548,"value":3549,"nodeType":867},{},[],"Tear one down and there are many more to take its place — and meanwhile the original is already evolving into something new.",{"data":3551,"content":3555,"nodeType":985},{"target":3552},{"sys":3553},{"id":3554,"type":982,"linkType":983},"3UDzUCCizPJhXp3SsoZuSK",[],{"data":3557,"content":3558,"nodeType":1058},{},[3559],{"data":3560,"marks":3561,"value":3563,"nodeType":867},{},[3562],{"type":865},"New techniques are being industrialized faster than ever",{"data":3565,"content":3566,"nodeType":876},{},[3567],{"data":3568,"marks":3569,"value":3570,"nodeType":867},{},[],"As well as the fragmentation of existing kits, we’re seeing new techniques added at an accelerating rate. ",{"data":3572,"content":3573,"nodeType":876},{},[3574,3578],{"data":3575,"marks":3576,"value":360,"nodeType":867},{},[3577],{"type":865},{"data":3579,"marks":3580,"value":3581,"nodeType":867},{},[]," is the clearest case study. From early nation state adoption in 2024, it took until 2026 for criminal adoption to really take off, but the take-up this year is unprecedented. The EvilTokens kit packaged device code phishing into a PhaaS offering with GPT-powered spear-phishing and adaptive landing pages, hitting 340+ organizations across five countries in March 2026. ",{"data":3583,"content":3584,"nodeType":876},{},[3585],{"data":3586,"marks":3587,"value":3588,"nodeType":867},{},[],"Now, device code functionality is now a core phish kit component. We’re tracking 18+ kits with device code phishing capabilities and a 37.5x increase in device code phishing detections this year alone, with the technique moving from state-sponsored exclusivity to something any PhaaS customer can rent.",{"data":3590,"content":3591,"nodeType":876},{},[3592,3596,3604,3608,3613,3617,3625],{"data":3593,"marks":3594,"value":3595,"nodeType":867},{},[],"Similarly, when we ",{"data":3597,"content":3599,"nodeType":915},{"uri":3598},"https://pushsecurity.com/blog/inside-criminal-phishing-panel",[3600],{"data":3601,"marks":3602,"value":3603,"nodeType":867},{},[],"infiltrated Doko's Panel",{"data":3605,"marks":3606,"value":3607,"nodeType":867},{},[]," — a ",{"data":3609,"marks":3610,"value":3612,"nodeType":867},{},[3611],{"type":865},"real-time vishing and AiTM platform",{"data":3614,"marks":3615,"value":3616,"nodeType":867},{},[]," used by ShinyHunters and affiliated groups — the codebase was full of LLM-generated artifacts. Multiple groups were using the templated vishing panel and spinning up their own variants, but the AI-generated indicators persisted throughout. This approach to real-time vishing + browser payload has been a ",{"data":3618,"content":3619,"nodeType":915},{"uri":1165},[3620],{"data":3621,"marks":3622,"value":3624,"nodeType":867},{},[3623],{"type":913},"mainstay of the Com affiliates like ShinyHunters this year",{"data":3626,"marks":3627,"value":2933,"nodeType":867},{},[],{"data":3629,"content":3633,"nodeType":985},{"target":3630},{"sys":3631},{"id":3632,"type":982,"linkType":983},"01mOiserRBXraawXwQyJNm",[],{"data":3635,"content":3636,"nodeType":876},{},[3637,3641,3645,3649,3658,3662,3670],{"data":3638,"marks":3639,"value":3640,"nodeType":867},{},[],"The broader ",{"data":3642,"marks":3643,"value":315,"nodeType":867},{},[3644],{"type":865},{"data":3646,"marks":3647,"value":3648,"nodeType":867},{},[]," family shows the same acceleration: First reported in early 2024 and adopted by four nation-state groups within a single quarter. Fast forward and ",{"data":3650,"content":3652,"nodeType":915},{"uri":3651},"https://www.crowdstrike.com/en-us/global-threat-report/",[3653],{"data":3654,"marks":3655,"value":3657,"nodeType":867},{},[3656],{"type":913},"CrowdStrike's data",{"data":3659,"marks":3660,"value":3661,"nodeType":867},{},[]," shows a 563% increase in fake CAPTCHA incidents (one of the more common ClickFix lure types), while ",{"data":3663,"content":3664,"nodeType":915},{"uri":3078},[3665],{"data":3666,"marks":3667,"value":3669,"nodeType":867},{},[3668],{"type":913},"Microsoft reported",{"data":3671,"marks":3672,"value":3673,"nodeType":867},{},[]," it as making up 47% of observed attacks according to their Digital Defense Report.",{"data":3675,"content":3676,"nodeType":876},{},[3677,3681,3686,3690,3698,3702,3709],{"data":3678,"marks":3679,"value":3680,"nodeType":867},{},[],"And ",{"data":3682,"marks":3683,"value":3685,"nodeType":867},{},[3684],{"type":865},"ConsentFix",{"data":3687,"marks":3688,"value":3689,"nodeType":867},{},[]," — a combination of ClickFix and OAuth consent phishing techniques — suggests the next compression is already underway. Push researchers ",{"data":3691,"content":3693,"nodeType":915},{"uri":3692},"https://pushsecurity.com/blog/consentfix/",[3694],{"data":3695,"marks":3696,"value":3697,"nodeType":867},{},[],"discovered the technique",{"data":3699,"marks":3700,"value":3701,"nodeType":867},{},[]," in December 2025 — a browser-native ClickFix variant hijacking OAuth consent grants via Azure CLI's localhost redirect. It was later confirmed to be tied to APT29. By January 2026, a ",{"data":3703,"content":3704,"nodeType":915},{"uri":1944},[3705],{"data":3706,"marks":3707,"value":3708,"nodeType":867},{},[],"criminal ConsentFix v3 toolkit",{"data":3710,"marks":3711,"value":3712,"nodeType":867},{},[]," had appeared on the XSS forum with Cloudflare Workers, ZoomInfo targeting, and automated exfiltration via Pipedream.",{"data":3714,"content":3718,"nodeType":985},{"target":3715},{"sys":3716},{"id":3717,"type":982,"linkType":983},"41FMif4T0y1maflzonWgL8",[],{"data":3720,"content":3721,"nodeType":942},{},[],{"data":3723,"content":3724,"nodeType":868},{},[3725],{"data":3726,"marks":3727,"value":3729,"nodeType":867},{},[3728],{"type":865},"Why technique-level detection is the only layer that holds",{"data":3731,"content":3732,"nodeType":876},{},[3733],{"data":3734,"marks":3735,"value":3736,"nodeType":867},{},[],"The middle of the Pyramid — tool signatures and artifacts — used to offer much more durable detection than infrastructure indicators. Fingerprinting a specific phishing kit by its JavaScript structure or HTML patterns provided a detection target that survived across dozens or hundreds of campaigns, even as the underlying domains rotated. Tool level detections are still better, but not by quite the same margin.",{"data":3738,"content":3742,"nodeType":985},{"target":3739},{"sys":3740},{"id":3741,"type":982,"linkType":983},"5pxaYdCIFiFKLPhRaPoldX",[],{"data":3744,"content":3745,"nodeType":876},{},[3746],{"data":3747,"marks":3748,"value":3749,"nodeType":867},{},[],"When the kit landscape was dominated by a handful of platforms, you could write signatures for Tycoon, Sneaky2FA, EvilProxy, and so on, and cover the lion's share of attacks. With the ecosystem now producing new variants and entirely new kits on a weekly basis, detecting by kit fingerprint starts to look uncomfortably similar to detecting by domain.",{"data":3751,"content":3752,"nodeType":876},{},[3753],{"data":3754,"marks":3755,"value":3756,"nodeType":867},{},[],"But many of these proliferating kits do share behavioral patterns at a deeper level than their code signatures. For example, every device code phishing kit implements fundamentally the same flow: present a lure, generate a device code via the OAuth Device Authorization endpoint, get the user to enter it on the legitimate authorization page, and poll for the resulting tokens. The frontends vary, the infrastructure varies, but the behavioral pattern doesn't.",{"data":3758,"content":3762,"nodeType":985},{"target":3759},{"sys":3760},{"id":3761,"type":982,"linkType":983},"FyyHayQtsJTwoB1kluMOl",[],{"data":3764,"content":3765,"nodeType":876},{},[3766],{"data":3767,"marks":3768,"value":3769,"nodeType":867},{},[],"Genuinely new attack techniques still require human creativity — an attacker has to identify a gap in how a legitimate protocol or feature can be subverted. That kind of innovation hasn't been automated. But the window to discover a technique, build a detection, and then deploy it before it is adopted by criminals at scale is compressing with each generation.",{"data":3771,"content":3772,"nodeType":876},{},[3773],{"data":3774,"marks":3775,"value":3776,"nodeType":867},{},[],"Organizations that detect at the technique level and deploy before commoditization have a structural advantage that increases over time. Waiting for indicators — even tool-level indicators — means chasing a curve that's accelerating away from you. This is the challenge we grapple with every day as we strive for the most resilient detections possible. ",{"data":3778,"content":3779,"nodeType":3804},{},[3780],{"data":3781,"content":3782,"nodeType":876},{},[3783,3787,3795,3799],{"data":3784,"marks":3785,"value":3786,"nodeType":867},{},[],"As our CPO Jacques Louw put it on ",{"data":3788,"content":3790,"nodeType":915},{"uri":3789},"https://risky.biz/RBNEWSSI128/",[3791],{"data":3792,"marks":3793,"value":3794,"nodeType":867},{},[],"Risky Business",{"data":3796,"marks":3797,"value":3798,"nodeType":867},{},[],": ",{"data":3800,"marks":3801,"value":3803,"nodeType":867},{},[3802],{"type":1303},"\"There's no list of bad domains anywhere in the product. It's a crutch — a false cheat code that stops you from doing the detection in the way that actually is resilient, because the next time you see it, it will be on a different domain.\"","blockquote",{"data":3806,"content":3807,"nodeType":942},{},[],{"data":3809,"content":3810,"nodeType":868},{},[3811],{"data":3812,"marks":3813,"value":3815,"nodeType":867},{},[3814],{"type":865},"What it takes to detect at the top of the Pyramid",{"data":3817,"content":3818,"nodeType":876},{},[3819],{"data":3820,"marks":3821,"value":3822,"nodeType":867},{},[],"If technique-level detection is the only layer that holds, two things have to be true about your detection capability: You need the right vantage point, and you need the research velocity to stay ahead.",{"data":3824,"content":3825,"nodeType":1058},{},[3826],{"data":3827,"marks":3828,"value":3830,"nodeType":867},{},[3829],{"type":865},"You need the right vantage point",{"data":3832,"content":3833,"nodeType":876},{},[3834],{"data":3835,"marks":3836,"value":3837,"nodeType":867},{},[],"Technique-level behaviors in browser-based identity attacks — how a phishing page orchestrates credential entry, how a device code flow presents its authorization prompt, how a ClickFix variant manipulates the clipboard — are visible in the browser session and nowhere else.",{"data":3839,"content":3840,"nodeType":876},{},[3841],{"data":3842,"marks":3843,"value":3844,"nodeType":867},{},[],"Network proxies see encrypted traffic and can attempt to reconstruct page behavior from metadata, but DOM manipulation, user interaction sequences, and script execution aren't visible from that vantage point. Email gateways see the delivery mechanism (or nothing at all in the increasing number of social media and search engine based attacks) but not the payload.",{"data":3846,"content":3847,"nodeType":876},{},[3848,3852,3860],{"data":3849,"marks":3850,"value":3851,"nodeType":867},{},[],"As we disclosed in our ",{"data":3853,"content":3854,"nodeType":915},{"uri":1702},[3855],{"data":3856,"marks":3857,"value":3859,"nodeType":867},{},[3858],{"type":913},"browser attacks report",{"data":3861,"marks":3862,"value":3863,"nodeType":867},{},[],", 95% of in-browser attacks we detect use some form of bot protection, often combined with conditional loading techniques like referrer and browser checks, reliably defeating automated analysis techniques. ",{"data":3865,"content":3866,"nodeType":876},{},[3867],{"data":3868,"marks":3869,"value":3870,"nodeType":867},{},[],"Behavioral detection at the technique level requires observing what happens on the page at the moment the user interacts with it — analyzing pages, not links. When you see the entire browsing flow — ad click, redirect chain, page render, credential prompt — an attack stands out immediately. Without that context, any detection system is forced to fill in gaps, and the gaps are where attacks hide.",{"data":3872,"content":3876,"nodeType":985},{"target":3873},{"sys":3874},{"id":3875,"type":982,"linkType":983},"4804g6u4POUDpL42bzP0EY",[],{"data":3878,"content":3879,"nodeType":876},{},[3880],{"data":3881,"marks":3882,"value":3883,"nodeType":867},{},[],"Push sits inside the browser session, observing this in real time. Its detections target the behavioral mechanics of techniques rather than the surface characteristics of individual kits or infrastructure.",{"data":3885,"content":3886,"nodeType":1058},{},[3887],{"data":3888,"marks":3889,"value":3891,"nodeType":867},{},[3890],{"type":865},"You need the research expertise",{"data":3893,"content":3894,"nodeType":876},{},[3895],{"data":3896,"marks":3897,"value":3898,"nodeType":867},{},[],"When the window between technique discovery and industrialized exploitation is measured in weeks rather than years, the detection pipeline needs to operate on that same compressed timescale.",{"data":3900,"content":3901,"nodeType":876},{},[3902,3906,3912],{"data":3903,"marks":3904,"value":3905,"nodeType":867},{},[],"This is where our ",{"data":3907,"content":3908,"nodeType":915},{"uri":1421},[3909],{"data":3910,"marks":3911,"value":1426,"nodeType":867},{},[],{"data":3913,"marks":3914,"value":3915,"nodeType":867},{},[]," fits. It's tripled our monthly detection output — not by generating bigger blocklists, but by scaling the process of discovering behavioral patterns across the telemetry generated by 3+ million browser deployments.",{"data":3917,"content":3918,"nodeType":876},{},[3919],{"data":3920,"marks":3921,"value":3922,"nodeType":867},{},[],"The detections it produces are technique-class by design, targeting how attacks work rather than the infrastructure or specific tool that implements them. The goal is curation, not accumulation — hundreds of high-fidelity behavioral detections rather than the billions of signatures and domain entries that traditional approaches require.",{"data":3924,"content":3925,"nodeType":876},{},[3926,3930,3938],{"data":3927,"marks":3928,"value":3929,"nodeType":867},{},[],"When we detected the first in-the-wild ",{"data":3931,"content":3933,"nodeType":915},{"uri":3932},"https://pushsecurity.com/blog/installfix/",[3934],{"data":3935,"marks":3936,"value":3937,"nodeType":867},{},[],"InstallFix attack",{"data":3939,"marks":3940,"value":3941,"nodeType":867},{},[]," through the pipeline — a user had searched for NotebookLM, clicked a paid Google ad, and was redirected to a fake page with a WebAssembly C2 connector — the detection shipped to all customers within minutes. It didn't depend on knowing the domain, the ad creative, or the specific kit. It depended on recognizing the technique itself.",{"data":3943,"content":3944,"nodeType":942},{},[],{"data":3946,"content":3947,"nodeType":868},{},[3948],{"data":3949,"marks":3950,"value":3952,"nodeType":867},{},[3951],{"type":865},"Technique-level detection is now the only option",{"data":3954,"content":3955,"nodeType":876},{},[3956],{"data":3957,"marks":3958,"value":3959,"nodeType":867},{},[],"As a framework for detection durability, the Pyramid of Pain is more relevant than ever. ",{"data":3961,"content":3962,"nodeType":876},{},[3963],{"data":3964,"marks":3965,"value":3966,"nodeType":867},{},[],"AI has made infrastructure indicators essentially disposable. The tools tier is compressing as criminal vendors vibe-code, fork, and clone tooling at machine speed. Technique-level detection is the layer that holds long-term to be able to proactively detect and block net-new attacks and the kits that power them. ",{"data":3968,"content":3969,"nodeType":876},{},[3970],{"data":3971,"marks":3972,"value":3973,"nodeType":867},{},[],"Novel attack techniques still require human creativity to discover, and detections built around how those techniques work can survive infrastructure rotation, tool proliferation, and kit fragmentation. Defending that layer requires a vantage point inside the browser session and a research pipeline fast enough to stay ahead of the accelerating path from discovery to industrialization.",{"data":3975,"content":3976,"nodeType":942},{},[],{"data":3978,"content":3979,"nodeType":876},{},[3980],{"data":3981,"marks":3982,"value":3983,"nodeType":867},{},[],"Push Security is the most powerful AI-native security tool in the browser. Think EDR, but for the browser — high-fidelity telemetry and real-time control across every session, on every device, with no browser migration required.",{"data":3985,"content":3986,"nodeType":876},{},[3987],{"data":3988,"marks":3989,"value":3990,"nodeType":867},{},[],"Security teams use Push to detect and stop advanced browser-based attacks like AiTM phishing, ClickFix, and session hijacking; gain visibility and control over AI tool usage across their workforce; harden identities by surfacing credential reuse, SSO gaps, and shadow IT; and support data loss and insider investigations with browser-layer telemetry that other tools can't see.",{"data":3992,"content":3993,"nodeType":876},{},[3994,3997,4004],{"data":3995,"marks":3996,"value":21,"nodeType":867},{},[],{"data":3998,"content":3999,"nodeType":915},{"uri":2689},[4000],{"data":4001,"marks":4002,"value":3225,"nodeType":867},{},[4003],{"type":913},{"data":4005,"marks":4006,"value":3229,"nodeType":867},{},[],"The Pyramid of Pain in the AI era: Why technique-level detection matters more than ever","AI is accelerating the collapse of indicator-based threat detection. Here's why you need technique-level detection to stay ahead.","2026-06-01T00:00:00.000Z","the-pyramid-of-pain-in-the-ai-era",{"items":4012},[4013,4015],{"sys":4014,"name":342},{"id":3240},{"sys":4016,"name":4018},{"id":4017},"6A5RXS31ZQx3PwryGb1IMy","Browser-based attacks",{"items":4020},[4021],{"fullName":4022,"firstName":4023,"jobTitle":4024,"profilePicture":4025},"Dan Green","Dan","Threat Research",{"url":4026},"https://images.ctfassets.net/y1cdw1ablpvd/7jik1VhFgA3kgzXBXTm2Vw/fcd8c171da644903d0827eafcfbcaad0/Dan_Headshot_2025.png","why-modern-browser-attacks-evade-edr","blog/why-modern-browser-attacks-evade-edr",{"json":4030},{"data":4031,"content":4032,"nodeType":1680},{},[4033],{"data":4034,"content":4035,"nodeType":876},{},[4036],{"data":4037,"marks":4038,"value":4039,"nodeType":867},{},[],"This article explains why the gap between what EDR sees and what happens inside the browser is exactly where attackers have built their playbook, and what it takes to close it.","This article explains the gap between what EDR sees and what happens inside the browser, and what it takes to close it.",{"id":4042,"publishedAt":4043},"3qMmscyEh3T1Mbf8qXQHmd","2026-08-12T12:00:46.858Z",{"items":4045},[4046,4048],{"sys":4047,"name":4018},{"id":4017},{"sys":4049,"name":297},{"id":2706},{"items":4051},[4052,4054,4056,4058,4060,4062,4064,4066,4068,4070,4072,4074,4076,4078,4080],{"sys":4053,"name":279,"slug":280,"tier":31},{"id":276},{"sys":4055,"name":297,"slug":298,"tier":31},{"id":294},{"sys":4057,"name":342,"slug":343,"tier":31},{"id":339},{"sys":4059,"name":413,"slug":414,"tier":31},{"id":410},{"sys":4061,"name":377,"slug":378,"tier":45},{"id":374},{"sys":4063,"name":261,"slug":262,"tier":45},{"id":258},{"sys":4065,"name":571,"slug":572,"tier":45},{"id":568},{"sys":4067,"name":315,"slug":316,"tier":45},{"id":312},{"sys":4069,"name":511,"slug":512,"tier":45},{"id":508},{"sys":4071,"name":360,"slug":361,"tier":45},{"id":357},{"sys":4073,"name":324,"slug":325,"tier":45},{"id":321},{"sys":4075,"name":475,"slug":476,"tier":45},{"id":472},{"sys":4077,"name":484,"slug":485,"tier":45},{"id":481},{"sys":4079,"name":244,"slug":245,"tier":45},{"id":241},{"sys":4081,"name":422,"slug":423,"tier":45},{"id":419},"tohekhxoD8wEmdq6HhALjxFwORVgBY5wCOC_F3fg4ag",{"id":4084,"title":4085,"authorsCollection":4086,"content":4095,"extension":228,"faqItemsCollection":5436,"faqTitle":59,"featured":6,"hashTags":59,"meta":5438,"metaTitle":5439,"ogImage":59,"postType":1767,"publishedDate":5440,"relatedBlogPostsCollection":5441,"slug":7937,"stem":7938,"subtitle":59,"summary":7939,"synopsis":7950,"sys":7951,"tagsCollection":7954,"topicsCollection":7960,"__hash__":7994},"blog/blog/making-the-business-case-for-a-browser-security-solution.json","How to make the business case for a browser security solution",{"items":4087},[4088],{"fullName":4089,"firstName":4090,"jobTitle":851,"socialLinks":4091,"profilePicture":4093},"Alex Henshall","Alex",[4092],"https://www.linkedin.com/in/alexhenshall/",{"url":4094},"https://images.ctfassets.net/y1cdw1ablpvd/2rz3Pre3b1MexPIQ4hzPUe/0ef8a092b7e7df00fbce3f7d1ccb96d1/Alex_Henshall.jpeg",{"json":4096,"links":5295},{"data":4097,"content":4098,"nodeType":1680},{},[4099,4118,4125,4132,4139,4146,4152,4155,4163,4170,4177,4196,4215,4222,4229,4236,4275,4282,4350,4362,4365,4373,4380,4386,4393,4400,4419,4426,4456,4489,4496,4502,4509,4516,4523,4614,4621,4628,4634,4641,4648,4671,4690,4713,4732,4751,4758,4765,4771,4778,4785,4816,4835,4841,4848,4867,4874,4881,4926,4933,4936,4944,4951,4958,4977,4984,5023,5040,5043,5051,5058,5197,5205,5223,5230,5237,5240,5248,5255,5262,5265,5271,5277],{"data":4100,"content":4101,"nodeType":876},{},[4102,4105,4114],{"data":4103,"marks":4104,"value":21,"nodeType":867},{},[],{"data":4106,"content":4108,"nodeType":915},{"uri":4107},"https://pushsecurity.com/blog/7-things-omdias-latest-report-tells-us-about-the-secure-enterprise-browser-market/",[4109],{"data":4110,"marks":4111,"value":4113,"nodeType":867},{},[4112],{"type":913},"Omdia's 2026 research",{"data":4115,"marks":4116,"value":4117,"nodeType":867},{},[]," found that 86% of organizations have already increased browser security spending in response to emerging threats, and 85% expect to spend more over the next 12–24 months. ",{"data":4119,"content":4120,"nodeType":876},{},[4121],{"data":4122,"marks":4123,"value":4124,"nodeType":867},{},[],"But finding budget for browser security solutions can be harder than it is for other security tools. Both Gartner and Omdia independently confirm that browser security is predominantly additive; Gartner states explicitly that secure enterprise browsers augment rather than replace existing security controls, and Omdia found that 80% of organizations expect to deploy browser security alongside their current stack.",{"data":4126,"content":4127,"nodeType":876},{},[4128],{"data":4129,"marks":4130,"value":4131,"nodeType":867},{},[],"In practice, that means there's typically no legacy line item to redirect or renewal to swap out. Instead, security leaders are left needing to build a business case from scratch, creating more work on top of an already demanding role. Having a proven framework that other security leaders are already using successfully makes that process significantly faster.",{"data":4133,"content":4134,"nodeType":876},{},[4135],{"data":4136,"marks":4137,"value":4138,"nodeType":867},{},[],"Push helps security leaders build these business cases every day and we've seen firsthand what works and where the budget comes from. ",{"data":4140,"content":4141,"nodeType":876},{},[4142],{"data":4143,"marks":4144,"value":4145,"nodeType":867},{},[],"This article distills those patterns into a practical framework you can use to build your own investment case, as well as provides real-world examples of how Push's customers have found budget to make their own investments in browser security tooling:",{"data":4147,"content":4151,"nodeType":985},{"target":4148},{"sys":4149},{"id":4150,"type":982,"linkType":983},"3qR5t9Y5wgRfzGqcRNXfNa",[],{"data":4153,"content":4154,"nodeType":942},{},[],{"data":4156,"content":4157,"nodeType":868},{},[4158],{"data":4159,"marks":4160,"value":4162,"nodeType":867},{},[4161],{"type":865},"The strategic imperatives that resonate with non-security executives",{"data":4164,"content":4165,"nodeType":876},{},[4166],{"data":4167,"marks":4168,"value":4169,"nodeType":867},{},[],"Two distinct strategic initiatives consistently prove to be effective in unlocking browser security budget. They come from different directions; one is driven by the board down to security, the other is driven by security up to the board. But both lead to the same investment and can be used in conjunction with one another.",{"data":4171,"content":4172,"nodeType":1058},{},[4173],{"data":4174,"marks":4175,"value":4176,"nodeType":867},{},[],"Option A | AI visibility and control: the mandate security teams are responding to",{"data":4178,"content":4179,"nodeType":876},{},[4180,4184,4192],{"data":4181,"marks":4182,"value":4183,"nodeType":867},{},[],"AI adoption isn't a security initiative; it's a business strategy decision that executives and boards are driving. They know the organization needs to harness AI to remain competitive, and most have already committed to accelerating its use. But they also know that ",{"data":4185,"content":4187,"nodeType":915},{"uri":4186},"https://pushsecurity.com/blog/what-push-data-reveals-about-the-state-of-shadow-ai/",[4188],{"data":4189,"marks":4190,"value":4191,"nodeType":867},{},[],"adoption without visibility creates risks they can't quantify or manage",{"data":4193,"marks":4194,"value":4195,"nodeType":867},{},[],", and they expect security to have the visibility and controls to close that gap.",{"data":4197,"content":4198,"nodeType":876},{},[4199,4203,4211],{"data":4200,"marks":4201,"value":4202,"nodeType":867},{},[],"The browser is the most practical place for security teams to get that visibility and control over AI usage. All AI tool usage — whether that's web apps, extensions, OAuth consent flows, data uploads — traverses the browser. A browser security platform like Push can ",{"data":4204,"content":4206,"nodeType":915},{"uri":4205},"https://pushsecurity.com/solution/achieve-security-outcomes/secure-ai",[4207],{"data":4208,"marks":4209,"value":4210,"nodeType":867},{},[],"discover which AI tools employees are actually using",{"data":4212,"marks":4213,"value":4214,"nodeType":867},{},[],", monitor how they're being used, track which AI services have been granted access to corporate systems, and enforce policy in real time.",{"data":4216,"content":4217,"nodeType":876},{},[4218],{"data":4219,"marks":4220,"value":4221,"nodeType":867},{},[],"What makes this particularly effective in a budget conversation is that security teams don’t need to explain or sell a new security risk or initiative, instead they're responding to one their executive team has already identified. When security can demonstrate a concrete plan to deliver AI visibility and control, the funding conversation is significantly shorter. The investment addresses the executive mandate while simultaneously providing additional capabilities for the security team like threat protection, identity and shadow IT security, and investigation support.",{"data":4223,"content":4224,"nodeType":1058},{},[4225],{"data":4226,"marks":4227,"value":4228,"nodeType":867},{},[],"Option B | Modern breaches that originate in the browser: the gap the existing stack wasn't designed to cover",{"data":4230,"content":4231,"nodeType":876},{},[4232],{"data":4233,"marks":4234,"value":4235,"nodeType":867},{},[],"The second strategic imperative requires more educating on the part of the security leader.",{"data":4237,"content":4238,"nodeType":876},{},[4239,4243,4249,4253,4260,4264,4271],{"data":4240,"marks":4241,"value":4242,"nodeType":867},{},[],"The highest-profile breaches in recent years — MGM, Caesars, Ticketmaster, M&S, Jaguar Land Rover — were all carried out by threat groups like ",{"data":4244,"content":4245,"nodeType":915},{"uri":1177},[4246],{"data":4247,"marks":4248,"value":1182,"nodeType":867},{},[],{"data":4250,"marks":4251,"value":4252,"nodeType":867},{},[]," using cloud-native, ",{"data":4254,"content":4255,"nodeType":915},{"uri":2557},[4256],{"data":4257,"marks":4258,"value":4259,"nodeType":867},{},[],"identity-based attack techniques",{"data":4261,"marks":4262,"value":4263,"nodeType":867},{},[],". They didn't compromise endpoints or exploit zero-day vulnerabilities. Instead, they compromised employees' cloud app accounts by targeting them with techniques that ",{"data":4265,"content":4266,"nodeType":915},{"uri":1702},[4267],{"data":4268,"marks":4269,"value":4270,"nodeType":867},{},[],"play out inside browser sessions",{"data":4272,"marks":4273,"value":4274,"nodeType":867},{},[]," where existing endpoint, network, and email controls have no visibility.",{"data":4276,"content":4277,"nodeType":876},{},[4278],{"data":4279,"marks":4280,"value":4281,"nodeType":867},{},[],"That doesn't mean your existing security investments are failing. Endpoint, network, and email controls have become effective enough that threat groups are now actively avoiding them by rerouting their attacks via the browser.",{"data":4283,"content":4284,"nodeType":1629},{},[4285,4306,4328],{"data":4286,"content":4287,"nodeType":1586},{},[4288],{"data":4289,"content":4290,"nodeType":876},{},[4291,4294,4302],{"data":4292,"marks":4293,"value":21,"nodeType":867},{},[],{"data":4295,"content":4296,"nodeType":915},{"uri":3651},[4297],{"data":4298,"marks":4299,"value":4301,"nodeType":867},{},[4300],{"type":913},"CrowdStrike's 2026 data",{"data":4303,"marks":4304,"value":4305,"nodeType":867},{},[]," shows 82% of attack detections are now malware-free. A new capability is needed to address this new playbook, and browser security closes that gap by detecting attacker behavior inside the session, where these attacks actually execute.",{"data":4307,"content":4308,"nodeType":1586},{},[4309],{"data":4310,"content":4311,"nodeType":876},{},[4312,4315,4324],{"data":4313,"marks":4314,"value":21,"nodeType":867},{},[],{"data":4316,"content":4318,"nodeType":915},{"uri":4317},"https://unit42.paloaltonetworks.com/2025-unit-42-global-incident-response-report-social-engineering-edition/",[4319],{"data":4320,"marks":4321,"value":4323,"nodeType":867},{},[4322],{"type":913},"Unit 42",{"data":4325,"marks":4326,"value":4327,"nodeType":867},{},[]," found that identity weaknesses played a material role in almost 90% of their investigations, and across more than 750 incident response engagements, 48% involved browser-based activity.",{"data":4329,"content":4330,"nodeType":1586},{},[4331],{"data":4332,"content":4333,"nodeType":876},{},[4334,4337,4346],{"data":4335,"marks":4336,"value":21,"nodeType":867},{},[],{"data":4338,"content":4340,"nodeType":915},{"uri":4339},"https://services.google.com/fh/files/misc/m-trends-2025-en.pdf",[4341],{"data":4342,"marks":4343,"value":4345,"nodeType":867},{},[4344],{"type":913},"Mandiant's data",{"data":4347,"marks":4348,"value":4349,"nodeType":867},{},[]," tells a similar story: threat actors exploited identity issues to gain initial access in 83% of incidents involving cloud and SaaS environments.",{"data":4351,"content":4352,"nodeType":876},{},[4353,4358],{"data":4354,"marks":4355,"value":4357,"nodeType":867},{},[4356],{"type":865},"Identity-based attacks executed via the browser are now the dominant attack pattern.",{"data":4359,"marks":4360,"value":4361,"nodeType":867},{},[]," That framing works in a budget conversation because it identifies a gap rather than asking to improve something that's already covered by an existing solution. It's also reinforced by the fact that the breaches and groups behind them like Scattered Spider were all reported on by the mainstream media, meaning non-security stakeholders are likely to already be somewhat aware of the risks and potential implications of them being realized.",{"data":4363,"content":4364,"nodeType":942},{},[],{"data":4366,"content":4367,"nodeType":868},{},[4368],{"data":4369,"marks":4370,"value":4372,"nodeType":867},{},[4371],{"type":865},"The economic case: five value drivers",{"data":4374,"content":4375,"nodeType":876},{},[4376],{"data":4377,"marks":4378,"value":4379,"nodeType":867},{},[],"Those strategic imperatives establish why something needs to be done, but they don't quantify the cost of inaction or demonstrate how the investment pays for itself. A CFO wants to see where the money comes from, what existing spend it offsets, and what measurable return it delivers. The economic investment case draws on five distinct value drivers, each grounded in capabilities specific to operating inside the browser session.",{"data":4381,"content":4385,"nodeType":985},{"target":4382},{"sys":4383},{"id":4384,"type":982,"linkType":983},"2W1G5GZWXLbo2hi6bTxAVs",[],{"data":4387,"content":4388,"nodeType":1058},{},[4389],{"data":4390,"marks":4391,"value":4392,"nodeType":867},{},[],"1. Avoided breach costs",{"data":4394,"content":4395,"nodeType":876},{},[4396],{"data":4397,"marks":4398,"value":4399,"nodeType":867},{},[],"This is the largest single value driver, but it's also the hardest to measure because the return is defined by the absence of an event rather than the presence of a saving. That said, the methodology is well-established in risk management, and CFOs already accept this logic for insurance and business continuity investments.",{"data":4401,"content":4402,"nodeType":876},{},[4403,4407,4415],{"data":4404,"marks":4405,"value":4406,"nodeType":867},{},[],"The detection gap described above has a direct financial consequence: every attack that slips through undetected is a potential breach incurring significant direct and indirect costs. Push helps you avoid these costs by detecting ",{"data":4408,"content":4410,"nodeType":915},{"uri":4409},"https://pushsecurity.com/solution/achieve-security-outcomes/stop-account-takeover",[4411],{"data":4412,"marks":4413,"value":4414,"nodeType":867},{},[],"browser-native attack TTPs",{"data":4416,"marks":4417,"value":4418,"nodeType":867},{},[]," and blocking them in real-time to prevent breaches at the earliest opportunity.",{"data":4420,"content":4421,"nodeType":876},{},[4422],{"data":4423,"marks":4424,"value":4425,"nodeType":867},{},[],"Even though the breach itself is unrealized, there are tangible leading indicators of success: reduced MTTD/MTTR, and fewer attacks progressing to account takeover or endpoint compromise; the stages at which incidents become more expensive to clean up.",{"data":4427,"content":4428,"nodeType":876},{},[4429,4433,4441,4444,4452],{"data":4430,"marks":4431,"value":4432,"nodeType":867},{},[],"Quantifying the savings generated by avoiding breaches requires an ",{"data":4434,"content":4436,"nodeType":915},{"uri":4435},"https://pushsecurity.com/blog/the-cisos-data-problem-and-how-browser-telemetry-can-help/",[4437],{"data":4438,"marks":4439,"value":4440,"nodeType":867},{},[],"estimation of your organization's breach probability and likely cost",{"data":4442,"marks":4443,"value":1679,"nodeType":867},{},[],{"data":4445,"content":4447,"nodeType":915},{"uri":4446},"https://www.ibm.com/reports/data-breach",[4448],{"data":4449,"marks":4450,"value":4451,"nodeType":867},{},[]," IBM's cost of a data breach report",{"data":4453,"marks":4454,"value":4455,"nodeType":867},{},[]," provides industry-specific benchmarks, though a more grounded alternative is to look at the disclosed costs of the breaches mentioned above and assess your exposure to the same techniques:",{"data":4457,"content":4458,"nodeType":1629},{},[4459,4469,4479],{"data":4460,"content":4461,"nodeType":1586},{},[4462],{"data":4463,"content":4464,"nodeType":876},{},[4465],{"data":4466,"marks":4467,"value":4468,"nodeType":867},{},[],"MGM reported over $100M in direct impact plus a $45M class-action settlement.",{"data":4470,"content":4471,"nodeType":1586},{},[4472],{"data":4473,"content":4474,"nodeType":876},{},[4475],{"data":4476,"marks":4477,"value":4478,"nodeType":867},{},[],"M&S lost £300M in profits with almost £1B wiped off its market valuation.",{"data":4480,"content":4481,"nodeType":1586},{},[4482],{"data":4483,"content":4484,"nodeType":876},{},[4485],{"data":4486,"marks":4487,"value":4488,"nodeType":867},{},[],"The JLR breach was severe enough for the UK government to underwrite a $1.5B loan to mitigate supply chain damage.",{"data":4490,"content":4491,"nodeType":876},{},[4492],{"data":4493,"marks":4494,"value":4495,"nodeType":867},{},[],"Your own incident data, red team results, or phishing simulation outcomes will increase accuracy further.",{"data":4497,"content":4501,"nodeType":985},{"target":4498},{"sys":4499},{"id":4500,"type":982,"linkType":983},"3SgrdUcQnQsnNLIR9UgBB",[],{"data":4503,"content":4504,"nodeType":1058},{},[4505],{"data":4506,"marks":4507,"value":4508,"nodeType":867},{},[],"2. Accelerated and safe AI adoption",{"data":4510,"content":4511,"nodeType":876},{},[4512],{"data":4513,"marks":4514,"value":4515,"nodeType":867},{},[],"Without effective AI visibility and control tooling, your security team becomes either the bottleneck for AI adoption or allows the risks to go unchecked. Every month that adoption is restricted or ungoverned has a productivity cost that compounds.",{"data":4517,"content":4518,"nodeType":876},{},[4519],{"data":4520,"marks":4521,"value":4522,"nodeType":867},{},[],"There's been plenty of research into the productivity impact of AI:",{"data":4524,"content":4525,"nodeType":1629},{},[4526,4548,4570,4592],{"data":4527,"content":4528,"nodeType":1586},{},[4529],{"data":4530,"content":4531,"nodeType":876},{},[4532,4535,4544],{"data":4533,"marks":4534,"value":21,"nodeType":867},{},[],{"data":4536,"content":4538,"nodeType":915},{"uri":4537},"https://www.nber.org/system/files/working_papers/w31161/w31161.pdf",[4539],{"data":4540,"marks":4541,"value":4543,"nodeType":867},{},[4542],{"type":913},"Stanford and MIT research",{"data":4545,"marks":4546,"value":4547,"nodeType":867},{},[]," found that workers with access to a generative AI assistant were 14% more productive on average, with novice workers seeing a 34% improvement.",{"data":4549,"content":4550,"nodeType":1586},{},[4551],{"data":4552,"content":4553,"nodeType":876},{},[4554,4557,4566],{"data":4555,"marks":4556,"value":21,"nodeType":867},{},[],{"data":4558,"content":4560,"nodeType":915},{"uri":4559},"https://www.accenture.com/us-en/insights/strategy/productivity-payoff",[4561],{"data":4562,"marks":4563,"value":4565,"nodeType":867},{},[4564],{"type":913},"Accenture's research",{"data":4567,"marks":4568,"value":4569,"nodeType":867},{},[]," estimates approximately $7,800 per employee per year in productivity value from generative AI for knowledge workers.",{"data":4571,"content":4572,"nodeType":1586},{},[4573],{"data":4574,"content":4575,"nodeType":876},{},[4576,4579,4588],{"data":4577,"marks":4578,"value":21,"nodeType":867},{},[],{"data":4580,"content":4582,"nodeType":915},{"uri":4581},"https://www.stlouisfed.org/on-the-economy/2025/feb/impact-generative-ai-work-productivity",[4583],{"data":4584,"marks":4585,"value":4587,"nodeType":867},{},[4586],{"type":913},"The Federal Reserve",{"data":4589,"marks":4590,"value":4591,"nodeType":867},{},[]," independently quantified it at 5.4% of work hours saved, roughly one full working day reclaimed per month.",{"data":4593,"content":4594,"nodeType":1586},{},[4595],{"data":4596,"content":4597,"nodeType":876},{},[4598,4601,4610],{"data":4599,"marks":4600,"value":21,"nodeType":867},{},[],{"data":4602,"content":4604,"nodeType":915},{"uri":4603},"https://www.mckinsey.com/capabilities/quantumblack/our-insights/the-state-of-ai",[4605],{"data":4606,"marks":4607,"value":4609,"nodeType":867},{},[4608],{"type":913},"McKinsey's 2025 data",{"data":4611,"marks":4612,"value":4613,"nodeType":867},{},[]," shows organizations leading on AI adoption report 5.8x average ROI within 14 months, and they outperform laggards in both profitability and revenue growth.",{"data":4615,"content":4616,"nodeType":876},{},[4617],{"data":4618,"marks":4619,"value":4620,"nodeType":867},{},[],"A browser security platform like Push removes the governance blocker. When you can see which AI tools employees are using, what data they're sharing, and what permissions they've granted, and enforce policy in real time, the answer to \"can our people use this?\" shifts from \"not yet, we need to assess the risk\" to \"yes, with our sensible guardrails.\"",{"data":4622,"content":4623,"nodeType":876},{},[4624],{"data":4625,"marks":4626,"value":4627,"nodeType":867},{},[],"Push delivers this by discovering every AI web app, browser, browser extension, and OAuth integration in use. It monitors data sharing through file uploads and clipboard activity, tracks OAuth consent flows where AI services request access to corporate tenants, and enforces policy at the point of action. This allows your team to very quickly get a handle on AI usage, mitigate risks and guide the business on how to best drive safe adoption.",{"data":4629,"content":4633,"nodeType":985},{"target":4630},{"sys":4631},{"id":4632,"type":982,"linkType":983},"6i7Z6jwFaztuoUCynXfrVH",[],{"data":4635,"content":4636,"nodeType":1058},{},[4637],{"data":4638,"marks":4639,"value":4640,"nodeType":867},{},[],"3. Greater return from existing security investments",{"data":4642,"content":4643,"nodeType":876},{},[4644],{"data":4645,"marks":4646,"value":4647,"nodeType":867},{},[],"Push generates direct labor savings in two ways that other tools can't replicate.",{"data":4649,"content":4650,"nodeType":876},{},[4651,4656,4660,4667],{"data":4652,"marks":4653,"value":4655,"nodeType":867},{},[4654],{"type":865},"First, identity hygiene remediation at scale.",{"data":4657,"marks":4658,"value":4659,"nodeType":867},{},[]," Push's customer data shows that for every 1,000 employees, an organization will typically have just over ",{"data":4661,"content":4662,"nodeType":915},{"uri":2912},[4663],{"data":4664,"marks":4665,"value":4666,"nodeType":867},{},[],"2,500 identity security vulnerabilities",{"data":4668,"marks":4669,"value":4670,"nodeType":867},{},[]," (missing MFA or weak, breached, reused passwords, etc).",{"data":4672,"content":4673,"nodeType":876},{},[4674,4678,4686],{"data":4675,"marks":4676,"value":4677,"nodeType":867},{},[],"Without Push, you could conservatively estimate that each vulnerability takes 5–10 minutes to resolve manually (inclusive of project management and reporting time) which translates to between 26 and 52 FTE days per thousand employees. ",{"data":4679,"content":4681,"nodeType":915},{"uri":4680},"https://pushsecurity.com/solution/achieve-security-outcomes/harden-unmanaged-identities",[4682],{"data":4683,"marks":4684,"value":4685,"nodeType":867},{},[],"Push automates this through in-browser guardrails",{"data":4687,"marks":4688,"value":4689,"nodeType":867},{},[]," that prompt users to fix issues at the point of login. That's thousands of identity vulnerabilities resolved without a single ticket being filed, and weeks of analyst time recovered annually at fully burdened rates.",{"data":4691,"content":4692,"nodeType":876},{},[4693,4698,4702,4710],{"data":4694,"marks":4695,"value":4697,"nodeType":867},{},[4696],{"type":865},"Second, investigation efficiency.",{"data":4699,"marks":4700,"value":4701,"nodeType":867},{},[]," Push detects attacks at the earliest and safest opportunity, as the attacker is attempting to gain initial access via the browser. The telemetry Push provides analysts with ",{"data":4703,"content":4705,"nodeType":915},{"uri":4704},"https://pushsecurity.com/solution/achieve-security-outcomes/investigate-browser-related-incidents",[4706],{"data":4707,"marks":4708,"value":4709,"nodeType":867},{},[],"accelerates their investigations across both external and insider threats",{"data":4711,"marks":4712,"value":1679,"nodeType":867},{},[],{"data":4714,"content":4715,"nodeType":876},{},[4716,4720,4728],{"data":4717,"marks":4718,"value":4719,"nodeType":867},{},[],"Here’s one example of that in action: Push eliminates ",{"data":4721,"content":4723,"nodeType":915},{"uri":4722},"https://pushsecurity.com/blog/verified-stolen-credential-detection/",[4724],{"data":4725,"marks":4726,"value":4727,"nodeType":867},{},[],"over 99% of compromised credential false positives",{"data":4729,"marks":4730,"value":4731,"nodeType":867},{},[]," in common TI feeds by only surfacing credentials actively being used and observed in the browser. Much like the first direct labour saving, Push saves your team weeks of effort confirming false positives and investigating complex account compromise incidents. It also reduces the likelihood of an incident progressing to the stage where a (costly) external incident response provider is needed. ",{"data":4733,"content":4734,"nodeType":876},{},[4735,4739,4747],{"data":4736,"marks":4737,"value":4738,"nodeType":867},{},[],"By automatically remediating identity security issues at scale, and accelerating investigations, Push eliminates much of the work that analysts typically find tedious and frustrating: manually chasing password resets, triaging false positives, ",{"data":4740,"content":4742,"nodeType":915},{"uri":4741},"https://pushsecurity.com/blog/fixing-secops-alert-fatigue-with-browser-telemetry/",[4743],{"data":4744,"marks":4745,"value":4746,"nodeType":867},{},[],"trawling through web proxy logs",{"data":4748,"marks":4749,"value":4750,"nodeType":867},{},[],". Removing that work means they can spend more time on the interesting, high-value aspects of their roles, which directly improves morale and retention.",{"data":4752,"content":4753,"nodeType":876},{},[4754],{"data":4755,"marks":4756,"value":4757,"nodeType":867},{},[],"In a market where replacing a fully ramped security analyst costs 80–150% of their annual salary and the new hire takes months to reach the same productivity, reduced attrition generates its own measurable saving in avoided recruitment, training, and lost productivity during the ramp-up period.",{"data":4759,"content":4760,"nodeType":876},{},[4761],{"data":4762,"marks":4763,"value":4764,"nodeType":867},{},[],"In addition to direct labor savings, Push improves the return on every other security investment in your stack. Browser-layer telemetry feeds into SIEM and SOAR platforms, enriching correlation rules and enabling custom detections that weren't previously possible, a multiplier on the value you're already getting from your existing security investments.",{"data":4766,"content":4770,"nodeType":985},{"target":4767},{"sys":4768},{"id":4769,"type":982,"linkType":983},"7EwWz1orX6QQtm5MHnaXDQ",[],{"data":4772,"content":4773,"nodeType":1058},{},[4774],{"data":4775,"marks":4776,"value":4777,"nodeType":867},{},[],"4. Reduced compliance and audit exposure",{"data":4779,"content":4780,"nodeType":876},{},[4781],{"data":4782,"marks":4783,"value":4784,"nodeType":867},{},[],"Every major security compliance framework — SOC 2, ISO 27001, HIPAA, PCI DSS, NIST, GDPR — requires MFA on accounts, strong and unique passwords, and visibility into which third-party applications are being entrusted with corporate data. These are foundational requirements and they apply across every application employees use, not just the ones IT has provisioned. Self-adopted Shadow IT and unmanaged identities create compliance gaps against these requirements that most organizations don't know they have until an auditor finds them.",{"data":4786,"content":4787,"nodeType":876},{},[4788,4791,4800,4804,4812],{"data":4789,"marks":4790,"value":21,"nodeType":867},{},[],{"data":4792,"content":4794,"nodeType":915},{"uri":4793},"https://pushsecurity.com/resources/mfa-regulation-compliance",[4795],{"data":4796,"marks":4797,"value":4799,"nodeType":867},{},[4798],{"type":913},"The consequences of gaps in these controls are increasingly financial.",{"data":4801,"marks":4802,"value":4803,"nodeType":867},{},[]," The City of Hamilton had its $18.3M cyber insurance claim denied after a ransomware attack because MFA wasn't fully implemented. The insurer ruled that incomplete MFA coverage voided the policy. ",{"data":4805,"content":4807,"nodeType":915},{"uri":4806},"https://pushsecurity.com/blog/what-the-expansion-of-nydfs-nycrr-part-500-means-for-mfa-compliance/",[4808],{"data":4809,"marks":4810,"value":4811,"nodeType":867},{},[],"NYDFS has levied $14 million in fines",{"data":4813,"marks":4814,"value":4815,"nodeType":867},{},[]," from companies with inadequate MFA. These aren't hypothetical risks, and they apply to requirements that Push can help you meet continuously rather than scrambling to find evidence during an audit or after an incident.",{"data":4817,"content":4818,"nodeType":876},{},[4819,4823,4831],{"data":4820,"marks":4821,"value":4822,"nodeType":867},{},[],"Push addresses these compliance requirements directly. It ",{"data":4824,"content":4826,"nodeType":915},{"uri":4825},"https://pushsecurity.com/solution/achieve-security-outcomes/secure-shadow-saas",[4827],{"data":4828,"marks":4829,"value":4830,"nodeType":867},{},[],"discovers every application employees actually use",{"data":4832,"marks":4833,"value":4834,"nodeType":867},{},[]," — directly from the login event in the browser, not from network traffic patterns. It also observes the authentication method, password strength, and MFA status for each account. The inventory provided by Push replaces weeks of manual spreadsheet work during audit preparation and gives your GRC team continuous evidence rather than a point-in-time snapshot assembled under pressure.",{"data":4836,"content":4840,"nodeType":985},{"target":4837},{"sys":4838},{"id":4839,"type":982,"linkType":983},"36lm2TMvlpEPrFfM8KEUqB",[],{"data":4842,"content":4843,"nodeType":1058},{},[4844],{"data":4845,"marks":4846,"value":4847,"nodeType":867},{},[],"5. Consolidated capability and reallocated spend",{"data":4849,"content":4850,"nodeType":876},{},[4851,4855,4863],{"data":4852,"marks":4853,"value":4854,"nodeType":867},{},[],"Push delivers against a ",{"data":4856,"content":4858,"nodeType":915},{"uri":4857},"https://pushsecurity.com/blog/the-top-10-security-problems-you-can-solve-in-the-browser-ranked-by-value/",[4859],{"data":4860,"marks":4861,"value":4862,"nodeType":867},{},[],"wide range of use cases",{"data":4864,"marks":4865,"value":4866,"nodeType":867},{},[]," — threat detection, AI governance, identity security, investigation support — that would otherwise require separate point solutions to address. That breadth of coverage from a single platform and deployment creates natural opportunities to consolidate spend.",{"data":4868,"content":4869,"nodeType":876},{},[4870],{"data":4871,"marks":4872,"value":4873,"nodeType":867},{},[],"AI governance is the most immediate example. Nearly every enterprise is evaluating standalone AI monitoring tools right now, and the price tags are significant. If your browser security platform already delivers the AI visibility and control capabilities like Push's described above — app discovery, data sharing monitoring, OAuth consent tracking, real-time policy enforcement — the case for a separate AI governance purchase weakens considerably. Paying separately for a tool that only does AI governance, when your browser security platform delivers it alongside detection, identity security, and investigation capability, is a hard spend to justify.",{"data":4875,"content":4876,"nodeType":876},{},[4877],{"data":4878,"marks":4879,"value":4880,"nodeType":867},{},[],"There's also a broader resource reallocation opportunity. Platforms like Push represent a new generation of security tooling that addresses the challenges posed by modern work and cyber attacks. The ROI they provide is high now and is likely to increase as the platform evolves alongside the threats and risks it addresses. Meanwhile, much of the legacy stack is moving in the opposite direction.",{"data":4882,"content":4883,"nodeType":1629},{},[4884,4906,4916],{"data":4885,"content":4886,"nodeType":1586},{},[4887],{"data":4888,"content":4889,"nodeType":876},{},[4890,4894,4902],{"data":4891,"marks":4892,"value":4893,"nodeType":867},{},[],"Network-centric tools like ",{"data":4895,"content":4897,"nodeType":915},{"uri":4896},"https://pushsecurity.com/blog/push-plus-network-security/",[4898],{"data":4899,"marks":4900,"value":4901,"nodeType":867},{},[],"SWGs and CASBs are becoming increasingly legacy",{"data":4903,"marks":4904,"value":4905,"nodeType":867},{},[]," as more activity moves off the traditional network and into the browser.",{"data":4907,"content":4908,"nodeType":1586},{},[4909],{"data":4910,"content":4911,"nodeType":876},{},[4912],{"data":4913,"marks":4914,"value":4915,"nodeType":867},{},[],"RBI deployments are difficult to justify when a browser extension achieves better security outcomes without the user experience penalty.",{"data":4917,"content":4918,"nodeType":1586},{},[4919],{"data":4920,"content":4921,"nodeType":876},{},[4922],{"data":4923,"marks":4924,"value":4925,"nodeType":867},{},[],"Phishing simulation programs — whose ROI has long been questioned by practitioners — are harder to justify when attackers are using AI to craft lures and pages that are indistinguishable from the real thing for even the most trained employees. If your browser security platform is already blocking real phishing attempts and delivering contextual security guidance at the actual point of risk, the marginal value of a simulation exercise weeks later diminishes considerably.",{"data":4927,"content":4928,"nodeType":876},{},[4929],{"data":4930,"marks":4931,"value":4932,"nodeType":867},{},[],"As legacy tooling becomes less relevant and more commoditized, you should expect to spend less on it. What you save can then be reallocated towards capabilities like Push that address the current threat landscape rather than the previous one legacy tools were designed for.",{"data":4934,"content":4935,"nodeType":942},{},[],{"data":4937,"content":4938,"nodeType":868},{},[4939],{"data":4940,"marks":4941,"value":4943,"nodeType":867},{},[4942],{"type":865},"Investment risk management",{"data":4945,"content":4946,"nodeType":876},{},[4947],{"data":4948,"marks":4949,"value":4950,"nodeType":867},{},[],"The final component of the business case is assessing the investment risk. Given that browser security solutions are typically a new capability, and therefore a new form of investment, there will naturally be questions about how safe an investment it is.",{"data":4952,"content":4953,"nodeType":876},{},[4954],{"data":4955,"marks":4956,"value":4957,"nodeType":867},{},[],"Browser security takes many forms and approaches, so this section speaks specifically to Push and why it represents a low-risk investment to make.",{"data":4959,"content":4960,"nodeType":876},{},[4961,4965,4973],{"data":4962,"marks":4963,"value":4964,"nodeType":867},{},[],"Push is simple to deploy. It installs as a browser extension via existing MDM tooling — it works on the browsers employees already use, with no migration to a new browser, no user retraining, and no change to workflows. ",{"data":4966,"content":4968,"nodeType":915},{"uri":4967},"https://pushsecurity.com/customer-stories",[4969],{"data":4970,"marks":4971,"value":4972,"nodeType":867},{},[],"Customers have rolled Push out to over 100,000 users in under an hour",{"data":4974,"marks":4975,"value":4976,"nodeType":867},{},[]," during normal office hours with zero downtime.",{"data":4978,"content":4979,"nodeType":876},{},[4980],{"data":4981,"marks":4982,"value":4983,"nodeType":867},{},[],"You start seeing findings and detections from day one, not after a months-long implementation project. That compresses time-to-value to a matter of hours, which directly de-risks the investment from a finance perspective. Push's high-fidelity telemetry results in a negligible false positive rate, minimizing the operational cost of running the platform. Push integrates into your existing security workflows and tools, like your SIEM, SOAR, and IdP, and doesn't require a dedicated team to manage, so you gain a new capability without taking on a new operational burden.",{"data":4985,"content":4986,"nodeType":876},{},[4987,4991,4997,5001,5008,5011,5019],{"data":4988,"marks":4989,"value":4990,"nodeType":867},{},[],"Push supports advanced security teams in highly targeted and regulated industries, with over 3 million browsers deployed worldwide. As one of the first browser security extensions, launched in 2022, Push has one of the longest track records in the space, and its research team regularly discovers novel attack techniques, including ",{"data":4992,"content":4993,"nodeType":915},{"uri":3692},[4994],{"data":4995,"marks":4996,"value":3685,"nodeType":867},{},[],{"data":4998,"marks":4999,"value":5000,"nodeType":867},{},[],",",{"data":5002,"content":5003,"nodeType":915},{"uri":2924},[5004],{"data":5005,"marks":5006,"value":5007,"nodeType":867},{},[]," ghost logins",{"data":5009,"marks":5010,"value":5000,"nodeType":867},{},[],{"data":5012,"content":5014,"nodeType":915},{"uri":5013},"https://pushsecurity.com/blog/samljacking-a-poisoned-tenant/",[5015],{"data":5016,"marks":5017,"value":5018,"nodeType":867},{},[]," SAMLjacking",{"data":5020,"marks":5021,"value":5022,"nodeType":867},{},[],", and regularly publishes campaign analysis referenced across the security community.",{"data":5024,"content":5025,"nodeType":876},{},[5026,5030,5036],{"data":5027,"marks":5028,"value":5029,"nodeType":867},{},[],"Finally, Push actively hunts for new and novel threats across your estate using its research and ",{"data":5031,"content":5032,"nodeType":915},{"uri":1421},[5033],{"data":5034,"marks":5035,"value":2585,"nodeType":867},{},[],{"data":5037,"marks":5038,"value":5039,"nodeType":867},{},[],", with no customer input required. That means you remain protected as the threat landscape evolves, and the capability continues to advance and deliver recurring value over the full contract period without additional effort from your team.",{"data":5041,"content":5042,"nodeType":942},{},[],{"data":5044,"content":5045,"nodeType":868},{},[5046],{"data":5047,"marks":5048,"value":5050,"nodeType":867},{},[5049],{"type":865},"Where has the budget actually come from for Push’s customers?",{"data":5052,"content":5053,"nodeType":876},{},[5054],{"data":5055,"marks":5056,"value":5057,"nodeType":867},{},[],"Push's customers have funded their browser security investment through several well-established routes:",{"data":5059,"content":5060,"nodeType":1629},{},[5061,5082,5115,5160,5182],{"data":5062,"content":5063,"nodeType":1586},{},[5064],{"data":5065,"content":5066,"nodeType":876},{},[5067,5071,5078],{"data":5068,"marks":5069,"value":5070,"nodeType":867},{},[],"Many teams had funded projects to increase their ",{"data":5072,"content":5073,"nodeType":915},{"uri":4205},[5074],{"data":5075,"marks":5076,"value":5077,"nodeType":867},{},[],"visibility and control over AI use",{"data":5079,"marks":5080,"value":5081,"nodeType":867},{},[]," in their organizations. Push gave them the instrumentation they needed to address their needs while also allowing them to address other valuable security use cases.",{"data":5083,"content":5084,"nodeType":1586},{},[5085],{"data":5086,"content":5087,"nodeType":876},{},[5088,5092,5099,5103,5111],{"data":5089,"marks":5090,"value":5091,"nodeType":867},{},[],"Push is frequently purchased following a security incident such as an ",{"data":5093,"content":5094,"nodeType":915},{"uri":1067},[5095],{"data":5096,"marks":5097,"value":5098,"nodeType":867},{},[],"AitM phishing breach",{"data":5100,"marks":5101,"value":5102,"nodeType":867},{},[]," or a ",{"data":5104,"content":5105,"nodeType":915},{"uri":1140},[5106],{"data":5107,"marks":5108,"value":5110,"nodeType":867},{},[5109],{"type":913},"ClickFix breach",{"data":5112,"marks":5113,"value":5114,"nodeType":867},{},[]," that existing tools failed to detect and stop.",{"data":5116,"content":5117,"nodeType":1586},{},[5118],{"data":5119,"content":5120,"nodeType":876},{},[5121,5125,5133,5137,5144,5148,5156],{"data":5122,"marks":5123,"value":5124,"nodeType":867},{},[],"Another leverage point has been ",{"data":5126,"content":5128,"nodeType":915},{"uri":5127},"https://pushsecurity.com/solution/tool-replacements/cloud-access-security-broker",[5129],{"data":5130,"marks":5131,"value":306,"nodeType":867},{},[5132],{"type":913},{"data":5134,"marks":5135,"value":5136,"nodeType":867},{},[],", ",{"data":5138,"content":5140,"nodeType":915},{"uri":5139},"https://pushsecurity.com/solution/tool-replacements/secure-web-gateways",[5141],{"data":5142,"marks":5143,"value":624,"nodeType":867},{},[],{"data":5145,"marks":5146,"value":5147,"nodeType":867},{},[],", and ",{"data":5149,"content":5151,"nodeType":915},{"uri":5150},"https://pushsecurity.com/solution/tool-replacements/remote-browser-isolation",[5152],{"data":5153,"marks":5154,"value":5155,"nodeType":867},{},[],"RBI",{"data":5157,"marks":5158,"value":5159,"nodeType":867},{},[]," renewals. The browser-native capabilities of a tool like Push let you either replace or reduce the scope — and cost — on those contracts without losing coverage.",{"data":5161,"content":5162,"nodeType":1586},{},[5163],{"data":5164,"content":5165,"nodeType":876},{},[5166,5170,5178],{"data":5167,"marks":5168,"value":5169,"nodeType":867},{},[],"A number of Push customers rolled out ",{"data":5171,"content":5173,"nodeType":915},{"uri":5172},"https://pushsecurity.com/solution/achieve-security-outcomes/secure-chromebooks",[5174],{"data":5175,"marks":5176,"value":5177,"nodeType":867},{},[],"Chromebooks",{"data":5179,"marks":5180,"value":5181,"nodeType":867},{},[]," to parts of their workforce and used the savings that generated to pay for Push. These devices fell outside of their standard EDR coverage and they found that Push provided all the visibility and protection they needed for Chromebook users.",{"data":5183,"content":5184,"nodeType":1586},{},[5185],{"data":5186,"content":5187,"nodeType":876},{},[5188,5192],{"data":5189,"marks":5190,"value":5191,"nodeType":867},{},[],"But overall, most customers choose to build the net-new case using ROI projections alone. Push customers see direct savings that cover the cost of deploying Push and indirect savings that run into the millions of dollars. ",{"data":5193,"marks":5194,"value":5196,"nodeType":867},{},[5195],{"type":865},"For every $1 invested, Push generates a return of $5 - $15 through a mixture of direct and indirect savings aligned to the five economic value drivers.",{"data":5198,"content":5199,"nodeType":1058},{},[5200],{"data":5201,"marks":5202,"value":5204,"nodeType":867},{},[5203],{"type":865},"Strengthening your case with PoV data",{"data":5206,"content":5207,"nodeType":876},{},[5208,5212,5219],{"data":5209,"marks":5210,"value":5211,"nodeType":867},{},[],"One practical step that strengthens any business case significantly is to ",{"data":5213,"content":5214,"nodeType":915},{"uri":1289},[5215],{"data":5216,"marks":5217,"value":5218,"nodeType":867},{},[],"run a proof of value",{"data":5220,"marks":5221,"value":5222,"nodeType":867},{},[],". A PoV deployment generates findings specific to your organization: real instances of employees being targeted in their browsers, the actual scale of your identity attack surface, and concrete shadow SaaS and AI usage data.",{"data":5224,"content":5225,"nodeType":876},{},[5226],{"data":5227,"marks":5228,"value":5229,"nodeType":867},{},[],"That evidence can be far more compelling to a CFO than generic industry benchmarks, and it hones the projected value from the framework using real-world data taken from your own environment. ",{"data":5231,"content":5232,"nodeType":876},{},[5233],{"data":5234,"marks":5235,"value":5236,"nodeType":867},{},[],"The drawback is that the kind of PoV that generates this type of evidence requires more time and effort to run. Security teams typically opt for this approach when they know they'll encounter stronger resistance to budget being made available and they'll really need to evidence the need in absolutely concrete terms.",{"data":5238,"content":5239,"nodeType":942},{},[],{"data":5241,"content":5242,"nodeType":868},{},[5243],{"data":5244,"marks":5245,"value":5247,"nodeType":867},{},[5246],{"type":865},"Closing thoughts: “nothing worth having comes easy”",{"data":5249,"content":5250,"nodeType":876},{},[5251],{"data":5252,"marks":5253,"value":5254,"nodeType":867},{},[],"The budget conversation for browser security takes more work than it does for a like-for-like tool replacement — but the security leaders who've been through it consistently find that the economic case is stronger than they expected going in. ",{"data":5256,"content":5257,"nodeType":876},{},[5258],{"data":5259,"marks":5260,"value":5261,"nodeType":867},{},[],"Both strategic imperatives are grounded in data any CFO can verify independently, the financial impact is quantifiable across multiple dimensions, and the routes to funding are well-established across organizations that have already made this investment.",{"data":5263,"content":5264,"nodeType":942},{},[],{"data":5266,"content":5267,"nodeType":876},{},[5268],{"data":5269,"marks":5270,"value":3983,"nodeType":867},{},[],{"data":5272,"content":5273,"nodeType":876},{},[5274],{"data":5275,"marks":5276,"value":3990,"nodeType":867},{},[],{"data":5278,"content":5279,"nodeType":876},{},[5280,5284,5292],{"data":5281,"marks":5282,"value":5283,"nodeType":867},{},[],"Book a ",{"data":5285,"content":5287,"nodeType":915},{"uri":5286},"https://pushsecurity.com/demo/",[5288],{"data":5289,"marks":5290,"value":5291,"nodeType":867},{},[],"live demo",{"data":5293,"marks":5294,"value":3229,"nodeType":867},{},[],{"entries":5296},{"hyperlink":5297,"inline":5298,"block":5299},[],[],[5300,5307,5333,5357,5384,5410],{"sys":5301,"__typename":1688,"title":5302,"caption":59,"layoutMode":59,"file":5303},{"id":4150},"business case framework",{"url":5304,"width":5305,"height":5306},"https://images.ctfassets.net/y1cdw1ablpvd/1TIwUkTfu8uJkxpF3vS8jS/e93b6ddfa432874452812c2566b5e031/business_case_framework_2x__4_.png",3200,2302,{"sys":5308,"__typename":1705,"content":5309,"name":5332,"title":59},{"id":4384},{"json":5310},{"nodeType":1680,"data":5311,"content":5312},{},[5313,5320],{"nodeType":876,"data":5314,"content":5315},{},[5316],{"nodeType":867,"value":5317,"marks":5318,"data":5319},"To illustrate the potential economic impact, each value driver below includes an estimate for a hypothetical 1,000-employee US technology company called ACME. The assumptions used are conservative and the benchmarks are publicly available. And while your own numbers will differ, the methodology used is transferable. ",[],{},{"nodeType":876,"data":5321,"content":5322},{},[5323,5327],{"nodeType":867,"value":5324,"marks":5325,"data":5326},"Using these estimates, ACME can conservatively expect a return of ",[],{},{"nodeType":867,"value":5328,"marks":5329,"data":5331},"$435K–$925K in combined annual value from direct labor savings, risk-adjusted cost avoidance, and accelerated productivity gains.",[5330],{"type":865},{},"Browser business case IB1",{"sys":5334,"__typename":1705,"content":5335,"name":5356,"title":59},{"id":4500},{"json":5336},{"nodeType":1680,"data":5337,"content":5338},{},[5339],{"nodeType":876,"data":5340,"content":5341},{},[5342,5347,5351],{"nodeType":867,"value":5343,"marks":5344,"data":5346},"ACME example: ",[5345],{"type":865},{},{"nodeType":867,"value":5348,"marks":5349,"data":5350},"IBM's data puts the average breach cost for a technology company at approximately $4.9M. Assuming a conservative 5–8% annual breach probability, and given that 80% of breaches are now identity-based and execute via the browser, the question is how much of that exposure Push eliminates. Push detects and blocks browser-native, identity-based attacks in real time. Even using a conservative 80% effectiveness estimate ",[],{},{"nodeType":867,"value":5352,"marks":5353,"data":5355},"the expected annual value is $150K–$250K.",[5354],{"type":865},{},"Browser business case IB2",{"sys":5358,"__typename":1705,"content":5359,"name":5383,"title":59},{"id":4632},{"json":5360},{"nodeType":1680,"data":5361,"content":5362},{},[5363],{"nodeType":876,"data":5364,"content":5365},{},[5366,5370,5374,5379],{"nodeType":867,"value":5343,"marks":5367,"data":5369},[5368],{"type":865},{},{"nodeType":867,"value":5371,"marks":5372,"data":5373},"for a 1,000-employee technology company where 60% of the workforce are knowledge workers, accelerating safe AI adoption by three to six months for 25–40% of those workers captures ",[],{},{"nodeType":867,"value":5375,"marks":5376,"data":5378},"$150K–$400K",[5377],{"type":865},{},{"nodeType":867,"value":5380,"marks":5381,"data":5382}," in productivity value.",[],{},"Browser business case IB3",{"sys":5385,"__typename":1705,"content":5386,"name":5409,"title":59},{"id":4769},{"json":5387},{"nodeType":1680,"data":5388,"content":5389},{},[5390],{"nodeType":876,"data":5391,"content":5392},{},[5393,5397,5401,5406],{"nodeType":867,"value":5343,"marks":5394,"data":5396},[5395],{"type":865},{},{"nodeType":867,"value":5398,"marks":5399,"data":5400},"Automated identity remediation across approximately 2,500 vulnerabilities recovers $25K–$35K in analyst time annually. Investigation efficiency gains from earlier detection and the elimination of compromised credential false positives save a further $45K–$65K. Reduced analyst attrition, driven by the removal of tedious manual work, avoids $15K–$25K in recruitment and ramp-up costs. Combined, this value driver represents ",[],{},{"nodeType":867,"value":5402,"marks":5403,"data":5405},"$85K–$125K annually",[5404],{"type":865},{},{"nodeType":867,"value":1679,"marks":5407,"data":5408},[],{},"Browser business case IB4",{"sys":5411,"__typename":1705,"content":5412,"name":5435,"title":59},{"id":4839},{"json":5413},{"nodeType":1680,"data":5414,"content":5415},{},[5416],{"nodeType":876,"data":5417,"content":5418},{},[5419,5423,5427,5432],{"nodeType":867,"value":5343,"marks":5420,"data":5422},[5421],{"type":865},{},{"nodeType":867,"value":5424,"marks":5425,"data":5426},"Push's automated inventory and continuous compliance evidence replaces approximately 1,000 hours of annual audit preparation effort, generating $8K–$25K in direct savings. The larger value is in risk avoidance: assuming a conservative 3–5% annual probability of a compliance-related financial event (e.g. a denied insurance claim or a regulatory fine) and an average impact of $5–8M, even a 30% reduction in that exposure represents $45K–$120K in expected annual value. ",[],{},{"nodeType":867,"value":5428,"marks":5429,"data":5431},"Combined: $50K–$150K",[5430],{"type":865},{},{"nodeType":867,"value":1679,"marks":5433,"data":5434},[],{},"Browser business case IB5",{"items":5437},[],{},"How to make the business case for browser security","2026-05-29T00:00:00.000Z",{"items":5442},[5443,6143,6690],{"__typename":1772,"sys":5444,"content":5446,"title":6129,"synopsis":6130,"hashTags":59,"publishedDate":6131,"slug":6132,"tagsCollection":6133,"authorsCollection":6139},{"id":5445},"1ThCW6Cx8Zcq2flramQdoj",{"json":5447},{"data":5448,"content":5449,"nodeType":1680},{},[5450,5457,5464,5486,5493,5500,5507,5510,5518,5525,5543,5550,5557,5605,5612,5620,5627,5634,5641,5644,5652,5659,5671,5678,5686,5705,5711,5751,5757,5764,5776,5782,5789,5806,5814,5821,5840,5846,5854,5861,6015,6018,6026,6033,6040,6043,6051,6058,6070,6082,6094,6106,6113],{"data":5451,"content":5452,"nodeType":876},{},[5453],{"data":5454,"marks":5455,"value":5456,"nodeType":867},{},[],"At first, it may seem like an obvious choice, partly because the category name \"Secure Enterprise Browser\" implies the answer is a full-stack browser. Plus, the most visible vendors in the space have spent the past few years marketing that exact choice as the only one. ",{"data":5458,"content":5459,"nodeType":876},{},[5460],{"data":5461,"marks":5462,"value":5463,"nodeType":867},{},[],"But the market tells a different story. The majority of vendors Gartner places in the SEB category are now extensions rather than full browsers, and Gartner explicitly notes that extensions have become the preferred option. ",{"data":5465,"content":5466,"nodeType":3804},{},[5467],{"data":5468,"content":5469,"nodeType":876},{},[5470,5474,5482],{"data":5471,"marks":5472,"value":5473,"nodeType":867},{},[],"The buyer-side data tells the same story: In ",{"data":5475,"content":5476,"nodeType":915},{"uri":4107},[5477],{"data":5478,"marks":5479,"value":5481,"nodeType":867},{},[5480],{"type":913},"Omdia's 2026 survey of 400 IT and security professionals",{"data":5483,"marks":5484,"value":5485,"nodeType":867},{},[],", 48% of organizations cited the ability to use their existing browsers as an important attribute in a secure browsing solution.",{"data":5487,"content":5488,"nodeType":876},{},[5489],{"data":5490,"marks":5491,"value":5492,"nodeType":867},{},[],"The truth is: Full-stack enterprise browsers and browser security extensions like Push aren’t competing products. They serve different needs for different teams, though they often get evaluated against each other.",{"data":5494,"content":5495,"nodeType":876},{},[5496],{"data":5497,"marks":5498,"value":5499,"nodeType":867},{},[],"Full-stack enterprise browsers serve the IT team's need to control the workspace. Browser security extensions like Push meet the security team's need to protect their users as they work in their browsers — a fundamentally different problem. ",{"data":5501,"content":5502,"nodeType":876},{},[5503],{"data":5504,"marks":5505,"value":5506,"nodeType":867},{},[],"In this article, we’ll cover why a feature-by-feature checklist is the wrong approach when selecting a secure browser platform, and what questions to consider instead. We’ll also discuss what each type of solution excels at, where Push fits in, and how to map your needs to the right solution.",{"data":5508,"content":5509,"nodeType":942},{},[],{"data":5511,"content":5512,"nodeType":868},{},[5513],{"data":5514,"marks":5515,"value":5517,"nodeType":867},{},[5516],{"type":865},"Full-stack enterprise browsers meet the IT team's need to control a workspace",{"data":5519,"content":5520,"nodeType":876},{},[5521],{"data":5522,"marks":5523,"value":5524,"nodeType":867},{},[],"Full-stack enterprise browsers like Island, Prisma Browser, and SURF Security are best understood as managed workspace platforms rather than browsers in the conventional sense. ",{"data":5526,"content":5527,"nodeType":3804},{},[5528],{"data":5529,"content":5530,"nodeType":876},{},[5531,5535,5540],{"data":5532,"marks":5533,"value":5534,"nodeType":867},{},[],"Island's own CEO Mike Fey has described the company's strategy as transforming the browser into ",{"data":5536,"marks":5537,"value":5539,"nodeType":867},{},[5538],{"type":1303},"\"a centralized, enterprise-grade platform, eliminating layers of legacy IT infrastructure by building more functionality in the browser.\"",{"data":5541,"marks":5542,"value":2167,"nodeType":867},{},[],{"data":5544,"content":5545,"nodeType":876},{},[5546],{"data":5547,"marks":5548,"value":5549,"nodeType":867},{},[],"Chrome Enterprise and Edge for Business occupy a related space as productivity-suite browsers extended with native security controls, sold as part of the broader Google and Microsoft workplace stacks. Different products with different lineage, but all of them converge on the same owner: an IT organization solving for workspace control.",{"data":5551,"content":5552,"nodeType":876},{},[5553],{"data":5554,"marks":5555,"value":5556,"nodeType":867},{},[],"The IT team is trying to achieve workspace policy compliance and access governance. Their primary use case is typically reducing reliance on legacy IT tools like VDI, VPN, remote browser isolation, DaaS, web filtering, and CASBs. In this world, the use cases look like: ",{"data":5558,"content":5559,"nodeType":1629},{},[5560,5575,5590],{"data":5561,"content":5562,"nodeType":1586},{},[5563],{"data":5564,"content":5565,"nodeType":876},{},[5566,5571],{"data":5567,"marks":5568,"value":5570,"nodeType":867},{},[5569],{"type":865},"Securing third-party contractors or BYOD",{"data":5572,"marks":5573,"value":5574,"nodeType":867},{},[]," where the workspace itself is the access control. ",{"data":5576,"content":5577,"nodeType":1586},{},[5578],{"data":5579,"content":5580,"nodeType":876},{},[5581,5586],{"data":5582,"marks":5583,"value":5585,"nodeType":867},{},[5584],{"type":865},"Regulated populations",{"data":5587,"marks":5588,"value":5589,"nodeType":867},{},[]," like call centers, BPO workforces, finance teams handling sensitive material, where output controls like watermarking, screenshot restriction, and print blocking need to be enforced at the OS rendering layer. ",{"data":5591,"content":5592,"nodeType":1586},{},[5593],{"data":5594,"content":5595,"nodeType":876},{},[5596,5601],{"data":5597,"marks":5598,"value":5600,"nodeType":867},{},[5599],{"type":865},"Legacy app support",{"data":5602,"marks":5603,"value":5604,"nodeType":867},{},[]," including IE-mode rendering for applications that have never been modernized. ",{"data":5606,"content":5607,"nodeType":876},{},[5608],{"data":5609,"marks":5610,"value":5611,"nodeType":867},{},[],"For these use cases, the architecture is well-suited, and there are numerous full-stack SEB solutions that address them well. Where the full-stack approach runs into trouble is in getting users to migrate onto a new browser and in justifying the cost of doing so. Both problems scale with the size of the workforce. ",{"data":5613,"content":5614,"nodeType":1058},{},[5615],{"data":5616,"marks":5617,"value":5619,"nodeType":867},{},[5618],{"type":865},"Cost of deployment is a significant blocker for full-stack browsers",{"data":5621,"content":5622,"nodeType":876},{},[5623],{"data":5624,"marks":5625,"value":5626,"nodeType":867},{},[],"The migration costs are easy to predict: deployment and configuration effort, help desk volume and — biggest of all — user resistance. But it’s the license cost that limits deployments in many organizations going from a free consumer browser to a paid replacement for the first time. ",{"data":5628,"content":5629,"nodeType":876},{},[5630],{"data":5631,"marks":5632,"value":5633,"nodeType":867},{},[],"In fact, Gartner notes that most buyers start with a single use case like covering contractors and rarely pursue organization-wide deployment for a full-stack enterprise browser. ",{"data":5635,"content":5636,"nodeType":876},{},[5637],{"data":5638,"marks":5639,"value":5640,"nodeType":867},{},[],"For organizations that do achieve a full-coverage deployment for these full-stack browsers, the need to manage drift in employee behavior over time gets harder. Agentic browsers like Comet, Atlas, and Dia are already starting to pull users toward AI-native workflows that consumer browsers don’t offer and full-stack enterprise browsers don’t currently match.",{"data":5642,"content":5643,"nodeType":942},{},[],{"data":5645,"content":5646,"nodeType":868},{},[5647],{"data":5648,"marks":5649,"value":5651,"nodeType":867},{},[5650],{"type":865},"What a browser security extension built for the security team looks like",{"data":5653,"content":5654,"nodeType":876},{},[5655],{"data":5656,"marks":5657,"value":5658,"nodeType":867},{},[],"Most browser security extensions on the market were built to address this migration hurdle. They attempt to take as many of the features of a full-stack browser as possible, but make it possible to deploy into users’ existing browsers, sidestepping a lot of the cost and rollout problems.",{"data":5660,"content":5661,"nodeType":876},{},[5662,5666],{"data":5663,"marks":5664,"value":5665,"nodeType":867},{},[],"LayerX, Seraphic, SquareX, and Keep Aware have all at some point echoed this approach in their product descriptions with the line ",{"data":5667,"marks":5668,"value":5670,"nodeType":867},{},[5669],{"type":1303},"\"make any browser an enterprise browser.\"",{"data":5672,"content":5673,"nodeType":876},{},[5674],{"data":5675,"marks":5676,"value":5677,"nodeType":867},{},[],"Ultimately, that approach is still aimed at solving problems for the IT team more than the security team.",{"data":5679,"content":5680,"nodeType":1058},{},[5681],{"data":5682,"marks":5683,"value":5685,"nodeType":867},{},[5684],{"type":865},"Push is different — we built a browser extension to meet the security team's needs",{"data":5687,"content":5688,"nodeType":876},{},[5689,5693,5701],{"data":5690,"marks":5691,"value":5692,"nodeType":867},{},[],"Push set out to meet a different need. Our team's background has always been in defending organizations against advanced attacks. We spent our careers working in red and blue teams throughout the network and endpoint eras of cyber attacks. The mission we started with in 2022 was to defend organizations against the ",{"data":5694,"content":5695,"nodeType":915},{"uri":1702},[5696],{"data":5697,"marks":5698,"value":5700,"nodeType":867},{},[5699],{"type":913},"new era of damaging cyber attacks that originate in the browser",{"data":5702,"marks":5703,"value":5704,"nodeType":867},{},[],". ",{"data":5706,"content":5710,"nodeType":985},{"target":5707},{"sys":5708},{"id":5709,"type":982,"linkType":983},"6BwJl8ZkiMore2o1BKx2w6",[],{"data":5712,"content":5713,"nodeType":876},{},[5714,5718,5727,5731,5736,5740,5748],{"data":5715,"marks":5716,"value":5717,"nodeType":867},{},[],"We chose a browser extension as the approach for our solution, not because we wanted to build an easier-to-deploy enterprise browser, but so we could use it as a security agent to collect high-fidelity telemetry for TTP-based detections, and apply real-time controls to stop attacks at the earliest opportunity in the modern  — ",{"data":5719,"content":5721,"nodeType":915},{"uri":5720},"https://pushsecurity.com/resources/browser-identity-attacks-matrix/",[5722],{"data":5723,"marks":5724,"value":5726,"nodeType":867},{},[5725],{"type":913},"browser and identity native",{"data":5728,"marks":5729,"value":5730,"nodeType":867},{},[],"  — kill chain. ",{"data":5732,"marks":5733,"value":5735,"nodeType":867},{},[5734],{"type":865},"In effect, we created EDR, but for the browser. ",{"data":5737,"marks":5738,"value":5739,"nodeType":867},{},[],"This is what gives Push the edge compared to other Secure Enterprise Browser solutions when it comes to tackling the highest priority threats in the browser — ",{"data":5741,"content":5742,"nodeType":915},{"uri":1289},[5743],{"data":5744,"marks":5745,"value":5747,"nodeType":867},{},[5746],{"type":913},"we’re optimized for this problem area",{"data":5749,"marks":5750,"value":5704,"nodeType":867},{},[],{"data":5752,"content":5756,"nodeType":985},{"target":5753},{"sys":5754},{"id":5755,"type":982,"linkType":983},"4nGzT9cNG0Yid93uUCCuTt",[],{"data":5758,"content":5759,"nodeType":876},{},[5760],{"data":5761,"marks":5762,"value":5763,"nodeType":867},{},[],"For a security team using Push’s extension, this means attacks get stopped at the earliest opportunity in the kill chain and before they cause harm. ",{"data":5765,"content":5766,"nodeType":876},{},[5767,5771],{"data":5768,"marks":5769,"value":5770,"nodeType":867},{},[],"When a user lands on a phishing page built to harvest their credentials, Push sees the page rendering and the JavaScript executing inside the DOM, and can block the credential submission before the form posts. When a user is being walked through a ClickFix or ConsentFix social engineering flow, Push sees the clipboard writes and the OAuth consent flow parameters being prepared, and can intervene before the user completes the action. When a session token is stolen and replayed against a different device, Push sees the session activity and surfaces the compromise. ",{"data":5772,"marks":5773,"value":5775,"nodeType":867},{},[5774],{"type":865},"Push does all of this from a browser extension, without needing to replace the user's browser. ",{"data":5777,"content":5781,"nodeType":985},{"target":5778},{"sys":5779},{"id":5780,"type":982,"linkType":983},"1FZEbn0K80d1jHRRTk7kL7",[],{"data":5783,"content":5784,"nodeType":876},{},[5785],{"data":5786,"marks":5787,"value":5788,"nodeType":867},{},[],"The same underlying technology also addresses other high-value security use cases: Visibility and control over AI usage; hardening identities and surfacing shadow IT; and supporting insider investigations and preventing data loss. ",{"data":5790,"content":5791,"nodeType":876},{},[5792,5795,5802],{"data":5793,"marks":5794,"value":964,"nodeType":867},{},[],{"data":5796,"content":5797,"nodeType":915},{"uri":4857},[5798],{"data":5799,"marks":5800,"value":5801,"nodeType":867},{},[],"highest-value use cases",{"data":5803,"marks":5804,"value":5805,"nodeType":867},{},[]," the browser can address are all powered by the same underlying technical capability, which is why Push's single extension can address four major security use cases rather than four separate tools needing four separate deployments. The success metric for security teams using Push is attacks averted or stopped, cyber risk reduced, and security posture and resilience strengthened — not workspace policy compliance.",{"data":5807,"content":5808,"nodeType":1058},{},[5809],{"data":5810,"marks":5811,"value":5813,"nodeType":867},{},[5812],{"type":865},"Proven at scale: What security leaders are saying",{"data":5815,"content":5816,"nodeType":876},{},[5817],{"data":5818,"marks":5819,"value":5820,"nodeType":867},{},[],"Push launched its browser extension in 2022, making it one of the first and longest-running browser security extensions in the category, and it is now deployed across more than three million browsers worldwide.",{"data":5822,"content":5823,"nodeType":876},{},[5824,5828,5836],{"data":5825,"marks":5826,"value":5827,"nodeType":867},{},[],"Many ",{"data":5829,"content":5830,"nodeType":915},{"uri":4967},[5831],{"data":5832,"marks":5833,"value":5835,"nodeType":867},{},[5834],{"type":913},"Push customers",{"data":5837,"marks":5838,"value":5839,"nodeType":867},{},[]," were initially considering full-stack enterprise browsers, but found that Push provided all the visibility and control they needed without the migration headache.",{"data":5841,"content":5845,"nodeType":985},{"target":5842},{"sys":5843},{"id":5844,"type":982,"linkType":983},"4RDIOAuVN10mZCtjltJCB4",[],{"data":5847,"content":5848,"nodeType":1058},{},[5849],{"data":5850,"marks":5851,"value":5853,"nodeType":867},{},[5852],{"type":865},"The extension matters, but it's what we built around it that really counts",{"data":5855,"content":5856,"nodeType":876},{},[5857],{"data":5858,"marks":5859,"value":5860,"nodeType":867},{},[],"The extension is the most visible part of the Push platform, but what Push has built around it makes the solution the most powerful security tool in the browser:",{"data":5862,"content":5863,"nodeType":1629},{},[5864,5910,5947,5985,6000],{"data":5865,"content":5866,"nodeType":1586},{},[5867],{"data":5868,"content":5869,"nodeType":876},{},[5870,5875,5879,5885,5888,5895,5899,5906],{"data":5871,"marks":5872,"value":5874,"nodeType":867},{},[5873],{"type":865},"In-house threat research that discovers attack techniques as they emerge.",{"data":5876,"marks":5877,"value":5878,"nodeType":867},{},[]," Push researchers track real-world adversary activity and discover new techniques as they appear, including ",{"data":5880,"content":5881,"nodeType":915},{"uri":3692},[5882],{"data":5883,"marks":5884,"value":3685,"nodeType":867},{},[],{"data":5886,"marks":5887,"value":5000,"nodeType":867},{},[],{"data":5889,"content":5890,"nodeType":915},{"uri":3932},[5891],{"data":5892,"marks":5893,"value":5894,"nodeType":867},{},[]," InstallFix",{"data":5896,"marks":5897,"value":5898,"nodeType":867},{},[],", and creating the ",{"data":5900,"content":5901,"nodeType":915},{"uri":2557},[5902],{"data":5903,"marks":5904,"value":5905,"nodeType":867},{},[],"Browser & Identity Attacks Matrix",{"data":5907,"marks":5908,"value":5909,"nodeType":867},{},[],". Detection is only as good as the threat understanding behind it, and research is what keeps that understanding ahead of what attackers are doing in the wild.",{"data":5911,"content":5912,"nodeType":1586},{},[5913],{"data":5914,"content":5915,"nodeType":876},{},[5916,5921,5925,5931,5935,5943],{"data":5917,"marks":5918,"value":5920,"nodeType":867},{},[5919],{"type":865},"Agentic threat hunting and detection engineering at machine speed.",{"data":5922,"marks":5923,"value":5924,"nodeType":867},{},[]," Push's ",{"data":5926,"content":5927,"nodeType":915},{"uri":1421},[5928],{"data":5929,"marks":5930,"value":2585,"nodeType":867},{},[],{"data":5932,"marks":5933,"value":5934,"nodeType":867},{},[]," operationalizes the research, generating new behavioral detections in minutes rather than quarterly releases — covering the ",{"data":5936,"content":5938,"nodeType":915},{"uri":5937},"https://pushsecurity.com/blog/how-the-browser-became-the-main-cyber-battleground/",[5939],{"data":5940,"marks":5941,"value":5942,"nodeType":867},{},[],"techniques behind the Scattered Spider, Scattered Lapsus$ Hunters, and ShinyHunters breaches",{"data":5944,"marks":5945,"value":5946,"nodeType":867},{},[]," of the past three years. Attackers are using AI to accelerate the pace at which they generate new lures, kits, and infrastructure; Push keeps security teams in front by advancing the capability at machine speed and scale.",{"data":5948,"content":5949,"nodeType":1586},{},[5950],{"data":5951,"content":5952,"nodeType":876},{},[5953,5958,5962,5969,5973,5981],{"data":5954,"marks":5955,"value":5957,"nodeType":867},{},[5956],{"type":865},"Collecting the right telemetry to surface both attacker behavior and risky user action.",{"data":5959,"marks":5960,"value":5961,"nodeType":867},{},[]," Telemetry by itself is just data — the value comes from knowing what to collect, why it matters, and how to turn it into detections and controls. Push combines deep instrumentation of the browser with the expertise to use what we collect: the same browser-layer telemetry that detects AiTM kits, ClickFix and ConsentFix lures, and session token replay also surfaces what users are pasting into AI tools, which ",{"data":5963,"content":5964,"nodeType":915},{"uri":2924},[5965],{"data":5966,"marks":5967,"value":5968,"nodeType":867},{},[],"SaaS apps they're logging into outside the IdP",{"data":5970,"marks":5971,"value":5972,"nodeType":867},{},[],", which OAuth grants are being made, and which ",{"data":5974,"content":5976,"nodeType":915},{"uri":5975},"https://pushsecurity.com/blog/browser-extension-management-guide/",[5977],{"data":5978,"marks":5979,"value":5980,"nodeType":867},{},[],"extensions are running in their browsers",{"data":5982,"marks":5983,"value":5984,"nodeType":867},{},[],". The threat detection and the identity, AI, and DLP use cases are not separate features — they are different applications of the same underlying telemetry, surfaced because Push knows what to look for.",{"data":5986,"content":5987,"nodeType":1586},{},[5988],{"data":5989,"content":5990,"nodeType":876},{},[5991,5996],{"data":5992,"marks":5993,"value":5995,"nodeType":867},{},[5994],{"type":865},"Enforcing the right controls at the right place at the right moment.",{"data":5997,"marks":5998,"value":5999,"nodeType":867},{},[]," Visibility without actionability is only half a solution. Push turns the browser into a strong control point for stopping attacks and risky user behaviors in real time — reusing passwords, intercepting credential submission to non-IdP domains, blocking ClickFix clipboard payloads before paste-execute, prompting MFA enrollment at the point of login, warning on weak or breached passwords at credential entry, and surfacing app banners that communicate policy at the moment of use. The same control surface that stops attackers stops the user's mistakes that lead to the next breach.",{"data":6001,"content":6002,"nodeType":1586},{},[6003],{"data":6004,"content":6005,"nodeType":876},{},[6006,6011],{"data":6007,"marks":6008,"value":6010,"nodeType":867},{},[6009],{"type":865},"Balancing security and privacy.",{"data":6012,"marks":6013,"value":6014,"nodeType":867},{},[]," Push is designed to give security teams the telemetry they need without monitoring personal browsing. By default, only logins to configured corporate domains are observed; personal browsing is not collected. (Though administrators have the option to observe personal account logins to work apps, and identify where browsers are being synced to personal accounts, which can result in password loss.) Plaintext passwords and form inputs are never transmitted — passwords are analyzed locally using salted partial hashes. Broader browser metadata is stored on the device and only transmitted when it matches a detection rule. Push does not train AI models on customer telemetry.",{"data":6016,"content":6017,"nodeType":942},{},[],{"data":6019,"content":6020,"nodeType":868},{},[6021],{"data":6022,"marks":6023,"value":6025,"nodeType":867},{},[6024],{"type":865},"Full-stack enterprise browsers and Push’s browser extension are not mutually exclusive",{"data":6027,"content":6028,"nodeType":876},{},[6029],{"data":6030,"marks":6031,"value":6032,"nodeType":867},{},[],"It’s worth pausing on a point that often gets lost in the way the market discusses this choice. Full-stack enterprise browsers and Push’s extension-based solution are not mutually exclusive. They do different things for different teams, and they run together. ",{"data":6034,"content":6035,"nodeType":876},{},[6036],{"data":6037,"marks":6038,"value":6039,"nodeType":867},{},[],"Push supports enterprise browsers like Island and Prisma Browser. Many of Push’s customers use a full-stack browser for the contractor population or regulated workload where the IT team needs workspace controls, and Push across the rest of the workforce to provide the deep security capabilities that the IT team is not measured on but the security team is. The right framing for many enterprises is not whether to choose full-stack or extension. It is full-stack for the IT use cases that need it, and Push everywhere else.",{"data":6041,"content":6042,"nodeType":942},{},[],{"data":6044,"content":6045,"nodeType":868},{},[6046],{"data":6047,"marks":6048,"value":6050,"nodeType":867},{},[6049],{"type":865},"Which one is right for your security team?",{"data":6052,"content":6053,"nodeType":876},{},[6054],{"data":6055,"marks":6056,"value":6057,"nodeType":867},{},[],"The answer follows from the need you are trying to meet. The scenarios below cover the most common real-world situations and the approach that fits each.",{"data":6059,"content":6060,"nodeType":876},{},[6061,6066],{"data":6062,"marks":6063,"value":6065,"nodeType":867},{},[6064],{"type":865},"Is your priority detecting and stopping attacks in the browser?",{"data":6067,"marks":6068,"value":6069,"nodeType":867},{},[]," Go with Push. Push detects and stops the threats actually breaching enterprises — AiTM phishing, ClickFix, OAuth abuse, malicious browser extensions. It also provides valuable additional insight during investigations to understand incidents better and decide how to respond to them. ",{"data":6071,"content":6072,"nodeType":876},{},[6073,6078],{"data":6074,"marks":6075,"value":6077,"nodeType":867},{},[6076],{"type":865},"Do you have a large contractor or third-party population needing locked-down workspace controls?",{"data":6079,"marks":6080,"value":6081,"nodeType":867},{},[]," Use a full-stack enterprise browser for that population and Push for everyone else. Watermarking, screenshot blocking and print restriction are OS-level controls that extensions cannot reliably replicate.",{"data":6083,"content":6084,"nodeType":876},{},[6085,6090],{"data":6086,"marks":6087,"value":6089,"nodeType":867},{},[6088],{"type":865},"Do you have a multi-browser estate including a mix of consumer and agentic browsers?",{"data":6091,"marks":6092,"value":6093,"nodeType":867},{},[]," Push will provide the coverage you need to secure users. The browser options are growing, and locking your workforce into a single corporate browser becomes harder every time a new productivity-shaping browser ships. Push regularly adds support for emerging browsers.",{"data":6095,"content":6096,"nodeType":876},{},[6097,6102],{"data":6098,"marks":6099,"value":6101,"nodeType":867},{},[6100],{"type":865},"Is significant BYOD or unmanaged-device coverage required.",{"data":6103,"marks":6104,"value":6105,"nodeType":867},{},[]," Push is a great option, particularly if you also have Chromebooks that fall outside of your EDR coverage. The extension can easily be installed via email or landing page self-enrollment, with options to enforce coverage through conditional access policies. This provides full threat detection and policy enforcement on devices the organization does not own.",{"data":6107,"content":6108,"nodeType":876},{},[6109],{"data":6110,"marks":6111,"value":6112,"nodeType":867},{},[],"In short, if you are solving for workspace control, the right tool is a full-stack enterprise browser. If you’re solving for protecting users as they work in their browsers, Push is the tool built specifically for that need — with the research depth, detection engineering, and operational scale to do the job.",{"data":6114,"content":6115,"nodeType":876},{},[6116,6119,6126],{"data":6117,"marks":6118,"value":21,"nodeType":867},{},[],{"data":6120,"content":6121,"nodeType":915},{"uri":2689},[6122],{"data":6123,"marks":6124,"value":1675,"nodeType":867},{},[6125],{"type":913},{"data":6127,"marks":6128,"value":1679,"nodeType":867},{},[],"Enterprise browser vs. browser extension: Which should your security team choose?","If you're building a shortlist of browser security vendors, do you need a full-stack enterprise browser, or browser security extension? ","2026-05-21T00:00:00.000Z","enterprise-browser-vs-browser-extension-which-should-your-security-team-choose",{"items":6134},[6135,6137],{"sys":6136,"name":297},{"id":2706},{"sys":6138,"name":2710},{"id":2709},{"items":6140},[6141],{"fullName":4089,"firstName":4090,"jobTitle":851,"profilePicture":6142},{"url":4094},{"__typename":1772,"sys":6144,"content":6146,"title":6676,"synopsis":6677,"hashTags":59,"publishedDate":6678,"slug":6679,"tagsCollection":6680,"authorsCollection":6686},{"id":6145},"7sZs2lHCTN8oYc2OIGCIQG",{"json":6147},{"data":6148,"content":6149,"nodeType":1680},{},[6150,6157,6160,6168,6184,6191,6198,6204,6212,6219,6226,6232,6249,6255,6271,6279,6295,6302,6309,6312,6320,6336,6342,6360,6366,6374,6397,6404,6407,6415,6422,6428,6435,6453,6461,6477,6480,6488,6504,6511,6518,6536,6539,6547,6554,6561,6568,6574,6582,6598,6605,6622,6625,6633,6640,6647,6653,6659],{"data":6151,"content":6152,"nodeType":876},{},[6153],{"data":6154,"marks":6155,"value":6156,"nodeType":867},{},[],"The headline finding getting the most airtime in 2026 is that vulnerability exploitation has overtaken credential abuse as the top single initial access vector, jumping to 31% from 20% the year before. The vulnerability management crisis driving this statistic is one of the most important stories in this year's data. But reading it as evidence that identity threats are receding would be a mistake, because the DBIR's own data tells a more complicated and more useful story when you look at the full picture.",{"data":6158,"content":6159,"nodeType":942},{},[],{"data":6161,"content":6162,"nodeType":868},{},[6163],{"data":6164,"marks":6165,"value":6167,"nodeType":867},{},[6166],{"type":865},"Vulnerability exploitation has caught up with identity — not replaced it",{"data":6169,"content":6170,"nodeType":876},{},[6171,6175,6180],{"data":6172,"marks":6173,"value":6174,"nodeType":867},{},[],"The DBIR's headline comparison pits vulnerability exploitation (31%) against credential abuse (13%) as individual vectors. That comparison is accurate but incomplete, because the DBIR tracks identity-related initial access across ",{"data":6176,"marks":6177,"value":6179,"nodeType":867},{},[6178],{"type":865},"three",{"data":6181,"marks":6182,"value":6183,"nodeType":867},{},[]," separate categories: phishing (16%), credential abuse (13%), and pretexting (6%). Before interpreting those numbers, there's a methodological wrinkle worth understanding.",{"data":6185,"content":6186,"nodeType":876},{},[6187],{"data":6188,"marks":6189,"value":6190,"nodeType":867},{},[],"This year's report added pretexting as a newly tracked initial access vector, reclassifying some incidents previously counted as credential abuse. The DBIR is transparent about the effect: without that change, credential abuse would have been 16% rather than 13%. On an apples-to-apples basis, identity-related initial access (phishing 16% + credential abuse 16%) comes to 32% — versus 31% for vulnerability exploitation.",{"data":6192,"content":6193,"nodeType":876},{},[6194],{"data":6195,"marks":6196,"value":6197,"nodeType":867},{},[],"To be precise about what moved: phishing held roughly flat year over year, but credential abuse saw a modest decline even on the adjusted basis (from 22% to 16%). Overall, the identity picture is broadly stable. The reason the two categories have converged is that vulnerability exploitation surged 55%, not that identity attacks meaningfully receded.",{"data":6199,"content":6203,"nodeType":985},{"target":6200},{"sys":6201},{"id":6202,"type":982,"linkType":983},"5GvSsSY4R6X34ZBMidZ54X",[],{"data":6205,"content":6206,"nodeType":1058},{},[6207],{"data":6208,"marks":6209,"value":6211,"nodeType":867},{},[6210],{"type":865},"The taxonomy gap",{"data":6213,"content":6214,"nodeType":876},{},[6215],{"data":6216,"marks":6217,"value":6218,"nodeType":867},{},[],"It's also worth asking how much the DBIR's initial access taxonomy can tell us. The figure that everyone is citing — Figure 10 — is labelled \"select enumerations,\" and the four tracked vectors (vulnerability exploitation, phishing, credential abuse, pretexting) add up to only 66% of initial access. A third of the picture isn't represented in the headline breakdown at all.",{"data":6220,"content":6221,"nodeType":876},{},[6222],{"data":6223,"marks":6224,"value":6225,"nodeType":867},{},[],"The cluster boundaries and where you draw them also changes the story. The DBIR classifies ClickFix under \"baiting\" — a category that covers malicious downloads and SEO poisoning — rather than phishing, even though the end goal is often the same: getting a user to execute something they shouldn't. Pretexting absorbed incidents that were previously credential abuse, shifting the numbers between categories. These are useful analytical clusters, but they aren't clean divisions of a neatly partitioned attack surface.",{"data":6227,"content":6231,"nodeType":985},{"target":6228},{"sys":6229},{"id":6230,"type":982,"linkType":983},"7t6ZcHDycaPOyLstX4r8zl",[],{"data":6233,"content":6234,"nodeType":876},{},[6235,6239,6246],{"data":6236,"marks":6237,"value":6238,"nodeType":867},{},[],"These are identity attacks at scale, and it isn't clear where — or whether — they show up in the DBIR's initial access vectors. This lack of depth in identity and in-browser attack vectors is common in many defensive models, which is why we've created our own ",{"data":6240,"content":6241,"nodeType":915},{"uri":5720},[6242],{"data":6243,"marks":6244,"value":6245,"nodeType":867},{},[],"Browser and Identity Attacks Matrix",{"data":6247,"marks":6248,"value":1679,"nodeType":867},{},[],{"data":6250,"content":6254,"nodeType":985},{"target":6251},{"sys":6252},{"id":6253,"type":982,"linkType":983},"53U3LHhhHFYnEpShdLmDqs",[],{"data":6256,"content":6257,"nodeType":876},{},[6258,6262,6267],{"data":6259,"marks":6260,"value":6261,"nodeType":867},{},[],"That convergence at initial access also understates the role credentials play across full breach chains. The DBIR states plainly that credential abuse at any point in the breach progression — not just as the first action — appears in ",{"data":6263,"marks":6264,"value":6266,"nodeType":867},{},[6265],{"type":865},"39% of all breaches",{"data":6268,"marks":6269,"value":6270,"nodeType":867},{},[],", making it the single most pervasive technique in the dataset. Credentials don't just open the front door; they unlock lateral movement, privilege escalation, and persistence throughout the attack chain.",{"data":6272,"content":6273,"nodeType":1058},{},[6274],{"data":6275,"marks":6276,"value":6278,"nodeType":867},{},[6277],{"type":865},"The vulnerability treadmill",{"data":6280,"content":6281,"nodeType":876},{},[6282,6286,6291],{"data":6283,"marks":6284,"value":6285,"nodeType":867},{},[],"The vulnerability exploitation surge itself is driven by a structural capacity crisis rather than a shift in attacker preference. Edge devices and VPNs now account for 22% of vulnerability-exploitation breaches, up from 3% the prior year — a ",{"data":6287,"marks":6288,"value":6290,"nodeType":867},{},[6289],{"type":1303},"sevenfold",{"data":6292,"marks":6293,"value":6294,"nodeType":867},{},[]," increase. Organizations face 50% more CISA KEV vulnerabilities to remediate than a year ago, median remediation time has increased from 32 to 43 days, and the volume of vulnerability records in the dataset has grown roughly eightfold.",{"data":6296,"content":6297,"nodeType":876},{},[6298],{"data":6299,"marks":6300,"value":6301,"nodeType":867},{},[],"This trend was already visible in last year's DBIR, when vulnerability exploitation jumped from 15% to 20%. AI-assisted exploit development may be compounding the problem — the DBIR's own data shows 32% of AI-assisted initial access targeting vulnerability exploitation — but the structural capacity crisis was accelerating well before AI became a meaningful factor in the attacker toolkit.",{"data":6303,"content":6304,"nodeType":876},{},[6305],{"data":6306,"marks":6307,"value":6308,"nodeType":867},{},[],"The vulnerability treadmill is accelerating, and the DBIR's remediation data shows defenders losing ground. But this is an additive problem, not a substitution. Both attack surfaces are growing. ",{"data":6310,"content":6311,"nodeType":942},{},[],{"data":6313,"content":6314,"nodeType":868},{},[6315],{"data":6316,"marks":6317,"value":6319,"nodeType":867},{},[6318],{"type":865},"Phishing has left the inbox",{"data":6321,"content":6322,"nodeType":876},{},[6323,6327,6332],{"data":6324,"marks":6325,"value":6326,"nodeType":867},{},[],"41% percent of social engineering breaches now involve vectors other than email, with approximately a quarter coming from social media or phone-based channels. Voice phishing simulations show a ",{"data":6328,"marks":6329,"value":6331,"nodeType":867},{},[6330],{"type":865},"40% higher success rate",{"data":6333,"marks":6334,"value":6335,"nodeType":867},{},[]," than email phishing — a median click rate of 2% versus 1.4%.",{"data":6337,"content":6341,"nodeType":985},{"target":6338},{"sys":6339},{"id":6340,"type":982,"linkType":983},"7pK8qqIDDNmHmJmlcybNoe",[],{"data":6343,"content":6344,"nodeType":876},{},[6345,6349,6356],{"data":6346,"marks":6347,"value":6348,"nodeType":867},{},[],"Even within the email channel, the data confirms what ",{"data":6350,"content":6351,"nodeType":915},{"uri":4857},[6352],{"data":6353,"marks":6354,"value":6355,"nodeType":867},{},[],"browser-level detection data has been showing",{"data":6357,"marks":6358,"value":6359,"nodeType":867},{},[],": credential harvesting dominates. The DBIR's email security gateway breakdown shows 80% of blocked attacks are credential or session phishing, with only 10% involving malware delivery, 5% callback phishing, and 3% BEC. If you're running an email security gateway, the vast majority of what it catches is credential phishing — and 41% of social engineering is arriving through channels it can't see at all.",{"data":6361,"content":6365,"nodeType":985},{"target":6362},{"sys":6363},{"id":6364,"type":982,"linkType":983},"6CvwzQA3gJ8B3RFzLrH7Kp",[],{"data":6367,"content":6368,"nodeType":1058},{},[6369],{"data":6370,"marks":6371,"value":6373,"nodeType":867},{},[6372],{"type":865},"The ClickFix detection gap",{"data":6375,"content":6376,"nodeType":876},{},[6377,6381,6388,6392],{"data":6378,"marks":6379,"value":6380,"nodeType":867},{},[],"The DBIR reports ClickFix at only 2.7% of attacks detected at the browser level. For context, ",{"data":6382,"content":6383,"nodeType":915},{"uri":1599},[6384],{"data":6385,"marks":6386,"value":6387,"nodeType":867},{},[],"CrowdStrike reported a 563% increase in ClickFix lures",{"data":6389,"marks":6390,"value":6391,"nodeType":867},{},[]," over the same period and Microsoft identified it as the most common initial access point at 47% of observed attacks. Push's own data shows ClickFix at a significantly higher proportion of browser-level detections, ",{"data":6393,"marks":6394,"value":6396,"nodeType":867},{},[6395],{"type":865},"with 4 in 5 delivered via search engines specifically.",{"data":6398,"content":6399,"nodeType":876},{},[6400],{"data":6401,"marks":6402,"value":6403,"nodeType":867},{},[],"The gap is striking, and the most likely explanation is a visibility one. ClickFix attacks result in a malware download or script execution on the endpoint — and without browser-layer context, that execution looks like any other malware delivery. If a contributing organization doesn't have visibility into the browser session that preceded the payload, they'd attribute the incident to \"malware download\" or \"user execution\" rather than ClickFix specifically. The DBIR's 2.7% probably reflects how often contributors could trace the chain back to a ClickFix page, not how often ClickFix was actually the delivery mechanism.",{"data":6405,"content":6406,"nodeType":942},{},[],{"data":6408,"content":6409,"nodeType":868},{},[6410],{"data":6411,"marks":6412,"value":6414,"nodeType":867},{},[6413],{"type":865},"Stolen credentials are the ransomware on-ramp",{"data":6416,"content":6417,"nodeType":876},{},[6418],{"data":6419,"marks":6420,"value":6421,"nodeType":867},{},[],"One of the most powerful findings in this year's DBIR is the quantification of the relationship between credential compromise and ransomware outcomes. Fifty percent of ransomware victims had a credential or infostealer event occur within 95 days prior to the ransomware attack, drawing a causal line from credential theft to ransomware deployment.",{"data":6423,"content":6427,"nodeType":985},{"target":6424},{"sys":6425},{"id":6426,"type":982,"linkType":983},"3ZwG5UiweFR4fYiDaxJJDm",[],{"data":6429,"content":6430,"nodeType":876},{},[6431],{"data":6432,"marks":6433,"value":6434,"nodeType":867},{},[],"The infostealer supply chain data reinforces the picture. Infostealers are surfacing an average of 2,362 breached corporate credentials per month from organizational email domains in stealer log datasets, and 54% of devices in Initial Access Broker logs had at least one infostealer installed. The 95-day median window is consistent with the known timeline from credential harvest to ransomware deployment.",{"data":6436,"content":6437,"nodeType":876},{},[6438,6442,6449],{"data":6439,"marks":6440,"value":6441,"nodeType":867},{},[],"That timeline reinforces an argument we've been making about ",{"data":6443,"content":6444,"nodeType":915},{"uri":4435},[6445],{"data":6446,"marks":6447,"value":6448,"nodeType":867},{},[],"where the intervention point needs to be",{"data":6450,"marks":6451,"value":6452,"nodeType":867},{},[],": detecting credential compromise upstream — at the point of credential entry, session creation, or stolen credential reuse — rather than waiting for the ransomware deployment that follows weeks or months later.",{"data":6454,"content":6455,"nodeType":1058},{},[6456],{"data":6457,"marks":6458,"value":6460,"nodeType":867},{},[6459],{"type":865},"Post-compromise tradecraft is shifting",{"data":6462,"content":6463,"nodeType":876},{},[6464,6468,6473],{"data":6465,"marks":6466,"value":6467,"nodeType":867},{},[],"The DBIR's post-compromise data adds another dimension. RMM tool abuse by threat actors showed a ",{"data":6469,"marks":6470,"value":6472,"nodeType":867},{},[6471],{"type":865},"240% increase",{"data":6474,"marks":6475,"value":6476,"nodeType":867},{},[]," over the prior year, while traditional backdoor and C2 malware usage fell 27%. Attackers are increasingly living off the land with the same remote access tools IT teams use. Post-compromise detection is getting harder, which makes catching the initial credential compromise upstream that much more valuable.",{"data":6478,"content":6479,"nodeType":942},{},[],{"data":6481,"content":6482,"nodeType":868},{},[6483],{"data":6484,"marks":6485,"value":6487,"nodeType":867},{},[6486],{"type":865},"Your vendors are half the problem",{"data":6489,"content":6490,"nodeType":876},{},[6491,6495,6500],{"data":6492,"marks":6493,"value":6494,"nodeType":867},{},[],"Third-party involvement in breaches reached ",{"data":6496,"marks":6497,"value":6499,"nodeType":867},{},[6498],{"type":865},"48%",{"data":6501,"marks":6502,"value":6503,"nodeType":867},{},[]," this year, up from 30% — a 60% increase that follows a prior year where the figure had already doubled.",{"data":6505,"content":6506,"nodeType":876},{},[6507],{"data":6508,"marks":6509,"value":6510,"nodeType":867},{},[],"The DBIR's root cause analysis maps directly to identity security: insecure authentication — absent MFA, improper credential rotation — and lack of least privilege enforcement account for a substantial share of cloud-based third-party incidents. Only 23% of third-party organizations fully remediated missing or improperly secured MFA on cloud accounts, and weak password and permission misconfigurations took a median of 8 months to resolve 50% of findings.",{"data":6512,"content":6513,"nodeType":876},{},[6514],{"data":6515,"marks":6516,"value":6517,"nodeType":867},{},[],"Eight months. That's the median timeline for third-party vendors to resolve the identity hygiene issues that create the attack surface in their environments — environments that your data lives in.",{"data":6519,"content":6520,"nodeType":876},{},[6521,6525,6532],{"data":6522,"marks":6523,"value":6524,"nodeType":867},{},[],"Extend that posture gap across every vendor and third-party integration, and you start to see why the third-party breach figure keeps climbing. Visibility into ",{"data":6526,"content":6527,"nodeType":915},{"uri":2225},[6528],{"data":6529,"marks":6530,"value":6531,"nodeType":867},{},[],"OAuth consent flows and third-party integration sprawl",{"data":6533,"marks":6534,"value":6535,"nodeType":867},{},[]," is the starting point for getting ahead of a supply chain problem that is structurally getting worse.",{"data":6537,"content":6538,"nodeType":942},{},[],{"data":6540,"content":6541,"nodeType":868},{},[6542],{"data":6543,"marks":6544,"value":6546,"nodeType":867},{},[6545],{"type":865},"AI is scaling known techniques — and creating new blind spots from the inside",{"data":6548,"content":6549,"nodeType":876},{},[6550],{"data":6551,"marks":6552,"value":6553,"nodeType":867},{},[],"The DBIR's AI analysis this year is grounded in a collaboration with Anthropic covering 793 threat actors who received enforcement action for violating acceptable use policy between March 2025 and February 2026. The findings are measured rather than alarmist: in the median case, actors sought AI assistance across about 15 distinct ATT&CK techniques, 44% of AI-assisted initial access was phishing-related, and less than 2.5% of techniques observed were classified as rare.",{"data":6555,"content":6556,"nodeType":876},{},[6557],{"data":6558,"marks":6559,"value":6560,"nodeType":867},{},[],"AI is currently an operational tool for attackers — automating and scaling known techniques rather than unlocking novel ones. Despite heavy AI-assisted focus on phishing, the DBIR's own incident dataset shows phishing as an initial access vector has barely changed year over year — suggesting AI may be uplifting less-experienced attackers to a higher baseline of lure quality without meaningfully increasing success rates against organizations that already have detection in place.",{"data":6562,"content":6563,"nodeType":876},{},[6564],{"data":6565,"marks":6566,"value":6567,"nodeType":867},{},[],"The more concerning number is the 32% of AI-assisted initial access targeting vulnerability exploitation — compounding the patching capacity crisis discussed earlier in a trend that was already accelerating before AI entered the picture.",{"data":6569,"content":6573,"nodeType":985},{"target":6570},{"sys":6571},{"id":6572,"type":982,"linkType":983},"4bFTnVx1SXMQzZSaICCJOn",[],{"data":6575,"content":6576,"nodeType":1058},{},[6577],{"data":6578,"marks":6579,"value":6581,"nodeType":867},{},[6580],{"type":865},"Shadow AI is the bigger problem",{"data":6583,"content":6584,"nodeType":876},{},[6585,6589,6594],{"data":6586,"marks":6587,"value":6588,"nodeType":867},{},[],"The sharper AI risk for most organizations, though, is internal. Forty-five percent of employees are now regular AI users on corporate devices — up from 15%, a threefold increase — and ",{"data":6590,"marks":6591,"value":6593,"nodeType":867},{},[6592],{"type":865},"67% of them use non-corporate accounts",{"data":6595,"marks":6596,"value":6597,"nodeType":867},{},[],". Shadow AI has become the third most common non-malicious insider action in DLP data, a fourfold increase over the prior year, with source code as the leading data type submitted to unauthorized AI platforms by a wide margin.",{"data":6599,"content":6600,"nodeType":876},{},[6601],{"data":6602,"marks":6603,"value":6604,"nodeType":867},{},[],"The browser extension angle is particularly relevant. More than 15% of users had unauthorized AI browser extensions installed, and the DBIR specifically notes that these extensions collect and retain browsing context from internal sites — creating a data exfiltration pathway that operates independently of traditional DLP controls.",{"data":6606,"content":6607,"nodeType":876},{},[6608,6612,6619],{"data":6609,"marks":6610,"value":6611,"nodeType":867},{},[],"This is moving faster than any previous shadow IT wave, and the data loss vector is the browser — where users interact with AI tools, where extensions collect context, and where OAuth consent grants connect AI services to corporate data. Visibility and control at that layer isn't a nice-to-have for AI governance; ",{"data":6613,"content":6614,"nodeType":915},{"uri":5975},[6615],{"data":6616,"marks":6617,"value":6618,"nodeType":867},{},[],"it's the minimum viable starting point",{"data":6620,"marks":6621,"value":1679,"nodeType":867},{},[],{"data":6623,"content":6624,"nodeType":942},{},[],{"data":6626,"content":6627,"nodeType":868},{},[6628],{"data":6629,"marks":6630,"value":6632,"nodeType":867},{},[6631],{"type":865},"What this means for defenders",{"data":6634,"content":6635,"nodeType":876},{},[6636],{"data":6637,"marks":6638,"value":6639,"nodeType":867},{},[],"The DBIR's 2026 data paints a picture of converging pressures rather than shifting priorities. Vulnerability exploitation surged, but identity-related initial access is broadly stable and credential abuse at 39% across full breach chains remains the single most pervasive technique in the dataset. Phishing is arriving through channels that email gateways can't see. The infostealer-to-ransomware pipeline now has longitudinal data behind it. Third-party involvement keeps climbing because vendor identity hygiene takes months to remediate. And shadow AI is creating data exposure pathways that most security stacks weren't designed to see.",{"data":6641,"content":6642,"nodeType":876},{},[6643],{"data":6644,"marks":6645,"value":6646,"nodeType":867},{},[],"The common thread across all of these findings is that the browser — where credentials are entered, sessions are created, OAuth consent is granted, AI tools are accessed, and extensions collect data — is the layer where these risks converge and where defenders need visibility and control if they're going to address them at the point of risk rather than after the fact.",{"data":6648,"content":6649,"nodeType":876},{},[6650],{"data":6651,"marks":6652,"value":3983,"nodeType":867},{},[],{"data":6654,"content":6655,"nodeType":876},{},[6656],{"data":6657,"marks":6658,"value":3990,"nodeType":867},{},[],{"data":6660,"content":6661,"nodeType":876},{},[6662,6665,6673],{"data":6663,"marks":6664,"value":21,"nodeType":867},{},[],{"data":6666,"content":6667,"nodeType":915},{"uri":2689},[6668],{"data":6669,"marks":6670,"value":6672,"nodeType":867},{},[6671],{"type":913},"Book a live demo to learn more.",{"data":6674,"marks":6675,"value":21,"nodeType":867},{},[],"What the Verizon DBIR tells us about how breaches happen in 2026","What we can learn from 2026's installment of the Verizon Data Breach Investigations Report.","2026-05-20T00:00:00.000Z","verizon-dbir-2026-review",{"items":6681},[6682,6684],{"sys":6683,"name":297},{"id":2706},{"sys":6685,"name":4018},{"id":4017},{"items":6687},[6688],{"fullName":3244,"firstName":3245,"jobTitle":3246,"profilePicture":6689},{"url":3248},{"__typename":1772,"sys":6691,"content":6693,"title":7923,"synopsis":7924,"hashTags":59,"publishedDate":7925,"slug":7926,"tagsCollection":7927,"authorsCollection":7933},{"id":6692},"6MoHWfQlVildcFYKSbfMcE",{"json":6694},{"data":6695,"content":6696,"nodeType":1680},{},[6697,6713,6719,6726,6733,6739,6742,6750,6758,6777,6824,6830,6845,6848,6856,6863,6891,6931,6938,6941,6949,6957,6964,6970,6977,6980,6988,6995,7037,7073,7080,7083,7091,7098,7123,7130,7172,7179,7182,7190,7198,7243,7250,7256,7259,7267,7275,7307,7314,7320,7327,7330,7338,7346,7375,7382,7389,7396,7399,7407,7415,7422,7428,7435,7458,7487,7490,7498,7506,7513,7520,7523,7531,7593,7596,7604,7611,7905,7908],{"data":6698,"content":6699,"nodeType":876},{},[6700,6704,6709],{"data":6701,"marks":6702,"value":6703,"nodeType":867},{},[],"Browser security solutions are one of the most significant additions to the enterprise security stack in recent years — and the data shows it. The browser is where ",{"data":6705,"marks":6706,"value":6708,"nodeType":867},{},[6707],{"type":865},"85% of work now happens",{"data":6710,"marks":6711,"value":6712,"nodeType":867},{},[],", where AI tools are accessed, and where attackers increasingly choose to strike.",{"data":6714,"content":6718,"nodeType":985},{"target":6715},{"sys":6716},{"id":6717,"type":982,"linkType":983},"5P6PyFbn4EakRNlIWtNzyL",[],{"data":6720,"content":6721,"nodeType":876},{},[6722],{"data":6723,"marks":6724,"value":6725,"nodeType":867},{},[],"But browser security is a nascent category. Getting a clear picture of which solution is right for your team, and how to get the most out of it, isn't straightforward. Current solutions on the market serve a wide range of IT and security use cases, with varying degrees of depth and differentiation across them. Not all use cases are equal in terms of their security value, and not all of them are best addressed in the browser.",{"data":6727,"content":6728,"nodeType":876},{},[6729],{"data":6730,"marks":6731,"value":6732,"nodeType":867},{},[],"This article ranks the security problems that browser security solutions can address by the value they deliver: a combination of the risk reduction on offer, and the degree to which the browser is genuinely the best (or only) layer to solve the problem. ",{"data":6734,"content":6738,"nodeType":985},{"target":6735},{"sys":6736},{"id":6737,"type":982,"linkType":983},"6SJPvEHizSYk29lEvVVNj",[],{"data":6740,"content":6741,"nodeType":942},{},[],{"data":6743,"content":6744,"nodeType":868},{},[6745],{"data":6746,"marks":6747,"value":6749,"nodeType":867},{},[6748],{"type":865},"#1 — Account takeover prevention: detecting credential attacks across all vectors",{"data":6751,"content":6752,"nodeType":876},{},[6753],{"data":6754,"marks":6755,"value":6757,"nodeType":867},{},[6756],{"type":865},"Security value: Very high | Browser fit: Uniquely suited",{"data":6759,"content":6760,"nodeType":876},{},[6761,6765,6773],{"data":6762,"marks":6763,"value":6764,"nodeType":867},{},[],"Account takeover (ATO) is the dominant entry point for enterprise breaches: ",{"data":6766,"content":6768,"nodeType":915},{"uri":6767},"https://www.crowdstrike.com/en-gb/resources/infographics/identity-security-risk-review/",[6769],{"data":6770,"marks":6771,"value":6772,"nodeType":867},{},[],"80% of all modern breaches involve compromised or stolen identities",{"data":6774,"marks":6775,"value":6776,"nodeType":867},{},[],". The attack surface is far wider than most identity tooling can see: credential stuffing, password spraying, ghost logins (password-based fallback authentication that persists after SSO is configured), weak or reused credentials on shadow SaaS apps, and accounts where MFA was never enforced.",{"data":6778,"content":6779,"nodeType":876},{},[6780,6784,6792,6795,6800,6803,6808,6812,6820],{"data":6781,"marks":6782,"value":6783,"nodeType":867},{},[],"According to ",{"data":6785,"content":6787,"nodeType":915},{"uri":6786},"https://cf-assets.www.cloudflare.com/slt3lc6tev37/sWDBUMNVtEJB9ZFLt1dUU/8d69e92de2edfb3bf59e7d21d57e7e1a/Cloudflare-2026-threat-report.pdf",[6788],{"data":6789,"marks":6790,"value":6791,"nodeType":867},{},[],"Cloudflare's 2026 Threat Report",{"data":6793,"marks":6794,"value":5136,"nodeType":867},{},[],{"data":6796,"marks":6797,"value":6799,"nodeType":867},{},[6798],{"type":865},"63% of all human logins involve credentials already compromised elsewhere",{"data":6801,"marks":6802,"value":5147,"nodeType":867},{},[],{"data":6804,"marks":6805,"value":6807,"nodeType":867},{},[6806],{"type":865},"94% of all login attempts originate from bots",{"data":6809,"marks":6810,"value":6811,"nodeType":867},{},[],". The ",{"data":6813,"content":6815,"nodeType":915},{"uri":6814},"https://pushsecurity.com/blog/snowflake-retro/",[6816],{"data":6817,"marks":6818,"value":6819,"nodeType":867},{},[],"Snowflake breach",{"data":6821,"marks":6822,"value":6823,"nodeType":867},{},[]," — 165+ organizations compromised, 1 billion+ records stolen — was powered almost entirely by ghost logins: accounts missing MFA that were susceptible to credential stuffing. It's particularly telling that 80% of the accounts impacted had prior breach exposure.",{"data":6825,"content":6829,"nodeType":985},{"target":6826},{"sys":6827},{"id":6828,"type":982,"linkType":983},"HbZ66kp5DiAZtwNGFJK7d",[],{"data":6831,"content":6832,"nodeType":876},{},[6833,6837,6842],{"data":6834,"marks":6835,"value":6836,"nodeType":867},{},[],"For organizations with contractors and BYOD users, the browser extension is also the only enterprise control deployable on devices that can't be MDM-enrolled — extending ATO detection to exactly the place where, per Verizon DBIR 2025, ",{"data":6838,"marks":6839,"value":6841,"nodeType":867},{},[6840],{"type":865},"46% of infostealer infections originate",{"data":6843,"marks":6844,"value":1679,"nodeType":867},{},[],{"data":6846,"content":6847,"nodeType":942},{},[],{"data":6849,"content":6850,"nodeType":868},{},[6851],{"data":6852,"marks":6853,"value":6855,"nodeType":867},{},[6854],{"type":865},"#2 — Detecting and stopping advanced phishing: AiTM, multi-channel delivery, and zero-day lures",{"data":6857,"content":6858,"nodeType":876},{},[6859],{"data":6860,"marks":6861,"value":6757,"nodeType":867},{},[6862],{"type":865},{"data":6864,"content":6865,"nodeType":876},{},[6866,6870,6878,6882,6887],{"data":6867,"marks":6868,"value":6869,"nodeType":867},{},[],"Adversary-in-the-Middle (AiTM) phishing — where an attacker's reverse proxy intercepts credentials and session tokens in real time — has become the standard technique for bypassing MFA at scale. ",{"data":6871,"content":6873,"nodeType":915},{"uri":6872},"https://www.esentire.com/resources/library/2026-threat-report",[6874],{"data":6875,"marks":6876,"value":6877,"nodeType":867},{},[],"eSentire's 2026 Threat Report",{"data":6879,"marks":6880,"value":6881,"nodeType":867},{},[]," attributes ",{"data":6883,"marks":6884,"value":6886,"nodeType":867},{},[6885],{"type":865},"63% of account compromise incidents to PhaaS kits",{"data":6888,"marks":6889,"value":6890,"nodeType":867},{},[],", with account compromise surging 389% year-over-year.",{"data":6892,"content":6893,"nodeType":876},{},[6894,6898,6906,6910,6915,6919,6927],{"data":6895,"marks":6896,"value":6897,"nodeType":867},{},[],"Traditional phishing controls are also no longer in the right place to intercept these attacks. The delivery channel has shifted decisively away from email: ",{"data":6899,"content":6901,"nodeType":915},{"uri":6900},"https://cloud.google.com/blog/topics/threat-intelligence/m-trends-2026",[6902],{"data":6903,"marks":6904,"value":6905,"nodeType":867},{},[],"Mandiant M-Trends 2026",{"data":6907,"marks":6908,"value":6909,"nodeType":867},{},[]," found email phishing dropped from 14% to 6% as an infection vector, and Push data shows ",{"data":6911,"marks":6912,"value":6914,"nodeType":867},{},[6913],{"type":865},"roughly 1 in 3 phishing payloads intercepted were delivered outside email entirely",{"data":6916,"marks":6917,"value":6918,"nodeType":867},{},[]," — via search engine malvertising, social platforms, and compromised websites. Meanwhile, ",{"data":6920,"content":6921,"nodeType":915},{"uri":1228},[6922],{"data":6923,"marks":6924,"value":6926,"nodeType":867},{},[6925],{"type":865},"89% of phishing domains are active for less than two days",{"data":6928,"marks":6929,"value":6930,"nodeType":867},{},[],", making blocklist-based detection structurally too slow — attackers can spin up, tear down, and move on before blocklists can catch up.",{"data":6932,"content":6933,"nodeType":876},{},[6934],{"data":6935,"marks":6936,"value":6937,"nodeType":867},{},[],"Modern phishing plays out entirely inside the browser session. The only detection layer that can see the phishing page structure, the credential entry, and the anomalous token context is the browser itself. Browser-native detection analyses page behavior rather than matching known-bad domains, which means it fires on zero-day kits regardless of how recently the infrastructure was stood up. Controls like credential entry guardrails add an additional layer — blocking corporate passwords from being submitted to unauthorized domains independently of content and behavior-based detections.",{"data":6939,"content":6940,"nodeType":942},{},[],{"data":6942,"content":6943,"nodeType":868},{},[6944],{"data":6945,"marks":6946,"value":6948,"nodeType":867},{},[6947],{"type":865},"#3 — Identity posture hardening: enforcing security across the apps your IdP doesn't manage",{"data":6950,"content":6951,"nodeType":876},{},[6952],{"data":6953,"marks":6954,"value":6956,"nodeType":867},{},[6955],{"type":865},"Security value: High | Browser fit: Uniquely suited",{"data":6958,"content":6959,"nodeType":876},{},[6960],{"data":6961,"marks":6962,"value":6963,"nodeType":867},{},[],"The first challenge is knowing what you're protecting. Every identity an employee creates — every app they sign up to, every password they set, every login that bypasses SSO — is an authentication event that happens inside a browser session. The browser is the only layer that observes all of these events regardless of whether the app is sanctioned, managed, or even known to IT. Solutions that rely on API-level integrations with known apps, network traffic inspection, or email sign-up notifications can only ever build a partial picture, because they can only see apps they already know about. The browser sees the login itself, which means it discovers the identity at the moment it's created or used — authentication method, password strength, MFA status, and all.",{"data":6965,"content":6969,"nodeType":985},{"target":6966},{"sys":6967},{"id":6968,"type":982,"linkType":983},"HETvBCPsKGkqLVtaasXH0",[],{"data":6971,"content":6972,"nodeType":876},{},[6973],{"data":6974,"marks":6975,"value":6976,"nodeType":867},{},[],"But discovery without enforcement is just an inventory problem. Being in the browser means that you're in a great position to act on what it finds at the moment of authentication. Browser-native guardrails that prompt MFA enrollment, guide users toward stronger credentials, and redirect to SSO login paths close the gap at scale, on every app, including those the IdP has never seen. They also produce the continuous, auditable evidence of MFA coverage and credential hygiene across the full application estate that regulators, insurers, and auditors increasingly require — evidence that no IdP-centric tool can provide for apps outside its scope.",{"data":6978,"content":6979,"nodeType":942},{},[],{"data":6981,"content":6982,"nodeType":868},{},[6983],{"data":6984,"marks":6985,"value":6987,"nodeType":867},{},[6986],{"type":865},"#4 — Browser extension security",{"data":6989,"content":6990,"nodeType":876},{},[6991],{"data":6992,"marks":6993,"value":6956,"nodeType":867},{},[6994],{"type":865},{"data":6996,"content":6997,"nodeType":876},{},[6998,7002,7011,7014,7022,7025,7033],{"data":6999,"marks":7000,"value":7001,"nodeType":867},{},[],"Browser extensions have become one of the most talked-about attack surfaces in security over the past 18 months, and understandably so — a string of high-profile supply chain compromises have collectively impacted tens of millions of users since late 2024 (",{"data":7003,"content":7005,"nodeType":915},{"uri":7004},"https://www.cyberhaven.com/blog/cyberhavens-chrome-extension-security-incident-and-what-were-doing-about-it",[7006],{"data":7007,"marks":7008,"value":7010,"nodeType":867},{},[7009],{"type":913},"Cyberhaven",{"data":7012,"marks":7013,"value":5136,"nodeType":867},{},[],{"data":7015,"content":7017,"nodeType":915},{"uri":7016},"https://thehackernews.com/2025/12/darkspectre-browser-extension-campaigns.html",[7018],{"data":7019,"marks":7020,"value":7021,"nodeType":867},{},[],"DarkSpectre",{"data":7023,"marks":7024,"value":5136,"nodeType":867},{},[],{"data":7026,"content":7028,"nodeType":915},{"uri":7027},"https://thehackernews.com/2025/12/trust-wallet-chrome-extension-hack.html",[7029],{"data":7030,"marks":7031,"value":7032,"nodeType":867},{},[],"Trust Wallet",{"data":7034,"marks":7035,"value":7036,"nodeType":867},{},[],", among many others).",{"data":7038,"content":7039,"nodeType":876},{},[7040,7043,7051,7055,7060,7064,7069],{"data":7041,"marks":7042,"value":21,"nodeType":867},{},[],{"data":7044,"content":7045,"nodeType":915},{"uri":1576},[7046],{"data":7047,"marks":7048,"value":7050,"nodeType":867},{},[7049],{"type":913},"Analysis of 20,000+ extensions across Push customers",{"data":7052,"marks":7053,"value":7054,"nodeType":867},{},[]," found ",{"data":7056,"marks":7057,"value":7059,"nodeType":867},{},[7058],{"type":865},"46.76% have the permission combinations needed to perform account takeover with no user interaction",{"data":7061,"marks":7062,"value":7063,"nodeType":867},{},[],", making permissions-based risk scoring effectively useless as a triage tool. The real threat model is not malicious extensions at install time — it's legitimate extensions that ",{"data":7065,"marks":7066,"value":7068,"nodeType":867},{},[7067],{"type":1303},"become",{"data":7070,"marks":7071,"value":7072,"nodeType":867},{},[]," malicious after an ownership transfer, developer account compromise, or silent update push. Every major extension supply chain breach of the past 18 months scored as low-risk immediately before compromise.",{"data":7074,"content":7075,"nodeType":876},{},[7076],{"data":7077,"marks":7078,"value":7079,"nodeType":867},{},[],"SWGs and network tools are structurally blind to this attack surface: a malicious extension exfiltrating session tokens generates no anomalous network signal — its traffic is indistinguishable from normal browsing. Endpoint agents have no visibility into extension behavior at the session level. Extension inventory, supply chain change monitoring — ownership transfers, permission escalations, developer contact changes — and enforcement all require browser-layer access by definition.",{"data":7081,"content":7082,"nodeType":942},{},[],{"data":7084,"content":7085,"nodeType":868},{},[7086],{"data":7087,"marks":7088,"value":7090,"nodeType":867},{},[7089],{"type":865},"#5 — Shadow SaaS discovery and OAuth integration governance",{"data":7092,"content":7093,"nodeType":876},{},[7094],{"data":7095,"marks":7096,"value":6956,"nodeType":867},{},[7097],{"type":865},{"data":7099,"content":7100,"nodeType":876},{},[7101,7105,7110,7114,7119],{"data":7102,"marks":7103,"value":7104,"nodeType":867},{},[],"Shadow SaaS discovery shares DNA with identity posture hardening (#3) — both start with the same browser-native visibility into login events that no other layer can replicate. Where identity posture focuses on hardening ",{"data":7106,"marks":7107,"value":7109,"nodeType":867},{},[7108],{"type":1303},"how",{"data":7111,"marks":7112,"value":7113,"nodeType":867},{},[]," employees authenticate, shadow SaaS discovery focuses on ",{"data":7115,"marks":7116,"value":7118,"nodeType":867},{},[7117],{"type":1303},"what",{"data":7120,"marks":7121,"value":7122,"nodeType":867},{},[]," they authenticate to: surfacing the full estate of applications in use across the organization, including those that IT has never sanctioned or even heard of.",{"data":7124,"content":7125,"nodeType":876},{},[7126],{"data":7127,"marks":7128,"value":7129,"nodeType":867},{},[],"OAuth integration governance is the component of shadow SaaS that is both the most potentially damaging and the hardest to surface through other means. The SaaS-to-SaaS OAuth pivot is now an industrialized attack pattern.",{"data":7131,"content":7132,"nodeType":1629},{},[7133,7152],{"data":7134,"content":7135,"nodeType":1586},{},[7136],{"data":7137,"content":7138,"nodeType":876},{},[7139,7142,7148],{"data":7140,"marks":7141,"value":964,"nodeType":867},{},[],{"data":7143,"content":7144,"nodeType":915},{"uri":1165},[7145],{"data":7146,"marks":7147,"value":1170,"nodeType":867},{},[],{"data":7149,"marks":7150,"value":7151,"nodeType":867},{},[]," Salesforce campaign — which compromised 1,000+ organizations and 1.5 billion records — demonstrated the full chain: the attacker didn't stop at stealing customer data but harvested OAuth tokens, AWS access keys, and Snowflake tokens from breached tenants and pivoted through connected services like Salesloft, Drift, and Gainsight to reach hundreds more organizations.",{"data":7153,"content":7154,"nodeType":1586},{},[7155],{"data":7156,"content":7157,"nodeType":876},{},[7158,7161,7168],{"data":7159,"marks":7160,"value":964,"nodeType":867},{},[],{"data":7162,"content":7163,"nodeType":915},{"uri":2225},[7164],{"data":7165,"marks":7166,"value":7167,"nodeType":867},{},[],"Context.ai → Vercel",{"data":7169,"marks":7170,"value":7171,"nodeType":867},{},[]," chain followed the same logic — stored OAuth tokens from a forgotten AI app trial provided the bridge into Google Workspace, internal dashboards, and API keys. These are not isolated incidents; they are the repeatable playbook for extracting maximum value from a single compromise through the trust relationships that OAuth connections encode.",{"data":7173,"content":7174,"nodeType":876},{},[7175],{"data":7176,"marks":7177,"value":7178,"nodeType":867},{},[],"Every OAuth consent grant transits the browser — the authorization prompt, the scope disclosure, the user's approval click, and the redirect that completes the grant all happen inside a browser session — which makes the browser the only layer where an unwanted grant can be intercepted before the token is issued and the persistent access path is created. Once a token exists, the damage is done: it survives password resets, MFA changes, and session revocations, and revoking it after the fact requires first knowing it was granted, which most organizations do not.",{"data":7180,"content":7181,"nodeType":942},{},[],{"data":7183,"content":7184,"nodeType":868},{},[7185],{"data":7186,"marks":7187,"value":7189,"nodeType":867},{},[7188],{"type":865},"#6 — Blocking ClickFix and social engineering-based malware delivery",{"data":7191,"content":7192,"nodeType":876},{},[7193],{"data":7194,"marks":7195,"value":7197,"nodeType":867},{},[7196],{"type":865},"Security value: High | Browser fit: Strong for interception — shared with endpoint security for execution. ConsentFix is a browser-native exception that is T1-aligned.",{"data":7199,"content":7200,"nodeType":876},{},[7201,7205,7210,7214,7221,7225,7230,7234,7239],{"data":7202,"marks":7203,"value":7204,"nodeType":867},{},[],"ClickFix was the most common initial access vector reported by Microsoft in 2025, accounting for ",{"data":7206,"marks":7207,"value":7209,"nodeType":867},{},[7208],{"type":865},"47% of observed attacks",{"data":7211,"marks":7212,"value":7213,"nodeType":867},{},[],". CrowdStrike's ",{"data":7215,"content":7216,"nodeType":915},{"uri":928},[7217],{"data":7218,"marks":7219,"value":7220,"nodeType":867},{},[],"2026 Global Threat Report",{"data":7222,"marks":7223,"value":7224,"nodeType":867},{},[]," identified fake CAPTCHA lures as the most common malware download type, increasing ",{"data":7226,"marks":7227,"value":7229,"nodeType":867},{},[7228],{"type":865},"563% year-over-year",{"data":7231,"marks":7232,"value":7233,"nodeType":867},{},[],". The technique writes a malicious command to the victim's clipboard and social-engineers them into executing it. It is fileless (bypassing download scanning), user-executed (bypassing endpoint behavioral detections), and ",{"data":7235,"marks":7236,"value":7238,"nodeType":867},{},[7237],{"type":865},"4 in 5 ClickFix payloads intercepted by Push arrived via search engines",{"data":7240,"marks":7241,"value":7242,"nodeType":867},{},[]," — not email (bypassing email anti-phishing controls).",{"data":7244,"content":7245,"nodeType":876},{},[7246],{"data":7247,"marks":7248,"value":7249,"nodeType":867},{},[],"The browser is the earliest and most effective intervention point — detecting the clipboard injection and social engineering lure before anything reaches the endpoint in executable form. But the problem doesn't end at the browser boundary: once the command has been pasted and run, detection and remediation become endpoint problems, and a mature defense requires both layers. The broader *Fix family — FileFix, InstallFix, and similar derivatives — follows the same pattern, with the browser providing the critical early-warning layer within a defense that spans browser and endpoint.",{"data":7251,"content":7255,"nodeType":985},{"target":7252},{"sys":7253},{"id":7254,"type":982,"linkType":983},"39alMHtw9FPHbQINqbAgBN",[],{"data":7257,"content":7258,"nodeType":942},{},[],{"data":7260,"content":7261,"nodeType":868},{},[7262],{"data":7263,"marks":7264,"value":7266,"nodeType":867},{},[7265],{"type":865},"#7 — AI visibility and control: enforcing which AI tools employees can use and how",{"data":7268,"content":7269,"nodeType":876},{},[7270],{"data":7271,"marks":7272,"value":7274,"nodeType":867},{},[7273],{"type":865},"Security value: High | Browser fit: Strong for access enforcement — but AI governance is not a new security problem so much as a force multiplier on existing ones",{"data":7276,"content":7277,"nodeType":876},{},[7278,7282,7290,7294,7303],{"data":7279,"marks":7280,"value":7281,"nodeType":867},{},[],"AI adoption is outpacing security governance at nearly every organization, and ",{"data":7283,"content":7284,"nodeType":915},{"uri":4107},[7285],{"data":7286,"marks":7287,"value":7289,"nodeType":867},{},[7288],{"type":865},"71% of organizations are concerned about data leakage via unsanctioned AI apps",{"data":7291,"marks":7292,"value":7293,"nodeType":867},{},[],". But the security problems that AI creates are not, for the most part, novel — they are existing Tier 1 problems amplified by a new category of tooling. Shadow AI apps are shadow SaaS (#5). AI OAuth integrations are OAuth governance (#5). AI browser extensions are extension security (#4). The risk of employees using personal AI accounts — ",{"data":7295,"content":7297,"nodeType":915},{"uri":7296},"https://keepaware.com/blog/46-of-sensitive-data-bypasses-your-dlp",[7298],{"data":7299,"marks":7300,"value":7302,"nodeType":867},{},[7301],{"type":865},"46% of sensitive inputs to AI tools are sent via personal accounts",{"data":7304,"marks":7305,"value":7306,"nodeType":867},{},[]," — is an identity posture problem (#3).",{"data":7308,"content":7309,"nodeType":876},{},[7310],{"data":7311,"marks":7312,"value":7313,"nodeType":867},{},[],"The component parts that allow you to govern AI are individually Tier 1 capabilities, and the browser is the best single layer for gaining visibility and control over AI usage — it sees the apps, the OAuth grants, the extensions, and the account context. But a complete end-to-end solution also requires a presence on the endpoint layer (for local AI tools, IDE-integrated agents, and API-level usage that never touches the browser), and prompt-level DLP on sanctioned tools is better handled by platform-native controls than by browser-layer observation.",{"data":7315,"content":7319,"nodeType":985},{"target":7316},{"sys":7317},{"id":7318,"type":982,"linkType":983},"6Py3z9VgjhKrchmYvhmbsq",[],{"data":7321,"content":7322,"nodeType":876},{},[7323],{"data":7324,"marks":7325,"value":7326,"nodeType":867},{},[],"The browser is what makes platform controls effective — if employees are using personal accounts, there are no enterprise audit logs to inspect. And for the growing category of AI agents, agentic browsers, and MCP-connected tools that operate through OAuth grants rather than direct user interaction, the browser is where the consent decisions that authorize those agents are made.",{"data":7328,"content":7329,"nodeType":942},{},[],{"data":7331,"content":7332,"nodeType":868},{},[7333],{"data":7334,"marks":7335,"value":7337,"nodeType":867},{},[7336],{"type":865},"#8 — Investigation acceleration and incident response: closing the missing middle",{"data":7339,"content":7340,"nodeType":876},{},[7341],{"data":7342,"marks":7343,"value":7345,"nodeType":867},{},[7344],{"type":865},"Security value: High | Browser fit: Strong — fills a structural gap complementary to endpoint, network, and identity telemetry",{"data":7347,"content":7348,"nodeType":876},{},[7349,7353,7358,7362,7371],{"data":7350,"marks":7351,"value":7352,"nodeType":867},{},[],"Endpoint logs show what processes executed. Network logs show traffic destinations. IdP logs show authentication events. None of them show what happened ",{"data":7354,"marks":7355,"value":7357,"nodeType":867},{},[7356],{"type":1303},"inside the browser session",{"data":7359,"marks":7360,"value":7361,"nodeType":867},{},[]," — the phishing page the user saw, the credentials they entered, the malicious OAuth consent grant, the data uploaded or pasted to an unsanctioned service. This is the missing middle of modern incident investigations, and for the ",{"data":7363,"content":7365,"nodeType":915},{"uri":7364},"https://www.paloaltonetworks.co.uk/resources/research/unit-42-incident-response-report",[7366],{"data":7367,"marks":7368,"value":7370,"nodeType":867},{},[7369],{"type":865},"48% of intrusions involving browser-based activity",{"data":7372,"marks":7373,"value":7374,"nodeType":867},{},[],", the absence of browser telemetry is a significant investigative gap.",{"data":7376,"content":7377,"nodeType":876},{},[7378],{"data":7379,"marks":7380,"value":7381,"nodeType":867},{},[],"Browser-layer telemetry fills that gap with a fundamentally different quality of signal: what users actually clicked, what pages loaded and how they behaved, what credentials were entered, what session activity followed — structured, high-fidelity data from inside the session where the attack played out. That's the difference between inferring what happened and seeing it directly, and it determines scope, drives containment decisions, and provides the direct evidential record that neither endpoint DLP nor network monitoring can supply for browser-native attacks.",{"data":7383,"content":7384,"nodeType":876},{},[7385],{"data":7386,"marks":7387,"value":7388,"nodeType":867},{},[],"Browser telemetry is a key addition to the investigative picture. Investigations are inherently multi-source — without browser data, reconstructing an incident from EDR, network, and IdP logs won't tell you the full picture (particularly when attacks are increasingly delivered outside of email, intercepting users as they browse the internet normally).",{"data":7390,"content":7391,"nodeType":876},{},[7392],{"data":7393,"marks":7394,"value":7395,"nodeType":867},{},[],"The browser provides the causal link that other sources miss: the bridge between \"a user visited a URL\" and \"credentials were submitted to a phishing page that issued a session token now being replayed from an attacker-controlled browser.\" Integrated with SIEM and SOAR platforms, that signal enables automated response workflows to execute on high-confidence detections without waiting for manual triage.",{"data":7397,"content":7398,"nodeType":942},{},[],{"data":7400,"content":7401,"nodeType":868},{},[7402],{"data":7403,"marks":7404,"value":7406,"nodeType":867},{},[7405],{"type":865},"#9 — Infostealer defense: detecting exposure and blocking delivery",{"data":7408,"content":7409,"nodeType":876},{},[7410],{"data":7411,"marks":7412,"value":7414,"nodeType":867},{},[7413],{"type":865},"Security value: High | Browser fit: Strong for delivery interception and stolen factor detection — complementary to endpoint security for execution",{"data":7416,"content":7417,"nodeType":876},{},[7418],{"data":7419,"marks":7420,"value":7421,"nodeType":867},{},[],"Infostealers are the upstream supply chain for a disproportionate share of the most damaging enterprise attacks — harvesting credentials, session cookies, and browser profile data en masse from infected devices, then selling the outputs on infostealer markets for use in credential stuffing, ATO, and ransomware campaigns.",{"data":7423,"content":7427,"nodeType":985},{"target":7424},{"sys":7425},{"id":7426,"type":982,"linkType":983},"5NF1afwu3zFGThZTtStVQA",[],{"data":7429,"content":7430,"nodeType":876},{},[7431],{"data":7432,"marks":7433,"value":7434,"nodeType":867},{},[],"The browser is relevant at two points in the infostealer kill chain. First, delivery interception: ClickFix (covered in #6) is now the primary infostealer delivery mechanism, and the browser is the only layer that can intercept it before execution. Second, detecting stolen factors when attackers attempt to use them — and infostealers produce two categories of stolen factor that the browser can guard against.",{"data":7436,"content":7437,"nodeType":1629},{},[7438,7448],{"data":7439,"content":7440,"nodeType":1586},{},[7441],{"data":7442,"content":7443,"nodeType":876},{},[7444],{"data":7445,"marks":7446,"value":7447,"nodeType":867},{},[],"Stolen credentials can be identified at the point of login: browser-layer detection flags credentials that appear in known breach datasets, catching infostealer-harvested passwords being replayed in credential stuffing campaigns before the account is compromised.",{"data":7449,"content":7450,"nodeType":1586},{},[7451],{"data":7452,"content":7453,"nodeType":876},{},[7454],{"data":7455,"marks":7456,"value":7457,"nodeType":867},{},[],"Stolen session tokens are caught through a different mechanism: sessions originating in instrumented browsers carry a marker, and when a token subsequently appears in an un-instrumented browser it is a confirmed stolen session — catching infostealer-harvested cookies being replayed regardless of how or where the token was originally harvested.",{"data":7459,"content":7460,"nodeType":876},{},[7461,7465,7474,7478,7483],{"data":7462,"marks":7463,"value":7464,"nodeType":867},{},[],"This is particularly critical for the ",{"data":7466,"content":7468,"nodeType":915},{"uri":7467},"https://www.verizon.com/business/en-gb/resources/reports/dbir/",[7469],{"data":7470,"marks":7471,"value":7473,"nodeType":867},{},[7472],{"type":865},"46% of infected devices that are unmanaged",{"data":7475,"marks":7476,"value":7477,"nodeType":867},{},[]," where EDR is absent and the stolen credentials and session tokens will never be detected at the endpoint. Infostealer ",{"data":7479,"marks":7480,"value":7482,"nodeType":867},{},[7481],{"type":1303},"execution",{"data":7484,"marks":7485,"value":7486,"nodeType":867},{},[]," remains an endpoint problem; the browser closes the delivery and replay gaps that endpoint tools miss.",{"data":7488,"content":7489,"nodeType":942},{},[],{"data":7491,"content":7492,"nodeType":868},{},[7493],{"data":7494,"marks":7495,"value":7497,"nodeType":867},{},[7496],{"type":865},"#10 — Data loss prevention: a key component of effective DLP, but not the full picture",{"data":7499,"content":7500,"nodeType":876},{},[7501],{"data":7502,"marks":7503,"value":7505,"nodeType":867},{},[7504],{"type":865},"Security value: Medium-high | Browser fit: Partial — complementary to dedicated DLP",{"data":7507,"content":7508,"nodeType":876},{},[7509],{"data":7510,"marks":7511,"value":7512,"nodeType":867},{},[],"File uploads to unsanctioned services, sensitive data pasted into AI tools, and exfiltration through personal accounts are genuine and growing risks that traditional email and endpoint-centric DLP tools were not designed to catch. Browser-layer controls provide real value here — particularly for BYOD users and contractors, where endpoint DLP agents cannot be deployed and the browser is the only available data loss visibility.",{"data":7514,"content":7515,"nodeType":876},{},[7516],{"data":7517,"marks":7518,"value":7519,"nodeType":867},{},[],"The honest scope: browser-layer DLP does not cover email-based loss, endpoint-to-endpoint transfers, or cloud API exfiltration. It closes specific and important gaps within a broader DLP strategy, not a replacement for one. A further distinction for organizations evaluating browser DLP for secure third-party access: full-stack enterprise browsers can enforce deeper output controls — watermarking, obfuscation, screenshot and print restrictions — at the OS rendering level that browser extensions cannot reliably replicate. Extension-based browser DLP is strongest for upload, input, and access control use cases rather than OS-level output restriction.",{"data":7521,"content":7522,"nodeType":942},{},[],{"data":7524,"content":7525,"nodeType":868},{},[7526],{"data":7527,"marks":7528,"value":7530,"nodeType":867},{},[7529],{"type":865},"Tier 3 — Lower Value: A problem best addressed outside of the browser",{"data":7532,"content":7533,"nodeType":1629},{},[7534,7549,7564,7579],{"data":7535,"content":7536,"nodeType":1586},{},[7537],{"data":7538,"content":7539,"nodeType":876},{},[7540,7545],{"data":7541,"marks":7542,"value":7544,"nodeType":867},{},[7543],{"type":865},"Browser exploit protection",{"data":7546,"marks":7547,"value":7548,"nodeType":867},{},[]," (narrow RCE/sandbox sense) ranks lower because browser zero-days represent just 9% of all zero-days reported to Google, and 82% of attack detections are now malware-free (CrowdStrike 2026). This is a problem for browser vendors to solve, and it's not a big enough problem to warrant enterprises investing in additional mitigating controls.",{"data":7550,"content":7551,"nodeType":1586},{},[7552],{"data":7553,"content":7554,"nodeType":876},{},[7555,7560],{"data":7556,"marks":7557,"value":7559,"nodeType":867},{},[7558],{"type":865},"Domain and URL category controls",{"data":7561,"marks":7562,"value":7563,"nodeType":867},{},[]," offer genuine browser-layer value but are commoditized by SWG and DNS filtering tools most organizations already operate. This can be provided in the browser, sure (and it's something we do at Push) but offers limited security value in terms of making a difference against modern attacks that quickly rotate these kinds of indicators and are designed to blend in.",{"data":7565,"content":7566,"nodeType":1586},{},[7567],{"data":7568,"content":7569,"nodeType":876},{},[7570,7575],{"data":7571,"marks":7572,"value":7574,"nodeType":867},{},[7573],{"type":865},"Access management",{"data":7576,"marks":7577,"value":7578,"nodeType":867},{},[]," — ZTNA, VPN replacement, PAM, BYOD access control — is an IT infrastructure and access architecture problem, not a security operations problem, and belongs to a different buyer with a different evaluation frame. There are numerous (typically full-stack) Enterprise Browser solutions on the market that address IT use cases like this well.",{"data":7580,"content":7581,"nodeType":1586},{},[7582],{"data":7583,"content":7584,"nodeType":876},{},[7585,7589],{"data":7586,"marks":7587,"value":781,"nodeType":867},{},[7588],{"type":865},{"data":7590,"marks":7591,"value":7592,"nodeType":867},{},[]," addresses browser exploit risk rather than the identity-first attacks that represent the majority of current enterprise browser risk, and introduces UX friction that limits deployment at scale. When it triggers, it introduces latency but still fails to detect and stop browser-native attacks.",{"data":7594,"content":7595,"nodeType":942},{},[],{"data":7597,"content":7598,"nodeType":868},{},[7599],{"data":7600,"marks":7601,"value":7603,"nodeType":867},{},[7602],{"type":865},"How Push Security maps to the highest-value security use cases",{"data":7605,"content":7606,"nodeType":876},{},[7607],{"data":7608,"marks":7609,"value":7610,"nodeType":867},{},[],"Push is purpose-built to address all of these problems using a flexible browser extension — plug into any browser with no migration, no host agent deployment, and no IT overhead — that delivers telemetry and control from day one, and extends coverage to every enrolled browser regardless of device ownership.",{"data":7612,"content":7613,"nodeType":7904},{},[7614,7641,7665,7689,7713,7737,7761,7785,7809,7833,7857,7881],{"data":7615,"content":7616,"nodeType":7640},{},[7617,7629],{"data":7618,"content":7619,"nodeType":7628},{},[7620],{"data":7621,"content":7622,"nodeType":876},{},[7623],{"data":7624,"marks":7625,"value":7627,"nodeType":867},{},[7626],{"type":865},"Security use case","table-cell",{"data":7630,"content":7631,"nodeType":7628},{},[7632],{"data":7633,"content":7634,"nodeType":876},{},[7635],{"data":7636,"marks":7637,"value":7639,"nodeType":867},{},[7638],{"type":865},"How Push addresses it","table-row",{"data":7642,"content":7643,"nodeType":7640},{},[7644,7655],{"data":7645,"content":7646,"nodeType":7628},{},[7647],{"data":7648,"content":7649,"nodeType":876},{},[7650],{"data":7651,"marks":7652,"value":7654,"nodeType":867},{},[7653],{"type":865},"Account takeover prevention",{"data":7656,"content":7657,"nodeType":7628},{},[7658],{"data":7659,"content":7660,"nodeType":876},{},[7661],{"data":7662,"marks":7663,"value":7664,"nodeType":867},{},[],"Surfaces and fixes ghost logins, weak and breached credentials and missing MFA controls across every app and device — including shadow SaaS and unmanaged devices invisible to the IdP. Push also detects and stops the attack techniques that typically lead to ATO early in the kill chain and before an account can be compromised.",{"data":7666,"content":7667,"nodeType":7640},{},[7668,7679],{"data":7669,"content":7670,"nodeType":7628},{},[7671],{"data":7672,"content":7673,"nodeType":876},{},[7674],{"data":7675,"marks":7676,"value":7678,"nodeType":867},{},[7677],{"type":865},"Advanced phishing detection",{"data":7680,"content":7681,"nodeType":7628},{},[7682],{"data":7683,"content":7684,"nodeType":876},{},[7685],{"data":7686,"marks":7687,"value":7688,"nodeType":867},{},[],"Behavioral page analysis detects phishing kits regardless of whether the domain is known-bad. Credential entry guardrails block corporate passwords from being submitted to unauthorized domains. TTP-based detection remains effective as attacker infrastructure rotates.",{"data":7690,"content":7691,"nodeType":7640},{},[7692,7703],{"data":7693,"content":7694,"nodeType":7628},{},[7695],{"data":7696,"content":7697,"nodeType":876},{},[7698],{"data":7699,"marks":7700,"value":7702,"nodeType":867},{},[7701],{"type":865},"Identity posture hardening",{"data":7704,"content":7705,"nodeType":7628},{},[7706],{"data":7707,"content":7708,"nodeType":876},{},[7709],{"data":7710,"marks":7711,"value":7712,"nodeType":867},{},[],"Enforces MFA, strong credentials, and SSO adoption across every app the IdP doesn't manage. Produces continuous, auditable MFA coverage and credential hygiene evidence across the full application and device estate.",{"data":7714,"content":7715,"nodeType":7640},{},[7716,7727],{"data":7717,"content":7718,"nodeType":7628},{},[7719],{"data":7720,"content":7721,"nodeType":876},{},[7722],{"data":7723,"marks":7724,"value":7726,"nodeType":867},{},[7725],{"type":865},"Browser extension security",{"data":7728,"content":7729,"nodeType":7628},{},[7730],{"data":7731,"content":7732,"nodeType":876},{},[7733],{"data":7734,"marks":7735,"value":7736,"nodeType":867},{},[],"Live extension inventory with supply chain change event monitoring — ownership transfers, permission escalations, developer contact changes — rather than static risk scoring. Supports default-deny allowlisting and remote extension removal. Blocks known-bad malicious extensions automatically.",{"data":7738,"content":7739,"nodeType":7640},{},[7740,7751],{"data":7741,"content":7742,"nodeType":7628},{},[7743],{"data":7744,"content":7745,"nodeType":876},{},[7746],{"data":7747,"marks":7748,"value":7750,"nodeType":867},{},[7749],{"type":865},"Shadow SaaS and OAuth governance",{"data":7752,"content":7753,"nodeType":7628},{},[7754],{"data":7755,"content":7756,"nodeType":876},{},[7757],{"data":7758,"marks":7759,"value":7760,"nodeType":867},{},[],"Discovers shadow SaaS from actual login events with full authentication context. Monitors and blocks OAuth consent flows — including AI and MCP integrations — in real time before persistent access paths are created.",{"data":7762,"content":7763,"nodeType":7640},{},[7764,7775],{"data":7765,"content":7766,"nodeType":7628},{},[7767],{"data":7768,"content":7769,"nodeType":876},{},[7770],{"data":7771,"marks":7772,"value":7774,"nodeType":867},{},[7773],{"type":865},"ClickFix and the *Fix family",{"data":7776,"content":7777,"nodeType":7628},{},[7778],{"data":7779,"content":7780,"nodeType":876},{},[7781],{"data":7782,"marks":7783,"value":7784,"nodeType":867},{},[],"Detects and blocks ClickFix lures, clipboard injection, and browser-native variants like ConsentFix in real time — before the payload executes or OAuth key material is captured.",{"data":7786,"content":7787,"nodeType":7640},{},[7788,7799],{"data":7789,"content":7790,"nodeType":7628},{},[7791],{"data":7792,"content":7793,"nodeType":876},{},[7794],{"data":7795,"marks":7796,"value":7798,"nodeType":867},{},[7797],{"type":865},"AI visibility & control",{"data":7800,"content":7801,"nodeType":7628},{},[7802],{"data":7803,"content":7804,"nodeType":876},{},[7805],{"data":7806,"marks":7807,"value":7808,"nodeType":867},{},[],"Enforces which AI tools employees can access and routes usage to corporate tenants. Governs AI browser extensions and blocks OAuth consent grants to unapproved AI applications — drawing on the same Tier 1 capabilities (OAuth governance, extension security, shadow SaaS discovery) that make this possible.",{"data":7810,"content":7811,"nodeType":7640},{},[7812,7823],{"data":7813,"content":7814,"nodeType":7628},{},[7815],{"data":7816,"content":7817,"nodeType":876},{},[7818],{"data":7819,"marks":7820,"value":7822,"nodeType":867},{},[7821],{"type":865},"Security investigations & incident response",{"data":7824,"content":7825,"nodeType":7628},{},[7826],{"data":7827,"content":7828,"nodeType":876},{},[7829],{"data":7830,"marks":7831,"value":7832,"nodeType":867},{},[],"High-fidelity session telemetry — page loads, credential entries, DOM changes, OAuth grants — fills the missing middle that endpoint, network, and IdP logs leave open. Feeds directly into SIEM and SOAR for automated response.",{"data":7834,"content":7835,"nodeType":7640},{},[7836,7847],{"data":7837,"content":7838,"nodeType":7628},{},[7839],{"data":7840,"content":7841,"nodeType":876},{},[7842],{"data":7843,"marks":7844,"value":7846,"nodeType":867},{},[7845],{"type":865},"Infostealer defense",{"data":7848,"content":7849,"nodeType":7628},{},[7850],{"data":7851,"content":7852,"nodeType":876},{},[7853],{"data":7854,"marks":7855,"value":7856,"nodeType":867},{},[],"Intercepts ClickFix-based infostealer delivery before execution. Detects token replay in unenrolled browser contexts — catching post-theft abuse from AiTM-sourced tokens and infostealer-harvested cookies, including from unmanaged devices.",{"data":7858,"content":7859,"nodeType":7640},{},[7860,7871],{"data":7861,"content":7862,"nodeType":7628},{},[7863],{"data":7864,"content":7865,"nodeType":876},{},[7866],{"data":7867,"marks":7868,"value":7870,"nodeType":867},{},[7869],{"type":865},"Data loss prevention",{"data":7872,"content":7873,"nodeType":7628},{},[7874],{"data":7875,"content":7876,"nodeType":876},{},[7877],{"data":7878,"marks":7879,"value":7880,"nodeType":867},{},[],"Observes file uploads, downloads, and sensitive data inputs across all applications. Extends data loss visibility to BYOD and contractor devices where endpoint DLP cannot reach.",{"data":7882,"content":7883,"nodeType":7640},{},[7884,7894],{"data":7885,"content":7886,"nodeType":7628},{},[7887],{"data":7888,"content":7889,"nodeType":876},{},[7890],{"data":7891,"marks":7892,"value":7559,"nodeType":867},{},[7893],{"type":865},{"data":7895,"content":7896,"nodeType":7628},{},[7897],{"data":7898,"content":7899,"nodeType":876},{},[7900],{"data":7901,"marks":7902,"value":7903,"nodeType":867},{},[],"Custom URL blocklists with wildcard support and REST API management for threat intelligence feed sync. Application category blocking restricts access to classes of apps (file-sharing, unsanctioned AI tools) configurable by user group. Domain categorization bringing SWG-style category blocking natively to the browser without a network proxy.","table",{"data":7906,"content":7907,"nodeType":942},{},[],{"data":7909,"content":7910,"nodeType":876},{},[7911,7914,7920],{"data":7912,"marks":7913,"value":1667,"nodeType":867},{},[],{"data":7915,"content":7916,"nodeType":915},{"uri":2689},[7917],{"data":7918,"marks":7919,"value":6672,"nodeType":867},{},[],{"data":7921,"marks":7922,"value":21,"nodeType":867},{},[],"The top 10 security problems you can solve in the browser — ranked by value","Ranking the security problems you can solve in the browser by security value and browser fit.","2026-05-14T00:00:00.000Z","the-top-10-security-problems-you-can-solve-in-the-browser-ranked-by-value",{"items":7928},[7929,7931],{"sys":7930,"name":297},{"id":2706},{"sys":7932,"name":2710},{"id":2709},{"items":7934},[7935],{"fullName":4089,"firstName":4090,"jobTitle":851,"profilePicture":7936},{"url":4094},"making-the-business-case-for-a-browser-security-solution","blog/making-the-business-case-for-a-browser-security-solution",{"json":7940},{"data":7941,"content":7942,"nodeType":1680},{},[7943],{"data":7944,"content":7945,"nodeType":876},{},[7946],{"data":7947,"marks":7948,"value":7949,"nodeType":867},{},[],"Browser security is one of the fastest-growing investment areas in enterprise security. It's clear that security teams need browser security solutions, but the challenge is often figuring out how to fund it.","Browser security is one of the fastest-growing investment areas in enterprise security. Here's our proven framework to create budget for browser security tools.",{"id":7952,"publishedAt":7953},"3u4XQlYOFzwY1nKVFaovos","2026-08-12T12:00:51.400Z",{"items":7955},[7956,7958],{"sys":7957,"name":297},{"id":2706},{"sys":7959,"name":2710},{"id":2709},{"items":7961},[7962,7964,7966,7968,7970,7972,7974,7976,7978,7980,7982,7984,7986,7988,7990,7992],{"sys":7963,"name":297,"slug":298,"tier":31},{"id":294},{"sys":7965,"name":413,"slug":414,"tier":31},{"id":410},{"sys":7967,"name":235,"slug":236,"tier":31},{"id":232},{"sys":7969,"name":279,"slug":280,"tier":31},{"id":276},{"sys":7971,"name":624,"slug":625,"tier":45},{"id":621},{"sys":7973,"name":306,"slug":307,"tier":45},{"id":303},{"sys":7975,"name":377,"slug":378,"tier":45},{"id":374},{"sys":7977,"name":580,"slug":581,"tier":45},{"id":577},{"sys":7979,"name":252,"slug":253,"tier":45},{"id":249},{"sys":7981,"name":589,"slug":590,"tier":45},{"id":586},{"sys":7983,"name":261,"slug":262,"tier":45},{"id":258},{"sys":7985,"name":315,"slug":316,"tier":45},{"id":312},{"sys":7987,"name":457,"slug":458,"tier":45},{"id":454},{"sys":7989,"name":502,"slug":503,"tier":45},{"id":499},{"sys":7991,"name":633,"slug":634,"tier":45},{"id":630},{"sys":7993,"name":386,"slug":387,"tier":45},{"id":383},"bBKwW9E1rG-3LgBNn6aPFkmENwD8ArxqVXJcqXlDmIg",{"id":7996,"title":6129,"authorsCollection":7997,"content":8002,"extension":228,"faqItemsCollection":8619,"faqTitle":59,"featured":6,"hashTags":59,"meta":8621,"metaTitle":8622,"ogImage":59,"postType":1767,"publishedDate":6131,"relatedBlogPostsCollection":8623,"slug":6132,"stem":11072,"subtitle":59,"summary":11073,"synopsis":6130,"sys":11084,"tagsCollection":11086,"topicsCollection":11092,"__hash__":11118},"blog/blog/enterprise-browser-vs-browser-extension-which-should-your-security-team-choose.json",{"items":7998},[7999],{"fullName":4089,"firstName":4090,"jobTitle":851,"socialLinks":8000,"profilePicture":8001},[4092],{"url":4094},{"json":8003,"links":8590},{"data":8004,"content":8005,"nodeType":1680},{},[8006,8012,8018,8037,8043,8049,8055,8058,8065,8071,8087,8093,8099,8141,8147,8154,8160,8166,8172,8175,8182,8188,8198,8204,8211,8227,8232,8265,8270,8276,8286,8291,8297,8312,8319,8325,8341,8346,8353,8359,8490,8493,8500,8506,8512,8515,8522,8528,8538,8548,8558,8568,8574],{"data":8007,"content":8008,"nodeType":876},{},[8009],{"data":8010,"marks":8011,"value":5456,"nodeType":867},{},[],{"data":8013,"content":8014,"nodeType":876},{},[8015],{"data":8016,"marks":8017,"value":5463,"nodeType":867},{},[],{"data":8019,"content":8020,"nodeType":3804},{},[8021],{"data":8022,"content":8023,"nodeType":876},{},[8024,8027,8034],{"data":8025,"marks":8026,"value":5473,"nodeType":867},{},[],{"data":8028,"content":8029,"nodeType":915},{"uri":4107},[8030],{"data":8031,"marks":8032,"value":5481,"nodeType":867},{},[8033],{"type":913},{"data":8035,"marks":8036,"value":5485,"nodeType":867},{},[],{"data":8038,"content":8039,"nodeType":876},{},[8040],{"data":8041,"marks":8042,"value":5492,"nodeType":867},{},[],{"data":8044,"content":8045,"nodeType":876},{},[8046],{"data":8047,"marks":8048,"value":5499,"nodeType":867},{},[],{"data":8050,"content":8051,"nodeType":876},{},[8052],{"data":8053,"marks":8054,"value":5506,"nodeType":867},{},[],{"data":8056,"content":8057,"nodeType":942},{},[],{"data":8059,"content":8060,"nodeType":868},{},[8061],{"data":8062,"marks":8063,"value":5517,"nodeType":867},{},[8064],{"type":865},{"data":8066,"content":8067,"nodeType":876},{},[8068],{"data":8069,"marks":8070,"value":5524,"nodeType":867},{},[],{"data":8072,"content":8073,"nodeType":3804},{},[8074],{"data":8075,"content":8076,"nodeType":876},{},[8077,8080,8084],{"data":8078,"marks":8079,"value":5534,"nodeType":867},{},[],{"data":8081,"marks":8082,"value":5539,"nodeType":867},{},[8083],{"type":1303},{"data":8085,"marks":8086,"value":2167,"nodeType":867},{},[],{"data":8088,"content":8089,"nodeType":876},{},[8090],{"data":8091,"marks":8092,"value":5549,"nodeType":867},{},[],{"data":8094,"content":8095,"nodeType":876},{},[8096],{"data":8097,"marks":8098,"value":5556,"nodeType":867},{},[],{"data":8100,"content":8101,"nodeType":1629},{},[8102,8115,8128],{"data":8103,"content":8104,"nodeType":1586},{},[8105],{"data":8106,"content":8107,"nodeType":876},{},[8108,8112],{"data":8109,"marks":8110,"value":5570,"nodeType":867},{},[8111],{"type":865},{"data":8113,"marks":8114,"value":5574,"nodeType":867},{},[],{"data":8116,"content":8117,"nodeType":1586},{},[8118],{"data":8119,"content":8120,"nodeType":876},{},[8121,8125],{"data":8122,"marks":8123,"value":5585,"nodeType":867},{},[8124],{"type":865},{"data":8126,"marks":8127,"value":5589,"nodeType":867},{},[],{"data":8129,"content":8130,"nodeType":1586},{},[8131],{"data":8132,"content":8133,"nodeType":876},{},[8134,8138],{"data":8135,"marks":8136,"value":5600,"nodeType":867},{},[8137],{"type":865},{"data":8139,"marks":8140,"value":5604,"nodeType":867},{},[],{"data":8142,"content":8143,"nodeType":876},{},[8144],{"data":8145,"marks":8146,"value":5611,"nodeType":867},{},[],{"data":8148,"content":8149,"nodeType":1058},{},[8150],{"data":8151,"marks":8152,"value":5619,"nodeType":867},{},[8153],{"type":865},{"data":8155,"content":8156,"nodeType":876},{},[8157],{"data":8158,"marks":8159,"value":5626,"nodeType":867},{},[],{"data":8161,"content":8162,"nodeType":876},{},[8163],{"data":8164,"marks":8165,"value":5633,"nodeType":867},{},[],{"data":8167,"content":8168,"nodeType":876},{},[8169],{"data":8170,"marks":8171,"value":5640,"nodeType":867},{},[],{"data":8173,"content":8174,"nodeType":942},{},[],{"data":8176,"content":8177,"nodeType":868},{},[8178],{"data":8179,"marks":8180,"value":5651,"nodeType":867},{},[8181],{"type":865},{"data":8183,"content":8184,"nodeType":876},{},[8185],{"data":8186,"marks":8187,"value":5658,"nodeType":867},{},[],{"data":8189,"content":8190,"nodeType":876},{},[8191,8194],{"data":8192,"marks":8193,"value":5665,"nodeType":867},{},[],{"data":8195,"marks":8196,"value":5670,"nodeType":867},{},[8197],{"type":1303},{"data":8199,"content":8200,"nodeType":876},{},[8201],{"data":8202,"marks":8203,"value":5677,"nodeType":867},{},[],{"data":8205,"content":8206,"nodeType":1058},{},[8207],{"data":8208,"marks":8209,"value":5685,"nodeType":867},{},[8210],{"type":865},{"data":8212,"content":8213,"nodeType":876},{},[8214,8217,8224],{"data":8215,"marks":8216,"value":5692,"nodeType":867},{},[],{"data":8218,"content":8219,"nodeType":915},{"uri":1702},[8220],{"data":8221,"marks":8222,"value":5700,"nodeType":867},{},[8223],{"type":913},{"data":8225,"marks":8226,"value":5704,"nodeType":867},{},[],{"data":8228,"content":8231,"nodeType":985},{"target":8229},{"sys":8230},{"id":5709,"type":982,"linkType":983},[],{"data":8233,"content":8234,"nodeType":876},{},[8235,8238,8245,8248,8252,8255,8262],{"data":8236,"marks":8237,"value":5717,"nodeType":867},{},[],{"data":8239,"content":8240,"nodeType":915},{"uri":5720},[8241],{"data":8242,"marks":8243,"value":5726,"nodeType":867},{},[8244],{"type":913},{"data":8246,"marks":8247,"value":5730,"nodeType":867},{},[],{"data":8249,"marks":8250,"value":5735,"nodeType":867},{},[8251],{"type":865},{"data":8253,"marks":8254,"value":5739,"nodeType":867},{},[],{"data":8256,"content":8257,"nodeType":915},{"uri":1289},[8258],{"data":8259,"marks":8260,"value":5747,"nodeType":867},{},[8261],{"type":913},{"data":8263,"marks":8264,"value":5704,"nodeType":867},{},[],{"data":8266,"content":8269,"nodeType":985},{"target":8267},{"sys":8268},{"id":5755,"type":982,"linkType":983},[],{"data":8271,"content":8272,"nodeType":876},{},[8273],{"data":8274,"marks":8275,"value":5763,"nodeType":867},{},[],{"data":8277,"content":8278,"nodeType":876},{},[8279,8282],{"data":8280,"marks":8281,"value":5770,"nodeType":867},{},[],{"data":8283,"marks":8284,"value":5775,"nodeType":867},{},[8285],{"type":865},{"data":8287,"content":8290,"nodeType":985},{"target":8288},{"sys":8289},{"id":5780,"type":982,"linkType":983},[],{"data":8292,"content":8293,"nodeType":876},{},[8294],{"data":8295,"marks":8296,"value":5788,"nodeType":867},{},[],{"data":8298,"content":8299,"nodeType":876},{},[8300,8303,8309],{"data":8301,"marks":8302,"value":964,"nodeType":867},{},[],{"data":8304,"content":8305,"nodeType":915},{"uri":4857},[8306],{"data":8307,"marks":8308,"value":5801,"nodeType":867},{},[],{"data":8310,"marks":8311,"value":5805,"nodeType":867},{},[],{"data":8313,"content":8314,"nodeType":1058},{},[8315],{"data":8316,"marks":8317,"value":5813,"nodeType":867},{},[8318],{"type":865},{"data":8320,"content":8321,"nodeType":876},{},[8322],{"data":8323,"marks":8324,"value":5820,"nodeType":867},{},[],{"data":8326,"content":8327,"nodeType":876},{},[8328,8331,8338],{"data":8329,"marks":8330,"value":5827,"nodeType":867},{},[],{"data":8332,"content":8333,"nodeType":915},{"uri":4967},[8334],{"data":8335,"marks":8336,"value":5835,"nodeType":867},{},[8337],{"type":913},{"data":8339,"marks":8340,"value":5839,"nodeType":867},{},[],{"data":8342,"content":8345,"nodeType":985},{"target":8343},{"sys":8344},{"id":5844,"type":982,"linkType":983},[],{"data":8347,"content":8348,"nodeType":1058},{},[8349],{"data":8350,"marks":8351,"value":5853,"nodeType":867},{},[8352],{"type":865},{"data":8354,"content":8355,"nodeType":876},{},[8356],{"data":8357,"marks":8358,"value":5860,"nodeType":867},{},[],{"data":8360,"content":8361,"nodeType":1629},{},[8362,8402,8433,8464,8477],{"data":8363,"content":8364,"nodeType":1586},{},[8365],{"data":8366,"content":8367,"nodeType":876},{},[8368,8372,8375,8381,8384,8390,8393,8399],{"data":8369,"marks":8370,"value":5874,"nodeType":867},{},[8371],{"type":865},{"data":8373,"marks":8374,"value":5878,"nodeType":867},{},[],{"data":8376,"content":8377,"nodeType":915},{"uri":3692},[8378],{"data":8379,"marks":8380,"value":3685,"nodeType":867},{},[],{"data":8382,"marks":8383,"value":5000,"nodeType":867},{},[],{"data":8385,"content":8386,"nodeType":915},{"uri":3932},[8387],{"data":8388,"marks":8389,"value":5894,"nodeType":867},{},[],{"data":8391,"marks":8392,"value":5898,"nodeType":867},{},[],{"data":8394,"content":8395,"nodeType":915},{"uri":2557},[8396],{"data":8397,"marks":8398,"value":5905,"nodeType":867},{},[],{"data":8400,"marks":8401,"value":5909,"nodeType":867},{},[],{"data":8403,"content":8404,"nodeType":1586},{},[8405],{"data":8406,"content":8407,"nodeType":876},{},[8408,8412,8415,8421,8424,8430],{"data":8409,"marks":8410,"value":5920,"nodeType":867},{},[8411],{"type":865},{"data":8413,"marks":8414,"value":5924,"nodeType":867},{},[],{"data":8416,"content":8417,"nodeType":915},{"uri":1421},[8418],{"data":8419,"marks":8420,"value":2585,"nodeType":867},{},[],{"data":8422,"marks":8423,"value":5934,"nodeType":867},{},[],{"data":8425,"content":8426,"nodeType":915},{"uri":5937},[8427],{"data":8428,"marks":8429,"value":5942,"nodeType":867},{},[],{"data":8431,"marks":8432,"value":5946,"nodeType":867},{},[],{"data":8434,"content":8435,"nodeType":1586},{},[8436],{"data":8437,"content":8438,"nodeType":876},{},[8439,8443,8446,8452,8455,8461],{"data":8440,"marks":8441,"value":5957,"nodeType":867},{},[8442],{"type":865},{"data":8444,"marks":8445,"value":5961,"nodeType":867},{},[],{"data":8447,"content":8448,"nodeType":915},{"uri":2924},[8449],{"data":8450,"marks":8451,"value":5968,"nodeType":867},{},[],{"data":8453,"marks":8454,"value":5972,"nodeType":867},{},[],{"data":8456,"content":8457,"nodeType":915},{"uri":5975},[8458],{"data":8459,"marks":8460,"value":5980,"nodeType":867},{},[],{"data":8462,"marks":8463,"value":5984,"nodeType":867},{},[],{"data":8465,"content":8466,"nodeType":1586},{},[8467],{"data":8468,"content":8469,"nodeType":876},{},[8470,8474],{"data":8471,"marks":8472,"value":5995,"nodeType":867},{},[8473],{"type":865},{"data":8475,"marks":8476,"value":5999,"nodeType":867},{},[],{"data":8478,"content":8479,"nodeType":1586},{},[8480],{"data":8481,"content":8482,"nodeType":876},{},[8483,8487],{"data":8484,"marks":8485,"value":6010,"nodeType":867},{},[8486],{"type":865},{"data":8488,"marks":8489,"value":6014,"nodeType":867},{},[],{"data":8491,"content":8492,"nodeType":942},{},[],{"data":8494,"content":8495,"nodeType":868},{},[8496],{"data":8497,"marks":8498,"value":6025,"nodeType":867},{},[8499],{"type":865},{"data":8501,"content":8502,"nodeType":876},{},[8503],{"data":8504,"marks":8505,"value":6032,"nodeType":867},{},[],{"data":8507,"content":8508,"nodeType":876},{},[8509],{"data":8510,"marks":8511,"value":6039,"nodeType":867},{},[],{"data":8513,"content":8514,"nodeType":942},{},[],{"data":8516,"content":8517,"nodeType":868},{},[8518],{"data":8519,"marks":8520,"value":6050,"nodeType":867},{},[8521],{"type":865},{"data":8523,"content":8524,"nodeType":876},{},[8525],{"data":8526,"marks":8527,"value":6057,"nodeType":867},{},[],{"data":8529,"content":8530,"nodeType":876},{},[8531,8535],{"data":8532,"marks":8533,"value":6065,"nodeType":867},{},[8534],{"type":865},{"data":8536,"marks":8537,"value":6069,"nodeType":867},{},[],{"data":8539,"content":8540,"nodeType":876},{},[8541,8545],{"data":8542,"marks":8543,"value":6077,"nodeType":867},{},[8544],{"type":865},{"data":8546,"marks":8547,"value":6081,"nodeType":867},{},[],{"data":8549,"content":8550,"nodeType":876},{},[8551,8555],{"data":8552,"marks":8553,"value":6089,"nodeType":867},{},[8554],{"type":865},{"data":8556,"marks":8557,"value":6093,"nodeType":867},{},[],{"data":8559,"content":8560,"nodeType":876},{},[8561,8565],{"data":8562,"marks":8563,"value":6101,"nodeType":867},{},[8564],{"type":865},{"data":8566,"marks":8567,"value":6105,"nodeType":867},{},[],{"data":8569,"content":8570,"nodeType":876},{},[8571],{"data":8572,"marks":8573,"value":6112,"nodeType":867},{},[],{"data":8575,"content":8576,"nodeType":876},{},[8577,8580,8587],{"data":8578,"marks":8579,"value":21,"nodeType":867},{},[],{"data":8581,"content":8582,"nodeType":915},{"uri":2689},[8583],{"data":8584,"marks":8585,"value":1675,"nodeType":867},{},[8586],{"type":913},{"data":8588,"marks":8589,"value":1679,"nodeType":867},{},[],{"entries":8591},{"hyperlink":8592,"inline":8593,"block":8594},[],[],[8595,8598,8606,8611],{"sys":8596,"__typename":1697,"type":1698,"ctaText":8597,"buttonLabel":151,"buttonColour":1701,"buttonUrl":1702},{"id":5709},"Read our report on the browser attack techniques security teams need to contend with in 2026 (no gates!)",{"sys":8599,"__typename":1688,"title":8600,"caption":8601,"layoutMode":59,"file":8602},{"id":5755},"Comparing ease of deployment x security value for browser security solutions","Comparing ease of deployment x security value for browser security solutions.",{"url":8603,"width":8604,"height":8605},"https://images.ctfassets.net/y1cdw1ablpvd/4z1RAFROesqaBF4H3qR8yu/1e21a68602402773bfa843fd0208d4ca/Screenshot_2026-07-27_at_10.36.43.png",1408,952,{"sys":8607,"__typename":1697,"type":1698,"ctaText":8608,"buttonLabel":8609,"buttonColour":1701,"buttonUrl":8610},{"id":5780},"Read our blog for a step-by-step guide to how Push protects against browser-based attacks. ","Read the blog","https://pushsecurity.com/blog/guide-how-to-use-push-controls-to-protect-your-users-from-modern-attacks/",{"sys":8612,"__typename":1688,"title":8613,"caption":8614,"layoutMode":59,"file":8615},{"id":5844},"SEB Blog Quote Callout","What security leaders have to say about Push.",{"url":8616,"width":8617,"height":8618},"https://images.ctfassets.net/y1cdw1ablpvd/3puINxgWMVBvsieKSMxbcA/d68e403607ea8786de911f7c0bbdd1d3/Frame_628075.png",1390,930,{"items":8620},[],{},"Enterprise browser vs. browser extension solution analysis",{"items":8624},[8625,9209,9991],{"__typename":1772,"sys":8626,"content":8628,"title":9195,"synopsis":9196,"hashTags":59,"publishedDate":9197,"slug":9198,"tagsCollection":9199,"authorsCollection":9205},{"id":8627},"LlTjdYp5ALHM3YIvsCibZ",{"json":8629},{"data":8630,"content":8631,"nodeType":1680},{},[8632,8639,8666,8673,8676,8684,8691,8698,8705,8713,8767,8774,8782,8789,8796,8804,8811,8818,8837,8868,8875,8878,8886,8894,8912,8920,8939,8947,8954,8962,8969,8977,8984,8987,8995,9002,9013,9031,9039,9046,9052,9060,9097,9103,9111,9128,9136,9154,9157,9165,9172,9179],{"data":8633,"content":8634,"nodeType":876},{},[8635],{"data":8636,"marks":8637,"value":8638,"nodeType":867},{},[],"Three browser security companies have been acquired by major security platforms in five months. CrowdStrike acquired Seraphic Security in January 2026. Zscaler absorbed SquareX in February. In May, Akamai announced the acquisition of LayerX. Add Palo Alto Networks' earlier acquisition of Talon, and the browser security market has consolidated faster than almost any adjacent security category before it.",{"data":8640,"content":8641,"nodeType":876},{},[8642,8646,8653,8656,8663],{"data":8643,"marks":8644,"value":8645,"nodeType":867},{},[],"These acquisitions recognize that the browser is now where employees work, where AI runs, and where the most damaging attacks on organizations originate. It’s telling that browser security already accounts for ",{"data":8647,"content":8648,"nodeType":915},{"uri":4107},[8649],{"data":8650,"marks":8651,"value":8652,"nodeType":867},{},[],"12.6% of the average security budget",{"data":8654,"marks":8655,"value":5147,"nodeType":867},{},[],{"data":8657,"content":8658,"nodeType":915},{"uri":4107},[8659],{"data":8660,"marks":8661,"value":8662,"nodeType":867},{},[],"85% of organizations expect to increase that spend over the next 12-24 months",{"data":8664,"marks":8665,"value":1679,"nodeType":867},{},[],{"data":8667,"content":8668,"nodeType":876},{},[8669],{"data":8670,"marks":8671,"value":8672,"nodeType":867},{},[],"But for security buyers, consolidation creates a risk as much as an opportunity. The question isn't whether your existing platform vendor now offers browser security — it's whether what they're offering can actually protect you as the threat landscape evolves.",{"data":8674,"content":8675,"nodeType":942},{},[],{"data":8677,"content":8678,"nodeType":868},{},[8679],{"data":8680,"marks":8681,"value":8683,"nodeType":867},{},[8682],{"type":865},"Why \"good enough\" isn't good enough in the browser",{"data":8685,"content":8686,"nodeType":876},{},[8687],{"data":8688,"marks":8689,"value":8690,"nodeType":867},{},[],"The consolidation pitch is tempting. If you're already a CrowdStrike, Zscaler, or Palo Alto customer, adding browser security through an existing relationship means fewer vendors, fewer contracts, and a coherent narrative about platform consolidation that plays well internally. ",{"data":8692,"content":8693,"nodeType":876},{},[8694],{"data":8695,"marks":8696,"value":8697,"nodeType":867},{},[],"Security teams make these kinds of tradeoffs all the time — accepting that your SASE vendor's threat intelligence feed may not match a dedicated provider, or that your EDR vendor's vulnerability management module may not match a dedicated scanner — are reasonable decisions where the operational benefit of consolidation outweighs the capability difference.",{"data":8699,"content":8700,"nodeType":876},{},[8701],{"data":8702,"marks":8703,"value":8704,"nodeType":867},{},[],"But browser security is a category where the stakes are too high to accept a \"good enough\" solution. The majority of all reported breaches now originate in the browser and attacker tradecraft in this space is advancing at an unprecedented rate thanks to AI. These risks warrant the strongest form of defense. Here are three reasons that “good enough” solutions don't give you that:",{"data":8706,"content":8707,"nodeType":1058},{},[8708],{"data":8709,"marks":8710,"value":8712,"nodeType":867},{},[8711],{"type":865},"1. Most platform browser solutions were built for the wrong problems",{"data":8714,"content":8715,"nodeType":876},{},[8716,8719,8728,8732,8740,8744,8752,8756,8763],{"data":8717,"marks":8718,"value":21,"nodeType":867},{},[],{"data":8720,"content":8722,"nodeType":915},{"uri":8721},"https://www.crowdstrike.com/en-us/resources/infographics/identity-security-risk-review/",[8723],{"data":8724,"marks":8725,"value":8727,"nodeType":867},{},[8726],{"type":913},"CrowdStrike's own research",{"data":8729,"marks":8730,"value":8731,"nodeType":867},{},[]," puts identity involvement in 80% of all modern breaches. Identity weaknesses played a material role in ",{"data":8733,"content":8735,"nodeType":915},{"uri":8734},"https://www.paloaltonetworks.com/resources/research/unit-42-incident-response-report",[8736],{"data":8737,"marks":8738,"value":8739,"nodeType":867},{},[],"almost 90% of Unit 42 incident response investigations",{"data":8741,"marks":8742,"value":8743,"nodeType":867},{},[],". The breaches making headlines — 2024's ",{"data":8745,"content":8747,"nodeType":915},{"uri":8746},"https://pushsecurity.com/blog/snowflake-retro",[8748],{"data":8749,"marks":8750,"value":8751,"nodeType":867},{},[],"mass Snowflake account compromises",{"data":8753,"marks":8754,"value":8755,"nodeType":867},{},[],", 2025's wave of Salesforce-targeted attacks, and 2026's ",{"data":8757,"content":8758,"nodeType":915},{"uri":1165},[8759],{"data":8760,"marks":8761,"value":8762,"nodeType":867},{},[],"continued spree of data theft and extortion",{"data":8764,"marks":8765,"value":8766,"nodeType":867},{},[]," — all trace back to identity weaknesses exploited through the browser: credentials stuffed into login pages that lacked MFA, session tokens hijacked via AiTM phishing, OAuth consent abused to grant persistent access, and device code flows manipulated to bypass authentication entirely. ",{"data":8768,"content":8769,"nodeType":876},{},[8770],{"data":8771,"marks":8772,"value":8773,"nodeType":867},{},[],"Yet Seraphic was built for browser runtime exploit prevention, SquareX for file-based malware sandboxing, LayerX for access governance and AI usage policy. These are real use cases, but they're not the use cases behind headline breaches. If your browser security solution checks a box for \"phishing protection\" but can't detect the identity attack techniques that are actually being industrialized and deployed at scale, you have a gap — and the danger is that you don't know it's there.",{"data":8775,"content":8776,"nodeType":1058},{},[8777],{"data":8778,"marks":8779,"value":8781,"nodeType":867},{},[8780],{"type":865},"2. Even solutions claiming the right capabilities often deliver them superficially",{"data":8783,"content":8784,"nodeType":876},{},[8785],{"data":8786,"marks":8787,"value":8788,"nodeType":867},{},[],"Every browser security vendor claims phishing detection, ClickFix protection, and session security. What varies enormously is whether those capabilities work against real, live, never-before-seen attacker infrastructure — or only against known-bad indicators that attackers rotate in minutes. 95% of in-browser attacks detected by Push used bot protection to evade blocklists; 89% of phishing domains are active for fewer than two days. ",{"data":8790,"content":8791,"nodeType":876},{},[8792],{"data":8793,"marks":8794,"value":8795,"nodeType":867},{},[],"A solution that appears comprehensive in a demo or PoV may leave significant gaps when tested against adversaries who understand exactly how security tools work and actively engineer around them. ",{"data":8797,"content":8798,"nodeType":1058},{},[8799],{"data":8800,"marks":8801,"value":8803,"nodeType":867},{},[8802],{"type":865},"3. AI is only going to widen the gap between \"good enough\" and what you need",{"data":8805,"content":8806,"nodeType":876},{},[8807],{"data":8808,"marks":8809,"value":8810,"nodeType":867},{},[],"When a browser security product is acquired, engineering effort turns inwards towards integration with the parent platform, not advancing detection capability. ",{"data":8812,"content":8813,"nodeType":876},{},[8814],{"data":8815,"marks":8816,"value":8817,"nodeType":867},{},[],"That dynamic plays out differently for each acquisition, but in Seraphic's case it is expected to be particularly heightened. Seraphic works by injecting an agent into the browser's JavaScript runtime. This is the same approach antivirus vendors have used for years, with well-documented stability consequences. Stability is now a top priority for CrowdStrike, which means the Seraphic integration will proceed cautiously. For buyers, that translates directly into slower capability advancement, not faster.",{"data":8819,"content":8820,"nodeType":876},{},[8821,8825,8833],{"data":8822,"marks":8823,"value":8824,"nodeType":867},{},[],"But this is no time for engineering efforts to turn inward, as the threat landscape continues to evolve at an unprecedented rate. You only need to look at the rise of techniques like device code phishing, which have gone from ",{"data":8826,"content":8827,"nodeType":915},{"uri":1116},[8828],{"data":8829,"marks":8830,"value":8832,"nodeType":867},{},[8831],{"type":913},"research curiosity to industrialized exploitation",{"data":8834,"marks":8835,"value":8836,"nodeType":867},{},[]," in a matter of months — in large part enabled by AI-powered tools and AI-assisted development. Similarly, AI has compressed the time to generate a convincing phishing campaign from hours to minutes. ",{"data":8838,"content":8839,"nodeType":876},{},[8840,8844,8851,8855,8864],{"data":8841,"marks":8842,"value":8843,"nodeType":867},{},[],"But it's not only external threats: ",{"data":8845,"content":8846,"nodeType":915},{"uri":4107},[8847],{"data":8848,"marks":8849,"value":8850,"nodeType":867},{},[],"92% of organizations allow employees to use public GenAI applications",{"data":8852,"marks":8853,"value":8854,"nodeType":867},{},[]," — every one of them with unsanctioned AI use occurring by design — employees are routinely entering sensitive data into unapproved AI tools, and ",{"data":8856,"content":8858,"nodeType":915},{"uri":8857},"https://www.gartner.com/en/newsroom/press-releases/2025-08-26-gartner-predicts-40-percent-of-enterprise-apps-will-feature-task-specific-ai-agents-by-2026-up-from-less-than-5-percent-in-2025",[8859],{"data":8860,"marks":8861,"value":8863,"nodeType":867},{},[8862],{"type":913},"Gartner predicts",{"data":8865,"marks":8866,"value":8867,"nodeType":867},{},[]," 40% of enterprise applications will feature AI agents by end of 2026, up from under 5% in 2025. ",{"data":8869,"content":8870,"nodeType":876},{},[8871],{"data":8872,"marks":8873,"value":8874,"nodeType":867},{},[],"The gap between an acquired product focused on integration and vendors whose single-minded focus is on stopping these emerging threats will continue to widen over time.",{"data":8876,"content":8877,"nodeType":942},{},[],{"data":8879,"content":8880,"nodeType":868},{},[8881],{"data":8882,"marks":8883,"value":8885,"nodeType":867},{},[8884],{"type":865},"How to identify a genuinely best-of-breed solution",{"data":8887,"content":8888,"nodeType":1058},{},[8889],{"data":8890,"marks":8891,"value":8893,"nodeType":867},{},[8892],{"type":865},"Start from your own requirements",{"data":8895,"content":8896,"nodeType":876},{},[8897,8901,8908],{"data":8898,"marks":8899,"value":8900,"nodeType":867},{},[],"Define the outcomes you need before speaking to any vendor. The ",{"data":8902,"content":8903,"nodeType":915},{"uri":4857},[8904],{"data":8905,"marks":8906,"value":8907,"nodeType":867},{},[],"highest-value browser security use cases",{"data":8909,"marks":8910,"value":8911,"nodeType":867},{},[]," are account takeover prevention, advanced phishing detection, identity posture hardening, browser extension security, and shadow SaaS and OAuth governance.",{"data":8913,"content":8914,"nodeType":1058},{},[8915],{"data":8916,"marks":8917,"value":8919,"nodeType":867},{},[8918],{"type":865},"Understand how it detects, not just what it claims",{"data":8921,"content":8922,"nodeType":876},{},[8923,8927,8935],{"data":8924,"marks":8925,"value":8926,"nodeType":867},{},[],"Most solutions rely on IoCs — matching known-bad domains, URLs, and IPs against feeds that attackers rotate in minutes.  There’s a major shortcoming with this approach, though: attackers rotate infrastructure faster than any blocklist updates and use bot protection to stay off threat intelligence feeds, making every attack feel ",{"data":8928,"content":8929,"nodeType":915},{"uri":3332},[8930],{"data":8931,"marks":8932,"value":8934,"nodeType":867},{},[8933],{"type":913},"like a zero-day",{"data":8936,"marks":8937,"value":8938,"nodeType":867},{},[],". The only approach that reliably works is TTP-based behavioral detection. Ask every vendor: are you detecting a known-bad indicator or a behavioral technique?",{"data":8940,"content":8941,"nodeType":1058},{},[8942],{"data":8943,"marks":8944,"value":8946,"nodeType":867},{},[8945],{"type":865},"Test against real attacker behavior",{"data":8948,"content":8949,"nodeType":876},{},[8950],{"data":8951,"marks":8952,"value":8953,"nodeType":867},{},[],"Don't evaluate phishing detection with old phishing URLs. By the time you’re running these tests their IoCs will already be on block-lists (see point above). Instead, deploy realistic testing scenarios and look for demonstrable evidence of stopping real-world phishing kits — Evilginx, Tycoon2FA, Sneaky2FA, and so on. ",{"data":8955,"content":8956,"nodeType":1058},{},[8957],{"data":8958,"marks":8959,"value":8961,"nodeType":867},{},[8960],{"type":865},"Assess innovation velocity",{"data":8963,"content":8964,"nodeType":876},{},[8965],{"data":8966,"marks":8967,"value":8968,"nodeType":867},{},[],"Ask every vendor about their research output and feature release history over the past six months — are they discovering and publishing novel attack techniques, or covering what others already documented? Are new detections shipping continuously, or in quarterly cycles? For acquired products specifically, also ask how the roadmap has changed since acquisition. ",{"data":8970,"content":8971,"nodeType":1058},{},[8972],{"data":8973,"marks":8974,"value":8976,"nodeType":867},{},[8975],{"type":865},"Consider operationalization, vendor focus, and lock-in",{"data":8978,"content":8979,"nodeType":876},{},[8980],{"data":8981,"marks":8982,"value":8983,"nodeType":867},{},[],"Many solutions demo well but create significant overhead at scale. Consider whether you want another agent on endpoints, and whether you have the resources to tune granular policies without drowning in false positives. Your requirements might not carry the same weight with a platform vendor with tens of thousands of customers across multiple product lines, versus a dedicated vendor whose entire roadmap exists to solve your problem. And factor in lock-in: every capability consolidated into an existing platform vendor reduces your ability to change direction later.",{"data":8985,"content":8986,"nodeType":942},{},[],{"data":8988,"content":8989,"nodeType":868},{},[8990],{"data":8991,"marks":8992,"value":8994,"nodeType":867},{},[8993],{"type":865},"Why Push is the best-of-breed browser security solution",{"data":8996,"content":8997,"nodeType":876},{},[8998],{"data":8999,"marks":9000,"value":9001,"nodeType":867},{},[],"Think of Push as EDR, but for the browser — high-fidelity telemetry and real-time control across every session, on every device, with no browser migration required. Here’s why customers choose Push as a best-of-breed solution:",{"data":9003,"content":9004,"nodeType":1058},{},[9005,9010],{"data":9006,"marks":9007,"value":9009,"nodeType":867},{},[9008],{"type":865},"Push is built for the security problems that actually cause breaches",{"data":9011,"marks":9012,"value":2136,"nodeType":867},{},[],{"data":9014,"content":9015,"nodeType":876},{},[9016,9020,9027],{"data":9017,"marks":9018,"value":9019,"nodeType":867},{},[],"The highest-value browser security problems — account takeover prevention, advanced phishing detection, identity posture hardening, browser extension security, shadow SaaS and OAuth governance — all require visibility inside the browser session. Push was built from the ground up for exactly that. The same foundational capability that detects AiTM phishing and ClickFix attacks also surfaces the exposure most security teams don't know they have: ",{"data":9021,"content":9022,"nodeType":915},{"uri":2912},[9023],{"data":9024,"marks":9025,"value":9026,"nodeType":867},{},[],"across Push's customer base",{"data":9028,"marks":9029,"value":9030,"nodeType":867},{},[],", 1 in 4 logins use passwords rather than SSO, 2 in 5 are unprotected by MFA, and 46.76% of browser extensions carry permissions sufficient to perform account takeover — none of it visible from the endpoint, network, or email layer.",{"data":9032,"content":9033,"nodeType":1058},{},[9034],{"data":9035,"marks":9036,"value":9038,"nodeType":867},{},[9037],{"type":865},"Push detects high-fidelity attacker TTPs, not low-level IoCs",{"data":9040,"content":9041,"nodeType":876},{},[9042],{"data":9043,"marks":9044,"value":9045,"nodeType":867},{},[],"Push's browser extension operates as a flight recorder inside the session, capturing every page load, credential submission, OAuth consent flow, and user action in real time. That telemetry surfaces attacker behavior — the page structure and script signatures of AiTM kits, the clipboard mechanics of ClickFix, the OAuth flow characteristics of ConsentFix — rather than infrastructure indicators that attackers rotate in minutes. This is how Push intercepts “zero-day” phishing using fresh infrastructure and domains every time, while most solutions are stuck playing known-bad whac-a-mole. ",{"data":9047,"content":9051,"nodeType":985},{"target":9048},{"sys":9049},{"id":9050,"type":982,"linkType":983},"4ho5gOHl1loo9Jtv9nPoq1",[],{"data":9053,"content":9054,"nodeType":1058},{},[9055],{"data":9056,"marks":9057,"value":9059,"nodeType":867},{},[9058],{"type":865},"Push’s research and agentic threat hunting keeps you ahead of attacker innovation",{"data":9061,"content":9062,"nodeType":876},{},[9063,9067,9073,9076,9083,9087,9093],{"data":9064,"marks":9065,"value":9066,"nodeType":867},{},[],"Push named ",{"data":9068,"content":9069,"nodeType":915},{"uri":3692},[9070],{"data":9071,"marks":9072,"value":3685,"nodeType":867},{},[],{"data":9074,"marks":9075,"value":1174,"nodeType":867},{},[],{"data":9077,"content":9078,"nodeType":915},{"uri":3932},[9079],{"data":9080,"marks":9081,"value":9082,"nodeType":867},{},[],"InstallFix",{"data":9084,"marks":9085,"value":9086,"nodeType":867},{},[]," before any other vendor detected either in production. That research feeds an ",{"data":9088,"content":9089,"nodeType":915},{"uri":1421},[9090],{"data":9091,"marks":9092,"value":2585,"nodeType":867},{},[],{"data":9094,"marks":9095,"value":9096,"nodeType":867},{},[]," built on two learning loops — an inner loop for real-time detection of known techniques, and an outer loop where autonomous agents continuously hunt across 3 million deployed browsers for emerging threats, writing new detections and deploying them to customer environments in minutes. ",{"data":9098,"content":9102,"nodeType":985},{"target":9099},{"sys":9100},{"id":9101,"type":982,"linkType":983},"17y3jchoPysKQTf2ra59Bv",[],{"data":9104,"content":9105,"nodeType":1058},{},[9106],{"data":9107,"marks":9108,"value":9110,"nodeType":867},{},[9109],{"type":865},"Push solves more use cases than just stopping advanced attacks",{"data":9112,"content":9113,"nodeType":876},{},[9114,9118,9125],{"data":9115,"marks":9116,"value":9117,"nodeType":867},{},[],"Push uses the same browser-layer visibility to surface every AI tool, agentic browser, extension, and OAuth integration in use across the organization — and enforce policy on what employees can do inside them in real time, including unsanctioned tools no other layer sees. The same technical capabilities provided by Push also harden the identity attack surface, prevent data loss, accelerate insider investigations, and let security teams write custom detections and policies for organization-specific risks. One extension, one deployment, ",{"data":9119,"content":9120,"nodeType":915},{"uri":4857},[9121],{"data":9122,"marks":9123,"value":9124,"nodeType":867},{},[],"multiple high-value use cases",{"data":9126,"marks":9127,"value":1679,"nodeType":867},{},[],{"data":9129,"content":9130,"nodeType":1058},{},[9131],{"data":9132,"marks":9133,"value":9135,"nodeType":867},{},[9134],{"type":865},"Push is built to be operationalized at scale, not just demoed",{"data":9137,"content":9138,"nodeType":876},{},[9139,9143,9150],{"data":9140,"marks":9141,"value":9142,"nodeType":867},{},[],"Push deploys to ",{"data":9144,"content":9145,"nodeType":915},{"uri":4967},[9146],{"data":9147,"marks":9148,"value":9149,"nodeType":867},{},[],"100,000 users in under one hour on a normal workday",{"data":9151,"marks":9152,"value":9153,"nodeType":867},{},[]," — no migration overhead or performance impact. The false positive rate is negligible, meaning no alert noise and no policy tuning overhead. And because Push is independent, it integrates into open ecosystems — feeding browser-layer telemetry into your SIEM, XDR, SOAR, and identity tools alongside the rest of your stack, without adding to your platform lock-in.",{"data":9155,"content":9156,"nodeType":942},{},[],{"data":9158,"content":9159,"nodeType":868},{},[9160],{"data":9161,"marks":9162,"value":9164,"nodeType":867},{},[9163],{"type":865},"Final thoughts",{"data":9166,"content":9167,"nodeType":876},{},[9168],{"data":9169,"marks":9170,"value":9171,"nodeType":867},{},[],"Three acquisitions in five months is a strong market signal, but a strong market signal about vendor interest in a category is not the same thing as a strong signal about capability. The attacker techniques and tooling behind breaches in 2026 are evolving faster than any acquired product with split engineering priorities can reasonably track. ",{"data":9173,"content":9174,"nodeType":876},{},[9175],{"data":9176,"marks":9177,"value":9178,"nodeType":867},{},[],"Security buyers who accept a bundled browser solution because it is included in an existing contract are making a procurement decision, not a security decision. The threats in the browser are serious and sophisticated enough to justify the investment in a tool built to stop them. If you agree, Push is worth a serious look.",{"data":9180,"content":9181,"nodeType":876},{},[9182,9185,9192],{"data":9183,"marks":9184,"value":21,"nodeType":867},{},[],{"data":9186,"content":9187,"nodeType":915},{"uri":2689},[9188],{"data":9189,"marks":9190,"value":6672,"nodeType":867},{},[9191],{"type":913},{"data":9193,"marks":9194,"value":21,"nodeType":867},{},[],"Why \"good enough\" isn’t enough: the case for best-of-breed browser security","Why \"good enough\" isn’t enough when it comes to browser security, and a best-of-breed approach is needed to tackle emerging threats.","2026-05-19T00:00:00.000Z","the-case-for-best-of-breed-browser-security",{"items":9200},[9201,9203],{"sys":9202,"name":297},{"id":2706},{"sys":9204,"name":4018},{"id":4017},{"items":9206},[9207],{"fullName":4089,"firstName":4090,"jobTitle":851,"profilePicture":9208},{"url":4094},{"__typename":1772,"sys":9210,"content":9212,"title":9977,"synopsis":9978,"hashTags":59,"publishedDate":9979,"slug":9980,"tagsCollection":9981,"authorsCollection":9987},{"id":9211},"2V130uMePtxAaefYQAKInb",{"json":9213},{"data":9214,"content":9215,"nodeType":1680},{},[9216,9222,9229,9236,9243,9246,9254,9261,9273,9285,9291,9298,9301,9309,9316,9322,9329,9336,9443,9450,9453,9461,9468,9531,9547,9553,9560,9563,9571,9578,9586,9593,9600,9631,9638,9646,9653,9660,9667,9675,9682,9689,9696,9699,9707,9719,9726,9733,9741,9748,9755,9763,9770,9833,9849,9867,9875,9882,9890,9897,9904,9911,9917,9925,9932,9939,9944,9951,9958,9965,9971],{"data":9217,"content":9221,"nodeType":985},{"target":9218},{"sys":9219},{"id":9220,"type":982,"linkType":983},"5CPZ96xixlhgh6oqQ2rfmO",[],{"data":9223,"content":9224,"nodeType":876},{},[9225],{"data":9226,"marks":9227,"value":9228,"nodeType":867},{},[],"When a security team evaluates browser security solutions, they're usually asking the right question: “How do we protect our users as they work in the browser?”",{"data":9230,"content":9231,"nodeType":876},{},[9232],{"data":9233,"marks":9234,"value":9235,"nodeType":867},{},[],"But the answer they get from many vendors is shaped by a fundamentally different threat model — one that treats the browser as a piece of software to be hardened against exploitation, rather than as the arena where your users’ identities get stolen.",{"data":9237,"content":9238,"nodeType":876},{},[9239],{"data":9240,"marks":9241,"value":9242,"nodeType":867},{},[],"This distinction has enormous consequences for your security posture and the return you can expect from your investment in a new solution.",{"data":9244,"content":9245,"nodeType":942},{},[],{"data":9247,"content":9248,"nodeType":868},{},[9249],{"data":9250,"marks":9251,"value":9253,"nodeType":867},{},[9252],{"type":865},"Two different problems, dressed the same",{"data":9255,"content":9256,"nodeType":876},{},[9257],{"data":9258,"marks":9259,"value":9260,"nodeType":867},{},[],"When it comes to protecting users as they work in the browser, security tools typically fall into one of two camps:",{"data":9262,"content":9263,"nodeType":876},{},[9264,9269],{"data":9265,"marks":9266,"value":9268,"nodeType":867},{},[9267],{"type":865},"The first camp:",{"data":9270,"marks":9271,"value":9272,"nodeType":867},{},[]," represented by solutions like Seraphic (now CrowdStrike) — is built around the threat of attacking the browser itself. The architecture is designed to scramble the browser’s JavaScript runtime and prevent exploits from detonating and breaking out of the browser sandbox. This is browser hardening: defending the browser as software against exploitation by attackers who want to compromise the underlying device.",{"data":9274,"content":9275,"nodeType":876},{},[9276,9281],{"data":9277,"marks":9278,"value":9280,"nodeType":867},{},[9279],{"type":865},"The second camp:",{"data":9282,"marks":9283,"value":9284,"nodeType":867},{},[]," and the one Push Security occupies uniquely, focuses on what happens inside the browser when a user is working normally. Phishing pages harvesting credentials. Session tokens being stolen. Malicious OAuth applications being granted access through social engineering. Adversary-in-the-middle proxies intercepting authentication flows. These attacks don't exploit the browser. They exploit the human — and now agents — using it via the browser's legitimate capabilities (think of it as LOTL, browser edition).",{"data":9286,"content":9290,"nodeType":985},{"target":9287},{"sys":9288},{"id":9289,"type":982,"linkType":983},"5Kw2kSrL8u4VyslxK8HCtR",[],{"data":9292,"content":9293,"nodeType":876},{},[9294],{"data":9295,"marks":9296,"value":9297,"nodeType":867},{},[],"The question for any security team evaluating this space: which of these threat models presents the greatest risks to my organization?",{"data":9299,"content":9300,"nodeType":942},{},[],{"data":9302,"content":9303,"nodeType":868},{},[9304],{"data":9305,"marks":9306,"value":9308,"nodeType":867},{},[9307],{"type":865},"How organizations are actually being breached",{"data":9310,"content":9311,"nodeType":876},{},[9312],{"data":9313,"marks":9314,"value":9315,"nodeType":867},{},[],"Let's look at the major breach campaigns of the last three years without the marketing filter and a pattern emerges immediately. Scattered Spider and its successors breached MGM Resorts, Caesars, M&S, JLR, and Salesforce customers — not through browser exploits, but through social engineering, phishing and Adversary-in-the-Middle attacks that stole session tokens and SSO credentials. ",{"data":9317,"content":9321,"nodeType":985},{"target":9318},{"sys":9319},{"id":9320,"type":982,"linkType":983},"2qIMTiyyIsQFAyGJ9Ikyej",[],{"data":9323,"content":9324,"nodeType":876},{},[9325],{"data":9326,"marks":9327,"value":9328,"nodeType":867},{},[],"In every case, the attack happened in the browser — using stolen identities to log into legitimate cloud services — not on the browser through exploitation of the browser engine itself.",{"data":9330,"content":9331,"nodeType":876},{},[9332],{"data":9333,"marks":9334,"value":9335,"nodeType":867},{},[],"The data from major threat intelligence sources is unambiguous:",{"data":9337,"content":9338,"nodeType":1629},{},[9339,9357,9376,9395,9414,9428],{"data":9340,"content":9341,"nodeType":1586},{},[9342],{"data":9343,"content":9344,"nodeType":876},{},[9345,9349,9353],{"data":9346,"marks":9347,"value":9348,"nodeType":867},{},[],"Identity weaknesses played a material role in ",{"data":9350,"marks":9351,"value":8739,"nodeType":867},{},[9352],{"type":865},{"data":9354,"marks":9355,"value":9356,"nodeType":867},{},[]," (Palo Alto Networks Unit 42 IR Report)",{"data":9358,"content":9359,"nodeType":1586},{},[9360],{"data":9361,"content":9362,"nodeType":876},{},[9363,9367,9372],{"data":9364,"marks":9365,"value":9366,"nodeType":867},{},[],"Credential abuse and phishing combined accounted for ",{"data":9368,"marks":9369,"value":9371,"nodeType":867},{},[9370],{"type":865},"38% of all breaches",{"data":9373,"marks":9374,"value":9375,"nodeType":867},{},[],", making identity the single largest breach vector (Verizon DBIR 2025)",{"data":9377,"content":9378,"nodeType":1586},{},[9379],{"data":9380,"content":9381,"nodeType":876},{},[9382,9386,9391],{"data":9383,"marks":9384,"value":9385,"nodeType":867},{},[],"Cloud-conscious intrusions — attackers using stolen identities to access cloud services — rose ",{"data":9387,"marks":9388,"value":9390,"nodeType":867},{},[9389],{"type":865},"37% in 2025",{"data":9392,"marks":9393,"value":9394,"nodeType":867},{},[],", up 266% among state-nexus actors (CrowdStrike 2026 Global Threat Report)",{"data":9396,"content":9397,"nodeType":1586},{},[9398],{"data":9399,"content":9400,"nodeType":876},{},[9401,9405,9410],{"data":9402,"marks":9403,"value":9404,"nodeType":867},{},[],"In cloud-related incidents, identity issues drove initial access in ",{"data":9406,"marks":9407,"value":9409,"nodeType":867},{},[9408],{"type":865},"83% of cases",{"data":9411,"marks":9412,"value":9413,"nodeType":867},{},[]," (Mandiant / Google Cloud Threat Horizons H1 2026)",{"data":9415,"content":9416,"nodeType":1586},{},[9417],{"data":9418,"content":9419,"nodeType":876},{},[9420,9424],{"data":9421,"marks":9422,"value":934,"nodeType":867},{},[9423],{"type":865},{"data":9425,"marks":9426,"value":9427,"nodeType":867},{},[]," — they don't touch the endpoint and abuse legitimate access and functionality (CrowdStrike 2026 Global Threat Report)",{"data":9429,"content":9430,"nodeType":1586},{},[9431],{"data":9432,"content":9433,"nodeType":876},{},[9434,9439],{"data":9435,"marks":9436,"value":9438,"nodeType":867},{},[9437],{"type":865},"49% of organizations",{"data":9440,"marks":9441,"value":9442,"nodeType":867},{},[]," suffered a successful browser-based attack in the last 12 months (Omdia 2026)",{"data":9444,"content":9445,"nodeType":876},{},[9446],{"data":9447,"marks":9448,"value":9449,"nodeType":867},{},[],"These aren't edge cases. This is now the primary attack playbook.",{"data":9451,"content":9452,"nodeType":942},{},[],{"data":9454,"content":9455,"nodeType":1058},{},[9456],{"data":9457,"marks":9458,"value":9460,"nodeType":867},{},[9459],{"type":865},"The economics of attack choice",{"data":9462,"content":9463,"nodeType":876},{},[9464],{"data":9465,"marks":9466,"value":9467,"nodeType":867},{},[],"Attackers are rational actors. They pick the cheapest, most reliable path to their objective. The economics of browser exploitation versus identity theft tell the whole story:",{"data":9469,"content":9470,"nodeType":1629},{},[9471,9486,9501,9516],{"data":9472,"content":9473,"nodeType":1586},{},[9474],{"data":9475,"content":9476,"nodeType":876},{},[9477,9481],{"data":9478,"marks":9479,"value":9480,"nodeType":867},{},[],"Chrome sandbox RCE exploit (bug bounty value): ",{"data":9482,"marks":9483,"value":9485,"nodeType":867},{},[9484],{"type":865},"$250,000",{"data":9487,"content":9488,"nodeType":1586},{},[9489],{"data":9490,"content":9491,"nodeType":876},{},[9492,9496],{"data":9493,"marks":9494,"value":9495,"nodeType":867},{},[],"IAB-provided IdP admin account: ",{"data":9497,"marks":9498,"value":9500,"nodeType":867},{},[9499],{"type":865},"~$3,000",{"data":9502,"content":9503,"nodeType":1586},{},[9504],{"data":9505,"content":9506,"nodeType":876},{},[9507,9511],{"data":9508,"marks":9509,"value":9510,"nodeType":867},{},[],"1-year phishing kit rental (PhaaS): ",{"data":9512,"marks":9513,"value":9515,"nodeType":867},{},[9514],{"type":865},"~$1,000",{"data":9517,"content":9518,"nodeType":1586},{},[9519],{"data":9520,"content":9521,"nodeType":876},{},[9522,9526],{"data":9523,"marks":9524,"value":9525,"nodeType":867},{},[],"Bulk stolen credential list: ",{"data":9527,"marks":9528,"value":9530,"nodeType":867},{},[9529],{"type":865},"~$15",{"data":9532,"content":9533,"nodeType":876},{},[9534,9538,9543],{"data":9535,"marks":9536,"value":9537,"nodeType":867},{},[],"Browser zero-days accounted for just ",{"data":9539,"marks":9540,"value":9542,"nodeType":867},{},[9541],{"type":865},"9% of all zero-days reported to Google in 2025",{"data":9544,"marks":9545,"value":9546,"nodeType":867},{},[]," — described by Google's own researchers as a \"historic low.\" Chrome's sandbox architecture, site isolation, and hardware-backed security features are the result of years of sustained hardening investment. When a browser vulnerability is discovered, Google typically deploys a patch within days.",{"data":9548,"content":9552,"nodeType":985},{"target":9549},{"sys":9550},{"id":9551,"type":982,"linkType":983},"5XWKHTT5J06yWcgZIOL95t",[],{"data":9554,"content":9555,"nodeType":876},{},[9556],{"data":9557,"marks":9558,"value":9559,"nodeType":867},{},[],"The bottom line: browser exploits are extraordinarily expensive to develop, increasingly difficult to execute reliably against a hardened modern browser, and patched rapidly when discovered. In sharp contrast, identity attacks are cheap to run, highly scalable, and have a low technical barrier to adoption — that’s why they’re responsible for the overwhelming majority of enterprise breaches. Attackers have voted with their resources.",{"data":9561,"content":9562,"nodeType":942},{},[],{"data":9564,"content":9565,"nodeType":868},{},[9566],{"data":9567,"marks":9568,"value":9570,"nodeType":867},{},[9569],{"type":865},"What you're actually buying with each vendor",{"data":9572,"content":9573,"nodeType":876},{},[9574],{"data":9575,"marks":9576,"value":9577,"nodeType":867},{},[],"Understanding the core architectural choice each vendor has made helps decode what their solution can and cannot protect you from.",{"data":9579,"content":9580,"nodeType":1058},{},[9581],{"data":9582,"marks":9583,"value":9585,"nodeType":867},{},[9584],{"type":865},"Seraphic (CrowdStrike)",{"data":9587,"content":9588,"nodeType":876},{},[9589],{"data":9590,"marks":9591,"value":9592,"nodeType":867},{},[],"Seraphic's architecture is built to inject into the browser's JavaScript runtime at the OS layer, scrambling browser internals to prevent exploits from executing. This is a technically sophisticated approach to a technically interesting problem that is, by every threat intelligence measure, not the problem causing enterprise breaches at scale.",{"data":9594,"content":9595,"nodeType":876},{},[9596],{"data":9597,"marks":9598,"value":9599,"nodeType":867},{},[],"Beyond the threat model mismatch, there are structural concerns with the approach itself. Injecting an agent into the browser's JS runtime is a technique with well-documented stability consequences. This is the same approach antivirus vendors have used for years, often at the cost of system stability. Seraphic now runs alongside the CrowdStrike Falcon sensor on managed devices, combining two heavyweight agents on the same machine. For any organization with CrowdStrike already deployed, the question isn't theoretical: how has that combination been validated in production environments?",{"data":9601,"content":9602,"nodeType":876},{},[9603,9607,9614,9618,9627],{"data":9604,"marks":9605,"value":9606,"nodeType":867},{},[],"There's also the managed-device limitation. Seraphic requires a kernel-level agent, which means it loses meaningful capability on unmanaged devices, BYOD machines, and contractor endpoints. This is not a niche concern: according to ",{"data":9608,"content":9609,"nodeType":915},{"uri":4107},[9610],{"data":9611,"marks":9612,"value":9613,"nodeType":867},{},[],"Omdia's 2026 browser security survey",{"data":9615,"marks":9616,"value":9617,"nodeType":867},{},[],", 32% of users access corporate applications from unmanaged devices at least occasionally. Agent-based solutions are blind to nearly a third of your actual attack surface by design. The Okta breach began on a support engineer's personal device, where ",{"data":9619,"content":9621,"nodeType":915},{"uri":9620},"https://pushsecurity.com/blog/browser-sync-attacks-where-personal-account-hacks-lead-to-corporate-breaches/",[9622],{"data":9623,"marks":9624,"value":9626,"nodeType":867},{},[9625],{"type":913},"corporate credentials had synced",{"data":9628,"marks":9629,"value":9630,"nodeType":867},{},[]," via Chrome's built-in profile sync. No agent, no visibility.",{"data":9632,"content":9633,"nodeType":876},{},[9634],{"data":9635,"marks":9636,"value":9637,"nodeType":867},{},[],"Teams evaluating Seraphic today are also buying into an integration roadmap, not a shipped capability. The acquisition by CrowdStrike closed in early 2026. The work of wiring browser telemetry into Falcon Fusion and correlating it with endpoint signals is currently a promise, not a production feature.",{"data":9639,"content":9640,"nodeType":1058},{},[9641],{"data":9642,"marks":9643,"value":9645,"nodeType":867},{},[9644],{"type":865},"SquareX (Zscaler)",{"data":9647,"content":9648,"nodeType":876},{},[9649],{"data":9650,"marks":9651,"value":9652,"nodeType":867},{},[],"SquareX's core capability is sandboxing suspicious file downloads inside disposable browser containers before they reach the endpoint. This is a legitimate approach to a real but declining problem. 82% of attack detections are now malware-free (CrowdStrike 2026 Global Threat Report) — attacks don't arrive as files to be sandboxed, they arrive as authenticated sessions. And the delivery channel shift makes the picture even starker: across Push's customer base, 1 in 3 phishing payloads are now delivered outside of email entirely — via social media, ads, and messaging platforms — and 4 in 5 ClickFix payloads arrive through search engines, not email. The threat that SquareX was architecturally designed to address is a shrinking share of the actual attack surface, and it's shrinking fast.",{"data":9654,"content":9655,"nodeType":876},{},[9656],{"data":9657,"marks":9658,"value":9659,"nodeType":867},{},[],"Zscaler already has sandboxing built into ZIA. For an existing Zscaler customer evaluating SquareX, the honest question is: what does this add beyond some extension analysis capability and what you already have? The AiTM phishing campaign that stole your user's credentials and accessed your cloud applications generates no malicious file, triggers no sandbox, and produces no network signal for Zscaler's traffic inspection to catch — because it happened entirely inside a browser session using legitimate authentication flows.",{"data":9661,"content":9662,"nodeType":876},{},[9663],{"data":9664,"marks":9665,"value":9666,"nodeType":867},{},[],"The acquisition also raises product focus questions. Being absorbed into a network-centric platform means SquareX is now optimized for Zscaler's priorities, not for standalone browser detection and response. Teams that care about investigation, threat hunting, and incident response should ask specifically what SquareX adds in those workflows under Zscaler ownership.",{"data":9668,"content":9669,"nodeType":1058},{},[9670],{"data":9671,"marks":9672,"value":9674,"nodeType":867},{},[9673],{"type":865},"LayerX",{"data":9676,"content":9677,"nodeType":876},{},[9678],{"data":9679,"marks":9680,"value":9681,"nodeType":867},{},[],"LayerX is primarily a policy enforcement and risk scoring platform focused on internal governance — controlling which applications employees access, what data moves through the browser, and whether behavior complies with internal rules.",{"data":9683,"content":9684,"nodeType":876},{},[9685],{"data":9686,"marks":9687,"value":9688,"nodeType":867},{},[],"Push Security covers that ground too. Push provides full visibility over AI tool usage, shadow SaaS, unmanaged identities, and data loss vectors — including sensitive data submitted through AI prompts, file uploads to personal cloud destinations, and OAuth grants to third-party applications. The same browser telemetry that detects external attacks also surfaces insider risks and powers DLP controls and compliance audit evidence, all from a single extension.",{"data":9690,"content":9691,"nodeType":876},{},[9692],{"data":9693,"marks":9694,"value":9695,"nodeType":867},{},[],"The critical difference is that Push goes significantly further. Where LayerX scores risk and enforces policy, Push detects active external attack techniques in real time: AiTM phishing kits as they execute, session tokens being stolen, ClickFix lures through behavioral analysis of page structure. These are the attacks causing the most damaging breaches today, and they don't surface on a risk score until after the damage is done. Push addresses both the governance problem and the external threat problem from the same platform. LayerX addresses only the first.",{"data":9697,"content":9698,"nodeType":942},{},[],{"data":9700,"content":9701,"nodeType":868},{},[9702],{"data":9703,"marks":9704,"value":9706,"nodeType":867},{},[9705],{"type":865},"Securing the organization via the browser: Push Security",{"data":9708,"content":9709,"nodeType":876},{},[9710,9715],{"data":9711,"marks":9712,"value":9714,"nodeType":867},{},[9713],{"type":865},"Push Security is built on a different architectural premise:",{"data":9716,"marks":9717,"value":9718,"nodeType":867},{},[]," the browser is not primarily a piece of software to harden against exploitation. It is the primary workplace, the primary SaaS access point, and the arena where the majority of modern identity attacks play out. The goal is to secure the organization via the browser — not just to secure the browser itself.",{"data":9720,"content":9721,"nodeType":876},{},[9722],{"data":9723,"marks":9724,"value":9725,"nodeType":867},{},[],"This means Push's detection surface is built around the attacks that are actually causing breaches: adversary-in-the-middle phishing, ClickFix and its many variants, credential stuffing against shadow identities, session token theft and replay, OAuth consent abuse, and the full spectrum of identity-based initial access techniques that dominate the modern threat landscape.",{"data":9727,"content":9728,"nodeType":876},{},[9729],{"data":9730,"marks":9731,"value":9732,"nodeType":867},{},[],"The deployment model reflects the threat model. Push deploys as a lightweight browser extension — no kernel-level agent, no device dependency, no migration to a new browser. It works on managed and unmanaged devices, across every traditional, enterprise and AI browser where employees are doing work and attackers are targeting them. The operational overhead is minimal by design: Push has been deployed to 100,000 users in under one hour during normal business hours.",{"data":9734,"content":9735,"nodeType":1058},{},[9736],{"data":9737,"marks":9738,"value":9740,"nodeType":867},{},[9739],{"type":865},"Detection philosophy: targeting what attackers can't change",{"data":9742,"content":9743,"nodeType":876},{},[9744],{"data":9745,"marks":9746,"value":9747,"nodeType":867},{},[],"Push's detection approach targets attacker TTPs rather than indicators of compromise that attackers can rotate in minutes. 95% of attacks detected by Push used some form of bot protection service — meaning the specific domain and IP were deliberately obscured. If your primary detection relies on blocklists, recent reports tell us that 89% of phishing domains will evade you: because they're active for less than two days, they can be spun up, down, and replaced faster than blocklists can keep up.",{"data":9749,"content":9750,"nodeType":876},{},[9751],{"data":9752,"marks":9753,"value":9754,"nodeType":867},{},[],"Behavioral detection of the attack technique — the AiTM relay structure, the credential entry on a cloned login page, the anomalous session context — remains valid regardless of what domain the attack is hosted on or which PhaaS kit was used to build it.",{"data":9756,"content":9757,"nodeType":1058},{},[9758],{"data":9759,"marks":9760,"value":9762,"nodeType":867},{},[9761],{"type":865},"Measuring the identity attack surface (it's bigger than you realize)",{"data":9764,"content":9765,"nodeType":876},{},[9766],{"data":9767,"marks":9768,"value":9769,"nodeType":867},{},[],"Because Push has visibility into actual login behavior across thousands of organizations, it can quantify the attack surface that identity-based attacks exploit. Of the last million logins observed by Push:",{"data":9771,"content":9772,"nodeType":1629},{},[9773,9788,9803,9818],{"data":9774,"content":9775,"nodeType":1586},{},[9776],{"data":9777,"content":9778,"nodeType":876},{},[9779,9784],{"data":9780,"marks":9781,"value":9783,"nodeType":867},{},[9782],{"type":865},"15 corporate identities were identified per employee",{"data":9785,"marks":9786,"value":9787,"nodeType":867},{},[]," used to access cloud apps",{"data":9789,"content":9790,"nodeType":1586},{},[9791],{"data":9792,"content":9793,"nodeType":876},{},[9794,9799],{"data":9795,"marks":9796,"value":9798,"nodeType":867},{},[9797],{"type":865},"1 in 4",{"data":9800,"marks":9801,"value":9802,"nodeType":867},{},[]," were password logins, not SSO",{"data":9804,"content":9805,"nodeType":1586},{},[9806],{"data":9807,"content":9808,"nodeType":876},{},[9809,9814],{"data":9810,"marks":9811,"value":9813,"nodeType":867},{},[9812],{"type":865},"2 in 5",{"data":9815,"marks":9816,"value":9817,"nodeType":867},{},[]," were not protected by MFA",{"data":9819,"content":9820,"nodeType":1586},{},[9821],{"data":9822,"content":9823,"nodeType":876},{},[9824,9829],{"data":9825,"marks":9826,"value":9828,"nodeType":867},{},[9827],{"type":865},"1 in 5",{"data":9830,"marks":9831,"value":9832,"nodeType":867},{},[]," used a weak, breached, or reused password",{"data":9834,"content":9835,"nodeType":876},{},[9836,9840,9845],{"data":9837,"marks":9838,"value":9839,"nodeType":867},{},[],"And it's not just login hygiene. Across Push's customer base, ",{"data":9841,"marks":9842,"value":9844,"nodeType":867},{},[9843],{"type":865},"46%+ of browser extensions in corporate environments have the permission combinations required for direct account takeover via session theft if they are malicious or compromised by an attacker",{"data":9846,"marks":9847,"value":9848,"nodeType":867},{},[],". Most organizations have no inventory of what's running in their employees' browsers, let alone visibility into what those extensions can access.",{"data":9850,"content":9851,"nodeType":876},{},[9852,9856,9863],{"data":9853,"marks":9854,"value":9855,"nodeType":867},{},[],"These aren't theoretical vulnerabilities. They're the specific weaknesses that browser-native identity attacks are designed to exploit. ",{"data":9857,"content":9858,"nodeType":915},{"uri":4435},[9859],{"data":9860,"marks":9861,"value":9862,"nodeType":867},{},[],"This visibility turns browser security from a reactive posture into a proactive one",{"data":9864,"marks":9865,"value":9866,"nodeType":867},{},[]," — you can see and remediate the identity weaknesses before an attacker exploits them, not just detect the attack while it's in progress.",{"data":9868,"content":9869,"nodeType":1058},{},[9870],{"data":9871,"marks":9872,"value":9874,"nodeType":867},{},[9873],{"type":865},"The ROI case",{"data":9876,"content":9877,"nodeType":876},{},[9878],{"data":9879,"marks":9880,"value":9881,"nodeType":867},{},[],"The ROI question for any security investment is: what quantum of real risk does this tool address, at what cost in money and operational friction?",{"data":9883,"content":9884,"nodeType":876},{},[9885],{"data":9886,"marks":9887,"value":9889,"nodeType":867},{},[9888],{"type":865},"That calculation looks very different depending on your threat model.",{"data":9891,"content":9892,"nodeType":876},{},[9893],{"data":9894,"marks":9895,"value":9896,"nodeType":867},{},[],"A solution focused on browser engine exploits and sandbox escapes is defending against an attack category that represents a tiny fraction of actual enterprise breaches, requires extraordinary attacker resources to execute, and is increasingly mitigated by browser vendors themselves through hardening and rapid patching. Chrome's automatic update cycle means that even when a browser vulnerability is discovered and disclosed, it is typically in front of users as a patch within days. The defenders here are Google, Mozilla, and Microsoft — with multi-billion dollar security teams and full access to the browser internals.",{"data":9898,"content":9899,"nodeType":876},{},[9900],{"data":9901,"marks":9902,"value":9903,"nodeType":867},{},[],"A solution focused on identity attacks via the browser — phishing, credential theft, session hijacking, OAuth abuse, malicious browser extensions — is defending against the primary cause of enterprise breaches, one that is accelerating (cloud-conscious intrusions up 37% in 2025, browser-based attacks increasing at 68% of organizations over the past two years per Omdia) and increasingly automated through PhaaS infrastructure that gives low-skill attackers enterprise-grade capability for $1,000 a year.",{"data":9905,"content":9906,"nodeType":876},{},[9907],{"data":9908,"marks":9909,"value":9910,"nodeType":867},{},[],"There's also a forward-looking dimension. The threat landscape isn't moving toward more browser exploitation. It's moving further into identity abuse. AI-powered phishing lowers the social engineering barrier. Agentic browsers will automate credential stuffing and account takeover at a scale that wasn't previously possible. And attackers are already adapting to authentication improvements: device code phishing has increased 37x since the start of 2026, a technique specifically designed to circumvent passkeys by bypassing the authentication flow entirely — the attacker never encounters a login page. The investment in identity-centric browser detection compounds over time as the attack surface evolves in the same direction.",{"data":9912,"content":9916,"nodeType":985},{"target":9913},{"sys":9914},{"id":9915,"type":982,"linkType":983},"cQ6WPV2NMYvDMZXifqzK1",[],{"data":9918,"content":9919,"nodeType":1058},{},[9920],{"data":9921,"marks":9922,"value":9924,"nodeType":867},{},[9923],{"type":865},"The verdict",{"data":9926,"content":9927,"nodeType":876},{},[9928],{"data":9929,"marks":9930,"value":9931,"nodeType":867},{},[],"Browser security is a real and growing priority — according to Omdia Research, it is now a top-five priority for 88% of security leaders and the top priority for 26% of them. 85% expect their browser security spending to increase over the next 12–24 months. The question isn't whether to invest. It's what to invest in.",{"data":9933,"content":9934,"nodeType":876},{},[9935],{"data":9936,"marks":9937,"value":9938,"nodeType":867},{},[],"The browser is where your users work, where attackers target them, and where the identity attacks causing the majority of enterprise breaches play out. But not all browser security investments address the same problem.",{"data":9940,"content":9943,"nodeType":985},{"target":9941},{"sys":9942},{"id":5755,"type":982,"linkType":983},[],{"data":9945,"content":9946,"nodeType":876},{},[9947],{"data":9948,"marks":9949,"value":9950,"nodeType":867},{},[],"Solutions like Seraphic are built to defend against a browser being exploited by an attacker trying to break out of the sandbox — an attack that represents a historic low as a share of enterprise incidents, and one that Google's own hardening and rapid patching increasingly mitigates automatically. SquareX is built around malware sandboxing — a legitimate but declining share of the initial access landscape, and a capability Zscaler's existing customers already partially have. LayerX focuses on internal governance rather than external threats.",{"data":9952,"content":9953,"nodeType":876},{},[9954],{"data":9955,"marks":9956,"value":9957,"nodeType":867},{},[],"Push Security is built to defend against the attacks that are behind the major breaches hitting the headlines: identity theft, credential abuse, session hijacking, and the full identity attack kill chain that plays out inside the browser every time an attacker logs in as your user. Every major threat intelligence report points to these as the primary breach vectors. The economics of attack choice guarantee they'll remain so.",{"data":9959,"content":9960,"nodeType":876},{},[9961],{"data":9962,"marks":9963,"value":9964,"nodeType":867},{},[],"The security team that deploys Push gets the greatest coverage of the highest-impact threats, on managed and unmanaged devices, with the lightest operational footprint. That is the browser security investment that moves the needle on real organizational risk — not the browser security investment that defends the software nobody's actually attacking.",{"data":9966,"content":9970,"nodeType":985},{"target":9967},{"sys":9968},{"id":9969,"type":982,"linkType":983},"3a2sEWgWKZulGLCFfODwk0",[],{"data":9972,"content":9973,"nodeType":876},{},[9974],{"data":9975,"marks":9976,"value":21,"nodeType":867},{},[],"How to avoid the browser security buyer's trap","Securing the browser vs. securing the organization via the browser — what's the difference?","2026-05-13T00:00:00.000Z","how-to-avoid-the-browser-security-buyers-trap",{"items":9982},[9983,9985],{"sys":9984,"name":297},{"id":2706},{"sys":9986,"name":2710},{"id":2709},{"items":9988},[9989],{"fullName":4089,"firstName":4090,"jobTitle":851,"profilePicture":9990},{"url":4094},{"__typename":1772,"sys":9992,"content":9993,"title":7923,"synopsis":7924,"hashTags":59,"publishedDate":7925,"slug":7926,"tagsCollection":11062,"authorsCollection":11068},{"id":6692},{"json":9994},{"data":9995,"content":9996,"nodeType":1680},{},[9997,10010,10015,10021,10027,10032,10035,10042,10049,10064,10102,10107,10120,10123,10130,10137,10159,10191,10197,10200,10207,10214,10220,10225,10231,10234,10241,10248,10282,10312,10318,10321,10328,10335,10355,10361,10400,10406,10409,10416,10423,10459,10465,10470,10473,10480,10487,10513,10519,10524,10530,10533,10540,10547,10570,10576,10582,10588,10591,10598,10605,10611,10616,10622,10643,10666,10669,10676,10683,10689,10695,10698,10705,10760,10763,10770,10776,11044,11047],{"data":9998,"content":9999,"nodeType":876},{},[10000,10003,10007],{"data":10001,"marks":10002,"value":6703,"nodeType":867},{},[],{"data":10004,"marks":10005,"value":6708,"nodeType":867},{},[10006],{"type":865},{"data":10008,"marks":10009,"value":6712,"nodeType":867},{},[],{"data":10011,"content":10014,"nodeType":985},{"target":10012},{"sys":10013},{"id":6717,"type":982,"linkType":983},[],{"data":10016,"content":10017,"nodeType":876},{},[10018],{"data":10019,"marks":10020,"value":6725,"nodeType":867},{},[],{"data":10022,"content":10023,"nodeType":876},{},[10024],{"data":10025,"marks":10026,"value":6732,"nodeType":867},{},[],{"data":10028,"content":10031,"nodeType":985},{"target":10029},{"sys":10030},{"id":6737,"type":982,"linkType":983},[],{"data":10033,"content":10034,"nodeType":942},{},[],{"data":10036,"content":10037,"nodeType":868},{},[10038],{"data":10039,"marks":10040,"value":6749,"nodeType":867},{},[10041],{"type":865},{"data":10043,"content":10044,"nodeType":876},{},[10045],{"data":10046,"marks":10047,"value":6757,"nodeType":867},{},[10048],{"type":865},{"data":10050,"content":10051,"nodeType":876},{},[10052,10055,10061],{"data":10053,"marks":10054,"value":6764,"nodeType":867},{},[],{"data":10056,"content":10057,"nodeType":915},{"uri":6767},[10058],{"data":10059,"marks":10060,"value":6772,"nodeType":867},{},[],{"data":10062,"marks":10063,"value":6776,"nodeType":867},{},[],{"data":10065,"content":10066,"nodeType":876},{},[10067,10070,10076,10079,10083,10086,10090,10093,10099],{"data":10068,"marks":10069,"value":6783,"nodeType":867},{},[],{"data":10071,"content":10072,"nodeType":915},{"uri":6786},[10073],{"data":10074,"marks":10075,"value":6791,"nodeType":867},{},[],{"data":10077,"marks":10078,"value":5136,"nodeType":867},{},[],{"data":10080,"marks":10081,"value":6799,"nodeType":867},{},[10082],{"type":865},{"data":10084,"marks":10085,"value":5147,"nodeType":867},{},[],{"data":10087,"marks":10088,"value":6807,"nodeType":867},{},[10089],{"type":865},{"data":10091,"marks":10092,"value":6811,"nodeType":867},{},[],{"data":10094,"content":10095,"nodeType":915},{"uri":6814},[10096],{"data":10097,"marks":10098,"value":6819,"nodeType":867},{},[],{"data":10100,"marks":10101,"value":6823,"nodeType":867},{},[],{"data":10103,"content":10106,"nodeType":985},{"target":10104},{"sys":10105},{"id":6828,"type":982,"linkType":983},[],{"data":10108,"content":10109,"nodeType":876},{},[10110,10113,10117],{"data":10111,"marks":10112,"value":6836,"nodeType":867},{},[],{"data":10114,"marks":10115,"value":6841,"nodeType":867},{},[10116],{"type":865},{"data":10118,"marks":10119,"value":1679,"nodeType":867},{},[],{"data":10121,"content":10122,"nodeType":942},{},[],{"data":10124,"content":10125,"nodeType":868},{},[10126],{"data":10127,"marks":10128,"value":6855,"nodeType":867},{},[10129],{"type":865},{"data":10131,"content":10132,"nodeType":876},{},[10133],{"data":10134,"marks":10135,"value":6757,"nodeType":867},{},[10136],{"type":865},{"data":10138,"content":10139,"nodeType":876},{},[10140,10143,10149,10152,10156],{"data":10141,"marks":10142,"value":6869,"nodeType":867},{},[],{"data":10144,"content":10145,"nodeType":915},{"uri":6872},[10146],{"data":10147,"marks":10148,"value":6877,"nodeType":867},{},[],{"data":10150,"marks":10151,"value":6881,"nodeType":867},{},[],{"data":10153,"marks":10154,"value":6886,"nodeType":867},{},[10155],{"type":865},{"data":10157,"marks":10158,"value":6890,"nodeType":867},{},[],{"data":10160,"content":10161,"nodeType":876},{},[10162,10165,10171,10174,10178,10181,10188],{"data":10163,"marks":10164,"value":6897,"nodeType":867},{},[],{"data":10166,"content":10167,"nodeType":915},{"uri":6900},[10168],{"data":10169,"marks":10170,"value":6905,"nodeType":867},{},[],{"data":10172,"marks":10173,"value":6909,"nodeType":867},{},[],{"data":10175,"marks":10176,"value":6914,"nodeType":867},{},[10177],{"type":865},{"data":10179,"marks":10180,"value":6918,"nodeType":867},{},[],{"data":10182,"content":10183,"nodeType":915},{"uri":1228},[10184],{"data":10185,"marks":10186,"value":6926,"nodeType":867},{},[10187],{"type":865},{"data":10189,"marks":10190,"value":6930,"nodeType":867},{},[],{"data":10192,"content":10193,"nodeType":876},{},[10194],{"data":10195,"marks":10196,"value":6937,"nodeType":867},{},[],{"data":10198,"content":10199,"nodeType":942},{},[],{"data":10201,"content":10202,"nodeType":868},{},[10203],{"data":10204,"marks":10205,"value":6948,"nodeType":867},{},[10206],{"type":865},{"data":10208,"content":10209,"nodeType":876},{},[10210],{"data":10211,"marks":10212,"value":6956,"nodeType":867},{},[10213],{"type":865},{"data":10215,"content":10216,"nodeType":876},{},[10217],{"data":10218,"marks":10219,"value":6963,"nodeType":867},{},[],{"data":10221,"content":10224,"nodeType":985},{"target":10222},{"sys":10223},{"id":6968,"type":982,"linkType":983},[],{"data":10226,"content":10227,"nodeType":876},{},[10228],{"data":10229,"marks":10230,"value":6976,"nodeType":867},{},[],{"data":10232,"content":10233,"nodeType":942},{},[],{"data":10235,"content":10236,"nodeType":868},{},[10237],{"data":10238,"marks":10239,"value":6987,"nodeType":867},{},[10240],{"type":865},{"data":10242,"content":10243,"nodeType":876},{},[10244],{"data":10245,"marks":10246,"value":6956,"nodeType":867},{},[10247],{"type":865},{"data":10249,"content":10250,"nodeType":876},{},[10251,10254,10261,10264,10270,10273,10279],{"data":10252,"marks":10253,"value":7001,"nodeType":867},{},[],{"data":10255,"content":10256,"nodeType":915},{"uri":7004},[10257],{"data":10258,"marks":10259,"value":7010,"nodeType":867},{},[10260],{"type":913},{"data":10262,"marks":10263,"value":5136,"nodeType":867},{},[],{"data":10265,"content":10266,"nodeType":915},{"uri":7016},[10267],{"data":10268,"marks":10269,"value":7021,"nodeType":867},{},[],{"data":10271,"marks":10272,"value":5136,"nodeType":867},{},[],{"data":10274,"content":10275,"nodeType":915},{"uri":7027},[10276],{"data":10277,"marks":10278,"value":7032,"nodeType":867},{},[],{"data":10280,"marks":10281,"value":7036,"nodeType":867},{},[],{"data":10283,"content":10284,"nodeType":876},{},[10285,10288,10295,10298,10302,10305,10309],{"data":10286,"marks":10287,"value":21,"nodeType":867},{},[],{"data":10289,"content":10290,"nodeType":915},{"uri":1576},[10291],{"data":10292,"marks":10293,"value":7050,"nodeType":867},{},[10294],{"type":913},{"data":10296,"marks":10297,"value":7054,"nodeType":867},{},[],{"data":10299,"marks":10300,"value":7059,"nodeType":867},{},[10301],{"type":865},{"data":10303,"marks":10304,"value":7063,"nodeType":867},{},[],{"data":10306,"marks":10307,"value":7068,"nodeType":867},{},[10308],{"type":1303},{"data":10310,"marks":10311,"value":7072,"nodeType":867},{},[],{"data":10313,"content":10314,"nodeType":876},{},[10315],{"data":10316,"marks":10317,"value":7079,"nodeType":867},{},[],{"data":10319,"content":10320,"nodeType":942},{},[],{"data":10322,"content":10323,"nodeType":868},{},[10324],{"data":10325,"marks":10326,"value":7090,"nodeType":867},{},[10327],{"type":865},{"data":10329,"content":10330,"nodeType":876},{},[10331],{"data":10332,"marks":10333,"value":6956,"nodeType":867},{},[10334],{"type":865},{"data":10336,"content":10337,"nodeType":876},{},[10338,10341,10345,10348,10352],{"data":10339,"marks":10340,"value":7104,"nodeType":867},{},[],{"data":10342,"marks":10343,"value":7109,"nodeType":867},{},[10344],{"type":1303},{"data":10346,"marks":10347,"value":7113,"nodeType":867},{},[],{"data":10349,"marks":10350,"value":7118,"nodeType":867},{},[10351],{"type":1303},{"data":10353,"marks":10354,"value":7122,"nodeType":867},{},[],{"data":10356,"content":10357,"nodeType":876},{},[10358],{"data":10359,"marks":10360,"value":7129,"nodeType":867},{},[],{"data":10362,"content":10363,"nodeType":1629},{},[10364,10382],{"data":10365,"content":10366,"nodeType":1586},{},[10367],{"data":10368,"content":10369,"nodeType":876},{},[10370,10373,10379],{"data":10371,"marks":10372,"value":964,"nodeType":867},{},[],{"data":10374,"content":10375,"nodeType":915},{"uri":1165},[10376],{"data":10377,"marks":10378,"value":1170,"nodeType":867},{},[],{"data":10380,"marks":10381,"value":7151,"nodeType":867},{},[],{"data":10383,"content":10384,"nodeType":1586},{},[10385],{"data":10386,"content":10387,"nodeType":876},{},[10388,10391,10397],{"data":10389,"marks":10390,"value":964,"nodeType":867},{},[],{"data":10392,"content":10393,"nodeType":915},{"uri":2225},[10394],{"data":10395,"marks":10396,"value":7167,"nodeType":867},{},[],{"data":10398,"marks":10399,"value":7171,"nodeType":867},{},[],{"data":10401,"content":10402,"nodeType":876},{},[10403],{"data":10404,"marks":10405,"value":7178,"nodeType":867},{},[],{"data":10407,"content":10408,"nodeType":942},{},[],{"data":10410,"content":10411,"nodeType":868},{},[10412],{"data":10413,"marks":10414,"value":7189,"nodeType":867},{},[10415],{"type":865},{"data":10417,"content":10418,"nodeType":876},{},[10419],{"data":10420,"marks":10421,"value":7197,"nodeType":867},{},[10422],{"type":865},{"data":10424,"content":10425,"nodeType":876},{},[10426,10429,10433,10436,10442,10445,10449,10452,10456],{"data":10427,"marks":10428,"value":7204,"nodeType":867},{},[],{"data":10430,"marks":10431,"value":7209,"nodeType":867},{},[10432],{"type":865},{"data":10434,"marks":10435,"value":7213,"nodeType":867},{},[],{"data":10437,"content":10438,"nodeType":915},{"uri":928},[10439],{"data":10440,"marks":10441,"value":7220,"nodeType":867},{},[],{"data":10443,"marks":10444,"value":7224,"nodeType":867},{},[],{"data":10446,"marks":10447,"value":7229,"nodeType":867},{},[10448],{"type":865},{"data":10450,"marks":10451,"value":7233,"nodeType":867},{},[],{"data":10453,"marks":10454,"value":7238,"nodeType":867},{},[10455],{"type":865},{"data":10457,"marks":10458,"value":7242,"nodeType":867},{},[],{"data":10460,"content":10461,"nodeType":876},{},[10462],{"data":10463,"marks":10464,"value":7249,"nodeType":867},{},[],{"data":10466,"content":10469,"nodeType":985},{"target":10467},{"sys":10468},{"id":7254,"type":982,"linkType":983},[],{"data":10471,"content":10472,"nodeType":942},{},[],{"data":10474,"content":10475,"nodeType":868},{},[10476],{"data":10477,"marks":10478,"value":7266,"nodeType":867},{},[10479],{"type":865},{"data":10481,"content":10482,"nodeType":876},{},[10483],{"data":10484,"marks":10485,"value":7274,"nodeType":867},{},[10486],{"type":865},{"data":10488,"content":10489,"nodeType":876},{},[10490,10493,10500,10503,10510],{"data":10491,"marks":10492,"value":7281,"nodeType":867},{},[],{"data":10494,"content":10495,"nodeType":915},{"uri":4107},[10496],{"data":10497,"marks":10498,"value":7289,"nodeType":867},{},[10499],{"type":865},{"data":10501,"marks":10502,"value":7293,"nodeType":867},{},[],{"data":10504,"content":10505,"nodeType":915},{"uri":7296},[10506],{"data":10507,"marks":10508,"value":7302,"nodeType":867},{},[10509],{"type":865},{"data":10511,"marks":10512,"value":7306,"nodeType":867},{},[],{"data":10514,"content":10515,"nodeType":876},{},[10516],{"data":10517,"marks":10518,"value":7313,"nodeType":867},{},[],{"data":10520,"content":10523,"nodeType":985},{"target":10521},{"sys":10522},{"id":7318,"type":982,"linkType":983},[],{"data":10525,"content":10526,"nodeType":876},{},[10527],{"data":10528,"marks":10529,"value":7326,"nodeType":867},{},[],{"data":10531,"content":10532,"nodeType":942},{},[],{"data":10534,"content":10535,"nodeType":868},{},[10536],{"data":10537,"marks":10538,"value":7337,"nodeType":867},{},[10539],{"type":865},{"data":10541,"content":10542,"nodeType":876},{},[10543],{"data":10544,"marks":10545,"value":7345,"nodeType":867},{},[10546],{"type":865},{"data":10548,"content":10549,"nodeType":876},{},[10550,10553,10557,10560,10567],{"data":10551,"marks":10552,"value":7352,"nodeType":867},{},[],{"data":10554,"marks":10555,"value":7357,"nodeType":867},{},[10556],{"type":1303},{"data":10558,"marks":10559,"value":7361,"nodeType":867},{},[],{"data":10561,"content":10562,"nodeType":915},{"uri":7364},[10563],{"data":10564,"marks":10565,"value":7370,"nodeType":867},{},[10566],{"type":865},{"data":10568,"marks":10569,"value":7374,"nodeType":867},{},[],{"data":10571,"content":10572,"nodeType":876},{},[10573],{"data":10574,"marks":10575,"value":7381,"nodeType":867},{},[],{"data":10577,"content":10578,"nodeType":876},{},[10579],{"data":10580,"marks":10581,"value":7388,"nodeType":867},{},[],{"data":10583,"content":10584,"nodeType":876},{},[10585],{"data":10586,"marks":10587,"value":7395,"nodeType":867},{},[],{"data":10589,"content":10590,"nodeType":942},{},[],{"data":10592,"content":10593,"nodeType":868},{},[10594],{"data":10595,"marks":10596,"value":7406,"nodeType":867},{},[10597],{"type":865},{"data":10599,"content":10600,"nodeType":876},{},[10601],{"data":10602,"marks":10603,"value":7414,"nodeType":867},{},[10604],{"type":865},{"data":10606,"content":10607,"nodeType":876},{},[10608],{"data":10609,"marks":10610,"value":7421,"nodeType":867},{},[],{"data":10612,"content":10615,"nodeType":985},{"target":10613},{"sys":10614},{"id":7426,"type":982,"linkType":983},[],{"data":10617,"content":10618,"nodeType":876},{},[10619],{"data":10620,"marks":10621,"value":7434,"nodeType":867},{},[],{"data":10623,"content":10624,"nodeType":1629},{},[10625,10634],{"data":10626,"content":10627,"nodeType":1586},{},[10628],{"data":10629,"content":10630,"nodeType":876},{},[10631],{"data":10632,"marks":10633,"value":7447,"nodeType":867},{},[],{"data":10635,"content":10636,"nodeType":1586},{},[10637],{"data":10638,"content":10639,"nodeType":876},{},[10640],{"data":10641,"marks":10642,"value":7457,"nodeType":867},{},[],{"data":10644,"content":10645,"nodeType":876},{},[10646,10649,10656,10659,10663],{"data":10647,"marks":10648,"value":7464,"nodeType":867},{},[],{"data":10650,"content":10651,"nodeType":915},{"uri":7467},[10652],{"data":10653,"marks":10654,"value":7473,"nodeType":867},{},[10655],{"type":865},{"data":10657,"marks":10658,"value":7477,"nodeType":867},{},[],{"data":10660,"marks":10661,"value":7482,"nodeType":867},{},[10662],{"type":1303},{"data":10664,"marks":10665,"value":7486,"nodeType":867},{},[],{"data":10667,"content":10668,"nodeType":942},{},[],{"data":10670,"content":10671,"nodeType":868},{},[10672],{"data":10673,"marks":10674,"value":7497,"nodeType":867},{},[10675],{"type":865},{"data":10677,"content":10678,"nodeType":876},{},[10679],{"data":10680,"marks":10681,"value":7505,"nodeType":867},{},[10682],{"type":865},{"data":10684,"content":10685,"nodeType":876},{},[10686],{"data":10687,"marks":10688,"value":7512,"nodeType":867},{},[],{"data":10690,"content":10691,"nodeType":876},{},[10692],{"data":10693,"marks":10694,"value":7519,"nodeType":867},{},[],{"data":10696,"content":10697,"nodeType":942},{},[],{"data":10699,"content":10700,"nodeType":868},{},[10701],{"data":10702,"marks":10703,"value":7530,"nodeType":867},{},[10704],{"type":865},{"data":10706,"content":10707,"nodeType":1629},{},[10708,10721,10734,10747],{"data":10709,"content":10710,"nodeType":1586},{},[10711],{"data":10712,"content":10713,"nodeType":876},{},[10714,10718],{"data":10715,"marks":10716,"value":7544,"nodeType":867},{},[10717],{"type":865},{"data":10719,"marks":10720,"value":7548,"nodeType":867},{},[],{"data":10722,"content":10723,"nodeType":1586},{},[10724],{"data":10725,"content":10726,"nodeType":876},{},[10727,10731],{"data":10728,"marks":10729,"value":7559,"nodeType":867},{},[10730],{"type":865},{"data":10732,"marks":10733,"value":7563,"nodeType":867},{},[],{"data":10735,"content":10736,"nodeType":1586},{},[10737],{"data":10738,"content":10739,"nodeType":876},{},[10740,10744],{"data":10741,"marks":10742,"value":7574,"nodeType":867},{},[10743],{"type":865},{"data":10745,"marks":10746,"value":7578,"nodeType":867},{},[],{"data":10748,"content":10749,"nodeType":1586},{},[10750],{"data":10751,"content":10752,"nodeType":876},{},[10753,10757],{"data":10754,"marks":10755,"value":781,"nodeType":867},{},[10756],{"type":865},{"data":10758,"marks":10759,"value":7592,"nodeType":867},{},[],{"data":10761,"content":10762,"nodeType":942},{},[],{"data":10764,"content":10765,"nodeType":868},{},[10766],{"data":10767,"marks":10768,"value":7603,"nodeType":867},{},[10769],{"type":865},{"data":10771,"content":10772,"nodeType":876},{},[10773],{"data":10774,"marks":10775,"value":7610,"nodeType":867},{},[],{"data":10777,"content":10778,"nodeType":7904},{},[10779,10802,10824,10846,10868,10890,10912,10934,10956,10978,11000,11022],{"data":10780,"content":10781,"nodeType":7640},{},[10782,10792],{"data":10783,"content":10784,"nodeType":7628},{},[10785],{"data":10786,"content":10787,"nodeType":876},{},[10788],{"data":10789,"marks":10790,"value":7627,"nodeType":867},{},[10791],{"type":865},{"data":10793,"content":10794,"nodeType":7628},{},[10795],{"data":10796,"content":10797,"nodeType":876},{},[10798],{"data":10799,"marks":10800,"value":7639,"nodeType":867},{},[10801],{"type":865},{"data":10803,"content":10804,"nodeType":7640},{},[10805,10815],{"data":10806,"content":10807,"nodeType":7628},{},[10808],{"data":10809,"content":10810,"nodeType":876},{},[10811],{"data":10812,"marks":10813,"value":7654,"nodeType":867},{},[10814],{"type":865},{"data":10816,"content":10817,"nodeType":7628},{},[10818],{"data":10819,"content":10820,"nodeType":876},{},[10821],{"data":10822,"marks":10823,"value":7664,"nodeType":867},{},[],{"data":10825,"content":10826,"nodeType":7640},{},[10827,10837],{"data":10828,"content":10829,"nodeType":7628},{},[10830],{"data":10831,"content":10832,"nodeType":876},{},[10833],{"data":10834,"marks":10835,"value":7678,"nodeType":867},{},[10836],{"type":865},{"data":10838,"content":10839,"nodeType":7628},{},[10840],{"data":10841,"content":10842,"nodeType":876},{},[10843],{"data":10844,"marks":10845,"value":7688,"nodeType":867},{},[],{"data":10847,"content":10848,"nodeType":7640},{},[10849,10859],{"data":10850,"content":10851,"nodeType":7628},{},[10852],{"data":10853,"content":10854,"nodeType":876},{},[10855],{"data":10856,"marks":10857,"value":7702,"nodeType":867},{},[10858],{"type":865},{"data":10860,"content":10861,"nodeType":7628},{},[10862],{"data":10863,"content":10864,"nodeType":876},{},[10865],{"data":10866,"marks":10867,"value":7712,"nodeType":867},{},[],{"data":10869,"content":10870,"nodeType":7640},{},[10871,10881],{"data":10872,"content":10873,"nodeType":7628},{},[10874],{"data":10875,"content":10876,"nodeType":876},{},[10877],{"data":10878,"marks":10879,"value":7726,"nodeType":867},{},[10880],{"type":865},{"data":10882,"content":10883,"nodeType":7628},{},[10884],{"data":10885,"content":10886,"nodeType":876},{},[10887],{"data":10888,"marks":10889,"value":7736,"nodeType":867},{},[],{"data":10891,"content":10892,"nodeType":7640},{},[10893,10903],{"data":10894,"content":10895,"nodeType":7628},{},[10896],{"data":10897,"content":10898,"nodeType":876},{},[10899],{"data":10900,"marks":10901,"value":7750,"nodeType":867},{},[10902],{"type":865},{"data":10904,"content":10905,"nodeType":7628},{},[10906],{"data":10907,"content":10908,"nodeType":876},{},[10909],{"data":10910,"marks":10911,"value":7760,"nodeType":867},{},[],{"data":10913,"content":10914,"nodeType":7640},{},[10915,10925],{"data":10916,"content":10917,"nodeType":7628},{},[10918],{"data":10919,"content":10920,"nodeType":876},{},[10921],{"data":10922,"marks":10923,"value":7774,"nodeType":867},{},[10924],{"type":865},{"data":10926,"content":10927,"nodeType":7628},{},[10928],{"data":10929,"content":10930,"nodeType":876},{},[10931],{"data":10932,"marks":10933,"value":7784,"nodeType":867},{},[],{"data":10935,"content":10936,"nodeType":7640},{},[10937,10947],{"data":10938,"content":10939,"nodeType":7628},{},[10940],{"data":10941,"content":10942,"nodeType":876},{},[10943],{"data":10944,"marks":10945,"value":7798,"nodeType":867},{},[10946],{"type":865},{"data":10948,"content":10949,"nodeType":7628},{},[10950],{"data":10951,"content":10952,"nodeType":876},{},[10953],{"data":10954,"marks":10955,"value":7808,"nodeType":867},{},[],{"data":10957,"content":10958,"nodeType":7640},{},[10959,10969],{"data":10960,"content":10961,"nodeType":7628},{},[10962],{"data":10963,"content":10964,"nodeType":876},{},[10965],{"data":10966,"marks":10967,"value":7822,"nodeType":867},{},[10968],{"type":865},{"data":10970,"content":10971,"nodeType":7628},{},[10972],{"data":10973,"content":10974,"nodeType":876},{},[10975],{"data":10976,"marks":10977,"value":7832,"nodeType":867},{},[],{"data":10979,"content":10980,"nodeType":7640},{},[10981,10991],{"data":10982,"content":10983,"nodeType":7628},{},[10984],{"data":10985,"content":10986,"nodeType":876},{},[10987],{"data":10988,"marks":10989,"value":7846,"nodeType":867},{},[10990],{"type":865},{"data":10992,"content":10993,"nodeType":7628},{},[10994],{"data":10995,"content":10996,"nodeType":876},{},[10997],{"data":10998,"marks":10999,"value":7856,"nodeType":867},{},[],{"data":11001,"content":11002,"nodeType":7640},{},[11003,11013],{"data":11004,"content":11005,"nodeType":7628},{},[11006],{"data":11007,"content":11008,"nodeType":876},{},[11009],{"data":11010,"marks":11011,"value":7870,"nodeType":867},{},[11012],{"type":865},{"data":11014,"content":11015,"nodeType":7628},{},[11016],{"data":11017,"content":11018,"nodeType":876},{},[11019],{"data":11020,"marks":11021,"value":7880,"nodeType":867},{},[],{"data":11023,"content":11024,"nodeType":7640},{},[11025,11035],{"data":11026,"content":11027,"nodeType":7628},{},[11028],{"data":11029,"content":11030,"nodeType":876},{},[11031],{"data":11032,"marks":11033,"value":7559,"nodeType":867},{},[11034],{"type":865},{"data":11036,"content":11037,"nodeType":7628},{},[11038],{"data":11039,"content":11040,"nodeType":876},{},[11041],{"data":11042,"marks":11043,"value":7903,"nodeType":867},{},[],{"data":11045,"content":11046,"nodeType":942},{},[],{"data":11048,"content":11049,"nodeType":876},{},[11050,11053,11059],{"data":11051,"marks":11052,"value":1667,"nodeType":867},{},[],{"data":11054,"content":11055,"nodeType":915},{"uri":2689},[11056],{"data":11057,"marks":11058,"value":6672,"nodeType":867},{},[],{"data":11060,"marks":11061,"value":21,"nodeType":867},{},[],{"items":11063},[11064,11066],{"sys":11065,"name":297},{"id":2706},{"sys":11067,"name":2710},{"id":2709},{"items":11069},[11070],{"fullName":4089,"firstName":4090,"jobTitle":851,"profilePicture":11071},{"url":4094},"blog/enterprise-browser-vs-browser-extension-which-should-your-security-team-choose",{"json":11074},{"data":11075,"content":11076,"nodeType":1680},{},[11077],{"data":11078,"content":11079,"nodeType":876},{},[11080],{"data":11081,"marks":11082,"value":11083,"nodeType":867},{},[],"If you're building a shortlist of browser security vendors, one of the first decisions you hit is an architectural one: full-stack enterprise browser, or browser security extension? ",{"id":5445,"publishedAt":11085},"2026-08-12T11:52:48.566Z",{"items":11087},[11088,11090],{"sys":11089,"name":297},{"id":2706},{"sys":11091,"name":2710},{"id":2709},{"items":11093},[11094,11096,11098,11100,11102,11104,11106,11108,11110,11112,11114,11116],{"sys":11095,"name":297,"slug":298,"tier":31},{"id":294},{"sys":11097,"name":279,"slug":280,"tier":31},{"id":276},{"sys":11099,"name":413,"slug":414,"tier":31},{"id":410},{"sys":11101,"name":386,"slug":387,"tier":45},{"id":383},{"sys":11103,"name":377,"slug":378,"tier":45},{"id":374},{"sys":11105,"name":261,"slug":262,"tier":45},{"id":258},{"sys":11107,"name":315,"slug":316,"tier":45},{"id":312},{"sys":11109,"name":484,"slug":485,"tier":45},{"id":481},{"sys":11111,"name":288,"slug":289,"tier":45},{"id":285},{"sys":11113,"name":624,"slug":625,"tier":45},{"id":621},{"sys":11115,"name":306,"slug":307,"tier":45},{"id":303},{"sys":11117,"name":589,"slug":590,"tier":45},{"id":586},"UhLNLgojmxTmt5rogpt-WncHPs8GJpCJ3gCXZJLR1EE",{"id":11120,"title":11121,"authorsCollection":11122,"content":11130,"extension":228,"faqItemsCollection":11721,"faqTitle":59,"featured":6,"hashTags":59,"meta":11723,"metaTitle":11724,"ogImage":59,"postType":1767,"publishedDate":9197,"relatedBlogPostsCollection":11725,"slug":16564,"stem":16565,"subtitle":59,"summary":16566,"synopsis":16577,"sys":16578,"tagsCollection":16581,"topicsCollection":16587,"__hash__":16633},"blog/blog/7-things-we-learned-from-john-hammond.json","7 things we learned from ‘Why the browser is the new battleground’ with John Hammond",{"items":11123},[11124],{"fullName":11125,"firstName":11126,"jobTitle":11127,"socialLinks":59,"profilePicture":11128},"Daniel Park","Daniel","Technical Content",{"url":11129},"https://images.ctfassets.net/y1cdw1ablpvd/6Cwg1xVeCdzUvxBIMfnDO5/6b18ed126b53611e7b521da34f900d29/254-0-2.jpg",{"json":11131,"links":11712},{"data":11132,"content":11133,"nodeType":1680},{},[11134,11154,11160,11163,11171,11221,11231,11234,11242,11260,11267,11291,11309,11312,11320,11339,11346,11353,11363,11366,11374,11405,11423,11426,11434,11451,11458,11465,11468,11476,11493,11500,11518,11528,11535,11538,11546,11563,11570,11577,11589,11599,11616,11619,11627,11634,11682],{"data":11135,"content":11136,"nodeType":876},{},[11137,11141,11150],{"data":11138,"marks":11139,"value":11140,"nodeType":867},{},[],"We recently sat down with ",{"data":11142,"content":11144,"nodeType":915},{"uri":11143},"https://www.youtube.com/@_JohnHammond",[11145],{"data":11146,"marks":11147,"value":11149,"nodeType":867},{},[11148],{"type":913},"John Hammond",{"data":11151,"marks":11152,"value":11153,"nodeType":867},{},[]," — Senior Principal Security Researcher at Huntress — for a live deep-dive into the browser-based attack techniques defining the 2026 threat landscape. The session covered AiTM phishing, ClickFix, ConsentFix, device code phishing, and the structural shifts making traditional security controls less effective against all of them. Here are seven takeaways.",{"data":11155,"content":11159,"nodeType":985},{"target":11156},{"sys":11157},{"id":11158,"type":982,"linkType":983},"5lJ49aLY0nApDeY69tNvUi",[],{"data":11161,"content":11162,"nodeType":942},{},[],{"data":11164,"content":11165,"nodeType":868},{},[11166],{"data":11167,"marks":11168,"value":11170,"nodeType":867},{},[11169],{"type":865},"1. Browser attacks are evolving faster than defenses can adapt",{"data":11172,"content":11173,"nodeType":876},{},[11174,11178,11185,11189,11196,11200,11207,11211,11218],{"data":11175,"marks":11176,"value":11177,"nodeType":867},{},[],"The overriding theme of the session wasn't any single technique — it was the pace of change across all of them. AiTM phishing has been ",{"data":11179,"content":11180,"nodeType":915},{"uri":995},[11181],{"data":11182,"marks":11183,"value":11184,"nodeType":867},{},[],"the dominant phishing technique",{"data":11186,"marks":11187,"value":11188,"nodeType":867},{},[]," for a couple of years now, but the variants layered on top of it are arriving faster than most security teams can evaluate, let alone deploy defenses against. ClickFix went from novel to ",{"data":11190,"content":11191,"nodeType":915},{"uri":2557},[11192],{"data":11193,"marks":11194,"value":11195,"nodeType":867},{},[],"the most common initial access vector observed by Microsoft",{"data":11197,"marks":11198,"value":11199,"nodeType":867},{},[]," within about a year. Device code phishing went from near-zero to ",{"data":11201,"content":11202,"nodeType":915},{"uri":1116},[11203],{"data":11204,"marks":11205,"value":11206,"nodeType":867},{},[],"at least 12 distinct kits",{"data":11208,"marks":11209,"value":11210,"nodeType":867},{},[]," in a matter of months. ConsentFix was detected as a zero-day technique by Push in late 2025 and has already been ",{"data":11212,"content":11213,"nodeType":915},{"uri":1944},[11214],{"data":11215,"marks":11216,"value":11217,"nodeType":867},{},[],"operationalized on criminal forums",{"data":11219,"marks":11220,"value":1679,"nodeType":867},{},[],{"data":11222,"content":11223,"nodeType":3804},{},[11224],{"data":11225,"content":11226,"nodeType":876},{},[11227],{"data":11228,"marks":11229,"value":11230,"nodeType":867},{},[],"As Luke put it toward the end of the session: \"I've seen this develop so fast over the last two years. This isn't what's coming — this is now. This is where the battleground is.\"",{"data":11232,"content":11233,"nodeType":942},{},[],{"data":11235,"content":11236,"nodeType":868},{},[11237],{"data":11238,"marks":11239,"value":11241,"nodeType":867},{},[11240],{"type":865},"2. AiTM phishing is table stakes for attackers ",{"data":11243,"content":11244,"nodeType":876},{},[11245,11249,11256],{"data":11246,"marks":11247,"value":11248,"nodeType":867},{},[],"Adversary-in-the-middle phishing — where a reverse proxy sits between the victim and the real login page, intercepting session tokens in real time to bypass MFA — is no longer an advanced technique. It's available as a commodity for-hire through Phishing-as-a-Service platforms like Tycoon2FA, Sneaky2FA, and others",{"data":11250,"content":11251,"nodeType":915},{"uri":995},[11252],{"data":11253,"marks":11254,"value":5000,"nodeType":867},{},[11255],{"type":913},{"data":11257,"marks":11258,"value":11259,"nodeType":867},{},[]," and the kits are getting harder to detect through traditional means.",{"data":11261,"content":11262,"nodeType":876},{},[11263],{"data":11264,"marks":11265,"value":11266,"nodeType":867},{},[],"Luke demoed the attacker's perspective using Evilginx — an open-source tool now commonly seen in criminal operations — showing how session tokens are captured in real time even when the victim enters their MFA code correctly. From the victim's side, the login feels completely normal.",{"data":11268,"content":11269,"nodeType":876},{},[11270,11275,11279,11288],{"data":11271,"marks":11272,"value":11274,"nodeType":867},{},[11273],{"type":865},"One of the key focuses in the session was how attackers are abusing legitimate infrastructure for both hosting and delivery of phishing pages. .",{"data":11276,"marks":11277,"value":11278,"nodeType":867},{},[]," The in-the-wild examples showed attack chains routing through multiple legitimate services — file-sharing platforms, TinyURL, Cloudflare Turnstile, Google Search redirects — before finally landing on the phishing page. This is a well established technique for ",{"data":11280,"content":11282,"nodeType":915},{"uri":11281},"https://phishing-techniques.pushsecurity.com/",[11283],{"data":11284,"marks":11285,"value":11287,"nodeType":867},{},[11286],{"type":913},"detection evasion",{"data":11289,"marks":11290,"value":5704,"nodeType":867},{},[],{"data":11292,"content":11293,"nodeType":876},{},[11294,11298,11305],{"data":11295,"marks":11296,"value":11297,"nodeType":867},{},[],"As John observed, \"the end user doesn't have that wherewithal or that observability understanding of how far they drove around across the internet\" before arriving at the credential-harvesting page. Push reconstructs these multi-hop chains into a ",{"data":11299,"content":11300,"nodeType":915},{"uri":8610},[11301],{"data":11302,"marks":11303,"value":11304,"nodeType":867},{},[],"complete timeline",{"data":11306,"marks":11307,"value":11308,"nodeType":867},{},[],", mapping the full redirect sequence even when individual hops are through trusted domains that wouldn't trigger any reputation-based alert — and crucially, detects malicious content on the phishing page itself rather than relying on known-bad IP and domain based checks that can only see the known-good sites used early in the chain.",{"data":11310,"content":11311,"nodeType":942},{},[],{"data":11313,"content":11314,"nodeType":868},{},[11315],{"data":11316,"marks":11317,"value":11319,"nodeType":867},{},[11318],{"type":865},"3. Email is losing its market share as a delivery vector",{"data":11321,"content":11322,"nodeType":876},{},[11323,11327,11335],{"data":11324,"marks":11325,"value":11326,"nodeType":867},{},[],"One of the most striking examples in the webinar was a targeted AiTM campaign ",{"data":11328,"content":11330,"nodeType":915},{"uri":11329},"https://pushsecurity.com/blog/new-phishing-campaign-identified-targeting-linkedin-users/",[11331],{"data":11332,"marks":11333,"value":11334,"nodeType":867},{},[],"Push detected last year",{"data":11336,"marks":11337,"value":11338,"nodeType":867},{},[]," that was delivered entirely via LinkedIn. Senior executives at tech companies received direct messages from compromised contacts — people they already knew, in some cases other employees of the same companies — offering involvement in private equity fundraising rounds connected to companies they had real involvement with. The targeting was precise and personal, and the redirect chain ran through sites.google.com and Microsoft Dynamics before landing on a cloned login page.",{"data":11340,"content":11341,"nodeType":876},{},[11342],{"data":11343,"marks":11344,"value":11345,"nodeType":867},{},[],"As Luke noted, LinkedIn occupies an unusual middle ground: \"It's this great way of targeting companies, but through a vector that can't really be monitored in the same way as other corporate systems, because it's kind of a personal platform.\" It's personal enough that companies can't realistically monitor it, but professional enough that employees routinely access it from corporate devices.",{"data":11347,"content":11348,"nodeType":876},{},[11349],{"data":11350,"marks":11351,"value":11352,"nodeType":867},{},[],"LinkedIn is only part of the shift. ClickFix attacks most commonly arrive via search results in 4 of 5 cases based on Push data. Luke noted \"not even malvertising, just organic search, uncovering legit websites that have been compromised.\" InstallFix pages appear as sponsored Google ads. ConsentFix pages were seeded on compromised websites found through normal browsing. In every case, the email gateway never sees the lure because the lure was never in an email. And of course, even if a compromised website is reported and removed, it’s easier than ever for an attacker to quickly tear down and rotate their sites to stay ahead of blocklists. ",{"data":11354,"content":11355,"nodeType":3804},{},[11356],{"data":11357,"content":11358,"nodeType":876},{},[11359],{"data":11360,"marks":11361,"value":11362,"nodeType":867},{},[],"As John put it: \"You could set up this lure or this trap out on the open internet so that anyone could fall for it at any point.\"",{"data":11364,"content":11365,"nodeType":942},{},[],{"data":11367,"content":11368,"nodeType":868},{},[11369],{"data":11370,"marks":11371,"value":11373,"nodeType":867},{},[11372],{"type":865},"4. ClickFix keeps evolving with multiple *Fix derivatives",{"data":11375,"content":11376,"nodeType":876},{},[11377,11381,11389,11393,11401],{"data":11378,"marks":11379,"value":11380,"nodeType":867},{},[],"ClickFix — where a malicious page silently writes a payload to the victim's clipboard and instructs them to paste and execute it — ",{"data":11382,"content":11383,"nodeType":915},{"uri":1599},[11384],{"data":11385,"marks":11386,"value":11388,"nodeType":867},{},[11387],{"type":913},"spawned an entire family of variants since its emergence, according to Push’s research",{"data":11390,"marks":11391,"value":11392,"nodeType":867},{},[],". The webinar showed how far the social engineering has come: Luke demonstrated a ",{"data":11394,"content":11396,"nodeType":915},{"uri":11395},"https://pushsecurity.com/blog/the-most-advanced-clickfix-yet/",[11397],{"data":11398,"marks":11399,"value":11400,"nodeType":867},{},[],"particularly sophisticated variant",{"data":11402,"marks":11403,"value":11404,"nodeType":867},{},[]," on a compromised legitimate website with an embedded instructional video and a countdown timer to manufacture urgency, targeting macOS. As John noted: \"It can be cross-platform because you're just preying on the human weakness. The video smooths it over for the user experience.\"",{"data":11406,"content":11407,"nodeType":876},{},[11408,11412,11419],{"data":11409,"marks":11410,"value":11411,"nodeType":867},{},[],"The more important point was structural. Because the user manually pastes and executes the command, \"from the EDR's perspective, the user just manually ran this command,\" Luke explained. \"It actually breaks that link from an EDR's perspective.\" EDR behavioral detections weigh execution context heavily — a PowerShell command spawned from a browser process tree is suspicious, but the same command initiated through the Run dialog looks like normal activity. Push ",{"data":11413,"content":11414,"nodeType":915},{"uri":1599},[11415],{"data":11416,"marks":11417,"value":11418,"nodeType":867},{},[],"detects ClickFix at the clipboard-injection stage",{"data":11420,"marks":11421,"value":11422,"nodeType":867},{},[],", before the payload ever reaches the endpoint, to bolster endpoint-level detections and extend protection to machines like BYOD, contractor, or developer devices where EDR is often missing or tuned-down.",{"data":11424,"content":11425,"nodeType":942},{},[],{"data":11427,"content":11428,"nodeType":868},{},[11429],{"data":11430,"marks":11431,"value":11433,"nodeType":867},{},[11432],{"type":865},"5. InstallFix turned the AI tool boom into an attack surface overnight",{"data":11435,"content":11436,"nodeType":876},{},[11437,11440,11447],{"data":11438,"marks":11439,"value":21,"nodeType":867},{},[],{"data":11441,"content":11442,"nodeType":915},{"uri":3932},[11443],{"data":11444,"marks":11445,"value":9082,"nodeType":867},{},[11446],{"type":913},{"data":11448,"marks":11449,"value":11450,"nodeType":867},{},[]," — a ClickFix variant that clones legitimate developer tool installation pages and swaps the install command for a malicious payload — was one of the clearest examples of how quickly a new attack pattern can go from zero to dominant. Luke showed side-by-side comparisons of real and fake Claude Code installation pages that were visually identical except for the payload itself, and fake Notebook LM pages appearing as top Google sponsored results.",{"data":11452,"content":11453,"nodeType":876},{},[11454],{"data":11455,"marks":11456,"value":11457,"nodeType":867},{},[],"The trajectory Luke described was striking: \"It literally started one day and then it's just been nonstop for the last couple of months since it started. It obviously is working really well.\" John added that the Claude Code variant in particular has been \"running rampant,\" and that he personally knows someone who fell for it.",{"data":11459,"content":11460,"nodeType":876},{},[11461],{"data":11462,"marks":11463,"value":11464,"nodeType":867},{},[],"What makes InstallFix effective is that it exploits a workflow that's become completely normalized — the rise of AI tools has encouraged even non-technical users to install software via terminal commands copied from documentation pages. When the fake page looks identical to the real one and the install method is exactly what you'd expect, the only tell is a base64-encoded payload that most users wouldn't think to scrutinize.",{"data":11466,"content":11467,"nodeType":942},{},[],{"data":11469,"content":11470,"nodeType":868},{},[11471],{"data":11472,"marks":11473,"value":11475,"nodeType":867},{},[11474],{"type":865},"6. ConsentFix plays out entirely in the browser, and criminals just got the playbook",{"data":11477,"content":11478,"nodeType":876},{},[11479,11482,11489],{"data":11480,"marks":11481,"value":21,"nodeType":867},{},[],{"data":11483,"content":11484,"nodeType":915},{"uri":3692},[11485],{"data":11486,"marks":11487,"value":3685,"nodeType":867},{},[11488],{"type":913},{"data":11490,"marks":11491,"value":11492,"nodeType":867},{},[]," was a key focus in the webinar, and for good reason — it represents a fundamentally different class of browser attack. Rather than proxying credentials (AiTM) or injecting endpoint payloads (ClickFix), ConsentFix abuses the OAuth authorization code flow via the Azure CLI's localhost redirect to obtain access tokens without ever touching a password or MFA prompt. As John put it: \"This one is really tricky because the entire attack and technique lives only within the browser. There are no little EDR artifacts to poke and play at.\"",{"data":11494,"content":11495,"nodeType":876},{},[11496],{"data":11497,"marks":11498,"value":11499,"nodeType":867},{},[],"Luke described how Push first detected ConsentFix in the wild — a genuine zero-day discovery that took multiple encounters to fully understand. The attackers were fingerprinting visitors by IP and browser, triggering the payload only once per visitor across all compromised sites, and performing conditional access checks on the email address provided before deciding whether to proceed. \"It took us seeing it a few times before we cracked it,\" Luke explained. \"And then we were like — wow. What is this? I've never seen this before.\"",{"data":11501,"content":11502,"nodeType":876},{},[11503,11507,11514],{"data":11504,"marks":11505,"value":11506,"nodeType":867},{},[],"The session then took an interesting turn when John revealed something he hadn't previously shared publicly: a  ",{"data":11508,"content":11509,"nodeType":915},{"uri":1944},[11510],{"data":11511,"marks":11512,"value":11513,"nodeType":867},{},[],"ConsentFix v3 toolkit",{"data":11515,"marks":11516,"value":11517,"nodeType":867},{},[]," posted on a well-known criminal forum, complete with a tutorial video, step-by-step instructions, and a zero-infrastructure approach using Cloudflare Workers for hosting, Dropbox for PDF delivery, and Pipedream as an automated exfiltration channel. \"They don’t need any infrastructure,\" John noted. \"They don’t have to host any servers or VPS. They could just cast this out to the whole wide world on the open internet.\"",{"data":11519,"content":11520,"nodeType":3804},{},[11521],{"data":11522,"content":11523,"nodeType":876},{},[11524],{"data":11525,"marks":11526,"value":11527,"nodeType":867},{},[],"Luke's assessment was clear: \"When we published our first article, we were thinking, surely we're going to see a huge increase in this technique. We haven't really — until now.\" ",{"data":11529,"content":11530,"nodeType":876},{},[11531],{"data":11532,"marks":11533,"value":11534,"nodeType":867},{},[],"With the criminal ecosystem now tooled up, the expectation is that ConsentFix will follow the same commoditization arc as other techniques discussed in the session.",{"data":11536,"content":11537,"nodeType":942},{},[],{"data":11539,"content":11540,"nodeType":868},{},[11541],{"data":11542,"marks":11543,"value":11545,"nodeType":867},{},[11544],{"type":865},"7. Device code phishing is the technique both speakers fear most (and it's just getting started)",{"data":11547,"content":11548,"nodeType":876},{},[11549,11553,11560],{"data":11550,"marks":11551,"value":11552,"nodeType":867},{},[],"When John asked Luke which technique felt most dangerous, the answer was immediate: ",{"data":11554,"content":11555,"nodeType":915},{"uri":1116},[11556],{"data":11557,"marks":11558,"value":11559,"nodeType":867},{},[],"device code phishing",{"data":11561,"marks":11562,"value":5704,"nodeType":867},{},[],{"data":11564,"content":11565,"nodeType":876},{},[11566],{"data":11567,"marks":11568,"value":11569,"nodeType":867},{},[],"The technique abuses the OAuth 2.0 device authorization grant flow — originally designed for input-constrained devices like TVs, but now primarily used in enterprise environments for CLI tool authentication (Azure CLI, GitHub CLI, AWS CLI). That everyday enterprise usage is exactly what makes the phishing so effective: users in developer-heavy organizations are already habituated to entering short codes as part of their normal workflow. The victim enters a code on a legitimate Microsoft login page, and if they're already authenticated, the entire compromise happens without entering a password or completing an MFA challenge.",{"data":11571,"content":11572,"nodeType":876},{},[11573],{"data":11574,"marks":11575,"value":11576,"nodeType":867},{},[],"Push is now tracking at least 12 distinct device code phishing kits, \"literally within the last couple of months — from basically zero to this.\" EvilTokens dominates at an estimated 90–95% of detected volume, but the kit landscape is diversifying fast. Luke's theory: every existing AiTM vendor is adding device code phishing as a module. When Push investigated the Venom kit, its AiTM component triggered existing Sneaky2FA detections — suggesting the same actors or codebase behind both. \"That's why we've seen such a rapid increase — it's worked so well that everyone is just doing the same thing now.\"",{"data":11578,"content":11579,"nodeType":876},{},[11580,11585],{"data":11581,"marks":11582,"value":11584,"nodeType":867},{},[11583],{"type":865},"What makes device code phishing uniquely dangerous is how little friction it presents to the victim.",{"data":11586,"marks":11587,"value":11588,"nodeType":867},{},[]," As Luke explained: \"It's purely identity-driven. It completely bypasses 2FA, even bypasses phishing-resistant factors like passkeys. And it's just not something that seems malicious to your average user. We haven't trained people to worry about being given a code and being told to type that code.\"",{"data":11590,"content":11591,"nodeType":3804},{},[11592],{"data":11593,"content":11594,"nodeType":876},{},[11595],{"data":11596,"marks":11597,"value":11598,"nodeType":867},{},[],"John's closing take: \"It still feels early and emergent, even though the technique has been known for a while. It hasn't been weaponized like it has right now. I think device code is just at the starting gun.\" ",{"data":11600,"content":11601,"nodeType":876},{},[11602,11606,11613],{"data":11603,"marks":11604,"value":11605,"nodeType":867},{},[],"The blast radius extends beyond Microsoft too — GitHub, Salesforce, and other platforms support the same underlying flow, and was exploited in 2025’s massive Salesforce campaign operated by ",{"data":11607,"content":11608,"nodeType":915},{"uri":1165},[11609],{"data":11610,"marks":11611,"value":1170,"nodeType":867},{},[11612],{"type":913},{"data":11614,"marks":11615,"value":1679,"nodeType":867},{},[],{"data":11617,"content":11618,"nodeType":942},{},[],{"data":11620,"content":11621,"nodeType":868},{},[11622],{"data":11623,"marks":11624,"value":11626,"nodeType":867},{},[11625],{"type":865},"What ties all of this together",{"data":11628,"content":11629,"nodeType":876},{},[11630],{"data":11631,"marks":11632,"value":11633,"nodeType":867},{},[],"Every technique covered in the webinar — AiTM, ClickFix, InstallFix, ConsentFix, device code phishing — is designed to operate in or through the browser, abuse legitimate infrastructure and authentication flows, and evade the traditional security stack. Email gateways don't see them because the delivery vector increasingly isn't email. EDR doesn't reliably block them because the attack either breaks the process tree attribution (ClickFix) or never touches the endpoint at all (ConsentFix, device code phishing). Network proxies don't see them because the attack plays out in client-side page content, DOM interactions, and OAuth flows that are invisible to traffic inspection.",{"data":11635,"content":11636,"nodeType":876},{},[11637,11641,11647,11650,11657,11660,11667,11671,11678],{"data":11638,"marks":11639,"value":11640,"nodeType":867},{},[],"Push detects all of them — ",{"data":11642,"content":11643,"nodeType":915},{"uri":8610},[11644],{"data":11645,"marks":11646,"value":261,"nodeType":867},{},[],{"data":11648,"marks":11649,"value":5000,"nodeType":867},{},[],{"data":11651,"content":11652,"nodeType":915},{"uri":1599},[11653],{"data":11654,"marks":11655,"value":11656,"nodeType":867},{},[]," ClickFix and the *Fix family",{"data":11658,"marks":11659,"value":5000,"nodeType":867},{},[],{"data":11661,"content":11662,"nodeType":915},{"uri":3692},[11663],{"data":11664,"marks":11665,"value":11666,"nodeType":867},{},[]," ConsentFix",{"data":11668,"marks":11669,"value":11670,"nodeType":867},{},[],", and",{"data":11672,"content":11673,"nodeType":915},{"uri":1116},[11674],{"data":11675,"marks":11676,"value":11677,"nodeType":867},{},[]," device code phishing",{"data":11679,"marks":11680,"value":11681,"nodeType":867},{},[]," — through behavioral detection at the browser layer, regardless of delivery channel, domain reputation, or infrastructure rotation. The detections target technique-class behaviors rather than specific kits or indicators, which is why Push detected ConsentFix as a zero-day and why new kit variants are typically caught by existing detection logic before a kit-specific rule is even written.",{"data":11683,"content":11684,"nodeType":876},{},[11685,11688,11697,11701,11708],{"data":11686,"marks":11687,"value":21,"nodeType":867},{},[],{"data":11689,"content":11691,"nodeType":915},{"uri":11690},"https://pushsecurity.com/resources/browser-attacks-why-browser-new-battleground",[11692],{"data":11693,"marks":11694,"value":11696,"nodeType":867},{},[11695],{"type":913},"Watch the full webinar",{"data":11698,"marks":11699,"value":11700,"nodeType":867},{},[]," to see the demos, attack chain timelines, and in-the-wild examples discussed in this post — or ",{"data":11702,"content":11703,"nodeType":915},{"uri":2689},[11704],{"data":11705,"marks":11706,"value":11707,"nodeType":867},{},[],"book a demo",{"data":11709,"marks":11710,"value":11711,"nodeType":867},{},[]," to see how Push handles them.",{"entries":11713},{"hyperlink":11714,"inline":11715,"block":11716},[],[],[11717],{"sys":11718,"__typename":1697,"type":1698,"ctaText":11719,"buttonLabel":11720,"buttonColour":1701,"buttonUrl":11690},{"id":11158},"Watch the full webinar on demand.","Watch now",{"items":11722},[],{},"7 things we learned from our conversation with John Hammond",{"items":11726},[11727,14744,15586],{"__typename":1772,"sys":11728,"content":11730,"title":14727,"synopsis":14728,"hashTags":59,"publishedDate":14729,"slug":361,"tagsCollection":14730,"authorsCollection":14736},{"id":11729},"5DmCqTU2Tg4adYScA5vT2x",{"json":11731},{"data":11732,"content":11733,"nodeType":1680},{},[11734,11740,11760,11778,11785,11791,11798,11805,11808,11816,11822,11906,11926,11932,11939,12055,12061,12064,12072,12079,12085,12088,12096,12137,12143,12150,12157,12164,12171,12190,12196,12202,12208,12214,12220,12226,12232,12238,12501,12504,12512,12647,12653,12656,12664,12704,12838,12844,12847,12855,13002,13008,13011,13019,13025,13165,13171,13177,13180,13188,13335,13341,13344,13352,13498,13504,13507,13515,13610,13616,13619,13627,13721,13727,13730,13738,13744,13877,13883,13886,13894,13943,13949,13952,13960,14099,14104,14107,14115,14247,14253,14256,14264,14276,14283,14289,14295,14302,14323,14339,14345,14348,14356,14364,14385,14406,14411,14418,14425,14433,14440,14447,14454,14462,14469,14520,14526,14529,14537,14544,14551,14598,14604,14611,14614,14622,14629,14636,14656,14662,14669,14677,14684],{"data":11735,"content":11739,"nodeType":985},{"target":11736},{"sys":11737},{"id":11738,"type":982,"linkType":983},"XOFOeNqmRHeiRbkPOJrP1",[],{"data":11741,"content":11742,"nodeType":876},{},[11743,11747,11756],{"data":11744,"marks":11745,"value":11746,"nodeType":867},{},[],"The OAuth 2.0 ",{"data":11748,"content":11750,"nodeType":915},{"uri":11749},"https://www.rfc-editor.org/rfc/rfc8628",[11751],{"data":11752,"marks":11753,"value":11755,"nodeType":867},{},[11754],{"type":913},"device authorization grant",{"data":11757,"marks":11758,"value":11759,"nodeType":867},{},[]," was designed to enable input-constrained devices to sign-in to apps by asking the user to complete the login on a separate device by entering a code. But today, it’s mainly used when accessing CLI tools, meaning that many users encounter the device code flow daily. ",{"data":11761,"content":11762,"nodeType":876},{},[11763,11766,11774],{"data":11764,"marks":11765,"value":21,"nodeType":867},{},[],{"data":11767,"content":11769,"nodeType":915},{"uri":11768},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/device_code_phishing/description.md",[11770],{"data":11771,"marks":11772,"value":360,"nodeType":867},{},[11773],{"type":913},{"data":11775,"marks":11776,"value":11777,"nodeType":867},{},[]," attacks designed to exploit this authorization flow are not new — it was among the first techniques that we added to the SaaS attacks matrix back in 2023. But it’s taken until now for it to really enter mainstream adoption. ",{"data":11779,"content":11780,"nodeType":876},{},[11781],{"data":11782,"marks":11783,"value":11784,"nodeType":867},{},[],"The technique tricks a user into issuing access tokens for an attacker-controlled application (not a device, confusingly). Any app that supports device code logins can be a target. Popular examples include Microsoft, Google, Salesforce, GitHub, and AWS. That said, Microsoft is, as always, much more heavily targeted at scale now than any other app.",{"data":11786,"content":11790,"nodeType":985},{"target":11787},{"sys":11788},{"id":11789,"type":982,"linkType":983},"Al0pGH8vmOYiufDFiAbt0",[],{"data":11792,"content":11793,"nodeType":876},{},[11794],{"data":11795,"marks":11796,"value":11797,"nodeType":867},{},[],"We’ve always been surprised that attackers haven’t commonly used device code phishing in their standard toolkit, preferring session-stealing AITM phishing and other social engineering attacks like ClickFix. But it’s pretty clear from the recent data that the shift to mainstream adoption has now happened. ",{"data":11799,"content":11800,"nodeType":876},{},[11801],{"data":11802,"marks":11803,"value":11804,"nodeType":867},{},[],"In this blog post, we’ll explore the history of device code phishing, what’s changed for it to enter mainstream adoption, how it works under the hood (with recent examples), and what security teams can do about it. ",{"data":11806,"content":11807,"nodeType":942},{},[],{"data":11809,"content":11810,"nodeType":868},{},[11811],{"data":11812,"marks":11813,"value":11815,"nodeType":867},{},[11814],{"type":865},"A brief history of device code phishing",{"data":11817,"content":11821,"nodeType":985},{"target":11818},{"sys":11819},{"id":11820,"type":982,"linkType":983},"6u3DgvSGChtTJu7l9I7PG1",[],{"data":11823,"content":11824,"nodeType":876},{},[11825,11829,11838,11842,11851,11855,11864,11868,11877,11881,11890,11893,11902],{"data":11826,"marks":11827,"value":11828,"nodeType":867},{},[],"The technique was first documented in 2020, before Secureworks released the first tooling framework ",{"data":11830,"content":11832,"nodeType":915},{"uri":11831},"https://github.com/secureworks/PhishInSuits",[11833],{"data":11834,"marks":11835,"value":11837,"nodeType":867},{},[11836],{"type":913},"PhishInSuits",{"data":11839,"marks":11840,"value":11841,"nodeType":867},{},[]," a year later. A host of research followed, including ",{"data":11843,"content":11845,"nodeType":915},{"uri":11844},"https://github.com/secureworks/squarephish",[11846],{"data":11847,"marks":11848,"value":11850,"nodeType":867},{},[11849],{"type":913},"SquarePhish",{"data":11852,"marks":11853,"value":11854,"nodeType":867},{},[]," v1 (using QR codes to trigger the 15 minute code expiration window), Dirk-Jan Mollema’s ",{"data":11856,"content":11858,"nodeType":915},{"uri":11857},"https://dirkjanm.io/phishing-for-microsoft-entra-primary-refresh-tokens/",[11859],{"data":11860,"marks":11861,"value":11863,"nodeType":867},{},[11862],{"type":913},"key research",{"data":11865,"marks":11866,"value":11867,"nodeType":867},{},[]," (chaining device code phishing via Microsoft apps into Primary Refresh Token (PRT) acquisition to gain full browser-level access) and Dennis Kniep’s ",{"data":11869,"content":11871,"nodeType":915},{"uri":11870},"https://github.com/denniskniep/DeviceCodePhishing",[11872],{"data":11873,"marks":11874,"value":11876,"nodeType":867},{},[11875],{"type":913},"DeviceCodePhishing tool",{"data":11878,"marks":11879,"value":11880,"nodeType":867},{},[]," which automates the entire flow with a headless browser. (Other recent noteworthy tools include ",{"data":11882,"content":11884,"nodeType":915},{"uri":11883},"https://github.com/nromsdahl/squarephish2",[11885],{"data":11886,"marks":11887,"value":11889,"nodeType":867},{},[11888],{"type":913},"SquarePhish2",{"data":11891,"marks":11892,"value":1174,"nodeType":867},{},[],{"data":11894,"content":11896,"nodeType":915},{"uri":11895},"https://github.com/praetorian-inc/GitPhish",[11897],{"data":11898,"marks":11899,"value":11901,"nodeType":867},{},[11900],{"type":913},"GitPhish",{"data":11903,"marks":11904,"value":11905,"nodeType":867},{},[],", so shout out to those too). ",{"data":11907,"content":11908,"nodeType":876},{},[11909,11913,11922],{"data":11910,"marks":11911,"value":11912,"nodeType":867},{},[],"It wasn’t until August 2024 that in-the-wild exploitation was first identified, with Russia-linked campaigns then continuing into 2025 before entering mainstream criminal adoption. This trend has continued to gather momentum in 2026 with ",{"data":11914,"content":11916,"nodeType":915},{"uri":11915},"https://thehackernews.com/2026/03/device-code-phishing-hits-340-microsoft.html",[11917],{"data":11918,"marks":11919,"value":11921,"nodeType":867},{},[11920],{"type":913},"EvilTokens",{"data":11923,"marks":11924,"value":11925,"nodeType":867},{},[],", the first reported criminal PhaaS kit for device code phishing, already powering massive campaigns after launching in February. ",{"data":11927,"content":11931,"nodeType":985},{"target":11928},{"sys":11929},{"id":11930,"type":982,"linkType":983},"6xsfmbYEzpW7CdDiNzO6cu",[],{"data":11933,"content":11934,"nodeType":876},{},[11935],{"data":11936,"marks":11937,"value":11938,"nodeType":867},{},[],"Some of the noteworthy in-the-wild campaigns include:",{"data":11940,"content":11941,"nodeType":1629},{},[11942,11975,11996],{"data":11943,"content":11944,"nodeType":1586},{},[11945],{"data":11946,"content":11947,"nodeType":876},{},[11948,11952,11960,11963,11971],{"data":11949,"marks":11950,"value":11951,"nodeType":867},{},[],"Storm-2372, tracked by ",{"data":11953,"content":11955,"nodeType":915},{"uri":11954},"https://www.microsoft.com/en-us/security/blog/2025/02/13/storm-2372-conducts-device-code-phishing-campaign/",[11956],{"data":11957,"marks":11958,"value":11959,"nodeType":867},{},[],"Microsoft",{"data":11961,"marks":11962,"value":1174,"nodeType":867},{},[],{"data":11964,"content":11966,"nodeType":915},{"uri":11965},"https://www.volexity.com/blog/2025/02/13/multiple-russian-threat-actors-targeting-microsoft-device-code-authentication/",[11967],{"data":11968,"marks":11969,"value":11970,"nodeType":867},{},[],"Volexity",{"data":11972,"marks":11973,"value":11974,"nodeType":867},{},[],", linked to multiple Russia-aligned clusters, combining spear-phishing and social engineering with device code phishing payloads against strategic intelligence targets.",{"data":11976,"content":11977,"nodeType":1586},{},[11978],{"data":11979,"content":11980,"nodeType":876},{},[11981,11985,11992],{"data":11982,"marks":11983,"value":11984,"nodeType":867},{},[],"The massive Salesforce campaign operated by ",{"data":11986,"content":11987,"nodeType":915},{"uri":1177},[11988],{"data":11989,"marks":11990,"value":11991,"nodeType":867},{},[],"Scattered Lapsus$ Hunters",{"data":11993,"marks":11994,"value":11995,"nodeType":867},{},[]," (SLH) combined vishing with a device code phishing payload targeting Salesforce. The attacks morphed into a broader supply chain campaign using stolen credentials, ultimately resulting in 1000+ organizations being compromised and over 1.5 billion stolen records claimed. ",{"data":11997,"content":11998,"nodeType":1586},{},[11999],{"data":12000,"content":12001,"nodeType":876},{},[12002,12006,12014,12018,12027,12030,12039,12043,12051],{"data":12003,"marks":12004,"value":12005,"nodeType":867},{},[],"A massive spike in activity in late 2025 and 2026. This includes ",{"data":12007,"content":12009,"nodeType":915},{"uri":12008},"https://www.proofpoint.com/us/blog/threat-insight/access-granted-phishing-device-code-authorization-account-takeover",[12010],{"data":12011,"marks":12012,"value":12013,"nodeType":867},{},[],"multiple threat clusters",{"data":12015,"marks":12016,"value":12017,"nodeType":867},{},[]," tracked using device code phishing techniques, more ",{"data":12019,"content":12021,"nodeType":915},{"uri":12020},"https://www.bleepingcomputer.com/news/security/hackers-target-microsoft-entra-accounts-in-device-code-vishing-attacks/",[12022],{"data":12023,"marks":12024,"value":12026,"nodeType":867},{},[12025],{"type":913},"criminal operations linked to SLH",{"data":12028,"marks":12029,"value":5147,"nodeType":867},{},[],{"data":12031,"content":12033,"nodeType":915},{"uri":12032},"https://newtonpaul.com/blog/device-code-phish-update/",[12034],{"data":12035,"marks":12036,"value":12038,"nodeType":867},{},[12037],{"type":913},"hundreds of organizations being targeted via PhaaS architecture,",{"data":12040,"marks":12041,"value":12042,"nodeType":867},{},[]," which looks to be the same campaign as the recently uncovered EvilTokens PhaaS reported by ",{"data":12044,"content":12045,"nodeType":915},{"uri":2022},[12046],{"data":12047,"marks":12048,"value":12050,"nodeType":867},{},[12049],{"type":913},"Huntress",{"data":12052,"marks":12053,"value":12054,"nodeType":867},{},[]," (featuring abuse of the Railway PaaS platform). ",{"data":12056,"content":12060,"nodeType":985},{"target":12057},{"sys":12058},{"id":12059,"type":982,"linkType":983},"3WLt6qLCK8CSwr0QZxZiMv",[],{"data":12062,"content":12063,"nodeType":942},{},[],{"data":12065,"content":12066,"nodeType":868},{},[12067],{"data":12068,"marks":12069,"value":12071,"nodeType":867},{},[12070],{"type":865},"What we’re seeing in the wild",{"data":12073,"content":12074,"nodeType":876},{},[12075],{"data":12076,"marks":12077,"value":12078,"nodeType":867},{},[],"As mentioned, we’ve also seen a huge spike in device code phishing activity this year, with multiple kits, page designs, and lure types. We’ve now identified 14+ distinct kits in circulation in the wild, with EvilTokens being the most prevalent. It’s clear that attackers are both spinning up their own kits and creative derivatives of others — we’ve seen kits that are visually similar to EvilTokens (close enough to be clones or forks) but with very different backends, for example AWS, Digital Ocean, 2cloud, and more. ",{"data":12080,"content":12084,"nodeType":985},{"target":12081},{"sys":12082},{"id":12083,"type":982,"linkType":983},"nJCbTw85GKXdqrlIkzZwi",[],{"data":12086,"content":12087,"nodeType":942},{},[],{"data":12089,"content":12090,"nodeType":1058},{},[12091],{"data":12092,"marks":12093,"value":12095,"nodeType":867},{},[12094],{"type":865},"“ANTIBOT” (EvilTokens)",{"data":12097,"content":12098,"nodeType":876},{},[12099,12102,12109,12112,12121,12125,12133],{"data":12100,"marks":12101,"value":21,"nodeType":867},{},[],{"data":12103,"content":12104,"nodeType":915},{"uri":2022},[12105],{"data":12106,"marks":12107,"value":12050,"nodeType":867},{},[12108],{"type":913},{"data":12110,"marks":12111,"value":5136,"nodeType":867},{},[],{"data":12113,"content":12115,"nodeType":915},{"uri":12114},"https://blog.sekoia.io/new-widespread-eviltokens-kit-device-code-phishing-as-a-service-part-1/",[12116],{"data":12117,"marks":12118,"value":12120,"nodeType":867},{},[12119],{"type":913},"Sekoia",{"data":12122,"marks":12123,"value":12124,"nodeType":867},{},[],", and researcher ",{"data":12126,"content":12127,"nodeType":915},{"uri":12032},[12128],{"data":12129,"marks":12130,"value":12132,"nodeType":867},{},[12131],{"type":913},"Paul Newton",{"data":12134,"marks":12135,"value":12136,"nodeType":867},{},[]," have already done a great job of providing IOCs for the recent EvilTokens activity spike, including multiple backend Railway IPs in authentication events. ",{"data":12138,"content":12142,"nodeType":985},{"target":12139},{"sys":12140},{"id":12141,"type":982,"linkType":983},"1XNviq5OvMf5TEAc59F6g5",[],{"data":12144,"content":12145,"nodeType":876},{},[12146],{"data":12147,"marks":12148,"value":12149,"nodeType":867},{},[],"Beyond the most widely observed implementation featuring a Cloudflare Workers frontend and Railway backend for authentication, we’ve also tracked additional versions of EvilTokens in circulation since January 2026 (many of which remain live along with the current “production” version of the kit). ",{"data":12151,"content":12152,"nodeType":876},{},[12153],{"data":12154,"marks":12155,"value":12156,"nodeType":867},{},[],"You can see an evolution of the kit in the videos and screenshots below, from early precursors seen in mid-January, the first mentions of ANTIBOT in the page code in late-January, the parallel development of a “Courts Access” fork that lacks the ANTIBOT references, and finally production EvilTokens in February. One of the key threads between the versions is the presence of a generateFallbackCode() JS function and use of a /generate-codes API call. ",{"data":12158,"content":12159,"nodeType":876},{},[12160],{"data":12161,"marks":12162,"value":12163,"nodeType":867},{},[],"Early implementations were quite different, for example using ScrapingBee to generate the displayed code, and varied hosting on vercel, fastly, edgeone, and others. ",{"data":12165,"content":12166,"nodeType":876},{},[12167],{"data":12168,"marks":12169,"value":12170,"nodeType":867},{},[],"After initially appearing on custom domains, the production version is now predominantly hosted on Cloudflare Workers, as per the broader tracking of the campaign. The descriptive HTML comments around ANTIBOT functions have also been removed in later versions. ",{"data":12172,"content":12173,"nodeType":876},{},[12174,12178,12186],{"data":12175,"marks":12176,"value":12177,"nodeType":867},{},[],"The production version of EvilTokens showcases common ",{"data":12179,"content":12180,"nodeType":915},{"uri":11281},[12181],{"data":12182,"marks":12183,"value":12185,"nodeType":867},{},[12184],{"type":913},"detection evasion techniques",{"data":12187,"marks":12188,"value":12189,"nodeType":867},{},[]," we've come to associate with PhaaS kits in the AiTM space — using multiple redirects through trusted sites before serving the malicious page, using bot protection to block security tools from analyzing the page, and so on. It also uses a pop-up window for the device code entry rather than a redirect, reducing the friction for the victim (it looks pretty convincing, too).",{"data":12191,"content":12195,"nodeType":985},{"target":12192},{"sys":12193},{"id":12194,"type":982,"linkType":983},"73rNOIEDPfP5IJwpFaxVc2",[],{"data":12197,"content":12201,"nodeType":985},{"target":12198},{"sys":12199},{"id":12200,"type":982,"linkType":983},"5BJSvOQUW9UpsQtoDNtgTC",[],{"data":12203,"content":12207,"nodeType":985},{"target":12204},{"sys":12205},{"id":12206,"type":982,"linkType":983},"3dbePPxVb4h4SauGg3glIL",[],{"data":12209,"content":12213,"nodeType":985},{"target":12210},{"sys":12211},{"id":12212,"type":982,"linkType":983},"1UOLcmNQvOsL5tdLSVuviq",[],{"data":12215,"content":12219,"nodeType":985},{"target":12216},{"sys":12217},{"id":12218,"type":982,"linkType":983},"55XRqLSwUUi2D4ZVpJboml",[],{"data":12221,"content":12225,"nodeType":985},{"target":12222},{"sys":12223},{"id":12224,"type":982,"linkType":983},"5wg5yr2Lo8t3f72ZV815c",[],{"data":12227,"content":12231,"nodeType":985},{"target":12228},{"sys":12229},{"id":12230,"type":982,"linkType":983},"35cowlL6i3rkGXOGmSxlI1",[],{"data":12233,"content":12234,"nodeType":876},{},[12235],{"data":12236,"marks":12237,"value":21,"nodeType":867},{},[],{"data":12239,"content":12240,"nodeType":7904},{},[12241,12265,12348,12400,12424],{"data":12242,"content":12243,"nodeType":7640},{},[12244,12255],{"data":12245,"content":12246,"nodeType":7628},{},[12247],{"data":12248,"content":12249,"nodeType":876},{},[12250],{"data":12251,"marks":12252,"value":12254,"nodeType":867},{},[12253],{"type":865},"Frontend infrastructure",{"data":12256,"content":12257,"nodeType":7628},{},[12258],{"data":12259,"content":12260,"nodeType":876},{},[12261],{"data":12262,"marks":12263,"value":12264,"nodeType":867},{},[],"Workers.dev, vercel.app, github.io, fastly.net, edgeone.dev",{"data":12266,"content":12267,"nodeType":7640},{},[12268,12279],{"data":12269,"content":12270,"nodeType":7628},{},[12271],{"data":12272,"content":12273,"nodeType":876},{},[12274],{"data":12275,"marks":12276,"value":12278,"nodeType":867},{},[12277],{"type":865},"Backend infrastructure",{"data":12280,"content":12281,"nodeType":7628},{},[12282,12312],{"data":12283,"content":12284,"nodeType":876},{},[12285,12290,12294,12299,12303,12308],{"data":12286,"marks":12287,"value":12289,"nodeType":867},{},[12288],{"type":865},"Example IP: (V3) ",{"data":12291,"marks":12292,"value":12293,"nodeType":867},{},[],"162.220.232.71 (Railway AS400940) ",{"data":12295,"marks":12296,"value":12298,"nodeType":867},{},[12297],{"type":865},"(V2)",{"data":12300,"marks":12301,"value":12302,"nodeType":867},{},[]," 71.11.42.193 ",{"data":12304,"marks":12305,"value":12307,"nodeType":867},{},[12306],{"type":865},"(V1) ",{"data":12309,"marks":12310,"value":12311,"nodeType":867},{},[],"72.218.25.107",{"data":12313,"content":12314,"nodeType":876},{},[12315,12320,12323,12328,12332,12336,12340,12344],{"data":12316,"marks":12317,"value":12319,"nodeType":867},{},[12318],{"type":865},"Backend User Agent:",{"data":12321,"marks":12322,"value":2136,"nodeType":867},{},[],{"data":12324,"marks":12325,"value":12327,"nodeType":867},{},[12326],{"type":865},"(V3) ",{"data":12329,"marks":12330,"value":12331,"nodeType":867},{},[],"node, ",{"data":12333,"marks":12334,"value":12298,"nodeType":867},{},[12335],{"type":865},{"data":12337,"marks":12338,"value":12339,"nodeType":867},{},[],", Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_4) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/73.0.3683 Safari/537.36 OPR/57.0.3098.91 ",{"data":12341,"marks":12342,"value":12307,"nodeType":867},{},[12343],{"type":865},{"data":12345,"marks":12346,"value":12347,"nodeType":867},{},[],"Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/71.0.3578.98 Safari/537.36 OPR/56.0.3051.52 ",{"data":12349,"content":12350,"nodeType":7640},{},[12351,12362],{"data":12352,"content":12353,"nodeType":7628},{},[12354],{"data":12355,"content":12356,"nodeType":876},{},[12357],{"data":12358,"marks":12359,"value":12361,"nodeType":867},{},[12360],{"type":865},"Network paths",{"data":12363,"content":12364,"nodeType":7628},{},[12365,12372,12379,12386,12393],{"data":12366,"content":12367,"nodeType":876},{},[12368],{"data":12369,"marks":12370,"value":12371,"nodeType":867},{},[],"/api/rate-limit ",{"data":12373,"content":12374,"nodeType":876},{},[12375],{"data":12376,"marks":12377,"value":12378,"nodeType":867},{},[],"/api/fingerprint ",{"data":12380,"content":12381,"nodeType":876},{},[12382],{"data":12383,"marks":12384,"value":12385,"nodeType":867},{},[],"/api/captcha-verify ",{"data":12387,"content":12388,"nodeType":876},{},[12389],{"data":12390,"marks":12391,"value":12392,"nodeType":867},{},[],"/api/init /api/generate-code ",{"data":12394,"content":12395,"nodeType":876},{},[12396],{"data":12397,"marks":12398,"value":12399,"nodeType":867},{},[],"/api/check-auth",{"data":12401,"content":12402,"nodeType":7640},{},[12403,12414],{"data":12404,"content":12405,"nodeType":7628},{},[12406],{"data":12407,"content":12408,"nodeType":876},{},[12409],{"data":12410,"marks":12411,"value":12413,"nodeType":867},{},[12412],{"type":865},"Lure themes",{"data":12415,"content":12416,"nodeType":7628},{},[12417],{"data":12418,"content":12419,"nodeType":876},{},[12420],{"data":12421,"marks":12422,"value":12423,"nodeType":867},{},[],"Various MS lures (e.g. Outlook, SharePoint, Teams) DocuSign, Adobe",{"data":12425,"content":12426,"nodeType":7640},{},[12427,12438],{"data":12428,"content":12429,"nodeType":7628},{},[12430],{"data":12431,"content":12432,"nodeType":876},{},[12433],{"data":12434,"marks":12435,"value":12437,"nodeType":867},{},[12436],{"type":865},"Example Domain",{"data":12439,"content":12440,"nodeType":7628},{},[12441,12453,12465,12477,12489],{"data":12442,"content":12443,"nodeType":876},{},[12444,12449],{"data":12445,"marks":12446,"value":12448,"nodeType":867},{},[12447],{"type":865},"Precursor A:",{"data":12450,"marks":12451,"value":12452,"nodeType":867},{},[]," teams-zpfvwnpxuc[.]edgeone.dev",{"data":12454,"content":12455,"nodeType":876},{},[12456,12461],{"data":12457,"marks":12458,"value":12460,"nodeType":867},{},[12459],{"type":865},"Precursor B: ",{"data":12462,"marks":12463,"value":12464,"nodeType":867},{},[],"authenticate-m365-accountsecurity-m-pi[.]vercel.app",{"data":12466,"content":12467,"nodeType":876},{},[12468,12473],{"data":12469,"marks":12470,"value":12472,"nodeType":867},{},[12471],{"type":865},"Courts Access: ",{"data":12474,"marks":12475,"value":12476,"nodeType":867},{},[],"secure-systems-validations-courts[.]vercel.app",{"data":12478,"content":12479,"nodeType":876},{},[12480,12485],{"data":12481,"marks":12482,"value":12484,"nodeType":867},{},[12483],{"type":865},"Early ANTIBOT:",{"data":12486,"marks":12487,"value":12488,"nodeType":867},{},[]," interface-auth-en-useast[.]global.ssl.fastly.net",{"data":12490,"content":12491,"nodeType":876},{},[12492,12497],{"data":12493,"marks":12494,"value":12496,"nodeType":867},{},[12495],{"type":865},"Production ANTIBOT: ",{"data":12498,"marks":12499,"value":12500,"nodeType":867},{},[],"index-z059-document-pending-reviewsign-xlss7994824[.]awalizer[.]workers.dev",{"data":12502,"content":12503,"nodeType":942},{},[],{"data":12505,"content":12506,"nodeType":1058},{},[12507],{"data":12508,"marks":12509,"value":12511,"nodeType":867},{},[12510],{"type":865},"“SHAREFILE”",{"data":12513,"content":12514,"nodeType":7904},{},[12515,12538,12577,12600,12623],{"data":12516,"content":12517,"nodeType":7640},{},[12518,12528],{"data":12519,"content":12520,"nodeType":7628},{},[12521],{"data":12522,"content":12523,"nodeType":876},{},[12524],{"data":12525,"marks":12526,"value":12254,"nodeType":867},{},[12527],{"type":865},{"data":12529,"content":12530,"nodeType":7628},{},[12531],{"data":12532,"content":12533,"nodeType":876},{},[12534],{"data":12535,"marks":12536,"value":12537,"nodeType":867},{},[],"No hosting markers visible.",{"data":12539,"content":12540,"nodeType":7640},{},[12541,12551],{"data":12542,"content":12543,"nodeType":7628},{},[12544],{"data":12545,"content":12546,"nodeType":876},{},[12547],{"data":12548,"marks":12549,"value":12278,"nodeType":867},{},[12550],{"type":865},{"data":12552,"content":12553,"nodeType":7628},{},[12554,12566],{"data":12555,"content":12556,"nodeType":876},{},[12557,12562],{"data":12558,"marks":12559,"value":12561,"nodeType":867},{},[12560],{"type":865},"Example IP:",{"data":12563,"marks":12564,"value":12565,"nodeType":867},{},[]," 147.45.60.47 (Global Connectivity Solutions LLP AS215540)",{"data":12567,"content":12568,"nodeType":876},{},[12569,12573],{"data":12570,"marks":12571,"value":12319,"nodeType":867},{},[12572],{"type":865},{"data":12574,"marks":12575,"value":12576,"nodeType":867},{},[]," node",{"data":12578,"content":12579,"nodeType":7640},{},[12580,12590],{"data":12581,"content":12582,"nodeType":7628},{},[12583],{"data":12584,"content":12585,"nodeType":876},{},[12586],{"data":12587,"marks":12588,"value":12361,"nodeType":867},{},[12589],{"type":865},{"data":12591,"content":12592,"nodeType":7628},{},[12593],{"data":12594,"content":12595,"nodeType":876},{},[12596],{"data":12597,"marks":12598,"value":12599,"nodeType":867},{},[],"POST /api/device/start  POST /api/device/poll",{"data":12601,"content":12602,"nodeType":7640},{},[12603,12613],{"data":12604,"content":12605,"nodeType":7628},{},[12606],{"data":12607,"content":12608,"nodeType":876},{},[12609],{"data":12610,"marks":12611,"value":12413,"nodeType":867},{},[12612],{"type":865},{"data":12614,"content":12615,"nodeType":7628},{},[12616],{"data":12617,"content":12618,"nodeType":876},{},[12619],{"data":12620,"marks":12621,"value":12622,"nodeType":867},{},[],"Citrix ShareFile document transfer — file card with sender info, expiry warning, download/preview buttons",{"data":12624,"content":12625,"nodeType":7640},{},[12626,12637],{"data":12627,"content":12628,"nodeType":7628},{},[12629],{"data":12630,"content":12631,"nodeType":876},{},[12632],{"data":12633,"marks":12634,"value":12636,"nodeType":867},{},[12635],{"type":865},"Example domain",{"data":12638,"content":12639,"nodeType":7628},{},[12640],{"data":12641,"content":12642,"nodeType":876},{},[12643],{"data":12644,"marks":12645,"value":12646,"nodeType":867},{},[],"cghdfg[.]vbchkioi[.]su",{"data":12648,"content":12652,"nodeType":985},{"target":12649},{"sys":12650},{"id":12651,"type":982,"linkType":983},"1TtZ6VsMSTlPvy7W996w9E",[],{"data":12654,"content":12655,"nodeType":942},{},[],{"data":12657,"content":12658,"nodeType":1058},{},[12659],{"data":12660,"marks":12661,"value":12663,"nodeType":867},{},[12662],{"type":865},"Kali365 (internal name “CLURE”)",{"data":12665,"content":12666,"nodeType":876},{},[12667,12671,12676,12680,12688,12692,12700],{"data":12668,"marks":12669,"value":12670,"nodeType":867},{},[],"Clure was recently linked to the ",{"data":12672,"marks":12673,"value":12675,"nodeType":867},{},[12674],{"type":865},"Kali365",{"data":12677,"marks":12678,"value":12679,"nodeType":867},{},[]," PhaaS platform based on an ",{"data":12681,"content":12683,"nodeType":915},{"uri":12682},"https://www.ic3.gov/PSA/2026/PSA260521",[12684],{"data":12685,"marks":12686,"value":12687,"nodeType":867},{},[],"FBI advisory",{"data":12689,"marks":12690,"value":12691,"nodeType":867},{},[]," and additional research from ",{"data":12693,"content":12695,"nodeType":915},{"uri":12694},"https://arcticwolf.com/resources/blog/token-bingo-dont-let-your-code-be-the-winner/",[12696],{"data":12697,"marks":12698,"value":12699,"nodeType":867},{},[],"Arctic Wolf",{"data":12701,"marks":12702,"value":12703,"nodeType":867},{},[],". This is yet another example of Device Code Phishing and AiTM phishing capabilities being integrated into unified phishing platforms. ",{"data":12705,"content":12706,"nodeType":7904},{},[12707,12730,12769,12792,12815],{"data":12708,"content":12709,"nodeType":7640},{},[12710,12720],{"data":12711,"content":12712,"nodeType":7628},{},[12713],{"data":12714,"content":12715,"nodeType":876},{},[12716],{"data":12717,"marks":12718,"value":12254,"nodeType":867},{},[12719],{"type":865},{"data":12721,"content":12722,"nodeType":7628},{},[12723],{"data":12724,"content":12725,"nodeType":876},{},[12726],{"data":12727,"marks":12728,"value":12729,"nodeType":867},{},[],"API on api.duemineral.uk:8443 and api.loadingdocuments.uk:8443 (rotates). ",{"data":12731,"content":12732,"nodeType":7640},{},[12733,12743],{"data":12734,"content":12735,"nodeType":7628},{},[12736],{"data":12737,"content":12738,"nodeType":876},{},[12739],{"data":12740,"marks":12741,"value":12278,"nodeType":867},{},[12742],{"type":865},{"data":12744,"content":12745,"nodeType":7628},{},[12746,12758],{"data":12747,"content":12748,"nodeType":876},{},[12749,12754],{"data":12750,"marks":12751,"value":12753,"nodeType":867},{},[12752],{"type":865},"Example IP: ",{"data":12755,"marks":12756,"value":12757,"nodeType":867},{},[],"162.243.166.119 (DigitalOcean AS14061)",{"data":12759,"content":12760,"nodeType":876},{},[12761,12765],{"data":12762,"marks":12763,"value":12319,"nodeType":867},{},[12764],{"type":865},{"data":12766,"marks":12767,"value":12768,"nodeType":867},{},[]," python-requests/2.32.5",{"data":12770,"content":12771,"nodeType":7640},{},[12772,12782],{"data":12773,"content":12774,"nodeType":7628},{},[12775],{"data":12776,"content":12777,"nodeType":876},{},[12778],{"data":12779,"marks":12780,"value":12361,"nodeType":867},{},[12781],{"type":865},{"data":12783,"content":12784,"nodeType":7628},{},[12785],{"data":12786,"content":12787,"nodeType":876},{},[12788],{"data":12789,"marks":12790,"value":12791,"nodeType":867},{},[],"GET /api/status/{numeric_SID} (port :8443)",{"data":12793,"content":12794,"nodeType":7640},{},[12795,12805],{"data":12796,"content":12797,"nodeType":7628},{},[12798],{"data":12799,"content":12800,"nodeType":876},{},[12801],{"data":12802,"marks":12803,"value":12413,"nodeType":867},{},[12804],{"type":865},{"data":12806,"content":12807,"nodeType":7628},{},[12808],{"data":12809,"content":12810,"nodeType":876},{},[12811],{"data":12812,"marks":12813,"value":12814,"nodeType":867},{},[],"SharePoint \"Team Site\" doc library, SharePoint \"Shared Document\" individual share",{"data":12816,"content":12817,"nodeType":7640},{},[12818,12828],{"data":12819,"content":12820,"nodeType":7628},{},[12821],{"data":12822,"content":12823,"nodeType":876},{},[12824],{"data":12825,"marks":12826,"value":12636,"nodeType":867},{},[12827],{"type":865},{"data":12829,"content":12830,"nodeType":7628},{},[12831],{"data":12832,"content":12833,"nodeType":876},{},[12834],{"data":12835,"marks":12836,"value":12837,"nodeType":867},{},[],"auth[.]duemineral[.]uk",{"data":12839,"content":12843,"nodeType":985},{"target":12840},{"sys":12841},{"id":12842,"type":982,"linkType":983},"Y1AiT3dJRTXz64pb68kca",[],{"data":12845,"content":12846,"nodeType":942},{},[],{"data":12848,"content":12849,"nodeType":1058},{},[12850],{"data":12851,"marks":12852,"value":12854,"nodeType":867},{},[12853],{"type":865},"“LINKID”",{"data":12856,"content":12857,"nodeType":7904},{},[12858,12881,12926,12956,12979],{"data":12859,"content":12860,"nodeType":7640},{},[12861,12871],{"data":12862,"content":12863,"nodeType":7628},{},[12864],{"data":12865,"content":12866,"nodeType":876},{},[12867],{"data":12868,"marks":12869,"value":12254,"nodeType":867},{},[12870],{"type":865},{"data":12872,"content":12873,"nodeType":7628},{},[12874],{"data":12875,"content":12876,"nodeType":876},{},[12877],{"data":12878,"marks":12879,"value":12880,"nodeType":867},{},[],"Adobe variant has Cloudflare challenge-platform iframe (CF-protected origin). Relative API paths — self-hosted.",{"data":12882,"content":12883,"nodeType":7640},{},[12884,12894],{"data":12885,"content":12886,"nodeType":7628},{},[12887],{"data":12888,"content":12889,"nodeType":876},{},[12890],{"data":12891,"marks":12892,"value":12278,"nodeType":867},{},[12893],{"type":865},{"data":12895,"content":12896,"nodeType":7628},{},[12897,12908,12915],{"data":12898,"content":12899,"nodeType":876},{},[12900,12904],{"data":12901,"marks":12902,"value":12753,"nodeType":867},{},[12903],{"type":865},{"data":12905,"marks":12906,"value":12907,"nodeType":867},{},[],"185.176.220.22 (2cloud.eu AS39845)",{"data":12909,"content":12910,"nodeType":876},{},[12911],{"data":12912,"marks":12913,"value":12914,"nodeType":867},{},[],"2600:1f10:470d:9a00:1437:ec30:be61:3494 (AWS AS16509)",{"data":12916,"content":12917,"nodeType":876},{},[12918,12922],{"data":12919,"marks":12920,"value":12319,"nodeType":867},{},[12921],{"type":865},{"data":12923,"marks":12924,"value":12925,"nodeType":867},{},[]," axios/1.10.0 , axios/1.13.6",{"data":12927,"content":12928,"nodeType":7640},{},[12929,12939],{"data":12930,"content":12931,"nodeType":7628},{},[12932],{"data":12933,"content":12934,"nodeType":876},{},[12935],{"data":12936,"marks":12937,"value":12361,"nodeType":867},{},[12938],{"type":865},{"data":12940,"content":12941,"nodeType":7628},{},[12942,12949],{"data":12943,"content":12944,"nodeType":876},{},[12945],{"data":12946,"marks":12947,"value":12948,"nodeType":867},{},[],"POST /api/device/start",{"data":12950,"content":12951,"nodeType":876},{},[12952],{"data":12953,"marks":12954,"value":12955,"nodeType":867},{},[],"GET /api/device/status/{sessionId}",{"data":12957,"content":12958,"nodeType":7640},{},[12959,12969],{"data":12960,"content":12961,"nodeType":7628},{},[12962],{"data":12963,"content":12964,"nodeType":876},{},[12965],{"data":12966,"marks":12967,"value":12413,"nodeType":867},{},[12968],{"type":865},{"data":12970,"content":12971,"nodeType":7628},{},[12972],{"data":12973,"content":12974,"nodeType":876},{},[12975],{"data":12976,"marks":12977,"value":12978,"nodeType":867},{},[],"MS Teams meeting invitation (with interactive date/time picker), Adobe Acrobat Sign document review",{"data":12980,"content":12981,"nodeType":7640},{},[12982,12992],{"data":12983,"content":12984,"nodeType":7628},{},[12985],{"data":12986,"content":12987,"nodeType":876},{},[12988],{"data":12989,"marks":12990,"value":12636,"nodeType":867},{},[12991],{"type":865},{"data":12993,"content":12994,"nodeType":7628},{},[12995],{"data":12996,"content":12997,"nodeType":876},{},[12998],{"data":12999,"marks":13000,"value":13001,"nodeType":867},{},[],"sdtr-site[.]cfd",{"data":13003,"content":13007,"nodeType":985},{"target":13004},{"sys":13005},{"id":13006,"type":982,"linkType":983},"22hsIzlkptC2JTIUtbOuUn",[],{"data":13009,"content":13010,"nodeType":942},{},[],{"data":13012,"content":13013,"nodeType":1058},{},[13014],{"data":13015,"marks":13016,"value":13018,"nodeType":867},{},[13017],{"type":865},"Device Code Lab (formerly codename \"AUTHOV”)",{"data":13020,"content":13024,"nodeType":985},{"target":13021},{"sys":13022},{"id":13023,"type":982,"linkType":983},"5vllVaa0Ry0wKs46ssrZLC",[],{"data":13026,"content":13027,"nodeType":7904},{},[13028,13051,13096,13119,13142],{"data":13029,"content":13030,"nodeType":7640},{},[13031,13041],{"data":13032,"content":13033,"nodeType":7628},{},[13034],{"data":13035,"content":13036,"nodeType":876},{},[13037],{"data":13038,"marks":13039,"value":12254,"nodeType":867},{},[13040],{"type":865},{"data":13042,"content":13043,"nodeType":7628},{},[13044],{"data":13045,"content":13046,"nodeType":876},{},[13047],{"data":13048,"marks":13049,"value":13050,"nodeType":867},{},[],"workers.dev",{"data":13052,"content":13053,"nodeType":7640},{},[13054,13064],{"data":13055,"content":13056,"nodeType":7628},{},[13057],{"data":13058,"content":13059,"nodeType":876},{},[13060],{"data":13061,"marks":13062,"value":12278,"nodeType":867},{},[13063],{"type":865},{"data":13065,"content":13066,"nodeType":7628},{},[13067,13078],{"data":13068,"content":13069,"nodeType":876},{},[13070,13074],{"data":13071,"marks":13072,"value":12753,"nodeType":867},{},[13073],{"type":865},{"data":13075,"marks":13076,"value":13077,"nodeType":867},{},[],"192.3.225.100 (HostPapa / ColoCrossing AS36352)",{"data":13079,"content":13080,"nodeType":876},{},[13081,13085,13088,13092],{"data":13082,"marks":13083,"value":12319,"nodeType":867},{},[13084],{"type":865},{"data":13086,"marks":13087,"value":2136,"nodeType":867},{},[],{"data":13089,"marks":13090,"value":2167,"nodeType":867},{},[13091],{"type":865},{"data":13093,"marks":13094,"value":13095,"nodeType":867},{},[],"python-httpx/0.28.1",{"data":13097,"content":13098,"nodeType":7640},{},[13099,13109],{"data":13100,"content":13101,"nodeType":7628},{},[13102],{"data":13103,"content":13104,"nodeType":876},{},[13105],{"data":13106,"marks":13107,"value":12361,"nodeType":867},{},[13108],{"type":865},{"data":13110,"content":13111,"nodeType":7628},{},[13112],{"data":13113,"content":13114,"nodeType":876},{},[13115],{"data":13116,"marks":13117,"value":13118,"nodeType":867},{},[],"GET /landing/api/session-status?session_id=&token=",{"data":13120,"content":13121,"nodeType":7640},{},[13122,13132],{"data":13123,"content":13124,"nodeType":7628},{},[13125],{"data":13126,"content":13127,"nodeType":876},{},[13128],{"data":13129,"marks":13130,"value":12413,"nodeType":867},{},[13131],{"type":865},{"data":13133,"content":13134,"nodeType":7628},{},[13135],{"data":13136,"content":13137,"nodeType":876},{},[13138],{"data":13139,"marks":13140,"value":13141,"nodeType":867},{},[],"Adobe Acrobat document sharing (PDF preview, sender avatar)",{"data":13143,"content":13144,"nodeType":7640},{},[13145,13155],{"data":13146,"content":13147,"nodeType":7628},{},[13148],{"data":13149,"content":13150,"nodeType":876},{},[13151],{"data":13152,"marks":13153,"value":12636,"nodeType":867},{},[13154],{"type":865},{"data":13156,"content":13157,"nodeType":7628},{},[13158],{"data":13159,"content":13160,"nodeType":876},{},[13161],{"data":13162,"marks":13163,"value":13164,"nodeType":867},{},[],"milosh-solibella-0dcio[.]sgttommy.workers.dev",{"data":13166,"content":13170,"nodeType":985},{"target":13167},{"sys":13168},{"id":13169,"type":982,"linkType":983},"6szO6IKJ32usyxIKX1efZy",[],{"data":13172,"content":13176,"nodeType":985},{"target":13173},{"sys":13174},{"id":13175,"type":982,"linkType":983},"lEqV3RTMIY8y011lnhX7P",[],{"data":13178,"content":13179,"nodeType":942},{},[],{"data":13181,"content":13182,"nodeType":1058},{},[13183],{"data":13184,"marks":13185,"value":13187,"nodeType":867},{},[13186],{"type":865},"“DOCUPOLL”",{"data":13189,"content":13190,"nodeType":7904},{},[13191,13214,13252,13289,13312],{"data":13192,"content":13193,"nodeType":7640},{},[13194,13204],{"data":13195,"content":13196,"nodeType":7628},{},[13197],{"data":13198,"content":13199,"nodeType":876},{},[13200],{"data":13201,"marks":13202,"value":12254,"nodeType":867},{},[13203],{"type":865},{"data":13205,"content":13206,"nodeType":7628},{},[13207],{"data":13208,"content":13209,"nodeType":876},{},[13210],{"data":13211,"marks":13212,"value":13213,"nodeType":867},{},[],"Github.io and workers.dev hosting",{"data":13215,"content":13216,"nodeType":7640},{},[13217,13227],{"data":13218,"content":13219,"nodeType":7628},{},[13220],{"data":13221,"content":13222,"nodeType":876},{},[13223],{"data":13224,"marks":13225,"value":12278,"nodeType":867},{},[13226],{"type":865},{"data":13228,"content":13229,"nodeType":7628},{},[13230,13241],{"data":13231,"content":13232,"nodeType":876},{},[13233,13237],{"data":13234,"marks":13235,"value":12753,"nodeType":867},{},[13236],{"type":865},{"data":13238,"marks":13239,"value":13240,"nodeType":867},{},[],"144.172.103.240 (FranTech Solutions / RouterHosting / Cloudzy AS14956)",{"data":13242,"content":13243,"nodeType":876},{},[13244,13248],{"data":13245,"marks":13246,"value":12319,"nodeType":867},{},[13247],{"type":865},{"data":13249,"marks":13250,"value":13251,"nodeType":867},{},[]," Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.102 Safari/537.36 Edge/18.19042",{"data":13253,"content":13254,"nodeType":7640},{},[13255,13265],{"data":13256,"content":13257,"nodeType":7628},{},[13258],{"data":13259,"content":13260,"nodeType":876},{},[13261],{"data":13262,"marks":13263,"value":12361,"nodeType":867},{},[13264],{"type":865},{"data":13266,"content":13267,"nodeType":7628},{},[13268,13275,13282],{"data":13269,"content":13270,"nodeType":876},{},[13271],{"data":13272,"marks":13273,"value":13274,"nodeType":867},{},[],"POST /api/v1/landing-pages/public/{slug}/init",{"data":13276,"content":13277,"nodeType":876},{},[13278],{"data":13279,"marks":13280,"value":13281,"nodeType":867},{},[],"POST .../poll",{"data":13283,"content":13284,"nodeType":876},{},[13285],{"data":13286,"marks":13287,"value":13288,"nodeType":867},{},[],"POST .../track",{"data":13290,"content":13291,"nodeType":7640},{},[13292,13302],{"data":13293,"content":13294,"nodeType":7628},{},[13295],{"data":13296,"content":13297,"nodeType":876},{},[13298],{"data":13299,"marks":13300,"value":12413,"nodeType":867},{},[13301],{"type":865},{"data":13303,"content":13304,"nodeType":7628},{},[13305],{"data":13306,"content":13307,"nodeType":876},{},[13308],{"data":13309,"marks":13310,"value":13311,"nodeType":867},{},[],"DocuSign document signing. One sample is a full scrape of real docusign.com (free-account page) with kit injected.",{"data":13313,"content":13314,"nodeType":7640},{},[13315,13325],{"data":13316,"content":13317,"nodeType":7628},{},[13318],{"data":13319,"content":13320,"nodeType":876},{},[13321],{"data":13322,"marks":13323,"value":12636,"nodeType":867},{},[13324],{"type":865},{"data":13326,"content":13327,"nodeType":7628},{},[13328],{"data":13329,"content":13330,"nodeType":876},{},[13331],{"data":13332,"marks":13333,"value":13334,"nodeType":867},{},[],"docufirmar[.]github.io",{"data":13336,"content":13340,"nodeType":985},{"target":13337},{"sys":13338},{"id":13339,"type":982,"linkType":983},"6Y1XABHnQD82R3MW80HnQZ",[],{"data":13342,"content":13343,"nodeType":942},{},[],{"data":13345,"content":13346,"nodeType":1058},{},[13347],{"data":13348,"marks":13349,"value":13351,"nodeType":867},{},[13350],{"type":865},"“FLOW_TOKEN”",{"data":13353,"content":13354,"nodeType":7904},{},[13355,13377,13422,13452,13475],{"data":13356,"content":13357,"nodeType":7640},{},[13358,13368],{"data":13359,"content":13360,"nodeType":7628},{},[13361],{"data":13362,"content":13363,"nodeType":876},{},[13364],{"data":13365,"marks":13366,"value":12254,"nodeType":867},{},[13367],{"type":865},{"data":13369,"content":13370,"nodeType":7628},{},[13371],{"data":13372,"content":13373,"nodeType":876},{},[13374],{"data":13375,"marks":13376,"value":13050,"nodeType":867},{},[],{"data":13378,"content":13379,"nodeType":7640},{},[13380,13390],{"data":13381,"content":13382,"nodeType":7628},{},[13383],{"data":13384,"content":13385,"nodeType":876},{},[13386],{"data":13387,"marks":13388,"value":12278,"nodeType":867},{},[13389],{"type":865},{"data":13391,"content":13392,"nodeType":7628},{},[13393,13404],{"data":13394,"content":13395,"nodeType":876},{},[13396,13400],{"data":13397,"marks":13398,"value":12753,"nodeType":867},{},[13399],{"type":865},{"data":13401,"marks":13402,"value":13403,"nodeType":867},{},[],"43.166.163.163 (Tencent Cloud AS132203)",{"data":13405,"content":13406,"nodeType":876},{},[13407,13411,13414,13418],{"data":13408,"marks":13409,"value":12319,"nodeType":867},{},[13410],{"type":865},{"data":13412,"marks":13413,"value":2136,"nodeType":867},{},[],{"data":13415,"marks":13416,"value":2167,"nodeType":867},{},[13417],{"type":865},{"data":13419,"marks":13420,"value":13421,"nodeType":867},{},[],"(null)",{"data":13423,"content":13424,"nodeType":7640},{},[13425,13435],{"data":13426,"content":13427,"nodeType":7628},{},[13428],{"data":13429,"content":13430,"nodeType":876},{},[13431],{"data":13432,"marks":13433,"value":12361,"nodeType":867},{},[13434],{"type":865},{"data":13436,"content":13437,"nodeType":7628},{},[13438,13445],{"data":13439,"content":13440,"nodeType":876},{},[13441],{"data":13442,"marks":13443,"value":13444,"nodeType":867},{},[],"POST /api/handler.php ",{"data":13446,"content":13447,"nodeType":876},{},[13448],{"data":13449,"marks":13450,"value":13451,"nodeType":867},{},[],"(actions: device_code_generate, device_code_poll_public)",{"data":13453,"content":13454,"nodeType":7640},{},[13455,13465],{"data":13456,"content":13457,"nodeType":7628},{},[13458],{"data":13459,"content":13460,"nodeType":876},{},[13461],{"data":13462,"marks":13463,"value":12413,"nodeType":867},{},[13464],{"type":865},{"data":13466,"content":13467,"nodeType":7628},{},[13468],{"data":13469,"content":13470,"nodeType":876},{},[13471],{"data":13472,"marks":13473,"value":13474,"nodeType":867},{},[],"DocuSign \"Salary Adjustment Document — 2026\", Microsoft banner · HR Department sender",{"data":13476,"content":13477,"nodeType":7640},{},[13478,13488],{"data":13479,"content":13480,"nodeType":7628},{},[13481],{"data":13482,"content":13483,"nodeType":876},{},[13484],{"data":13485,"marks":13486,"value":12636,"nodeType":867},{},[13487],{"type":865},{"data":13489,"content":13490,"nodeType":7628},{},[13491],{"data":13492,"content":13493,"nodeType":876},{},[13494],{"data":13495,"marks":13496,"value":13497,"nodeType":867},{},[],"salaryadjustment-2afb52.pmb6fefc52b3f9aa5c2dbf[.]workers.dev",{"data":13499,"content":13503,"nodeType":985},{"target":13500},{"sys":13501},{"id":13502,"type":982,"linkType":983},"6xiTDHStbiJh7LMhjAZcPd",[],{"data":13505,"content":13506,"nodeType":942},{},[],{"data":13508,"content":13509,"nodeType":1058},{},[13510],{"data":13511,"marks":13512,"value":13514,"nodeType":867},{},[13513],{"type":865},"“PAPRIKA”",{"data":13516,"content":13517,"nodeType":7904},{},[13518,13541,13564,13587],{"data":13519,"content":13520,"nodeType":7640},{},[13521,13531],{"data":13522,"content":13523,"nodeType":7628},{},[13524],{"data":13525,"content":13526,"nodeType":876},{},[13527],{"data":13528,"marks":13529,"value":12254,"nodeType":867},{},[13530],{"type":865},{"data":13532,"content":13533,"nodeType":7628},{},[13534],{"data":13535,"content":13536,"nodeType":876},{},[13537],{"data":13538,"marks":13539,"value":13540,"nodeType":867},{},[],"AWS S3 hosting",{"data":13542,"content":13543,"nodeType":7640},{},[13544,13554],{"data":13545,"content":13546,"nodeType":7628},{},[13547],{"data":13548,"content":13549,"nodeType":876},{},[13550],{"data":13551,"marks":13552,"value":12361,"nodeType":867},{},[13553],{"type":865},{"data":13555,"content":13556,"nodeType":7628},{},[13557],{"data":13558,"content":13559,"nodeType":876},{},[13560],{"data":13561,"marks":13562,"value":13563,"nodeType":867},{},[],"POST /api/v1/loader",{"data":13565,"content":13566,"nodeType":7640},{},[13567,13577],{"data":13568,"content":13569,"nodeType":7628},{},[13570],{"data":13571,"content":13572,"nodeType":876},{},[13573],{"data":13574,"marks":13575,"value":12413,"nodeType":867},{},[13576],{"type":865},{"data":13578,"content":13579,"nodeType":7628},{},[13580],{"data":13581,"content":13582,"nodeType":876},{},[13583],{"data":13584,"marks":13585,"value":13586,"nodeType":867},{},[],"MS login clone (\"Sign in to your account\"), \"Office 365\" branding, fake \"Powered by Okta\" footer",{"data":13588,"content":13589,"nodeType":7640},{},[13590,13600],{"data":13591,"content":13592,"nodeType":7628},{},[13593],{"data":13594,"content":13595,"nodeType":876},{},[13596],{"data":13597,"marks":13598,"value":12636,"nodeType":867},{},[13599],{"type":865},{"data":13601,"content":13602,"nodeType":7628},{},[13603],{"data":13604,"content":13605,"nodeType":876},{},[13606],{"data":13607,"marks":13608,"value":13609,"nodeType":867},{},[],"redirect-523346-d95027ec[.]s3.amazonaws.com",{"data":13611,"content":13615,"nodeType":985},{"target":13612},{"sys":13613},{"id":13614,"type":982,"linkType":983},"6WFXqUDzcJHKWSwVIcDZAf",[],{"data":13617,"content":13618,"nodeType":942},{},[],{"data":13620,"content":13621,"nodeType":1058},{},[13622],{"data":13623,"marks":13624,"value":13626,"nodeType":867},{},[13625],{"type":865},"“DCSTATUS”",{"data":13628,"content":13629,"nodeType":7904},{},[13630,13652,13675,13698],{"data":13631,"content":13632,"nodeType":7640},{},[13633,13643],{"data":13634,"content":13635,"nodeType":7628},{},[13636],{"data":13637,"content":13638,"nodeType":876},{},[13639],{"data":13640,"marks":13641,"value":12254,"nodeType":867},{},[13642],{"type":865},{"data":13644,"content":13645,"nodeType":7628},{},[13646],{"data":13647,"content":13648,"nodeType":876},{},[13649],{"data":13650,"marks":13651,"value":12537,"nodeType":867},{},[],{"data":13653,"content":13654,"nodeType":7640},{},[13655,13665],{"data":13656,"content":13657,"nodeType":7628},{},[13658],{"data":13659,"content":13660,"nodeType":876},{},[13661],{"data":13662,"marks":13663,"value":12361,"nodeType":867},{},[13664],{"type":865},{"data":13666,"content":13667,"nodeType":7628},{},[13668],{"data":13669,"content":13670,"nodeType":876},{},[13671],{"data":13672,"marks":13673,"value":13674,"nodeType":867},{},[],"GET /dc/status/{base64url_sid}",{"data":13676,"content":13677,"nodeType":7640},{},[13678,13688],{"data":13679,"content":13680,"nodeType":7628},{},[13681],{"data":13682,"content":13683,"nodeType":876},{},[13684],{"data":13685,"marks":13686,"value":12413,"nodeType":867},{},[13687],{"type":865},{"data":13689,"content":13690,"nodeType":7628},{},[13691],{"data":13692,"content":13693,"nodeType":876},{},[13694],{"data":13695,"marks":13696,"value":13697,"nodeType":867},{},[],"Generic \"Microsoft 365 - Secure Access\" verification page",{"data":13699,"content":13700,"nodeType":7640},{},[13701,13711],{"data":13702,"content":13703,"nodeType":7628},{},[13704],{"data":13705,"content":13706,"nodeType":876},{},[13707],{"data":13708,"marks":13709,"value":12636,"nodeType":867},{},[13710],{"type":865},{"data":13712,"content":13713,"nodeType":7628},{},[13714],{"data":13715,"content":13716,"nodeType":876},{},[13717],{"data":13718,"marks":13719,"value":13720,"nodeType":867},{},[],"owa[.]apmmacleans[.]ca",{"data":13722,"content":13726,"nodeType":985},{"target":13723},{"sys":13724},{"id":13725,"type":982,"linkType":983},"ugYhHeXY1lQdKooALmrIs",[],{"data":13728,"content":13729,"nodeType":942},{},[],{"data":13731,"content":13732,"nodeType":1058},{},[13733],{"data":13734,"marks":13735,"value":13737,"nodeType":867},{},[13736],{"type":865},"“DOLCE”",{"data":13739,"content":13743,"nodeType":985},{"target":13740},{"sys":13741},{"id":13742,"type":982,"linkType":983},"7TzU6kk01Un45NB0buEz2",[],{"data":13745,"content":13746,"nodeType":7904},{},[13747,13770,13808,13831,13854],{"data":13748,"content":13749,"nodeType":7640},{},[13750,13760],{"data":13751,"content":13752,"nodeType":7628},{},[13753],{"data":13754,"content":13755,"nodeType":876},{},[13756],{"data":13757,"marks":13758,"value":12254,"nodeType":867},{},[13759],{"type":865},{"data":13761,"content":13762,"nodeType":7628},{},[13763],{"data":13764,"content":13765,"nodeType":876},{},[13766],{"data":13767,"marks":13768,"value":13769,"nodeType":867},{},[],"Microsoft PowerApps hosting",{"data":13771,"content":13772,"nodeType":7640},{},[13773,13783],{"data":13774,"content":13775,"nodeType":7628},{},[13776],{"data":13777,"content":13778,"nodeType":876},{},[13779],{"data":13780,"marks":13781,"value":12278,"nodeType":867},{},[13782],{"type":865},{"data":13784,"content":13785,"nodeType":7628},{},[13786,13797],{"data":13787,"content":13788,"nodeType":876},{},[13789,13793],{"data":13790,"marks":13791,"value":12753,"nodeType":867},{},[13792],{"type":865},{"data":13794,"marks":13795,"value":13796,"nodeType":867},{},[],"34.53.159.84 (Google Cloud AS396982)",{"data":13798,"content":13799,"nodeType":876},{},[13800,13804],{"data":13801,"marks":13802,"value":12319,"nodeType":867},{},[13803],{"type":865},{"data":13805,"marks":13806,"value":13807,"nodeType":867},{},[]," Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/123.0.0.0 Safari/537.36",{"data":13809,"content":13810,"nodeType":7640},{},[13811,13821],{"data":13812,"content":13813,"nodeType":7628},{},[13814],{"data":13815,"content":13816,"nodeType":876},{},[13817],{"data":13818,"marks":13819,"value":12361,"nodeType":867},{},[13820],{"type":865},{"data":13822,"content":13823,"nodeType":7628},{},[13824],{"data":13825,"content":13826,"nodeType":876},{},[13827],{"data":13828,"marks":13829,"value":13830,"nodeType":867},{},[],"GET /api/generatecode (CloudFront)",{"data":13832,"content":13833,"nodeType":7640},{},[13834,13844],{"data":13835,"content":13836,"nodeType":7628},{},[13837],{"data":13838,"content":13839,"nodeType":876},{},[13840],{"data":13841,"marks":13842,"value":12413,"nodeType":867},{},[13843],{"type":865},{"data":13845,"content":13846,"nodeType":7628},{},[13847],{"data":13848,"content":13849,"nodeType":876},{},[13850],{"data":13851,"marks":13852,"value":13853,"nodeType":867},{},[],"Dolce & Gabbana branded, Italian language, MS account verification",{"data":13855,"content":13856,"nodeType":7640},{},[13857,13867],{"data":13858,"content":13859,"nodeType":7628},{},[13860],{"data":13861,"content":13862,"nodeType":876},{},[13863],{"data":13864,"marks":13865,"value":12636,"nodeType":867},{},[13866],{"type":865},{"data":13868,"content":13869,"nodeType":7628},{},[13870],{"data":13871,"content":13872,"nodeType":876},{},[13873],{"data":13874,"marks":13875,"value":13876,"nodeType":867},{},[],"data-migration-dolcegabbana[.]powerappsportals.com",{"data":13878,"content":13882,"nodeType":985},{"target":13879},{"sys":13880},{"id":13881,"type":982,"linkType":983},"4ayQDvpf5NNOBrj9wZZRiO",[],{"data":13884,"content":13885,"nodeType":942},{},[],{"data":13887,"content":13888,"nodeType":1058},{},[13889],{"data":13890,"marks":13891,"value":13893,"nodeType":867},{},[13892],{"type":865},"Venom",{"data":13895,"content":13896,"nodeType":7904},{},[13897,13920],{"data":13898,"content":13899,"nodeType":7640},{},[13900,13910],{"data":13901,"content":13902,"nodeType":7628},{},[13903],{"data":13904,"content":13905,"nodeType":876},{},[13906],{"data":13907,"marks":13908,"value":12361,"nodeType":867},{},[13909],{"type":865},{"data":13911,"content":13912,"nodeType":7628},{},[13913],{"data":13914,"content":13915,"nodeType":876},{},[13916],{"data":13917,"marks":13918,"value":13919,"nodeType":867},{},[],"POST /token/api/device/start\nGET /token/api/device/status/{sessionId}",{"data":13921,"content":13922,"nodeType":7640},{},[13923,13933],{"data":13924,"content":13925,"nodeType":7628},{},[13926],{"data":13927,"content":13928,"nodeType":876},{},[13929],{"data":13930,"marks":13931,"value":12413,"nodeType":867},{},[13932],{"type":865},{"data":13934,"content":13935,"nodeType":7628},{},[13936],{"data":13937,"content":13938,"nodeType":876},{},[13939],{"data":13940,"marks":13941,"value":13942,"nodeType":867},{},[],"Various: examples include DocuSign \"Verification\" (Microsoft sign-in pretext); DHL \"Delivery Checkpoint\" package shipment pretext",{"data":13944,"content":13948,"nodeType":985},{"target":13945},{"sys":13946},{"id":13947,"type":982,"linkType":983},"79C3fces0hgTdf3G68cIrf",[],{"data":13950,"content":13951,"nodeType":942},{},[],{"data":13953,"content":13954,"nodeType":1058},{},[13955],{"data":13956,"marks":13957,"value":13959,"nodeType":867},{},[13958],{"type":865},"Tycoon2FA",{"data":13961,"content":13962,"nodeType":7904},{},[13963,13993,14030,14053,14076],{"data":13964,"content":13965,"nodeType":7640},{},[13966,13976],{"data":13967,"content":13968,"nodeType":7628},{},[13969],{"data":13970,"content":13971,"nodeType":876},{},[13972],{"data":13973,"marks":13974,"value":12254,"nodeType":867},{},[13975],{"type":865},{"data":13977,"content":13978,"nodeType":7628},{},[13979,13986],{"data":13980,"content":13981,"nodeType":876},{},[13982],{"data":13983,"marks":13984,"value":13985,"nodeType":867},{},[],"Github.io and Cloudflare Workers (workers.dev) hosting",{"data":13987,"content":13988,"nodeType":876},{},[13989],{"data":13990,"marks":13991,"value":13992,"nodeType":867},{},[],"Compromised-site landing pages and CF Workers (*.workers.dev) used as frontends; victim email passed in URL as last path segment ($base64) or ?acct/?encoded query",{"data":13994,"content":13995,"nodeType":7640},{},[13996,14006],{"data":13997,"content":13998,"nodeType":7628},{},[13999],{"data":14000,"content":14001,"nodeType":876},{},[14002],{"data":14003,"marks":14004,"value":12278,"nodeType":867},{},[14005],{"type":865},{"data":14007,"content":14008,"nodeType":7628},{},[14009,14020],{"data":14010,"content":14011,"nodeType":876},{},[14012,14016],{"data":14013,"marks":14014,"value":12753,"nodeType":867},{},[14015],{"type":865},{"data":14017,"marks":14018,"value":14019,"nodeType":867},{},[],"47.253.5.88 (Alibaba Cloud)",{"data":14021,"content":14022,"nodeType":876},{},[14023,14027],{"data":14024,"marks":14025,"value":12319,"nodeType":867},{},[14026],{"type":865},{"data":14028,"marks":14029,"value":12576,"nodeType":867},{},[],{"data":14031,"content":14032,"nodeType":7640},{},[14033,14043],{"data":14034,"content":14035,"nodeType":7628},{},[14036],{"data":14037,"content":14038,"nodeType":876},{},[14039],{"data":14040,"marks":14041,"value":12361,"nodeType":867},{},[14042],{"type":865},{"data":14044,"content":14045,"nodeType":7628},{},[14046],{"data":14047,"content":14048,"nodeType":876},{},[14049],{"data":14050,"marks":14051,"value":14052,"nodeType":867},{},[],"GET /api/session/{UUIDv4} polled with header X-API-Key: \u003Cprefix>_\u003C64-hex> (key materialised at runtime via atob(window.__cyb3r.k)) \nPOST /api/device-code with body {\"prt_foci_session_id\": \"\u003CUUID>\"} (second-stage code retrieval after initial session error)",{"data":14054,"content":14055,"nodeType":7640},{},[14056,14066],{"data":14057,"content":14058,"nodeType":7628},{},[14059],{"data":14060,"content":14061,"nodeType":876},{},[14062],{"data":14063,"marks":14064,"value":12413,"nodeType":867},{},[14065],{"type":865},{"data":14067,"content":14068,"nodeType":7628},{},[14069],{"data":14070,"content":14071,"nodeType":876},{},[14072],{"data":14073,"marks":14074,"value":14075,"nodeType":867},{},[],"Various: SharePoint \"Remittance Advice\"; Microsoft 365 generic sign-in; Microsoft 365 Voicemail (.mp3 attachment); OneDrive \"Shared file\"; German \"Sicheres Dokumentenportal\" PDF lure",{"data":14077,"content":14078,"nodeType":7640},{},[14079,14089],{"data":14080,"content":14081,"nodeType":7628},{},[14082],{"data":14083,"content":14084,"nodeType":876},{},[14085],{"data":14086,"marks":14087,"value":12636,"nodeType":867},{},[14088],{"type":865},{"data":14090,"content":14091,"nodeType":7628},{},[14092],{"data":14093,"content":14094,"nodeType":876},{},[14095],{"data":14096,"marks":14097,"value":14098,"nodeType":867},{},[],"afriqbeauglobal[.]com/homepage/index[.]html",{"data":14100,"content":14103,"nodeType":985},{"target":14101},{"sys":14102},{"id":3554,"type":982,"linkType":983},[],{"data":14105,"content":14106,"nodeType":942},{},[],{"data":14108,"content":14109,"nodeType":1058},{},[14110],{"data":14111,"marks":14112,"value":14114,"nodeType":867},{},[14113],{"type":865},"\"CYB3R\"",{"data":14116,"content":14117,"nodeType":7904},{},[14118,14141,14179,14201,14224],{"data":14119,"content":14120,"nodeType":7640},{},[14121,14131],{"data":14122,"content":14123,"nodeType":7628},{},[14124],{"data":14125,"content":14126,"nodeType":876},{},[14127],{"data":14128,"marks":14129,"value":12254,"nodeType":867},{},[14130],{"type":865},{"data":14132,"content":14133,"nodeType":7628},{},[14134],{"data":14135,"content":14136,"nodeType":876},{},[14137],{"data":14138,"marks":14139,"value":14140,"nodeType":867},{},[],"Cloudflare Workers (workers.dev) hosting",{"data":14142,"content":14143,"nodeType":7640},{},[14144,14154],{"data":14145,"content":14146,"nodeType":7628},{},[14147],{"data":14148,"content":14149,"nodeType":876},{},[14150],{"data":14151,"marks":14152,"value":12278,"nodeType":867},{},[14153],{"type":865},{"data":14155,"content":14156,"nodeType":7628},{},[14157,14168],{"data":14158,"content":14159,"nodeType":876},{},[14160,14164],{"data":14161,"marks":14162,"value":12753,"nodeType":867},{},[14163],{"type":865},{"data":14165,"marks":14166,"value":14167,"nodeType":867},{},[],"2400:8d60:2::1:c116:843e (Evoxt VPS)",{"data":14169,"content":14170,"nodeType":876},{},[14171,14175],{"data":14172,"marks":14173,"value":12319,"nodeType":867},{},[14174],{"type":865},{"data":14176,"marks":14177,"value":14178,"nodeType":867},{},[]," axios/1.13.6",{"data":14180,"content":14181,"nodeType":7640},{},[14182,14192],{"data":14183,"content":14184,"nodeType":7628},{},[14185],{"data":14186,"content":14187,"nodeType":876},{},[14188],{"data":14189,"marks":14190,"value":12361,"nodeType":867},{},[14191],{"type":865},{"data":14193,"content":14194,"nodeType":7628},{},[14195],{"data":14196,"content":14197,"nodeType":876},{},[14198],{"data":14199,"marks":14200,"value":14052,"nodeType":867},{},[],{"data":14202,"content":14203,"nodeType":7640},{},[14204,14214],{"data":14205,"content":14206,"nodeType":7628},{},[14207],{"data":14208,"content":14209,"nodeType":876},{},[14210],{"data":14211,"marks":14212,"value":12413,"nodeType":867},{},[14213],{"type":865},{"data":14215,"content":14216,"nodeType":7628},{},[14217],{"data":14218,"content":14219,"nodeType":876},{},[14220],{"data":14221,"marks":14222,"value":14223,"nodeType":867},{},[],"DocuSign in Spanish (\"Documento Firmar — COTIZACIÓN/ESTIMACIÓN.pdf\", \"Complete su firma\", \"Verifique su identidad\", \"Continuar a Microsoft\").",{"data":14225,"content":14226,"nodeType":7640},{},[14227,14237],{"data":14228,"content":14229,"nodeType":7628},{},[14230],{"data":14231,"content":14232,"nodeType":876},{},[14233],{"data":14234,"marks":14235,"value":12636,"nodeType":867},{},[14236],{"type":865},{"data":14238,"content":14239,"nodeType":7628},{},[14240],{"data":14241,"content":14242,"nodeType":876},{},[14243],{"data":14244,"marks":14245,"value":14246,"nodeType":867},{},[],"muzagestion[.]secure-share[.]workers.dev",{"data":14248,"content":14252,"nodeType":985},{"target":14249},{"sys":14250},{"id":14251,"type":982,"linkType":983},"5EU0QNteiQcYybKG1W1cS3",[],{"data":14254,"content":14255,"nodeType":942},{},[],{"data":14257,"content":14258,"nodeType":868},{},[14259],{"data":14260,"marks":14261,"value":14263,"nodeType":867},{},[14262],{"type":865},"Device code phishing under the hood",{"data":14265,"content":14266,"nodeType":876},{},[14267,14271],{"data":14268,"marks":14269,"value":14270,"nodeType":867},{},[],"The attacker POSTs to the authorization server's device authorization endpoint with its client_id (i.e. an application ID) and requested scopes or resources. The server responds with a device_code (used for polling), a user_code, a verification_uri, an expires_in value, and a polling interval. The user visits the URL, enters the code and approves the request. Meanwhile, the device polls the token endpoint. Once approved, the server returns an access token, a refresh token (if offline_access was requested), and an ID token (if openid was included). ",{"data":14272,"marks":14273,"value":14275,"nodeType":867},{},[14274],{"type":865},"The attacker now has API access to the victim's account. ",{"data":14277,"content":14278,"nodeType":876},{},[14279],{"data":14280,"marks":14281,"value":14282,"nodeType":867},{},[],"Broadly, this gives the attacker a comparable level of control to a “normal” phishing attack (with conditions based on the scopes granted and specific app being targeted) while API access grants additional capabilities beyond standard browser sessions. When combined with other techniques, this access can be exchanged to open normal browser app sessions and access SSO connected apps.",{"data":14284,"content":14288,"nodeType":985},{"target":14285},{"sys":14286},{"id":14287,"type":982,"linkType":983},"4WtQR2xsE236yoyhSXj58Z",[],{"data":14290,"content":14294,"nodeType":985},{"target":14291},{"sys":14292},{"id":14293,"type":982,"linkType":983},"1x7Lip7JdY2xlHKKurT7qJ",[],{"data":14296,"content":14297,"nodeType":876},{},[14298],{"data":14299,"marks":14300,"value":14301,"nodeType":867},{},[],"At this point, you can achieve a number of objectives both inside the app ecosystem and across SSO connected apps — e.g. data theft, disruption, and ultimately extortion.",{"data":14303,"content":14304,"nodeType":876},{},[14305,14309,14314,14318],{"data":14306,"marks":14307,"value":14308,"nodeType":867},{},[],"Critically, the initial request to generate a device code is typically ",{"data":14310,"marks":14311,"value":14313,"nodeType":867},{},[14312],{"type":865},"unauthenticated",{"data":14315,"marks":14316,"value":14317,"nodeType":867},{},[]," across all providers — ",{"data":14319,"marks":14320,"value":14322,"nodeType":867},{},[14321],{"type":865},"anyone can generate one, from any machine, without proving any relationship to the target organization.",{"data":14324,"content":14325,"nodeType":876},{},[14326,14330,14335],{"data":14327,"marks":14328,"value":14329,"nodeType":867},{},[],"So, the attacker has to deliver a set of instructions via a phishing channel (e.g. email, social media DM, corp IM platform, and so on) with a device code that they have generated. The victim then enters this code on the ",{"data":14331,"marks":14332,"value":14334,"nodeType":867},{},[14333],{"type":865},"legitimate device code login page",{"data":14336,"marks":14337,"value":14338,"nodeType":867},{},[]," for that app and issues the tokens to the attacker.",{"data":14340,"content":14344,"nodeType":985},{"target":14341},{"sys":14342},{"id":14343,"type":982,"linkType":983},"1txUYuQjH9FlbDGTo8AbZB",[],{"data":14346,"content":14347,"nodeType":942},{},[],{"data":14349,"content":14350,"nodeType":868},{},[14351],{"data":14352,"marks":14353,"value":14355,"nodeType":867},{},[14354],{"type":865},"Why device code phishing is so dangerous",{"data":14357,"content":14358,"nodeType":1058},{},[14359],{"data":14360,"marks":14361,"value":14363,"nodeType":867},{},[14362],{"type":865},"Device code phishing bypasses authentication controls (including passkeys)",{"data":14365,"content":14366,"nodeType":876},{},[14367,14371,14376,14380],{"data":14368,"marks":14369,"value":14370,"nodeType":867},{},[],"A device code phishing attack ",{"data":14372,"marks":14373,"value":14375,"nodeType":867},{},[14374],{"type":865},"cannot be prevented with authentication controls",{"data":14377,"marks":14378,"value":14379,"nodeType":867},{},[],". This includes all forms of MFA and ",{"data":14381,"marks":14382,"value":14384,"nodeType":867},{},[14383],{"type":865},"even “phishing-resistant” authentication methods such as passkeys. ",{"data":14386,"content":14387,"nodeType":876},{},[14388,14393,14397,14402],{"data":14389,"marks":14390,"value":14392,"nodeType":867},{},[14391],{"type":865},"The device code authorization is effectively performed post-authentication. ",{"data":14394,"marks":14395,"value":14396,"nodeType":867},{},[],"If you already have an active session in your browser, entering the device code and selecting your account from a drop-down menu is all that's needed. ",{"data":14398,"marks":14399,"value":14401,"nodeType":867},{},[14400],{"type":865},"No password or MFA required. ",{"data":14403,"marks":14404,"value":14405,"nodeType":867},{},[],"You can see an example in the video below.",{"data":14407,"content":14410,"nodeType":985},{"target":14408},{"sys":14409},{"id":13339,"type":982,"linkType":983},[],{"data":14412,"content":14413,"nodeType":876},{},[14414],{"data":14415,"marks":14416,"value":14417,"nodeType":867},{},[],"Even if you do have to sign in again (because you're not already signed in for some reason), the attack still works because it isn't targeting the login — it's targeting the authorization layer instead.",{"data":14419,"content":14420,"nodeType":876},{},[14421],{"data":14422,"marks":14423,"value":14424,"nodeType":867},{},[],"This is what makes device code phishing different to other standard phishing methods like AiTM phishing (and arguably even more effective in environments with strict identity control enforcement). ",{"data":14426,"content":14427,"nodeType":1058},{},[14428],{"data":14429,"marks":14430,"value":14432,"nodeType":867},{},[14431],{"type":865},"Device code logins are a feature, not a vulnerability, making attacks difficult to block",{"data":14434,"content":14435,"nodeType":876},{},[14436],{"data":14437,"marks":14438,"value":14439,"nodeType":867},{},[],"Device code authorization is a legitimate mechanism regularly used in enterprise environments, particularly for CLI logins. Tools like Azure CLI, GitHub CLI, and AWS CLI all use (or have used) the device code flow as a primary or fallback authentication method. This creates a dual problem for defenders. ",{"data":14441,"content":14442,"nodeType":876},{},[14443],{"data":14444,"marks":14445,"value":14446,"nodeType":867},{},[],"First, the phishing attack happens entirely on a legitimate site — there's no fake login page, no malicious payload to scan for, and the URL in the browser is genuine. Since there's no traditional phishing content being delivered, these attacks are more resistant to detection by email and network security tools.",{"data":14448,"content":14449,"nodeType":876},{},[14450],{"data":14451,"marks":14452,"value":14453,"nodeType":867},{},[],"Second, the widespread legitimate use of device code flow — particularly among developers and technical users — normalizes the experience of entering device codes. A phishing lure asking them to do the same thing is indistinguishable from a legitimate IT request. And for non-technical users, this experience isn't much different to, for example, entering a code sent via email or authenticator app. ",{"data":14455,"content":14456,"nodeType":1058},{},[14457],{"data":14458,"marks":14459,"value":14461,"nodeType":867},{},[14460],{"type":865},"Multiple apps are vulnerable, with different risk profiles",{"data":14463,"content":14464,"nodeType":876},{},[14465],{"data":14466,"marks":14467,"value":14468,"nodeType":867},{},[],"Various apps implement the device code flow, each with different levels of control and default security, but the risk is not uniform across platforms. ",{"data":14470,"content":14471,"nodeType":1629},{},[14472,14487,14501],{"data":14473,"content":14474,"nodeType":1586},{},[14475],{"data":14476,"content":14477,"nodeType":876},{},[14478,14483],{"data":14479,"marks":14480,"value":14482,"nodeType":867},{},[14481],{"type":865},"Google Workspace ",{"data":14484,"marks":14485,"value":14486,"nodeType":867},{},[],"is a significantly lower-risk target because Google explicitly limits which scopes are available to the device code flow — Gmail, Calendar, and most Workspace APIs are simply unavailable through this mechanism. ",{"data":14488,"content":14489,"nodeType":1586},{},[14490],{"data":14491,"content":14492,"nodeType":876},{},[14493,14497],{"data":14494,"marks":14495,"value":11959,"nodeType":867},{},[14496],{"type":865},{"data":14498,"marks":14499,"value":14500,"nodeType":867},{},[]," offers the broadest attack surface due to unrestricted scopes, reusable first-party client IDs, and the FOCI/PRT escalation paths. ",{"data":14502,"content":14503,"nodeType":1586},{},[14504],{"data":14505,"content":14506,"nodeType":876},{},[14507,14511,14516],{"data":14508,"marks":14509,"value":14510,"nodeType":867},{},[],"Apps like ",{"data":14512,"marks":14513,"value":14515,"nodeType":867},{},[14514],{"type":865},"GitHub",{"data":14517,"marks":14518,"value":14519,"nodeType":867},{},[]," sit in between — broad scopes are available (including full repository access), but the attacker must control their own OAuth app and the victim sees an explicit consent screen. ",{"data":14521,"content":14525,"nodeType":985},{"target":14522},{"sys":14523},{"id":14524,"type":982,"linkType":983},"ejNSC76jge1p1zzz9wwiG",[],{"data":14527,"content":14528,"nodeType":942},{},[],{"data":14530,"content":14531,"nodeType":868},{},[14532],{"data":14533,"marks":14534,"value":14536,"nodeType":867},{},[14535],{"type":865},"Security recommendations",{"data":14538,"content":14539,"nodeType":876},{},[14540],{"data":14541,"marks":14542,"value":14543,"nodeType":867},{},[],"Security teams need to consider the risk posed by device code phishing across multiple apps where device code authorization grants are common, particularly for developers and technical users. ",{"data":14545,"content":14546,"nodeType":876},{},[14547],{"data":14548,"marks":14549,"value":14550,"nodeType":867},{},[],"In an ideal world, you would simply block device code logins. But this can’t be done without causing serious disruption in some environments, while some apps simply don’t provide the tools required to do so. For example, device code is the default CLI sign-in method for GitHub. Developer-heavy organizations are likely to encounter higher levels of legitimate use.",{"data":14552,"content":14553,"nodeType":876},{},[14554,14558,14567,14571,14576,14580,14585,14589,14594],{"data":14555,"marks":14556,"value":14557,"nodeType":867},{},[],"Microsoft arguably offers the strongest control options (other than Google, who negate it right out of the gate), though they do require a fair amount of work. ",{"data":14559,"content":14561,"nodeType":915},{"uri":14560},"https://techcommunity.microsoft.com/blog/microsoft-entra-blog/new-microsoft-managed-policies-to-raise-your-identity-security-posture/4286758",[14562],{"data":14563,"marks":14564,"value":14566,"nodeType":867},{},[14565],{"type":913},"Microsoft now explicitly recommends",{"data":14568,"marks":14569,"value":14570,"nodeType":867},{},[]," blocking device code flow for tenants that haven't used it in the past 25 days. Their guidance is to create a custom CA policy: target relevant users, set the ",{"data":14572,"marks":14573,"value":14575,"nodeType":867},{},[14574],{"type":865},"Authentication Flows",{"data":14577,"marks":14578,"value":14579,"nodeType":867},{},[]," condition to block ",{"data":14581,"marks":14582,"value":14584,"nodeType":867},{},[14583],{"type":865},"Device Code Flow",{"data":14586,"marks":14587,"value":14588,"nodeType":867},{},[],", and set the grant control to ",{"data":14590,"marks":14591,"value":14593,"nodeType":867},{},[14592],{"type":865},"Block Access",{"data":14595,"marks":14596,"value":14597,"nodeType":867},{},[],". Deploy in report-only mode first to identify any legitimate device code usage, then enforce with narrow exceptions.",{"data":14599,"content":14603,"nodeType":985},{"target":14600},{"sys":14601},{"id":14602,"type":982,"linkType":983},"mQIj2o9xRzkZYKNmanB25",[],{"data":14605,"content":14606,"nodeType":876},{},[14607],{"data":14608,"marks":14609,"value":14610,"nodeType":867},{},[],"For other apps, you’re mainly limited to monitoring and response. Ensuring you’re getting authentication logs for these apps is vital, and searching for unusual access patterns (e.g. unusual login protocols, having different IPs for the authorization grant and subsequent account activity). ",{"data":14612,"content":14613,"nodeType":942},{},[],{"data":14615,"content":14616,"nodeType":868},{},[14617],{"data":14618,"marks":14619,"value":14621,"nodeType":867},{},[14620],{"type":865},"How Push Security can help",{"data":14623,"content":14624,"nodeType":876},{},[14625],{"data":14626,"marks":14627,"value":14628,"nodeType":867},{},[],"Push customers can use our browser-based capabilities to overcome the limitations of app-level controls and detect, intercept, and shut down attacks in real time. ",{"data":14630,"content":14631,"nodeType":876},{},[14632],{"data":14633,"marks":14634,"value":14635,"nodeType":867},{},[],"Our research team is already tracking multiple device code phishing campaigns and toolkits, including the EvilTokens kit. Blocking controls are already in place to prevent customers from interacting with malicious pages that match our detections for these new toolkits, ensuring that these pages can be identified and blocked in real time regardless of the infrastructure. ",{"data":14637,"content":14638,"nodeType":876},{},[14639,14643,14652],{"data":14640,"marks":14641,"value":14642,"nodeType":867},{},[],"Using Push you can also ",{"data":14644,"content":14646,"nodeType":915},{"uri":14645},"https://pushsecurity.com/help/can-i-use-push-to-help-protect-against-device-code-phishing-scenarios/",[14647],{"data":14648,"marks":14649,"value":14651,"nodeType":867},{},[14650],{"type":913},"configure in-browser warnings",{"data":14653,"marks":14654,"value":14655,"nodeType":867},{},[]," whenever a user accesses a URL used for device code logins. This provides universal, last-mile protection against even ‘zero-day’ device code phishing attacks using previously unidentified toolkits.  ",{"data":14657,"content":14661,"nodeType":985},{"target":14658},{"sys":14659},{"id":14660,"type":982,"linkType":983},"3JsbGaOKSS3INzBUJpoh1W",[],{"data":14663,"content":14664,"nodeType":876},{},[14665],{"data":14666,"marks":14667,"value":14668,"nodeType":867},{},[],"When a user visits those URLs, Push will also emit a webhook event that the banner was shown and acknowledged. If a user opts to proceed, you can treat this as a high-fidelity alert for your security team to investigate, providing app-agnostic telemetry that may not already be provided in your logs from that particular vendor. You can also simply use Push to block users from accessing device login pages if you’re confident that disruption won’t be caused. ",{"data":14670,"content":14671,"nodeType":1058},{},[14672],{"data":14673,"marks":14674,"value":14676,"nodeType":867},{},[14675],{"type":865},"Learn more about Push",{"data":14678,"content":14679,"nodeType":876},{},[14680],{"data":14681,"marks":14682,"value":14683,"nodeType":867},{},[],"Push Security's browser-based security platform detects and blocks browser-based attacks like AiTM phishing, credential stuffing, malicious browser extensions, ClickFix, and session hijacking. You don't need to wait until it all goes wrong either — you can use Push to proactively find and fix vulnerabilities across the apps that your employees use, like ghost logins, SSO coverage gaps, MFA gaps, vulnerable passwords, and more to harden your attack surface.",{"data":14685,"content":14686,"nodeType":876},{},[14687,14691,14700,14703,14712,14716,14724],{"data":14688,"marks":14689,"value":14690,"nodeType":867},{},[],"To learn more about Push, ",{"data":14692,"content":14694,"nodeType":915},{"uri":14693},"https://pushsecurity.com/resources/product-brochure",[14695],{"data":14696,"marks":14697,"value":14699,"nodeType":867},{},[14698],{"type":913},"check out our latest product overview",{"data":14701,"marks":14702,"value":5136,"nodeType":867},{},[],{"data":14704,"content":14706,"nodeType":915},{"uri":14705},"https://pushsecurity.com/product-demo/",[14707],{"data":14708,"marks":14709,"value":14711,"nodeType":867},{},[14710],{"type":913},"view our demo library",{"data":14713,"marks":14714,"value":14715,"nodeType":867},{},[],", or ",{"data":14717,"content":14718,"nodeType":915},{"uri":2689},[14719],{"data":14720,"marks":14721,"value":14723,"nodeType":867},{},[14722],{"type":913},"book some time with one of our team for a live demo",{"data":14725,"marks":14726,"value":1679,"nodeType":867},{},[],"Device code phishing attacks have skyrocketed: here’s what you need to know","Device code phishing is seeing a huge spike in adoption in 2026, enabling attackers to steal access tokens while bypassing standard access controls.","2026-04-04T00:00:00.000Z",{"items":14731},[14732,14734],{"sys":14733,"name":4018},{"id":4017},{"sys":14735,"name":342},{"id":3240},{"items":14737},[14738],{"fullName":14739,"firstName":14740,"jobTitle":14741,"profilePicture":14742},"Luke Jennings","Luke","Vice President, R&D",{"url":14743},"https://images.ctfassets.net/y1cdw1ablpvd/4Hosb4zKi1dA0PUyDLMe1h/27e09d894861f2196ba794037986fb08/T016S22KZ96-U02NVQM7ZD4-57761d542d83-512.jpeg",{"__typename":1772,"sys":14745,"content":14747,"title":15572,"synopsis":15573,"hashTags":59,"publishedDate":15574,"slug":15575,"tagsCollection":15576,"authorsCollection":15582},{"id":14746},"211Dd0EIrXPOFpvRgs0fEE",{"json":14748},{"data":14749,"content":14750,"nodeType":1680},{},[14751,14770,14789,14806,14812,14815,14823,14830,14837,14844,14851,14859,14862,14870,14877,14884,14891,14896,14904,14922,14929,14936,14952,14960,14989,15005,15012,15039,15047,15077,15084,15092,15110,15117,15124,15130,15137,15145,15163,15170,15189,15196,15199,15207,15214,15299,15306,15322,15325,15355,15374,15381,15388,15391,15399,15417,15424,15431,15448,15451,15459,15466,15499,15506,15523,15541,15547,15550,15557],{"data":14752,"content":14753,"nodeType":876},{},[14754,14758,14766],{"data":14755,"marks":14756,"value":14757,"nodeType":867},{},[],"When we released the ",{"data":14759,"content":14761,"nodeType":915},{"uri":14760},"https://pushsecurity.com/blog/saas-attack-techniques/",[14762],{"data":14763,"marks":14764,"value":14765,"nodeType":867},{},[],"SaaS attack matrix",{"data":14767,"marks":14768,"value":14769,"nodeType":867},{},[]," in 2023, we were anticipating a shift that was just beginning to take shape. The techniques that attackers were using to compromise cloud applications and identities weren't well represented in existing frameworks, and many of the ones we documented hadn't yet been widely observed in the wild.",{"data":14771,"content":14772,"nodeType":876},{},[14773,14777,14785],{"data":14774,"marks":14775,"value":14776,"nodeType":867},{},[],"A year later, we ",{"data":14778,"content":14780,"nodeType":915},{"uri":14779},"https://pushsecurity.com/blog/the-saas-attack-matrix-one-year-on/",[14781],{"data":14782,"marks":14783,"value":14784,"nodeType":867},{},[],"reviewed what had changed",{"data":14786,"marks":14787,"value":14788,"nodeType":867},{},[]," and found that the initial access phase — the techniques designed to compromise an identity in the first place — was where almost all of the attacker innovation was concentrated. And two years on, that trend has become the story of the modern threat landscape. ",{"data":14790,"content":14791,"nodeType":876},{},[14792,14796,14802],{"data":14793,"marks":14794,"value":14795,"nodeType":867},{},[],"Today, we're re-releasing the matrix as the ",{"data":14797,"content":14798,"nodeType":915},{"uri":5720},[14799],{"data":14800,"marks":14801,"value":5905,"nodeType":867},{},[],{"data":14803,"marks":14804,"value":14805,"nodeType":867},{},[],". The name change isn't cosmetic. It reflects that the attacks driving the most consequential breaches are browser-based and identity-first.",{"data":14807,"content":14811,"nodeType":985},{"target":14808},{"sys":14809},{"id":14810,"type":982,"linkType":983},"MSnrBRJtiQxpv2qxFLCVE",[],{"data":14813,"content":14814,"nodeType":942},{},[],{"data":14816,"content":14817,"nodeType":868},{},[14818],{"data":14819,"marks":14820,"value":14822,"nodeType":867},{},[14821],{"type":865},"Why the scope needed to change",{"data":14824,"content":14825,"nodeType":876},{},[14826],{"data":14827,"marks":14828,"value":14829,"nodeType":867},{},[],"The original SaaS attack matrix was built around a specific insight: that attacks targeting modern business applications played out entirely over the internet, without touching endpoints or internal networks in any way that EDR or network detection tools would recognize.",{"data":14831,"content":14832,"nodeType":876},{},[14833],{"data":14834,"marks":14835,"value":14836,"nodeType":867},{},[],"That framing was useful, and it remains true. But it anchored the matrix to the post-access phase — what attackers do once they're inside a SaaS application — and didn't give enough weight to the initial access techniques that determine whether attackers get there in the first place.",{"data":14838,"content":14839,"nodeType":876},{},[14840],{"data":14841,"marks":14842,"value":14843,"nodeType":867},{},[],"The problem is that initial access is where the overwhelming majority of attacker innovation and investment is concentrated, and the techniques being used to achieve it are best understood as browser and identity attacks rather than SaaS-specific ones. AiTM phishing, ClickFix and its growing family of clipboard-injection variants, device code phishing, OAuth consent abuse, credential stuffing powered by infostealer supply chains, malicious browser extensions all happen in or via the browser.",{"data":14845,"content":14846,"nodeType":876},{},[14847],{"data":14848,"marks":14849,"value":14850,"nodeType":867},{},[],"Another issue is that \"SaaS\" has arguably ceased to be a meaningful category. When we consider that most organizations run the majority of their business on cloud applications, the difference between what constitutes \"SaaS\" versus cloud versus just \"business IT\" is pretty blurry (and feels like an academic rather than practical difference).",{"data":14852,"content":14853,"nodeType":876},{},[14854],{"data":14855,"marks":14856,"value":14858,"nodeType":867},{},[14857],{"type":865},"So it's less about whether an attack is a \"SaaS attack\" and more about how these attacks actually play out. ",{"data":14860,"content":14861,"nodeType":942},{},[],{"data":14863,"content":14864,"nodeType":868},{},[14865],{"data":14866,"marks":14867,"value":14869,"nodeType":867},{},[14868],{"type":865},"The technique landscape has transformed",{"data":14871,"content":14872,"nodeType":876},{},[14873],{"data":14874,"marks":14875,"value":14876,"nodeType":867},{},[],"The second part to the change is the fact that scale and speed of attacker innovation in the space justifies it.",{"data":14878,"content":14879,"nodeType":876},{},[14880],{"data":14881,"marks":14882,"value":14883,"nodeType":867},{},[],"When we launched the matrix in mid-2023, AiTM phishing was emerging as a serious concern but was far from ubiquitous. ClickFix didn't exist as a named technique. Device code phishing was a curiosity documented by a handful of researchers. ConsentFix was years away from being discovered. Browser extension supply chain attacks were rare enough to be individually notable.",{"data":14885,"content":14886,"nodeType":876},{},[14887],{"data":14888,"marks":14889,"value":14890,"nodeType":867},{},[],"In the two and a half years since, every one of these has become a mainstream, industrialized attack technique — and several have converged in ways that would have been hard to predict.",{"data":14892,"content":14895,"nodeType":985},{"target":14893},{"sys":14894},{"id":9289,"type":982,"linkType":983},[],{"data":14897,"content":14898,"nodeType":1058},{},[14899],{"data":14900,"marks":14901,"value":14903,"nodeType":867},{},[14902],{"type":865},"AiTM phishing has become the default phishing method",{"data":14905,"content":14906,"nodeType":876},{},[14907,14911,14918],{"data":14908,"marks":14909,"value":14910,"nodeType":867},{},[],"AiTM phishing is now the standard, powered by Phishing-as-a-Service kits that operate with the release cycles and customer support of legitimate SaaS products. Tycoon 2FA alone accounted for ",{"data":14912,"content":14913,"nodeType":915},{"uri":995},[14914],{"data":14915,"marks":14916,"value":14917,"nodeType":867},{},[],"62% of phishing detected by Microsoft",{"data":14919,"marks":14920,"value":14921,"nodeType":867},{},[]," and over 64,000 confirmed incidents, with Sneaky2FA, FlowerStorm, Evilginx, and a growing roster of competitors filling out the marketplace.",{"data":14923,"content":14924,"nodeType":876},{},[14925],{"data":14926,"marks":14927,"value":14928,"nodeType":867},{},[],"AiTM is constantly evolving, with vendors adding new features, capabilities, detection evasion techniques, and so on. Abuse of legitimate platforms, and increasingly AI-assisted development means that it’s trivial for attackers to spin up and tear down infrastructure, scale their campaigns, target specific organizations with crafted pages and lures, and generally means that attackers can operate highly sophisticated attacks with minimal effort and complexity. This makes AiTM and other PhaaS-powered techniques extremely accessible to all kinds of criminals.  ",{"data":14930,"content":14931,"nodeType":876},{},[14932],{"data":14933,"marks":14934,"value":14935,"nodeType":867},{},[],"These kits are delivered across several browser-based channels — not just email. Push data consistently shows that roughly 1 in 3 phishing payloads we intercept arrive via social media, search ads, messaging apps, or other non-email vectors.",{"data":14937,"content":14938,"nodeType":876},{},[14939,14943,14948],{"data":14940,"marks":14941,"value":14942,"nodeType":867},{},[],"Vishing has also surged as a delivery channel — CrowdStrike documented a ",{"data":14944,"marks":14945,"value":14947,"nodeType":867},{},[14946],{"type":865},"442% year-over-year increase",{"data":14949,"marks":14950,"value":14951,"nodeType":867},{},[],", and Mandiant found it was the single most common initial vector in cloud compromises at 23%. But the trend that matters isn't voice calls in isolation; it's voice calls combined with browser-based payloads, where a live operator guides the victim into an AiTM page or device code flow that the call alone could not execute.",{"data":14953,"content":14954,"nodeType":1058},{},[14955],{"data":14956,"marks":14957,"value":14959,"nodeType":867},{},[14958],{"type":865},"ClickFix is the top reported initial access vector",{"data":14961,"content":14962,"nodeType":876},{},[14963,14967,14974,14978,14985],{"data":14964,"marks":14965,"value":14966,"nodeType":867},{},[],"ClickFix has gone from nonexistent to one of the most prevalent initial access techniques in under 18 months. Microsoft reported it as the ",{"data":14968,"content":14969,"nodeType":915},{"uri":3078},[14970],{"data":14971,"marks":14972,"value":14973,"nodeType":867},{},[],"most common initial access vector in 2025",{"data":14975,"marks":14976,"value":14977,"nodeType":867},{},[],", accounting for 47% of observed attacks, while CrowdStrike documented a ",{"data":14979,"content":14980,"nodeType":915},{"uri":928},[14981],{"data":14982,"marks":14983,"value":14984,"nodeType":867},{},[],"563% increase",{"data":14986,"marks":14987,"value":14988,"nodeType":867},{},[]," in fake CAPTCHA lures (a top ClickFix style).",{"data":14990,"content":14991,"nodeType":876},{},[14992,14996,15001],{"data":14993,"marks":14994,"value":14995,"nodeType":867},{},[],"ClickFix is admittedly an outlier in a browser attacks matrix — the payload ultimately executes on the endpoint, not in the browser — but the delivery is overwhelmingly browser-based: ",{"data":14997,"marks":14998,"value":15000,"nodeType":867},{},[14999],{"type":865},"4 in 5 ClickFix payloads",{"data":15002,"marks":15003,"value":15004,"nodeType":867},{},[]," intercepted by Push arrive via search engines as a result of malvertising or compromised web pages, not email, which means the browser is the only control point that actually sees the attack before the user pastes the malicious command.",{"data":15006,"content":15007,"nodeType":876},{},[15008],{"data":15009,"marks":15010,"value":15011,"nodeType":867},{},[],"ClickFix is now the primary delivery mechanism for infostealer malware, which is in turn the primary source of the stolen credentials and session tokens that power credential stuffing and session hijacking — which means the technique sits at the start of a cycle where one class of browser-delivered attack generates the raw material for the next.",{"data":15013,"content":15014,"nodeType":876},{},[15015,15019,15025,15029,15035],{"data":15016,"marks":15017,"value":15018,"nodeType":867},{},[],"The success of ClickFix has predictably spawned a growing family of derivatives — FileFix, CrashFix, ",{"data":15020,"content":15021,"nodeType":915},{"uri":3932},[15022],{"data":15023,"marks":15024,"value":9082,"nodeType":867},{},[],{"data":15026,"marks":15027,"value":15028,"nodeType":867},{},[]," — and much of the naming is marketing hype around variations on the same clipboard-injection mechanic. But ",{"data":15030,"content":15031,"nodeType":915},{"uri":3692},[15032],{"data":15033,"marks":15034,"value":3685,"nodeType":867},{},[],{"data":15036,"marks":15037,"value":15038,"nodeType":867},{},[]," was a genuinely novel development.",{"data":15040,"content":15041,"nodeType":1058},{},[15042],{"data":15043,"marks":15044,"value":15046,"nodeType":867},{},[15045],{"type":865},"Browser-native ClickFix: ConsentFix",{"data":15048,"content":15049,"nodeType":876},{},[15050,15054,15062,15066,15073],{"data":15051,"marks":15052,"value":15053,"nodeType":867},{},[],"ConsentFix is a fully browser-native attack that merged ClickFix-style social engineering with OAuth consent abuse, compromising accounts through a legitimate Microsoft authorization flow with no endpoint component at all. ConsentFix was ",{"data":15055,"content":15057,"nodeType":915},{"uri":15056},"https://pushsecurity.com/blog/consentfix-debrief/",[15058],{"data":15059,"marks":15060,"value":15061,"nodeType":867},{},[],"traced to APT29",{"data":15063,"marks":15064,"value":15065,"nodeType":867},{},[]," and has since been ",{"data":15067,"content":15068,"nodeType":915},{"uri":1944},[15069],{"data":15070,"marks":15071,"value":15072,"nodeType":867},{},[],"commercialized on criminal forums",{"data":15074,"marks":15075,"value":15076,"nodeType":867},{},[],", following the same path from state-sponsored technique to commodity criminal tooling that we've seen repeatedly in this space.",{"data":15078,"content":15079,"nodeType":876},{},[15080],{"data":15081,"marks":15082,"value":15083,"nodeType":867},{},[],"ConsentFix demonstrates that the clipboard-injection mechanic can evolve into something that operates entirely within the browser, eliminating the endpoint detection surface that traditional ClickFix still exposed.",{"data":15085,"content":15086,"nodeType":1058},{},[15087],{"data":15088,"marks":15089,"value":15091,"nodeType":867},{},[15090],{"type":865},"Attackers have pivoted to authorization attacks to get around login controls",{"data":15093,"content":15094,"nodeType":876},{},[15095,15099,15106],{"data":15096,"marks":15097,"value":15098,"nodeType":867},{},[],"Authorization attacks like device code phishing have seen a ",{"data":15100,"content":15101,"nodeType":915},{"uri":1116},[15102],{"data":15103,"marks":15104,"value":15105,"nodeType":867},{},[],"37.5x increase",{"data":15107,"marks":15108,"value":15109,"nodeType":867},{},[]," since the start of 2026, with at least 12 distinct kits now offering the technique. It bypasses standard authentication controls — including passkeys — because the attack occurs through the OAuth device authorization flow rather than the standard login flow. ",{"data":15111,"content":15112,"nodeType":876},{},[15113],{"data":15114,"marks":15115,"value":15116,"nodeType":867},{},[],"The technique was first associated with nation-state actors like Storm-2372, but went from espionage-grade to commodity PhaaS tooling in roughly eighteen months, with kits like EvilTokens and Venom now offering turnkey device code phishing as a service.",{"data":15118,"content":15119,"nodeType":876},{},[15120],{"data":15121,"marks":15122,"value":15123,"nodeType":867},{},[],"The device code authorization is effectively performed post-authentication. If you already have an active session in your browser, entering the device code and selecting your account from a drop-down menu is all that's needed. No password or MFA required. You can see an example in the video below.",{"data":15125,"content":15129,"nodeType":985},{"target":15126},{"sys":15127},{"id":15128,"type":982,"linkType":983},"2WPb41lNRajdpt5pogQg8M",[],{"data":15131,"content":15132,"nodeType":876},{},[15133],{"data":15134,"marks":15135,"value":15136,"nodeType":867},{},[],"And the ecosystem is adapting to this opportunity: established AiTM vendors like Tycoon are adding authorization-focused options alongside their existing credential-harvesting capabilities, which points toward multi-technique platforms where operators pick the right tool for whatever defenses the target has in place.",{"data":15138,"content":15139,"nodeType":1058},{},[15140],{"data":15141,"marks":15142,"value":15144,"nodeType":867},{},[15143],{"type":865},"Malicious and hacked browser extensions are one of the fastest growing threats",{"data":15146,"content":15147,"nodeType":876},{},[15148,15152,15159],{"data":15149,"marks":15150,"value":15151,"nodeType":867},{},[],"Malicious browser extensions have matured from an occasional nuisance into a scalable supply chain attack vector. The ",{"data":15153,"content":15154,"nodeType":915},{"uri":1576},[15155],{"data":15156,"marks":15157,"value":15158,"nodeType":867},{},[],"Cyberhaven compromise",{"data":15160,"marks":15161,"value":15162,"nodeType":867},{},[]," in December 2024 — where approximately 35 extensions were weaponized through a single OAuth phishing campaign targeting developers — impacted 2.6 million users and demonstrated that extension supply chain attacks can achieve the kind of reach that used to require a compromised software update server.",{"data":15164,"content":15165,"nodeType":876},{},[15166],{"data":15167,"marks":15168,"value":15169,"nodeType":867},{},[],"Since Cyberhaven, the pace has only accelerated. In 2026 alone, researchers have publicly disclosed at least 250 confirmed malicious browser extensions affecting roughly 1.75 million users, alongside a further 370+ extensions engaged in undisclosed or policy-disclosed data harvesting affecting an additional 44 million users. That doesn't count the extensions from late-2025 campaigns (DarkSpectre, AITOPIA, Trust Wallet) whose impacts carried into 2026.",{"data":15171,"content":15172,"nodeType":876},{},[15173,15177,15185],{"data":15174,"marks":15175,"value":15176,"nodeType":867},{},[],"The attack paths have also expanded. Beyond phishing developers for take over Web Store accounts (the Cyberhaven playbook), attackers are buying existing extensions from developers, waiting for ownership transfers or abandonments to take over, and increasingly vibe-coding their own functional extensions from scratch to build an audience that can later be weaponized. The common thread is that ",{"data":15178,"content":15179,"nodeType":915},{"uri":1576},[15180],{"data":15181,"marks":15182,"value":15184,"nodeType":867},{},[15183],{"type":913},"most malicious extensions didn't start out malicious",{"data":15186,"marks":15187,"value":15188,"nodeType":867},{},[]," — they started as legitimate tools and were turned into weapons after the fact.",{"data":15190,"content":15191,"nodeType":876},{},[15192],{"data":15193,"marks":15194,"value":15195,"nodeType":867},{},[],"None of this is happening in isolation. The threat landscape has reoriented around browser-based initial access and identity compromise — and the matrix needed to catch up.",{"data":15197,"content":15198,"nodeType":942},{},[],{"data":15200,"content":15201,"nodeType":868},{},[15202],{"data":15203,"marks":15204,"value":15206,"nodeType":867},{},[15205],{"type":865},"The evolution is playing out in public breaches",{"data":15208,"content":15209,"nodeType":876},{},[15210],{"data":15211,"marks":15212,"value":15213,"nodeType":867},{},[],"It’s worth reinforcing that when the SaaS matrix was first released, many of these attacks hadn’t been seen in the wild. The change today is staggering:",{"data":15215,"content":15216,"nodeType":1629},{},[15217,15237,15259,15279],{"data":15218,"content":15219,"nodeType":1586},{},[15220],{"data":15221,"content":15222,"nodeType":876},{},[15223,15227,15233],{"data":15224,"marks":15225,"value":15226,"nodeType":867},{},[],"When ",{"data":15228,"content":15229,"nodeType":915},{"uri":1177},[15230],{"data":15231,"marks":15232,"value":11991,"nodeType":867},{},[],{"data":15234,"marks":15235,"value":15236,"nodeType":867},{},[]," compromised over a thousand organizations' Salesforce tenants through device code phishing, the attack started with a phone call, moved through a browser-based authorization flow for the attacker’s app, and ended with mass data exfiltration via API.",{"data":15238,"content":15239,"nodeType":1586},{},[15240],{"data":15241,"content":15242,"nodeType":876},{},[15243,15247,15255],{"data":15244,"marks":15245,"value":15246,"nodeType":867},{},[],"When the same collective launched ",{"data":15248,"content":15250,"nodeType":915},{"uri":15249},"https://pushsecurity.com/blog/unpacking-the-latest-slh-campaign/",[15251],{"data":15252,"marks":15253,"value":15254,"nodeType":867},{},[],"AiTM phishing campaigns",{"data":15256,"marks":15257,"value":15258,"nodeType":867},{},[]," targeting Okta and Entra SSO, the phishing page was operated by a human in real time and delivered over a voice call — not email.",{"data":15260,"content":15261,"nodeType":1586},{},[15262],{"data":15263,"content":15264,"nodeType":876},{},[15265,15268,15275],{"data":15266,"marks":15267,"value":15226,"nodeType":867},{},[],{"data":15269,"content":15270,"nodeType":915},{"uri":3692},[15271],{"data":15272,"marks":15273,"value":15274,"nodeType":867},{},[],"APT29 deployed ConsentFix",{"data":15276,"marks":15277,"value":15278,"nodeType":867},{},[]," across dozens of compromised websites, the entire attack chain was browser-native, abusing a legitimate Microsoft OAuth flow to bypass MFA without proxying a single credential.",{"data":15280,"content":15281,"nodeType":1586},{},[15282],{"data":15283,"content":15284,"nodeType":876},{},[15285,15288,15295],{"data":15286,"marks":15287,"value":964,"nodeType":867},{},[],{"data":15289,"content":15291,"nodeType":915},{"uri":15290},"https://pushsecurity.com/blog/identity-attacks-in-the-wild/#id-snowflake-june-2024",[15292],{"data":15293,"marks":15294,"value":6819,"nodeType":867},{},[],{"data":15296,"marks":15297,"value":15298,"nodeType":867},{},[]," — arguably the most consequential credential-based campaign of the past several years — saw 165 organizations breached using credentials that had been sitting in infostealer dumps for years, replayed against Snowflake tenants that lacked mandatory MFA. The attack surface wasn't Snowflake's application logic; it was the identity hygiene gap that every organization carries across hundreds of apps.",{"data":15300,"content":15301,"nodeType":876},{},[15302],{"data":15303,"marks":15304,"value":15305,"nodeType":867},{},[],"And that’s just the big picture. Every month we’re tracking new public breaches involving browser and identity TTPs — which again, are just the tip of the iceberg when you consider that many breaches are settled quietly without hitting the headlines. ",{"data":15307,"content":15308,"nodeType":876},{},[15309,15313,15318],{"data":15310,"marks":15311,"value":15312,"nodeType":867},{},[],"One of the key drivers here is the shrinking time-to-exploit. CrowdStrike's average e-crime breakout time is down to ",{"data":15314,"marks":15315,"value":15317,"nodeType":867},{},[15316],{"type":865},"29 minutes",{"data":15319,"marks":15320,"value":15321,"nodeType":867},{},[],", with the fastest recorded at 27 seconds. When attackers can move from initial access to data exfiltration within minutes, the window for post-compromise detection collapses to near zero. The best chance of stopping the attack is at the point of initial access before the identity is compromised.",{"data":15323,"content":15324,"nodeType":942},{},[],{"data":15326,"content":15327,"nodeType":868},{},[15328,15333,15339,15344,15350],{"data":15329,"marks":15330,"value":15332,"nodeType":867},{},[15331],{"type":865},"Sidenote: why we're looking at attacks ",{"data":15334,"marks":15335,"value":15338,"nodeType":867},{},[15336,15337],{"type":1303},{"type":865},"in",{"data":15340,"marks":15341,"value":15343,"nodeType":867},{},[15342],{"type":865}," the browser, not ",{"data":15345,"marks":15346,"value":15349,"nodeType":867},{},[15347,15348],{"type":1303},{"type":865},"on",{"data":15351,"marks":15352,"value":15354,"nodeType":867},{},[15353],{"type":865}," the browser",{"data":15356,"content":15357,"nodeType":876},{},[15358,15362,15370],{"data":15359,"marks":15360,"value":15361,"nodeType":867},{},[],"Calling this a \"browser attacks\" matrix needs clarification. We're not talking about browser exploits — RCE vulnerabilities, sandbox escapes, memory corruption bugs. Those attacks target the browser itself, they're extraordinarily expensive to develop, and they're increasingly rare. Browser zero-days hit a ",{"data":15363,"content":15365,"nodeType":915},{"uri":15364},"https://cloud.google.com/blog/topics/threat-intelligence/2025-zero-day-review",[15366],{"data":15367,"marks":15368,"value":15369,"nodeType":867},{},[],"historic low of 9%",{"data":15371,"marks":15372,"value":15373,"nodeType":867},{},[]," of all zero-days reported to Google, and a Chrome RCE commands a $250,000 bug bounty.",{"data":15375,"content":15376,"nodeType":876},{},[15377],{"data":15378,"marks":15379,"value":15380,"nodeType":867},{},[],"In comparison, a one-year phishing kit rental costs $1,000. A bulk stolen credential list costs $15. An initial-access-broker-provided IdP admin account costs $3,000. When it costs orders of magnitude less to exploit the person using the browser than to exploit the browser itself, attackers will take the cheaper option every time.",{"data":15382,"content":15383,"nodeType":876},{},[15384],{"data":15385,"marks":15386,"value":15387,"nodeType":867},{},[],"It's worth heading off the obvious counterargument: won't AI-assisted vulnerability discovery eventually make browser exploits cheaper? Perhaps — but it will simultaneously make them easier for browser vendors to find and patch, and vendors like Google and Microsoft have the engineering capacity and financial incentive to scale AI-driven remediation far faster than attackers can scale exploit development.",{"data":15389,"content":15390,"nodeType":942},{},[],{"data":15392,"content":15393,"nodeType":868},{},[15394],{"data":15395,"marks":15396,"value":15398,"nodeType":867},{},[15397],{"type":865},"What hasn't changed",{"data":15400,"content":15401,"nodeType":876},{},[15402,15406,15413],{"data":15403,"marks":15404,"value":15405,"nodeType":867},{},[],"The matrix remains open-source, community-maintained, and available on ",{"data":15407,"content":15409,"nodeType":915},{"uri":15408},"https://github.com/pushsecurity/saas-attacks",[15410],{"data":15411,"marks":15412,"value":14515,"nodeType":867},{},[],{"data":15414,"marks":15415,"value":15416,"nodeType":867},{},[],". The goal is the same as it was in 2023: to give offensive and defensive security teams a shared reference point for the techniques that matter most.",{"data":15418,"content":15419,"nodeType":876},{},[15420],{"data":15421,"marks":15422,"value":15423,"nodeType":867},{},[],"We built it because there was a gap in how the industry talked about these techniques, and that gap still exists — MITRE ATT&CK remains essential for endpoint and network TTPs, but the browser-based, identity-first techniques behind most modern breaches are still underrepresented in traditional frameworks.",{"data":15425,"content":15426,"nodeType":876},{},[15427],{"data":15428,"marks":15429,"value":15430,"nodeType":867},{},[],"We continue to maintain the matrix with input from red teams, detection engineers, and threat researchers across the community. Some of the most valuable additions over the past two years have come from practitioners who encountered a technique on an engagement or in an investigation and contributed it back to the repository.",{"data":15432,"content":15433,"nodeType":876},{},[15434,15438,15445],{"data":15435,"marks":15436,"value":15437,"nodeType":867},{},[],"If you're an offensive security professional using these techniques on engagements, or a defender building detections against them, we want to hear from you. Submit a PR, open a discussion, or flag a technique we've missed on ",{"data":15439,"content":15441,"nodeType":915},{"uri":15440},"https://github.com/pushsecurity/browser-identity-attacks-matrix",[15442],{"data":15443,"marks":15444,"value":14515,"nodeType":867},{},[],{"data":15446,"marks":15447,"value":1679,"nodeType":867},{},[],{"data":15449,"content":15450,"nodeType":942},{},[],{"data":15452,"content":15453,"nodeType":868},{},[15454],{"data":15455,"marks":15456,"value":15458,"nodeType":867},{},[15457],{"type":865},"Looking ahead",{"data":15460,"content":15461,"nodeType":876},{},[15462],{"data":15463,"marks":15464,"value":15465,"nodeType":867},{},[],"The pace of attacker innovation in browser-based initial access techniques over the past 18 months has been unlike anything we've tracked before — technique after technique moving from research curiosity to industrialized criminal tooling within months, not years.",{"data":15467,"content":15468,"nodeType":1629},{},[15469,15479,15489],{"data":15470,"content":15471,"nodeType":1586},{},[15472],{"data":15473,"content":15474,"nodeType":876},{},[15475],{"data":15476,"marks":15477,"value":15478,"nodeType":867},{},[],"AiTM platforms are adding authorization-based attack options alongside their credential-harvesting capabilities.",{"data":15480,"content":15481,"nodeType":1586},{},[15482],{"data":15483,"content":15484,"nodeType":876},{},[15485],{"data":15486,"marks":15487,"value":15488,"nodeType":867},{},[],"ClickFix has spawned fully browser-native variants.",{"data":15490,"content":15491,"nodeType":1586},{},[15492],{"data":15493,"content":15494,"nodeType":876},{},[15495],{"data":15496,"marks":15497,"value":15498,"nodeType":867},{},[],"AI is lowering the cost of producing convincing social engineering and phishing infrastructure at scale.",{"data":15500,"content":15501,"nodeType":876},{},[15502],{"data":15503,"marks":15504,"value":15505,"nodeType":867},{},[],"We don't see any of this slowing down, and that's exactly why thinking about these attacks as a browser problem instead of siloing them across email, endpoint, network, and cloud categories, each with a partial view of the picture (and still missing the whole when combined).",{"data":15507,"content":15508,"nodeType":876},{},[15509,15513,15520],{"data":15510,"marks":15511,"value":15512,"nodeType":867},{},[],"The Browser & Identity Attacks Matrix is our contribution to keeping that shared understanding current. You can ",{"data":15514,"content":15515,"nodeType":915},{"uri":5720},[15516],{"data":15517,"marks":15518,"value":15519,"nodeType":867},{},[],"explore the matrix here",{"data":15521,"marks":15522,"value":1679,"nodeType":867},{},[],{"data":15524,"content":15525,"nodeType":876},{},[15526,15530,15537],{"data":15527,"marks":15528,"value":15529,"nodeType":867},{},[],"You can also read our recent ",{"data":15531,"content":15532,"nodeType":915},{"uri":1702},[15533],{"data":15534,"marks":15535,"value":15536,"nodeType":867},{},[],"browser attack techniques report",{"data":15538,"marks":15539,"value":15540,"nodeType":867},{},[]," for more information.",{"data":15542,"content":15546,"nodeType":985},{"target":15543},{"sys":15544},{"id":15545,"type":982,"linkType":983},"1hx6sxpyEzxn4F4jc1RGQi",[],{"data":15548,"content":15549,"nodeType":942},{},[],{"data":15551,"content":15552,"nodeType":876},{},[15553],{"data":15554,"marks":15555,"value":15556,"nodeType":867},{},[],"Push Security is the most powerful AI-native security tool in the browser. Think EDR, but for the browser — high-fidelity telemetry and real-time control across every session, on every device, with no browser migration required. Security teams use Push to detect and stop advanced browser-based attacks like AiTM phishing, ClickFix, and session hijacking; gain visibility and control over AI tool usage across their workforce; harden identities by surfacing credential reuse, SSO gaps, and shadow IT; and support data loss and insider investigations with browser-layer telemetry that other tools can't see.",{"data":15558,"content":15559,"nodeType":876},{},[15560,15563,15569],{"data":15561,"marks":15562,"value":5283,"nodeType":867},{},[],{"data":15564,"content":15565,"nodeType":915},{"uri":2689},[15566],{"data":15567,"marks":15568,"value":5291,"nodeType":867},{},[],{"data":15570,"marks":15571,"value":3229,"nodeType":867},{},[],"Introducing the Browser & Identity Attacks Matrix","We're re-releasing the SaaS attack matrix as the Browser & Identity Attacks Matrix. Here's why we've decided to make the change and what it means.","2026-05-08T00:00:00.000Z","introducing-the-browser-and-identity-attacks-matrix",{"items":15577},[15578,15580],{"sys":15579,"name":4018},{"id":4017},{"sys":15581,"name":342},{"id":3240},{"items":15583},[15584],{"fullName":4022,"firstName":4023,"jobTitle":4024,"profilePicture":15585},{"url":4026},{"__typename":1772,"sys":15587,"content":15589,"title":16551,"synopsis":16552,"hashTags":59,"publishedDate":15574,"slug":16553,"tagsCollection":16554,"authorsCollection":16560},{"id":15588},"3jF1fypt08TNlSoWuoMWhj",{"json":15590},{"data":15591,"content":15592,"nodeType":1680},{},[15593,15619,15650,15693,15736,15742,15754,15757,15765,15816,15823,15846,15852,15855,15863,15891,15898,15906,15912,15915,15923,15930,15948,15955,15997,16004,16007,16015,16034,16089,16092,16100,16118,16136,16143,16150,16162,16174,16186,16198,16214,16222,16229,16232,16238,16244,16259,16262,16270,16288,16545],{"data":15594,"content":15595,"nodeType":876},{},[15596,15600,15606,15610,15615],{"data":15597,"marks":15598,"value":15599,"nodeType":867},{},[],"ShinyHunters and the broader SLH (",{"data":15601,"content":15602,"nodeType":915},{"uri":1177},[15603],{"data":15604,"marks":15605,"value":11991,"nodeType":867},{},[],{"data":15607,"marks":15608,"value":15609,"nodeType":867},{},[],") collective have claimed breaches at thousands of organizations over the past twelve months across retail, technology, aviation, financial services, media, gaming, and education, in what amounts to the most sustained data theft and extortion operation in recent cybercrime history. SLH's genealogy traces through a merger of Scattered Spider, Lapsus$, and ShinyHunters, all parts of ",{"data":15611,"marks":15612,"value":15614,"nodeType":867},{},[15613],{"type":865},"the Com",{"data":15616,"marks":15617,"value":15618,"nodeType":867},{},[],", a broader community of English-speaking cybercriminals with international links. ",{"data":15620,"content":15621,"nodeType":876},{},[15622,15626,15634,15638,15646],{"data":15623,"marks":15624,"value":15625,"nodeType":867},{},[],"The confirmed victim list reads like a Fortune 500 directory: Coca-Cola, Cisco, Qantas, Coinbase, ADT, Aflac, SoundCloud, Rockstar Games, Charter Communications, and recently ",{"data":15627,"content":15629,"nodeType":915},{"uri":15628},"https://www.bleepingcomputer.com/news/security/instructure-confirms-data-breach-shinyhunters-claims-attack/",[15630],{"data":15631,"marks":15632,"value":15633,"nodeType":867},{},[],"Instructure",{"data":15635,"marks":15636,"value":15637,"nodeType":867},{},[]," — whose breach ",{"data":15639,"content":15641,"nodeType":915},{"uri":15640},"https://krebsonsecurity.com/2026/05/canvas-breach-disrupts-schools-colleges-nationwide/",[15642],{"data":15643,"marks":15644,"value":15645,"nodeType":867},{},[],"disrupted schools and universities nationwide",{"data":15647,"marks":15648,"value":15649,"nodeType":867},{},[]," during final exams — among dozens more named publicly and likely many more that haven't been (breaches settled quickly behind closed doors don't always make it into the public eye). ShinyHunters alone claimed over 1.5 billion stolen Salesforce records from a single campaign targeting more than 1,000 organizations.",{"data":15651,"content":15652,"nodeType":876},{},[15653,15657,15665,15669,15677,15681,15689],{"data":15654,"marks":15655,"value":15656,"nodeType":867},{},[],"Additional operating clusters, including Cordial Spider and Snarky Spider (which CrowdStrike ",{"data":15658,"content":15660,"nodeType":915},{"uri":15659},"https://cyberscoop.com/crowdstrike-cordial-spider-snarky-spider-extortion-attacks/",[15661],{"data":15662,"marks":15663,"value":15664,"nodeType":867},{},[],"characterizes as the new generation of Scattered Spider",{"data":15666,"marks":15667,"value":15668,"nodeType":867},{},[],") run parallel campaigns against different target sectors, unified not by shared infrastructure but by a shared playbook of techniques that exploit the structural weakness in modern SaaS-first organizations. ",{"data":15670,"content":15672,"nodeType":915},{"uri":15671},"https://github.com/PaloAltoNetworks/Unit42-timely-threat-intel/blob/main/2026-03-12-Vishing-Campaigns-Lead-to-Data-Theft-and-Extortion.txt",[15673],{"data":15674,"marks":15675,"value":15676,"nodeType":867},{},[],"Unit 42 documented",{"data":15678,"marks":15679,"value":15680,"nodeType":867},{},[]," these groups moving from initial compromise to complete data exfiltration in under an hour — faster than most organizations can even begin to respond. Newer groups with links to the SLH ecosystem like CoinbaseCartel have also continued the tradition of weaponizing stolen credentials from the infostealer economy at scale, as ShinyHunters did in the ",{"data":15682,"content":15684,"nodeType":915},{"uri":15683},"https://www.bleepingcomputer.com/news/security/shinyhunters-claims-15-billion-salesforce-records-stolen-in-drift-hacks/",[15685],{"data":15686,"marks":15687,"value":15688,"nodeType":867},{},[],"2024 Snowflake breach",{"data":15690,"marks":15691,"value":15692,"nodeType":867},{},[]," that compromised over 165 customer environments (and claimed another billion-plus records).",{"data":15694,"content":15695,"nodeType":876},{},[15696,15700,15708,15712,15720,15724,15732],{"data":15697,"marks":15698,"value":15699,"nodeType":867},{},[],"Not every SLH breach is browser-based — the Instructure breach (275 million individuals, ~330 school login portals defaced) began with a Salesforce tenant compromise in September 2025, but resurfaced in May 2026 after attackers exploited a ",{"data":15701,"content":15703,"nodeType":915},{"uri":15702},"https://www.bitdefender.com/en-gb/blog/businessinsights/technical-advisory-shinyhunters-breach-instructure-canvas-lms",[15704],{"data":15705,"marks":15706,"value":15707,"nodeType":867},{},[],"vulnerability affecting Canvas's Free-For-Teacher program",{"data":15709,"marks":15710,"value":15711,"nodeType":867},{},[]," (it's now been confirmed that Instructure \"",{"data":15713,"content":15715,"nodeType":915},{"uri":15714},"https://www.instructure.com/incident_update",[15716],{"data":15717,"marks":15718,"value":15719,"nodeType":867},{},[],"reached a settlement",{"data":15721,"marks":15722,"value":15723,"nodeType":867},{},[],"\" for the deletion of the data, and shut down the free account tier), while the Coinbase breach cost ",{"data":15725,"content":15727,"nodeType":915},{"uri":15726},"https://www.bleepingcomputer.com/news/security/coinbase-discloses-breach-faces-up-to-400-million-in-losses/",[15728],{"data":15729,"marks":15730,"value":15731,"nodeType":867},{},[],"$180M–400M through insider bribery",{"data":15733,"marks":15734,"value":15735,"nodeType":867},{},[]," — but these are the exceptions that prove the rule. ",{"data":15737,"content":15741,"nodeType":985},{"target":15738},{"sys":15739},{"id":15740,"type":982,"linkType":983},"4qNrbDyMJIumQfdbh9YVkU",[],{"data":15743,"content":15744,"nodeType":876},{},[15745,15750],{"data":15746,"marks":15747,"value":15749,"nodeType":867},{},[15748],{"type":865},"The vast majority of SLH campaigns over the past year converge on three browser-based attack vectors: vishing combined with AiTM phishing, device code phishing exploiting account authorization flows, and OAuth supply chain attacks through compromised third-party integrators.",{"data":15751,"marks":15752,"value":15753,"nodeType":867},{},[]," Each is well-documented, each has produced confirmed victims at scale, and each is detectable or preventable through browser-layer security controls.",{"data":15755,"content":15756,"nodeType":942},{},[],{"data":15758,"content":15759,"nodeType":868},{},[15760],{"data":15761,"marks":15762,"value":15764,"nodeType":867},{},[15763],{"type":865},"Vector 1: Vishing combined with AiTM phishing",{"data":15766,"content":15767,"nodeType":876},{},[15768,15772,15780,15783,15791,15794,15801,15805,15813],{"data":15769,"marks":15770,"value":15771,"nodeType":867},{},[],"The most visible campaign right now pairs targeted voice calls with adversary-in-the-middle phishing pages — an approach that ",{"data":15773,"content":15775,"nodeType":915},{"uri":15774},"https://cloud.google.com/blog/topics/threat-intelligence/expansion-shinyhunters-saas-data-theft",[15776],{"data":15777,"marks":15778,"value":15779,"nodeType":867},{},[],"Mandiant",{"data":15781,"marks":15782,"value":5000,"nodeType":867},{},[],{"data":15784,"content":15786,"nodeType":915},{"uri":15785},"https://www.crowdstrike.com/en-us/blog/defending-against-cordial-spider-and-snarky-spider-with-falcon-shield/",[15787],{"data":15788,"marks":15789,"value":15790,"nodeType":867},{},[]," CrowdStrike",{"data":15792,"marks":15793,"value":11670,"nodeType":867},{},[],{"data":15795,"content":15796,"nodeType":915},{"uri":15671},[15797],{"data":15798,"marks":15799,"value":15800,"nodeType":867},{},[]," Unit 42",{"data":15802,"marks":15803,"value":15804,"nodeType":867},{},[]," have all documented from the incident response side, and which Push has ",{"data":15806,"content":15808,"nodeType":915},{"uri":15807},"https://pushsecurity.com/blog/inside-criminal-phishing-panel/",[15809],{"data":15810,"marks":15811,"value":15812,"nodeType":867},{},[],"documented from inside the attacker's own operator panels",{"data":15814,"marks":15815,"value":1679,"nodeType":867},{},[],{"data":15817,"content":15818,"nodeType":876},{},[15819],{"data":15820,"marks":15821,"value":15822,"nodeType":867},{},[],"An attacker impersonating IT support calls the target employee, establishes urgency — often citing a \"mandatory passkey rollout\" or a \"security compliance update\" — and directs them to a victim-branded AiTM phishing page (typically at a domain like \u003Ccompany>sso.com or \u003Ccompany>internal.com). The attack is processed by a live human in real time, relaying credentials and MFA codes to the legitimate identity provider as they are entered, capturing the resulting session token, and granting the attacker an authenticated session. ",{"data":15824,"content":15825,"nodeType":876},{},[15826,15830,15837,15841],{"data":15827,"marks":15828,"value":15829,"nodeType":867},{},[],"One of the reasons that this method is becoming so widespread is the commoditization of effective tools. Push's ",{"data":15831,"content":15832,"nodeType":915},{"uri":15807},[15833],{"data":15834,"marks":15835,"value":15836,"nodeType":867},{},[],"infiltration of the criminal phishing panels",{"data":15838,"marks":15839,"value":15840,"nodeType":867},{},[]," identified over 400 linked domains across four distinct infrastructure clusters. ",{"data":15842,"marks":15843,"value":15845,"nodeType":867},{},[15844],{"type":865},"This mirrors the pattern that turned AiTM phishing from a specialist capability into an industrialized market with competing PhaaS platforms, but with the added complication that voice phishing as the delivery vector makes the attack invisible to traditional anti-phishing controls at the email layer.",{"data":15847,"content":15851,"nodeType":985},{"target":15848},{"sys":15849},{"id":15850,"type":982,"linkType":983},"1Yhthl0PILGW7EmCcZUrNv",[],{"data":15853,"content":15854,"nodeType":942},{},[],{"data":15856,"content":15857,"nodeType":868},{},[15858],{"data":15859,"marks":15860,"value":15862,"nodeType":867},{},[15861],{"type":865},"Vector 2: Vishing combined with device code phishing",{"data":15864,"content":15865,"nodeType":876},{},[15866,15869,15876,15880,15887],{"data":15867,"marks":15868,"value":964,"nodeType":867},{},[],{"data":15870,"content":15871,"nodeType":915},{"uri":15249},[15872],{"data":15873,"marks":15874,"value":15875,"nodeType":867},{},[],"ShinyHunters Salesforce campaign",{"data":15877,"marks":15878,"value":15879,"nodeType":867},{},[]," that ran through 2025 and into 2026 used device code phishing as one of its core methods, ",{"data":15881,"content":15882,"nodeType":915},{"uri":15683},[15883],{"data":15884,"marks":15885,"value":15886,"nodeType":867},{},[],"compromising over 1,000 organizations and claiming 1.5 billion stolen records",{"data":15888,"marks":15889,"value":15890,"nodeType":867},{},[]," — including an attempted extortion of Salesforce itself. The attack involved registering an attacker-controlled \"DataLoader\" application mimicking a legitimate Salesforce tool, configuring it to request broad OAuth scopes including full API access and refresh token generation, and guiding victims through the device authorization flow via vishing calls.",{"data":15892,"content":15893,"nodeType":876},{},[15894],{"data":15895,"marks":15896,"value":15897,"nodeType":867},{},[],"Device code phishing exploits the OAuth 2.0 device authorization grant — a flow designed for devices without browsers, like smart TVs, but used in a wide range of scenarios including CLI logins — by tricking users into entering a code on Microsoft's (or another identity provider's) legitimate verification page. Since the victim is usually signed into the app in their browser, there’s no login at all. They simply navigate to the app’s device code login page and enter an attacker-provided code to grant the attacker an access token. ",{"data":15899,"content":15900,"nodeType":876},{},[15901],{"data":15902,"marks":15903,"value":15905,"nodeType":867},{},[15904],{"type":865},"This is what makes device code phishing structurally different from AiTM: it defeats all MFA (including passkeys) because the attack doesn’t target the login, but the authorization layer instead.",{"data":15907,"content":15911,"nodeType":985},{"target":15908},{"sys":15909},{"id":15910,"type":982,"linkType":983},"3ElQz8sLATnR8RY5nVlBGM",[],{"data":15913,"content":15914,"nodeType":942},{},[],{"data":15916,"content":15917,"nodeType":868},{},[15918],{"data":15919,"marks":15920,"value":15922,"nodeType":867},{},[15921],{"type":865},"Vector 3: OAuth supply chain attacks through compromised integrators",{"data":15924,"content":15925,"nodeType":876},{},[15926],{"data":15927,"marks":15928,"value":15929,"nodeType":867},{},[],"The third vector does not require the attacker to phish the victim organization's employees at all. Instead, it exploits the OAuth trust relationships that organizations create when they connect third-party SaaS vendors into their environments — and the consequence is that every organization that authorized one of these integrations effectively extended its security boundary to include the vendor's own security posture.",{"data":15931,"content":15932,"nodeType":876},{},[15933,15936,15944],{"data":15934,"marks":15935,"value":964,"nodeType":867},{},[],{"data":15937,"content":15939,"nodeType":915},{"uri":15938},"https://cloud.google.com/blog/topics/threat-intelligence/data-theft-salesforce-instances-via-salesloft-drift",[15940],{"data":15941,"marks":15942,"value":15943,"nodeType":867},{},[],"Salesloft/Drift supply chain attack",{"data":15945,"marks":15946,"value":15947,"nodeType":867},{},[]," demonstrated this at scale in 2025: in an extension of the previously mentioned device code phishing campaign, the attacker compromised Salesloft's GitHub environment, used TruffleHog to find secrets, stole Drift OAuth tokens, and used them to access downstream Salesforce environments. The same pattern was later repeated at Gainsight. ",{"data":15949,"content":15950,"nodeType":876},{},[15951],{"data":15952,"marks":15953,"value":15954,"nodeType":867},{},[],"Along with the previously mentioned device code phishing attacks,  more than 1000 organizations were breached. The attackers then harvested AWS keys, Snowflake credentials, and stored passwords from breached Salesforce instances, compounding the access into progressively wider reach.",{"data":15956,"content":15957,"nodeType":876},{},[15958,15962,15970,15974,15982,15986,15993],{"data":15959,"marks":15960,"value":15961,"nodeType":867},{},[],"The same structural pattern has continued into 2026 with the Anodot supply chain compromise, which has produced confirmed breaches at ",{"data":15963,"content":15965,"nodeType":915},{"uri":15964},"https://www.bleepingcomputer.com/news/security/vimeo-data-breach-exposes-personal-information-of-119-000-people/",[15966],{"data":15967,"marks":15968,"value":15969,"nodeType":867},{},[],"Vimeo",{"data":15971,"marks":15972,"value":15973,"nodeType":867},{},[]," (119,000 users), Rockstar Games (78.6 million records), and ",{"data":15975,"content":15977,"nodeType":915},{"uri":15976},"https://www.bleepingcomputer.com/news/security/zara-data-breach-exposed-personal-information-of-197-000-people/",[15978],{"data":15979,"marks":15980,"value":15981,"nodeType":867},{},[],"Zara/Inditex",{"data":15983,"marks":15984,"value":15985,"nodeType":867},{},[]," (197,000 people), with further downstream victims likely still emerging. The ",{"data":15987,"content":15988,"nodeType":915},{"uri":2225},[15989],{"data":15990,"marks":15991,"value":15992,"nodeType":867},{},[],"Vercel breach",{"data":15994,"marks":15995,"value":15996,"nodeType":867},{},[],", which involved compromised OAuth tokens from Context.ai cascading into Google Workspace, also reinforces the same attack pattern (though it was likely not a ShinyHunters operation despite being claimed by someone pretending to be them).",{"data":15998,"content":15999,"nodeType":876},{},[16000],{"data":16001,"marks":16002,"value":16003,"nodeType":867},{},[],"A forgotten SaaS integration can easily become the pivot point for downstream compromise. The moment you authorize a third-party integration, your security boundary extends to include that vendor. If the third-party is compromised, every downstream customer organization with an active integration is exposed.",{"data":16005,"content":16006,"nodeType":942},{},[],{"data":16008,"content":16009,"nodeType":868},{},[16010],{"data":16011,"marks":16012,"value":16014,"nodeType":867},{},[16013],{"type":865},"The infostealer credential playbook sits alongside these attacks",{"data":16016,"content":16017,"nodeType":876},{},[16018,16022,16030],{"data":16019,"marks":16020,"value":16021,"nodeType":867},{},[],"Alongside the three vectors above, ShinyHunters has a track record of exploiting the infostealer credential economy at scale — and it predates any of them. The 2024 Snowflake campaign — 165+ customer environments compromised, over a billion records stolen from AT&T, Ticketmaster, Santander, and Advance Auto Parts among others — was built entirely on infostealer-harvested credentials replayed against MFA-less tenants, with ",{"data":16023,"content":16025,"nodeType":915},{"uri":16024},"https://cloud.google.com/blog/topics/threat-intelligence/unc5537-snowflake-data-theft-extortion",[16026],{"data":16027,"marks":16028,"value":16029,"nodeType":867},{},[],"Mandiant's investigation",{"data":16031,"marks":16032,"value":16033,"nodeType":867},{},[]," finding that 80% of compromised accounts had prior breach exposure in datasets dating back to 2020. The credentials were already circulating in criminal marketplaces; ShinyHunters simply purchased and operationalized them at industrial scale.",{"data":16035,"content":16036,"nodeType":876},{},[16037,16041,16049,16053,16061,16065,16073,16077,16085],{"data":16038,"marks":16039,"value":16040,"nodeType":867},{},[],"The same methodology powered the ",{"data":16042,"content":16044,"nodeType":915},{"uri":16043},"https://pushsecurity.com/blog/why-attackers-are-targeting-jira-with-stolen-credentials/",[16045],{"data":16046,"marks":16047,"value":16048,"nodeType":867},{},[],"HellCat Jira campaign",{"data":16050,"marks":16051,"value":16052,"nodeType":867},{},[]," through 2024–2025, and has now been industrialized as a standalone operation by ",{"data":16054,"content":16056,"nodeType":915},{"uri":16055},"https://www.halcyon.ai/jp/threat-group/coinbasecartel",[16057],{"data":16058,"marks":16059,"value":16060,"nodeType":867},{},[],"CoinbaseCartel",{"data":16062,"marks":16063,"value":16064,"nodeType":867},{},[],", another criminal group reported to be an offshoot of SLH. CoinbaseCartel's model is familiar: purchase old infostealer credentials, use them to access cloud and development environments, exfiltrate data, and demand ransom. ",{"data":16066,"content":16068,"nodeType":915},{"uri":16067},"https://www.infostealers.com/article/inside-the-coinbase-cartel-how-infostealer-credentials-fueled-a-100-company-ransomware-spree/",[16069],{"data":16070,"marks":16071,"value":16072,"nodeType":867},{},[],"Hudson Rock's analysis",{"data":16074,"marks":16075,"value":16076,"nodeType":867},{},[]," of the group's 170+ claimed victims confirms that roughly 80% had prior infostealer infections predating the attacks. The most recent named victim is ",{"data":16078,"content":16080,"nodeType":915},{"uri":16079},"https://www.bleepingcomputer.com/news/security/grafana-says-stolen-github-token-let-hackers-steal-codebase/",[16081],{"data":16082,"marks":16083,"value":16084,"nodeType":867},{},[],"Grafana",{"data":16086,"marks":16087,"value":16088,"nodeType":867},{},[],", where a GitHub token compromised via the TanStack npm supply chain attack and missed during credential rotation was used to download the codebase and attempt extortion. ",{"data":16090,"content":16091,"nodeType":942},{},[],{"data":16093,"content":16094,"nodeType":868},{},[16095],{"data":16096,"marks":16097,"value":16099,"nodeType":867},{},[16098],{"type":865},"These attacks all happen in the browser",{"data":16101,"content":16102,"nodeType":876},{},[16103,16107,16114],{"data":16104,"marks":16105,"value":16106,"nodeType":867},{},[],"Every one of these attack chains is a browser-based attack that either occurs in the browser (AiTM phishing, device code phishing) or could have been prevented at the browser layer (OAuth consent governance). The techniques are interchangeable — the",{"data":16108,"content":16109,"nodeType":915},{"uri":1116},[16110],{"data":16111,"marks":16112,"value":16113,"nodeType":867},{},[]," same criminal kits now offer AiTM and device code phishing side by side",{"data":16115,"marks":16116,"value":16117,"nodeType":867},{},[],", and the same threat actor (ShinyHunters) has used all three vectors across different campaigns within the same twelve-month period.",{"data":16119,"content":16120,"nodeType":876},{},[16121,16125,16132],{"data":16122,"marks":16123,"value":16124,"nodeType":867},{},[],"Additionally, infostealer infections themselves are increasingly delivered through browser-based methods like ",{"data":16126,"content":16128,"nodeType":915},{"uri":16127},"https://pushsecurity.com/blog/introducing-malicious-copy-paste-detection",[16129],{"data":16130,"marks":16131,"value":315,"nodeType":867},{},[],{"data":16133,"marks":16134,"value":16135,"nodeType":867},{},[],", closing the loop between the credential supply side and the browser-layer detection point.",{"data":16137,"content":16138,"nodeType":1058},{},[16139],{"data":16140,"marks":16141,"value":2541,"nodeType":867},{},[16142],{"type":865},{"data":16144,"content":16145,"nodeType":876},{},[16146],{"data":16147,"marks":16148,"value":16149,"nodeType":867},{},[],"Push operates at the exact point in each of these attack chains where automated intervention can still prevent the compromise. ",{"data":16151,"content":16152,"nodeType":876},{},[16153,16158],{"data":16154,"marks":16155,"value":16157,"nodeType":867},{},[16156],{"type":865},"For vishing + AiTM attacks, ",{"data":16159,"marks":16160,"value":16161,"nodeType":867},{},[],"Push's behavioral phishing detection analyzes and blocks the phishing page in real time by detecting it from the user's browser — regardless of the domains used, hosting infrastructure, or where the URL was delivered.  ",{"data":16163,"content":16164,"nodeType":876},{},[16165,16170],{"data":16166,"marks":16167,"value":16169,"nodeType":867},{},[16168],{"type":865},"For device code phishing,",{"data":16171,"marks":16172,"value":16173,"nodeType":867},{},[]," Push detects the phishing pages associated with device code phishing kits — including generic, technique-class detections that catch new kits without requiring kit-specific signatures. Second, Push provides an additional layer of protection on the legitimate device code authentication pages themselves, preventing users from entering attacker-supplied codes into them. Together, these detections cover both the kit-operated phishing infrastructure and the legitimate auth pages that the attack flow depends on.",{"data":16175,"content":16176,"nodeType":876},{},[16177,16182],{"data":16178,"marks":16179,"value":16181,"nodeType":867},{},[16180],{"type":865},"For OAuth supply chain attacks,",{"data":16183,"marks":16184,"value":16185,"nodeType":867},{},[]," Push's detects and controls OAuth consent flows at the browser layer — capturing which application is requesting access, what scopes it's requesting, and whether the grant should be permitted under organizational policy. Push customers can also block OAuth connection requests as they transit the browser, enabling security teams to stop unwanted integrations being added in the first place. ",{"data":16187,"content":16188,"nodeType":876},{},[16189,16194],{"data":16190,"marks":16191,"value":16193,"nodeType":867},{},[16192],{"type":865},"For the infostealer credential playbook,",{"data":16195,"marks":16196,"value":16197,"nodeType":867},{},[]," Push's stolen credential detection identifies when employees are using credentials that have appeared in breach datasets or dark web feeds — catching the moment a dormant infostealer credential surfaces at a browser-based login, as well as surfacing insecure login methods missing mitigating controls like MFA and enforcing them through in-browser guardrails. And on the supply side, Push's ClickFix detection addresses the browser-based delivery vector that is now the primary method for distributing infostealer malware in the first place.",{"data":16199,"content":16200,"nodeType":876},{},[16201,16204,16211],{"data":16202,"marks":16203,"value":21,"nodeType":867},{},[],{"data":16205,"content":16206,"nodeType":915},{"uri":8610},[16207],{"data":16208,"marks":16209,"value":16210,"nodeType":867},{},[],"Learn more about how you can use Push controls to protect your users from in-browser threats here. ",{"data":16212,"marks":16213,"value":21,"nodeType":867},{},[],{"data":16215,"content":16216,"nodeType":1058},{},[16217],{"data":16218,"marks":16219,"value":16221,"nodeType":867},{},[16220],{"type":865},"Closing thoughts",{"data":16223,"content":16224,"nodeType":876},{},[16225],{"data":16226,"marks":16227,"value":16228,"nodeType":867},{},[],"The campaigns documented in this post are not historical — they are ongoing, with new victims surfacing weekly and the underlying criminal infrastructure still actively developing. But the defensive strategy does not require anticipating which specific group, vector, or target sector comes next, because all of them converge on the same control point: the browser, where the attack begins or the integration decision is made. Organizations with browser-layer detection and OAuth governance in place have defense-in-depth against the full range of techniques these groups employ, regardless of which specific vector any given campaign uses.",{"data":16230,"content":16231,"nodeType":942},{},[],{"data":16233,"content":16234,"nodeType":876},{},[16235],{"data":16236,"marks":16237,"value":1667,"nodeType":867},{},[],{"data":16239,"content":16240,"nodeType":876},{},[16241],{"data":16242,"marks":16243,"value":3990,"nodeType":867},{},[],{"data":16245,"content":16246,"nodeType":876},{},[16247,16250,16256],{"data":16248,"marks":16249,"value":21,"nodeType":867},{},[],{"data":16251,"content":16252,"nodeType":915},{"uri":5286},[16253],{"data":16254,"marks":16255,"value":6672,"nodeType":867},{},[],{"data":16257,"marks":16258,"value":21,"nodeType":867},{},[],{"data":16260,"content":16261,"nodeType":942},{},[],{"data":16263,"content":16264,"nodeType":868},{},[16265],{"data":16266,"marks":16267,"value":16269,"nodeType":867},{},[16268],{"type":865},"Appendix: named ShinyHunters victims since May 2025",{"data":16271,"content":16272,"nodeType":876},{},[16273,16277,16284],{"data":16274,"marks":16275,"value":16276,"nodeType":867},{},[],"To give an indication of the scale, the following table documents all publicly named victims attributed to ShinyHunters specifically since the Salesforce campaign began in May 2025. It is not exhaustive: ShinyHunters has claimed over 1,000 organizations in aggregate across its Salesforce campaigns alone, and many victims have not been publicly named. This list also doesn’t include the billion-plus records compromised in the 2024 Snowflake breaches. The major ransomware attacks executed against M&S, Co-op, and Jaguar Land Rover claimed by the ",{"data":16278,"content":16279,"nodeType":915},{"uri":1177},[16280],{"data":16281,"marks":16282,"value":16283,"nodeType":867},{},[],"Scattered Lapsus$ Hunters \"brand\"",{"data":16285,"marks":16286,"value":16287,"nodeType":867},{},[]," also aren't listed below. ",{"data":16289,"content":16290,"nodeType":7904},{},[16291,16338,16402,16450,16498],{"data":16292,"content":16293,"nodeType":7640},{},[16294,16305,16316,16327],{"data":16295,"content":16296,"nodeType":7628},{},[16297],{"data":16298,"content":16299,"nodeType":876},{},[16300],{"data":16301,"marks":16302,"value":16304,"nodeType":867},{},[16303],{"type":865},"Campaign",{"data":16306,"content":16307,"nodeType":7628},{},[16308],{"data":16309,"content":16310,"nodeType":876},{},[16311],{"data":16312,"marks":16313,"value":16315,"nodeType":867},{},[16314],{"type":865},"Began",{"data":16317,"content":16318,"nodeType":7628},{},[16319],{"data":16320,"content":16321,"nodeType":876},{},[16322],{"data":16323,"marks":16324,"value":16326,"nodeType":867},{},[16325],{"type":865},"Named victims",{"data":16328,"content":16329,"nodeType":7628},{},[16330],{"data":16331,"content":16332,"nodeType":876},{},[16333],{"data":16334,"marks":16335,"value":16337,"nodeType":867},{},[16336],{"type":865},"Confirmed impact",{"data":16339,"content":16340,"nodeType":7640},{},[16341,16365,16375,16385],{"data":16342,"content":16343,"nodeType":7628},{},[16344],{"data":16345,"content":16346,"nodeType":876},{},[16347,16352,16356,16361],{"data":16348,"marks":16349,"value":16351,"nodeType":867},{},[16350],{"type":865},"ShinyHunters Salesforce Vishing",{"data":16353,"marks":16354,"value":16355,"nodeType":867},{},[]," (vishing + device code phishing → Salesforce connected app authorization) \n\n& ",{"data":16357,"marks":16358,"value":16360,"nodeType":867},{},[16359],{"type":865},"Salesloft/Drift Supply Chain",{"data":16362,"marks":16363,"value":16364,"nodeType":867},{},[]," (stolen OAuth tokens → downstream Salesforce access)",{"data":16366,"content":16367,"nodeType":7628},{},[16368],{"data":16369,"content":16370,"nodeType":876},{},[16371],{"data":16372,"marks":16373,"value":16374,"nodeType":867},{},[],"May 2025",{"data":16376,"content":16377,"nodeType":7628},{},[16378],{"data":16379,"content":16380,"nodeType":876},{},[16381],{"data":16382,"marks":16383,"value":16384,"nodeType":867},{},[],"Coca-Cola Europacific Partners, Cisco, Qantas, LVMH, Adidas, Google, Chanel, Pandora, Allianz Life, Air France-KLM, Farmers Insurance, Workday, TransUnion, Stellantis, Kering, Odido, Hallmark, Salesloft (origin), Toast, Avalara, Fastly, Cato Networks, Cloudflare, Palo Alto Networks, Zscaler, Tenable, Elastic, JFrog, CyberArk, Rubrik, BeyondTrust, Proofpoint, Workiva, Mercer Advisors, Beacon Pointe, Ameriprise, Kemper, Udemy, 7-Eleven, Mytheresa, Marcus & Millichap, Carnival, Pitney Bowes, Alert 360, Amtrak, McGraw-Hill, Canada Life, Charter Communications",{"data":16386,"content":16387,"nodeType":7628},{},[16388,16395],{"data":16389,"content":16390,"nodeType":876},{},[16391],{"data":16392,"marks":16393,"value":16394,"nodeType":867},{},[],"49 named victims. Confirmed individual impact includes 23M+ records (Coca-Cola), 5.7M records (Qantas), 6.2M customers (Odido), 4.4M consumers (TransUnion), up to 18M records (Stellantis), 13.5M emails (McGraw-Hill), 8.2M emails (Pitney Bowes), 7.5M emails (Carnival), 7-Eleven: 185K confirmed by HIBP (SSNs, driver's licenses; franchisee data), Charter Communications: millions of records claimed (company disputes scope). ",{"data":16396,"content":16397,"nodeType":876},{},[16398],{"data":16399,"marks":16400,"value":16401,"nodeType":867},{},[],"ShinyHunters claims 1.5B+ Salesforce records across 1,000+ organizations total.",{"data":16403,"content":16404,"nodeType":7640},{},[16405,16420,16430,16440],{"data":16406,"content":16407,"nodeType":7628},{},[16408],{"data":16409,"content":16410,"nodeType":876},{},[16411,16416],{"data":16412,"marks":16413,"value":16415,"nodeType":867},{},[16414],{"type":865},"Vishing + AiTM SSO",{"data":16417,"marks":16418,"value":16419,"nodeType":867},{},[]," (vishing → AiTM phishing page → SSO session capture → SaaS data exfiltration)",{"data":16421,"content":16422,"nodeType":7628},{},[16423],{"data":16424,"content":16425,"nodeType":876},{},[16426],{"data":16427,"marks":16428,"value":16429,"nodeType":867},{},[],"Aug 2025",{"data":16431,"content":16432,"nodeType":7628},{},[16433],{"data":16434,"content":16435,"nodeType":876},{},[16436],{"data":16437,"marks":16438,"value":16439,"nodeType":867},{},[],"SoundCloud, GrubHub, Panera Bread, Match Group, Crunchbase, Betterment, CarMax, Edmunds, CarGurus, Hims & Hers, University of Pennsylvania, Harvard University, Optimizely, TELUS Digital, Crunchyroll, ADT",{"data":16441,"content":16442,"nodeType":7628},{},[16443],{"data":16444,"content":16445,"nodeType":876},{},[16446],{"data":16447,"marks":16448,"value":16449,"nodeType":867},{},[],"16 named victims. Confirmed individual impact includes ~30M records (SoundCloud), ~14M records (Panera), 10M+ records (Match Group), ~20M records (Betterment), 5.5M people (ADT), 1M+ records (UPenn), ~1PB stolen from TELUS Digital ($65M ransom refused).",{"data":16451,"content":16452,"nodeType":7640},{},[16453,16468,16478,16488],{"data":16454,"content":16455,"nodeType":7628},{},[16456],{"data":16457,"content":16458,"nodeType":876},{},[16459,16464],{"data":16460,"marks":16461,"value":16463,"nodeType":867},{},[16462],{"type":865},"Anodot Supply Chain",{"data":16465,"marks":16466,"value":16467,"nodeType":867},{},[]," (stolen OAuth tokens → downstream Snowflake/BigQuery access)",{"data":16469,"content":16470,"nodeType":7628},{},[16471],{"data":16472,"content":16473,"nodeType":876},{},[16474],{"data":16475,"marks":16476,"value":16477,"nodeType":867},{},[],"Apr 2026",{"data":16479,"content":16480,"nodeType":7628},{},[16481],{"data":16482,"content":16483,"nodeType":876},{},[16484],{"data":16485,"marks":16486,"value":16487,"nodeType":867},{},[],"Anodot/Glassbox (origin), Rockstar Games, Vimeo, Zara/Inditex",{"data":16489,"content":16490,"nodeType":7628},{},[16491],{"data":16492,"content":16493,"nodeType":876},{},[16494],{"data":16495,"marks":16496,"value":16497,"nodeType":867},{},[],"4 named victims (12+ total claimed). 78.6M records (Rockstar Games), 197K individuals (Zara), 119K individuals (Vimeo).",{"data":16499,"content":16500,"nodeType":7640},{},[16501,16516,16525,16535],{"data":16502,"content":16503,"nodeType":7628},{},[16504],{"data":16505,"content":16506,"nodeType":876},{},[16507,16512],{"data":16508,"marks":16509,"value":16511,"nodeType":867},{},[16510],{"type":865},"Other SLH-attributed",{"data":16513,"marks":16514,"value":16515,"nodeType":867},{},[]," (misc. vectors including infostealer chains, CI/CD supply chain, SaaS platform compromise)",{"data":16517,"content":16518,"nodeType":7628},{},[16519],{"data":16520,"content":16521,"nodeType":876},{},[16522],{"data":16523,"marks":16524,"value":16374,"nodeType":867},{},[],{"data":16526,"content":16527,"nodeType":7628},{},[16528],{"data":16529,"content":16530,"nodeType":876},{},[16531],{"data":16532,"marks":16533,"value":16534,"nodeType":867},{},[],"UK Legal Aid Agency, Mixpanel, Wynn Resorts, Woflow, Vercel, European Commission, Mercor, Medtronic, Instructure",{"data":16536,"content":16537,"nodeType":7628},{},[16538],{"data":16539,"content":16540,"nodeType":876},{},[16541],{"data":16542,"marks":16543,"value":16544,"nodeType":867},{},[],"10 named victims across varied vectors. Notable: Vercel (Lumma Stealer → Context.ai OAuth app → Google Workspace), European Commission (poisoned Trivy GitHub Action → 340GB across 71 EU entities)",{"data":16546,"content":16547,"nodeType":876},{},[16548],{"data":16549,"marks":16550,"value":21,"nodeType":867},{},[],"The three attack techniques behind ShinyHunters' 2026 campaigns ","ShinyHunters' breach of Instructure is the latest in a long series of attacks. Here's our view of the big picture. ","analyzing-the-instructure-breach",{"items":16555},[16556,16558],{"sys":16557,"name":4018},{"id":4017},{"sys":16559,"name":342},{"id":3240},{"items":16561},[16562],{"fullName":4022,"firstName":4023,"jobTitle":4024,"profilePicture":16563},{"url":4026},"7-things-we-learned-from-john-hammond","blog/7-things-we-learned-from-john-hammond",{"json":16567},{"data":16568,"content":16569,"nodeType":1680},{},[16570],{"data":16571,"content":16572,"nodeType":876},{},[16573],{"data":16574,"marks":16575,"value":16576,"nodeType":867},{},[],"Luke Jennings (Push VP of Research) and John Hammond (Senior Principal Security Researcher, Huntress) walked through the browser-based attack techniques defining the 2026 threat landscape.","Here are 7 things we learned from our conversation with John Hammond on the \"Why the browser is the new battleground\" webinar. ",{"id":16579,"publishedAt":16580},"6V12IJexyAkFFVIrbwlNPq","2026-08-12T12:00:57.289Z",{"items":16582},[16583,16585],{"sys":16584,"name":4018},{"id":4017},{"sys":16586,"name":297},{"id":2706},{"items":16588},[16589,16591,16593,16595,16597,16599,16601,16603,16605,16607,16609,16611,16613,16615,16617,16619,16621,16623,16625,16627,16629,16631],{"sys":16590,"name":279,"slug":280,"tier":31},{"id":276},{"sys":16592,"name":519,"slug":520,"tier":31},{"id":516},{"sys":16594,"name":413,"slug":414,"tier":31},{"id":410},{"sys":16596,"name":297,"slug":298,"tier":31},{"id":294},{"sys":16598,"name":342,"slug":343,"tier":31},{"id":339},{"sys":16600,"name":235,"slug":236,"tier":31},{"id":232},{"sys":16602,"name":261,"slug":262,"tier":45},{"id":258},{"sys":16604,"name":315,"slug":316,"tier":45},{"id":312},{"sys":16606,"name":360,"slug":361,"tier":45},{"id":357},{"sys":16608,"name":484,"slug":485,"tier":45},{"id":481},{"sys":16610,"name":475,"slug":476,"tier":45},{"id":472},{"sys":16612,"name":511,"slug":512,"tier":45},{"id":508},{"sys":16614,"name":324,"slug":325,"tier":45},{"id":321},{"sys":16616,"name":571,"slug":572,"tier":45},{"id":568},{"sys":16618,"name":466,"slug":467,"tier":45},{"id":463},{"sys":16620,"name":440,"slug":441,"tier":45},{"id":437},{"sys":16622,"name":607,"slug":608,"tier":45},{"id":604},{"sys":16624,"name":377,"slug":378,"tier":45},{"id":374},{"sys":16626,"name":431,"slug":432,"tier":45},{"id":428},{"sys":16628,"name":448,"slug":449,"tier":45},{"id":445},{"sys":16630,"name":493,"slug":494,"tier":45},{"id":490},{"sys":16632,"name":244,"slug":245,"tier":45},{"id":241},"q4U5IPhRMZseIs6ceVJ_ZzUpucxUy-2TaBbYB9CbBVE",{"id":16635,"title":9977,"authorsCollection":16636,"content":16641,"extension":228,"faqItemsCollection":17416,"faqTitle":59,"featured":6,"hashTags":59,"meta":17418,"metaTitle":17419,"ogImage":59,"postType":1767,"publishedDate":9979,"relatedBlogPostsCollection":17420,"slug":9980,"stem":19647,"subtitle":59,"summary":19648,"synopsis":9978,"sys":19659,"tagsCollection":19661,"topicsCollection":19667,"__hash__":19715},"blog/blog/how-to-avoid-the-browser-security-buyers-trap.json",{"items":16637},[16638],{"fullName":4089,"firstName":4090,"jobTitle":851,"socialLinks":16639,"profilePicture":16640},[4092],{"url":4094},{"json":16642,"links":17301},{"data":16643,"content":16644,"nodeType":1680},{},[16645,16650,16656,16662,16668,16671,16678,16684,16694,16704,16709,16715,16718,16725,16731,16736,16742,16748,16841,16847,16850,16857,16863,16918,16931,16936,16942,16945,16952,16958,16965,16971,16977,17002,17008,17015,17021,17027,17033,17040,17046,17052,17058,17061,17068,17078,17084,17090,17097,17103,17109,17116,17122,17177,17190,17205,17212,17218,17225,17231,17237,17243,17248,17255,17261,17267,17272,17278,17284,17290,17295],{"data":16646,"content":16649,"nodeType":985},{"target":16647},{"sys":16648},{"id":9220,"type":982,"linkType":983},[],{"data":16651,"content":16652,"nodeType":876},{},[16653],{"data":16654,"marks":16655,"value":9228,"nodeType":867},{},[],{"data":16657,"content":16658,"nodeType":876},{},[16659],{"data":16660,"marks":16661,"value":9235,"nodeType":867},{},[],{"data":16663,"content":16664,"nodeType":876},{},[16665],{"data":16666,"marks":16667,"value":9242,"nodeType":867},{},[],{"data":16669,"content":16670,"nodeType":942},{},[],{"data":16672,"content":16673,"nodeType":868},{},[16674],{"data":16675,"marks":16676,"value":9253,"nodeType":867},{},[16677],{"type":865},{"data":16679,"content":16680,"nodeType":876},{},[16681],{"data":16682,"marks":16683,"value":9260,"nodeType":867},{},[],{"data":16685,"content":16686,"nodeType":876},{},[16687,16691],{"data":16688,"marks":16689,"value":9268,"nodeType":867},{},[16690],{"type":865},{"data":16692,"marks":16693,"value":9272,"nodeType":867},{},[],{"data":16695,"content":16696,"nodeType":876},{},[16697,16701],{"data":16698,"marks":16699,"value":9280,"nodeType":867},{},[16700],{"type":865},{"data":16702,"marks":16703,"value":9284,"nodeType":867},{},[],{"data":16705,"content":16708,"nodeType":985},{"target":16706},{"sys":16707},{"id":9289,"type":982,"linkType":983},[],{"data":16710,"content":16711,"nodeType":876},{},[16712],{"data":16713,"marks":16714,"value":9297,"nodeType":867},{},[],{"data":16716,"content":16717,"nodeType":942},{},[],{"data":16719,"content":16720,"nodeType":868},{},[16721],{"data":16722,"marks":16723,"value":9308,"nodeType":867},{},[16724],{"type":865},{"data":16726,"content":16727,"nodeType":876},{},[16728],{"data":16729,"marks":16730,"value":9315,"nodeType":867},{},[],{"data":16732,"content":16735,"nodeType":985},{"target":16733},{"sys":16734},{"id":9320,"type":982,"linkType":983},[],{"data":16737,"content":16738,"nodeType":876},{},[16739],{"data":16740,"marks":16741,"value":9328,"nodeType":867},{},[],{"data":16743,"content":16744,"nodeType":876},{},[16745],{"data":16746,"marks":16747,"value":9335,"nodeType":867},{},[],{"data":16749,"content":16750,"nodeType":1629},{},[16751,16767,16783,16799,16815,16828],{"data":16752,"content":16753,"nodeType":1586},{},[16754],{"data":16755,"content":16756,"nodeType":876},{},[16757,16760,16764],{"data":16758,"marks":16759,"value":9348,"nodeType":867},{},[],{"data":16761,"marks":16762,"value":8739,"nodeType":867},{},[16763],{"type":865},{"data":16765,"marks":16766,"value":9356,"nodeType":867},{},[],{"data":16768,"content":16769,"nodeType":1586},{},[16770],{"data":16771,"content":16772,"nodeType":876},{},[16773,16776,16780],{"data":16774,"marks":16775,"value":9366,"nodeType":867},{},[],{"data":16777,"marks":16778,"value":9371,"nodeType":867},{},[16779],{"type":865},{"data":16781,"marks":16782,"value":9375,"nodeType":867},{},[],{"data":16784,"content":16785,"nodeType":1586},{},[16786],{"data":16787,"content":16788,"nodeType":876},{},[16789,16792,16796],{"data":16790,"marks":16791,"value":9385,"nodeType":867},{},[],{"data":16793,"marks":16794,"value":9390,"nodeType":867},{},[16795],{"type":865},{"data":16797,"marks":16798,"value":9394,"nodeType":867},{},[],{"data":16800,"content":16801,"nodeType":1586},{},[16802],{"data":16803,"content":16804,"nodeType":876},{},[16805,16808,16812],{"data":16806,"marks":16807,"value":9404,"nodeType":867},{},[],{"data":16809,"marks":16810,"value":9409,"nodeType":867},{},[16811],{"type":865},{"data":16813,"marks":16814,"value":9413,"nodeType":867},{},[],{"data":16816,"content":16817,"nodeType":1586},{},[16818],{"data":16819,"content":16820,"nodeType":876},{},[16821,16825],{"data":16822,"marks":16823,"value":934,"nodeType":867},{},[16824],{"type":865},{"data":16826,"marks":16827,"value":9427,"nodeType":867},{},[],{"data":16829,"content":16830,"nodeType":1586},{},[16831],{"data":16832,"content":16833,"nodeType":876},{},[16834,16838],{"data":16835,"marks":16836,"value":9438,"nodeType":867},{},[16837],{"type":865},{"data":16839,"marks":16840,"value":9442,"nodeType":867},{},[],{"data":16842,"content":16843,"nodeType":876},{},[16844],{"data":16845,"marks":16846,"value":9449,"nodeType":867},{},[],{"data":16848,"content":16849,"nodeType":942},{},[],{"data":16851,"content":16852,"nodeType":1058},{},[16853],{"data":16854,"marks":16855,"value":9460,"nodeType":867},{},[16856],{"type":865},{"data":16858,"content":16859,"nodeType":876},{},[16860],{"data":16861,"marks":16862,"value":9467,"nodeType":867},{},[],{"data":16864,"content":16865,"nodeType":1629},{},[16866,16879,16892,16905],{"data":16867,"content":16868,"nodeType":1586},{},[16869],{"data":16870,"content":16871,"nodeType":876},{},[16872,16875],{"data":16873,"marks":16874,"value":9480,"nodeType":867},{},[],{"data":16876,"marks":16877,"value":9485,"nodeType":867},{},[16878],{"type":865},{"data":16880,"content":16881,"nodeType":1586},{},[16882],{"data":16883,"content":16884,"nodeType":876},{},[16885,16888],{"data":16886,"marks":16887,"value":9495,"nodeType":867},{},[],{"data":16889,"marks":16890,"value":9500,"nodeType":867},{},[16891],{"type":865},{"data":16893,"content":16894,"nodeType":1586},{},[16895],{"data":16896,"content":16897,"nodeType":876},{},[16898,16901],{"data":16899,"marks":16900,"value":9510,"nodeType":867},{},[],{"data":16902,"marks":16903,"value":9515,"nodeType":867},{},[16904],{"type":865},{"data":16906,"content":16907,"nodeType":1586},{},[16908],{"data":16909,"content":16910,"nodeType":876},{},[16911,16914],{"data":16912,"marks":16913,"value":9525,"nodeType":867},{},[],{"data":16915,"marks":16916,"value":9530,"nodeType":867},{},[16917],{"type":865},{"data":16919,"content":16920,"nodeType":876},{},[16921,16924,16928],{"data":16922,"marks":16923,"value":9537,"nodeType":867},{},[],{"data":16925,"marks":16926,"value":9542,"nodeType":867},{},[16927],{"type":865},{"data":16929,"marks":16930,"value":9546,"nodeType":867},{},[],{"data":16932,"content":16935,"nodeType":985},{"target":16933},{"sys":16934},{"id":9551,"type":982,"linkType":983},[],{"data":16937,"content":16938,"nodeType":876},{},[16939],{"data":16940,"marks":16941,"value":9559,"nodeType":867},{},[],{"data":16943,"content":16944,"nodeType":942},{},[],{"data":16946,"content":16947,"nodeType":868},{},[16948],{"data":16949,"marks":16950,"value":9570,"nodeType":867},{},[16951],{"type":865},{"data":16953,"content":16954,"nodeType":876},{},[16955],{"data":16956,"marks":16957,"value":9577,"nodeType":867},{},[],{"data":16959,"content":16960,"nodeType":1058},{},[16961],{"data":16962,"marks":16963,"value":9585,"nodeType":867},{},[16964],{"type":865},{"data":16966,"content":16967,"nodeType":876},{},[16968],{"data":16969,"marks":16970,"value":9592,"nodeType":867},{},[],{"data":16972,"content":16973,"nodeType":876},{},[16974],{"data":16975,"marks":16976,"value":9599,"nodeType":867},{},[],{"data":16978,"content":16979,"nodeType":876},{},[16980,16983,16989,16992,16999],{"data":16981,"marks":16982,"value":9606,"nodeType":867},{},[],{"data":16984,"content":16985,"nodeType":915},{"uri":4107},[16986],{"data":16987,"marks":16988,"value":9613,"nodeType":867},{},[],{"data":16990,"marks":16991,"value":9617,"nodeType":867},{},[],{"data":16993,"content":16994,"nodeType":915},{"uri":9620},[16995],{"data":16996,"marks":16997,"value":9626,"nodeType":867},{},[16998],{"type":913},{"data":17000,"marks":17001,"value":9630,"nodeType":867},{},[],{"data":17003,"content":17004,"nodeType":876},{},[17005],{"data":17006,"marks":17007,"value":9637,"nodeType":867},{},[],{"data":17009,"content":17010,"nodeType":1058},{},[17011],{"data":17012,"marks":17013,"value":9645,"nodeType":867},{},[17014],{"type":865},{"data":17016,"content":17017,"nodeType":876},{},[17018],{"data":17019,"marks":17020,"value":9652,"nodeType":867},{},[],{"data":17022,"content":17023,"nodeType":876},{},[17024],{"data":17025,"marks":17026,"value":9659,"nodeType":867},{},[],{"data":17028,"content":17029,"nodeType":876},{},[17030],{"data":17031,"marks":17032,"value":9666,"nodeType":867},{},[],{"data":17034,"content":17035,"nodeType":1058},{},[17036],{"data":17037,"marks":17038,"value":9674,"nodeType":867},{},[17039],{"type":865},{"data":17041,"content":17042,"nodeType":876},{},[17043],{"data":17044,"marks":17045,"value":9681,"nodeType":867},{},[],{"data":17047,"content":17048,"nodeType":876},{},[17049],{"data":17050,"marks":17051,"value":9688,"nodeType":867},{},[],{"data":17053,"content":17054,"nodeType":876},{},[17055],{"data":17056,"marks":17057,"value":9695,"nodeType":867},{},[],{"data":17059,"content":17060,"nodeType":942},{},[],{"data":17062,"content":17063,"nodeType":868},{},[17064],{"data":17065,"marks":17066,"value":9706,"nodeType":867},{},[17067],{"type":865},{"data":17069,"content":17070,"nodeType":876},{},[17071,17075],{"data":17072,"marks":17073,"value":9714,"nodeType":867},{},[17074],{"type":865},{"data":17076,"marks":17077,"value":9718,"nodeType":867},{},[],{"data":17079,"content":17080,"nodeType":876},{},[17081],{"data":17082,"marks":17083,"value":9725,"nodeType":867},{},[],{"data":17085,"content":17086,"nodeType":876},{},[17087],{"data":17088,"marks":17089,"value":9732,"nodeType":867},{},[],{"data":17091,"content":17092,"nodeType":1058},{},[17093],{"data":17094,"marks":17095,"value":9740,"nodeType":867},{},[17096],{"type":865},{"data":17098,"content":17099,"nodeType":876},{},[17100],{"data":17101,"marks":17102,"value":9747,"nodeType":867},{},[],{"data":17104,"content":17105,"nodeType":876},{},[17106],{"data":17107,"marks":17108,"value":9754,"nodeType":867},{},[],{"data":17110,"content":17111,"nodeType":1058},{},[17112],{"data":17113,"marks":17114,"value":9762,"nodeType":867},{},[17115],{"type":865},{"data":17117,"content":17118,"nodeType":876},{},[17119],{"data":17120,"marks":17121,"value":9769,"nodeType":867},{},[],{"data":17123,"content":17124,"nodeType":1629},{},[17125,17138,17151,17164],{"data":17126,"content":17127,"nodeType":1586},{},[17128],{"data":17129,"content":17130,"nodeType":876},{},[17131,17135],{"data":17132,"marks":17133,"value":9783,"nodeType":867},{},[17134],{"type":865},{"data":17136,"marks":17137,"value":9787,"nodeType":867},{},[],{"data":17139,"content":17140,"nodeType":1586},{},[17141],{"data":17142,"content":17143,"nodeType":876},{},[17144,17148],{"data":17145,"marks":17146,"value":9798,"nodeType":867},{},[17147],{"type":865},{"data":17149,"marks":17150,"value":9802,"nodeType":867},{},[],{"data":17152,"content":17153,"nodeType":1586},{},[17154],{"data":17155,"content":17156,"nodeType":876},{},[17157,17161],{"data":17158,"marks":17159,"value":9813,"nodeType":867},{},[17160],{"type":865},{"data":17162,"marks":17163,"value":9817,"nodeType":867},{},[],{"data":17165,"content":17166,"nodeType":1586},{},[17167],{"data":17168,"content":17169,"nodeType":876},{},[17170,17174],{"data":17171,"marks":17172,"value":9828,"nodeType":867},{},[17173],{"type":865},{"data":17175,"marks":17176,"value":9832,"nodeType":867},{},[],{"data":17178,"content":17179,"nodeType":876},{},[17180,17183,17187],{"data":17181,"marks":17182,"value":9839,"nodeType":867},{},[],{"data":17184,"marks":17185,"value":9844,"nodeType":867},{},[17186],{"type":865},{"data":17188,"marks":17189,"value":9848,"nodeType":867},{},[],{"data":17191,"content":17192,"nodeType":876},{},[17193,17196,17202],{"data":17194,"marks":17195,"value":9855,"nodeType":867},{},[],{"data":17197,"content":17198,"nodeType":915},{"uri":4435},[17199],{"data":17200,"marks":17201,"value":9862,"nodeType":867},{},[],{"data":17203,"marks":17204,"value":9866,"nodeType":867},{},[],{"data":17206,"content":17207,"nodeType":1058},{},[17208],{"data":17209,"marks":17210,"value":9874,"nodeType":867},{},[17211],{"type":865},{"data":17213,"content":17214,"nodeType":876},{},[17215],{"data":17216,"marks":17217,"value":9881,"nodeType":867},{},[],{"data":17219,"content":17220,"nodeType":876},{},[17221],{"data":17222,"marks":17223,"value":9889,"nodeType":867},{},[17224],{"type":865},{"data":17226,"content":17227,"nodeType":876},{},[17228],{"data":17229,"marks":17230,"value":9896,"nodeType":867},{},[],{"data":17232,"content":17233,"nodeType":876},{},[17234],{"data":17235,"marks":17236,"value":9903,"nodeType":867},{},[],{"data":17238,"content":17239,"nodeType":876},{},[17240],{"data":17241,"marks":17242,"value":9910,"nodeType":867},{},[],{"data":17244,"content":17247,"nodeType":985},{"target":17245},{"sys":17246},{"id":9915,"type":982,"linkType":983},[],{"data":17249,"content":17250,"nodeType":1058},{},[17251],{"data":17252,"marks":17253,"value":9924,"nodeType":867},{},[17254],{"type":865},{"data":17256,"content":17257,"nodeType":876},{},[17258],{"data":17259,"marks":17260,"value":9931,"nodeType":867},{},[],{"data":17262,"content":17263,"nodeType":876},{},[17264],{"data":17265,"marks":17266,"value":9938,"nodeType":867},{},[],{"data":17268,"content":17271,"nodeType":985},{"target":17269},{"sys":17270},{"id":5755,"type":982,"linkType":983},[],{"data":17273,"content":17274,"nodeType":876},{},[17275],{"data":17276,"marks":17277,"value":9950,"nodeType":867},{},[],{"data":17279,"content":17280,"nodeType":876},{},[17281],{"data":17282,"marks":17283,"value":9957,"nodeType":867},{},[],{"data":17285,"content":17286,"nodeType":876},{},[17287],{"data":17288,"marks":17289,"value":9964,"nodeType":867},{},[],{"data":17291,"content":17294,"nodeType":985},{"target":17292},{"sys":17293},{"id":9969,"type":982,"linkType":983},[],{"data":17296,"content":17297,"nodeType":876},{},[17298],{"data":17299,"marks":17300,"value":21,"nodeType":867},{},[],{"entries":17302},{"hyperlink":17303,"inline":17304,"block":17305},[],[],[17306,17332,17336,17372,17395,17409,17412],{"sys":17307,"__typename":1705,"content":17308,"name":17331,"title":59},{"id":9220},{"json":17309},{"nodeType":1680,"data":17310,"content":17311},{},[17312,17324],{"nodeType":876,"data":17313,"content":17314},{},[17315,17320],{"nodeType":867,"value":17316,"marks":17317,"data":17319},"TL;DR:",[17318],{"type":865},{},{"nodeType":867,"value":17321,"marks":17322,"data":17323}," Not all browser security investments address the same threat. Seraphic (Crowdstrike) focuses on browser exploitation, SquareX (ZScaler) on malware sandboxing, LayerX on internal governance. None of these address the attacks that are actually causing the most damaging breaches today: identity theft, credential abuse, and session hijacking that play out entirely inside the browser using legitimate authentication flows. Push Security is built specifically for that threat model — delivering the greatest coverage against the most damaging attacks, without the user friction, operational management burden, or stability risks associated with other solutions.",[],{},{"nodeType":876,"data":17325,"content":17326},{},[17327],{"nodeType":867,"value":17328,"marks":17329,"data":17330},"\n",[],{},"Browser security buyer's trap IB1",{"sys":17333,"__typename":1697,"type":1698,"ctaText":17334,"buttonLabel":17335,"buttonColour":1701,"buttonUrl":1702},{"id":9289},"Get our latest technical whitepaper to learn about the state of browser-based attacks in 2026 (no sign-up required).","Download Now",{"sys":17337,"__typename":1705,"content":17338,"name":17371,"title":59},{"id":9320},{"json":17339},{"data":17340,"content":17341,"nodeType":1680},{},[17342],{"data":17343,"content":17344,"nodeType":876},{},[17345,17349,17356,17359,17367],{"data":17346,"marks":17347,"value":17348,"nodeType":867},{},[],"You can read about ",{"data":17350,"content":17351,"nodeType":915},{"uri":1177},[17352],{"data":17353,"marks":17354,"value":11991,"nodeType":867},{},[17355],{"type":913},{"data":17357,"marks":17358,"value":1174,"nodeType":867},{},[],{"data":17360,"content":17361,"nodeType":915},{"uri":1165},[17362],{"data":17363,"marks":17364,"value":17366,"nodeType":867},{},[17365],{"type":913},"ShinyHunters’ 2026 campaigns and TTPs",{"data":17368,"marks":17369,"value":17370,"nodeType":867},{},[]," in our dedicated blog posts. ","Browser security buyer's trap IB2",{"sys":17373,"__typename":1705,"content":17374,"name":17394,"title":59},{"id":9551},{"json":17375},{"data":17376,"content":17377,"nodeType":1680},{},[17378],{"data":17379,"content":17380,"nodeType":876},{},[17381,17385,17390],{"data":17382,"marks":17383,"value":17384,"nodeType":867},{},[],"It's worth heading off the obvious counterargument: ",{"data":17386,"marks":17387,"value":17389,"nodeType":867},{},[17388],{"type":865},"won't AI-assisted vulnerability discovery eventually make browser exploits cheaper? ",{"data":17391,"marks":17392,"value":17393,"nodeType":867},{},[],"Perhaps — but it will simultaneously make them easier for browser vendors to find and patch, and vendors like Google and Microsoft have the engineering capacity and financial incentive to scale AI-driven remediation far faster than attackers can scale exploit development. ","Browser security buyer's trap IB3",{"sys":17396,"__typename":1705,"content":17397,"name":17408,"title":59},{"id":9915},{"json":17398},{"nodeType":1680,"data":17399,"content":17400},{},[17401],{"nodeType":876,"data":17402,"content":17403},{},[17404],{"nodeType":867,"value":17405,"marks":17406,"data":17407},"Solutions optimized for browser exploitation are defending against a shrinking attack category. Browser vendors are very good at closing those vulnerabilities, quickly. The ROI trajectory points the wrong way.",[],{},"Browser security buyer's trap IB4",{"sys":17410,"__typename":1688,"title":8600,"caption":8601,"layoutMode":59,"file":17411},{"id":5755},{"url":8603,"width":8604,"height":8605},{"sys":17413,"__typename":1697,"type":1698,"ctaText":17414,"buttonLabel":17415,"buttonColour":1701,"buttonUrl":5286},{"id":9969},"Ready to learn more about Push? Book a demo with one of our team. ","Book a Demo",{"items":17417},[],{},"Solving for attacks that happen in, not on the browser",{"items":17421},[17422,18372,19205],{"__typename":1772,"sys":17423,"content":17425,"title":18358,"synopsis":18359,"hashTags":59,"publishedDate":18360,"slug":18361,"tagsCollection":18362,"authorsCollection":18368},{"id":17424},"1jfqiWQlL6qkn3i9yjNbFB",{"json":17426},{"data":17427,"content":17428,"nodeType":1680},{},[17429,17436,17457,17469,17476,17484,17491,17513,17520,17527,17534,17546,17552,17555,17563,17579,17598,17708,17713,17720,17726,17734,17741,17753,17760,17766,17773,17796,17803,17810,17816,17819,17827,17834,17842,17849,17864,17871,17878,17886,17893,17900,17908,17915,17922,17925,17933,17940,17948,17955,17962,17969,17976,17984,17991,18023,18030,18037,18043,18050,18058,18065,18143,18149,18157,18173,18180,18186,18193,18209,18212,18220,18227,18234,18240,18247,18292,18299,18306,18313,18319,18322,18330,18336,18342],{"data":17430,"content":17431,"nodeType":876},{},[17432],{"data":17433,"marks":17434,"value":17435,"nodeType":867},{},[],"In March, our threat hunting engine flagged something it hadn’t seen before.",{"data":17437,"content":17438,"nodeType":876},{},[17439,17443,17453],{"data":17440,"marks":17441,"value":17442,"nodeType":867},{},[],"Our research team had already been tracking the growing use of ",{"data":17444,"content":17448,"nodeType":17452},{"target":17445},{"sys":17446},{"id":17447,"type":982,"linkType":983},"2U6QpQ9rkY8x5ES48okHZB",[17449],{"data":17450,"marks":17451,"value":441,"nodeType":867},{},[],"entry-hyperlink",{"data":17454,"marks":17455,"value":17456,"nodeType":867},{},[]," tied to phishing campaigns. Malvertising frequently targets users via Google Search results, inserting malicious ads or redirects in place of legitimate ads, and using the familiar context of the search results page to trick users into clicking.",{"data":17458,"content":17459,"nodeType":876},{},[17460,17464],{"data":17461,"marks":17462,"value":17463,"nodeType":867},{},[],"To defend Push customers against this threat, we needed a way to spot malicious activity arising from clicking on Google ads. ",{"data":17465,"marks":17466,"value":17468,"nodeType":867},{},[17467],{"type":1303},"But how to separate signal from noise?",{"data":17470,"content":17471,"nodeType":876},{},[17472],{"data":17473,"marks":17474,"value":17475,"nodeType":867},{},[],"Our hunt combined the skills of human researchers and AI agents to find 12 meaningful results from trillions of browser events visible to the Push extension across our install base.",{"data":17477,"content":17478,"nodeType":876},{},[17479],{"data":17480,"marks":17481,"value":17483,"nodeType":867},{},[17482],{"type":865},"Of those, one was novel. ",{"data":17485,"content":17486,"nodeType":876},{},[17487],{"data":17488,"marks":17489,"value":17490,"nodeType":867},{},[],"A user had searched for NotebookLM, clicked a paid Google ad, and gotten redirected to a page impersonating NotebookLM. The page itself was just a facade fronting a Cloudflare Pages-hosted phishing kit with a WebAssembly C2 connector. To the user, it looked like a completely on-brand NotebookLM page, and if they had run the fake install prompt, they would have installed malware. (Note: NotebookLM doesn’t even require a local install, but the page was convincing enough — and AI platforms are changing so quickly — that the lure was extremely believable.)",{"data":17492,"content":17493,"nodeType":876},{},[17494,17499,17509],{"data":17495,"marks":17496,"value":17498,"nodeType":867},{},[17497],{"type":865},"We had found our first in-the-wild ",{"data":17500,"content":17504,"nodeType":17452},{"target":17501},{"sys":17502},{"id":17503,"type":982,"linkType":983},"7bG71Eo43crbIHKzczooVS",[17505],{"data":17506,"marks":17507,"value":3937,"nodeType":867},{},[17508],{"type":865},{"data":17510,"marks":17511,"value":1679,"nodeType":867},{},[17512],{"type":865},{"data":17514,"content":17515,"nodeType":876},{},[17516],{"data":17517,"marks":17518,"value":17519,"nodeType":867},{},[],"Within minutes, our analysis agents created detections, and researchers shipped a new detection to every Push customer. ",{"data":17521,"content":17522,"nodeType":876},{},[17523],{"data":17524,"marks":17525,"value":17526,"nodeType":867},{},[],"Eighteen months ago, it would have taken a human analyst days or even weeks to unpack the attack, comb through web requests, de-obfuscate web code, trace JavaScript execution, and extract signals of tactics, techniques, and procedures (TTPs) beyond short-lived single-use IOCs like domain name, then get their work coded up as a detection and deployed to customers. ",{"data":17528,"content":17529,"nodeType":876},{},[17530],{"data":17531,"marks":17532,"value":17533,"nodeType":867},{},[],"That was viable when new tools or techniques showed up once or twice a quarter. It doesn’t stand a chance when attack evolutions occur weekly or even daily. That’s the reality now with AI-generated adversary tools.",{"data":17535,"content":17536,"nodeType":876},{},[17537,17542],{"data":17538,"marks":17539,"value":17541,"nodeType":867},{},[17540],{"type":865},"So, can AI agents replace human threat researchers?",{"data":17543,"marks":17544,"value":17545,"nodeType":867},{},[]," That’s the wrong question. Can AI agents massively scale the expertise of a seasoned human threat hunter without getting bored of repetitive tasks, missing pertinent but easily overlooked details, or creating operational siloes dependent on one person’s knowledge — and do its work continuously across trillions of data points? Yes, absolutely.",{"data":17547,"content":17551,"nodeType":985},{"target":17548},{"sys":17549},{"id":17550,"type":982,"linkType":983},"3OiZ7BrViCTTMmHUAbloEt",[],{"data":17553,"content":17554,"nodeType":942},{},[],{"data":17556,"content":17557,"nodeType":868},{},[17558],{"data":17559,"marks":17560,"value":17562,"nodeType":867},{},[17561],{"type":865},"Why scaling browser threat detection requires more than more analysts",{"data":17564,"content":17565,"nodeType":876},{},[17566,17570,17575],{"data":17567,"marks":17568,"value":17569,"nodeType":867},{},[],"Already this year, we’ve ",{"data":17571,"marks":17572,"value":17574,"nodeType":867},{},[17573],{"type":865},"tripled",{"data":17576,"marks":17577,"value":17578,"nodeType":867},{},[]," the cumulative number of detections shipped to Push customers using this pipeline. That output points to the first problem we set out to solve by employing AI agents: Scaling our research team’s considerable expertise.",{"data":17580,"content":17581,"nodeType":876},{},[17582,17586,17594],{"data":17583,"marks":17584,"value":17585,"nodeType":867},{},[],"Push’s R&D team are experts at understanding and unpacking modern browser-based attacks. This is essential when you consider how quickly attacks themselves are evolving. When we created the ",{"data":17587,"content":17590,"nodeType":17452},{"target":17588},{"sys":17589},{"id":14746,"type":982,"linkType":983},[17591],{"data":17592,"marks":17593,"value":5905,"nodeType":867},{},[],{"data":17595,"marks":17596,"value":17597,"nodeType":867},{},[]," in 2023 (then called the SaaS Attacks Matrix), many of the ideas in it were theoretical. Not anymore. ",{"data":17599,"content":17600,"nodeType":1629},{},[17601,17611,17634],{"data":17602,"content":17603,"nodeType":1586},{},[17604],{"data":17605,"content":17606,"nodeType":876},{},[17607],{"data":17608,"marks":17609,"value":17610,"nodeType":867},{},[],"We’ve tracked the rise of AiTM phish kits from their status as MFA-bypassing novelties to the emergence of an entire criminal ecosystem built around increasingly sophisticated Phishing-as-a-Service tools. ",{"data":17612,"content":17613,"nodeType":1586},{},[17614],{"data":17615,"content":17616,"nodeType":876},{},[17617,17621,17630],{"data":17618,"marks":17619,"value":17620,"nodeType":867},{},[],"We imagined the simple but effective power of using device code authorization for phishing three years ago; in the last few months, we’ve detected a 37x increase in ",{"data":17622,"content":17625,"nodeType":17452},{"target":17623},{"sys":17624},{"id":11729,"type":982,"linkType":983},[17626],{"data":17627,"marks":17628,"value":17629,"nodeType":867},{},[],"device code phishing attacks",{"data":17631,"marks":17632,"value":17633,"nodeType":867},{},[]," across our install base. ",{"data":17635,"content":17636,"nodeType":1586},{},[17637],{"data":17638,"content":17639,"nodeType":876},{},[17640,17644,17653,17657,17666,17670,17680,17683,17691,17694,17704],{"data":17641,"marks":17642,"value":17643,"nodeType":867},{},[],"We were also the first to detect a novel post-authorization attack we dubbed ",{"data":17645,"content":17649,"nodeType":17452},{"target":17646},{"sys":17647},{"id":17648,"type":982,"linkType":983},"71EaaK7lfl6bQBbkAU0qjv",[17650],{"data":17651,"marks":17652,"value":3685,"nodeType":867},{},[],{"data":17654,"marks":17655,"value":17656,"nodeType":867},{},[]," that combines OAuth consent phishing and ClickFix-style user prompts; reported on the rise of the ridiculously simple yet effective ",{"data":17658,"content":17661,"nodeType":17452},{"target":17659},{"sys":17660},{"id":17503,"type":982,"linkType":983},[17662],{"data":17663,"marks":17664,"value":17665,"nodeType":867},{},[],"InstallFix technique",{"data":17667,"marks":17668,"value":17669,"nodeType":867},{},[]," described earlier; and detected an array of other ",{"data":17671,"content":17675,"nodeType":17452},{"target":17672},{"sys":17673},{"id":17674,"type":982,"linkType":983},"2YmiesBvJHGw4wiKEKzLUq",[17676],{"data":17677,"marks":17678,"value":17679,"nodeType":867},{},[],"creative",{"data":17681,"marks":17682,"value":2136,"nodeType":867},{},[],{"data":17684,"content":17687,"nodeType":17452},{"target":17685},{"sys":17686},{"id":17447,"type":982,"linkType":983},[17688],{"data":17689,"marks":17690,"value":520,"nodeType":867},{},[],{"data":17692,"marks":17693,"value":2136,"nodeType":867},{},[],{"data":17695,"content":17699,"nodeType":17452},{"target":17696},{"sys":17697},{"id":17698,"type":982,"linkType":983},"6Zosy4SU0LpjlaSWX75peb",[17700],{"data":17701,"marks":17702,"value":17703,"nodeType":867},{},[],"campaigns",{"data":17705,"marks":17706,"value":17707,"nodeType":867},{},[]," tied to malvertising scams.",{"data":17709,"content":17712,"nodeType":985},{"target":17710},{"sys":17711},{"id":6253,"type":982,"linkType":983},[],{"data":17714,"content":17715,"nodeType":876},{},[17716],{"data":17717,"marks":17718,"value":17719,"nodeType":867},{},[],"With an agentic approach, we could scale this expertise and reduce the time it takes to go from technique discovery to production-ready detection. This speed is critical now because adversaries are also using AI tools to do their work, exploding the number of trivial-to-rotate indicators of compromise and overwhelming existing detection workflows that lack an equivalent machine speed.",{"data":17721,"content":17725,"nodeType":985},{"target":17722},{"sys":17723},{"id":17724,"type":982,"linkType":983},"1u00uFbC4xsvP9lqahXbgD",[],{"data":17727,"content":17728,"nodeType":1058},{},[17729],{"data":17730,"marks":17731,"value":17733,"nodeType":867},{},[17732],{"type":865},"Scaling behavioral detections, not just making bigger blocklists",{"data":17735,"content":17736,"nodeType":876},{},[17737],{"data":17738,"marks":17739,"value":17740,"nodeType":867},{},[],"But output numbers alone don’t tell the story of successful detections. That’s the other problem we set out to solve at scale: Most secure browser solutions rely on detection logic based on blocking known-bad indicators like domains, IPs, and URLs.",{"data":17742,"content":17743,"nodeType":876},{},[17744,17749],{"data":17745,"marks":17746,"value":17748,"nodeType":867},{},[17747],{"type":865},"If your solution offers 1,000 detections, and they’re all based on known-bad indicators that are easily rotated, then you’ve got 1,000 detections that worked once and will likely never fire again. ",{"data":17750,"marks":17751,"value":17752,"nodeType":867},{},[],"They certainly won’t catch subtle adaptations in adversary techniques that don’t rely on infrastructure changes, which are easy for attackers to swap anyway. ",{"data":17754,"content":17755,"nodeType":876},{},[17756],{"data":17757,"marks":17758,"value":17759,"nodeType":867},{},[],"Push does it differently. Our detection engine is focused on hunting for tactics, techniques, and procedures: the behavioral fingerprints of an attack, not just the infrastructure it runs on. ",{"data":17761,"content":17765,"nodeType":985},{"target":17762},{"sys":17763},{"id":17764,"type":982,"linkType":983},"5jR3YVUiusHGnXDOyrgYpr",[],{"data":17767,"content":17768,"nodeType":876},{},[17769],{"data":17770,"marks":17771,"value":17772,"nodeType":867},{},[],"Instead of blocking based on known-bad domains, URLs, and IPs, our detections are built around user-level and page-level behaviors like what scripts load, how redirects behave, what events fire, what actions a user takes and what happens next, etc. (In fact, Push detections don’t even use any infrastructure-based IOCs, though customers can write their own custom detections if they have a specific IOC they’re keeping an eye on.)",{"data":17774,"content":17775,"nodeType":876},{},[17776,17781,17791],{"data":17777,"marks":17778,"value":17780,"nodeType":867},{},[17779],{"type":865},"All the detections we write would survive infrastructure rotation by adversaries, and many of our existing detections have caught never-before-seen evolutions in TTPs. That’s because we focus on the top of the ",{"data":17782,"content":17786,"nodeType":17452},{"target":17783},{"sys":17784},{"id":17785,"type":982,"linkType":983},"1qegIy4rMdm5XZXnIEoKpE",[17787],{"data":17788,"marks":17789,"value":972,"nodeType":867},{},[17790],{"type":865},{"data":17792,"marks":17793,"value":17795,"nodeType":867},{},[17794],{"type":865},", the indicators that are hardest for attackers to change.",{"data":17797,"content":17798,"nodeType":876},{},[17799],{"data":17800,"marks":17801,"value":17802,"nodeType":867},{},[],"This focus on detecting TTPs has always been our approach. But with the acceleration in both attack types and the ease with which adversaries rotate infrastructure, we needed to build capabilities that scaled our knowledge. ",{"data":17804,"content":17805,"nodeType":876},{},[17806],{"data":17807,"marks":17808,"value":17809,"nodeType":867},{},[],"We did this not by replacing researchers, but by continuously activating their expertise. You can hear what our CEO and Co-founder Adam had to say about this below. ",{"data":17811,"content":17815,"nodeType":985},{"target":17812},{"sys":17813},{"id":17814,"type":982,"linkType":983},"C9gr4nF3f6CW45Aol9xij",[],{"data":17817,"content":17818,"nodeType":942},{},[],{"data":17820,"content":17821,"nodeType":868},{},[17822],{"data":17823,"marks":17824,"value":17826,"nodeType":867},{},[17825],{"type":865},"Core principles for agentic threat hunting",{"data":17828,"content":17829,"nodeType":876},{},[17830],{"data":17831,"marks":17832,"value":17833,"nodeType":867},{},[],"Three principles make Push's agentic threat hunting and detection engineering pipeline work:",{"data":17835,"content":17836,"nodeType":1058},{},[17837],{"data":17838,"marks":17839,"value":17841,"nodeType":867},{},[17840],{"type":865},"Context matters more than custom models",{"data":17843,"content":17844,"nodeType":876},{},[17845],{"data":17846,"marks":17847,"value":17848,"nodeType":867},{},[],"We’re not AI researchers; we’re security researchers — we aren't trying to compete in building the most intelligent models. And in our view, AI models are quickly becoming commoditized like cloud infrastructure, anyway. Luckily, the commercial models today already excel at understanding web code. We just need to harness their power with our expertise.",{"data":17850,"content":17851,"nodeType":876},{},[17852,17856,17860],{"data":17853,"marks":17854,"value":17855,"nodeType":867},{},[],"So at Push, we use a variety of commercial AI models and tools in complementary ways. What matters most is the telemetry they analyze, and that’s where Push’s existing product infrastructure shines: We’re already deployed into over ",{"data":17857,"marks":17858,"value":1435,"nodeType":867},{},[17859],{"type":865},{"data":17861,"marks":17862,"value":17863,"nodeType":867},{},[],", and the Push browser extension includes a component that operates as a flight recorder to locally record everything that matters inside a browser session.",{"data":17865,"content":17866,"nodeType":876},{},[17867],{"data":17868,"marks":17869,"value":17870,"nodeType":867},{},[],"This universe of metadata — DOM elements, tab context, script execution, network traffic, user actions, credential entry, etc. — becomes the searchable corpus for hunts. Metadata is stored locally in users’ browsers and only queried during targeted threat hunts. ",{"data":17872,"content":17873,"nodeType":876},{},[17874],{"data":17875,"marks":17876,"value":17877,"nodeType":867},{},[],"This approach avoids dragnet collection of sensitive data. Instead, we focus on collecting metadata and distilling that into patterns and insights that provide context for agents to perform their analysis. This means that Push also does not train or fine-tune models on customer data.",{"data":17879,"content":17880,"nodeType":1058},{},[17881],{"data":17882,"marks":17883,"value":17885,"nodeType":867},{},[17884],{"type":865},"Agents are only as good as the context you give them. Good context is researcher-led",{"data":17887,"content":17888,"nodeType":876},{},[17889],{"data":17890,"marks":17891,"value":17892,"nodeType":867},{},[],"AI agents don’t know how to identify the TTPs of browser-based attacks until you give them the right context, and Push researchers have spent years unpacking these techniques and tools. Agents at Push consume our internal knowledge base of identified TTPs, and both humans and agents perform meta-analyses to check their work. The agents have access to large libraries of traces of human interactions with real phishing kits. This is a powerful dataset to build on.",{"data":17894,"content":17895,"nodeType":876},{},[17896],{"data":17897,"marks":17898,"value":17899,"nodeType":867},{},[],"When we don’t get the results we want from AI models, the question is “What context is it missing? What does our human team know that the agents don’t, and how can we give them that context — do they need data, tools, better workflows?” That closes the gap in performance and keeps quality high.",{"data":17901,"content":17902,"nodeType":1058},{},[17903],{"data":17904,"marks":17905,"value":17907,"nodeType":867},{},[17906],{"type":865},"Integrated architecture that makes agentic AI the throughput layer, not a bolt-on",{"data":17909,"content":17910,"nodeType":876},{},[17911],{"data":17912,"marks":17913,"value":17914,"nodeType":867},{},[],"The constraint we’re trying to break by using AI isn’t knowledge, it’s throughput. Our researchers deeply understand the techniques and tools. An agentic pipeline can apply that understanding continuously across millions of browsers and trillions of events, ingest new external signals, generate hunt hypotheses, triage results, and return only the findings that warrant escalation.",{"data":17916,"content":17917,"nodeType":876},{},[17918],{"data":17919,"marks":17920,"value":17921,"nodeType":867},{},[],"This approach relies on tight integration of our product and our agentic workflows. We’ll take a closer look at that in the next section.",{"data":17923,"content":17924,"nodeType":942},{},[],{"data":17926,"content":17927,"nodeType":868},{},[17928],{"data":17929,"marks":17930,"value":17932,"nodeType":867},{},[17931],{"type":865},"How the agentic detection pipeline runs",{"data":17934,"content":17935,"nodeType":876},{},[17936],{"data":17937,"marks":17938,"value":17939,"nodeType":867},{},[],"Now let’s look at how agentic threat detection actually works, and some of the emerging best practices we’ve identified. We'll cover two example hunts, one initiated autonomously by the agents themselves, and one by our research team. ",{"data":17941,"content":17942,"nodeType":1058},{},[17943],{"data":17944,"marks":17945,"value":17947,"nodeType":867},{},[17946],{"type":865},"Example 1: Autonomous threat hunt",{"data":17949,"content":17950,"nodeType":876},{},[17951],{"data":17952,"marks":17953,"value":17954,"nodeType":867},{},[],"Push’s threat hunting pipeline ingested context from research articles describing a new attack technique, and an agent developed hypotheses on what to hunt for across Push’s install base to identify instances of this attack. ",{"data":17956,"content":17957,"nodeType":876},{},[17958],{"data":17959,"marks":17960,"value":17961,"nodeType":867},{},[],"The agent crafted detection queries and then refined them to reduce false positives. The successful query ran across stored metadata and returned results, validating that there were zero false positives. ",{"data":17963,"content":17964,"nodeType":876},{},[17965],{"data":17966,"marks":17967,"value":17968,"nodeType":867},{},[],"The validated query became a scheduled job that runs on a regular cadence to monitor for potentially malicious signals. A triage agent then received any matches, did an initial analysis, and passed anything that looked suspicious to another agent to perform deeper analysis. This deep analysis agent wields the full investigative toolkit that a human researcher would — using Push’s internal knowledge base, domain age and registration analysis, URLScan and whois lookups, DOM image analysis, and contextual analysis of page-level and user-level behaviors, etc.",{"data":17970,"content":17971,"nodeType":876},{},[17972],{"data":17973,"marks":17974,"value":17975,"nodeType":867},{},[],"Within a few minutes, it can filter a thousand or more signals in a hunt trace down to a handful with meaning and provide an actionable assessment. Then, once the TTP was well-understood, other agents wrote and refined detections that can raise alerts for customers when an event of this type is seen. The Push platform immediately applies the customer’s configured security controls, such as blocking users from interacting with malicious pages.",{"data":17977,"content":17978,"nodeType":1058},{},[17979],{"data":17980,"marks":17981,"value":17983,"nodeType":867},{},[17982],{"type":865},"Example 2: Human-initiated threat hunt",{"data":17985,"content":17986,"nodeType":876},{},[17987],{"data":17988,"marks":17989,"value":17990,"nodeType":867},{},[],"Now, going back to the example from the beginning of the article: InstallFix. This hunt started with a thorny problem our research team needed to solve: How to detect bad things downstream of a user interacting with a Google ad? We needed a way to pinpoint the bad links from the good ones.",{"data":17992,"content":17993,"nodeType":876},{},[17994,17998,18003,18006,18011,18014,18019],{"data":17995,"marks":17996,"value":17997,"nodeType":867},{},[],"Our researchers collaborated with agents to formulate the right parameters for hunt queries, taking into account that good ads are normally bought by companies with marketing budgets, so therefore ads will be expected to redirect to pages hosted on custom domains, not shared domains like ",{"data":17999,"marks":18000,"value":18002,"nodeType":867},{},[18001],{"type":865},"*pages.dev",{"data":18004,"marks":18005,"value":5136,"nodeType":867},{},[],{"data":18007,"marks":18008,"value":18010,"nodeType":867},{},[18009],{"type":865},"*workers.dev",{"data":18012,"marks":18013,"value":5136,"nodeType":867},{},[],{"data":18015,"marks":18016,"value":18018,"nodeType":867},{},[18017],{"type":865},"*squarespace.com",{"data":18020,"marks":18021,"value":18022,"nodeType":867},{},[],", etc.",{"data":18024,"content":18025,"nodeType":876},{},[18026],{"data":18027,"marks":18028,"value":18029,"nodeType":867},{},[],"Our AI agents already understood key TTPs that indicated potential maliciousness on a page: password prompts, file downloads, OAuth integrations, clipboard copies, and similar user prompts that are frequently abused.",{"data":18031,"content":18032,"nodeType":876},{},[18033],{"data":18034,"marks":18035,"value":18036,"nodeType":867},{},[],"The agent ran several queries that returned matching browsing traces — the term we use for sequences of events in a session or tab context — where the user clicked a Google ad, was redirected to a page on a shared hosting domain, and then clicked a button to copy content to their clipboard.",{"data":18038,"content":18042,"nodeType":985},{"target":18039},{"sys":18040},{"id":18041,"type":982,"linkType":983},"4IWOrWuvbwzWRJUkINiwKH",[],{"data":18044,"content":18045,"nodeType":876},{},[18046],{"data":18047,"marks":18048,"value":18049,"nodeType":867},{},[],"We got back high-fidelity findings and then tuned the query into a continuous detection that leveraged existing detection logic around related techniques. This process also effectively back-tests new detections, so we know we’re not going to generate a lot of false positives. Result: A new detection against a new technique, plus several improvements to existing detections.",{"data":18051,"content":18052,"nodeType":1058},{},[18053],{"data":18054,"marks":18055,"value":18057,"nodeType":867},{},[18056],{"type":865},"What infrastructure is needed for agentic threat hunting?",{"data":18059,"content":18060,"nodeType":876},{},[18061],{"data":18062,"marks":18063,"value":18064,"nodeType":867},{},[],"Both of these examples illustrate the end-to-end workflows supported by this pipeline. From an infrastructure perspective, you can think about the pipeline as composed of:",{"data":18066,"content":18067,"nodeType":1629},{},[18068,18083,18098,18113,18128],{"data":18069,"content":18070,"nodeType":1586},{},[18071],{"data":18072,"content":18073,"nodeType":876},{},[18074,18079],{"data":18075,"marks":18076,"value":18078,"nodeType":867},{},[18077],{"type":865},"A flight recorder: ",{"data":18080,"marks":18081,"value":18082,"nodeType":867},{},[],"The Push extension-powered capability that collects and locally stores browser event metadata from users’ browsers.",{"data":18084,"content":18085,"nodeType":1586},{},[18086],{"data":18087,"content":18088,"nodeType":876},{},[18089,18094],{"data":18090,"marks":18091,"value":18093,"nodeType":867},{},[18092],{"type":865},"A knowledge base:",{"data":18095,"marks":18096,"value":18097,"nodeType":867},{},[]," Structured knowledge about what Push knows about TTPs and its existing body of detection logic, as well as externally sourced signals of new attack trends.",{"data":18099,"content":18100,"nodeType":1586},{},[18101],{"data":18102,"content":18103,"nodeType":876},{},[18104,18109],{"data":18105,"marks":18106,"value":18108,"nodeType":867},{},[18107],{"type":865},"Agents as tools: ",{"data":18110,"marks":18111,"value":18112,"nodeType":867},{},[],"Role-segmented agents that work as a team to triage, investigate, develop hunt queries, return analyses, write detections, and review each others’ work for completeness and accuracy.",{"data":18114,"content":18115,"nodeType":1586},{},[18116],{"data":18117,"content":18118,"nodeType":876},{},[18119,18124],{"data":18120,"marks":18121,"value":18123,"nodeType":867},{},[18122],{"type":865},"Humans in the loop: ",{"data":18125,"marks":18126,"value":18127,"nodeType":867},{},[],"Human researchers who collaborate with agents to initiate hunts and tune detections.",{"data":18129,"content":18130,"nodeType":1586},{},[18131],{"data":18132,"content":18133,"nodeType":876},{},[18134,18139],{"data":18135,"marks":18136,"value":18138,"nodeType":867},{},[18137],{"type":865},"Platform controls: ",{"data":18140,"marks":18141,"value":18142,"nodeType":867},{},[],"The Push administrator-configured controls that specify how to respond to detected events like AiTM phishing, tuneable by scope, user groups, browser profiles, apps, etc.",{"data":18144,"content":18148,"nodeType":985},{"target":18145},{"sys":18146},{"id":18147,"type":982,"linkType":983},"7FY0vCBUXOt4vnudFuKALC",[],{"data":18150,"content":18151,"nodeType":1058},{},[18152],{"data":18153,"marks":18154,"value":18156,"nodeType":867},{},[18155],{"type":865},"What are the best practices for agentic threat detection?",{"data":18158,"content":18159,"nodeType":876},{},[18160,18164,18169],{"data":18161,"marks":18162,"value":18163,"nodeType":867},{},[],"To be effective, agents must specialize and focus. This is the ",{"data":18165,"marks":18166,"value":18168,"nodeType":867},{},[18167],{"type":865},"agents as tools",{"data":18170,"marks":18171,"value":18172,"nodeType":867},{},[]," concept. When we’re asking AI agents to take massive amounts of data and make a high-level decision about a signal in observed browser events, they must work as a team, finding intelligent ways to condense information without losing important context or hallucinating.",{"data":18174,"content":18175,"nodeType":876},{},[18176],{"data":18177,"marks":18178,"value":18179,"nodeType":867},{},[],"Creating a hierarchy of agent jobs — including agents to perform meta-analyses to catch mistakes and verify conclusions — makes the agents effective by giving them a manageable focus that controls the size of context windows.",{"data":18181,"content":18185,"nodeType":985},{"target":18182},{"sys":18183},{"id":18184,"type":982,"linkType":983},"3fzJCknMUmh4Z7YnhBSbsT",[],{"data":18187,"content":18188,"nodeType":876},{},[18189],{"data":18190,"marks":18191,"value":18192,"nodeType":867},{},[],"Creating an agentic workflow requires operationalizing your internal knowledge in a repeatable and trustworthy way. Sharing rich context from human discoveries is the key to getting the best results out of agents. ",{"data":18194,"content":18195,"nodeType":876},{},[18196,18200,18205],{"data":18197,"marks":18198,"value":18199,"nodeType":867},{},[],"It's vital too that the agent uses ",{"data":18201,"marks":18202,"value":18204,"nodeType":867},{},[18203],{"type":865},"privacy-preserving methods and infrastructure.",{"data":18206,"marks":18207,"value":18208,"nodeType":867},{},[]," The Push agent is designed to respect customer and user privacy while enabling high-fidelity detections. We do this by collecting broad browser metadata but storing it locally in users’ browsers and only querying that metadata during active threat hunting investigations.",{"data":18210,"content":18211,"nodeType":942},{},[],{"data":18213,"content":18214,"nodeType":868},{},[18215],{"data":18216,"marks":18217,"value":18219,"nodeType":867},{},[18218],{"type":865},"The compounding effect and how it benefits Push customers",{"data":18221,"content":18222,"nodeType":876},{},[18223],{"data":18224,"marks":18225,"value":18226,"nodeType":867},{},[],"At Push, we think about our detection capability as two learning loops with a compounding effect: An inner loop that serves as our real-time detection and response engine for known attacker techniques, and an outer loop that is the continuous learning our agents do as they hunt for new threats, analyze emerging behaviors, and create new detections. ",{"data":18228,"content":18229,"nodeType":876},{},[18230],{"data":18231,"marks":18232,"value":18233,"nodeType":867},{},[],"The outer loop feeds the inner loop, and vice versa.",{"data":18235,"content":18239,"nodeType":985},{"target":18236},{"sys":18237},{"id":18238,"type":982,"linkType":983},"1Jjqll7IIX2QRxN37gjFMH",[],{"data":18241,"content":18242,"nodeType":876},{},[18243],{"data":18244,"marks":18245,"value":18246,"nodeType":867},{},[],"Customers benefit from this approach because it means they:",{"data":18248,"content":18249,"nodeType":1629},{},[18250,18272,18282],{"data":18251,"content":18252,"nodeType":1586},{},[18253],{"data":18254,"content":18255,"nodeType":876},{},[18256,18260,18268],{"data":18257,"marks":18258,"value":18259,"nodeType":867},{},[],"Regularly receive ready-made detections against both known and emerging browser-based threats, without having to write their own detections. (Push also provides the ability to write your own ",{"data":18261,"content":18263,"nodeType":915},{"uri":18262},"/help/audience/engineering/resources/custom-detections",[18264],{"data":18265,"marks":18266,"value":18267,"nodeType":867},{},[],"custom detections",{"data":18269,"marks":18270,"value":18271,"nodeType":867},{},[],", too, for environment-specific use cases.)",{"data":18273,"content":18274,"nodeType":1586},{},[18275],{"data":18276,"content":18277,"nodeType":876},{},[18278],{"data":18279,"marks":18280,"value":18281,"nodeType":867},{},[],"Can configure Push’s response actions based on their security goals and environment. Agents act as the threat-hunting and detection engineering team; Push customers set the thresholds for how they want to respond. For example, customers can use Push controls to block all AiTM phishing attacks (or even carve out exceptions for their own incident responders to be able to visit malicious pages with just a warning), and agents continually feed new indicators into detection logic for that class of attack.",{"data":18283,"content":18284,"nodeType":1586},{},[18285],{"data":18286,"content":18287,"nodeType":876},{},[18288],{"data":18289,"marks":18290,"value":18291,"nodeType":867},{},[],"Get pre-digested and actionable intelligence from every detection, with extremely high fidelity.",{"data":18293,"content":18294,"nodeType":876},{},[18295],{"data":18296,"marks":18297,"value":18298,"nodeType":867},{},[],"This all equates to your own advanced browser threat protection, without requiring the specialized in-house expertise we’ve spent years building.",{"data":18300,"content":18301,"nodeType":876},{},[18302],{"data":18303,"marks":18304,"value":18305,"nodeType":867},{},[],"If you’re a Push customer, you already know that we regularly collaborate with security teams to identify and refine detection use cases, and assist with investigations. In the past few months alone, we’ve worked closely with teams targeted by device code phishing, and InstallFix and ClickFix campaigns, among others. ",{"data":18307,"content":18308,"nodeType":876},{},[18309],{"data":18310,"marks":18311,"value":18312,"nodeType":867},{},[],"If you’re not a customer and are curious about how Push’s agentic threat hunting and detection engineering capabilities can address your use cases, please get in touch.",{"data":18314,"content":18318,"nodeType":985},{"target":18315},{"sys":18316},{"id":18317,"type":982,"linkType":983},"607jrBjlD1vtcbkDfD04DE",[],{"data":18320,"content":18321,"nodeType":942},{},[],{"data":18323,"content":18324,"nodeType":868},{},[18325],{"data":18326,"marks":18327,"value":18329,"nodeType":867},{},[18328],{"type":865},"Learn more",{"data":18331,"content":18332,"nodeType":876},{},[18333],{"data":18334,"marks":18335,"value":3983,"nodeType":867},{},[],{"data":18337,"content":18338,"nodeType":876},{},[18339],{"data":18340,"marks":18341,"value":3990,"nodeType":867},{},[],{"data":18343,"content":18344,"nodeType":876},{},[18345,18348,18355],{"data":18346,"marks":18347,"value":5283,"nodeType":867},{},[],{"data":18349,"content":18351,"nodeType":915},{"uri":18350},"/demo",[18352],{"data":18353,"marks":18354,"value":5291,"nodeType":867},{},[],{"data":18356,"marks":18357,"value":3229,"nodeType":867},{},[],"Can AI replace a threat researcher? What we learned building an agentic threat hunting pipeline","How we built an end-to-end threat hunting and detection engineering capability at Push that uses AI agents as a force multiplier.","2026-05-12T00:00:00.000Z","can-ai-replace-a-threat-researcher-what-we-learned-building-an-agentic-threat-hunting-pipeline",{"items":18363},[18364,18366],{"sys":18365,"name":4018},{"id":4017},{"sys":18367,"name":342},{"id":3240},{"items":18369},[18370],{"fullName":2714,"firstName":2715,"jobTitle":851,"profilePicture":18371},{"url":2717},{"__typename":1772,"sys":18373,"content":18374,"title":16551,"synopsis":16552,"hashTags":59,"publishedDate":15574,"slug":16553,"tagsCollection":19195,"authorsCollection":19201},{"id":15588},{"json":18375},{"data":18376,"content":18377,"nodeType":1680},{},[18378,18400,18424,18457,18490,18495,18505,18508,18515,18557,18563,18582,18587,18590,18597,18621,18627,18634,18639,18642,18649,18655,18670,18676,18709,18715,18718,18725,18740,18782,18785,18792,18807,18822,18829,18835,18845,18855,18865,18875,18890,18897,18903,18906,18912,18918,18933,18936,18943,18958,19189],{"data":18379,"content":18380,"nodeType":876},{},[18381,18384,18390,18393,18397],{"data":18382,"marks":18383,"value":15599,"nodeType":867},{},[],{"data":18385,"content":18386,"nodeType":915},{"uri":1177},[18387],{"data":18388,"marks":18389,"value":11991,"nodeType":867},{},[],{"data":18391,"marks":18392,"value":15609,"nodeType":867},{},[],{"data":18394,"marks":18395,"value":15614,"nodeType":867},{},[18396],{"type":865},{"data":18398,"marks":18399,"value":15618,"nodeType":867},{},[],{"data":18401,"content":18402,"nodeType":876},{},[18403,18406,18412,18415,18421],{"data":18404,"marks":18405,"value":15625,"nodeType":867},{},[],{"data":18407,"content":18408,"nodeType":915},{"uri":15628},[18409],{"data":18410,"marks":18411,"value":15633,"nodeType":867},{},[],{"data":18413,"marks":18414,"value":15637,"nodeType":867},{},[],{"data":18416,"content":18417,"nodeType":915},{"uri":15640},[18418],{"data":18419,"marks":18420,"value":15645,"nodeType":867},{},[],{"data":18422,"marks":18423,"value":15649,"nodeType":867},{},[],{"data":18425,"content":18426,"nodeType":876},{},[18427,18430,18436,18439,18445,18448,18454],{"data":18428,"marks":18429,"value":15656,"nodeType":867},{},[],{"data":18431,"content":18432,"nodeType":915},{"uri":15659},[18433],{"data":18434,"marks":18435,"value":15664,"nodeType":867},{},[],{"data":18437,"marks":18438,"value":15668,"nodeType":867},{},[],{"data":18440,"content":18441,"nodeType":915},{"uri":15671},[18442],{"data":18443,"marks":18444,"value":15676,"nodeType":867},{},[],{"data":18446,"marks":18447,"value":15680,"nodeType":867},{},[],{"data":18449,"content":18450,"nodeType":915},{"uri":15683},[18451],{"data":18452,"marks":18453,"value":15688,"nodeType":867},{},[],{"data":18455,"marks":18456,"value":15692,"nodeType":867},{},[],{"data":18458,"content":18459,"nodeType":876},{},[18460,18463,18469,18472,18478,18481,18487],{"data":18461,"marks":18462,"value":15699,"nodeType":867},{},[],{"data":18464,"content":18465,"nodeType":915},{"uri":15702},[18466],{"data":18467,"marks":18468,"value":15707,"nodeType":867},{},[],{"data":18470,"marks":18471,"value":15711,"nodeType":867},{},[],{"data":18473,"content":18474,"nodeType":915},{"uri":15714},[18475],{"data":18476,"marks":18477,"value":15719,"nodeType":867},{},[],{"data":18479,"marks":18480,"value":15723,"nodeType":867},{},[],{"data":18482,"content":18483,"nodeType":915},{"uri":15726},[18484],{"data":18485,"marks":18486,"value":15731,"nodeType":867},{},[],{"data":18488,"marks":18489,"value":15735,"nodeType":867},{},[],{"data":18491,"content":18494,"nodeType":985},{"target":18492},{"sys":18493},{"id":15740,"type":982,"linkType":983},[],{"data":18496,"content":18497,"nodeType":876},{},[18498,18502],{"data":18499,"marks":18500,"value":15749,"nodeType":867},{},[18501],{"type":865},{"data":18503,"marks":18504,"value":15753,"nodeType":867},{},[],{"data":18506,"content":18507,"nodeType":942},{},[],{"data":18509,"content":18510,"nodeType":868},{},[18511],{"data":18512,"marks":18513,"value":15764,"nodeType":867},{},[18514],{"type":865},{"data":18516,"content":18517,"nodeType":876},{},[18518,18521,18527,18530,18536,18539,18545,18548,18554],{"data":18519,"marks":18520,"value":15771,"nodeType":867},{},[],{"data":18522,"content":18523,"nodeType":915},{"uri":15774},[18524],{"data":18525,"marks":18526,"value":15779,"nodeType":867},{},[],{"data":18528,"marks":18529,"value":5000,"nodeType":867},{},[],{"data":18531,"content":18532,"nodeType":915},{"uri":15785},[18533],{"data":18534,"marks":18535,"value":15790,"nodeType":867},{},[],{"data":18537,"marks":18538,"value":11670,"nodeType":867},{},[],{"data":18540,"content":18541,"nodeType":915},{"uri":15671},[18542],{"data":18543,"marks":18544,"value":15800,"nodeType":867},{},[],{"data":18546,"marks":18547,"value":15804,"nodeType":867},{},[],{"data":18549,"content":18550,"nodeType":915},{"uri":15807},[18551],{"data":18552,"marks":18553,"value":15812,"nodeType":867},{},[],{"data":18555,"marks":18556,"value":1679,"nodeType":867},{},[],{"data":18558,"content":18559,"nodeType":876},{},[18560],{"data":18561,"marks":18562,"value":15822,"nodeType":867},{},[],{"data":18564,"content":18565,"nodeType":876},{},[18566,18569,18575,18578],{"data":18567,"marks":18568,"value":15829,"nodeType":867},{},[],{"data":18570,"content":18571,"nodeType":915},{"uri":15807},[18572],{"data":18573,"marks":18574,"value":15836,"nodeType":867},{},[],{"data":18576,"marks":18577,"value":15840,"nodeType":867},{},[],{"data":18579,"marks":18580,"value":15845,"nodeType":867},{},[18581],{"type":865},{"data":18583,"content":18586,"nodeType":985},{"target":18584},{"sys":18585},{"id":15850,"type":982,"linkType":983},[],{"data":18588,"content":18589,"nodeType":942},{},[],{"data":18591,"content":18592,"nodeType":868},{},[18593],{"data":18594,"marks":18595,"value":15862,"nodeType":867},{},[18596],{"type":865},{"data":18598,"content":18599,"nodeType":876},{},[18600,18603,18609,18612,18618],{"data":18601,"marks":18602,"value":964,"nodeType":867},{},[],{"data":18604,"content":18605,"nodeType":915},{"uri":15249},[18606],{"data":18607,"marks":18608,"value":15875,"nodeType":867},{},[],{"data":18610,"marks":18611,"value":15879,"nodeType":867},{},[],{"data":18613,"content":18614,"nodeType":915},{"uri":15683},[18615],{"data":18616,"marks":18617,"value":15886,"nodeType":867},{},[],{"data":18619,"marks":18620,"value":15890,"nodeType":867},{},[],{"data":18622,"content":18623,"nodeType":876},{},[18624],{"data":18625,"marks":18626,"value":15897,"nodeType":867},{},[],{"data":18628,"content":18629,"nodeType":876},{},[18630],{"data":18631,"marks":18632,"value":15905,"nodeType":867},{},[18633],{"type":865},{"data":18635,"content":18638,"nodeType":985},{"target":18636},{"sys":18637},{"id":15910,"type":982,"linkType":983},[],{"data":18640,"content":18641,"nodeType":942},{},[],{"data":18643,"content":18644,"nodeType":868},{},[18645],{"data":18646,"marks":18647,"value":15922,"nodeType":867},{},[18648],{"type":865},{"data":18650,"content":18651,"nodeType":876},{},[18652],{"data":18653,"marks":18654,"value":15929,"nodeType":867},{},[],{"data":18656,"content":18657,"nodeType":876},{},[18658,18661,18667],{"data":18659,"marks":18660,"value":964,"nodeType":867},{},[],{"data":18662,"content":18663,"nodeType":915},{"uri":15938},[18664],{"data":18665,"marks":18666,"value":15943,"nodeType":867},{},[],{"data":18668,"marks":18669,"value":15947,"nodeType":867},{},[],{"data":18671,"content":18672,"nodeType":876},{},[18673],{"data":18674,"marks":18675,"value":15954,"nodeType":867},{},[],{"data":18677,"content":18678,"nodeType":876},{},[18679,18682,18688,18691,18697,18700,18706],{"data":18680,"marks":18681,"value":15961,"nodeType":867},{},[],{"data":18683,"content":18684,"nodeType":915},{"uri":15964},[18685],{"data":18686,"marks":18687,"value":15969,"nodeType":867},{},[],{"data":18689,"marks":18690,"value":15973,"nodeType":867},{},[],{"data":18692,"content":18693,"nodeType":915},{"uri":15976},[18694],{"data":18695,"marks":18696,"value":15981,"nodeType":867},{},[],{"data":18698,"marks":18699,"value":15985,"nodeType":867},{},[],{"data":18701,"content":18702,"nodeType":915},{"uri":2225},[18703],{"data":18704,"marks":18705,"value":15992,"nodeType":867},{},[],{"data":18707,"marks":18708,"value":15996,"nodeType":867},{},[],{"data":18710,"content":18711,"nodeType":876},{},[18712],{"data":18713,"marks":18714,"value":16003,"nodeType":867},{},[],{"data":18716,"content":18717,"nodeType":942},{},[],{"data":18719,"content":18720,"nodeType":868},{},[18721],{"data":18722,"marks":18723,"value":16014,"nodeType":867},{},[18724],{"type":865},{"data":18726,"content":18727,"nodeType":876},{},[18728,18731,18737],{"data":18729,"marks":18730,"value":16021,"nodeType":867},{},[],{"data":18732,"content":18733,"nodeType":915},{"uri":16024},[18734],{"data":18735,"marks":18736,"value":16029,"nodeType":867},{},[],{"data":18738,"marks":18739,"value":16033,"nodeType":867},{},[],{"data":18741,"content":18742,"nodeType":876},{},[18743,18746,18752,18755,18761,18764,18770,18773,18779],{"data":18744,"marks":18745,"value":16040,"nodeType":867},{},[],{"data":18747,"content":18748,"nodeType":915},{"uri":16043},[18749],{"data":18750,"marks":18751,"value":16048,"nodeType":867},{},[],{"data":18753,"marks":18754,"value":16052,"nodeType":867},{},[],{"data":18756,"content":18757,"nodeType":915},{"uri":16055},[18758],{"data":18759,"marks":18760,"value":16060,"nodeType":867},{},[],{"data":18762,"marks":18763,"value":16064,"nodeType":867},{},[],{"data":18765,"content":18766,"nodeType":915},{"uri":16067},[18767],{"data":18768,"marks":18769,"value":16072,"nodeType":867},{},[],{"data":18771,"marks":18772,"value":16076,"nodeType":867},{},[],{"data":18774,"content":18775,"nodeType":915},{"uri":16079},[18776],{"data":18777,"marks":18778,"value":16084,"nodeType":867},{},[],{"data":18780,"marks":18781,"value":16088,"nodeType":867},{},[],{"data":18783,"content":18784,"nodeType":942},{},[],{"data":18786,"content":18787,"nodeType":868},{},[18788],{"data":18789,"marks":18790,"value":16099,"nodeType":867},{},[18791],{"type":865},{"data":18793,"content":18794,"nodeType":876},{},[18795,18798,18804],{"data":18796,"marks":18797,"value":16106,"nodeType":867},{},[],{"data":18799,"content":18800,"nodeType":915},{"uri":1116},[18801],{"data":18802,"marks":18803,"value":16113,"nodeType":867},{},[],{"data":18805,"marks":18806,"value":16117,"nodeType":867},{},[],{"data":18808,"content":18809,"nodeType":876},{},[18810,18813,18819],{"data":18811,"marks":18812,"value":16124,"nodeType":867},{},[],{"data":18814,"content":18815,"nodeType":915},{"uri":16127},[18816],{"data":18817,"marks":18818,"value":315,"nodeType":867},{},[],{"data":18820,"marks":18821,"value":16135,"nodeType":867},{},[],{"data":18823,"content":18824,"nodeType":1058},{},[18825],{"data":18826,"marks":18827,"value":2541,"nodeType":867},{},[18828],{"type":865},{"data":18830,"content":18831,"nodeType":876},{},[18832],{"data":18833,"marks":18834,"value":16149,"nodeType":867},{},[],{"data":18836,"content":18837,"nodeType":876},{},[18838,18842],{"data":18839,"marks":18840,"value":16157,"nodeType":867},{},[18841],{"type":865},{"data":18843,"marks":18844,"value":16161,"nodeType":867},{},[],{"data":18846,"content":18847,"nodeType":876},{},[18848,18852],{"data":18849,"marks":18850,"value":16169,"nodeType":867},{},[18851],{"type":865},{"data":18853,"marks":18854,"value":16173,"nodeType":867},{},[],{"data":18856,"content":18857,"nodeType":876},{},[18858,18862],{"data":18859,"marks":18860,"value":16181,"nodeType":867},{},[18861],{"type":865},{"data":18863,"marks":18864,"value":16185,"nodeType":867},{},[],{"data":18866,"content":18867,"nodeType":876},{},[18868,18872],{"data":18869,"marks":18870,"value":16193,"nodeType":867},{},[18871],{"type":865},{"data":18873,"marks":18874,"value":16197,"nodeType":867},{},[],{"data":18876,"content":18877,"nodeType":876},{},[18878,18881,18887],{"data":18879,"marks":18880,"value":21,"nodeType":867},{},[],{"data":18882,"content":18883,"nodeType":915},{"uri":8610},[18884],{"data":18885,"marks":18886,"value":16210,"nodeType":867},{},[],{"data":18888,"marks":18889,"value":21,"nodeType":867},{},[],{"data":18891,"content":18892,"nodeType":1058},{},[18893],{"data":18894,"marks":18895,"value":16221,"nodeType":867},{},[18896],{"type":865},{"data":18898,"content":18899,"nodeType":876},{},[18900],{"data":18901,"marks":18902,"value":16228,"nodeType":867},{},[],{"data":18904,"content":18905,"nodeType":942},{},[],{"data":18907,"content":18908,"nodeType":876},{},[18909],{"data":18910,"marks":18911,"value":1667,"nodeType":867},{},[],{"data":18913,"content":18914,"nodeType":876},{},[18915],{"data":18916,"marks":18917,"value":3990,"nodeType":867},{},[],{"data":18919,"content":18920,"nodeType":876},{},[18921,18924,18930],{"data":18922,"marks":18923,"value":21,"nodeType":867},{},[],{"data":18925,"content":18926,"nodeType":915},{"uri":5286},[18927],{"data":18928,"marks":18929,"value":6672,"nodeType":867},{},[],{"data":18931,"marks":18932,"value":21,"nodeType":867},{},[],{"data":18934,"content":18935,"nodeType":942},{},[],{"data":18937,"content":18938,"nodeType":868},{},[18939],{"data":18940,"marks":18941,"value":16269,"nodeType":867},{},[18942],{"type":865},{"data":18944,"content":18945,"nodeType":876},{},[18946,18949,18955],{"data":18947,"marks":18948,"value":16276,"nodeType":867},{},[],{"data":18950,"content":18951,"nodeType":915},{"uri":1177},[18952],{"data":18953,"marks":18954,"value":16283,"nodeType":867},{},[],{"data":18956,"marks":18957,"value":16287,"nodeType":867},{},[],{"data":18959,"content":18960,"nodeType":7904},{},[18961,19004,19060,19103,19146],{"data":18962,"content":18963,"nodeType":7640},{},[18964,18974,18984,18994],{"data":18965,"content":18966,"nodeType":7628},{},[18967],{"data":18968,"content":18969,"nodeType":876},{},[18970],{"data":18971,"marks":18972,"value":16304,"nodeType":867},{},[18973],{"type":865},{"data":18975,"content":18976,"nodeType":7628},{},[18977],{"data":18978,"content":18979,"nodeType":876},{},[18980],{"data":18981,"marks":18982,"value":16315,"nodeType":867},{},[18983],{"type":865},{"data":18985,"content":18986,"nodeType":7628},{},[18987],{"data":18988,"content":18989,"nodeType":876},{},[18990],{"data":18991,"marks":18992,"value":16326,"nodeType":867},{},[18993],{"type":865},{"data":18995,"content":18996,"nodeType":7628},{},[18997],{"data":18998,"content":18999,"nodeType":876},{},[19000],{"data":19001,"marks":19002,"value":16337,"nodeType":867},{},[19003],{"type":865},{"data":19005,"content":19006,"nodeType":7640},{},[19007,19027,19036,19045],{"data":19008,"content":19009,"nodeType":7628},{},[19010],{"data":19011,"content":19012,"nodeType":876},{},[19013,19017,19020,19024],{"data":19014,"marks":19015,"value":16351,"nodeType":867},{},[19016],{"type":865},{"data":19018,"marks":19019,"value":16355,"nodeType":867},{},[],{"data":19021,"marks":19022,"value":16360,"nodeType":867},{},[19023],{"type":865},{"data":19025,"marks":19026,"value":16364,"nodeType":867},{},[],{"data":19028,"content":19029,"nodeType":7628},{},[19030],{"data":19031,"content":19032,"nodeType":876},{},[19033],{"data":19034,"marks":19035,"value":16374,"nodeType":867},{},[],{"data":19037,"content":19038,"nodeType":7628},{},[19039],{"data":19040,"content":19041,"nodeType":876},{},[19042],{"data":19043,"marks":19044,"value":16384,"nodeType":867},{},[],{"data":19046,"content":19047,"nodeType":7628},{},[19048,19054],{"data":19049,"content":19050,"nodeType":876},{},[19051],{"data":19052,"marks":19053,"value":16394,"nodeType":867},{},[],{"data":19055,"content":19056,"nodeType":876},{},[19057],{"data":19058,"marks":19059,"value":16401,"nodeType":867},{},[],{"data":19061,"content":19062,"nodeType":7640},{},[19063,19076,19085,19094],{"data":19064,"content":19065,"nodeType":7628},{},[19066],{"data":19067,"content":19068,"nodeType":876},{},[19069,19073],{"data":19070,"marks":19071,"value":16415,"nodeType":867},{},[19072],{"type":865},{"data":19074,"marks":19075,"value":16419,"nodeType":867},{},[],{"data":19077,"content":19078,"nodeType":7628},{},[19079],{"data":19080,"content":19081,"nodeType":876},{},[19082],{"data":19083,"marks":19084,"value":16429,"nodeType":867},{},[],{"data":19086,"content":19087,"nodeType":7628},{},[19088],{"data":19089,"content":19090,"nodeType":876},{},[19091],{"data":19092,"marks":19093,"value":16439,"nodeType":867},{},[],{"data":19095,"content":19096,"nodeType":7628},{},[19097],{"data":19098,"content":19099,"nodeType":876},{},[19100],{"data":19101,"marks":19102,"value":16449,"nodeType":867},{},[],{"data":19104,"content":19105,"nodeType":7640},{},[19106,19119,19128,19137],{"data":19107,"content":19108,"nodeType":7628},{},[19109],{"data":19110,"content":19111,"nodeType":876},{},[19112,19116],{"data":19113,"marks":19114,"value":16463,"nodeType":867},{},[19115],{"type":865},{"data":19117,"marks":19118,"value":16467,"nodeType":867},{},[],{"data":19120,"content":19121,"nodeType":7628},{},[19122],{"data":19123,"content":19124,"nodeType":876},{},[19125],{"data":19126,"marks":19127,"value":16477,"nodeType":867},{},[],{"data":19129,"content":19130,"nodeType":7628},{},[19131],{"data":19132,"content":19133,"nodeType":876},{},[19134],{"data":19135,"marks":19136,"value":16487,"nodeType":867},{},[],{"data":19138,"content":19139,"nodeType":7628},{},[19140],{"data":19141,"content":19142,"nodeType":876},{},[19143],{"data":19144,"marks":19145,"value":16497,"nodeType":867},{},[],{"data":19147,"content":19148,"nodeType":7640},{},[19149,19162,19171,19180],{"data":19150,"content":19151,"nodeType":7628},{},[19152],{"data":19153,"content":19154,"nodeType":876},{},[19155,19159],{"data":19156,"marks":19157,"value":16511,"nodeType":867},{},[19158],{"type":865},{"data":19160,"marks":19161,"value":16515,"nodeType":867},{},[],{"data":19163,"content":19164,"nodeType":7628},{},[19165],{"data":19166,"content":19167,"nodeType":876},{},[19168],{"data":19169,"marks":19170,"value":16374,"nodeType":867},{},[],{"data":19172,"content":19173,"nodeType":7628},{},[19174],{"data":19175,"content":19176,"nodeType":876},{},[19177],{"data":19178,"marks":19179,"value":16534,"nodeType":867},{},[],{"data":19181,"content":19182,"nodeType":7628},{},[19183],{"data":19184,"content":19185,"nodeType":876},{},[19186],{"data":19187,"marks":19188,"value":16544,"nodeType":867},{},[],{"data":19190,"content":19191,"nodeType":876},{},[19192],{"data":19193,"marks":19194,"value":21,"nodeType":867},{},[],{"items":19196},[19197,19199],{"sys":19198,"name":4018},{"id":4017},{"sys":19200,"name":342},{"id":3240},{"items":19202},[19203],{"fullName":4022,"firstName":4023,"jobTitle":4024,"profilePicture":19204},{"url":4026},{"__typename":1772,"sys":19206,"content":19207,"title":3230,"synopsis":3231,"hashTags":59,"publishedDate":3232,"slug":3233,"tagsCollection":19637,"authorsCollection":19643},{"id":2720},{"json":19208},{"data":19209,"content":19210,"nodeType":1680},{},[19211,19218,19242,19247,19253,19268,19281,19284,19291,19304,19320,19340,19345,19358,19382,19387,19392,19405,19408,19415,19421,19428,19444,19457,19464,19486,19492,19499,19523,19529,19536,19542,19547,19550,19557,19563,19570,19575,19578,19585,19591,19597,19603,19613,19616,19622],{"data":19212,"content":19213,"nodeType":868},{},[19214],{"data":19215,"marks":19216,"value":2732,"nodeType":867},{},[19217],{"type":865},{"data":19219,"content":19220,"nodeType":876},{},[19221,19224,19230,19233,19239],{"data":19222,"marks":19223,"value":2739,"nodeType":867},{},[],{"data":19225,"content":19226,"nodeType":915},{"uri":2742},[19227],{"data":19228,"marks":19229,"value":2747,"nodeType":867},{},[],{"data":19231,"marks":19232,"value":2751,"nodeType":867},{},[],{"data":19234,"content":19235,"nodeType":915},{"uri":2754},[19236],{"data":19237,"marks":19238,"value":2759,"nodeType":867},{},[],{"data":19240,"marks":19241,"value":2763,"nodeType":867},{},[],{"data":19243,"content":19246,"nodeType":985},{"target":19244},{"sys":19245},{"id":2768,"type":982,"linkType":983},[],{"data":19248,"content":19249,"nodeType":876},{},[19250],{"data":19251,"marks":19252,"value":2776,"nodeType":867},{},[],{"data":19254,"content":19255,"nodeType":876},{},[19256,19259,19265],{"data":19257,"marks":19258,"value":2783,"nodeType":867},{},[],{"data":19260,"content":19261,"nodeType":915},{"uri":2786},[19262],{"data":19263,"marks":19264,"value":2791,"nodeType":867},{},[],{"data":19266,"marks":19267,"value":2795,"nodeType":867},{},[],{"data":19269,"content":19270,"nodeType":876},{},[19271,19274,19278],{"data":19272,"marks":19273,"value":2802,"nodeType":867},{},[],{"data":19275,"marks":19276,"value":2807,"nodeType":867},{},[19277],{"type":865},{"data":19279,"marks":19280,"value":1679,"nodeType":867},{},[],{"data":19282,"content":19283,"nodeType":942},{},[],{"data":19285,"content":19286,"nodeType":868},{},[19287],{"data":19288,"marks":19289,"value":2821,"nodeType":867},{},[19290],{"type":865},{"data":19292,"content":19293,"nodeType":876},{},[19294,19297,19301],{"data":19295,"marks":19296,"value":2828,"nodeType":867},{},[],{"data":19298,"marks":19299,"value":2833,"nodeType":867},{},[19300],{"type":1303},{"data":19302,"marks":19303,"value":1679,"nodeType":867},{},[],{"data":19305,"content":19306,"nodeType":876},{},[19307,19310,19317],{"data":19308,"marks":19309,"value":2843,"nodeType":867},{},[],{"data":19311,"content":19312,"nodeType":915},{"uri":2557},[19313],{"data":19314,"marks":19315,"value":2851,"nodeType":867},{},[19316],{"type":913},{"data":19318,"marks":19319,"value":2855,"nodeType":867},{},[],{"data":19321,"content":19322,"nodeType":876},{},[19323,19326,19330,19333,19337],{"data":19324,"marks":19325,"value":2862,"nodeType":867},{},[],{"data":19327,"marks":19328,"value":2867,"nodeType":867},{},[19329],{"type":865},{"data":19331,"marks":19332,"value":2871,"nodeType":867},{},[],{"data":19334,"marks":19335,"value":2876,"nodeType":867},{},[19336],{"type":1303},{"data":19338,"marks":19339,"value":2880,"nodeType":867},{},[],{"data":19341,"content":19344,"nodeType":985},{"target":19342},{"sys":19343},{"id":2885,"type":982,"linkType":983},[],{"data":19346,"content":19347,"nodeType":876},{},[19348,19351,19355],{"data":19349,"marks":19350,"value":2893,"nodeType":867},{},[],{"data":19352,"marks":19353,"value":2898,"nodeType":867},{},[19354],{"type":865},{"data":19356,"marks":19357,"value":2902,"nodeType":867},{},[],{"data":19359,"content":19360,"nodeType":876},{},[19361,19364,19370,19373,19379],{"data":19362,"marks":19363,"value":2909,"nodeType":867},{},[],{"data":19365,"content":19366,"nodeType":915},{"uri":2912},[19367],{"data":19368,"marks":19369,"value":2917,"nodeType":867},{},[],{"data":19371,"marks":19372,"value":2921,"nodeType":867},{},[],{"data":19374,"content":19375,"nodeType":915},{"uri":2924},[19376],{"data":19377,"marks":19378,"value":2929,"nodeType":867},{},[],{"data":19380,"marks":19381,"value":2933,"nodeType":867},{},[],{"data":19383,"content":19386,"nodeType":985},{"target":19384},{"sys":19385},{"id":2938,"type":982,"linkType":983},[],{"data":19388,"content":19391,"nodeType":985},{"target":19389},{"sys":19390},{"id":2944,"type":982,"linkType":983},[],{"data":19393,"content":19394,"nodeType":876},{},[19395,19398,19402],{"data":19396,"marks":19397,"value":2952,"nodeType":867},{},[],{"data":19399,"marks":19400,"value":2957,"nodeType":867},{},[19401],{"type":865},{"data":19403,"marks":19404,"value":2961,"nodeType":867},{},[],{"data":19406,"content":19407,"nodeType":942},{},[],{"data":19409,"content":19410,"nodeType":868},{},[19411],{"data":19412,"marks":19413,"value":2972,"nodeType":867},{},[19414],{"type":865},{"data":19416,"content":19417,"nodeType":876},{},[19418],{"data":19419,"marks":19420,"value":2979,"nodeType":867},{},[],{"data":19422,"content":19423,"nodeType":1058},{},[19424],{"data":19425,"marks":19426,"value":2987,"nodeType":867},{},[19427],{"type":865},{"data":19429,"content":19430,"nodeType":876},{},[19431,19434,19441],{"data":19432,"marks":19433,"value":21,"nodeType":867},{},[],{"data":19435,"content":19436,"nodeType":915},{"uri":2225},[19437],{"data":19438,"marks":19439,"value":3001,"nodeType":867},{},[19440],{"type":913},{"data":19442,"marks":19443,"value":3005,"nodeType":867},{},[],{"data":19445,"content":19446,"nodeType":876},{},[19447,19450,19454],{"data":19448,"marks":19449,"value":3012,"nodeType":867},{},[],{"data":19451,"marks":19452,"value":3017,"nodeType":867},{},[19453],{"type":865},{"data":19455,"marks":19456,"value":3021,"nodeType":867},{},[],{"data":19458,"content":19459,"nodeType":1058},{},[19460],{"data":19461,"marks":19462,"value":288,"nodeType":867},{},[19463],{"type":865},{"data":19465,"content":19466,"nodeType":876},{},[19467,19471,19479,19483],{"data":19468,"marks":19469,"value":21,"nodeType":867},{},[19470],{"type":865},{"data":19472,"content":19473,"nodeType":915},{"uri":1576},[19474],{"data":19475,"marks":19476,"value":3044,"nodeType":867},{},[19477,19478],{"type":913},{"type":865},{"data":19480,"marks":19481,"value":3049,"nodeType":867},{},[19482],{"type":865},{"data":19484,"marks":19485,"value":3053,"nodeType":867},{},[],{"data":19487,"content":19488,"nodeType":876},{},[19489],{"data":19490,"marks":19491,"value":3060,"nodeType":867},{},[],{"data":19493,"content":19494,"nodeType":1058},{},[19495],{"data":19496,"marks":19497,"value":3068,"nodeType":867},{},[19498],{"type":865},{"data":19500,"content":19501,"nodeType":876},{},[19502,19505,19511,19514,19520],{"data":19503,"marks":19504,"value":3075,"nodeType":867},{},[],{"data":19506,"content":19507,"nodeType":915},{"uri":3078},[19508],{"data":19509,"marks":19510,"value":3083,"nodeType":867},{},[],{"data":19512,"marks":19513,"value":3087,"nodeType":867},{},[],{"data":19515,"content":19516,"nodeType":915},{"uri":928},[19517],{"data":19518,"marks":19519,"value":3094,"nodeType":867},{},[],{"data":19521,"marks":19522,"value":3098,"nodeType":867},{},[],{"data":19524,"content":19525,"nodeType":876},{},[19526],{"data":19527,"marks":19528,"value":3105,"nodeType":867},{},[],{"data":19530,"content":19531,"nodeType":1058},{},[19532],{"data":19533,"marks":19534,"value":3113,"nodeType":867},{},[19535],{"type":865},{"data":19537,"content":19538,"nodeType":876},{},[19539],{"data":19540,"marks":19541,"value":3120,"nodeType":867},{},[],{"data":19543,"content":19546,"nodeType":985},{"target":19544},{"sys":19545},{"id":3125,"type":982,"linkType":983},[],{"data":19548,"content":19549,"nodeType":942},{},[],{"data":19551,"content":19552,"nodeType":868},{},[19553],{"data":19554,"marks":19555,"value":3137,"nodeType":867},{},[19556],{"type":865},{"data":19558,"content":19559,"nodeType":876},{},[19560],{"data":19561,"marks":19562,"value":3144,"nodeType":867},{},[],{"data":19564,"content":19565,"nodeType":876},{},[19566],{"data":19567,"marks":19568,"value":3152,"nodeType":867},{},[19569],{"type":865},{"data":19571,"content":19574,"nodeType":985},{"target":19572},{"sys":19573},{"id":3157,"type":982,"linkType":983},[],{"data":19576,"content":19577,"nodeType":942},{},[],{"data":19579,"content":19580,"nodeType":1058},{},[19581],{"data":19582,"marks":19583,"value":3169,"nodeType":867},{},[19584],{"type":865},{"data":19586,"content":19587,"nodeType":876},{},[19588],{"data":19589,"marks":19590,"value":3176,"nodeType":867},{},[],{"data":19592,"content":19593,"nodeType":876},{},[19594],{"data":19595,"marks":19596,"value":3183,"nodeType":867},{},[],{"data":19598,"content":19599,"nodeType":876},{},[19600],{"data":19601,"marks":19602,"value":3190,"nodeType":867},{},[],{"data":19604,"content":19605,"nodeType":876},{},[19606,19610],{"data":19607,"marks":19608,"value":3198,"nodeType":867},{},[19609],{"type":865},{"data":19611,"marks":19612,"value":3202,"nodeType":867},{},[],{"data":19614,"content":19615,"nodeType":942},{},[],{"data":19617,"content":19618,"nodeType":876},{},[19619],{"data":19620,"marks":19621,"value":1667,"nodeType":867},{},[],{"data":19623,"content":19624,"nodeType":876},{},[19625,19628,19634],{"data":19626,"marks":19627,"value":3218,"nodeType":867},{},[],{"data":19629,"content":19630,"nodeType":915},{"uri":1670},[19631],{"data":19632,"marks":19633,"value":3225,"nodeType":867},{},[],{"data":19635,"marks":19636,"value":3229,"nodeType":867},{},[],{"items":19638},[19639,19641],{"sys":19640,"name":2710},{"id":2709},{"sys":19642,"name":342},{"id":3240},{"items":19644},[19645],{"fullName":3244,"firstName":3245,"jobTitle":3246,"profilePicture":19646},{"url":3248},"blog/how-to-avoid-the-browser-security-buyers-trap",{"json":19649},{"data":19650,"content":19651,"nodeType":1680},{},[19652],{"data":19653,"content":19654,"nodeType":876},{},[19655],{"data":19656,"marks":19657,"value":19658,"nodeType":867},{},[],"Securing the browser vs. securing the organization via the browser — what's the difference? Most browser security solutions defend against the browser being hacked, but these aren't the attacks that are actually leading to major breaches. ",{"id":9211,"publishedAt":19660},"2026-08-13T09:35:09.806Z",{"items":19662},[19663,19665],{"sys":19664,"name":297},{"id":2706},{"sys":19666,"name":2710},{"id":2709},{"items":19668},[19669,19671,19673,19675,19677,19679,19681,19683,19685,19687,19689,19691,19693,19695,19697,19699,19701,19703,19705,19707,19709,19711,19713],{"sys":19670,"name":297,"slug":298,"tier":31},{"id":294},{"sys":19672,"name":279,"slug":280,"tier":31},{"id":276},{"sys":19674,"name":413,"slug":414,"tier":31},{"id":410},{"sys":19676,"name":519,"slug":520,"tier":31},{"id":516},{"sys":19678,"name":342,"slug":343,"tier":31},{"id":339},{"sys":19680,"name":386,"slug":387,"tier":45},{"id":383},{"sys":19682,"name":511,"slug":512,"tier":45},{"id":508},{"sys":19684,"name":261,"slug":262,"tier":45},{"id":258},{"sys":19686,"name":571,"slug":572,"tier":45},{"id":568},{"sys":19688,"name":333,"slug":334,"tier":45},{"id":330},{"sys":19690,"name":324,"slug":325,"tier":45},{"id":321},{"sys":19692,"name":484,"slug":485,"tier":45},{"id":481},{"sys":19694,"name":315,"slug":316,"tier":45},{"id":312},{"sys":19696,"name":360,"slug":361,"tier":45},{"id":357},{"sys":19698,"name":395,"slug":396,"tier":45},{"id":392},{"sys":19700,"name":589,"slug":590,"tier":45},{"id":586},{"sys":19702,"name":288,"slug":289,"tier":45},{"id":285},{"sys":19704,"name":502,"slug":503,"tier":45},{"id":499},{"sys":19706,"name":457,"slug":458,"tier":45},{"id":454},{"sys":19708,"name":377,"slug":378,"tier":45},{"id":374},{"sys":19710,"name":624,"slug":625,"tier":45},{"id":621},{"sys":19712,"name":368,"slug":369,"tier":45},{"id":365},{"sys":19714,"name":244,"slug":245,"tier":45},{"id":241},"5C3_54ldAqXGDnFfNyrEkB5PAE-NWpPCxwC0yi4pkDk",{"id":19717,"title":19718,"authorsCollection":19719,"content":19723,"extension":228,"faqItemsCollection":20124,"faqTitle":59,"featured":6,"hashTags":59,"meta":20126,"metaTitle":20127,"ogImage":59,"postType":1767,"publishedDate":20128,"relatedBlogPostsCollection":20129,"slug":21025,"stem":21026,"subtitle":59,"summary":21027,"synopsis":21038,"sys":21039,"tagsCollection":21042,"topicsCollection":21048,"__hash__":21066},"blog/blog/push-plus-endpoint-security.json","Push + Endpoint Security: Extending detection and response to the browser",{"items":19720},[19721],{"fullName":849,"firstName":850,"jobTitle":851,"socialLinks":59,"profilePicture":19722},{"url":853},{"json":19724,"links":20108},{"data":19725,"content":19726,"nodeType":1680},{},[19727,19735,19742,19749,19761,19773,19781,19788,19795,19802,19808,19811,19819,19826,19833,19845,19852,19859,19867,19874,19922,19938,19945,19953,19960,19987,19994,20002,20050,20057,20096,20102],{"data":19728,"content":19729,"nodeType":868},{},[19730],{"data":19731,"marks":19732,"value":19734,"nodeType":867},{},[19733],{"type":865},"EDR is still the best tool for attacks that touch the endpoint",{"data":19736,"content":19737,"nodeType":876},{},[19738],{"data":19739,"marks":19740,"value":19741,"nodeType":867},{},[],"Endpoint Detection and Response (EDR) tooling is fundamental to modern security. It earned its place as a foundational control by moving defense away from static, known-bad indicators and toward deep, real-time detection, investigation, and response based on behavior observed in a live environment. ",{"data":19743,"content":19744,"nodeType":876},{},[19745],{"data":19746,"marks":19747,"value":19748,"nodeType":867},{},[],"By running an agent inside the operating system, EDR gave defenders something they never had before: visibility into what was actually happening on the host as it happened, and the ability to act on it.",{"data":19750,"content":19751,"nodeType":876},{},[19752,19756],{"data":19753,"marks":19754,"value":19755,"nodeType":867},{},[],"That agent-level visibility is still incredibly powerful. File system changes, process execution, memory behavior, or registry modifications is the kind of telemetry that enables threat hunting, exposes fileless attacks, and allows teams to contain incidents by isolating a device or killing a malicious process. ",{"data":19757,"marks":19758,"value":19760,"nodeType":867},{},[19759],{"type":865},"For anything that touches the endpoint, EDR remains the right tool.",{"data":19762,"content":19763,"nodeType":876},{},[19764,19768],{"data":19765,"marks":19766,"value":19767,"nodeType":867},{},[],"But that’s the key constraint: ",{"data":19769,"marks":19770,"value":19772,"nodeType":867},{},[19771],{"type":1303},"for anything that touches the endpoint.",{"data":19774,"content":19775,"nodeType":1058},{},[19776],{"data":19777,"marks":19778,"value":19780,"nodeType":867},{},[19779],{"type":865},"But modern attacks have moved beyond the endpoint",{"data":19782,"content":19783,"nodeType":876},{},[19784],{"data":19785,"marks":19786,"value":19787,"nodeType":867},{},[],"The reality of how work gets done has shifted. Most applications are now SaaS-based and accessed entirely through a browser. Employees authenticate, move data, administer systems, and interact with customers inside a browser window. And attackers have followed them there.",{"data":19789,"content":19790,"nodeType":876},{},[19791],{"data":19792,"marks":19793,"value":19794,"nodeType":867},{},[],"When attacks play out in the browser, endpoint-level signals often never appear. From the operating system’s perspective, there’s just a browser process behaving normally. The EDR agent is doing exactly what it was designed to do, but the activity that matters is happening within the browser itself.",{"data":19796,"content":19797,"nodeType":876},{},[19798],{"data":19799,"marks":19800,"value":19801,"nodeType":867},{},[],"That’s the gap teams are running into. EDR protects the integrity of the host, but it has no visibility into the live application session inside the browser. And as attackers consciously avoid the endpoint entirely, that blind spot is becoming harder to ignore.",{"data":19803,"content":19807,"nodeType":985},{"target":19804},{"sys":19805},{"id":19806,"type":982,"linkType":983},"7aVTgi4Btxl6PpzQl8kipW",[],{"data":19809,"content":19810,"nodeType":942},{},[],{"data":19812,"content":19813,"nodeType":868},{},[19814],{"data":19815,"marks":19816,"value":19818,"nodeType":867},{},[19817],{"type":865},"Attackers are consciously evading EDR",{"data":19820,"content":19821,"nodeType":876},{},[19822],{"data":19823,"marks":19824,"value":19825,"nodeType":867},{},[],"The gap endpoint teams are running into isn’t accidental. It’s the result of attackers adapting to where defenders are strongest (and weakest).",{"data":19827,"content":19828,"nodeType":876},{},[19829],{"data":19830,"marks":19831,"value":19832,"nodeType":867},{},[],"Modern EDR has made compromising the host operating system expensive and noisy. Deep telemetry and constant monitoring mean that even when an attacker manages to execute code on a device, that action is quickly under scrutiny. From there, progress is slow. After all, lateral movement and persistence take time, and all of it carries risk and generates signals defenders are good at catching.",{"data":19834,"content":19835,"nodeType":876},{},[19836,19841],{"data":19837,"marks":19838,"value":19840,"nodeType":867},{},[19839],{"type":865},"So attackers take a different route. ",{"data":19842,"marks":19843,"value":19844,"nodeType":867},{},[],"Instead of targeting the OS, they operate inside the browser session, abusing legitimate access paths to cloud applications directly over the internet. The endpoint just sees a browser session, not the malicious activity that's happening inside it. ",{"data":19846,"content":19847,"nodeType":876},{},[19848],{"data":19849,"marks":19850,"value":19851,"nodeType":867},{},[],"EDR agents are extremely good at protecting the operating system, but their visibility largely stops at the browser boundary. They can see that a browser process is running. They can’t see what a user is actually interacting with inside a specific tab, or what code is executing within the browser.",{"data":19853,"content":19854,"nodeType":876},{},[19855],{"data":19856,"marks":19857,"value":19858,"nodeType":867},{},[],"This is the shift security teams are feeling. Attacks don’t trigger endpoint alerts because they aren’t endpoint attacks. They unfold inside the browser, over standard web sessions, using legitimate accounts. To EDR, the host is unaffected. To the business, the damage is already underway.",{"data":19860,"content":19861,"nodeType":1058},{},[19862],{"data":19863,"marks":19864,"value":19866,"nodeType":867},{},[19865],{"type":865},"How modern attacks circumvent EDR",{"data":19868,"content":19869,"nodeType":876},{},[19870],{"data":19871,"marks":19872,"value":19873,"nodeType":867},{},[],"Examples of modern attacks that are consciously evading EDR by staying off the endpoint include:",{"data":19875,"content":19876,"nodeType":1629},{},[19877,19892,19907],{"data":19878,"content":19879,"nodeType":1586},{},[19880],{"data":19881,"content":19882,"nodeType":876},{},[19883,19888],{"data":19884,"marks":19885,"value":19887,"nodeType":867},{},[19886],{"type":865},"AiTM phishing: ",{"data":19889,"marks":19890,"value":19891,"nodeType":867},{},[],"Sophisticated attacker-in-the-middle phishing kits render convincing login pages directly in the browser and proxy authentication in real time, stealing credentials or MFA tokens as the user enters them. From the OS perspective, nothing appears unusual; EDR can’t see the page structure or scripts running inside the tab.",{"data":19893,"content":19894,"nodeType":1586},{},[19895],{"data":19896,"content":19897,"nodeType":876},{},[19898,19903],{"data":19899,"marks":19900,"value":19902,"nodeType":867},{},[19901],{"type":865},"Session hijacking:",{"data":19904,"marks":19905,"value":19906,"nodeType":867},{},[]," When attackers obtain a valid session token, they gain persistent access to an account without needing a password at all. Once in use, the session typically blends into normal browser activity, generating no endpoint data. ",{"data":19908,"content":19909,"nodeType":1586},{},[19910],{"data":19911,"content":19912,"nodeType":876},{},[19913,19918],{"data":19914,"marks":19915,"value":19917,"nodeType":867},{},[19916],{"type":865},"Malicious browser extensions:",{"data":19919,"marks":19920,"value":19921,"nodeType":867},{},[]," Malicious extensions (either made by attackers or hijacked by them) can read page content, intercept credentials, or siphon session tokens. Because extensions operate inside the browser’s execution model, their behavior is largely invisible to endpoint tooling focused on OS-level activity.",{"data":19923,"content":19924,"nodeType":876},{},[19925,19929,19934],{"data":19926,"marks":19927,"value":19928,"nodeType":867},{},[],"Even attacks that nominally involve the endpoint often stay outside EDR’s strongest visibility. ",{"data":19930,"marks":19931,"value":19933,"nodeType":867},{},[19932],{"type":865},"ClickFix-style social engineering",{"data":19935,"marks":19936,"value":19937,"nodeType":867},{},[]," is a good example. Attackers manipulate users into taking risky actions that look legitimate, the most prominent example being executing malicious commands on the host that are deliberately obfuscated or broken into benign-looking steps. While EDR may catch the code execution (and any malware the execution attempts to install), these techniques are designed to stay ambiguous enough to avoid reliable detection.",{"data":19939,"content":19940,"nodeType":876},{},[19941],{"data":19942,"marks":19943,"value":19944,"nodeType":867},{},[],"All of these attacks succeed for the same reason: the activity unfolds inside the browser. And because EDR was never designed to observe or control what happens inside a live browser session, attackers can operate there with far less resistance.",{"data":19946,"content":19947,"nodeType":1058},{},[19948],{"data":19949,"marks":19950,"value":19952,"nodeType":867},{},[19951],{"type":865},"Extending detection and response to the browser",{"data":19954,"content":19955,"nodeType":876},{},[19956],{"data":19957,"marks":19958,"value":19959,"nodeType":867},{},[],"Defenders need to meet attackers where they actually operate. That means establishing real detection and response capabilities inside the browser itself.",{"data":19961,"content":19962,"nodeType":876},{},[19963,19967,19972,19976,19984],{"data":19964,"marks":19965,"value":19966,"nodeType":867},{},[],"When endpoint security evolved, it did so by putting an agent on the host to observe behavior, collect telemetry, and act at the source — ",{"data":19968,"marks":19969,"value":19971,"nodeType":867},{},[19970],{"type":865},"getting inside the data stream",{"data":19973,"marks":19974,"value":19975,"nodeType":867},{},[],". The same logic applies here. If the browser is where credentials are entered, sessions are established, and attacks unfold, then it needs to be treated as a security surface in its own right. ",{"data":19977,"content":19979,"nodeType":915},{"uri":19978},"https://pushsecurity.com/blog/push-plus-network-security",[19980],{"data":19981,"marks":19982,"value":19983,"nodeType":867},{},[],"That doesn't mean just looking at web traffic, but examining client-side browser processes and activity that are the best, earliest indicators of bad activity. ",{"data":19985,"marks":19986,"value":21,"nodeType":867},{},[],{"data":19988,"content":19989,"nodeType":876},{},[19990],{"data":19991,"marks":19992,"value":19993,"nodeType":867},{},[],"This doesn’t replace EDR. EDR secures the host. Identity tools govern authentication. But the browser, the layer that connects users to everything else, is a blind spot. Extending detection and response into that layer fills the gap while complementing the controls that already work.",{"data":19995,"content":19996,"nodeType":1058},{},[19997],{"data":19998,"marks":19999,"value":20001,"nodeType":867},{},[20000],{"type":865},"Your browser detection and response checklist",{"data":20003,"content":20004,"nodeType":1629},{},[20005,20020,20035],{"data":20006,"content":20007,"nodeType":1586},{},[20008],{"data":20009,"content":20010,"nodeType":876},{},[20011,20016],{"data":20012,"marks":20013,"value":20015,"nodeType":867},{},[20014],{"type":865},"Browser-native protection: ",{"data":20017,"marks":20018,"value":20019,"nodeType":867},{},[],"Running inside the browser is the only way you can see what page a user is interacting with, what scripts are running, and how the session is behaving in real time. It’s also the only place you can reliably distinguish between normal user activity and attacker-driven manipulation.",{"data":20021,"content":20022,"nodeType":1586},{},[20023],{"data":20024,"content":20025,"nodeType":876},{},[20026,20031],{"data":20027,"marks":20028,"value":20030,"nodeType":867},{},[20029],{"type":865},"Behavioral detection:",{"data":20032,"marks":20033,"value":20034,"nodeType":867},{},[]," Detection can’t rely on static indicators. It has to be based on behaviors — like how pages render, how credentials are submitted, and how sessions are established and abused. ",{"data":20036,"content":20037,"nodeType":1586},{},[20038],{"data":20039,"content":20040,"nodeType":876},{},[20041,20046],{"data":20042,"marks":20043,"value":20045,"nodeType":867},{},[20044],{"type":865},"Real-time interception:",{"data":20047,"marks":20048,"value":20049,"nodeType":867},{},[]," Response has to be immediate. Blocking credential submission, interrupting a malicious action, capturing high-fidelity context, all of that needs to happen at the point of interaction — before an account is compromised.",{"data":20051,"content":20052,"nodeType":876},{},[20053],{"data":20054,"marks":20055,"value":20056,"nodeType":867},{},[],"This is what it means to extend detection and response to the browser: not another tool bolted onto the stack, but a necessary evolution in how modern attacks are actually stopped.",{"data":20058,"content":20059,"nodeType":3804},{},[20060],{"data":20061,"content":20062,"nodeType":876},{},[20063,20067,20074,20077,20084,20087,20093],{"data":20064,"marks":20065,"value":20066,"nodeType":867},{},[],"Want to learn more about Push? ",{"data":20068,"content":20069,"nodeType":915},{"uri":14693},[20070],{"data":20071,"marks":20072,"value":20073,"nodeType":867},{},[],"Check out our latest product overview",{"data":20075,"marks":20076,"value":5136,"nodeType":867},{},[],{"data":20078,"content":20079,"nodeType":915},{"uri":14705},[20080],{"data":20081,"marks":20082,"value":20083,"nodeType":867},{},[],"visit our demo library",{"data":20085,"marks":20086,"value":14715,"nodeType":867},{},[],{"data":20088,"content":20089,"nodeType":915},{"uri":2689},[20090],{"data":20091,"marks":20092,"value":14723,"nodeType":867},{},[],{"data":20094,"marks":20095,"value":1679,"nodeType":867},{},[],{"data":20097,"content":20101,"nodeType":985},{"target":20098},{"sys":20099},{"id":20100,"type":982,"linkType":983},"1doMkOu2ZuGqMp2VJgV5pb",[],{"data":20103,"content":20104,"nodeType":876},{},[20105],{"data":20106,"marks":20107,"value":21,"nodeType":867},{},[],{"entries":20109},{"hyperlink":20110,"inline":20111,"block":20112},[],[],[20113,20121],{"sys":20114,"__typename":1688,"title":20115,"caption":20116,"layoutMode":59,"file":20117},{"id":19806},"Security Eras","Modern attacks play out in the browser, exploiting a security blindspot",{"url":20118,"width":20119,"height":20120},"https://images.ctfassets.net/y1cdw1ablpvd/4zqrAlec1qJaCnE4OUFT7A/7dcd3f568ec90308ba1025ab5be686bb/Screenshot_2026-01-30_at_12.22.19.png",3418,1788,{"sys":20122,"__typename":1697,"type":1698,"ctaText":20123,"buttonLabel":17415,"buttonColour":1701,"buttonUrl":5286},{"id":20100},"Stop browser-based attacks in real time. Book a demo today. ",{"items":20125},[],{},"Push + Endpoint Security: Extending D&R to the browser","2026-01-30T00:00:00.000Z",{"items":20130},[20131,20637],{"__typename":1772,"sys":20132,"content":20134,"title":20624,"synopsis":20625,"hashTags":59,"publishedDate":20128,"slug":20626,"tagsCollection":20627,"authorsCollection":20633},{"id":20133},"5caCcGCqMMPm5KlwUv0sbz",{"json":20135},{"data":20136,"content":20137,"nodeType":1680},{},[20138,20146,20153,20160,20172,20180,20187,20194,20201,20209,20212,20220,20227,20234,20241,20258,20264,20271,20289,20297,20416,20419,20427,20434,20446,20453,20459,20466,20473,20481,20488,20496,20503,20510,20517,20565,20577,20613,20618],{"data":20139,"content":20140,"nodeType":868},{},[20141],{"data":20142,"marks":20143,"value":20145,"nodeType":867},{},[20144],{"type":865},"Defense used to start at the network perimeter",{"data":20147,"content":20148,"nodeType":876},{},[20149],{"data":20150,"marks":20151,"value":20152,"nodeType":867},{},[],"If you've been working in security for any length of time, you know where defense starts: the network. Long before cloud-first or SaaS-first became default, the perimeter was where defenders had leverage: visibility, enforcement, and control over traffic moving in and out of the organization.",{"data":20154,"content":20155,"nodeType":876},{},[20156],{"data":20157,"marks":20158,"value":20159,"nodeType":867},{},[],"That mental model hasn’t disappeared. Secure Web Gateways, Cloud Access Security Brokers, and the converged Security Service Edge architecture exist because the problem they solve is still real. Organizations generate an enormous volume of web traffic, and someone has to monitor it, filter it, and enforce policy at scale. These tools sit inline, log metadata, apply categorization, and block what’s already known to be dangerous. Without them, the environment quickly becomes unmanageable and extremely difficult to secure.",{"data":20161,"content":20162,"nodeType":876},{},[20163,20167],{"data":20164,"marks":20165,"value":20166,"nodeType":867},{},[],"They are very good at what they were designed to do: securing the wire. ",{"data":20168,"marks":20169,"value":20171,"nodeType":867},{},[20170],{"type":865},"But what happens over the wire is not the full picture. ",{"data":20173,"content":20174,"nodeType":1058},{},[20175],{"data":20176,"marks":20177,"value":20179,"nodeType":867},{},[20178],{"type":865},"Traffic isn't the whole picture anymore",{"data":20181,"content":20182,"nodeType":876},{},[20183],{"data":20184,"marks":20185,"value":20186,"nodeType":867},{},[],"A significant amount of activity happens locally, inside the browser, beyond the visibility of network controls. Modern webpages are effectively complicated web apps that are rendered client-side via JavaScript — and not everything that happens on the page is traffic-generating. ",{"data":20188,"content":20189,"nodeType":876},{},[20190],{"data":20191,"marks":20192,"value":20193,"nodeType":867},{},[],"That distinction matters more than it used to. Authentication, data access, administrative actions, almost all of it now happens inside a browser tab. As a result, the browser has become a central point of both productivity and risk.",{"data":20195,"content":20196,"nodeType":876},{},[20197],{"data":20198,"marks":20199,"value":20200,"nodeType":867},{},[],"Network tools still see the pipeline of traffic moving back and forth. But attackers have adapted to operate within that pipeline rather than around it. They don’t need to break the connection or trigger obvious anomalies. They target the content rendered inside the browser and the user interacting with it.",{"data":20202,"content":20203,"nodeType":876},{},[20204],{"data":20205,"marks":20206,"value":20208,"nodeType":867},{},[20207],{"type":865},"That leaves security teams with noisy traffic visibility and very little insight into the actual attack unfolding inside the browser session.",{"data":20210,"content":20211,"nodeType":942},{},[],{"data":20213,"content":20214,"nodeType":868},{},[20215],{"data":20216,"marks":20217,"value":20219,"nodeType":867},{},[20218],{"type":865},"Traffic visibility vs. in-browser context",{"data":20221,"content":20222,"nodeType":876},{},[20223],{"data":20224,"marks":20225,"value":20226,"nodeType":867},{},[],"The modern attacker's playbook is built on a simple idea: stay inside the network’s line of sight without triggering detections or enforcement. Containing operations to the browser layer provides attackers with an easy bypass of many traditional network controls without ever needing to break or evade them outright.",{"data":20228,"content":20229,"nodeType":876},{},[20230],{"data":20231,"marks":20232,"value":20233,"nodeType":867},{},[],"They do this by staying ahead of known-bad detection models, constantly rotating domains and URLs, using anti-analysis techniques, and delivering phishing lures through channels that bypass traditional network ingress points like the email gateway (like social media or SMS). In many cases, the link is never evaluated by perimeter controls at all.",{"data":20235,"content":20236,"nodeType":876},{},[20237],{"data":20238,"marks":20239,"value":20240,"nodeType":867},{},[],"This creates a fundamental visibility gap. Network security tools can see a request going to a legitimate-looking destination, but they can’t observe what happens once the page executes client-side in the browser. Malicious scripts and phishing elements often don’t appear until after the page loads and a user interacts with it, leaving nothing obviously known-bad for network controls to detect.",{"data":20242,"content":20243,"nodeType":876},{},[20244,20248,20254],{"data":20245,"marks":20246,"value":20247,"nodeType":867},{},[],"Blocklists don’t help much here either. Domains rotate constantly, and the window between a phishing site going live and being categorized as malicious is more than enough time for an attacker to succeed. Until that happens, the traffic appears benign and the user is free to interact with the page. And to make matters worse, attackers are leveraging ",{"data":20249,"content":20250,"nodeType":915},{"uri":1240},[20251],{"data":20252,"marks":20253,"value":12185,"nodeType":867},{},[],{"data":20255,"marks":20256,"value":20257,"nodeType":867},{},[]," designed to frustrate these detections — meaning most bad pages aren't spotted until it's way too late. ",{"data":20259,"content":20263,"nodeType":985},{"target":20260},{"sys":20261},{"id":20262,"type":982,"linkType":983},"38X1De97xJ8B6GNXTHW6Y5",[],{"data":20265,"content":20266,"nodeType":876},{},[20267],{"data":20268,"marks":20269,"value":20270,"nodeType":867},{},[],"Consider attacker-in-the-middle phishing. From the proxy’s perspective, everything looks clean: user → reputable domain → “standard” web traffic. The phishing infrastructure is often hidden behind redirects or conditional logic designed to screen out proxies and scanners. Inside the browser session, however, credentials are intercepted, session tokens are harvested, and MFA is bypassed in real time.",{"data":20272,"content":20273,"nodeType":876},{},[20274,20278,20285],{"data":20275,"marks":20276,"value":20277,"nodeType":867},{},[],"For ",{"data":20279,"content":20280,"nodeType":915},{"uri":1177},[20281],{"data":20282,"marks":20283,"value":20284,"nodeType":867},{},[],"modern threat groups",{"data":20286,"marks":20287,"value":20288,"nodeType":867},{},[],", these obscured attack vectors lead directly to initial access and account takeover. The network is no longer the control point where the most consequential attacks can be reliably stopped.",{"data":20290,"content":20291,"nodeType":876},{},[20292],{"data":20293,"marks":20294,"value":20296,"nodeType":867},{},[20295],{"type":1303},"Browser telemetry is key to detecting and blocking malicious content in real-time, rather than relying on blocklists using known-bad indicators like domains and IPs that go out of date as quickly as new entries appear.",{"data":20298,"content":20299,"nodeType":7904},{},[20300,20324,20347,20370,20393],{"data":20301,"content":20302,"nodeType":7640},{},[20303,20314],{"data":20304,"content":20305,"nodeType":20313},{},[20306],{"data":20307,"content":20308,"nodeType":876},{},[20309],{"data":20310,"marks":20311,"value":20312,"nodeType":867},{},[],"What you see with traffic analysis","table-header-cell",{"data":20315,"content":20316,"nodeType":20313},{},[20317],{"data":20318,"content":20319,"nodeType":876},{},[20320],{"data":20321,"marks":20322,"value":20323,"nodeType":867},{},[],"What you can see with browser telemetry",{"data":20325,"content":20326,"nodeType":7640},{},[20327,20337],{"data":20328,"content":20329,"nodeType":7628},{},[20330],{"data":20331,"content":20332,"nodeType":876},{},[20333],{"data":20334,"marks":20335,"value":20336,"nodeType":867},{},[],"HTTP request/response bodies ",{"data":20338,"content":20339,"nodeType":7628},{},[20340],{"data":20341,"content":20342,"nodeType":876},{},[20343],{"data":20344,"marks":20345,"value":20346,"nodeType":867},{},[],"DOM structure fingerprints",{"data":20348,"content":20349,"nodeType":7640},{},[20350,20360],{"data":20351,"content":20352,"nodeType":7628},{},[20353],{"data":20354,"content":20355,"nodeType":876},{},[20356],{"data":20357,"marks":20358,"value":20359,"nodeType":867},{},[],"URLs and headers",{"data":20361,"content":20362,"nodeType":7628},{},[20363],{"data":20364,"content":20365,"nodeType":876},{},[20366],{"data":20367,"marks":20368,"value":20369,"nodeType":867},{},[],"User interaction metadata ",{"data":20371,"content":20372,"nodeType":7640},{},[20373,20383],{"data":20374,"content":20375,"nodeType":7628},{},[20376],{"data":20377,"content":20378,"nodeType":876},{},[20379],{"data":20380,"marks":20381,"value":20382,"nodeType":867},{},[],"Cookie values in transit",{"data":20384,"content":20385,"nodeType":7628},{},[20386],{"data":20387,"content":20388,"nodeType":876},{},[20389],{"data":20390,"marks":20391,"value":20392,"nodeType":867},{},[],"Cookie names and attributes",{"data":20394,"content":20395,"nodeType":7640},{},[20396,20406],{"data":20397,"content":20398,"nodeType":7628},{},[20399],{"data":20400,"content":20401,"nodeType":876},{},[20402],{"data":20403,"marks":20404,"value":20405,"nodeType":867},{},[],"Static JS code",{"data":20407,"content":20408,"nodeType":7628},{},[20409],{"data":20410,"content":20411,"nodeType":876},{},[20412],{"data":20413,"marks":20414,"value":20415,"nodeType":867},{},[],"Script execution patterns and dynamic JS analysis",{"data":20417,"content":20418,"nodeType":942},{},[],{"data":20420,"content":20421,"nodeType":868},{},[20422],{"data":20423,"marks":20424,"value":20426,"nodeType":867},{},[20425],{"type":865},"Securing the browser session is key to stopping modern threats",{"data":20428,"content":20429,"nodeType":876},{},[20430],{"data":20431,"marks":20432,"value":20433,"nodeType":867},{},[],"If the browser is where users actually work, and where attackers actually operate, then that’s the layer that defenders need to understand and control.",{"data":20435,"content":20436,"nodeType":876},{},[20437,20441],{"data":20438,"marks":20439,"value":20440,"nodeType":867},{},[],"Modern web-based attacks don’t succeed because traffic goes uninspected. They succeed because network inspection can’t follow the interaction far enough. Traffic shows where data went, not what the user actually saw or did, ",{"data":20442,"marks":20443,"value":20445,"nodeType":867},{},[20444],{"type":865},"and in today’s attacks, that distinction matters.",{"data":20447,"content":20448,"nodeType":876},{},[20449],{"data":20450,"marks":20451,"value":20452,"nodeType":867},{},[],"To stop these threats, you have to see what the user is actually interacting with. Things like what scripts are loading, how the DOM is being manipulated, or whether the login form a user is using is legitimate or being proxied. Those are page-level signals, and they only exist inside the browser tab.",{"data":20454,"content":20458,"nodeType":985},{"target":20455},{"sys":20456},{"id":20457,"type":982,"linkType":983},"6qMaivxhJ3xT9DkwXGcCSJ",[],{"data":20460,"content":20461,"nodeType":876},{},[20462],{"data":20463,"marks":20464,"value":20465,"nodeType":867},{},[],"That same shift applies to control. Destination-based blocking breaks down when the destination itself appears legitimate. Effective intervention requires decisions based on behavior as it unfolds so teams can stop risky or malicious activity that would compromise an account.",{"data":20467,"content":20468,"nodeType":876},{},[20469],{"data":20470,"marks":20471,"value":20472,"nodeType":867},{},[],"And visibility can’t stop at centrally managed applications. Shadow SaaS breaks any assumption that access patterns are uniform or fully governed by the IdP. Local accounts, duplicate identities, and password-only logins don’t show up clearly in network telemetry, but they materially expand the attack surface. Seeing every login, across every app, directly from the browser is the only way to build an accurate picture of who has access to what.",{"data":20474,"content":20475,"nodeType":1058},{},[20476],{"data":20477,"marks":20478,"value":20480,"nodeType":867},{},[20479],{"type":865},"Push provides the missing context for network security",{"data":20482,"content":20483,"nodeType":876},{},[20484],{"data":20485,"marks":20486,"value":20487,"nodeType":867},{},[],"At this point, the gap should be clear. Network security gives you strong control over traffic, but very little insight into what actually happens once that traffic lands in a user’s browser.",{"data":20489,"content":20490,"nodeType":876},{},[20491],{"data":20492,"marks":20493,"value":20495,"nodeType":867},{},[20494],{"type":865},"This is where Push can help.",{"data":20497,"content":20498,"nodeType":876},{},[20499],{"data":20500,"marks":20501,"value":20502,"nodeType":867},{},[],"The Push browser agent extends monitoring into the browser itself, providing the visibility and control that perimeter-based tools can’t deliver. It doesn’t replace SSE, SWG, or CASB. Those tools remain the right way to manage traffic and enforce policy at the edge. Push complements them by operating in the one place they can’t: inside the live browser session.",{"data":20504,"content":20505,"nodeType":876},{},[20506],{"data":20507,"marks":20508,"value":20509,"nodeType":867},{},[],"Push does this by deploying a browser-native agent, similar in spirit to how EDR works at the host level. That agent gives defenders direct insight into what the network can’t see like the page being rendered, how the user is interacting with it, and the attack techniques that play out entirely within the tab.",{"data":20511,"content":20512,"nodeType":876},{},[20513],{"data":20514,"marks":20515,"value":20516,"nodeType":867},{},[],"With Push deployed, teams gain:",{"data":20518,"content":20519,"nodeType":1629},{},[20520,20535,20550],{"data":20521,"content":20522,"nodeType":1586},{},[20523],{"data":20524,"content":20525,"nodeType":876},{},[20526,20531],{"data":20527,"marks":20528,"value":20530,"nodeType":867},{},[20529],{"type":865},"Real-time, in-browser threat detection:",{"data":20532,"marks":20533,"value":20534,"nodeType":867},{},[]," Detect and stop attacks like AiTM phishing and session hijacking based on what’s actually happening in the browser. Instead of relying on blocklists or downstream signals, Push identifies attacker behavior as it unfolds and can intervene before credentials or session tokens are stolen.",{"data":20536,"content":20537,"nodeType":1586},{},[20538],{"data":20539,"content":20540,"nodeType":876},{},[20541,20546],{"data":20542,"marks":20543,"value":20545,"nodeType":867},{},[20544],{"type":865},"Complete visibility into SaaS access: ",{"data":20547,"marks":20548,"value":20549,"nodeType":867},{},[],"Build a true inventory of user identities and authentication methods across every application in use, including shadow SaaS. Push fills the gaps left by network and IdP logs, giving teams a real picture of where access exists and how it’s being granted.",{"data":20551,"content":20552,"nodeType":1586},{},[20553],{"data":20554,"content":20555,"nodeType":876},{},[20556,20561],{"data":20557,"marks":20558,"value":20560,"nodeType":867},{},[20559],{"type":865},"Streamlined hardening at the point of access:",{"data":20562,"marks":20563,"value":20564,"nodeType":867},{},[]," Use the browser as a control point to enforce secure login behavior everywhere it matters. Mandate MFA, steer users toward SSO, and block risky credentials on unmanaged apps, shifting from reactive cleanup to continuous, preventative hardening.",{"data":20566,"content":20567,"nodeType":876},{},[20568,20572],{"data":20569,"marks":20570,"value":20571,"nodeType":867},{},[],"The result is a unified model and real defense in depth. ",{"data":20573,"marks":20574,"value":20576,"nodeType":867},{},[20575],{"type":865},"Network tools secure the pipeline, and Push secures the user moving through it.",{"data":20578,"content":20579,"nodeType":3804},{},[20580],{"data":20581,"content":20582,"nodeType":876},{},[20583,20586,20592,20595,20601,20604,20610],{"data":20584,"marks":20585,"value":20066,"nodeType":867},{},[],{"data":20587,"content":20588,"nodeType":915},{"uri":14693},[20589],{"data":20590,"marks":20591,"value":20073,"nodeType":867},{},[],{"data":20593,"marks":20594,"value":5136,"nodeType":867},{},[],{"data":20596,"content":20597,"nodeType":915},{"uri":14705},[20598],{"data":20599,"marks":20600,"value":20083,"nodeType":867},{},[],{"data":20602,"marks":20603,"value":14715,"nodeType":867},{},[],{"data":20605,"content":20606,"nodeType":915},{"uri":2689},[20607],{"data":20608,"marks":20609,"value":14723,"nodeType":867},{},[],{"data":20611,"marks":20612,"value":1679,"nodeType":867},{},[],{"data":20614,"content":20617,"nodeType":985},{"target":20615},{"sys":20616},{"id":20100,"type":982,"linkType":983},[],{"data":20619,"content":20620,"nodeType":876},{},[20621],{"data":20622,"marks":20623,"value":21,"nodeType":867},{},[],"Push + Network Security: The gap between seeing the packet and securing the session","Why network and web traffic only gives you part of the picture when it comes to modern browser-based attacks. ","push-plus-network-security",{"items":20628},[20629,20631],{"sys":20630,"name":4018},{"id":4017},{"sys":20632,"name":342},{"id":3240},{"items":20634},[20635],{"fullName":849,"firstName":850,"jobTitle":851,"profilePicture":20636},{"url":853},{"__typename":1772,"sys":20638,"content":20640,"title":21011,"synopsis":21012,"hashTags":59,"publishedDate":21013,"slug":21014,"tagsCollection":21015,"authorsCollection":21021},{"id":20639},"2k2aDK5dyQKlQBrk66pMXE",{"json":20641},{"data":20642,"content":20643,"nodeType":1680},{},[20644,20652,20659,20666,20673,20680,20687,20695,20702,20709,20716,20719,20727,20734,20741,20748,20755,20773,20781,20788,20795,20802,20805,20813,20829,20845,20852,20860,20867,20874,20881,20888,20893,20900,20963,20966,21005],{"data":20645,"content":20646,"nodeType":868},{},[20647],{"data":20648,"marks":20649,"value":20651,"nodeType":867},{},[20650],{"type":865},"Cloud security tools ensure secure configurations",{"data":20653,"content":20654,"nodeType":876},{},[20655],{"data":20656,"marks":20657,"value":20658,"nodeType":867},{},[],"If you’re a cloud security architect, you probably don’t think in terms of firewalls and perimeters anymore. You think in control planes. Your job isn’t protecting a box or a subnet; it’s governing a sprawling web of IAM roles, service principals, APIs, and permissions that exist mostly as configuration and code. In this world, the boundary isn’t physical or even networked, it’s defined entirely by how your environment is configured.",{"data":20660,"content":20661,"nodeType":876},{},[20662],{"data":20663,"marks":20664,"value":20665,"nodeType":867},{},[],"The way most teams approached that problem was pragmatic. As cloud environments scaled, it became impossible to secure it by inspection or tribal knowledge. Cloud Security Posture Management tools and, later, Cloud Native Application Protection Platforms emerged to solve a very real problem: visibility and control over cloud configuration at scale. They gave teams a way to continuously assess infrastructure, track misconfigurations, and understand risk across accounts, regions, and services without drowning in raw provider logs.",{"data":20667,"content":20668,"nodeType":876},{},[20669],{"data":20670,"marks":20671,"value":20672,"nodeType":867},{},[],"That capability is important. Without it, cloud security simply doesn’t function. ",{"data":20674,"content":20675,"nodeType":876},{},[20676],{"data":20677,"marks":20678,"value":20679,"nodeType":867},{},[],"CSPM and CNAPP answer the question of “is my cloud environment configured securely?”. They tell you whether an IAM role is too permissive, whether a resource is exposed, or whether a policy violates best practice. They tell you when a user or account is trying to do something they shouldn’t. ",{"data":20681,"content":20682,"nodeType":876},{},[20683],{"data":20684,"marks":20685,"value":20686,"nodeType":867},{},[],"What they don’t answer is a different, increasingly important question: “What happens when attacker behavior is indistinguishable from legitimate user behavior?”",{"data":20688,"content":20689,"nodeType":1058},{},[20690],{"data":20691,"marks":20692,"value":20694,"nodeType":867},{},[20693],{"type":865},"But they can’t stop “legitimate” actions",{"data":20696,"content":20697,"nodeType":876},{},[20698],{"data":20699,"marks":20700,"value":20701,"nodeType":867},{},[],"The gap (or lack of) between legitimate user behavior and malicious abuse is becoming more relevant as cloud breaches change shape. ",{"data":20703,"content":20704,"nodeType":876},{},[20705],{"data":20706,"marks":20707,"value":20708,"nodeType":867},{},[],"In many of today’s incidents, attackers aren’t exploiting misconfigurations or abusing the cloud control plane directly. They’re compromising users. Once an authentication has occurred through illegitimate means, whether phishing, session hijacking, or token theft, the attacker operates entirely within an approved session.",{"data":20710,"content":20711,"nodeType":876},{},[20712],{"data":20713,"marks":20714,"value":20715,"nodeType":867},{},[],"From the perspective of cloud security tooling, very little looks wrong. The identity is valid. The access patterns appear expected. The infrastructure remains correctly configured. As long as the attacker operates within the bounds of what looks “normal”, no alarms are triggered. Meanwhile, sensitive actions are carried out through the browser, using the same interfaces and workflows as a real user.",{"data":20717,"content":20718,"nodeType":942},{},[],{"data":20720,"content":20721,"nodeType":868},{},[20722],{"data":20723,"marks":20724,"value":20726,"nodeType":867},{},[20725],{"type":865},"The gap between the IdP and the final API call — the “missing middle” in your security stack",{"data":20728,"content":20729,"nodeType":876},{},[20730],{"data":20731,"marks":20732,"value":20733,"nodeType":867},{},[],"The browser session sits outside the telemetry and control model of infrastructure-focused cloud security tools. We call this the \"missing middle.\" It’s the space between the IdP login and the final cloud API call. ",{"data":20735,"content":20736,"nodeType":876},{},[20737],{"data":20738,"marks":20739,"value":20740,"nodeType":867},{},[],"In theory, you could try to close the gap by stitching together logs from every SaaS application in your environment. In practice, anyone who’s attempted this knows how quickly it falls apart. ",{"data":20742,"content":20743,"nodeType":876},{},[20744],{"data":20745,"marks":20746,"value":20747,"nodeType":867},{},[],"Each integration is brittle and expensive to maintain, and many applications don’t expose the level of telemetry you actually need, even if you’re willing to fork out for the top Security++ product tier. When you’re dealing with hundreds of apps per enterprise, each with their own configuration complexity, there’s a good chance that your solution focused on “core” cloud apps doesn’t actually have visibility of the full attack surface.",{"data":20749,"content":20750,"nodeType":876},{},[20751],{"data":20752,"marks":20753,"value":20754,"nodeType":867},{},[],"When logs do exist, they rarely show what you actually need. To a CSPM or CNAPP, it looks like an authorized user doing authorized things. A file was accessed or a setting was changed. What those tools can’t see is that the browser session itself was being manipulated in real time.",{"data":20756,"content":20757,"nodeType":876},{},[20758,20761,20769],{"data":20759,"marks":20760,"value":20277,"nodeType":867},{},[],{"data":20762,"content":20763,"nodeType":915},{"uri":1177},[20764],{"data":20765,"marks":20766,"value":20768,"nodeType":867},{},[20767],{"type":913},"modern, cloud-native threat groups",{"data":20770,"marks":20771,"value":20772,"nodeType":867},{},[],", this lack of session-level visibility is their greatest advantage. They bypass the strong configuration and identity controls you’ve already implemented by simply stepping into the authorized stream. And by the time infrastructure-level signals suggest something is wrong, the attacker has already accomplished what they came for.",{"data":20774,"content":20775,"nodeType":1058},{},[20776],{"data":20777,"marks":20778,"value":20780,"nodeType":867},{},[20779],{"type":865},"Secure everything, still lose",{"data":20782,"content":20783,"nodeType":876},{},[20784],{"data":20785,"marks":20786,"value":20787,"nodeType":867},{},[],"At some point, this forces a hard realization: you can do everything “right” at the cloud and identity layers and still lose.",{"data":20789,"content":20790,"nodeType":876},{},[20791],{"data":20792,"marks":20793,"value":20794,"nodeType":867},{},[],"You can lock down infrastructure-as-code, tighten IAM policies, enforce conditional access, and pass every posture check you care about. But none of that changes where access actually happens. When users work in cloud services, they do it through a browser. And once a session is established, that browser session becomes the real control plane.",{"data":20796,"content":20797,"nodeType":876},{},[20798],{"data":20799,"marks":20800,"value":20801,"nodeType":867},{},[],"That’s the shift cloud security teams are running into. The problem isn’t that CSPM or CNAPP failed, it’s that they can’t see the full picture. Bridging the missing middle means treating the browser session itself as something you can inspect and defend.",{"data":20803,"content":20804,"nodeType":942},{},[],{"data":20806,"content":20807,"nodeType":868},{},[20808],{"data":20809,"marks":20810,"value":20812,"nodeType":867},{},[20811],{"type":865},"Why moving detection and response to the browser is the solution",{"data":20814,"content":20815,"nodeType":876},{},[20816,20820,20825],{"data":20817,"marks":20818,"value":20819,"nodeType":867},{},[],"First, ",{"data":20821,"marks":20822,"value":20824,"nodeType":867},{},[20823],{"type":865},"detection has to move into the browser",{"data":20826,"marks":20827,"value":20828,"nodeType":867},{},[],". Modern cloud attacks don’t announce themselves with known indicators or suspicious IPs; it’s all about behavior. A phishing kit rendering inside a login page. A session token being silently exfiltrated. A user interacting with a page that looks legitimate but isn’t. You only see those signals by inspecting the page, the scripts, and the user’s interaction, in real time, inside the tab, before any cloud API ever gets touched.",{"data":20830,"content":20831,"nodeType":876},{},[20832,20836,20841],{"data":20833,"marks":20834,"value":20835,"nodeType":867},{},[],"Second, ",{"data":20837,"marks":20838,"value":20840,"nodeType":867},{},[20839],{"type":865},"posture can’t stop at the IdP or cloud configuration.",{"data":20842,"marks":20843,"value":20844,"nodeType":867},{},[]," It’s not enough to enforce MFA and SSO at a handful of centrally managed apps and assume the rest of the estate follows suit. Shadow SaaS breaks that assumption immediately. Local accounts, duplicate identities, and MFA gaps undermine cloud access controls, even when your AWS or Azure configuration is otherwise airtight. If a sensitive app allows password-only access, that weakness propagates straight back into your cloud environment.",{"data":20846,"content":20847,"nodeType":876},{},[20848],{"data":20849,"marks":20850,"value":20851,"nodeType":867},{},[],"Finally, when something does go wrong, teams need more than a login timestamp and an IP address. They need to know what the user actually saw and did. Click-by-click browser session data is what allows responders to understand intent, scope impact accurately, and determine whether a session was abused or simply used.",{"data":20853,"content":20854,"nodeType":1058},{},[20855],{"data":20856,"marks":20857,"value":20859,"nodeType":867},{},[20858],{"type":865},"Visibility into the browser session holds the answers",{"data":20861,"content":20862,"nodeType":876},{},[20863],{"data":20864,"marks":20865,"value":20866,"nodeType":867},{},[],"If the browser session is where cloud access actually happens, then treating it as a black box is no longer viable.",{"data":20868,"content":20869,"nodeType":876},{},[20870],{"data":20871,"marks":20872,"value":20873,"nodeType":867},{},[],"This is where Push Security fits. Push is designed to cover the missing middle, not by replacing your existing cloud security stack, but by extending it into the one place it can’t reach on its own: the live browser session.",{"data":20875,"content":20876,"nodeType":876},{},[20877],{"data":20878,"marks":20879,"value":20880,"nodeType":867},{},[],"CSPM and CNAPP remain the right tools for securing cloud configuration and infrastructure. They tell you whether IAM policies are sane, resources are exposed, and guardrails are in place. Push addresses a different problem. It focuses on what happens once access is granted, when identity moves from configuration into motion.",{"data":20882,"content":20883,"nodeType":876},{},[20884],{"data":20885,"marks":20886,"value":20887,"nodeType":867},{},[],"Push does this by deploying a browser-native agent, like EDR operates at the host level. That agent gives defenders direct visibility into the application session itself like the page structure being rendered, the user’s interaction with it, and the behaviors attackers rely on when they hijack sessions in real time.",{"data":20889,"content":20892,"nodeType":985},{"target":20890},{"sys":20891},{"id":20457,"type":982,"linkType":983},[],{"data":20894,"content":20895,"nodeType":876},{},[20896],{"data":20897,"marks":20898,"value":20899,"nodeType":867},{},[],"That visibility changes how cloud access can be defended.",{"data":20901,"content":20902,"nodeType":1629},{},[20903,20918,20933,20948],{"data":20904,"content":20905,"nodeType":1586},{},[20906],{"data":20907,"content":20908,"nodeType":876},{},[20909,20914],{"data":20910,"marks":20911,"value":20913,"nodeType":867},{},[20912],{"type":865},"Real-time detection in the browser:",{"data":20915,"marks":20916,"value":20917,"nodeType":867},{},[]," Detect in-browser attacker techniques as they happen, left of boom. Phishing kits rendering inside login flows, session tokens being intercepted, credential submission into lookalike pages — Push observes these behaviors directly and can block them before any cloud API is touched or a console is reached.",{"data":20919,"content":20920,"nodeType":1586},{},[20921],{"data":20922,"content":20923,"nodeType":876},{},[20924,20929],{"data":20925,"marks":20926,"value":20928,"nodeType":867},{},[20927],{"type":865},"Complete visibility into cloud access paths:",{"data":20930,"marks":20931,"value":20932,"nodeType":867},{},[]," Build an accurate inventory of how users are actually accessing cloud services. Push surfaces every application in use, including shadow SaaS, and shows which accounts are local, duplicated, missing MFA, or bypassing SSO — crucial visibility that falls between the cracks of application and identity provider. ",{"data":20934,"content":20935,"nodeType":1586},{},[20936],{"data":20937,"content":20938,"nodeType":876},{},[20939,20944],{"data":20940,"marks":20941,"value":20943,"nodeType":867},{},[20942],{"type":865},"Active hardening at the point of access:",{"data":20945,"marks":20946,"value":20947,"nodeType":867},{},[]," Enforce secure login behavior across the entire application surface, not just centrally managed apps. Push can steer users toward using MFA and SSO and block risky credentials on unmanaged tools, closing identity gaps before they’re exploited.",{"data":20949,"content":20950,"nodeType":1586},{},[20951],{"data":20952,"content":20953,"nodeType":876},{},[20954,20959],{"data":20955,"marks":20956,"value":20958,"nodeType":867},{},[20957],{"type":865},"Session-level context for rapid response:",{"data":20960,"marks":20961,"value":20962,"nodeType":867},{},[]," When something does go wrong, Push provides the missing ground truth. Instead of stitching together partial logs or relying on brittle app-level integrations, responders can see exactly what the user saw and did in the browser (from context generated directly from the browser session itself) making it possible to understand intent, assess scope accurately, and contain a compromised session quickly.",{"data":20964,"content":20965,"nodeType":942},{},[],{"data":20967,"content":20968,"nodeType":3804},{},[20969],{"data":20970,"content":20971,"nodeType":876},{},[20972,20975,20982,20985,20992,20995,21002],{"data":20973,"marks":20974,"value":20066,"nodeType":867},{},[],{"data":20976,"content":20977,"nodeType":915},{"uri":14693},[20978],{"data":20979,"marks":20980,"value":20073,"nodeType":867},{},[20981],{"type":913},{"data":20983,"marks":20984,"value":5136,"nodeType":867},{},[],{"data":20986,"content":20987,"nodeType":915},{"uri":14705},[20988],{"data":20989,"marks":20990,"value":20083,"nodeType":867},{},[20991],{"type":913},{"data":20993,"marks":20994,"value":14715,"nodeType":867},{},[],{"data":20996,"content":20997,"nodeType":915},{"uri":2689},[20998],{"data":20999,"marks":21000,"value":14723,"nodeType":867},{},[21001],{"type":913},{"data":21003,"marks":21004,"value":1679,"nodeType":867},{},[],{"data":21006,"content":21007,"nodeType":876},{},[21008],{"data":21009,"marks":21010,"value":21,"nodeType":867},{},[],"Push + Cloud Security: What do you do when bad looks normal?","Why cloud security tools only give you part of the picture when it comes to modern attacks. ","2026-02-06T00:00:00.000Z","push-plus-cloud-security",{"items":21016},[21017,21019],{"sys":21018,"name":4018},{"id":4017},{"sys":21020,"name":342},{"id":3240},{"items":21022},[21023],{"fullName":849,"firstName":850,"jobTitle":851,"profilePicture":21024},{"url":853},"push-plus-endpoint-security","blog/push-plus-endpoint-security",{"json":21028},{"data":21029,"content":21030,"nodeType":1680},{},[21031],{"data":21032,"content":21033,"nodeType":876},{},[21034],{"data":21035,"marks":21036,"value":21037,"nodeType":867},{},[],"One of the key questions we often hear is \"we've already got EDR, so why do we need to be in the browser too?\". Well, here's the answer!","Why extending detection and response into the browser is crucial in the face of modern attacks that consciously evade the network and endpoint. ",{"id":21040,"publishedAt":21041},"6YWYKGESlyUKQxvhKmBzeH","2026-08-13T09:35:41.299Z",{"items":21043},[21044,21046],{"sys":21045,"name":4018},{"id":4017},{"sys":21047,"name":342},{"id":3240},{"items":21049},[21050,21052,21054,21056,21058,21060,21062,21064],{"sys":21051,"name":297,"slug":298,"tier":31},{"id":294},{"sys":21053,"name":279,"slug":280,"tier":31},{"id":276},{"sys":21055,"name":342,"slug":343,"tier":31},{"id":339},{"sys":21057,"name":377,"slug":378,"tier":45},{"id":374},{"sys":21059,"name":261,"slug":262,"tier":45},{"id":258},{"sys":21061,"name":571,"slug":572,"tier":45},{"id":568},{"sys":21063,"name":288,"slug":289,"tier":45},{"id":285},{"sys":21065,"name":315,"slug":316,"tier":45},{"id":312},"JhUSIdUT34jBz7baqPjVEhg0kgv0ylAjyUoc9hrf0Ok",{"id":21068,"title":21069,"authorsCollection":21070,"content":21076,"extension":228,"faqItemsCollection":21729,"faqTitle":59,"featured":6,"hashTags":59,"meta":21731,"metaTitle":21732,"ogImage":59,"postType":21733,"publishedDate":21734,"relatedBlogPostsCollection":21735,"slug":23610,"stem":23611,"subtitle":59,"summary":23612,"synopsis":23622,"sys":23623,"tagsCollection":23626,"topicsCollection":23632,"__hash__":23660},"blog/blog/the-most-advanced-clickfix-yet.json","The most advanced ClickFix yet?",{"items":21071},[21072],{"fullName":4022,"firstName":4023,"jobTitle":4024,"socialLinks":21073,"profilePicture":21075},[21074],"https://www.linkedin.com/in/daniel-g-/",{"url":4026},{"json":21077,"links":21653},{"data":21078,"content":21079,"nodeType":1680},{},[21080,21087,21094,21106,21112,21119,21122,21130,21137,21143,21159,21166,21189,21196,21202,21205,21213,21246,21252,21271,21277,21296,21303,21309,21312,21320,21327,21347,21354,21374,21381,21387,21390,21398,21405,21438,21445,21452,21498,21517,21527,21534,21537,21545,21565,21572,21579,21585,21588,21595,21615,21642,21647],{"data":21081,"content":21082,"nodeType":876},{},[21083],{"data":21084,"marks":21085,"value":21086,"nodeType":867},{},[],"ClickFix attacks have skyrocketed in the last year. This social engineering attack has established itself as a key part of the modern attacker’s toolkit, tricking victims into running malicious code on their device.",{"data":21088,"content":21089,"nodeType":876},{},[21090],{"data":21091,"marks":21092,"value":21093,"nodeType":867},{},[],"As we showcased in our last webinar and at our threat briefing in London earlier this month, ClickFix is evolving fast, in terms of the web pages themselves, the delivery mechanisms by which they are sent to victims, and the nature of the payload and its execution.",{"data":21095,"content":21096,"nodeType":876},{},[21097,21101],{"data":21098,"marks":21099,"value":21100,"nodeType":867},{},[],"One particular example stood out to us in our research. ",{"data":21102,"marks":21103,"value":21105,"nodeType":867},{},[21104],{"type":865},"So, is this the most advanced ClickFix you’ve seen?",{"data":21107,"content":21111,"nodeType":985},{"target":21108},{"sys":21109},{"id":21110,"type":982,"linkType":983},"ID7VKJNOZk729P5zBOBjZ",[],{"data":21113,"content":21114,"nodeType":876},{},[21115],{"data":21116,"marks":21117,"value":21118,"nodeType":867},{},[],"Let’s break it down further.",{"data":21120,"content":21121,"nodeType":942},{},[],{"data":21123,"content":21124,"nodeType":868},{},[21125],{"data":21126,"marks":21127,"value":21129,"nodeType":867},{},[21128],{"type":865},"How ClickFix pages are evolving",{"data":21131,"content":21132,"nodeType":876},{},[21133],{"data":21134,"marks":21135,"value":21136,"nodeType":867},{},[],"The CloudFlare-based lure is a great example of how ClickFix pages themselves are evolving — and becoming increasingly convincing to users. ",{"data":21138,"content":21142,"nodeType":985},{"target":21139},{"sys":21140},{"id":21141,"type":982,"linkType":983},"4wJOgtofImjbsekyXMc5Ec",[],{"data":21144,"content":21145,"nodeType":876},{},[21146,21150,21155],{"data":21147,"marks":21148,"value":21149,"nodeType":867},{},[],"This is an incredibly slick example — ",{"data":21151,"marks":21152,"value":21154,"nodeType":867},{},[21153],{"type":865},"it almost looks like Cloudflare shipped a new kind of bot check service. ",{"data":21156,"marks":21157,"value":21158,"nodeType":867},{},[],"The embedded video, countdown timer, and counter for “users verified in the last hour” all serve to increase the sense of authenticity, and put extra pressure on the victim to complete the check. ",{"data":21160,"content":21161,"nodeType":876},{},[21162],{"data":21163,"marks":21164,"value":21165,"nodeType":867},{},[],"There are a couple of extra things happening under the hood here, too:",{"data":21167,"content":21168,"nodeType":1629},{},[21169,21179],{"data":21170,"content":21171,"nodeType":1586},{},[21172],{"data":21173,"content":21174,"nodeType":876},{},[21175],{"data":21176,"marks":21177,"value":21178,"nodeType":867},{},[],"The page is adapting to the device that you’re visiting from, serving up instructions specific to the user’s Mac (increasingly common as ClickFix expands to support different Operating Systems).",{"data":21180,"content":21181,"nodeType":1586},{},[21182],{"data":21183,"content":21184,"nodeType":876},{},[21185],{"data":21186,"marks":21187,"value":21188,"nodeType":867},{},[],"The page is automatically copying the malicious code to the user’s clipboard via JavaScript (which we see in 9/10 cases).",{"data":21190,"content":21191,"nodeType":876},{},[21192],{"data":21193,"marks":21194,"value":21195,"nodeType":867},{},[],"For the past decade or more, user awareness has focused on stopping users from clicking links in suspicious emails, downloading risky files, and entering their username and password into random websites. It hasn’t focused on opening up a program and running a command — so it’s no surprise that this kind of highly convincing page is so effective at duping victims into following the instructions. ",{"data":21197,"content":21201,"nodeType":985},{"target":21198},{"sys":21199},{"id":21200,"type":982,"linkType":983},"LiVIyGxdAaUXUfvKjD6ON",[],{"data":21203,"content":21204,"nodeType":942},{},[],{"data":21206,"content":21207,"nodeType":868},{},[21208],{"data":21209,"marks":21210,"value":21212,"nodeType":867},{},[21211],{"type":865},"How ClickFix delivery methods are evolving",{"data":21214,"content":21215,"nodeType":876},{},[21216,21220,21229,21233,21242],{"data":21217,"marks":21218,"value":21219,"nodeType":867},{},[],"There’s also the fact that this page wasn’t accessed via email. The top delivery vector for ClickFix attacks that we’ve observed is, in fact, Google Search — in the form of ",{"data":21221,"content":21223,"nodeType":915},{"uri":21222},"https://phishing-techniques.pushsecurity.com/techniques/malvertising/",[21224],{"data":21225,"marks":21226,"value":21228,"nodeType":867},{},[21227],{"type":913},"poisoned search results and malicious advertising (malvertising)",{"data":21230,"marks":21231,"value":21232,"nodeType":867},{},[],". Attackers are either taking over legitimate sites (there’s a ",{"data":21234,"content":21236,"nodeType":915},{"uri":21235},"https://www.bleepingcomputer.com/news/security/hackers-launch-mass-attacks-exploiting-outdated-wordpress-plugins/",[21237],{"data":21238,"marks":21239,"value":21241,"nodeType":867},{},[21240],{"type":913},"steady supply of website hosting and CMS vulnerabilities",{"data":21243,"marks":21244,"value":21245,"nodeType":867},{},[]," to take advantage of) or simply vibe-coding their own sites and optimizing them for various search terms. ",{"data":21247,"content":21251,"nodeType":985},{"target":21248},{"sys":21249},{"id":21250,"type":982,"linkType":983},"6N9EmH6AaN6Hr4xk6ozATR",[],{"data":21253,"content":21254,"nodeType":876},{},[21255,21259,21268],{"data":21256,"marks":21257,"value":21258,"nodeType":867},{},[],"And because most anti-phishing controls are implemented via email, by using ",{"data":21260,"content":21262,"nodeType":915},{"uri":21261},"https://pushsecurity.com/blog/why-attackers-are-moving-beyond-email-based-phishing?utm_source=thehackernews&utm_medium=sponsored-content&utm_term=article",[21263],{"data":21264,"marks":21265,"value":21267,"nodeType":867},{},[21266],{"type":913},"non-email delivery vectors, an entire layer of detection opportunity is cut out",{"data":21269,"marks":21270,"value":5704,"nodeType":867},{},[],{"data":21272,"content":21276,"nodeType":985},{"target":21273},{"sys":21274},{"id":21275,"type":982,"linkType":983},"1CWsZlLFX9TS53J1uamOG8",[],{"data":21278,"content":21279,"nodeType":876},{},[21280,21284,21292],{"data":21281,"marks":21282,"value":21283,"nodeType":867},{},[],"But even when they are sent via email, ClickFix pages, like other modern phishing sites, are using a range of ",{"data":21285,"content":21287,"nodeType":915},{"uri":21286},"https://pushsecurity.com/blog/phishing-detection-evasion-launch?utm_source=thehackernews&utm_medium=sponsored-content&utm_term=article",[21288],{"data":21289,"marks":21290,"value":12185,"nodeType":867},{},[21291],{"type":913},{"data":21293,"marks":21294,"value":21295,"nodeType":867},{},[]," that prevent them being flagged by security tools — from email scanners, to web-crawling security tools, to web proxies analyzing network traffic. Detection evasion mainly involves camouflaging and rotating domains to stay ahead of known-bad detections (i.e. blocklists), using bot protection to prevent analysis, and heavily obfuscating page content to stop detection signatures firing. ",{"data":21297,"content":21298,"nodeType":876},{},[21299],{"data":21300,"marks":21301,"value":21302,"nodeType":867},{},[],"Finally, because the code is copied inside the browser sandbox, typical security tools are unable to observe and flag this action as potentially malicious. This means that the last — and only — opportunity for organizations to stop ClickFix is on the endpoint, after the user has attempted to run the malicious code.",{"data":21304,"content":21308,"nodeType":985},{"target":21305},{"sys":21306},{"id":21307,"type":982,"linkType":983},"3HiqpIBWWMr5FMi3IBzXcc",[],{"data":21310,"content":21311,"nodeType":942},{},[],{"data":21313,"content":21314,"nodeType":868},{},[21315],{"data":21316,"marks":21317,"value":21319,"nodeType":867},{},[21318],{"type":865},"How ClickFix payloads are evolving",{"data":21321,"content":21322,"nodeType":876},{},[21323],{"data":21324,"marks":21325,"value":21326,"nodeType":867},{},[],"It’s not just the ClickFix page and delivery mechanisms that are evolving — the services where code is being run, and the type of payload, are also increasingly varied. ",{"data":21328,"content":21329,"nodeType":876},{},[21330,21334,21343],{"data":21331,"marks":21332,"value":21333,"nodeType":867},{},[],"While the main payloads observed by Push are mshta and PowerShell, ",{"data":21335,"content":21337,"nodeType":915},{"uri":21336},"https://mhaggis.github.io/ClickGrab/techniques.html",[21338],{"data":21339,"marks":21340,"value":21342,"nodeType":867},{},[21341],{"type":913},"attackers are abusing a wide range of LOLBINS",{"data":21344,"marks":21345,"value":21346,"nodeType":867},{},[]," targeting different services across Operating Systems.",{"data":21348,"content":21349,"nodeType":876},{},[21350],{"data":21351,"marks":21352,"value":21353,"nodeType":867},{},[],"While it is possible to disable the Win+R dialog box and limit the applications that can be run from the File Explorer address bar, it is not possible to similarly restrict users from interacting with other legitimate services to run malicious commands. ",{"data":21355,"content":21356,"nodeType":876},{},[21357,21361,21370],{"data":21358,"marks":21359,"value":21360,"nodeType":867},{},[],"Another recent example termed ",{"data":21362,"content":21364,"nodeType":915},{"uri":21363},"https://expel.com/blog/cache-smuggling-when-a-picture-isnt-a-thousand-words/",[21365],{"data":21366,"marks":21367,"value":21369,"nodeType":867},{},[21368],{"type":913},"cache smuggling",{"data":21371,"marks":21372,"value":21373,"nodeType":867},{},[]," was also identified by security researchers. This technique combines a ClickFix approach with JavaScript that caches a malicious file posing as a JPG. This means that the ClickFix command executes locally — effectively getting an entire zip file onto the local system without the PowerShell command needing to make any web requests.",{"data":21375,"content":21376,"nodeType":876},{},[21377],{"data":21378,"marks":21379,"value":21380,"nodeType":867},{},[],"Finally, it’s worth considering the future of ClickFix. The current attack path straddles browser and endpoint — what if it could take place entirely in the browser and evade EDR altogether? ",{"data":21382,"content":21386,"nodeType":985},{"target":21383},{"sys":21384},{"id":21385,"type":982,"linkType":983},"2rUDKawJnrmZVtxfNcSNha",[],{"data":21388,"content":21389,"nodeType":942},{},[],{"data":21391,"content":21392,"nodeType":868},{},[21393],{"data":21394,"marks":21395,"value":21397,"nodeType":867},{},[21396],{"type":865},"What’s the impact of ClickFix evolution?",{"data":21399,"content":21400,"nodeType":876},{},[21401],{"data":21402,"marks":21403,"value":21404,"nodeType":867},{},[],"To summarize:",{"data":21406,"content":21407,"nodeType":1629},{},[21408,21418,21428],{"data":21409,"content":21410,"nodeType":1586},{},[21411],{"data":21412,"content":21413,"nodeType":876},{},[21414],{"data":21415,"marks":21416,"value":21417,"nodeType":867},{},[],"ClickFix pages are becoming increasingly sophisticated, making it more likely that victims will fall for the social engineering.",{"data":21419,"content":21420,"nodeType":1586},{},[21421],{"data":21422,"content":21423,"nodeType":876},{},[21424],{"data":21425,"marks":21426,"value":21427,"nodeType":867},{},[],"ClickFix delivery is evading traditional monitoring controls at the email layer to reach victims. ",{"data":21429,"content":21430,"nodeType":1586},{},[21431],{"data":21432,"content":21433,"nodeType":876},{},[21434],{"data":21435,"marks":21436,"value":21437,"nodeType":867},{},[],"ClickFix payloads are becoming more varied and are finding new ways to evade security controls. ",{"data":21439,"content":21440,"nodeType":876},{},[21441],{"data":21442,"marks":21443,"value":21444,"nodeType":867},{},[],"This means that EDR-based interception of malware execution is the last — and only — real line of defense for most organizations, kicking in after the initial script has been run (typically acting as a stager for the real malware). ",{"data":21446,"content":21447,"nodeType":876},{},[21448],{"data":21449,"marks":21450,"value":21451,"nodeType":867},{},[],"Malware execution can and should be intercepted by EDR, but it’s not foolproof. ",{"data":21453,"content":21454,"nodeType":1629},{},[21455,21478,21488],{"data":21456,"content":21457,"nodeType":1586},{},[21458],{"data":21459,"content":21460,"nodeType":876},{},[21461,21465,21474],{"data":21462,"marks":21463,"value":21464,"nodeType":867},{},[],"Attackers are constantly ",{"data":21466,"content":21468,"nodeType":915},{"uri":21467},"https://www.infostealers.com/article/logins-zip-leverages-chromium-zero-day-stealthy-infostealer-builder-promises-99-credential-theft-in-under-12-seconds/",[21469],{"data":21470,"marks":21471,"value":21473,"nodeType":867},{},[21472],{"type":913},"developing new tools and capabilities",{"data":21475,"marks":21476,"value":21477,"nodeType":867},{},[]," to bypass EDR in the cat-and-mouse game between attackers and defenders.",{"data":21479,"content":21480,"nodeType":1586},{},[21481],{"data":21482,"content":21483,"nodeType":876},{},[21484],{"data":21485,"marks":21486,"value":21487,"nodeType":867},{},[],"Because ClickFix attacks are user initiated, context might be missing that lead to the alert being misclassified. This can mean the difference between the level of priority alert that is raised, and whether or not it is automatically blocked.",{"data":21489,"content":21490,"nodeType":1586},{},[21491],{"data":21492,"content":21493,"nodeType":876},{},[21494],{"data":21495,"marks":21496,"value":21497,"nodeType":867},{},[],"If you’re an organization that allows employees and contractors to use unmanaged BYOD devices, there’s a strong chance that there are gaps in your EDR coverage.",{"data":21499,"content":21500,"nodeType":876},{},[21501,21505,21513],{"data":21502,"marks":21503,"value":21504,"nodeType":867},{},[],"This is why attackers are doubling down. According to the ",{"data":21506,"content":21508,"nodeType":915},{"uri":21507},"https://cdn-dynmedia-1.microsoft.com/is/content/microsoftcorp/microsoft/msc/documents/presentations/CSR/Microsoft-Digital-Defense-Report-2025.pdf#page=1",[21509],{"data":21510,"marks":21511,"value":21512,"nodeType":867},{},[],"2025 Microsoft Digital Defense report",{"data":21514,"marks":21515,"value":21516,"nodeType":867},{},[],", ClickFix was the most common initial access method in the last year, accounting for 47% of attacks. That's a pretty significant stat.",{"data":21518,"content":21519,"nodeType":3804},{},[21520],{"data":21521,"content":21522,"nodeType":876},{},[21523],{"data":21524,"marks":21525,"value":21526,"nodeType":867},{},[],"47% of attacks started with ClickFix in the last year, according to Microsoft.",{"data":21528,"content":21529,"nodeType":876},{},[21530],{"data":21531,"marks":21532,"value":21533,"nodeType":867},{},[],"Ultimately, organizations are leaving themselves relying on a single line of defense — if the attack isn’t detected and blocked by EDR, it isn’t spotted at all. ",{"data":21535,"content":21536,"nodeType":942},{},[],{"data":21538,"content":21539,"nodeType":868},{},[21540],{"data":21541,"marks":21542,"value":21544,"nodeType":867},{},[21543],{"type":865},"Don’t gamble on a single point of failure ",{"data":21546,"content":21547,"nodeType":876},{},[21548,21552,21561],{"data":21549,"marks":21550,"value":21551,"nodeType":867},{},[],"Push Security’s latest feature, ",{"data":21553,"content":21555,"nodeType":915},{"uri":21554},"https://pushsecurity.com/blog/introducing-malicious-copy-paste-detection?utm_source=thehackernews&utm_medium=sponsored-content&utm_term=article",[21556],{"data":21557,"marks":21558,"value":21560,"nodeType":867},{},[21559],{"type":913},"malicious copy and paste detection",{"data":21562,"marks":21563,"value":21564,"nodeType":867},{},[],", tackles ClickFix-style attacks at the earliest opportunity through browser-based detection and blocking. This is a universally effective control that works regardless of the lure delivery channel, page style and structure, or the specifics of the malware type and execution.",{"data":21566,"content":21567,"nodeType":876},{},[21568],{"data":21569,"marks":21570,"value":21571,"nodeType":867},{},[],"Unlike heavy-handed DLP solutions that block copy-paste altogether, Push protects your employees without disrupting their user experience or hampering productivity.",{"data":21573,"content":21574,"nodeType":876},{},[21575],{"data":21576,"marks":21577,"value":21578,"nodeType":867},{},[],"By adding a new layer of protection in the browser, security teams can reduce the strain on their EDR and reduce the risk of host-based controls being bypassed through misconfiguration or attacker innovation. ",{"data":21580,"content":21584,"nodeType":985},{"target":21581},{"sys":21582},{"id":21583,"type":982,"linkType":983},"sALkMt8UbTZ2f34hKvGLj",[],{"data":21586,"content":21587,"nodeType":942},{},[],{"data":21589,"content":21590,"nodeType":868},{},[21591],{"data":21592,"marks":21593,"value":18329,"nodeType":867},{},[21594],{"type":865},{"data":21596,"content":21597,"nodeType":876},{},[21598,21602,21611],{"data":21599,"marks":21600,"value":21601,"nodeType":867},{},[],"If you want to learn more about ClickFix attacks and how they’re evolving, ",{"data":21603,"content":21605,"nodeType":915},{"uri":21604},"https://pushsecurity.com/resources/clickfix",[21606],{"data":21607,"marks":21608,"value":21610,"nodeType":867},{},[21609],{"type":913},"check out our latest webinar (now available on-demand!)",{"data":21612,"marks":21613,"value":21614,"nodeType":867},{},[]," where we dive into real-world ClickFix examples and demonstrate how ClickFix sites work under the hood. ",{"data":21616,"content":21617,"nodeType":876},{},[21618,21621,21628,21632,21639],{"data":21619,"marks":21620,"value":14690,"nodeType":867},{},[],{"data":21622,"content":21623,"nodeType":915},{"uri":14693},[21624],{"data":21625,"marks":21626,"value":14699,"nodeType":867},{},[21627],{"type":913},{"data":21629,"marks":21630,"value":21631,"nodeType":867},{},[]," or ",{"data":21633,"content":21634,"nodeType":915},{"uri":2689},[21635],{"data":21636,"marks":21637,"value":14723,"nodeType":867},{},[21638],{"type":913},{"data":21640,"marks":21641,"value":1679,"nodeType":867},{},[],{"data":21643,"content":21646,"nodeType":985},{"target":21644},{"sys":21645},{"id":21200,"type":982,"linkType":983},[],{"data":21648,"content":21649,"nodeType":876},{},[21650],{"data":21651,"marks":21652,"value":21,"nodeType":867},{},[],{"entries":21654},{"hyperlink":21655,"inline":21656,"block":21657},[],[],[21658,21663,21669,21673,21696,21703,21717,21724],{"sys":21659,"__typename":21660,"title":21069,"arcadeDemoUrl":21661,"playText":21662},{"id":21110},"ArcadeDemo","https://demo.arcade.software/yQIHbuD990Dk5CjI1cvS?embed","1 mins",{"sys":21664,"__typename":1688,"title":21665,"caption":21665,"layoutMode":59,"file":21666},{"id":21141},"The most advanced ClickFix page we’ve seen — complete with an embedded video showing the victim how to complete the check.",{"url":21667,"width":1693,"height":21668},"https://images.ctfassets.net/y1cdw1ablpvd/ImveC0bIdp4QxXqHyQKz9/526f7ae589f71d0c23c7c738b8d0bc90/image3.png",1117,{"sys":21670,"__typename":1697,"type":1698,"ctaText":21671,"buttonLabel":21672,"buttonColour":1701,"buttonUrl":21604},{"id":21200},"Check out our latest webinar for a deep dive into the evolution of ClickFix-style attacks, with real-world examples from investigations.","Watch On-demand",{"sys":21674,"__typename":1705,"content":21675,"name":21695,"title":59},{"id":21250},{"json":21676},{"data":21677,"content":21678,"nodeType":1680},{},[21679],{"data":21680,"content":21681,"nodeType":876},{},[21682,21686,21691],{"data":21683,"marks":21684,"value":21685,"nodeType":867},{},[],"Of the ClickFix pages intercepted by Push where the delivery vector was observed, ",{"data":21687,"marks":21688,"value":21690,"nodeType":867},{},[21689],{"type":865},"4 in 5 were accessed via Google Search.",{"data":21692,"marks":21693,"value":21694,"nodeType":867},{},[]," While other examples may have been stopped by controls such as email before the page could be loaded by the user, this shows a significant monitoring gap when it comes to non-email delivery vectors.","ClickFix blog insight box 2",{"sys":21697,"__typename":1688,"title":21698,"caption":21698,"layoutMode":59,"file":21699},{"id":21275},"Like other modern phishing attacks, ClickFix lures are distributed all over the internet — not just email.",{"url":21700,"width":21701,"height":21702},"https://images.ctfassets.net/y1cdw1ablpvd/4l0xLRs8Z1w3aXMbzzyFPL/9cb4721c53379da31a4019371072a7ef/image1.png",1696,986,{"sys":21704,"__typename":1705,"content":21705,"name":21716,"title":59},{"id":21307},{"json":21706},{"data":21707,"content":21708,"nodeType":1680},{},[21709],{"data":21710,"content":21711,"nodeType":876},{},[21712],{"data":21713,"marks":21714,"value":21715,"nodeType":867},{},[],"Although there are ways to block web pages from performing copy to clipboard via device settings or group policy, the practical reality of ClickFix means that these methods are not effective. Because ClickFix is a user gesture initiated paste event (some form of user interaction such as a button press is required on the page before loading the ClickFix lure) it cannot be blocked from the host.","ClickFix insight box 1",{"sys":21718,"__typename":1688,"title":21719,"caption":21719,"layoutMode":59,"file":21720},{"id":21385},"The current hybrid attack path sees the attacker deliver lures in the browser, to compromise the endpoint, to get access to creds and cookies stored in the browser. What if you could skip the endpoint altogether? ",{"url":21721,"width":21722,"height":21723},"https://images.ctfassets.net/y1cdw1ablpvd/7kIZUmQkiHKKX0kjZQYfia/a7957baa43f54fe407779e845240e27e/image2.png",1970,816,{"sys":21725,"__typename":21660,"title":21726,"arcadeDemoUrl":21727,"playText":21728},{"id":21583},"ClickFix Feature Release","https://demo.arcade.software/qhzGMAx2q3b6IRlHqBsB?embed","2 mins",{"items":21730},[],{},"Analyzing sophisticated ClickFix lures seen in the wild","threat-research","2025-11-06T00:00:00.000Z",{"items":21736},[21737,22313,22949],{"__typename":1772,"sys":21738,"content":21740,"title":22299,"synopsis":22300,"hashTags":59,"publishedDate":22301,"slug":22302,"tagsCollection":22303,"authorsCollection":22309},{"id":21739},"4wtqKNN8D4tvbICAQ17L1Z",{"json":21741},{"data":21742,"content":21743,"nodeType":1680},{},[21744,21752,21759,21766,21773,21779,21782,21790,21797,21804,21820,21864,21870,21877,21893,21900,21906,21909,21917,21924,21940,21959,21979,21999,22006,22009,22017,22036,22069,22075,22081,22084,22092,22111,22131,22138,22157,22163,22169,22172,22180,22187,22194,22227,22234,22237,22245,22252,22259,22266,22273],{"data":21745,"content":21746,"nodeType":868},{},[21747],{"data":21748,"marks":21749,"value":21751,"nodeType":867},{},[21750],{"type":865},"Phishing has moved outside of the mailbox",{"data":21753,"content":21754,"nodeType":876},{},[21755],{"data":21756,"marks":21757,"value":21758,"nodeType":867},{},[],"Because of the changes to working practices, employees are more accessible than ever to external attackers. Once upon a time, email was the primary communication channel with the wider world, and work happened locally — on your device, and inside your locked-down network environment. This made email and the endpoint the highest priority from a security perspective. ",{"data":21760,"content":21761,"nodeType":876},{},[21762],{"data":21763,"marks":21764,"value":21765,"nodeType":867},{},[],"But now, with modern work happening across a network of decentralized internet apps, and more varied communication channels outside of email, it’s harder to stop users from interacting with malicious content.",{"data":21767,"content":21768,"nodeType":876},{},[21769],{"data":21770,"marks":21771,"value":21772,"nodeType":867},{},[],"Attackers can deliver links over instant messenger apps, social media, SMS, malicious ads, and using in-app messenger functionality, as well as sending emails directly from SaaS services to bypass email-based checks. Likewise, there are now hundreds of apps per enterprise to target, with varying levels of account security configuration.",{"data":21774,"content":21778,"nodeType":985},{"target":21775},{"sys":21776},{"id":21777,"type":982,"linkType":983},"1tDciIJqKnNoR4FqZChjTy",[],{"data":21780,"content":21781,"nodeType":942},{},[],{"data":21783,"content":21784,"nodeType":868},{},[21785],{"data":21786,"marks":21787,"value":21789,"nodeType":867},{},[21788],{"type":865},"Why am I not hearing about this more? ",{"data":21791,"content":21792,"nodeType":876},{},[21793],{"data":21794,"marks":21795,"value":21796,"nodeType":867},{},[],"Phishing attacks outside of email usually go unreported. This is to be expected when most of the industry’s data on phishing attacks comes from email security vendors and tools. ",{"data":21798,"content":21799,"nodeType":876},{},[21800],{"data":21801,"marks":21802,"value":21803,"nodeType":867},{},[],"If phishing bypasses the email layer, most organizations are left relying on user reported attacks. Some organizations might supplement this with a web proxy, but these are being increasingly defeated by modern phishing kits, which use an array of obfuscation and detection evasion techniques to bypass these detections. ",{"data":21805,"content":21806,"nodeType":876},{},[21807,21811,21816],{"data":21808,"marks":21809,"value":21810,"nodeType":867},{},[],"The most valuable information for security teams today is the webpage that is loaded ",{"data":21812,"marks":21813,"value":21815,"nodeType":867},{},[21814],{"type":1303},"through",{"data":21817,"marks":21818,"value":21819,"nodeType":867},{},[]," the network traffic: What does the HTML body look like? What is the user likely seeing on the page? To do this, you need to stitch together and reconstruct what the browser is doing by looking at the network data. Except for very simple websites, this happens through JavaScript on the client side. ",{"data":21821,"content":21822,"nodeType":876},{},[21823,21827,21836,21839,21848,21851,21860],{"data":21824,"marks":21825,"value":21826,"nodeType":867},{},[],"This is hard enough when analysing a typical SaaS app. But the latest generation of fully customized Attacker-in-the-Middle (AitM) phishing kits are going out of their way to make this as challenging as possible, using techniques like ",{"data":21828,"content":21830,"nodeType":915},{"uri":21829},"https://phishing-techniques.pushsecurity.com/techniques/dom-obfuscation/",[21831],{"data":21832,"marks":21833,"value":21835,"nodeType":867},{},[21834],{"type":913},"DOM obfuscation",{"data":21837,"marks":21838,"value":5136,"nodeType":867},{},[],{"data":21840,"content":21842,"nodeType":915},{"uri":21841},"https://phishing-techniques.pushsecurity.com/techniques/page-obfuscation/",[21843],{"data":21844,"marks":21845,"value":21847,"nodeType":867},{},[21846],{"type":913},"Page obfuscation",{"data":21849,"marks":21850,"value":5147,"nodeType":867},{},[],{"data":21852,"content":21854,"nodeType":915},{"uri":21853},"https://phishing-techniques.pushsecurity.com/techniques/code-obfuscation/",[21855],{"data":21856,"marks":21857,"value":21859,"nodeType":867},{},[21858],{"type":913},"Code obfuscation",{"data":21861,"marks":21862,"value":21863,"nodeType":867},{},[]," so all you see at a network layer is a garbled, obfuscated mess of JS code.",{"data":21865,"content":21869,"nodeType":985},{"target":21866},{"sys":21867},{"id":21868,"type":982,"linkType":983},"71QsaPju68i5QiJcgQlHDs",[],{"data":21871,"content":21872,"nodeType":876},{},[21873],{"data":21874,"marks":21875,"value":21876,"nodeType":867},{},[],"So, non-email phishing is going broadly undetected through technical controls. And even when spotted and reported by a user — what can you really do about it?",{"data":21878,"content":21879,"nodeType":876},{},[21880,21884,21889],{"data":21881,"marks":21882,"value":21883,"nodeType":867},{},[],"Take a social media phish. You can’t see which other accounts were targeted or hit in your user base. Unlike email, there’s no way to recall or quarantine the same message hitting multiple users. There’s no rule you can modify, or senders you can block. You can report the account, and ",{"data":21885,"marks":21886,"value":21888,"nodeType":867},{},[21887],{"type":1303},"maybe",{"data":21890,"marks":21891,"value":21892,"nodeType":867},{},[]," something will happen when the site owner gets around to it — but the attacker has probably got what they needed by then and moved on. ",{"data":21894,"content":21895,"nodeType":876},{},[21896],{"data":21897,"marks":21898,"value":21899,"nodeType":867},{},[],"Most organizations simply block the URLs involved. But this doesn’t really help when attackers are rapidly rotating their phishing domains — by the time you block one site, another three have already taken its place. ",{"data":21901,"content":21905,"nodeType":985},{"target":21902},{"sys":21903},{"id":21904,"type":982,"linkType":983},"1II2kHyOZcShLsexx1TAgy",[],{"data":21907,"content":21908,"nodeType":942},{},[],{"data":21910,"content":21911,"nodeType":868},{},[21912],{"data":21913,"marks":21914,"value":21916,"nodeType":867},{},[21915],{"type":865},"But aren’t these just personal accounts?",{"data":21918,"content":21919,"nodeType":876},{},[21920],{"data":21921,"marks":21922,"value":21923,"nodeType":867},{},[],"Modern phishing attacks blur the boundary between corporate and personal. The fact is that your employees are routinely accessing personal messaging and social media apps on their corporate devices. Users are signed into apps like LinkedIn, X, WhatsApp, Signal, even message boards like Reddit on their work laptop and/or mobile devices. And with malicious links being found on search engines (aka. malvertising), they can even stumble upon them while browsing the web normally.",{"data":21925,"content":21926,"nodeType":876},{},[21927,21931,21936],{"data":21928,"marks":21929,"value":21930,"nodeType":867},{},[],"In short: anywhere that your users can be contacted by someone outside of your organization presents an opportunity for phishing. In fact, in most of these cases people ",{"data":21932,"marks":21933,"value":21935,"nodeType":867},{},[21934],{"type":865},"expect ",{"data":21937,"marks":21938,"value":21939,"nodeType":867},{},[],"to be contacted by people they don’t know. ",{"data":21941,"content":21942,"nodeType":876},{},[21943,21947,21955],{"data":21944,"marks":21945,"value":21946,"nodeType":867},{},[],"It’s also a myth that campaigns can’t be targeted in the same way on these platforms, that they’re somehow more random and therefore less dangerous. For example, social media accounts are some of the easiest for attackers to create en masse — or take over. According to the most recent ",{"data":21948,"content":21950,"nodeType":915},{"uri":21949},"https://www.verizon.com/business/resources/T149/reports/2025-dbir-data-breach-investigations-report.pdf",[21951],{"data":21952,"marks":21953,"value":2183,"nodeType":867},{},[21954],{"type":913},{"data":21956,"marks":21957,"value":21958,"nodeType":867},{},[],", 60%+ of creds found in infostealer logs were from social media sites. They’re also likely to use single-factor logins. If an attacker can take over one account, and use it to credibly communicate with one of your employees, they have a way higher likelihood of being successful than with your average unsolicited email. ",{"data":21960,"content":21961,"nodeType":876},{},[21962,21966,21975],{"data":21963,"marks":21964,"value":21965,"nodeType":867},{},[],"Malicious ads can also be targeted. For example, Google Ads can be targeted to searches coming from specific geographic locations, tailored to specific email domain matches, or specific device types (e.g. desktop, mobile, etc.). If you know where your target organization is located, you can tailor the ad to that location. Phishing sites also often come with ",{"data":21967,"content":21969,"nodeType":915},{"uri":21968},"https://phishing-techniques.pushsecurity.com/techniques/conditional-loading/",[21970],{"data":21971,"marks":21972,"value":21974,"nodeType":867},{},[21973],{"type":913},"conditional loading",{"data":21976,"marks":21977,"value":21978,"nodeType":867},{},[]," parameters to only deliver the malicious payload under specific conditions — for example, only if the visitor came from a particular email campaign link, or only if they are in a certain organization, using a certain browser, from a specific IP range, etc. ",{"data":21980,"content":21981,"nodeType":876},{},[21982,21986,21995],{"data":21983,"marks":21984,"value":21985,"nodeType":867},{},[],"And even if the attacker only manages to reach your employee on their personal device, this can still be laundered into a corporate account compromise. Just look at the ",{"data":21987,"content":21989,"nodeType":915},{"uri":21988},"https://sec.okta.com/articles/2023/11/unauthorized-access-oktas-support-case-management-system-root-cause",[21990],{"data":21991,"marks":21992,"value":21994,"nodeType":867},{},[21993],{"type":913},"2023 Okta breach",{"data":21996,"marks":21997,"value":21998,"nodeType":867},{},[],", where an attacker exploited the fact that an Okta employee had signed into a personal Google profile on their work device. This meant any credentials saved in their browser were synced to their personal device — including a customer support system service account providing access to 134 customer tenants. When their personal device got hacked, so too did all of their work credentials.",{"data":22000,"content":22001,"nodeType":876},{},[22002],{"data":22003,"marks":22004,"value":22005,"nodeType":867},{},[],"So, there’s plenty of scope for non-email phishing to result in targeted phishing campaigns. If anything, it’s arguably less work for the attacker to spin up these non-email campaigns than it is to do the necessary legwork to create and build up email sender reputation!",{"data":22007,"content":22008,"nodeType":942},{},[],{"data":22010,"content":22011,"nodeType":868},{},[22012],{"data":22013,"marks":22014,"value":22016,"nodeType":867},{},[22015],{"type":865},"Case study: LinkedIn spear-phishing",{"data":22018,"content":22019,"nodeType":876},{},[22020,22023,22032],{"data":22021,"marks":22022,"value":21,"nodeType":867},{},[],{"data":22024,"content":22026,"nodeType":915},{"uri":22025},"https://pushsecurity.com/blog/how-push-stopped-a-high-risk-linkedin-spear-phishing-attack/",[22027],{"data":22028,"marks":22029,"value":22031,"nodeType":867},{},[22030],{"type":913},"Attackers recently ran a LinkedIn spear-phishing campaign targeting tech company execs.",{"data":22033,"marks":22034,"value":22035,"nodeType":867},{},[]," The victims were targeted via LinkedIn direct message from another exec about a fake investment opportunity. The sender’s account had been compromised and used to approach high-value targets. ",{"data":22037,"content":22038,"nodeType":876},{},[22039,22043,22052,22056,22065],{"data":22040,"marks":22041,"value":22042,"nodeType":867},{},[],"The attack led the victim through a chain of custom pages hosted on ",{"data":22044,"content":22046,"nodeType":915},{"uri":22045},"https://phishing-techniques.pushsecurity.com/techniques/trusted-website-hosting/",[22047],{"data":22048,"marks":22049,"value":22051,"nodeType":867},{},[22050],{"type":913},"legitimate sites",{"data":22053,"marks":22054,"value":22055,"nodeType":867},{},[]," (a well-known ",{"data":22057,"content":22059,"nodeType":915},{"uri":22058},"https://pushsecurity.com/resources/phishing-evolution?",[22060],{"data":22061,"marks":22062,"value":22064,"nodeType":867},{},[22063],{"type":913},"detection evasion technique",{"data":22066,"marks":22067,"value":22068,"nodeType":867},{},[],") such as Google Sites, Google Search, and Microsoft Dynamics, before serving up an Attacker-in-the-Middle phishing page impersonating Google Workspace, before serving up a session-stealing AitM phishing page. ",{"data":22070,"content":22074,"nodeType":985},{"target":22071},{"sys":22072},{"id":22073,"type":982,"linkType":983},"1cEvEzLdKIuj6zuGn9aWJB",[],{"data":22076,"content":22080,"nodeType":985},{"target":22077},{"sys":22078},{"id":22079,"type":982,"linkType":983},"6LfBXkDKqh1ogCMxaxyV6x",[],{"data":22082,"content":22083,"nodeType":942},{},[],{"data":22085,"content":22086,"nodeType":868},{},[22087],{"data":22088,"marks":22089,"value":22091,"nodeType":867},{},[22090],{"type":865},"Case study: Google Search malvertising",{"data":22093,"content":22094,"nodeType":876},{},[22095,22098,22107],{"data":22096,"marks":22097,"value":21,"nodeType":867},{},[],{"data":22099,"content":22101,"nodeType":915},{"uri":22100},"https://pushsecurity.com/blog/investigating-a-recent-malvertising-campaign-targeting-onfido-customers/",[22102],{"data":22103,"marks":22104,"value":22106,"nodeType":867},{},[22105],{"type":913},"A company was hit with a targeted Google ad",{"data":22108,"marks":22109,"value":22110,"nodeType":867},{},[]," which was designed to look highly convincing, and positioned above the legitimate ad. This took advantage of the fact that many users will search for login pages rather than accessing the site via bookmark. ",{"data":22112,"content":22113,"nodeType":876},{},[22114,22118,22127],{"data":22115,"marks":22116,"value":22117,"nodeType":867},{},[],"In this case, the attacker had made use of a ",{"data":22119,"content":22121,"nodeType":915},{"uri":22120},"https://phishing-techniques.pushsecurity.com/techniques/rentable-subdomains/",[22122],{"data":22123,"marks":22124,"value":22126,"nodeType":867},{},[22125],{"type":913},"rentable subdomain",{"data":22128,"marks":22129,"value":22130,"nodeType":867},{},[]," (us[.]com) to make the link appear highly legitimate, with only small changes to the real URL that were easy to miss. ",{"data":22132,"content":22133,"nodeType":876},{},[22134],{"data":22135,"marks":22136,"value":22137,"nodeType":867},{},[],"Instead of the real login, the link took the victim to a session-stealing AITM page.  ",{"data":22139,"content":22140,"nodeType":876},{},[22141,22145,22153],{"data":22142,"marks":22143,"value":22144,"nodeType":867},{},[],"This was later traced back to a ",{"data":22146,"content":22148,"nodeType":915},{"uri":22147},"https://pushsecurity.com/blog/scattered-spider-ttp-evolution-in-2025/",[22149],{"data":22150,"marks":22151,"value":1182,"nodeType":867},{},[22152],{"type":913},{"data":22154,"marks":22155,"value":22156,"nodeType":867},{},[]," campaign.",{"data":22158,"content":22162,"nodeType":985},{"target":22159},{"sys":22160},{"id":22161,"type":982,"linkType":983},"5o1LEkZfeYVjMZmROi3Yh",[],{"data":22164,"content":22168,"nodeType":985},{"target":22165},{"sys":22166},{"id":22167,"type":982,"linkType":983},"4RAXFNPdvUXjMDUE7tc10a",[],{"data":22170,"content":22171,"nodeType":942},{},[],{"data":22173,"content":22174,"nodeType":868},{},[22175],{"data":22176,"marks":22177,"value":22179,"nodeType":867},{},[22178],{"type":865},"What can an attacker do with a compromised account? ",{"data":22181,"content":22182,"nodeType":876},{},[22183],{"data":22184,"marks":22185,"value":22186,"nodeType":867},{},[],"It’s important to think about the bigger picture when it comes to a modern phishing compromise. ",{"data":22188,"content":22189,"nodeType":876},{},[22190],{"data":22191,"marks":22192,"value":22193,"nodeType":867},{},[],"Most phishing attacks focus on core enterprise cloud platforms such as Microsoft and Google, or specialist Identity Providers like Okta. Taking over one of these accounts doesn’t just give access to the core apps and data within the respective app, but also enables the attacker to leverage SSO to sign into any connected app that the employee logs into with their account. ",{"data":22195,"content":22196,"nodeType":876},{},[22197,22201,22210,22214,22223],{"data":22198,"marks":22199,"value":22200,"nodeType":867},{},[],"This gives an attacker access to just about every core business function and dataset in your organization. And from this point, it’s much easier to target other users of these internal apps — using internal messenger apps like ",{"data":22202,"content":22204,"nodeType":915},{"uri":22203},"https://pushsecurity.com/blog/phishing-slack-persistence/",[22205],{"data":22206,"marks":22207,"value":22209,"nodeType":867},{},[22208],{"type":913},"Slack or Teams",{"data":22211,"marks":22212,"value":22213,"nodeType":867},{},[],", or techniques like ",{"data":22215,"content":22217,"nodeType":915},{"uri":22216},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/samljacking/description.md",[22218],{"data":22219,"marks":22220,"value":22222,"nodeType":867},{},[22221],{"type":913},"SAMLjacking",{"data":22224,"marks":22225,"value":22226,"nodeType":867},{},[]," to turn an app into a watering hole for other users trying to log in. ",{"data":22228,"content":22229,"nodeType":876},{},[22230],{"data":22231,"marks":22232,"value":22233,"nodeType":867},{},[],"A single account compromise can quickly snowball into a multi-million dollar, business-wide breach.",{"data":22235,"content":22236,"nodeType":942},{},[],{"data":22238,"content":22239,"nodeType":868},{},[22240],{"data":22241,"marks":22242,"value":22244,"nodeType":867},{},[22243],{"type":865},"What can organizations do about non-email phishing? ",{"data":22246,"content":22247,"nodeType":876},{},[22248],{"data":22249,"marks":22250,"value":22251,"nodeType":867},{},[],"It’s clear that the traditional anti-phishing toolset hasn’t kept up with phishing innovation. ",{"data":22253,"content":22254,"nodeType":876},{},[22255],{"data":22256,"marks":22257,"value":22258,"nodeType":867},{},[],"To tackle modern phishing attacks, organizations need a solution that detects and blocks phishing across all apps and delivery vectors. ",{"data":22260,"content":22261,"nodeType":876},{},[22262],{"data":22263,"marks":22264,"value":22265,"nodeType":867},{},[],"Push Security doesn’t detect the redirect tricks, or rely on outdated domain TI feeds. It doesn’t matter what delivery channel or camouflage methods are used, Push detects and blocks attacks by identifying the attack in real time, as the user loads and interacts with the page in their web browser.",{"data":22267,"content":22268,"nodeType":876},{},[22269],{"data":22270,"marks":22271,"value":22272,"nodeType":867},{},[],"Push’s browser-based security platform provides comprehensive identity attack detection and response capabilities against techniques like AiTM phishing, credential stuffing, ClickFixing, malicious browser extensions, and session hijacking using stolen session tokens. ",{"data":22274,"content":22275,"nodeType":876},{},[22276,22279,22286,22289,22296],{"data":22277,"marks":22278,"value":14690,"nodeType":867},{},[],{"data":22280,"content":22281,"nodeType":915},{"uri":14693},[22282],{"data":22283,"marks":22284,"value":14699,"nodeType":867},{},[22285],{"type":913},{"data":22287,"marks":22288,"value":21631,"nodeType":867},{},[],{"data":22290,"content":22291,"nodeType":915},{"uri":2689},[22292],{"data":22293,"marks":22294,"value":14723,"nodeType":867},{},[22295],{"type":913},{"data":22297,"marks":22298,"value":1679,"nodeType":867},{},[],"Why attackers are moving beyond email-based phishing","Why phishing attacks are moving away from exclusively email-based delivery, and what this means for security teams. \n","2025-09-18T00:00:00.000Z","why-attackers-are-moving-beyond-email-based-phishing",{"items":22304},[22305,22307],{"sys":22306,"name":4018},{"id":4017},{"sys":22308,"name":342},{"id":3240},{"items":22310},[22311],{"fullName":4022,"firstName":4023,"jobTitle":4024,"profilePicture":22312},{"url":4026},{"__typename":1772,"sys":22314,"content":22316,"title":22935,"synopsis":22936,"hashTags":59,"publishedDate":22937,"slug":22938,"tagsCollection":22939,"authorsCollection":22945},{"id":22315},"1u8RJxC00HbBhCBVxcDnkK",{"json":22317},{"data":22318,"content":22319,"nodeType":1680},{},[22320,22365,22422,22437,22442,22449,22452,22460,22467,22474,22481,22501,22508,22514,22532,22538,22541,22549,22556,22564,22583,22590,22597,22604,22612,22619,22626,22632,22639,22672,22678,22686,22705,22712,22735,22742,22749,22755,22762,22765,22773,22787,22807,22814,22821,22828,22833,22841,22860,22863,22870,22877,22884,22891,22898,22924,22929],{"data":22321,"content":22322,"nodeType":876},{},[22323,22327,22335,22339,22348,22352,22361],{"data":22324,"marks":22325,"value":22326,"nodeType":867},{},[],"One of the biggest security trends in the past year has been the emergence of the attack technique known as ",{"data":22328,"content":22330,"nodeType":915},{"uri":22329},"https://www.microsoft.com/en-us/security/blog/2025/08/21/think-before-you-clickfix-analyzing-the-clickfix-social-engineering-technique/",[22331],{"data":22332,"marks":22333,"value":315,"nodeType":867},{},[22334],{"type":913},{"data":22336,"marks":22337,"value":22338,"nodeType":867},{},[],". Various reports indicate that ClickFix is fast becoming one of the most prevalent attack techniques this year, with ",{"data":22340,"content":22342,"nodeType":915},{"uri":22341},"https://www.scworld.com/news/clickfix-phishing-links-increased-nearly-400-in-12-months-report-says",[22343],{"data":22344,"marks":22345,"value":22347,"nodeType":867},{},[22346],{"type":913},"one study",{"data":22349,"marks":22350,"value":22351,"nodeType":867},{},[]," reporting that email-based ClickFix attacks have increased by 400% YOY, and ",{"data":22353,"content":22355,"nodeType":915},{"uri":22354},"https://web-assets.esetstatic.com/wls/en/papers/threat-reports/eset-threat-report-h12025.pdf",[22356],{"data":22357,"marks":22358,"value":22360,"nodeType":867},{},[22359],{"type":913},"another",{"data":22362,"marks":22363,"value":22364,"nodeType":867},{},[]," highlighting a 517% increase in the past 6 months. ",{"data":22366,"content":22367,"nodeType":876},{},[22368,22372,22381,22384,22393,22396,22405,22409,22418],{"data":22369,"marks":22370,"value":22371,"nodeType":867},{},[],"ClickFix is known to be regularly used by the Interlock ransomware group and other prolific threat actors. A number of recent public data breaches have been linked to ClickFix attacks as the attack vector, such as ",{"data":22373,"content":22375,"nodeType":915},{"uri":22374},"https://www.bleepingcomputer.com/news/security/kettering-health-confirms-interlock-ransomware-behind-cyberattack/",[22376],{"data":22377,"marks":22378,"value":22380,"nodeType":867},{},[22379],{"type":913},"Kettering Health",{"data":22382,"marks":22383,"value":5136,"nodeType":867},{},[],{"data":22385,"content":22387,"nodeType":915},{"uri":22386},"https://www.bleepingcomputer.com/news/security/interlock-ransomware-claims-davita-attack-leaks-stolen-data/",[22388],{"data":22389,"marks":22390,"value":22392,"nodeType":867},{},[22391],{"type":913},"DaVita",{"data":22394,"marks":22395,"value":5136,"nodeType":867},{},[],{"data":22397,"content":22399,"nodeType":915},{"uri":22398},"https://www.infosecurity-magazine.com/news/st-paul-mayor-interlock-data-leak/",[22400],{"data":22401,"marks":22402,"value":22404,"nodeType":867},{},[22403],{"type":913},"City of St. Paul, Minnesota",{"data":22406,"marks":22407,"value":22408,"nodeType":867},{},[],", and the ",{"data":22410,"content":22412,"nodeType":915},{"uri":22411},"https://www.blackfog.com/texas-tech-cyberattack-1-4m-records-compromised/",[22413],{"data":22414,"marks":22415,"value":22417,"nodeType":867},{},[22416],{"type":913},"Texas Tech University Health Sciences Centers",{"data":22419,"marks":22420,"value":22421,"nodeType":867},{},[]," (with many more breaches likely to involve ClickFix where the attack vector wasn’t known or disclosed).",{"data":22423,"content":22424,"nodeType":876},{},[22425,22429,22433],{"data":22426,"marks":22427,"value":22428,"nodeType":867},{},[],"Push’s latest feature, ",{"data":22430,"marks":22431,"value":21560,"nodeType":867},{},[22432],{"type":865},{"data":22434,"marks":22435,"value":22436,"nodeType":867},{},[],", tackles ClickFix-style attacks at the earliest opportunity through browser-based detection, with a universally effective control that works regardless of the lure delivery channel, or page style and structure. ",{"data":22438,"content":22441,"nodeType":985},{"target":22439},{"sys":22440},{"id":21583,"type":982,"linkType":983},[],{"data":22443,"content":22444,"nodeType":876},{},[22445],{"data":22446,"marks":22447,"value":22448,"nodeType":867},{},[],"Before we get into the specifics of the feature, let’s take a look at what ClickFix is and why it poses a detection and response challenge to security teams.",{"data":22450,"content":22451,"nodeType":942},{},[],{"data":22453,"content":22454,"nodeType":868},{},[22455],{"data":22456,"marks":22457,"value":22459,"nodeType":867},{},[22458],{"type":865},"ClickFix 101",{"data":22461,"content":22462,"nodeType":876},{},[22463],{"data":22464,"marks":22465,"value":22466,"nodeType":867},{},[],"ClickFix attacks prompt the user to solve some kind of problem or challenge in the browser — most commonly a CAPTCHA, but also things like fixing an error on a webpage. The name is a little misleading though — the key factor in the attack is that they trick users into running malicious commands on their device by copying malicious code from the page clipboard and running it locally. (For simplicity we’ll keep calling it ClickFix, but we’re not happy about it.)",{"data":22468,"content":22469,"nodeType":876},{},[22470],{"data":22471,"marks":22472,"value":22473,"nodeType":867},{},[],"The copy action is either performed manually by the user, or automatically by the page. Manual copies typically include additional social engineering to lure the victim into hitting CTRL+C, while automatic copies are performed using JavaScript running on the page. Most ClickFix pages we've seen are automatic copies, which makes sense — fewer steps means the user is more likely to follow the instruction.",{"data":22475,"content":22476,"nodeType":876},{},[22477],{"data":22478,"marks":22479,"value":22480,"nodeType":867},{},[],"Most commonly, these attacks are used to deliver remote access software or infostealer malware using stolen session cookies and credentials to facilitate attacks on business apps and services. From there, the attacker simply dumps the data and holds the victim to ransom for its deletion — often dropping ransomware afterwards for double the extortion. ",{"data":22482,"content":22483,"nodeType":876},{},[22484,22488,22497],{"data":22485,"marks":22486,"value":22487,"nodeType":867},{},[],"The attack gives the victim instructions that involve clicking prompts and copying, pasting, and running commands directly in the Windows Run dialog box, Terminal, or PowerShell in order to “fix” the fake problem that they’re experiencing. Variants such as ",{"data":22489,"content":22491,"nodeType":915},{"uri":22490},"https://mrd0x.com/filefix-clickfix-alternative/",[22492],{"data":22493,"marks":22494,"value":22496,"nodeType":867},{},[22495],{"type":913},"FileFix",{"data":22498,"marks":22499,"value":22500,"nodeType":867},{},[]," have also emerged which instead use the File Explorer Address Bar to execute OS commands.",{"data":22502,"content":22503,"nodeType":876},{},[22504],{"data":22505,"marks":22506,"value":22507,"nodeType":867},{},[],"Links to malicious ClickFix pages are distributed over various delivery channels, with attacks shifting from traditional email-based delivery to social media, instant messaging apps, malicious ads in places like Google Search, and using in-app notifications and messages across numerous SaaS services. ",{"data":22509,"content":22513,"nodeType":985},{"target":22510},{"sys":22511},{"id":22512,"type":982,"linkType":983},"1I9ERDY2tuspw5zVMV5DbY",[],{"data":22515,"content":22516,"nodeType":876},{},[22517,22521,22528],{"data":22518,"marks":22519,"value":22520,"nodeType":867},{},[],"ClickFix comes in a variety of lures, including impersonating CAPTCHA, Cloudflare Turnstile, simulating an error loading a webpage, and many more. They have also been observed targeting a ",{"data":22522,"content":22523,"nodeType":915},{"uri":21336},[22524],{"data":22525,"marks":22526,"value":22527,"nodeType":867},{},[],"wide range of services",{"data":22529,"marks":22530,"value":22531,"nodeType":867},{},[]," to execute code. ",{"data":22533,"content":22537,"nodeType":985},{"target":22534},{"sys":22535},{"id":22536,"type":982,"linkType":983},"1SG52ta1hcBZ3gYDsSJvsm",[],{"data":22539,"content":22540,"nodeType":942},{},[],{"data":22542,"content":22543,"nodeType":868},{},[22544],{"data":22545,"marks":22546,"value":22548,"nodeType":867},{},[22547],{"type":865},"Why are ClickFix attacks so effective?",{"data":22550,"content":22551,"nodeType":876},{},[22552],{"data":22553,"marks":22554,"value":22555,"nodeType":867},{},[],"To understand the effectiveness of ClickFix-style attacks, we need to look more closely at the mechanisms that security teams have at their disposal to counter these attacks. ",{"data":22557,"content":22558,"nodeType":1058},{},[22559],{"data":22560,"marks":22561,"value":22563,"nodeType":867},{},[22562],{"type":865},"Detection challenges during delivery",{"data":22565,"content":22566,"nodeType":876},{},[22567,22571,22579],{"data":22568,"marks":22569,"value":22570,"nodeType":867},{},[],"We’ve written extensively about ",{"data":22572,"content":22573,"nodeType":915},{"uri":1240},[22574],{"data":22575,"marks":22576,"value":22578,"nodeType":867},{},[22577],{"type":913},"the evolution in phishing techniques and tooling",{"data":22580,"marks":22581,"value":22582,"nodeType":867},{},[],", and what this means for the reliability of traditional detections at the network and endpoint layer. ",{"data":22584,"content":22585,"nodeType":876},{},[22586],{"data":22587,"marks":22588,"value":22589,"nodeType":867},{},[],"The latest generation of phishing pages are dynamically obfuscating the code that loads the web page, implementing custom bot protection (e.g. CAPTCHA or Cloudflare Turnstile), using runtime anti-analysis features, and using legitimate SaaS and cloud services to host and deliver phishing links to cover their tracks.",{"data":22591,"content":22592,"nodeType":876},{},[22593],{"data":22594,"marks":22595,"value":22596,"nodeType":867},{},[],"This means that traditional anti-phishing tools at the email and network layer are struggling to keep up, with many attacks evading email-based detections (or bypassing email altogether). At the same time, proxy-based solutions now see a garbled mess of JavaScript code without the necessary context of what is actually happening in the browser to be able to piece it together effectively. Even if they don’t realize it, this means many organizations are now relying solely on blocking known-bad sites and hosts — a wildly ineffective solution in 2025 with the rate that attackers refresh and rotate their phishing infrastructure. ",{"data":22598,"content":22599,"nodeType":876},{},[22600],{"data":22601,"marks":22602,"value":22603,"nodeType":867},{},[],"In addition to the fact that ClickFix page styles and content can vary significantly, this means that detecting ClickFix delivery using traditional tooling is highly unreliable. ",{"data":22605,"content":22606,"nodeType":1058},{},[22607],{"data":22608,"marks":22609,"value":22611,"nodeType":867},{},[22610],{"type":865},"Detection challenges during execution",{"data":22613,"content":22614,"nodeType":876},{},[22615],{"data":22616,"marks":22617,"value":22618,"nodeType":867},{},[],"Most of the detection heavy lifting is being done at the endpoint, looking for user-level code execution and malware running on a device. ",{"data":22620,"content":22621,"nodeType":876},{},[22622],{"data":22623,"marks":22624,"value":22625,"nodeType":867},{},[],"However, the number of ClickFix-related headlines in the news would indicate that endpoint controls are being routinely bypassed, or perhaps evaded altogether by targeting personal or BYOD devices. ",{"data":22627,"content":22631,"nodeType":985},{"target":22628},{"sys":22629},{"id":22630,"type":982,"linkType":983},"pocty4OhER5EXr8BDwdzo",[],{"data":22633,"content":22634,"nodeType":876},{},[22635],{"data":22636,"marks":22637,"value":22638,"nodeType":867},{},[],"There are a number of reasons that endpoint-level ClickFix detections can be bypassed:",{"data":22640,"content":22641,"nodeType":1629},{},[22642,22652,22662],{"data":22643,"content":22644,"nodeType":1586},{},[22645],{"data":22646,"content":22647,"nodeType":876},{},[22648],{"data":22649,"marks":22650,"value":22651,"nodeType":867},{},[],"The step of downloading a file from the web is bypassed altogether. In a ClickFix/FileFix attack, the initial “dropper” is essentially a command string provided by the attacker and executed by legitimate system utilities. There is often no new executable file written to disk when the user runs the command. The final payload may be loaded directly into memory or injected into trusted programs (using living-off-the-land techniques). Without a file to quarantine, there's no \"Mark of the Web\" to make it appear suspicious. ",{"data":22653,"content":22654,"nodeType":1586},{},[22655],{"data":22656,"content":22657,"nodeType":876},{},[22658],{"data":22659,"marks":22660,"value":22661,"nodeType":867},{},[],"From the EDR’s point of view, a trusted parent process is launching a script – which might not immediately be judged as malicious, especially if the command is obfuscated or uses allowed system functions. Since the action is initiated by the user, it blends in with normal user-driven administration tasks. ",{"data":22663,"content":22664,"nodeType":1586},{},[22665],{"data":22666,"content":22667,"nodeType":876},{},[22668],{"data":22669,"marks":22670,"value":22671,"nodeType":867},{},[],"The PowerShell commands themselves might be obfuscated or broken into stages to avoid easy detection by heuristic rules. EDR telemetry might record that a PowerShell process ran, but without a known bad signature or a clear policy violation, it may not flag it immediately. ",{"data":22673,"content":22677,"nodeType":985},{"target":22674},{"sys":22675},{"id":22676,"type":982,"linkType":983},"6djGsqBFTHlLLITpTK7IMk",[],{"data":22679,"content":22680,"nodeType":1058},{},[22681],{"data":22682,"marks":22683,"value":22685,"nodeType":867},{},[22684],{"type":865},"Accessing ClickFix-style capabilities is easier than ever",{"data":22687,"content":22688,"nodeType":876},{},[22689,22693,22701],{"data":22690,"marks":22691,"value":22692,"nodeType":867},{},[],"This capability is increasingly available to all levels of threat actor, with ",{"data":22694,"content":22695,"nodeType":915},{"uri":22329},[22696],{"data":22697,"marks":22698,"value":22700,"nodeType":867},{},[22699],{"type":913},"off-the-shelf options available",{"data":22702,"marks":22703,"value":22704,"nodeType":867},{},[]," in the form of ClickFix builders (also called “Win + R”) on popular hacker forums since late 2024. ",{"data":22706,"content":22707,"nodeType":876},{},[22708],{"data":22709,"marks":22710,"value":22711,"nodeType":867},{},[],"Attackers are bundling ClickFix builders into their existing kits to:",{"data":22713,"content":22714,"nodeType":1629},{},[22715,22725],{"data":22716,"content":22717,"nodeType":1586},{},[22718],{"data":22719,"content":22720,"nodeType":876},{},[22721],{"data":22722,"marks":22723,"value":22724,"nodeType":867},{},[],"Use pre-canned landing pages with various lures including Cloudflare. ",{"data":22726,"content":22727,"nodeType":1586},{},[22728],{"data":22729,"content":22730,"nodeType":876},{},[22731],{"data":22732,"marks":22733,"value":22734,"nodeType":867},{},[],"Offer construction of malicious commands that users will paste into the Windows Run dialog. ",{"data":22736,"content":22737,"nodeType":876},{},[22738],{"data":22739,"marks":22740,"value":22741,"nodeType":867},{},[],"These kits claim to guarantee antivirus and web protection bypass (some even promise that they can bypass Microsoft Defender SmartScreen), as well as payload persistence. The cost of subscription to such a service might be between US$200 to US$1,500 per month. ",{"data":22743,"content":22744,"nodeType":876},{},[22745],{"data":22746,"marks":22747,"value":22748,"nodeType":867},{},[],"In short, these capabilities are increasingly accessible to the general population of hackers, and it is increasingly in the interests of malware developers to offer premium hacker tools designed to bypass current detections. ",{"data":22750,"content":22754,"nodeType":985},{"target":22751},{"sys":22752},{"id":22753,"type":982,"linkType":983},"5hkRsOBZCOABAShCo8RjJg",[],{"data":22756,"content":22757,"nodeType":876},{},[22758],{"data":22759,"marks":22760,"value":22761,"nodeType":867},{},[],"In any case, relying on just-in-time detection at the point of execution is increasingly unreliable and will always be at the mercy of the cat-and-mouse game between attackers and defenders. Organizations employing custom detections looking for specific malware behavior are likely to have better success than those relying on out-of-the-box EDR configs, but this requires continual maintenance to be effective. ",{"data":22763,"content":22764,"nodeType":942},{},[],{"data":22766,"content":22767,"nodeType":868},{},[22768],{"data":22769,"marks":22770,"value":22772,"nodeType":867},{},[22771],{"type":865},"Solving ClickFix detection in the browser with Push",{"data":22774,"content":22775,"nodeType":876},{},[22776,22779,22783],{"data":22777,"marks":22778,"value":22428,"nodeType":867},{},[],{"data":22780,"marks":22781,"value":21560,"nodeType":867},{},[22782],{"type":865},{"data":22784,"marks":22785,"value":22786,"nodeType":867},{},[],", tackles ClickFix-style attacks at the earliest opportunity through browser-based detection and blocking, with a universally effective control that works regardless of the lure delivery channel, page style and structure, or the specifics of the malware type and execution.",{"data":22788,"content":22789,"nodeType":876},{},[22790,22794,22803],{"data":22791,"marks":22792,"value":22793,"nodeType":867},{},[],"A key part of our design philosophy is to find ways to universally detect attacker TTPs by analyzing generic attacker actions that can’t be avoided by the attacker. One of our best prior examples of this is with our ",{"data":22795,"content":22797,"nodeType":915},{"uri":22796},"https://pushsecurity.com/blog/introducing-sso-password-protection/",[22798],{"data":22799,"marks":22800,"value":22802,"nodeType":867},{},[22801],{"type":913},"password protection feature",{"data":22804,"marks":22805,"value":22806,"nodeType":867},{},[],", which detects and blocks phishing attacks by triggering when a user attempts to enter a password that belongs to one domain on a different domain. ",{"data":22808,"content":22809,"nodeType":876},{},[22810],{"data":22811,"marks":22812,"value":22813,"nodeType":867},{},[],"In the case of ClickFix, every attack involves copying a malicious script from a page — a behavior the attacker can’t avoid.",{"data":22815,"content":22816,"nodeType":876},{},[22817],{"data":22818,"marks":22819,"value":22820,"nodeType":867},{},[],"Unlike heavy-handed DLP solutions that block copy-paste altogether, Push protects your employees without disrupting their user experience or hampering productivity. ",{"data":22822,"content":22823,"nodeType":876},{},[22824],{"data":22825,"marks":22826,"value":22827,"nodeType":867},{},[],"Check out the video below to see Push in action. ",{"data":22829,"content":22832,"nodeType":985},{"target":22830},{"sys":22831},{"id":21583,"type":982,"linkType":983},[],{"data":22834,"content":22835,"nodeType":1058},{},[22836],{"data":22837,"marks":22838,"value":22840,"nodeType":867},{},[22839],{"type":865},"Enable ClickFix detection in just a few clicks",{"data":22842,"content":22843,"nodeType":876},{},[22844,22848,22856],{"data":22845,"marks":22846,"value":22847,"nodeType":867},{},[],"Check out the ",{"data":22849,"content":22851,"nodeType":915},{"uri":22850},"https://pushsecurity.com/help/10141/#start",[22852],{"data":22853,"marks":22854,"value":22855,"nodeType":867},{},[],"help article",{"data":22857,"marks":22858,"value":22859,"nodeType":867},{},[]," for step-by-step instructions on how to enable the control. ",{"data":22861,"content":22862,"nodeType":942},{},[],{"data":22864,"content":22865,"nodeType":868},{},[22866],{"data":22867,"marks":22868,"value":14676,"nodeType":867},{},[22869],{"type":865},{"data":22871,"content":22872,"nodeType":876},{},[22873],{"data":22874,"marks":22875,"value":22876,"nodeType":867},{},[],"Push provides last mile protection against browser-based attacks, adding a net-new layer of technical protection in the browser. ",{"data":22878,"content":22879,"nodeType":876},{},[22880],{"data":22881,"marks":22882,"value":22883,"nodeType":867},{},[],"Right now, most organizations are left relying on user awareness. Faced with increasingly novel attack types, encountered all over the internet, users are being caught unawares — further reducing the efficacy of an already fragile control. ",{"data":22885,"content":22886,"nodeType":876},{},[22887],{"data":22888,"marks":22889,"value":22890,"nodeType":867},{},[],"By seeing what the user sees in the browser, as they see it, as well as monitoring for risky behaviors, Push provides a strong backstop against an ever-expanding landscape of browser-based exploits. ",{"data":22892,"content":22893,"nodeType":876},{},[22894],{"data":22895,"marks":22896,"value":22897,"nodeType":867},{},[],"Push’s browser-based security platform provides comprehensive identity attack detection and response capabilities against techniques like AiTM phishing, credential stuffing, ClickFixing, malicious browser extensions, and session hijacking using stolen session tokens. You can also use Push to find and fix vulnerabilities across the apps that your employees use, like ghost logins, SSO coverage gaps, MFA gaps, vulnerable passwords, risky OAuth integrations, and more to harden your identity attack surface.",{"data":22899,"content":22900,"nodeType":876},{},[22901,22904,22911,22914,22921],{"data":22902,"marks":22903,"value":14690,"nodeType":867},{},[],{"data":22905,"content":22906,"nodeType":915},{"uri":14693},[22907],{"data":22908,"marks":22909,"value":14699,"nodeType":867},{},[22910],{"type":913},{"data":22912,"marks":22913,"value":21631,"nodeType":867},{},[],{"data":22915,"content":22916,"nodeType":915},{"uri":2689},[22917],{"data":22918,"marks":22919,"value":14723,"nodeType":867},{},[22920],{"type":913},{"data":22922,"marks":22923,"value":1679,"nodeType":867},{},[],{"data":22925,"content":22928,"nodeType":985},{"target":22926},{"sys":22927},{"id":22676,"type":982,"linkType":983},[],{"data":22930,"content":22931,"nodeType":876},{},[22932],{"data":22933,"marks":22934,"value":21,"nodeType":867},{},[],"Introducing malicious copy and paste detection","Push now detects malware delivery in the browser, supporting a layered defense against endpoint attacks. ","2025-10-09T00:00:00.000Z","introducing-malicious-copy-paste-detection",{"items":22940},[22941,22943],{"sys":22942,"name":342},{"id":3240},{"sys":22944,"name":4018},{"id":4017},{"items":22946},[22947],{"fullName":4022,"firstName":4023,"jobTitle":4024,"profilePicture":22948},{"url":4026},{"__typename":1772,"sys":22950,"content":22952,"title":23596,"synopsis":23597,"hashTags":59,"publishedDate":23598,"slug":23599,"tagsCollection":23600,"authorsCollection":23606},{"id":22951},"62Zyr35VUmijkpupWk3hoD",{"json":22953},{"data":22954,"content":22955,"nodeType":1680},{},[22956,22972,22979,22982,22990,22997,23004,23024,23030,23037,23044,23051,23058,23061,23069,23076,23082,23089,23097,23104,23111,23117,23137,23143,23150,23156,23163,23168,23171,23179,23195,23202,23232,23239,23246,23252,23259,23266,23273,23276,23284,23302,23308,23315,23322,23328,23335,23342,23345,23353,23360,23380,23424,23431,23438,23445,23448,23456,23463,23470,23477,23480,23488,23495,23526,23546,23553,23556,23564,23571,23578],{"data":22957,"content":22958,"nodeType":876},{},[22959,22963,22968],{"data":22960,"marks":22961,"value":22962,"nodeType":867},{},[],"The view that \"the browser is the new endpoint\" and \"the new battleground for cyber attacks\" is becoming increasingly advocated by security leaders. But what does this ",{"data":22964,"marks":22965,"value":22967,"nodeType":867},{},[22966],{"type":1303},"actually",{"data":22969,"marks":22970,"value":22971,"nodeType":867},{},[]," mean for security teams? ",{"data":22973,"content":22974,"nodeType":876},{},[22975],{"data":22976,"marks":22977,"value":22978,"nodeType":867},{},[],"In this article, we’re cutting out the jargon to explore what a browser-based attack is, and what’s required for effective detection and response. ",{"data":22980,"content":22981,"nodeType":942},{},[],{"data":22983,"content":22984,"nodeType":868},{},[22985],{"data":22986,"marks":22987,"value":22989,"nodeType":867},{},[22988],{"type":865},"What is the goal of a browser-based attack?   ",{"data":22991,"content":22992,"nodeType":876},{},[22993],{"data":22994,"marks":22995,"value":22996,"nodeType":867},{},[],"First, it’s important to establish what the point of a browser-based attack is.",{"data":22998,"content":22999,"nodeType":876},{},[23000],{"data":23001,"marks":23002,"value":23003,"nodeType":867},{},[],"In most scenarios, attackers don’t think of themselves as attacking your web browser. Their end-goal is to compromise your business apps and data. That means going after the third-party apps and services that are now the backbone of business IT — and therefore the top target for attackers. ",{"data":23005,"content":23006,"nodeType":876},{},[23007,23011,23020],{"data":23008,"marks":23009,"value":23010,"nodeType":867},{},[],"The most common attack path today sees attackers log into third-party services, dump the data, and monetize it through extortion. You need only look at last year’s ",{"data":23012,"content":23014,"nodeType":915},{"uri":23013},"https://pushsecurity.com/blog/snowflake-retro?utm_source=bleeping-computer&utm_medium=sponsored-content&utm_term=article",[23015],{"data":23016,"marks":23017,"value":23019,"nodeType":867},{},[23018],{"type":913},"Snowflake",{"data":23021,"marks":23022,"value":23023,"nodeType":867},{},[]," customer breaches or the still-ongoing Salesforce attacks to see the impact.",{"data":23025,"content":23029,"nodeType":985},{"target":23026},{"sys":23027},{"id":23028,"type":982,"linkType":983},"5agrVXzEdwALmew2F5SPDp",[],{"data":23031,"content":23032,"nodeType":876},{},[23033],{"data":23034,"marks":23035,"value":23036,"nodeType":867},{},[],"The most logical way to do this is by targeting users of those apps. And because of the changes to working practices, your users are more accessible than ever to external attackers.",{"data":23038,"content":23039,"nodeType":876},{},[23040],{"data":23041,"marks":23042,"value":23043,"nodeType":867},{},[],"Once upon a time, email was the primary communication channel with the wider world, and work happened locally — on your device, and inside your locked-down network environment. This made email and the endpoint the highest priority from a security perspective. But now, with modern work happening across a network of decentralized internet apps, and more varied communication channels outside of email, it’s harder to stop users from interacting with malicious content (at least, without significantly impeding their ability to do their jobs).",{"data":23045,"content":23046,"nodeType":876},{},[23047],{"data":23048,"marks":23049,"value":23050,"nodeType":867},{},[],"Given that the browser is the place where business apps are accessed and used, it makes sense that attacks are increasingly playing out there too. ",{"data":23052,"content":23053,"nodeType":876},{},[23054],{"data":23055,"marks":23056,"value":23057,"nodeType":867},{},[],"With that covered off, let’s take a closer look at the most prevalent browser-based attack techniques being used by attackers in the wild today.",{"data":23059,"content":23060,"nodeType":942},{},[],{"data":23062,"content":23063,"nodeType":868},{},[23064],{"data":23065,"marks":23066,"value":23068,"nodeType":867},{},[23067],{"type":865},"The 6 key browser-based attacks that security teams need to know about",{"data":23070,"content":23071,"nodeType":876},{},[23072],{"data":23073,"marks":23074,"value":23075,"nodeType":867},{},[],"Attacks that target users in their web browsers have seen an unprecedented rise in recent years. ",{"data":23077,"content":23081,"nodeType":985},{"target":23078},{"sys":23079},{"id":23080,"type":982,"linkType":983},"4ogNqZdObSIJXavHP44lom",[],{"data":23083,"content":23084,"nodeType":876},{},[23085],{"data":23086,"marks":23087,"value":23088,"nodeType":867},{},[],"Here's our breakdown of the top 6 browser-based attacks that should be on every security team's radar right now. ",{"data":23090,"content":23091,"nodeType":1058},{},[23092],{"data":23093,"marks":23094,"value":23096,"nodeType":867},{},[23095],{"type":865},"1. Phishing for credentials and sessions",{"data":23098,"content":23099,"nodeType":876},{},[23100],{"data":23101,"marks":23102,"value":23103,"nodeType":867},{},[],"The most direct way for an attacker to compromise a business application is to phish a user of that app. You might not necessarily think of phishing as a browser-based attack, but that’s exactly what it is today. ",{"data":23105,"content":23106,"nodeType":876},{},[23107],{"data":23108,"marks":23109,"value":23110,"nodeType":867},{},[],"Phishing tooling and infrastructure has evolved a lot in the past decade, while the changes to business IT means there are both many more vectors for phishing attack delivery, and apps and identities to target. Attackers can deliver links over instant messenger apps, social media, SMS, malicious ads, and using in-app messenger functionality, as well as sending emails directly from SaaS services to bypass email-based checks. Likewise, there are now hundreds of apps per enterprise to target, with varying levels of account security configuration. ",{"data":23112,"content":23116,"nodeType":985},{"target":23113},{"sys":23114},{"id":23115,"type":982,"linkType":983},"3SrKOgpedLMQRpKIZqUQur",[],{"data":23118,"content":23119,"nodeType":876},{},[23120,23124,23133],{"data":23121,"marks":23122,"value":23123,"nodeType":867},{},[],"Whereas phishing was once entirely focused on credential theft, modern phishing attacks see the attacker intercept the victim’s session on the target app, using reverse-proxy Attacker-in-the-Middle kits that are the standard choice for attackers today. This means most forms of MFA can be bypassed, with the exception of passkeys (though attackers are finding ways to work around passkeys using ",{"data":23125,"content":23127,"nodeType":915},{"uri":23126},"https://pushsecurity.com/blog/mfa-downgrade-attacks/?utm_source=bleeping-computer&utm_medium=sponsored-content&utm_term=article",[23128],{"data":23129,"marks":23130,"value":23132,"nodeType":867},{},[23131],{"type":913},"downgrade attacks",{"data":23134,"marks":23135,"value":23136,"nodeType":867},{},[],"). ",{"data":23138,"content":23142,"nodeType":985},{"target":23139},{"sys":23140},{"id":23141,"type":982,"linkType":983},"2sOFEdAwQZjWOGzNAlGavb",[],{"data":23144,"content":23145,"nodeType":876},{},[23146],{"data":23147,"marks":23148,"value":23149,"nodeType":867},{},[],"There are other key differences to be aware of too. Today, phishing operates on an industrial scale, using an array of obfuscation and detection evasion techniques. The latest generation of fully customized AitM phishing kits are dynamically obfuscating the code that loads the web page, implementing custom bot protection (e.g. CAPTCHA or Cloudflare Turnstile), using runtime anti-analysis features, and using legitimate SaaS and cloud services to host and deliver phishing links to cover their tracks.",{"data":23151,"content":23152,"nodeType":876},{},[23153],{"data":23154,"marks":23155,"value":22596,"nodeType":867},{},[],{"data":23157,"content":23158,"nodeType":876},{},[23159],{"data":23160,"marks":23161,"value":23162,"nodeType":867},{},[],"These changes make phishing more effective than ever, and increasingly difficult to detect and block without being able to observe and analyze web pages that a user interacts with in real time — something only possible with browser-level visibility. ",{"data":23164,"content":23167,"nodeType":985},{"target":23165},{"sys":23166},{"id":21904,"type":982,"linkType":983},[],{"data":23169,"content":23170,"nodeType":942},{},[],{"data":23172,"content":23173,"nodeType":1058},{},[23174],{"data":23175,"marks":23176,"value":23178,"nodeType":867},{},[23177],{"type":865},"2. Malicious copy and paste (aka. ClickFix, FileFix, etc.)",{"data":23180,"content":23181,"nodeType":876},{},[23182,23185,23192],{"data":23183,"marks":23184,"value":22326,"nodeType":867},{},[],{"data":23186,"content":23187,"nodeType":915},{"uri":22329},[23188],{"data":23189,"marks":23190,"value":315,"nodeType":867},{},[23191],{"type":913},{"data":23193,"marks":23194,"value":5704,"nodeType":867},{},[],{"data":23196,"content":23197,"nodeType":876},{},[23198],{"data":23199,"marks":23200,"value":23201,"nodeType":867},{},[],"Originally known as “Fake CAPTCHA”, these attacks attempt to trick users into running malicious commands on their device — typically by solving some form of verification challenge in the browser. ",{"data":23203,"content":23204,"nodeType":876},{},[23205,23209,23216,23220,23229],{"data":23206,"marks":23207,"value":23208,"nodeType":867},{},[],"In reality, by solving the challenge, the victim is actually copying malicious code from the page clipboard and running it on their device. It typically gives the victim instructions that involve clicking prompts and copying, pasting, and running commands directly in the Windows Run dialog box, Terminal, or PowerShell. Variants such as ",{"data":23210,"content":23211,"nodeType":915},{"uri":22490},[23212],{"data":23213,"marks":23214,"value":22496,"nodeType":867},{},[23215],{"type":913},{"data":23217,"marks":23218,"value":23219,"nodeType":867},{},[]," have also emerged which instead uses the File Explorer Address Bar to execute OS commands, while recent examples have seen this attack branch out to ",{"data":23221,"content":23223,"nodeType":915},{"uri":23222},"https://www.bleepingcomputer.com/news/security/fake-mac-fixes-trick-users-into-installing-new-shamos-infostealer/",[23224],{"data":23225,"marks":23226,"value":23228,"nodeType":867},{},[23227],{"type":913},"Mac via the macOS terminal",{"data":23230,"marks":23231,"value":1679,"nodeType":867},{},[],{"data":23233,"content":23234,"nodeType":876},{},[23235],{"data":23236,"marks":23237,"value":23238,"nodeType":867},{},[],"Most commonly, these attacks are used to deliver infostealer malware, using stolen session cookies and credentials to access business apps and services. ",{"data":23240,"content":23241,"nodeType":876},{},[23242],{"data":23243,"marks":23244,"value":23245,"nodeType":867},{},[],"Like modern credential and session phishing, links to malicious pages are distributed over various delivery channels and using a variety of lures, including impersonating CAPTCHA, Cloudflare Turnstile, simulating an error loading a webpage, and many more. ",{"data":23247,"content":23251,"nodeType":985},{"target":23248},{"sys":23249},{"id":23250,"type":982,"linkType":983},"6O9YiOfhpGFCDsTil9F3On",[],{"data":23253,"content":23254,"nodeType":876},{},[23255],{"data":23256,"marks":23257,"value":23258,"nodeType":867},{},[],"The variance in lure, and differences between different versions of the same lure, can make it difficult to fingerprint and detect based on visual elements alone. Also, many of the same protections being used to obfuscate and prevent analysis of phishing pages also apply to ClickFix pages, making it equally challenging to detect and block them. ",{"data":23260,"content":23261,"nodeType":876},{},[23262],{"data":23263,"marks":23264,"value":23265,"nodeType":867},{},[],"This leaves most of the detection and blocking down to endpoint-layer controls around user-level code execution and malware running on a device. The quantity of ClickFix-related headlines in the news would indicate that endpoint controls are being routinely bypassed, or perhaps evaded altogether by targeting personal or BYOD devices. ",{"data":23267,"content":23268,"nodeType":876},{},[23269],{"data":23270,"marks":23271,"value":23272,"nodeType":867},{},[],"There is a significant opportunity to detect these attacks in the browser and stop them at the earliest opportunity, before they reach the endpoint. Every ClickFix attack and variant has a key action in common — malicious code is copied from the page’s clipboard. In some cases, this happens without any user interaction (where the only requirement on the user is to run code that has been silently copied behind the scenes), presenting a strong indicator of malicious behavior that can be observed in the browser. ",{"data":23274,"content":23275,"nodeType":942},{},[],{"data":23277,"content":23278,"nodeType":1058},{},[23279],{"data":23280,"marks":23281,"value":23283,"nodeType":867},{},[23282],{"type":865},"3. Malicious OAuth integrations",{"data":23285,"content":23286,"nodeType":876},{},[23287,23291,23299],{"data":23288,"marks":23289,"value":23290,"nodeType":867},{},[],"Malicious OAuth integrations are another way for attackers to compromise an app by tricking a user into authorizing an integration with a malicious, attacker-controlled app, with the level of data access and functionality dictated by the scopes authorized in the request. This is also known as ",{"data":23292,"content":23294,"nodeType":915},{"uri":23293},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/consent_phishing/description.md",[23295],{"data":23296,"marks":23297,"value":23298,"nodeType":867},{},[],"consent phishing",{"data":23300,"marks":23301,"value":2933,"nodeType":867},{},[],{"data":23303,"content":23307,"nodeType":985},{"target":23304},{"sys":23305},{"id":23306,"type":982,"linkType":983},"5JaP4WSfFsFSbvaa9BQBOq",[],{"data":23309,"content":23310,"nodeType":876},{},[23311],{"data":23312,"marks":23313,"value":23314,"nodeType":867},{},[],"This is an effective way for attackers to bypass hardened authentication and access controls by sidestepping the typical login process to take over an account and compromise business apps. This includes phishing-resistant MFA methods like passkeys — since the standard login process does not apply. ",{"data":23316,"content":23317,"nodeType":876},{},[23318],{"data":23319,"marks":23320,"value":23321,"nodeType":867},{},[],"A variant of this attack has dominated the headlines recently with the ongoing Salesforce breaches. In this scenario, the attacker tricked the victim into authorizing an attacker-controlled OAuth app via the device code authorization flow in Salesforce, which requires the user to enter an 8-digit code in place of a password or MFA factor.",{"data":23323,"content":23327,"nodeType":985},{"target":23324},{"sys":23325},{"id":23326,"type":982,"linkType":983},"3odEFcUcpKN553gHh2P5yr",[],{"data":23329,"content":23330,"nodeType":876},{},[23331],{"data":23332,"marks":23333,"value":23334,"nodeType":867},{},[],"Preventing malicious OAuth grants being authorized requires tight in-app management of user permissions and tenant security settings. This is no mean feat when considering the 100s of apps in use across the modern enterprise, many of which are not centrally managed by IT and security teams (or in some cases, are completely unknown to them). Even then, you’re limited by the controls made available by the app vendor. In this case, Salesforce has announced planned changes to OAuth app authorization in order to improve security prompted by these attacks — but many more apps with insecure configs exist for attackers to take advantage of in future. ",{"data":23336,"content":23337,"nodeType":876},{},[23338],{"data":23339,"marks":23340,"value":23341,"nodeType":867},{},[],"However, unlike app-specific integrations, browser-based security tools are well positioned to observe OAuth grants across all apps accessed in the browser — even the ones the security team doesn’t manage or know about, or without needing to pay for the app’s special security add-on to get visibility.",{"data":23343,"content":23344,"nodeType":942},{},[],{"data":23346,"content":23347,"nodeType":1058},{},[23348],{"data":23349,"marks":23350,"value":23352,"nodeType":867},{},[23351],{"type":865},"4. Malicious browser extensions",{"data":23354,"content":23355,"nodeType":876},{},[23356],{"data":23357,"marks":23358,"value":23359,"nodeType":867},{},[],"Malicious browser extensions are another way for attackers to compromise your business apps by observing and capturing logins as they happen, and/or extracting session cookies and credentials saved in the browser cache and password manager. ",{"data":23361,"content":23362,"nodeType":876},{},[23363,23367,23376],{"data":23364,"marks":23365,"value":23366,"nodeType":867},{},[],"Attackers do this by creating their own malicious extension and tricking your users into installing it, or taking over an existing extension to gain access to browsers where it is already installed (",{"data":23368,"content":23370,"nodeType":915},{"uri":23369},"https://secureannex.com/blog/buying-browser-extensions/",[23371],{"data":23372,"marks":23373,"value":23375,"nodeType":867},{},[23374],{"type":913},"it’s very easy for attackers to buy and add malicious updates to existing extensions",{"data":23377,"marks":23378,"value":23379,"nodeType":867},{},[],", easily passing extension web store security checks). ",{"data":23381,"content":23382,"nodeType":876},{},[23383,23387,23396,23400,23409,23412,23421],{"data":23384,"marks":23385,"value":23386,"nodeType":867},{},[],"The news around extension-based compromises has been on the rise since the ",{"data":23388,"content":23390,"nodeType":915},{"uri":23389},"https://www.bleepingcomputer.com/news/security/new-details-reveal-how-hackers-hijacked-35-google-chrome-extensions/",[23391],{"data":23392,"marks":23393,"value":23395,"nodeType":867},{},[23394],{"type":913},"Cyberhaven extension",{"data":23397,"marks":23398,"value":23399,"nodeType":867},{},[]," was hacked in December 2024, along with at least 35 other extensions. Since then, there has been regular reporting on data-stealing extensions ",{"data":23401,"content":23403,"nodeType":915},{"uri":23402},"https://www.bleepingcomputer.com/news/security/data-stealing-chrome-extensions-impersonate-fortinet-youtube-vpns/",[23404],{"data":23405,"marks":23406,"value":23408,"nodeType":867},{},[23407],{"type":913},"impersonating legitimate brands",{"data":23410,"marks":23411,"value":5147,"nodeType":867},{},[],{"data":23413,"content":23415,"nodeType":915},{"uri":23414},"https://www.bleepingcomputer.com/news/security/chrome-extensions-with-6-million-installs-have-hidden-tracking-code/",[23416],{"data":23417,"marks":23418,"value":23420,"nodeType":867},{},[23419],{"type":913},"impacting millions of users",{"data":23422,"marks":23423,"value":1679,"nodeType":867},{},[],{"data":23425,"content":23426,"nodeType":876},{},[23427],{"data":23428,"marks":23429,"value":23430,"nodeType":867},{},[],"Risky browser extension permissions include broad data access, the ability to modify website content, track user activity, capture screenshots, and manage tabs or network requests. Permissions like \"read and change all data on all websites\" or access to cookies and browsing history are particularly dangerous as they can be exploited for session hijacking, data theft, malware injection, or phishing.",{"data":23432,"content":23433,"nodeType":876},{},[23434],{"data":23435,"marks":23436,"value":23437,"nodeType":867},{},[],"Generally, your employees should not be randomly installing browser extensions unless pre-approved by your security team. The reality, however, is that many organizations have very little visibility of the extensions their employees are using, and the potential risk they’re exposed to as a result. ",{"data":23439,"content":23440,"nodeType":876},{},[23441],{"data":23442,"marks":23443,"value":23444,"nodeType":867},{},[],"To tackle malicious extensions, security tools operating in the browser can track the browser extensions deployed, highlight risky permissions, compare with known-malicious extensions, identify fraudulent/unofficial versions of a legitimate extension, and highlight other risky properties commonly associated with malicious extensions (e.g. “Developer” extensions). ",{"data":23446,"content":23447,"nodeType":942},{},[],{"data":23449,"content":23450,"nodeType":1058},{},[23451],{"data":23452,"marks":23453,"value":23455,"nodeType":867},{},[23454],{"type":865},"5. Malicious file delivery",{"data":23457,"content":23458,"nodeType":876},{},[23459],{"data":23460,"marks":23461,"value":23462,"nodeType":867},{},[],"Malicious files have been a core part of malware delivery and credential theft for many years. Just as non-email channels like malvertising and drive-by attacks are used to deliver phishing and ClickFix lures, malicious files are also distributed through similar means — leaving malicious file detection to basic known-bad checks, sandbox analysis using a proxy (not that useful in the context of sandbox-aware malware) or runtime analysis on the endpoint. ",{"data":23464,"content":23465,"nodeType":876},{},[23466],{"data":23467,"marks":23468,"value":23469,"nodeType":867},{},[],"This doesn’t just have to be malicious executables directly dropping malware onto the device. File downloads can also contain additional links taking the user to malicious content. In fact, one of the most common types of downloadable content are HTML Applications (HTAs), commonly used to spawn local phishing pages to stealthily capture credentials. More recently, attackers have been weaponizing SVG files for a similar purpose, running as self-contained phishing pages that render fake login portals entirely client-side. ",{"data":23471,"content":23472,"nodeType":876},{},[23473],{"data":23474,"marks":23475,"value":23476,"nodeType":867},{},[],"Even if malicious content cannot always be flagged from surface-level inspection of a file, recording file downloads in the browser is a useful addition to endpoint-based malware protection, and provides another layer of defense against file downloads that perform client-side attacks, or redirect the user to malicious web-based content. ",{"data":23478,"content":23479,"nodeType":942},{},[],{"data":23481,"content":23482,"nodeType":1058},{},[23483],{"data":23484,"marks":23485,"value":23487,"nodeType":867},{},[23486],{"type":865},"6. Stolen credentials and MFA gaps",{"data":23489,"content":23490,"nodeType":876},{},[23491],{"data":23492,"marks":23493,"value":23494,"nodeType":867},{},[],"This last one isn’t so much a browser-based attack, but it is a product of them. When credentials are stolen through phishing or infostealer malware they can be used to take over accounts missing MFA. ",{"data":23496,"content":23497,"nodeType":876},{},[23498,23502,23509,23513,23522],{"data":23499,"marks":23500,"value":23501,"nodeType":867},{},[],"This isn’t the most sophisticated attack, but it’s very effective. You need only look at last year’s ",{"data":23503,"content":23504,"nodeType":915},{"uri":23013},[23505],{"data":23506,"marks":23507,"value":23019,"nodeType":867},{},[23508],{"type":913},{"data":23510,"marks":23511,"value":23512,"nodeType":867},{},[]," account compromises or the ",{"data":23514,"content":23516,"nodeType":915},{"uri":23515},"https://pushsecurity.com/blog/why-attackers-are-targeting-jira-with-stolen-credentials?utm_source=bleeping-computer&utm_medium=sponsored-content&utm_term=article",[23517],{"data":23518,"marks":23519,"value":23521,"nodeType":867},{},[23520],{"type":913},"Jira",{"data":23523,"marks":23524,"value":23525,"nodeType":867},{},[]," attacks earlier this year to see how attackers harness stolen credentials at scale. ",{"data":23527,"content":23528,"nodeType":876},{},[23529,23533,23542],{"data":23530,"marks":23531,"value":23532,"nodeType":867},{},[],"With the modern enterprise using hundreds of apps, the likelihood that an app hasn’t been configured for mandatory MFA (if possible) is high. And even when an app has been configured for SSO and connected to your primary corporate identity, ",{"data":23534,"content":23536,"nodeType":915},{"uri":23535},"https://pushsecurity.com/blog/how-many-vulnerable-identities-do-you-have/?utm_source=bleeping-computer&utm_medium=sponsored-content&utm_term=sidebar",[23537],{"data":23538,"marks":23539,"value":23541,"nodeType":867},{},[23540],{"type":913},"local “ghost logins” can continue to exist",{"data":23543,"marks":23544,"value":23545,"nodeType":867},{},[],", accepting passwords with no MFA required. Just having visibility of your primary Identity Provider accounts (e.g. Google, Microsoft, Okta) and SSO-connected apps doesn't give you a full picture of your identity surface.",{"data":23547,"content":23548,"nodeType":876},{},[23549],{"data":23550,"marks":23551,"value":23552,"nodeType":867},{},[],"Logins can also be observed in the browser — in fact, it’s as close to a universal source of truth as you’re going to get about how your employees are actually logging in, which apps they’re using, and whether MFA is present, enabling security teams to find and fix vulnerable logins before they can be exploited by attackers. ",{"data":23554,"content":23555,"nodeType":942},{},[],{"data":23557,"content":23558,"nodeType":868},{},[23559],{"data":23560,"marks":23561,"value":23563,"nodeType":867},{},[23562],{"type":865},"Conclusion",{"data":23565,"content":23566,"nodeType":876},{},[23567],{"data":23568,"marks":23569,"value":23570,"nodeType":867},{},[],"Attacks are increasingly happening in the browser. That makes it the perfect place to detect and respond to these attacks. But right now, the browser is a blind-spot for most security teams. ",{"data":23572,"content":23573,"nodeType":876},{},[23574],{"data":23575,"marks":23576,"value":23577,"nodeType":867},{},[],"Push Security’s browser-based security platform provides comprehensive detection and response capabilities against the leading cause of breaches. Push blocks browser-based attacks like AiTM phishing, credential stuffing, password spraying and session hijacking using stolen session tokens. You can also use Push to find and fix vulnerabilities across the apps that your employees use, like ghost logins, SSO coverage gaps, MFA gaps, vulnerable passwords, risky OAuth integrations, and more to harden your identity attack surface.",{"data":23579,"content":23580,"nodeType":876},{},[23581,23585,23593],{"data":23582,"marks":23583,"value":23584,"nodeType":867},{},[],"If you want to learn more about how Push helps you to detect and stop attacks in the browser, ",{"data":23586,"content":23588,"nodeType":915},{"uri":23587},"https://pushsecurity.com/demo?utm_source=bleeping-computer&utm_medium=sponsored-content&utm_term=article",[23589],{"data":23590,"marks":23591,"value":14723,"nodeType":867},{},[23592],{"type":913},{"data":23594,"marks":23595,"value":1679,"nodeType":867},{},[],"6 browser-based attacks every security team should be prepared for","What security teams need to know about the browser-based attack techniques that are the leading cause of breaches.","2025-09-05T00:00:00.000Z","6-browser-based-attacks-every-security-team-should-be-prepared-for",{"items":23601},[23602,23604],{"sys":23603,"name":4018},{"id":4017},{"sys":23605,"name":342},{"id":3240},{"items":23607},[23608],{"fullName":4022,"firstName":4023,"jobTitle":4024,"profilePicture":23609},{"url":4026},"the-most-advanced-clickfix-yet","blog/the-most-advanced-clickfix-yet",{"json":23613},{"data":23614,"content":23615,"nodeType":1680},{},[23616],{"data":23617,"content":23618,"nodeType":876},{},[23619],{"data":23620,"marks":23621,"value":23622,"nodeType":867},{},[],"Breaking down the most sophisticated ClickFix page we’ve seen in the wild — and what it tells us about the future of malicious copy-and-paste attacks. ",{"id":23624,"publishedAt":23625},"7rVNBW6rYXnXMpI0JEwzgR","2026-08-12T11:53:36.977Z",{"items":23627},[23628,23630],{"sys":23629,"name":342},{"id":3240},{"sys":23631,"name":4018},{"id":4017},{"items":23633},[23634,23636,23638,23640,23642,23644,23646,23648,23650,23652,23654,23656,23658],{"sys":23635,"name":279,"slug":280,"tier":31},{"id":276},{"sys":23637,"name":519,"slug":520,"tier":31},{"id":516},{"sys":23639,"name":342,"slug":343,"tier":31},{"id":339},{"sys":23641,"name":642,"slug":643,"tier":31},{"id":639},{"sys":23643,"name":315,"slug":316,"tier":45},{"id":312},{"sys":23645,"name":440,"slug":441,"tier":45},{"id":437},{"sys":23647,"name":475,"slug":476,"tier":45},{"id":472},{"sys":23649,"name":607,"slug":608,"tier":45},{"id":604},{"sys":23651,"name":448,"slug":449,"tier":45},{"id":445},{"sys":23653,"name":422,"slug":423,"tier":45},{"id":419},{"sys":23655,"name":563,"slug":564,"tier":45},{"id":560},{"sys":23657,"name":351,"slug":352,"tier":45},{"id":348},{"sys":23659,"name":377,"slug":378,"tier":45},{"id":374},"a1jszNvRBWsjUMRu9Ko6-JrZIirWNf1_NCdmXg2F2qU",{"id":23662,"title":22935,"authorsCollection":23663,"content":23668,"extension":228,"faqItemsCollection":24259,"faqTitle":59,"featured":6,"hashTags":59,"meta":24261,"metaTitle":24262,"ogImage":59,"postType":24263,"publishedDate":22937,"relatedBlogPostsCollection":24264,"slug":22938,"stem":25764,"subtitle":25765,"summary":25766,"synopsis":22936,"sys":25777,"tagsCollection":25779,"topicsCollection":25785,"__hash__":25815},"blog/blog/introducing-malicious-copy-paste-detection.json",{"items":23664},[23665],{"fullName":4022,"firstName":4023,"jobTitle":4024,"socialLinks":23666,"profilePicture":23667},[21074],{"url":4026},{"json":23669,"links":24203},{"data":23670,"content":23671,"nodeType":1680},{},[23672,23708,23754,23767,23772,23778,23781,23788,23794,23800,23806,23822,23828,23833,23848,23853,23856,23863,23869,23876,23892,23898,23904,23910,23917,23923,23929,23934,23940,23970,23975,23982,23998,24004,24025,24031,24037,24042,24048,24051,24058,24071,24087,24093,24099,24105,24110,24117,24132,24135,24142,24148,24154,24160,24166,24192,24197],{"data":23673,"content":23674,"nodeType":876},{},[23675,23678,23685,23688,23695,23698,23705],{"data":23676,"marks":23677,"value":22326,"nodeType":867},{},[],{"data":23679,"content":23680,"nodeType":915},{"uri":22329},[23681],{"data":23682,"marks":23683,"value":315,"nodeType":867},{},[23684],{"type":913},{"data":23686,"marks":23687,"value":22338,"nodeType":867},{},[],{"data":23689,"content":23690,"nodeType":915},{"uri":22341},[23691],{"data":23692,"marks":23693,"value":22347,"nodeType":867},{},[23694],{"type":913},{"data":23696,"marks":23697,"value":22351,"nodeType":867},{},[],{"data":23699,"content":23700,"nodeType":915},{"uri":22354},[23701],{"data":23702,"marks":23703,"value":22360,"nodeType":867},{},[23704],{"type":913},{"data":23706,"marks":23707,"value":22364,"nodeType":867},{},[],{"data":23709,"content":23710,"nodeType":876},{},[23711,23714,23721,23724,23731,23734,23741,23744,23751],{"data":23712,"marks":23713,"value":22371,"nodeType":867},{},[],{"data":23715,"content":23716,"nodeType":915},{"uri":22374},[23717],{"data":23718,"marks":23719,"value":22380,"nodeType":867},{},[23720],{"type":913},{"data":23722,"marks":23723,"value":5136,"nodeType":867},{},[],{"data":23725,"content":23726,"nodeType":915},{"uri":22386},[23727],{"data":23728,"marks":23729,"value":22392,"nodeType":867},{},[23730],{"type":913},{"data":23732,"marks":23733,"value":5136,"nodeType":867},{},[],{"data":23735,"content":23736,"nodeType":915},{"uri":22398},[23737],{"data":23738,"marks":23739,"value":22404,"nodeType":867},{},[23740],{"type":913},{"data":23742,"marks":23743,"value":22408,"nodeType":867},{},[],{"data":23745,"content":23746,"nodeType":915},{"uri":22411},[23747],{"data":23748,"marks":23749,"value":22417,"nodeType":867},{},[23750],{"type":913},{"data":23752,"marks":23753,"value":22421,"nodeType":867},{},[],{"data":23755,"content":23756,"nodeType":876},{},[23757,23760,23764],{"data":23758,"marks":23759,"value":22428,"nodeType":867},{},[],{"data":23761,"marks":23762,"value":21560,"nodeType":867},{},[23763],{"type":865},{"data":23765,"marks":23766,"value":22436,"nodeType":867},{},[],{"data":23768,"content":23771,"nodeType":985},{"target":23769},{"sys":23770},{"id":21583,"type":982,"linkType":983},[],{"data":23773,"content":23774,"nodeType":876},{},[23775],{"data":23776,"marks":23777,"value":22448,"nodeType":867},{},[],{"data":23779,"content":23780,"nodeType":942},{},[],{"data":23782,"content":23783,"nodeType":868},{},[23784],{"data":23785,"marks":23786,"value":22459,"nodeType":867},{},[23787],{"type":865},{"data":23789,"content":23790,"nodeType":876},{},[23791],{"data":23792,"marks":23793,"value":22466,"nodeType":867},{},[],{"data":23795,"content":23796,"nodeType":876},{},[23797],{"data":23798,"marks":23799,"value":22473,"nodeType":867},{},[],{"data":23801,"content":23802,"nodeType":876},{},[23803],{"data":23804,"marks":23805,"value":22480,"nodeType":867},{},[],{"data":23807,"content":23808,"nodeType":876},{},[23809,23812,23819],{"data":23810,"marks":23811,"value":22487,"nodeType":867},{},[],{"data":23813,"content":23814,"nodeType":915},{"uri":22490},[23815],{"data":23816,"marks":23817,"value":22496,"nodeType":867},{},[23818],{"type":913},{"data":23820,"marks":23821,"value":22500,"nodeType":867},{},[],{"data":23823,"content":23824,"nodeType":876},{},[23825],{"data":23826,"marks":23827,"value":22507,"nodeType":867},{},[],{"data":23829,"content":23832,"nodeType":985},{"target":23830},{"sys":23831},{"id":22512,"type":982,"linkType":983},[],{"data":23834,"content":23835,"nodeType":876},{},[23836,23839,23845],{"data":23837,"marks":23838,"value":22520,"nodeType":867},{},[],{"data":23840,"content":23841,"nodeType":915},{"uri":21336},[23842],{"data":23843,"marks":23844,"value":22527,"nodeType":867},{},[],{"data":23846,"marks":23847,"value":22531,"nodeType":867},{},[],{"data":23849,"content":23852,"nodeType":985},{"target":23850},{"sys":23851},{"id":22536,"type":982,"linkType":983},[],{"data":23854,"content":23855,"nodeType":942},{},[],{"data":23857,"content":23858,"nodeType":868},{},[23859],{"data":23860,"marks":23861,"value":22548,"nodeType":867},{},[23862],{"type":865},{"data":23864,"content":23865,"nodeType":876},{},[23866],{"data":23867,"marks":23868,"value":22555,"nodeType":867},{},[],{"data":23870,"content":23871,"nodeType":1058},{},[23872],{"data":23873,"marks":23874,"value":22563,"nodeType":867},{},[23875],{"type":865},{"data":23877,"content":23878,"nodeType":876},{},[23879,23882,23889],{"data":23880,"marks":23881,"value":22570,"nodeType":867},{},[],{"data":23883,"content":23884,"nodeType":915},{"uri":1240},[23885],{"data":23886,"marks":23887,"value":22578,"nodeType":867},{},[23888],{"type":913},{"data":23890,"marks":23891,"value":22582,"nodeType":867},{},[],{"data":23893,"content":23894,"nodeType":876},{},[23895],{"data":23896,"marks":23897,"value":22589,"nodeType":867},{},[],{"data":23899,"content":23900,"nodeType":876},{},[23901],{"data":23902,"marks":23903,"value":22596,"nodeType":867},{},[],{"data":23905,"content":23906,"nodeType":876},{},[23907],{"data":23908,"marks":23909,"value":22603,"nodeType":867},{},[],{"data":23911,"content":23912,"nodeType":1058},{},[23913],{"data":23914,"marks":23915,"value":22611,"nodeType":867},{},[23916],{"type":865},{"data":23918,"content":23919,"nodeType":876},{},[23920],{"data":23921,"marks":23922,"value":22618,"nodeType":867},{},[],{"data":23924,"content":23925,"nodeType":876},{},[23926],{"data":23927,"marks":23928,"value":22625,"nodeType":867},{},[],{"data":23930,"content":23933,"nodeType":985},{"target":23931},{"sys":23932},{"id":22630,"type":982,"linkType":983},[],{"data":23935,"content":23936,"nodeType":876},{},[23937],{"data":23938,"marks":23939,"value":22638,"nodeType":867},{},[],{"data":23941,"content":23942,"nodeType":1629},{},[23943,23952,23961],{"data":23944,"content":23945,"nodeType":1586},{},[23946],{"data":23947,"content":23948,"nodeType":876},{},[23949],{"data":23950,"marks":23951,"value":22651,"nodeType":867},{},[],{"data":23953,"content":23954,"nodeType":1586},{},[23955],{"data":23956,"content":23957,"nodeType":876},{},[23958],{"data":23959,"marks":23960,"value":22661,"nodeType":867},{},[],{"data":23962,"content":23963,"nodeType":1586},{},[23964],{"data":23965,"content":23966,"nodeType":876},{},[23967],{"data":23968,"marks":23969,"value":22671,"nodeType":867},{},[],{"data":23971,"content":23974,"nodeType":985},{"target":23972},{"sys":23973},{"id":22676,"type":982,"linkType":983},[],{"data":23976,"content":23977,"nodeType":1058},{},[23978],{"data":23979,"marks":23980,"value":22685,"nodeType":867},{},[23981],{"type":865},{"data":23983,"content":23984,"nodeType":876},{},[23985,23988,23995],{"data":23986,"marks":23987,"value":22692,"nodeType":867},{},[],{"data":23989,"content":23990,"nodeType":915},{"uri":22329},[23991],{"data":23992,"marks":23993,"value":22700,"nodeType":867},{},[23994],{"type":913},{"data":23996,"marks":23997,"value":22704,"nodeType":867},{},[],{"data":23999,"content":24000,"nodeType":876},{},[24001],{"data":24002,"marks":24003,"value":22711,"nodeType":867},{},[],{"data":24005,"content":24006,"nodeType":1629},{},[24007,24016],{"data":24008,"content":24009,"nodeType":1586},{},[24010],{"data":24011,"content":24012,"nodeType":876},{},[24013],{"data":24014,"marks":24015,"value":22724,"nodeType":867},{},[],{"data":24017,"content":24018,"nodeType":1586},{},[24019],{"data":24020,"content":24021,"nodeType":876},{},[24022],{"data":24023,"marks":24024,"value":22734,"nodeType":867},{},[],{"data":24026,"content":24027,"nodeType":876},{},[24028],{"data":24029,"marks":24030,"value":22741,"nodeType":867},{},[],{"data":24032,"content":24033,"nodeType":876},{},[24034],{"data":24035,"marks":24036,"value":22748,"nodeType":867},{},[],{"data":24038,"content":24041,"nodeType":985},{"target":24039},{"sys":24040},{"id":22753,"type":982,"linkType":983},[],{"data":24043,"content":24044,"nodeType":876},{},[24045],{"data":24046,"marks":24047,"value":22761,"nodeType":867},{},[],{"data":24049,"content":24050,"nodeType":942},{},[],{"data":24052,"content":24053,"nodeType":868},{},[24054],{"data":24055,"marks":24056,"value":22772,"nodeType":867},{},[24057],{"type":865},{"data":24059,"content":24060,"nodeType":876},{},[24061,24064,24068],{"data":24062,"marks":24063,"value":22428,"nodeType":867},{},[],{"data":24065,"marks":24066,"value":21560,"nodeType":867},{},[24067],{"type":865},{"data":24069,"marks":24070,"value":22786,"nodeType":867},{},[],{"data":24072,"content":24073,"nodeType":876},{},[24074,24077,24084],{"data":24075,"marks":24076,"value":22793,"nodeType":867},{},[],{"data":24078,"content":24079,"nodeType":915},{"uri":22796},[24080],{"data":24081,"marks":24082,"value":22802,"nodeType":867},{},[24083],{"type":913},{"data":24085,"marks":24086,"value":22806,"nodeType":867},{},[],{"data":24088,"content":24089,"nodeType":876},{},[24090],{"data":24091,"marks":24092,"value":22813,"nodeType":867},{},[],{"data":24094,"content":24095,"nodeType":876},{},[24096],{"data":24097,"marks":24098,"value":22820,"nodeType":867},{},[],{"data":24100,"content":24101,"nodeType":876},{},[24102],{"data":24103,"marks":24104,"value":22827,"nodeType":867},{},[],{"data":24106,"content":24109,"nodeType":985},{"target":24107},{"sys":24108},{"id":21583,"type":982,"linkType":983},[],{"data":24111,"content":24112,"nodeType":1058},{},[24113],{"data":24114,"marks":24115,"value":22840,"nodeType":867},{},[24116],{"type":865},{"data":24118,"content":24119,"nodeType":876},{},[24120,24123,24129],{"data":24121,"marks":24122,"value":22847,"nodeType":867},{},[],{"data":24124,"content":24125,"nodeType":915},{"uri":22850},[24126],{"data":24127,"marks":24128,"value":22855,"nodeType":867},{},[],{"data":24130,"marks":24131,"value":22859,"nodeType":867},{},[],{"data":24133,"content":24134,"nodeType":942},{},[],{"data":24136,"content":24137,"nodeType":868},{},[24138],{"data":24139,"marks":24140,"value":14676,"nodeType":867},{},[24141],{"type":865},{"data":24143,"content":24144,"nodeType":876},{},[24145],{"data":24146,"marks":24147,"value":22876,"nodeType":867},{},[],{"data":24149,"content":24150,"nodeType":876},{},[24151],{"data":24152,"marks":24153,"value":22883,"nodeType":867},{},[],{"data":24155,"content":24156,"nodeType":876},{},[24157],{"data":24158,"marks":24159,"value":22890,"nodeType":867},{},[],{"data":24161,"content":24162,"nodeType":876},{},[24163],{"data":24164,"marks":24165,"value":22897,"nodeType":867},{},[],{"data":24167,"content":24168,"nodeType":876},{},[24169,24172,24179,24182,24189],{"data":24170,"marks":24171,"value":14690,"nodeType":867},{},[],{"data":24173,"content":24174,"nodeType":915},{"uri":14693},[24175],{"data":24176,"marks":24177,"value":14699,"nodeType":867},{},[24178],{"type":913},{"data":24180,"marks":24181,"value":21631,"nodeType":867},{},[],{"data":24183,"content":24184,"nodeType":915},{"uri":2689},[24185],{"data":24186,"marks":24187,"value":14723,"nodeType":867},{},[24188],{"type":913},{"data":24190,"marks":24191,"value":1679,"nodeType":867},{},[],{"data":24193,"content":24196,"nodeType":985},{"target":24194},{"sys":24195},{"id":22676,"type":982,"linkType":983},[],{"data":24198,"content":24199,"nodeType":876},{},[24200],{"data":24201,"marks":24202,"value":21,"nodeType":867},{},[],{"entries":24204},{"hyperlink":24205,"inline":24206,"block":24207},[],[],[24208,24210,24214,24220,24247,24253],{"sys":24209,"__typename":21660,"title":21726,"arcadeDemoUrl":21727,"playText":21728},{"id":21583},{"sys":24211,"__typename":1688,"title":24212,"caption":24212,"layoutMode":59,"file":24213},{"id":22512},"Phishing delivery channels have significantly expanded from the days of email-based phishing attacks",{"url":21700,"width":21701,"height":21702},{"sys":24215,"__typename":1688,"title":24216,"caption":24216,"layoutMode":59,"file":24217},{"id":22536},"Examples of ClickFix lures used by attackers in the wild.",{"url":24218,"width":1693,"height":24219},"https://images.ctfassets.net/y1cdw1ablpvd/7AH10e5YpESPdIBIH4YjHO/e7d5553657b6b0f20d6ed563d69af1e4/image3.png",1955,{"sys":24221,"__typename":1705,"content":24222,"name":24246,"title":59},{"id":22630},{"json":24223},{"nodeType":1680,"data":24224,"content":24225},{},[24226],{"nodeType":876,"data":24227,"content":24228},{},[24229,24233,24242],{"nodeType":867,"value":24230,"marks":24231,"data":24232},"Attacks on BYOD or personal devices are increasingly leading to corporate breaches where email accounts are being used to sign into corporate browser profiles. This results in corporate credentials inadvertently saved and synced across devices being exposed in the breach (the most well-known example of this being in ",[],{},{"nodeType":915,"data":24234,"content":24236},{"uri":24235},"https://sec.okta.com/articles/2023/11/unauthorized-access-oktas-support-case-management-system-root-cause/?utm_source=chatgpt.com",[24237],{"nodeType":867,"value":24238,"marks":24239,"data":24241},"Okta’s 2023 support case management system breach",[24240],{"type":913},{},{"nodeType":867,"value":24243,"marks":24244,"data":24245},").",[],{},"clickfix insight box 1",{"sys":24248,"__typename":1697,"type":1698,"ctaText":24249,"buttonLabel":24250,"buttonColour":24251,"buttonUrl":24252},{"id":22676},"Register for our webinar to learn more about the latest developments in ClickFix attacks and why they're so effective.","Register Now","sea blue","https://pushsecurity.com/webinar/clickfix",{"sys":24254,"__typename":1688,"title":24255,"caption":24255,"layoutMode":59,"file":24256},{"id":22753},"ClickFix builder screenshots. Source: Microsoft",{"url":24257,"width":1693,"height":24258},"https://images.ctfassets.net/y1cdw1ablpvd/2adTEIfv1YmEkXzzKA5UFC/47fd4025b72923dd0a1a16eb736e8980/image2.png",540,{"items":24260},[],{},"Detect ClickFix-style attacks in the browser","product-feature",{"items":24265},[24266,24599,25261],{"__typename":1772,"sys":24267,"content":24269,"title":24585,"synopsis":24586,"hashTags":59,"publishedDate":24587,"slug":24588,"tagsCollection":24589,"authorsCollection":24595},{"id":24268},"4bYO5rVy9n2OO3vtMVQeda",{"json":24270},{"data":24271,"content":24272,"nodeType":1680},{},[24273,24280,24298,24314,24321,24328,24331,24338,24345,24398,24405,24411,24414,24421,24428,24435,24442,24449,24466,24472,24479,24486,24503,24509,24516,24523,24530,24537,24544,24547,24554,24573,24579],{"data":24274,"content":24275,"nodeType":868},{},[24276],{"data":24277,"marks":24278,"value":24279,"nodeType":867},{},[],"All phishing eventually leads to the browser",{"data":24281,"content":24282,"nodeType":876},{},[24283,24287,24295],{"data":24284,"marks":24285,"value":24286,"nodeType":867},{},[],"The best attack detection methods are those that focus on ",{"data":24288,"content":24289,"nodeType":915},{"uri":967},[24290],{"data":24291,"marks":24292,"value":24294,"nodeType":867},{},[24293],{"type":913},"detecting indicators that are difficult for attackers to change or obfuscate",{"data":24296,"marks":24297,"value":5704,"nodeType":867},{},[],{"data":24299,"content":24300,"nodeType":876},{},[24301,24305,24310],{"data":24302,"marks":24303,"value":24304,"nodeType":867},{},[],"For a credential phishing attack to succeed, the victim ",{"data":24306,"marks":24307,"value":24309,"nodeType":867},{},[24308],{"type":913},"has",{"data":24311,"marks":24312,"value":24313,"nodeType":867},{},[]," to enter their password into a webpage. There’s no two-ways about it, attackers cannot change this. ",{"data":24315,"content":24316,"nodeType":876},{},[24317],{"data":24318,"marks":24319,"value":24320,"nodeType":867},{},[],"So it stands to reason that, if you can detect this user behavior, and block them from entering their password, then you can stop phishing. ",{"data":24322,"content":24323,"nodeType":876},{},[24324],{"data":24325,"marks":24326,"value":24327,"nodeType":867},{},[],"This is exactly what Push does.",{"data":24329,"content":24330,"nodeType":942},{},[],{"data":24332,"content":24333,"nodeType":1058},{},[24334],{"data":24335,"marks":24336,"value":24337,"nodeType":867},{},[],"Most anti-phishing tools are easily bypassed",{"data":24339,"content":24340,"nodeType":876},{},[24341],{"data":24342,"marks":24343,"value":24344,"nodeType":867},{},[],"Other anti-phishing tools rely on detecting elements of the attack that attackers can change and hide, such as domains or the webpage contents. Attackers use tricks to evade these detection, like:",{"data":24346,"content":24347,"nodeType":1629},{},[24348,24358,24368,24378,24388],{"data":24349,"content":24350,"nodeType":1586},{},[24351],{"data":24352,"content":24353,"nodeType":876},{},[24354],{"data":24355,"marks":24356,"value":24357,"nodeType":867},{},[],"Using Cloudflare Workers to block automatic analysis of their phishing site",{"data":24359,"content":24360,"nodeType":1586},{},[24361],{"data":24362,"content":24363,"nodeType":876},{},[24364],{"data":24365,"marks":24366,"value":24367,"nodeType":867},{},[],"Hacking a Wordpress blog to get a reputable domain that passes domain checks ",{"data":24369,"content":24370,"nodeType":1586},{},[24371],{"data":24372,"content":24373,"nodeType":876},{},[24374],{"data":24375,"marks":24376,"value":24377,"nodeType":867},{},[],"Using redirects and rotating the URLs delivered to the victim to bypass link analysis",{"data":24379,"content":24380,"nodeType":1586},{},[24381],{"data":24382,"content":24383,"nodeType":876},{},[24384],{"data":24385,"marks":24386,"value":24387,"nodeType":867},{},[],"Randomizing the HTML title for the web page to bypass blocklists ",{"data":24389,"content":24390,"nodeType":1586},{},[24391],{"data":24392,"content":24393,"nodeType":876},{},[24394],{"data":24395,"marks":24396,"value":24397,"nodeType":867},{},[],"One-time phishing links that only work the first time they are clicked",{"data":24399,"content":24400,"nodeType":876},{},[24401],{"data":24402,"marks":24403,"value":24404,"nodeType":867},{},[],"Push is putting an end to this game of cat and mouse, by keeping it really simple; you can’t phish someone who can’t put their password into a phishing page. ",{"data":24406,"content":24410,"nodeType":985},{"target":24407},{"sys":24408},{"id":24409,"type":982,"linkType":983},"6AwOZSpqaChmeksnj4SyWE",[],{"data":24412,"content":24413,"nodeType":942},{},[],{"data":24415,"content":24416,"nodeType":1058},{},[24417],{"data":24418,"marks":24419,"value":24420,"nodeType":867},{},[],"Domain-binding passwords",{"data":24422,"content":24423,"nodeType":876},{},[24424],{"data":24425,"marks":24426,"value":24427,"nodeType":867},{},[],"If you’re familiar with how passkeys are domain-bound, then think of what Push does as domain-binding passwords. We pin the password to its legitimate domain(s) and then don’t allow it to be entered into any webpage on any other domain. ",{"data":24429,"content":24430,"nodeType":876},{},[24431],{"data":24432,"marks":24433,"value":24434,"nodeType":867},{},[],"But just because you’ve stopped your users from being phished doesn’t mean you don’t want to know when attackers are attempting to phish your users and how. ",{"data":24436,"content":24437,"nodeType":876},{},[24438],{"data":24439,"marks":24440,"value":24441,"nodeType":867},{},[],"Push still inspects webpages to see if attackers are rendering cloned app login pages in the browser or if known AitM and BitM toolkits are being used. This way you don’t lose visibility of the unsuccessful attacks that are targeting your users. Think of it as a handy second and third layer of defense.",{"data":24443,"content":24444,"nodeType":876},{},[24445],{"data":24446,"marks":24447,"value":24448,"nodeType":867},{},[],"Lets run through a quick before and after example:",{"data":24450,"content":24451,"nodeType":1058},{},[24452,24456,24462],{"data":24453,"marks":24454,"value":24455,"nodeType":867},{},[],"Scenario 1: An attacker attempts to phish an employee that ",{"data":24457,"marks":24458,"value":24461,"nodeType":867},{},[24459,24460],{"type":913},{"type":865},"doesn’t",{"data":24463,"marks":24464,"value":24465,"nodeType":867},{},[]," have Push deployed to their browser.",{"data":24467,"content":24471,"nodeType":985},{"target":24468},{"sys":24469},{"id":24470,"type":982,"linkType":983},"2CbGMUSJsP1mNeHkmpLl6N",[],{"data":24473,"content":24474,"nodeType":876},{},[24475],{"data":24476,"marks":24477,"value":24478,"nodeType":867},{},[],"Here, an attacker hacks a Wordpress blog to get a reputable domain and then runs a phishing toolkit on the webpage. They email one of your employees a link to it. Your SWG / email scanning solution inspects it in a sandbox but the phish kit detects this and redirects to a benign site so that it passes the inspection. ",{"data":24480,"content":24481,"nodeType":876},{},[24482],{"data":24483,"marks":24484,"value":24485,"nodeType":867},{},[],"Your user gets the email with the link and is now free to interact with the phishing page. They enter their credentials plus MFA code into the page and voila! The attacker steals them and is able to compromise the user’s account.  ",{"data":24487,"content":24488,"nodeType":1058},{},[24489,24493,24499],{"data":24490,"marks":24491,"value":24492,"nodeType":867},{},[],"Scenario 2: An attacker attempts to phish an employee that ",{"data":24494,"marks":24495,"value":24498,"nodeType":867},{},[24496,24497],{"type":913},{"type":865},"does",{"data":24500,"marks":24501,"value":24502,"nodeType":867},{},[]," have Push deployed to their browser. ",{"data":24504,"content":24508,"nodeType":985},{"target":24505},{"sys":24506},{"id":24507,"type":982,"linkType":983},"77smnID1woCfFJrJPyTvKY",[],{"data":24510,"content":24511,"nodeType":876},{},[24512],{"data":24513,"marks":24514,"value":24515,"nodeType":867},{},[],"This time, the attacker uses the same phishing toolkit and domain from the first example. But in reality, they don’t have to send it to your employee using email, instead, they could use LinkedIn messenger, Slack, Teams, or any application that allows employees to communicate with each other. ",{"data":24517,"content":24518,"nodeType":876},{},[24519],{"data":24520,"marks":24521,"value":24522,"nodeType":867},{},[],"Like before, the user receives the link, opens it and starts to enter their credentials into the webpage. This time though, the Push browser extension inspects the webpage running in the user's browser. Push observes that the webpage is a login page and the user is entering their password into the page.",{"data":24524,"content":24525,"nodeType":876},{},[24526],{"data":24527,"marks":24528,"value":24529,"nodeType":867},{},[],"The first detection Push makes is checking that the password the user is entering matches the domain that password is pinned to. Since it doesn't match, based on this detection alone the user is automatically redirected to a blocking page. An important point to make here is that the password never leaves the user’s browser and the check is made using a shortened salted hash of the password.   ",{"data":24531,"content":24532,"nodeType":876},{},[24533],{"data":24534,"marks":24535,"value":24536,"nodeType":867},{},[],"The second detection Push makes is that the rendered web app is using a cloned app login page. The third detection is that a phishing toolkit is running in the web app code. ",{"data":24538,"content":24539,"nodeType":876},{},[24540],{"data":24541,"marks":24542,"value":24543,"nodeType":867},{},[],"In this particular scenario these second and third detections serve as useful context for understanding the nature of the phishing attack. But both will still redirect to a blocking page if they are triggered in isolation of the other phishing detections. ",{"data":24545,"content":24546,"nodeType":942},{},[],{"data":24548,"content":24549,"nodeType":868},{},[24550],{"data":24551,"marks":24552,"value":24553,"nodeType":867},{},[],"We don’t just stop phishing attacks",{"data":24555,"content":24556,"nodeType":876},{},[24557,24561,24569],{"data":24558,"marks":24559,"value":24560,"nodeType":867},{},[],"We also detect other identity-related attack techniques used to compromise user accounts. That includes credential stuffing, password spraying and session hijacking using stolen session tokens. If you want to learn more about how Push helps you to detect and defeat common identity attack techniques, ",{"data":24562,"content":24563,"nodeType":915},{"uri":5286},[24564],{"data":24565,"marks":24566,"value":24568,"nodeType":867},{},[24567],{"type":913},"book some time with one of our team",{"data":24570,"marks":24571,"value":24572,"nodeType":867},{},[],".  ",{"data":24574,"content":24578,"nodeType":985},{"target":24575},{"sys":24576},{"id":24577,"type":982,"linkType":983},"2JSmYDaiAciOx7Z1MRuJlA",[],{"data":24580,"content":24581,"nodeType":876},{},[24582],{"data":24583,"marks":24584,"value":21,"nodeType":867},{},[],"Detecting and blocking phishing attacks in the browser","How Push detects and blocks phishing attempts in the browser – explained in less than two minutes. ","2024-10-23T00:00:00.000Z","detecting-and-blocking-phishing-attacks-in-the-browser",{"items":24590},[24591,24593],{"sys":24592,"name":4018},{"id":4017},{"sys":24594,"name":342},{"id":3240},{"items":24596},[24597],{"fullName":4089,"firstName":4090,"jobTitle":851,"profilePicture":24598},{"url":4094},{"__typename":1772,"sys":24600,"content":24602,"title":25247,"synopsis":25248,"hashTags":59,"publishedDate":25249,"slug":25250,"tagsCollection":25251,"authorsCollection":25257},{"id":24601},"wikyVxlHwKUOKM9xo19eP",{"json":24603},{"data":24604,"content":24605,"nodeType":1680},{},[24606,24612,24615,24622,24645,24676,24686,24705,24712,24718,24725,24741,24748,24751,24758,24765,24784,24791,24837,24844,24850,24856,24863,24896,24910,24913,24920,24927,24934,24941,24948,24955,24962,25070,25076,25091,25098,25113,25146,25161,25168,25183,25189,25196,25203,25209,25216,25222,25229],{"data":24607,"content":24611,"nodeType":985},{"target":24608},{"sys":24609},{"id":24610,"type":982,"linkType":983},"1hUpsNwuhEXwSPijvRflTq",[],{"data":24613,"content":24614,"nodeType":942},{},[],{"data":24616,"content":24617,"nodeType":876},{},[24618],{"data":24619,"marks":24620,"value":24621,"nodeType":867},{},[],"There are two things every security operations engineer can agree on:",{"data":24623,"content":24624,"nodeType":1629},{},[24625,24635],{"data":24626,"content":24627,"nodeType":1586},{},[24628],{"data":24629,"content":24630,"nodeType":876},{},[24631],{"data":24632,"marks":24633,"value":24634,"nodeType":867},{},[],"Get MFA on every account on every app.",{"data":24636,"content":24637,"nodeType":1586},{},[24638],{"data":24639,"content":24640,"nodeType":876},{},[24641],{"data":24642,"marks":24643,"value":24644,"nodeType":867},{},[],"This is stupidly harder to achieve than it seems.",{"data":24646,"content":24647,"nodeType":876},{},[24648,24652,24660,24664,24672],{"data":24649,"marks":24650,"value":24651,"nodeType":867},{},[],"The penalties for failing to solve this hard simple problem are abundantly clear. Stolen credentials accounted for roughly half of the initial access methods observed this year across 30,000+ attacks, according to Verizon’s 2024 ",{"data":24653,"content":24654,"nodeType":915},{"uri":2177},[24655],{"data":24656,"marks":24657,"value":24659,"nodeType":867},{},[24658],{"type":913},"Data Breach Investigations Report",{"data":24661,"marks":24662,"value":24663,"nodeType":867},{},[],". And ",{"data":24665,"content":24667,"nodeType":915},{"uri":24666},"https://pushsecurity.com/blog/2024-identity-breaches/",[24668],{"data":24669,"marks":24670,"value":24671,"nodeType":867},{},[],"in a review of 30 publicly disclosed breaches involving identity attacks",{"data":24673,"marks":24674,"value":24675,"nodeType":867},{},[]," in 2024, we found that 73% (almost three-quarters) were the result of compromised credentials, with the rest the result of phishing. ",{"data":24677,"content":24678,"nodeType":3804},{},[24679],{"data":24680,"content":24681,"nodeType":876},{},[24682],{"data":24683,"marks":24684,"value":24685,"nodeType":867},{},[],"Three-quarters of publicly disclosed breaches involving identity attacks in 2024 involved compromised credentials and missing MFA.",{"data":24687,"content":24688,"nodeType":876},{},[24689,24693,24701],{"data":24690,"marks":24691,"value":24692,"nodeType":867},{},[],"In the case of the ",{"data":24694,"content":24695,"nodeType":915},{"uri":6814},[24696],{"data":24697,"marks":24698,"value":24700,"nodeType":867},{},[24699],{"type":913},"Snowflake incident",{"data":24702,"marks":24703,"value":24704,"nodeType":867},{},[]," earlier this year, a lack of MFA meant the difference between an enormous and murky firefight to clean up accounts breached with legitimate credentials, and a decent night’s sleep. The result was hundreds of millions of breached customer records, nine publicly named victims, and at least one ransom paid.",{"data":24706,"content":24707,"nodeType":876},{},[24708],{"data":24709,"marks":24710,"value":24711,"nodeType":867},{},[],"“Do you know how many accounts we have on this third-party service, who owns them, how many tenants, whether those creds are shared elsewhere, and their security posture?” is not a fun question to answer on a Friday. ",{"data":24713,"content":24717,"nodeType":985},{"target":24714},{"sys":24715},{"id":24716,"type":982,"linkType":983},"6hg6PLXWMZaEDnGekHEzmD",[],{"data":24719,"content":24720,"nodeType":876},{},[24721],{"data":24722,"marks":24723,"value":24724,"nodeType":867},{},[],"For SecOps teams we’ve helped here at Push that responded to incidents affecting third-party apps (like Snowflake), the first item on the recovery plan is to finally solve that hard simple problem: No more MFA gaps.",{"data":24726,"content":24727,"nodeType":876},{},[24728,24732,24737],{"data":24729,"marks":24730,"value":24731,"nodeType":867},{},[],"With our latest feature release, ",{"data":24733,"marks":24734,"value":24736,"nodeType":867},{},[24735],{"type":865},"MFA enforcement",{"data":24738,"marks":24739,"value":24740,"nodeType":867},{},[],", this is so much easier. With MFA enforcement, Push administrators can configure a control to prompt employees to enroll in MFA whenever Push detects that they’re not registered — even on apps that don’t natively provide any administrative enforcement option for MFA. This capability is made possible by the Push browser extension, which uses in-browser messaging and simple workflows to guide users right where they work.",{"data":24742,"content":24743,"nodeType":876},{},[24744],{"data":24745,"marks":24746,"value":24747,"nodeType":867},{},[],"In this article, we’ll cover how Push helps you identify and close MFA gaps, how our new enforcement feature is one part of that solution, and how you can test the platform yourself.",{"data":24749,"content":24750,"nodeType":942},{},[],{"data":24752,"content":24753,"nodeType":868},{},[24754],{"data":24755,"marks":24756,"value":24757,"nodeType":867},{},[],"Shining a light on MFA gaps",{"data":24759,"content":24760,"nodeType":876},{},[24761],{"data":24762,"marks":24763,"value":24764,"nodeType":867},{},[],"There’s no question that the rise of ubiquitous multi-factor authentication has been an enormous advance for defenders in cybersecurity. ",{"data":24766,"content":24767,"nodeType":876},{},[24768,24772,24781],{"data":24769,"marks":24770,"value":24771,"nodeType":867},{},[],"Yet several years into this journey, the problem of verifying and enforcing MFA coverage across an organization remains a bit of a ",{"data":24773,"content":24775,"nodeType":915},{"uri":24774},"https://en.wikipedia.org/wiki/Puzzle_box",[24776],{"data":24777,"marks":24778,"value":24780,"nodeType":867},{},[24779],{"type":913},"puzzle box",{"data":24782,"marks":24783,"value":1679,"nodeType":867},{},[],{"data":24785,"content":24786,"nodeType":876},{},[24787],{"data":24788,"marks":24789,"value":24790,"nodeType":867},{},[],"Why is this?",{"data":24792,"content":24793,"nodeType":1629},{},[24794,24804,24814],{"data":24795,"content":24796,"nodeType":1586},{},[24797],{"data":24798,"content":24799,"nodeType":876},{},[24800],{"data":24801,"marks":24802,"value":24803,"nodeType":867},{},[],"Complex overlapping (and occasionally contradictory) configurations for enterprise MFA solutions can result in entire employee groups not registered for MFA, and other critical missing pieces.",{"data":24805,"content":24806,"nodeType":1586},{},[24807],{"data":24808,"content":24809,"nodeType":876},{},[24810],{"data":24811,"marks":24812,"value":24813,"nodeType":867},{},[],"With a sprawling ecosystem of both SSO-managed and unmanaged self-adopted SaaS, MFA coverage ends up looking more like a patchwork than a unified layer of protection. Security teams lack visibility of freemium and self-purchased apps, and when signup is simple, many users will naturally skip MFA registration to remove a layer of friction. The end result is often a suite of core apps managed via SSO that enforce MFA — and a lot of other unmanaged apps that don’t (true nightmare fodder).",{"data":24815,"content":24816,"nodeType":1586},{},[24817],{"data":24818,"content":24819,"nodeType":876},{},[24820,24824,24833],{"data":24821,"marks":24822,"value":24823,"nodeType":867},{},[],"Another annoying piece of the puzzle box: Even in organizations with a high adoption rate of phishing-resistant MFA methods, having backup MFA methods (and a lack of total visibility into all of those registered methods) can create situations where ",{"data":24825,"content":24827,"nodeType":915},{"uri":24826},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/mfa_downgrade/description.md",[24828],{"data":24829,"marks":24830,"value":24832,"nodeType":867},{},[24831],{"type":913},"MFA downgrade attacks",{"data":24834,"marks":24835,"value":24836,"nodeType":867},{},[]," are still possible. In MFA downgrade attacks, backup MFA methods that are less secure such as SMS or TOTP can be exploited, effectively bypassing more phishing-resistant methods.",{"data":24838,"content":24839,"nodeType":876},{},[24840],{"data":24841,"marks":24842,"value":24843,"nodeType":867},{},[],"The challenges of solving this puzzle are evident. ",{"data":24845,"content":24849,"nodeType":985},{"target":24846},{"sys":24847},{"id":24848,"type":982,"linkType":983},"2BBiFx8pHjSCeLTlP6n6da",[],{"data":24851,"content":24855,"nodeType":985},{"target":24852},{"sys":24853},{"id":24854,"type":982,"linkType":983},"2QnWVpPYRyJQaQ5TuKSSLp",[],{"data":24857,"content":24858,"nodeType":876},{},[24859],{"data":24860,"marks":24861,"value":24862,"nodeType":867},{},[],"To shine a light on MFA gaps, then, security teams need three things:",{"data":24864,"content":24865,"nodeType":1629},{},[24866,24876,24886],{"data":24867,"content":24868,"nodeType":1586},{},[24869],{"data":24870,"content":24871,"nodeType":876},{},[24872],{"data":24873,"marks":24874,"value":24875,"nodeType":867},{},[],"A full accounting of their identity attack surface, including accounts on unmanaged and freemium apps not on SSO.",{"data":24877,"content":24878,"nodeType":1586},{},[24879],{"data":24880,"content":24881,"nodeType":876},{},[24882],{"data":24883,"marks":24884,"value":24885,"nodeType":867},{},[],"A trustworthy out-of-band method for verifying MFA coverage, beyond the tangle of conditional access rules.",{"data":24887,"content":24888,"nodeType":1586},{},[24889],{"data":24890,"content":24891,"nodeType":876},{},[24892],{"data":24893,"marks":24894,"value":24895,"nodeType":867},{},[],"Visibility into which MFA methods are registered to a given account.",{"data":24897,"content":24898,"nodeType":876},{},[24899,24903,24907],{"data":24900,"marks":24901,"value":24902,"nodeType":867},{},[],"You can get all three with the Push platform. The missing piece we’ve now added is a way to automatically prompt employees to add MFA wherever it’s missing. Enter ",{"data":24904,"marks":24905,"value":24736,"nodeType":867},{},[24906],{"type":865},{"data":24908,"marks":24909,"value":1679,"nodeType":867},{},[],{"data":24911,"content":24912,"nodeType":942},{},[],{"data":24914,"content":24915,"nodeType":868},{},[24916],{"data":24917,"marks":24918,"value":24919,"nodeType":867},{},[],"How Push helps you ensure MFA coverage",{"data":24921,"content":24922,"nodeType":876},{},[24923],{"data":24924,"marks":24925,"value":24926,"nodeType":867},{},[],"Let’s take a look at a hypothetical incident response scenario to see how Push’s identity visibility and security controls help you ensure MFA coverage.",{"data":24928,"content":24929,"nodeType":876},{},[24930],{"data":24931,"marks":24932,"value":24933,"nodeType":867},{},[],"We’ll assume that prior to this incident, you had already deployed the Push browser extension, which you can install and enforce using any MDM solution, on all major browsers.",{"data":24935,"content":24936,"nodeType":876},{},[24937],{"data":24938,"marks":24939,"value":24940,"nodeType":867},{},[],"It’s a Friday afternoon (sorry).",{"data":24942,"content":24943,"nodeType":876},{},[24944],{"data":24945,"marks":24946,"value":24947,"nodeType":867},{},[],"News breaks that there’s been a suspected breach at a popular enterprise SaaS service.",{"data":24949,"content":24950,"nodeType":876},{},[24951],{"data":24952,"marks":24953,"value":24954,"nodeType":867},{},[],"You’re familiar with the service, but you don’t believe it’s a core managed app at your organization. Unfortunately, that does not mean you don’t have accounts (sorry again).",{"data":24956,"content":24957,"nodeType":876},{},[24958],{"data":24959,"marks":24960,"value":24961,"nodeType":867},{},[],"Using Push, you can:",{"data":24963,"content":24964,"nodeType":1629},{},[24965,24984,24994,25021,25048],{"data":24966,"content":24967,"nodeType":1586},{},[24968],{"data":24969,"content":24970,"nodeType":876},{},[24971,24975,24980],{"data":24972,"marks":24973,"value":24974,"nodeType":867},{},[],"Immediately check whether the Push extension has observed employee usage of the breached app. It will appear on the ",{"data":24976,"marks":24977,"value":24979,"nodeType":867},{},[24978],{"type":865},"Apps",{"data":24981,"marks":24982,"value":24983,"nodeType":867},{},[]," table. From this overview, you can see how many accounts Push has seen on that app and how they are accessing it (SSO vs. other methods, such as local password login).",{"data":24985,"content":24986,"nodeType":1586},{},[24987],{"data":24988,"content":24989,"nodeType":876},{},[24990],{"data":24991,"marks":24992,"value":24993,"nodeType":867},{},[],"For those accounts on the breached app, you can quickly see whether they have MFA, and which methods are registered. To determine MFA status, the Push extension uses the existing user’s active session on an app to query that account’s MFA registration status using the app’s own API, providing a trustworthy verification. ",{"data":24995,"content":24996,"nodeType":1586},{},[24997],{"data":24998,"content":24999,"nodeType":876},{},[25000,25004,25009,25013,25018],{"data":25001,"marks":25002,"value":25003,"nodeType":867},{},[],"You can also see whether the users’ passwords have any security issues, such as a verified stolen credential, or a password that’s weak or reused by filtering the ",{"data":25005,"marks":25006,"value":25008,"nodeType":867},{},[25007],{"type":865},"Accounts",{"data":25010,"marks":25011,"value":25012,"nodeType":867},{},[]," list for ",{"data":25014,"marks":25015,"value":25017,"nodeType":867},{},[25016],{"type":865},"Findings",{"data":25019,"marks":25020,"value":1679,"nodeType":867},{},[],{"data":25022,"content":25023,"nodeType":1586},{},[25024],{"data":25025,"content":25026,"nodeType":876},{},[25027,25031,25035,25039,25044],{"data":25028,"marks":25029,"value":25030,"nodeType":867},{},[],"For accounts that lack MFA, you can then configure the ",{"data":25032,"marks":25033,"value":24736,"nodeType":867},{},[25034],{"type":865},{"data":25036,"marks":25037,"value":25038,"nodeType":867},{},[]," control from the ",{"data":25040,"marks":25041,"value":25043,"nodeType":867},{},[25042],{"type":865},"Controls",{"data":25045,"marks":25046,"value":25047,"nodeType":867},{},[]," page. This will prompt employees who lack MFA to set it up whenever they next use the app. In parallel, you can reach out to affected employees through your preferred comms channel and ask them to immediately register for MFA and change their password on the app. ",{"data":25049,"content":25050,"nodeType":1586},{},[25051],{"data":25052,"content":25053,"nodeType":876},{},[25054,25058,25067],{"data":25055,"marks":25056,"value":25057,"nodeType":867},{},[],"Then use Push’s webhooks to monitor for MFA registrations and password changes to roll in, by querying the ",{"data":25059,"content":25061,"nodeType":915},{"uri":25060},"https://pushsecurity.redoc.ly/webhooks-v1#operation/login-event",[25062],{"data":25063,"marks":25064,"value":25066,"nodeType":867},{},[25065],{"type":913},"Login event",{"data":25068,"marks":25069,"value":1679,"nodeType":867},{},[],{"data":25071,"content":25075,"nodeType":985},{"target":25072},{"sys":25073},{"id":25074,"type":982,"linkType":983},"4OVJU6FRSVU9j1WB9NGyJ4",[],{"data":25077,"content":25078,"nodeType":876},{},[25079,25083,25087],{"data":25080,"marks":25081,"value":25082,"nodeType":867},{},[],"By combining visibility of your workforce identities — including granular context on their MFA registration status, MFA methods, and password security, even on unmanaged apps — with in-browser controls like ",{"data":25084,"marks":25085,"value":24736,"nodeType":867},{},[25086],{"type":865},{"data":25088,"marks":25089,"value":25090,"nodeType":867},{},[],", Push helps security teams respond quickly and with assurance that they have the right information and tools to remediate the issue.",{"data":25092,"content":25093,"nodeType":868},{},[25094],{"data":25095,"marks":25096,"value":25097,"nodeType":867},{},[],"A closer look at MFA enforcement",{"data":25099,"content":25100,"nodeType":876},{},[25101,25105,25109],{"data":25102,"marks":25103,"value":25104,"nodeType":867},{},[],"With the in-browser ",{"data":25106,"marks":25107,"value":24736,"nodeType":867},{},[25108],{"type":865},{"data":25110,"marks":25111,"value":25112,"nodeType":867},{},[]," control, we chose this approach to close the loop on missing MFA issues because:",{"data":25114,"content":25115,"nodeType":1629},{},[25116,25126,25136],{"data":25117,"content":25118,"nodeType":1586},{},[25119],{"data":25120,"content":25121,"nodeType":876},{},[25122],{"data":25123,"marks":25124,"value":25125,"nodeType":867},{},[],"It meets users where they are, in the most relevant context where they can successfully address the issue.",{"data":25127,"content":25128,"nodeType":1586},{},[25129],{"data":25130,"content":25131,"nodeType":876},{},[25132],{"data":25133,"marks":25134,"value":25135,"nodeType":867},{},[],"It solves the problem of enforcing MFA on apps that are outside of administrative control — or that don’t provide any administrative controls to enforce MFA registration natively.",{"data":25137,"content":25138,"nodeType":1586},{},[25139],{"data":25140,"content":25141,"nodeType":876},{},[25142],{"data":25143,"marks":25144,"value":25145,"nodeType":867},{},[],"It’s tenant-agnostic. That means that you can enforce MFA for a given app on all tenants of that app, even those free-tier or test tenants that you don’t know about and have no control over.",{"data":25147,"content":25148,"nodeType":876},{},[25149,25153,25157],{"data":25150,"marks":25151,"value":25152,"nodeType":867},{},[],"As a happy side effect, your compliance team will thank you for finally allowing them to attest to where MFA is ",{"data":25154,"marks":25155,"value":22967,"nodeType":867},{},[25156],{"type":1303},{"data":25158,"marks":25159,"value":25160,"nodeType":867},{},[]," enforced — with verified results, visible at the account level in Push’s admin reporting — across your environment.",{"data":25162,"content":25163,"nodeType":876},{},[25164],{"data":25165,"marks":25166,"value":25167,"nodeType":867},{},[],"Here’s a closer look at how it works:",{"data":25169,"content":25170,"nodeType":876},{},[25171,25175,25179],{"data":25172,"marks":25173,"value":25174,"nodeType":867},{},[],"To enable MFA enforcement, use the configuration tile on the ",{"data":25176,"marks":25177,"value":25043,"nodeType":867},{},[25178],{"type":865},{"data":25180,"marks":25181,"value":25182,"nodeType":867},{},[]," page of the Push admin console and select which apps should require MFA registration. The control currently works with ~90 high-value apps, including Postman, Retool, Datadog, Atlassian, Okta, and others.",{"data":25184,"content":25188,"nodeType":985},{"target":25185},{"sys":25186},{"id":25187,"type":982,"linkType":983},"2sDbYZL4oJDxLMbYErJfIN",[],{"data":25190,"content":25191,"nodeType":876},{},[25192],{"data":25193,"marks":25194,"value":25195,"nodeType":867},{},[],"You can then customize the message the employees will see.",{"data":25197,"content":25198,"nodeType":876},{},[25199],{"data":25200,"marks":25201,"value":25202,"nodeType":867},{},[],"On the end-user side, employees will see a banner with your message as soon as they use an app where they lack MFA. ",{"data":25204,"content":25208,"nodeType":985},{"target":25205},{"sys":25206},{"id":25207,"type":982,"linkType":983},"37aH1maXXkF8DxgjUod5dn",[],{"data":25210,"content":25211,"nodeType":876},{},[25212],{"data":25213,"marks":25214,"value":25215,"nodeType":867},{},[],"To complete MFA registration, the user can go directly to the app’s MFA registration page from a link in the banner (Push provides this link automatically, where one exists). The extension will query the user’s MFA status regularly in the background and when MFA registration is completed, the banner will disappear and the Push platform will clear the “No MFA” security finding for that account.",{"data":25217,"content":25221,"nodeType":985},{"target":25218},{"sys":25219},{"id":25220,"type":982,"linkType":983},"3yb4KjhH3AbvvSnfMbNONr",[],{"data":25223,"content":25224,"nodeType":868},{},[25225],{"data":25226,"marks":25227,"value":25228,"nodeType":867},{},[],"Find out more",{"data":25230,"content":25231,"nodeType":876},{},[25232,25236,25243],{"data":25233,"marks":25234,"value":25235,"nodeType":867},{},[],"To test our MFA visibility and control features, ",{"data":25237,"content":25238,"nodeType":915},{"uri":18350},[25239],{"data":25240,"marks":25241,"value":25242,"nodeType":867},{},[],"request a demo",{"data":25244,"marks":25245,"value":25246,"nodeType":867},{},[]," from our team. We look forward to helping you finally turn the challenge of MFA coverage into a simple problem, easily solved.","No more hard simple problems: Enforce MFA on third-party apps with Push","Using Push to enforce MFA on third-party apps in the browser — even where MFA enforcement isn't supported by the app itself.","2025-01-16T00:00:00.000Z","enforce-mfa-on-third-party-apps",{"items":25252},[25253,25255],{"sys":25254,"name":297},{"id":2706},{"sys":25256,"name":342},{"id":3240},{"items":25258},[25259],{"fullName":2714,"firstName":2715,"jobTitle":851,"profilePicture":25260},{"url":2717},{"__typename":1772,"sys":25262,"content":25264,"title":25750,"synopsis":25751,"hashTags":59,"publishedDate":25752,"slug":25753,"tagsCollection":25754,"authorsCollection":25760},{"id":25263},"6jYmU1ROpwI41mmzk7ioKd",{"json":25265},{"data":25266,"content":25267,"nodeType":1680},{},[25268,25275,25282,25285,25292,25326,25338,25363,25370,25373,25380,25387,25394,25400,25407,25437,25443,25450,25470,25476,25483,25489,25492,25499,25535,25542,25585,25592,25598,25605,25612,25615,25622,25629,25636,25656,25662,25669,25676,25683,25689,25696,25702,25705,25712,25719,25726],{"data":25269,"content":25270,"nodeType":876},{},[25271],{"data":25272,"marks":25273,"value":25274,"nodeType":867},{},[],"After more than two decades in cybersecurity, I’ve witnessed the evolution (and at times, devolution) of detection and response capabilities. I’ve sat in countless SOCs watching analysts drown in a sea of alerts, spent hours chasing false positives, and seen talented security professionals burn out from the relentless noise of low-fidelity detection systems. ",{"data":25276,"content":25277,"nodeType":876},{},[25278],{"data":25279,"marks":25280,"value":25281,"nodeType":867},{},[],"It’s a problem that’s reached crisis proportions, and it’s exactly why our approach to browser security represents not just a technological shift, but a philosophical one.",{"data":25283,"content":25284,"nodeType":942},{},[],{"data":25286,"content":25287,"nodeType":868},{},[25288],{"data":25289,"marks":25290,"value":25291,"nodeType":867},{},[],"The alert fatigue epidemic",{"data":25293,"content":25294,"nodeType":876},{},[25295,25299,25304,25308,25313,25317,25322],{"data":25296,"marks":25297,"value":25298,"nodeType":867},{},[],"Early in my career, getting ",{"data":25300,"marks":25301,"value":25303,"nodeType":867},{},[25302],{"type":1303},"any",{"data":25305,"marks":25306,"value":25307,"nodeType":867},{},[]," alert felt like a victory. We were flying blind outside of our small windows of network traffic. But as the industry matured, something troubling happened: we began equating ",{"data":25309,"marks":25310,"value":25312,"nodeType":867},{},[25311],{"type":865},"volume",{"data":25314,"marks":25315,"value":25316,"nodeType":867},{},[]," with ",{"data":25318,"marks":25319,"value":25321,"nodeType":867},{},[25320],{"type":865},"value",{"data":25323,"marks":25324,"value":25325,"nodeType":867},{},[],". Vendors started competing on how many alerts they could generate, how much data they could collect, and how comprehensive their “visibility” could be. ",{"data":25327,"content":25328,"nodeType":876},{},[25329,25333],{"data":25330,"marks":25331,"value":25332,"nodeType":867},{},[],"Security teams followed suit with operational metrics that captured how many alerts they’d resolved, how many “attacks” they’d stopped, and how many tickets they’d opened and closed in a given work cycle. But as many teams have now realized, ",{"data":25334,"marks":25335,"value":25337,"nodeType":867},{},[25336],{"type":865},"volume is a vanity metric; fidelity is what keeps you safe.",{"data":25339,"content":25340,"nodeType":876},{},[25341,25345,25354,25358],{"data":25342,"marks":25343,"value":25344,"nodeType":867},{},[],"In my course on ",{"data":25346,"content":25348,"nodeType":915},{"uri":25347},"https://www.sans.org/cyber-security-courses/building-leading-security-operations-centers",[25349],{"data":25350,"marks":25351,"value":25353,"nodeType":867},{},[25352],{"type":913},"Building and Leading Security Operations teams",{"data":25355,"marks":25356,"value":25357,"nodeType":867},{},[],", we discuss the importance of analytic outcomes and addressing ineffective alerts to continuously improve fidelity. My students often find it hard to believe how much time and effort it takes to audit alert quality and implement continuous improvements on a large scale. This isn’t just an operational problem — it’s an existential threat to effective security. ",{"data":25359,"marks":25360,"value":25362,"nodeType":867},{},[25361],{"type":865},"When everything is an alert, nothing is. ",{"data":25364,"content":25365,"nodeType":876},{},[25366],{"data":25367,"marks":25368,"value":25369,"nodeType":867},{},[],"And while we have been busy focusing on more (and occasionally, better) detections at the endpoint and network layers, attackers have shifted to infrastructure that isn’t as well-instrumented: SaaS and the browser.",{"data":25371,"content":25372,"nodeType":942},{},[],{"data":25374,"content":25375,"nodeType":868},{},[25376],{"data":25377,"marks":25378,"value":25379,"nodeType":867},{},[],"The browser: a new frontier in detection and response",{"data":25381,"content":25382,"nodeType":876},{},[25383],{"data":25384,"marks":25385,"value":25386,"nodeType":867},{},[],"Today, the browser is the place where most cyber attacks happen. It’s where users interact with the applications that your business runs on, handle sensitive data, and unfortunately, where they encounter sophisticated phishing campaigns, credential harvesting attacks, and malicious downloads. ",{"data":25388,"content":25389,"nodeType":876},{},[25390],{"data":25391,"marks":25392,"value":25393,"nodeType":867},{},[],"Yet for most security teams, the browser remains a black box, obscured from the view from the network and the endpoint. Even worse, attack models often applied to detection engineering for endpoint or network-centric threats don’t really apply; modern identity attacks skip entire phases of the attack chain, eliminating many detection opportunities along the way. The modern attack path doesn’t need to touch the endpoint or your network at all — it can happen entirely over the internet. ",{"data":25395,"content":25399,"nodeType":985},{"target":25396},{"sys":25397},{"id":25398,"type":982,"linkType":983},"4wYYgbKmmVAZTF7niXJEGc",[],{"data":25401,"content":25402,"nodeType":1058},{},[25403],{"data":25404,"marks":25405,"value":25406,"nodeType":867},{},[],"Attackers are exploiting the detection gap",{"data":25408,"content":25409,"nodeType":876},{},[25410,25414,25421,25425,25433],{"data":25411,"marks":25412,"value":25413,"nodeType":867},{},[],"You only need to look at in-the-wild breaches such as last year’s ",{"data":25415,"content":25416,"nodeType":915},{"uri":6814},[25417],{"data":25418,"marks":25419,"value":23019,"nodeType":867},{},[25420],{"type":913},{"data":25422,"marks":25423,"value":25424,"nodeType":867},{},[]," attacks, or the recent ",{"data":25426,"content":25427,"nodeType":915},{"uri":15683},[25428],{"data":25429,"marks":25430,"value":25432,"nodeType":867},{},[25431],{"type":913},"Salesforce",{"data":25434,"marks":25435,"value":25436,"nodeType":867},{},[]," breaches to see the impact that attackers can have by executing attacks entirely over the internet, without touching traditional network devices or user endpoints. ",{"data":25438,"content":25442,"nodeType":985},{"target":25439},{"sys":25440},{"id":25441,"type":982,"linkType":983},"VfTps3SGKJDlhFcmh42d9",[],{"data":25444,"content":25445,"nodeType":876},{},[25446],{"data":25447,"marks":25448,"value":25449,"nodeType":867},{},[],"But even in the context of more “conventional” attacks (e.g. the classic route of compromising an endpoint, moving laterally through an environment, taking control of a domain, and deploying ransomware), most of the time, these attacks begin in the browser with identities and cloud apps rather than exploit-driven initial access — such as with the recent attacks on Marks & Spencer, Co-op, and Jaguar Land Rover. ",{"data":25451,"content":25452,"nodeType":876},{},[25453,25457,25466],{"data":25454,"marks":25455,"value":25456,"nodeType":867},{},[],"While the ",{"data":25458,"content":25460,"nodeType":915},{"uri":25459},"https://cloud.google.com/security/resources/insights/targeted-attack-lifecycle",[25461],{"data":25462,"marks":25463,"value":25465,"nodeType":867},{},[25464],{"type":913},"attack cycle",{"data":25467,"marks":25468,"value":25469,"nodeType":867},{},[]," and similar mental models are valuable for planning in-depth detections of sophisticated, multi-stage attacks, focusing too heavily on them can lead to overlooked scenarios. These high-profile incidents have demonstrated the opportunity cost of neglecting visibility into attacks that don't perfectly align with these models. ",{"data":25471,"content":25475,"nodeType":985},{"target":25472},{"sys":25473},{"id":25474,"type":982,"linkType":983},"3TsKtoWuxQMFl1xd3w1j86",[],{"data":25477,"content":25478,"nodeType":876},{},[25479],{"data":25480,"marks":25481,"value":25482,"nodeType":867},{},[],"Just as endpoint detection and response revolutionized host-based security by providing visibility and control directly at the point of attack, browser-based security platforms can do the same for web-borne threats. It’s an important addition to the detection and response stack that illuminates a “missing middle” in modern attack investigations, and intervenes in real time, much like traditional EDR did for the endpoint years ago.",{"data":25484,"content":25488,"nodeType":985},{"target":25485},{"sys":25486},{"id":25487,"type":982,"linkType":983},"1eCXGC6U6SdzHmOH1gv24O",[],{"data":25490,"content":25491,"nodeType":942},{},[],{"data":25493,"content":25494,"nodeType":868},{},[25495],{"data":25496,"marks":25497,"value":25498,"nodeType":867},{},[],"High-fidelity detection: quality over quantity",{"data":25500,"content":25501,"nodeType":876},{},[25502,25506,25513,25517,25522,25526,25531],{"data":25503,"marks":25504,"value":25505,"nodeType":867},{},[],"Our ",{"data":25507,"content":25508,"nodeType":915},{"uri":967},[25509],{"data":25510,"marks":25511,"value":25512,"nodeType":867},{},[],"design philosophy",{"data":25514,"marks":25515,"value":25516,"nodeType":867},{},[]," centers on a principle often overlooked in the security industry: prioritizing actionable problems for security teams. This involves differentiating between \"",{"data":25518,"marks":25519,"value":25521,"nodeType":867},{},[25520],{"type":865},"events",{"data":25523,"marks":25524,"value":25525,"nodeType":867},{},[],"\" – environment data that may or may not be useful – and \"",{"data":25527,"marks":25528,"value":25530,"nodeType":867},{},[25529],{"type":865},"detections",{"data":25532,"marks":25533,"value":25534,"nodeType":867},{},[],"\" – high-fidelity, actionable signals with a negligible false positive rate. We also empower our customers with the ability to intervene in real-time when there are high-confidence indicators of an attack. We focus on detecting not atomic indicators, but on attacker tooling and behaviors.",{"data":25536,"content":25537,"nodeType":876},{},[25538],{"data":25539,"marks":25540,"value":25541,"nodeType":867},{},[],"Compare this to traditional approaches that might generate alerts for:",{"data":25543,"content":25544,"nodeType":1629},{},[25545,25555,25565,25575],{"data":25546,"content":25547,"nodeType":1586},{},[25548],{"data":25549,"content":25550,"nodeType":876},{},[25551],{"data":25552,"marks":25553,"value":25554,"nodeType":867},{},[],"Visiting domains with low reputation scores (but not necessarily malicious)",{"data":25556,"content":25557,"nodeType":1586},{},[25558],{"data":25559,"content":25560,"nodeType":876},{},[25561],{"data":25562,"marks":25563,"value":25564,"nodeType":867},{},[],"Downloading files that match certain heuristics (but may be legitimate)",{"data":25566,"content":25567,"nodeType":1586},{},[25568],{"data":25569,"content":25570,"nodeType":876},{},[25571],{"data":25572,"marks":25573,"value":25574,"nodeType":867},{},[],"Accessing new web applications (that may be approved, or tacitly allowed, shadow IT)",{"data":25576,"content":25577,"nodeType":1586},{},[25578],{"data":25579,"content":25580,"nodeType":876},{},[25581],{"data":25582,"marks":25583,"value":25584,"nodeType":867},{},[],"Employee usernames, passwords, and email addresses for sale on the dark web (which may no longer be valid)",{"data":25586,"content":25587,"nodeType":876},{},[25588],{"data":25589,"marks":25590,"value":25591,"nodeType":867},{},[],"These low-fidelity alerts create work without providing solutions. They force analysts to become investigators rather than responders, spending precious time determining whether an alert represents a genuine threat rather than focusing on mitigation and recovery. ",{"data":25593,"content":25597,"nodeType":985},{"target":25594},{"sys":25595},{"id":25596,"type":982,"linkType":983},"4MydcqvHnWsziCOPUNC3YS",[],{"data":25599,"content":25600,"nodeType":876},{},[25601],{"data":25602,"marks":25603,"value":25604,"nodeType":867},{},[],"Poor quality detections also present an easy opportunity for security teams to commit a cardinal sin: disrupting users and business processes without a clear justification for doing so. User trust and support should always be treated as a finite resource, and every account locked, website blocked, and laptop reimaged chips away at that resource. ",{"data":25606,"content":25607,"nodeType":876},{},[25608],{"data":25609,"marks":25610,"value":25611,"nodeType":867},{},[],"Likewise, the more disruptive, the more likely users will look for ways around said controls. If your users are actively working against you, and feel you are preventing them from doing their jobs, they’ll always find new and unexpected ways around security blocks. ",{"data":25613,"content":25614,"nodeType":942},{},[],{"data":25616,"content":25617,"nodeType":868},{},[25618],{"data":25619,"marks":25620,"value":25621,"nodeType":867},{},[],"The SOC analyst's perspective",{"data":25623,"content":25624,"nodeType":876},{},[25625],{"data":25626,"marks":25627,"value":25628,"nodeType":867},{},[],"The most successful SOC analysts share a common trait: they’re extraordinarily good at quickly distinguishing signal from noise. But this skill shouldn’t be required! It’s a failure of our detection systems that we’re forcing human analysts to perform pattern matching that our technology should handle. ",{"data":25630,"content":25631,"nodeType":876},{},[25632],{"data":25633,"marks":25634,"value":25635,"nodeType":867},{},[],"But even for the most skilled analyst, it’s a tall order to ask your security team to also be experts in every cloud app your business relies on, making it even harder than normal to build context-driven alerts. Most of the time, the information required simply doesn't exist, with logs simply not available (generally, or at your product tier) or the work required to extract the logs and turn them into context-driven alerts hasn’t happened yet. If your team is under-resourced and drowning in low-fidelity alerts already, then realistically it might never happen. ",{"data":25637,"content":25638,"nodeType":876},{},[25639,25643,25652],{"data":25640,"marks":25641,"value":25642,"nodeType":867},{},[],"Effective browser security changes this dynamic. Instead of presenting analysts with hundreds of “suspicious web activity” alerts that require investigation, ",{"data":25644,"content":25646,"nodeType":915},{"uri":25645},"https://pushsecurity.com/blog/detecting-and-blocking-phishing-attacks-in-the-browser/",[25647],{"data":25648,"marks":25649,"value":25651,"nodeType":867},{},[25650],{"type":913},"our platform focuses on high-reliability indicators",{"data":25653,"marks":25654,"value":25655,"nodeType":867},{},[]," like whether a phishing kit was observed running on the page, or whether the page was cloned from a legitimate site. We even detect user behaviors that could indicate a risk in the context of a phishing attack, like when a user attempts to authenticate with credentials that have been previously used on another page — either a sign of credential reuse (bad) or a phishing attack (even worse) — at which point Push can be set to block the attack in real time. ",{"data":25657,"content":25661,"nodeType":985},{"target":25658},{"sys":25659},{"id":25660,"type":982,"linkType":983},"3998Iy2kp9MW0HFeqmo900",[],{"data":25663,"content":25664,"nodeType":1058},{},[25665],{"data":25666,"marks":25667,"value":25668,"nodeType":867},{},[],"Browser security provides a new layer of protection, reducing the risk of breach",{"data":25670,"content":25671,"nodeType":876},{},[25672],{"data":25673,"marks":25674,"value":25675,"nodeType":867},{},[],"Attack detection has always been a cat-and-mouse game. For years, attackers have grappled with endpoint and network security vendors. And sometimes, the attackers win. The fact is that a lot of attacker innovation has gone into sandbox aware malware, breaking detection signatures, disabling security tools, and so on.    ",{"data":25677,"content":25678,"nodeType":876},{},[25679],{"data":25680,"marks":25681,"value":25682,"nodeType":867},{},[],"But with so many attacks now passing through the browser, defending it enables badness to be filtered out before it reaches the endpoint or network controls that attackers are looking to consciously evade. By preventing malware being delivered, or identities from being compromised, attacks otherwise crafted to evade traditional security controls can be intercepted early — making the crucial difference in whether a breach happens or not.",{"data":25684,"content":25688,"nodeType":985},{"target":25685},{"sys":25686},{"id":25687,"type":982,"linkType":983},"4Bh7uOkeguNJFmJ1XUQ317",[],{"data":25690,"content":25691,"nodeType":876},{},[25692],{"data":25693,"marks":25694,"value":25695,"nodeType":867},{},[],"And when it comes to the cloud-centric attacks that attackers are finding so much success with today, this is in effect a net new capability. ",{"data":25697,"content":25701,"nodeType":985},{"target":25698},{"sys":25699},{"id":25700,"type":982,"linkType":983},"4JdaY8I3f6Ub2Kifc9Rsj9",[],{"data":25703,"content":25704,"nodeType":942},{},[],{"data":25706,"content":25707,"nodeType":868},{},[25708],{"data":25709,"marks":25710,"value":25711,"nodeType":867},{},[],"Learn more about Push Security",{"data":25713,"content":25714,"nodeType":876},{},[25715],{"data":25716,"marks":25717,"value":25718,"nodeType":867},{},[],"The browser represents one of the most significant opportunities in cybersecurity today. As we continue to expand our browser-based security capabilities, we remain committed to this high-fidelity approach. We’re building features that not only detect and prevent attacks but also provide security teams with the rich telemetry they need to develop custom queries and detections.",{"data":25720,"content":25721,"nodeType":876},{},[25722],{"data":25723,"marks":25724,"value":25725,"nodeType":867},{},[],"Push Security’s browser-based security platform provides comprehensive detection and response capabilities against techniques like AiTM phishing, credential stuffing, ClickFixing, malicious browser extensions, and session hijacking using stolen session tokens. You can also use Push to find and fix vulnerabilities across the apps that your employees use, like ghost logins, SSO coverage gaps, MFA gaps, vulnerable passwords, risky OAuth integrations, and more to harden your identity attack surface.",{"data":25727,"content":25728,"nodeType":876},{},[25729,25732,25738,25741,25747],{"data":25730,"marks":25731,"value":14690,"nodeType":867},{},[],{"data":25733,"content":25734,"nodeType":915},{"uri":14693},[25735],{"data":25736,"marks":25737,"value":14699,"nodeType":867},{},[],{"data":25739,"marks":25740,"value":21631,"nodeType":867},{},[],{"data":25742,"content":25743,"nodeType":915},{"uri":2689},[25744],{"data":25745,"marks":25746,"value":14723,"nodeType":867},{},[],{"data":25748,"marks":25749,"value":1679,"nodeType":867},{},[],"Fixing SecOps alert fatigue with browser telemetry","How browser data can improve detection fidelity and reduce alert fatigue, enabling SecOps teams to save time and detect more attacks.","2025-10-07T00:00:00.000Z","fixing-secops-alert-fatigue-with-browser-telemetry",{"items":25755},[25756,25758],{"sys":25757,"name":342},{"id":3240},{"sys":25759,"name":4018},{"id":4017},{"items":25761},[25762],{"fullName":3244,"firstName":3245,"jobTitle":3246,"profilePicture":25763},{"url":3248},"blog/introducing-malicious-copy-paste-detection","Detect ClickFix-style attacks where users copy malicious scripts from their browser.",{"json":25767},{"data":25768,"content":25769,"nodeType":1680},{},[25770],{"data":25771,"content":25772,"nodeType":876},{},[25773],{"data":25774,"marks":25775,"value":25776,"nodeType":867},{},[],"ClickFix, FileFix, fake CAPTCHA — whatever you call it, users interacting with malicious scripts in their web browser is a fast-growing source of security breaches. To tackle this threat, Push now detects malware delivery in the browser, supporting a layered defense against endpoint attacks. ",{"id":22315,"publishedAt":25778},"2026-08-12T11:53:43.034Z",{"items":25780},[25781,25783],{"sys":25782,"name":342},{"id":3240},{"sys":25784,"name":4018},{"id":4017},{"items":25786},[25787,25789,25791,25793,25795,25797,25799,25801,25803,25805,25807,25809,25811,25813],{"sys":25788,"name":279,"slug":280,"tier":31},{"id":276},{"sys":25790,"name":342,"slug":343,"tier":31},{"id":339},{"sys":25792,"name":297,"slug":298,"tier":31},{"id":294},{"sys":25794,"name":519,"slug":520,"tier":31},{"id":516},{"sys":25796,"name":642,"slug":643,"tier":31},{"id":639},{"sys":25798,"name":315,"slug":316,"tier":45},{"id":312},{"sys":25800,"name":448,"slug":449,"tier":45},{"id":445},{"sys":25802,"name":377,"slug":378,"tier":45},{"id":374},{"sys":25804,"name":607,"slug":608,"tier":45},{"id":604},{"sys":25806,"name":475,"slug":476,"tier":45},{"id":472},{"sys":25808,"name":440,"slug":441,"tier":45},{"id":437},{"sys":25810,"name":422,"slug":423,"tier":45},{"id":419},{"sys":25812,"name":537,"slug":538,"tier":45},{"id":534},{"sys":25814,"name":351,"slug":352,"tier":45},{"id":348},"WhJoIJQgr5uOa_CBJjozZ6Xe_GSP57ObHYXigZLLKo0",{"id":25817,"title":25818,"authorsCollection":25819,"content":25824,"extension":228,"faqItemsCollection":26657,"faqTitle":59,"featured":6,"hashTags":59,"meta":26659,"metaTitle":26660,"ogImage":59,"postType":1767,"publishedDate":26661,"relatedBlogPostsCollection":26662,"slug":28597,"stem":28598,"subtitle":59,"summary":28599,"synopsis":28609,"sys":28610,"tagsCollection":28613,"topicsCollection":28619,"__hash__":28671},"blog/blog/how-the-browser-became-the-main-cyber-battleground.json","How the browser became the main cyber battleground",{"items":25820},[25821],{"fullName":4022,"firstName":4023,"jobTitle":4024,"socialLinks":25822,"profilePicture":25823},[21074],{"url":4026},{"json":25825,"links":26602},{"data":25826,"content":25827,"nodeType":1680},{},[25828,25835,25868,25875,25881,25888,25920,25927,25933,25936,25944,25951,25958,26015,26033,26045,26052,26058,26061,26069,26085,26091,26098,26104,26111,26148,26154,26157,26165,26172,26179,26304,26310,26341,26348,26351,26359,26366,26373,26414,26443,26450,26526,26532,26535,26542,26549,26569,26572,26579,26586],{"data":25829,"content":25830,"nodeType":876},{},[25831],{"data":25832,"marks":25833,"value":25834,"nodeType":867},{},[],"Until recently, the cyber attacker methodology behind the biggest breaches of the last decade or so has been pretty consistent:",{"data":25836,"content":25837,"nodeType":1629},{},[25838,25848,25858],{"data":25839,"content":25840,"nodeType":1586},{},[25841],{"data":25842,"content":25843,"nodeType":876},{},[25844],{"data":25845,"marks":25846,"value":25847,"nodeType":867},{},[],"Compromise an endpoint via software exploit, or social engineering a user to run malware on their device; ",{"data":25849,"content":25850,"nodeType":1586},{},[25851],{"data":25852,"content":25853,"nodeType":876},{},[25854],{"data":25855,"marks":25856,"value":25857,"nodeType":867},{},[],"Find ways to move laterally inside the network and compromise privileged identities;",{"data":25859,"content":25860,"nodeType":1586},{},[25861],{"data":25862,"content":25863,"nodeType":876},{},[25864],{"data":25865,"marks":25866,"value":25867,"nodeType":867},{},[],"Repeat as needed until you can execute your desired attack — usually stealing data from file shares, deploying ransomware, or both. ",{"data":25869,"content":25870,"nodeType":876},{},[25871],{"data":25872,"marks":25873,"value":25874,"nodeType":867},{},[],"But attacks have fundamentally changed as networks have evolved. With the SaaS-ification of enterprise IT, core business systems aren’t locally deployed and centrally managed in the way they used to be. Instead, they’re logged into over the internet, via a web browser.",{"data":25876,"content":25880,"nodeType":985},{"target":25877},{"sys":25878},{"id":25879,"type":982,"linkType":983},"4h4hUYAghbZavOwjRTnBe2",[],{"data":25882,"content":25883,"nodeType":876},{},[25884],{"data":25885,"marks":25886,"value":25887,"nodeType":867},{},[],"Under the shared responsibility model, the part that’s left to the business consuming a SaaS service is mostly constrained to how they manage identities — the vehicle by which the app is accessed and used by the workforce. It’s no surprise that this has become the soft underbelly in the crosshairs of attackers. ",{"data":25889,"content":25890,"nodeType":876},{},[25891,25895,25903,25907,25916],{"data":25892,"marks":25893,"value":25894,"nodeType":867},{},[],"We’ve seen this time and again in the biggest breaches of recent years, with the highlights including the massive ",{"data":25896,"content":25897,"nodeType":915},{"uri":6814},[25898],{"data":25899,"marks":25900,"value":25902,"nodeType":867},{},[25901],{"type":913},"Snowflake campaign in 2024",{"data":25904,"marks":25905,"value":25906,"nodeType":867},{},[]," and the ",{"data":25908,"content":25910,"nodeType":915},{"uri":25909},"https://pushsecurity.com/blog/key-takeaways-from-the-scattered-spider-attacks-on-insurance-firms/",[25911],{"data":25912,"marks":25913,"value":25915,"nodeType":867},{},[25914],{"type":913},"2025 crime wave attributed to Scattered Spider",{"data":25917,"marks":25918,"value":25919,"nodeType":867},{},[],".   ",{"data":25921,"content":25922,"nodeType":876},{},[25923],{"data":25924,"marks":25925,"value":25926,"nodeType":867},{},[],"These attacks are so successful because while attackers have moved with the changes to enterprise IT, security hasn’t really kept up. ",{"data":25928,"content":25932,"nodeType":985},{"target":25929},{"sys":25930},{"id":25931,"type":982,"linkType":983},"xH0ZqgKQXCRRZGYVs6xt6",[],{"data":25934,"content":25935,"nodeType":942},{},[],{"data":25937,"content":25938,"nodeType":868},{},[25939],{"data":25940,"marks":25941,"value":25943,"nodeType":867},{},[25942],{"type":865},"The browser is the new battleground — and a security blind spot",{"data":25945,"content":25946,"nodeType":876},{},[25947],{"data":25948,"marks":25949,"value":25950,"nodeType":867},{},[],"Taking over workforce identities is the first objective for attackers looking to target an organization, and the browser is the place where the attacks against users happen. This is because it’s where these digital identities are created and used — and their credentials and sessions live. This is what the attacker wants to get their hands on. ",{"data":25952,"content":25953,"nodeType":876},{},[25954],{"data":25955,"marks":25956,"value":25957,"nodeType":867},{},[],"Stolen credentials can be used as part of targeted attacks or in broader credential stuffing (cycling known username and credential pairs against various apps and platforms), while stolen session tokens can be used to log in directly to an active session, bypassing the authentication process. ",{"data":25959,"content":25960,"nodeType":876},{},[25961,25965,25970,25973,25978,25981,25986,25989,25994,25997,26002,26006,26011],{"data":25962,"marks":25963,"value":25964,"nodeType":867},{},[],"There are a few different techniques that attackers can use to get access to these identities. Attackers harvest stolen credentials from various places — ",{"data":25966,"marks":25967,"value":25969,"nodeType":867},{},[25968],{"type":865},"data breach dumps",{"data":25971,"marks":25972,"value":5136,"nodeType":867},{},[],{"data":25974,"marks":25975,"value":25977,"nodeType":867},{},[25976],{"type":865},"mass",{"data":25979,"marks":25980,"value":2136,"nodeType":867},{},[],{"data":25982,"marks":25983,"value":25985,"nodeType":867},{},[25984],{"type":865},"credential",{"data":25987,"marks":25988,"value":2136,"nodeType":867},{},[],{"data":25990,"marks":25991,"value":25993,"nodeType":867},{},[25992],{"type":865},"phishing campaigns,",{"data":25995,"marks":25996,"value":2136,"nodeType":867},{},[],{"data":25998,"marks":25999,"value":26001,"nodeType":867},{},[26000],{"type":865},"infostealer logs",{"data":26003,"marks":26004,"value":26005,"nodeType":867},{},[],", even ",{"data":26007,"marks":26008,"value":26010,"nodeType":867},{},[26009],{"type":865},"malicious browser extensions",{"data":26012,"marks":26013,"value":26014,"nodeType":867},{},[]," that they’ve tricked an employee into installing. In fact, the cyber crime ecosystem itself has shifted on its axis to cater to this, with hackers specifically taking on the role of harvesting credentials and establishing account access for others to exploit. ",{"data":26016,"content":26017,"nodeType":876},{},[26018,26022,26029],{"data":26019,"marks":26020,"value":26021,"nodeType":867},{},[],"The high-profile ",{"data":26023,"content":26024,"nodeType":915},{"uri":6814},[26025],{"data":26026,"marks":26027,"value":23019,"nodeType":867},{},[26028],{"type":913},{"data":26030,"marks":26031,"value":26032,"nodeType":867},{},[]," breaches in 2024 signalled a watershed moment in the shift to identity-driven breaches, where attackers logged into accounts across hundreds of customer tenants using stolen credentials. One of the primary sources of the stolen credentials used in the attacks were infostealer logs dating back to 2020 — breached passwords that hadn’t been rotated or mitigated with MFA. ",{"data":26034,"content":26035,"nodeType":876},{},[26036,26040],{"data":26037,"marks":26038,"value":26039,"nodeType":867},{},[],"Infostealers are notable because they’re an endpoint malware attack designed to harvest credentials and session tokens (often from the browser) to enable the attacker to then log into those services… through their own web browser. ",{"data":26041,"marks":26042,"value":26044,"nodeType":867},{},[26043],{"type":865},"So, even today’s endpoint attacks are seeing the attacker pivot back into the browser in order to get to identities — the key to the online apps and services where exploitable data and functionality now resides. ",{"data":26046,"content":26047,"nodeType":876},{},[26048],{"data":26049,"marks":26050,"value":26051,"nodeType":867},{},[],"The problem here is that this is a blind spot for the security tools we’re currently reliant upon — which don’t have the fine-grained visibility required. This is very similar to the challenge that the industry faced prior to the introduction of EDR in the 2010s — the main sources of data are looking from the outside-in, lacking the process-level visibility and context to be able to detect and stop attacks as they happen.",{"data":26053,"content":26057,"nodeType":985},{"target":26054},{"sys":26055},{"id":26056,"type":982,"linkType":983},"2qoMH6qCNJc7it7sTuKl4F",[],{"data":26059,"content":26060,"nodeType":942},{},[],{"data":26062,"content":26063,"nodeType":868},{},[26064],{"data":26065,"marks":26066,"value":26068,"nodeType":867},{},[26067],{"type":865},"Identity is the prize, browser is the platform — and phishing is the weapon of choice",{"data":26070,"content":26071,"nodeType":876},{},[26072,26076,26081],{"data":26073,"marks":26074,"value":26075,"nodeType":867},{},[],"But the technique that’s STILL driving the most impactful identity-driven breaches? ",{"data":26077,"marks":26078,"value":26080,"nodeType":867},{},[26079],{"type":865},"It’s phishing",{"data":26082,"marks":26083,"value":26084,"nodeType":867},{},[],". Phishing for credentials, sessions, OAuth consent, authorization codes. Phishing via email, instant messenger, social media, malicious Google ads… it all happens in, or leads to, the browser. ",{"data":26086,"content":26090,"nodeType":985},{"target":26087},{"sys":26088},{"id":26089,"type":982,"linkType":983},"6Gsd3G0sOibNxgVLimb2wV",[],{"data":26092,"content":26093,"nodeType":876},{},[26094],{"data":26095,"marks":26096,"value":26097,"nodeType":867},{},[],"And modern phishing attacks are more effective than ever. Today, phishing operates on an industrial scale, using an array of obfuscation and detection evasion techniques to block email and network security tools from intercepting them. Probably the most common example today is the use of bot protection (think CAPTCHA or Cloudflare Turnstile), using legitimate anti-spam features to block security tools. ",{"data":26099,"content":26103,"nodeType":985},{"target":26100},{"sys":26101},{"id":26102,"type":982,"linkType":983},"6M1My4lSKItu6Qdv4hO1RA",[],{"data":26105,"content":26106,"nodeType":876},{},[26107],{"data":26108,"marks":26109,"value":26110,"nodeType":867},{},[],"The latest generation of fully customized AitM phishing kits are dynamically obfuscating the code that loads the web page, implementing custom CAPTCHA, and using runtime anti-analysis features, making them increasingly difficult to detect. The ways in which links are delivered has also increased in sophistication, with more delivery channels (as we showed above) and the use of legitimate SaaS services for camouflage. ",{"data":26112,"content":26113,"nodeType":876},{},[26114,26118,26123,26127,26132,26136,26145],{"data":26115,"marks":26116,"value":26117,"nodeType":867},{},[],"And the latest trends indicate that attackers are responding to increasingly hardened IdP/SSO configuration by exploiting alternative phishing techniques that ",{"data":26119,"marks":26120,"value":26122,"nodeType":867},{},[26121],{"type":865},"circumvent MFA and passkeys",{"data":26124,"marks":26125,"value":26126,"nodeType":867},{},[],", most commonly by ",{"data":26128,"marks":26129,"value":26131,"nodeType":867},{},[26130],{"type":865},"downgrading to a phishable backup authentication method",{"data":26133,"marks":26134,"value":26135,"nodeType":867},{},[]," — which you can see in action below, and ",{"data":26137,"content":26139,"nodeType":915},{"uri":26138},"https://pushsecurity.com/blog/mfa-downgrade-attacks/",[26140],{"data":26141,"marks":26142,"value":26144,"nodeType":867},{},[26143],{"type":913},"read more about here",{"data":26146,"marks":26147,"value":24572,"nodeType":867},{},[],{"data":26149,"content":26153,"nodeType":985},{"target":26150},{"sys":26151},{"id":26152,"type":982,"linkType":983},"54I3YQ2gK26a8FIocQ3WYT",[],{"data":26155,"content":26156,"nodeType":942},{},[],{"data":26158,"content":26159,"nodeType":868},{},[26160],{"data":26161,"marks":26162,"value":26164,"nodeType":867},{},[26163],{"type":865},"Identities are the lowest-hanging fruit for attackers to aim for",{"data":26166,"content":26167,"nodeType":876},{},[26168],{"data":26169,"marks":26170,"value":26171,"nodeType":867},{},[],"The goal of the modern attacker, and the easiest way into your business’s digital environment, is to compromise identities. Whether you’re dealing with phishing attacks, malicious browser extensions, or infostealer malware, the objective remains the same — account takeover. ",{"data":26173,"content":26174,"nodeType":876},{},[26175],{"data":26176,"marks":26177,"value":26178,"nodeType":867},{},[],"Organizations are dealing with a vast and vulnerable attack surface consisting of:",{"data":26180,"content":26181,"nodeType":1629},{},[26182,26203,26224,26246],{"data":26183,"content":26184,"nodeType":1586},{},[26185],{"data":26186,"content":26187,"nodeType":876},{},[26188,26191,26199],{"data":26189,"marks":26190,"value":21,"nodeType":867},{},[],{"data":26192,"content":26193,"nodeType":915},{"uri":2912},[26194],{"data":26195,"marks":26196,"value":26198,"nodeType":867},{},[26197],{"type":913},"Hundreds of applications, with thousands of accounts",{"data":26200,"marks":26201,"value":26202,"nodeType":867},{},[]," spread across the app estate.",{"data":26204,"content":26205,"nodeType":1586},{},[26206],{"data":26207,"content":26208,"nodeType":876},{},[26209,26213,26221],{"data":26210,"marks":26211,"value":26212,"nodeType":867},{},[],"Accounts vulnerable to MFA-bypass phishing kits, because they are using a login method that is not phishing-resistant, or because ",{"data":26214,"content":26215,"nodeType":915},{"uri":26138},[26216],{"data":26217,"marks":26218,"value":26220,"nodeType":867},{},[26219],{"type":913},"the login method can be downgraded",{"data":26222,"marks":26223,"value":1679,"nodeType":867},{},[],{"data":26225,"content":26226,"nodeType":1586},{},[26227],{"data":26228,"content":26229,"nodeType":876},{},[26230,26234,26243],{"data":26231,"marks":26232,"value":26233,"nodeType":867},{},[],"Accounts with a weak, reused, or breached password and no MFA altogether (usually the result of a forgotten-about ",{"data":26235,"content":26237,"nodeType":915},{"uri":26236},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/ghost_logins/description.md",[26238],{"data":26239,"marks":26240,"value":26242,"nodeType":867},{},[26241],{"type":913},"ghost login",{"data":26244,"marks":26245,"value":24243,"nodeType":867},{},[],{"data":26247,"content":26248,"nodeType":1586},{},[26249],{"data":26250,"content":26251,"nodeType":876},{},[26252,26256,26265,26268,26277,26281,26288,26291,26300],{"data":26253,"marks":26254,"value":26255,"nodeType":867},{},[],"Bypassing the authentication process entirely to evade otherwise phishing-resistant authentication methods, by abusing features like ",{"data":26257,"content":26259,"nodeType":915},{"uri":26258},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/api_keys/description.md",[26260],{"data":26261,"marks":26262,"value":26264,"nodeType":867},{},[26263],{"type":913},"API key creation",{"data":26266,"marks":26267,"value":5136,"nodeType":867},{},[],{"data":26269,"content":26271,"nodeType":915},{"uri":26270},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/app_specific_password_phishing/description.md",[26272],{"data":26273,"marks":26274,"value":26276,"nodeType":867},{},[26275],{"type":913},"app-specific passwords",{"data":26278,"marks":26279,"value":26280,"nodeType":867},{},[],", OAuth ",{"data":26282,"content":26283,"nodeType":915},{"uri":23293},[26284],{"data":26285,"marks":26286,"value":23298,"nodeType":867},{},[26287],{"type":913},{"data":26289,"marks":26290,"value":5136,"nodeType":867},{},[],{"data":26292,"content":26294,"nodeType":915},{"uri":26293},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/cross-idp_impersonation/description.md",[26295],{"data":26296,"marks":26297,"value":26299,"nodeType":867},{},[26298],{"type":913},"cross-IdP impersonation",{"data":26301,"marks":26302,"value":26303,"nodeType":867},{},[],", and more.  ",{"data":26305,"content":26309,"nodeType":985},{"target":26306},{"sys":26307},{"id":26308,"type":982,"linkType":983},"3WFzina1t5j6bDlTlGQA0l",[],{"data":26311,"content":26312,"nodeType":876},{},[26313,26317,26326,26330,26337],{"data":26314,"marks":26315,"value":26316,"nodeType":867},{},[],"A key driver of identity vulnerability is the ",{"data":26318,"content":26320,"nodeType":915},{"uri":26319},"https://pushsecurity.com/blog/minimum-viable-identity-security/",[26321],{"data":26322,"marks":26323,"value":26325,"nodeType":867},{},[26324],{"type":913},"huge variance in the configurability of accounts per application",{"data":26327,"marks":26328,"value":26329,"nodeType":867},{},[],", with different levels of centralized visibility and security control of identities provided — for example, while one app can be locked down to only accept SSO logins via SAML and automatically remove any unused passwords, another provides no control or visibility of login method or MFA status (another big driver of the ",{"data":26331,"content":26332,"nodeType":915},{"uri":6814},[26333],{"data":26334,"marks":26335,"value":23019,"nodeType":867},{},[26336],{"type":913},{"data":26338,"marks":26339,"value":26340,"nodeType":867},{},[]," breaches last year). Unfortunately, as a by-product of product-led growth and something that is compounded by every new SaaS startup that hits the market, this situation doesn’t look like it’s going to change anytime soon. ",{"data":26342,"content":26343,"nodeType":876},{},[26344],{"data":26345,"marks":26346,"value":26347,"nodeType":867},{},[],"The end result is that identities are misconfigured, invisible to the security team, and routinely exploited by commodity attacker tooling. It’s no surprise that they’re the primary target for attackers today. ",{"data":26349,"content":26350,"nodeType":942},{},[],{"data":26352,"content":26353,"nodeType":868},{},[26354],{"data":26355,"marks":26356,"value":26358,"nodeType":867},{},[26357],{"type":865},"The solution: The browser as a telemetry source and control point",{"data":26360,"content":26361,"nodeType":876},{},[26362],{"data":26363,"marks":26364,"value":26365,"nodeType":867},{},[],"Because identity attacks play out in the browser, it’s the perfect place for security teams to observe, intercept, and shut down these attacks. ",{"data":26367,"content":26368,"nodeType":876},{},[26369],{"data":26370,"marks":26371,"value":26372,"nodeType":867},{},[],"The browser has a number of advantages over the different places where identity can be observed and protected, because:",{"data":26374,"content":26375,"nodeType":1629},{},[26376,26386,26396],{"data":26377,"content":26378,"nodeType":1586},{},[26379],{"data":26380,"content":26381,"nodeType":876},{},[26382],{"data":26383,"marks":26384,"value":26385,"nodeType":867},{},[],"You aren’t limited to the apps and identities directly connected to your IdP (a fraction of your workforce identity sprawl). ",{"data":26387,"content":26388,"nodeType":1586},{},[26389],{"data":26390,"content":26391,"nodeType":876},{},[26392],{"data":26393,"marks":26394,"value":26395,"nodeType":867},{},[],"You aren’t limited to the apps that you know about and manage centrally — you can observe every login that passes through the browser.",{"data":26397,"content":26398,"nodeType":1586},{},[26399],{"data":26400,"content":26401,"nodeType":876},{},[26402,26406,26410],{"data":26403,"marks":26404,"value":26405,"nodeType":867},{},[],"You can observe all the properties of a login, including the login method, MFA method, etc. You’d otherwise need API access to ",{"data":26407,"marks":26408,"value":21888,"nodeType":867},{},[26409],{"type":1303},{"data":26411,"marks":26412,"value":26413,"nodeType":867},{},[]," get this information (depending on whether an API is provided and whether this specific data can be interrogated, also not standard for many apps). ",{"data":26415,"content":26416,"nodeType":876},{},[26417,26421,26426,26430,26439],{"data":26418,"marks":26419,"value":26420,"nodeType":867},{},[],"It’s obvious with all that we’ve covered so far that fixing every identity vulnerability is an ominous task — the SaaS ecosystem itself is working against you. ",{"data":26422,"marks":26423,"value":26425,"nodeType":867},{},[26424],{"type":865},"This is why detecting and responding to identity attacks is essential. ",{"data":26427,"marks":26428,"value":26429,"nodeType":867},{},[],"Because identity compromise almost always involves phishing or social engineering a user to perform an action in their browser (with some exceptions — like the ",{"data":26431,"content":26433,"nodeType":915},{"uri":26432},"https://pushsecurity.com/blog/scattered-spider-defending-against-help-desk-scams/",[26434],{"data":26435,"marks":26436,"value":26438,"nodeType":867},{},[26437],{"type":913},"Scattered Spider-related help desk attacks",{"data":26440,"marks":26441,"value":26442,"nodeType":867},{},[]," seen recently), it’s also the perfect place to monitor for and intercept attacks. ",{"data":26444,"content":26445,"nodeType":876},{},[26446],{"data":26447,"marks":26448,"value":26449,"nodeType":867},{},[],"In the browser, you gather deep, contextualized information about page behavior and user inputs that can be used to detect and shut down risky scenarios in real time. Take the example of phishing pages. Because Push operates in the browser, it sees everything:",{"data":26451,"content":26452,"nodeType":1629},{},[26453,26463,26473,26483,26506,26516],{"data":26454,"content":26455,"nodeType":1586},{},[26456],{"data":26457,"content":26458,"nodeType":876},{},[26459],{"data":26460,"marks":26461,"value":26462,"nodeType":867},{},[],"The page layout.",{"data":26464,"content":26465,"nodeType":1586},{},[26466],{"data":26467,"content":26468,"nodeType":876},{},[26469],{"data":26470,"marks":26471,"value":26472,"nodeType":867},{},[],"Where the user came from (through the whole redirect chain).",{"data":26474,"content":26475,"nodeType":1586},{},[26476],{"data":26477,"content":26478,"nodeType":876},{},[26479],{"data":26480,"marks":26481,"value":26482,"nodeType":867},{},[],"Page interaction events — e.g. tabs opened and closed, popup windows, forms submitted, etc.",{"data":26484,"content":26485,"nodeType":1586},{},[26486],{"data":26487,"content":26488,"nodeType":876},{},[26489,26493,26502],{"data":26490,"marks":26491,"value":26492,"nodeType":867},{},[],"The password they enter ",{"data":26494,"content":26496,"nodeType":915},{"uri":26495},"https://pushsecurity.com/help/10043/#how-push-securely-analyzes-passwords",[26497],{"data":26498,"marks":26499,"value":26501,"nodeType":867},{},[26500],{"type":913},"(as a salted, abbreviated hash)",{"data":26503,"marks":26504,"value":26505,"nodeType":867},{},[],", and whether a password was typed or copied, and where from.",{"data":26507,"content":26508,"nodeType":1586},{},[26509],{"data":26510,"content":26511,"nodeType":876},{},[26512],{"data":26513,"marks":26514,"value":26515,"nodeType":867},{},[],"What scripts are running on the page and whether they are potentially malicious.",{"data":26517,"content":26518,"nodeType":1586},{},[26519],{"data":26520,"content":26521,"nodeType":876},{},[26522],{"data":26523,"marks":26524,"value":26525,"nodeType":867},{},[],"Where credentials are being sent.",{"data":26527,"content":26531,"nodeType":985},{"target":26528},{"sys":26529},{"id":26530,"type":982,"linkType":983},"6kQejVS63FQ6Oy8nIm6UlV",[],{"data":26533,"content":26534,"nodeType":942},{},[],{"data":26536,"content":26537,"nodeType":868},{},[26538],{"data":26539,"marks":26540,"value":23563,"nodeType":867},{},[26541],{"type":865},{"data":26543,"content":26544,"nodeType":876},{},[26545],{"data":26546,"marks":26547,"value":26548,"nodeType":867},{},[],"Identity attacks are the biggest unsolved problem facing security teams today and the leading cause of security breaches. At the same time, the browser presents security teams with all the tools they need to prevent, detect, and respond to identity-based attacks — proactively by finding and fixing identity vulnerabilities, and reactively by detecting and blocking attacks against users in real time. ",{"data":26550,"content":26551,"nodeType":876},{},[26552,26556,26565],{"data":26553,"marks":26554,"value":26555,"nodeType":867},{},[],"Organizations need to move past the old ways of doing identity security — relying on MFA attestations, identity management dashboards, and ",{"data":26557,"content":26559,"nodeType":915},{"uri":26558},"https://pushsecurity.com/blog/three-reasons-why-browser-is-best-for-stopping-phishing-attacks/",[26560],{"data":26561,"marks":26562,"value":26564,"nodeType":867},{},[26563],{"type":913},"legacy email and network anti-phishing tools",{"data":26566,"marks":26567,"value":26568,"nodeType":867},{},[],". And there’s no better place to stop these attacks than in the browser. ",{"data":26570,"content":26571,"nodeType":942},{},[],{"data":26573,"content":26574,"nodeType":868},{},[26575],{"data":26576,"marks":26577,"value":25228,"nodeType":867},{},[26578],{"type":865},{"data":26580,"content":26581,"nodeType":876},{},[26582],{"data":26583,"marks":26584,"value":26585,"nodeType":867},{},[],"Push Security’s browser-based security platform provides comprehensive detection and response capabilities against the leading cause of breaches. Push blocks identity attacks like AiTM phishing, credential stuffing, password spraying and session hijacking using stolen session tokens. You can also use Push to find and fix identity vulnerabilities across the apps that your employees use, like ghost logins, SSO coverage gaps, MFA gaps, vulnerable passwords, risky OAuth integrations, and more.",{"data":26587,"content":26588,"nodeType":876},{},[26589,26592,26599],{"data":26590,"marks":26591,"value":23584,"nodeType":867},{},[],{"data":26593,"content":26594,"nodeType":915},{"uri":2689},[26595],{"data":26596,"marks":26597,"value":14723,"nodeType":867},{},[26598],{"type":913},{"data":26600,"marks":26601,"value":1679,"nodeType":867},{},[],{"entries":26603},{"hyperlink":26604,"inline":26605,"block":26606},[],[],[26607,26614,26618,26624,26630,26638,26642,26650],{"sys":26608,"__typename":1688,"title":26609,"caption":26609,"layoutMode":59,"file":26610},{"id":25879},"Attacks have shifted from targeting local networks to SaaS services, accessed through employee web browsers.",{"url":26611,"width":26612,"height":26613},"https://images.ctfassets.net/y1cdw1ablpvd/SadRsmdnNZofhrKddH01D/1ba16316bdfa666b2bc387d5b694e515/image2.png",1506,574,{"sys":26615,"__typename":1697,"type":1698,"ctaText":26616,"buttonLabel":17335,"buttonColour":24251,"buttonUrl":26617},{"id":25931},"Read how the transformation of business IT has shaped the evolution of phishing attacks in our latest whitepaper.","https://pushsecurity.com/resources/phishing-evolution",{"sys":26619,"__typename":1688,"title":26620,"caption":26620,"layoutMode":59,"file":26621},{"id":26056},"EDR solved endpoint attacks by getting deep visibility into OS-level processes and activity — we now face a similar visibility problem in the browser. ",{"url":26622,"width":1693,"height":26623},"https://images.ctfassets.net/y1cdw1ablpvd/2KuUuYKf2Q9TlIJ9fkOI82/9a52cae72564e69d3cfe8b3b613eb950/image5.png",632,{"sys":26625,"__typename":1688,"title":26626,"caption":26626,"layoutMode":59,"file":26627},{"id":26089},"Phishing is now multi- and cross-channel, targeting a vast range of cloud and SaaS apps using flexible AitM toolkits — but all roads inevitably lead to the browser.",{"url":26628,"width":1693,"height":26629},"https://images.ctfassets.net/y1cdw1ablpvd/4p8sf1x8PfWF06ndwTsdf9/136ed45c7912459a70dbb53b62cf5a90/image6.png",1003,{"sys":26631,"__typename":1688,"title":26632,"caption":26633,"layoutMode":59,"file":26634},{"id":26102},"Cloudflare Turnstile is a simple way for attackers to block automated analysis of their phishing kits — it should probably come with a trigger warning for incident responders.","Cloudflare Turnstile is a simple way for security teams to prevent automated analysis — it should probably come with a trigger warning for incident responders.",{"url":26635,"width":26636,"height":26637},"https://images.ctfassets.net/y1cdw1ablpvd/6gGDHL1jECCm4j02gZZlYe/92e4362eea9fb712aeb64bdd7fb19d59/image3.png",1262,464,{"sys":26639,"__typename":21660,"title":26640,"arcadeDemoUrl":26641,"playText":21728},{"id":26152},"MFA Downgrade Demo","https://demo.arcade.software/1MzRfFaRCD2pYPhIXkvi?embed",{"sys":26643,"__typename":1688,"title":26644,"caption":26645,"layoutMode":59,"file":26646},{"id":26308},"Infographic showing the identity vulnerability spread for a 1,000 seat organization","A 1,000 user organization has over 15,000 accounts with various configurations and associated vulnerabilities.",{"url":26647,"width":26648,"height":26649},"https://images.ctfassets.net/y1cdw1ablpvd/266iLQBVsJIQEx6dnUEVrZ/eb5b1be79b7b29365baf299053fddf42/Infographic.png",5480,3012,{"sys":26651,"__typename":1688,"title":26652,"caption":26652,"layoutMode":59,"file":26653},{"id":26530},"Being in the browser gives you unrivalled visibility of phishing page activity and user behavior.",{"url":26654,"width":26655,"height":26656},"https://images.ctfassets.net/y1cdw1ablpvd/42mmDkjfXn0uOkTyvFLNqG/0385dadcb0731bea1de1ca5ae6ee7c18/image1.png",1560,766,{"items":26658},[],{},"Why the browser is now the main cyber attack surface","2025-08-15T00:00:00.000Z",{"items":26663},[26664,27665,28027],{"__typename":1772,"sys":26665,"content":26667,"title":27651,"synopsis":27652,"hashTags":59,"publishedDate":27653,"slug":27654,"tagsCollection":27655,"authorsCollection":27661},{"id":26666},"6OFdfAsoPUECeRAetWvedp",{"json":26668},{"data":26669,"content":26670,"nodeType":1680},{},[26671,26678,26690,26702,26714,26726,26732,26751,26758,26774,26781,26787,26790,26798,26805,26812,26819,26825,26828,26836,26843,26863,26870,26877,26884,26891,26897,26904,26911,26918,26946,26953,26971,26978,26985,27005,27025,27045,27051,27058,27074,27081,27088,27095,27114,27122,27129,27136,27139,27147,27154,27161,27168,27211,27217,27224,27239,27328,27334,27341,27348,27411,27418,27425,27432,27438,27445,27452,27459,27465,27472,27479,27486,27492,27511,27518,27525,27568,27574,27577,27585,27609,27612,27619,27626,27633],{"data":26672,"content":26673,"nodeType":876},{},[26674],{"data":26675,"marks":26676,"value":26677,"nodeType":867},{},[],"Oh, look! A time capsule from 2010. Wonder what’s inside … ",{"data":26679,"content":26680,"nodeType":876},{},[26681,26686],{"data":26682,"marks":26683,"value":26685,"nodeType":867},{},[26684],{"type":865},"Listening to:",{"data":26687,"marks":26688,"value":26689,"nodeType":867},{},[]," “Like a G6” by Far East Movement (on a Nokia C7 — hey, it even had a touchscreen).",{"data":26691,"content":26692,"nodeType":876},{},[26693,26698],{"data":26694,"marks":26695,"value":26697,"nodeType":867},{},[26696],{"type":865},"Major news event:",{"data":26699,"marks":26700,"value":26701,"nodeType":867},{},[]," Eyjafjallajökull volcano erupts in Iceland, disrupting air travel.",{"data":26703,"content":26704,"nodeType":876},{},[26705,26710],{"data":26706,"marks":26707,"value":26709,"nodeType":867},{},[26708],{"type":865},"Worried about:",{"data":26711,"marks":26712,"value":26713,"nodeType":867},{},[]," Exploitable Flash browser plugins and static HTML phishing sites.",{"data":26715,"content":26716,"nodeType":876},{},[26717,26722],{"data":26718,"marks":26719,"value":26721,"nodeType":867},{},[26720],{"type":865},"How to be a hero?",{"data":26723,"marks":26724,"value":26725,"nodeType":867},{},[]," Roll out the latest AV, implement a web proxy, and add a “report phishing” button to your email solution.",{"data":26727,"content":26731,"nodeType":985},{"target":26728},{"sys":26729},{"id":26730,"type":982,"linkType":983},"54xYbMs0ii96xb2jgQVX9m",[],{"data":26733,"content":26734,"nodeType":876},{},[26735,26739,26747],{"data":26736,"marks":26737,"value":26738,"nodeType":867},{},[],"We’re halfway through 2025, and the time capsule for this year may need to be an XL when it comes to ",{"data":26740,"content":26741,"nodeType":915},{"uri":22147},[26742],{"data":26743,"marks":26744,"value":26746,"nodeType":867},{},[26745],{"type":913},"how much has happened",{"data":26748,"marks":26749,"value":26750,"nodeType":867},{},[]," in the world of browser-based attacks. (Yet fittingly, Drake’s “Nokia” is a pop hit.)",{"data":26752,"content":26753,"nodeType":876},{},[26754],{"data":26755,"marks":26756,"value":26757,"nodeType":867},{},[],"While at least we don’t have to worry about Flash anymore, the browser is now the new battleground, and workforce identities are the most common target. Security teams are struggling with approaches and tools that attackers have outpaced.",{"data":26759,"content":26760,"nodeType":876},{},[26761,26765,26770],{"data":26762,"marks":26763,"value":26764,"nodeType":867},{},[],"In this article, we’ll cover how browser-based attacks have evolved, and how Push is taking a new approach with the release of our ",{"data":26766,"marks":26767,"value":26769,"nodeType":867},{},[26768],{"type":865},"Detections",{"data":26771,"marks":26772,"value":26773,"nodeType":867},{},[]," capabilities, now generally available to all customers.",{"data":26775,"content":26776,"nodeType":876},{},[26777],{"data":26778,"marks":26779,"value":26780,"nodeType":867},{},[],"Push Detections use real-time telemetry to help you understand context, user behavior, and attacker techniques, and then respond — a modern tool for modern browser-based attacks.",{"data":26782,"content":26786,"nodeType":985},{"target":26783},{"sys":26784},{"id":26785,"type":982,"linkType":983},"2ULDSj85bXtT2OgpXKBHtB",[],{"data":26788,"content":26789,"nodeType":942},{},[],{"data":26791,"content":26792,"nodeType":868},{},[26793],{"data":26794,"marks":26795,"value":26797,"nodeType":867},{},[26796],{"type":865},"The old world vs. the new world",{"data":26799,"content":26800,"nodeType":876},{},[26801],{"data":26802,"marks":26803,"value":26804,"nodeType":867},{},[],"In the early 2010s, the typical attack path involved sending a user an email with a link to a static HTML webpage (most commonly a generic Exchange Web Access clone) that tricked them into giving you Active Directory creds. These could be used to log in to an exposed remote desktop service or the victim’s mailbox, giving the attacker a foothold to install malware. Anyone who’s done “red teaming 101” will recognize this scenario. ",{"data":26806,"content":26807,"nodeType":876},{},[26808],{"data":26809,"marks":26810,"value":26811,"nodeType":867},{},[],"A compromised identity was once just part of a system compromise. That meant the scope of detection and response was focused on the organization’s Active Directory domain, correlated with endpoint and network logs. ",{"data":26813,"content":26814,"nodeType":876},{},[26815],{"data":26816,"marks":26817,"value":26818,"nodeType":867},{},[],"But now, identity attacks happen beyond traditional on-premises networks, impacting cloud identities that are created, used, and attacked in the browser. What was once the familiar backbone of business IT — internal apps and thick clients — has been replaced with a sprawling cloud and SaaS ecosystem that can be targeted directly via identity, without touching the endpoint. ",{"data":26820,"content":26824,"nodeType":985},{"target":26821},{"sys":26822},{"id":26823,"type":982,"linkType":983},"2F2p4eTMCHo3LfNQJZeGWB",[],{"data":26826,"content":26827,"nodeType":942},{},[],{"data":26829,"content":26830,"nodeType":868},{},[26831],{"data":26832,"marks":26833,"value":26835,"nodeType":867},{},[26834],{"type":865},"Why detection and response hasn’t kept up with threat evolution",{"data":26837,"content":26838,"nodeType":876},{},[26839],{"data":26840,"marks":26841,"value":26842,"nodeType":867},{},[],"This shift in attacker TTPs is forcing a change in how we handle detection and response. ",{"data":26844,"content":26845,"nodeType":876},{},[26846,26850,26859],{"data":26847,"marks":26848,"value":26849,"nodeType":867},{},[],"But a lot of organizations are still applying the same old playbooks to this new world where identity attacks are the ",{"data":26851,"content":26853,"nodeType":915},{"uri":26852},"https://pushsecurity.com/resources/2024-identity-attacks",[26854],{"data":26855,"marks":26856,"value":26858,"nodeType":867},{},[26857],{"type":913},"leading cause of breaches",{"data":26860,"marks":26861,"value":26862,"nodeType":867},{},[],", with uneven outcomes. ",{"data":26864,"content":26865,"nodeType":876},{},[26866],{"data":26867,"marks":26868,"value":26869,"nodeType":867},{},[],"This isn’t because of a lack of effort or skill on the part of security teams. It’s a reflection of the tools that have been available. ",{"data":26871,"content":26872,"nodeType":876},{},[26873],{"data":26874,"marks":26875,"value":26876,"nodeType":867},{},[],"Let’s look at some of the ways detection and response hasn’t kept up with the evolution of browser-borne threats in this new landscape.",{"data":26878,"content":26879,"nodeType":1058},{},[26880],{"data":26881,"marks":26882,"value":26883,"nodeType":867},{},[],"Incomplete identity visibility ",{"data":26885,"content":26886,"nodeType":876},{},[26887],{"data":26888,"marks":26889,"value":26890,"nodeType":867},{},[],"Today’s cloud identity providers see a fraction of the overall logins your users make to online apps, compared to the comprehensive visibility of Active Directory in the old world. You don’t know where users are logging in, how they’re logging in, or whether these logins are securely using phishing-resistant methods.",{"data":26892,"content":26896,"nodeType":985},{"target":26893},{"sys":26894},{"id":26895,"type":982,"linkType":983},"1SUYueQct7dtWwLh3AaAtA",[],{"data":26898,"content":26899,"nodeType":876},{},[26900],{"data":26901,"marks":26902,"value":26903,"nodeType":867},{},[],"This means that identity attacks are routinely bypassing preventative, account hygiene-based controls, putting the strain on detection and response. ",{"data":26905,"content":26906,"nodeType":1058},{},[26907],{"data":26908,"marks":26909,"value":26910,"nodeType":867},{},[],"Limited detection coverage ",{"data":26912,"content":26913,"nodeType":876},{},[26914],{"data":26915,"marks":26916,"value":26917,"nodeType":867},{},[],"Email and network security tools got pretty good at intercepting old-school phishing attacks like the ones from our proverbial time capsule: static HTML pages delivered over email that could be intercepted and analyzed when entering the mailbox or being loaded by the user. ",{"data":26919,"content":26920,"nodeType":876},{},[26921,26925,26934,26938,26942],{"data":26922,"marks":26923,"value":26924,"nodeType":867},{},[],"But with modern phishing attacks dynamically obfuscating the code that loads the web page, implementing custom bot protection, and using runtime anti-analysis features, they’re ",{"data":26926,"content":26927,"nodeType":915},{"uri":3332},[26928],{"data":26929,"marks":26930,"value":26933,"nodeType":867},{},[26931,26932],{"type":913},{"type":865},"increasingly difficult to detect",{"data":26935,"marks":26936,"value":2136,"nodeType":867},{},[26937],{"type":865},{"data":26939,"marks":26940,"value":26941,"nodeType":867},{},[],"using conventional tools",{"data":26943,"marks":26944,"value":25919,"nodeType":867},{},[26945],{"type":865},{"data":26947,"content":26948,"nodeType":876},{},[26949],{"data":26950,"marks":26951,"value":26952,"nodeType":867},{},[],"Of course, email-based detections aren’t much use if attackers are using legitimate services to camouflage their links, or bypassing email altogether by switching to alternative delivery channels like messaging apps (such as Slack and Teams), as well as public services like LinkedIn and Reddit. ",{"data":26954,"content":26955,"nodeType":876},{},[26956,26960,26967],{"data":26957,"marks":26958,"value":26959,"nodeType":867},{},[],"More recently, groups like ",{"data":26961,"content":26962,"nodeType":915},{"uri":22147},[26963],{"data":26964,"marks":26965,"value":1182,"nodeType":867},{},[26966],{"type":913},{"data":26968,"marks":26969,"value":26970,"nodeType":867},{},[]," have even been seen using malvertising techniques, delivering phishing links masquerading as paid Google ads.",{"data":26972,"content":26973,"nodeType":1058},{},[26974],{"data":26975,"marks":26976,"value":26977,"nodeType":867},{},[],"Inadequate security logs",{"data":26979,"content":26980,"nodeType":876},{},[26981],{"data":26982,"marks":26983,"value":26984,"nodeType":867},{},[],"If you fail to spot the attack pre-account takeover, you’re reliant on being able to detect and investigate suspicious or malicious activity resulting from the compromise. ",{"data":26986,"content":26987,"nodeType":876},{},[26988,26992,27001],{"data":26989,"marks":26990,"value":26991,"nodeType":867},{},[],"This was more straightforward (if not easy) when you had the luxury of a ",{"data":26993,"content":26995,"nodeType":915},{"uri":26994},"https://pushsecurity.com/blog/shifting-detection-left-for-more-effective-itdr/",[26996],{"data":26997,"marks":26998,"value":27000,"nodeType":867},{},[26999],{"type":913},"typical on-prem network to fall back",{"data":27002,"marks":27003,"value":27004,"nodeType":867},{},[]," on. But with cloud exploitation taking place in a matter of minutes, you don’t get much warning — and your endpoint and network-based alarms can’t help you. ",{"data":27006,"content":27007,"nodeType":876},{},[27008,27012,27021],{"data":27009,"marks":27010,"value":27011,"nodeType":867},{},[],"The situation is further complicated by the fact that you simply don’t have the logs you need because of the huge variability in how cloud and SaaS services provide logs (with many ",{"data":27013,"content":27015,"nodeType":915},{"uri":27014},"https://pushsecurity.com/blog/minimum-viable-identity-security/#id-enable-security-teams-to-detect-and-respond-to-identity-attacks",[27016],{"data":27017,"marks":27018,"value":27020,"nodeType":867},{},[27019],{"type":913},"failing to provide security logs",{"data":27022,"marks":27023,"value":27024,"nodeType":867},{},[]," with relevant data points at all). So chances are you’re flying blind when it comes to large chunks of your business app suite. ",{"data":27026,"content":27027,"nodeType":876},{},[27028,27032,27041],{"data":27029,"marks":27030,"value":27031,"nodeType":867},{},[],"Ultimately, you’re stuck with what you can observe — typically network traffic. But ",{"data":27033,"content":27035,"nodeType":915},{"uri":27034},"https://pushsecurity.com/blog/the-web-proxy-is-dead-long-live-the-browser-extension/",[27036],{"data":27037,"marks":27038,"value":27040,"nodeType":867},{},[27039],{"type":913},"even with a TLS-terminating proxy",{"data":27042,"marks":27043,"value":27044,"nodeType":867},{},[],", extracting fine-grained identity data points isn’t really achievable. You’re looking from the outside-in at malicious activity that’s happening in the user’s browser and trying to infer what happened.  ",{"data":27046,"content":27050,"nodeType":985},{"target":27047},{"sys":27048},{"id":27049,"type":982,"linkType":983},"7FMdHtbE63GMCavObETf3O",[],{"data":27052,"content":27053,"nodeType":1058},{},[27054],{"data":27055,"marks":27056,"value":27057,"nodeType":867},{},[],"Spotty control enforcement",{"data":27059,"content":27060,"nodeType":876},{},[27061,27065,27070],{"data":27062,"marks":27063,"value":27064,"nodeType":867},{},[],"And in the case that you do identify that a user clicked a malicious link and ",{"data":27066,"marks":27067,"value":27069,"nodeType":867},{},[27068],{"type":1303},"maybe ",{"data":27071,"marks":27072,"value":27073,"nodeType":867},{},[],"entered their credentials into the page — now what? ",{"data":27075,"content":27076,"nodeType":876},{},[27077],{"data":27078,"marks":27079,"value":27080,"nodeType":867},{},[],"You can reset the account in the affected app, ideally terminating active sessions — which may or may not be possible, depending on the app. This might take a while if you don’t centrally manage the app, and involve some painful emergency phone calls to employees. ",{"data":27082,"content":27083,"nodeType":876},{},[27084],{"data":27085,"marks":27086,"value":27087,"nodeType":867},{},[],"What about apps where the same password is reused? ",{"data":27089,"content":27090,"nodeType":876},{},[27091],{"data":27092,"marks":27093,"value":27094,"nodeType":867},{},[],"Or if it’s an IdP account used for SSO, what about the other apps that might be accessible now? ",{"data":27096,"content":27097,"nodeType":876},{},[27098,27102,27110],{"data":27099,"marks":27100,"value":27101,"nodeType":867},{},[],"If the attacker has created stealthy backdoors that persist through credential changes (like ",{"data":27103,"content":27104,"nodeType":915},{"uri":26236},[27105],{"data":27106,"marks":27107,"value":27109,"nodeType":867},{},[27108],{"type":913},"creating an API key or a malicious OAuth integration",{"data":27111,"marks":27112,"value":27113,"nodeType":867},{},[],") they could still be lurking in your environment.",{"data":27115,"content":27116,"nodeType":876},{},[27117],{"data":27118,"marks":27119,"value":27121,"nodeType":867},{},[27120],{"type":865},"Suddenly, you’re not dealing with one possible control point, you’re dealing with several. ",{"data":27123,"content":27124,"nodeType":876},{},[27125],{"data":27126,"marks":27127,"value":27128,"nodeType":867},{},[],"And if you can’t trace the attack back to a source — because your email solution missed it, or it didn’t come via email, how can you triage the impact to other users? ",{"data":27130,"content":27131,"nodeType":876},{},[27132],{"data":27133,"marks":27134,"value":27135,"nodeType":867},{},[],"It’s no wonder that security teams are struggling to adapt. ",{"data":27137,"content":27138,"nodeType":942},{},[],{"data":27140,"content":27141,"nodeType":868},{},[27142],{"data":27143,"marks":27144,"value":27146,"nodeType":867},{},[27145],{"type":865},"How Push is solving modern identity investigations in the browser",{"data":27148,"content":27149,"nodeType":876},{},[27150],{"data":27151,"marks":27152,"value":27153,"nodeType":867},{},[],"The good news? We’ve seen this phenomenon play out before: In the early 2010s, in fact, when AV evolved into EDR. What was the big innovation then? Getting inside the data stream, in real time, and detecting and responding from a much higher-fidelity source of telemetry.",{"data":27155,"content":27156,"nodeType":876},{},[27157],{"data":27158,"marks":27159,"value":27160,"nodeType":867},{},[],"This time around, security teams need tools that take them inside the browser layer.",{"data":27162,"content":27163,"nodeType":876},{},[27164],{"data":27165,"marks":27166,"value":27167,"nodeType":867},{},[],"This approach gives you the right vantage point to defend against and investigate browser-based identity attacks, providing access to:",{"data":27169,"content":27170,"nodeType":1629},{},[27171,27181,27191,27201],{"data":27172,"content":27173,"nodeType":1586},{},[27174],{"data":27175,"content":27176,"nodeType":876},{},[27177],{"data":27178,"marks":27179,"value":27180,"nodeType":867},{},[],"Full decrypted HTTP traffic — not just DNS and TCP/IP metadata",{"data":27182,"content":27183,"nodeType":1586},{},[27184],{"data":27185,"content":27186,"nodeType":876},{},[27187],{"data":27188,"marks":27189,"value":27190,"nodeType":867},{},[],"Full user interaction tracing — every click, keystroke, or DOM change",{"data":27192,"content":27193,"nodeType":1586},{},[27194],{"data":27195,"content":27196,"nodeType":876},{},[27197],{"data":27198,"marks":27199,"value":27200,"nodeType":867},{},[],"Full inspection at every layer of execution, not just the initial HTML served",{"data":27202,"content":27203,"nodeType":1586},{},[27204],{"data":27205,"content":27206,"nodeType":876},{},[27207],{"data":27208,"marks":27209,"value":27210,"nodeType":867},{},[],"Full access to browser APIs, to correlate with browser history, local storage, cookies, etc.",{"data":27212,"content":27216,"nodeType":985},{"target":27213},{"sys":27214},{"id":27215,"type":982,"linkType":983},"5qt0s8e1TIEUxhU1GzFO63",[],{"data":27218,"content":27219,"nodeType":876},{},[27220],{"data":27221,"marks":27222,"value":27223,"nodeType":867},{},[],"With this data, teams have the information they need to respond to and investigate browser-based attacks. But to become valuable, this data needs a translation layer that turns it from raw logs into actionable information.",{"data":27225,"content":27226,"nodeType":876},{},[27227,27231,27235],{"data":27228,"marks":27229,"value":27230,"nodeType":867},{},[],"That’s where Push’s ",{"data":27232,"marks":27233,"value":26769,"nodeType":867},{},[27234],{"type":865},{"data":27236,"marks":27237,"value":27238,"nodeType":867},{},[]," capability comes in. With it, you can:",{"data":27240,"content":27241,"nodeType":1629},{},[27242,27278,27288,27298,27308,27318],{"data":27243,"content":27244,"nodeType":1586},{},[27245],{"data":27246,"content":27247,"nodeType":876},{},[27248,27252,27261,27265,27274],{"data":27249,"marks":27250,"value":27251,"nodeType":867},{},[],"Get alerted in your platform of choice (via the Push admin console, ",{"data":27253,"content":27255,"nodeType":915},{"uri":27254},"https://pushsecurity.com/help/audience/administrators/docs/connect-to-siem-or-soar/send-webhook-events-to-slack/",[27256],{"data":27257,"marks":27258,"value":27260,"nodeType":867},{},[27259],{"type":913},"Slack integration",{"data":27262,"marks":27263,"value":27264,"nodeType":867},{},[],", or your ",{"data":27266,"content":27268,"nodeType":915},{"uri":27267},"https://pushsecurity.com/help/audience/administrators/docs/connect-to-siem-or-soar/",[27269],{"data":27270,"marks":27271,"value":27273,"nodeType":867},{},[27272],{"type":913},"SIEM/SOAR",{"data":27275,"marks":27276,"value":27277,"nodeType":867},{},[]," of choice) whenever Push detects a browser-based attack, such as AiTM phishing or a cloned login page.",{"data":27279,"content":27280,"nodeType":1586},{},[27281],{"data":27282,"content":27283,"nodeType":876},{},[27284],{"data":27285,"marks":27286,"value":27287,"nodeType":867},{},[],"Review a curated timeline of the incident: Where a phishing link originated; whether a user entered their credentials on the page; what kind of phishkit was used; and whether the attack was blocked by Push.",{"data":27289,"content":27290,"nodeType":1586},{},[27291],{"data":27292,"content":27293,"nodeType":876},{},[27294],{"data":27295,"marks":27296,"value":27297,"nodeType":867},{},[],"See all the other impacted accounts and apps that shared a password with the phished account so you can remediate them.",{"data":27299,"content":27300,"nodeType":1586},{},[27301],{"data":27302,"content":27303,"nodeType":876},{},[27304],{"data":27305,"marks":27306,"value":27307,"nodeType":867},{},[],"See a screenshot captured by the Push browser extension of the phishing page, so you can see exactly what the user saw before the page disappears.",{"data":27309,"content":27310,"nodeType":1586},{},[27311],{"data":27312,"content":27313,"nodeType":876},{},[27314],{"data":27315,"marks":27316,"value":27317,"nodeType":867},{},[],"Get additional context from urlscan.io about the domains connected to the incident, helping you understand whether a domain has been reported as malicious by other users, when it was registered, and how many times it’s been scanned.",{"data":27319,"content":27320,"nodeType":1586},{},[27321],{"data":27322,"content":27323,"nodeType":876},{},[27324],{"data":27325,"marks":27326,"value":27327,"nodeType":867},{},[],"Interrogate and send this telemetry to your SIEM for you to operationalize it as part of SecOps workflows and hunt across events for similar incident characteristics.",{"data":27329,"content":27333,"nodeType":985},{"target":27330},{"sys":27331},{"id":27332,"type":982,"linkType":983},"5iPYWpPx4IZ2M1DykQiWsN",[],{"data":27335,"content":27336,"nodeType":1058},{},[27337],{"data":27338,"marks":27339,"value":27340,"nodeType":867},{},[],"Browser context",{"data":27342,"content":27343,"nodeType":876},{},[27344],{"data":27345,"marks":27346,"value":27347,"nodeType":867},{},[],"With Push, there’s no more: ",{"data":27349,"content":27350,"nodeType":1629},{},[27351,27361,27371,27381,27391,27401],{"data":27352,"content":27353,"nodeType":1586},{},[27354],{"data":27355,"content":27356,"nodeType":876},{},[27357],{"data":27358,"marks":27359,"value":27360,"nodeType":867},{},[],"Waiting (and hoping) that a browser-based attack gets recognized and reported by a user.",{"data":27362,"content":27363,"nodeType":1586},{},[27364],{"data":27365,"content":27366,"nodeType":876},{},[27367],{"data":27368,"marks":27369,"value":27370,"nodeType":867},{},[],"Guesswork as to exactly what happened on the phishing page. ",{"data":27372,"content":27373,"nodeType":1586},{},[27374],{"data":27375,"content":27376,"nodeType":876},{},[27377],{"data":27378,"marks":27379,"value":27380,"nodeType":867},{},[],"Struggling to get your hands on a live version of the page to see if it was actually malicious and getting thwarted because the attacker used a one-time phishing link. ",{"data":27382,"content":27383,"nodeType":1586},{},[27384],{"data":27385,"content":27386,"nodeType":876},{},[27387],{"data":27388,"marks":27389,"value":27390,"nodeType":867},{},[],"Manually tracing the attack to see if it arrived by email so you can quarantine the messages. ",{"data":27392,"content":27393,"nodeType":1586},{},[27394],{"data":27395,"content":27396,"nodeType":876},{},[27397],{"data":27398,"marks":27399,"value":27400,"nodeType":867},{},[],"Trawling through voluminous proxy logs for scraps of information (who else visited the link; where did it originate; etc.).",{"data":27402,"content":27403,"nodeType":1586},{},[27404],{"data":27405,"content":27406,"nodeType":876},{},[27407],{"data":27408,"marks":27409,"value":27410,"nodeType":867},{},[],"Spending precious time on urlscan or VirusTotal to get basic context on a domain or IP address. ",{"data":27412,"content":27413,"nodeType":876},{},[27414],{"data":27415,"marks":27416,"value":27417,"nodeType":867},{},[],"Instead, Push gives you all the information you need in one place to investigate and respond. ",{"data":27419,"content":27420,"nodeType":876},{},[27421],{"data":27422,"marks":27423,"value":27424,"nodeType":867},{},[],"The foundation for these detections is the Push browser agent, which can be silently installed in all major browsers in your environment to begin streaming information about a user’s entire identity footprint. ",{"data":27426,"content":27427,"nodeType":876},{},[27428],{"data":27429,"marks":27430,"value":27431,"nodeType":867},{},[],"This valuable telemetry, combined with Push’s out-of-the-box controls and detections, gives you a seat on the user’s side of the equation, capturing reliable information about network requests, scripts loaded by a malicious website, and what a user clicked and navigated to: the ingredients for showing you how a browser-based attack unfolded, start to finish.",{"data":27433,"content":27437,"nodeType":985},{"target":27434},{"sys":27435},{"id":27436,"type":982,"linkType":983},"7ylgcaNDrxYhw7bULixM1C",[],{"data":27439,"content":27440,"nodeType":876},{},[27441],{"data":27442,"marks":27443,"value":27444,"nodeType":867},{},[],"Push raises a detection when it observes a phishing attack or when a user attempts to visit a blocked URL. You can view detections in the Push admin console, or send them to your SIEM or SOAR for correlation and analysis.",{"data":27446,"content":27447,"nodeType":1058},{},[27448],{"data":27449,"marks":27450,"value":27451,"nodeType":867},{},[],"Screenshot capture",{"data":27453,"content":27454,"nodeType":876},{},[27455],{"data":27456,"marks":27457,"value":27458,"nodeType":867},{},[],"The Push extension can also capture a screenshot at the time of a detection firing. This means security teams can see the visual characteristics of the page even if it’s since been taken down (and no more looking at bot protection screens like Cloudflare Turnstile on urlscan). ",{"data":27460,"content":27464,"nodeType":985},{"target":27461},{"sys":27462},{"id":27463,"type":982,"linkType":983},"58HPrc7wImm3mLxPK0yJOG",[],{"data":27466,"content":27467,"nodeType":1058},{},[27468],{"data":27469,"marks":27470,"value":27471,"nodeType":867},{},[],"Blast radius analysis for all impacted accounts & apps",{"data":27473,"content":27474,"nodeType":876},{},[27475],{"data":27476,"marks":27477,"value":27478,"nodeType":867},{},[],"With Push’s knowledge of your workforce identities — based on observing logins in the browser that use corporate credentials — the platform can also provide an analysis of the blast radius of an attack by showing you where other accounts and apps are impacted or at risk.",{"data":27480,"content":27481,"nodeType":876},{},[27482],{"data":27483,"marks":27484,"value":27485,"nodeType":867},{},[],"This information helps you understand the true impact of an incident so you can remediate all affected accounts.",{"data":27487,"content":27491,"nodeType":985},{"target":27488},{"sys":27489},{"id":27490,"type":982,"linkType":983},"77e8XMl2Rb0p7ZrG2wmURO",[],{"data":27493,"content":27494,"nodeType":876},{},[27495,27499,27507],{"data":27496,"marks":27497,"value":27498,"nodeType":867},{},[],"Push is able to provide this blast radius analysis by ",{"data":27500,"content":27501,"nodeType":915},{"uri":26495},[27502],{"data":27503,"marks":27504,"value":27506,"nodeType":867},{},[27505],{"type":913},"securely fingerprinting users’ passwords",{"data":27508,"marks":27509,"value":27510,"nodeType":867},{},[]," when a login is observed; analyzing them for security posture issues such as missing MFA, or stolen, weak, or reused passwords; and then raising that relevant context for a given detection.",{"data":27512,"content":27513,"nodeType":1058},{},[27514],{"data":27515,"marks":27516,"value":27517,"nodeType":867},{},[],"Correlated context from urlscan.io",{"data":27519,"content":27520,"nodeType":876},{},[27521],{"data":27522,"marks":27523,"value":27524,"nodeType":867},{},[],"Finally, through an integration with urlscan.io, Push is able to provide additional context about the domains involved in a detection event, including:",{"data":27526,"content":27527,"nodeType":1629},{},[27528,27538,27548,27558],{"data":27529,"content":27530,"nodeType":1586},{},[27531],{"data":27532,"content":27533,"nodeType":876},{},[27534],{"data":27535,"marks":27536,"value":27537,"nodeType":867},{},[],"When they were created",{"data":27539,"content":27540,"nodeType":1586},{},[27541],{"data":27542,"content":27543,"nodeType":876},{},[27544],{"data":27545,"marks":27546,"value":27547,"nodeType":867},{},[],"How many times they have previously been scanned",{"data":27549,"content":27550,"nodeType":1586},{},[27551],{"data":27552,"content":27553,"nodeType":876},{},[27554],{"data":27555,"marks":27556,"value":27557,"nodeType":867},{},[],"When they were last scanned",{"data":27559,"content":27560,"nodeType":1586},{},[27561],{"data":27562,"content":27563,"nodeType":876},{},[27564],{"data":27565,"marks":27566,"value":27567,"nodeType":867},{},[],"If urlscan has marked them as suspicious",{"data":27569,"content":27573,"nodeType":985},{"target":27570},{"sys":27571},{"id":27572,"type":982,"linkType":983},"2AKpAk65XdmaGBfe2V4qZ5",[],{"data":27575,"content":27576,"nodeType":942},{},[],{"data":27578,"content":27579,"nodeType":868},{},[27580],{"data":27581,"marks":27582,"value":27584,"nodeType":867},{},[27583],{"type":865},"Check out our latest webinar for practical guidance in real-world scenarios",{"data":27586,"content":27587,"nodeType":876},{},[27588,27592,27601,27604],{"data":27589,"marks":27590,"value":27591,"nodeType":867},{},[],"For practical advice and applied examples of how to use Push data in incident response — as well as some bonus examples of automated response and remediation use cases — ",{"data":27593,"content":27595,"nodeType":915},{"uri":27594},"https://pushsecurity.com/webinar/identity-detection-response",[27596],{"data":27597,"marks":27598,"value":27600,"nodeType":867},{},[27599],{"type":913},"join us live on August 13 for our webinar",{"data":27602,"marks":27603,"value":5136,"nodeType":867},{},[],{"data":27605,"marks":27606,"value":27608,"nodeType":867},{},[27607],{"type":865},"“Identity attacks have changed — have your IR playbooks?”",{"data":27610,"content":27611,"nodeType":942},{},[],{"data":27613,"content":27614,"nodeType":868},{},[27615],{"data":27616,"marks":27617,"value":14676,"nodeType":867},{},[27618],{"type":865},{"data":27620,"content":27621,"nodeType":876},{},[27622],{"data":27623,"marks":27624,"value":27625,"nodeType":867},{},[],"Push’s browser-based security platform provides comprehensive identity attack detection and response capabilities against techniques like AiTM phishing, credential stuffing, password spraying, and session hijacking using stolen session tokens. ",{"data":27627,"content":27628,"nodeType":876},{},[27629],{"data":27630,"marks":27631,"value":27632,"nodeType":867},{},[],"You can also use Push to find and fix identity vulnerabilities across every app that your employees use, including ghost logins; SSO coverage gaps; MFA gaps; weak, breached and reused passwords; risky OAuth integrations; and more.",{"data":27634,"content":27635,"nodeType":876},{},[27636,27640,27648],{"data":27637,"marks":27638,"value":27639,"nodeType":867},{},[],"If you want to learn more about how Push helps you to detect and defeat common identity attack techniques, ",{"data":27641,"content":27642,"nodeType":915},{"uri":5286},[27643],{"data":27644,"marks":27645,"value":27647,"nodeType":867},{},[27646],{"type":913},"request a demo.",{"data":27649,"marks":27650,"value":21,"nodeType":867},{},[],"Introducing Push Detections: Equipping SecOps and IR teams to stop browser-based attacks","We’re launching a new Detections capability, enabling security teams to more effectively investigate and triage alerts, and build more effective workflows. ","2025-07-29T00:00:00.000Z","introducing-push-detections",{"items":27656},[27657,27659],{"sys":27658,"name":342},{"id":3240},{"sys":27660,"name":4018},{"id":4017},{"items":27662},[27663],{"fullName":2714,"firstName":2715,"jobTitle":851,"profilePicture":27664},{"url":2717},{"__typename":1772,"sys":27666,"content":27668,"title":28015,"synopsis":28016,"hashTags":59,"publishedDate":28017,"slug":28018,"tagsCollection":28019,"authorsCollection":28023},{"id":27667},"4rLP8wr6HnvBG2OzqYYKpF",{"json":27669},{"data":27670,"content":27671,"nodeType":1680},{},[27672,27679,27686,27693,27699,27706,27739,27746,27753,27760,27766,27773,27780,27798,27804,27811,27831,27851,27858,27865,27872,27879,27886,27893,27900,27920,27927,27934,27940,27947,27954,27979,27985,28003,28009],{"data":27673,"content":27674,"nodeType":876},{},[27675],{"data":27676,"marks":27677,"value":27678,"nodeType":867},{},[],"Scattered Spider has shown the world the devastating effects attackers can achieve by socially engineering IT help desks into performing MFA resets so they can take over accounts on sensitive corporate apps. ",{"data":27680,"content":27681,"nodeType":876},{},[27682],{"data":27683,"marks":27684,"value":27685,"nodeType":867},{},[],"That’s why we’re introducing Employee Identity Verification Codes — a simple, browser-based identity check that gives your help desk a reliable way to confirm they’re talking to someone from your organization.",{"data":27687,"content":27688,"nodeType":876},{},[27689],{"data":27690,"marks":27691,"value":27692,"nodeType":867},{},[],"Push now provides your employees with a rotating 6-digit verification code in their browser via the Push Security extension. When an employee contacts your IT help desk to request an MFA reset or access recovery, the help desk can ask for this code to verify their identity — ensuring it’s really them, and not an attacker.",{"data":27694,"content":27698,"nodeType":985},{"target":27695},{"sys":27696},{"id":27697,"type":982,"linkType":983},"3PkiGgzwSt9Nb5rsGRiQVZ",[],{"data":27700,"content":27701,"nodeType":876},{},[27702],{"data":27703,"marks":27704,"value":27705,"nodeType":867},{},[],"The employee identity verification codes are:",{"data":27707,"content":27708,"nodeType":1629},{},[27709,27719,27729],{"data":27710,"content":27711,"nodeType":1586},{},[27712],{"data":27713,"content":27714,"nodeType":876},{},[27715],{"data":27716,"marks":27717,"value":27718,"nodeType":867},{},[],"Session-aware - generated in users’ browsers and only visible to them when they click on the Push Security extension icon in their browser toolbar.",{"data":27720,"content":27721,"nodeType":1586},{},[27722],{"data":27723,"content":27724,"nodeType":876},{},[27725],{"data":27726,"marks":27727,"value":27728,"nodeType":867},{},[],"Rotating: they change every 24 hours",{"data":27730,"content":27731,"nodeType":1586},{},[27732],{"data":27733,"content":27734,"nodeType":876},{},[27735],{"data":27736,"marks":27737,"value":27738,"nodeType":867},{},[],"Lightweight: no additional apps or devices required",{"data":27740,"content":27741,"nodeType":876},{},[27742],{"data":27743,"marks":27744,"value":27745,"nodeType":867},{},[],"It’s a fast, simple verification method — directly in the employee’s browser — that addresses a real-world threat.",{"data":27747,"content":27748,"nodeType":868},{},[27749],{"data":27750,"marks":27751,"value":27752,"nodeType":867},{},[],"We think it’s swell, but don’t just take our word for it …",{"data":27754,"content":27755,"nodeType":876},{},[27756],{"data":27757,"marks":27758,"value":27759,"nodeType":867},{},[],"Eric Rubin — a Senior Manager in GitLab’s Corporate Security team — has already rolled out Employee Identity Verification Codes across his workforce. Here’s what he had to say about it:",{"data":27761,"content":27765,"nodeType":985},{"target":27762},{"sys":27763},{"id":27764,"type":982,"linkType":983},"5ZLaA869NXpMjVwkswEyOB",[],{"data":27767,"content":27768,"nodeType":876},{},[27769],{"data":27770,"marks":27771,"value":27772,"nodeType":867},{},[],"Thank you, Eric!",{"data":27774,"content":27775,"nodeType":868},{},[27776],{"data":27777,"marks":27778,"value":27779,"nodeType":867},{},[],"Why are help desk identity verification methods so hot right now?",{"data":27781,"content":27782,"nodeType":876},{},[27783,27787,27794],{"data":27784,"marks":27785,"value":27786,"nodeType":867},{},[],"A number of the high-profile incidents attributed to the ",{"data":27788,"content":27789,"nodeType":915},{"uri":22147},[27790],{"data":27791,"marks":27792,"value":27793,"nodeType":867},{},[],"Scattered Spider cybercriminal group",{"data":27795,"marks":27796,"value":27797,"nodeType":867},{},[]," saw them socially engineer IT help desks into resetting MFA on employee accounts that they had already acquired valid credentials for. These compromised accounts were typically on IdP systems like Okta providing SSO access to large numbers of downstream applications.",{"data":27799,"content":27803,"nodeType":985},{"target":27800},{"sys":27801},{"id":27802,"type":982,"linkType":983},"2F2dpOkyXWnrKgFC3dSl67",[],{"data":27805,"content":27806,"nodeType":1058},{},[27807],{"data":27808,"marks":27809,"value":27810,"nodeType":867},{},[],"Case study: The MGM Resorts breach",{"data":27812,"content":27813,"nodeType":876},{},[27814,27818,27827],{"data":27815,"marks":27816,"value":27817,"nodeType":867},{},[],"One of Scattered Spider’s most notorious and well-documented attacks was against ",{"data":27819,"content":27821,"nodeType":915},{"uri":27820},"https://pushsecurity.com/blog/identity-attacks-in-the-wild/#id-mgm-resorts-september-2023",[27822],{"data":27823,"marks":27824,"value":27826,"nodeType":867},{},[27825],{"type":913},"MGM Resorts",{"data":27828,"marks":27829,"value":27830,"nodeType":867},{},[],". Scattered Spider socially engineered MGM Resorts’ help desk personnel to bypass MFA and log in to accounts for which they had acquired valid login credentials via credential phishing and historical infostealer compromises. ",{"data":27832,"content":27833,"nodeType":876},{},[27834,27838,27847],{"data":27835,"marks":27836,"value":27837,"nodeType":867},{},[],"They specifically targeted accounts with Super Administrator privileges within MGM Resorts’ Okta tenant, which they then used to register a second, attacker-controlled IdP via ",{"data":27839,"content":27841,"nodeType":915},{"uri":27840},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/inbound_federation/description.md",[27842],{"data":27843,"marks":27844,"value":27846,"nodeType":867},{},[27845],{"type":913},"inbound federation",{"data":27848,"marks":27849,"value":27850,"nodeType":867},{},[],". This then enabled them to impersonate any user within the Okta tenant. ",{"data":27852,"content":27853,"nodeType":876},{},[27854],{"data":27855,"marks":27856,"value":27857,"nodeType":867},{},[],"The attackers were then able to abuse SSO access to downstream apps and platforms from various accounts, culminating in deployment of ransomware to around 100 ESXi servers and data exfiltration. ",{"data":27859,"content":27860,"nodeType":876},{},[27861],{"data":27862,"marks":27863,"value":27864,"nodeType":867},{},[],"The breach resulted in a 36-hour outage, a $100M hit to its Q3 results, one-time cyber consulting fees in the region of $10M, and a class-action lawsuit later settled for $45M. ",{"data":27866,"content":27867,"nodeType":1058},{},[27868],{"data":27869,"marks":27870,"value":27871,"nodeType":867},{},[],"Reassessing help desk verification processes",{"data":27873,"content":27874,"nodeType":876},{},[27875],{"data":27876,"marks":27877,"value":27878,"nodeType":867},{},[],"Scattered Spider’s high-profile attacks — including its most recent against UK retailers Marks & Spencer’s and the Co-op — has prompted many security teams to reassess the verification processes used by their IT help desks when an employee requests an MFA reset or access to sensitive applications. ",{"data":27880,"content":27881,"nodeType":876},{},[27882],{"data":27883,"marks":27884,"value":27885,"nodeType":867},{},[],"Initial guidance from across the industry included the use of call-back verification for any MFA or credential changes requested by an employee. However, Scattered Spider are also known to use SIM-swapping to trick mobile carriers into transferring a victim’s phone number to a SIM card controlled by the attacker - thereby allowing them to intercept verification calls. ",{"data":27887,"content":27888,"nodeType":868},{},[27889],{"data":27890,"marks":27891,"value":27892,"nodeType":867},{},[],"Simple verification using your employees’ browsers",{"data":27894,"content":27895,"nodeType":876},{},[27896],{"data":27897,"marks":27898,"value":27899,"nodeType":867},{},[],"Push already provides several controls that directly align to the other TTPs used by Scattered Spider. They include detecting stolen credentials, cloned login pages, AitM toolkits and compromised IdP sessions. ",{"data":27901,"content":27902,"nodeType":876},{},[27903,27907,27916],{"data":27904,"marks":27905,"value":27906,"nodeType":867},{},[],"(BTW, if this piques your interest, you can ",{"data":27908,"content":27910,"nodeType":915},{"uri":27909},"https://pushsecurity.com/resources?type=webinar#content",[27911],{"data":27912,"marks":27913,"value":27915,"nodeType":867},{},[27914],{"type":913},"stream our latest webinar",{"data":27917,"marks":27918,"value":27919,"nodeType":867},{},[]," where we deep-dive into Scattered Spider, how their TTPs are evolving in 2025, and what Push is doing to protect organizations against them.) ",{"data":27921,"content":27922,"nodeType":876},{},[27923],{"data":27924,"marks":27925,"value":27926,"nodeType":867},{},[],"But to provide our customers with an additional layer of defense against the Scattered Spider attack chain, we wanted to see how we could make it harder for attackers to socially engineer IT help desks into gaining access to IdP systems and sensitive apps.",{"data":27928,"content":27929,"nodeType":876},{},[27930],{"data":27931,"marks":27932,"value":27933,"nodeType":867},{},[],"As so often is the case, the answer was staring us right in the face - we can use our browser extension. By placing a verification code in the details tray of every employees’ Push extension, they can use that to verify their identity with their help desk team.",{"data":27935,"content":27939,"nodeType":985},{"target":27936},{"sys":27937},{"id":27938,"type":982,"linkType":983},"4hRJVGqKGyOHJ8NSsQYWGP",[],{"data":27941,"content":27942,"nodeType":868},{},[27943],{"data":27944,"marks":27945,"value":27946,"nodeType":867},{},[],"Get started today!",{"data":27948,"content":27949,"nodeType":876},{},[27950],{"data":27951,"marks":27952,"value":27953,"nodeType":867},{},[],"Employee verification codes is a Labs feature, which means it’s available on an early-access basis. We're particularly interested in hearing your feedback on how to develop this feature further.",{"data":27955,"content":27956,"nodeType":876},{},[27957,27961,27966,27970,27975],{"data":27958,"marks":27959,"value":27960,"nodeType":867},{},[],"You can enable Labs features by going to the ",{"data":27962,"marks":27963,"value":27965,"nodeType":867},{},[27964],{"type":865},"Settings",{"data":27967,"marks":27968,"value":27969,"nodeType":867},{},[]," page of the Push admin console and choosing the ",{"data":27971,"marks":27972,"value":27974,"nodeType":867},{},[27973],{"type":865},"Labs",{"data":27976,"marks":27977,"value":27978,"nodeType":867},{},[]," tab.",{"data":27980,"content":27984,"nodeType":985},{"target":27981},{"sys":27982},{"id":27983,"type":982,"linkType":983},"6TyqP2eOmalIF6RRoe476Y",[],{"data":27986,"content":27987,"nodeType":876},{},[27988,27992,27999],{"data":27989,"marks":27990,"value":27991,"nodeType":867},{},[],"If you’d like to find out more about this feature, and the other ways Push is stopping identity attacks in the browser, ",{"data":27993,"content":27994,"nodeType":915},{"uri":5286},[27995],{"data":27996,"marks":27997,"value":11707,"nodeType":867},{},[27998],{"type":913},{"data":28000,"marks":28001,"value":28002,"nodeType":867},{},[]," with one of our team. ",{"data":28004,"content":28008,"nodeType":985},{"target":28005},{"sys":28006},{"id":28007,"type":982,"linkType":983},"7xBE9MrnMy3hfwIkhLhNhQ",[],{"data":28010,"content":28011,"nodeType":876},{},[28012],{"data":28013,"marks":28014,"value":21,"nodeType":867},{},[],"A simple, browser-based way to protect your help desk against social engineering","Push's new Employee Identity Verification Codes feature is a simple way for your help desk to confirm they’re talking to someone from your organization.\n","2025-06-19T00:00:00.000Z","employee-identity-verification-codes-release",{"items":28020},[28021],{"sys":28022,"name":297},{"id":2706},{"items":28024},[28025],{"fullName":4089,"firstName":4090,"jobTitle":851,"profilePicture":28026},{"url":4094},{"__typename":1772,"sys":28028,"content":28030,"title":28579,"synopsis":28580,"hashTags":59,"publishedDate":28581,"slug":28582,"tagsCollection":28583,"authorsCollection":28589},{"id":28029},"4XZ6qCr8pjJvcD7hi09x2Y",{"json":28031},{"data":28032,"content":28033,"nodeType":1680},{},[28034,28053,28060,28083,28090,28097,28104,28124,28130,28133,28141,28148,28168,28213,28257,28288,28308,28313,28316,28324,28331,28338,28345,28352,28475,28482,28485,28492,28509,28526,28529,28537,28554,28561],{"data":28035,"content":28036,"nodeType":876},{},[28037,28041,28049],{"data":28038,"marks":28039,"value":28040,"nodeType":867},{},[],"Almost two years ago, we released our ",{"data":28042,"content":28043,"nodeType":915},{"uri":15408},[28044],{"data":28045,"marks":28046,"value":28048,"nodeType":867},{},[28047],{"type":913},"SaaS attacks matrix",{"data":28050,"marks":28051,"value":28052,"nodeType":867},{},[]," on GitHub. At the time, our research into modern attack patterns showed us that attackers were increasingly relying on cloud-native techniques, taking advantage of the shift in business IT from traditional on-premise networks to a web of third-party services accessed over the internet. ",{"data":28054,"content":28055,"nodeType":876},{},[28056],{"data":28057,"marks":28058,"value":28059,"nodeType":867},{},[],"As part of our work in maintaining and updating the SaaS attacks matrix in line with our own research and attacks in the wild, we identified that:",{"data":28061,"content":28062,"nodeType":1629},{},[28063,28073],{"data":28064,"content":28065,"nodeType":1586},{},[28066],{"data":28067,"content":28068,"nodeType":876},{},[28069],{"data":28070,"marks":28071,"value":28072,"nodeType":867},{},[],"The fastest growing category since day 1 has been initial access, which is entirely driven by identity-based techniques (i.e. logging into apps).",{"data":28074,"content":28075,"nodeType":1586},{},[28076],{"data":28077,"content":28078,"nodeType":876},{},[28079],{"data":28080,"marks":28081,"value":28082,"nodeType":867},{},[],"Phishing in various forms is the most widely used, and generally effective, of all the initial access techniques we encounter. ",{"data":28084,"content":28085,"nodeType":876},{},[28086],{"data":28087,"marks":28088,"value":28089,"nodeType":867},{},[],"It’s increasingly difficult to reflect a lot of the research we’re doing within the parameters of the SaaS attacks matrix when attackers are doing so much (and to varying levels) in how they architect their phishing sites, distribute links and lures, and find novel ways around authentication and access controls. ",{"data":28091,"content":28092,"nodeType":876},{},[28093],{"data":28094,"marks":28095,"value":28096,"nodeType":867},{},[],"Equally, while there’s a huge amount of valuable research and deep-dive analysis of how individual phishing kits are behaving produced by security firms, there’s a gap in how we’re bringing together this knowledge and understanding the broad strokes of why and how phishing attacks are still so successful.  ",{"data":28098,"content":28099,"nodeType":876},{},[28100],{"data":28101,"marks":28102,"value":28103,"nodeType":867},{},[],"We come across so many phishing attacks on a daily basis that it’s impossible to write a deep-dive teardown on every one — and to some extent it wouldn’t be useful to do so. What’s arguably more valuable is understanding the patterns and commonalities across phishing campaigns that can help us to understand, generally, how malicious tooling and tradecraft is evolving. ",{"data":28105,"content":28106,"nodeType":876},{},[28107,28111,28120],{"data":28108,"marks":28109,"value":28110,"nodeType":867},{},[],"So, we decided to ",{"data":28112,"content":28114,"nodeType":915},{"uri":28113},"https://pushsecurity.github.io/phishing-techniques/",[28115],{"data":28116,"marks":28117,"value":28119,"nodeType":867},{},[28118],{"type":913},"create a new resource",{"data":28121,"marks":28122,"value":28123,"nodeType":867},{},[]," giving phishing the space to breathe that it deserves. ",{"data":28125,"content":28129,"nodeType":985},{"target":28126},{"sys":28127},{"id":28128,"type":982,"linkType":983},"7rK8RR8KKQ9DbBouZKnjs6",[],{"data":28131,"content":28132,"nodeType":942},{},[],{"data":28134,"content":28135,"nodeType":868},{},[28136],{"data":28137,"marks":28138,"value":28140,"nodeType":867},{},[28139],{"type":865},"How phishing has evolved",{"data":28142,"content":28143,"nodeType":876},{},[28144],{"data":28145,"marks":28146,"value":28147,"nodeType":867},{},[],"It’s easy to write off phishing as unsophisticated and simplistic, particularly when we think back to the first generation of phishing attacks — static HTML pages purely designed to steal your username and password, linked directly from an email. ",{"data":28149,"content":28150,"nodeType":876},{},[28151,28155,28164],{"data":28152,"marks":28153,"value":28154,"nodeType":867},{},[],"Modern phishing has changed a lot in the past decade or so. ",{"data":28156,"content":28158,"nodeType":915},{"uri":28157},"https://phishing-techniques.pushsecurity.com/techniques/aitm-phishing/",[28159],{"data":28160,"marks":28161,"value":28163,"nodeType":867},{},[28162],{"type":913},"MFA-bypassing  Attacker-in-the-Middle (AitM) kits",{"data":28165,"marks":28166,"value":28167,"nodeType":867},{},[]," are table stakes — anyone can pick up a copy of Evilginx and immediately blow past most email and network security solutions on the market.  ",{"data":28169,"content":28170,"nodeType":876},{},[28171,28175,28183,28187,28196,28200,28209],{"data":28172,"marks":28173,"value":28174,"nodeType":867},{},[],"But the most sophisticated attacks — the ones that usually hit the headlines in the form of major breaches — are doing much more than this. The latest generation of fully customized AitM phishing kits are ",{"data":28176,"content":28177,"nodeType":915},{"uri":21853},[28178],{"data":28179,"marks":28180,"value":28182,"nodeType":867},{},[28181],{"type":913},"dynamically obfuscating the code that loads the web page",{"data":28184,"marks":28185,"value":28186,"nodeType":867},{},[],", implementing ",{"data":28188,"content":28190,"nodeType":915},{"uri":28189},"https://phishing-techniques.pushsecurity.com/techniques/bot-protection/",[28191],{"data":28192,"marks":28193,"value":28195,"nodeType":867},{},[28194],{"type":913},"bot protection through custom CAPTCHA",{"data":28197,"marks":28198,"value":28199,"nodeType":867},{},[],", and using ",{"data":28201,"content":28203,"nodeType":915},{"uri":28202},"https://phishing-techniques.pushsecurity.com/techniques/anti-sandbox/",[28204],{"data":28205,"marks":28206,"value":28208,"nodeType":867},{},[28207],{"type":913},"runtime anti-analysis features",{"data":28210,"marks":28211,"value":28212,"nodeType":867},{},[],", making them increasingly difficult to detect by the tools most enterprises are using to combat the problem. ",{"data":28214,"content":28215,"nodeType":876},{},[28216,28220,28227,28231,28240,28244,28253],{"data":28217,"marks":28218,"value":28219,"nodeType":867},{},[],"The techniques used by attackers to deliver phishing lures are also more sophisticated. Groups like Scattered Spider have been seen using ",{"data":28221,"content":28222,"nodeType":915},{"uri":21222},[28223],{"data":28224,"marks":28225,"value":441,"nodeType":867},{},[28226],{"type":913},{"data":28228,"marks":28229,"value":28230,"nodeType":867},{},[]," techniques, delivering phishing links via paid Google ads, while phishing campaigns are frequently encountered in ",{"data":28232,"content":28234,"nodeType":915},{"uri":28233},"https://phishing-techniques.pushsecurity.com/techniques/instant-messenger/",[28235],{"data":28236,"marks":28237,"value":28239,"nodeType":867},{},[28238],{"type":913},"IM apps",{"data":28241,"marks":28242,"value":28243,"nodeType":867},{},[]," (such as Slack and Teams), as well as ",{"data":28245,"content":28247,"nodeType":915},{"uri":28246},"https://phishing-techniques.pushsecurity.com/techniques/social-media/",[28248],{"data":28249,"marks":28250,"value":28252,"nodeType":867},{},[28251],{"type":913},"public messaging services",{"data":28254,"marks":28255,"value":28256,"nodeType":867},{},[]," like LinkedIn messenger and Reddit — bypassing email altogether. ",{"data":28258,"content":28259,"nodeType":876},{},[28260,28264,28273,28277,28285],{"data":28261,"marks":28262,"value":28263,"nodeType":867},{},[],"The latest trends indicate that attackers are responding to increasingly hardened IdP/SSO configuration by using alternative phishing techniques that circumvent MFA and passkeys, either by ",{"data":28265,"content":28267,"nodeType":915},{"uri":28266},"https://phishing-techniques.pushsecurity.com/techniques/mfa-downgrade/",[28268],{"data":28269,"marks":28270,"value":28272,"nodeType":867},{},[28271],{"type":913},"downgrading to a backup (less secure) authentication method",{"data":28274,"marks":28275,"value":28276,"nodeType":867},{},[],", or sidestepping the legitimate auth process entirely through methods like ",{"data":28278,"content":28280,"nodeType":915},{"uri":28279},"https://phishing-techniques.pushsecurity.com/techniques/consent-phishing/",[28281],{"data":28282,"marks":28283,"value":23298,"nodeType":867},{},[28284],{"type":913},{"data":28286,"marks":28287,"value":5704,"nodeType":867},{},[],{"data":28289,"content":28290,"nodeType":876},{},[28291,28295,28304],{"data":28292,"marks":28293,"value":28294,"nodeType":867},{},[],"Attackers have also realized how much valuable data exists in Shadow SaaS highlighted by major SaaS breaches impacting apps like Snowflake. This is driving ",{"data":28296,"content":28298,"nodeType":915},{"uri":28297},"https://phishing-techniques.pushsecurity.com/techniques/saas-admins/",[28299],{"data":28300,"marks":28301,"value":28303,"nodeType":867},{},[28302],{"type":913},"broader targeting against apps like Slack, Mailchimp, Postman, GitHub, and other commonly-used business apps directly",{"data":28305,"marks":28306,"value":28307,"nodeType":867},{},[]," — bypassing IdPs (MS, Google, Okta, etc.) that typically have more robust authentication controls in place.",{"data":28309,"content":28312,"nodeType":985},{"target":28310},{"sys":28311},{"id":21904,"type":982,"linkType":983},[],{"data":28314,"content":28315,"nodeType":942},{},[],{"data":28317,"content":28318,"nodeType":868},{},[28319],{"data":28320,"marks":28321,"value":28323,"nodeType":867},{},[28322],{"type":865},"Using the phishing detection evasion techniques matrix",{"data":28325,"content":28326,"nodeType":876},{},[28327],{"data":28328,"marks":28329,"value":28330,"nodeType":867},{},[],"With so much attacker innovation happening in the phishing space, it’s tricky for security teams and solution vendors to have a big picture view of the subtle changes attackers are making to their phishing attacks, and precisely why they’re doing it — or more specifically, which detection techniques they’re evading. ",{"data":28332,"content":28333,"nodeType":876},{},[28334],{"data":28335,"marks":28336,"value":28337,"nodeType":867},{},[],"If you look at one of the many phishing kit teardowns found in security blogs online (including our own) it can be hard to see the wood for the trees when it comes to understanding why a phishing page behaves in the way it does — why is it behaving in this way? What control exactly is this trying to get around? ",{"data":28339,"content":28340,"nodeType":876},{},[28341],{"data":28342,"marks":28343,"value":28344,"nodeType":867},{},[],"By creating a simple framework breaking down the categories of a phishing attack into phases, each with its own specific attacker objective, we can better understand phishing kit behavior and track meaningful changes over time. This ensures that we understand how we need to adapt to as an industry in order to detect and block these attacks. ",{"data":28346,"content":28347,"nodeType":876},{},[28348],{"data":28349,"marks":28350,"value":28351,"nodeType":867},{},[],"The matrix covers the following categories:",{"data":28353,"content":28354,"nodeType":1629},{},[28355,28370,28385,28400,28415,28430,28445,28460],{"data":28356,"content":28357,"nodeType":1586},{},[28358],{"data":28359,"content":28360,"nodeType":876},{},[28361,28366],{"data":28362,"marks":28363,"value":28365,"nodeType":867},{},[28364],{"type":865},"Phase 1: Targeting",{"data":28367,"marks":28368,"value":28369,"nodeType":867},{},[]," — Identifying apps and users to evade security controls and achieve the shortest time-to-impact of a phishing attack. ",{"data":28371,"content":28372,"nodeType":1586},{},[28373],{"data":28374,"content":28375,"nodeType":876},{},[28376,28381],{"data":28377,"marks":28378,"value":28380,"nodeType":867},{},[28379],{"type":865},"Phase 2: Link delivery",{"data":28382,"marks":28383,"value":28384,"nodeType":867},{},[]," — Deliver links using phishing vectors that evade traditional security controls. ",{"data":28386,"content":28387,"nodeType":1586},{},[28388],{"data":28389,"content":28390,"nodeType":876},{},[28391,28396],{"data":28392,"marks":28393,"value":28395,"nodeType":867},{},[28394],{"type":865},"Phase 3: Link camouflage",{"data":28397,"marks":28398,"value":28399,"nodeType":867},{},[]," — Masking malicious links to prevent detection at the email, network proxy, or safe browsing layer. ",{"data":28401,"content":28402,"nodeType":1586},{},[28403],{"data":28404,"content":28405,"nodeType":876},{},[28406,28411],{"data":28407,"marks":28408,"value":28410,"nodeType":867},{},[28409],{"type":865},"Phase 4: TI evasion ",{"data":28412,"marks":28413,"value":28414,"nodeType":867},{},[],"— Preventing TI feeds from flagging and blocking known-bad domains by masking or changing elements likely to be flagged.",{"data":28416,"content":28417,"nodeType":1586},{},[28418],{"data":28419,"content":28420,"nodeType":876},{},[28421,28426],{"data":28422,"marks":28423,"value":28425,"nodeType":867},{},[28424],{"type":865},"Phase 5: Anti-analysis",{"data":28427,"marks":28428,"value":28429,"nodeType":867},{},[]," — Techniques to defeat automated “sandbox” analysis tools by preventing security teams and bots from accessing the page.",{"data":28431,"content":28432,"nodeType":1586},{},[28433],{"data":28434,"content":28435,"nodeType":876},{},[28436,28441],{"data":28437,"marks":28438,"value":28440,"nodeType":867},{},[28439],{"type":865},"Phase 6: Page obfuscation",{"data":28442,"marks":28443,"value":28444,"nodeType":867},{},[]," — Obfuscating page elements to break detection signatures analysing page content and code. ",{"data":28446,"content":28447,"nodeType":1586},{},[28448],{"data":28449,"content":28450,"nodeType":876},{},[28451,28456],{"data":28452,"marks":28453,"value":28455,"nodeType":867},{},[28454],{"type":865},"Phase 7: Defeat MFA & CA",{"data":28457,"marks":28458,"value":28459,"nodeType":867},{},[]," — Defeat authentication and access controls in order to successfully execute the phishing attack.",{"data":28461,"content":28462,"nodeType":1586},{},[28463],{"data":28464,"content":28465,"nodeType":876},{},[28466,28471],{"data":28467,"marks":28468,"value":28470,"nodeType":867},{},[28469],{"type":865},"Phase 8: Account takeover",{"data":28472,"marks":28473,"value":28474,"nodeType":867},{},[]," — Achieve a form of account takeover and conclude the identity attack, enabling further exploitation to take place.",{"data":28476,"content":28477,"nodeType":876},{},[28478],{"data":28479,"marks":28480,"value":28481,"nodeType":867},{},[],"Combining techniques and approaches from these categories is what enables attackers to bypass the majority of phishing detection controls they encounter today. You typically find that the more advanced the phishing kit / attacker, the more techniques they’ll leverage. And as phishing infrastructure becomes increasingly templated and commodified with as-a-Service or for-hire models, the average phishing attack will employ more of these measures to counter security controls. ",{"data":28483,"content":28484,"nodeType":942},{},[],{"data":28486,"content":28487,"nodeType":868},{},[28488],{"data":28489,"marks":28490,"value":18329,"nodeType":867},{},[28491],{"type":865},{"data":28493,"content":28494,"nodeType":876},{},[28495,28498,28506],{"data":28496,"marks":28497,"value":21,"nodeType":867},{},[],{"data":28499,"content":28500,"nodeType":915},{"uri":28113},[28501],{"data":28502,"marks":28503,"value":28505,"nodeType":867},{},[28504],{"type":913},"You can find the matrix here.",{"data":28507,"marks":28508,"value":21,"nodeType":867},{},[],{"data":28510,"content":28511,"nodeType":876},{},[28512,28516,28523],{"data":28513,"marks":28514,"value":28515,"nodeType":867},{},[],"If you want to learn more about the research that led us to this point, and our take on how and why phishing attacks have evolved, ",{"data":28517,"content":28518,"nodeType":915},{"uri":26617},[28519],{"data":28520,"marks":28521,"value":28522,"nodeType":867},{},[],"you can also check out our latest whitepaper. ",{"data":28524,"marks":28525,"value":21,"nodeType":867},{},[],{"data":28527,"content":28528,"nodeType":942},{},[],{"data":28530,"content":28531,"nodeType":868},{},[28532],{"data":28533,"marks":28534,"value":28536,"nodeType":867},{},[28535],{"type":865},"Get involved!",{"data":28538,"content":28539,"nodeType":876},{},[28540,28544,28550],{"data":28541,"marks":28542,"value":28543,"nodeType":867},{},[],"Like the ",{"data":28545,"content":28546,"nodeType":915},{"uri":15408},[28547],{"data":28548,"marks":28549,"value":14765,"nodeType":867},{},[],{"data":28551,"marks":28552,"value":28553,"nodeType":867},{},[],", we’d love to see the security community using and helping us to maintain this resource to ensure it stays up to date with techniques as they evolve. ",{"data":28555,"content":28556,"nodeType":876},{},[28557],{"data":28558,"marks":28559,"value":28560,"nodeType":867},{},[],"Unlike the SaaS matrix, which we’ve seen mostly leveraged by offensive security practitioners, phishing detection evasion techniques are most useful to blue teamers looking to assess current detection capabilities and understand why certain attacks got through existing defenses. ",{"data":28562,"content":28563,"nodeType":876},{},[28564,28568,28576],{"data":28565,"marks":28566,"value":28567,"nodeType":867},{},[],"If you’d like to add techniques you’ve observed or examples that you think demonstrate them, ",{"data":28569,"content":28571,"nodeType":915},{"uri":28570},"https://github.com/pushsecurity/phishing-techniques",[28572],{"data":28573,"marks":28574,"value":28575,"nodeType":867},{},[],"get involved on GitHub!",{"data":28577,"marks":28578,"value":21,"nodeType":867},{},[],"Introducing our guide to phishing detection evasion techniques","Introducing our latest resource for security teams breaking down the techniques that modern phishing attacks are using to evade detection. ","2025-08-06T00:00:00.000Z","phishing-detection-evasion-launch",{"items":28584},[28585,28587],{"sys":28586,"name":342},{"id":3240},{"sys":28588,"name":4018},{"id":4017},{"items":28590},[28591],{"fullName":28592,"firstName":28593,"jobTitle":28594,"profilePicture":28595},"Jacques Louw","Jacques","Co-founder / CRO",{"url":28596},"https://images.ctfassets.net/y1cdw1ablpvd/39m8bektV23lnCRcEq0G8h/2a08f6276a50744f1a4b499b273f6bb2/Push_Founders_at_Cahoots_October_28_2022_by_Doug_Coombe-21.jpg","how-the-browser-became-the-main-cyber-battleground","blog/how-the-browser-became-the-main-cyber-battleground",{"json":28600},{"data":28601,"content":28602,"nodeType":1680},{},[28603],{"data":28604,"content":28605,"nodeType":876},{},[28606],{"data":28607,"marks":28608,"value":28609,"nodeType":867},{},[],"How attacks have moved away from endpoints and internal networks to the browser — a blind spot for traditional security tools.",{"id":28611,"publishedAt":28612},"31m73YMGdCyqVmjHulBwER","2026-08-12T11:53:53.682Z",{"items":28614},[28615,28617],{"sys":28616,"name":342},{"id":3240},{"sys":28618,"name":4018},{"id":4017},{"items":28620},[28621,28623,28625,28627,28629,28631,28633,28635,28637,28639,28641,28643,28645,28647,28649,28651,28653,28655,28657,28659,28661,28663,28665,28667,28669],{"sys":28622,"name":279,"slug":280,"tier":31},{"id":276},{"sys":28624,"name":297,"slug":298,"tier":31},{"id":294},{"sys":28626,"name":413,"slug":414,"tier":31},{"id":410},{"sys":28628,"name":519,"slug":520,"tier":31},{"id":516},{"sys":28630,"name":545,"slug":546,"tier":31},{"id":542},{"sys":28632,"name":342,"slug":343,"tier":31},{"id":339},{"sys":28634,"name":642,"slug":643,"tier":31},{"id":639},{"sys":28636,"name":377,"slug":378,"tier":45},{"id":374},{"sys":28638,"name":404,"slug":405,"tier":45},{"id":401},{"sys":28640,"name":324,"slug":325,"tier":45},{"id":321},{"sys":28642,"name":333,"slug":334,"tier":45},{"id":330},{"sys":28644,"name":571,"slug":572,"tier":45},{"id":568},{"sys":28646,"name":422,"slug":423,"tier":45},{"id":419},{"sys":28648,"name":261,"slug":262,"tier":45},{"id":258},{"sys":28650,"name":466,"slug":467,"tier":45},{"id":463},{"sys":28652,"name":457,"slug":458,"tier":45},{"id":454},{"sys":28654,"name":395,"slug":396,"tier":45},{"id":392},{"sys":28656,"name":288,"slug":289,"tier":45},{"id":285},{"sys":28658,"name":484,"slug":485,"tier":45},{"id":481},{"sys":28660,"name":589,"slug":590,"tier":45},{"id":586},{"sys":28662,"name":607,"slug":608,"tier":45},{"id":604},{"sys":28664,"name":475,"slug":476,"tier":45},{"id":472},{"sys":28666,"name":511,"slug":512,"tier":45},{"id":508},{"sys":28668,"name":493,"slug":494,"tier":45},{"id":490},{"sys":28670,"name":440,"slug":441,"tier":45},{"id":437},"PonpZ2he3fGXpKQWTeIZC0k0nbZ5ZfYtQyn8NDwmYDI",{"id":28673,"title":27651,"authorsCollection":28674,"content":28678,"extension":228,"faqItemsCollection":29620,"faqTitle":59,"featured":6,"hashTags":59,"meta":29622,"metaTitle":29623,"ogImage":59,"postType":24263,"publishedDate":27653,"relatedBlogPostsCollection":29624,"slug":27654,"stem":31230,"subtitle":59,"summary":31231,"synopsis":27652,"sys":31242,"tagsCollection":31244,"topicsCollection":31250,"__hash__":31292},"blog/blog/introducing-push-detections.json",{"items":28675},[28676],{"fullName":2714,"firstName":2715,"jobTitle":851,"socialLinks":59,"profilePicture":28677},{"url":2717},{"json":28679,"links":29526},{"data":28680,"content":28681,"nodeType":1680},{},[28682,28688,28698,28708,28718,28728,28733,28749,28755,28768,28774,28779,28782,28789,28795,28801,28807,28812,28815,28822,28828,28844,28850,28856,28862,28868,28873,28879,28885,28891,28916,28922,28938,28944,28950,28966,28982,28998,29003,29009,29022,29028,29034,29040,29056,29063,29069,29075,29078,29085,29091,29097,29103,29142,29147,29153,29166,29243,29248,29254,29260,29317,29323,29329,29335,29340,29346,29352,29358,29363,29369,29375,29381,29386,29402,29408,29414,29453,29458,29461,29468,29488,29491,29498,29504,29510],{"data":28683,"content":28684,"nodeType":876},{},[28685],{"data":28686,"marks":28687,"value":26677,"nodeType":867},{},[],{"data":28689,"content":28690,"nodeType":876},{},[28691,28695],{"data":28692,"marks":28693,"value":26685,"nodeType":867},{},[28694],{"type":865},{"data":28696,"marks":28697,"value":26689,"nodeType":867},{},[],{"data":28699,"content":28700,"nodeType":876},{},[28701,28705],{"data":28702,"marks":28703,"value":26697,"nodeType":867},{},[28704],{"type":865},{"data":28706,"marks":28707,"value":26701,"nodeType":867},{},[],{"data":28709,"content":28710,"nodeType":876},{},[28711,28715],{"data":28712,"marks":28713,"value":26709,"nodeType":867},{},[28714],{"type":865},{"data":28716,"marks":28717,"value":26713,"nodeType":867},{},[],{"data":28719,"content":28720,"nodeType":876},{},[28721,28725],{"data":28722,"marks":28723,"value":26721,"nodeType":867},{},[28724],{"type":865},{"data":28726,"marks":28727,"value":26725,"nodeType":867},{},[],{"data":28729,"content":28732,"nodeType":985},{"target":28730},{"sys":28731},{"id":26730,"type":982,"linkType":983},[],{"data":28734,"content":28735,"nodeType":876},{},[28736,28739,28746],{"data":28737,"marks":28738,"value":26738,"nodeType":867},{},[],{"data":28740,"content":28741,"nodeType":915},{"uri":22147},[28742],{"data":28743,"marks":28744,"value":26746,"nodeType":867},{},[28745],{"type":913},{"data":28747,"marks":28748,"value":26750,"nodeType":867},{},[],{"data":28750,"content":28751,"nodeType":876},{},[28752],{"data":28753,"marks":28754,"value":26757,"nodeType":867},{},[],{"data":28756,"content":28757,"nodeType":876},{},[28758,28761,28765],{"data":28759,"marks":28760,"value":26764,"nodeType":867},{},[],{"data":28762,"marks":28763,"value":26769,"nodeType":867},{},[28764],{"type":865},{"data":28766,"marks":28767,"value":26773,"nodeType":867},{},[],{"data":28769,"content":28770,"nodeType":876},{},[28771],{"data":28772,"marks":28773,"value":26780,"nodeType":867},{},[],{"data":28775,"content":28778,"nodeType":985},{"target":28776},{"sys":28777},{"id":26785,"type":982,"linkType":983},[],{"data":28780,"content":28781,"nodeType":942},{},[],{"data":28783,"content":28784,"nodeType":868},{},[28785],{"data":28786,"marks":28787,"value":26797,"nodeType":867},{},[28788],{"type":865},{"data":28790,"content":28791,"nodeType":876},{},[28792],{"data":28793,"marks":28794,"value":26804,"nodeType":867},{},[],{"data":28796,"content":28797,"nodeType":876},{},[28798],{"data":28799,"marks":28800,"value":26811,"nodeType":867},{},[],{"data":28802,"content":28803,"nodeType":876},{},[28804],{"data":28805,"marks":28806,"value":26818,"nodeType":867},{},[],{"data":28808,"content":28811,"nodeType":985},{"target":28809},{"sys":28810},{"id":26823,"type":982,"linkType":983},[],{"data":28813,"content":28814,"nodeType":942},{},[],{"data":28816,"content":28817,"nodeType":868},{},[28818],{"data":28819,"marks":28820,"value":26835,"nodeType":867},{},[28821],{"type":865},{"data":28823,"content":28824,"nodeType":876},{},[28825],{"data":28826,"marks":28827,"value":26842,"nodeType":867},{},[],{"data":28829,"content":28830,"nodeType":876},{},[28831,28834,28841],{"data":28832,"marks":28833,"value":26849,"nodeType":867},{},[],{"data":28835,"content":28836,"nodeType":915},{"uri":26852},[28837],{"data":28838,"marks":28839,"value":26858,"nodeType":867},{},[28840],{"type":913},{"data":28842,"marks":28843,"value":26862,"nodeType":867},{},[],{"data":28845,"content":28846,"nodeType":876},{},[28847],{"data":28848,"marks":28849,"value":26869,"nodeType":867},{},[],{"data":28851,"content":28852,"nodeType":876},{},[28853],{"data":28854,"marks":28855,"value":26876,"nodeType":867},{},[],{"data":28857,"content":28858,"nodeType":1058},{},[28859],{"data":28860,"marks":28861,"value":26883,"nodeType":867},{},[],{"data":28863,"content":28864,"nodeType":876},{},[28865],{"data":28866,"marks":28867,"value":26890,"nodeType":867},{},[],{"data":28869,"content":28872,"nodeType":985},{"target":28870},{"sys":28871},{"id":26895,"type":982,"linkType":983},[],{"data":28874,"content":28875,"nodeType":876},{},[28876],{"data":28877,"marks":28878,"value":26903,"nodeType":867},{},[],{"data":28880,"content":28881,"nodeType":1058},{},[28882],{"data":28883,"marks":28884,"value":26910,"nodeType":867},{},[],{"data":28886,"content":28887,"nodeType":876},{},[28888],{"data":28889,"marks":28890,"value":26917,"nodeType":867},{},[],{"data":28892,"content":28893,"nodeType":876},{},[28894,28897,28905,28909,28912],{"data":28895,"marks":28896,"value":26924,"nodeType":867},{},[],{"data":28898,"content":28899,"nodeType":915},{"uri":3332},[28900],{"data":28901,"marks":28902,"value":26933,"nodeType":867},{},[28903,28904],{"type":913},{"type":865},{"data":28906,"marks":28907,"value":2136,"nodeType":867},{},[28908],{"type":865},{"data":28910,"marks":28911,"value":26941,"nodeType":867},{},[],{"data":28913,"marks":28914,"value":25919,"nodeType":867},{},[28915],{"type":865},{"data":28917,"content":28918,"nodeType":876},{},[28919],{"data":28920,"marks":28921,"value":26952,"nodeType":867},{},[],{"data":28923,"content":28924,"nodeType":876},{},[28925,28928,28935],{"data":28926,"marks":28927,"value":26959,"nodeType":867},{},[],{"data":28929,"content":28930,"nodeType":915},{"uri":22147},[28931],{"data":28932,"marks":28933,"value":1182,"nodeType":867},{},[28934],{"type":913},{"data":28936,"marks":28937,"value":26970,"nodeType":867},{},[],{"data":28939,"content":28940,"nodeType":1058},{},[28941],{"data":28942,"marks":28943,"value":26977,"nodeType":867},{},[],{"data":28945,"content":28946,"nodeType":876},{},[28947],{"data":28948,"marks":28949,"value":26984,"nodeType":867},{},[],{"data":28951,"content":28952,"nodeType":876},{},[28953,28956,28963],{"data":28954,"marks":28955,"value":26991,"nodeType":867},{},[],{"data":28957,"content":28958,"nodeType":915},{"uri":26994},[28959],{"data":28960,"marks":28961,"value":27000,"nodeType":867},{},[28962],{"type":913},{"data":28964,"marks":28965,"value":27004,"nodeType":867},{},[],{"data":28967,"content":28968,"nodeType":876},{},[28969,28972,28979],{"data":28970,"marks":28971,"value":27011,"nodeType":867},{},[],{"data":28973,"content":28974,"nodeType":915},{"uri":27014},[28975],{"data":28976,"marks":28977,"value":27020,"nodeType":867},{},[28978],{"type":913},{"data":28980,"marks":28981,"value":27024,"nodeType":867},{},[],{"data":28983,"content":28984,"nodeType":876},{},[28985,28988,28995],{"data":28986,"marks":28987,"value":27031,"nodeType":867},{},[],{"data":28989,"content":28990,"nodeType":915},{"uri":27034},[28991],{"data":28992,"marks":28993,"value":27040,"nodeType":867},{},[28994],{"type":913},{"data":28996,"marks":28997,"value":27044,"nodeType":867},{},[],{"data":28999,"content":29002,"nodeType":985},{"target":29000},{"sys":29001},{"id":27049,"type":982,"linkType":983},[],{"data":29004,"content":29005,"nodeType":1058},{},[29006],{"data":29007,"marks":29008,"value":27057,"nodeType":867},{},[],{"data":29010,"content":29011,"nodeType":876},{},[29012,29015,29019],{"data":29013,"marks":29014,"value":27064,"nodeType":867},{},[],{"data":29016,"marks":29017,"value":27069,"nodeType":867},{},[29018],{"type":1303},{"data":29020,"marks":29021,"value":27073,"nodeType":867},{},[],{"data":29023,"content":29024,"nodeType":876},{},[29025],{"data":29026,"marks":29027,"value":27080,"nodeType":867},{},[],{"data":29029,"content":29030,"nodeType":876},{},[29031],{"data":29032,"marks":29033,"value":27087,"nodeType":867},{},[],{"data":29035,"content":29036,"nodeType":876},{},[29037],{"data":29038,"marks":29039,"value":27094,"nodeType":867},{},[],{"data":29041,"content":29042,"nodeType":876},{},[29043,29046,29053],{"data":29044,"marks":29045,"value":27101,"nodeType":867},{},[],{"data":29047,"content":29048,"nodeType":915},{"uri":26236},[29049],{"data":29050,"marks":29051,"value":27109,"nodeType":867},{},[29052],{"type":913},{"data":29054,"marks":29055,"value":27113,"nodeType":867},{},[],{"data":29057,"content":29058,"nodeType":876},{},[29059],{"data":29060,"marks":29061,"value":27121,"nodeType":867},{},[29062],{"type":865},{"data":29064,"content":29065,"nodeType":876},{},[29066],{"data":29067,"marks":29068,"value":27128,"nodeType":867},{},[],{"data":29070,"content":29071,"nodeType":876},{},[29072],{"data":29073,"marks":29074,"value":27135,"nodeType":867},{},[],{"data":29076,"content":29077,"nodeType":942},{},[],{"data":29079,"content":29080,"nodeType":868},{},[29081],{"data":29082,"marks":29083,"value":27146,"nodeType":867},{},[29084],{"type":865},{"data":29086,"content":29087,"nodeType":876},{},[29088],{"data":29089,"marks":29090,"value":27153,"nodeType":867},{},[],{"data":29092,"content":29093,"nodeType":876},{},[29094],{"data":29095,"marks":29096,"value":27160,"nodeType":867},{},[],{"data":29098,"content":29099,"nodeType":876},{},[29100],{"data":29101,"marks":29102,"value":27167,"nodeType":867},{},[],{"data":29104,"content":29105,"nodeType":1629},{},[29106,29115,29124,29133],{"data":29107,"content":29108,"nodeType":1586},{},[29109],{"data":29110,"content":29111,"nodeType":876},{},[29112],{"data":29113,"marks":29114,"value":27180,"nodeType":867},{},[],{"data":29116,"content":29117,"nodeType":1586},{},[29118],{"data":29119,"content":29120,"nodeType":876},{},[29121],{"data":29122,"marks":29123,"value":27190,"nodeType":867},{},[],{"data":29125,"content":29126,"nodeType":1586},{},[29127],{"data":29128,"content":29129,"nodeType":876},{},[29130],{"data":29131,"marks":29132,"value":27200,"nodeType":867},{},[],{"data":29134,"content":29135,"nodeType":1586},{},[29136],{"data":29137,"content":29138,"nodeType":876},{},[29139],{"data":29140,"marks":29141,"value":27210,"nodeType":867},{},[],{"data":29143,"content":29146,"nodeType":985},{"target":29144},{"sys":29145},{"id":27215,"type":982,"linkType":983},[],{"data":29148,"content":29149,"nodeType":876},{},[29150],{"data":29151,"marks":29152,"value":27223,"nodeType":867},{},[],{"data":29154,"content":29155,"nodeType":876},{},[29156,29159,29163],{"data":29157,"marks":29158,"value":27230,"nodeType":867},{},[],{"data":29160,"marks":29161,"value":26769,"nodeType":867},{},[29162],{"type":865},{"data":29164,"marks":29165,"value":27238,"nodeType":867},{},[],{"data":29167,"content":29168,"nodeType":1629},{},[29169,29198,29207,29216,29225,29234],{"data":29170,"content":29171,"nodeType":1586},{},[29172],{"data":29173,"content":29174,"nodeType":876},{},[29175,29178,29185,29188,29195],{"data":29176,"marks":29177,"value":27251,"nodeType":867},{},[],{"data":29179,"content":29180,"nodeType":915},{"uri":27254},[29181],{"data":29182,"marks":29183,"value":27260,"nodeType":867},{},[29184],{"type":913},{"data":29186,"marks":29187,"value":27264,"nodeType":867},{},[],{"data":29189,"content":29190,"nodeType":915},{"uri":27267},[29191],{"data":29192,"marks":29193,"value":27273,"nodeType":867},{},[29194],{"type":913},{"data":29196,"marks":29197,"value":27277,"nodeType":867},{},[],{"data":29199,"content":29200,"nodeType":1586},{},[29201],{"data":29202,"content":29203,"nodeType":876},{},[29204],{"data":29205,"marks":29206,"value":27287,"nodeType":867},{},[],{"data":29208,"content":29209,"nodeType":1586},{},[29210],{"data":29211,"content":29212,"nodeType":876},{},[29213],{"data":29214,"marks":29215,"value":27297,"nodeType":867},{},[],{"data":29217,"content":29218,"nodeType":1586},{},[29219],{"data":29220,"content":29221,"nodeType":876},{},[29222],{"data":29223,"marks":29224,"value":27307,"nodeType":867},{},[],{"data":29226,"content":29227,"nodeType":1586},{},[29228],{"data":29229,"content":29230,"nodeType":876},{},[29231],{"data":29232,"marks":29233,"value":27317,"nodeType":867},{},[],{"data":29235,"content":29236,"nodeType":1586},{},[29237],{"data":29238,"content":29239,"nodeType":876},{},[29240],{"data":29241,"marks":29242,"value":27327,"nodeType":867},{},[],{"data":29244,"content":29247,"nodeType":985},{"target":29245},{"sys":29246},{"id":27332,"type":982,"linkType":983},[],{"data":29249,"content":29250,"nodeType":1058},{},[29251],{"data":29252,"marks":29253,"value":27340,"nodeType":867},{},[],{"data":29255,"content":29256,"nodeType":876},{},[29257],{"data":29258,"marks":29259,"value":27347,"nodeType":867},{},[],{"data":29261,"content":29262,"nodeType":1629},{},[29263,29272,29281,29290,29299,29308],{"data":29264,"content":29265,"nodeType":1586},{},[29266],{"data":29267,"content":29268,"nodeType":876},{},[29269],{"data":29270,"marks":29271,"value":27360,"nodeType":867},{},[],{"data":29273,"content":29274,"nodeType":1586},{},[29275],{"data":29276,"content":29277,"nodeType":876},{},[29278],{"data":29279,"marks":29280,"value":27370,"nodeType":867},{},[],{"data":29282,"content":29283,"nodeType":1586},{},[29284],{"data":29285,"content":29286,"nodeType":876},{},[29287],{"data":29288,"marks":29289,"value":27380,"nodeType":867},{},[],{"data":29291,"content":29292,"nodeType":1586},{},[29293],{"data":29294,"content":29295,"nodeType":876},{},[29296],{"data":29297,"marks":29298,"value":27390,"nodeType":867},{},[],{"data":29300,"content":29301,"nodeType":1586},{},[29302],{"data":29303,"content":29304,"nodeType":876},{},[29305],{"data":29306,"marks":29307,"value":27400,"nodeType":867},{},[],{"data":29309,"content":29310,"nodeType":1586},{},[29311],{"data":29312,"content":29313,"nodeType":876},{},[29314],{"data":29315,"marks":29316,"value":27410,"nodeType":867},{},[],{"data":29318,"content":29319,"nodeType":876},{},[29320],{"data":29321,"marks":29322,"value":27417,"nodeType":867},{},[],{"data":29324,"content":29325,"nodeType":876},{},[29326],{"data":29327,"marks":29328,"value":27424,"nodeType":867},{},[],{"data":29330,"content":29331,"nodeType":876},{},[29332],{"data":29333,"marks":29334,"value":27431,"nodeType":867},{},[],{"data":29336,"content":29339,"nodeType":985},{"target":29337},{"sys":29338},{"id":27436,"type":982,"linkType":983},[],{"data":29341,"content":29342,"nodeType":876},{},[29343],{"data":29344,"marks":29345,"value":27444,"nodeType":867},{},[],{"data":29347,"content":29348,"nodeType":1058},{},[29349],{"data":29350,"marks":29351,"value":27451,"nodeType":867},{},[],{"data":29353,"content":29354,"nodeType":876},{},[29355],{"data":29356,"marks":29357,"value":27458,"nodeType":867},{},[],{"data":29359,"content":29362,"nodeType":985},{"target":29360},{"sys":29361},{"id":27463,"type":982,"linkType":983},[],{"data":29364,"content":29365,"nodeType":1058},{},[29366],{"data":29367,"marks":29368,"value":27471,"nodeType":867},{},[],{"data":29370,"content":29371,"nodeType":876},{},[29372],{"data":29373,"marks":29374,"value":27478,"nodeType":867},{},[],{"data":29376,"content":29377,"nodeType":876},{},[29378],{"data":29379,"marks":29380,"value":27485,"nodeType":867},{},[],{"data":29382,"content":29385,"nodeType":985},{"target":29383},{"sys":29384},{"id":27490,"type":982,"linkType":983},[],{"data":29387,"content":29388,"nodeType":876},{},[29389,29392,29399],{"data":29390,"marks":29391,"value":27498,"nodeType":867},{},[],{"data":29393,"content":29394,"nodeType":915},{"uri":26495},[29395],{"data":29396,"marks":29397,"value":27506,"nodeType":867},{},[29398],{"type":913},{"data":29400,"marks":29401,"value":27510,"nodeType":867},{},[],{"data":29403,"content":29404,"nodeType":1058},{},[29405],{"data":29406,"marks":29407,"value":27517,"nodeType":867},{},[],{"data":29409,"content":29410,"nodeType":876},{},[29411],{"data":29412,"marks":29413,"value":27524,"nodeType":867},{},[],{"data":29415,"content":29416,"nodeType":1629},{},[29417,29426,29435,29444],{"data":29418,"content":29419,"nodeType":1586},{},[29420],{"data":29421,"content":29422,"nodeType":876},{},[29423],{"data":29424,"marks":29425,"value":27537,"nodeType":867},{},[],{"data":29427,"content":29428,"nodeType":1586},{},[29429],{"data":29430,"content":29431,"nodeType":876},{},[29432],{"data":29433,"marks":29434,"value":27547,"nodeType":867},{},[],{"data":29436,"content":29437,"nodeType":1586},{},[29438],{"data":29439,"content":29440,"nodeType":876},{},[29441],{"data":29442,"marks":29443,"value":27557,"nodeType":867},{},[],{"data":29445,"content":29446,"nodeType":1586},{},[29447],{"data":29448,"content":29449,"nodeType":876},{},[29450],{"data":29451,"marks":29452,"value":27567,"nodeType":867},{},[],{"data":29454,"content":29457,"nodeType":985},{"target":29455},{"sys":29456},{"id":27572,"type":982,"linkType":983},[],{"data":29459,"content":29460,"nodeType":942},{},[],{"data":29462,"content":29463,"nodeType":868},{},[29464],{"data":29465,"marks":29466,"value":27584,"nodeType":867},{},[29467],{"type":865},{"data":29469,"content":29470,"nodeType":876},{},[29471,29474,29481,29484],{"data":29472,"marks":29473,"value":27591,"nodeType":867},{},[],{"data":29475,"content":29476,"nodeType":915},{"uri":27594},[29477],{"data":29478,"marks":29479,"value":27600,"nodeType":867},{},[29480],{"type":913},{"data":29482,"marks":29483,"value":5136,"nodeType":867},{},[],{"data":29485,"marks":29486,"value":27608,"nodeType":867},{},[29487],{"type":865},{"data":29489,"content":29490,"nodeType":942},{},[],{"data":29492,"content":29493,"nodeType":868},{},[29494],{"data":29495,"marks":29496,"value":14676,"nodeType":867},{},[29497],{"type":865},{"data":29499,"content":29500,"nodeType":876},{},[29501],{"data":29502,"marks":29503,"value":27625,"nodeType":867},{},[],{"data":29505,"content":29506,"nodeType":876},{},[29507],{"data":29508,"marks":29509,"value":27632,"nodeType":867},{},[],{"data":29511,"content":29512,"nodeType":876},{},[29513,29516,29523],{"data":29514,"marks":29515,"value":27639,"nodeType":867},{},[],{"data":29517,"content":29518,"nodeType":915},{"uri":5286},[29519],{"data":29520,"marks":29521,"value":27647,"nodeType":867},{},[29522],{"type":913},{"data":29524,"marks":29525,"value":21,"nodeType":867},{},[],{"entries":29527},{"hyperlink":29528,"inline":29529,"block":29530},[],[],[29531,29539,29543,29549,29574,29582,29589,29595,29602,29608,29614],{"sys":29532,"__typename":1688,"title":29533,"caption":29534,"layoutMode":59,"file":29535},{"id":26730},"Detections feature blog image 1","A version of NOW that sadly does not exist in the wild.",{"url":29536,"width":29537,"height":29538},"https://images.ctfassets.net/y1cdw1ablpvd/2jy8iOjUaE3L329TI67enQ/c47f600f8dc32c6358565791f4898443/image3.png",916,594,{"sys":29540,"__typename":21660,"title":29541,"arcadeDemoUrl":29542,"playText":21728},{"id":26785},"Detection walk-through 2","https://demo.arcade.software/gnOatHxEHaDs9SFRiDHY?embed",{"sys":29544,"__typename":1688,"title":29545,"caption":26609,"layoutMode":59,"file":29546},{"id":26823},"Detections Feature Blog: Attack Evolution",{"url":29547,"width":1693,"height":29548},"https://images.ctfassets.net/y1cdw1ablpvd/HzZeEBTpsqO575ni4j8oX/ccbc8ecf1b7dadfd9f2ec15f20399760/image4.png",815,{"sys":29550,"__typename":1705,"content":29551,"name":29573,"title":59},{"id":26895},{"json":29552},{"data":29553,"content":29554,"nodeType":1680},{},[29555],{"data":29556,"content":29557,"nodeType":876},{},[29558,29562,29569],{"data":29559,"marks":29560,"value":29561,"nodeType":867},{},[],"And even if your users are using phishing-resistant login methods, attackers are routinely using ",{"data":29563,"content":29564,"nodeType":915},{"uri":26138},[29565],{"data":29566,"marks":29567,"value":23132,"nodeType":867},{},[29568],{"type":913},{"data":29570,"marks":29571,"value":29572,"nodeType":867},{},[]," to take advantage of less secure backup login methods — which they’re achieving using Adversary-in-the-Middle phishing kits that are the standard choice for attackers today.","Detection blog: insight box",{"sys":29575,"__typename":1688,"title":29576,"caption":29577,"layoutMode":59,"file":29578},{"id":27049},"Detections blog: Email and network layer identity tools are looking from the outside-in at attacks that happen in the victim’s web browser.","Email and network layer identity tools are looking from the outside-in at attacks that happen in the victim’s web browser.",{"url":29579,"width":29580,"height":29581},"https://images.ctfassets.net/y1cdw1ablpvd/1488clWVU9FbuCVLfK4kcW/c014d62cdba4a6bc9312a7b1ff36b469/image9.png",1694,884,{"sys":29583,"__typename":1688,"title":29584,"caption":26652,"layoutMode":59,"file":29585},{"id":27215},"Detections blog: Being in the browser gives you unrivalled visibility of phishing page activity and user behavior.",{"url":29586,"width":29587,"height":29588},"https://images.ctfassets.net/y1cdw1ablpvd/4ogsAA3hGcMII18MwTYn6T/6fdf3ef0e6e59ecf412fd0748ba24145/Screenshot_2025-04-29_at_11.35.47.png",1942,924,{"sys":29590,"__typename":1688,"title":29591,"caption":29591,"layoutMode":59,"file":29592},{"id":27332},"Using Push, you can get a detailed timeline of what occurred in the browser during a security incident, including a screenshot of the phishing site and a view into all the impacted accounts.",{"url":29593,"width":29594,"height":1693},"https://images.ctfassets.net/y1cdw1ablpvd/aRWXKrYsTBsWNyLZD6xnq/19da00363042e2ec3b065cce711022da/image6.png",1504,{"sys":29596,"__typename":1688,"title":29597,"caption":29597,"layoutMode":59,"file":29598},{"id":27436},"Timeline detail from a detection, from link source to whether credentials were entered and a session was successfully created.",{"url":29599,"width":29600,"height":29601},"https://images.ctfassets.net/y1cdw1ablpvd/b7EMaJoZDdrMnbUYpNJYt/3f18f47eec73f3bb82fd453694179215/image1.png",1442,1562,{"sys":29603,"__typename":1688,"title":29604,"caption":29604,"layoutMode":59,"file":29605},{"id":27463},"Screenshot detail from a detection.",{"url":29606,"width":1693,"height":29607},"https://images.ctfassets.net/y1cdw1ablpvd/16pqmMfgYn5t66uCSAN4U9/f1c9ff29c31a14c2ea302455876776bf/image7.png",551,{"sys":29609,"__typename":1688,"title":29610,"caption":29610,"layoutMode":59,"file":29611},{"id":27490},"Blast radius detail from a detection showing login methods, compromised apps and at-risk accounts. ",{"url":29612,"width":1693,"height":29613},"https://images.ctfassets.net/y1cdw1ablpvd/78sUsmdsMFzElZjekjcn1R/31f9c1b5d9d04e94236d7f9888924609/image2.png",639,{"sys":29615,"__typename":1688,"title":29616,"caption":29616,"layoutMode":59,"file":29617},{"id":27572},"urlscan.io enrichment on a detection",{"url":29618,"width":1693,"height":29619},"https://images.ctfassets.net/y1cdw1ablpvd/32AfP4MM4lIuS8rTsuEXjj/65582616381c6f3f522101e1fb81f726/image5.png",1354,{"items":29621},[],{},"Introducing Push Detections: Equipping SecOps and IR teams",{"items":29625},[29626,30255,30560],{"__typename":1772,"sys":29627,"content":29629,"title":30241,"synopsis":30242,"hashTags":59,"publishedDate":30243,"slug":30244,"tagsCollection":30245,"authorsCollection":30251},{"id":29628},"XQHcBu5kiSBd6MMwICYI4",{"json":29630},{"data":29631,"content":29632,"nodeType":1680},{},[29633,29640,29647,29655,29684,29691,29697,29700,29708,29715,29722,29765,29772,29779,29782,29790,29797,29804,29811,29829,29836,29842,29850,29857,29864,29871,29877,29880,29888,29896,29903,29911,29918,29980,29987,29995,30002,30035,30043,30050,30058,30065,30073,30080,30133,30140,30143,30151,30158,30175,30208,30229,30235],{"data":29634,"content":29635,"nodeType":876},{},[29636],{"data":29637,"marks":29638,"value":29639,"nodeType":867},{},[],"Phishing has undergone a radical transformation. The laughably bad emails and fake PayPal logins of the past have given way to sophisticated campaigns engineered to slip through even the most hardened security stacks. ",{"data":29641,"content":29642,"nodeType":876},{},[29643],{"data":29644,"marks":29645,"value":29646,"nodeType":867},{},[],"Today’s phishing attacks are faster, more adaptable, and harder to catch with traditional tools. Email filters and threat intel still play an important role, but they’re often reacting to threats that are already in motion, and by the time a phishing link is flagged and blocklisted, someone has probably already clicked — and the attacker has moved onto their next set of links.",{"data":29648,"content":29649,"nodeType":876},{},[29650],{"data":29651,"marks":29652,"value":29654,"nodeType":867},{},[29653],{"type":865},"The problem isn’t that phishing has evolved. It’s that our defenses haven’t.",{"data":29656,"content":29657,"nodeType":876},{},[29658,29662,29671,29675,29680],{"data":29659,"marks":29660,"value":29661,"nodeType":867},{},[],"That’s where ",{"data":29663,"content":29665,"nodeType":915},{"uri":29664},"https://pushsecurity.com/uc/zero-day-phishing-protection",[29666],{"data":29667,"marks":29668,"value":29670,"nodeType":867},{},[29669],{"type":913},"Push Security",{"data":29672,"marks":29673,"value":29674,"nodeType":867},{},[]," comes in. By embedding real-time detection directly into the browser, the very place where phishing attacks unfold, Push offers a fundamentally new way to stop phishing: ",{"data":29676,"marks":29677,"value":29679,"nodeType":867},{},[29678],{"type":1303},"as it happens",{"data":29681,"marks":29682,"value":29683,"nodeType":867},{},[],", regardless of whether or not the exact attack has ever been seen before. ",{"data":29685,"content":29686,"nodeType":876},{},[29687],{"data":29688,"marks":29689,"value":29690,"nodeType":867},{},[],"Check out the video to see how it works. ",{"data":29692,"content":29696,"nodeType":985},{"target":29693},{"sys":29694},{"id":29695,"type":982,"linkType":983},"4LaKobadjp19jjocLXcW4E",[],{"data":29698,"content":29699,"nodeType":942},{},[],{"data":29701,"content":29702,"nodeType":868},{},[29703],{"data":29704,"marks":29705,"value":29707,"nodeType":867},{},[29706],{"type":865},"The modern phishing playground",{"data":29709,"content":29710,"nodeType":876},{},[29711],{"data":29712,"marks":29713,"value":29714,"nodeType":867},{},[],"Phishing attacks today look nothing like the blunt instruments of a few years ago. These are fast, customized, and often completely ephemeral. A phishing domain might go live at 9 a.m., compromise scores of credentials, and be gone before lunch, long before it ever hits a threat intel feed.",{"data":29716,"content":29717,"nodeType":876},{},[29718],{"data":29719,"marks":29720,"value":29721,"nodeType":867},{},[],"Modern attackers use:",{"data":29723,"content":29724,"nodeType":1629},{},[29725,29735,29745,29755],{"data":29726,"content":29727,"nodeType":1586},{},[29728],{"data":29729,"content":29730,"nodeType":876},{},[29731],{"data":29732,"marks":29733,"value":29734,"nodeType":867},{},[],"Dynamic content and user-adaptive emails that can be easily changed based on the target’s identity and environment.",{"data":29736,"content":29737,"nodeType":1586},{},[29738],{"data":29739,"content":29740,"nodeType":876},{},[29741],{"data":29742,"marks":29743,"value":29744,"nodeType":867},{},[],"Obfuscated URLs hidden behind trusted services (like Google Sites), making reputation analysis less than reliable.",{"data":29746,"content":29747,"nodeType":1586},{},[29748],{"data":29749,"content":29750,"nodeType":876},{},[29751],{"data":29752,"marks":29753,"value":29754,"nodeType":867},{},[],"Real-time proxying tools to clone login flows and harvest credentials.",{"data":29756,"content":29757,"nodeType":1586},{},[29758],{"data":29759,"content":29760,"nodeType":876},{},[29761],{"data":29762,"marks":29763,"value":29764,"nodeType":867},{},[],"Rapid-fire infrastructure rotation, making the attack’s infrastructure almost impossible to track in time.",{"data":29766,"content":29767,"nodeType":876},{},[29768],{"data":29769,"marks":29770,"value":29771,"nodeType":867},{},[],"These attacks often bypass traditional defenses entirely, not because the tools are broken, but because they were designed for a different era, one where phishing pages lived for days or weeks, not minutes.",{"data":29773,"content":29774,"nodeType":876},{},[29775],{"data":29776,"marks":29777,"value":29778,"nodeType":867},{},[],"It’s not enough to know what was bad yesterday. You need to know what’s happening now.",{"data":29780,"content":29781,"nodeType":942},{},[],{"data":29783,"content":29784,"nodeType":868},{},[29785],{"data":29786,"marks":29787,"value":29789,"nodeType":867},{},[29788],{"type":865},"Why blocklists and perimeter defenses are falling behind",{"data":29791,"content":29792,"nodeType":876},{},[29793],{"data":29794,"marks":29795,"value":29796,"nodeType":867},{},[],"The security ecosystem has long depended on reputation-based systems: block the known bad, allow the rest. That worked when attackers reused infrastructure and relied on mass campaigns. Today’s adversaries have adapted.",{"data":29798,"content":29799,"nodeType":876},{},[29800],{"data":29801,"marks":29802,"value":29803,"nodeType":867},{},[],"Consider a scenario similar to the one from our video:",{"data":29805,"content":29806,"nodeType":876},{},[29807],{"data":29808,"marks":29809,"value":29810,"nodeType":867},{},[],"A staff member receives an email appearing to be from Microsoft Teams. It includes dynamic content that mirrors their actual environment, including their username, company logo, and real collaboration data. The embedded link takes them to a cloned Microsoft login page hosted on a benign-looking subdomain. The site is brand new. It’s not on any blocklist. Your email filter passes it. The employee logs in. Credentials and session tokens? Gone.",{"data":29812,"content":29813,"nodeType":876},{},[29814,29818,29825],{"data":29815,"marks":29816,"value":29817,"nodeType":867},{},[],"And that’s just step one. The attacker now pivots to connected apps like ",{"data":29819,"content":29820,"nodeType":915},{"uri":16043},[29821],{"data":29822,"marks":29823,"value":23521,"nodeType":867},{},[29824],{"type":913},{"data":29826,"marks":29827,"value":29828,"nodeType":867},{},[],", Confluence, or AWS, moving laterally through your cloud environment using the compromised credentials.",{"data":29830,"content":29831,"nodeType":876},{},[29832],{"data":29833,"marks":29834,"value":29835,"nodeType":867},{},[],"Traditional tools often miss these threats not due to a lack of sophistication, but because they’re looking from the outside in. The browser is where the attack actually unfolds. Without visibility there, key indicators of compromise go undetected.",{"data":29837,"content":29841,"nodeType":985},{"target":29838},{"sys":29839},{"id":29840,"type":982,"linkType":983},"1UGu43QxCiYofkeGtOMp5J",[],{"data":29843,"content":29844,"nodeType":868},{},[29845],{"data":29846,"marks":29847,"value":29849,"nodeType":867},{},[29848],{"type":865},"Rethinking where phishing defense happens",{"data":29851,"content":29852,"nodeType":876},{},[29853],{"data":29854,"marks":29855,"value":29856,"nodeType":867},{},[],"Push changes where phishing protection happens, from upstream detection to point-of-interaction control. Instead of chasing malicious links through email gateways or external threat feeds, Push embeds lightweight, always-on protection directly, as users go about their work in the browser.",{"data":29858,"content":29859,"nodeType":876},{},[29860],{"data":29861,"marks":29862,"value":29863,"nodeType":867},{},[],"Push monitors what’s happening in each session: how pages are built, how they behave, and how users interact with them. That means it can recognize when a login prompt doesn’t match your identity provider or when a script behaves like part of a phishing toolkit.",{"data":29865,"content":29866,"nodeType":876},{},[29867],{"data":29868,"marks":29869,"value":29870,"nodeType":867},{},[],"When Push identifies something suspicious, it takes action right away. Logins are interrupted before any data is exposed. Users get clear guidance in-browser. And security teams receive detailed telemetry that shows exactly what happened, who was targeted, and how the threat was stopped.",{"data":29872,"content":29876,"nodeType":985},{"target":29873},{"sys":29874},{"id":29875,"type":982,"linkType":983},"7Hu3kypFWwJAGOuQp0kYmU",[],{"data":29878,"content":29879,"nodeType":942},{},[],{"data":29881,"content":29882,"nodeType":868},{},[29883],{"data":29884,"marks":29885,"value":29887,"nodeType":867},{},[29886],{"type":865},"The benefits of browser-native phishing defense",{"data":29889,"content":29890,"nodeType":1058},{},[29891],{"data":29892,"marks":29893,"value":29895,"nodeType":867},{},[29894],{"type":865},"True zero-day protection",{"data":29897,"content":29898,"nodeType":876},{},[29899],{"data":29900,"marks":29901,"value":29902,"nodeType":867},{},[],"Push doesn’t rely on known indicators of compromise. It evaluates the actual behavior and context of every session in real-time. Whether the phishing site was created 5 months ago or 5 minutes ago is irrelevant — Push detects it and shuts it down.",{"data":29904,"content":29905,"nodeType":1058},{},[29906],{"data":29907,"marks":29908,"value":29910,"nodeType":867},{},[29909],{"type":865},"Contextual threat detection",{"data":29912,"content":29913,"nodeType":876},{},[29914],{"data":29915,"marks":29916,"value":29917,"nodeType":867},{},[],"Because Push operates in the browser, it sees everything:",{"data":29919,"content":29920,"nodeType":1629},{},[29921,29931,29941,29960,29970],{"data":29922,"content":29923,"nodeType":1586},{},[29924],{"data":29925,"content":29926,"nodeType":876},{},[29927],{"data":29928,"marks":29929,"value":29930,"nodeType":867},{},[],"The page layout",{"data":29932,"content":29933,"nodeType":1586},{},[29934],{"data":29935,"content":29936,"nodeType":876},{},[29937],{"data":29938,"marks":29939,"value":29940,"nodeType":867},{},[],"Where the user came from",{"data":29942,"content":29943,"nodeType":1586},{},[29944],{"data":29945,"content":29946,"nodeType":876},{},[29947,29950,29957],{"data":29948,"marks":29949,"value":26492,"nodeType":867},{},[],{"data":29951,"content":29952,"nodeType":915},{"uri":26495},[29953],{"data":29954,"marks":29955,"value":26501,"nodeType":867},{},[29956],{"type":913},{"data":29958,"marks":29959,"value":21,"nodeType":867},{},[],{"data":29961,"content":29962,"nodeType":1586},{},[29963],{"data":29964,"content":29965,"nodeType":876},{},[29966],{"data":29967,"marks":29968,"value":29969,"nodeType":867},{},[],"What scripts are running",{"data":29971,"content":29972,"nodeType":1586},{},[29973],{"data":29974,"content":29975,"nodeType":876},{},[29976],{"data":29977,"marks":29978,"value":29979,"nodeType":867},{},[],"And where credentials are being sent",{"data":29981,"content":29982,"nodeType":876},{},[29983],{"data":29984,"marks":29985,"value":29986,"nodeType":867},{},[],"This context enables Push to stop even well-camouflaged phishing attempts, including AitM attacks that bypass MFA.",{"data":29988,"content":29989,"nodeType":1058},{},[29990],{"data":29991,"marks":29992,"value":29994,"nodeType":867},{},[29993],{"type":865},"Real-time interception of malicious activity",{"data":29996,"content":29997,"nodeType":876},{},[29998],{"data":29999,"marks":30000,"value":30001,"nodeType":867},{},[],"As soon as a phishing attempt is confirmed, the response is immediate:",{"data":30003,"content":30004,"nodeType":1629},{},[30005,30015,30025],{"data":30006,"content":30007,"nodeType":1586},{},[30008],{"data":30009,"content":30010,"nodeType":876},{},[30011],{"data":30012,"marks":30013,"value":30014,"nodeType":867},{},[],"Credential entry is halted.",{"data":30016,"content":30017,"nodeType":1586},{},[30018],{"data":30019,"content":30020,"nodeType":876},{},[30021],{"data":30022,"marks":30023,"value":30024,"nodeType":867},{},[],"Sessions are revoked.",{"data":30026,"content":30027,"nodeType":1586},{},[30028],{"data":30029,"content":30030,"nodeType":876},{},[30031],{"data":30032,"marks":30033,"value":30034,"nodeType":867},{},[],"The user is protected without delay.",{"data":30036,"content":30037,"nodeType":1058},{},[30038],{"data":30039,"marks":30040,"value":30042,"nodeType":867},{},[30041],{"type":865},"Reduced incident response overhead",{"data":30044,"content":30045,"nodeType":876},{},[30046],{"data":30047,"marks":30048,"value":30049,"nodeType":867},{},[],"Most phishing attacks end in hours of IR and expensive cleanup. With Push, attacks don’t escalate beyond the initial click. That means fewer compromised accounts, fewer escalations, and less fatigue on your security team.",{"data":30051,"content":30052,"nodeType":1058},{},[30053],{"data":30054,"marks":30055,"value":30057,"nodeType":867},{},[30056],{"type":865},"Empowered, educated users",{"data":30059,"content":30060,"nodeType":876},{},[30061],{"data":30062,"marks":30063,"value":30064,"nodeType":867},{},[],"Push doesn’t just block phishing; it helps users learn from it. When someone interacts with a suspicious page, they get clear, actionable feedback right in the browser. Over time, these in-the-moment cues help build stronger phishing awareness across your workforce. Employee-facing messages are fully customizable to match the tone and style of your organization.",{"data":30066,"content":30067,"nodeType":1058},{},[30068],{"data":30069,"marks":30070,"value":30072,"nodeType":867},{},[30071],{"type":865},"A new paradigm for identity security",{"data":30074,"content":30075,"nodeType":876},{},[30076],{"data":30077,"marks":30078,"value":30079,"nodeType":867},{},[],"While phishing detection is core, Push also helps you defend your entire browser-based identity attack surface. That means protecting against other common forms of account compromise, like:",{"data":30081,"content":30082,"nodeType":1629},{},[30083,30093,30103,30113,30123],{"data":30084,"content":30085,"nodeType":1586},{},[30086],{"data":30087,"content":30088,"nodeType":876},{},[30089],{"data":30090,"marks":30091,"value":30092,"nodeType":867},{},[],"Employees using breached or reused passwords",{"data":30094,"content":30095,"nodeType":1586},{},[30096],{"data":30097,"content":30098,"nodeType":876},{},[30099],{"data":30100,"marks":30101,"value":30102,"nodeType":867},{},[],"Missing or misconfigured MFA",{"data":30104,"content":30105,"nodeType":1586},{},[30106],{"data":30107,"content":30108,"nodeType":876},{},[30109],{"data":30110,"marks":30111,"value":30112,"nodeType":867},{},[],"Ghost logins that bypass your identity provider",{"data":30114,"content":30115,"nodeType":1586},{},[30116],{"data":30117,"content":30118,"nodeType":876},{},[30119],{"data":30120,"marks":30121,"value":30122,"nodeType":867},{},[],"Token-based session hijacking",{"data":30124,"content":30125,"nodeType":1586},{},[30126],{"data":30127,"content":30128,"nodeType":876},{},[30129],{"data":30130,"marks":30131,"value":30132,"nodeType":867},{},[],"Shadow SaaS usage",{"data":30134,"content":30135,"nodeType":876},{},[30136],{"data":30137,"marks":30138,"value":30139,"nodeType":867},{},[],"Because Push runs directly in the browser, it gives you visibility across every app your employees access, whether it’s officially managed or not. And it doesn’t just alert, it actively helps you fix the issues, guiding users to take action when risks are found.",{"data":30141,"content":30142,"nodeType":942},{},[],{"data":30144,"content":30145,"nodeType":868},{},[30146],{"data":30147,"marks":30148,"value":30150,"nodeType":867},{},[30149],{"type":865},"Modern phishing requires a modern defense",{"data":30152,"content":30153,"nodeType":876},{},[30154],{"data":30155,"marks":30156,"value":30157,"nodeType":867},{},[],"Phishing is no longer an email problem. It’s not even just a domain reputation problem. It’s an identity attack problem, and the only place you can see those attacks in action is inside the browser.",{"data":30159,"content":30160,"nodeType":876},{},[30161,30165,30172],{"data":30162,"marks":30163,"value":30164,"nodeType":867},{},[],"Push Security gives you a new advantage: proactive, in-browser protection against modern phishing campaigns — ",{"data":30166,"content":30167,"nodeType":915},{"uri":29664},[30168],{"data":30169,"marks":30170,"value":30171,"nodeType":867},{},[],"even those with never-before-seen phishing sites",{"data":30173,"marks":30174,"value":1679,"nodeType":867},{},[],{"data":30176,"content":30177,"nodeType":1629},{},[30178,30188,30198],{"data":30179,"content":30180,"nodeType":1586},{},[30181],{"data":30182,"content":30183,"nodeType":876},{},[30184],{"data":30185,"marks":30186,"value":30187,"nodeType":867},{},[],"See the phish happen.",{"data":30189,"content":30190,"nodeType":1586},{},[30191],{"data":30192,"content":30193,"nodeType":876},{},[30194],{"data":30195,"marks":30196,"value":30197,"nodeType":867},{},[],"Stop it in real time.",{"data":30199,"content":30200,"nodeType":1586},{},[30201],{"data":30202,"content":30203,"nodeType":876},{},[30204],{"data":30205,"marks":30206,"value":30207,"nodeType":867},{},[],"Keep your workforce identities safe.",{"data":30209,"content":30210,"nodeType":876},{},[30211,30216,30224],{"data":30212,"marks":30213,"value":30215,"nodeType":867},{},[30214],{"type":865},"Want to see Push in action? ",{"data":30217,"content":30218,"nodeType":915},{"uri":5286},[30219],{"data":30220,"marks":30221,"value":30223,"nodeType":867},{},[30222],{"type":865},"Book a demo",{"data":30225,"marks":30226,"value":30228,"nodeType":867},{},[30227],{"type":865}," and watch a real-time phishing attack get stopped mid-flow.",{"data":30230,"content":30234,"nodeType":985},{"target":30231},{"sys":30232},{"id":30233,"type":982,"linkType":983},"7eSsPjEj178j3ViloaChbQ",[],{"data":30236,"content":30237,"nodeType":876},{},[30238],{"data":30239,"marks":30240,"value":21,"nodeType":867},{},[],"How browser-level controls change the fight against phishing","Attackers are routinely defeating conventional email, network, and endpoint-based security controls. Here's how browser controls can level the playing field.","2025-06-26T00:00:00.000Z","how-browser-level-controls-change-the-fight-against-phishing",{"items":30246},[30247,30249],{"sys":30248,"name":4018},{"id":4017},{"sys":30250,"name":342},{"id":3240},{"items":30252},[30253],{"fullName":849,"firstName":850,"jobTitle":851,"profilePicture":30254},{"url":853},{"__typename":1772,"sys":30256,"content":30257,"title":28015,"synopsis":28016,"hashTags":59,"publishedDate":28017,"slug":28018,"tagsCollection":30552,"authorsCollection":30556},{"id":27667},{"json":30258},{"data":30259,"content":30260,"nodeType":1680},{},[30261,30267,30273,30279,30284,30290,30320,30326,30332,30338,30343,30349,30355,30370,30375,30381,30397,30413,30419,30425,30431,30437,30443,30449,30455,30471,30477,30483,30488,30494,30500,30520,30525,30541,30546],{"data":30262,"content":30263,"nodeType":876},{},[30264],{"data":30265,"marks":30266,"value":27678,"nodeType":867},{},[],{"data":30268,"content":30269,"nodeType":876},{},[30270],{"data":30271,"marks":30272,"value":27685,"nodeType":867},{},[],{"data":30274,"content":30275,"nodeType":876},{},[30276],{"data":30277,"marks":30278,"value":27692,"nodeType":867},{},[],{"data":30280,"content":30283,"nodeType":985},{"target":30281},{"sys":30282},{"id":27697,"type":982,"linkType":983},[],{"data":30285,"content":30286,"nodeType":876},{},[30287],{"data":30288,"marks":30289,"value":27705,"nodeType":867},{},[],{"data":30291,"content":30292,"nodeType":1629},{},[30293,30302,30311],{"data":30294,"content":30295,"nodeType":1586},{},[30296],{"data":30297,"content":30298,"nodeType":876},{},[30299],{"data":30300,"marks":30301,"value":27718,"nodeType":867},{},[],{"data":30303,"content":30304,"nodeType":1586},{},[30305],{"data":30306,"content":30307,"nodeType":876},{},[30308],{"data":30309,"marks":30310,"value":27728,"nodeType":867},{},[],{"data":30312,"content":30313,"nodeType":1586},{},[30314],{"data":30315,"content":30316,"nodeType":876},{},[30317],{"data":30318,"marks":30319,"value":27738,"nodeType":867},{},[],{"data":30321,"content":30322,"nodeType":876},{},[30323],{"data":30324,"marks":30325,"value":27745,"nodeType":867},{},[],{"data":30327,"content":30328,"nodeType":868},{},[30329],{"data":30330,"marks":30331,"value":27752,"nodeType":867},{},[],{"data":30333,"content":30334,"nodeType":876},{},[30335],{"data":30336,"marks":30337,"value":27759,"nodeType":867},{},[],{"data":30339,"content":30342,"nodeType":985},{"target":30340},{"sys":30341},{"id":27764,"type":982,"linkType":983},[],{"data":30344,"content":30345,"nodeType":876},{},[30346],{"data":30347,"marks":30348,"value":27772,"nodeType":867},{},[],{"data":30350,"content":30351,"nodeType":868},{},[30352],{"data":30353,"marks":30354,"value":27779,"nodeType":867},{},[],{"data":30356,"content":30357,"nodeType":876},{},[30358,30361,30367],{"data":30359,"marks":30360,"value":27786,"nodeType":867},{},[],{"data":30362,"content":30363,"nodeType":915},{"uri":22147},[30364],{"data":30365,"marks":30366,"value":27793,"nodeType":867},{},[],{"data":30368,"marks":30369,"value":27797,"nodeType":867},{},[],{"data":30371,"content":30374,"nodeType":985},{"target":30372},{"sys":30373},{"id":27802,"type":982,"linkType":983},[],{"data":30376,"content":30377,"nodeType":1058},{},[30378],{"data":30379,"marks":30380,"value":27810,"nodeType":867},{},[],{"data":30382,"content":30383,"nodeType":876},{},[30384,30387,30394],{"data":30385,"marks":30386,"value":27817,"nodeType":867},{},[],{"data":30388,"content":30389,"nodeType":915},{"uri":27820},[30390],{"data":30391,"marks":30392,"value":27826,"nodeType":867},{},[30393],{"type":913},{"data":30395,"marks":30396,"value":27830,"nodeType":867},{},[],{"data":30398,"content":30399,"nodeType":876},{},[30400,30403,30410],{"data":30401,"marks":30402,"value":27837,"nodeType":867},{},[],{"data":30404,"content":30405,"nodeType":915},{"uri":27840},[30406],{"data":30407,"marks":30408,"value":27846,"nodeType":867},{},[30409],{"type":913},{"data":30411,"marks":30412,"value":27850,"nodeType":867},{},[],{"data":30414,"content":30415,"nodeType":876},{},[30416],{"data":30417,"marks":30418,"value":27857,"nodeType":867},{},[],{"data":30420,"content":30421,"nodeType":876},{},[30422],{"data":30423,"marks":30424,"value":27864,"nodeType":867},{},[],{"data":30426,"content":30427,"nodeType":1058},{},[30428],{"data":30429,"marks":30430,"value":27871,"nodeType":867},{},[],{"data":30432,"content":30433,"nodeType":876},{},[30434],{"data":30435,"marks":30436,"value":27878,"nodeType":867},{},[],{"data":30438,"content":30439,"nodeType":876},{},[30440],{"data":30441,"marks":30442,"value":27885,"nodeType":867},{},[],{"data":30444,"content":30445,"nodeType":868},{},[30446],{"data":30447,"marks":30448,"value":27892,"nodeType":867},{},[],{"data":30450,"content":30451,"nodeType":876},{},[30452],{"data":30453,"marks":30454,"value":27899,"nodeType":867},{},[],{"data":30456,"content":30457,"nodeType":876},{},[30458,30461,30468],{"data":30459,"marks":30460,"value":27906,"nodeType":867},{},[],{"data":30462,"content":30463,"nodeType":915},{"uri":27909},[30464],{"data":30465,"marks":30466,"value":27915,"nodeType":867},{},[30467],{"type":913},{"data":30469,"marks":30470,"value":27919,"nodeType":867},{},[],{"data":30472,"content":30473,"nodeType":876},{},[30474],{"data":30475,"marks":30476,"value":27926,"nodeType":867},{},[],{"data":30478,"content":30479,"nodeType":876},{},[30480],{"data":30481,"marks":30482,"value":27933,"nodeType":867},{},[],{"data":30484,"content":30487,"nodeType":985},{"target":30485},{"sys":30486},{"id":27938,"type":982,"linkType":983},[],{"data":30489,"content":30490,"nodeType":868},{},[30491],{"data":30492,"marks":30493,"value":27946,"nodeType":867},{},[],{"data":30495,"content":30496,"nodeType":876},{},[30497],{"data":30498,"marks":30499,"value":27953,"nodeType":867},{},[],{"data":30501,"content":30502,"nodeType":876},{},[30503,30506,30510,30513,30517],{"data":30504,"marks":30505,"value":27960,"nodeType":867},{},[],{"data":30507,"marks":30508,"value":27965,"nodeType":867},{},[30509],{"type":865},{"data":30511,"marks":30512,"value":27969,"nodeType":867},{},[],{"data":30514,"marks":30515,"value":27974,"nodeType":867},{},[30516],{"type":865},{"data":30518,"marks":30519,"value":27978,"nodeType":867},{},[],{"data":30521,"content":30524,"nodeType":985},{"target":30522},{"sys":30523},{"id":27983,"type":982,"linkType":983},[],{"data":30526,"content":30527,"nodeType":876},{},[30528,30531,30538],{"data":30529,"marks":30530,"value":27991,"nodeType":867},{},[],{"data":30532,"content":30533,"nodeType":915},{"uri":5286},[30534],{"data":30535,"marks":30536,"value":11707,"nodeType":867},{},[30537],{"type":913},{"data":30539,"marks":30540,"value":28002,"nodeType":867},{},[],{"data":30542,"content":30545,"nodeType":985},{"target":30543},{"sys":30544},{"id":28007,"type":982,"linkType":983},[],{"data":30547,"content":30548,"nodeType":876},{},[30549],{"data":30550,"marks":30551,"value":21,"nodeType":867},{},[],{"items":30553},[30554],{"sys":30555,"name":297},{"id":2706},{"items":30557},[30558],{"fullName":4089,"firstName":4090,"jobTitle":851,"profilePicture":30559},{"url":4094},{"__typename":1772,"sys":30561,"content":30563,"title":31216,"synopsis":31217,"hashTags":59,"publishedDate":31218,"slug":31219,"tagsCollection":31220,"authorsCollection":31226},{"id":30562},"7dqGkFzSMA00bIJ94rW4na",{"json":30564},{"data":30565,"content":30566,"nodeType":1680},{},[30567,30574,30581,30587,30612,30631,30634,30642,30649,30656,30664,30684,30687,30695,30702,30707,30714,30720,30723,30731,30738,30745,30768,30775,30808,30815,30823,30842,30849,30855,30882,30913,30921,30928,30935,30968,30971,30979,30998,31005,31028,31035,31041,31044,31052,31059,31183,31186,31193,31200],{"data":30568,"content":30569,"nodeType":876},{},[30570],{"data":30571,"marks":30572,"value":30573,"nodeType":867},{},[],"As awareness grows around many MFA methods being “phishable” (i.e. not phishing resistant), passwordless authentication methods are being increasingly advocated. ",{"data":30575,"content":30576,"nodeType":876},{},[30577],{"data":30578,"marks":30579,"value":30580,"nodeType":867},{},[],"This is a good thing. The most commonly used MFA factors (like SMS codes, push notifications, and app-based OTP) are routinely bypassed, with modern reverse-proxy phishing kits the most common method. ",{"data":30582,"content":30586,"nodeType":985},{"target":30583},{"sys":30584},{"id":30585,"type":982,"linkType":983},"ImwzE2R9qaHaqlWn0GqIa",[],{"data":30588,"content":30589,"nodeType":876},{},[30590,30594,30599,30603,30608],{"data":30591,"marks":30592,"value":30593,"nodeType":867},{},[],"Often referred to as a “passkey”, passwordless authentication typically consists of a hardware security device that is built-into your laptop (e.g. the fingerprint sensor on a laptop) or something you plug into your device (e.g. a Yubikey). Because passkey-based logins are domain-bound, trying to use a passkey for ",{"data":30595,"marks":30596,"value":30598,"nodeType":867},{},[30597],{"type":913},"microsoft.com",{"data":30600,"marks":30601,"value":30602,"nodeType":867},{},[]," on ",{"data":30604,"marks":30605,"value":30607,"nodeType":867},{},[30606],{"type":913},"phishing.com",{"data":30609,"marks":30610,"value":30611,"nodeType":867},{},[]," simply won’t generate the correct value to pass the authentication check, even when proxied using an AitM kit. ",{"data":30613,"content":30614,"nodeType":876},{},[30615,30619,30628],{"data":30616,"marks":30617,"value":30618,"nodeType":867},{},[],"However, attackers have realized that even as these new phishing-resistant methods are starting to become used, most users still have alternative MFA methods active. The attacker can then do what’s called a ",{"data":30620,"content":30621,"nodeType":915},{"uri":24826},[30622],{"data":30623,"marks":30624,"value":30627,"nodeType":867},{},[30625,30626],{"type":913},{"type":865},"downgrade attack",{"data":30629,"marks":30630,"value":1679,"nodeType":867},{},[],{"data":30632,"content":30633,"nodeType":942},{},[],{"data":30635,"content":30636,"nodeType":868},{},[30637],{"data":30638,"marks":30639,"value":30641,"nodeType":867},{},[30640],{"type":865},"Downgrade attacks 101",{"data":30643,"content":30644,"nodeType":876},{},[30645],{"data":30646,"marks":30647,"value":30648,"nodeType":867},{},[],"When conducting an Attacker-in-the-Middle phishing attack, the attacker doesn’t need to relay 100% of the messages accurately. Instead, they can alter some of them. The app might ask the user “You need to MFA — do you want to use your passkey, or your backup authenticator code?”, but the phishing website might modify this page to say “You need to MFA — use your backup authenticator code” not giving you the option to use your secure passkey. This is called a downgrade attack.",{"data":30650,"content":30651,"nodeType":876},{},[30652],{"data":30653,"marks":30654,"value":30655,"nodeType":867},{},[],"This can also be applied to accounts that use SSO as the default login method. In this scenario, the phish kit can select a backup username and password option to allow the phishing attack to proceed.  ",{"data":30657,"content":30658,"nodeType":876},{},[30659],{"data":30660,"marks":30661,"value":30663,"nodeType":867},{},[30662],{"type":865},"So, you have a situation where even if a phishing-resistant login method exists, the presence of a less secure backup method means the account is still vulnerable to phishing attacks. ",{"data":30665,"content":30666,"nodeType":876},{},[30667,30671,30680],{"data":30668,"marks":30669,"value":30670,"nodeType":867},{},[],"These attacks are effective across a number of sites and login methods that support passkey-based logins, for example, Windows Hello, Okta FastPass, and Google Workspace. As an example, here’s a link to a ",{"data":30672,"content":30674,"nodeType":915},{"uri":30673},"https://github.com/yudasm/WHfB-o365-Phishlet",[30675],{"data":30676,"marks":30677,"value":30679,"nodeType":867},{},[30678],{"type":913},"custom phishlet for Evilginx",{"data":30681,"marks":30682,"value":30683,"nodeType":867},{},[]," targeting Windows Hello for Business. A small caveat is that changes made by Microsoft have since broken this plugin, but we were able to write our own custom phishlet to achieve the same outcome. ",{"data":30685,"content":30686,"nodeType":942},{},[],{"data":30688,"content":30689,"nodeType":868},{},[30690],{"data":30691,"marks":30692,"value":30694,"nodeType":867},{},[30693],{"type":865},"MFA downgrade in action",{"data":30696,"content":30697,"nodeType":876},{},[30698],{"data":30699,"marks":30700,"value":30701,"nodeType":867},{},[],"Check out the video below to see an example of using Evilginx with a custom phishlet to downgrade authentication for a Microsoft account using Windows Hello. ",{"data":30703,"content":30706,"nodeType":985},{"target":30704},{"sys":30705},{"id":26152,"type":982,"linkType":983},[],{"data":30708,"content":30709,"nodeType":876},{},[30710],{"data":30711,"marks":30712,"value":30713,"nodeType":867},{},[],"We’ve encountered similar functionality in criminal phishing platforms we’ve investigated such as Tycoon — in this case, targeting Google accounts. This snippet is notable in that it includes JavaScript to abuse UI features to bypass passkeys.",{"data":30715,"content":30719,"nodeType":985},{"target":30716},{"sys":30717},{"id":30718,"type":982,"linkType":983},"5Vya1VApSisr0000HuTLY2",[],{"data":30721,"content":30722,"nodeType":942},{},[],{"data":30724,"content":30725,"nodeType":868},{},[30726],{"data":30727,"marks":30728,"value":30730,"nodeType":867},{},[30729],{"type":865},"Mitigations (and challenges)",{"data":30732,"content":30733,"nodeType":876},{},[30734],{"data":30735,"marks":30736,"value":30737,"nodeType":867},{},[],"MFA downgrade is made possible by the existence of backup authentication methods. So the obvious solution is to remove backup/unused login and MFA methods from your accounts, ensuring you’re accessing apps using SSO from a hardened Identity Provider (IdP) account (e.g. Okta, Entra, Google Workspace). ",{"data":30739,"content":30740,"nodeType":876},{},[30741],{"data":30742,"marks":30743,"value":30744,"nodeType":867},{},[],"In the ideal world, you’d be:",{"data":30746,"content":30747,"nodeType":1629},{},[30748,30758],{"data":30749,"content":30750,"nodeType":1586},{},[30751],{"data":30752,"content":30753,"nodeType":876},{},[30754],{"data":30755,"marks":30756,"value":30757,"nodeType":867},{},[],"Using only one IdP account, which you access via passkey, with no backup methods.",{"data":30759,"content":30760,"nodeType":1586},{},[30761],{"data":30762,"content":30763,"nodeType":876},{},[30764],{"data":30765,"marks":30766,"value":30767,"nodeType":867},{},[],"Accessing all business apps using SSO from your locked-down IdP account. ",{"data":30769,"content":30770,"nodeType":876},{},[30771],{"data":30772,"marks":30773,"value":30774,"nodeType":867},{},[],"The reality is way different, though. Because going totally passwordless is hard. It requires a large investment of time, money, and training for end-users. You’ll find many cautionary tales of companies starting on their passkey adoption journey and ultimately failing to make it a reality. This is largely because:",{"data":30776,"content":30777,"nodeType":1629},{},[30778,30788,30798],{"data":30779,"content":30780,"nodeType":1586},{},[30781],{"data":30782,"content":30783,"nodeType":876},{},[30784],{"data":30785,"marks":30786,"value":30787,"nodeType":867},{},[],"In environments with a mix of older and newer infrastructure, it can be challenging to get complete coverage. ",{"data":30789,"content":30790,"nodeType":1586},{},[30791],{"data":30792,"content":30793,"nodeType":876},{},[30794],{"data":30795,"marks":30796,"value":30797,"nodeType":867},{},[],"Not every device comes with an in-built biometric identification method, so you need to use a second device — which employees may struggle with (especially when they lose it and aren’t familiar with how to regain account access).",{"data":30799,"content":30800,"nodeType":1586},{},[30801],{"data":30802,"content":30803,"nodeType":876},{},[30804],{"data":30805,"marks":30806,"value":30807,"nodeType":867},{},[],"Most apps don’t allow you to log in directly with a passkey, meaning you need to SSO from your IdP account. But many apps don’t support every preferred SSO provider, and fail to provide SAML support, so there can be gaps.  ",{"data":30809,"content":30810,"nodeType":876},{},[30811],{"data":30812,"marks":30813,"value":30814,"nodeType":867},{},[],"And ultimately, because of the self-service, product-led growth fuelled nature of most online services today, it’s easy for users to slip back into using passwords — and hard for security teams to find and remove them (particularly if an app isn’t centrally managed). And the level of support that different apps provide users and administrators to secure how they access their services varies significantly. ",{"data":30816,"content":30817,"nodeType":1058},{},[30818],{"data":30819,"marks":30820,"value":30822,"nodeType":867},{},[30821],{"type":865},"Most apps make removing phishable authentication hard",{"data":30824,"content":30825,"nodeType":876},{},[30826,30830,30838],{"data":30827,"marks":30828,"value":30829,"nodeType":867},{},[],"While some providers are taking steps to go passwordless by default, which makes it easier to remove passwords (e.g. ",{"data":30831,"content":30833,"nodeType":915},{"uri":30832},"https://techcommunity.microsoft.com/blog/microsoft-entra-blog/introducing-password-removal-for-microsoft-accounts/2747280",[30834],{"data":30835,"marks":30836,"value":11959,"nodeType":867},{},[30837],{"type":913},{"data":30839,"marks":30840,"value":30841,"nodeType":867},{},[]," recently made a big deal of its desire to get rid of passwords), the quality of identity security management functionality varies significantly from app to app. ",{"data":30843,"content":30844,"nodeType":876},{},[30845],{"data":30846,"marks":30847,"value":30848,"nodeType":867},{},[],"Many apps default to the most recently used or strongest login method, but very few automatically lock you in to using the strongest method available. Most of the time, these kinds of controls also need to be configured in the app — which can be challenging if your security team doesn’t manage it (or simply isn’t aware of it). ",{"data":30850,"content":30854,"nodeType":985},{"target":30851},{"sys":30852},{"id":30853,"type":982,"linkType":983},"4X9MR0CbSMltOmw767XNOm",[],{"data":30856,"content":30857,"nodeType":876},{},[30858,30862,30867,30871,30878],{"data":30859,"marks":30860,"value":30861,"nodeType":867},{},[],"Finally, configuring MFA is often an additive process — you start by adding a phone number, then you add an authenticator app or a passkey. Just like we find that most accounts with SSO ",{"data":30863,"marks":30864,"value":30866,"nodeType":867},{},[30865],{"type":865},"also",{"data":30868,"marks":30869,"value":30870,"nodeType":867},{},[]," have a password login configured (also known as ",{"data":30872,"content":30873,"nodeType":915},{"uri":26236},[30874],{"data":30875,"marks":30876,"value":2929,"nodeType":867},{},[30877],{"type":913},{"data":30879,"marks":30880,"value":30881,"nodeType":867},{},[],"), most accounts with MFA typically have multiple methods attached to their account. ",{"data":30883,"content":30884,"nodeType":876},{},[30885,30889,30897,30900,30909],{"data":30886,"marks":30887,"value":30888,"nodeType":867},{},[],"The result is that even if you can successfully lock down a handful of apps, many more will continue to be susceptible to phishing attacks using commonly available downgrade functionality. And as attackers diversify the apps they target (such as these recent examples targeting ",{"data":30890,"content":30891,"nodeType":915},{"uri":22100},[30892],{"data":30893,"marks":30894,"value":30896,"nodeType":867},{},[30895],{"type":913},"Onfido",{"data":30898,"marks":30899,"value":1174,"nodeType":867},{},[],{"data":30901,"content":30903,"nodeType":915},{"uri":30902},"https://pushsecurity.com/blog/dissecting-a-recent-mailchimp-phishing-attack/",[30904],{"data":30905,"marks":30906,"value":30908,"nodeType":867},{},[30907],{"type":913},"MailChimp",{"data":30910,"marks":30911,"value":30912,"nodeType":867},{},[],"), this becomes increasingly likely. ",{"data":30914,"content":30915,"nodeType":1058},{},[30916],{"data":30917,"marks":30918,"value":30920,"nodeType":867},{},[30919],{"type":865},"Conditional access is a useful mitigation if configured properly, but only on apps which support it",{"data":30922,"content":30923,"nodeType":876},{},[30924],{"data":30925,"marks":30926,"value":30927,"nodeType":867},{},[],"Conditional access policies are a useful last line of defense against account takeover attacks by denying logins that don't meet certain criteria, even if they user is able to authenticate. In larger IdP platforms that typically support more granular conditional access policies, this is a useful addition when configured correctly. However, many apps simply don't support conditional access, so will be vulnerable to attackers targeting them directly (as opposed to first logging into e.g. Microsoft or Google, and then accessing downstream apps via SSO). ",{"data":30929,"content":30930,"nodeType":876},{},[30931],{"data":30932,"marks":30933,"value":30934,"nodeType":867},{},[],"That said, locking down your core IdP platforms with robust conditional access should be a top priority for security teams. Useful policies that should be configured include:",{"data":30936,"content":30937,"nodeType":1629},{},[30938,30948,30958],{"data":30939,"content":30940,"nodeType":1586},{},[30941],{"data":30942,"content":30943,"nodeType":876},{},[30944],{"data":30945,"marks":30946,"value":30947,"nodeType":867},{},[],"Limiting logins to domain-joined devices.",{"data":30949,"content":30950,"nodeType":1586},{},[30951],{"data":30952,"content":30953,"nodeType":876},{},[30954],{"data":30955,"marks":30956,"value":30957,"nodeType":867},{},[],"Set phishing-resistant MFA as required. ",{"data":30959,"content":30960,"nodeType":1586},{},[30961],{"data":30962,"content":30963,"nodeType":876},{},[30964],{"data":30965,"marks":30966,"value":30967,"nodeType":867},{},[],"(Where possible) limit logins to trusted IP ranges. ",{"data":30969,"content":30970,"nodeType":942},{},[],{"data":30972,"content":30973,"nodeType":868},{},[30974],{"data":30975,"marks":30976,"value":30978,"nodeType":867},{},[30977],{"type":865},"Tackling MFA downgrade with Push Security",{"data":30980,"content":30981,"nodeType":876},{},[30982,30986,30994],{"data":30983,"marks":30984,"value":30985,"nodeType":867},{},[],"Phishing-resistant authentication methods like passkeys are key to the future of enterprise identity security, but organizations need to recognize that adopting passkeys isn’t a silver bullet. Ensuring that passkeys are the only authentication method supported by your business apps is no mean feat, considering ",{"data":30987,"content":30988,"nodeType":915},{"uri":2912},[30989],{"data":30990,"marks":30991,"value":30993,"nodeType":867},{},[30992],{"type":913},"most organizations are using hundreds of them",{"data":30995,"marks":30996,"value":30997,"nodeType":867},{},[]," — all with their own specific ways of handling and administering identities. ",{"data":30999,"content":31000,"nodeType":876},{},[31001],{"data":31002,"marks":31003,"value":31004,"nodeType":867},{},[],"That’s why we support a layered defense, providing last-mile protection by:",{"data":31006,"content":31007,"nodeType":1629},{},[31008,31018],{"data":31009,"content":31010,"nodeType":1586},{},[31011],{"data":31012,"content":31013,"nodeType":876},{},[31014],{"data":31015,"marks":31016,"value":31017,"nodeType":867},{},[],"Intercepting and blocking phishing attacks in the browser to prevent AiTM attacks using downgrade techniques.",{"data":31019,"content":31020,"nodeType":1586},{},[31021],{"data":31022,"content":31023,"nodeType":876},{},[31024],{"data":31025,"marks":31026,"value":31027,"nodeType":867},{},[],"Identifying backup MFA and login methods across the business apps your employees use, so they can be removed (individually or through app-level configuration changes).",{"data":31029,"content":31030,"nodeType":876},{},[31031],{"data":31032,"marks":31033,"value":31034,"nodeType":867},{},[],"Here’s how it works.",{"data":31036,"content":31040,"nodeType":985},{"target":31037},{"sys":31038},{"id":31039,"type":982,"linkType":983},"2uvItnfaOQZHa4a9BIIhRn",[],{"data":31042,"content":31043,"nodeType":942},{},[],{"data":31045,"content":31046,"nodeType":868},{},[31047],{"data":31048,"marks":31049,"value":31051,"nodeType":867},{},[31050],{"type":865},"Further reading",{"data":31053,"content":31054,"nodeType":876},{},[31055],{"data":31056,"marks":31057,"value":31058,"nodeType":867},{},[],"MFA downgrade is just one method of getting into an otherwise locked-down account. Attackers are also finding ways to bypass the standard authentication process entirely, through: ",{"data":31060,"content":31061,"nodeType":1629},{},[31062,31095,31129,31149],{"data":31063,"content":31064,"nodeType":1586},{},[31065],{"data":31066,"content":31067,"nodeType":876},{},[31068,31071,31079,31083,31092],{"data":31069,"marks":31070,"value":21,"nodeType":867},{},[],{"data":31072,"content":31073,"nodeType":915},{"uri":26270},[31074],{"data":31075,"marks":31076,"value":31078,"nodeType":867},{},[31077],{"type":913},"App-specific password phishing",{"data":31080,"marks":31081,"value":31082,"nodeType":867},{},[],", where attackers can abuse functionality designed to enable users to log into apps that don’t support modern authentication. (",{"data":31084,"content":31086,"nodeType":915},{"uri":31085},"https://pushsecurity.com/blog/app-specific-password-phishing/",[31087],{"data":31088,"marks":31089,"value":31091,"nodeType":867},{},[31090],{"type":913},"Read the article for more information here",{"data":31093,"marks":31094,"value":24243,"nodeType":867},{},[],{"data":31096,"content":31097,"nodeType":1586},{},[31098],{"data":31099,"content":31100,"nodeType":876},{},[31101,31104,31112,31116,31125],{"data":31102,"marks":31103,"value":21,"nodeType":867},{},[],{"data":31105,"content":31106,"nodeType":915},{"uri":23293},[31107],{"data":31108,"marks":31109,"value":31111,"nodeType":867},{},[31110],{"type":913},"Consent phishing",{"data":31113,"marks":31114,"value":31115,"nodeType":867},{},[],", which sees the victim accept OAuth scopes for an attacker-controlled app integration granting access to the account without needing to directly compromise it. (",{"data":31117,"content":31119,"nodeType":915},{"uri":31118},"https://pushsecurity.com/blog/how-consent-phishing-is-evolving/",[31120],{"data":31121,"marks":31122,"value":31124,"nodeType":867},{},[31123],{"type":913},"You can read more about recent examples here",{"data":31126,"marks":31127,"value":31128,"nodeType":867},{},[],".) ",{"data":31130,"content":31131,"nodeType":1586},{},[31132],{"data":31133,"content":31134,"nodeType":876},{},[31135,31138,31145],{"data":31136,"marks":31137,"value":21,"nodeType":867},{},[],{"data":31139,"content":31140,"nodeType":915},{"uri":11768},[31141],{"data":31142,"marks":31143,"value":360,"nodeType":867},{},[31144],{"type":913},{"data":31146,"marks":31147,"value":31148,"nodeType":867},{},[],", functionally very similar to consent phishing but involving the victim entering a code for authorization. ",{"data":31150,"content":31151,"nodeType":1586},{},[31152],{"data":31153,"content":31154,"nodeType":876},{},[31155,31158,31166,31170,31179],{"data":31156,"marks":31157,"value":21,"nodeType":867},{},[],{"data":31159,"content":31160,"nodeType":915},{"uri":26293},[31161],{"data":31162,"marks":31163,"value":31165,"nodeType":867},{},[31164],{"type":913},"Cross-IdP impersonation",{"data":31167,"marks":31168,"value":31169,"nodeType":867},{},[],", which sees the attacker register a new IdP connected to the victim’s email account that can be used to access connected apps via SSO without directly compromising the primary IdP. (",{"data":31171,"content":31173,"nodeType":915},{"uri":31172},"https://pushsecurity.com/blog/a-new-class-of-phishing-verification-phishing-and-cross-idp-impersonation/",[31174],{"data":31175,"marks":31176,"value":31178,"nodeType":867},{},[31177],{"type":913},"You can read more about this here",{"data":31180,"marks":31181,"value":31182,"nodeType":867},{},[],".)",{"data":31184,"content":31185,"nodeType":942},{},[],{"data":31187,"content":31188,"nodeType":868},{},[31189],{"data":31190,"marks":31191,"value":18329,"nodeType":867},{},[31192],{"type":865},{"data":31194,"content":31195,"nodeType":876},{},[31196],{"data":31197,"marks":31198,"value":31199,"nodeType":867},{},[],"Push Security’s browser-based security platform provides comprehensive identity attack detection and response capabilities against techniques like AiTM phishing, credential stuffing, password spraying and session hijacking using stolen session tokens. You can also use Push to find and fix identity vulnerabilities across every app that your employees use, like: ghost logins; SSO coverage gaps; MFA gaps; weak, breached and reused passwords; risky OAuth integrations; and more.",{"data":31201,"content":31202,"nodeType":876},{},[31203,31206,31213],{"data":31204,"marks":31205,"value":27639,"nodeType":867},{},[],{"data":31207,"content":31208,"nodeType":915},{"uri":5286},[31209],{"data":31210,"marks":31211,"value":14723,"nodeType":867},{},[31212],{"type":913},{"data":31214,"marks":31215,"value":1679,"nodeType":867},{},[],"MFA downgrade: How attackers are getting around phishing-resistant authentication","MFA downgrade attacks are an increasingly common technique used by attackers to bypass phishing-resistant authentication methods registered to an account.","2025-07-21T00:00:00.000Z","mfa-downgrade-attacks",{"items":31221},[31222,31224],{"sys":31223,"name":342},{"id":3240},{"sys":31225,"name":4018},{"id":4017},{"items":31227},[31228],{"fullName":14739,"firstName":14740,"jobTitle":14741,"profilePicture":31229},{"url":14743},"blog/introducing-push-detections",{"json":31232},{"data":31233,"content":31234,"nodeType":1680},{},[31235],{"data":31236,"content":31237,"nodeType":876},{},[31238],{"data":31239,"marks":31240,"value":31241,"nodeType":867},{},[],"We’re launching a new Detections capability to provide deeper context and fine-grained data points on attacks that Push intercepts in the browser — enabling security teams to more effectively investigate and triage alerts, and build more effective workflows. ",{"id":26666,"publishedAt":31243},"2026-08-12T11:57:07.160Z",{"items":31245},[31246,31248],{"sys":31247,"name":342},{"id":3240},{"sys":31249,"name":4018},{"id":4017},{"items":31251},[31252,31254,31256,31258,31260,31262,31264,31266,31268,31270,31272,31274,31276,31278,31280,31282,31284,31286,31288,31290],{"sys":31253,"name":342,"slug":343,"tier":31},{"id":339},{"sys":31255,"name":297,"slug":298,"tier":31},{"id":294},{"sys":31257,"name":279,"slug":280,"tier":31},{"id":276},{"sys":31259,"name":413,"slug":414,"tier":31},{"id":410},{"sys":31261,"name":519,"slug":520,"tier":31},{"id":516},{"sys":31263,"name":642,"slug":643,"tier":31},{"id":639},{"sys":31265,"name":598,"slug":599,"tier":45},{"id":595},{"sys":31267,"name":351,"slug":352,"tier":45},{"id":348},{"sys":31269,"name":261,"slug":262,"tier":45},{"id":258},{"sys":31271,"name":466,"slug":467,"tier":45},{"id":463},{"sys":31273,"name":324,"slug":325,"tier":45},{"id":321},{"sys":31275,"name":571,"slug":572,"tier":45},{"id":568},{"sys":31277,"name":475,"slug":476,"tier":45},{"id":472},{"sys":31279,"name":440,"slug":441,"tier":45},{"id":437},{"sys":31281,"name":395,"slug":396,"tier":45},{"id":392},{"sys":31283,"name":484,"slug":485,"tier":45},{"id":481},{"sys":31285,"name":404,"slug":405,"tier":45},{"id":401},{"sys":31287,"name":502,"slug":503,"tier":45},{"id":499},{"sys":31289,"name":333,"slug":334,"tier":45},{"id":330},{"sys":31291,"name":377,"slug":378,"tier":45},{"id":374},"OT40_IRQG6rt0Aw2rPIT9BdVFUpnaaEb-tDlia6pFD4",{"id":31294,"title":30241,"authorsCollection":31295,"content":31299,"extension":228,"faqItemsCollection":31863,"faqTitle":59,"featured":6,"hashTags":59,"meta":31865,"metaTitle":31866,"ogImage":59,"postType":1767,"publishedDate":30243,"relatedBlogPostsCollection":31867,"slug":30244,"stem":33124,"subtitle":59,"summary":33125,"synopsis":30242,"sys":33136,"tagsCollection":33138,"topicsCollection":33144,"__hash__":33176},"blog/blog/how-browser-level-controls-change-the-fight-against-phishing.json",{"items":31296},[31297],{"fullName":849,"firstName":850,"jobTitle":851,"socialLinks":59,"profilePicture":31298},{"url":853},{"json":31300,"links":31840},{"data":31301,"content":31302,"nodeType":1680},{},[31303,31309,31315,31322,31345,31351,31356,31359,31366,31372,31378,31417,31423,31429,31432,31439,31445,31451,31457,31473,31479,31484,31491,31497,31503,31509,31514,31517,31524,31531,31537,31544,31550,31608,31614,31621,31627,31657,31664,31670,31677,31683,31690,31696,31744,31750,31753,31760,31766,31781,31811,31829,31834],{"data":31304,"content":31305,"nodeType":876},{},[31306],{"data":31307,"marks":31308,"value":29639,"nodeType":867},{},[],{"data":31310,"content":31311,"nodeType":876},{},[31312],{"data":31313,"marks":31314,"value":29646,"nodeType":867},{},[],{"data":31316,"content":31317,"nodeType":876},{},[31318],{"data":31319,"marks":31320,"value":29654,"nodeType":867},{},[31321],{"type":865},{"data":31323,"content":31324,"nodeType":876},{},[31325,31328,31335,31338,31342],{"data":31326,"marks":31327,"value":29661,"nodeType":867},{},[],{"data":31329,"content":31330,"nodeType":915},{"uri":29664},[31331],{"data":31332,"marks":31333,"value":29670,"nodeType":867},{},[31334],{"type":913},{"data":31336,"marks":31337,"value":29674,"nodeType":867},{},[],{"data":31339,"marks":31340,"value":29679,"nodeType":867},{},[31341],{"type":1303},{"data":31343,"marks":31344,"value":29683,"nodeType":867},{},[],{"data":31346,"content":31347,"nodeType":876},{},[31348],{"data":31349,"marks":31350,"value":29690,"nodeType":867},{},[],{"data":31352,"content":31355,"nodeType":985},{"target":31353},{"sys":31354},{"id":29695,"type":982,"linkType":983},[],{"data":31357,"content":31358,"nodeType":942},{},[],{"data":31360,"content":31361,"nodeType":868},{},[31362],{"data":31363,"marks":31364,"value":29707,"nodeType":867},{},[31365],{"type":865},{"data":31367,"content":31368,"nodeType":876},{},[31369],{"data":31370,"marks":31371,"value":29714,"nodeType":867},{},[],{"data":31373,"content":31374,"nodeType":876},{},[31375],{"data":31376,"marks":31377,"value":29721,"nodeType":867},{},[],{"data":31379,"content":31380,"nodeType":1629},{},[31381,31390,31399,31408],{"data":31382,"content":31383,"nodeType":1586},{},[31384],{"data":31385,"content":31386,"nodeType":876},{},[31387],{"data":31388,"marks":31389,"value":29734,"nodeType":867},{},[],{"data":31391,"content":31392,"nodeType":1586},{},[31393],{"data":31394,"content":31395,"nodeType":876},{},[31396],{"data":31397,"marks":31398,"value":29744,"nodeType":867},{},[],{"data":31400,"content":31401,"nodeType":1586},{},[31402],{"data":31403,"content":31404,"nodeType":876},{},[31405],{"data":31406,"marks":31407,"value":29754,"nodeType":867},{},[],{"data":31409,"content":31410,"nodeType":1586},{},[31411],{"data":31412,"content":31413,"nodeType":876},{},[31414],{"data":31415,"marks":31416,"value":29764,"nodeType":867},{},[],{"data":31418,"content":31419,"nodeType":876},{},[31420],{"data":31421,"marks":31422,"value":29771,"nodeType":867},{},[],{"data":31424,"content":31425,"nodeType":876},{},[31426],{"data":31427,"marks":31428,"value":29778,"nodeType":867},{},[],{"data":31430,"content":31431,"nodeType":942},{},[],{"data":31433,"content":31434,"nodeType":868},{},[31435],{"data":31436,"marks":31437,"value":29789,"nodeType":867},{},[31438],{"type":865},{"data":31440,"content":31441,"nodeType":876},{},[31442],{"data":31443,"marks":31444,"value":29796,"nodeType":867},{},[],{"data":31446,"content":31447,"nodeType":876},{},[31448],{"data":31449,"marks":31450,"value":29803,"nodeType":867},{},[],{"data":31452,"content":31453,"nodeType":876},{},[31454],{"data":31455,"marks":31456,"value":29810,"nodeType":867},{},[],{"data":31458,"content":31459,"nodeType":876},{},[31460,31463,31470],{"data":31461,"marks":31462,"value":29817,"nodeType":867},{},[],{"data":31464,"content":31465,"nodeType":915},{"uri":16043},[31466],{"data":31467,"marks":31468,"value":23521,"nodeType":867},{},[31469],{"type":913},{"data":31471,"marks":31472,"value":29828,"nodeType":867},{},[],{"data":31474,"content":31475,"nodeType":876},{},[31476],{"data":31477,"marks":31478,"value":29835,"nodeType":867},{},[],{"data":31480,"content":31483,"nodeType":985},{"target":31481},{"sys":31482},{"id":29840,"type":982,"linkType":983},[],{"data":31485,"content":31486,"nodeType":868},{},[31487],{"data":31488,"marks":31489,"value":29849,"nodeType":867},{},[31490],{"type":865},{"data":31492,"content":31493,"nodeType":876},{},[31494],{"data":31495,"marks":31496,"value":29856,"nodeType":867},{},[],{"data":31498,"content":31499,"nodeType":876},{},[31500],{"data":31501,"marks":31502,"value":29863,"nodeType":867},{},[],{"data":31504,"content":31505,"nodeType":876},{},[31506],{"data":31507,"marks":31508,"value":29870,"nodeType":867},{},[],{"data":31510,"content":31513,"nodeType":985},{"target":31511},{"sys":31512},{"id":29875,"type":982,"linkType":983},[],{"data":31515,"content":31516,"nodeType":942},{},[],{"data":31518,"content":31519,"nodeType":868},{},[31520],{"data":31521,"marks":31522,"value":29887,"nodeType":867},{},[31523],{"type":865},{"data":31525,"content":31526,"nodeType":1058},{},[31527],{"data":31528,"marks":31529,"value":29895,"nodeType":867},{},[31530],{"type":865},{"data":31532,"content":31533,"nodeType":876},{},[31534],{"data":31535,"marks":31536,"value":29902,"nodeType":867},{},[],{"data":31538,"content":31539,"nodeType":1058},{},[31540],{"data":31541,"marks":31542,"value":29910,"nodeType":867},{},[31543],{"type":865},{"data":31545,"content":31546,"nodeType":876},{},[31547],{"data":31548,"marks":31549,"value":29917,"nodeType":867},{},[],{"data":31551,"content":31552,"nodeType":1629},{},[31553,31562,31571,31590,31599],{"data":31554,"content":31555,"nodeType":1586},{},[31556],{"data":31557,"content":31558,"nodeType":876},{},[31559],{"data":31560,"marks":31561,"value":29930,"nodeType":867},{},[],{"data":31563,"content":31564,"nodeType":1586},{},[31565],{"data":31566,"content":31567,"nodeType":876},{},[31568],{"data":31569,"marks":31570,"value":29940,"nodeType":867},{},[],{"data":31572,"content":31573,"nodeType":1586},{},[31574],{"data":31575,"content":31576,"nodeType":876},{},[31577,31580,31587],{"data":31578,"marks":31579,"value":26492,"nodeType":867},{},[],{"data":31581,"content":31582,"nodeType":915},{"uri":26495},[31583],{"data":31584,"marks":31585,"value":26501,"nodeType":867},{},[31586],{"type":913},{"data":31588,"marks":31589,"value":21,"nodeType":867},{},[],{"data":31591,"content":31592,"nodeType":1586},{},[31593],{"data":31594,"content":31595,"nodeType":876},{},[31596],{"data":31597,"marks":31598,"value":29969,"nodeType":867},{},[],{"data":31600,"content":31601,"nodeType":1586},{},[31602],{"data":31603,"content":31604,"nodeType":876},{},[31605],{"data":31606,"marks":31607,"value":29979,"nodeType":867},{},[],{"data":31609,"content":31610,"nodeType":876},{},[31611],{"data":31612,"marks":31613,"value":29986,"nodeType":867},{},[],{"data":31615,"content":31616,"nodeType":1058},{},[31617],{"data":31618,"marks":31619,"value":29994,"nodeType":867},{},[31620],{"type":865},{"data":31622,"content":31623,"nodeType":876},{},[31624],{"data":31625,"marks":31626,"value":30001,"nodeType":867},{},[],{"data":31628,"content":31629,"nodeType":1629},{},[31630,31639,31648],{"data":31631,"content":31632,"nodeType":1586},{},[31633],{"data":31634,"content":31635,"nodeType":876},{},[31636],{"data":31637,"marks":31638,"value":30014,"nodeType":867},{},[],{"data":31640,"content":31641,"nodeType":1586},{},[31642],{"data":31643,"content":31644,"nodeType":876},{},[31645],{"data":31646,"marks":31647,"value":30024,"nodeType":867},{},[],{"data":31649,"content":31650,"nodeType":1586},{},[31651],{"data":31652,"content":31653,"nodeType":876},{},[31654],{"data":31655,"marks":31656,"value":30034,"nodeType":867},{},[],{"data":31658,"content":31659,"nodeType":1058},{},[31660],{"data":31661,"marks":31662,"value":30042,"nodeType":867},{},[31663],{"type":865},{"data":31665,"content":31666,"nodeType":876},{},[31667],{"data":31668,"marks":31669,"value":30049,"nodeType":867},{},[],{"data":31671,"content":31672,"nodeType":1058},{},[31673],{"data":31674,"marks":31675,"value":30057,"nodeType":867},{},[31676],{"type":865},{"data":31678,"content":31679,"nodeType":876},{},[31680],{"data":31681,"marks":31682,"value":30064,"nodeType":867},{},[],{"data":31684,"content":31685,"nodeType":1058},{},[31686],{"data":31687,"marks":31688,"value":30072,"nodeType":867},{},[31689],{"type":865},{"data":31691,"content":31692,"nodeType":876},{},[31693],{"data":31694,"marks":31695,"value":30079,"nodeType":867},{},[],{"data":31697,"content":31698,"nodeType":1629},{},[31699,31708,31717,31726,31735],{"data":31700,"content":31701,"nodeType":1586},{},[31702],{"data":31703,"content":31704,"nodeType":876},{},[31705],{"data":31706,"marks":31707,"value":30092,"nodeType":867},{},[],{"data":31709,"content":31710,"nodeType":1586},{},[31711],{"data":31712,"content":31713,"nodeType":876},{},[31714],{"data":31715,"marks":31716,"value":30102,"nodeType":867},{},[],{"data":31718,"content":31719,"nodeType":1586},{},[31720],{"data":31721,"content":31722,"nodeType":876},{},[31723],{"data":31724,"marks":31725,"value":30112,"nodeType":867},{},[],{"data":31727,"content":31728,"nodeType":1586},{},[31729],{"data":31730,"content":31731,"nodeType":876},{},[31732],{"data":31733,"marks":31734,"value":30122,"nodeType":867},{},[],{"data":31736,"content":31737,"nodeType":1586},{},[31738],{"data":31739,"content":31740,"nodeType":876},{},[31741],{"data":31742,"marks":31743,"value":30132,"nodeType":867},{},[],{"data":31745,"content":31746,"nodeType":876},{},[31747],{"data":31748,"marks":31749,"value":30139,"nodeType":867},{},[],{"data":31751,"content":31752,"nodeType":942},{},[],{"data":31754,"content":31755,"nodeType":868},{},[31756],{"data":31757,"marks":31758,"value":30150,"nodeType":867},{},[31759],{"type":865},{"data":31761,"content":31762,"nodeType":876},{},[31763],{"data":31764,"marks":31765,"value":30157,"nodeType":867},{},[],{"data":31767,"content":31768,"nodeType":876},{},[31769,31772,31778],{"data":31770,"marks":31771,"value":30164,"nodeType":867},{},[],{"data":31773,"content":31774,"nodeType":915},{"uri":29664},[31775],{"data":31776,"marks":31777,"value":30171,"nodeType":867},{},[],{"data":31779,"marks":31780,"value":1679,"nodeType":867},{},[],{"data":31782,"content":31783,"nodeType":1629},{},[31784,31793,31802],{"data":31785,"content":31786,"nodeType":1586},{},[31787],{"data":31788,"content":31789,"nodeType":876},{},[31790],{"data":31791,"marks":31792,"value":30187,"nodeType":867},{},[],{"data":31794,"content":31795,"nodeType":1586},{},[31796],{"data":31797,"content":31798,"nodeType":876},{},[31799],{"data":31800,"marks":31801,"value":30197,"nodeType":867},{},[],{"data":31803,"content":31804,"nodeType":1586},{},[31805],{"data":31806,"content":31807,"nodeType":876},{},[31808],{"data":31809,"marks":31810,"value":30207,"nodeType":867},{},[],{"data":31812,"content":31813,"nodeType":876},{},[31814,31818,31825],{"data":31815,"marks":31816,"value":30215,"nodeType":867},{},[31817],{"type":865},{"data":31819,"content":31820,"nodeType":915},{"uri":5286},[31821],{"data":31822,"marks":31823,"value":30223,"nodeType":867},{},[31824],{"type":865},{"data":31826,"marks":31827,"value":30228,"nodeType":867},{},[31828],{"type":865},{"data":31830,"content":31833,"nodeType":985},{"target":31831},{"sys":31832},{"id":30233,"type":982,"linkType":983},[],{"data":31835,"content":31836,"nodeType":876},{},[31837],{"data":31838,"marks":31839,"value":21,"nodeType":867},{},[],{"entries":31841},{"hyperlink":31842,"inline":31843,"block":31844},[],[],[31845,31849,31853,31860],{"sys":31846,"__typename":21660,"title":31847,"arcadeDemoUrl":31848,"playText":21728},{"id":29695},"Stop phishing attacks in the browser with Push Security","https://demo.arcade.software/iMcqa8vaDB0AjfmJFTk7?embed",{"sys":31850,"__typename":1697,"type":1698,"ctaText":31851,"buttonLabel":21672,"buttonColour":1701,"buttonUrl":31852},{"id":29840},"Check out our on-demand webinar for our breakdown of why phishing attacks are still the weapon of choice for attackers in 2025.","https://pushsecurity.com/webinar/phishing",{"sys":31854,"__typename":1688,"title":31855,"caption":31856,"layoutMode":59,"file":31857},{"id":29875},"Phishing block screen","Block pages are customizable to ensure that users know their organization is protecting them.",{"url":31858,"width":1693,"height":31859},"https://images.ctfassets.net/y1cdw1ablpvd/6InFhVkJJOPhsojQoub04K/b43e32cfa0bdc423dc993e930ebe1ae2/image1.png",1125,{"sys":31861,"__typename":1697,"type":1698,"ctaText":31862,"buttonLabel":17415,"buttonColour":1701,"buttonUrl":5286},{"id":30233},"Book a demo to see Push detect and shut down phishing attacks in real time.",{"items":31864},[],{},"Browser security tackles phishing where it really happens",{"items":31868},[31869,32533,32838],{"__typename":1772,"sys":31870,"content":31872,"title":32519,"synopsis":32520,"hashTags":59,"publishedDate":32521,"slug":32522,"tagsCollection":32523,"authorsCollection":32529},{"id":31871},"3dtvtDQdcQ6fAW7CB8VOFP",{"json":31873},{"data":31874,"content":31875,"nodeType":1680},{},[31876,31883,31890,31897,31900,31908,31915,31935,31968,31974,31994,32000,32025,32028,32036,32043,32058,32073,32079,32086,32093,32099,32115,32118,32126,32133,32140,32147,32154,32157,32165,32172,32179,32199,32206,32214,32256,32263,32269,32276,32282,32289,32292,32300,32315,32322,32364,32376,32379,32387,32394,32401,32434,32441,32461,32467,32473,32476,32483,32490,32507,32513],{"data":31877,"content":31878,"nodeType":876},{},[31879],{"data":31880,"marks":31881,"value":31882,"nodeType":867},{},[],"Phishing attacks remain a huge challenge for organizations in 2025. In fact, with attackers increasingly leveraging identity-based techniques over software exploits, phishing arguably poses a bigger threat than ever before. ",{"data":31884,"content":31885,"nodeType":876},{},[31886],{"data":31887,"marks":31888,"value":31889,"nodeType":867},{},[],"Attackers are turning to identity attacks like phishing because they can achieve all of the same objectives as they would in a traditional endpoint or network attack, simply by logging into a victim’s account. And with organizations now using hundreds of internet apps across their workforce, the scope of accounts that can be phished or targeted with stolen credentials has grown exponentially. ",{"data":31891,"content":31892,"nodeType":876},{},[31893],{"data":31894,"marks":31895,"value":31896,"nodeType":867},{},[],"With MFA-bypassing phishing kits the new normal, capable of phishing accounts protected by SMS, OTP, and push-based methods, detection controls are being put under constant pressure as prevention controls fall short. ",{"data":31898,"content":31899,"nodeType":942},{},[],{"data":31901,"content":31902,"nodeType":868},{},[31903],{"data":31904,"marks":31905,"value":31907,"nodeType":867},{},[31906],{"type":865},"Attackers are bypassing detection controls",{"data":31909,"content":31910,"nodeType":876},{},[31911],{"data":31912,"marks":31913,"value":31914,"nodeType":867},{},[],"The majority of phishing detection and control enforcement is focused at the email and network layer — typically at the Secure Email Gateway (SEG), Secure Web Gateway (SWG)/proxy, or both. ",{"data":31916,"content":31917,"nodeType":876},{},[31918,31922,31931],{"data":31919,"marks":31920,"value":31921,"nodeType":867},{},[],"But attackers know this, ",{"data":31923,"content":31925,"nodeType":915},{"uri":31924},"https://pushsecurity.com/blog/how-aitm-phishing-kits-evade-detection-p2/",[31926],{"data":31927,"marks":31928,"value":31930,"nodeType":867},{},[31929],{"type":913},"and are taking steps to avoid these controls",{"data":31932,"marks":31933,"value":31934,"nodeType":867},{},[],", by:",{"data":31936,"content":31937,"nodeType":1629},{},[31938,31948,31958],{"data":31939,"content":31940,"nodeType":1586},{},[31941],{"data":31942,"content":31943,"nodeType":876},{},[31944],{"data":31945,"marks":31946,"value":31947,"nodeType":867},{},[],"Routinely evading IoC driven blocklists by dynamically rotating and updating commonly signatured elements like IPs, domains, and URLs.",{"data":31949,"content":31950,"nodeType":1586},{},[31951],{"data":31952,"content":31953,"nodeType":876},{},[31954],{"data":31955,"marks":31956,"value":31957,"nodeType":867},{},[],"Preventing analysis of their phishing pages by implementing bot protection like CAPTCHA or Cloudflare Turnstile alongside other detection evasion methods. ",{"data":31959,"content":31960,"nodeType":1586},{},[31961],{"data":31962,"content":31963,"nodeType":876},{},[31964],{"data":31965,"marks":31966,"value":31967,"nodeType":867},{},[],"Changing visual and DOM elements on the page so that even when the page is loaded, detection signatures may fail to trigger.  ",{"data":31969,"content":31973,"nodeType":985},{"target":31970},{"sys":31971},{"id":31972,"type":982,"linkType":983},"5w44LsamEfcwSACx3MA997",[],{"data":31975,"content":31976,"nodeType":876},{},[31977,31981,31990],{"data":31978,"marks":31979,"value":31980,"nodeType":867},{},[],"And in fact, by launching multi- and cross-channel attacks, attackers are evading email-based controls entirely. Just see ",{"data":31982,"content":31984,"nodeType":915},{"uri":31983},"https://pushsecurity.com/blog/investigating-a-recent-malvertising-campaign-targeting-onfido-customers/?utm_campaign=12081956-FY25Q2_Hacker-News-Article&utm_source=thehackernews&utm_medium=sponsored&utm_content=external-article",[31985],{"data":31986,"marks":31987,"value":31989,"nodeType":867},{},[31988],{"type":913},"this recent example",{"data":31991,"marks":31992,"value":31993,"nodeType":867},{},[],", where attackers impersonating Onfido delivered their phishing attack via malicious Google ads (aka malvertising) — bypassing email altogether. ",{"data":31995,"content":31999,"nodeType":985},{"target":31996},{"sys":31997},{"id":31998,"type":982,"linkType":983},"3sGmVHl1Rwjyw3TMZSYuy4",[],{"data":32001,"content":32002,"nodeType":876},{},[32003,32007,32012,32016,32021],{"data":32004,"marks":32005,"value":32006,"nodeType":867},{},[],"It’s worth pointing out the limitations of email-based solutions here too. Email has some additional checks around the sender’s reputation and things like DMARC/DKIM, but these don’t actually identify malicious ",{"data":32008,"marks":32009,"value":32011,"nodeType":867},{},[32010],{"type":865},"pages",{"data":32013,"marks":32014,"value":32015,"nodeType":867},{},[],". Similarly, some modern email solutions are doing much deeper analysis of the ",{"data":32017,"marks":32018,"value":32020,"nodeType":867},{},[32019],{"type":865},"content",{"data":32022,"marks":32023,"value":32024,"nodeType":867},{},[]," of an email. But… that doesn’t really help with identifying the phishing sites themselves (just indicates that one might be linked in the email). This is much more appropriate for BEC-style attacks where the goal is to social engineer the victim, as opposed to linking them to a malicious page. And this still doesn’t help with attacks launched over different mediums as we’ve highlighted above.",{"data":32026,"content":32027,"nodeType":942},{},[],{"data":32029,"content":32030,"nodeType":868},{},[32031],{"data":32032,"marks":32033,"value":32035,"nodeType":867},{},[32034],{"type":865},"How browser-based detection and response can level the playing field",{"data":32037,"content":32038,"nodeType":876},{},[32039],{"data":32040,"marks":32041,"value":32042,"nodeType":867},{},[],"Most phishing attacks involve the delivery of a malicious link to a user. The user clicks the link and loads a malicious page. In the vast majority of cases, the malicious page is a login portal for a specific website, where the goal for the attacker is to steal the victim’s account.",{"data":32044,"content":32045,"nodeType":876},{},[32046,32050,32054],{"data":32047,"marks":32048,"value":32049,"nodeType":867},{},[],"These attacks are happening pretty much exclusively in the victim’s browser. So rather than building more email or network based controls looking from the outside-in at phishing pages accessed in the browser, there’s a huge opportunity presented by building phishing detection and response capabilities ",{"data":32051,"marks":32052,"value":1304,"nodeType":867},{},[32053],{"type":1303},{"data":32055,"marks":32056,"value":32057,"nodeType":867},{},[]," the browser. ",{"data":32059,"content":32060,"nodeType":876},{},[32061,32065,32070],{"data":32062,"marks":32063,"value":32064,"nodeType":867},{},[],"When we look at the history of detection and response, this makes a lot of sense. When endpoint attacks skyrocketed in the late 2000s / early 2010s, they took advantage of the fact that defenders were trying to detect malware with primarily network-based detections, signature-based analysis of files, and running files in sandboxes (which was reliably defeated with sandbox-aware malware and using things as simple as putting an execution delay in the code). But this gave way to EDR, which presented a better way of observing and intercepting malicious software in ",{"data":32066,"marks":32067,"value":32069,"nodeType":867},{},[32068],{"type":865},"real-time",{"data":32071,"marks":32072,"value":5704,"nodeType":867},{},[],{"data":32074,"content":32078,"nodeType":985},{"target":32075},{"sys":32076},{"id":32077,"type":982,"linkType":983},"1KFwJvbIMiWHb1erWlljZf",[],{"data":32080,"content":32081,"nodeType":876},{},[32082],{"data":32083,"marks":32084,"value":32085,"nodeType":867},{},[],"The key here was getting inside the data stream to be able to observe activity in real-time on the endpoint. ",{"data":32087,"content":32088,"nodeType":876},{},[32089],{"data":32090,"marks":32091,"value":32092,"nodeType":867},{},[],"We’re in a similar position today. Modern phishing attacks are happening on web pages accessed via the browser, and the tools we’re relying on — email, network, even endpoint — don’t have the required visibility. They’re looking from the outside-in. ",{"data":32094,"content":32098,"nodeType":985},{"target":32095},{"sys":32096},{"id":32097,"type":982,"linkType":983},"59t6AcjpRjs3VQQXQO3PWu",[],{"data":32100,"content":32101,"nodeType":876},{},[32102,32106,32111],{"data":32103,"marks":32104,"value":32105,"nodeType":867},{},[],"But what if we could do detection and response from ",{"data":32107,"marks":32108,"value":32110,"nodeType":867},{},[32109],{"type":865},"inside the browser?",{"data":32112,"marks":32113,"value":32114,"nodeType":867},{},[]," Here’s three reasons why the browser is best for stopping phishing attacks:",{"data":32116,"content":32117,"nodeType":942},{},[],{"data":32119,"content":32120,"nodeType":868},{},[32121],{"data":32122,"marks":32123,"value":32125,"nodeType":867},{},[32124],{"type":865},"#1: Analyze pages, not links",{"data":32127,"content":32128,"nodeType":876},{},[32129],{"data":32130,"marks":32131,"value":32132,"nodeType":867},{},[],"Common phishing detections rely on the analysis of links or static HTML as opposed to malicious pages. Modern phishing pages are no longer static HTML — like most other modern web pages, these are dynamic web apps rendered in the browser, with JavaScript dynamically rewriting the page and launching the malicious content. This means that most basic, static checks fail to identify the malicious content running on the page. ",{"data":32134,"content":32135,"nodeType":876},{},[32136],{"data":32137,"marks":32138,"value":32139,"nodeType":867},{},[],"Without deeper analysis, you’re reliant on analyzing things like domains, URLs and IP addresses against known-bad blocklists. But these are all highly disposable. Attackers are buying them in bulk, constantly taking over legitimate domains, and generally planning for the fact that they’ll get through a lot of them. Modern phishing architecture is also able to dynamically rotate and update the links served to visitors from a continually refreshed pool (so every person that clicks the link gets served a different URL) and even going as far as using things like one-time magic links (which also means that any security team members trying to investigate the page later won’t be able to do so). ",{"data":32141,"content":32142,"nodeType":876},{},[32143],{"data":32144,"marks":32145,"value":32146,"nodeType":867},{},[],"Ultimately, this means that blocklists just aren’t that effective — because it’s trivial for attackers to change the indicators being used to create detections. If you think about the Pyramid of Pain, these indicators sit right at the bottom — the kind of thing we’ve been moving away from for years in the endpoint security world.  ",{"data":32148,"content":32149,"nodeType":876},{},[32150],{"data":32151,"marks":32152,"value":32153,"nodeType":867},{},[],"But in the browser, you can observe the rendered web page in all its glory. With much deeper visibility of the page (and its malicious elements) you can…",{"data":32155,"content":32156,"nodeType":942},{},[],{"data":32158,"content":32159,"nodeType":868},{},[32160],{"data":32161,"marks":32162,"value":32164,"nodeType":867},{},[32163],{"type":865},"#2: Detect TTPs, not IoCs",{"data":32166,"content":32167,"nodeType":876},{},[32168],{"data":32169,"marks":32170,"value":32171,"nodeType":867},{},[],"Even where TTP-based detections are in play, they’re typically reliant on either piecing together network requests, or loading the page in a sandbox. ",{"data":32173,"content":32174,"nodeType":876},{},[32175],{"data":32176,"marks":32177,"value":32178,"nodeType":867},{},[],"However, attackers are getting pretty good at evading sandbox analysis — simply by implementing bot protection by requiring user interaction with a CAPTCHA or Cloudflare Turnstile. Even if you can get past Turnstile, then you’ll need to supply the correct URL parameters and headers, and execute JavaScript, to be served the malicious page. This means that a defender who knows the domain name can’t discover the malicious behavior just by making a simple HTTP(S) request to the domain.",{"data":32180,"content":32181,"nodeType":876},{},[32182,32186,32195],{"data":32183,"marks":32184,"value":32185,"nodeType":867},{},[],"And if all this wasn’t enough, ",{"data":32187,"content":32189,"nodeType":915},{"uri":32188},"https://pushsecurity.com/blog/how-aitm-phishing-kits-evade-detection-p2/?utm_campaign=12081956-FY25Q2_Hacker-News-Article&utm_source=thehackernews&utm_medium=sponsored&utm_content=external-article",[32190],{"data":32191,"marks":32192,"value":32194,"nodeType":867},{},[32193],{"type":913},"they’re also obfuscating both visual and DOM elements to prevent signature-based detections from picking them up",{"data":32196,"marks":32197,"value":32198,"nodeType":867},{},[]," — so even if you can land on the page, there’s a high chance that your detections won’t trigger.",{"data":32200,"content":32201,"nodeType":876},{},[32202],{"data":32203,"marks":32204,"value":32205,"nodeType":867},{},[],"When using a proxy, you’ll have some visibility of the network traffic generated by a user accessing and interacting with a page. However, you’ll struggle to correlate key actions like whether the user entered their password with the specific tab when dealing with the sheer volume of disorganized network traffic data. ",{"data":32207,"content":32208,"nodeType":876},{},[32209],{"data":32210,"marks":32211,"value":32213,"nodeType":867},{},[32212],{"type":865},"But you get much better visibility of all this in the browser, with access to:",{"data":32215,"content":32216,"nodeType":1629},{},[32217,32226,32236,32246],{"data":32218,"content":32219,"nodeType":1586},{},[32220],{"data":32221,"content":32222,"nodeType":876},{},[32223],{"data":32224,"marks":32225,"value":27180,"nodeType":867},{},[],{"data":32227,"content":32228,"nodeType":1586},{},[32229],{"data":32230,"content":32231,"nodeType":876},{},[32232],{"data":32233,"marks":32234,"value":32235,"nodeType":867},{},[],"Full user interaction tracing — every click, keystroke, or DOM change can be traced",{"data":32237,"content":32238,"nodeType":1586},{},[32239],{"data":32240,"content":32241,"nodeType":876},{},[32242],{"data":32243,"marks":32244,"value":32245,"nodeType":867},{},[],"Full inspection at every layer of execution, not just initial HTML served",{"data":32247,"content":32248,"nodeType":1586},{},[32249],{"data":32250,"content":32251,"nodeType":876},{},[32252],{"data":32253,"marks":32254,"value":32255,"nodeType":867},{},[],"Full access to browser APIs, to correlate with browser history, local storage, attached cookies, etc.",{"data":32257,"content":32258,"nodeType":876},{},[32259],{"data":32260,"marks":32261,"value":32262,"nodeType":867},{},[],"This gives you everything you need to build high-fidelity detections focused on page behavior and user interaction – that are much harder for attackers to get around when compared to IoC-based detections. ",{"data":32264,"content":32268,"nodeType":985},{"target":32265},{"sys":32266},{"id":32267,"type":982,"linkType":983},"1YggWcADAWgt3sUkXMsVIw",[],{"data":32270,"content":32271,"nodeType":876},{},[32272],{"data":32273,"marks":32274,"value":32275,"nodeType":867},{},[],"In the browser, you get much better visibility of the user and page behavior to enable phishing page detection.",{"data":32277,"content":32281,"nodeType":985},{"target":32278},{"sys":32279},{"id":32280,"type":982,"linkType":983},"1BKgjnYkLJIRW0LJZYpfga",[],{"data":32283,"content":32284,"nodeType":876},{},[32285],{"data":32286,"marks":32287,"value":32288,"nodeType":867},{},[],"And with this new visibility, because you’re in the browser and seeing the page at the same time as the user is interacting with it, you can…",{"data":32290,"content":32291,"nodeType":942},{},[],{"data":32293,"content":32294,"nodeType":868},{},[32295],{"data":32296,"marks":32297,"value":32299,"nodeType":867},{},[32298],{"type":865},"#3: Intercept in real time, not post mortem",{"data":32301,"content":32302,"nodeType":876},{},[32303,32307,32312],{"data":32304,"marks":32305,"value":32306,"nodeType":867},{},[],"For non-browser solutions, ",{"data":32308,"marks":32309,"value":32311,"nodeType":867},{},[32310],{"type":865},"real-time phishing detection is basically nonexistent",{"data":32313,"marks":32314,"value":5704,"nodeType":867},{},[],{"data":32316,"content":32317,"nodeType":876},{},[32318],{"data":32319,"marks":32320,"value":32321,"nodeType":867},{},[],"At best, your proxy-based solution might be able to detect malicious behavior via the network traffic generated by your user interacting with the page. But because of the complexity of reconstructing network requests post-TLS-encryption, this typically happens on a time delay and is not entirely reliable. ",{"data":32323,"content":32324,"nodeType":876},{},[32325,32329,32334,32338,32343,32347,32351,32355,32360],{"data":32326,"marks":32327,"value":32328,"nodeType":867},{},[],"If a page is flagged, it usually requires further investigation by a security team to rule out any false positives and kick off an investigation. This can take ",{"data":32330,"marks":32331,"value":32333,"nodeType":867},{},[32332],{"type":865},"hours",{"data":32335,"marks":32336,"value":32337,"nodeType":867},{},[]," at best, probably ",{"data":32339,"marks":32340,"value":32342,"nodeType":867},{},[32341],{"type":865},"days",{"data":32344,"marks":32345,"value":32346,"nodeType":867},{},[],". Then, once a page is identified as malicious and IoCs are created, it can take ",{"data":32348,"marks":32349,"value":32342,"nodeType":867},{},[32350],{"type":865},{"data":32352,"marks":32353,"value":32354,"nodeType":867},{},[]," or even ",{"data":32356,"marks":32357,"value":32359,"nodeType":867},{},[32358],{"type":865},"weeks",{"data":32361,"marks":32362,"value":32363,"nodeType":867},{},[]," before the information is distributed, TI feeds are updated, and ingested into blocklists. ",{"data":32365,"content":32366,"nodeType":876},{},[32367,32371],{"data":32368,"marks":32369,"value":32370,"nodeType":867},{},[],"But in the browser, you’re observing the page in real-time, as the user sees it, from inside the browser. This is a game changer when it comes to not just detecting, but intercepting and shutting down attacks before a user is phished and the damage is done. ",{"data":32372,"marks":32373,"value":32375,"nodeType":867},{},[32374],{"type":865},"This changes the focus from post mortem containment and cleanup, to pre-compromise interception in real time. ",{"data":32377,"content":32378,"nodeType":942},{},[],{"data":32380,"content":32381,"nodeType":868},{},[32382],{"data":32383,"marks":32384,"value":32386,"nodeType":867},{},[32385],{"type":865},"The future of phishing detection and response is browser based",{"data":32388,"content":32389,"nodeType":876},{},[32390],{"data":32391,"marks":32392,"value":32393,"nodeType":867},{},[],"Push provides a browser-based identity security solution that intercepts phishing attacks as they happen — in employee browsers. Being in the browser delivers a lot of advantages when it comes to detecting and intercepting phishing attacks. You see the live webpage that the user sees, as they see it, meaning you have much better visibility of malicious elements running on the page. It also means that you can implement real-time controls that kick in when a malicious element is detected. ",{"data":32395,"content":32396,"nodeType":876},{},[32397],{"data":32398,"marks":32399,"value":32400,"nodeType":867},{},[],"When a phishing attack hits a user with Push, regardless of the delivery channel, our browser extension inspects the webpage running in the user's browser. Push observes that the webpage is a login page and the user is entering their password into the page, detecting that:",{"data":32402,"content":32403,"nodeType":1629},{},[32404,32414,32424],{"data":32405,"content":32406,"nodeType":1586},{},[32407],{"data":32408,"content":32409,"nodeType":876},{},[32410],{"data":32411,"marks":32412,"value":32413,"nodeType":867},{},[],"The password the user is entering into the phishing site has been used to log into another site previously. This means that the password is being reused (bad) or the user is being phished (even worse).  ",{"data":32415,"content":32416,"nodeType":1586},{},[32417],{"data":32418,"content":32419,"nodeType":876},{},[32420],{"data":32421,"marks":32422,"value":32423,"nodeType":867},{},[],"The web page is cloned from a legitimate login page that has been fingerprinted by Push. ",{"data":32425,"content":32426,"nodeType":1586},{},[32427],{"data":32428,"content":32429,"nodeType":876},{},[32430],{"data":32431,"marks":32432,"value":32433,"nodeType":867},{},[],"A phishing toolkit is running on the web page. ",{"data":32435,"content":32436,"nodeType":876},{},[32437],{"data":32438,"marks":32439,"value":32440,"nodeType":867},{},[],"As a result, the user is blocked from interacting with the phishing site and prevented from continuing. ",{"data":32442,"content":32443,"nodeType":876},{},[32444,32449,32458],{"data":32445,"marks":32446,"value":32448,"nodeType":867},{},[32447],{"type":865},"These are good examples of detections that are difficult (or impossible) for an attacker to evade — you can’t phish a victim if they can’t enter their credentials into your phishing site! ",{"data":32450,"content":32452,"nodeType":915},{"uri":32451},"https://pushsecurity.com/blog/detecting-and-blocking-phishing-attacks-in-the-browser/?utm_campaign=12081956-FY25Q2_Hacker-News-Article&utm_source=thehackernews&utm_medium=sponsored&utm_content=external-article",[32453],{"data":32454,"marks":32455,"value":32457,"nodeType":867},{},[32456],{"type":913},"Find out more about how Push detects and blocks phishing attacks here.",{"data":32459,"marks":32460,"value":21,"nodeType":867},{},[],{"data":32462,"content":32466,"nodeType":985},{"target":32463},{"sys":32464},{"id":32465,"type":982,"linkType":983},"4ixcEsEW4EyqckOTmP5Pbb",[],{"data":32468,"content":32472,"nodeType":985},{"target":32469},{"sys":32470},{"id":32471,"type":982,"linkType":983},"4PJKxWTroEPohYm4mklfl6",[],{"data":32474,"content":32475,"nodeType":942},{},[],{"data":32477,"content":32478,"nodeType":868},{},[32479],{"data":32480,"marks":32481,"value":18329,"nodeType":867},{},[32482],{"type":865},{"data":32484,"content":32485,"nodeType":876},{},[32486],{"data":32487,"marks":32488,"value":32489,"nodeType":867},{},[],"It doesn’t stop there — Push provides comprehensive identity attack detection and response capabilities against techniques like credential stuffing, password spraying and session hijacking using stolen session tokens. You can also use Push to find and fix identity vulnerabilities across every app that your employees use like: ghost logins; SSO coverage gaps; MFA gaps; weak, breached and reused passwords; risky OAuth integrations; and more. ",{"data":32491,"content":32492,"nodeType":876},{},[32493,32496,32504],{"data":32494,"marks":32495,"value":27639,"nodeType":867},{},[],{"data":32497,"content":32499,"nodeType":915},{"uri":32498},"https://pushsecurity.com/demo?utm_campaign=12081956-FY25Q2_Hacker-News-Article&utm_source=thehackernews&utm_medium=sponsored&utm_content=external-article",[32500],{"data":32501,"marks":32502,"value":14723,"nodeType":867},{},[32503],{"type":913},{"data":32505,"marks":32506,"value":1679,"nodeType":867},{},[],{"data":32508,"content":32512,"nodeType":985},{"target":32509},{"sys":32510},{"id":32511,"type":982,"linkType":983},"2DviJNOMbKgbcqwkNl0LDP",[],{"data":32514,"content":32515,"nodeType":876},{},[32516],{"data":32517,"marks":32518,"value":21,"nodeType":867},{},[],"Three reasons why browser is best for stopping phishing attacks","Why being in the browser gives defenders a key advantage over network and email phishing prevention, detection, and response tools. ","2025-04-28T00:00:00.000Z","three-reasons-why-browser-is-best-for-stopping-phishing-attacks",{"items":32524},[32525,32527],{"sys":32526,"name":342},{"id":3240},{"sys":32528,"name":4018},{"id":4017},{"items":32530},[32531],{"fullName":4022,"firstName":4023,"jobTitle":4024,"profilePicture":32532},{"url":4026},{"__typename":1772,"sys":32534,"content":32535,"title":28015,"synopsis":28016,"hashTags":59,"publishedDate":28017,"slug":28018,"tagsCollection":32830,"authorsCollection":32834},{"id":27667},{"json":32536},{"data":32537,"content":32538,"nodeType":1680},{},[32539,32545,32551,32557,32562,32568,32598,32604,32610,32616,32621,32627,32633,32648,32653,32659,32675,32691,32697,32703,32709,32715,32721,32727,32733,32749,32755,32761,32766,32772,32778,32798,32803,32819,32824],{"data":32540,"content":32541,"nodeType":876},{},[32542],{"data":32543,"marks":32544,"value":27678,"nodeType":867},{},[],{"data":32546,"content":32547,"nodeType":876},{},[32548],{"data":32549,"marks":32550,"value":27685,"nodeType":867},{},[],{"data":32552,"content":32553,"nodeType":876},{},[32554],{"data":32555,"marks":32556,"value":27692,"nodeType":867},{},[],{"data":32558,"content":32561,"nodeType":985},{"target":32559},{"sys":32560},{"id":27697,"type":982,"linkType":983},[],{"data":32563,"content":32564,"nodeType":876},{},[32565],{"data":32566,"marks":32567,"value":27705,"nodeType":867},{},[],{"data":32569,"content":32570,"nodeType":1629},{},[32571,32580,32589],{"data":32572,"content":32573,"nodeType":1586},{},[32574],{"data":32575,"content":32576,"nodeType":876},{},[32577],{"data":32578,"marks":32579,"value":27718,"nodeType":867},{},[],{"data":32581,"content":32582,"nodeType":1586},{},[32583],{"data":32584,"content":32585,"nodeType":876},{},[32586],{"data":32587,"marks":32588,"value":27728,"nodeType":867},{},[],{"data":32590,"content":32591,"nodeType":1586},{},[32592],{"data":32593,"content":32594,"nodeType":876},{},[32595],{"data":32596,"marks":32597,"value":27738,"nodeType":867},{},[],{"data":32599,"content":32600,"nodeType":876},{},[32601],{"data":32602,"marks":32603,"value":27745,"nodeType":867},{},[],{"data":32605,"content":32606,"nodeType":868},{},[32607],{"data":32608,"marks":32609,"value":27752,"nodeType":867},{},[],{"data":32611,"content":32612,"nodeType":876},{},[32613],{"data":32614,"marks":32615,"value":27759,"nodeType":867},{},[],{"data":32617,"content":32620,"nodeType":985},{"target":32618},{"sys":32619},{"id":27764,"type":982,"linkType":983},[],{"data":32622,"content":32623,"nodeType":876},{},[32624],{"data":32625,"marks":32626,"value":27772,"nodeType":867},{},[],{"data":32628,"content":32629,"nodeType":868},{},[32630],{"data":32631,"marks":32632,"value":27779,"nodeType":867},{},[],{"data":32634,"content":32635,"nodeType":876},{},[32636,32639,32645],{"data":32637,"marks":32638,"value":27786,"nodeType":867},{},[],{"data":32640,"content":32641,"nodeType":915},{"uri":22147},[32642],{"data":32643,"marks":32644,"value":27793,"nodeType":867},{},[],{"data":32646,"marks":32647,"value":27797,"nodeType":867},{},[],{"data":32649,"content":32652,"nodeType":985},{"target":32650},{"sys":32651},{"id":27802,"type":982,"linkType":983},[],{"data":32654,"content":32655,"nodeType":1058},{},[32656],{"data":32657,"marks":32658,"value":27810,"nodeType":867},{},[],{"data":32660,"content":32661,"nodeType":876},{},[32662,32665,32672],{"data":32663,"marks":32664,"value":27817,"nodeType":867},{},[],{"data":32666,"content":32667,"nodeType":915},{"uri":27820},[32668],{"data":32669,"marks":32670,"value":27826,"nodeType":867},{},[32671],{"type":913},{"data":32673,"marks":32674,"value":27830,"nodeType":867},{},[],{"data":32676,"content":32677,"nodeType":876},{},[32678,32681,32688],{"data":32679,"marks":32680,"value":27837,"nodeType":867},{},[],{"data":32682,"content":32683,"nodeType":915},{"uri":27840},[32684],{"data":32685,"marks":32686,"value":27846,"nodeType":867},{},[32687],{"type":913},{"data":32689,"marks":32690,"value":27850,"nodeType":867},{},[],{"data":32692,"content":32693,"nodeType":876},{},[32694],{"data":32695,"marks":32696,"value":27857,"nodeType":867},{},[],{"data":32698,"content":32699,"nodeType":876},{},[32700],{"data":32701,"marks":32702,"value":27864,"nodeType":867},{},[],{"data":32704,"content":32705,"nodeType":1058},{},[32706],{"data":32707,"marks":32708,"value":27871,"nodeType":867},{},[],{"data":32710,"content":32711,"nodeType":876},{},[32712],{"data":32713,"marks":32714,"value":27878,"nodeType":867},{},[],{"data":32716,"content":32717,"nodeType":876},{},[32718],{"data":32719,"marks":32720,"value":27885,"nodeType":867},{},[],{"data":32722,"content":32723,"nodeType":868},{},[32724],{"data":32725,"marks":32726,"value":27892,"nodeType":867},{},[],{"data":32728,"content":32729,"nodeType":876},{},[32730],{"data":32731,"marks":32732,"value":27899,"nodeType":867},{},[],{"data":32734,"content":32735,"nodeType":876},{},[32736,32739,32746],{"data":32737,"marks":32738,"value":27906,"nodeType":867},{},[],{"data":32740,"content":32741,"nodeType":915},{"uri":27909},[32742],{"data":32743,"marks":32744,"value":27915,"nodeType":867},{},[32745],{"type":913},{"data":32747,"marks":32748,"value":27919,"nodeType":867},{},[],{"data":32750,"content":32751,"nodeType":876},{},[32752],{"data":32753,"marks":32754,"value":27926,"nodeType":867},{},[],{"data":32756,"content":32757,"nodeType":876},{},[32758],{"data":32759,"marks":32760,"value":27933,"nodeType":867},{},[],{"data":32762,"content":32765,"nodeType":985},{"target":32763},{"sys":32764},{"id":27938,"type":982,"linkType":983},[],{"data":32767,"content":32768,"nodeType":868},{},[32769],{"data":32770,"marks":32771,"value":27946,"nodeType":867},{},[],{"data":32773,"content":32774,"nodeType":876},{},[32775],{"data":32776,"marks":32777,"value":27953,"nodeType":867},{},[],{"data":32779,"content":32780,"nodeType":876},{},[32781,32784,32788,32791,32795],{"data":32782,"marks":32783,"value":27960,"nodeType":867},{},[],{"data":32785,"marks":32786,"value":27965,"nodeType":867},{},[32787],{"type":865},{"data":32789,"marks":32790,"value":27969,"nodeType":867},{},[],{"data":32792,"marks":32793,"value":27974,"nodeType":867},{},[32794],{"type":865},{"data":32796,"marks":32797,"value":27978,"nodeType":867},{},[],{"data":32799,"content":32802,"nodeType":985},{"target":32800},{"sys":32801},{"id":27983,"type":982,"linkType":983},[],{"data":32804,"content":32805,"nodeType":876},{},[32806,32809,32816],{"data":32807,"marks":32808,"value":27991,"nodeType":867},{},[],{"data":32810,"content":32811,"nodeType":915},{"uri":5286},[32812],{"data":32813,"marks":32814,"value":11707,"nodeType":867},{},[32815],{"type":913},{"data":32817,"marks":32818,"value":28002,"nodeType":867},{},[],{"data":32820,"content":32823,"nodeType":985},{"target":32821},{"sys":32822},{"id":28007,"type":982,"linkType":983},[],{"data":32825,"content":32826,"nodeType":876},{},[32827],{"data":32828,"marks":32829,"value":21,"nodeType":867},{},[],{"items":32831},[32832],{"sys":32833,"name":297},{"id":2706},{"items":32835},[32836],{"fullName":4089,"firstName":4090,"jobTitle":851,"profilePicture":32837},{"url":4094},{"__typename":1772,"sys":32839,"content":32840,"title":24585,"synopsis":24586,"hashTags":59,"publishedDate":24587,"slug":24588,"tagsCollection":33114,"authorsCollection":33120},{"id":24268},{"json":32841},{"data":32842,"content":32843,"nodeType":1680},{},[32844,32850,32866,32879,32885,32891,32894,32900,32906,32954,32960,32965,32968,32974,32980,32986,32992,32998,33012,33017,33023,33029,33043,33048,33054,33060,33066,33072,33078,33081,33087,33103,33108],{"data":32845,"content":32846,"nodeType":868},{},[32847],{"data":32848,"marks":32849,"value":24279,"nodeType":867},{},[],{"data":32851,"content":32852,"nodeType":876},{},[32853,32856,32863],{"data":32854,"marks":32855,"value":24286,"nodeType":867},{},[],{"data":32857,"content":32858,"nodeType":915},{"uri":967},[32859],{"data":32860,"marks":32861,"value":24294,"nodeType":867},{},[32862],{"type":913},{"data":32864,"marks":32865,"value":5704,"nodeType":867},{},[],{"data":32867,"content":32868,"nodeType":876},{},[32869,32872,32876],{"data":32870,"marks":32871,"value":24304,"nodeType":867},{},[],{"data":32873,"marks":32874,"value":24309,"nodeType":867},{},[32875],{"type":913},{"data":32877,"marks":32878,"value":24313,"nodeType":867},{},[],{"data":32880,"content":32881,"nodeType":876},{},[32882],{"data":32883,"marks":32884,"value":24320,"nodeType":867},{},[],{"data":32886,"content":32887,"nodeType":876},{},[32888],{"data":32889,"marks":32890,"value":24327,"nodeType":867},{},[],{"data":32892,"content":32893,"nodeType":942},{},[],{"data":32895,"content":32896,"nodeType":1058},{},[32897],{"data":32898,"marks":32899,"value":24337,"nodeType":867},{},[],{"data":32901,"content":32902,"nodeType":876},{},[32903],{"data":32904,"marks":32905,"value":24344,"nodeType":867},{},[],{"data":32907,"content":32908,"nodeType":1629},{},[32909,32918,32927,32936,32945],{"data":32910,"content":32911,"nodeType":1586},{},[32912],{"data":32913,"content":32914,"nodeType":876},{},[32915],{"data":32916,"marks":32917,"value":24357,"nodeType":867},{},[],{"data":32919,"content":32920,"nodeType":1586},{},[32921],{"data":32922,"content":32923,"nodeType":876},{},[32924],{"data":32925,"marks":32926,"value":24367,"nodeType":867},{},[],{"data":32928,"content":32929,"nodeType":1586},{},[32930],{"data":32931,"content":32932,"nodeType":876},{},[32933],{"data":32934,"marks":32935,"value":24377,"nodeType":867},{},[],{"data":32937,"content":32938,"nodeType":1586},{},[32939],{"data":32940,"content":32941,"nodeType":876},{},[32942],{"data":32943,"marks":32944,"value":24387,"nodeType":867},{},[],{"data":32946,"content":32947,"nodeType":1586},{},[32948],{"data":32949,"content":32950,"nodeType":876},{},[32951],{"data":32952,"marks":32953,"value":24397,"nodeType":867},{},[],{"data":32955,"content":32956,"nodeType":876},{},[32957],{"data":32958,"marks":32959,"value":24404,"nodeType":867},{},[],{"data":32961,"content":32964,"nodeType":985},{"target":32962},{"sys":32963},{"id":24409,"type":982,"linkType":983},[],{"data":32966,"content":32967,"nodeType":942},{},[],{"data":32969,"content":32970,"nodeType":1058},{},[32971],{"data":32972,"marks":32973,"value":24420,"nodeType":867},{},[],{"data":32975,"content":32976,"nodeType":876},{},[32977],{"data":32978,"marks":32979,"value":24427,"nodeType":867},{},[],{"data":32981,"content":32982,"nodeType":876},{},[32983],{"data":32984,"marks":32985,"value":24434,"nodeType":867},{},[],{"data":32987,"content":32988,"nodeType":876},{},[32989],{"data":32990,"marks":32991,"value":24441,"nodeType":867},{},[],{"data":32993,"content":32994,"nodeType":876},{},[32995],{"data":32996,"marks":32997,"value":24448,"nodeType":867},{},[],{"data":32999,"content":33000,"nodeType":1058},{},[33001,33004,33009],{"data":33002,"marks":33003,"value":24455,"nodeType":867},{},[],{"data":33005,"marks":33006,"value":24461,"nodeType":867},{},[33007,33008],{"type":913},{"type":865},{"data":33010,"marks":33011,"value":24465,"nodeType":867},{},[],{"data":33013,"content":33016,"nodeType":985},{"target":33014},{"sys":33015},{"id":24470,"type":982,"linkType":983},[],{"data":33018,"content":33019,"nodeType":876},{},[33020],{"data":33021,"marks":33022,"value":24478,"nodeType":867},{},[],{"data":33024,"content":33025,"nodeType":876},{},[33026],{"data":33027,"marks":33028,"value":24485,"nodeType":867},{},[],{"data":33030,"content":33031,"nodeType":1058},{},[33032,33035,33040],{"data":33033,"marks":33034,"value":24492,"nodeType":867},{},[],{"data":33036,"marks":33037,"value":24498,"nodeType":867},{},[33038,33039],{"type":913},{"type":865},{"data":33041,"marks":33042,"value":24502,"nodeType":867},{},[],{"data":33044,"content":33047,"nodeType":985},{"target":33045},{"sys":33046},{"id":24507,"type":982,"linkType":983},[],{"data":33049,"content":33050,"nodeType":876},{},[33051],{"data":33052,"marks":33053,"value":24515,"nodeType":867},{},[],{"data":33055,"content":33056,"nodeType":876},{},[33057],{"data":33058,"marks":33059,"value":24522,"nodeType":867},{},[],{"data":33061,"content":33062,"nodeType":876},{},[33063],{"data":33064,"marks":33065,"value":24529,"nodeType":867},{},[],{"data":33067,"content":33068,"nodeType":876},{},[33069],{"data":33070,"marks":33071,"value":24536,"nodeType":867},{},[],{"data":33073,"content":33074,"nodeType":876},{},[33075],{"data":33076,"marks":33077,"value":24543,"nodeType":867},{},[],{"data":33079,"content":33080,"nodeType":942},{},[],{"data":33082,"content":33083,"nodeType":868},{},[33084],{"data":33085,"marks":33086,"value":24553,"nodeType":867},{},[],{"data":33088,"content":33089,"nodeType":876},{},[33090,33093,33100],{"data":33091,"marks":33092,"value":24560,"nodeType":867},{},[],{"data":33094,"content":33095,"nodeType":915},{"uri":5286},[33096],{"data":33097,"marks":33098,"value":24568,"nodeType":867},{},[33099],{"type":913},{"data":33101,"marks":33102,"value":24572,"nodeType":867},{},[],{"data":33104,"content":33107,"nodeType":985},{"target":33105},{"sys":33106},{"id":24577,"type":982,"linkType":983},[],{"data":33109,"content":33110,"nodeType":876},{},[33111],{"data":33112,"marks":33113,"value":21,"nodeType":867},{},[],{"items":33115},[33116,33118],{"sys":33117,"name":4018},{"id":4017},{"sys":33119,"name":342},{"id":3240},{"items":33121},[33122],{"fullName":4089,"firstName":4090,"jobTitle":851,"profilePicture":33123},{"url":4094},"blog/how-browser-level-controls-change-the-fight-against-phishing",{"json":33126},{"data":33127,"content":33128,"nodeType":1680},{},[33129],{"data":33130,"content":33131,"nodeType":876},{},[33132],{"data":33133,"marks":33134,"value":33135,"nodeType":867},{},[],"Attackers have moved their phishing attacks out of the mailbox and are finding ever more ways to defeat conventional email, network, and endpoint-based security controls. Here's how browser-based security platforms can level the playing field and help security teams to stay ahead of the never-ending barrage of phishing attacks. ",{"id":29628,"publishedAt":33137},"2026-08-12T11:54:06.623Z",{"items":33139},[33140,33142],{"sys":33141,"name":4018},{"id":4017},{"sys":33143,"name":342},{"id":3240},{"items":33145},[33146,33148,33150,33152,33154,33156,33158,33160,33162,33164,33166,33168,33170,33172,33174],{"sys":33147,"name":519,"slug":520,"tier":31},{"id":516},{"sys":33149,"name":297,"slug":298,"tier":31},{"id":294},{"sys":33151,"name":279,"slug":280,"tier":31},{"id":276},{"sys":33153,"name":413,"slug":414,"tier":31},{"id":410},{"sys":33155,"name":342,"slug":343,"tier":31},{"id":339},{"sys":33157,"name":261,"slug":262,"tier":45},{"id":258},{"sys":33159,"name":324,"slug":325,"tier":45},{"id":321},{"sys":33161,"name":571,"slug":572,"tier":45},{"id":568},{"sys":33163,"name":395,"slug":396,"tier":45},{"id":392},{"sys":33165,"name":589,"slug":590,"tier":45},{"id":586},{"sys":33167,"name":457,"slug":458,"tier":45},{"id":454},{"sys":33169,"name":502,"slug":503,"tier":45},{"id":499},{"sys":33171,"name":351,"slug":352,"tier":45},{"id":348},{"sys":33173,"name":404,"slug":405,"tier":45},{"id":401},{"sys":33175,"name":377,"slug":378,"tier":45},{"id":374},"GwuurOJwwWImrgCMoJrHzz0X_W43W9FzqPECPeskE4M",{"id":33178,"title":32519,"authorsCollection":33179,"content":33184,"extension":228,"faqItemsCollection":33800,"faqTitle":59,"featured":6,"hashTags":59,"meta":33802,"metaTitle":33803,"ogImage":59,"postType":1767,"publishedDate":32521,"relatedBlogPostsCollection":33804,"slug":32522,"stem":35520,"subtitle":59,"summary":35521,"synopsis":32520,"sys":35532,"tagsCollection":35534,"topicsCollection":35540,"__hash__":35570},"blog/blog/three-reasons-why-browser-is-best-for-stopping-phishing-attacks.json",{"items":33180},[33181],{"fullName":4022,"firstName":4023,"jobTitle":4024,"socialLinks":33182,"profilePicture":33183},[21074],{"url":4026},{"json":33185,"links":33744},{"data":33186,"content":33187,"nodeType":1680},{},[33188,33194,33200,33206,33209,33216,33222,33238,33268,33273,33289,33294,33314,33317,33324,33330,33343,33356,33361,33367,33373,33378,33391,33394,33401,33407,33413,33419,33425,33428,33435,33441,33447,33463,33469,33476,33515,33521,33526,33532,33537,33543,33546,33553,33566,33572,33606,33616,33619,33626,33632,33638,33668,33674,33691,33696,33701,33704,33711,33717,33733,33738],{"data":33189,"content":33190,"nodeType":876},{},[33191],{"data":33192,"marks":33193,"value":31882,"nodeType":867},{},[],{"data":33195,"content":33196,"nodeType":876},{},[33197],{"data":33198,"marks":33199,"value":31889,"nodeType":867},{},[],{"data":33201,"content":33202,"nodeType":876},{},[33203],{"data":33204,"marks":33205,"value":31896,"nodeType":867},{},[],{"data":33207,"content":33208,"nodeType":942},{},[],{"data":33210,"content":33211,"nodeType":868},{},[33212],{"data":33213,"marks":33214,"value":31907,"nodeType":867},{},[33215],{"type":865},{"data":33217,"content":33218,"nodeType":876},{},[33219],{"data":33220,"marks":33221,"value":31914,"nodeType":867},{},[],{"data":33223,"content":33224,"nodeType":876},{},[33225,33228,33235],{"data":33226,"marks":33227,"value":31921,"nodeType":867},{},[],{"data":33229,"content":33230,"nodeType":915},{"uri":31924},[33231],{"data":33232,"marks":33233,"value":31930,"nodeType":867},{},[33234],{"type":913},{"data":33236,"marks":33237,"value":31934,"nodeType":867},{},[],{"data":33239,"content":33240,"nodeType":1629},{},[33241,33250,33259],{"data":33242,"content":33243,"nodeType":1586},{},[33244],{"data":33245,"content":33246,"nodeType":876},{},[33247],{"data":33248,"marks":33249,"value":31947,"nodeType":867},{},[],{"data":33251,"content":33252,"nodeType":1586},{},[33253],{"data":33254,"content":33255,"nodeType":876},{},[33256],{"data":33257,"marks":33258,"value":31957,"nodeType":867},{},[],{"data":33260,"content":33261,"nodeType":1586},{},[33262],{"data":33263,"content":33264,"nodeType":876},{},[33265],{"data":33266,"marks":33267,"value":31967,"nodeType":867},{},[],{"data":33269,"content":33272,"nodeType":985},{"target":33270},{"sys":33271},{"id":31972,"type":982,"linkType":983},[],{"data":33274,"content":33275,"nodeType":876},{},[33276,33279,33286],{"data":33277,"marks":33278,"value":31980,"nodeType":867},{},[],{"data":33280,"content":33281,"nodeType":915},{"uri":31983},[33282],{"data":33283,"marks":33284,"value":31989,"nodeType":867},{},[33285],{"type":913},{"data":33287,"marks":33288,"value":31993,"nodeType":867},{},[],{"data":33290,"content":33293,"nodeType":985},{"target":33291},{"sys":33292},{"id":31998,"type":982,"linkType":983},[],{"data":33295,"content":33296,"nodeType":876},{},[33297,33300,33304,33307,33311],{"data":33298,"marks":33299,"value":32006,"nodeType":867},{},[],{"data":33301,"marks":33302,"value":32011,"nodeType":867},{},[33303],{"type":865},{"data":33305,"marks":33306,"value":32015,"nodeType":867},{},[],{"data":33308,"marks":33309,"value":32020,"nodeType":867},{},[33310],{"type":865},{"data":33312,"marks":33313,"value":32024,"nodeType":867},{},[],{"data":33315,"content":33316,"nodeType":942},{},[],{"data":33318,"content":33319,"nodeType":868},{},[33320],{"data":33321,"marks":33322,"value":32035,"nodeType":867},{},[33323],{"type":865},{"data":33325,"content":33326,"nodeType":876},{},[33327],{"data":33328,"marks":33329,"value":32042,"nodeType":867},{},[],{"data":33331,"content":33332,"nodeType":876},{},[33333,33336,33340],{"data":33334,"marks":33335,"value":32049,"nodeType":867},{},[],{"data":33337,"marks":33338,"value":1304,"nodeType":867},{},[33339],{"type":1303},{"data":33341,"marks":33342,"value":32057,"nodeType":867},{},[],{"data":33344,"content":33345,"nodeType":876},{},[33346,33349,33353],{"data":33347,"marks":33348,"value":32064,"nodeType":867},{},[],{"data":33350,"marks":33351,"value":32069,"nodeType":867},{},[33352],{"type":865},{"data":33354,"marks":33355,"value":5704,"nodeType":867},{},[],{"data":33357,"content":33360,"nodeType":985},{"target":33358},{"sys":33359},{"id":32077,"type":982,"linkType":983},[],{"data":33362,"content":33363,"nodeType":876},{},[33364],{"data":33365,"marks":33366,"value":32085,"nodeType":867},{},[],{"data":33368,"content":33369,"nodeType":876},{},[33370],{"data":33371,"marks":33372,"value":32092,"nodeType":867},{},[],{"data":33374,"content":33377,"nodeType":985},{"target":33375},{"sys":33376},{"id":32097,"type":982,"linkType":983},[],{"data":33379,"content":33380,"nodeType":876},{},[33381,33384,33388],{"data":33382,"marks":33383,"value":32105,"nodeType":867},{},[],{"data":33385,"marks":33386,"value":32110,"nodeType":867},{},[33387],{"type":865},{"data":33389,"marks":33390,"value":32114,"nodeType":867},{},[],{"data":33392,"content":33393,"nodeType":942},{},[],{"data":33395,"content":33396,"nodeType":868},{},[33397],{"data":33398,"marks":33399,"value":32125,"nodeType":867},{},[33400],{"type":865},{"data":33402,"content":33403,"nodeType":876},{},[33404],{"data":33405,"marks":33406,"value":32132,"nodeType":867},{},[],{"data":33408,"content":33409,"nodeType":876},{},[33410],{"data":33411,"marks":33412,"value":32139,"nodeType":867},{},[],{"data":33414,"content":33415,"nodeType":876},{},[33416],{"data":33417,"marks":33418,"value":32146,"nodeType":867},{},[],{"data":33420,"content":33421,"nodeType":876},{},[33422],{"data":33423,"marks":33424,"value":32153,"nodeType":867},{},[],{"data":33426,"content":33427,"nodeType":942},{},[],{"data":33429,"content":33430,"nodeType":868},{},[33431],{"data":33432,"marks":33433,"value":32164,"nodeType":867},{},[33434],{"type":865},{"data":33436,"content":33437,"nodeType":876},{},[33438],{"data":33439,"marks":33440,"value":32171,"nodeType":867},{},[],{"data":33442,"content":33443,"nodeType":876},{},[33444],{"data":33445,"marks":33446,"value":32178,"nodeType":867},{},[],{"data":33448,"content":33449,"nodeType":876},{},[33450,33453,33460],{"data":33451,"marks":33452,"value":32185,"nodeType":867},{},[],{"data":33454,"content":33455,"nodeType":915},{"uri":32188},[33456],{"data":33457,"marks":33458,"value":32194,"nodeType":867},{},[33459],{"type":913},{"data":33461,"marks":33462,"value":32198,"nodeType":867},{},[],{"data":33464,"content":33465,"nodeType":876},{},[33466],{"data":33467,"marks":33468,"value":32205,"nodeType":867},{},[],{"data":33470,"content":33471,"nodeType":876},{},[33472],{"data":33473,"marks":33474,"value":32213,"nodeType":867},{},[33475],{"type":865},{"data":33477,"content":33478,"nodeType":1629},{},[33479,33488,33497,33506],{"data":33480,"content":33481,"nodeType":1586},{},[33482],{"data":33483,"content":33484,"nodeType":876},{},[33485],{"data":33486,"marks":33487,"value":27180,"nodeType":867},{},[],{"data":33489,"content":33490,"nodeType":1586},{},[33491],{"data":33492,"content":33493,"nodeType":876},{},[33494],{"data":33495,"marks":33496,"value":32235,"nodeType":867},{},[],{"data":33498,"content":33499,"nodeType":1586},{},[33500],{"data":33501,"content":33502,"nodeType":876},{},[33503],{"data":33504,"marks":33505,"value":32245,"nodeType":867},{},[],{"data":33507,"content":33508,"nodeType":1586},{},[33509],{"data":33510,"content":33511,"nodeType":876},{},[33512],{"data":33513,"marks":33514,"value":32255,"nodeType":867},{},[],{"data":33516,"content":33517,"nodeType":876},{},[33518],{"data":33519,"marks":33520,"value":32262,"nodeType":867},{},[],{"data":33522,"content":33525,"nodeType":985},{"target":33523},{"sys":33524},{"id":32267,"type":982,"linkType":983},[],{"data":33527,"content":33528,"nodeType":876},{},[33529],{"data":33530,"marks":33531,"value":32275,"nodeType":867},{},[],{"data":33533,"content":33536,"nodeType":985},{"target":33534},{"sys":33535},{"id":32280,"type":982,"linkType":983},[],{"data":33538,"content":33539,"nodeType":876},{},[33540],{"data":33541,"marks":33542,"value":32288,"nodeType":867},{},[],{"data":33544,"content":33545,"nodeType":942},{},[],{"data":33547,"content":33548,"nodeType":868},{},[33549],{"data":33550,"marks":33551,"value":32299,"nodeType":867},{},[33552],{"type":865},{"data":33554,"content":33555,"nodeType":876},{},[33556,33559,33563],{"data":33557,"marks":33558,"value":32306,"nodeType":867},{},[],{"data":33560,"marks":33561,"value":32311,"nodeType":867},{},[33562],{"type":865},{"data":33564,"marks":33565,"value":5704,"nodeType":867},{},[],{"data":33567,"content":33568,"nodeType":876},{},[33569],{"data":33570,"marks":33571,"value":32321,"nodeType":867},{},[],{"data":33573,"content":33574,"nodeType":876},{},[33575,33578,33582,33585,33589,33592,33596,33599,33603],{"data":33576,"marks":33577,"value":32328,"nodeType":867},{},[],{"data":33579,"marks":33580,"value":32333,"nodeType":867},{},[33581],{"type":865},{"data":33583,"marks":33584,"value":32337,"nodeType":867},{},[],{"data":33586,"marks":33587,"value":32342,"nodeType":867},{},[33588],{"type":865},{"data":33590,"marks":33591,"value":32346,"nodeType":867},{},[],{"data":33593,"marks":33594,"value":32342,"nodeType":867},{},[33595],{"type":865},{"data":33597,"marks":33598,"value":32354,"nodeType":867},{},[],{"data":33600,"marks":33601,"value":32359,"nodeType":867},{},[33602],{"type":865},{"data":33604,"marks":33605,"value":32363,"nodeType":867},{},[],{"data":33607,"content":33608,"nodeType":876},{},[33609,33612],{"data":33610,"marks":33611,"value":32370,"nodeType":867},{},[],{"data":33613,"marks":33614,"value":32375,"nodeType":867},{},[33615],{"type":865},{"data":33617,"content":33618,"nodeType":942},{},[],{"data":33620,"content":33621,"nodeType":868},{},[33622],{"data":33623,"marks":33624,"value":32386,"nodeType":867},{},[33625],{"type":865},{"data":33627,"content":33628,"nodeType":876},{},[33629],{"data":33630,"marks":33631,"value":32393,"nodeType":867},{},[],{"data":33633,"content":33634,"nodeType":876},{},[33635],{"data":33636,"marks":33637,"value":32400,"nodeType":867},{},[],{"data":33639,"content":33640,"nodeType":1629},{},[33641,33650,33659],{"data":33642,"content":33643,"nodeType":1586},{},[33644],{"data":33645,"content":33646,"nodeType":876},{},[33647],{"data":33648,"marks":33649,"value":32413,"nodeType":867},{},[],{"data":33651,"content":33652,"nodeType":1586},{},[33653],{"data":33654,"content":33655,"nodeType":876},{},[33656],{"data":33657,"marks":33658,"value":32423,"nodeType":867},{},[],{"data":33660,"content":33661,"nodeType":1586},{},[33662],{"data":33663,"content":33664,"nodeType":876},{},[33665],{"data":33666,"marks":33667,"value":32433,"nodeType":867},{},[],{"data":33669,"content":33670,"nodeType":876},{},[33671],{"data":33672,"marks":33673,"value":32440,"nodeType":867},{},[],{"data":33675,"content":33676,"nodeType":876},{},[33677,33681,33688],{"data":33678,"marks":33679,"value":32448,"nodeType":867},{},[33680],{"type":865},{"data":33682,"content":33683,"nodeType":915},{"uri":32451},[33684],{"data":33685,"marks":33686,"value":32457,"nodeType":867},{},[33687],{"type":913},{"data":33689,"marks":33690,"value":21,"nodeType":867},{},[],{"data":33692,"content":33695,"nodeType":985},{"target":33693},{"sys":33694},{"id":32465,"type":982,"linkType":983},[],{"data":33697,"content":33700,"nodeType":985},{"target":33698},{"sys":33699},{"id":32471,"type":982,"linkType":983},[],{"data":33702,"content":33703,"nodeType":942},{},[],{"data":33705,"content":33706,"nodeType":868},{},[33707],{"data":33708,"marks":33709,"value":18329,"nodeType":867},{},[33710],{"type":865},{"data":33712,"content":33713,"nodeType":876},{},[33714],{"data":33715,"marks":33716,"value":32489,"nodeType":867},{},[],{"data":33718,"content":33719,"nodeType":876},{},[33720,33723,33730],{"data":33721,"marks":33722,"value":27639,"nodeType":867},{},[],{"data":33724,"content":33725,"nodeType":915},{"uri":32498},[33726],{"data":33727,"marks":33728,"value":14723,"nodeType":867},{},[33729],{"type":913},{"data":33731,"marks":33732,"value":1679,"nodeType":867},{},[],{"data":33734,"content":33737,"nodeType":985},{"target":33735},{"sys":33736},{"id":32511,"type":982,"linkType":983},[],{"data":33739,"content":33740,"nodeType":876},{},[33741],{"data":33742,"marks":33743,"value":21,"nodeType":867},{},[],{"entries":33745},{"hyperlink":33746,"inline":33747,"block":33748},[],[],[33749,33756,33762,33768,33772,33779,33784,33792,33796],{"sys":33750,"__typename":1688,"title":33751,"caption":33751,"layoutMode":59,"file":33752},{"id":31972},"Implementing bot checks like Clouflare Turnstile is an effective way to bypass sandbox analysis tools",{"url":33753,"width":33754,"height":33755},"https://images.ctfassets.net/y1cdw1ablpvd/DbEYzQt7m3jY56ALCYWEy/59846e7bd4a3ed204722a9d561e97231/image2.png",938,361,{"sys":33757,"__typename":1688,"title":33758,"caption":33758,"layoutMode":59,"file":33759},{"id":31998},"Attackers are bypassing email by targeting their victims across IM, social media, using malicious ads, and by sending messages using trusted apps",{"url":33760,"width":1693,"height":33761},"https://images.ctfassets.net/y1cdw1ablpvd/70wT3oO5yuDvKcdVDTwsca/0bebd357b1f6c61ff690fcdc3af297fe/image6.png",874,{"sys":33763,"__typename":1688,"title":33764,"caption":59,"layoutMode":59,"file":33765},{"id":32077},"EDR enabled real-time detection and response at the OS level rather than relying on traffic to and from the endpoint. ",{"url":33766,"width":1693,"height":33767},"https://images.ctfassets.net/y1cdw1ablpvd/3gSjR1ecPh6HIhaG27mMLl/018623f5cadfa9866a2b452899c6357e/image5.png",1187,{"sys":33769,"__typename":1688,"title":33770,"caption":33770,"layoutMode":59,"file":33771},{"id":32097},"Current phishing detection isn’t in the right place to observe and stop malicious activity in real time.",{"url":29579,"width":29580,"height":29581},{"sys":33773,"__typename":1688,"title":33774,"caption":33775,"layoutMode":59,"file":33776},{"id":32267},"Phishing pyramid of pain","Getting real-time visibility of page/user behavior and malicious toolkits running on the page is key to moving to TTP-based detections, rather than chasing quickly-changing IoCs",{"url":33777,"width":1693,"height":33778},"https://images.ctfassets.net/y1cdw1ablpvd/4uJD4Qgy3EH0x2ilhV7UsO/262f91bd23f54d557a2cc1da1a8ac6d8/image1.png",1352,{"sys":33780,"__typename":1688,"title":33781,"caption":33782,"layoutMode":59,"file":33783},{"id":32280},"Browser activity detection","Being in the browser gives you unrivalled visibility of phishing page activity and user behavior",{"url":29586,"width":29587,"height":29588},{"sys":33785,"__typename":1688,"title":33786,"caption":33787,"layoutMode":59,"file":33788},{"id":32465},"Phishing toolkit detection","Accessing pages running malicious phishing toolkits is automatically blocked. ",{"url":33789,"width":33790,"height":33791},"https://images.ctfassets.net/y1cdw1ablpvd/3ylgW0MDCCesBjQsoqjD4P/a8bc4df9a430aca6c725f913d2bc6444/image11.png",1440,767,{"sys":33793,"__typename":1697,"type":1698,"ctaText":33794,"buttonLabel":33795,"buttonColour":1701,"buttonUrl":25645},{"id":32471},"See how Push detects and blocks phishing attacks in the browser.","Read the Blog",{"sys":33797,"__typename":1697,"type":1698,"ctaText":33798,"buttonLabel":21672,"buttonColour":1701,"buttonUrl":33799},{"id":32511},"Frustrated that phishing attacks are still so successful in 2025? Check out on-demand latest webinar where we analyze exactly why and where controls are failing.","https://pushsecurity.com/resources/phishing-2025",{"items":33801},[],{},"Three reasons why browser is best for stopping phishing",{"items":33805},[33806,34290,35069],{"__typename":1772,"sys":33807,"content":33809,"title":34276,"synopsis":34277,"hashTags":59,"publishedDate":34278,"slug":34279,"tagsCollection":34280,"authorsCollection":34286},{"id":33808},"51p0V5Vr4I9rapUytBWX0R",{"json":33810},{"data":33811,"content":33812,"nodeType":1680},{},[33813,33821,33828,33835,33840,33847,33853,33860,33867,33870,33878,33885,33892,33915,33922,33925,33933,33948,33954,33961,33967,33974,33981,33984,33992,34011,34017,34024,34030,34033,34041,34061,34067,34074,34080,34100,34106,34112,34115,34123,34130,34137,34143,34146,34154,34161,34168,34171,34179,34186,34193,34199,34206,34239,34245,34252,34259],{"data":33814,"content":33815,"nodeType":868},{},[33816],{"data":33817,"marks":33818,"value":33820,"nodeType":867},{},[33819],{"type":865},"What happened",{"data":33822,"content":33823,"nodeType":876},{},[33824],{"data":33825,"marks":33826,"value":33827,"nodeType":867},{},[],"On April 11th our browser-based phishing detection controls were triggered for a user with the Push extension installed. ",{"data":33829,"content":33830,"nodeType":876},{},[33831],{"data":33832,"marks":33833,"value":33834,"nodeType":867},{},[],"The user had visited the url dashboard[.]onfido[.].us[.]com after entering a Google search for ‘onfido’, a site they had previously accessed for work and had an account on. A convincing looking Google ad duped the user into clicking the fake link.",{"data":33836,"content":33839,"nodeType":985},{"target":33837},{"sys":33838},{"id":22161,"type":982,"linkType":983},[],{"data":33841,"content":33842,"nodeType":876},{},[33843],{"data":33844,"marks":33845,"value":33846,"nodeType":867},{},[],"Although the page was not the official login page for Onfido, it appeared legitimate enough at first glance to trick the user. ",{"data":33848,"content":33852,"nodeType":985},{"target":33849},{"sys":33850},{"id":33851,"type":982,"linkType":983},"4Tp1RJ3eSx7r79wwm9d9DZ",[],{"data":33854,"content":33855,"nodeType":876},{},[33856],{"data":33857,"marks":33858,"value":33859,"nodeType":867},{},[],"After clicking the link, the user was blocked from interacting with the malicious page running Evilginx by Push. We then took action to identify other Onfido users within the Push customer base and notify them accordingly of the campaign. ",{"data":33861,"content":33862,"nodeType":876},{},[33863],{"data":33864,"marks":33865,"value":33866,"nodeType":867},{},[],"There are a few interesting elements worth exploring. Let’s dive in. ",{"data":33868,"content":33869,"nodeType":942},{},[],{"data":33871,"content":33872,"nodeType":868},{},[33873],{"data":33874,"marks":33875,"value":33877,"nodeType":867},{},[33876],{"type":865},"Why Onfido?",{"data":33879,"content":33880,"nodeType":876},{},[33881],{"data":33882,"marks":33883,"value":33884,"nodeType":867},{},[],"Onfido is an interesting choice. It’s not your typical phishing target, which points to an interesting trend we’ve observed where attackers are diversifying their phishing targets. ",{"data":33886,"content":33887,"nodeType":876},{},[33888],{"data":33889,"marks":33890,"value":33891,"nodeType":867},{},[],"There are two main reasons for this:",{"data":33893,"content":33894,"nodeType":1629},{},[33895,33905],{"data":33896,"content":33897,"nodeType":1586},{},[33898],{"data":33899,"content":33900,"nodeType":876},{},[33901],{"data":33902,"marks":33903,"value":33904,"nodeType":867},{},[],"People are becoming increasingly suspicious of phishing attacks targeting core apps such as Microsoft, Google, Okta, etc. and are much more likely to spot real vs fake pages. ",{"data":33906,"content":33907,"nodeType":1586},{},[33908],{"data":33909,"content":33910,"nodeType":876},{},[33911],{"data":33912,"marks":33913,"value":33914,"nodeType":867},{},[],"Because highly targeted apps like IdPs and enterprise cloud platforms are becoming increasingly hardened from an identity perspective, attackers have a lower chance of success relative to accounts on the long tail of internet apps used by an organization — many of which simply cannot be securely configured in the same way (e.g. no passkey/WebAuthn support, limited admin controls to discover and remediate identity security gaps, etc.). ",{"data":33916,"content":33917,"nodeType":876},{},[33918],{"data":33919,"marks":33920,"value":33921,"nodeType":867},{},[],"Onfido is also an interesting example in that it definitely contains valuable data that attackers can take advantage of. As a digital identity solution, it presents a significant risk from both a personal and company perspective if compromised, with plenty of PII that can be leveraged to extort a victim — and clear bad press (and possible regulator scrutiny) if the data is leaked!",{"data":33923,"content":33924,"nodeType":942},{},[],{"data":33926,"content":33927,"nodeType":868},{},[33928],{"data":33929,"marks":33930,"value":33932,"nodeType":867},{},[33931],{"type":865},"Why Google ads?",{"data":33934,"content":33935,"nodeType":876},{},[33936,33940,33944],{"data":33937,"marks":33938,"value":33939,"nodeType":867},{},[],"The attack is a form of ",{"data":33941,"marks":33942,"value":441,"nodeType":867},{},[33943],{"type":865},{"data":33945,"marks":33946,"value":33947,"nodeType":867},{},[]," where attackers distribute malicious links via ads — in this case, via Google. This is just one example of the many non-email phishing channels that attackers have at their disposal today. ",{"data":33949,"content":33953,"nodeType":985},{"target":33950},{"sys":33951},{"id":33952,"type":982,"linkType":983},"7kfeOKGXEWVL5RW5jFnQBo",[],{"data":33955,"content":33956,"nodeType":876},{},[33957],{"data":33958,"marks":33959,"value":33960,"nodeType":867},{},[],"The use of malvertising has a couple of notable advantages here. Namely, because Google ads do not use the same reputation-based checks as an email security provider does, the attacker can use freshly created domains to conduct the attack. Usually, attackers would aim to take over existing domains with a reputation already built up, or spend 6-12 months bedding in their domains so that they pass mail filters. ",{"data":33962,"content":33966,"nodeType":985},{"target":33963},{"sys":33964},{"id":33965,"type":982,"linkType":983},"499fj1Xark8Bj7iQjv9Vsm",[],{"data":33968,"content":33969,"nodeType":876},{},[33970],{"data":33971,"marks":33972,"value":33973,"nodeType":867},{},[],"But in this case, the domain was registered only shortly before being used. We detected it only a few hours after it had been registered — and it’s already been taken down since (no doubt to be replaced with the next one). This means it’s easy for attackers to spin up these malvertising campaigns at will, without any real forward planning. ",{"data":33975,"content":33976,"nodeType":876},{},[33977],{"data":33978,"marks":33979,"value":33980,"nodeType":867},{},[],"In fact, malvertising doesn’t require much effort on the attacker’s part whatsoever. As a watering hole, you put the link up and wait for the clicks to roll in. Unfortunately, many people Google search for sites that they frequently use rather than accessing via bookmark, opening them up to these kinds of malvertising attacks. ",{"data":33982,"content":33983,"nodeType":942},{},[],{"data":33985,"content":33986,"nodeType":1058},{},[33987],{"data":33988,"marks":33989,"value":33991,"nodeType":867},{},[33990],{"type":865},"No frills ",{"data":33993,"content":33994,"nodeType":876},{},[33995,33999,34007],{"data":33996,"marks":33997,"value":33998,"nodeType":867},{},[],"Unlike many of the other campaigns using MFA-bypass phishing kits we’ve seen in the wild, the attacker put very little effort into obfuscating the malicious page. We’ve seen some using things like Cloudflare Turnstile, CAPTCHA, or even ",{"data":34000,"content":34001,"nodeType":915},{"uri":31118},[34002],{"data":34003,"marks":34004,"value":34006,"nodeType":867},{},[34005],{"type":913},"Consent Phishing for OIDC scopes ",{"data":34008,"marks":34009,"value":34010,"nodeType":867},{},[],"to break sandbox detections and prevent security tools from reaching the malicious content to analyze it. ",{"data":34012,"content":34016,"nodeType":985},{"target":34013},{"sys":34014},{"id":34015,"type":982,"linkType":983},"7csybR6fJlCWsRy91CbNYL",[],{"data":34018,"content":34019,"nodeType":876},{},[34020],{"data":34021,"marks":34022,"value":34023,"nodeType":867},{},[],"That said, there was evidence to suggest that the domain required a specific URL path — namely, the page must be accessed via Google ads to load. When the page was accessed without the correct parameters set, we were forwarded to a nonexistent page within the legitimate onfido.com domain, resulting in a 404 error.",{"data":34025,"content":34029,"nodeType":985},{"target":34026},{"sys":34027},{"id":34028,"type":982,"linkType":983},"658fTppp0l1YkoMERiQ1Oj",[],{"data":34031,"content":34032,"nodeType":942},{},[],{"data":34034,"content":34035,"nodeType":868},{},[34036],{"data":34037,"marks":34038,"value":34040,"nodeType":867},{},[34039],{"type":865},"What’s interesting about the domain?",{"data":34042,"content":34043,"nodeType":876},{},[34044,34048,34057],{"data":34045,"marks":34046,"value":34047,"nodeType":867},{},[],"One of the things that really stood out to us was the hosting domain — ",{"data":34049,"content":34051,"nodeType":915},{"uri":34050},"http://us.com",[34052],{"data":34053,"marks":34054,"value":34056,"nodeType":867},{},[34055],{"type":913},"us.com",{"data":34058,"marks":34059,"value":34060,"nodeType":867},{},[],". Unlike the official government TLD .us, us.com is designed to look and feel legit but does not require any US affiliation or evidence of a US presence. This isn’t a TLD, it’s just a domain selling subdomains within their domain. This means there’s no WHOIS information available on the domains. ",{"data":34062,"content":34066,"nodeType":985},{"target":34063},{"sys":34064},{"id":34065,"type":982,"linkType":983},"7HtOWLePxPclyfODqC0oR",[],{"data":34068,"content":34069,"nodeType":876},{},[34070],{"data":34071,"marks":34072,"value":34073,"nodeType":867},{},[],"This is incredibly deceptive to the user and will fool many people glancing at the link. It doesn’t look as obviously suspicious as your .xyz or .biz and has the feel of a legitimate domain. It’s also incredibly cheap to pick up .us.com domains right now. ",{"data":34075,"content":34079,"nodeType":985},{"target":34076},{"sys":34077},{"id":34078,"type":982,"linkType":983},"5CHWwlH2ZFZiVOQWMpkquy",[],{"data":34081,"content":34082,"nodeType":876},{},[34083,34087,34096],{"data":34084,"marks":34085,"value":34086,"nodeType":867},{},[],"You can find additional information on ",{"data":34088,"content":34090,"nodeType":915},{"uri":34089},"https://urlscan.io/result/0196338c-75ea-720c-a0e4-c2898acc4779/",[34091],{"data":34092,"marks":34093,"value":34095,"nodeType":867},{},[34094],{"type":913},"urlscan",{"data":34097,"marks":34098,"value":34099,"nodeType":867},{},[]," here.",{"data":34101,"content":34105,"nodeType":985},{"target":34102},{"sys":34103},{"id":34104,"type":982,"linkType":983},"6hdBHT8SrC6z7O0gIc7xnh",[],{"data":34107,"content":34111,"nodeType":985},{"target":34108},{"sys":34109},{"id":34110,"type":982,"linkType":983},"3KxFiCeGlk7fVC8k1oo7cX",[],{"data":34113,"content":34114,"nodeType":942},{},[],{"data":34116,"content":34117,"nodeType":868},{},[34118],{"data":34119,"marks":34120,"value":34122,"nodeType":867},{},[34121],{"type":865},"Isn’t Evilginx a red team tool?",{"data":34124,"content":34125,"nodeType":876},{},[34126],{"data":34127,"marks":34128,"value":34129,"nodeType":867},{},[],"Evilginx is nominally a red team tool, but we frequently spot it being used in phishing campaigns against our customers. Evilginx is a great choice for attackers looking to target non-standard web apps because it is capable of emulating a range of domains — it’s designed to be flexible and work for any page without generating a load of custom JavaScript that might stand out to security tools/analysts. ",{"data":34131,"content":34132,"nodeType":876},{},[34133],{"data":34134,"marks":34135,"value":34136,"nodeType":867},{},[],"If you want to see an example of Evilginx being used to phish a user, check out the example below. ",{"data":34138,"content":34142,"nodeType":985},{"target":34139},{"sys":34140},{"id":34141,"type":982,"linkType":983},"7IuP0mcRZJkL8YGNoZo5Dj",[],{"data":34144,"content":34145,"nodeType":942},{},[],{"data":34147,"content":34148,"nodeType":868},{},[34149],{"data":34150,"marks":34151,"value":34153,"nodeType":867},{},[34152],{"type":865},"What can you do about it?",{"data":34155,"content":34156,"nodeType":876},{},[34157],{"data":34158,"marks":34159,"value":34160,"nodeType":867},{},[],"There’s not a huge amount of impartial advice to give here unfortunately. With malicious Google ads not going away anytime soon, response action is limited. If you are an Onfido user, be sure to block the URL and any related patterns (we noticed that after appearing to have been taken down initially, the site has reappeared at dashboard[.]onfido[.]us[.]com/users/sign_in and no longer appears to require the same URL path). However, it goes without saying that this is a temporary measure and the attacker will no doubt rotate the domain in the near future. ",{"data":34162,"content":34163,"nodeType":876},{},[34164],{"data":34165,"marks":34166,"value":34167,"nodeType":867},{},[],"One good option is to encourage your users to bookmark their links rather than Google searching for the page. If you’re using an IdP with an application dashboard like Okta, Microsoft, or Google, this provides a convenient way to find all your apps in one place. ",{"data":34169,"content":34170,"nodeType":942},{},[],{"data":34172,"content":34173,"nodeType":868},{},[34174],{"data":34175,"marks":34176,"value":34178,"nodeType":867},{},[34177],{"type":865},"Bonus: How Push stopped the attack",{"data":34180,"content":34181,"nodeType":876},{},[34182],{"data":34183,"marks":34184,"value":34185,"nodeType":867},{},[],"Interested in how we stopped the attack?",{"data":34187,"content":34188,"nodeType":876},{},[34189],{"data":34190,"marks":34191,"value":34192,"nodeType":867},{},[],"When the user visited the page, Push detected Evilginx running on the page and blocked the user. Check it out.",{"data":34194,"content":34198,"nodeType":985},{"target":34195},{"sys":34196},{"id":34197,"type":982,"linkType":983},"5QavzZPS4siFvHCBhpujEe",[],{"data":34200,"content":34201,"nodeType":876},{},[34202],{"data":34203,"marks":34204,"value":34205,"nodeType":867},{},[],"Using our browser-based security platform, you can also see all users with an account on Onfido across your workforce. Using Push, you can:",{"data":34207,"content":34208,"nodeType":1629},{},[34209,34219,34229],{"data":34210,"content":34211,"nodeType":1586},{},[34212],{"data":34213,"content":34214,"nodeType":876},{},[34215],{"data":34216,"marks":34217,"value":34218,"nodeType":867},{},[],"Quickly identify which users have a password-based login set for their account (and therefore could be phished). ",{"data":34220,"content":34221,"nodeType":1586},{},[34222],{"data":34223,"content":34224,"nodeType":876},{},[34225],{"data":34226,"marks":34227,"value":34228,"nodeType":867},{},[],"Identify users to enable them to be contacted about the attacks targeting Onfido.",{"data":34230,"content":34231,"nodeType":1586},{},[34232],{"data":34233,"content":34234,"nodeType":876},{},[34235],{"data":34236,"marks":34237,"value":34238,"nodeType":867},{},[],"Set an app banner for Onfido warning users of the attacks and guiding them to access and login to the app via your SSO solution. ",{"data":34240,"content":34244,"nodeType":985},{"target":34241},{"sys":34242},{"id":34243,"type":982,"linkType":983},"23B4EHUs1vt0se5r1cUI4t",[],{"data":34246,"content":34247,"nodeType":1058},{},[34248],{"data":34249,"marks":34250,"value":24553,"nodeType":867},{},[34251],{"type":865},{"data":34253,"content":34254,"nodeType":876},{},[34255],{"data":34256,"marks":34257,"value":34258,"nodeType":867},{},[],"It doesn’t stop there — Push provides comprehensive identity attack detection and response capabilities against techniques like credential stuffing, password spraying and session hijacking using stolen session tokens. You can also use Push to find and fix identity vulnerabilities across every app that your employees use like: ghost logins; SSO coverage gaps; MFA gaps; weak, breached and reused passwords; risky OAuth integrations; and more. ",{"data":34260,"content":34261,"nodeType":876},{},[34262,34266,34272],{"data":34263,"marks":34264,"value":34265,"nodeType":867},{},[],"If you want to learn more about how Push helps you to detect and defeat advanced identity attack techniques in the browser, ",{"data":34267,"content":34268,"nodeType":915},{"uri":2689},[34269],{"data":34270,"marks":34271,"value":24568,"nodeType":867},{},[],{"data":34273,"marks":34274,"value":34275,"nodeType":867},{},[]," for a live demo.","Investigating a recent malvertising campaign targeting Onfido customers","We recently investigated a malvertising campaign using Evilginx to target Onfido customers via Google ads.","2025-04-15T00:00:00.000Z","investigating-a-recent-malvertising-campaign-targeting-onfido-customers",{"items":34281},[34282,34284],{"sys":34283,"name":4018},{"id":4017},{"sys":34285,"name":342},{"id":3240},{"items":34287},[34288],{"fullName":14739,"firstName":14740,"jobTitle":14741,"profilePicture":34289},{"url":14743},{"__typename":1772,"sys":34291,"content":34293,"title":35055,"synopsis":35056,"hashTags":59,"publishedDate":35057,"slug":35058,"tagsCollection":35059,"authorsCollection":35065},{"id":34292},"3RhqaMQEBAQBdfHDQeoELF",{"json":34294},{"data":34295,"content":34296,"nodeType":1680},{},[34297,34304,34337,34344,34363,34370,34373,34380,34387,34393,34400,34406,34412,34419,34436,34442,34449,34452,34460,34479,34502,34509,34517,34524,34531,34537,34545,34565,34584,34590,34597,34603,34611,34643,34649,34656,34659,34667,34674,34694,34701,34707,34715,34722,34729,34736,34743,34811,34818,34826,34845,34851,34858,34865,34871,34878,34884,34892,34899,34905,34911,34918,34921,34928,34958,34965,34984,34991,35002,35009,35012,35019,35038],{"data":34298,"content":34299,"nodeType":876},{},[34300],{"data":34301,"marks":34302,"value":34303,"nodeType":867},{},[],"Phishing attacks using Attacker-in-the-Middle (AitM) kits are increasingly the default for both credential harvesting campaigns and targeted phishing attacks. It’s easy to see why, too:",{"data":34305,"content":34306,"nodeType":1629},{},[34307,34317,34327],{"data":34308,"content":34309,"nodeType":1586},{},[34310],{"data":34311,"content":34312,"nodeType":876},{},[34313],{"data":34314,"marks":34315,"value":34316,"nodeType":867},{},[],"They’re very difficult to spot as a user and often function like the real page should, logging the victim into the genuine site once the phish is complete",{"data":34318,"content":34319,"nodeType":1586},{},[34320],{"data":34321,"content":34322,"nodeType":876},{},[34323],{"data":34324,"marks":34325,"value":34326,"nodeType":867},{},[],"They’re incredibly scalable, and attackers have an increasing number of options to choose from when it comes to off-the-shelf tools and commercial Phishing-as-a-Service offerings ",{"data":34328,"content":34329,"nodeType":1586},{},[34330],{"data":34331,"content":34332,"nodeType":876},{},[34333],{"data":34334,"marks":34335,"value":34336,"nodeType":867},{},[],"And most importantly, they reliably bypass 99% of the MFA methods encountered in the wild, defeating OTP, SMS and push-based authentication",{"data":34338,"content":34339,"nodeType":876},{},[34340],{"data":34341,"marks":34342,"value":34343,"nodeType":867},{},[],"There are basically no downsides to AitM for an attacker. But all the same, they don’t get all that much publicity — probably because traditional phishing prevention solutions are failing to detect them (before the attack succeeds, anyway — and nobody really wants to own up to that). ",{"data":34345,"content":34346,"nodeType":876},{},[34347,34351,34360],{"data":34348,"marks":34349,"value":34350,"nodeType":867},{},[],"So, it’s refreshing to see Troy Hunt, creator of the widely used Have I Been Pwned (HIBP) service, ",{"data":34352,"content":34354,"nodeType":915},{"uri":34353},"https://www.troyhunt.com/a-sneaky-phish-just-grabbed-my-mailchimp-mailing-list/",[34355],{"data":34356,"marks":34357,"value":34359,"nodeType":867},{},[34358],{"type":913},"publicly discussing a recent attack he fell victim to",{"data":34361,"marks":34362,"value":5704,"nodeType":867},{},[],{"data":34364,"content":34365,"nodeType":876},{},[34366],{"data":34367,"marks":34368,"value":34369,"nodeType":867},{},[],"Before we consider the significance of Troy failing to spot the phish — the creator of one of the most widely used services for stolen passwords, working with government on phishing prevention guidance — let's start by breaking down the attack itself. ",{"data":34371,"content":34372,"nodeType":942},{},[],{"data":34374,"content":34375,"nodeType":868},{},[34376],{"data":34377,"marks":34378,"value":33820,"nodeType":867},{},[34379],{"type":865},{"data":34381,"content":34382,"nodeType":876},{},[34383],{"data":34384,"marks":34385,"value":34386,"nodeType":867},{},[],"Troy received a phishing email appearing to be from MailChimp prompting him to sign into his account, with the lure informing him it had had been restricted due to a spam complaint",{"data":34388,"content":34392,"nodeType":985},{"target":34389},{"sys":34390},{"id":34391,"type":982,"linkType":983},"5A4CPvTyKhClC8LgHY5916",[],{"data":34394,"content":34395,"nodeType":876},{},[34396],{"data":34397,"marks":34398,"value":34399,"nodeType":867},{},[],"The email matched Mailchimp’s brand, but the sender address was obviously suspicious. Unfortunately, Troy initially accessed the email via mobile, which hid the sender address — which he then missed when accessing from his PC. ",{"data":34401,"content":34405,"nodeType":985},{"target":34402},{"sys":34403},{"id":34404,"type":982,"linkType":983},"1JWw4jO3qxxJeHO3qtMuZc",[],{"data":34407,"content":34411,"nodeType":985},{"target":34408},{"sys":34409},{"id":34410,"type":982,"linkType":983},"1ebM2R90arTKlCmxmtvYjz",[],{"data":34413,"content":34414,"nodeType":876},{},[34415],{"data":34416,"marks":34417,"value":34418,"nodeType":867},{},[],"Troy was directed to the page hxxps://mailchimp-sso.com. Troy entered his credentials and MFA token and logged in. The page hung and he realized he had been phished…",{"data":34420,"content":34421,"nodeType":876},{},[34422,34426,34433],{"data":34423,"marks":34424,"value":34425,"nodeType":867},{},[],"The attack then automatically executed, with the attacker exporting 16,000 contact records from MailChimp and creating an API key to provide backdoor access to the app (a form of ",{"data":34427,"content":34428,"nodeType":915},{"uri":26236},[34429],{"data":34430,"marks":34431,"value":26242,"nodeType":867},{},[34432],{"type":913},{"data":34434,"marks":34435,"value":24243,"nodeType":867},{},[],{"data":34437,"content":34441,"nodeType":985},{"target":34438},{"sys":34439},{"id":34440,"type":982,"linkType":983},"2MDWfQFU69GaiMCxdvvq8U",[],{"data":34443,"content":34444,"nodeType":876},{},[34445],{"data":34446,"marks":34447,"value":34448,"nodeType":867},{},[],"Let’s have a look at what makes this attack interesting. ",{"data":34450,"content":34451,"nodeType":942},{},[],{"data":34453,"content":34454,"nodeType":868},{},[34455],{"data":34456,"marks":34457,"value":34459,"nodeType":867},{},[34458],{"type":865},"Breaking the attack down",{"data":34461,"content":34462,"nodeType":876},{},[34463,34467,34475],{"data":34464,"marks":34465,"value":34466,"nodeType":867},{},[],"As far as ",{"data":34468,"content":34469,"nodeType":915},{"uri":31924},[34470],{"data":34471,"marks":34472,"value":34474,"nodeType":867},{},[34473],{"type":913},"some of the AitM attacks we’ve observed in the wild",{"data":34476,"marks":34477,"value":34478,"nodeType":867},{},[]," go, this wasn’t the most advanced example we’ve seen: ",{"data":34480,"content":34481,"nodeType":1629},{},[34482,34492],{"data":34483,"content":34484,"nodeType":1586},{},[34485],{"data":34486,"content":34487,"nodeType":876},{},[34488],{"data":34489,"marks":34490,"value":34491,"nodeType":867},{},[],"It didn’t try to obfuscate the notably suspicious sender address or use a legit SaaS service to give the email sender a reputable domain.",{"data":34493,"content":34494,"nodeType":1586},{},[34495],{"data":34496,"content":34497,"nodeType":876},{},[34498],{"data":34499,"marks":34500,"value":34501,"nodeType":867},{},[],"It didn’t see the victim access the real login page, and instead terminated the connection at the point the credentials were captured — meaning Troy was immediately suspicious (I guess it doesn’t really matter given the attack executed instantly, automatically).",{"data":34503,"content":34504,"nodeType":876},{},[34505],{"data":34506,"marks":34507,"value":34508,"nodeType":867},{},[],"That said, it did use a few interesting tricks and techniques. ",{"data":34510,"content":34511,"nodeType":1058},{},[34512],{"data":34513,"marks":34514,"value":34516,"nodeType":867},{},[34515],{"type":865},"Enumerating suitable victims",{"data":34518,"content":34519,"nodeType":876},{},[34520],{"data":34521,"marks":34522,"value":34523,"nodeType":867},{},[],"It’s notable that Troy claims the email he used to access MailChimp wasn’t used anywhere else — meaning the attacker probably guessed it. The domain is partially obscured here but it's likely that this is Troy’s own personal domain. It isn’t too much of a stretch to imagine that organizations frequently set up dedicated email addresses for their MailChimp accounts or newsletters generally (e.g. mailchimp@exampledomain.com). ",{"data":34525,"content":34526,"nodeType":876},{},[34527],{"data":34528,"marks":34529,"value":34530,"nodeType":867},{},[],"Undeniably, Troy’s MailChimp account is probably more of a target than most given the success of his newsletter, but it’s still likely that the attacker spammed many possible address and domain combinations to see what stuck. There’s a degree of luck, but also some smart guesswork at play here. ",{"data":34532,"content":34536,"nodeType":985},{"target":34533},{"sys":34534},{"id":34535,"type":982,"linkType":983},"5TgXthj5tsvWX87QHZH1WQ",[],{"data":34538,"content":34539,"nodeType":1058},{},[34540],{"data":34541,"marks":34542,"value":34544,"nodeType":867},{},[34543],{"type":865},"Using legit services like Cloudflare to defeat detections ",{"data":34546,"content":34547,"nodeType":876},{},[34548,34552,34561],{"data":34549,"marks":34550,"value":34551,"nodeType":867},{},[],"The attacker used Cloudflare to host the domain, which is ",{"data":34553,"content":34555,"nodeType":915},{"uri":34554},"https://pushsecurity.com/blog/how-aitm-phishing-kits-evade-detection/",[34556],{"data":34557,"marks":34558,"value":34560,"nodeType":867},{},[34559],{"type":913},"consistent with what we’ve observed attackers doing in the wild",{"data":34562,"marks":34563,"value":34564,"nodeType":867},{},[],". Even if this means that Cloudflare will probably take the domain down eventually, they aren’t great at identifying the page right away. Given the rate at which attacker infrastructure is burned and rotated, the pros outweigh the cons for the attacker by giving the site legitimate hosting infrastructure, which can defeat some of the common checks performed by anti-phishing tools.",{"data":34566,"content":34567,"nodeType":876},{},[34568,34572,34580],{"data":34569,"marks":34570,"value":34571,"nodeType":867},{},[],"Troy also mentions seeing a 'Cloudflare anti-automation widget' when accessing the page, which is most likely Cloudflare Turnstile — a creative alternative to CAPTCHA to prevent security bots from accessing and loading malicious pages to analyse them. We've seen attackers use Turnstile ",{"data":34573,"content":34574,"nodeType":915},{"uri":34554},[34575],{"data":34576,"marks":34577,"value":34579,"nodeType":867},{},[34578],{"type":913},"along with a host of other obfuscation techniques",{"data":34581,"marks":34582,"value":34583,"nodeType":867},{},[]," to defeat common detections by preventing security tools from analysing the malicious page. ",{"data":34585,"content":34589,"nodeType":985},{"target":34586},{"sys":34587},{"id":34588,"type":982,"linkType":983},"2X1r1qbE5CVcJ0xVcESGK7",[],{"data":34591,"content":34592,"nodeType":876},{},[34593],{"data":34594,"marks":34595,"value":34596,"nodeType":867},{},[],"Although this page has now been taken down, the campaign undoubtedly continues — another will have been rotated in to take its place. ",{"data":34598,"content":34602,"nodeType":985},{"target":34599},{"sys":34600},{"id":34601,"type":982,"linkType":983},"26wnNFTED2f6O1HtqL3Cgu",[],{"data":34604,"content":34605,"nodeType":1058},{},[34606],{"data":34607,"marks":34608,"value":34610,"nodeType":867},{},[34609],{"type":865},"Configuring ghost logins via API keys to backdoor the account ",{"data":34612,"content":34613,"nodeType":876},{},[34614,34618,34627,34631,34639],{"data":34615,"marks":34616,"value":34617,"nodeType":867},{},[],"The attacker also configured an API key — a smart way to backdoor an app and something we’ve previously ",{"data":34619,"content":34621,"nodeType":915},{"uri":34620},"https://pushsecurity.com/resources/phishing-detecting-evilginx-evilnovnc-muraena-and-modlishka",[34622],{"data":34623,"marks":34624,"value":34626,"nodeType":867},{},[34625],{"type":913},"demonstrated in our webinars",{"data":34628,"marks":34629,"value":34630,"nodeType":867},{},[]," as a ",{"data":34632,"content":34633,"nodeType":915},{"uri":15408},[34634],{"data":34635,"marks":34636,"value":34638,"nodeType":867},{},[34637],{"type":913},"SaaS-native attack technique",{"data":34640,"marks":34641,"value":34642,"nodeType":867},{},[]," for persistence. It means that even if the credentials are changed, the attacker can maintain access to the account.",{"data":34644,"content":34648,"nodeType":985},{"target":34645},{"sys":34646},{"id":34647,"type":982,"linkType":983},"35GkKL1rXnWHNZa1EBHLyD",[],{"data":34650,"content":34651,"nodeType":876},{},[34652],{"data":34653,"marks":34654,"value":34655,"nodeType":867},{},[],"Now, as a security pro, Troy noticed this and deleted it — but many less technical victims wouldn’t know to do this. It’s also not unusual for automated emails from applications to go to spam — meaning some victims potentially wouldn’t spot the notification sent to them. ",{"data":34657,"content":34658,"nodeType":942},{},[],{"data":34660,"content":34661,"nodeType":868},{},[34662],{"data":34663,"marks":34664,"value":34666,"nodeType":867},{},[34665],{"type":865},"But — why MailChimp? ",{"data":34668,"content":34669,"nodeType":876},{},[34670],{"data":34671,"marks":34672,"value":34673,"nodeType":867},{},[],"This was the big question we asked ourselves when looking into this attack. Most phishing attacks targeting businesses tend to focus on core platforms like Microsoft, Google Workspace, etc. — usually Identity Providers (IdPs) that provide both access to email and downstream apps via SSO. It’s the biggest bang for their buck and most tooling is preconfigured to support these platforms. So MailChimp seems an unusual choice at first glance. ",{"data":34675,"content":34676,"nodeType":876},{},[34677,34681,34690],{"data":34678,"marks":34679,"value":34680,"nodeType":867},{},[],"But, we’ve seen recently that it's getting easier for attackers to ",{"data":34682,"content":34684,"nodeType":915},{"uri":34683},"https://www.bleepingcomputer.com/news/security/darcula-phaas-can-now-auto-generate-phishing-kits-for-any-brand/",[34685],{"data":34686,"marks":34687,"value":34689,"nodeType":867},{},[34688],{"type":913},"impersonate a broader range of brands",{"data":34691,"marks":34692,"value":34693,"nodeType":867},{},[],". And there’s something to be said for targeting an app like MailChimp — your guard is naturally probably lower than it would be for a Microsoft-based phish, increasing the chance of success. ",{"data":34695,"content":34696,"nodeType":876},{},[34697],{"data":34698,"marks":34699,"value":34700,"nodeType":867},{},[],"But what’s the payout? The data collected doesn’t seem to be overly valuable — 16k records including email address, IP, and rough geolocation data. Not particularly exploitable by itself…",{"data":34702,"content":34706,"nodeType":985},{"target":34703},{"sys":34704},{"id":34705,"type":982,"linkType":983},"OjZtHXit6WO6Zd9tCUYpJ",[],{"data":34708,"content":34709,"nodeType":1058},{},[34710],{"data":34711,"marks":34712,"value":34714,"nodeType":867},{},[34713],{"type":865},"Part of a multi stage attack? ",{"data":34716,"content":34717,"nodeType":876},{},[34718],{"data":34719,"marks":34720,"value":34721,"nodeType":867},{},[],"This gets a lot more interesting when you consider the different things an attacker might do as part of a broader campaign. ",{"data":34723,"content":34724,"nodeType":876},{},[34725],{"data":34726,"marks":34727,"value":34728,"nodeType":867},{},[],"With access to MailChimp, an attacker can send emails on behalf of the compromised account. These emails are highly trusted and expected from the sender, meaning people receiving them are much more likely to engage with the content, click the links, etc. ",{"data":34730,"content":34731,"nodeType":876},{},[34732],{"data":34733,"marks":34734,"value":34735,"nodeType":867},{},[],"So what if an attacker compromised an account, inserted a load of malicious links into the newsletter, and used it in itself as a mass-phishing vector, designed to capture user credentials or deliver malware? Pretty devious! If you scale this up across multiple victims (and not all of them realize that they’ve been phished) you’ve suddenly got your hands on an incredibly valuable phishing vector that is much more likely to succeed than your average cold approach. ",{"data":34737,"content":34738,"nodeType":876},{},[34739],{"data":34740,"marks":34741,"value":34742,"nodeType":867},{},[],"Then, with the additional victims, you could target accounts that are much more inherently valuable to an attacker. You could:",{"data":34744,"content":34745,"nodeType":1629},{},[34746,34778,34801],{"data":34747,"content":34748,"nodeType":1586},{},[34749],{"data":34750,"content":34751,"nodeType":876},{},[34752,34756,34763,34767,34774],{"data":34753,"marks":34754,"value":34755,"nodeType":867},{},[],"Deploy infostealer malware, which has dominated the headlines since the success of the ",{"data":34757,"content":34758,"nodeType":915},{"uri":6814},[34759],{"data":34760,"marks":34761,"value":23019,"nodeType":867},{},[34762],{"type":913},{"data":34764,"marks":34765,"value":34766,"nodeType":867},{},[]," attacks last year, and are continually resulting in data breaches via attackers logging into apps using stolen credentials such as the recent attacks on ",{"data":34768,"content":34769,"nodeType":915},{"uri":16043},[34770],{"data":34771,"marks":34772,"value":23521,"nodeType":867},{},[34773],{"type":913},{"data":34775,"marks":34776,"value":34777,"nodeType":867},{},[]," platforms.",{"data":34779,"content":34780,"nodeType":1586},{},[34781],{"data":34782,"content":34783,"nodeType":876},{},[34784,34788,34797],{"data":34785,"marks":34786,"value":34787,"nodeType":867},{},[],"Target personal apps for banking, email, e-com, and other easily monetizable services — which is increasingly easy to do at-scale using ",{"data":34789,"content":34791,"nodeType":915},{"uri":34790},"https://www.bleepingcomputer.com/news/security/new-atlantis-aio-automates-credential-stuffing-on-140-services/",[34792],{"data":34793,"marks":34794,"value":34796,"nodeType":867},{},[34795],{"type":913},"tooling for hire",{"data":34798,"marks":34799,"value":34800,"nodeType":867},{},[]," with stolen credentials.",{"data":34802,"content":34803,"nodeType":1586},{},[34804],{"data":34805,"content":34806,"nodeType":876},{},[34807],{"data":34808,"marks":34809,"value":34810,"nodeType":867},{},[],"Even attempt to deploy ransomware and other malicious software to progress an attack on user devices and networks (a pretty relevant use case for the many subscribers of Troy’s newsletter accessing it on their corporate device!).",{"data":34812,"content":34813,"nodeType":876},{},[34814],{"data":34815,"marks":34816,"value":34817,"nodeType":867},{},[],"Even grabbing the list of newsletter sign-ups could enable the attacker to perform this attack from a different MailChimp account, so anyone subscribed to Troy’s newsletter should be wary of emails impersonating Troy’s newsletter reaching them from a different sender address than usual. ",{"data":34819,"content":34820,"nodeType":1058},{},[34821],{"data":34822,"marks":34823,"value":34825,"nodeType":867},{},[34824],{"type":865},"Account security limitations",{"data":34827,"content":34828,"nodeType":876},{},[34829,34833,34841],{"data":34830,"marks":34831,"value":34832,"nodeType":867},{},[],"On the theme of MailChimp, it’s also notable that MailChimp doesn’t appear to offer SAML support. ",{"data":34834,"content":34836,"nodeType":915},{"uri":34835},"https://www.okta.com/integrations/mailchimp/",[34837],{"data":34838,"marks":34839,"value":34840,"nodeType":867},{},[],"Okta lists the app as only available for SWA",{"data":34842,"marks":34843,"value":34844,"nodeType":867},{},[]," (where separate credentials are created to access the app, managed through Okta — more like a password manager than genuine SSO via SAML or OIDC).",{"data":34846,"content":34850,"nodeType":985},{"target":34847},{"sys":34848},{"id":34849,"type":982,"linkType":983},"7b4RZhUIqJMF1OxmyR0qKH",[],{"data":34852,"content":34853,"nodeType":876},{},[34854],{"data":34855,"marks":34856,"value":34857,"nodeType":867},{},[],"This means you’re forced to use a username and password. Your only SSO option is to sign in with Google — which many non-Google Workspace users may not have access to. ",{"data":34859,"content":34860,"nodeType":876},{},[34861],{"data":34862,"marks":34863,"value":34864,"nodeType":867},{},[],"As Troy points out, MailChimp also fails to offer support for phishing-resistant MFA. This is pretty typical (if disappointing) for the long tail of SaaS apps, which typically leave WebAuthn / passkey support to the IdP. Except in this case, support for SSO in general is limited, meaning you can only use passkeys if you’re logging in with Google. ",{"data":34866,"content":34870,"nodeType":985},{"target":34867},{"sys":34868},{"id":34869,"type":982,"linkType":983},"2lT7fBiOq4JxpMxSLrdUOv",[],{"data":34872,"content":34873,"nodeType":876},{},[34874],{"data":34875,"marks":34876,"value":34877,"nodeType":867},{},[],"So it’s possible that attackers have noticed that accounts in MailChimp are far more likely to have insecure accounts than other traditional phishing targets — simply because they cannot be configured as securely. ",{"data":34879,"content":34883,"nodeType":985},{"target":34880},{"sys":34881},{"id":34882,"type":982,"linkType":983},"30APqb65kzTA4ySWJIkxGh",[],{"data":34885,"content":34886,"nodeType":1058},{},[34887],{"data":34888,"marks":34889,"value":34891,"nodeType":867},{},[34890],{"type":865},"It might not just be MailChimp",{"data":34893,"content":34894,"nodeType":876},{},[34895],{"data":34896,"marks":34897,"value":34898,"nodeType":867},{},[],"It looks like the same attackers have previously targeted ActiveCampaign, a marketing email and automation platform, based on GitHub comments from December. A domain previously flagged as malicious relating to ActiveCampaign currently redirects to the malicious MailChimp domain seen in Troy’s attack.",{"data":34900,"content":34904,"nodeType":985},{"target":34901},{"sys":34902},{"id":34903,"type":982,"linkType":983},"7M8W9vAYdqPN8NMU8Ug7jq",[],{"data":34906,"content":34910,"nodeType":985},{"target":34907},{"sys":34908},{"id":34909,"type":982,"linkType":983},"7CJfZwc9BpzIL7Fma1Y6o1",[],{"data":34912,"content":34913,"nodeType":876},{},[34914],{"data":34915,"marks":34916,"value":34917,"nodeType":867},{},[],"This could point to a broader campaign targeting similar SaaS platforms for marketing automation and email distribution.",{"data":34919,"content":34920,"nodeType":942},{},[],{"data":34922,"content":34923,"nodeType":868},{},[34924],{"data":34925,"marks":34926,"value":16221,"nodeType":867},{},[34927],{"type":865},{"data":34929,"content":34930,"nodeType":876},{},[34931,34935,34942,34945,34954],{"data":34932,"marks":34933,"value":34934,"nodeType":867},{},[],"MailChimp might seem an unusual target but there are a lot of ways that attackers can abuse SaaS services, as we’ve discussed at length in our public research with the ",{"data":34936,"content":34937,"nodeType":915},{"uri":15408},[34938],{"data":34939,"marks":34940,"value":28048,"nodeType":867},{},[34941],{"type":913},{"data":34943,"marks":34944,"value":1174,"nodeType":867},{},[],{"data":34946,"content":34948,"nodeType":915},{"uri":34947},"https://pushsecurity.com/resources/",[34949],{"data":34950,"marks":34951,"value":34953,"nodeType":867},{},[34952],{"type":913},"many webinars and conference talks",{"data":34955,"marks":34956,"value":34957,"nodeType":867},{},[],". Account takeover through modern phishing attacks like the one we've analysed here is key to unlocking this attack surface. ",{"data":34959,"content":34960,"nodeType":876},{},[34961],{"data":34962,"marks":34963,"value":34964,"nodeType":867},{},[],"While the vast majority of phishing attacks that we observe do focus on core platforms like Microsoft, Google Workspace and Okta, it makes sense that attackers are broadening their focus to take advantage of the fact that phishing targeting these accounts is less obviously a target, and these accounts are often much less securely configured. But there are many ways to target the interconnected ecosystem of SaaS apps in creative ways that most organizations (and users) are seriously underprepared for. ",{"data":34966,"content":34967,"nodeType":876},{},[34968,34972,34980],{"data":34969,"marks":34970,"value":34971,"nodeType":867},{},[],"Attackers have been targeting consumers and individuals via their sprawl of internet apps for some time — are more business-focused threat groups waking up to the opportunity of targeting SaaS? After all, it’s a ",{"data":34973,"content":34974,"nodeType":915},{"uri":26994},[34975],{"data":34976,"marks":34977,"value":34979,"nodeType":867},{},[34978],{"type":913},"great way to evade established controls elsewhere on the network and endpoints",{"data":34981,"marks":34982,"value":34983,"nodeType":867},{},[],", and you can achieve your objectives simply by logging in to (often weakly secured) user accounts.  ",{"data":34985,"content":34986,"nodeType":876},{},[34987],{"data":34988,"marks":34989,"value":34990,"nodeType":867},{},[],"The moral of the story? Phishing attacks are getting pretty sophisticated (and often much more sophisticated than this). Even security pros get phished sometimes!",{"data":34992,"content":34993,"nodeType":3804},{},[34994],{"data":34995,"content":34996,"nodeType":876},{},[34997],{"data":34998,"marks":34999,"value":35001,"nodeType":867},{},[35000],{"type":865},"This is clear indicator that we need stronger technical controls to prevent phishing. If even someone like Troy can be phished, the only reasonable conclusion is that humans will always be susceptible to phishing, no matter how much awareness training they receive. ",{"data":35003,"content":35004,"nodeType":876},{},[35005],{"data":35006,"marks":35007,"value":35008,"nodeType":867},{},[],"A big thanks to Troy for sharing his write-up of the incident!",{"data":35010,"content":35011,"nodeType":942},{},[],{"data":35013,"content":35014,"nodeType":868},{},[35015],{"data":35016,"marks":35017,"value":2541,"nodeType":867},{},[35018],{"type":865},{"data":35020,"content":35021,"nodeType":876},{},[35022,35026,35035],{"data":35023,"marks":35024,"value":35025,"nodeType":867},{},[],"Push takes a unique browser-based approach to detecting and intercepting phishing attacks that overcomes many of the tricks and techniques attackers use to defeat conventional anti-phishing controls. To learn more, ",{"data":35027,"content":35029,"nodeType":915},{"uri":35028},"https://pushsecurity.com/blog/why-its-time-for-phishing-prevention-to-move-beyond-email/",[35030],{"data":35031,"marks":35032,"value":35034,"nodeType":867},{},[35033],{"type":913},"check out our recent blog post",{"data":35036,"marks":35037,"value":5704,"nodeType":867},{},[],{"data":35039,"content":35040,"nodeType":876},{},[35041,35045,35052],{"data":35042,"marks":35043,"value":35044,"nodeType":867},{},[],"And if you want to see how Push helps you to detect and defeat common identity attack techniques like AiTM phishing, credential stuffing, and session hijacking while improving your workforce identity posture, book some time with one of our team for a ",{"data":35046,"content":35047,"nodeType":915},{"uri":5286},[35048],{"data":35049,"marks":35050,"value":5291,"nodeType":867},{},[35051],{"type":913},{"data":35053,"marks":35054,"value":1679,"nodeType":867},{},[],"Dissecting a recent MailChimp phishing attack","HIBP creator and well-known security person Troy Hunt recently blogged about a phish he fell for. Here’s what it tells us about how phishing is evolving. ","2025-03-28T00:00:00.000Z","dissecting-a-recent-mailchimp-phishing-attack",{"items":35060},[35061,35063],{"sys":35062,"name":4018},{"id":4017},{"sys":35064,"name":342},{"id":3240},{"items":35066},[35067],{"fullName":4022,"firstName":4023,"jobTitle":4024,"profilePicture":35068},{"url":4026},{"__typename":1772,"sys":35070,"content":35072,"title":35506,"synopsis":35507,"hashTags":59,"publishedDate":35508,"slug":35509,"tagsCollection":35510,"authorsCollection":35516},{"id":35071},"3uLWz59In1waXGcLB9cnPq",{"json":35073},{"data":35074,"content":35075,"nodeType":1680},{},[35076,35105,35125,35132,35139,35142,35150,35157,35163,35169,35175,35182,35202,35208,35211,35219,35226,35233,35240,35246,35253,35260,35266,35273,35292,35297,35304,35307,35315,35322,35328,35335,35380,35386,35393,35396,35404,35411,35418,35424,35429,35435,35438,35446,35453,35459,35466,35473,35476,35483,35489],{"data":35077,"content":35078,"nodeType":876},{},[35079,35082,35089,35093,35101],{"data":35080,"marks":35081,"value":21,"nodeType":867},{},[],{"data":35083,"content":35084,"nodeType":915},{"uri":23293},[35085],{"data":35086,"marks":35087,"value":31111,"nodeType":867},{},[35088],{"type":913},{"data":35090,"marks":35091,"value":35092,"nodeType":867},{},[]," was one of the first techniques we added to the ",{"data":35094,"content":35096,"nodeType":915},{"uri":35095},"https://github.com/pushsecurity/saas-attacks?tab=readme-ov-file",[35097],{"data":35098,"marks":35099,"value":28048,"nodeType":867},{},[35100],{"type":913},{"data":35102,"marks":35103,"value":35104,"nodeType":867},{},[],", where attackers trick users into authorizing malicious OAuth apps. ",{"data":35106,"content":35107,"nodeType":876},{},[35108,35112,35121],{"data":35109,"marks":35110,"value":35111,"nodeType":867},{},[],"The attacker sends a phishing link to a target that requests permissions to access sensitive data or permissions to perform dangerous actions for an app the victim is using. If the target grants consent for the permissions, the adversary gains that level of access over the target’s account — and certain data and functionality ",{"data":35113,"content":35115,"nodeType":915},{"uri":35114},"https://pushsecurity.com/blog/the-risky-terrain-of-oauth-scopes-in-third-party/",[35116],{"data":35117,"marks":35118,"value":35120,"nodeType":867},{},[35119],{"type":913},"depending on the scopes granted",{"data":35122,"marks":35123,"value":35124,"nodeType":867},{},[],". This attack bypasses MFA entirely (including phishing-resistant MFA) by sidestepping the login process — think of it as an authorization attack, as opposed to an authentication one. Naturally, this means it also persists through typical authentication changes like a password reset. ",{"data":35126,"content":35127,"nodeType":876},{},[35128],{"data":35129,"marks":35130,"value":35131,"nodeType":867},{},[],"Consent phishing has been primarily aimed at getting access to larger cloud platforms like Microsoft Azure or Google Workspace tenants, or more complex apps like GitHub. These apps present an obvious opportunity to attackers in terms of the functionality and and data they contain.  ",{"data":35133,"content":35134,"nodeType":876},{},[35135],{"data":35136,"marks":35137,"value":35138,"nodeType":867},{},[],"Two separate cases of consent phishing have hit the headlines this month representing very different use cases — let’s compare them. ",{"data":35140,"content":35141,"nodeType":942},{},[],{"data":35143,"content":35144,"nodeType":868},{},[35145],{"data":35146,"marks":35147,"value":35149,"nodeType":867},{},[35148],{"type":865},"1. Classic consent phishing",{"data":35151,"content":35152,"nodeType":876},{},[35153],{"data":35154,"marks":35155,"value":35156,"nodeType":867},{},[],"Attackers targeted GitHub users across 12,000 repositories by creating fake security alert issues in GitHub repositories. These legit-looking alerts send the victim to a GitHub authorization page for a \"gitsecurityapp\" OAuth app that requests a lot of very risky scopes granting full access to a user's account and repositories.",{"data":35158,"content":35162,"nodeType":985},{"target":35159},{"sys":35160},{"id":35161,"type":982,"linkType":983},"7s7VLePAQzhzXJ6cFkSCAe",[],{"data":35164,"content":35168,"nodeType":985},{"target":35165},{"sys":35166},{"id":35167,"type":982,"linkType":983},"5dppSzNOgffeZTZK2lG6V5",[],{"data":35170,"content":35174,"nodeType":985},{"target":35171},{"sys":35172},{"id":35173,"type":982,"linkType":983},"1dsYU7bM5mPW1AXyRLnqpp",[],{"data":35176,"content":35177,"nodeType":876},{},[35178],{"data":35179,"marks":35180,"value":35181,"nodeType":867},{},[],"Once authorized, the attacker has extensive access to the account, from which point they can modify repositories to conduct further attacks against users (e.g. by infecting them with malware), poison the repos and services connected to the repository, and exfiltrate any sensitive data the account has access to. ",{"data":35183,"content":35184,"nodeType":876},{},[35185,35189,35198],{"data":35186,"marks":35187,"value":35188,"nodeType":867},{},[],"Alongside consent phishing, this is an example of ",{"data":35190,"content":35192,"nodeType":915},{"uri":35191},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/in-app_phishing/description.md",[35193],{"data":35194,"marks":35195,"value":35197,"nodeType":867},{},[35196],{"type":913},"in-app phishing",{"data":35199,"marks":35200,"value":35201,"nodeType":867},{},[],", which avoids delivering the message via corporate email. Even if the target gets an email notification, the phish isn’t delivered via email directly, and so email-based scanning solutions won’t detect it — they’ll receive a legitimate notification email directly from GitHub. It’s also less likely to raise suspicion as GitHub issue notifications are expected, increasing the click chance. ",{"data":35203,"content":35207,"nodeType":985},{"target":35204},{"sys":35205},{"id":35206,"type":982,"linkType":983},"6d6MMyPQ7vaY2KrJTHGeO6",[],{"data":35209,"content":35210,"nodeType":942},{},[],{"data":35212,"content":35213,"nodeType":868},{},[35214],{"data":35215,"marks":35216,"value":35218,"nodeType":867},{},[35217],{"type":865},"2. Not really consent phishing?",{"data":35220,"content":35221,"nodeType":876},{},[35222],{"data":35223,"marks":35224,"value":35225,"nodeType":867},{},[],"This example is much more unusual. In this case, the attacker used malicious Microsoft OAuth apps impersonating Adobe and DocuSign. ",{"data":35227,"content":35228,"nodeType":876},{},[35229],{"data":35230,"marks":35231,"value":35232,"nodeType":867},{},[],"Rather than trying to grab lots of juicy permissions for Microsoft, the attacker used consent phishing to prevent automated analysis of their phishing page by security tools. To be served the real phishing page, you need to first authorize the fake OAuth app — meaning that security tools and bots won’t be able to reach the page to determine if it’s malicious or not. ",{"data":35234,"content":35235,"nodeType":876},{},[35236],{"data":35237,"marks":35238,"value":35239,"nodeType":867},{},[],"The attack started with attackers sending phishing emails to target users with a fake password reset lure. ",{"data":35241,"content":35245,"nodeType":985},{"target":35242},{"sys":35243},{"id":35244,"type":982,"linkType":983},"3cLd6EbraN9fKuGgL0kkgC",[],{"data":35247,"content":35248,"nodeType":876},{},[35249],{"data":35250,"marks":35251,"value":35252,"nodeType":867},{},[],"Because the initial phishing link directs to the legitimate login.microsoftonline.com URL, it appears legitimate and bypasses common domain-based security checks. ",{"data":35254,"content":35255,"nodeType":876},{},[35256],{"data":35257,"marks":35258,"value":35259,"nodeType":867},{},[],"After clicking the link, the user signs into their real Microsoft account (this might even happen automatically if the user is already signed in on the device/browser they’re using). They are then redirected to a permissions request page for the fake OAuth app. ",{"data":35261,"content":35265,"nodeType":985},{"target":35262},{"sys":35263},{"id":35264,"type":982,"linkType":983},"6O4CSx1VCoPAIjjsnKzu75",[],{"data":35267,"content":35268,"nodeType":876},{},[35269],{"data":35270,"marks":35271,"value":35272,"nodeType":867},{},[],"The permissions requested by the app (profile, email, openid) are so limited as to be basically unexploitable. They are also the same permissions you would accept if you were authorizing Microsoft to perform a social login (SSO via OIDC) to a third party app.",{"data":35274,"content":35275,"nodeType":876},{},[35276,35280,35288],{"data":35277,"marks":35278,"value":35279,"nodeType":867},{},[],"Clicking the link redirects the victim to the malicious page but masks it using the legit Cloudflare Turnstile service. As well as making the page look more credible (since its fronted by a legit service to block bots) this is a common detection evasion technique we’ve ",{"data":35281,"content":35282,"nodeType":915},{"uri":34554},[35283],{"data":35284,"marks":35285,"value":35287,"nodeType":867},{},[35286],{"type":913},"blogged about previously",{"data":35289,"marks":35290,"value":35291,"nodeType":867},{},[]," which prevents security solutions from accessing and analysing the malicious page. ",{"data":35293,"content":35296,"nodeType":985},{"target":35294},{"sys":35295},{"id":34015,"type":982,"linkType":983},[],{"data":35298,"content":35299,"nodeType":876},{},[35300],{"data":35301,"marks":35302,"value":35303,"nodeType":867},{},[],"After completing the verification, the page (and the malicious phishing kit element) is finally loaded. If the victim authenticates, the session will be stolen by the attacker, along with the captured credentials and MFA code. ",{"data":35305,"content":35306,"nodeType":942},{},[],{"data":35308,"content":35309,"nodeType":868},{},[35310],{"data":35311,"marks":35312,"value":35314,"nodeType":867},{},[35313],{"type":865},"Using consent phishing to evade detection",{"data":35316,"content":35317,"nodeType":876},{},[35318],{"data":35319,"marks":35320,"value":35321,"nodeType":867},{},[],"The attacker is essentially using their fake OAuth app to prevent security analysts and bots from analysing the real phishing page, because the first page loaded is a link to a legitimate Microsoft domain. They’re also layering it with a range of other detection evasion techniques like using Cloudflare Turnstile.  ",{"data":35323,"content":35327,"nodeType":985},{"target":35324},{"sys":35325},{"id":35326,"type":982,"linkType":983},"4Bi9YoMwWVmKoWfkh5tiTA",[],{"data":35329,"content":35330,"nodeType":876},{},[35331],{"data":35332,"marks":35333,"value":35334,"nodeType":867},{},[],"We’ve previously blogged about how attackers are using layered detection evasion techniques to circumvent typical phishing page detections, which are often email-based, including:",{"data":35336,"content":35337,"nodeType":1629},{},[35338,35359],{"data":35339,"content":35340,"nodeType":1586},{},[35341],{"data":35342,"content":35343,"nodeType":876},{},[35344,35347,35355],{"data":35345,"marks":35346,"value":21,"nodeType":867},{},[],{"data":35348,"content":35349,"nodeType":915},{"uri":34554},[35350],{"data":35351,"marks":35352,"value":35354,"nodeType":867},{},[35353],{"type":913},"Prevent analysis of phishing pages",{"data":35356,"marks":35357,"value":35358,"nodeType":867},{},[]," by security bots, including using legitimate services like Cloudflare Workers and Turnstile (as above), CAPTCHA, and various sandbox-aware techniques to ensure only the intended victim is served the phishing page, such as only providing the correct parameters to load the page if the correct path is followed (rather than attempting to load the malicious page by going directly to the domain). ",{"data":35360,"content":35361,"nodeType":1586},{},[35362],{"data":35363,"content":35364,"nodeType":876},{},[35365,35368,35376],{"data":35366,"marks":35367,"value":21,"nodeType":867},{},[],{"data":35369,"content":35370,"nodeType":915},{"uri":31924},[35371],{"data":35372,"marks":35373,"value":35375,"nodeType":867},{},[35374],{"type":913},"DOM and visual obfuscation",{"data":35377,"marks":35378,"value":35379,"nodeType":867},{},[]," of phishing pages when the victim does land on the page to prevent it from being identified as malicious through signature-based detection of page elements. ",{"data":35381,"content":35385,"nodeType":985},{"target":35382},{"sys":35383},{"id":35384,"type":982,"linkType":983},"2dN8np5odBecf7r1vBr69K",[],{"data":35387,"content":35388,"nodeType":876},{},[35389],{"data":35390,"marks":35391,"value":35392,"nodeType":867},{},[],"This seems a bit overkill and many of the steps here are likely to raise suspicion — like the fact that you’re never asked to provide the original code for the password reset, and are asked to unexpectedly consent to an OAuth app. But clearly, the attacker is more concerned about bypassing technical safeguards than human ones (not a great endorsement for the state of phishing awareness training). ",{"data":35394,"content":35395,"nodeType":942},{},[],{"data":35397,"content":35398,"nodeType":868},{},[35399],{"data":35400,"marks":35401,"value":35403,"nodeType":867},{},[35402],{"type":865},"How Push detects and blocks phishing attacks",{"data":35405,"content":35406,"nodeType":876},{},[35407],{"data":35408,"marks":35409,"value":35410,"nodeType":867},{},[],"Push overcomes the various detection evasion techniques shown here by using in-browser detections based on the phishing page that the user sees. This means that no matter where the user accesses the link from (email, IM platform, social media, or anywhere else on the internet) Push can observe and analyse the page to determine if it's malicious. ",{"data":35412,"content":35413,"nodeType":876},{},[35414],{"data":35415,"marks":35416,"value":35417,"nodeType":867},{},[],"Push uses layered detections based on identifying the phishing kit running on the page itself, whether the page is cloned from a legitimate login page, as well as detecting whether the credentials being entered on the page have been used to log into your SSO account previously. ",{"data":35419,"content":35423,"nodeType":985},{"target":35420},{"sys":35421},{"id":35422,"type":982,"linkType":983},"6B1toQAf44rDzQZijYRd9g",[],{"data":35425,"content":35428,"nodeType":985},{"target":35426},{"sys":35427},{"id":32465,"type":982,"linkType":983},[],{"data":35430,"content":35434,"nodeType":985},{"target":35431},{"sys":35432},{"id":35433,"type":982,"linkType":983},"01musWa3FUiO0CVFNWfwcy",[],{"data":35436,"content":35437,"nodeType":942},{},[],{"data":35439,"content":35440,"nodeType":868},{},[35441],{"data":35442,"marks":35443,"value":35445,"nodeType":867},{},[35444],{"type":865},"Using Push to review OAuth integrations",{"data":35447,"content":35448,"nodeType":876},{},[35449],{"data":35450,"marks":35451,"value":35452,"nodeType":867},{},[],"You can also use Push to discover and remove risky OAuth integrations accepted by your users. ",{"data":35454,"content":35458,"nodeType":985},{"target":35455},{"sys":35456},{"id":35457,"type":982,"linkType":983},"5kJvy5SBcWLrK2EhLyR1ZD",[],{"data":35460,"content":35461,"nodeType":876},{},[35462],{"data":35463,"marks":35464,"value":35465,"nodeType":867},{},[],"This shows which OAuth apps have been added, which apps they are integrated with, what permissions they’ve been granted, as well as other properties that indicate risk (e.g. whether the app’s publisher has been verified). ",{"data":35467,"content":35468,"nodeType":876},{},[35469],{"data":35470,"marks":35471,"value":35472,"nodeType":867},{},[],"If your users are consent phished, you’ll be notified via webhook event that a new integration has been added. These risky integrations can be removed via the Push platform by clicking ‘delete integration’. ",{"data":35474,"content":35475,"nodeType":942},{},[],{"data":35477,"content":35478,"nodeType":868},{},[35479],{"data":35480,"marks":35481,"value":24553,"nodeType":867},{},[35482],{"type":865},{"data":35484,"content":35485,"nodeType":876},{},[35486],{"data":35487,"marks":35488,"value":32489,"nodeType":867},{},[],{"data":35490,"content":35491,"nodeType":876},{},[35492,35495,35503],{"data":35493,"marks":35494,"value":27639,"nodeType":867},{},[],{"data":35496,"content":35498,"nodeType":915},{"uri":35497},"https://pushsecurity.com/demo?utm_campaign=9983377-FY25Q1_Bleeping-Computer-Organic-Article&utm_source=bleepingcomputer&utm_medium=sponsored-content&utm_content=organic%20article",[35499],{"data":35500,"marks":35501,"value":24568,"nodeType":867},{},[35502],{"type":913},{"data":35504,"marks":35505,"value":34275,"nodeType":867},{},[],"How consent phishing is evolving to defeat detection controls","Consent phishing is where attackers trick users into authorizing access for malicious OAuth apps. Here's how attackers are using this technique in the wild.","2025-03-31T00:00:00.000Z","how-consent-phishing-is-evolving",{"items":35511},[35512,35514],{"sys":35513,"name":4018},{"id":4017},{"sys":35515,"name":342},{"id":3240},{"items":35517},[35518],{"fullName":4022,"firstName":4023,"jobTitle":4024,"profilePicture":35519},{"url":4026},"blog/three-reasons-why-browser-is-best-for-stopping-phishing-attacks",{"json":35522},{"data":35523,"content":35524,"nodeType":1680},{},[35525],{"data":35526,"content":35527,"nodeType":876},{},[35528],{"data":35529,"marks":35530,"value":35531,"nodeType":867},{},[],"Why being in the browser gives defenders a key advantage over network- and email-based phishing prevention, detection, and response tools. ",{"id":31871,"publishedAt":35533},"2026-08-12T11:54:13.980Z",{"items":35535},[35536,35538],{"sys":35537,"name":342},{"id":3240},{"sys":35539,"name":4018},{"id":4017},{"items":35541},[35542,35544,35546,35548,35550,35552,35554,35556,35558,35560,35562,35564,35566,35568],{"sys":35543,"name":519,"slug":520,"tier":31},{"id":516},{"sys":35545,"name":297,"slug":298,"tier":31},{"id":294},{"sys":35547,"name":279,"slug":280,"tier":31},{"id":276},{"sys":35549,"name":342,"slug":343,"tier":31},{"id":339},{"sys":35551,"name":413,"slug":414,"tier":31},{"id":410},{"sys":35553,"name":324,"slug":325,"tier":45},{"id":321},{"sys":35555,"name":261,"slug":262,"tier":45},{"id":258},{"sys":35557,"name":511,"slug":512,"tier":45},{"id":508},{"sys":35559,"name":466,"slug":467,"tier":45},{"id":463},{"sys":35561,"name":440,"slug":441,"tier":45},{"id":437},{"sys":35563,"name":475,"slug":476,"tier":45},{"id":472},{"sys":35565,"name":351,"slug":352,"tier":45},{"id":348},{"sys":35567,"name":377,"slug":378,"tier":45},{"id":374},{"sys":35569,"name":624,"slug":625,"tier":45},{"id":621},"3YshXuJ5vCxZNUkwHxNIDFHPP05eO3yxWJmeqIDYoPA",{"id":35572,"title":35573,"authorsCollection":35574,"content":35579,"extension":228,"faqItemsCollection":36118,"faqTitle":59,"featured":6,"hashTags":59,"meta":36120,"metaTitle":36121,"ogImage":59,"postType":1767,"publishedDate":32521,"relatedBlogPostsCollection":36122,"slug":37606,"stem":37607,"subtitle":59,"summary":37608,"synopsis":37619,"sys":37620,"tagsCollection":37623,"topicsCollection":37629,"__hash__":37657},"blog/blog/why-most-phishing-attacks-feel-like-a-zero-day.json","Why most phishing attacks feel like a zero-day",{"items":35575},[35576],{"fullName":4022,"firstName":4023,"jobTitle":4024,"socialLinks":35577,"profilePicture":35578},[21074],{"url":4026},{"json":35580,"links":36086},{"data":35581,"content":35582,"nodeType":1680},{},[35583,35589,35595,35607,35619,35622,35630,35636,35643,35650,35657,35664,35670,35677,35682,35685,35693,35700,35733,35740,35748,35755,35762,35769,35775,35783,35790,35795,35802,35823,35830,35838,35845,35852,35859,35864,35871,35888,35891,35899,35913,35919,35953,35961,35964,35972,35979,35993,35998,36004,36010,36017,36022,36029,36034,36037,36044,36050,36055,36060,36080],{"data":35584,"content":35585,"nodeType":876},{},[35586],{"data":35587,"marks":35588,"value":31882,"nodeType":867},{},[],{"data":35590,"content":35591,"nodeType":876},{},[35592],{"data":35593,"marks":35594,"value":31896,"nodeType":867},{},[],{"data":35596,"content":35597,"nodeType":876},{},[35598,35602],{"data":35599,"marks":35600,"value":35601,"nodeType":867},{},[],"A key challenge with phishing detection is that based on the known-bad indicators that we as an industry use to commonly detect phishing pages, pretty much every phishing attack looks different and uses a unique combination of domain, URL, IPs, page composition, target app, etc. ",{"data":35603,"marks":35604,"value":35606,"nodeType":867},{},[35605],{"type":865},"Effectively, every phishing attack is completely novel. You might even describe them as “zero-days” (cue the collective sharp intake of breath)...",{"data":35608,"content":35609,"nodeType":876},{},[35610,35614],{"data":35611,"marks":35612,"value":35613,"nodeType":867},{},[],"The goal here isn’t to sensationalize phishing attacks — quite the opposite. Rather, this shines a light on the state of phishing detection controls. ",{"data":35615,"marks":35616,"value":35618,"nodeType":867},{},[35617],{"type":865},"Frankly, if every phishing attack is a zero-day, something has gone very wrong with how we detect these attacks…",{"data":35620,"content":35621,"nodeType":942},{},[],{"data":35623,"content":35624,"nodeType":868},{},[35625],{"data":35626,"marks":35627,"value":35629,"nodeType":867},{},[35628],{"type":865},"Phishing detection 101",{"data":35631,"content":35632,"nodeType":876},{},[35633],{"data":35634,"marks":35635,"value":32042,"nodeType":867},{},[],{"data":35637,"content":35638,"nodeType":876},{},[35639],{"data":35640,"marks":35641,"value":35642,"nodeType":867},{},[],"Phishing detection, at its core, relies on blocklists made up of indicators of compromise (IoCs) relating to phishing pages that have been successfully identified as malicious. These IoCs consist of malicious domains, URLs, and IPs that have appeared in an attack. ",{"data":35644,"content":35645,"nodeType":876},{},[35646],{"data":35647,"marks":35648,"value":35649,"nodeType":867},{},[],"IoCs are collected by security vendors and service providers across a range of sources. Mostly though, the malicious page needs to be used in a phishing campaign before it has a chance of being detected. This means that a would-be victim needs to interact with it in some way — either by falling for a phishing attack, or reporting it as suspicious. ",{"data":35651,"content":35652,"nodeType":876},{},[35653],{"data":35654,"marks":35655,"value":35656,"nodeType":867},{},[],"Once a page is flagged, it can be investigated — either manually (by a security person) or automatically (by a product/tool). If the page can be accessed and analyzed, and malicious content is found (more on this later) then the page’s IoCs can be collected and added to a blocklist. ",{"data":35658,"content":35659,"nodeType":876},{},[35660],{"data":35661,"marks":35662,"value":35663,"nodeType":867},{},[],"This information will then begin to circulate across the various threat intelligence feeds and security products leveraging this information. The majority of phishing detection and control enforcement is focused at the email and network layer — typically at the Secure Email Gateway (SEG), Secure Web Gateway (SWG)/proxy, or both. ",{"data":35665,"content":35669,"nodeType":985},{"target":35666},{"sys":35667},{"id":35668,"type":982,"linkType":983},"7xPrHlTjDI1Lc620fAnxvX",[],{"data":35671,"content":35672,"nodeType":876},{},[35673],{"data":35674,"marks":35675,"value":35676,"nodeType":867},{},[],"If you’re following the thought pattern here, you can probably already see the root of the problem. To detect and block a phishing page, it needs to be used in an attack first…",{"data":35678,"content":35681,"nodeType":985},{"target":35679},{"sys":35680},{"id":32511,"type":982,"linkType":983},[],{"data":35683,"content":35684,"nodeType":942},{},[],{"data":35686,"content":35687,"nodeType":868},{},[35688],{"data":35689,"marks":35690,"value":35692,"nodeType":867},{},[35691],{"type":865},"Why most phishing attacks are zero-day",{"data":35694,"content":35695,"nodeType":876},{},[35696],{"data":35697,"marks":35698,"value":35699,"nodeType":867},{},[],"Attackers know that phishing detection and blocking:",{"data":35701,"content":35702,"nodeType":1629},{},[35703,35713,35723],{"data":35704,"content":35705,"nodeType":1586},{},[35706],{"data":35707,"content":35708,"nodeType":876},{},[35709],{"data":35710,"marks":35711,"value":35712,"nodeType":867},{},[],"Relies on blocklisting IoCs like domains, URLs and IPs",{"data":35714,"content":35715,"nodeType":1586},{},[35716],{"data":35717,"content":35718,"nodeType":876},{},[35719],{"data":35720,"marks":35721,"value":35722,"nodeType":867},{},[],"Is situated at the email and network layer",{"data":35724,"content":35725,"nodeType":1586},{},[35726],{"data":35727,"content":35728,"nodeType":876},{},[35729],{"data":35730,"marks":35731,"value":35732,"nodeType":867},{},[],"Requires that a page is accessed and analyzed before it can be blocked",{"data":35734,"content":35735,"nodeType":876},{},[35736],{"data":35737,"marks":35738,"value":35739,"nodeType":867},{},[],"These methods have remained practically unchanged for more than a decade. So it stands to reason that attackers are getting pretty good at avoiding them. ",{"data":35741,"content":35742,"nodeType":1058},{},[35743],{"data":35744,"marks":35745,"value":35747,"nodeType":867},{},[35746],{"type":865},"It’s easy for attackers to evade IoC-based detections",{"data":35749,"content":35750,"nodeType":876},{},[35751],{"data":35752,"marks":35753,"value":35754,"nodeType":867},{},[],"Phishing domains are highly disposable by nature. Attackers are buying them in bulk, constantly taking over legitimate domains, and generally planning for the fact that they’ll get through a lot of them.",{"data":35756,"content":35757,"nodeType":876},{},[35758],{"data":35759,"marks":35760,"value":35761,"nodeType":867},{},[],"Modern phishing architecture is also able to dynamically rotate and update commonly signatured elements — for example, by dynamically rotating the links served to visitors from a continually refreshed pool (so every person that clicks the link gets served a different URL) and even going as far as using things like one-time magic links (which also means that any security team members trying to investigate the page later won’t be able to do so). ",{"data":35763,"content":35764,"nodeType":876},{},[35765],{"data":35766,"marks":35767,"value":35768,"nodeType":867},{},[],"You could look at which IP address the user connects to, but these days it’s very simple for attackers to add a new IP to their cloud-hosted server. If a domain is flagged as known-bad, the attacker only has to register a new domain, or compromise a WordPress server on an already trusted domain. Both of these things are happening on a massive scale as attackers pre-plan for the fact that their domains will be burned at some point. ",{"data":35770,"content":35771,"nodeType":876},{},[35772],{"data":35773,"marks":35774,"value":32146,"nodeType":867},{},[],{"data":35776,"content":35777,"nodeType":1058},{},[35778],{"data":35779,"marks":35780,"value":35782,"nodeType":867},{},[35781],{"type":865},"Phishing doesn’t just happen over email",{"data":35784,"content":35785,"nodeType":876},{},[35786],{"data":35787,"marks":35788,"value":35789,"nodeType":867},{},[],"To evade email-based detections, attackers are going multi- and cross-channel with their attacks. ",{"data":35791,"content":35794,"nodeType":985},{"target":35792},{"sys":35793},{"id":31998,"type":982,"linkType":983},[],{"data":35796,"content":35797,"nodeType":876},{},[35798],{"data":35799,"marks":35800,"value":35801,"nodeType":867},{},[],"Not only are attackers using different phishing vectors, they’re chaining them together to prevent security tools from intercepting the link. So for example, a social media message that sends you a non-malicious PDF with a link embedded in it, that finally directs you to a malicious webpage.",{"data":35803,"content":35804,"nodeType":876},{},[35805,35809,35813,35816,35820],{"data":35806,"marks":35807,"value":35808,"nodeType":867},{},[],"It’s worth also pointing out the limitations of email-based solutions here too. Email has some additional checks around the sender’s reputation and things like DMARC/DKIM, but these don’t actually identify malicious ",{"data":35810,"marks":35811,"value":32011,"nodeType":867},{},[35812],{"type":865},{"data":35814,"marks":35815,"value":32015,"nodeType":867},{},[],{"data":35817,"marks":35818,"value":32020,"nodeType":867},{},[35819],{"type":865},{"data":35821,"marks":35822,"value":32024,"nodeType":867},{},[],{"data":35824,"content":35825,"nodeType":876},{},[35826],{"data":35827,"marks":35828,"value":35829,"nodeType":867},{},[],"In any case, while modern email solutions can bring a lot more to the table, neither email or network (proxy) based tools can’t definitively know that a page is malicious unless they can access the page and analyze it… ",{"data":35831,"content":35832,"nodeType":1058},{},[35833],{"data":35834,"marks":35835,"value":35837,"nodeType":867},{},[35836],{"type":865},"Attackers are preventing their pages from being analyzed",{"data":35839,"content":35840,"nodeType":876},{},[35841],{"data":35842,"marks":35843,"value":35844,"nodeType":867},{},[],"Both email and network (proxy) based solutions rely on being able to inspect and analyze a page to identify whether it is malicious or not, after which IoCs are generated that can be enforced when a link is clicked (or received in your email inbox).",{"data":35846,"content":35847,"nodeType":876},{},[35848],{"data":35849,"marks":35850,"value":35851,"nodeType":867},{},[],"Modern phishing pages aren’t static HTML — like most other modern web pages, these are dynamic web apps rendered in the browser, with JavaScript dynamically rewriting the page and launching the malicious content. This means that most basic, static checks fail to identify the malicious content running on the page. ",{"data":35853,"content":35854,"nodeType":876},{},[35855],{"data":35856,"marks":35857,"value":35858,"nodeType":867},{},[],"To address this, both email and network security tools will try to explode links in a sandbox to observe the page’s behavior. But attackers are getting around this simply by implementing bot protection by requiring user interaction with a CAPTCHA or Cloudflare Turnstile. ",{"data":35860,"content":35863,"nodeType":985},{"target":35861},{"sys":35862},{"id":31972,"type":982,"linkType":983},[],{"data":35865,"content":35866,"nodeType":876},{},[35867],{"data":35868,"marks":35869,"value":35870,"nodeType":867},{},[],"Even if you can get past Turnstile, then you’ll need to supply the correct URL parameters and headers, and execute JavaScript, to be served the malicious page. This means that a defender who knows the domain name can’t discover the malicious behavior just by making a simple HTTP(S) request to the domain.",{"data":35872,"content":35873,"nodeType":876},{},[35874,35877,35885],{"data":35875,"marks":35876,"value":32185,"nodeType":867},{},[],{"data":35878,"content":35880,"nodeType":915},{"uri":35879},"https://pushsecurity.com/blog/how-aitm-phishing-kits-evade-detection-p2/?utm_campaign=12100141-FY25Q2_Bleeping-Computer-Article&utm_source=bleepingcomputer&utm_medium=sponsored&utm_content=external-article",[35881],{"data":35882,"marks":35883,"value":32194,"nodeType":867},{},[35884],{"type":913},{"data":35886,"marks":35887,"value":32198,"nodeType":867},{},[],{"data":35889,"content":35890,"nodeType":942},{},[],{"data":35892,"content":35893,"nodeType":868},{},[35894],{"data":35895,"marks":35896,"value":35898,"nodeType":867},{},[35897],{"type":865},"Phishing attacks are zero-day because phishing detection is post mortem",{"data":35900,"content":35901,"nodeType":876},{},[35902,35906,35910],{"data":35903,"marks":35904,"value":35905,"nodeType":867},{},[],"The result of these detection evasion and obfuscation techniques is that ",{"data":35907,"marks":35908,"value":32311,"nodeType":867},{},[35909],{"type":865},{"data":35911,"marks":35912,"value":5704,"nodeType":867},{},[],{"data":35914,"content":35915,"nodeType":876},{},[35916],{"data":35917,"marks":35918,"value":32321,"nodeType":867},{},[],{"data":35920,"content":35921,"nodeType":876},{},[35922,35925,35929,35932,35936,35939,35943,35946,35950],{"data":35923,"marks":35924,"value":32328,"nodeType":867},{},[],{"data":35926,"marks":35927,"value":32333,"nodeType":867},{},[35928],{"type":865},{"data":35930,"marks":35931,"value":32337,"nodeType":867},{},[],{"data":35933,"marks":35934,"value":32342,"nodeType":867},{},[35935],{"type":865},{"data":35937,"marks":35938,"value":32346,"nodeType":867},{},[],{"data":35940,"marks":35941,"value":32342,"nodeType":867},{},[35942],{"type":865},{"data":35944,"marks":35945,"value":32354,"nodeType":867},{},[],{"data":35947,"marks":35948,"value":32359,"nodeType":867},{},[35949],{"type":865},{"data":35951,"marks":35952,"value":32363,"nodeType":867},{},[],{"data":35954,"content":35955,"nodeType":876},{},[35956],{"data":35957,"marks":35958,"value":35960,"nodeType":867},{},[35959],{"type":865},"The result? Most phishing attacks are entirely novel because phishing detection is inherently post mortem — it relies on known-bads. How does something become known-bad? When a user is phished…",{"data":35962,"content":35963,"nodeType":942},{},[],{"data":35965,"content":35966,"nodeType":868},{},[35967],{"data":35968,"marks":35969,"value":35971,"nodeType":867},{},[35970],{"type":865},"To fix phishing detection, we need real-time analysis",{"data":35973,"content":35974,"nodeType":876},{},[35975],{"data":35976,"marks":35977,"value":35978,"nodeType":867},{},[],"It’s clear that how we detect and block phishing attacks is fundamentally flawed. The good news is, we’ve been here before. ",{"data":35980,"content":35981,"nodeType":876},{},[35982,35986,35990],{"data":35983,"marks":35984,"value":35985,"nodeType":867},{},[],"When endpoint attacks skyrocketed in the late 2000s / early 2010s, they took advantage of the fact that defenders were trying to detect malware with primarily network-based detections, signature-based analysis of files, and running files in sandboxes (which was reliably defeated with sandbox-aware malware and using things as simple as putting an execution delay in the code). But this gave way to EDR, which presented a better way of observing and intercepting malicious software in ",{"data":35987,"marks":35988,"value":32069,"nodeType":867},{},[35989],{"type":865},{"data":35991,"marks":35992,"value":5704,"nodeType":867},{},[],{"data":35994,"content":35997,"nodeType":985},{"target":35995},{"sys":35996},{"id":32077,"type":982,"linkType":983},[],{"data":35999,"content":36000,"nodeType":876},{},[36001],{"data":36002,"marks":36003,"value":32085,"nodeType":867},{},[],{"data":36005,"content":36006,"nodeType":876},{},[36007],{"data":36008,"marks":36009,"value":32092,"nodeType":867},{},[],{"data":36011,"content":36012,"nodeType":876},{},[36013],{"data":36014,"marks":36015,"value":36016,"nodeType":867},{},[],"In many ways, the browser is the new Operating System. It’s where modern work predominantly takes place — and where attacks are happening too.  ",{"data":36018,"content":36021,"nodeType":985},{"target":36019},{"sys":36020},{"id":32097,"type":982,"linkType":983},[],{"data":36023,"content":36024,"nodeType":876},{},[36025],{"data":36026,"marks":36027,"value":36028,"nodeType":867},{},[],"To stop phishing attacks as they happen, we need to be able to observe the page in real-time, as the user sees it from inside the browser. Not in a sandbox — seeing the real page, at the same time as the user. Only then can we build the detection and containment controls required to move phishing beyond the current cat-and-mouse game, where attackers are always two steps ahead. ",{"data":36030,"content":36033,"nodeType":985},{"target":36031},{"sys":36032},{"id":32267,"type":982,"linkType":983},[],{"data":36035,"content":36036,"nodeType":942},{},[],{"data":36038,"content":36039,"nodeType":868},{},[36040],{"data":36041,"marks":36042,"value":32386,"nodeType":867},{},[36043],{"type":865},{"data":36045,"content":36046,"nodeType":876},{},[36047],{"data":36048,"marks":36049,"value":32393,"nodeType":867},{},[],{"data":36051,"content":36054,"nodeType":985},{"target":36052},{"sys":36053},{"id":32280,"type":982,"linkType":983},[],{"data":36056,"content":36059,"nodeType":985},{"target":36057},{"sys":36058},{"id":32511,"type":982,"linkType":983},[],{"data":36061,"content":36062,"nodeType":3804},{},[36063],{"data":36064,"content":36065,"nodeType":876},{},[36066,36069,36077],{"data":36067,"marks":36068,"value":27639,"nodeType":867},{},[],{"data":36070,"content":36072,"nodeType":915},{"uri":36071},"https://pushsecurity.com/demo?utm_campaign=12100141-FY25Q2_Bleeping-Computer-Article&utm_source=bleepingcomputer&utm_medium=sponsored&utm_content=external-article",[36073],{"data":36074,"marks":36075,"value":14723,"nodeType":867},{},[36076],{"type":913},{"data":36078,"marks":36079,"value":1679,"nodeType":867},{},[],{"data":36081,"content":36082,"nodeType":876},{},[36083],{"data":36084,"marks":36085,"value":21,"nodeType":867},{},[],{"entries":36087},{"hyperlink":36088,"inline":36089,"block":36090},[],[],[36091,36098,36100,36103,36106,36109,36112,36115],{"sys":36092,"__typename":1688,"title":36093,"caption":59,"layoutMode":59,"file":36094},{"id":35668},"IoC-based blocklists underpin phishing detection and blocking",{"url":36095,"width":36096,"height":36097},"https://images.ctfassets.net/y1cdw1ablpvd/7xI33nDHdy4CsCARPa7K27/d42254dd924c9dca70437d7277d37328/Screenshot_2025-04-28_at_14.46.57.png",1932,836,{"sys":36099,"__typename":1697,"type":1698,"ctaText":33798,"buttonLabel":21672,"buttonColour":1701,"buttonUrl":33799},{"id":32511},{"sys":36101,"__typename":1688,"title":33758,"caption":33758,"layoutMode":59,"file":36102},{"id":31998},{"url":33760,"width":1693,"height":33761},{"sys":36104,"__typename":1688,"title":33751,"caption":33751,"layoutMode":59,"file":36105},{"id":31972},{"url":33753,"width":33754,"height":33755},{"sys":36107,"__typename":1688,"title":33764,"caption":59,"layoutMode":59,"file":36108},{"id":32077},{"url":33766,"width":1693,"height":33767},{"sys":36110,"__typename":1688,"title":33770,"caption":33770,"layoutMode":59,"file":36111},{"id":32097},{"url":29579,"width":29580,"height":29581},{"sys":36113,"__typename":1688,"title":33774,"caption":33775,"layoutMode":59,"file":36114},{"id":32267},{"url":33777,"width":1693,"height":33778},{"sys":36116,"__typename":1688,"title":33781,"caption":33782,"layoutMode":59,"file":36117},{"id":32280},{"url":29586,"width":29587,"height":29588},{"items":36119},[],{},"Why blocklists can't stop modern phishing",{"items":36123},[36124,36542,37214],{"__typename":1772,"sys":36125,"content":36126,"title":34276,"synopsis":34277,"hashTags":59,"publishedDate":34278,"slug":34279,"tagsCollection":36532,"authorsCollection":36538},{"id":33808},{"json":36127},{"data":36128,"content":36129,"nodeType":1680},{},[36130,36137,36143,36149,36154,36160,36165,36171,36177,36180,36187,36193,36199,36220,36226,36229,36236,36249,36254,36260,36265,36271,36277,36280,36287,36303,36308,36314,36319,36322,36329,36345,36350,36356,36361,36377,36382,36387,36390,36397,36403,36409,36414,36417,36424,36430,36436,36439,36446,36452,36458,36463,36469,36499,36504,36511,36517],{"data":36131,"content":36132,"nodeType":868},{},[36133],{"data":36134,"marks":36135,"value":33820,"nodeType":867},{},[36136],{"type":865},{"data":36138,"content":36139,"nodeType":876},{},[36140],{"data":36141,"marks":36142,"value":33827,"nodeType":867},{},[],{"data":36144,"content":36145,"nodeType":876},{},[36146],{"data":36147,"marks":36148,"value":33834,"nodeType":867},{},[],{"data":36150,"content":36153,"nodeType":985},{"target":36151},{"sys":36152},{"id":22161,"type":982,"linkType":983},[],{"data":36155,"content":36156,"nodeType":876},{},[36157],{"data":36158,"marks":36159,"value":33846,"nodeType":867},{},[],{"data":36161,"content":36164,"nodeType":985},{"target":36162},{"sys":36163},{"id":33851,"type":982,"linkType":983},[],{"data":36166,"content":36167,"nodeType":876},{},[36168],{"data":36169,"marks":36170,"value":33859,"nodeType":867},{},[],{"data":36172,"content":36173,"nodeType":876},{},[36174],{"data":36175,"marks":36176,"value":33866,"nodeType":867},{},[],{"data":36178,"content":36179,"nodeType":942},{},[],{"data":36181,"content":36182,"nodeType":868},{},[36183],{"data":36184,"marks":36185,"value":33877,"nodeType":867},{},[36186],{"type":865},{"data":36188,"content":36189,"nodeType":876},{},[36190],{"data":36191,"marks":36192,"value":33884,"nodeType":867},{},[],{"data":36194,"content":36195,"nodeType":876},{},[36196],{"data":36197,"marks":36198,"value":33891,"nodeType":867},{},[],{"data":36200,"content":36201,"nodeType":1629},{},[36202,36211],{"data":36203,"content":36204,"nodeType":1586},{},[36205],{"data":36206,"content":36207,"nodeType":876},{},[36208],{"data":36209,"marks":36210,"value":33904,"nodeType":867},{},[],{"data":36212,"content":36213,"nodeType":1586},{},[36214],{"data":36215,"content":36216,"nodeType":876},{},[36217],{"data":36218,"marks":36219,"value":33914,"nodeType":867},{},[],{"data":36221,"content":36222,"nodeType":876},{},[36223],{"data":36224,"marks":36225,"value":33921,"nodeType":867},{},[],{"data":36227,"content":36228,"nodeType":942},{},[],{"data":36230,"content":36231,"nodeType":868},{},[36232],{"data":36233,"marks":36234,"value":33932,"nodeType":867},{},[36235],{"type":865},{"data":36237,"content":36238,"nodeType":876},{},[36239,36242,36246],{"data":36240,"marks":36241,"value":33939,"nodeType":867},{},[],{"data":36243,"marks":36244,"value":441,"nodeType":867},{},[36245],{"type":865},{"data":36247,"marks":36248,"value":33947,"nodeType":867},{},[],{"data":36250,"content":36253,"nodeType":985},{"target":36251},{"sys":36252},{"id":33952,"type":982,"linkType":983},[],{"data":36255,"content":36256,"nodeType":876},{},[36257],{"data":36258,"marks":36259,"value":33960,"nodeType":867},{},[],{"data":36261,"content":36264,"nodeType":985},{"target":36262},{"sys":36263},{"id":33965,"type":982,"linkType":983},[],{"data":36266,"content":36267,"nodeType":876},{},[36268],{"data":36269,"marks":36270,"value":33973,"nodeType":867},{},[],{"data":36272,"content":36273,"nodeType":876},{},[36274],{"data":36275,"marks":36276,"value":33980,"nodeType":867},{},[],{"data":36278,"content":36279,"nodeType":942},{},[],{"data":36281,"content":36282,"nodeType":1058},{},[36283],{"data":36284,"marks":36285,"value":33991,"nodeType":867},{},[36286],{"type":865},{"data":36288,"content":36289,"nodeType":876},{},[36290,36293,36300],{"data":36291,"marks":36292,"value":33998,"nodeType":867},{},[],{"data":36294,"content":36295,"nodeType":915},{"uri":31118},[36296],{"data":36297,"marks":36298,"value":34006,"nodeType":867},{},[36299],{"type":913},{"data":36301,"marks":36302,"value":34010,"nodeType":867},{},[],{"data":36304,"content":36307,"nodeType":985},{"target":36305},{"sys":36306},{"id":34015,"type":982,"linkType":983},[],{"data":36309,"content":36310,"nodeType":876},{},[36311],{"data":36312,"marks":36313,"value":34023,"nodeType":867},{},[],{"data":36315,"content":36318,"nodeType":985},{"target":36316},{"sys":36317},{"id":34028,"type":982,"linkType":983},[],{"data":36320,"content":36321,"nodeType":942},{},[],{"data":36323,"content":36324,"nodeType":868},{},[36325],{"data":36326,"marks":36327,"value":34040,"nodeType":867},{},[36328],{"type":865},{"data":36330,"content":36331,"nodeType":876},{},[36332,36335,36342],{"data":36333,"marks":36334,"value":34047,"nodeType":867},{},[],{"data":36336,"content":36337,"nodeType":915},{"uri":34050},[36338],{"data":36339,"marks":36340,"value":34056,"nodeType":867},{},[36341],{"type":913},{"data":36343,"marks":36344,"value":34060,"nodeType":867},{},[],{"data":36346,"content":36349,"nodeType":985},{"target":36347},{"sys":36348},{"id":34065,"type":982,"linkType":983},[],{"data":36351,"content":36352,"nodeType":876},{},[36353],{"data":36354,"marks":36355,"value":34073,"nodeType":867},{},[],{"data":36357,"content":36360,"nodeType":985},{"target":36358},{"sys":36359},{"id":34078,"type":982,"linkType":983},[],{"data":36362,"content":36363,"nodeType":876},{},[36364,36367,36374],{"data":36365,"marks":36366,"value":34086,"nodeType":867},{},[],{"data":36368,"content":36369,"nodeType":915},{"uri":34089},[36370],{"data":36371,"marks":36372,"value":34095,"nodeType":867},{},[36373],{"type":913},{"data":36375,"marks":36376,"value":34099,"nodeType":867},{},[],{"data":36378,"content":36381,"nodeType":985},{"target":36379},{"sys":36380},{"id":34104,"type":982,"linkType":983},[],{"data":36383,"content":36386,"nodeType":985},{"target":36384},{"sys":36385},{"id":34110,"type":982,"linkType":983},[],{"data":36388,"content":36389,"nodeType":942},{},[],{"data":36391,"content":36392,"nodeType":868},{},[36393],{"data":36394,"marks":36395,"value":34122,"nodeType":867},{},[36396],{"type":865},{"data":36398,"content":36399,"nodeType":876},{},[36400],{"data":36401,"marks":36402,"value":34129,"nodeType":867},{},[],{"data":36404,"content":36405,"nodeType":876},{},[36406],{"data":36407,"marks":36408,"value":34136,"nodeType":867},{},[],{"data":36410,"content":36413,"nodeType":985},{"target":36411},{"sys":36412},{"id":34141,"type":982,"linkType":983},[],{"data":36415,"content":36416,"nodeType":942},{},[],{"data":36418,"content":36419,"nodeType":868},{},[36420],{"data":36421,"marks":36422,"value":34153,"nodeType":867},{},[36423],{"type":865},{"data":36425,"content":36426,"nodeType":876},{},[36427],{"data":36428,"marks":36429,"value":34160,"nodeType":867},{},[],{"data":36431,"content":36432,"nodeType":876},{},[36433],{"data":36434,"marks":36435,"value":34167,"nodeType":867},{},[],{"data":36437,"content":36438,"nodeType":942},{},[],{"data":36440,"content":36441,"nodeType":868},{},[36442],{"data":36443,"marks":36444,"value":34178,"nodeType":867},{},[36445],{"type":865},{"data":36447,"content":36448,"nodeType":876},{},[36449],{"data":36450,"marks":36451,"value":34185,"nodeType":867},{},[],{"data":36453,"content":36454,"nodeType":876},{},[36455],{"data":36456,"marks":36457,"value":34192,"nodeType":867},{},[],{"data":36459,"content":36462,"nodeType":985},{"target":36460},{"sys":36461},{"id":34197,"type":982,"linkType":983},[],{"data":36464,"content":36465,"nodeType":876},{},[36466],{"data":36467,"marks":36468,"value":34205,"nodeType":867},{},[],{"data":36470,"content":36471,"nodeType":1629},{},[36472,36481,36490],{"data":36473,"content":36474,"nodeType":1586},{},[36475],{"data":36476,"content":36477,"nodeType":876},{},[36478],{"data":36479,"marks":36480,"value":34218,"nodeType":867},{},[],{"data":36482,"content":36483,"nodeType":1586},{},[36484],{"data":36485,"content":36486,"nodeType":876},{},[36487],{"data":36488,"marks":36489,"value":34228,"nodeType":867},{},[],{"data":36491,"content":36492,"nodeType":1586},{},[36493],{"data":36494,"content":36495,"nodeType":876},{},[36496],{"data":36497,"marks":36498,"value":34238,"nodeType":867},{},[],{"data":36500,"content":36503,"nodeType":985},{"target":36501},{"sys":36502},{"id":34243,"type":982,"linkType":983},[],{"data":36505,"content":36506,"nodeType":1058},{},[36507],{"data":36508,"marks":36509,"value":24553,"nodeType":867},{},[36510],{"type":865},{"data":36512,"content":36513,"nodeType":876},{},[36514],{"data":36515,"marks":36516,"value":34258,"nodeType":867},{},[],{"data":36518,"content":36519,"nodeType":876},{},[36520,36523,36529],{"data":36521,"marks":36522,"value":34265,"nodeType":867},{},[],{"data":36524,"content":36525,"nodeType":915},{"uri":2689},[36526],{"data":36527,"marks":36528,"value":24568,"nodeType":867},{},[],{"data":36530,"marks":36531,"value":34275,"nodeType":867},{},[],{"items":36533},[36534,36536],{"sys":36535,"name":4018},{"id":4017},{"sys":36537,"name":342},{"id":3240},{"items":36539},[36540],{"fullName":14739,"firstName":14740,"jobTitle":14741,"profilePicture":36541},{"url":14743},{"__typename":1772,"sys":36543,"content":36544,"title":35055,"synopsis":35056,"hashTags":59,"publishedDate":35057,"slug":35058,"tagsCollection":37204,"authorsCollection":37210},{"id":34292},{"json":36545},{"data":36546,"content":36547,"nodeType":1680},{},[36548,36554,36584,36590,36606,36612,36615,36622,36628,36633,36639,36644,36649,36655,36671,36676,36682,36685,36692,36708,36729,36735,36742,36748,36754,36759,36766,36782,36798,36803,36809,36814,36821,36847,36852,36858,36861,36868,36874,36890,36896,36901,36908,36914,36920,36926,36932,36992,36998,37005,37020,37025,37031,37037,37042,37048,37053,37060,37066,37071,37076,37082,37085,37092,37118,37124,37140,37146,37156,37162,37165,37172,37188],{"data":36549,"content":36550,"nodeType":876},{},[36551],{"data":36552,"marks":36553,"value":34303,"nodeType":867},{},[],{"data":36555,"content":36556,"nodeType":1629},{},[36557,36566,36575],{"data":36558,"content":36559,"nodeType":1586},{},[36560],{"data":36561,"content":36562,"nodeType":876},{},[36563],{"data":36564,"marks":36565,"value":34316,"nodeType":867},{},[],{"data":36567,"content":36568,"nodeType":1586},{},[36569],{"data":36570,"content":36571,"nodeType":876},{},[36572],{"data":36573,"marks":36574,"value":34326,"nodeType":867},{},[],{"data":36576,"content":36577,"nodeType":1586},{},[36578],{"data":36579,"content":36580,"nodeType":876},{},[36581],{"data":36582,"marks":36583,"value":34336,"nodeType":867},{},[],{"data":36585,"content":36586,"nodeType":876},{},[36587],{"data":36588,"marks":36589,"value":34343,"nodeType":867},{},[],{"data":36591,"content":36592,"nodeType":876},{},[36593,36596,36603],{"data":36594,"marks":36595,"value":34350,"nodeType":867},{},[],{"data":36597,"content":36598,"nodeType":915},{"uri":34353},[36599],{"data":36600,"marks":36601,"value":34359,"nodeType":867},{},[36602],{"type":913},{"data":36604,"marks":36605,"value":5704,"nodeType":867},{},[],{"data":36607,"content":36608,"nodeType":876},{},[36609],{"data":36610,"marks":36611,"value":34369,"nodeType":867},{},[],{"data":36613,"content":36614,"nodeType":942},{},[],{"data":36616,"content":36617,"nodeType":868},{},[36618],{"data":36619,"marks":36620,"value":33820,"nodeType":867},{},[36621],{"type":865},{"data":36623,"content":36624,"nodeType":876},{},[36625],{"data":36626,"marks":36627,"value":34386,"nodeType":867},{},[],{"data":36629,"content":36632,"nodeType":985},{"target":36630},{"sys":36631},{"id":34391,"type":982,"linkType":983},[],{"data":36634,"content":36635,"nodeType":876},{},[36636],{"data":36637,"marks":36638,"value":34399,"nodeType":867},{},[],{"data":36640,"content":36643,"nodeType":985},{"target":36641},{"sys":36642},{"id":34404,"type":982,"linkType":983},[],{"data":36645,"content":36648,"nodeType":985},{"target":36646},{"sys":36647},{"id":34410,"type":982,"linkType":983},[],{"data":36650,"content":36651,"nodeType":876},{},[36652],{"data":36653,"marks":36654,"value":34418,"nodeType":867},{},[],{"data":36656,"content":36657,"nodeType":876},{},[36658,36661,36668],{"data":36659,"marks":36660,"value":34425,"nodeType":867},{},[],{"data":36662,"content":36663,"nodeType":915},{"uri":26236},[36664],{"data":36665,"marks":36666,"value":26242,"nodeType":867},{},[36667],{"type":913},{"data":36669,"marks":36670,"value":24243,"nodeType":867},{},[],{"data":36672,"content":36675,"nodeType":985},{"target":36673},{"sys":36674},{"id":34440,"type":982,"linkType":983},[],{"data":36677,"content":36678,"nodeType":876},{},[36679],{"data":36680,"marks":36681,"value":34448,"nodeType":867},{},[],{"data":36683,"content":36684,"nodeType":942},{},[],{"data":36686,"content":36687,"nodeType":868},{},[36688],{"data":36689,"marks":36690,"value":34459,"nodeType":867},{},[36691],{"type":865},{"data":36693,"content":36694,"nodeType":876},{},[36695,36698,36705],{"data":36696,"marks":36697,"value":34466,"nodeType":867},{},[],{"data":36699,"content":36700,"nodeType":915},{"uri":31924},[36701],{"data":36702,"marks":36703,"value":34474,"nodeType":867},{},[36704],{"type":913},{"data":36706,"marks":36707,"value":34478,"nodeType":867},{},[],{"data":36709,"content":36710,"nodeType":1629},{},[36711,36720],{"data":36712,"content":36713,"nodeType":1586},{},[36714],{"data":36715,"content":36716,"nodeType":876},{},[36717],{"data":36718,"marks":36719,"value":34491,"nodeType":867},{},[],{"data":36721,"content":36722,"nodeType":1586},{},[36723],{"data":36724,"content":36725,"nodeType":876},{},[36726],{"data":36727,"marks":36728,"value":34501,"nodeType":867},{},[],{"data":36730,"content":36731,"nodeType":876},{},[36732],{"data":36733,"marks":36734,"value":34508,"nodeType":867},{},[],{"data":36736,"content":36737,"nodeType":1058},{},[36738],{"data":36739,"marks":36740,"value":34516,"nodeType":867},{},[36741],{"type":865},{"data":36743,"content":36744,"nodeType":876},{},[36745],{"data":36746,"marks":36747,"value":34523,"nodeType":867},{},[],{"data":36749,"content":36750,"nodeType":876},{},[36751],{"data":36752,"marks":36753,"value":34530,"nodeType":867},{},[],{"data":36755,"content":36758,"nodeType":985},{"target":36756},{"sys":36757},{"id":34535,"type":982,"linkType":983},[],{"data":36760,"content":36761,"nodeType":1058},{},[36762],{"data":36763,"marks":36764,"value":34544,"nodeType":867},{},[36765],{"type":865},{"data":36767,"content":36768,"nodeType":876},{},[36769,36772,36779],{"data":36770,"marks":36771,"value":34551,"nodeType":867},{},[],{"data":36773,"content":36774,"nodeType":915},{"uri":34554},[36775],{"data":36776,"marks":36777,"value":34560,"nodeType":867},{},[36778],{"type":913},{"data":36780,"marks":36781,"value":34564,"nodeType":867},{},[],{"data":36783,"content":36784,"nodeType":876},{},[36785,36788,36795],{"data":36786,"marks":36787,"value":34571,"nodeType":867},{},[],{"data":36789,"content":36790,"nodeType":915},{"uri":34554},[36791],{"data":36792,"marks":36793,"value":34579,"nodeType":867},{},[36794],{"type":913},{"data":36796,"marks":36797,"value":34583,"nodeType":867},{},[],{"data":36799,"content":36802,"nodeType":985},{"target":36800},{"sys":36801},{"id":34588,"type":982,"linkType":983},[],{"data":36804,"content":36805,"nodeType":876},{},[36806],{"data":36807,"marks":36808,"value":34596,"nodeType":867},{},[],{"data":36810,"content":36813,"nodeType":985},{"target":36811},{"sys":36812},{"id":34601,"type":982,"linkType":983},[],{"data":36815,"content":36816,"nodeType":1058},{},[36817],{"data":36818,"marks":36819,"value":34610,"nodeType":867},{},[36820],{"type":865},{"data":36822,"content":36823,"nodeType":876},{},[36824,36827,36834,36837,36844],{"data":36825,"marks":36826,"value":34617,"nodeType":867},{},[],{"data":36828,"content":36829,"nodeType":915},{"uri":34620},[36830],{"data":36831,"marks":36832,"value":34626,"nodeType":867},{},[36833],{"type":913},{"data":36835,"marks":36836,"value":34630,"nodeType":867},{},[],{"data":36838,"content":36839,"nodeType":915},{"uri":15408},[36840],{"data":36841,"marks":36842,"value":34638,"nodeType":867},{},[36843],{"type":913},{"data":36845,"marks":36846,"value":34642,"nodeType":867},{},[],{"data":36848,"content":36851,"nodeType":985},{"target":36849},{"sys":36850},{"id":34647,"type":982,"linkType":983},[],{"data":36853,"content":36854,"nodeType":876},{},[36855],{"data":36856,"marks":36857,"value":34655,"nodeType":867},{},[],{"data":36859,"content":36860,"nodeType":942},{},[],{"data":36862,"content":36863,"nodeType":868},{},[36864],{"data":36865,"marks":36866,"value":34666,"nodeType":867},{},[36867],{"type":865},{"data":36869,"content":36870,"nodeType":876},{},[36871],{"data":36872,"marks":36873,"value":34673,"nodeType":867},{},[],{"data":36875,"content":36876,"nodeType":876},{},[36877,36880,36887],{"data":36878,"marks":36879,"value":34680,"nodeType":867},{},[],{"data":36881,"content":36882,"nodeType":915},{"uri":34683},[36883],{"data":36884,"marks":36885,"value":34689,"nodeType":867},{},[36886],{"type":913},{"data":36888,"marks":36889,"value":34693,"nodeType":867},{},[],{"data":36891,"content":36892,"nodeType":876},{},[36893],{"data":36894,"marks":36895,"value":34700,"nodeType":867},{},[],{"data":36897,"content":36900,"nodeType":985},{"target":36898},{"sys":36899},{"id":34705,"type":982,"linkType":983},[],{"data":36902,"content":36903,"nodeType":1058},{},[36904],{"data":36905,"marks":36906,"value":34714,"nodeType":867},{},[36907],{"type":865},{"data":36909,"content":36910,"nodeType":876},{},[36911],{"data":36912,"marks":36913,"value":34721,"nodeType":867},{},[],{"data":36915,"content":36916,"nodeType":876},{},[36917],{"data":36918,"marks":36919,"value":34728,"nodeType":867},{},[],{"data":36921,"content":36922,"nodeType":876},{},[36923],{"data":36924,"marks":36925,"value":34735,"nodeType":867},{},[],{"data":36927,"content":36928,"nodeType":876},{},[36929],{"data":36930,"marks":36931,"value":34742,"nodeType":867},{},[],{"data":36933,"content":36934,"nodeType":1629},{},[36935,36964,36983],{"data":36936,"content":36937,"nodeType":1586},{},[36938],{"data":36939,"content":36940,"nodeType":876},{},[36941,36944,36951,36954,36961],{"data":36942,"marks":36943,"value":34755,"nodeType":867},{},[],{"data":36945,"content":36946,"nodeType":915},{"uri":6814},[36947],{"data":36948,"marks":36949,"value":23019,"nodeType":867},{},[36950],{"type":913},{"data":36952,"marks":36953,"value":34766,"nodeType":867},{},[],{"data":36955,"content":36956,"nodeType":915},{"uri":16043},[36957],{"data":36958,"marks":36959,"value":23521,"nodeType":867},{},[36960],{"type":913},{"data":36962,"marks":36963,"value":34777,"nodeType":867},{},[],{"data":36965,"content":36966,"nodeType":1586},{},[36967],{"data":36968,"content":36969,"nodeType":876},{},[36970,36973,36980],{"data":36971,"marks":36972,"value":34787,"nodeType":867},{},[],{"data":36974,"content":36975,"nodeType":915},{"uri":34790},[36976],{"data":36977,"marks":36978,"value":34796,"nodeType":867},{},[36979],{"type":913},{"data":36981,"marks":36982,"value":34800,"nodeType":867},{},[],{"data":36984,"content":36985,"nodeType":1586},{},[36986],{"data":36987,"content":36988,"nodeType":876},{},[36989],{"data":36990,"marks":36991,"value":34810,"nodeType":867},{},[],{"data":36993,"content":36994,"nodeType":876},{},[36995],{"data":36996,"marks":36997,"value":34817,"nodeType":867},{},[],{"data":36999,"content":37000,"nodeType":1058},{},[37001],{"data":37002,"marks":37003,"value":34825,"nodeType":867},{},[37004],{"type":865},{"data":37006,"content":37007,"nodeType":876},{},[37008,37011,37017],{"data":37009,"marks":37010,"value":34832,"nodeType":867},{},[],{"data":37012,"content":37013,"nodeType":915},{"uri":34835},[37014],{"data":37015,"marks":37016,"value":34840,"nodeType":867},{},[],{"data":37018,"marks":37019,"value":34844,"nodeType":867},{},[],{"data":37021,"content":37024,"nodeType":985},{"target":37022},{"sys":37023},{"id":34849,"type":982,"linkType":983},[],{"data":37026,"content":37027,"nodeType":876},{},[37028],{"data":37029,"marks":37030,"value":34857,"nodeType":867},{},[],{"data":37032,"content":37033,"nodeType":876},{},[37034],{"data":37035,"marks":37036,"value":34864,"nodeType":867},{},[],{"data":37038,"content":37041,"nodeType":985},{"target":37039},{"sys":37040},{"id":34869,"type":982,"linkType":983},[],{"data":37043,"content":37044,"nodeType":876},{},[37045],{"data":37046,"marks":37047,"value":34877,"nodeType":867},{},[],{"data":37049,"content":37052,"nodeType":985},{"target":37050},{"sys":37051},{"id":34882,"type":982,"linkType":983},[],{"data":37054,"content":37055,"nodeType":1058},{},[37056],{"data":37057,"marks":37058,"value":34891,"nodeType":867},{},[37059],{"type":865},{"data":37061,"content":37062,"nodeType":876},{},[37063],{"data":37064,"marks":37065,"value":34898,"nodeType":867},{},[],{"data":37067,"content":37070,"nodeType":985},{"target":37068},{"sys":37069},{"id":34903,"type":982,"linkType":983},[],{"data":37072,"content":37075,"nodeType":985},{"target":37073},{"sys":37074},{"id":34909,"type":982,"linkType":983},[],{"data":37077,"content":37078,"nodeType":876},{},[37079],{"data":37080,"marks":37081,"value":34917,"nodeType":867},{},[],{"data":37083,"content":37084,"nodeType":942},{},[],{"data":37086,"content":37087,"nodeType":868},{},[37088],{"data":37089,"marks":37090,"value":16221,"nodeType":867},{},[37091],{"type":865},{"data":37093,"content":37094,"nodeType":876},{},[37095,37098,37105,37108,37115],{"data":37096,"marks":37097,"value":34934,"nodeType":867},{},[],{"data":37099,"content":37100,"nodeType":915},{"uri":15408},[37101],{"data":37102,"marks":37103,"value":28048,"nodeType":867},{},[37104],{"type":913},{"data":37106,"marks":37107,"value":1174,"nodeType":867},{},[],{"data":37109,"content":37110,"nodeType":915},{"uri":34947},[37111],{"data":37112,"marks":37113,"value":34953,"nodeType":867},{},[37114],{"type":913},{"data":37116,"marks":37117,"value":34957,"nodeType":867},{},[],{"data":37119,"content":37120,"nodeType":876},{},[37121],{"data":37122,"marks":37123,"value":34964,"nodeType":867},{},[],{"data":37125,"content":37126,"nodeType":876},{},[37127,37130,37137],{"data":37128,"marks":37129,"value":34971,"nodeType":867},{},[],{"data":37131,"content":37132,"nodeType":915},{"uri":26994},[37133],{"data":37134,"marks":37135,"value":34979,"nodeType":867},{},[37136],{"type":913},{"data":37138,"marks":37139,"value":34983,"nodeType":867},{},[],{"data":37141,"content":37142,"nodeType":876},{},[37143],{"data":37144,"marks":37145,"value":34990,"nodeType":867},{},[],{"data":37147,"content":37148,"nodeType":3804},{},[37149],{"data":37150,"content":37151,"nodeType":876},{},[37152],{"data":37153,"marks":37154,"value":35001,"nodeType":867},{},[37155],{"type":865},{"data":37157,"content":37158,"nodeType":876},{},[37159],{"data":37160,"marks":37161,"value":35008,"nodeType":867},{},[],{"data":37163,"content":37164,"nodeType":942},{},[],{"data":37166,"content":37167,"nodeType":868},{},[37168],{"data":37169,"marks":37170,"value":2541,"nodeType":867},{},[37171],{"type":865},{"data":37173,"content":37174,"nodeType":876},{},[37175,37178,37185],{"data":37176,"marks":37177,"value":35025,"nodeType":867},{},[],{"data":37179,"content":37180,"nodeType":915},{"uri":35028},[37181],{"data":37182,"marks":37183,"value":35034,"nodeType":867},{},[37184],{"type":913},{"data":37186,"marks":37187,"value":5704,"nodeType":867},{},[],{"data":37189,"content":37190,"nodeType":876},{},[37191,37194,37201],{"data":37192,"marks":37193,"value":35044,"nodeType":867},{},[],{"data":37195,"content":37196,"nodeType":915},{"uri":5286},[37197],{"data":37198,"marks":37199,"value":5291,"nodeType":867},{},[37200],{"type":913},{"data":37202,"marks":37203,"value":1679,"nodeType":867},{},[],{"items":37205},[37206,37208],{"sys":37207,"name":4018},{"id":4017},{"sys":37209,"name":342},{"id":3240},{"items":37211},[37212],{"fullName":4022,"firstName":4023,"jobTitle":4024,"profilePicture":37213},{"url":4026},{"__typename":1772,"sys":37215,"content":37216,"title":35506,"synopsis":35507,"hashTags":59,"publishedDate":35508,"slug":35509,"tagsCollection":37596,"authorsCollection":37602},{"id":35071},{"json":37217},{"data":37218,"content":37219,"nodeType":1680},{},[37220,37246,37262,37268,37274,37277,37284,37290,37295,37300,37305,37311,37327,37332,37335,37342,37348,37354,37360,37365,37371,37377,37382,37388,37404,37409,37415,37418,37425,37431,37436,37442,37483,37488,37494,37497,37504,37510,37516,37521,37526,37531,37534,37541,37547,37552,37558,37564,37567,37574,37580],{"data":37221,"content":37222,"nodeType":876},{},[37223,37226,37233,37236,37243],{"data":37224,"marks":37225,"value":21,"nodeType":867},{},[],{"data":37227,"content":37228,"nodeType":915},{"uri":23293},[37229],{"data":37230,"marks":37231,"value":31111,"nodeType":867},{},[37232],{"type":913},{"data":37234,"marks":37235,"value":35092,"nodeType":867},{},[],{"data":37237,"content":37238,"nodeType":915},{"uri":35095},[37239],{"data":37240,"marks":37241,"value":28048,"nodeType":867},{},[37242],{"type":913},{"data":37244,"marks":37245,"value":35104,"nodeType":867},{},[],{"data":37247,"content":37248,"nodeType":876},{},[37249,37252,37259],{"data":37250,"marks":37251,"value":35111,"nodeType":867},{},[],{"data":37253,"content":37254,"nodeType":915},{"uri":35114},[37255],{"data":37256,"marks":37257,"value":35120,"nodeType":867},{},[37258],{"type":913},{"data":37260,"marks":37261,"value":35124,"nodeType":867},{},[],{"data":37263,"content":37264,"nodeType":876},{},[37265],{"data":37266,"marks":37267,"value":35131,"nodeType":867},{},[],{"data":37269,"content":37270,"nodeType":876},{},[37271],{"data":37272,"marks":37273,"value":35138,"nodeType":867},{},[],{"data":37275,"content":37276,"nodeType":942},{},[],{"data":37278,"content":37279,"nodeType":868},{},[37280],{"data":37281,"marks":37282,"value":35149,"nodeType":867},{},[37283],{"type":865},{"data":37285,"content":37286,"nodeType":876},{},[37287],{"data":37288,"marks":37289,"value":35156,"nodeType":867},{},[],{"data":37291,"content":37294,"nodeType":985},{"target":37292},{"sys":37293},{"id":35161,"type":982,"linkType":983},[],{"data":37296,"content":37299,"nodeType":985},{"target":37297},{"sys":37298},{"id":35167,"type":982,"linkType":983},[],{"data":37301,"content":37304,"nodeType":985},{"target":37302},{"sys":37303},{"id":35173,"type":982,"linkType":983},[],{"data":37306,"content":37307,"nodeType":876},{},[37308],{"data":37309,"marks":37310,"value":35181,"nodeType":867},{},[],{"data":37312,"content":37313,"nodeType":876},{},[37314,37317,37324],{"data":37315,"marks":37316,"value":35188,"nodeType":867},{},[],{"data":37318,"content":37319,"nodeType":915},{"uri":35191},[37320],{"data":37321,"marks":37322,"value":35197,"nodeType":867},{},[37323],{"type":913},{"data":37325,"marks":37326,"value":35201,"nodeType":867},{},[],{"data":37328,"content":37331,"nodeType":985},{"target":37329},{"sys":37330},{"id":35206,"type":982,"linkType":983},[],{"data":37333,"content":37334,"nodeType":942},{},[],{"data":37336,"content":37337,"nodeType":868},{},[37338],{"data":37339,"marks":37340,"value":35218,"nodeType":867},{},[37341],{"type":865},{"data":37343,"content":37344,"nodeType":876},{},[37345],{"data":37346,"marks":37347,"value":35225,"nodeType":867},{},[],{"data":37349,"content":37350,"nodeType":876},{},[37351],{"data":37352,"marks":37353,"value":35232,"nodeType":867},{},[],{"data":37355,"content":37356,"nodeType":876},{},[37357],{"data":37358,"marks":37359,"value":35239,"nodeType":867},{},[],{"data":37361,"content":37364,"nodeType":985},{"target":37362},{"sys":37363},{"id":35244,"type":982,"linkType":983},[],{"data":37366,"content":37367,"nodeType":876},{},[37368],{"data":37369,"marks":37370,"value":35252,"nodeType":867},{},[],{"data":37372,"content":37373,"nodeType":876},{},[37374],{"data":37375,"marks":37376,"value":35259,"nodeType":867},{},[],{"data":37378,"content":37381,"nodeType":985},{"target":37379},{"sys":37380},{"id":35264,"type":982,"linkType":983},[],{"data":37383,"content":37384,"nodeType":876},{},[37385],{"data":37386,"marks":37387,"value":35272,"nodeType":867},{},[],{"data":37389,"content":37390,"nodeType":876},{},[37391,37394,37401],{"data":37392,"marks":37393,"value":35279,"nodeType":867},{},[],{"data":37395,"content":37396,"nodeType":915},{"uri":34554},[37397],{"data":37398,"marks":37399,"value":35287,"nodeType":867},{},[37400],{"type":913},{"data":37402,"marks":37403,"value":35291,"nodeType":867},{},[],{"data":37405,"content":37408,"nodeType":985},{"target":37406},{"sys":37407},{"id":34015,"type":982,"linkType":983},[],{"data":37410,"content":37411,"nodeType":876},{},[37412],{"data":37413,"marks":37414,"value":35303,"nodeType":867},{},[],{"data":37416,"content":37417,"nodeType":942},{},[],{"data":37419,"content":37420,"nodeType":868},{},[37421],{"data":37422,"marks":37423,"value":35314,"nodeType":867},{},[37424],{"type":865},{"data":37426,"content":37427,"nodeType":876},{},[37428],{"data":37429,"marks":37430,"value":35321,"nodeType":867},{},[],{"data":37432,"content":37435,"nodeType":985},{"target":37433},{"sys":37434},{"id":35326,"type":982,"linkType":983},[],{"data":37437,"content":37438,"nodeType":876},{},[37439],{"data":37440,"marks":37441,"value":35334,"nodeType":867},{},[],{"data":37443,"content":37444,"nodeType":1629},{},[37445,37464],{"data":37446,"content":37447,"nodeType":1586},{},[37448],{"data":37449,"content":37450,"nodeType":876},{},[37451,37454,37461],{"data":37452,"marks":37453,"value":21,"nodeType":867},{},[],{"data":37455,"content":37456,"nodeType":915},{"uri":34554},[37457],{"data":37458,"marks":37459,"value":35354,"nodeType":867},{},[37460],{"type":913},{"data":37462,"marks":37463,"value":35358,"nodeType":867},{},[],{"data":37465,"content":37466,"nodeType":1586},{},[37467],{"data":37468,"content":37469,"nodeType":876},{},[37470,37473,37480],{"data":37471,"marks":37472,"value":21,"nodeType":867},{},[],{"data":37474,"content":37475,"nodeType":915},{"uri":31924},[37476],{"data":37477,"marks":37478,"value":35375,"nodeType":867},{},[37479],{"type":913},{"data":37481,"marks":37482,"value":35379,"nodeType":867},{},[],{"data":37484,"content":37487,"nodeType":985},{"target":37485},{"sys":37486},{"id":35384,"type":982,"linkType":983},[],{"data":37489,"content":37490,"nodeType":876},{},[37491],{"data":37492,"marks":37493,"value":35392,"nodeType":867},{},[],{"data":37495,"content":37496,"nodeType":942},{},[],{"data":37498,"content":37499,"nodeType":868},{},[37500],{"data":37501,"marks":37502,"value":35403,"nodeType":867},{},[37503],{"type":865},{"data":37505,"content":37506,"nodeType":876},{},[37507],{"data":37508,"marks":37509,"value":35410,"nodeType":867},{},[],{"data":37511,"content":37512,"nodeType":876},{},[37513],{"data":37514,"marks":37515,"value":35417,"nodeType":867},{},[],{"data":37517,"content":37520,"nodeType":985},{"target":37518},{"sys":37519},{"id":35422,"type":982,"linkType":983},[],{"data":37522,"content":37525,"nodeType":985},{"target":37523},{"sys":37524},{"id":32465,"type":982,"linkType":983},[],{"data":37527,"content":37530,"nodeType":985},{"target":37528},{"sys":37529},{"id":35433,"type":982,"linkType":983},[],{"data":37532,"content":37533,"nodeType":942},{},[],{"data":37535,"content":37536,"nodeType":868},{},[37537],{"data":37538,"marks":37539,"value":35445,"nodeType":867},{},[37540],{"type":865},{"data":37542,"content":37543,"nodeType":876},{},[37544],{"data":37545,"marks":37546,"value":35452,"nodeType":867},{},[],{"data":37548,"content":37551,"nodeType":985},{"target":37549},{"sys":37550},{"id":35457,"type":982,"linkType":983},[],{"data":37553,"content":37554,"nodeType":876},{},[37555],{"data":37556,"marks":37557,"value":35465,"nodeType":867},{},[],{"data":37559,"content":37560,"nodeType":876},{},[37561],{"data":37562,"marks":37563,"value":35472,"nodeType":867},{},[],{"data":37565,"content":37566,"nodeType":942},{},[],{"data":37568,"content":37569,"nodeType":868},{},[37570],{"data":37571,"marks":37572,"value":24553,"nodeType":867},{},[37573],{"type":865},{"data":37575,"content":37576,"nodeType":876},{},[37577],{"data":37578,"marks":37579,"value":32489,"nodeType":867},{},[],{"data":37581,"content":37582,"nodeType":876},{},[37583,37586,37593],{"data":37584,"marks":37585,"value":27639,"nodeType":867},{},[],{"data":37587,"content":37588,"nodeType":915},{"uri":35497},[37589],{"data":37590,"marks":37591,"value":24568,"nodeType":867},{},[37592],{"type":913},{"data":37594,"marks":37595,"value":34275,"nodeType":867},{},[],{"items":37597},[37598,37600],{"sys":37599,"name":4018},{"id":4017},{"sys":37601,"name":342},{"id":3240},{"items":37603},[37604],{"fullName":4022,"firstName":4023,"jobTitle":4024,"profilePicture":37605},{"url":4026},"why-most-phishing-attacks-feel-like-a-zero-day","blog/why-most-phishing-attacks-feel-like-a-zero-day",{"json":37609},{"data":37610,"content":37611,"nodeType":1680},{},[37612],{"data":37613,"content":37614,"nodeType":876},{},[37615],{"data":37616,"marks":37617,"value":37618,"nodeType":867},{},[],"Most phishing attacks involve a phishing page that has never been seen before. When anti-phishing relies on detecting and blocking based on known bad, it makes every attack feel like a zero-day.","Most phishing attacks involve a phishing page that has never been seen before. When detection relies on known-bad, this makes every attack feel like a zero-day.",{"id":37621,"publishedAt":37622},"7JngmuGwqKvYLzU8bGMTQD","2026-08-12T11:54:15.444Z",{"items":37624},[37625,37627],{"sys":37626,"name":342},{"id":3240},{"sys":37628,"name":4018},{"id":4017},{"items":37630},[37631,37633,37635,37637,37639,37641,37643,37645,37647,37649,37651,37653,37655],{"sys":37632,"name":519,"slug":520,"tier":31},{"id":516},{"sys":37634,"name":279,"slug":280,"tier":31},{"id":276},{"sys":37636,"name":342,"slug":343,"tier":31},{"id":339},{"sys":37638,"name":297,"slug":298,"tier":31},{"id":294},{"sys":37640,"name":413,"slug":414,"tier":31},{"id":410},{"sys":37642,"name":351,"slug":352,"tier":45},{"id":348},{"sys":37644,"name":324,"slug":325,"tier":45},{"id":321},{"sys":37646,"name":261,"slug":262,"tier":45},{"id":258},{"sys":37648,"name":511,"slug":512,"tier":45},{"id":508},{"sys":37650,"name":466,"slug":467,"tier":45},{"id":463},{"sys":37652,"name":475,"slug":476,"tier":45},{"id":472},{"sys":37654,"name":377,"slug":378,"tier":45},{"id":374},{"sys":37656,"name":624,"slug":625,"tier":45},{"id":621},"_hVeJr0vFCPFcnV5XxbOSgDCp9AT_ABzf5fAJPmLcuI",{"id":37659,"title":37660,"authorsCollection":37661,"content":37669,"extension":228,"faqItemsCollection":37829,"faqTitle":59,"featured":6,"hashTags":59,"meta":37831,"metaTitle":37832,"ogImage":59,"postType":37833,"publishedDate":37834,"relatedBlogPostsCollection":37835,"slug":39252,"stem":39253,"subtitle":59,"summary":39254,"synopsis":39265,"sys":39266,"tagsCollection":39269,"topicsCollection":39275,"__hash__":39283},"blog/blog/why-im-joining-push-security-the-team-redefining-itdr.json","Why I’m joining Push Security, from our new Chief Revenue Officer",{"items":37662},[37663],{"fullName":37664,"firstName":37665,"jobTitle":37666,"socialLinks":59,"profilePicture":37667},"Kevin Arsenault","Kevin","Chief Revenue Officer",{"url":37668},"https://images.ctfassets.net/y1cdw1ablpvd/4zJDawMiFCxIXpAZpb5TJn/3f018223f2ad11a75cea33339a8f66a2/image__21_.png",{"json":37670,"links":37824},{"data":37671,"content":37672,"nodeType":1680},{},[37673,37680,37696,37703,37710,37717,37724,37731,37747,37754,37779,37798,37805],{"data":37674,"content":37675,"nodeType":876},{},[37676],{"data":37677,"marks":37678,"value":37679,"nodeType":867},{},[],"Over the course of my career, I have had the chance to work with some incredible teams at places like Proofpoint and CrowdStrike, both of which were trailblazers in protecting clients from advanced adversary attacks. As I take on this new role at Push Security, I am excited to be joining another team where the foresight into how cyber attacks are evolving is front and center. As attackers shift to infiltrating organizations via user identities, Push is meeting that shift by pioneering a new approach in the identity threat detection and response (ITDR) space, with browser-based identity protection. ",{"data":37681,"content":37682,"nodeType":876},{},[37683,37687,37692],{"data":37684,"marks":37685,"value":37686,"nodeType":867},{},[],"When I first sat down with our CEO Adam Bateman and heard his vision, it was clear to me that Push recognizes that attacks are evolving and the bad actors have set their sights on the new perimeter – identity. Recent attacks making headlines, like the Snowflake incident over the summer, make it clear that cyber attacks are fundamentally changing. It’s a bit of a cliche, but hackers don’t hack in anymore, they",{"data":37688,"marks":37689,"value":37691,"nodeType":867},{},[37690],{"type":1303}," log in",{"data":37693,"marks":37694,"value":37695,"nodeType":867},{},[],". Push is at the forefront of tackling this problem in a way that no one else is addressing. Our approach to browser telemetry is a game-changer in the way we can approach and defend against identity attacks.",{"data":37697,"content":37698,"nodeType":1058},{},[37699],{"data":37700,"marks":37701,"value":37702,"nodeType":867},{},[],"Legacy ITDR-aligned solutions feel like bolt-ons, not true problem solvers",{"data":37704,"content":37705,"nodeType":876},{},[37706],{"data":37707,"marks":37708,"value":37709,"nodeType":867},{},[],"Talking with industry friends and advisors before taking this new role confirmed what I believe: that Push has the potential to drive a much-needed evolution in identity security. The modern ITDR space is still relatively early, with many pain points around the blind spots of existing tools and a less-than-satisfactory state of SaaS logging, leaving many security teams in the dark. ",{"data":37711,"content":37712,"nodeType":876},{},[37713],{"data":37714,"marks":37715,"value":37716,"nodeType":867},{},[],"In a world dominated by vendors who have lost focus on providing best-of-breed features designed for specific problems in favor of very broad product portfolios that try to solve everything-everywhere-all-at-once, ITDR is not yet a problem space that is being adequately served by traditional vendors and tools. ",{"data":37718,"content":37719,"nodeType":876},{},[37720],{"data":37721,"marks":37722,"value":37723,"nodeType":867},{},[],"Push Security’s unique solution has the power to move the industry forward in ways that could set new standards for gathering deeper data on these attacks, as well as responding and intercepting them as they happen – just as EDR did a decade ago.",{"data":37725,"content":37726,"nodeType":876},{},[37727],{"data":37728,"marks":37729,"value":37730,"nodeType":867},{},[],"When I joined Proofpoint, I decided to leave my desk behind to carry a bag and get on the road. This gave me a first hand view of what challenges security teams were facing and what was necessary to help solve them. It put me at the cross section of cyber security and compliance, and we built teams and solutions that made it possible for organizations to achieve these milestones. ",{"data":37732,"content":37733,"nodeType":876},{},[37734,37738,37743],{"data":37735,"marks":37736,"value":37737,"nodeType":867},{},[],"I then had an incredible opportunity to do it all over again with CrowdStrike, where I joined a very talented early team and witnessed the explosive growth in EDR. I see a parallel here with Push; nobody knew they needed EDR until new vendors brought it forward. At the time, the critics said ‘",{"data":37739,"marks":37740,"value":37742,"nodeType":867},{},[37741],{"type":1303},"hey, we’re good with anti-virus, why would we need anything else?",{"data":37744,"marks":37745,"value":37746,"nodeType":867},{},[],"’ Of course, you’d be laughed out of the room for holding the same view today. Similarly, I believe we’ll see security products in the browser become equally indispensable. ",{"data":37748,"content":37749,"nodeType":1058},{},[37750],{"data":37751,"marks":37752,"value":37753,"nodeType":867},{},[],"Push can be a power tool for security teams",{"data":37755,"content":37756,"nodeType":876},{},[37757,37761,37766,37770,37775],{"data":37758,"marks":37759,"value":37760,"nodeType":867},{},[],"Getting access to browser telemetry in a smart, impactful way has been a tough nut to crack, but Push is bringing it front-and-center. It’s one of those things that makes you think: ",{"data":37762,"marks":37763,"value":37765,"nodeType":867},{},[37764],{"type":1303},"‘why hasn’t this been done before?’",{"data":37767,"marks":37768,"value":37769,"nodeType":867},{},[]," And from my initial conversations with Push customers you see the mirror of this: ",{"data":37771,"marks":37772,"value":37774,"nodeType":867},{},[37773],{"type":1303},"‘could you imagine going back to life without it?’",{"data":37776,"marks":37777,"value":37778,"nodeType":867},{},[]," Seeing and hearing just how customers love Push, and how they have developed a solution that is both secure and highly scalable, gives me confidence in what the future holds for our team. ",{"data":37780,"content":37781,"nodeType":876},{},[37782,37786,37795],{"data":37783,"marks":37784,"value":37785,"nodeType":867},{},[],"And it’s not just about being in the browser, it’s what you do with it that is important. When you look at the backgrounds of the Push Security founders and their offensive security heritage, you can see how and why they are thinking about applying these new capabilities to drive SecOps teams and processes. It’s not just about box-ticking; it’s about genuinely hitting attackers where it hurts and making a meaningful difference to disrupting identity attacks – the #1 threat facing organizations today and responsible for nearly ",{"data":37787,"content":37789,"nodeType":915},{"uri":37788},"https://pushsecurity.com/blog/identity-attacks-in-the-wild/",[37790],{"data":37791,"marks":37792,"value":37794,"nodeType":867},{},[37793],{"type":913},"75 percent of today’s breaches according to some industry estimates",{"data":37796,"marks":37797,"value":1679,"nodeType":867},{},[],{"data":37799,"content":37800,"nodeType":876},{},[37801],{"data":37802,"marks":37803,"value":37804,"nodeType":867},{},[],"My career has always been about working with people, building strong teams, and creating environments where everyone feels they’re contributing to a powerful mission. Having learned from and worked with some of the best, I am proud of the culture I helped create at past companies, and I see the same potential at Push. It’s early days, and that’s exactly where I love to be. ",{"data":37806,"content":37807,"nodeType":876},{},[37808,37812,37821],{"data":37809,"marks":37810,"value":37811,"nodeType":867},{},[],"Push Security really is on the cusp of something transformative, and I’m ready to jump in, bring my experience, and help lead the charge in this next chapter of identity-first security. If you would like to learn more about what we are doing at Push and how we can help your organization, connect with me on ",{"data":37813,"content":37815,"nodeType":915},{"uri":37814},"https://www.linkedin.com/in/karsenault1/",[37816],{"data":37817,"marks":37818,"value":37820,"nodeType":867},{},[37819],{"type":913},"LinkedIn",{"data":37822,"marks":37823,"value":1679,"nodeType":867},{},[],{"entries":37825},{"hyperlink":37826,"block":37827,"inline":37828},[],[],[],{"items":37830},[],{},"Kevin Arsenault joins Push Security as Chief Revenue Officer","company-news","2024-11-21T00:00:00.000Z",{"items":37836},[37837,38159,38445],{"__typename":1772,"sys":37838,"content":37840,"title":38145,"synopsis":38146,"hashTags":59,"publishedDate":38147,"slug":38148,"tagsCollection":38149,"authorsCollection":38155},{"id":37839},"2oCKAlWLSHMLeZF6j8YniH",{"json":37841},{"data":37842,"content":37843,"nodeType":1680},{},[37844,37851,37858,37865,37872,37879,37886,37893,37898,37905,37912,37919,37926,37933,37953,37960,37967,37984,37991,38002,38009,38041,38048,38055,38062,38069,38074,38081,38088,38095,38102,38109,38115,38133,38139],{"data":37845,"content":37846,"nodeType":876},{},[37847],{"data":37848,"marks":37849,"value":37850,"nodeType":867},{},[],"There are many factors that can make a user account vulnerable to identity-based attack techniques. Using Push data, we calculated how many vulnerable identities the average organization has, showing how different vulnerabilities leave an identity exposed to different methods of account takeover. ",{"data":37852,"content":37853,"nodeType":868},{},[37854],{"data":37855,"marks":37856,"value":37857,"nodeType":867},{},[],"Our dataset",{"data":37859,"content":37860,"nodeType":876},{},[37861],{"data":37862,"marks":37863,"value":37864,"nodeType":867},{},[],"This analysis is based on a snapshot of when organizations begin using the Push platform, once enrollment has completed. Data from trial and partially deployed organizations is excluded. ",{"data":37866,"content":37867,"nodeType":876},{},[37868],{"data":37869,"marks":37870,"value":37871,"nodeType":867},{},[],"Early adopters of new identity security products like Push are likely to have a higher than average level of maturity in this area – even prior to using Push. So, the findings may not be accurate for all organizations, particularly those with lower awareness of identity security challenges. ",{"data":37873,"content":37874,"nodeType":876},{},[37875],{"data":37876,"marks":37877,"value":37878,"nodeType":867},{},[],"It’s also worth noting that passwordless authentication makes up a very small percentage of the overall authentication factors detected. If you’re in the minority of organizations that have widely adopted something like passkeys or biometric authentication, your identity posture will probably look quite different. But, you should still be wary of backup phishable factors and SSO gaps – more on this below.",{"data":37880,"content":37881,"nodeType":868},{},[37882],{"data":37883,"marks":37884,"value":37885,"nodeType":867},{},[],"Identity configurations and how they can be exploited",{"data":37887,"content":37888,"nodeType":876},{},[37889],{"data":37890,"marks":37891,"value":37892,"nodeType":867},{},[],"We analyzed a sample dataset of 300,000 accounts and the associated login methods – this is what we found. ",{"data":37894,"content":37897,"nodeType":985},{"target":37895},{"sys":37896},{"id":24854,"type":982,"linkType":983},[],{"data":37899,"content":37900,"nodeType":876},{},[37901],{"data":37902,"marks":37903,"value":37904,"nodeType":867},{},[],"Some of the key insights are explored below. ",{"data":37906,"content":37907,"nodeType":1058},{},[37908],{"data":37909,"marks":37910,"value":37911,"nodeType":867},{},[],"Organizations are using more apps and identities than they realize",{"data":37913,"content":37914,"nodeType":876},{},[37915],{"data":37916,"marks":37917,"value":37918,"nodeType":867},{},[],"On average, each employee has ~15 identities tied to the business apps that they use, and each organization uses ~220 apps. The number of apps per organization doesn't show a strong correlation with the size of the organization. But, the number of accounts per user does tend to be lower for organizations with a larger employee base. ",{"data":37920,"content":37921,"nodeType":1058},{},[37922],{"data":37923,"marks":37924,"value":37925,"nodeType":867},{},[],"Many accounts lack the most basic protections",{"data":37927,"content":37928,"nodeType":876},{},[37929],{"data":37930,"marks":37931,"value":37932,"nodeType":867},{},[],"37% of all accounts do not have MFA set, while ~9% of accounts with a password also have a breached, weak, or reused password, making them highly susceptible to account takeover. ",{"data":37934,"content":37935,"nodeType":876},{},[37936,37940,37949],{"data":37937,"marks":37938,"value":37939,"nodeType":867},{},[],"This might not seem that high at face value – but it’s enough that attackers can feasibly take over accounts linked to every business app used in the organization just by abusing password vulnerabilities through attacks like ",{"data":37941,"content":37943,"nodeType":915},{"uri":37942},"https://pushsecurity.com/blog/what-is-credential-stuffing/",[37944],{"data":37945,"marks":37946,"value":37948,"nodeType":867},{},[37947],{"type":913},"credential stuffing",{"data":37950,"marks":37951,"value":37952,"nodeType":867},{},[],". For a 1,000 user organization, this leaves them with 1,367 user accounts that are highly vulnerable to account takeover.",{"data":37954,"content":37955,"nodeType":876},{},[37956],{"data":37957,"marks":37958,"value":37959,"nodeType":867},{},[],"The situation gets worse when a password is the sole login method set, with these accounts lacking MFA in 4 out of 5 cases. ",{"data":37961,"content":37962,"nodeType":1058},{},[37963],{"data":37964,"marks":37965,"value":37966,"nodeType":867},{},[],"SSO is not a silver bullet",{"data":37968,"content":37969,"nodeType":876},{},[37970,37974,37981],{"data":37971,"marks":37972,"value":37973,"nodeType":867},{},[],"SSO can be used to reduce an organization's susceptibility to password-based attacks, but the vast majority (97%) of SSO logins track back to an original password login to an IdP (due to the marginal use of passwordless authentication) while in 10% of cases a local password login is set alongside SSO – potentially introducing ",{"data":37975,"content":37976,"nodeType":915},{"uri":2924},[37977],{"data":37978,"marks":37979,"value":2929,"nodeType":867},{},[37980],{"type":913},{"data":37982,"marks":37983,"value":1679,"nodeType":867},{},[],{"data":37985,"content":37986,"nodeType":876},{},[37987],{"data":37988,"marks":37989,"value":37990,"nodeType":867},{},[],"You might expect these password-based logins to be highly scrutinized due to the criticality of these accounts – but we found that 1 in 5 IdP accounts is missing MFA, and a non-unique password is present for 10% of IdP accounts (meaning that if the same username and password combination is compromised on another app, the risk of a lateral account compromise is much higher). ",{"data":37992,"content":37993,"nodeType":876},{},[37994,37998],{"data":37995,"marks":37996,"value":37997,"nodeType":867},{},[],"Since Microsoft, Okta, and Google IdP accounts are the most targeted identities by attackers due to their value if compromised, these accounts are under a huge amount of pressure from attackers – ",{"data":37999,"marks":38000,"value":38001,"nodeType":867},{},[],"multiplying the risk to single factor authentication IdP accounts.",{"data":38003,"content":38004,"nodeType":1058},{},[38005],{"data":38006,"marks":38007,"value":38008,"nodeType":867},{},[],"Pretty much all identities can be phished",{"data":38010,"content":38011,"nodeType":876},{},[38012,38016,38025,38029,38037],{"data":38013,"marks":38014,"value":38015,"nodeType":867},{},[],"Almost all identities (~99%) are susceptible to phishing attacks – either because MFA is missing, or the types of MFA implemented are weak to modern phishing attacks such as ",{"data":38017,"content":38019,"nodeType":915},{"uri":38018},"https://pushsecurity.com/blog/phishing-2-0-how-phishing-toolkits-are-evolving-with-aitm/",[38020],{"data":38021,"marks":38022,"value":38024,"nodeType":867},{},[38023],{"type":913},"Adversary in the Middle (AitM) phishing kits",{"data":38026,"marks":38027,"value":38028,"nodeType":867},{},[],", or techniques such as ",{"data":38030,"content":38032,"nodeType":915},{"uri":38031},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/mfa_fatigue/description.md",[38033],{"data":38034,"marks":38035,"value":38036,"nodeType":867},{},[],"MFA fatigue",{"data":38038,"marks":38039,"value":38040,"nodeType":867},{},[],". The most common MFA methods are phone call, push notification, and one-time passcode – all of which are phishable or bypassable. ",{"data":38042,"content":38043,"nodeType":876},{},[38044],{"data":38045,"marks":38046,"value":38047,"nodeType":867},{},[],"Even in the small number of cases where we identified a passwordless authentication method that is regarded as phishing-resistant (e.g. passkeys, biometrics, etc.) there is a backup, phishable method set for over half of them. ",{"data":38049,"content":38050,"nodeType":868},{},[38051],{"data":38052,"marks":38053,"value":38054,"nodeType":867},{},[],"So... what does this mean in real terms? ",{"data":38056,"content":38057,"nodeType":876},{},[38058],{"data":38059,"marks":38060,"value":38061,"nodeType":867},{},[],"The main conclusion from the data is that identity vulnerabilities exist almost everywhere. Some are certainly more likely to be exploited than others (e.g. an account with a reused password and no MFA is a higher risk than an account with MFA) but attackers have the means to take over most accounts using widely available tooling and know-how. ",{"data":38063,"content":38064,"nodeType":876},{},[38065],{"data":38066,"marks":38067,"value":38068,"nodeType":867},{},[],"To bring this to life, here’s an infographic representing the identity attack surface for a 1,000 seat organization. ",{"data":38070,"content":38073,"nodeType":985},{"target":38071},{"sys":38072},{"id":26308,"type":982,"linkType":983},[],{"data":38075,"content":38076,"nodeType":876},{},[38077],{"data":38078,"marks":38079,"value":38080,"nodeType":867},{},[],"This shows that investing in your identity security baseline only gets you so far – ultimately, you need to be prepared to detect and respond to attacks rather than relying on prevention alone. That said, progress over perfection should always be the aim when it comes to posture management, and shoring up your identity vulnerabilities is an important long-term project. ",{"data":38082,"content":38083,"nodeType":868},{},[38084],{"data":38085,"marks":38086,"value":38087,"nodeType":867},{},[],"Detection and response is the key",{"data":38089,"content":38090,"nodeType":876},{},[38091],{"data":38092,"marks":38093,"value":38094,"nodeType":867},{},[],"Looking at the scale of the challenge, it’s pretty clear that completely scrubbing your workforce identities of all possible vulnerabilities isn’t really an achievable goal. A strong baseline is important, but it will only ever get you so far. Rather than playing whack-a-mole, organizations need to prepare to detect and respond to the techniques and tools being used by attackers when they exploit these vulnerabilities.  ",{"data":38096,"content":38097,"nodeType":876},{},[38098],{"data":38099,"marks":38100,"value":38101,"nodeType":867},{},[],"This is nothing new – this approach has been preached by security operations leaders for more than a decade. But until now, identity security has been much more focused on prevention than detection and response. And with attackers increasingly turning to identity attacks, the sheer volume of identity vulnerabilities (and the rate that they are introduced) means that posture management alone isn’t sufficient.",{"data":38103,"content":38104,"nodeType":876},{},[38105],{"data":38106,"marks":38107,"value":38108,"nodeType":867},{},[],"Like endpoint and network security before, you can no longer rely on prevention alone, and organizations need to ensure they can detect and respond to indicators of identity attacks to be able to manage the risk effectively. ",{"data":38110,"content":38111,"nodeType":868},{},[38112],{"data":38113,"marks":38114,"value":2541,"nodeType":867},{},[],{"data":38116,"content":38117,"nodeType":876},{},[38118,38122,38130],{"data":38119,"marks":38120,"value":38121,"nodeType":867},{},[],"Push helps organizations to detect and prevent identity attacks as they happen, by intercepting and shutting down attacks in the browser. It also provides valuable data to find and fix identity vulnerabilities before they can be exploited. ",{"data":38123,"content":38124,"nodeType":915},{"uri":5286},[38125],{"data":38126,"marks":38127,"value":38129,"nodeType":867},{},[38128],{"type":913},"Book a demo here to find out more.",{"data":38131,"marks":38132,"value":21,"nodeType":867},{},[],{"data":38134,"content":38138,"nodeType":985},{"target":38135},{"sys":38136},{"id":38137,"type":982,"linkType":983},"11p9wnGrZHqp3XPpThHFk3",[],{"data":38140,"content":38141,"nodeType":876},{},[38142],{"data":38143,"marks":38144,"value":21,"nodeType":867},{},[],"How many vulnerable identities do you have?","Using Push data to calculate how many vulnerable identities the average organization has, and how they lead to different methods of account takeover. ","2024-10-15T00:00:00.000Z","how-many-vulnerable-identities-do-you-have",{"items":38150},[38151,38153],{"sys":38152,"name":4018},{"id":4017},{"sys":38154,"name":342},{"id":3240},{"items":38156},[38157],{"fullName":4022,"firstName":4023,"jobTitle":4024,"profilePicture":38158},{"url":4026},{"__typename":1772,"sys":38160,"content":38161,"title":24585,"synopsis":24586,"hashTags":59,"publishedDate":24587,"slug":24588,"tagsCollection":38435,"authorsCollection":38441},{"id":24268},{"json":38162},{"data":38163,"content":38164,"nodeType":1680},{},[38165,38171,38187,38200,38206,38212,38215,38221,38227,38275,38281,38286,38289,38295,38301,38307,38313,38319,38333,38338,38344,38350,38364,38369,38375,38381,38387,38393,38399,38402,38408,38424,38429],{"data":38166,"content":38167,"nodeType":868},{},[38168],{"data":38169,"marks":38170,"value":24279,"nodeType":867},{},[],{"data":38172,"content":38173,"nodeType":876},{},[38174,38177,38184],{"data":38175,"marks":38176,"value":24286,"nodeType":867},{},[],{"data":38178,"content":38179,"nodeType":915},{"uri":967},[38180],{"data":38181,"marks":38182,"value":24294,"nodeType":867},{},[38183],{"type":913},{"data":38185,"marks":38186,"value":5704,"nodeType":867},{},[],{"data":38188,"content":38189,"nodeType":876},{},[38190,38193,38197],{"data":38191,"marks":38192,"value":24304,"nodeType":867},{},[],{"data":38194,"marks":38195,"value":24309,"nodeType":867},{},[38196],{"type":913},{"data":38198,"marks":38199,"value":24313,"nodeType":867},{},[],{"data":38201,"content":38202,"nodeType":876},{},[38203],{"data":38204,"marks":38205,"value":24320,"nodeType":867},{},[],{"data":38207,"content":38208,"nodeType":876},{},[38209],{"data":38210,"marks":38211,"value":24327,"nodeType":867},{},[],{"data":38213,"content":38214,"nodeType":942},{},[],{"data":38216,"content":38217,"nodeType":1058},{},[38218],{"data":38219,"marks":38220,"value":24337,"nodeType":867},{},[],{"data":38222,"content":38223,"nodeType":876},{},[38224],{"data":38225,"marks":38226,"value":24344,"nodeType":867},{},[],{"data":38228,"content":38229,"nodeType":1629},{},[38230,38239,38248,38257,38266],{"data":38231,"content":38232,"nodeType":1586},{},[38233],{"data":38234,"content":38235,"nodeType":876},{},[38236],{"data":38237,"marks":38238,"value":24357,"nodeType":867},{},[],{"data":38240,"content":38241,"nodeType":1586},{},[38242],{"data":38243,"content":38244,"nodeType":876},{},[38245],{"data":38246,"marks":38247,"value":24367,"nodeType":867},{},[],{"data":38249,"content":38250,"nodeType":1586},{},[38251],{"data":38252,"content":38253,"nodeType":876},{},[38254],{"data":38255,"marks":38256,"value":24377,"nodeType":867},{},[],{"data":38258,"content":38259,"nodeType":1586},{},[38260],{"data":38261,"content":38262,"nodeType":876},{},[38263],{"data":38264,"marks":38265,"value":24387,"nodeType":867},{},[],{"data":38267,"content":38268,"nodeType":1586},{},[38269],{"data":38270,"content":38271,"nodeType":876},{},[38272],{"data":38273,"marks":38274,"value":24397,"nodeType":867},{},[],{"data":38276,"content":38277,"nodeType":876},{},[38278],{"data":38279,"marks":38280,"value":24404,"nodeType":867},{},[],{"data":38282,"content":38285,"nodeType":985},{"target":38283},{"sys":38284},{"id":24409,"type":982,"linkType":983},[],{"data":38287,"content":38288,"nodeType":942},{},[],{"data":38290,"content":38291,"nodeType":1058},{},[38292],{"data":38293,"marks":38294,"value":24420,"nodeType":867},{},[],{"data":38296,"content":38297,"nodeType":876},{},[38298],{"data":38299,"marks":38300,"value":24427,"nodeType":867},{},[],{"data":38302,"content":38303,"nodeType":876},{},[38304],{"data":38305,"marks":38306,"value":24434,"nodeType":867},{},[],{"data":38308,"content":38309,"nodeType":876},{},[38310],{"data":38311,"marks":38312,"value":24441,"nodeType":867},{},[],{"data":38314,"content":38315,"nodeType":876},{},[38316],{"data":38317,"marks":38318,"value":24448,"nodeType":867},{},[],{"data":38320,"content":38321,"nodeType":1058},{},[38322,38325,38330],{"data":38323,"marks":38324,"value":24455,"nodeType":867},{},[],{"data":38326,"marks":38327,"value":24461,"nodeType":867},{},[38328,38329],{"type":913},{"type":865},{"data":38331,"marks":38332,"value":24465,"nodeType":867},{},[],{"data":38334,"content":38337,"nodeType":985},{"target":38335},{"sys":38336},{"id":24470,"type":982,"linkType":983},[],{"data":38339,"content":38340,"nodeType":876},{},[38341],{"data":38342,"marks":38343,"value":24478,"nodeType":867},{},[],{"data":38345,"content":38346,"nodeType":876},{},[38347],{"data":38348,"marks":38349,"value":24485,"nodeType":867},{},[],{"data":38351,"content":38352,"nodeType":1058},{},[38353,38356,38361],{"data":38354,"marks":38355,"value":24492,"nodeType":867},{},[],{"data":38357,"marks":38358,"value":24498,"nodeType":867},{},[38359,38360],{"type":913},{"type":865},{"data":38362,"marks":38363,"value":24502,"nodeType":867},{},[],{"data":38365,"content":38368,"nodeType":985},{"target":38366},{"sys":38367},{"id":24507,"type":982,"linkType":983},[],{"data":38370,"content":38371,"nodeType":876},{},[38372],{"data":38373,"marks":38374,"value":24515,"nodeType":867},{},[],{"data":38376,"content":38377,"nodeType":876},{},[38378],{"data":38379,"marks":38380,"value":24522,"nodeType":867},{},[],{"data":38382,"content":38383,"nodeType":876},{},[38384],{"data":38385,"marks":38386,"value":24529,"nodeType":867},{},[],{"data":38388,"content":38389,"nodeType":876},{},[38390],{"data":38391,"marks":38392,"value":24536,"nodeType":867},{},[],{"data":38394,"content":38395,"nodeType":876},{},[38396],{"data":38397,"marks":38398,"value":24543,"nodeType":867},{},[],{"data":38400,"content":38401,"nodeType":942},{},[],{"data":38403,"content":38404,"nodeType":868},{},[38405],{"data":38406,"marks":38407,"value":24553,"nodeType":867},{},[],{"data":38409,"content":38410,"nodeType":876},{},[38411,38414,38421],{"data":38412,"marks":38413,"value":24560,"nodeType":867},{},[],{"data":38415,"content":38416,"nodeType":915},{"uri":5286},[38417],{"data":38418,"marks":38419,"value":24568,"nodeType":867},{},[38420],{"type":913},{"data":38422,"marks":38423,"value":24572,"nodeType":867},{},[],{"data":38425,"content":38428,"nodeType":985},{"target":38426},{"sys":38427},{"id":24577,"type":982,"linkType":983},[],{"data":38430,"content":38431,"nodeType":876},{},[38432],{"data":38433,"marks":38434,"value":21,"nodeType":867},{},[],{"items":38436},[38437,38439],{"sys":38438,"name":4018},{"id":4017},{"sys":38440,"name":342},{"id":3240},{"items":38442},[38443],{"fullName":4089,"firstName":4090,"jobTitle":851,"profilePicture":38444},{"url":4094},{"__typename":1772,"sys":38446,"content":38448,"title":39236,"synopsis":39237,"hashTags":59,"publishedDate":39238,"slug":39239,"tagsCollection":39240,"authorsCollection":39248},{"id":38447},"20FcoPvHu7zXkTQyv9MmK0",{"json":38449},{"data":38450,"content":38451,"nodeType":1680},{},[38452,38458,38465,38516,38523,38530,38545,38552,38559,38642,38649,38655,38662,38669,38684,38691,38698,38721,38745,38751,38771,38778,38785,38816,38823,38830,38836,38854,38861,38868,38875,38882,38888,38906,38913,38920,38927,38934,38940,38959,38966,38973,38979,38998,39005,39012,39019,39067,39074,39145,39160,39166,39173,39180,39187,39194,39212,39218],{"data":38453,"content":38457,"nodeType":985},{"target":38454},{"sys":38455},{"id":38456,"type":982,"linkType":983},"7rud2H1hcTAOhxh9zHzxP6",[],{"data":38459,"content":38460,"nodeType":876},{},[38461],{"data":38462,"marks":38463,"value":38464,"nodeType":867},{},[],"If someone asked you where you work, you probably wouldn’t answer, “My browser.” But that would be the truth.",{"data":38466,"content":38467,"nodeType":876},{},[38468,38472,38480,38483,38491,38494,38501,38504,38512],{"data":38469,"marks":38470,"value":38471,"nodeType":867},{},[],"(Threat actors already know where you work, of course, and they’ve been capitalizing on the massive shift to cloud-based workforces. Just look at any of the ",{"data":38473,"content":38475,"nodeType":915},{"uri":38474},"https://www.crowdstrike.com/global-threat-report/",[38476],{"data":38477,"marks":38478,"value":38479,"nodeType":867},{},[],"latest",{"data":38481,"marks":38482,"value":2136,"nodeType":867},{},[],{"data":38484,"content":38486,"nodeType":915},{"uri":38485},"https://redcanary.com/threat-detection-report/techniques/cloud-accounts/",[38487],{"data":38488,"marks":38489,"value":38490,"nodeType":867},{},[],"threat",{"data":38492,"marks":38493,"value":2136,"nodeType":867},{},[],{"data":38495,"content":38496,"nodeType":915},{"uri":2177},[38497],{"data":38498,"marks":38499,"value":38500,"nodeType":867},{},[],"research",{"data":38502,"marks":38503,"value":2136,"nodeType":867},{},[],{"data":38505,"content":38507,"nodeType":915},{"uri":38506},"https://www.lab539.com/blog/6-months-tracking-aitm-campaigns",[38508],{"data":38509,"marks":38510,"value":38511,"nodeType":867},{},[],"reports",{"data":38513,"marks":38514,"value":38515,"nodeType":867},{},[]," on identity-based attacks to see how good a job they’ve been doing.)",{"data":38517,"content":38518,"nodeType":876},{},[38519],{"data":38520,"marks":38521,"value":38522,"nodeType":867},{},[],"To get visibility of your infrastructure in order to build a strong detection and response program, the equation used to look something like:",{"data":38524,"content":38525,"nodeType":876},{},[38526],{"data":38527,"marks":38528,"value":38529,"nodeType":867},{},[],"Network traffic + Logs + Endpoints = Profit!",{"data":38531,"content":38532,"nodeType":876},{},[38533,38537,38542],{"data":38534,"marks":38535,"value":38536,"nodeType":867},{},[],"But now there’s a missing piece, as identity infrastructure sprawls across IdPs, core apps, shadow SaaS and third-party integrations: ",{"data":38538,"marks":38539,"value":38541,"nodeType":867},{},[38540],{"type":865},"Browser telemetry",{"data":38543,"marks":38544,"value":1679,"nodeType":867},{},[],{"data":38546,"content":38547,"nodeType":876},{},[38548],{"data":38549,"marks":38550,"value":38551,"nodeType":867},{},[],"As a browser agent, Push is uniquely positioned to provide telemetry you can’t easily get anywhere else. We believe that this missing piece is the key to stopping identity attacks by providing the context both for first-class detections and security controls, as well as key correlations for events you observe in traditional log sources.",{"data":38553,"content":38554,"nodeType":876},{},[38555],{"data":38556,"marks":38557,"value":38558,"nodeType":867},{},[],"Now we have a better way to bring Push’s data to life to solve meaningful security challenges:",{"data":38560,"content":38561,"nodeType":1629},{},[38562,38591],{"data":38563,"content":38564,"nodeType":1586},{},[38565],{"data":38566,"content":38567,"nodeType":876},{},[38568,38573,38577,38587],{"data":38569,"marks":38570,"value":38572,"nodeType":867},{},[38571],{"type":865},"Plug-and-play security controls",{"data":38574,"marks":38575,"value":38576,"nodeType":867},{},[],", accessible from the new ",{"data":38578,"content":38582,"nodeType":17452},{"target":38579},{"sys":38580},{"id":38581,"type":982,"linkType":983},"BtDLgVZRWQ3Ov4WgDQX1W",[38583],{"data":38584,"marks":38585,"value":25043,"nodeType":867},{},[38586],{"type":865},{"data":38588,"marks":38589,"value":38590,"nodeType":867},{},[]," page in the Push platform",{"data":38592,"content":38593,"nodeType":1586},{},[38594],{"data":38595,"content":38596,"nodeType":876},{},[38597,38602,38606,38614,38617,38625,38629,38638],{"data":38598,"marks":38599,"value":38601,"nodeType":867},{},[38600],{"type":865},"Choose-your-own-adventure tooling",{"data":38603,"marks":38604,"value":38605,"nodeType":867},{},[],", including a ",{"data":38607,"content":38609,"nodeType":915},{"uri":38608},"https://pushsecurity.redoc.ly/rest-v1/",[38610],{"data":38611,"marks":38612,"value":38613,"nodeType":867},{},[],"REST API",{"data":38615,"marks":38616,"value":5136,"nodeType":867},{},[],{"data":38618,"content":38620,"nodeType":915},{"uri":38619},"https://pushsecurity.redoc.ly/webhooks-v1/",[38621],{"data":38622,"marks":38623,"value":38624,"nodeType":867},{},[],"webhooks",{"data":38626,"marks":38627,"value":38628,"nodeType":867},{},[],", and a new ",{"data":38630,"content":38632,"nodeType":915},{"uri":38631},"/help/audience/administrators/docs/connect-to-siem-or-soar/#using-the-events-page",[38633],{"data":38634,"marks":38635,"value":38637,"nodeType":867},{},[38636],{"type":865},"Events",{"data":38639,"marks":38640,"value":38641,"nodeType":867},{},[]," page to help you visualize and build custom detections and automations.",{"data":38643,"content":38644,"nodeType":876},{},[38645],{"data":38646,"marks":38647,"value":38648,"nodeType":867},{},[],"Let’s take a closer look.",{"data":38650,"content":38654,"nodeType":985},{"target":38651},{"sys":38652},{"id":38653,"type":982,"linkType":983},"6iKFd9Qys2SSuNqKVQB7ka",[],{"data":38656,"content":38657,"nodeType":868},{},[38658],{"data":38659,"marks":38660,"value":38661,"nodeType":867},{},[],"Plug-and-play controls",{"data":38663,"content":38664,"nodeType":876},{},[38665],{"data":38666,"marks":38667,"value":38668,"nodeType":867},{},[],"Security visibility without security control is a recipe for a stress headache, so we’re big believers in providing meaningful interventions that are easy to use.",{"data":38670,"content":38671,"nodeType":876},{},[38672,38676,38680],{"data":38673,"marks":38674,"value":38675,"nodeType":867},{},[],"With the new ",{"data":38677,"marks":38678,"value":25043,"nodeType":867},{},[38679],{"type":865},{"data":38681,"marks":38682,"value":38683,"nodeType":867},{},[]," page in the Push admin console, you can now find these preconfigured detections and interventions in one place. They cover use cases that any organization can benefit from, and take a unique browser-based approach to solving some thorny issues.",{"data":38685,"content":38686,"nodeType":876},{},[38687],{"data":38688,"marks":38689,"value":38690,"nodeType":867},{},[],"These controls include:",{"data":38692,"content":38693,"nodeType":1058},{},[38694],{"data":38695,"marks":38696,"value":38697,"nodeType":867},{},[],"Phishing tool detection",{"data":38699,"content":38700,"nodeType":876},{},[38701,38705,38710,38713,38718],{"data":38702,"marks":38703,"value":38704,"nodeType":867},{},[],"Detect and block when employees visit webpages that use advanced phishing tools such as Evilginx or EvilNoVNC, among others. These adversary-in-the-middle (AitM) toolkits can mimic legitimate login screens, such as an Okta login page, to steal ",{"data":38706,"marks":38707,"value":38709,"nodeType":867},{},[38708],{"type":865},"credentials",{"data":38711,"marks":38712,"value":1174,"nodeType":867},{},[],{"data":38714,"marks":38715,"value":38717,"nodeType":867},{},[38716],{"type":865},"MFA codes",{"data":38719,"marks":38720,"value":1679,"nodeType":867},{},[],{"data":38722,"content":38723,"nodeType":876},{},[38724,38728,38733,38736,38741],{"data":38725,"marks":38726,"value":38727,"nodeType":867},{},[],"Push emits a webhook event when the browser agent detects attributes of these malware. You can also set Push to ",{"data":38729,"marks":38730,"value":38732,"nodeType":867},{},[38731],{"type":865},"Warn",{"data":38734,"marks":38735,"value":21631,"nodeType":867},{},[],{"data":38737,"marks":38738,"value":38740,"nodeType":867},{},[38739],{"type":865},"Block",{"data":38742,"marks":38743,"value":38744,"nodeType":867},{},[]," mode to display a customizable message to end-users when they encounter a phishing site.",{"data":38746,"content":38750,"nodeType":985},{"target":38747},{"sys":38748},{"id":38749,"type":982,"linkType":983},"2ylIkR0JXHkFStGuCFRjlN",[],{"data":38752,"content":38753,"nodeType":876},{},[38754,38758,38768],{"data":38755,"marks":38756,"value":38757,"nodeType":867},{},[],"More about ",{"data":38759,"content":38763,"nodeType":17452},{"target":38760},{"sys":38761},{"id":38762,"type":982,"linkType":983},"7KRnTSnJAbbiho69gNyN0B",[38764],{"data":38765,"marks":38766,"value":38767,"nodeType":867},{},[],"phishing tool detection",{"data":38769,"marks":38770,"value":21,"nodeType":867},{},[],{"data":38772,"content":38773,"nodeType":1058},{},[38774],{"data":38775,"marks":38776,"value":38777,"nodeType":867},{},[],"SSO password protection",{"data":38779,"content":38780,"nodeType":876},{},[38781],{"data":38782,"marks":38783,"value":38784,"nodeType":867},{},[],"Prevent employees from reusing their corporate SSO password on any page that doesn’t belong to the identity provider, including phishing sites. This means that even if that employee was the first person to get phished using a new attacker site, Push still detects it and blocks it.",{"data":38786,"content":38787,"nodeType":876},{},[38788,38792,38796,38799,38803,38807,38812],{"data":38789,"marks":38790,"value":38791,"nodeType":867},{},[],"Customize the message that end-users see in ",{"data":38793,"marks":38794,"value":38732,"nodeType":867},{},[38795],{"type":865},{"data":38797,"marks":38798,"value":21631,"nodeType":867},{},[],{"data":38800,"marks":38801,"value":38740,"nodeType":867},{},[38802],{"type":865},{"data":38804,"marks":38805,"value":38806,"nodeType":867},{},[]," mode, or start out in ",{"data":38808,"marks":38809,"value":38811,"nodeType":867},{},[38810],{"type":865},"Monitor",{"data":38813,"marks":38814,"value":38815,"nodeType":867},{},[]," mode to catch any false positives before you enforce the control.",{"data":38817,"content":38818,"nodeType":876},{},[38819],{"data":38820,"marks":38821,"value":38822,"nodeType":867},{},[],"This feature supports the following identity providers: Okta, Microsoft 365, Google Workspace, JumpCloud, Duo, and Ping Identity.",{"data":38824,"content":38825,"nodeType":876},{},[38826],{"data":38827,"marks":38828,"value":38829,"nodeType":867},{},[],"Push will also emit a webhook event when an SSO password is used, and if an employee clicks through the warning screen.",{"data":38831,"content":38835,"nodeType":985},{"target":38832},{"sys":38833},{"id":38834,"type":982,"linkType":983},"25c8M2gWYFST7yYxGEji2s",[],{"data":38837,"content":38838,"nodeType":876},{},[38839,38842,38851],{"data":38840,"marks":38841,"value":38757,"nodeType":867},{},[],{"data":38843,"content":38847,"nodeType":17452},{"target":38844},{"sys":38845},{"id":38846,"type":982,"linkType":983},"6FYHbkcRUrtznPo7RarRsz",[38848],{"data":38849,"marks":38850,"value":38777,"nodeType":867},{},[],{"data":38852,"marks":38853,"value":21,"nodeType":867},{},[],{"data":38855,"content":38856,"nodeType":1058},{},[38857],{"data":38858,"marks":38859,"value":38860,"nodeType":867},{},[],"URL blocking",{"data":38862,"content":38863,"nodeType":876},{},[38864],{"data":38865,"marks":38866,"value":38867,"nodeType":867},{},[],"When you find malicious sites you want to block, such as when responding to a phishing incident, add them to a blocklist and prevent other employees from accessing those sites. ",{"data":38869,"content":38870,"nodeType":876},{},[38871],{"data":38872,"marks":38873,"value":38874,"nodeType":867},{},[],"URL blocking can be used in tandem with Push’s anti-phishing controls, so that as you discover malicious sites, you can block them from a central blocklist. This offers a kind of herd immunity where you can block other users from visiting a malicious site as soon as you have a single incident.",{"data":38876,"content":38877,"nodeType":876},{},[38878],{"data":38879,"marks":38880,"value":38881,"nodeType":867},{},[],"You can programmatically manage the blocklist using the Push REST API or sync to other threat intelligence sources you consume.",{"data":38883,"content":38887,"nodeType":985},{"target":38884},{"sys":38885},{"id":38886,"type":982,"linkType":983},"3m00cFiUDAnddsOBOpkeiZ",[],{"data":38889,"content":38890,"nodeType":876},{},[38891,38894,38903],{"data":38892,"marks":38893,"value":38757,"nodeType":867},{},[],{"data":38895,"content":38899,"nodeType":17452},{"target":38896},{"sys":38897},{"id":38898,"type":982,"linkType":983},"P0coHgQAdRL0YTu4Rwd4z",[38900],{"data":38901,"marks":38902,"value":38860,"nodeType":867},{},[],{"data":38904,"marks":38905,"value":21,"nodeType":867},{},[],{"data":38907,"content":38908,"nodeType":1058},{},[38909],{"data":38910,"marks":38911,"value":38912,"nodeType":867},{},[],"Session token theft detection",{"data":38914,"content":38915,"nodeType":876},{},[38916],{"data":38917,"marks":38918,"value":38919,"nodeType":867},{},[],"Inject a unique marker provided by the Push browser agent into the User Agent string of sessions that occur in browsers enrolled in Push. ",{"data":38921,"content":38922,"nodeType":876},{},[38923],{"data":38924,"marks":38925,"value":38926,"nodeType":867},{},[],"By analyzing logs from your IdP, you can identify activity from the same session that both has the Push marker and that lacks the marker. This can only ever happen when a session is extracted from a browser and maliciously imported into a different browser.",{"data":38928,"content":38929,"nodeType":876},{},[38930],{"data":38931,"marks":38932,"value":38933,"nodeType":867},{},[],"This is a high-fidelity signal that a session token has been stolen and is being used.",{"data":38935,"content":38939,"nodeType":985},{"target":38936},{"sys":38937},{"id":38938,"type":982,"linkType":983},"43rk3TCqN269Vr2YWT4llP",[],{"data":38941,"content":38942,"nodeType":876},{},[38943,38946,38956],{"data":38944,"marks":38945,"value":38757,"nodeType":867},{},[],{"data":38947,"content":38951,"nodeType":17452},{"target":38948},{"sys":38949},{"id":38950,"type":982,"linkType":983},"1UMZdjyNQt4Y7NBb2wuK4L",[38952],{"data":38953,"marks":38954,"value":38955,"nodeType":867},{},[],"session token theft detection",{"data":38957,"marks":38958,"value":21,"nodeType":867},{},[],{"data":38960,"content":38961,"nodeType":1058},{},[38962],{"data":38963,"marks":38964,"value":38965,"nodeType":867},{},[],"App banners",{"data":38967,"content":38968,"nodeType":876},{},[38969],{"data":38970,"marks":38971,"value":38972,"nodeType":867},{},[],"Add guardrails to employees’ use of SaaS apps with in-browser app banner messages you customize with your own text. You can require users to acknowledge having read a message before they can access an app, or even require them to submit a reason for using an app before they can log in.",{"data":38974,"content":38978,"nodeType":985},{"target":38975},{"sys":38976},{"id":38977,"type":982,"linkType":983},"5nEKTBz6mauHI5mg8jB4ea",[],{"data":38980,"content":38981,"nodeType":876},{},[38982,38985,38995],{"data":38983,"marks":38984,"value":38757,"nodeType":867},{},[],{"data":38986,"content":38990,"nodeType":17452},{"target":38987},{"sys":38988},{"id":38989,"type":982,"linkType":983},"2ZpKnuljaUH0jzVaae4SMN",[38991],{"data":38992,"marks":38993,"value":38994,"nodeType":867},{},[],"app banners",{"data":38996,"marks":38997,"value":21,"nodeType":867},{},[],{"data":38999,"content":39000,"nodeType":868},{},[39001],{"data":39002,"marks":39003,"value":39004,"nodeType":867},{},[],"Choose your own adventure",{"data":39006,"content":39007,"nodeType":876},{},[39008],{"data":39009,"marks":39010,"value":39011,"nodeType":867},{},[],"Want to do something creative? We've got you covered. Push provides a wealth of raw telemetry via the Push REST API and webhook events. Use this data to build both proactive and reactive security operations workflows, or add missing context to other sources, such as your IdP, application, or endpoint logs.",{"data":39013,"content":39014,"nodeType":876},{},[39015],{"data":39016,"marks":39017,"value":39018,"nodeType":867},{},[],"You can use this browser telemetry to:",{"data":39020,"content":39021,"nodeType":1629},{},[39022,39037,39052],{"data":39023,"content":39024,"nodeType":1586},{},[39025],{"data":39026,"content":39027,"nodeType":876},{},[39028,39033],{"data":39029,"marks":39030,"value":39032,"nodeType":867},{},[39031],{"type":865},"Harden identities and reduce account compromise",{"data":39034,"marks":39035,"value":39036,"nodeType":867},{},[],", such as alerting you when passwords are identified in public data breaches or when employees are using an unapproved app or when an SSO app is accessed via local account.",{"data":39038,"content":39039,"nodeType":1586},{},[39040],{"data":39041,"content":39042,"nodeType":876},{},[39043,39048],{"data":39044,"marks":39045,"value":39047,"nodeType":867},{},[39046],{"type":865},"Monitor for suspicious activity or high-risk changes",{"data":39049,"marks":39050,"value":39051,"nodeType":867},{},[],", such as checking for MFA method changes, or flagging when employees reuse corporate SSO passwords or visit sites running phishing malware.",{"data":39053,"content":39054,"nodeType":1586},{},[39055],{"data":39056,"content":39057,"nodeType":876},{},[39058,39063],{"data":39059,"marks":39060,"value":39062,"nodeType":867},{},[39061],{"type":865},"Investigate indicators of compromise",{"data":39064,"marks":39065,"value":39066,"nodeType":867},{},[],", such as correlating login events with platform logs, searching for recent signups to risky apps, or identifying post-compromise lateral movement opportunities.",{"data":39068,"content":39069,"nodeType":876},{},[39070],{"data":39071,"marks":39072,"value":39073,"nodeType":867},{},[],"In the “make my life easier” category, you can also use Push telemetry to:",{"data":39075,"content":39076,"nodeType":1629},{},[39077,39096,39115,39130],{"data":39078,"content":39079,"nodeType":1586},{},[39080],{"data":39081,"content":39082,"nodeType":876},{},[39083,39087,39092],{"data":39084,"marks":39085,"value":39086,"nodeType":867},{},[],"Automate a workflow ",{"data":39088,"marks":39089,"value":39091,"nodeType":867},{},[39090],{"type":865},"showing you all the accounts and apps used by an offboarded employee",{"data":39093,"marks":39094,"value":39095,"nodeType":867},{},[],", and their account login methods.",{"data":39097,"content":39098,"nodeType":1586},{},[39099],{"data":39100,"content":39101,"nodeType":876},{},[39102,39106,39111],{"data":39103,"marks":39104,"value":39105,"nodeType":867},{},[],"Automate a workflow to",{"data":39107,"marks":39108,"value":39110,"nodeType":867},{},[39109],{"type":865}," revoke licenses on SaaS after a period of inactivity",{"data":39112,"marks":39113,"value":39114,"nodeType":867},{},[],", saving money.",{"data":39116,"content":39117,"nodeType":1586},{},[39118],{"data":39119,"content":39120,"nodeType":876},{},[39121,39126],{"data":39122,"marks":39123,"value":39125,"nodeType":867},{},[39124],{"type":865},"Build an approved apps list in your company wiki",{"data":39127,"marks":39128,"value":39129,"nodeType":867},{},[],", synced from Push’s source of truth.",{"data":39131,"content":39132,"nodeType":1586},{},[39133],{"data":39134,"content":39135,"nodeType":876},{},[39136,39141],{"data":39137,"marks":39138,"value":39140,"nodeType":867},{},[39139],{"type":865},"Force-reset an IdP password if Push finds a compromised password",{"data":39142,"marks":39143,"value":39144,"nodeType":867},{},[]," on an employee account.",{"data":39146,"content":39147,"nodeType":876},{},[39148,39152,39156],{"data":39149,"marks":39150,"value":39151,"nodeType":867},{},[],"To help you visualize and plan how you will use this telemetry, Push also provides an ",{"data":39153,"marks":39154,"value":38637,"nodeType":867},{},[39155],{"type":865},{"data":39157,"marks":39158,"value":39159,"nodeType":867},{},[]," page in the admin console with a rolling 7-day snapshot of all the events in your environment.",{"data":39161,"content":39165,"nodeType":985},{"target":39162},{"sys":39163},{"id":39164,"type":982,"linkType":983},"2a3bJ5sN8dJ0c1kQtZiag7",[],{"data":39167,"content":39168,"nodeType":876},{},[39169],{"data":39170,"marks":39171,"value":39172,"nodeType":867},{},[],"The Events page can help you see real-world examples, understand the attributes of each event, and gauge event volume before you ingest data into a SIEM or other platform.",{"data":39174,"content":39175,"nodeType":868},{},[39176],{"data":39177,"marks":39178,"value":39179,"nodeType":867},{},[],"What if you don’t have a SIEM?",{"data":39181,"content":39182,"nodeType":876},{},[39183],{"data":39184,"marks":39185,"value":39186,"nodeType":867},{},[],"While you’d need a SIEM for writing detections and performing log correlations, you can still get a lot of value out of Push telemetry if you don’t have one.",{"data":39188,"content":39189,"nodeType":876},{},[39190],{"data":39191,"marks":39192,"value":39193,"nodeType":867},{},[],"Use Push’s webhook events to send alerts directly to your Slack, Teams, or other chat platform, or build workflows that hook into your ticketing system or SOAR platform.",{"data":39195,"content":39196,"nodeType":876},{},[39197,39201,39208],{"data":39198,"marks":39199,"value":39200,"nodeType":867},{},[],"Review our ",{"data":39202,"content":39203,"nodeType":915},{"uri":38619},[39204],{"data":39205,"marks":39206,"value":39207,"nodeType":867},{},[],"webhooks documentation",{"data":39209,"marks":39210,"value":39211,"nodeType":867},{},[]," for a list of events.",{"data":39213,"content":39214,"nodeType":868},{},[39215],{"data":39216,"marks":39217,"value":25228,"nodeType":867},{},[],{"data":39219,"content":39220,"nodeType":876},{},[39221,39225,39232],{"data":39222,"marks":39223,"value":39224,"nodeType":867},{},[],"If you want to see Push in action, ",{"data":39226,"content":39228,"nodeType":915},{"uri":39227},"/demo/",[39229],{"data":39230,"marks":39231,"value":11707,"nodeType":867},{},[],{"data":39233,"marks":39234,"value":39235,"nodeType":867},{},[],". We’ll be happy to show you these features, along with how we discover all the apps your employees are using — even the ones not behind SSO.","Introducing set-and-forget controls that stop real-world identity attacks","Enable detections and interventions in the browser using Push’s new security controls.","2024-07-02T00:00:00.000Z","introducing-set-and-forget-controls-that-stop-real-world-identity-attacks",{"items":39241},[39242,39246],{"sys":39243,"name":39245},{"id":39244},"5jk0kqjSdSK2L0YiistQjY","Release notes",{"sys":39247,"name":342},{"id":3240},{"items":39249},[39250],{"fullName":2714,"firstName":2715,"jobTitle":851,"profilePicture":39251},{"url":2717},"why-im-joining-push-security-the-team-redefining-itdr","blog/why-im-joining-push-security-the-team-redefining-itdr",{"json":39255},{"data":39256,"content":39257,"nodeType":1680},{},[39258],{"data":39259,"content":39260,"nodeType":876},{},[39261],{"data":39262,"marks":39263,"value":39264,"nodeType":867},{},[],"I'm excited to announce my new role as Chief Revenue Officer at Push, the team bringing identity threat detection and response into every browser. ","Push's new Chief Revenue Officer, Kevin Arsenault, shares why he decided to join the Push team.",{"id":39267,"publishedAt":39268},"7yvGkRGcpQcS7wYfH3xA17","2026-08-13T09:35:05.294Z",{"items":39270},[39271],{"sys":39272,"name":39274},{"id":39273},"4EtskIWlj3SOH3UHbFR8uG","Company news",{"items":39276},[39277,39279,39281],{"sys":39278,"name":413,"slug":414,"tier":31},{"id":410},{"sys":39280,"name":297,"slug":298,"tier":31},{"id":294},{"sys":39282,"name":377,"slug":378,"tier":45},{"id":374},"9ekrrzNpo5ewFTT6Ja4KxbdfdhekzOekRN-IDdnZK4w",{"id":39285,"title":39286,"authorsCollection":39287,"content":39292,"extension":228,"faqItemsCollection":40170,"faqTitle":59,"featured":6,"hashTags":59,"meta":40172,"metaTitle":40173,"ogImage":40174,"postType":1767,"publishedDate":40176,"relatedBlogPostsCollection":40177,"slug":43141,"stem":43142,"subtitle":59,"summary":43143,"synopsis":43154,"sys":43155,"tagsCollection":43158,"topicsCollection":43164,"__hash__":43194},"blog/blog/shifting-detection-left-for-more-effective-threat-detection.json","Shifting detection left for more effective threat detection",{"items":39288},[39289],{"fullName":4022,"firstName":4023,"jobTitle":4024,"socialLinks":39290,"profilePicture":39291},[21074],{"url":4026},{"json":39293,"links":40115},{"data":39294,"content":39295,"nodeType":1680},{},[39296,39303,39310,39317,39323,39331,39338,39344,39351,39357,39364,39372,39379,39385,39392,39423,39430,39437,39470,39478,39485,39493,39501,39508,39515,39534,39541,39548,39555,39563,39570,39577,39610,39617,39670,39677,39684,39692,39699,39706,39713,39721,39728,39751,39758,39806,39813,39819,39826,39869,39876,39884,39891,39898,39929,39937,39944,39950,39957,39963,39970,39976,39983,40069,40076,40083,40090,40108],{"data":39297,"content":39298,"nodeType":876},{},[39299],{"data":39300,"marks":39301,"value":39302,"nodeType":867},{},[],"As an industry, we’ve been conditioned to think about threat detection and response as something that happens post-compromise. Best practice has formed around resources like the Cyber Kill Chain and the MITRE ATT&CK Framework which focus on detecting indicators of an attacker presence on your network, and their behaviors and actions as they move through it.",{"data":39304,"content":39305,"nodeType":876},{},[39306],{"data":39307,"marks":39308,"value":39309,"nodeType":867},{},[],"But with the shift to identity attacks, where attackers look to take over accounts on internet-facing apps and services, relying on an assumed compromise approach to detection is becoming less reliable. The most significant breaches of the last 12-18 months have been the result of browser-based attacks where an attacker has taken over an account, exfiltrated data… and that’s it. ",{"data":39311,"content":39312,"nodeType":876},{},[39313],{"data":39314,"marks":39315,"value":39316,"nodeType":867},{},[],"This change means that the typical methods of post-compromise detection and response become much less viable. So, we’re going to talk a bit about what’s changed, why controls are failing, and what we’re doing here at Push to address the detection gaps. ",{"data":39318,"content":39322,"nodeType":985},{"target":39319},{"sys":39320},{"id":39321,"type":982,"linkType":983},"4179AY8ZEIJ3Ce9jszn4fA",[],{"data":39324,"content":39325,"nodeType":868},{},[39326],{"data":39327,"marks":39328,"value":39330,"nodeType":867},{},[39329],{"type":865},"The good old days",{"data":39332,"content":39333,"nodeType":876},{},[39334],{"data":39335,"marks":39336,"value":39337,"nodeType":867},{},[],"Over the previous decade the typical attack paths, and the controls that have formed around it, have become very familiar to SecOps teams. ",{"data":39339,"content":39343,"nodeType":985},{"target":39340},{"sys":39341},{"id":39342,"type":982,"linkType":983},"4AOzwBGuNkXXogyqy46ki5",[],{"data":39345,"content":39346,"nodeType":876},{},[39347],{"data":39348,"marks":39349,"value":39350,"nodeType":867},{},[],"Even with the more recent transition to enterprise cloud and hybrid networking, the broad offensive logic of “land and expand” remains. This has seen the typical view of a network-based attack path simply expand to add first enterprise cloud, and then SaaS to the picture. ",{"data":39352,"content":39356,"nodeType":985},{"target":39353},{"sys":39354},{"id":39355,"type":982,"linkType":983},"2J3s38YOVcMuJuTdryhERA",[],{"data":39358,"content":39359,"nodeType":876},{},[39360],{"data":39361,"marks":39362,"value":39363,"nodeType":867},{},[],"And while this sort of attack path is theoretically possible, what happens in reality looks quite different. ",{"data":39365,"content":39366,"nodeType":868},{},[39367],{"data":39368,"marks":39369,"value":39371,"nodeType":867},{},[39370],{"type":865},"The new world",{"data":39373,"content":39374,"nodeType":876},{},[39375],{"data":39376,"marks":39377,"value":39378,"nodeType":867},{},[],"Instead of needing to progress through the network, moving laterally, elevating privileges, etc. modern account takeover tends to take a much more direct approach. ",{"data":39380,"content":39384,"nodeType":985},{"target":39381},{"sys":39382},{"id":39383,"type":982,"linkType":983},"6wIzMu3jBhaas9jtpV48bz",[],{"data":39386,"content":39387,"nodeType":876},{},[39388],{"data":39389,"marks":39390,"value":39391,"nodeType":867},{},[],"It’s a common misconception that SaaS compromise typically comes after the traditional attack chain (a myth largely promoted by old-school consultancy providers, MSSPs, and managed SOC providers). There’s no need for an attacker looking to take over a SaaS account to target the network first – and many organizations today simply no longer have a network in the conventional sense.  ",{"data":39393,"content":39394,"nodeType":876},{},[39395,39399,39407,39411,39420],{"data":39396,"marks":39397,"value":39398,"nodeType":867},{},[],"This isn’t to say that there aren’t examples of longer SaaS compromises involving lateral movement from SaaS to SaaS, or SaaS to cloud (",{"data":39400,"content":39401,"nodeType":915},{"uri":15408},[39402],{"data":39403,"marks":39404,"value":39406,"nodeType":867},{},[39405],{"type":913},"we created a whole attack matrix demonstrating the art of the possible here",{"data":39408,"marks":39409,"value":39410,"nodeType":867},{},[],"). Equally, there are examples of very short and direct attacks in enterprise cloud environments leading to ransomware deployment (for example, ",{"data":39412,"content":39414,"nodeType":915},{"uri":39413},"https://www.bleepingcomputer.com/news/security/mgm-casinos-esxi-servers-allegedly-encrypted-in-ransomware-attack/",[39415],{"data":39416,"marks":39417,"value":39419,"nodeType":867},{},[39418],{"type":913},"Scattered Spider turning an initial account takeover in Okta into a full-scale VMware ESXi ransomware compromise",{"data":39421,"marks":39422,"value":23136,"nodeType":867},{},[],{"data":39424,"content":39425,"nodeType":876},{},[39426],{"data":39427,"marks":39428,"value":39429,"nodeType":867},{},[],"But statistically, the average network or enterprise cloud attack involves much more complex lateral movement, privilege escalation, and defense evasion than the average SaaS attack path. ",{"data":39431,"content":39432,"nodeType":876},{},[39433],{"data":39434,"marks":39435,"value":39436,"nodeType":867},{},[],"The Snowflake attack path is a useful case study here: ",{"data":39438,"content":39439,"nodeType":1629},{},[39440,39450,39460],{"data":39441,"content":39442,"nodeType":1586},{},[39443],{"data":39444,"content":39445,"nodeType":876},{},[39446],{"data":39447,"marks":39448,"value":39449,"nodeType":867},{},[],"Attackers logged into the Snowflake tenant of ~165 organizations using stolen credentials to access user accounts via the web-based ‘SnowSight’ portal. ",{"data":39451,"content":39452,"nodeType":1586},{},[39453],{"data":39454,"content":39455,"nodeType":876},{},[39456],{"data":39457,"marks":39458,"value":39459,"nodeType":867},{},[],"To take advantage of the many exposed accounts, the attacker created a utility performing account takeover and recon at-scale. ",{"data":39461,"content":39462,"nodeType":1586},{},[39463],{"data":39464,"content":39465,"nodeType":876},{},[39466],{"data":39467,"marks":39468,"value":39469,"nodeType":867},{},[],"The attack finished with the attacker executing the same set of SQL commands across customer instances to stage and exfiltrate data. ",{"data":39471,"content":39472,"nodeType":876},{},[39473],{"data":39474,"marks":39475,"value":39477,"nodeType":867},{},[39476],{"type":865},"And that’s it. ",{"data":39479,"content":39480,"nodeType":876},{},[39481],{"data":39482,"marks":39483,"value":39484,"nodeType":867},{},[],"Since these attacks happen in-app, to be able to detect and intercept them you’d need deep app-level telemetry, and probably the ability to automate any containment and response activities. But unfortunately…",{"data":39486,"content":39487,"nodeType":868},{},[39488],{"data":39489,"marks":39490,"value":39492,"nodeType":867},{},[39491],{"type":865},"Detecting and responding after account takeover is really, really difficult",{"data":39494,"content":39495,"nodeType":1058},{},[39496],{"data":39497,"marks":39498,"value":39500,"nodeType":867},{},[39499],{"type":865},"Limited log data ",{"data":39502,"content":39503,"nodeType":876},{},[39504],{"data":39505,"marks":39506,"value":39507,"nodeType":867},{},[],"The first challenge is that in-app malicious activity is mostly indistinguishable from legitimate user behavior. Even mass data exfiltration might appear legitimate depending on what the app is used for!",{"data":39509,"content":39510,"nodeType":876},{},[39511],{"data":39512,"marks":39513,"value":39514,"nodeType":867},{},[],"To meaningfully detect malicious activity in-app, for starters you would need visibility of user behavior and actions. Unfortunately, you don’t have this. ",{"data":39516,"content":39517,"nodeType":876},{},[39518,39522,39530],{"data":39519,"marks":39520,"value":39521,"nodeType":867},{},[],"We’ve previously discussed in detail why ",{"data":39523,"content":39524,"nodeType":915},{"uri":27034},[39525],{"data":39526,"marks":39527,"value":39529,"nodeType":867},{},[39528],{"type":913},"log sources like network (web proxy), IdP, and app logs fall short",{"data":39531,"marks":39532,"value":39533,"nodeType":867},{},[]," when it comes to identity attacks, but the TL;DR is that most applications provide extremely limited security logging (if they provide it at all). ",{"data":39535,"content":39536,"nodeType":876},{},[39537],{"data":39538,"marks":39539,"value":39540,"nodeType":867},{},[],"When logs are available, you’re limited to the events that the third-party deems suitable to log. Out of the 100 most popular apps we see across our customers, and perhaps the few dozen or so that are security critical, only a small handful provide any useful logging. So extremely risky actions, like cloning a private GitHub repo, or downloading SharePoint files via ‘open in app’ or file syncing, don’t generate any logs at all. ",{"data":39542,"content":39543,"nodeType":876},{},[39544],{"data":39545,"marks":39546,"value":39547,"nodeType":867},{},[],"Further, the lack of out-of-the-box connectors for many apps means that complex custom architectures are often required for ingestion.",{"data":39549,"content":39550,"nodeType":876},{},[39551],{"data":39552,"marks":39553,"value":39554,"nodeType":867},{},[],"So, even if logs are available and you’re able to ingest them into your SIEM, there’s no guarantee that the telemetry available will contribute to any meaningful detection of malicious activity. ",{"data":39556,"content":39557,"nodeType":1058},{},[39558],{"data":39559,"marks":39560,"value":39562,"nodeType":867},{},[39561],{"type":865},"Limited response capabilities",{"data":39564,"content":39565,"nodeType":876},{},[39566],{"data":39567,"marks":39568,"value":39569,"nodeType":867},{},[],"By some miracle, you’ve detected an account takeover. Now what?",{"data":39571,"content":39572,"nodeType":876},{},[39573],{"data":39574,"marks":39575,"value":39576,"nodeType":867},{},[],"The ability to respond to an attack is dictated by the controls that are available to the security team. Unfortunately:",{"data":39578,"content":39579,"nodeType":1629},{},[39580,39590,39600],{"data":39581,"content":39582,"nodeType":1586},{},[39583],{"data":39584,"content":39585,"nodeType":876},{},[39586],{"data":39587,"marks":39588,"value":39589,"nodeType":867},{},[],"Depending on the app and how it was adopted, there’s no guarantee that you have admin rights. ",{"data":39591,"content":39592,"nodeType":1586},{},[39593],{"data":39594,"content":39595,"nodeType":876},{},[39596],{"data":39597,"marks":39598,"value":39599,"nodeType":867},{},[],"It’s not guaranteed that admins will have the required security features available to them, like forcing a logout on a session or disabling an account (you may not even know who the users and admins are within your organization, particularly if it was self-adopted by a specific team). ",{"data":39601,"content":39602,"nodeType":1586},{},[39603],{"data":39604,"content":39605,"nodeType":876},{},[39606],{"data":39607,"marks":39608,"value":39609,"nodeType":867},{},[],"Response probably requires that you log into the app and perform these actions in the admin interface (rather than being something you can orchestrate via SIEM workflow or API).",{"data":39611,"content":39612,"nodeType":876},{},[39613],{"data":39614,"marks":39615,"value":39616,"nodeType":867},{},[],"So at the point that the SecOps team is engaged, the team needs to be able to respond by eradicating the attacker’s access and closing the vulnerabilities exploited to prevent re-entry. To do this, the team needs to be able to identify, for example:",{"data":39618,"content":39619,"nodeType":1629},{},[39620,39630,39640,39650,39660],{"data":39621,"content":39622,"nodeType":1586},{},[39623],{"data":39624,"content":39625,"nodeType":876},{},[39626],{"data":39627,"marks":39628,"value":39629,"nodeType":867},{},[],"How the attacker gained access to the account",{"data":39631,"content":39632,"nodeType":1586},{},[39633],{"data":39634,"content":39635,"nodeType":876},{},[39636],{"data":39637,"marks":39638,"value":39639,"nodeType":867},{},[],"What the attacker did using the compromised account",{"data":39641,"content":39642,"nodeType":1586},{},[39643],{"data":39644,"content":39645,"nodeType":876},{},[39646],{"data":39647,"marks":39648,"value":39649,"nodeType":867},{},[],"Whether any alternative access methods were established (e.g. backup emails, API keys, or OAuth integrations)",{"data":39651,"content":39652,"nodeType":1586},{},[39653],{"data":39654,"content":39655,"nodeType":876},{},[39656],{"data":39657,"marks":39658,"value":39659,"nodeType":867},{},[],"Where the attacker could have laterally moved to using the account (based on the integrations and permissions of the identity)",{"data":39661,"content":39662,"nodeType":1586},{},[39663],{"data":39664,"content":39665,"nodeType":876},{},[39666],{"data":39667,"marks":39668,"value":39669,"nodeType":867},{},[],"Other accounts the attacker could also access using the same credentials",{"data":39671,"content":39672,"nodeType":876},{},[39673],{"data":39674,"marks":39675,"value":39676,"nodeType":867},{},[],"Given the limited tools available and the probable lack of app-specific knowledge (you can’t be an expert in every app!), by the time you’ve managed to respond, the attacker has probably already sailed off into the sunset with all of the data they can lay their hands on. ",{"data":39678,"content":39679,"nodeType":876},{},[39680],{"data":39681,"marks":39682,"value":39683,"nodeType":867},{},[],"Clearly, post-compromise detection and response isn’t really a viable option – you’re basically entering full response and recovery mode at this point. ",{"data":39685,"content":39686,"nodeType":868},{},[39687],{"data":39688,"marks":39689,"value":39691,"nodeType":867},{},[39690],{"type":865},"Shifting detection left",{"data":39693,"content":39694,"nodeType":876},{},[39695],{"data":39696,"marks":39697,"value":39698,"nodeType":867},{},[],"If you can’t reasonably detect and respond to post-compromise activity, it makes detecting and blocking initial access much more important. ",{"data":39700,"content":39701,"nodeType":876},{},[39702],{"data":39703,"marks":39704,"value":39705,"nodeType":867},{},[],"Again, it seems obvious, but it’s yet another notion that’s fallen under the radar – despite the trendiness of ‘shifting left’ in other areas like software development and vulnerability management. Partly because as we’ve discussed, post-compromise detection and response has been the norm for so long. But also because we’ve accepted the status quo of the (somewhat disappointing) preventative controls that are available. ",{"data":39707,"content":39708,"nodeType":876},{},[39709],{"data":39710,"marks":39711,"value":39712,"nodeType":867},{},[],"First, let’s isolate the techniques and steps that attackers typically rely on for account takeover. ",{"data":39714,"content":39715,"nodeType":1058},{},[39716],{"data":39717,"marks":39718,"value":39720,"nodeType":867},{},[39719],{"type":865},"Methods of account takeover",{"data":39722,"content":39723,"nodeType":876},{},[39724],{"data":39725,"marks":39726,"value":39727,"nodeType":867},{},[],"To be able to hijack an account, an attacker needs to possess one of two things:",{"data":39729,"content":39730,"nodeType":1629},{},[39731,39741],{"data":39732,"content":39733,"nodeType":1586},{},[39734],{"data":39735,"content":39736,"nodeType":876},{},[39737],{"data":39738,"marks":39739,"value":39740,"nodeType":867},{},[],"Authentication material e.g. a username and password, with a login portal URL.",{"data":39742,"content":39743,"nodeType":1586},{},[39744],{"data":39745,"content":39746,"nodeType":876},{},[39747],{"data":39748,"marks":39749,"value":39750,"nodeType":867},{},[],"Session material e.g. session cookies. ",{"data":39752,"content":39753,"nodeType":876},{},[39754],{"data":39755,"marks":39756,"value":39757,"nodeType":867},{},[],"There are three main ways that an attacker can hijack an account by acquiring (or generating) these materials: Phishing, infostealers, and credential stuffing. ",{"data":39759,"content":39760,"nodeType":1629},{},[39761,39776,39791],{"data":39762,"content":39763,"nodeType":1586},{},[39764],{"data":39765,"content":39766,"nodeType":876},{},[39767,39772],{"data":39768,"marks":39769,"value":39771,"nodeType":867},{},[39770],{"type":865},"Phishing:",{"data":39773,"marks":39774,"value":39775,"nodeType":867},{},[]," Stealing valid authentication and session material from victims, including usernames, passwords, and session cookies (if AitM or BitM), for a specific site or app.",{"data":39777,"content":39778,"nodeType":1586},{},[39779],{"data":39780,"content":39781,"nodeType":876},{},[39782,39787],{"data":39783,"marks":39784,"value":39786,"nodeType":867},{},[39785],{"type":865},"Infostealers:",{"data":39788,"marks":39789,"value":39790,"nodeType":867},{},[]," Stealing valid authentication and session material from the victim’s web browsers for all apps that the user has signed into, as well as desktop information from the device.",{"data":39792,"content":39793,"nodeType":1586},{},[39794],{"data":39795,"content":39796,"nodeType":876},{},[39797,39802],{"data":39798,"marks":39799,"value":39801,"nodeType":867},{},[39800],{"type":865},"Credential stuffing: ",{"data":39803,"marks":39804,"value":39805,"nodeType":867},{},[],"Using previously breached authentication or session material in data breach dumps, or taking advantage of weak or guessable passwords (as a result of password reuse).",{"data":39807,"content":39808,"nodeType":876},{},[39809],{"data":39810,"marks":39811,"value":39812,"nodeType":867},{},[],"Once this information has been acquired, the attack path follows a similar journey regardless of the initial attack technique, ending in the attacker initiating a session in their own browser. ",{"data":39814,"content":39818,"nodeType":985},{"target":39815},{"sys":39816},{"id":39817,"type":982,"linkType":983},"7CJT84yPsiUaUO4Mfb6oFd",[],{"data":39820,"content":39821,"nodeType":876},{},[39822],{"data":39823,"marks":39824,"value":39825,"nodeType":867},{},[],"Clearly, there are a number of steps here that involve user behaviors/actions that could in theory be detected with the right visibility:",{"data":39827,"content":39828,"nodeType":1629},{},[39829,39839,39849,39859],{"data":39830,"content":39831,"nodeType":1586},{},[39832],{"data":39833,"content":39834,"nodeType":876},{},[39835],{"data":39836,"marks":39837,"value":39838,"nodeType":867},{},[],"The victim being sent and accessing a malicious link, or downloading a malicious file",{"data":39840,"content":39841,"nodeType":1586},{},[39842],{"data":39843,"content":39844,"nodeType":876},{},[39845],{"data":39846,"marks":39847,"value":39848,"nodeType":867},{},[],"The victim loading a malicious webpage",{"data":39850,"content":39851,"nodeType":1586},{},[39852],{"data":39853,"content":39854,"nodeType":876},{},[39855],{"data":39856,"marks":39857,"value":39858,"nodeType":867},{},[],"The victim interacting with a malicious webpage, such as entering their credentials",{"data":39860,"content":39861,"nodeType":1586},{},[39862],{"data":39863,"content":39864,"nodeType":876},{},[39865],{"data":39866,"marks":39867,"value":39868,"nodeType":867},{},[],"(If an infostealer attack) The victim executing malware on their device",{"data":39870,"content":39871,"nodeType":876},{},[39872],{"data":39873,"marks":39874,"value":39875,"nodeType":867},{},[],"Finally, the attacker must also access the stolen account from their own device/browser.",{"data":39877,"content":39878,"nodeType":1058},{},[39879],{"data":39880,"marks":39881,"value":39883,"nodeType":867},{},[39882],{"type":865},"Existing controls are falling short",{"data":39885,"content":39886,"nodeType":876},{},[39887],{"data":39888,"marks":39889,"value":39890,"nodeType":867},{},[],"So, now we know what these attacks look like, how do you feasibly detect and block them? ",{"data":39892,"content":39893,"nodeType":876},{},[39894],{"data":39895,"marks":39896,"value":39897,"nodeType":867},{},[],"The vast majority of identity attacks take place entirely over the internet. These attacks don’t involve traditional network and endpoint-based techniques, and therefore don’t run into many of your existing perimeter controls. Infostealer attacks are the exception in that they do involve an endpoint compromise (and therefore come up against EDR), but attackers are continually finding new bypass techniques, or are targeting unmanaged devices that are not protected by EDR. ",{"data":39899,"content":39900,"nodeType":876},{},[39901,39905,39913,39917,39925],{"data":39902,"marks":39903,"value":39904,"nodeType":867},{},[],"This leaves us in the hands of TI-driven blocklists and SWG/email controls that identify and block malicious content. However, these controls are largely based on ",{"data":39906,"content":39907,"nodeType":915},{"uri":967},[39908],{"data":39909,"marks":39910,"value":39912,"nodeType":867},{},[39911],{"type":913},"indicators like domain names, URLs, and IPs",{"data":39914,"marks":39915,"value":39916,"nodeType":867},{},[]," which are easy for attackers to change (and therefore bypass). Where pages and downloads are analyzed, ",{"data":39918,"content":39919,"nodeType":915},{"uri":34554},[39920],{"data":39921,"marks":39922,"value":39924,"nodeType":867},{},[39923],{"type":913},"attackers are routinely implementing obfuscation measures to defeat more advanced dynamic controls",{"data":39926,"marks":39927,"value":39928,"nodeType":867},{},[]," with a lot of success, or using techniques like HTML smuggling to bypass download scanning tools. ",{"data":39930,"content":39931,"nodeType":1058},{},[39932],{"data":39933,"marks":39934,"value":39936,"nodeType":867},{},[39935],{"type":865},"Detecting and responding to account takeover with Push",{"data":39938,"content":39939,"nodeType":876},{},[39940],{"data":39941,"marks":39942,"value":39943,"nodeType":867},{},[],"But, Push’s vantage point in the browser gives us a very different perspective. Because in the browser, you have much better visibility of the rendered web page (meaning it's much harder to disguise malicious content). You also aren’t restricted to email, and can intercept a user loading a malicious page whatever it’s source. ",{"data":39945,"content":39949,"nodeType":985},{"target":39946},{"sys":39947},{"id":39948,"type":982,"linkType":983},"4JpFRHGRGEbCb1hNF0CGlE",[],{"data":39951,"content":39952,"nodeType":876},{},[39953],{"data":39954,"marks":39955,"value":39956,"nodeType":867},{},[],"So, let’s compare the typical web-based controls that organizations rely on against what’s possible using Push’s browser-based solution. We’ll put EDR to one side here and focus on a typical phishing attack, since the majority of the attack path happens over the internet (and the attacker has to return to the internet to access the app/account anyway). ",{"data":39958,"content":39962,"nodeType":985},{"target":39959},{"sys":39960},{"id":39961,"type":982,"linkType":983},"4ua9ZNNSnxJnRLwJvRTaf1",[],{"data":39964,"content":39965,"nodeType":876},{},[39966],{"data":39967,"marks":39968,"value":39969,"nodeType":867},{},[],"You can see here that attackers have established methods of routinely bypassing these controls. In contrast, with Push, there are layered detections against different stages of the attack path to account takeover, providing defense-in-depth should a layer be somehow bypassed.",{"data":39971,"content":39975,"nodeType":985},{"target":39972},{"sys":39973},{"id":39974,"type":982,"linkType":983},"ogIj92nzV9Q2Z7I9YOgG3",[],{"data":39977,"content":39978,"nodeType":876},{},[39979],{"data":39980,"marks":39981,"value":39982,"nodeType":867},{},[],"In practice, this creates four strong lines of defense – all before an attacker can even take over an account. ",{"data":39984,"content":39985,"nodeType":1629},{},[39986,40007,40028,40048],{"data":39987,"content":39988,"nodeType":1586},{},[39989],{"data":39990,"content":39991,"nodeType":876},{},[39992,39996,40004],{"data":39993,"marks":39994,"value":39995,"nodeType":867},{},[],"1st line: ",{"data":39997,"content":39999,"nodeType":915},{"uri":39998},"https://pushsecurity.com/blog/introducing-cloned-login-page-detection/",[40000],{"data":40001,"marks":40002,"value":40003,"nodeType":867},{},[],"Detecting when a login page that you access is cloned from a legitimate page.",{"data":40005,"marks":40006,"value":21,"nodeType":867},{},[],{"data":40008,"content":40009,"nodeType":1586},{},[40010],{"data":40011,"content":40012,"nodeType":876},{},[40013,40017,40025],{"data":40014,"marks":40015,"value":40016,"nodeType":867},{},[],"2nd line: ",{"data":40018,"content":40020,"nodeType":915},{"uri":40019},"https://pushsecurity.com/blog/introducing-aitm-phishing-toolkit-detection-powered-by-the-push-browser/",[40021],{"data":40022,"marks":40023,"value":40024,"nodeType":867},{},[],"Detecting and blocking access to a page with a known phishing kit signature present on the page",{"data":40026,"marks":40027,"value":5704,"nodeType":867},{},[],{"data":40029,"content":40030,"nodeType":1586},{},[40031],{"data":40032,"content":40033,"nodeType":876},{},[40034,40038,40045],{"data":40035,"marks":40036,"value":40037,"nodeType":867},{},[],"3rd line: ",{"data":40039,"content":40040,"nodeType":915},{"uri":22796},[40041],{"data":40042,"marks":40043,"value":40044,"nodeType":867},{},[],"Detecting and blocking the user behavior of entering their password into any site that the password doesn’t belong to",{"data":40046,"marks":40047,"value":5704,"nodeType":867},{},[],{"data":40049,"content":40050,"nodeType":1586},{},[40051],{"data":40052,"content":40053,"nodeType":876},{},[40054,40058,40066],{"data":40055,"marks":40056,"value":40057,"nodeType":867},{},[],"4th line: ",{"data":40059,"content":40061,"nodeType":915},{"uri":40060},"https://pushsecurity.com/blog/introducing-session-token-theft-detection-why-browser-is-best/",[40062],{"data":40063,"marks":40064,"value":40065,"nodeType":867},{},[],"Detecting when an attacker resumes a stolen session in a browser without the Push extension running. ",{"data":40067,"marks":40068,"value":21,"nodeType":867},{},[],{"data":40070,"content":40071,"nodeType":876},{},[40072],{"data":40073,"marks":40074,"value":40075,"nodeType":867},{},[],"Each of these controls either detects and blocks the account takeover attempt outright, or provides a high-fidelity indicator that should trigger a priority investigation via your SecOps workflow. ",{"data":40077,"content":40078,"nodeType":868},{},[40079],{"data":40080,"marks":40081,"value":23563,"nodeType":867},{},[40082],{"type":865},{"data":40084,"content":40085,"nodeType":876},{},[40086],{"data":40087,"marks":40088,"value":40089,"nodeType":867},{},[],"Hopefully we’ve demonstrated shifting detection left isn’t just possible, but essential for defending against modern identity attacks and account takeover. ",{"data":40091,"content":40092,"nodeType":876},{},[40093,40097,40105],{"data":40094,"marks":40095,"value":40096,"nodeType":867},{},[],"This is the second post in our design philosophy series, so if you want to read about how we’re building detections that are hard for attackers to bypass using the Pyramid of Pain, ",{"data":40098,"content":40099,"nodeType":915},{"uri":967},[40100],{"data":40101,"marks":40102,"value":40104,"nodeType":867},{},[40103],{"type":913},"you can check it out here",{"data":40106,"marks":40107,"value":5704,"nodeType":867},{},[],{"data":40109,"content":40110,"nodeType":876},{},[40111],{"data":40112,"marks":40113,"value":40114,"nodeType":867},{},[],"We look forward to sharing more about our design philosophy with you in the future! ",{"entries":40116},{"hyperlink":40117,"inline":40118,"block":40119},[],[],[40120,40123,40130,40137,40143,40149,40157,40164],{"sys":40121,"__typename":1697,"type":1698,"ctaText":40122,"buttonLabel":8609,"buttonColour":1701,"buttonUrl":967},{"id":39321},"New to the series? Read our first design principles blog on building better detections using the Pyramid of Pain",{"sys":40124,"__typename":1688,"title":40125,"caption":40125,"layoutMode":59,"file":40126},{"id":39342},"Network compromise in a traditional 'on-prem' environment",{"url":40127,"width":40128,"height":40129},"https://images.ctfassets.net/y1cdw1ablpvd/2kWUeTHvxsqJDvXP0v2Mev/57cc372e313a1d36e9c53e4c099831b1/Traditional_attack_path.png",1362,597,{"sys":40131,"__typename":1688,"title":40132,"caption":40132,"layoutMode":59,"file":40133},{"id":39355},"The typical attack path (according to old-school consultancies and MSSPs)",{"url":40134,"width":40135,"height":40136},"https://images.ctfassets.net/y1cdw1ablpvd/2lqJtgZROb1Qyoa0myb692/37dedf4120ba60cfb340fd3a69bea248/Typical_hybrid_attack_path.png",1535,893,{"sys":40138,"__typename":1688,"title":40139,"caption":40139,"layoutMode":59,"file":40140},{"id":39383},"The average SaaS attack path involves direct in-app compromise following account takeover",{"url":40141,"width":40128,"height":40142},"https://images.ctfassets.net/y1cdw1ablpvd/3DOQd2fcWYdjMSVBZZvHHU/2cd487cb316aef8acd77e14a1960c391/SaaS_attack_path.png",458,{"sys":40144,"__typename":1688,"title":40145,"caption":40146,"layoutMode":59,"file":40147},{"id":39817},"Paths to account takeover","Overlapping paths to account takeover via phishing, infostealers and credential stuffing",{"url":40148,"width":40135,"height":40136},"https://images.ctfassets.net/y1cdw1ablpvd/3UZL6NydNnGa0kJHF9s6Ld/2fdb6d3aa8abb45d89cf334f5d3e9139/Paths_to_account_takeover__1_.png",{"sys":40150,"__typename":1688,"title":40151,"caption":40152,"layoutMode":59,"file":40153},{"id":39948},"Browser visibility and telemetry","The browser provides deep, real time visibility of the rendered web app and user activity",{"url":40154,"width":40155,"height":40156},"https://images.ctfassets.net/y1cdw1ablpvd/7ntzZN0bNnt4Rc3kseTfji/d303986b42f9bab60a6566c5694d26b7/image2.png",1786,738,{"sys":40158,"__typename":1688,"title":40159,"caption":40160,"layoutMode":59,"file":40161},{"id":39961},"Identity attack detection without Push","TI-driven blocklists and email scanning tools are routinely bypassed by attackers",{"url":40162,"width":40135,"height":40163},"https://images.ctfassets.net/y1cdw1ablpvd/1pyLJUgcNuPV2hHz8BgXt6/6e587945d0985e9025e9e628efc2e227/Phishing_detection_without_Push__6_.png",764,{"sys":40165,"__typename":1688,"title":40166,"caption":40167,"layoutMode":59,"file":40168},{"id":39974},"Identity attack detection with Push","Push detects and blocks multiple stages of an account takeover attempt",{"url":40169,"width":40135,"height":40163},"https://images.ctfassets.net/y1cdw1ablpvd/3DfcvJLYux6dAVkf6w0izK/0b2ecf039f7f8c749c05a4cde306f4b6/Session_hijacking_detection_with_Push__1_.png",{"items":40171},[],{},"Detect attacks left of boom, before attackers get a foothold",{"url":40175},"https://images.ctfassets.net/y1cdw1ablpvd/32uMppErtDqKKUWVxBF0xG/5dc1ab2271688efacead5b0aaf2cab8e/Legacy_and_modern_attack_paths.png","2024-10-25T00:00:00.000Z",{"items":40178},[40179,40837,42071],{"__typename":1772,"sys":40180,"content":40181,"title":40823,"synopsis":40824,"hashTags":59,"publishedDate":40825,"slug":40826,"tagsCollection":40827,"authorsCollection":40833},{"id":17785},{"json":40182},{"data":40183,"content":40184,"nodeType":1680},{},[40185,40192,40199,40223,40229,40236,40243,40246,40253,40273,40279,40286,40327,40334,40341,40348,40355,40362,40369,40387,40395,40398,40405,40412,40419,40426,40433,40440,40447,40495,40502,40509,40516,40536,40543,40550,40557,40564,40571,40578,40585,40602,40620,40663,40670,40677,40737,40744,40747,40754,40770,40788,40795,40801,40807,40810,40816],{"data":40186,"content":40187,"nodeType":876},{},[40188],{"data":40189,"marks":40190,"value":40191,"nodeType":867},{},[],"The field of threat detection and security monitoring has changed significantly over the last decade. Security tools and product categories have been added and replaced, specialist disciplines established, and methodologies created. ",{"data":40193,"content":40194,"nodeType":876},{},[40195],{"data":40196,"marks":40197,"value":40198,"nodeType":867},{},[],"Naturally, defenders have had to mature their approach because of the changing nature of the threat facing organizations. Attackers have always looked for new ways to target their victims, and naturally, defenders have had to adapt, forcing attackers to change things up… it’s a cat and mouse game. ",{"data":40200,"content":40201,"nodeType":876},{},[40202,40206,40214,40218],{"data":40203,"marks":40204,"value":40205,"nodeType":867},{},[],"Blue teamers have used the concept of the ",{"data":40207,"content":40209,"nodeType":915},{"uri":40208},"https://detect-respond.blogspot.com/2013/03/the-pyramid-of-pain.html",[40210],{"data":40211,"marks":40212,"value":972,"nodeType":867},{},[40213],{"type":913},{"data":40215,"marks":40216,"value":40217,"nodeType":867},{},[]," for over a decade. The logic is simple: ",{"data":40219,"marks":40220,"value":40222,"nodeType":867},{},[40221],{"type":865},"Focus on detecting and responding to indicators that are hard for attackers to change. ",{"data":40224,"content":40228,"nodeType":985},{"target":40225},{"sys":40226},{"id":40227,"type":982,"linkType":983},"6cG2fx3AikwptyEyXKrYCK",[],{"data":40230,"content":40231,"nodeType":876},{},[40232],{"data":40233,"marks":40234,"value":40235,"nodeType":867},{},[],"If an attacker only has to tweak a variable to get around your detection rule, like adding a space to change a hash value, it’s probably not a very good detection. It’s not going to remain effective for long and you’re always going to be one step behind the attacker – waiting for them to make their next move so you can react. This usually ends up meaning that attackers enjoy at least some success before they can be shut out again. ",{"data":40237,"content":40238,"nodeType":876},{},[40239],{"data":40240,"marks":40241,"value":40242,"nodeType":867},{},[],"The Pyramid of Pain – and the goal of implementing hard-to-bypass detections that hit attackers where it hurts – is central to our design philosophy. But before we get into how we apply this approach, and the types of controls we’ve created as a result, it’s useful to look at how IT and security have changed since the Pyramid was created more than a decade ago. ",{"data":40244,"content":40245,"nodeType":942},{},[],{"data":40247,"content":40248,"nodeType":868},{},[40249],{"data":40250,"marks":40251,"value":40252,"nodeType":867},{},[],"A new era for cyber security",{"data":40254,"content":40255,"nodeType":876},{},[40256,40260,40269],{"data":40257,"marks":40258,"value":40259,"nodeType":867},{},[],"We’ve spoken a lot about how we’re in the midst of a new era in cybersecurity, in which identity is now the outermost digital perimeter for security teams to defend. (",{"data":40261,"content":40263,"nodeType":915},{"uri":40262},"https://pushsecurity.com/resources/video/the-new-saas-cyber-kill-chain-so-con-2024/",[40264],{"data":40265,"marks":40266,"value":40268,"nodeType":867},{},[40267],{"type":913},"You’ll be familiar with this if you’ve seen any of Luke’s talks on the New SaaS Cyber Kill Chain.",{"data":40270,"marks":40271,"value":40272,"nodeType":867},{},[],") ",{"data":40274,"content":40278,"nodeType":985},{"target":40275},{"sys":40276},{"id":40277,"type":982,"linkType":983},"6nYSZAYpsbj78jKm0q75zs",[],{"data":40280,"content":40281,"nodeType":876},{},[40282],{"data":40283,"marks":40284,"value":40285,"nodeType":867},{},[],"This is primarily because modern working is no longer contained to a heavily centralized corporate network, and instead happens primarily in applications accessed over the internet via web browser.",{"data":40287,"content":40288,"nodeType":876},{},[40289,40293,40300,40304,40311,40315,40323],{"data":40290,"marks":40291,"value":40292,"nodeType":867},{},[],"In this new world, attacks don’t even have to touch the old perimeters, because all the data and functionality they could want exists on the public internet. As a result, we’re seeing more and more ",{"data":40294,"content":40295,"nodeType":915},{"uri":14760},[40296],{"data":40297,"marks":40298,"value":40299,"nodeType":867},{},[],"attacks targeting SaaS apps",{"data":40301,"marks":40302,"value":40303,"nodeType":867},{},[],", with the entire attack chain being concluded outside customer networks, not touching any traditional endpoints or networks. The ",{"data":40305,"content":40306,"nodeType":915},{"uri":15290},[40307],{"data":40308,"marks":40309,"value":40310,"nodeType":867},{},[],"recent attacks on Snowflake customers",{"data":40312,"marks":40313,"value":40314,"nodeType":867},{},[],", hailed ",{"data":40316,"content":40318,"nodeType":915},{"uri":40317},"https://www.wired.com/story/snowflake-breach-advanced-auto-parts-lendingtree/",[40319],{"data":40320,"marks":40321,"value":40322,"nodeType":867},{},[],"one of the biggest breaches in history",{"data":40324,"marks":40325,"value":40326,"nodeType":867},{},[],", demonstrate this risk all too well. ",{"data":40328,"content":40329,"nodeType":876},{},[40330],{"data":40331,"marks":40332,"value":40333,"nodeType":867},{},[],"This creates a problem for security teams looking to detect and respond to these attacks. ",{"data":40335,"content":40336,"nodeType":1058},{},[40337],{"data":40338,"marks":40339,"value":40340,"nodeType":867},{},[],"Attacks today are shorter and faster, but just as dangerous",{"data":40342,"content":40343,"nodeType":876},{},[40344],{"data":40345,"marks":40346,"value":40347,"nodeType":867},{},[],"Detecting and responding to identity attacks – phishing, credential stuffing, etc. – used to be just one possible method of initial access in quite a lengthy Kill Chain that stretched from the compromise of the user device, pivoting to internal network resources, escalating privileges, moving laterally, and finally achieving their objectives.",{"data":40349,"content":40350,"nodeType":876},{},[40351],{"data":40352,"marks":40353,"value":40354,"nodeType":867},{},[],"This meant that defenders could adopt an assumed compromise mentality and build layered detections, as well as proactively hunting for threats across these various stages and layers of the network. The more actions an attacker has to perform, the more opportunities for detection, and the higher the likelihood that they’ll be caught in the act before any real, lasting damage can be caused. ",{"data":40356,"content":40357,"nodeType":876},{},[40358],{"data":40359,"marks":40360,"value":40361,"nodeType":867},{},[],"Today, attackers have a lot of opportunities to cause significant damage for much less effort than before. For example, if the goal is to compromise an app like Snowflake and dump the data from it, the Kill Chain is way shorter than a traditional network-based attack. And all the great tools and security products you have, like EDR, don’t come into play. ",{"data":40363,"content":40364,"nodeType":876},{},[40365],{"data":40366,"marks":40367,"value":40368,"nodeType":867},{},[],"This means that the initial layer of anti-account takeover controls are much more important in this context. But, the historical detections in this space – email gateway security products, analyzing web pages for malicious content, and URL blocklisting – are either less relevant, or built upon easy to bypass detections toward the bottom of the Pyramid of Pain. ",{"data":40370,"content":40371,"nodeType":876},{},[40372,40376,40383],{"data":40373,"marks":40374,"value":40375,"nodeType":867},{},[],"As an example, ",{"data":40377,"content":40378,"nodeType":915},{"uri":34554},[40379],{"data":40380,"marks":40381,"value":40382,"nodeType":867},{},[],"we recently published an article on all the ways that AitM phishing sites are evading detection",{"data":40384,"marks":40385,"value":40386,"nodeType":867},{},[],". TL;DR – there are a lot, and they seem to be quite effective. But this is partly because the majority of the detections they're trying to avoid are built on shaky ground.   ",{"data":40388,"content":40389,"nodeType":876},{},[40390],{"data":40391,"marks":40392,"value":40394,"nodeType":867},{},[40393],{"type":865},"So what? Well, it’s clear that the controls that the industry has relied on in the past to stop identity attacks are too easy to bypass, and are no longer sufficient. ",{"data":40396,"content":40397,"nodeType":942},{},[],{"data":40399,"content":40400,"nodeType":868},{},[40401],{"data":40402,"marks":40403,"value":40404,"nodeType":867},{},[],"Building effective identity threat detection controls",{"data":40406,"content":40407,"nodeType":876},{},[40408],{"data":40409,"marks":40410,"value":40411,"nodeType":867},{},[],"Now we’ve covered the problem that we set out to solve, let’s look at what we’re doing differently. ",{"data":40413,"content":40414,"nodeType":876},{},[40415],{"data":40416,"marks":40417,"value":40418,"nodeType":867},{},[],"In order to climb the Pyramid toward the apex, you need to find ways to detect increasingly generic parts of an attack technique. So you want to avoid things like what a specific malware’s code looks like, or where it connects back to. But what the malware does, or what happens when it runs, is more generic, and therefore more interesting to us.  ",{"data":40420,"content":40421,"nodeType":876},{},[40422],{"data":40423,"marks":40424,"value":40425,"nodeType":867},{},[],"The shift from static code signatures and fuzzy hashes to dynamic analysis of what code does on a live system is at the heart of why EDR killed antivirus a decade ago. It proved at-scale the value of moving detections up the pyramid.",{"data":40427,"content":40428,"nodeType":876},{},[40429],{"data":40430,"marks":40431,"value":40432,"nodeType":867},{},[],"We’re always on the lookout for ways to move our detections up the pyramid as well. It’s easiest to explain how we’ve applied this by looking at an example. ",{"data":40434,"content":40435,"nodeType":1058},{},[40436],{"data":40437,"marks":40438,"value":40439,"nodeType":867},{},[],"Scenario: Detecting a web-based phishing attack",{"data":40441,"content":40442,"nodeType":876},{},[40443],{"data":40444,"marks":40445,"value":40446,"nodeType":867},{},[],"Let’s break down the stages of a web-based phishing attack as an example. For a user to be successfully phished:",{"data":40448,"content":40449,"nodeType":1629},{},[40450,40465,40480],{"data":40451,"content":40452,"nodeType":1586},{},[40453],{"data":40454,"content":40455,"nodeType":876},{},[40456,40461],{"data":40457,"marks":40458,"value":40460,"nodeType":867},{},[40459],{"type":865},"Stage 1:",{"data":40462,"marks":40463,"value":40464,"nodeType":867},{},[]," The victim must be lured to visit a website.",{"data":40466,"content":40467,"nodeType":1586},{},[40468],{"data":40469,"content":40470,"nodeType":876},{},[40471,40476],{"data":40472,"marks":40473,"value":40475,"nodeType":867},{},[40474],{"type":865},"Stage 2:",{"data":40477,"marks":40478,"value":40479,"nodeType":867},{},[]," The website must somehow trick or convince the user that it’s legitimate and trustworthy, for example by mimicking a legitimate site.",{"data":40481,"content":40482,"nodeType":1586},{},[40483],{"data":40484,"content":40485,"nodeType":876},{},[40486,40491],{"data":40487,"marks":40488,"value":40490,"nodeType":867},{},[40489],{"type":865},"Stage 3:",{"data":40492,"marks":40493,"value":40494,"nodeType":867},{},[]," The user must enter their actual credentials into that website.",{"data":40496,"content":40497,"nodeType":876},{},[40498],{"data":40499,"marks":40500,"value":40501,"nodeType":867},{},[],"So, how might you go about detecting this attack? Let’s start from the bottom of the pyramid and work our way up.",{"data":40503,"content":40504,"nodeType":1058},{},[40505],{"data":40506,"marks":40507,"value":40508,"nodeType":867},{},[],"Stage 1: Determining if a URL, IP, or domain is bad",{"data":40510,"content":40511,"nodeType":876},{},[40512],{"data":40513,"marks":40514,"value":40515,"nodeType":867},{},[],"You might start by looking for the lure – historically an email. You could look for links in emails, or links in attachments in an email and then check if they are bad (which is essentially what email security products do). You could look for known-bad URLs in emails, but these change for every phishing campaign. In modern attacks, every target can receive a unique email and link. Even just using a URL shortener can bypass this. It’s equivalent to a malware hash – trivial to change, and therefore not a great thing to pin your detections on. ",{"data":40517,"content":40518,"nodeType":876},{},[40519,40523,40532],{"data":40520,"marks":40521,"value":40522,"nodeType":867},{},[],"You could look at which IP address the user connects to, but these days it’s very simple for attackers to add a new IP to their cloud-hosted server. If a domain is flagged as known-bad, the attacker only has to register a new domain, or compromise a WordPress server on an already trusted domain. Both of these things are ",{"data":40524,"content":40526,"nodeType":915},{"uri":40525},"https://www.bleepingcomputer.com/news/security/revolver-rabbit-gang-registers-500-000-domains-for-malware-campaigns/",[40527],{"data":40528,"marks":40529,"value":40531,"nodeType":867},{},[40530],{"type":913},"happening on a massive scale",{"data":40533,"marks":40534,"value":40535,"nodeType":867},{},[]," as attackers pre-plan for the fact that their domains will be burned at some point. Attackers are more than happy to spend $10-$20 per new domain in the grand scheme of the potential proceeds of crime. ",{"data":40537,"content":40538,"nodeType":876},{},[40539],{"data":40540,"marks":40541,"value":40542,"nodeType":867},{},[],"But there’s a more fundamental flaw here – for defenders to know that a URL, IP, or domain name is bad, it needs to be reported first. When are things reported? Typically after being used in an attack – so unfortunately, someone always gets hurt.  ",{"data":40544,"content":40545,"nodeType":1058},{},[40546],{"data":40547,"marks":40548,"value":40549,"nodeType":867},{},[],"Stage 2: Determining if a site is legitimate",{"data":40551,"content":40552,"nodeType":876},{},[40553],{"data":40554,"marks":40555,"value":40556,"nodeType":867},{},[],"So how can we detect a phishing website, on day-zero, the first time anyone runs into it? Well we can look at the second step – does the URL resemble a real website, does the HTML code for a page look similar to a legitimate login page for a known website, is it loading the same image files? This is not trivial to detect, but with the right fuzzy matches and image analysis it can be automated.",{"data":40558,"content":40559,"nodeType":876},{},[40560],{"data":40561,"marks":40562,"value":40563,"nodeType":867},{},[],"We’ve now moved up a level on the Pyramid – we’re detecting website artifacts. If we see a legitimate looking website on an unknown domain, it’s likely to be a malicious clone.",{"data":40565,"content":40566,"nodeType":876},{},[40567],{"data":40568,"marks":40569,"value":40570,"nodeType":867},{},[],"Unfortunately, the attacker’s website doesn’t need to send each visitor to the same website. It can change dynamically based on where the visitor is coming from – or even randomly, so that not all visitors are served the phishing page. This means that tools which resolve where the links in emails go to be able to analyze them (such as email security appliances) don’t necessarily see the same site the user is actually visiting – a fact that is commonly abused by attackers to bypass detection. It’s critical that detection happens on the actual web page that the victim sees.",{"data":40572,"content":40573,"nodeType":1058},{},[40574],{"data":40575,"marks":40576,"value":40577,"nodeType":867},{},[],"Stage 3: Detecting the user entering their credentials",{"data":40579,"content":40580,"nodeType":876},{},[40581],{"data":40582,"marks":40583,"value":40584,"nodeType":867},{},[],"For a phishing attack to succeed, the victim must enter their actual credentials into the webpage. If you can stop the user entering their real password, there’s no attack. There’s no getting around it. ",{"data":40586,"content":40587,"nodeType":876},{},[40588,40592,40599],{"data":40589,"marks":40590,"value":40591,"nodeType":867},{},[],"So, this is exactly what we did: Earlier this year, we released a control which ",{"data":40593,"content":40594,"nodeType":915},{"uri":22796},[40595],{"data":40596,"marks":40597,"value":40598,"nodeType":867},{},[],"stops users from entering their password belonging to a particular login page anywhere else",{"data":40600,"marks":40601,"value":1679,"nodeType":867},{},[],{"data":40603,"content":40604,"nodeType":876},{},[40605,40609,40616],{"data":40606,"marks":40607,"value":40608,"nodeType":867},{},[],"Seems simple, right? By focusing on this generic action, that always has to happen, you can essentially stop your users being phished altogether. This means, it doesn’t matter ",{"data":40610,"content":40611,"nodeType":915},{"uri":34554},[40612],{"data":40613,"marks":40614,"value":40615,"nodeType":867},{},[],"what the attacker does before that point",{"data":40617,"marks":40618,"value":40619,"nodeType":867},{},[],":",{"data":40621,"content":40622,"nodeType":1629},{},[40623,40633,40643,40653],{"data":40624,"content":40625,"nodeType":1586},{},[40626],{"data":40627,"content":40628,"nodeType":876},{},[40629],{"data":40630,"marks":40631,"value":40632,"nodeType":867},{},[],"It doesn't matter if they run the site using Cloudflare Workers to block automatic analysis.",{"data":40634,"content":40635,"nodeType":1586},{},[40636],{"data":40637,"content":40638,"nodeType":876},{},[40639],{"data":40640,"marks":40641,"value":40642,"nodeType":867},{},[],"It doesn’t matter if they hack a WordPress blog to get a reputable domain.",{"data":40644,"content":40645,"nodeType":1586},{},[40646],{"data":40647,"content":40648,"nodeType":876},{},[40649],{"data":40650,"marks":40651,"value":40652,"nodeType":867},{},[],"It doesn’t matter if they use clever redirects and rotate the URLs delivered to the user.",{"data":40654,"content":40655,"nodeType":1586},{},[40656],{"data":40657,"content":40658,"nodeType":876},{},[40659],{"data":40660,"marks":40661,"value":40662,"nodeType":867},{},[],"It doesn’t matter if they randomize the HTML title for the web page. ",{"data":40664,"content":40665,"nodeType":876},{},[40666],{"data":40667,"marks":40668,"value":40669,"nodeType":867},{},[],"They can’t avoid the fact that a user is required to enter their credentials on the page for the attack to succeed. ",{"data":40671,"content":40672,"nodeType":876},{},[40673],{"data":40674,"marks":40675,"value":40676,"nodeType":867},{},[],"So, when you apply the Pyramid of Pain to some of the controls we’ve shipped this year, we get a clear feel for the value, from highest to lowest:",{"data":40678,"content":40679,"nodeType":1629},{},[40680,40699,40718],{"data":40681,"content":40682,"nodeType":1586},{},[40683],{"data":40684,"content":40685,"nodeType":876},{},[40686,40690,40696],{"data":40687,"marks":40688,"value":40689,"nodeType":867},{},[],"User Behavior: ",{"data":40691,"content":40692,"nodeType":915},{"uri":22796},[40693],{"data":40694,"marks":40695,"value":40044,"nodeType":867},{},[],{"data":40697,"marks":40698,"value":5704,"nodeType":867},{},[],{"data":40700,"content":40701,"nodeType":1586},{},[40702],{"data":40703,"content":40704,"nodeType":876},{},[40705,40709,40715],{"data":40706,"marks":40707,"value":40708,"nodeType":867},{},[],"Tool Behavior: ",{"data":40710,"content":40711,"nodeType":915},{"uri":39998},[40712],{"data":40713,"marks":40714,"value":40003,"nodeType":867},{},[],{"data":40716,"marks":40717,"value":21,"nodeType":867},{},[],{"data":40719,"content":40720,"nodeType":1586},{},[40721],{"data":40722,"content":40723,"nodeType":876},{},[40724,40728,40734],{"data":40725,"marks":40726,"value":40727,"nodeType":867},{},[],"Tool Signature: ",{"data":40729,"content":40730,"nodeType":915},{"uri":40019},[40731],{"data":40732,"marks":40733,"value":40024,"nodeType":867},{},[],{"data":40735,"marks":40736,"value":5704,"nodeType":867},{},[],{"data":40738,"content":40739,"nodeType":876},{},[40740],{"data":40741,"marks":40742,"value":40743,"nodeType":867},{},[],"Naturally, we want to continue focusing on the apex of the Pyramid – at TTPs and Tools – to ensure that the controls we build are as robust as possible, and can’t be bypassed by attackers. ",{"data":40745,"content":40746,"nodeType":942},{},[],{"data":40748,"content":40749,"nodeType":868},{},[40750],{"data":40751,"marks":40752,"value":40753,"nodeType":867},{},[],"The power of the Push browser agent",{"data":40755,"content":40756,"nodeType":876},{},[40757,40761,40766],{"data":40758,"marks":40759,"value":40760,"nodeType":867},{},[],"You might ask: ",{"data":40762,"marks":40763,"value":40765,"nodeType":867},{},[40764],{"type":865},"If it’s so simple, why hasn’t this been done yet?",{"data":40767,"marks":40768,"value":40769,"nodeType":867},{},[]," Well, before now, there was no good way of doing it! Teams simply didn’t have tools in the right place to be able to capture the level of data needed, or respond effectively (i.e. automatically, at the point of impact). ",{"data":40771,"content":40772,"nodeType":876},{},[40773,40777,40784],{"data":40774,"marks":40775,"value":40776,"nodeType":867},{},[],"This is where being in the browser comes into play. The browser is a great place to observe the behavior of a page in real time, without needing to reconstruct decrypted HTTP data post-TLS termination and try to guess what the rendered page in all its Javascript-infused glory actually does, ",{"data":40778,"content":40779,"nodeType":915},{"uri":27034},[40780],{"data":40781,"marks":40782,"value":40783,"nodeType":867},{},[],"as we’ve blogged about previously",{"data":40785,"marks":40786,"value":40787,"nodeType":867},{},[],". As we’ve seen through the ability to not only detect but prevent phishing attacks, it’s also a great control enforcement point, as you’re able to intercept the user at the point of impact, and you sit as closely as possible to where their work typically happens – in the browser. ",{"data":40789,"content":40790,"nodeType":876},{},[40791],{"data":40792,"marks":40793,"value":40794,"nodeType":867},{},[],"To illustrate how crucial the browser is to implementing controls that sit at the apex of the Pyramid of Pain, we created a modified version designed specifically for identity attacks. ",{"data":40796,"content":40800,"nodeType":985},{"target":40797},{"sys":40798},{"id":40799,"type":982,"linkType":983},"HrK2xQak6KfjInDbeSgv8",[],{"data":40802,"content":40806,"nodeType":985},{"target":40803},{"sys":40804},{"id":40805,"type":982,"linkType":983},"7kLilJ8Y08smUI9ttM3BSO",[],{"data":40808,"content":40809,"nodeType":942},{},[],{"data":40811,"content":40812,"nodeType":868},{},[40813],{"data":40814,"marks":40815,"value":23563,"nodeType":867},{},[],{"data":40817,"content":40818,"nodeType":876},{},[40819],{"data":40820,"marks":40821,"value":40822,"nodeType":867},{},[],"Hopefully, this blog post has shone a light on why we do things the way we do here at Push. The goal of building generic detections that are difficult, painful, and costly for attackers to bypass is a key part of our design strategy, and we look forward to sharing many more controls with you that demonstrate this in the future.","Our design philosophy: Detecting what matters","This is the first blog in a short series we’re putting together about the ‘why’ behind the ‘what’ at Push. This entry is focused on threat detection. ","2024-08-05T00:00:00.000Z","our-design-philosophy-detecting-what-matters",{"items":40828},[40829,40831],{"sys":40830,"name":342},{"id":3240},{"sys":40832,"name":4018},{"id":4017},{"items":40834},[40835],{"fullName":4022,"firstName":4023,"jobTitle":4024,"profilePicture":40836},{"url":4026},{"__typename":1772,"sys":40838,"content":40840,"title":42057,"synopsis":42058,"hashTags":59,"publishedDate":42059,"slug":42060,"tagsCollection":42061,"authorsCollection":42067},{"id":40839},"489LTCEVau7lh88tLgSPX5",{"json":40841},{"data":40842,"content":40843,"nodeType":1680},{},[40844,40851,40871,40878,40884,40891,40922,40928,40934,40941,40948,40954,40961,40981,40988,40995,41001,41008,41015,41063,41081,41088,41095,41102,41108,41115,41122,41129,41136,41143,41150,41162,41168,41175,41193,41211,41218,41225,41245,41252,41269,41276,41327,41334,41353,41360,41365,41382,41400,41407,41425,41432,41438,41445,41464,41471,41478,41484,41491,41498,41505,41512,41518,41525,41532,41539,41546,41552,41559,41566,41578,41594,41601,41608,41674,41681,41688,41695,41702,41709,41716,41723,41730,41748,41755,41761,41768,41774,41781,41788,41795,41801,41808,41815,41822,41855,41862,41869,41876,41883,41890,41897,41904,41911,41959,41965,41972,42015,42021,42028,42045,42051],{"data":40845,"content":40846,"nodeType":876},{},[40847],{"data":40848,"marks":40849,"value":40850,"nodeType":867},{},[],"The last time “hacking” topped the attacker actions chart in a Verizon DBIR, Gamestop was being saved by Redditors, ChatGPT didn’t exist, and Will Smith was welcome at the Oscars. ",{"data":40852,"content":40853,"nodeType":876},{},[40854,40858,40867],{"data":40855,"marks":40856,"value":40857,"nodeType":867},{},[],"That’s right, it was back in the ",{"data":40859,"content":40861,"nodeType":915},{"uri":40860},"https://www.verizon.com/business/resources/reports/dbir/2021/masters-guide/",[40862],{"data":40863,"marks":40864,"value":40866,"nodeType":867},{},[40865],{"type":913},"2021 DBIR",{"data":40868,"marks":40869,"value":40870,"nodeType":867},{},[]," that good old-fashioned hacking was the thing hackers did the most. ",{"data":40872,"content":40873,"nodeType":876},{},[40874],{"data":40875,"marks":40876,"value":40877,"nodeType":867},{},[],"In every report since, stolen credentials have been the most common “select way-in” (weird term, I know). In this year’s DBIR, stolen credentials accounted for roughly half of the breaches recorded. ",{"data":40879,"content":40883,"nodeType":985},{"target":40880},{"sys":40881},{"id":40882,"type":982,"linkType":983},"16WQ5Siz92HZKCjDsxWBdr",[],{"data":40885,"content":40886,"nodeType":876},{},[40887],{"data":40888,"marks":40889,"value":40890,"nodeType":867},{},[],"These stats, along with others like CrowdStrike’s widely cited “80% of attacks involve identity and compromised credentials,” continue to prove that “hackers don’t hack in, they log in.” ",{"data":40892,"content":40893,"nodeType":876},{},[40894,40898,40906,40910,40918],{"data":40895,"marks":40896,"value":40897,"nodeType":867},{},[],"In the last year, more stories behind those statistics have started to emerge with a series of high profile “no-hack” identity attacks hitting the headlines – the most recent being the ",{"data":40899,"content":40901,"nodeType":915},{"uri":40900},"https://pushsecurity.com/resources/video/snowflake-the-tip-of-the-iceberg/",[40902],{"data":40903,"marks":40904,"value":24700,"nodeType":867},{},[40905],{"type":913},{"data":40907,"marks":40908,"value":40909,"nodeType":867},{},[],". You can read more about that breach and others in our repository of ",{"data":40911,"content":40912,"nodeType":915},{"uri":37788},[40913],{"data":40914,"marks":40915,"value":40917,"nodeType":867},{},[40916],{"type":913},"identity attacks in the wild",{"data":40919,"marks":40920,"value":40921,"nodeType":867},{},[]," where we take a deep dive into the techniques attackers have been using. ",{"data":40923,"content":40927,"nodeType":985},{"target":40924},{"sys":40925},{"id":40926,"type":982,"linkType":983},"6QY3hnMLMJvnk6zYHYa6pf",[],{"data":40929,"content":40933,"nodeType":985},{"target":40930},{"sys":40931},{"id":40932,"type":982,"linkType":983},"7oAUuhbwgEH5XnDZrm5Zk9",[],{"data":40935,"content":40936,"nodeType":876},{},[40937],{"data":40938,"marks":40939,"value":40940,"nodeType":867},{},[],"Why should they go to the effort of targeting hardened and well-monitored attack surfaces like networks and endpoints with 0-day exploits or EDR-evading malware, when they can instead simply take a set of stolen credentials and fire them at popular business apps to see which pop open?",{"data":40942,"content":40943,"nodeType":876},{},[40944],{"data":40945,"marks":40946,"value":40947,"nodeType":867},{},[],"Taking over an account is the equivalent of compromising an endpoint or getting a foothold on a web-facing server. From this point, an attacker can move laterally, escalate their privileges, and achieve their objective of deploying ransomware, stealing data or disrupting business-critical systems. ",{"data":40949,"content":40953,"nodeType":985},{"target":40950},{"sys":40951},{"id":40952,"type":982,"linkType":983},"3vdbE3kqFxvhE145q2CwOy",[],{"data":40955,"content":40956,"nodeType":876},{},[40957],{"data":40958,"marks":40959,"value":40960,"nodeType":867},{},[],"The data shows that account takeover, whether it’s using stolen credentials or session tokens, is now the route of least resistance for attackers, and the #1 attack vector for security teams to defend against.",{"data":40962,"content":40963,"nodeType":876},{},[40964,40968,40977],{"data":40965,"marks":40966,"value":40967,"nodeType":867},{},[],"I’m sure you already use a number of tools to secure your workforce identities – MFA, SSO, EDR, etc., and all of them have an important role to play. That said, they also have limitations that attackers are exploiting. We’ve laid out some of the ",{"data":40969,"content":40971,"nodeType":915},{"uri":40970},"https://pushsecurity.com/blog/5-reasons-why-push-security-shouldnt-exist/",[40972],{"data":40973,"marks":40974,"value":40976,"nodeType":867},{},[40975],{"type":913},"typical misconceptions that can undermine an identity security strategy",{"data":40978,"marks":40979,"value":40980,"nodeType":867},{},[]," so you can avoid the common pitfalls and achieve defense in depth.",{"data":40982,"content":40983,"nodeType":868},{},[40984],{"data":40985,"marks":40986,"value":40987,"nodeType":867},{},[],"Push vs. account takeover techniques",{"data":40989,"content":40990,"nodeType":876},{},[40991],{"data":40992,"marks":40993,"value":40994,"nodeType":867},{},[],"In this article, we’re going to show you how to use Push to bolster your identity security strategy and prevent account takeover. More specifically, we’ll cover how Push prevents, detects, and blocks some of the common attack techniques seen in this account takeover attack chain:",{"data":40996,"content":41000,"nodeType":985},{"target":40997},{"sys":40998},{"id":40999,"type":982,"linkType":983},"1FPMzCU0mBgpg1GMSz1sJH",[],{"data":41002,"content":41003,"nodeType":876},{},[41004],{"data":41005,"marks":41006,"value":41007,"nodeType":867},{},[],"Push uses browser data collected by our browser agent to either detect the attack techniques directly, or identify the vulnerabilities being exploited. Upon making a detection, the browser agent enforces a relevant security control to either block the attack or prevent the user from introducing a vulnerability.",{"data":41009,"content":41010,"nodeType":876},{},[41011],{"data":41012,"marks":41013,"value":41014,"nodeType":867},{},[],"If you’re wondering why we’ve opted to build our tool in the browser, the short answer is that being in the browser gives us:",{"data":41016,"content":41017,"nodeType":1629},{},[41018,41033,41048],{"data":41019,"content":41020,"nodeType":1586},{},[41021],{"data":41022,"content":41023,"nodeType":876},{},[41024,41029],{"data":41025,"marks":41026,"value":41028,"nodeType":867},{},[41027],{"type":865},"The broadest visibility",{"data":41030,"marks":41031,"value":41032,"nodeType":867},{},[]," across all workforce identities, including unmanaged identities outside your IdP.",{"data":41034,"content":41035,"nodeType":1586},{},[41036],{"data":41037,"content":41038,"nodeType":876},{},[41039,41044],{"data":41040,"marks":41041,"value":41043,"nodeType":867},{},[41042],{"type":865},"The best telemetry",{"data":41045,"marks":41046,"value":41047,"nodeType":867},{},[]," for detecting identity attack TTPs and tools.",{"data":41049,"content":41050,"nodeType":1586},{},[41051],{"data":41052,"content":41053,"nodeType":876},{},[41054,41059],{"data":41055,"marks":41056,"value":41058,"nodeType":867},{},[41057],{"type":865},"The perfect enforcement point",{"data":41060,"marks":41061,"value":41062,"nodeType":867},{},[]," for stopping attacker actions or risky employee actions in real time. ",{"data":41064,"content":41065,"nodeType":876},{},[41066,41070,41078],{"data":41067,"marks":41068,"value":41069,"nodeType":867},{},[],"If you want a more detailed technical explanation, you can read this article by Dan on ",{"data":41071,"content":41072,"nodeType":915},{"uri":27034},[41073],{"data":41074,"marks":41075,"value":41077,"nodeType":867},{},[41076],{"type":913},"why browser data is a better source of telemetry for detecting identity attacks than network, IdP and app logs",{"data":41079,"marks":41080,"value":1679,"nodeType":867},{},[],{"data":41082,"content":41083,"nodeType":876},{},[41084],{"data":41085,"marks":41086,"value":41087,"nodeType":867},{},[],"Now we’ve cleared that up, let's look at some account takeover techniques.",{"data":41089,"content":41090,"nodeType":868},{},[41091],{"data":41092,"marks":41093,"value":41094,"nodeType":867},{},[],"Part 1: Phishing (including AitM and BitM toolkits)",{"data":41096,"content":41097,"nodeType":876},{},[41098],{"data":41099,"marks":41100,"value":41101,"nodeType":867},{},[],"Phishing has been around since forever and there’s a mature category of solutions that are designed to detect and prevent it. But despite solutions like security awareness training, phishing domain detection services and email filtering tools, phishing is still one of the top breach vectors. ",{"data":41103,"content":41107,"nodeType":985},{"target":41104},{"sys":41105},{"id":41106,"type":982,"linkType":983},"4urh9lIuo0ePgVIJZNtP2B",[],{"data":41109,"content":41110,"nodeType":876},{},[41111],{"data":41112,"marks":41113,"value":41114,"nodeType":867},{},[],"We’ve all been conditioned to think about phishing as something that happens over email, but it’s actually the browser where most of the action happens, regardless of the initial delivery channel. Push’s position in the browser gives you the ideal vantage point for detecting and stopping phishing attacks.",{"data":41116,"content":41117,"nodeType":876},{},[41118],{"data":41119,"marks":41120,"value":41121,"nodeType":867},{},[],"The Push browser agent performs both passive observation and active interrogation in order to detect employees having their passwords harvested or visiting cloned app login pages or pages using AitM/BitM toolkits. Phishing attacks are detected in real time so Push blocks them before your employees can enter their credentials.",{"data":41123,"content":41124,"nodeType":1058},{},[41125],{"data":41126,"marks":41127,"value":41128,"nodeType":867},{},[],"Detecting phishing through user behavior",{"data":41130,"content":41131,"nodeType":876},{},[41132],{"data":41133,"marks":41134,"value":41135,"nodeType":867},{},[],"Rather than trying to detect phishing websites and domains that constantly change, Push detects and blocks phishing attempts based on observing user behavior in the browser.",{"data":41137,"content":41138,"nodeType":876},{},[41139],{"data":41140,"marks":41141,"value":41142,"nodeType":867},{},[],"Push does this by observing all logins and generating a fingerprint (or technically a k-anonymized salted partial hash) of the user’s password. This fingerprint is then stored locally to allow Push to perform comparisons.",{"data":41144,"content":41145,"nodeType":876},{},[41146],{"data":41147,"marks":41148,"value":41149,"nodeType":867},{},[],"To detect potential phishing attacks, the browser agent compares the observed password fingerprint to known fingerprints for passwords that already exist in local storage.",{"data":41151,"content":41152,"nodeType":876},{},[41153,41158],{"data":41154,"marks":41155,"value":41157,"nodeType":867},{},[41156],{"type":865},"This means that it works even if that employee was the first person to get phished using a new attacker site: ",{"data":41159,"marks":41160,"value":41161,"nodeType":867},{},[],"Push still detects it and blocks it before your employee can submit their credentials. It also works regardless of the delivery vector used to get the phishing link to the intended victim.",{"data":41163,"content":41167,"nodeType":985},{"target":41164},{"sys":41165},{"id":41166,"type":982,"linkType":983},"2V2My5IpdVUwh4QugqInUw",[],{"data":41169,"content":41170,"nodeType":876},{},[41171],{"data":41172,"marks":41173,"value":41174,"nodeType":867},{},[],"Once you’ve discovered a malicious site, you can use Push’s companion feature, URL blocking, to add the domain to a blocklist and prevent your other end-users from even visiting the site.",{"data":41176,"content":41177,"nodeType":876},{},[41178,41182,41189],{"data":41179,"marks":41180,"value":41181,"nodeType":867},{},[],"You can programmatically manage URL blocking as part of responding to an attempted phishing incident by using the ",{"data":41183,"content":41184,"nodeType":915},{"uri":38608},[41185],{"data":41186,"marks":41187,"value":41188,"nodeType":867},{},[],"Push REST API",{"data":41190,"marks":41191,"value":41192,"nodeType":867},{},[]," to automatically add URLs to the blocklist or to sync with other threat intelligence sources of known-bad sites.",{"data":41194,"content":41195,"nodeType":876},{},[41196,41200,41208],{"data":41197,"marks":41198,"value":41199,"nodeType":867},{},[],"You can find out more about this control in this ",{"data":41201,"content":41202,"nodeType":915},{"uri":22796},[41203],{"data":41204,"marks":41205,"value":41207,"nodeType":867},{},[41206],{"type":913},"deep-dive article",{"data":41209,"marks":41210,"value":5704,"nodeType":867},{},[],{"data":41212,"content":41213,"nodeType":1058},{},[41214],{"data":41215,"marks":41216,"value":41217,"nodeType":867},{},[],"Detecting cloned login pages",{"data":41219,"content":41220,"nodeType":876},{},[41221],{"data":41222,"marks":41223,"value":41224,"nodeType":867},{},[],"It’s now very easy for attackers to create cloned login pages that appear to be legitimate, tricking users into providing their credentials. ",{"data":41226,"content":41227,"nodeType":876},{},[41228,41232,41241],{"data":41229,"marks":41230,"value":41231,"nodeType":867},{},[],"There’s a number of phishing kits that allow the attacker to simply copy the HTML code from a legitimate website and duplicate it on the malicious site, creating a virtually identical interface that tricks users into entering their credentials. A final sprinkle of typosquatting techniques completes the illusion of legitimacy. The Federal Communications Commission (FCC) ",{"data":41233,"content":41235,"nodeType":915},{"uri":41234},"https://www.nextgov.com/cybersecurity/2024/03/fcc-staff-targeted-phishing-attack-cloned-agency-login-site/394609/",[41236],{"data":41237,"marks":41238,"value":41240,"nodeType":867},{},[41239],{"type":913},"was a recent target",{"data":41242,"marks":41243,"value":41244,"nodeType":867},{},[]," of this kind of attack. ",{"data":41246,"content":41247,"nodeType":876},{},[41248],{"data":41249,"marks":41250,"value":41251,"nodeType":867},{},[],"Push’s cloned app detection feature detects fraudulent login pages by inspecting the resources and structure of pages users log into and fingerprinting them so they can be used to detect when that action occurs on the wrong domain. ",{"data":41253,"content":41254,"nodeType":876},{},[41255,41259,41266],{"data":41256,"marks":41257,"value":41258,"nodeType":867},{},[],"You can ",{"data":41260,"content":41261,"nodeType":915},{"uri":39998},[41262],{"data":41263,"marks":41264,"value":41265,"nodeType":867},{},[],"read more about this feature here",{"data":41267,"marks":41268,"value":1679,"nodeType":867},{},[],{"data":41270,"content":41271,"nodeType":1058},{},[41272],{"data":41273,"marks":41274,"value":41275,"nodeType":867},{},[],"Detecting AitM and BitM toolkits",{"data":41277,"content":41278,"nodeType":876},{},[41279,41283,41291,41294,41302,41305,41313,41316,41324],{"data":41280,"marks":41281,"value":41282,"nodeType":867},{},[],"Adversary-in-the-Middle (AitM) phishing is a technique that uses dedicated tooling to act as a proxy between the target and a legitimate login portal for an application, principally to bypass MFA. As it’s a proxy to the real application, the page will appear exactly as the user expects, making this technique difficult to spot. Popular AitM toolkits include ",{"data":41284,"content":41286,"nodeType":915},{"uri":41285},"https://github.com/drk1wi/Modlishka",[41287],{"data":41288,"marks":41289,"value":41290,"nodeType":867},{},[],"Modlishka",{"data":41292,"marks":41293,"value":5136,"nodeType":867},{},[],{"data":41295,"content":41297,"nodeType":915},{"uri":41296},"https://github.com/muraenateam/muraena",[41298],{"data":41299,"marks":41300,"value":41301,"nodeType":867},{},[],"Muraena",{"data":41303,"marks":41304,"value":5136,"nodeType":867},{},[],{"data":41306,"content":41308,"nodeType":915},{"uri":41307},"https://github.com/kgretzky/evilginx2",[41309],{"data":41310,"marks":41311,"value":41312,"nodeType":867},{},[],"Evilginx",{"data":41314,"marks":41315,"value":1174,"nodeType":867},{},[],{"data":41317,"content":41319,"nodeType":915},{"uri":41318},"https://www.bleepingcomputer.com/news/security/evilproxy-uses-indeedcom-open-redirect-for-microsoft-365-phishing/",[41320],{"data":41321,"marks":41322,"value":41323,"nodeType":867},{},[],"Evilproxy",{"data":41325,"marks":41326,"value":5704,"nodeType":867},{},[],{"data":41328,"content":41329,"nodeType":876},{},[41330],{"data":41331,"marks":41332,"value":41333,"nodeType":867},{},[],"Browser-in-the-Middle (BitM) toolkits are different to AitM toolkits because they don’t act as a reverse proxy. Instead, they trick their victim into directly controlling the attacker’s own browser using remote desktop screen sharing and control approaches — think of this like VNC or RDP but using the browser as a client. This is the virtual equivalent of an attacker handing their laptop to their victim, asking them to log in to an app for them, and then taking their laptop back afterwards.",{"data":41335,"content":41336,"nodeType":876},{},[41337,41341,41350],{"data":41338,"marks":41339,"value":41340,"nodeType":867},{},[],"We’ve conducted a lot of research into AitM and BitM toolkits recently. If you want to learn more about how they work and see a demo of them in action, ",{"data":41342,"content":41344,"nodeType":915},{"uri":41343},"https://pushsecurity.com/resources/video/phishing-detecting-evilginx-evilnovnc-muraena-and-modlishka/",[41345],{"data":41346,"marks":41347,"value":41349,"nodeType":867},{},[41348],{"type":913},"head over here",{"data":41351,"marks":41352,"value":5704,"nodeType":867},{},[],{"data":41354,"content":41355,"nodeType":876},{},[41356],{"data":41357,"marks":41358,"value":41359,"nodeType":867},{},[],"Push gives you a preconfigured set of detections for AitM and BitM toolkits, informed by our threat detection team’s research into their behavior. This phishing tool detection feature will automatically prevent users from accessing a site that’s running one of these malicious tools, and display a custom warning message to your end-users.",{"data":41361,"content":41364,"nodeType":985},{"target":41362},{"sys":41363},{"id":32465,"type":982,"linkType":983},[],{"data":41366,"content":41367,"nodeType":876},{},[41368,41372,41378],{"data":41369,"marks":41370,"value":41371,"nodeType":867},{},[],"Administrators can also consume phishing tool detection events via the ",{"data":41373,"content":41374,"nodeType":915},{"uri":38608},[41375],{"data":41376,"marks":41377,"value":41188,"nodeType":867},{},[],{"data":41379,"marks":41380,"value":41381,"nodeType":867},{},[]," into their SIEM or use Push’s webhooks to alert when a warn or block event has occurred.",{"data":41383,"content":41384,"nodeType":876},{},[41385,41389,41397],{"data":41386,"marks":41387,"value":41388,"nodeType":867},{},[],"You can read a full write-up of this feature if you want to ",{"data":41390,"content":41391,"nodeType":915},{"uri":40019},[41392],{"data":41393,"marks":41394,"value":41396,"nodeType":867},{},[41395],{"type":913},"learn more",{"data":41398,"marks":41399,"value":5704,"nodeType":867},{},[],{"data":41401,"content":41402,"nodeType":868},{},[41403],{"data":41404,"marks":41405,"value":41406,"nodeType":867},{},[],"Part 2: Infostealer malware",{"data":41408,"content":41409,"nodeType":876},{},[41410,41414,41421],{"data":41411,"marks":41412,"value":41413,"nodeType":867},{},[],"The recent ",{"data":41415,"content":41416,"nodeType":915},{"uri":15290},[41417],{"data":41418,"marks":41419,"value":6819,"nodeType":867},{},[41420],{"type":913},{"data":41422,"marks":41423,"value":41424,"nodeType":867},{},[]," highlighted how infostealer malware is becoming a serious issue for security teams. As well as being able to steal credentials for account takeover, infostealers can also be used to steal session tokens which then allow the attacker to assume an already authorized session without needing to bypass MFA.   ",{"data":41426,"content":41427,"nodeType":876},{},[41428],{"data":41429,"marks":41430,"value":41431,"nodeType":867},{},[],"Nearly half of the malware detected last year by Sophos targeted victims’ data specifically, and the majority of that malware was classified as infostealers. ",{"data":41433,"content":41437,"nodeType":985},{"target":41434},{"sys":41435},{"id":41436,"type":982,"linkType":983},"66B5MBFIhbmky7VuLGbuM3",[],{"data":41439,"content":41440,"nodeType":876},{},[41441],{"data":41442,"marks":41443,"value":41444,"nodeType":867},{},[],"Infostealers are primarily being used by Initial Access Brokers to harvest credentials and session tokens that they then sell to other threat actors intent on executing more penetrating attacks (e.g. ransomware).  ",{"data":41446,"content":41447,"nodeType":876},{},[41448,41452,41461],{"data":41449,"marks":41450,"value":41451,"nodeType":867},{},[],"EDR is seen as the go-to solution for defending against infostealer malware. However, attackers are always looking for ways to get around security controls by obfuscating malicious behavior and evading signature-based checks. For example, ",{"data":41453,"content":41455,"nodeType":915},{"uri":41454},"https://thehackernews.com/2024/07/microsoft-defender-flaw-exploited-to.html",[41456],{"data":41457,"marks":41458,"value":41460,"nodeType":867},{},[41459],{"type":913},"a flaw in Microsoft Defender SmartScreen was recently exploited to deliver infostealer malware",{"data":41462,"marks":41463,"value":1679,"nodeType":867},{},[],{"data":41465,"content":41466,"nodeType":876},{},[41467],{"data":41468,"marks":41469,"value":41470,"nodeType":867},{},[],"Getting total coverage across your endpoint estate is notoriously difficult, if not totally unrealistic. Unless the malware is stopped on execution, then data will inevitably be stolen, and will continue to be taken until stopped (or it self-terminates). And once an attacker has stolen employee credentials or sessions, the credential stuffing and session hijacking attacks that come next won’t touch the endpoint. ",{"data":41472,"content":41473,"nodeType":876},{},[41474],{"data":41475,"marks":41476,"value":41477,"nodeType":867},{},[],"For those reasons, you can’t rely on EDR as a single line of defense against infostealers. Push gives you those extra layers of defense to stop account takeover attempts that use stolen credentials and sessions.",{"data":41479,"content":41483,"nodeType":985},{"target":41480},{"sys":41481},{"id":41482,"type":982,"linkType":983},"4YB6DLIE5TvaAsAAUoJd5v",[],{"data":41485,"content":41486,"nodeType":1058},{},[41487],{"data":41488,"marks":41489,"value":41490,"nodeType":867},{},[],"Detecting stolen sessions ",{"data":41492,"content":41493,"nodeType":876},{},[41494],{"data":41495,"marks":41496,"value":41497,"nodeType":867},{},[],"Push uses its browser agent to inject a unique marker into the user agent string of sessions that occur in browsers enrolled in Push. You then add the list of domains where you wish to inject the marker into sessions, such as an identity provider like Okta or Microsoft. ",{"data":41499,"content":41500,"nodeType":876},{},[41501],{"data":41502,"marks":41503,"value":41504,"nodeType":867},{},[],"By analyzing logs from the IdP, you can identify activity from the same session that both has the Push marker and that lacks the marker. This can only ever happen when a session is extracted from a browser and maliciously imported into a different browser.",{"data":41506,"content":41507,"nodeType":876},{},[41508],{"data":41509,"marks":41510,"value":41511,"nodeType":867},{},[],"This is a high-fidelity signal that a stolen session token is being used by an attacker. It’s certainly a lot cleaner than relying on IP-based or geolocation-based signals, which result in frequent false positives.",{"data":41513,"content":41517,"nodeType":985},{"target":41514},{"sys":41515},{"id":41516,"type":982,"linkType":983},"1XNNkaoW64t3PPvC54KGXF",[],{"data":41519,"content":41520,"nodeType":1058},{},[41521],{"data":41522,"marks":41523,"value":41524,"nodeType":867},{},[],"Detecting stolen credentials being sold on the dark web",{"data":41526,"content":41527,"nodeType":876},{},[41528],{"data":41529,"marks":41530,"value":41531,"nodeType":867},{},[],"Push integrates stolen credential threat intelligence and alerts you when your employees’ credentials are being sold on the dark web. ",{"data":41533,"content":41534,"nodeType":876},{},[41535],{"data":41536,"marks":41537,"value":41538,"nodeType":867},{},[],"Commercial TI feeds of stolen credentials have been available for some time. But what we’ve found is that the false-positive rate is incredibly high and the vast majority of credentials are no longer in use.",{"data":41540,"content":41541,"nodeType":876},{},[41542],{"data":41543,"marks":41544,"value":41545,"nodeType":867},{},[],"Push validates that leaked credentials match those that are currently being used by your employees to authenticate on any apps they are using in the browser. That means that any alerts or automated actions generated by Push are actionable true positives, cutting out a huge amount of noise and saving your security team time. ",{"data":41547,"content":41551,"nodeType":985},{"target":41548},{"sys":41549},{"id":41550,"type":982,"linkType":983},"3RnPM0ioGWi3CFMLkxQanO",[],{"data":41553,"content":41554,"nodeType":868},{},[41555],{"data":41556,"marks":41557,"value":41558,"nodeType":867},{},[],"Part 3: Credential stuffing",{"data":41560,"content":41561,"nodeType":876},{},[41562],{"data":41563,"marks":41564,"value":41565,"nodeType":867},{},[],"The previous sections looked at how Push detects and stops common techniques used for stealing and acquiring credentials. We’re now going to cover how Push stops stolen credentials from being used to access and take over employee accounts. ",{"data":41567,"content":41568,"nodeType":876},{},[41569,41574],{"data":41570,"marks":41571,"value":41573,"nodeType":867},{},[41572],{"type":865},"Credential stuffing ",{"data":41575,"marks":41576,"value":41577,"nodeType":867},{},[],"is when attackers use tools that automate the process of taking a list of stolen passwords and retargeting those credentials against different apps.",{"data":41579,"content":41580,"nodeType":876},{},[41581,41585,41590],{"data":41582,"marks":41583,"value":41584,"nodeType":867},{},[],"Closely related to credential stuffing is ",{"data":41586,"marks":41587,"value":41589,"nodeType":867},{},[41588],{"type":865},"password spraying",{"data":41591,"marks":41592,"value":41593,"nodeType":867},{},[],". Instead of using stolen credentials, an attacker uses a list of commonly used usernames and passwords to attempt to compromise accounts. ",{"data":41595,"content":41596,"nodeType":876},{},[41597],{"data":41598,"marks":41599,"value":41600,"nodeType":867},{},[],"Both credential stuffing and password spraying are high-volume, automated attacks, and they are an unrelenting problem for most businesses. Microsoft observes 4,000 of them every second and nearly half of all login requests Auth0 receive each day are attempts at credential stuffing. ",{"data":41602,"content":41603,"nodeType":876},{},[41604],{"data":41605,"marks":41606,"value":41607,"nodeType":867},{},[],"The true scale of the problem is hard to grasp, as neither app vendors nor users have effective means of monitoring for unauthorized access. Typically these breaches are only detected when:",{"data":41609,"content":41610,"nodeType":1629},{},[41611,41631,41652],{"data":41612,"content":41613,"nodeType":1586},{},[41614],{"data":41615,"content":41616,"nodeType":876},{},[41617,41621,41628],{"data":41618,"marks":41619,"value":41620,"nodeType":867},{},[],"The attacker leaks the data they’ve stolen, like in the ",{"data":41622,"content":41623,"nodeType":915},{"uri":15290},[41624],{"data":41625,"marks":41626,"value":6819,"nodeType":867},{},[41627],{"type":913},{"data":41629,"marks":41630,"value":5704,"nodeType":867},{},[],{"data":41632,"content":41633,"nodeType":1586},{},[41634],{"data":41635,"content":41636,"nodeType":876},{},[41637,41641,41649],{"data":41638,"marks":41639,"value":41640,"nodeType":867},{},[],"The attacker deploys ransomware that results in business disruption, like that suffered by ",{"data":41642,"content":41643,"nodeType":915},{"uri":27820},[41644],{"data":41645,"marks":41646,"value":41648,"nodeType":867},{},[41647],{"type":913},"MGM resorts",{"data":41650,"marks":41651,"value":1679,"nodeType":867},{},[],{"data":41653,"content":41654,"nodeType":1586},{},[41655],{"data":41656,"content":41657,"nodeType":876},{},[41658,41662,41671],{"data":41659,"marks":41660,"value":41661,"nodeType":867},{},[],"The attackers use a compromised account to do something deliberately in the public eye. For example, when the SEC’s X (formerly Twitter) account was compromised and ",{"data":41663,"content":41665,"nodeType":915},{"uri":41664},"https://incyber.org/en/article/fake-sec-tweet-triggers-bitcoin-surge/#:~:text=The%20fake%20headline%20convinced%20a,an%20unauthorized%20tweet%20was%20posted.",[41666],{"data":41667,"marks":41668,"value":41670,"nodeType":867},{},[41669],{"type":913},"sent out a message announcing the approval of Bitcoin ETF",{"data":41672,"marks":41673,"value":24572,"nodeType":867},{},[],{"data":41675,"content":41676,"nodeType":876},{},[41677],{"data":41678,"marks":41679,"value":41680,"nodeType":867},{},[],"Push gives you a number of controls to combat attacks using stolen and guessed passwords, both to prevent them from occurring, and detect them when they do.",{"data":41682,"content":41683,"nodeType":1058},{},[41684],{"data":41685,"marks":41686,"value":41687,"nodeType":867},{},[],"Prevent employees using credentials that have already been stolen and leaked",{"data":41689,"content":41690,"nodeType":876},{},[41691],{"data":41692,"marks":41693,"value":41694,"nodeType":867},{},[],"First, let's stop your employees from using any credentials that have already been stolen and are available to attackers for use in a credential-stuffing attack. ",{"data":41696,"content":41697,"nodeType":876},{},[41698],{"data":41699,"marks":41700,"value":41701,"nodeType":867},{},[],"Push monitors stolen credential threat intelligence and compares it to the credentials employees are currently using to access their apps. ",{"data":41703,"content":41704,"nodeType":876},{},[41705],{"data":41706,"marks":41707,"value":41708,"nodeType":867},{},[],"You might be wondering, “Does that mean Push sees all our employees’ passwords!?” No. Rather, we use a fingerprint of each password and it's checked locally in the users’ browser and never leaves it. ",{"data":41710,"content":41711,"nodeType":876},{},[41712],{"data":41713,"marks":41714,"value":41715,"nodeType":867},{},[],"When we get a match – a stolen password that could successfully be used in a credential-stuffing attack – Push alerts you.",{"data":41717,"content":41718,"nodeType":1058},{},[41719],{"data":41720,"marks":41721,"value":41722,"nodeType":867},{},[],"Enforce MFA on all employee accounts",{"data":41724,"content":41725,"nodeType":876},{},[41726],{"data":41727,"marks":41728,"value":41729,"nodeType":867},{},[],"Next step is to secure the accounts most vulnerable to a credential stuffing attack – those that only use a password for single-factor authentication. ",{"data":41731,"content":41732,"nodeType":876},{},[41733,41737,41745],{"data":41734,"marks":41735,"value":41736,"nodeType":867},{},[],"If you’re using SSO to access apps, then it’s easy to overlook instances where local accounts (e.g. username and password logins) are missing MFA – particularly if you’re relying on an IdP solution to audit and enforce MFA. ",{"data":41738,"content":41739,"nodeType":915},{"uri":2924},[41740],{"data":41741,"marks":41742,"value":41744,"nodeType":867},{},[41743],{"type":913},"You can read more about this problem in our blog post on ghost logins",{"data":41746,"marks":41747,"value":5704,"nodeType":867},{},[],{"data":41749,"content":41750,"nodeType":876},{},[41751],{"data":41752,"marks":41753,"value":41754,"nodeType":867},{},[],"Push observes every login made by your employees (both inside and outside SSO) and inspects the authentication protocols used. Accounts that are missing MFA are identified and presented to you in the Push platform.",{"data":41756,"content":41760,"nodeType":985},{"target":41757},{"sys":41758},{"id":41759,"type":982,"linkType":983},"4t1PHxzadoTBjtJua6dzuJ",[],{"data":41762,"content":41763,"nodeType":876},{},[41764],{"data":41765,"marks":41766,"value":41767,"nodeType":867},{},[],"You can then use Push to enforce MFA on employee accounts, or present them with in-browser guidance requesting that they enable it themselves.  ",{"data":41769,"content":41773,"nodeType":985},{"target":41770},{"sys":41771},{"id":41772,"type":982,"linkType":983},"3JSTEJGtLT0hfwnkpLRP4K",[],{"data":41775,"content":41776,"nodeType":1058},{},[41777],{"data":41778,"marks":41779,"value":41780,"nodeType":867},{},[],"Prevent multiple accounts being compromised by credential stuffing due to password reuse",{"data":41782,"content":41783,"nodeType":876},{},[41784],{"data":41785,"marks":41786,"value":41787,"nodeType":867},{},[],"The credential stuffing tools that attackers use will target a long list of popular business apps. If a password is reused across multiple apps and is breached, the blast radius is naturally increased – the attacker will be able to hijack multiple accounts, across numerous business applications.",{"data":41789,"content":41790,"nodeType":876},{},[41791],{"data":41792,"marks":41793,"value":41794,"nodeType":867},{},[],"Push detects when employees are trying to use the same password across multiple apps. When this happens, you can request that they change their password.",{"data":41796,"content":41800,"nodeType":985},{"target":41797},{"sys":41798},{"id":41799,"type":982,"linkType":983},"7ARHp2JPiHeKRYHwa2jwIZ",[],{"data":41802,"content":41803,"nodeType":1058},{},[41804],{"data":41805,"marks":41806,"value":41807,"nodeType":867},{},[],"Prevent password spraying breaches",{"data":41809,"content":41810,"nodeType":876},{},[41811],{"data":41812,"marks":41813,"value":41814,"nodeType":867},{},[],"To stop your employees’ accounts from being breached by password spraying attacks, Push checks every password to see if it is easily guessable for attackers.",{"data":41816,"content":41817,"nodeType":876},{},[41818],{"data":41819,"marks":41820,"value":41821,"nodeType":867},{},[],"To determine if a password is easily guessable, the Push browser agent automatically checks the password against:",{"data":41823,"content":41824,"nodeType":1629},{},[41825,41835,41845],{"data":41826,"content":41827,"nodeType":1586},{},[41828],{"data":41829,"content":41830,"nodeType":876},{},[41831],{"data":41832,"marks":41833,"value":41834,"nodeType":867},{},[],"A list of top 10,000 weak base passwords.",{"data":41836,"content":41837,"nodeType":1586},{},[41838],{"data":41839,"content":41840,"nodeType":876},{},[41841],{"data":41842,"marks":41843,"value":41844,"nodeType":867},{},[],"Number and special character variations on these weak base passwords, for example: Password1! or January2022.",{"data":41846,"content":41847,"nodeType":1586},{},[41848],{"data":41849,"content":41850,"nodeType":876},{},[41851],{"data":41852,"marks":41853,"value":41854,"nodeType":867},{},[],"Variations on these weak base passwords that replace letters with numerals (1337), for example: P455w0rd.",{"data":41856,"content":41857,"nodeType":876},{},[41858],{"data":41859,"marks":41860,"value":41861,"nodeType":867},{},[],"You can also add your own custom word list that employees and attackers will predictably try and use. Push will then stop those words being used as part of passwords.",{"data":41863,"content":41864,"nodeType":1058},{},[41865],{"data":41866,"marks":41867,"value":41868,"nodeType":867},{},[],"Detect unauthorized sessions  ",{"data":41870,"content":41871,"nodeType":876},{},[41872],{"data":41873,"marks":41874,"value":41875,"nodeType":867},{},[],"Once you have enabled all the Push controls that prevent employees from creating and using accounts that can be easily compromised by credential stuffing and password spraying attacks, the next line of defense is to detect when accounts are taken over.",{"data":41877,"content":41878,"nodeType":876},{},[41879],{"data":41880,"marks":41881,"value":41882,"nodeType":867},{},[],"Push uses its browser agent to inject a unique marker into the user agent string of sessions that occur in browsers enrolled in Push. You then add the list of domains that you want to have injected with the session marker. ",{"data":41884,"content":41885,"nodeType":876},{},[41886],{"data":41887,"marks":41888,"value":41889,"nodeType":867},{},[],"By analyzing logs from the IdP, you can identify activity from the same session that both has the Push marker and that lacks the marker. This indicates that the session is not being used by the legitimate user (your employees) in their usual work browser, and could be an attacker using their account. ",{"data":41891,"content":41892,"nodeType":1058},{},[41893],{"data":41894,"marks":41895,"value":41896,"nodeType":867},{},[],"Reduce your identity attack surface",{"data":41898,"content":41899,"nodeType":876},{},[41900],{"data":41901,"marks":41902,"value":41903,"nodeType":867},{},[],"Finally, you’ll likely want to reduce your attack surface that can be targeted by credential stuffing. In other words, reduce the number of username and password accounts your employees have. ",{"data":41905,"content":41906,"nodeType":876},{},[41907],{"data":41908,"marks":41909,"value":41910,"nodeType":867},{},[],"There are a few ways that Push can help you do this.",{"data":41912,"content":41913,"nodeType":1629},{},[41914,41929,41944],{"data":41915,"content":41916,"nodeType":1586},{},[41917],{"data":41918,"content":41919,"nodeType":876},{},[41920,41925],{"data":41921,"marks":41922,"value":41924,"nodeType":867},{},[41923],{"type":865},"Block access to unapproved apps",{"data":41926,"marks":41927,"value":41928,"nodeType":867},{},[],". Using Push, you can create a block list of apps that you don’t want your users to create accounts and identities on.",{"data":41930,"content":41931,"nodeType":1586},{},[41932],{"data":41933,"content":41934,"nodeType":876},{},[41935,41940],{"data":41936,"marks":41937,"value":41939,"nodeType":867},{},[41938],{"type":865},"Use app banners to stop users from creating local accounts",{"data":41941,"marks":41942,"value":41943,"nodeType":867},{},[],". When an employee goes to sign up to an app, Push will present an app banner that tells them to use their SSO identity and not to create a username and password account.",{"data":41945,"content":41946,"nodeType":1586},{},[41947],{"data":41948,"content":41949,"nodeType":876},{},[41950,41955],{"data":41951,"marks":41952,"value":41954,"nodeType":867},{},[41953],{"type":865},"Get existing accounts and apps behind SSO",{"data":41956,"marks":41957,"value":41958,"nodeType":867},{},[],". Push shows you how your employees are logging in to every account on every app, including whether they’re using SAML or OIDC SSO. Armed with this data, you can get your employees to use your preferred SSO solution on the apps where it’s already available, and look into whether other popular apps being used in the business offer SSO.",{"data":41960,"content":41964,"nodeType":985},{"target":41961},{"sys":41962},{"id":41963,"type":982,"linkType":983},"3y8L55hbcQaRYPCdYYb3xA",[],{"data":41966,"content":41967,"nodeType":868},{},[41968],{"data":41969,"marks":41970,"value":41971,"nodeType":867},{},[],"Stop account takeover at the push of a button",{"data":41973,"content":41974,"nodeType":876},{},[41975,41979,41986,41990,41995,41998,42003,42007,42011],{"data":41976,"marks":41977,"value":41978,"nodeType":867},{},[],"We’ve described a lot of controls in this article. The good news is that they’re all pre-configured on the the ",{"data":41980,"content":41982,"nodeType":915},{"uri":41981},"https://pushsecurity.com/help/audience/administrators/docs/manage-security-controls/#start",[41983],{"data":41984,"marks":41985,"value":25043,"nodeType":867},{},[],{"data":41987,"marks":41988,"value":41989,"nodeType":867},{},[]," page in the Push platform. When you get started with Push, you can simply turn on all the controls you want, and decide whether you want them to work in ",{"data":41991,"marks":41992,"value":41994,"nodeType":867},{},[41993],{"type":865},"monitor",{"data":41996,"marks":41997,"value":5136,"nodeType":867},{},[],{"data":41999,"marks":42000,"value":42002,"nodeType":867},{},[42001],{"type":865},"warn",{"data":42004,"marks":42005,"value":42006,"nodeType":867},{},[]," mode or ",{"data":42008,"marks":42009,"value":87,"nodeType":867},{},[42010],{"type":865},{"data":42012,"marks":42013,"value":42014,"nodeType":867},{},[]," mode.    ",{"data":42016,"content":42020,"nodeType":985},{"target":42017},{"sys":42018},{"id":42019,"type":982,"linkType":983},"6FCuO78yQMNZvkcbcALmis",[],{"data":42022,"content":42023,"nodeType":1058},{},[42024],{"data":42025,"marks":42026,"value":42027,"nodeType":867},{},[],"See it for yourself",{"data":42029,"content":42030,"nodeType":876},{},[42031,42035,42041],{"data":42032,"marks":42033,"value":42034,"nodeType":867},{},[],"To learn more, ",{"data":42036,"content":42037,"nodeType":915},{"uri":5286},[42038],{"data":42039,"marks":42040,"value":11707,"nodeType":867},{},[],{"data":42042,"marks":42043,"value":42044,"nodeType":867},{},[],". We’ll be happy to show you these features, along with how we discover all the apps your employees are using, even the ones not behind SSO.",{"data":42046,"content":42050,"nodeType":985},{"target":42047},{"sys":42048},{"id":42049,"type":982,"linkType":983},"4IRtR9zicpB7lXdz2RvIlK",[],{"data":42052,"content":42053,"nodeType":876},{},[42054],{"data":42055,"marks":42056,"value":21,"nodeType":867},{},[],"Hackers don’t hack in, they log in: How to prevent account takeover with Push","How Push stops attackers from using identity attack tools and techniques to compromise your employee user accounts. ","2024-08-19T00:00:00.000Z","how-to-prevent-account-takeover-with-push",{"items":42062},[42063,42065],{"sys":42064,"name":342},{"id":3240},{"sys":42066,"name":4018},{"id":4017},{"items":42068},[42069],{"fullName":4089,"firstName":4090,"jobTitle":851,"profilePicture":42070},{"url":4094},{"__typename":1772,"sys":42072,"content":42074,"title":43127,"synopsis":43128,"hashTags":59,"publishedDate":43129,"slug":43130,"tagsCollection":43131,"authorsCollection":43137},{"id":42073},"1LxqUNZpD2VynzSqbv719Z",{"json":42075},{"data":42076,"content":42077,"nodeType":1680},{},[42078,42096,42103,42110,42117,42124,42127,42134,42220,42227,42234,42241,42256,42276,42283,42286,42293,42300,42306,42323,42347,42354,42361,42393,42424,42431,42449,42456,42463,42470,42478,42485,42514,42520,42537,42569,42576,42595,42602,42609,42627,42634,42641,42644,42651,42658,42665,42668,42675,42682,42689,42708,42841,42848,42851,42858,42865,42966,42973,42980,42983,42990,42997,43048,43055,43062,43065,43071,43078,43096,43115,43121],{"data":42079,"content":42080,"nodeType":876},{},[42081,42085,42092],{"data":42082,"marks":42083,"value":42084,"nodeType":867},{},[],"When we created the ",{"data":42086,"content":42087,"nodeType":915},{"uri":15408},[42088],{"data":42089,"marks":42090,"value":14765,"nodeType":867},{},[42091],{"type":913},{"data":42093,"marks":42094,"value":42095,"nodeType":867},{},[],", we made a conscious break away from the endpoint-focused techniques captured in industry resources like the MITRE ATT&CK Framework. ",{"data":42097,"content":42098,"nodeType":876},{},[42099],{"data":42100,"marks":42101,"value":42102,"nodeType":867},{},[],"At the time, we were anticipating a shift that was yet to fully materialize. But, a lot can change (and has changed) in the space of a year. We’ve seen the impact of SaaS account takeover attacks laid bare. Snowflake, billed one of the biggest breaches in history, is a telling example that we’ll no doubt look back on as a watershed moment. ",{"data":42104,"content":42105,"nodeType":876},{},[42106],{"data":42107,"marks":42108,"value":42109,"nodeType":867},{},[],"It isn’t an exaggeration or marketing fluff to say that identity attacks are the #1 threat facing organizations today. SaaS apps, and the identities that are used to access them, are clearly the weakest link – and therefore the lowest-hanging fruit for attackers to reach for. ",{"data":42111,"content":42112,"nodeType":876},{},[42113],{"data":42114,"marks":42115,"value":42116,"nodeType":867},{},[],"This makes resources like the SaaS attack matrix more relevant than ever – both for red teams seeking to emulate the latest offensive techniques, and blue teams trying to defend against them. Understanding these techniques is essential for building effective defenses, and identifying where new platforms and controls are required to do so. ",{"data":42118,"content":42119,"nodeType":876},{},[42120],{"data":42121,"marks":42122,"value":42123,"nodeType":867},{},[],"Let’s take a look at what we’ve learned so far.",{"data":42125,"content":42126,"nodeType":942},{},[],{"data":42128,"content":42129,"nodeType":868},{},[42130],{"data":42131,"marks":42132,"value":42133,"nodeType":867},{},[],"Hot right now: Initial access techniques",{"data":42135,"content":42136,"nodeType":876},{},[42137,42141,42148,42151,42160,42163,42172,42175,42182,42185,42194,42198,42206,42209,42217],{"data":42138,"marks":42139,"value":42140,"nodeType":867},{},[],"The majority of techniques we've seen rise to prominence in 2023/4 sit predominantly in the initial access phase. Since the matrix first launched, we’ve added more techniques to initial access than any other category, including ",{"data":42142,"content":42143,"nodeType":915},{"uri":26236},[42144],{"data":42145,"marks":42146,"value":2929,"nodeType":867},{},[42147],{"type":913},{"data":42149,"marks":42150,"value":5136,"nodeType":867},{},[],{"data":42152,"content":42154,"nodeType":915},{"uri":42153},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/aitm_phishing/description.md",[42155],{"data":42156,"marks":42157,"value":42159,"nodeType":867},{},[42158],{"type":913},"AitM phishing",{"data":42161,"marks":42162,"value":5136,"nodeType":867},{},[],{"data":42164,"content":42166,"nodeType":915},{"uri":42165},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/session_cookie_theft/description.md",[42167],{"data":42168,"marks":42169,"value":42171,"nodeType":867},{},[42170],{"type":913},"session cookie theft",{"data":42173,"marks":42174,"value":5136,"nodeType":867},{},[],{"data":42176,"content":42177,"nodeType":915},{"uri":24826},[42178],{"data":42179,"marks":42180,"value":24832,"nodeType":867},{},[42181],{"type":913},{"data":42183,"marks":42184,"value":5147,"nodeType":867},{},[],{"data":42186,"content":42188,"nodeType":915},{"uri":42187},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/guest_access_abuse/description.md",[42189],{"data":42190,"marks":42191,"value":42193,"nodeType":867},{},[42192],{"type":913},"guest access abuse,",{"data":42195,"marks":42196,"value":42197,"nodeType":867},{},[]," all of which are methods of account takeover – complementing the classics like ",{"data":42199,"content":42201,"nodeType":915},{"uri":42200},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/credential_stuffing/description.md",[42202],{"data":42203,"marks":42204,"value":37948,"nodeType":867},{},[42205],{"type":913},{"data":42207,"marks":42208,"value":1174,"nodeType":867},{},[],{"data":42210,"content":42212,"nodeType":915},{"uri":42211},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/email_phishing/description.md",[42213],{"data":42214,"marks":42215,"value":42216,"nodeType":867},{},[],"email phishing",{"data":42218,"marks":42219,"value":1679,"nodeType":867},{},[],{"data":42221,"content":42222,"nodeType":876},{},[42223],{"data":42224,"marks":42225,"value":42226,"nodeType":867},{},[],"We’ll spend a bit of time delving into these techniques in the next section, but let’s first consider what this tells us about SaaS attacks. ",{"data":42228,"content":42229,"nodeType":1058},{},[42230],{"data":42231,"marks":42232,"value":42233,"nodeType":867},{},[],"Identity attacks are the leading cause of SaaS breaches",{"data":42235,"content":42236,"nodeType":876},{},[42237],{"data":42238,"marks":42239,"value":42240,"nodeType":867},{},[],"The initial identity attack designed to achieve account takeover is the most important part of the SaaS attack chain. The fact that attackers are focused on finding new ways of compromising identities illustrates the value, but also the fragility of the identity controls that most organizations are relying on (which may also be one of the reasons attackers are fixated on it). Whether we’re talking about anti-phishing protections, conditional access policies, or MFA – attackers are continually finding new ways of getting around them.",{"data":42242,"content":42243,"nodeType":876},{},[42244,42248,42253],{"data":42245,"marks":42246,"value":42247,"nodeType":867},{},[],"And, if all an attacker really needs to do to cause harm is log into an app and abuse its legitimate features and functions, there really is no margin for error – you need to successfully stop the initial identity attack ",{"data":42249,"marks":42250,"value":42252,"nodeType":867},{},[42251],{"type":865},"every time",{"data":42254,"marks":42255,"value":2933,"nodeType":867},{},[],{"data":42257,"content":42258,"nodeType":876},{},[42259,42263,42272],{"data":42260,"marks":42261,"value":42262,"nodeType":867},{},[],"You can’t rely on your endpoint and network controls to catch them later like you used to. Equally, it’s unlikely that your CASB or DLP solution can stop a legitimate app using legitimate features like ",{"data":42264,"content":42266,"nodeType":915},{"uri":42265},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/shadow_workflows/description.md",[42267],{"data":42268,"marks":42269,"value":42271,"nodeType":867},{},[42270],{"type":913},"API-based workflows",{"data":42273,"marks":42274,"value":42275,"nodeType":867},{},[]," from sending data to attacker-controlled infrastructure. ",{"data":42277,"content":42278,"nodeType":876},{},[42279],{"data":42280,"marks":42281,"value":42282,"nodeType":867},{},[],"It’s a classic case of attackers only needing to win once. And right now, it’s a numbers game that they’re winning enough to keep them coming back for more. ",{"data":42284,"content":42285,"nodeType":942},{},[],{"data":42287,"content":42288,"nodeType":868},{},[42289],{"data":42290,"marks":42291,"value":42292,"nodeType":867},{},[],"Most wanted: Techniques gaining notoriety in the wild",{"data":42294,"content":42295,"nodeType":876},{},[42296],{"data":42297,"marks":42298,"value":42299,"nodeType":867},{},[],"Let’s take a closer look at some of the techniques we’ve seen rise to prominence in 2023/4. ",{"data":42301,"content":42302,"nodeType":1058},{},[42303],{"data":42304,"marks":42305,"value":395,"nodeType":867},{},[],{"data":42307,"content":42308,"nodeType":876},{},[42309,42312,42319],{"data":42310,"marks":42311,"value":21,"nodeType":867},{},[],{"data":42313,"content":42314,"nodeType":915},{"uri":26236},[42315],{"data":42316,"marks":42317,"value":395,"nodeType":867},{},[42318],{"type":913},{"data":42320,"marks":42321,"value":42322,"nodeType":867},{},[]," is a technique that exploits the fact that SaaS user accounts often enable multiple simultaneous logins using different sign-in methods. ",{"data":42324,"content":42325,"nodeType":876},{},[42326,42330,42335,42338,42343],{"data":42327,"marks":42328,"value":42329,"nodeType":867},{},[],"Ghost logins can be used for both the ",{"data":42331,"marks":42332,"value":42334,"nodeType":867},{},[42333],{"type":865},"initial access",{"data":42336,"marks":42337,"value":1174,"nodeType":867},{},[],{"data":42339,"marks":42340,"value":42342,"nodeType":867},{},[42341],{"type":865},"persistence",{"data":42344,"marks":42345,"value":42346,"nodeType":867},{},[]," stages of a cyber attack, doubling up as a defense evasion technique because of low login method visibility.",{"data":42348,"content":42349,"nodeType":876},{},[42350],{"data":42351,"marks":42352,"value":42353,"nodeType":867},{},[],"For initial access, the technique exploits the fact that local and SSO logins can exist simultaneously. Given that many apps are self-adopted by users, it’s likely that many users will default to a local username and password login at this stage. If the app is later adopted companywide and brought into SSO, the original local login will continue to exist unless explicitly disabled or deleted. ",{"data":42355,"content":42356,"nodeType":876},{},[42357],{"data":42358,"marks":42359,"value":42360,"nodeType":867},{},[],"Because MFA is applied at the app and IdP level independently, it is possible to end up with an SSO login that requires MFA (via the IdP login), but a local login that does not. This creates an easy target identity for attackers to look for. When combined with other identity vulnerabilities such as weak, breached, and/or reused passwords, attackers can easily automate ghost login discovery and exploitation at scale.  ",{"data":42362,"content":42363,"nodeType":876},{},[42364,42368,42376,42380,42389],{"data":42365,"marks":42366,"value":42367,"nodeType":867},{},[],"We saw the impact of ghost logins for initial access with ",{"data":42369,"content":42370,"nodeType":915},{"uri":15290},[42371],{"data":42372,"marks":42373,"value":42375,"nodeType":867},{},[42374],{"type":913},"the recent ShinyHunters campaign against Snowflake customers",{"data":42377,"marks":42378,"value":42379,"nodeType":867},{},[],". Because Snowflake accounts did not require mandatory MFA for accounts, or give admins the ability to enforce MFA by default, attackers were able to find and exploit a large number of Snowflake accounts using breached credentials from historical data breach dumps. Much of the industry response focused on ensuring SSO and MFA were deployed, but ",{"data":42381,"content":42383,"nodeType":915},{"uri":42382},"https://pushsecurity.com/resources/video/demonstrating-ghost-logins-in-snowflake-and-how-to-remediate-them/",[42384],{"data":42385,"marks":42386,"value":42388,"nodeType":867},{},[42387],{"type":913},"the practicalities of gathering data and manually unsetting local passwords in Snowflake",{"data":42390,"marks":42391,"value":42392,"nodeType":867},{},[]," meant that ghost logins were easy to overlook by organizations responding to the attacks.   ",{"data":42394,"content":42395,"nodeType":876},{},[42396,42400,42408,42412,42420],{"data":42397,"marks":42398,"value":42399,"nodeType":867},{},[],"Ghost logins can also be created after an attacker has established access to an app. For example, if a social login is used to access an account, an adversary may be able to configure a separate username/password login, or even (though much less commonly) connect a second social account that the adversary controls. If the account has sufficient privileges, it may also be possible to ",{"data":42401,"content":42402,"nodeType":915},{"uri":5013},[42403],{"data":42404,"marks":42405,"value":42407,"nodeType":867},{},[42406],{"type":913},"set up or change the SAML login settings to inject a malicious URL",{"data":42409,"marks":42410,"value":42411,"nodeType":867},{},[]," (for example to an attacker controlled tenant) or simply ",{"data":42413,"content":42414,"nodeType":915},{"uri":26258},[42415],{"data":42416,"marks":42417,"value":42419,"nodeType":867},{},[42418],{"type":913},"configure API access",{"data":42421,"marks":42422,"value":42423,"nodeType":867},{},[]," to forgo the need to log in entirely. ",{"data":42425,"content":42426,"nodeType":1058},{},[42427],{"data":42428,"marks":42429,"value":42430,"nodeType":867},{},[],"AitM phishing ",{"data":42432,"content":42433,"nodeType":876},{},[42434,42437,42445],{"data":42435,"marks":42436,"value":21,"nodeType":867},{},[],{"data":42438,"content":42439,"nodeType":915},{"uri":42153},[42440],{"data":42441,"marks":42442,"value":42444,"nodeType":867},{},[42443],{"type":913},"Adversary-in-the-Middle (AitM) phishing",{"data":42446,"marks":42447,"value":42448,"nodeType":867},{},[]," is a newer variant of phishing that uses dedicated tooling to act as a web proxy between the victim and a legitimate login portal for an application the victim has access to, principally to make it easier to defeat MFA protection (with the victim responding to the MFA request as part of the attack).",{"data":42450,"content":42451,"nodeType":876},{},[42452],{"data":42453,"marks":42454,"value":42455,"nodeType":867},{},[],"As it’s a proxy to the real application, the page will appear exactly as the user expects, because they are logging into the legitimate site – just taking a detour via the attacker’s device. For example, if accessing their webmail, the user will see all their real emails; if accessing their cloud file store then all their real files will be present, etc. ",{"data":42457,"content":42458,"nodeType":876},{},[42459],{"data":42460,"marks":42461,"value":42462,"nodeType":867},{},[],"This gives AitM an increased sense of authenticity and makes the compromise less obvious to the user. Because the attacker is sitting in the middle of this connection, they are able to observe all interactions and take control of the authenticated session. ",{"data":42464,"content":42465,"nodeType":876},{},[42466],{"data":42467,"marks":42468,"value":42469,"nodeType":867},{},[],"Alongside AitM phishing is Browser-in-the-Middle (BitM), really a form of sub-technique. Rather than act as a reverse web proxy, this technique tricks a target into directly controlling the attacker’s own browser remotely using desktop screen sharing and control approaches (such as VNC and RDP). ",{"data":42471,"content":42472,"nodeType":876},{},[42473],{"data":42474,"marks":42475,"value":42477,"nodeType":867},{},[42476],{"type":865},"This is the virtual equivalent of an attacker handing their laptop to their victim, asking them to login to Okta for them, and then taking their laptop back afterwards.",{"data":42479,"content":42480,"nodeType":876},{},[42481],{"data":42482,"marks":42483,"value":42484,"nodeType":867},{},[],"A growing majority of modern phishing attacks typically leverage AitM or BitM tooling – they are now the standard choice for threat actors, offering the ability to bypass MFA without any real tradeoff. ",{"data":42486,"content":42487,"nodeType":876},{},[42488,42492,42500,42503,42511],{"data":42489,"marks":42490,"value":42491,"nodeType":867},{},[],"For more information you can ",{"data":42493,"content":42494,"nodeType":915},{"uri":38018},[42495],{"data":42496,"marks":42497,"value":42499,"nodeType":867},{},[42498],{"type":913},"read our recent blog post",{"data":42501,"marks":42502,"value":21631,"nodeType":867},{},[],{"data":42504,"content":42505,"nodeType":915},{"uri":41343},[42506],{"data":42507,"marks":42508,"value":42510,"nodeType":867},{},[42509],{"type":913},"watch our on-demand webinar on Phishing 2.0 to see AitM and BitM tools like Evilginx and EvilnoVNC in action",{"data":42512,"marks":42513,"value":5704,"nodeType":867},{},[],{"data":42515,"content":42516,"nodeType":1058},{},[42517],{"data":42518,"marks":42519,"value":333,"nodeType":867},{},[],{"data":42521,"content":42522,"nodeType":876},{},[42523,42526,42533],{"data":42524,"marks":42525,"value":21,"nodeType":867},{},[],{"data":42527,"content":42528,"nodeType":915},{"uri":42200},[42529],{"data":42530,"marks":42531,"value":333,"nodeType":867},{},[42532],{"type":913},{"data":42534,"marks":42535,"value":42536,"nodeType":867},{},[]," attacks continue to pose a risk to organizations. Despite the fact that MFA has now become an expected control, accounts without MFA continue to be hacked as a result of using weak, reused, and/or previously breached credentials. ",{"data":42538,"content":42539,"nodeType":876},{},[42540,42544,42552,42556,42565],{"data":42541,"marks":42542,"value":42543,"nodeType":867},{},[],"Credential stuffing is being fed by an increase in the number of ",{"data":42545,"content":42547,"nodeType":915},{"uri":42546},"https://pushsecurity.com/blog/what-the-rise-of-infostealers-says-about-identity-attacks/?utm_source=ebook&utm_medium=organic",[42548],{"data":42549,"marks":42550,"value":423,"nodeType":867},{},[42551],{"type":913},{"data":42553,"marks":42554,"value":42555,"nodeType":867},{},[]," attacks designed to harvest credentials to be sold on criminal marketplaces. Infostealers have been boosted by the success of the Snowflake attacks (",{"data":42557,"content":42559,"nodeType":915},{"uri":42558},"https://pushsecurity.com/blog/identity-attacks-in-the-wild/#id-snowflake-june-2024?utm_source=ebook&utm_medium=organic",[42560],{"data":42561,"marks":42562,"value":42564,"nodeType":867},{},[42563],{"type":913},"where 80% of the credentials used to access accounts could be traced back to infostealer infections dating back to 2020",{"data":42566,"marks":42567,"value":42568,"nodeType":867},{},[],"). ",{"data":42570,"content":42571,"nodeType":1058},{},[42572],{"data":42573,"marks":42574,"value":42575,"nodeType":867},{},[],"Session cookie theft",{"data":42577,"content":42578,"nodeType":876},{},[42579,42583,42591],{"data":42580,"marks":42581,"value":42582,"nodeType":867},{},[],"Attackers are increasingly ",{"data":42584,"content":42585,"nodeType":915},{"uri":42165},[42586],{"data":42587,"marks":42588,"value":42590,"nodeType":867},{},[42589],{"type":913},"targeting session cookies",{"data":42592,"marks":42593,"value":42594,"nodeType":867},{},[]," to be able to hijack live user sessions as a means of getting around MFA. Although session cookies are predominantly stolen via infostealers, techniques like AitM and BitM phishing described above are also methods of stealing session cookies and hijacking sessions.",{"data":42596,"content":42597,"nodeType":876},{},[42598],{"data":42599,"marks":42600,"value":42601,"nodeType":867},{},[],"While the majority of infostealer data dumps result in credential stuffing attacks rather than session hijacking, as the infostealer marketplace continues to heat up, it’s likely that more instances of session cookie theft will be the cause of breaches going forward. ",{"data":42603,"content":42604,"nodeType":1058},{},[42605],{"data":42606,"marks":42607,"value":42608,"nodeType":867},{},[],"MFA downgrade",{"data":42610,"content":42611,"nodeType":876},{},[42612,42616,42623],{"data":42613,"marks":42614,"value":42615,"nodeType":867},{},[],"While many organizations are waking up to the fact that it’s not enough to have any old MFA method, it’s still often overlooked that you need to actually remove or disable the phishable methods. Otherwise, in many cases they remain valid, opening affected identities up to ",{"data":42617,"content":42618,"nodeType":915},{"uri":24826},[42619],{"data":42620,"marks":42621,"value":42608,"nodeType":867},{},[42622],{"type":913},{"data":42624,"marks":42625,"value":42626,"nodeType":867},{},[]," attacks. ",{"data":42628,"content":42629,"nodeType":876},{},[42630],{"data":42631,"marks":42632,"value":42633,"nodeType":867},{},[],"Just because a user has a phishing-resistant factor setup (such as passkeys) and may use them by default, it does not mean they are necessarily enforced. Often, services support the use of multiple authentication options, particularly for second factors. In particular, passkeys are device-bound and so enforcing their use prevents logins from other devices and can cause recovery issues in a lost/broken device scenario. Therefore, it’s common for the default case to be that passkey authentication is optional, rather than required.",{"data":42635,"content":42636,"nodeType":876},{},[42637],{"data":42638,"marks":42639,"value":42640,"nodeType":867},{},[],"When used in combination with AitM phishing tools, it’s possible for attackers to modify requests/responses so as to prevent the ability of passkeys to be selected as a login option and prompting the user to use vulnerable factors, such as passwords, TOTPs and push notifications instead. Since the server-side supports other authentication options, if the user continues and enters one of these alternative factors then their authenticated session will be compromised – despite the fact they usually use phishing-resistant MFA methods like passkeys or similar.",{"data":42642,"content":42643,"nodeType":942},{},[],{"data":42645,"content":42646,"nodeType":868},{},[42647],{"data":42648,"marks":42649,"value":42650,"nodeType":867},{},[],"Use case inspo: How red teamers are using the SaaS attack matrix",{"data":42652,"content":42653,"nodeType":876},{},[42654],{"data":42655,"marks":42656,"value":42657,"nodeType":867},{},[],"The techniques that advanced red teams are using to (ethically) hack into their clients are always a good indicator of what direction hackers in the real world are headed.  ",{"data":42659,"content":42660,"nodeType":876},{},[42661],{"data":42662,"marks":42663,"value":42664,"nodeType":867},{},[],"We spoke to a few of the best red teams around to see how they are using the matrix: Let’s see what they had to say. ",{"data":42666,"content":42667,"nodeType":942},{},[],{"data":42669,"content":42670,"nodeType":1058},{},[42671],{"data":42672,"marks":42673,"value":42674,"nodeType":867},{},[],"Rob Maslen | Managing Principal Consultant | MDSec",{"data":42676,"content":42677,"nodeType":876},{},[42678],{"data":42679,"marks":42680,"value":42681,"nodeType":867},{},[],"“We use the matrix throughout our engagements: When scoping and proposing projects to clients, during testing to assist our consultants in successfully utilizing novel SaaS-attack techniques, and for reporting to provide a common language across the vendors that they work with. ",{"data":42683,"content":42684,"nodeType":876},{},[42685],{"data":42686,"marks":42687,"value":42688,"nodeType":867},{},[],"It’s been most useful to us when performing engagements on more modern Zero Trust Environments where macOS is predominantly the Operating System of choice. The objectives tend to be either access to critical applications that reside within the cloud and require the compromise of SaaS credentials, or to gain privileged access to a SaaS application. Whilst resources like the MITRE ATT&CK Framework can help to describe the techniques that have been used against a more traditional environment, the SaaS Matrix aids with performing and describing attacks against a more modern infrastructure.  ",{"data":42690,"content":42691,"nodeType":876},{},[42692,42696,42704],{"data":42693,"marks":42694,"value":42695,"nodeType":867},{},[],"The technique we’ve seen most success with, across both traditional Active Directory attacks and more modern Zero Trust Environments, is ",{"data":42697,"content":42698,"nodeType":915},{"uri":42165},[42699],{"data":42700,"marks":42701,"value":42703,"nodeType":867},{},[42702],{"type":913},"Session Cookie Theft",{"data":42705,"marks":42706,"value":42707,"nodeType":867},{},[],". The protection of browser cookies (for inexplicable reasons) has had less engineering attention than it should have, opening up opportunities for lateral movement using session cookies, credentials, or API keys recovered from a host becomes a key technique. In our experience defensive tooling has yet to catch up with this threat. ",{"data":42709,"content":42710,"nodeType":876},{},[42711,42715,42724,42727,42736,42739,42748,42751,42758,42761,42768,42771,42779,42782,42790,42793,42802,42805,42813,42817,42826,42829,42838],{"data":42712,"marks":42713,"value":42714,"nodeType":867},{},[],"We’ve also seen success with various techniques across Kill Chain stages, including ",{"data":42716,"content":42718,"nodeType":915},{"uri":42717},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/subdomain_tenant_discovery/description.md",[42719],{"data":42720,"marks":42721,"value":42723,"nodeType":867},{},[42722],{"type":913},"Subdomain tenant discovery",{"data":42725,"marks":42726,"value":5136,"nodeType":867},{},[],{"data":42728,"content":42730,"nodeType":915},{"uri":42729},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/dns_reconnaissance/description.md",[42731],{"data":42732,"marks":42733,"value":42735,"nodeType":867},{},[42734],{"type":913},"DNS reconnaissance",{"data":42737,"marks":42738,"value":5136,"nodeType":867},{},[],{"data":42740,"content":42742,"nodeType":915},{"uri":42741},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/username_enumeration/description.md",[42743],{"data":42744,"marks":42745,"value":42747,"nodeType":867},{},[42746],{"type":913},"username enumeration",{"data":42749,"marks":42750,"value":5136,"nodeType":867},{},[],{"data":42752,"content":42753,"nodeType":915},{"uri":23293},[42754],{"data":42755,"marks":42756,"value":23298,"nodeType":867},{},[42757],{"type":913},{"data":42759,"marks":42760,"value":5136,"nodeType":867},{},[],{"data":42762,"content":42763,"nodeType":915},{"uri":11768},[42764],{"data":42765,"marks":42766,"value":11559,"nodeType":867},{},[42767],{"type":913},{"data":42769,"marks":42770,"value":5136,"nodeType":867},{},[],{"data":42772,"content":42773,"nodeType":915},{"uri":42187},[42774],{"data":42775,"marks":42776,"value":42778,"nodeType":867},{},[42777],{"type":913},"guest access abuse",{"data":42780,"marks":42781,"value":5136,"nodeType":867},{},[],{"data":42783,"content":42784,"nodeType":915},{"uri":42265},[42785],{"data":42786,"marks":42787,"value":42789,"nodeType":867},{},[42788],{"type":913},"shadow workflows",{"data":42791,"marks":42792,"value":5136,"nodeType":867},{},[],{"data":42794,"content":42796,"nodeType":915},{"uri":42795},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/oauth_tokens/description.md",[42797],{"data":42798,"marks":42799,"value":42801,"nodeType":867},{},[42800],{"type":913},"OAuth tokens",{"data":42803,"marks":42804,"value":5136,"nodeType":867},{},[],{"data":42806,"content":42807,"nodeType":915},{"uri":26258},[42808],{"data":42809,"marks":42810,"value":42812,"nodeType":867},{},[42811],{"type":913},"API keys",{"data":42814,"marks":42815,"value":42816,"nodeType":867},{},[]," (as long as you ensure the target isn't notified – make sure you delete the notification of creation email!), ",{"data":42818,"content":42820,"nodeType":915},{"uri":42819},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/api_secret_theft/description.md",[42821],{"data":42822,"marks":42823,"value":42825,"nodeType":867},{},[42824],{"type":913},"API secret theft",{"data":42827,"marks":42828,"value":5147,"nodeType":867},{},[],{"data":42830,"content":42832,"nodeType":915},{"uri":42831},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/link_backdooring/description.md",[42833],{"data":42834,"marks":42835,"value":42837,"nodeType":867},{},[42836],{"type":913},"link backdooring",{"data":42839,"marks":42840,"value":5704,"nodeType":867},{},[],{"data":42842,"content":42843,"nodeType":876},{},[42844],{"data":42845,"marks":42846,"value":42847,"nodeType":867},{},[],"Embracing the modern Zero Trust architecture with its greater SaaS usage does not come without security risks, and while it does invalidate a large number of the attacks that can be performed within an AD environment, the SaaS attack matrix is a great way of illustrating how these attacks work, as well as helping red and blue teams respectively to simulate and defend against them.\" ",{"data":42849,"content":42850,"nodeType":942},{},[],{"data":42852,"content":42853,"nodeType":1058},{},[42854],{"data":42855,"marks":42856,"value":42857,"nodeType":867},{},[],"Tom Ellson | Head of Offensive Security | Stripe OLT",{"data":42859,"content":42860,"nodeType":876},{},[42861],{"data":42862,"marks":42863,"value":42864,"nodeType":867},{},[],"“We've used the SaaS attack matrix across several cloud-native engagements, for both initial access and lateral movement. My go-to techniques so far have been:",{"data":42866,"content":42867,"nodeType":1629},{},[42868,42895,42917,42939],{"data":42869,"content":42870,"nodeType":1586},{},[42871],{"data":42872,"content":42873,"nodeType":876},{},[42874,42877,42887,42891],{"data":42875,"marks":42876,"value":21,"nodeType":867},{},[],{"data":42878,"content":42880,"nodeType":915},{"uri":42879},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/im_phishing/description.md",[42881],{"data":42882,"marks":42883,"value":42886,"nodeType":867},{},[42884,42885],{"type":913},{"type":865},"IM phishing:",{"data":42888,"marks":42889,"value":2136,"nodeType":867},{},[42890],{"type":865},{"data":42892,"marks":42893,"value":42894,"nodeType":867},{},[],"Phishing via Microsoft Teams in particular has been highly successful, especially when paired with a number of abusable “features” (working as intended, clearly). ",{"data":42896,"content":42897,"nodeType":1586},{},[42898],{"data":42899,"content":42900,"nodeType":876},{},[42901,42904,42913],{"data":42902,"marks":42903,"value":21,"nodeType":867},{},[],{"data":42905,"content":42906,"nodeType":915},{"uri":11768},[42907],{"data":42908,"marks":42909,"value":42912,"nodeType":867},{},[42910,42911],{"type":913},{"type":865},"Device code phishing:",{"data":42914,"marks":42915,"value":42916,"nodeType":867},{},[]," We use this for both initial access and persistence. It’s a great way of getting around MFA by tricking the victim into following the device approval process for our device, but using their device. ",{"data":42918,"content":42919,"nodeType":1586},{},[42920],{"data":42921,"content":42922,"nodeType":876},{},[42923,42926,42935],{"data":42924,"marks":42925,"value":21,"nodeType":867},{},[],{"data":42927,"content":42928,"nodeType":915},{"uri":42153},[42929],{"data":42930,"marks":42931,"value":42934,"nodeType":867},{},[42932,42933],{"type":913},{"type":865},"AitM phishing:",{"data":42936,"marks":42937,"value":42938,"nodeType":867},{},[]," This is now a staple for credential harvesting. Better security controls force us to abuse other avenues to bypass conditional access policies, such as extraction of the PRT token from the end user device, thus granting us claimed access, which can be achieved using AitM and BitM techniques.",{"data":42940,"content":42941,"nodeType":1586},{},[42942],{"data":42943,"content":42944,"nodeType":876},{},[42945,42948,42958,42962],{"data":42946,"marks":42947,"value":21,"nodeType":867},{},[],{"data":42949,"content":42951,"nodeType":915},{"uri":42950},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/oauth_token_enumeration/description.md",[42952],{"data":42953,"marks":42954,"value":42957,"nodeType":867},{},[42955,42956],{"type":913},{"type":865},"OAuth token enumeration:",{"data":42959,"marks":42960,"value":2136,"nodeType":867},{},[42961],{"type":865},{"data":42963,"marks":42964,"value":42965,"nodeType":867},{},[],"Once an account has been compromised, the Myapps portal is commonly used to validate the accessible applications and further target downstream apps to access data and functionality. ",{"data":42967,"content":42968,"nodeType":876},{},[42969],{"data":42970,"marks":42971,"value":42972,"nodeType":867},{},[],"We’re usually targeting M365 environments but have still found these attack techniques to be highly effective. In some cases, we’ve leveraged other SaaS applications such as abusing in-app phishing via GitHub to compromise development pipelines. The matrix is particularly useful as a playbook of further attacks once initial access has been established. Even just the awareness of how to pivot from SaaS to SaaS (and sometimes back to Microsoft or Google) is really eye-opening for red teams, and adds a new dimension to the security testing that our clients are used to experiencing. ",{"data":42974,"content":42975,"nodeType":876},{},[42976],{"data":42977,"marks":42978,"value":42979,"nodeType":867},{},[],"Because of the success of using these methods, we’ve now incorporated the SaaS attack matrix techniques into our purple teaming methodology to ensure that our clients can build awareness of their detection visibility gaps when it comes to identity attacks, and are routinely benchmarked against them.”  ",{"data":42981,"content":42982,"nodeType":942},{},[],{"data":42984,"content":42985,"nodeType":1058},{},[42986],{"data":42987,"marks":42988,"value":42989,"nodeType":867},{},[],"Max Corbridge | Head of Adversarial Simulation | JUMPSEC",{"data":42991,"content":42992,"nodeType":876},{},[42993],{"data":42994,"marks":42995,"value":42996,"nodeType":867},{},[],"“I’ve been a big fan of the matrix from day one. We use it for two main purposes – as a catalog of TTPs to apply during threat modeling exercises with cloud-native clients, and as a guide for how to apply novel TTPs to different apps and situations. The wiki descriptions, video demonstrations and references help enormously with this. ",{"data":42998,"content":42999,"nodeType":876},{},[43000,43004,43012,43015,43022,43025,43034,43037,43044],{"data":43001,"marks":43002,"value":43003,"nodeType":867},{},[],"We’ve mostly relied on ",{"data":43005,"content":43006,"nodeType":915},{"uri":42879},[43007],{"data":43008,"marks":43009,"value":43011,"nodeType":867},{},[43010],{"type":913},"IM phishing",{"data":43013,"marks":43014,"value":5136,"nodeType":867},{},[],{"data":43016,"content":43017,"nodeType":915},{"uri":42153},[43018],{"data":43019,"marks":43020,"value":42159,"nodeType":867},{},[43021],{"type":913},{"data":43023,"marks":43024,"value":5136,"nodeType":867},{},[],{"data":43026,"content":43028,"nodeType":915},{"uri":43027},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/abuse_existing_oauth_integrations/description.md",[43029],{"data":43030,"marks":43031,"value":43033,"nodeType":867},{},[43032],{"type":913},"abusing OAuth integrations",{"data":43035,"marks":43036,"value":5147,"nodeType":867},{},[],{"data":43038,"content":43039,"nodeType":915},{"uri":22216},[43040],{"data":43041,"marks":43042,"value":22222,"nodeType":867},{},[43043],{"type":913},{"data":43045,"marks":43046,"value":43047,"nodeType":867},{},[],". In one recent engagement, we were able to compromise a cloud identity with limited permissions in the target Azure environment. We were able to enumerate additional OAuth integrations to laterally move to a third-party IT Service Management SaaS application, which presented a much easier target to elevate privileges. We actually ended up finding a number of 0-days in the application, which we then used as a trusted platform to launch a covert spear-phishing campaign against specific high-privilege users, communicating back-and-forth as though we were a genuine support team, and hiding risky changes to cover our tracks. Ultimately we were able to pivot back into the target Azure estate, but now with administrative privileges. ",{"data":43049,"content":43050,"nodeType":876},{},[43051],{"data":43052,"marks":43053,"value":43054,"nodeType":867},{},[],"This really shows how third-party identities and apps are often the soft underbelly for a lot of otherwise pretty secure orgs that we work with, and we’re enjoying the challenge of finding new ways of getting to the crown jewels. ",{"data":43056,"content":43057,"nodeType":876},{},[43058],{"data":43059,"marks":43060,"value":43061,"nodeType":867},{},[],"In my eyes the world of cloud and SaaS-native attack techniques is under-researched for how increasingly relevant it is becoming. Many of the older TTPs and tradecraft are no longer relevant in a cloud-native world, and even when the techniques are consistent with the ways we used to target networks and endpoints, the context and how it actually works is completely different. So, resources like the SaaS attack matrix will continue to be needed for both offensive and defensive security practitioners going forwards”.",{"data":43063,"content":43064,"nodeType":942},{},[],{"data":43066,"content":43067,"nodeType":868},{},[43068],{"data":43069,"marks":43070,"value":28536,"nodeType":867},{},[],{"data":43072,"content":43073,"nodeType":876},{},[43074],{"data":43075,"marks":43076,"value":43077,"nodeType":867},{},[],"Hopefully you're now feeling inspired to get involved and start applying the SaaS attack matrix yourself. And if you’ve been using the matrix and want to share your experience with us, we’d love to hear from you. ",{"data":43079,"content":43080,"nodeType":876},{},[43081,43085,43092],{"data":43082,"marks":43083,"value":43084,"nodeType":867},{},[],"We hope to see your comments, discussions, or PRs on ",{"data":43086,"content":43087,"nodeType":915},{"uri":15408},[43088],{"data":43089,"marks":43090,"value":14515,"nodeType":867},{},[43091],{"type":913},{"data":43093,"marks":43094,"value":43095,"nodeType":867},{},[],"!",{"data":43097,"content":43098,"nodeType":876},{},[43099,43103,43112],{"data":43100,"marks":43101,"value":43102,"nodeType":867},{},[],"If this has piqued your interest, we’ve just released a 2024 edition of our SaaS attacks report: ",{"data":43104,"content":43106,"nodeType":915},{"uri":43105},"https://pushsecurity.com/resources/book/saas-attacks-report/",[43107],{"data":43108,"marks":43109,"value":43111,"nodeType":867},{},[43110],{"type":913},"get your copy here",{"data":43113,"marks":43114,"value":5704,"nodeType":867},{},[],{"data":43116,"content":43120,"nodeType":985},{"target":43117},{"sys":43118},{"id":43119,"type":982,"linkType":983},"J11G6XCdDAYu0GQbKGCnm",[],{"data":43122,"content":43123,"nodeType":876},{},[43124],{"data":43125,"marks":43126,"value":21,"nodeType":867},{},[],"The SaaS attack matrix: A year in review","It’s been almost exactly a year since we released our open source repository of SaaS-native attack techniques. Let's reflect on what’s changed. ","2024-08-27T00:00:00.000Z","the-saas-attack-matrix-one-year-on",{"items":43132},[43133,43135],{"sys":43134,"name":4018},{"id":4017},{"sys":43136,"name":342},{"id":3240},{"items":43138},[43139],{"fullName":4022,"firstName":4023,"jobTitle":4024,"profilePicture":43140},{"url":4026},"shifting-detection-left-for-more-effective-threat-detection","blog/shifting-detection-left-for-more-effective-threat-detection",{"json":43144},{"data":43145,"content":43146,"nodeType":1680},{},[43147],{"data":43148,"content":43149,"nodeType":876},{},[43150],{"data":43151,"marks":43152,"value":43153,"nodeType":867},{},[],"This is the second blog in our series looking at the ‘why’ behind the ‘what’ at Push. In this entry, we’re exploring the idea of shifting detection and response left in the face of modern attacks. ","Why relying on post-compromise detection and response is no longer an option for modern browser-based attacks.",{"id":43156,"publishedAt":43157},"4Bc6qX9kURetHcK7nkS8on","2026-08-12T11:54:56.314Z",{"items":43159},[43160,43162],{"sys":43161,"name":342},{"id":3240},{"sys":43163,"name":4018},{"id":4017},{"items":43165},[43166,43168,43170,43172,43174,43176,43178,43180,43182,43184,43186,43188,43190,43192],{"sys":43167,"name":342,"slug":343,"tier":31},{"id":339},{"sys":43169,"name":279,"slug":280,"tier":31},{"id":276},{"sys":43171,"name":297,"slug":298,"tier":31},{"id":294},{"sys":43173,"name":413,"slug":414,"tier":31},{"id":410},{"sys":43175,"name":519,"slug":520,"tier":31},{"id":516},{"sys":43177,"name":351,"slug":352,"tier":45},{"id":348},{"sys":43179,"name":261,"slug":262,"tier":45},{"id":258},{"sys":43181,"name":324,"slug":325,"tier":45},{"id":321},{"sys":43183,"name":571,"slug":572,"tier":45},{"id":568},{"sys":43185,"name":422,"slug":423,"tier":45},{"id":419},{"sys":43187,"name":333,"slug":334,"tier":45},{"id":330},{"sys":43189,"name":624,"slug":625,"tier":45},{"id":621},{"sys":43191,"name":598,"slug":599,"tier":45},{"id":595},{"sys":43193,"name":377,"slug":378,"tier":45},{"id":374},"WqLI4ex55T2BBZsNDP_NW5IbAa7A2KBFIxwJtYqQAvc",{"id":43196,"title":40823,"authorsCollection":43197,"content":43202,"extension":228,"faqItemsCollection":43789,"faqTitle":59,"featured":6,"hashTags":59,"meta":43791,"metaTitle":43792,"ogImage":43793,"postType":1767,"publishedDate":40825,"relatedBlogPostsCollection":43794,"slug":40826,"stem":45415,"subtitle":59,"summary":45416,"synopsis":40824,"sys":45427,"tagsCollection":45429,"topicsCollection":45435,"__hash__":45463},"blog/blog/our-design-philosophy-detecting-what-matters.json",{"items":43198},[43199],{"fullName":4022,"firstName":4023,"jobTitle":4024,"socialLinks":43200,"profilePicture":43201},[21074],{"url":4026},{"json":43203,"links":43757},{"data":43204,"content":43205,"nodeType":1680},{},[43206,43212,43218,43238,43243,43249,43255,43258,43264,43280,43285,43291,43324,43330,43336,43342,43348,43354,43360,43375,43382,43385,43391,43397,43403,43409,43415,43421,43427,43469,43475,43481,43487,43503,43509,43515,43521,43527,43533,43539,43545,43560,43575,43614,43620,43626,43683,43689,43692,43698,43711,43726,43732,43737,43742,43745,43751],{"data":43207,"content":43208,"nodeType":876},{},[43209],{"data":43210,"marks":43211,"value":40191,"nodeType":867},{},[],{"data":43213,"content":43214,"nodeType":876},{},[43215],{"data":43216,"marks":43217,"value":40198,"nodeType":867},{},[],{"data":43219,"content":43220,"nodeType":876},{},[43221,43224,43231,43234],{"data":43222,"marks":43223,"value":40205,"nodeType":867},{},[],{"data":43225,"content":43226,"nodeType":915},{"uri":40208},[43227],{"data":43228,"marks":43229,"value":972,"nodeType":867},{},[43230],{"type":913},{"data":43232,"marks":43233,"value":40217,"nodeType":867},{},[],{"data":43235,"marks":43236,"value":40222,"nodeType":867},{},[43237],{"type":865},{"data":43239,"content":43242,"nodeType":985},{"target":43240},{"sys":43241},{"id":40227,"type":982,"linkType":983},[],{"data":43244,"content":43245,"nodeType":876},{},[43246],{"data":43247,"marks":43248,"value":40235,"nodeType":867},{},[],{"data":43250,"content":43251,"nodeType":876},{},[43252],{"data":43253,"marks":43254,"value":40242,"nodeType":867},{},[],{"data":43256,"content":43257,"nodeType":942},{},[],{"data":43259,"content":43260,"nodeType":868},{},[43261],{"data":43262,"marks":43263,"value":40252,"nodeType":867},{},[],{"data":43265,"content":43266,"nodeType":876},{},[43267,43270,43277],{"data":43268,"marks":43269,"value":40259,"nodeType":867},{},[],{"data":43271,"content":43272,"nodeType":915},{"uri":40262},[43273],{"data":43274,"marks":43275,"value":40268,"nodeType":867},{},[43276],{"type":913},{"data":43278,"marks":43279,"value":40272,"nodeType":867},{},[],{"data":43281,"content":43284,"nodeType":985},{"target":43282},{"sys":43283},{"id":40277,"type":982,"linkType":983},[],{"data":43286,"content":43287,"nodeType":876},{},[43288],{"data":43289,"marks":43290,"value":40285,"nodeType":867},{},[],{"data":43292,"content":43293,"nodeType":876},{},[43294,43297,43303,43306,43312,43315,43321],{"data":43295,"marks":43296,"value":40292,"nodeType":867},{},[],{"data":43298,"content":43299,"nodeType":915},{"uri":14760},[43300],{"data":43301,"marks":43302,"value":40299,"nodeType":867},{},[],{"data":43304,"marks":43305,"value":40303,"nodeType":867},{},[],{"data":43307,"content":43308,"nodeType":915},{"uri":15290},[43309],{"data":43310,"marks":43311,"value":40310,"nodeType":867},{},[],{"data":43313,"marks":43314,"value":40314,"nodeType":867},{},[],{"data":43316,"content":43317,"nodeType":915},{"uri":40317},[43318],{"data":43319,"marks":43320,"value":40322,"nodeType":867},{},[],{"data":43322,"marks":43323,"value":40326,"nodeType":867},{},[],{"data":43325,"content":43326,"nodeType":876},{},[43327],{"data":43328,"marks":43329,"value":40333,"nodeType":867},{},[],{"data":43331,"content":43332,"nodeType":1058},{},[43333],{"data":43334,"marks":43335,"value":40340,"nodeType":867},{},[],{"data":43337,"content":43338,"nodeType":876},{},[43339],{"data":43340,"marks":43341,"value":40347,"nodeType":867},{},[],{"data":43343,"content":43344,"nodeType":876},{},[43345],{"data":43346,"marks":43347,"value":40354,"nodeType":867},{},[],{"data":43349,"content":43350,"nodeType":876},{},[43351],{"data":43352,"marks":43353,"value":40361,"nodeType":867},{},[],{"data":43355,"content":43356,"nodeType":876},{},[43357],{"data":43358,"marks":43359,"value":40368,"nodeType":867},{},[],{"data":43361,"content":43362,"nodeType":876},{},[43363,43366,43372],{"data":43364,"marks":43365,"value":40375,"nodeType":867},{},[],{"data":43367,"content":43368,"nodeType":915},{"uri":34554},[43369],{"data":43370,"marks":43371,"value":40382,"nodeType":867},{},[],{"data":43373,"marks":43374,"value":40386,"nodeType":867},{},[],{"data":43376,"content":43377,"nodeType":876},{},[43378],{"data":43379,"marks":43380,"value":40394,"nodeType":867},{},[43381],{"type":865},{"data":43383,"content":43384,"nodeType":942},{},[],{"data":43386,"content":43387,"nodeType":868},{},[43388],{"data":43389,"marks":43390,"value":40404,"nodeType":867},{},[],{"data":43392,"content":43393,"nodeType":876},{},[43394],{"data":43395,"marks":43396,"value":40411,"nodeType":867},{},[],{"data":43398,"content":43399,"nodeType":876},{},[43400],{"data":43401,"marks":43402,"value":40418,"nodeType":867},{},[],{"data":43404,"content":43405,"nodeType":876},{},[43406],{"data":43407,"marks":43408,"value":40425,"nodeType":867},{},[],{"data":43410,"content":43411,"nodeType":876},{},[43412],{"data":43413,"marks":43414,"value":40432,"nodeType":867},{},[],{"data":43416,"content":43417,"nodeType":1058},{},[43418],{"data":43419,"marks":43420,"value":40439,"nodeType":867},{},[],{"data":43422,"content":43423,"nodeType":876},{},[43424],{"data":43425,"marks":43426,"value":40446,"nodeType":867},{},[],{"data":43428,"content":43429,"nodeType":1629},{},[43430,43443,43456],{"data":43431,"content":43432,"nodeType":1586},{},[43433],{"data":43434,"content":43435,"nodeType":876},{},[43436,43440],{"data":43437,"marks":43438,"value":40460,"nodeType":867},{},[43439],{"type":865},{"data":43441,"marks":43442,"value":40464,"nodeType":867},{},[],{"data":43444,"content":43445,"nodeType":1586},{},[43446],{"data":43447,"content":43448,"nodeType":876},{},[43449,43453],{"data":43450,"marks":43451,"value":40475,"nodeType":867},{},[43452],{"type":865},{"data":43454,"marks":43455,"value":40479,"nodeType":867},{},[],{"data":43457,"content":43458,"nodeType":1586},{},[43459],{"data":43460,"content":43461,"nodeType":876},{},[43462,43466],{"data":43463,"marks":43464,"value":40490,"nodeType":867},{},[43465],{"type":865},{"data":43467,"marks":43468,"value":40494,"nodeType":867},{},[],{"data":43470,"content":43471,"nodeType":876},{},[43472],{"data":43473,"marks":43474,"value":40501,"nodeType":867},{},[],{"data":43476,"content":43477,"nodeType":1058},{},[43478],{"data":43479,"marks":43480,"value":40508,"nodeType":867},{},[],{"data":43482,"content":43483,"nodeType":876},{},[43484],{"data":43485,"marks":43486,"value":40515,"nodeType":867},{},[],{"data":43488,"content":43489,"nodeType":876},{},[43490,43493,43500],{"data":43491,"marks":43492,"value":40522,"nodeType":867},{},[],{"data":43494,"content":43495,"nodeType":915},{"uri":40525},[43496],{"data":43497,"marks":43498,"value":40531,"nodeType":867},{},[43499],{"type":913},{"data":43501,"marks":43502,"value":40535,"nodeType":867},{},[],{"data":43504,"content":43505,"nodeType":876},{},[43506],{"data":43507,"marks":43508,"value":40542,"nodeType":867},{},[],{"data":43510,"content":43511,"nodeType":1058},{},[43512],{"data":43513,"marks":43514,"value":40549,"nodeType":867},{},[],{"data":43516,"content":43517,"nodeType":876},{},[43518],{"data":43519,"marks":43520,"value":40556,"nodeType":867},{},[],{"data":43522,"content":43523,"nodeType":876},{},[43524],{"data":43525,"marks":43526,"value":40563,"nodeType":867},{},[],{"data":43528,"content":43529,"nodeType":876},{},[43530],{"data":43531,"marks":43532,"value":40570,"nodeType":867},{},[],{"data":43534,"content":43535,"nodeType":1058},{},[43536],{"data":43537,"marks":43538,"value":40577,"nodeType":867},{},[],{"data":43540,"content":43541,"nodeType":876},{},[43542],{"data":43543,"marks":43544,"value":40584,"nodeType":867},{},[],{"data":43546,"content":43547,"nodeType":876},{},[43548,43551,43557],{"data":43549,"marks":43550,"value":40591,"nodeType":867},{},[],{"data":43552,"content":43553,"nodeType":915},{"uri":22796},[43554],{"data":43555,"marks":43556,"value":40598,"nodeType":867},{},[],{"data":43558,"marks":43559,"value":1679,"nodeType":867},{},[],{"data":43561,"content":43562,"nodeType":876},{},[43563,43566,43572],{"data":43564,"marks":43565,"value":40608,"nodeType":867},{},[],{"data":43567,"content":43568,"nodeType":915},{"uri":34554},[43569],{"data":43570,"marks":43571,"value":40615,"nodeType":867},{},[],{"data":43573,"marks":43574,"value":40619,"nodeType":867},{},[],{"data":43576,"content":43577,"nodeType":1629},{},[43578,43587,43596,43605],{"data":43579,"content":43580,"nodeType":1586},{},[43581],{"data":43582,"content":43583,"nodeType":876},{},[43584],{"data":43585,"marks":43586,"value":40632,"nodeType":867},{},[],{"data":43588,"content":43589,"nodeType":1586},{},[43590],{"data":43591,"content":43592,"nodeType":876},{},[43593],{"data":43594,"marks":43595,"value":40642,"nodeType":867},{},[],{"data":43597,"content":43598,"nodeType":1586},{},[43599],{"data":43600,"content":43601,"nodeType":876},{},[43602],{"data":43603,"marks":43604,"value":40652,"nodeType":867},{},[],{"data":43606,"content":43607,"nodeType":1586},{},[43608],{"data":43609,"content":43610,"nodeType":876},{},[43611],{"data":43612,"marks":43613,"value":40662,"nodeType":867},{},[],{"data":43615,"content":43616,"nodeType":876},{},[43617],{"data":43618,"marks":43619,"value":40669,"nodeType":867},{},[],{"data":43621,"content":43622,"nodeType":876},{},[43623],{"data":43624,"marks":43625,"value":40676,"nodeType":867},{},[],{"data":43627,"content":43628,"nodeType":1629},{},[43629,43647,43665],{"data":43630,"content":43631,"nodeType":1586},{},[43632],{"data":43633,"content":43634,"nodeType":876},{},[43635,43638,43644],{"data":43636,"marks":43637,"value":40689,"nodeType":867},{},[],{"data":43639,"content":43640,"nodeType":915},{"uri":22796},[43641],{"data":43642,"marks":43643,"value":40044,"nodeType":867},{},[],{"data":43645,"marks":43646,"value":5704,"nodeType":867},{},[],{"data":43648,"content":43649,"nodeType":1586},{},[43650],{"data":43651,"content":43652,"nodeType":876},{},[43653,43656,43662],{"data":43654,"marks":43655,"value":40708,"nodeType":867},{},[],{"data":43657,"content":43658,"nodeType":915},{"uri":39998},[43659],{"data":43660,"marks":43661,"value":40003,"nodeType":867},{},[],{"data":43663,"marks":43664,"value":21,"nodeType":867},{},[],{"data":43666,"content":43667,"nodeType":1586},{},[43668],{"data":43669,"content":43670,"nodeType":876},{},[43671,43674,43680],{"data":43672,"marks":43673,"value":40727,"nodeType":867},{},[],{"data":43675,"content":43676,"nodeType":915},{"uri":40019},[43677],{"data":43678,"marks":43679,"value":40024,"nodeType":867},{},[],{"data":43681,"marks":43682,"value":5704,"nodeType":867},{},[],{"data":43684,"content":43685,"nodeType":876},{},[43686],{"data":43687,"marks":43688,"value":40743,"nodeType":867},{},[],{"data":43690,"content":43691,"nodeType":942},{},[],{"data":43693,"content":43694,"nodeType":868},{},[43695],{"data":43696,"marks":43697,"value":40753,"nodeType":867},{},[],{"data":43699,"content":43700,"nodeType":876},{},[43701,43704,43708],{"data":43702,"marks":43703,"value":40760,"nodeType":867},{},[],{"data":43705,"marks":43706,"value":40765,"nodeType":867},{},[43707],{"type":865},{"data":43709,"marks":43710,"value":40769,"nodeType":867},{},[],{"data":43712,"content":43713,"nodeType":876},{},[43714,43717,43723],{"data":43715,"marks":43716,"value":40776,"nodeType":867},{},[],{"data":43718,"content":43719,"nodeType":915},{"uri":27034},[43720],{"data":43721,"marks":43722,"value":40783,"nodeType":867},{},[],{"data":43724,"marks":43725,"value":40787,"nodeType":867},{},[],{"data":43727,"content":43728,"nodeType":876},{},[43729],{"data":43730,"marks":43731,"value":40794,"nodeType":867},{},[],{"data":43733,"content":43736,"nodeType":985},{"target":43734},{"sys":43735},{"id":40799,"type":982,"linkType":983},[],{"data":43738,"content":43741,"nodeType":985},{"target":43739},{"sys":43740},{"id":40805,"type":982,"linkType":983},[],{"data":43743,"content":43744,"nodeType":942},{},[],{"data":43746,"content":43747,"nodeType":868},{},[43748],{"data":43749,"marks":43750,"value":23563,"nodeType":867},{},[],{"data":43752,"content":43753,"nodeType":876},{},[43754],{"data":43755,"marks":43756,"value":40822,"nodeType":867},{},[],{"entries":43758},{"hyperlink":43759,"inline":43760,"block":43761},[],[],[43762,43770,43778,43786],{"sys":43763,"__typename":1688,"title":43764,"caption":43765,"layoutMode":59,"file":43766},{"id":40227},"Pyramid of Pain: Original","Original Pyramid of Pain model, created by David Bianco.",{"url":43767,"width":43768,"height":43769},"https://images.ctfassets.net/y1cdw1ablpvd/7dPJT7PYKX71FCCi0GeDzg/16fb3b07959612a45c1b7636da33e541/image3.png",720,405,{"sys":43771,"__typename":1688,"title":43772,"caption":43773,"layoutMode":59,"file":43774},{"id":40277},"A new era for cyber attacks","The digital perimeter for organizations has shifted as business IT has evolved: We now know how attacks are playing out, but the industry response is still being defined.",{"url":43775,"width":43776,"height":43777},"https://images.ctfassets.net/y1cdw1ablpvd/6Sflv5jP0xHb8gLVIvcGaG/098d8fc27c15e74c2e7d2b860218ec89/Slide_16_9_-_27__2_.png",1920,1080,{"sys":43779,"__typename":1688,"title":43780,"caption":43781,"layoutMode":59,"file":43782},{"id":40799},"Pyramid of pain: Identity attacks edition","Applying the Pyramid of Pain concept to identity attacks.",{"url":43783,"width":43784,"height":43785},"https://images.ctfassets.net/y1cdw1ablpvd/30YWVepOBUQeSVGynF251a/3821d6b78bf8cc2edac6770f587e1ed8/Frame_627569__10_.png",2815,1087,{"sys":43787,"__typename":1697,"type":1698,"ctaText":43788,"buttonLabel":33795,"buttonColour":1701,"buttonUrl":27034},{"id":40805},"Learn more about how browser telemetry stacks up against up against other data sources for detecting identity attacks.",{"items":43790},[],{},"Our approach to threat detection controls",{"url":43783},{"items":43795},[43796,44485,44992],{"__typename":1772,"sys":43797,"content":43798,"title":39236,"synopsis":39237,"hashTags":59,"publishedDate":39238,"slug":39239,"tagsCollection":44475,"authorsCollection":44481},{"id":38447},{"json":43799},{"data":43800,"content":43801,"nodeType":1680},{},[43802,43807,43813,43855,43861,43867,43880,43886,43892,43961,43967,43972,43978,43984,43997,44003,44009,44029,44049,44054,44071,44077,44083,44110,44116,44122,44127,44144,44150,44156,44162,44168,44173,44190,44196,44202,44208,44214,44219,44236,44242,44248,44253,44270,44276,44282,44288,44330,44336,44397,44410,44415,44421,44427,44433,44439,44454,44460],{"data":43803,"content":43806,"nodeType":985},{"target":43804},{"sys":43805},{"id":38456,"type":982,"linkType":983},[],{"data":43808,"content":43809,"nodeType":876},{},[43810],{"data":43811,"marks":43812,"value":38464,"nodeType":867},{},[],{"data":43814,"content":43815,"nodeType":876},{},[43816,43819,43825,43828,43834,43837,43843,43846,43852],{"data":43817,"marks":43818,"value":38471,"nodeType":867},{},[],{"data":43820,"content":43821,"nodeType":915},{"uri":38474},[43822],{"data":43823,"marks":43824,"value":38479,"nodeType":867},{},[],{"data":43826,"marks":43827,"value":2136,"nodeType":867},{},[],{"data":43829,"content":43830,"nodeType":915},{"uri":38485},[43831],{"data":43832,"marks":43833,"value":38490,"nodeType":867},{},[],{"data":43835,"marks":43836,"value":2136,"nodeType":867},{},[],{"data":43838,"content":43839,"nodeType":915},{"uri":2177},[43840],{"data":43841,"marks":43842,"value":38500,"nodeType":867},{},[],{"data":43844,"marks":43845,"value":2136,"nodeType":867},{},[],{"data":43847,"content":43848,"nodeType":915},{"uri":38506},[43849],{"data":43850,"marks":43851,"value":38511,"nodeType":867},{},[],{"data":43853,"marks":43854,"value":38515,"nodeType":867},{},[],{"data":43856,"content":43857,"nodeType":876},{},[43858],{"data":43859,"marks":43860,"value":38522,"nodeType":867},{},[],{"data":43862,"content":43863,"nodeType":876},{},[43864],{"data":43865,"marks":43866,"value":38529,"nodeType":867},{},[],{"data":43868,"content":43869,"nodeType":876},{},[43870,43873,43877],{"data":43871,"marks":43872,"value":38536,"nodeType":867},{},[],{"data":43874,"marks":43875,"value":38541,"nodeType":867},{},[43876],{"type":865},{"data":43878,"marks":43879,"value":1679,"nodeType":867},{},[],{"data":43881,"content":43882,"nodeType":876},{},[43883],{"data":43884,"marks":43885,"value":38551,"nodeType":867},{},[],{"data":43887,"content":43888,"nodeType":876},{},[43889],{"data":43890,"marks":43891,"value":38558,"nodeType":867},{},[],{"data":43893,"content":43894,"nodeType":1629},{},[43895,43920],{"data":43896,"content":43897,"nodeType":1586},{},[43898],{"data":43899,"content":43900,"nodeType":876},{},[43901,43905,43908,43917],{"data":43902,"marks":43903,"value":38572,"nodeType":867},{},[43904],{"type":865},{"data":43906,"marks":43907,"value":38576,"nodeType":867},{},[],{"data":43909,"content":43912,"nodeType":17452},{"target":43910},{"sys":43911},{"id":38581,"type":982,"linkType":983},[43913],{"data":43914,"marks":43915,"value":25043,"nodeType":867},{},[43916],{"type":865},{"data":43918,"marks":43919,"value":38590,"nodeType":867},{},[],{"data":43921,"content":43922,"nodeType":1586},{},[43923],{"data":43924,"content":43925,"nodeType":876},{},[43926,43930,43933,43939,43942,43948,43951,43958],{"data":43927,"marks":43928,"value":38601,"nodeType":867},{},[43929],{"type":865},{"data":43931,"marks":43932,"value":38605,"nodeType":867},{},[],{"data":43934,"content":43935,"nodeType":915},{"uri":38608},[43936],{"data":43937,"marks":43938,"value":38613,"nodeType":867},{},[],{"data":43940,"marks":43941,"value":5136,"nodeType":867},{},[],{"data":43943,"content":43944,"nodeType":915},{"uri":38619},[43945],{"data":43946,"marks":43947,"value":38624,"nodeType":867},{},[],{"data":43949,"marks":43950,"value":38628,"nodeType":867},{},[],{"data":43952,"content":43953,"nodeType":915},{"uri":38631},[43954],{"data":43955,"marks":43956,"value":38637,"nodeType":867},{},[43957],{"type":865},{"data":43959,"marks":43960,"value":38641,"nodeType":867},{},[],{"data":43962,"content":43963,"nodeType":876},{},[43964],{"data":43965,"marks":43966,"value":38648,"nodeType":867},{},[],{"data":43968,"content":43971,"nodeType":985},{"target":43969},{"sys":43970},{"id":38653,"type":982,"linkType":983},[],{"data":43973,"content":43974,"nodeType":868},{},[43975],{"data":43976,"marks":43977,"value":38661,"nodeType":867},{},[],{"data":43979,"content":43980,"nodeType":876},{},[43981],{"data":43982,"marks":43983,"value":38668,"nodeType":867},{},[],{"data":43985,"content":43986,"nodeType":876},{},[43987,43990,43994],{"data":43988,"marks":43989,"value":38675,"nodeType":867},{},[],{"data":43991,"marks":43992,"value":25043,"nodeType":867},{},[43993],{"type":865},{"data":43995,"marks":43996,"value":38683,"nodeType":867},{},[],{"data":43998,"content":43999,"nodeType":876},{},[44000],{"data":44001,"marks":44002,"value":38690,"nodeType":867},{},[],{"data":44004,"content":44005,"nodeType":1058},{},[44006],{"data":44007,"marks":44008,"value":38697,"nodeType":867},{},[],{"data":44010,"content":44011,"nodeType":876},{},[44012,44015,44019,44022,44026],{"data":44013,"marks":44014,"value":38704,"nodeType":867},{},[],{"data":44016,"marks":44017,"value":38709,"nodeType":867},{},[44018],{"type":865},{"data":44020,"marks":44021,"value":1174,"nodeType":867},{},[],{"data":44023,"marks":44024,"value":38717,"nodeType":867},{},[44025],{"type":865},{"data":44027,"marks":44028,"value":1679,"nodeType":867},{},[],{"data":44030,"content":44031,"nodeType":876},{},[44032,44035,44039,44042,44046],{"data":44033,"marks":44034,"value":38727,"nodeType":867},{},[],{"data":44036,"marks":44037,"value":38732,"nodeType":867},{},[44038],{"type":865},{"data":44040,"marks":44041,"value":21631,"nodeType":867},{},[],{"data":44043,"marks":44044,"value":38740,"nodeType":867},{},[44045],{"type":865},{"data":44047,"marks":44048,"value":38744,"nodeType":867},{},[],{"data":44050,"content":44053,"nodeType":985},{"target":44051},{"sys":44052},{"id":38749,"type":982,"linkType":983},[],{"data":44055,"content":44056,"nodeType":876},{},[44057,44060,44068],{"data":44058,"marks":44059,"value":38757,"nodeType":867},{},[],{"data":44061,"content":44064,"nodeType":17452},{"target":44062},{"sys":44063},{"id":38762,"type":982,"linkType":983},[44065],{"data":44066,"marks":44067,"value":38767,"nodeType":867},{},[],{"data":44069,"marks":44070,"value":21,"nodeType":867},{},[],{"data":44072,"content":44073,"nodeType":1058},{},[44074],{"data":44075,"marks":44076,"value":38777,"nodeType":867},{},[],{"data":44078,"content":44079,"nodeType":876},{},[44080],{"data":44081,"marks":44082,"value":38784,"nodeType":867},{},[],{"data":44084,"content":44085,"nodeType":876},{},[44086,44089,44093,44096,44100,44103,44107],{"data":44087,"marks":44088,"value":38791,"nodeType":867},{},[],{"data":44090,"marks":44091,"value":38732,"nodeType":867},{},[44092],{"type":865},{"data":44094,"marks":44095,"value":21631,"nodeType":867},{},[],{"data":44097,"marks":44098,"value":38740,"nodeType":867},{},[44099],{"type":865},{"data":44101,"marks":44102,"value":38806,"nodeType":867},{},[],{"data":44104,"marks":44105,"value":38811,"nodeType":867},{},[44106],{"type":865},{"data":44108,"marks":44109,"value":38815,"nodeType":867},{},[],{"data":44111,"content":44112,"nodeType":876},{},[44113],{"data":44114,"marks":44115,"value":38822,"nodeType":867},{},[],{"data":44117,"content":44118,"nodeType":876},{},[44119],{"data":44120,"marks":44121,"value":38829,"nodeType":867},{},[],{"data":44123,"content":44126,"nodeType":985},{"target":44124},{"sys":44125},{"id":38834,"type":982,"linkType":983},[],{"data":44128,"content":44129,"nodeType":876},{},[44130,44133,44141],{"data":44131,"marks":44132,"value":38757,"nodeType":867},{},[],{"data":44134,"content":44137,"nodeType":17452},{"target":44135},{"sys":44136},{"id":38846,"type":982,"linkType":983},[44138],{"data":44139,"marks":44140,"value":38777,"nodeType":867},{},[],{"data":44142,"marks":44143,"value":21,"nodeType":867},{},[],{"data":44145,"content":44146,"nodeType":1058},{},[44147],{"data":44148,"marks":44149,"value":38860,"nodeType":867},{},[],{"data":44151,"content":44152,"nodeType":876},{},[44153],{"data":44154,"marks":44155,"value":38867,"nodeType":867},{},[],{"data":44157,"content":44158,"nodeType":876},{},[44159],{"data":44160,"marks":44161,"value":38874,"nodeType":867},{},[],{"data":44163,"content":44164,"nodeType":876},{},[44165],{"data":44166,"marks":44167,"value":38881,"nodeType":867},{},[],{"data":44169,"content":44172,"nodeType":985},{"target":44170},{"sys":44171},{"id":38886,"type":982,"linkType":983},[],{"data":44174,"content":44175,"nodeType":876},{},[44176,44179,44187],{"data":44177,"marks":44178,"value":38757,"nodeType":867},{},[],{"data":44180,"content":44183,"nodeType":17452},{"target":44181},{"sys":44182},{"id":38898,"type":982,"linkType":983},[44184],{"data":44185,"marks":44186,"value":38860,"nodeType":867},{},[],{"data":44188,"marks":44189,"value":21,"nodeType":867},{},[],{"data":44191,"content":44192,"nodeType":1058},{},[44193],{"data":44194,"marks":44195,"value":38912,"nodeType":867},{},[],{"data":44197,"content":44198,"nodeType":876},{},[44199],{"data":44200,"marks":44201,"value":38919,"nodeType":867},{},[],{"data":44203,"content":44204,"nodeType":876},{},[44205],{"data":44206,"marks":44207,"value":38926,"nodeType":867},{},[],{"data":44209,"content":44210,"nodeType":876},{},[44211],{"data":44212,"marks":44213,"value":38933,"nodeType":867},{},[],{"data":44215,"content":44218,"nodeType":985},{"target":44216},{"sys":44217},{"id":38938,"type":982,"linkType":983},[],{"data":44220,"content":44221,"nodeType":876},{},[44222,44225,44233],{"data":44223,"marks":44224,"value":38757,"nodeType":867},{},[],{"data":44226,"content":44229,"nodeType":17452},{"target":44227},{"sys":44228},{"id":38950,"type":982,"linkType":983},[44230],{"data":44231,"marks":44232,"value":38955,"nodeType":867},{},[],{"data":44234,"marks":44235,"value":21,"nodeType":867},{},[],{"data":44237,"content":44238,"nodeType":1058},{},[44239],{"data":44240,"marks":44241,"value":38965,"nodeType":867},{},[],{"data":44243,"content":44244,"nodeType":876},{},[44245],{"data":44246,"marks":44247,"value":38972,"nodeType":867},{},[],{"data":44249,"content":44252,"nodeType":985},{"target":44250},{"sys":44251},{"id":38977,"type":982,"linkType":983},[],{"data":44254,"content":44255,"nodeType":876},{},[44256,44259,44267],{"data":44257,"marks":44258,"value":38757,"nodeType":867},{},[],{"data":44260,"content":44263,"nodeType":17452},{"target":44261},{"sys":44262},{"id":38989,"type":982,"linkType":983},[44264],{"data":44265,"marks":44266,"value":38994,"nodeType":867},{},[],{"data":44268,"marks":44269,"value":21,"nodeType":867},{},[],{"data":44271,"content":44272,"nodeType":868},{},[44273],{"data":44274,"marks":44275,"value":39004,"nodeType":867},{},[],{"data":44277,"content":44278,"nodeType":876},{},[44279],{"data":44280,"marks":44281,"value":39011,"nodeType":867},{},[],{"data":44283,"content":44284,"nodeType":876},{},[44285],{"data":44286,"marks":44287,"value":39018,"nodeType":867},{},[],{"data":44289,"content":44290,"nodeType":1629},{},[44291,44304,44317],{"data":44292,"content":44293,"nodeType":1586},{},[44294],{"data":44295,"content":44296,"nodeType":876},{},[44297,44301],{"data":44298,"marks":44299,"value":39032,"nodeType":867},{},[44300],{"type":865},{"data":44302,"marks":44303,"value":39036,"nodeType":867},{},[],{"data":44305,"content":44306,"nodeType":1586},{},[44307],{"data":44308,"content":44309,"nodeType":876},{},[44310,44314],{"data":44311,"marks":44312,"value":39047,"nodeType":867},{},[44313],{"type":865},{"data":44315,"marks":44316,"value":39051,"nodeType":867},{},[],{"data":44318,"content":44319,"nodeType":1586},{},[44320],{"data":44321,"content":44322,"nodeType":876},{},[44323,44327],{"data":44324,"marks":44325,"value":39062,"nodeType":867},{},[44326],{"type":865},{"data":44328,"marks":44329,"value":39066,"nodeType":867},{},[],{"data":44331,"content":44332,"nodeType":876},{},[44333],{"data":44334,"marks":44335,"value":39073,"nodeType":867},{},[],{"data":44337,"content":44338,"nodeType":1629},{},[44339,44355,44371,44384],{"data":44340,"content":44341,"nodeType":1586},{},[44342],{"data":44343,"content":44344,"nodeType":876},{},[44345,44348,44352],{"data":44346,"marks":44347,"value":39086,"nodeType":867},{},[],{"data":44349,"marks":44350,"value":39091,"nodeType":867},{},[44351],{"type":865},{"data":44353,"marks":44354,"value":39095,"nodeType":867},{},[],{"data":44356,"content":44357,"nodeType":1586},{},[44358],{"data":44359,"content":44360,"nodeType":876},{},[44361,44364,44368],{"data":44362,"marks":44363,"value":39105,"nodeType":867},{},[],{"data":44365,"marks":44366,"value":39110,"nodeType":867},{},[44367],{"type":865},{"data":44369,"marks":44370,"value":39114,"nodeType":867},{},[],{"data":44372,"content":44373,"nodeType":1586},{},[44374],{"data":44375,"content":44376,"nodeType":876},{},[44377,44381],{"data":44378,"marks":44379,"value":39125,"nodeType":867},{},[44380],{"type":865},{"data":44382,"marks":44383,"value":39129,"nodeType":867},{},[],{"data":44385,"content":44386,"nodeType":1586},{},[44387],{"data":44388,"content":44389,"nodeType":876},{},[44390,44394],{"data":44391,"marks":44392,"value":39140,"nodeType":867},{},[44393],{"type":865},{"data":44395,"marks":44396,"value":39144,"nodeType":867},{},[],{"data":44398,"content":44399,"nodeType":876},{},[44400,44403,44407],{"data":44401,"marks":44402,"value":39151,"nodeType":867},{},[],{"data":44404,"marks":44405,"value":38637,"nodeType":867},{},[44406],{"type":865},{"data":44408,"marks":44409,"value":39159,"nodeType":867},{},[],{"data":44411,"content":44414,"nodeType":985},{"target":44412},{"sys":44413},{"id":39164,"type":982,"linkType":983},[],{"data":44416,"content":44417,"nodeType":876},{},[44418],{"data":44419,"marks":44420,"value":39172,"nodeType":867},{},[],{"data":44422,"content":44423,"nodeType":868},{},[44424],{"data":44425,"marks":44426,"value":39179,"nodeType":867},{},[],{"data":44428,"content":44429,"nodeType":876},{},[44430],{"data":44431,"marks":44432,"value":39186,"nodeType":867},{},[],{"data":44434,"content":44435,"nodeType":876},{},[44436],{"data":44437,"marks":44438,"value":39193,"nodeType":867},{},[],{"data":44440,"content":44441,"nodeType":876},{},[44442,44445,44451],{"data":44443,"marks":44444,"value":39200,"nodeType":867},{},[],{"data":44446,"content":44447,"nodeType":915},{"uri":38619},[44448],{"data":44449,"marks":44450,"value":39207,"nodeType":867},{},[],{"data":44452,"marks":44453,"value":39211,"nodeType":867},{},[],{"data":44455,"content":44456,"nodeType":868},{},[44457],{"data":44458,"marks":44459,"value":25228,"nodeType":867},{},[],{"data":44461,"content":44462,"nodeType":876},{},[44463,44466,44472],{"data":44464,"marks":44465,"value":39224,"nodeType":867},{},[],{"data":44467,"content":44468,"nodeType":915},{"uri":39227},[44469],{"data":44470,"marks":44471,"value":11707,"nodeType":867},{},[],{"data":44473,"marks":44474,"value":39235,"nodeType":867},{},[],{"items":44476},[44477,44479],{"sys":44478,"name":39245},{"id":39244},{"sys":44480,"name":342},{"id":3240},{"items":44482},[44483],{"fullName":2714,"firstName":2715,"jobTitle":851,"profilePicture":44484},{"url":2717},{"__typename":1772,"sys":44486,"content":44488,"title":44978,"synopsis":44979,"hashTags":59,"publishedDate":44980,"slug":44981,"tagsCollection":44982,"authorsCollection":44988},{"id":44487},"6Uvqu6LcWzOVfA9mxtu841",{"json":44489},{"data":44490,"content":44491,"nodeType":1680},{},[44492,44498,44505,44538,44545,44565,44572,44617,44624,44631,44638,44643,44650,44739,44746,44753,44776,44783,44790,44797,44804,44811,44818,44868,44875,44881,44899,44905,44912,44919,44926,44933,44940,44947,44954,44960],{"data":44493,"content":44497,"nodeType":985},{"target":44494},{"sys":44495},{"id":44496,"type":982,"linkType":983},"2HffP4X7owzpfj41jnzXmV",[],{"data":44499,"content":44500,"nodeType":876},{},[44501],{"data":44502,"marks":44503,"value":44504,"nodeType":867},{},[],"To detect session token theft, you need three things:",{"data":44506,"content":44507,"nodeType":1629},{},[44508,44518,44528],{"data":44509,"content":44510,"nodeType":1586},{},[44511],{"data":44512,"content":44513,"nodeType":876},{},[44514],{"data":44515,"marks":44516,"value":44517,"nodeType":867},{},[],"Robust logs that provide an identifier to help tie activity to a specific session",{"data":44519,"content":44520,"nodeType":1586},{},[44521],{"data":44522,"content":44523,"nodeType":876},{},[44524],{"data":44525,"marks":44526,"value":44527,"nodeType":867},{},[],"A well-oiled SOC to correlate observed activity in those logs",{"data":44529,"content":44530,"nodeType":1586},{},[44531],{"data":44532,"content":44533,"nodeType":876},{},[44534],{"data":44535,"marks":44536,"value":44537,"nodeType":867},{},[],"And telemetry to tie those logs to a trusted endpoint",{"data":44539,"content":44540,"nodeType":876},{},[44541],{"data":44542,"marks":44543,"value":44544,"nodeType":867},{},[],"The only problem? That third thing didn’t really exist. So we created it.",{"data":44546,"content":44547,"nodeType":876},{},[44548,44552,44561],{"data":44549,"marks":44550,"value":44551,"nodeType":867},{},[],"In this article, we’ll cover how Push’s recently released ",{"data":44553,"content":44555,"nodeType":915},{"uri":44554},"https://pushsecurity.com/help/10114#start",[44556],{"data":44557,"marks":44558,"value":44560,"nodeType":867},{},[44559],{"type":913},"session theft detection",{"data":44562,"marks":44563,"value":44564,"nodeType":867},{},[]," feature works, why we built it, and why the unique control point provided by a browser agent unlocks new capabilities for blue teams fighting the effects of infostealer malware and other stolen credential-based attacks.",{"data":44566,"content":44567,"nodeType":868},{},[44568],{"data":44569,"marks":44570,"value":44571,"nodeType":867},{},[],"(You probably already know) Why this matters",{"data":44573,"content":44574,"nodeType":876},{},[44575,44579,44588,44592,44601,44605,44613],{"data":44576,"marks":44577,"value":44578,"nodeType":867},{},[],"Session token theft is a ",{"data":44580,"content":44582,"nodeType":915},{"uri":44581},"https://owasp.org/www-community/attacks/Session_hijacking_attack",[44583],{"data":44584,"marks":44585,"value":44587,"nodeType":867},{},[44586],{"type":913},"session hijacking",{"data":44589,"marks":44590,"value":44591,"nodeType":867},{},[]," technique where endpoint malware is used to extract sessions from an endpoint, and until recently it was ",{"data":44593,"content":44595,"nodeType":915},{"uri":44594},"https://www.microsoft.com/en-us/security/blog/2022/11/16/token-tactics-how-to-prevent-detect-and-respond-to-cloud-token-theft/",[44596],{"data":44597,"marks":44598,"value":44600,"nodeType":867},{},[44599],{"type":913},"relatively rare",{"data":44602,"marks":44603,"value":44604,"nodeType":867},{},[],". It’s easier to ",{"data":44606,"content":44607,"nodeType":915},{"uri":37942},[44608],{"data":44609,"marks":44610,"value":44612,"nodeType":867},{},[44611],{"type":913},"gain access via a password",{"data":44614,"marks":44615,"value":44616,"nodeType":867},{},[]," than it is to steal a session cookie. ",{"data":44618,"content":44619,"nodeType":876},{},[44620],{"data":44621,"marks":44622,"value":44623,"nodeType":867},{},[],"But there’s an inverse relationship between session-based attacks and MFA adoption. As MFA becomes widespread, adversaries turn to new effective methods of initial entry.",{"data":44625,"content":44626,"nodeType":876},{},[44627],{"data":44628,"marks":44629,"value":44630,"nodeType":867},{},[],"An increasingly common approach involves the use of infostealer malware, which can extract saved credentials, browser cookies, cryptowallets, and other valuable data from the infected endpoint.",{"data":44632,"content":44633,"nodeType":876},{},[44634],{"data":44635,"marks":44636,"value":44637,"nodeType":867},{},[],"Using stolen tokens, adversaries don’t need to bypass MFA directly. They can simply import the tokens into their browser and assume an already authorized session.",{"data":44639,"content":44642,"nodeType":985},{"target":44640},{"sys":44641},{"id":41436,"type":982,"linkType":983},[],{"data":44644,"content":44645,"nodeType":876},{},[44646],{"data":44647,"marks":44648,"value":44649,"nodeType":867},{},[],"A few recent stats show the scope of the problem:",{"data":44651,"content":44652,"nodeType":1629},{},[44653,44675,44697,44718],{"data":44654,"content":44655,"nodeType":1586},{},[44656],{"data":44657,"content":44658,"nodeType":876},{},[44659,44663,44672],{"data":44660,"marks":44661,"value":44662,"nodeType":867},{},[],"Nearly half of the malware detected last year by Sophos targeted victims’ data specifically, and the majority of that malware was classified as infostealers. Source: ",{"data":44664,"content":44666,"nodeType":915},{"uri":44665},"https://news.sophos.com/en-us/2024/03/12/2024-sophos-threat-report/",[44667],{"data":44668,"marks":44669,"value":44671,"nodeType":867},{},[44670],{"type":913},"2024 Sophos Threat Report",{"data":44673,"marks":44674,"value":21,"nodeType":867},{},[],{"data":44676,"content":44677,"nodeType":1586},{},[44678],{"data":44679,"content":44680,"nodeType":876},{},[44681,44685,44694],{"data":44682,"marks":44683,"value":44684,"nodeType":867},{},[],"Information-stealing malware accounted for nearly 10 percent of activity that Red Canary was able to associate with named threats last year. They also found a rise in stealer malware targeting macOS compared to previous years. Source: ",{"data":44686,"content":44688,"nodeType":915},{"uri":44687},"https://redcanary.com/threat-detection-report/trends/info-stealers/",[44689],{"data":44690,"marks":44691,"value":44693,"nodeType":867},{},[44692],{"type":913},"2024 Red Canary Threat Detection Report",{"data":44695,"marks":44696,"value":21,"nodeType":867},{},[],{"data":44698,"content":44699,"nodeType":1586},{},[44700],{"data":44701,"content":44702,"nodeType":876},{},[44703,44707,44715],{"data":44704,"marks":44705,"value":44706,"nodeType":867},{},[],"Stolen credentials continued to rank as the top initial access method for breaches analyzed by Verizon. Source: ",{"data":44708,"content":44709,"nodeType":915},{"uri":2177},[44710],{"data":44711,"marks":44712,"value":44714,"nodeType":867},{},[44713],{"type":913},"2024 Data Breach Investigations Report",{"data":44716,"marks":44717,"value":21,"nodeType":867},{},[],{"data":44719,"content":44720,"nodeType":1586},{},[44721],{"data":44722,"content":44723,"nodeType":876},{},[44724,44728,44736],{"data":44725,"marks":44726,"value":44727,"nodeType":867},{},[],"The number of token replay attacks is increasing, with Microsoft detecting 147,000 attacks in 2023, a 111% increase year-over-year. Source: ",{"data":44729,"content":44731,"nodeType":915},{"uri":44730},"https://techcommunity.microsoft.com/t5/microsoft-entra-blog/how-to-break-the-token-theft-cyber-attack-chain/ba-p/4062700",[44732],{"data":44733,"marks":44734,"value":44735,"nodeType":867},{},[],"Microsoft Blog",{"data":44737,"marks":44738,"value":21,"nodeType":867},{},[],{"data":44740,"content":44741,"nodeType":868},{},[44742],{"data":44743,"marks":44744,"value":44745,"nodeType":867},{},[],"What's missing from current defenses",{"data":44747,"content":44748,"nodeType":876},{},[44749],{"data":44750,"marks":44751,"value":44752,"nodeType":867},{},[],"When defending against infostealer malware or other forms of session and credential theft, there are a few common challenges that organizations may face:",{"data":44754,"content":44755,"nodeType":1629},{},[44756,44766],{"data":44757,"content":44758,"nodeType":1586},{},[44759],{"data":44760,"content":44761,"nodeType":876},{},[44762],{"data":44763,"marks":44764,"value":44765,"nodeType":867},{},[],"Their endpoint security tooling doesn’t provide complete coverage across their device fleet, though they thought it did.",{"data":44767,"content":44768,"nodeType":1586},{},[44769],{"data":44770,"content":44771,"nodeType":876},{},[44772],{"data":44773,"marks":44774,"value":44775,"nodeType":867},{},[],"The malware is good enough to evade EDR detection, or it was able to execute and exfiltrate sessions or other data before it was stopped.",{"data":44777,"content":44778,"nodeType":876},{},[44779],{"data":44780,"marks":44781,"value":44782,"nodeType":867},{},[],"Existing approaches to detecting stolen sessions also pose a noisy problem. Relying on IP-based or geolocation-based signals can result in frequent false positives. (And not all identity provider logs include a session identifier that you can use to perform correlations in the first place.)",{"data":44784,"content":44785,"nodeType":876},{},[44786],{"data":44787,"marks":44788,"value":44789,"nodeType":867},{},[],"The missing piece is a trusted signal for legitimate sessions that you can use to correlate with other data in order to identify unexpected activity that indicates a compromised identity and device.",{"data":44791,"content":44792,"nodeType":868},{},[44793],{"data":44794,"marks":44795,"value":44796,"nodeType":867},{},[],"Generating unique telemetry via the browser",{"data":44798,"content":44799,"nodeType":876},{},[44800],{"data":44801,"marks":44802,"value":44803,"nodeType":867},{},[],"Push’s solution to detecting stolen sessions falls into the category of “so simple, why didn’t this already exist?”",{"data":44805,"content":44806,"nodeType":876},{},[44807],{"data":44808,"marks":44809,"value":44810,"nodeType":867},{},[],"The answer: Because you need to be in the browser to do it. The Push browser agent sits in a unique position that we can leverage to provide telemetry that otherwise would be extremely difficult to create.",{"data":44812,"content":44813,"nodeType":876},{},[44814],{"data":44815,"marks":44816,"value":44817,"nodeType":867},{},[],"Here’s how it works:",{"data":44819,"content":44820,"nodeType":1629},{},[44821,44831,44841],{"data":44822,"content":44823,"nodeType":1586},{},[44824],{"data":44825,"content":44826,"nodeType":876},{},[44827],{"data":44828,"marks":44829,"value":44830,"nodeType":867},{},[],"Via the Push browser agent, Push injects a unique marker into the user agent string of sessions that occur in browsers enrolled in Push.",{"data":44832,"content":44833,"nodeType":1586},{},[44834],{"data":44835,"content":44836,"nodeType":876},{},[44837],{"data":44838,"marks":44839,"value":44840,"nodeType":867},{},[],"Administrators then add the list of domains where they wish to inject the marker into sessions, such as an identity provider like Okta or Microsoft.",{"data":44842,"content":44843,"nodeType":1586},{},[44844],{"data":44845,"content":44846,"nodeType":876},{},[44847,44851,44855,44859,44864],{"data":44848,"marks":44849,"value":44850,"nodeType":867},{},[],"By analyzing logs from the IdP, you can identify activity from the same session that both ",{"data":44852,"marks":44853,"value":24309,"nodeType":867},{},[44854],{"type":1303},{"data":44856,"marks":44857,"value":44858,"nodeType":867},{},[]," the Push marker and that ",{"data":44860,"marks":44861,"value":44863,"nodeType":867},{},[44862],{"type":1303},"lacks",{"data":44865,"marks":44866,"value":44867,"nodeType":867},{},[]," the marker. This can only ever happen when a session is extracted from a browser and maliciously imported into a different browser.",{"data":44869,"content":44870,"nodeType":876},{},[44871],{"data":44872,"marks":44873,"value":44874,"nodeType":867},{},[],"This is a high-fidelity signal that a stolen session token is in use.",{"data":44876,"content":44880,"nodeType":985},{"target":44877},{"sys":44878},{"id":44879,"type":982,"linkType":983},"3zQamWSaZFIbMUhQZtM2II",[],{"data":44882,"content":44883,"nodeType":876},{},[44884,44888,44896],{"data":44885,"marks":44886,"value":44887,"nodeType":867},{},[],"Learn more about configuring this feature in our ",{"data":44889,"content":44890,"nodeType":915},{"uri":44554},[44891],{"data":44892,"marks":44893,"value":44895,"nodeType":867},{},[44894],{"type":913},"Help Center",{"data":44897,"marks":44898,"value":1679,"nodeType":867},{},[],{"data":44900,"content":44904,"nodeType":985},{"target":44901},{"sys":44902},{"id":44903,"type":982,"linkType":983},"35dpGqNY6cTM0fSQRflLiO",[],{"data":44906,"content":44907,"nodeType":868},{},[44908],{"data":44909,"marks":44910,"value":44911,"nodeType":867},{},[],"Unlocking new capabilities for blue teams",{"data":44913,"content":44914,"nodeType":876},{},[44915],{"data":44916,"marks":44917,"value":44918,"nodeType":867},{},[],"As we’ve said before, we see browser telemetry and browser-based controls as the missing piece in security strategies to stop identity attacks — particularly for modern organizations with complex identity ecosystems that span IdPs, SaaS apps, OAuth-connected apps, and more.",{"data":44920,"content":44921,"nodeType":876},{},[44922],{"data":44923,"marks":44924,"value":44925,"nodeType":867},{},[],"Where the browser agent approach particularly shines is that it’s application-agnostic. ",{"data":44927,"content":44928,"nodeType":876},{},[44929],{"data":44930,"marks":44931,"value":44932,"nodeType":867},{},[],"As long as the app you want to monitor provides robust logs, you can inject the Push-supplied marker into any session on any app. ",{"data":44934,"content":44935,"nodeType":876},{},[44936],{"data":44937,"marks":44938,"value":44939,"nodeType":867},{},[],"This allows you to detect suspicious activity even on internal corporate assets, such as an intranet. ",{"data":44941,"content":44942,"nodeType":876},{},[44943],{"data":44944,"marks":44945,"value":44946,"nodeType":867},{},[],"A tidy side effect is that you can also use this feature to identify unmanaged devices accessing sensitive corporate internal resources because they will lack the Push browser agent-supplied marker.",{"data":44948,"content":44949,"nodeType":876},{},[44950],{"data":44951,"marks":44952,"value":44953,"nodeType":867},{},[],"There are probably a few other creative use cases for this feature, so we look forward to seeing what you come up with!",{"data":44955,"content":44956,"nodeType":868},{},[44957],{"data":44958,"marks":44959,"value":25228,"nodeType":867},{},[],{"data":44961,"content":44962,"nodeType":876},{},[44963,44967,44974],{"data":44964,"marks":44965,"value":44966,"nodeType":867},{},[],"To see Push in action, ",{"data":44968,"content":44969,"nodeType":915},{"uri":5286},[44970],{"data":44971,"marks":44972,"value":11707,"nodeType":867},{},[44973],{"type":913},{"data":44975,"marks":44976,"value":44977,"nodeType":867},{},[],". We’ll be happy to show you this feature, along with how we discover all the apps your employees are using, even the ones not behind SSO, and how we detect vulnerable identities and stop identity attacks with browser-based controls.","Introducing session token theft detection: Why browser is best","Push's browser agent identifies session token theft by adding telemetry to the user agent string to create a new high-fidelity signal for your security team.","2024-06-25T00:00:00.000Z","introducing-session-token-theft-detection-why-browser-is-best",{"items":44983},[44984,44986],{"sys":44985,"name":342},{"id":3240},{"sys":44987,"name":39245},{"id":39244},{"items":44989},[44990],{"fullName":2714,"firstName":2715,"jobTitle":851,"profilePicture":44991},{"url":2717},{"__typename":1772,"sys":44993,"content":44995,"title":45401,"synopsis":45402,"hashTags":59,"publishedDate":45403,"slug":45404,"tagsCollection":45405,"authorsCollection":45411},{"id":44994},"4EfGLsD4qOkE4AoTUoL83m",{"json":44996},{"data":44997,"content":44998,"nodeType":1680},{},[44999,45005,45026,45047,45065,45085,45108,45115,45135,45156,45163,45169,45176,45183,45190,45197,45204,45211,45218,45225,45232,45252,45259,45265,45288,45295,45310,45316,45335,45342,45349,45355,45362,45380,45386],{"data":45000,"content":45004,"nodeType":985},{"target":45001},{"sys":45002},{"id":45003,"type":982,"linkType":983},"B8i0EK90Dn7FLrJXR4ANh",[],{"data":45006,"content":45007,"nodeType":876},{},[45008,45012,45022],{"data":45009,"marks":45010,"value":45011,"nodeType":867},{},[],"Is the golden era of MFA protection over? Watch a demo of an ",{"data":45013,"content":45017,"nodeType":17452},{"target":45014},{"sys":45015},{"id":45016,"type":982,"linkType":983},"7DJnckJxP4CXyXhPJJpby5",[45018],{"data":45019,"marks":45020,"value":45021,"nodeType":867},{},[],"EvilNoVNC phishing attack",{"data":45023,"marks":45024,"value":45025,"nodeType":867},{},[]," and you may be left sweating a little and whispering “FIDO2” like a protection spell.",{"data":45027,"content":45028,"nodeType":876},{},[45029,45033,45043],{"data":45030,"marks":45031,"value":45032,"nodeType":867},{},[],"With the widespread adoption of MFA, attackers are ",{"data":45034,"content":45038,"nodeType":17452},{"target":45035},{"sys":45036},{"id":45037,"type":982,"linkType":983},"6XIts2UEnrsJDki8gKDXyI",[45039],{"data":45040,"marks":45041,"value":45042,"nodeType":867},{},[],"increasingly turning",{"data":45044,"marks":45045,"value":45046,"nodeType":867},{},[]," to more sophisticated methods of credential theft as their initial point of entry. ",{"data":45048,"content":45049,"nodeType":876},{},[45050,45054,45061],{"data":45051,"marks":45052,"value":45053,"nodeType":867},{},[],"Newer phishing approaches include reverse proxies as well as tools that mimic legitimate login pages by rendering the webpages and then displaying those renders to the unsuspecting end-user. While these tools are not always common knowledge among blue teams, their use is ",{"data":45055,"content":45056,"nodeType":915},{"uri":38506},[45057],{"data":45058,"marks":45059,"value":45060,"nodeType":867},{},[],"on the rise",{"data":45062,"marks":45063,"value":45064,"nodeType":867},{},[],", an unsurprising response to the broad use of multi-factor authentication in many organizations.",{"data":45066,"content":45067,"nodeType":876},{},[45068,45072,45081],{"data":45069,"marks":45070,"value":45071,"nodeType":867},{},[],"What sets this generation of ",{"data":45073,"content":45076,"nodeType":17452},{"target":45074},{"sys":45075},{"id":45016,"type":982,"linkType":983},[45077],{"data":45078,"marks":45079,"value":45080,"nodeType":867},{},[],"Adversary-in-the-Middle (AitM) phishing tools",{"data":45082,"marks":45083,"value":45084,"nodeType":867},{},[]," apart? ",{"data":45086,"content":45087,"nodeType":1629},{},[45088,45098],{"data":45089,"content":45090,"nodeType":1586},{},[45091],{"data":45092,"content":45093,"nodeType":876},{},[45094],{"data":45095,"marks":45096,"value":45097,"nodeType":867},{},[],"They act as a proxy between the user and a legitimate web login page, allowing the attacker to bypass MFA and harvest credentials and session tokens.",{"data":45099,"content":45100,"nodeType":1586},{},[45101],{"data":45102,"content":45103,"nodeType":876},{},[45104],{"data":45105,"marks":45106,"value":45107,"nodeType":867},{},[],"They give off little scent to end-users, because the end-user is logging into the legitimate site, just by taking a detour via the attacker’s device.",{"data":45109,"content":45110,"nodeType":876},{},[45111],{"data":45112,"marks":45113,"value":45114,"nodeType":867},{},[],"These AitM tools are also difficult to detect — unless you have eyes in the browser.",{"data":45116,"content":45117,"nodeType":876},{},[45118,45122,45131],{"data":45119,"marks":45120,"value":45121,"nodeType":867},{},[],"Powered by the Push browser agent, Push now offers a ",{"data":45123,"content":45126,"nodeType":17452},{"target":45124},{"sys":45125},{"id":38762,"type":982,"linkType":983},[45127],{"data":45128,"marks":45129,"value":45130,"nodeType":867},{},[],"preconfigured set of detections",{"data":45132,"marks":45133,"value":45134,"nodeType":867},{},[]," for phishing tools like Evilginx and others, informed by our threat detection team’s research into their behavior. This phishing tool detection feature will automatically prevent users from accessing a site that’s running one of these malicious tools, and display a custom warning message to your end-users.",{"data":45136,"content":45137,"nodeType":876},{},[45138,45142,45152],{"data":45139,"marks":45140,"value":45141,"nodeType":867},{},[],"While Push already provides strong phishing protection by ",{"data":45143,"content":45147,"nodeType":17452},{"target":45144},{"sys":45145},{"id":45146,"type":982,"linkType":983},"4UtRVoFElDduWJBx9Sa4Cw",[45148],{"data":45149,"marks":45150,"value":45151,"nodeType":867},{},[],"preventing SSO password use",{"data":45153,"marks":45154,"value":45155,"nodeType":867},{},[]," on non-IdP webpages (in other words, it stops you from using your Okta password on any page that isn’t an Okta login page), this new feature allows us to sharpen our anti-phishing capabilities by detecting malware on a site before a user even interacts with the page. ",{"data":45157,"content":45158,"nodeType":876},{},[45159],{"data":45160,"marks":45161,"value":45162,"nodeType":867},{},[],"In this article, we’ll describe our approach to detecting these newer phishing tools, including how we’re borrowing techniques from the world of EDR, and how you can combine phishing tool detection with other Push controls for a defense-in-depth strategy that covers both the user and the application sides of the equation.",{"data":45164,"content":45168,"nodeType":985},{"target":45165},{"sys":45166},{"id":45167,"type":982,"linkType":983},"59q6klX2j7ClgUvmix93sG",[],{"data":45170,"content":45171,"nodeType":868},{},[45172],{"data":45173,"marks":45174,"value":45175,"nodeType":867},{},[],"Taking a page from EDR",{"data":45177,"content":45178,"nodeType":876},{},[45179],{"data":45180,"marks":45181,"value":45182,"nodeType":867},{},[],"Most phishing prevention solutions rely on lists of known-bad sites as the source of intelligence. These are always going to be a step behind reality because they rely on ever-shifting secondary attributes such as domain names (though we won’t be disabling Chrome Safe Browsing anytime soon, and we’re not trying to replace it).",{"data":45184,"content":45185,"nodeType":876},{},[45186],{"data":45187,"marks":45188,"value":45189,"nodeType":867},{},[],"As veterans of the EDR world, we’re drawn to think in analogous terms. With detecting AitM phishing tools, that means expanding on the concept of dynamic analysis on the endpoint. EDR allows you to dynamically analyze the behavior of malware live and at scale, rather than focusing on easy-to-change indicators like file hashes or domain names.",{"data":45191,"content":45192,"nodeType":876},{},[45193],{"data":45194,"marks":45195,"value":45196,"nodeType":867},{},[],"Applying this idea to malware that runs in the browser requires a solution that is in the browser, like the Push browser agent.",{"data":45198,"content":45199,"nodeType":876},{},[45200],{"data":45201,"marks":45202,"value":45203,"nodeType":867},{},[],"So we’re expanding the attributes that are traditionally analyzed to spot indicators of compromise (IoCs) beyond domains, file names, file hashes, IP addresses, etc., to also include behavioral attributes of malware that are much harder to change, such as Javascript calls being made or data structures saved to local storage.",{"data":45205,"content":45206,"nodeType":876},{},[45207],{"data":45208,"marks":45209,"value":45210,"nodeType":867},{},[],"By performing behavioral analysis on AitM automated proxy tools, we can directly analyze the application for a precise and immediate identification. ",{"data":45212,"content":45213,"nodeType":876},{},[45214],{"data":45215,"marks":45216,"value":45217,"nodeType":867},{},[],"Push researchers are regularly identifying and adding detections for new toolkits — think of this like Push’s database of threat research in action.",{"data":45219,"content":45220,"nodeType":868},{},[45221],{"data":45222,"marks":45223,"value":45224,"nodeType":867},{},[],"How it works",{"data":45226,"content":45227,"nodeType":876},{},[45228],{"data":45229,"marks":45230,"value":45231,"nodeType":867},{},[],"If you’re new to Push, a bit of context may be useful. Push uses a browser agent deployed to employee browsers (we support all major browsers) to prevent, detect, and block identity attacks. ",{"data":45233,"content":45234,"nodeType":876},{},[45235,45239,45248],{"data":45236,"marks":45237,"value":45238,"nodeType":867},{},[],"By directly observing user behavior at the login event, Push provides broad and actionable context across all the apps your employees are using, how they are accessing them, their MFA methods, and where they’re using insecure and reused passwords. With this context as the foundation, Push enforces your desired ",{"data":45240,"content":45243,"nodeType":17452},{"target":45241},{"sys":45242},{"id":38581,"type":982,"linkType":983},[45244],{"data":45245,"marks":45246,"value":45247,"nodeType":867},{},[],"security controls",{"data":45249,"marks":45250,"value":45251,"nodeType":867},{},[],", including preventing SSO password reuse, blocking malicious websites, or steering employees to approved apps only.",{"data":45253,"content":45254,"nodeType":876},{},[45255],{"data":45256,"marks":45257,"value":45258,"nodeType":867},{},[],"Once configured by an administrator, phishing tool detection will immediately check for the fingerprints of these toolkits as end-users visit websites and then display your custom warn or block message. ",{"data":45260,"content":45264,"nodeType":985},{"target":45261},{"sys":45262},{"id":45263,"type":982,"linkType":983},"1LdHJjTDlOiie5mctbAVvZ",[],{"data":45266,"content":45267,"nodeType":876},{},[45268,45272,45276,45280,45284],{"data":45269,"marks":45270,"value":45271,"nodeType":867},{},[],"In ",{"data":45273,"marks":45274,"value":38740,"nodeType":867},{},[45275],{"type":865},{"data":45277,"marks":45278,"value":45279,"nodeType":867},{},[]," mode, users cannot proceed to the site where malicious software has been detected. In ",{"data":45281,"marks":45282,"value":38732,"nodeType":867},{},[45283],{"type":865},{"data":45285,"marks":45286,"value":45287,"nodeType":867},{},[]," mode, users can choose to proceed if they are sure it’s not a phishing site.",{"data":45289,"content":45290,"nodeType":876},{},[45291],{"data":45292,"marks":45293,"value":45294,"nodeType":867},{},[],"In both cases, users do not need to interact with a page (by typing, clicking, etc.) for Push to trigger the custom message. ",{"data":45296,"content":45297,"nodeType":876},{},[45298,45301,45307],{"data":45299,"marks":45300,"value":41371,"nodeType":867},{},[],{"data":45302,"content":45303,"nodeType":915},{"uri":38608},[45304],{"data":45305,"marks":45306,"value":41188,"nodeType":867},{},[],{"data":45308,"marks":45309,"value":41381,"nodeType":867},{},[],{"data":45311,"content":45315,"nodeType":985},{"target":45312},{"sys":45313},{"id":45314,"type":982,"linkType":983},"6oAhxLBPVxN3Rcw2kFeVtG",[],{"data":45317,"content":45318,"nodeType":876},{},[45319,45323,45331],{"data":45320,"marks":45321,"value":45322,"nodeType":867},{},[],"Pairing this phishing detection capability with Push’s ",{"data":45324,"content":45327,"nodeType":17452},{"target":45325},{"sys":45326},{"id":38846,"type":982,"linkType":983},[45328],{"data":45329,"marks":45330,"value":38777,"nodeType":867},{},[],{"data":45332,"marks":45333,"value":45334,"nodeType":867},{},[]," feature provides a strong defense-in-depth strategy for stopping credential theft.",{"data":45336,"content":45337,"nodeType":876},{},[45338],{"data":45339,"marks":45340,"value":45341,"nodeType":867},{},[],"SSO password protection works by analyzing user behavior — namely, is a user entering their SSO password onto a page that does not belong to the legitimate identity provider.",{"data":45343,"content":45344,"nodeType":876},{},[45345],{"data":45346,"marks":45347,"value":45348,"nodeType":867},{},[],"Phishing tool detection adds in the application-level behavioral analysis. In addition, when Push identifies a new, previously unknown phishing tool in the wild via blocked SSO credential theft, we add its fingerprints to the browser agent’s detective capabilities.  ",{"data":45350,"content":45351,"nodeType":868},{},[45352],{"data":45353,"marks":45354,"value":15458,"nodeType":867},{},[],{"data":45356,"content":45357,"nodeType":876},{},[45358],{"data":45359,"marks":45360,"value":45361,"nodeType":867},{},[],"We’re just scratching the surface on this approach and are exploring how Push can identify and block other web-delivered malware and Javascript-based attack types beyond AitM tools. Think HTML smuggling, tabnabbing, and the like.",{"data":45363,"content":45364,"nodeType":876},{},[45365,45369,45377],{"data":45366,"marks":45367,"value":45368,"nodeType":867},{},[],"Got feedback? We’d ",{"data":45370,"content":45372,"nodeType":915},{"uri":45371},"/contact/",[45373],{"data":45374,"marks":45375,"value":45376,"nodeType":867},{},[],"love to talk",{"data":45378,"marks":45379,"value":1679,"nodeType":867},{},[],{"data":45381,"content":45382,"nodeType":868},{},[45383],{"data":45384,"marks":45385,"value":25228,"nodeType":867},{},[],{"data":45387,"content":45388,"nodeType":876},{},[45389,45392,45398],{"data":45390,"marks":45391,"value":44966,"nodeType":867},{},[],{"data":45393,"content":45394,"nodeType":915},{"uri":5286},[45395],{"data":45396,"marks":45397,"value":11707,"nodeType":867},{},[],{"data":45399,"marks":45400,"value":44977,"nodeType":867},{},[],"Introducing AitM phishing toolkit detection, powered by the Push browser agent","Push analyzes behavioral attributes of malware to identify phishing tools like Evilginx and NakedPages and immediately block end-users from visiting them.","2024-06-06T00:00:00.000Z","introducing-aitm-phishing-toolkit-detection-powered-by-the-push-browser",{"items":45406},[45407,45409],{"sys":45408,"name":39245},{"id":39244},{"sys":45410,"name":342},{"id":3240},{"items":45412},[45413],{"fullName":2714,"firstName":2715,"jobTitle":851,"profilePicture":45414},{"url":2717},"blog/our-design-philosophy-detecting-what-matters",{"json":45417},{"data":45418,"content":45419,"nodeType":1680},{},[45420],{"data":45421,"content":45422,"nodeType":876},{},[45423],{"data":45424,"marks":45425,"value":45426,"nodeType":867},{},[],"This is the first blog in a short series we’re putting together about the ‘why’ behind the ‘what’ at Push. This entry is focused on threat detection: Let’s get started. ",{"id":17785,"publishedAt":45428},"2026-08-12T11:55:05.842Z",{"items":45430},[45431,45433],{"sys":45432,"name":342},{"id":3240},{"sys":45434,"name":4018},{"id":4017},{"items":45436},[45437,45439,45441,45443,45445,45447,45449,45451,45453,45455,45457,45459,45461],{"sys":45438,"name":342,"slug":343,"tier":31},{"id":339},{"sys":45440,"name":279,"slug":280,"tier":31},{"id":276},{"sys":45442,"name":519,"slug":520,"tier":31},{"id":516},{"sys":45444,"name":297,"slug":298,"tier":31},{"id":294},{"sys":45446,"name":413,"slug":414,"tier":31},{"id":410},{"sys":45448,"name":642,"slug":643,"tier":31},{"id":639},{"sys":45450,"name":351,"slug":352,"tier":45},{"id":348},{"sys":45452,"name":261,"slug":262,"tier":45},{"id":258},{"sys":45454,"name":324,"slug":325,"tier":45},{"id":321},{"sys":45456,"name":404,"slug":405,"tier":45},{"id":401},{"sys":45458,"name":377,"slug":378,"tier":45},{"id":374},{"sys":45460,"name":624,"slug":625,"tier":45},{"id":621},{"sys":45462,"name":528,"slug":529,"tier":45},{"id":525},"V_GfOg_A8krAbLonDFD7Ocweyw1xk5tdvcy0AoFJpsA",{"id":45465,"title":45466,"authorsCollection":45467,"content":45472,"extension":228,"faqItemsCollection":46636,"faqTitle":59,"featured":6,"hashTags":59,"meta":46638,"metaTitle":46639,"ogImage":59,"postType":21733,"publishedDate":46640,"relatedBlogPostsCollection":46641,"slug":48493,"stem":48494,"subtitle":59,"summary":48495,"synopsis":48506,"sys":48507,"tagsCollection":48510,"topicsCollection":48516,"__hash__":48556},"blog/blog/what-the-rise-of-infostealers-says-about-identity-attacks.json","What the rise of infostealers says about identity attacks",{"items":45468},[45469],{"fullName":4022,"firstName":4023,"jobTitle":4024,"socialLinks":45470,"profilePicture":45471},[21074],{"url":4026},{"json":45473,"links":46613},{"data":45474,"content":45475,"nodeType":1680},{},[45476,45505,45517,45533,45540,45547,45550,45557,45564,45694,45701,45708,45802,45809,45816,45869,45876,45899,45956,45959,45966,45985,46005,46012,46031,46038,46050,46053,46060,46067,46115,46122,46129,46147,46150,46157,46164,46171,46187,46194,46201,46208,46228,46235,46242,46249,46256,46275,46282,46289,46296,46303,46332,46338,46341,46348,46355,46361,46368,46375,46398,46405,46412,46455,46471,46490,46496,46503,46510,46517,46549,46594,46601,46607],{"data":45477,"content":45478,"nodeType":876},{},[45479,45483,45491,45494,45501],{"data":45480,"marks":45481,"value":45482,"nodeType":867},{},[],"Infostealer malware seems to be grabbing the headlines right now. It’s easy to see why, too, after laying claim to one of the ",{"data":45484,"content":45485,"nodeType":915},{"uri":40317},[45486],{"data":45487,"marks":45488,"value":45490,"nodeType":867},{},[45489],{"type":913},"biggest breaches in history",{"data":45492,"marks":45493,"value":6811,"nodeType":867},{},[],{"data":45495,"content":45496,"nodeType":915},{"uri":15290},[45497],{"data":45498,"marks":45499,"value":40310,"nodeType":867},{},[45500],{"type":913},{"data":45502,"marks":45503,"value":45504,"nodeType":867},{},[]," saw ~165 businesses compromised using stolen credentials, resulting in millions of breached customer records, with the full impact still emerging. ",{"data":45506,"content":45507,"nodeType":876},{},[45508,45512],{"data":45509,"marks":45510,"value":45511,"nodeType":867},{},[],"Notably, ",{"data":45513,"marks":45514,"value":45516,"nodeType":867},{},[45515],{"type":865},"80% of the credentials used to access Snowflake customer accounts had found their way online after being stolen in infostealer infections – dating back as early as 2020. ",{"data":45518,"content":45519,"nodeType":876},{},[45520,45524,45529],{"data":45521,"marks":45522,"value":45523,"nodeType":867},{},[],"The Snowflake situation is a reminder of how lucrative stolen credentials can be for attackers – and how the cybercrime ecosystem has tilted as a result. As the saying goes nowadays, ",{"data":45525,"marks":45526,"value":45528,"nodeType":867},{},[45527],{"type":865},"hackers don’t hack in, they log in",{"data":45530,"marks":45531,"value":45532,"nodeType":867},{},[],". Stolen credentials are the lowest hanging fruit available to attackers, and their appetite (and the ecosystem needed to feed it) is insatiable. As an attacker, the prospect of picking up access to a major enterprise for just $10 or less (or even for free) is hard to resist – why wouldn’t you buy a ticket and take the gamble?  ",{"data":45534,"content":45535,"nodeType":876},{},[45536],{"data":45537,"marks":45538,"value":45539,"nodeType":867},{},[],"Infostealers are a huge part of the shift toward identity attacks. Along with phishing, infostealers are the primary mechanism for attackers to harvest credentials. Unlike phishing, infostealers can collect a large number of credentials (and other helpful data saved in the browser) in one fell swoop. But, they do have limitations. For example, you would expect any credible EDR to detect and block these attacks. And yet, the success of the attacks on Snowflake customers show us that gaps are being found and exploited.  ",{"data":45541,"content":45542,"nodeType":876},{},[45543],{"data":45544,"marks":45545,"value":45546,"nodeType":867},{},[],"In this article, we’ll look at the history of infostealers, how they work, and what the trends show us about how the cybercrime ecosystem is leaning into the opportunity they present.    ",{"data":45548,"content":45549,"nodeType":942},{},[],{"data":45551,"content":45552,"nodeType":868},{},[45553],{"data":45554,"marks":45555,"value":45556,"nodeType":867},{},[],"The state of infostealers today",{"data":45558,"content":45559,"nodeType":876},{},[45560],{"data":45561,"marks":45562,"value":45563,"nodeType":867},{},[],"Infostealers, and the mass credential harvesting they enable, are a big part of the rise in identity attacks. The stats support this, as:",{"data":45565,"content":45566,"nodeType":1629},{},[45567,45589,45611,45631,45652,45672],{"data":45568,"content":45569,"nodeType":1586},{},[45570],{"data":45571,"content":45572,"nodeType":876},{},[45573,45577,45586],{"data":45574,"marks":45575,"value":45576,"nodeType":867},{},[],"One million new stealer logs are distributed every month, with an estimated 3-5% containing credentials and session cookies to corporate IT environments (",{"data":45578,"content":45580,"nodeType":915},{"uri":45579},"https://www.bleepingcomputer.com/news/security/single-sign-on-and-the-cybercrime-ecosystem/",[45581],{"data":45582,"marks":45583,"value":45585,"nodeType":867},{},[45584],{"type":913},"Flare",{"data":45587,"marks":45588,"value":24243,"nodeType":867},{},[],{"data":45590,"content":45591,"nodeType":1586},{},[45592],{"data":45593,"content":45594,"nodeType":876},{},[45595,45599,45608],{"data":45596,"marks":45597,"value":45598,"nodeType":867},{},[],"Infostealer activity increased by 266% in 2023, while the number of attacks featuring valid credentials saw a 71% increase year-over-year (",{"data":45600,"content":45602,"nodeType":915},{"uri":45601},"https://www.ibm.com/downloads/cas/L0GKXDWJ",[45603],{"data":45604,"marks":45605,"value":45607,"nodeType":867},{},[45606],{"type":913},"IBM",{"data":45609,"marks":45610,"value":24243,"nodeType":867},{},[],{"data":45612,"content":45613,"nodeType":1586},{},[45614],{"data":45615,"content":45616,"nodeType":876},{},[45617,45621,45628],{"data":45618,"marks":45619,"value":45620,"nodeType":867},{},[],"147,000 token replay attacks were detected by Microsoft in 2023, an 111% increase year-over-year (",{"data":45622,"content":45623,"nodeType":915},{"uri":44730},[45624],{"data":45625,"marks":45626,"value":11959,"nodeType":867},{},[45627],{"type":913},{"data":45629,"marks":45630,"value":23136,"nodeType":867},{},[],{"data":45632,"content":45633,"nodeType":1586},{},[45634],{"data":45635,"content":45636,"nodeType":876},{},[45637,45641,45649],{"data":45638,"marks":45639,"value":45640,"nodeType":867},{},[],"Over 1000 credentials are posted online per day, per marketplace with an average sale price of $10, and 65% posted less than one day after being collected (",{"data":45642,"content":45643,"nodeType":915},{"uri":7467},[45644],{"data":45645,"marks":45646,"value":45648,"nodeType":867},{},[45647],{"type":913},"Verizon",{"data":45650,"marks":45651,"value":24243,"nodeType":867},{},[],{"data":45653,"content":45654,"nodeType":1586},{},[45655],{"data":45656,"content":45657,"nodeType":876},{},[45658,45662,45669],{"data":45659,"marks":45660,"value":45661,"nodeType":867},{},[],"Nearly half of the malware detected last year by Sophos targeted victims’ data specifically, and the majority of that malware was classified as infostealers (",{"data":45663,"content":45664,"nodeType":915},{"uri":44665},[45665],{"data":45666,"marks":45667,"value":45668,"nodeType":867},{},[],"Sophos",{"data":45670,"marks":45671,"value":24243,"nodeType":867},{},[],{"data":45673,"content":45674,"nodeType":1586},{},[45675],{"data":45676,"content":45677,"nodeType":876},{},[45678,45682,45691],{"data":45679,"marks":45680,"value":45681,"nodeType":867},{},[],"Attacks on session cookies happen at the same order of magnitude as password-based attacks (",{"data":45683,"content":45685,"nodeType":915},{"uri":45684},"https://github.com/WICG/dbsc/issues/13#issuecomment-1977657864",[45686],{"data":45687,"marks":45688,"value":45690,"nodeType":867},{},[45689],{"type":913},"Google",{"data":45692,"marks":45693,"value":24243,"nodeType":867},{},[],{"data":45695,"content":45696,"nodeType":1058},{},[45697],{"data":45698,"marks":45699,"value":45700,"nodeType":867},{},[],"How did we get here?",{"data":45702,"content":45703,"nodeType":876},{},[45704],{"data":45705,"marks":45706,"value":45707,"nodeType":867},{},[],"Let’s go back to the beginning. When they first emerged, infostealers were designed to steal online banking and credit card information. The most notable early example comes from as far back as 2006 with the ZeuS trojan. After the ZeuS source code was leaked in March 2011, the creation of multiple variants boosted the popularity of this type of malware and inspired the development of infostealers with increasingly sophisticated capabilities.",{"data":45709,"content":45710,"nodeType":876},{},[45711,45715,45724,45728,45737,45741,45750,45753,45762,45765,45774,45777,45786,45789,45798],{"data":45712,"marks":45713,"value":45714,"nodeType":867},{},[],"Modern infostealers rose to prominence in around 2018 with the emergence of ",{"data":45716,"content":45718,"nodeType":915},{"uri":45717},"https://malpedia.caad.fkie.fraunhofer.de/details/win.arkei_stealer",[45719],{"data":45720,"marks":45721,"value":45723,"nodeType":867},{},[45722],{"type":913},"Arkei",{"data":45725,"marks":45726,"value":45727,"nodeType":867},{},[],", which quickly spawned the more popular ",{"data":45729,"content":45731,"nodeType":915},{"uri":45730},"https://malpedia.caad.fkie.fraunhofer.de/details/win.vidar",[45732],{"data":45733,"marks":45734,"value":45736,"nodeType":867},{},[45735],{"type":913},"Vidar",{"data":45738,"marks":45739,"value":45740,"nodeType":867},{},[]," stealer. Today, some of the most popular families are ",{"data":45742,"content":45744,"nodeType":915},{"uri":45743},"https://malpedia.caad.fkie.fraunhofer.de/details/win.risepro",[45745],{"data":45746,"marks":45747,"value":45749,"nodeType":867},{},[45748],{"type":913},"RisePro",{"data":45751,"marks":45752,"value":5136,"nodeType":867},{},[],{"data":45754,"content":45756,"nodeType":915},{"uri":45755},"https://malpedia.caad.fkie.fraunhofer.de/details/win.redline_stealer",[45757],{"data":45758,"marks":45759,"value":45761,"nodeType":867},{},[45760],{"type":913},"RedLine",{"data":45763,"marks":45764,"value":5136,"nodeType":867},{},[],{"data":45766,"content":45768,"nodeType":915},{"uri":45767},"https://malpedia.caad.fkie.fraunhofer.de/details/win.stealc",[45769],{"data":45770,"marks":45771,"value":45773,"nodeType":867},{},[45772],{"type":913},"StealC",{"data":45775,"marks":45776,"value":5136,"nodeType":867},{},[],{"data":45778,"content":45780,"nodeType":915},{"uri":45779},"https://malpedia.caad.fkie.fraunhofer.de/details/win.raccoon",[45781],{"data":45782,"marks":45783,"value":45785,"nodeType":867},{},[45784],{"type":913},"Raccoon",{"data":45787,"marks":45788,"value":5147,"nodeType":867},{},[],{"data":45790,"content":45792,"nodeType":915},{"uri":45791},"https://malpedia.caad.fkie.fraunhofer.de/details/win.lumma",[45793],{"data":45794,"marks":45795,"value":45797,"nodeType":867},{},[45796],{"type":913},"Lumma",{"data":45799,"marks":45800,"value":45801,"nodeType":867},{},[],", with new variants and families appearing all the time. ",{"data":45803,"content":45804,"nodeType":876},{},[45805],{"data":45806,"marks":45807,"value":45808,"nodeType":867},{},[],"Infostealers are used by all manner of threat actors of varying levels of sophistication. For larger groups with sufficient resources, the creation of new, custom stealers and malware packages is a common tactic to attempt to evade detection. ",{"data":45810,"content":45811,"nodeType":876},{},[45812],{"data":45813,"marks":45814,"value":45815,"nodeType":867},{},[],"But despite all the variants, infostealers do have common capabilities and characteristics, such as:",{"data":45817,"content":45818,"nodeType":1629},{},[45819,45829,45839,45849,45859],{"data":45820,"content":45821,"nodeType":1586},{},[45822],{"data":45823,"content":45824,"nodeType":876},{},[45825],{"data":45826,"marks":45827,"value":45828,"nodeType":867},{},[],"Extracting information from the browsers of a compromised device, such as passwords, cookies, autofill information, downloaded file information.",{"data":45830,"content":45831,"nodeType":1586},{},[45832],{"data":45833,"content":45834,"nodeType":876},{},[45835],{"data":45836,"marks":45837,"value":45838,"nodeType":867},{},[],"Snapshotting the desktop and system inventory, with details such as the username, location data, hardware configuration, and information regarding installed security software.",{"data":45840,"content":45841,"nodeType":1586},{},[45842],{"data":45843,"content":45844,"nodeType":876},{},[45845],{"data":45846,"marks":45847,"value":45848,"nodeType":867},{},[],"Sending stolen data back to a C2 server.",{"data":45850,"content":45851,"nodeType":1586},{},[45852],{"data":45853,"content":45854,"nodeType":876},{},[45855],{"data":45856,"marks":45857,"value":45858,"nodeType":867},{},[],"Facilitating the deployment of additional tools and malware as part of a package. ",{"data":45860,"content":45861,"nodeType":1586},{},[45862],{"data":45863,"content":45864,"nodeType":876},{},[45865],{"data":45866,"marks":45867,"value":45868,"nodeType":867},{},[],"Often (but not always) self-terminating once complete, leaving little trace on the victim machine and no ongoing behavior that might be detected. ",{"data":45870,"content":45871,"nodeType":876},{},[45872],{"data":45873,"marks":45874,"value":45875,"nodeType":867},{},[],"Infostealers are distributed in similar ways to other types of malware, such as:",{"data":45877,"content":45878,"nodeType":1629},{},[45879,45889],{"data":45880,"content":45881,"nodeType":1586},{},[45882],{"data":45883,"content":45884,"nodeType":876},{},[45885],{"data":45886,"marks":45887,"value":45888,"nodeType":867},{},[],"Delivery of malicious executable files via phishing emails or by having a victim download content from a malicious website. ",{"data":45890,"content":45891,"nodeType":1586},{},[45892],{"data":45893,"content":45894,"nodeType":876},{},[45895],{"data":45896,"marks":45897,"value":45898,"nodeType":867},{},[],"‘Drive-by’ style attacks where the victim has only to visit an infected website.",{"data":45900,"content":45901,"nodeType":876},{},[45902,45906,45915,45918,45927,45930,45939,45943,45952],{"data":45903,"marks":45904,"value":45905,"nodeType":867},{},[],"They’re typically spread via malvertising, P2P downloads, and deceptive software download sites. ",{"data":45907,"content":45909,"nodeType":915},{"uri":45908},"https://www.bleepingcomputer.com/news/security/fake-cheat-lures-gamers-into-spreading-infostealer-malware/",[45910],{"data":45911,"marks":45912,"value":45914,"nodeType":867},{},[45913],{"type":913},"Gaming forums",{"data":45916,"marks":45917,"value":5136,"nodeType":867},{},[],{"data":45919,"content":45921,"nodeType":915},{"uri":45920},"https://cybersecuritynews.com/facebook-account-hijack-malware/",[45922],{"data":45923,"marks":45924,"value":45926,"nodeType":867},{},[45925],{"type":913},"Facebook ads",{"data":45928,"marks":45929,"value":5147,"nodeType":867},{},[],{"data":45931,"content":45933,"nodeType":915},{"uri":45932},"https://www.fortinet.com/blog/threat-research/lumma-variant-on-youtube",[45934],{"data":45935,"marks":45936,"value":45938,"nodeType":867},{},[45937],{"type":913},"YouTube video descriptions",{"data":45940,"marks":45941,"value":45942,"nodeType":867},{},[]," are popular locations for malicious links, but recent examples also include ",{"data":45944,"content":45946,"nodeType":915},{"uri":45945},"https://www.bleepingcomputer.com/news/security/over-3-000-github-accounts-used-by-malware-distribution-service/",[45947],{"data":45948,"marks":45949,"value":45951,"nodeType":867},{},[45950],{"type":913},"complex malware distribution networks on GitHub",{"data":45953,"marks":45954,"value":45955,"nodeType":867},{},[]," – such as the recent campaign from ‘Stargazer Goblin’ with more than 3,000 fake accounts creating and promoting hundreds of fake repositories to increase their apparent legitimacy and make them more likely to appear on GitHub's trending section.",{"data":45957,"content":45958,"nodeType":942},{},[],{"data":45960,"content":45961,"nodeType":868},{},[45962],{"data":45963,"marks":45964,"value":45965,"nodeType":867},{},[],"Infostealers are key to the cybercrime ecosystem",{"data":45967,"content":45968,"nodeType":876},{},[45969,45973,45981],{"data":45970,"marks":45971,"value":45972,"nodeType":867},{},[],"After being stolen, ",{"data":45974,"content":45975,"nodeType":915},{"uri":45579},[45976],{"data":45977,"marks":45978,"value":45980,"nodeType":867},{},[45979],{"type":913},"infostealer data inevitably finds its way onto hacker forums and marketplaces",{"data":45982,"marks":45983,"value":45984,"nodeType":867},{},[],", both on the clearweb and darkweb. Popular infostealers have their own dedicated Telegram channels to advertise and sell stolen data. Private channels also exist, with the channel owner distributing tens of thousands of logs per week to a limited number of threat actors who pay $200-$400 for access to the channel. This allows them to get ‘first pick’ of stolen logs, which are later shared through public Telegram channels. ",{"data":45986,"content":45987,"nodeType":876},{},[45988,45992,46001],{"data":45989,"marks":45990,"value":45991,"nodeType":867},{},[],"Public data eventually makes its way onto services such as Have I Been Pwned (HIBP), which gives individuals and security teams some visibility of which credentials have been compromised. For example, ",{"data":45993,"content":45995,"nodeType":915},{"uri":45994},"https://www.troyhunt.com/telegram-combolists-and-361m-email-addresses/",[45996],{"data":45997,"marks":45998,"value":46000,"nodeType":867},{},[45999],{"type":913},"in June, Troy Hunt (creator of HIBP) wrote",{"data":46002,"marks":46003,"value":46004,"nodeType":867},{},[]," about the impact of channels like Telegram and the sale of combolists (username, password, login portal URL), after being sent 122GB of data scraped out of thousands of Telegram channels, containing 361M unique email addresses (of which 151M had never been seen in HIBP before). ",{"data":46006,"content":46007,"nodeType":876},{},[46008],{"data":46009,"marks":46010,"value":46011,"nodeType":867},{},[],"The cybercrime ecosystem is complex, with a developed supply chain and organizations fulfilling different roles as a result: from malware-as-a-service developers, to initial access brokers, to the operators that actually conduct the attacks (be they ransomware, data theft, etc.) – and many, many other roles in between. Sometimes, a single group and/or its affiliates will conduct the full chain, but this is far less common today. ",{"data":46013,"content":46014,"nodeType":876},{},[46015,46018,46027],{"data":46016,"marks":46017,"value":21,"nodeType":867},{},[],{"data":46019,"content":46021,"nodeType":915},{"uri":46020},"https://www.secureworks.com/research/the-growing-threat-from-infostealers",[46022],{"data":46023,"marks":46024,"value":46026,"nodeType":867},{},[46025],{"type":913},"Infostealers are often sold by malware developers to other attackers as a monthly subscription service.",{"data":46028,"marks":46029,"value":46030,"nodeType":867},{},[]," The price can range from $50 to over $1,000 USD per month for access to a stealer command and control (C2) server operated by the developer. The service often features a range of support functions, including multiple ways to view, download, and share stolen data. Self-hosted stealer C2 servers are also available and are usually sold for a flat fee. ",{"data":46032,"content":46033,"nodeType":876},{},[46034],{"data":46035,"marks":46036,"value":46037,"nodeType":867},{},[],"There’s also evidence that there is an element of target coordination – with one marketplace, Russian Market, allowing users to ‘preorder’ credentials for a $1,000 USD deposit from 2022. ",{"data":46039,"content":46040,"nodeType":876},{},[46041,46046],{"data":46042,"marks":46043,"value":46045,"nodeType":867},{},[46044],{"type":865},"So what? Well, there's evidently an abundance of breached data already online, and attackers have the tools readily available to have this pile grow exponentially bigger and more useful.",{"data":46047,"marks":46048,"value":46049,"nodeType":867},{},[]," It’s also probably more coordinated than we like to admit – a particularly intimidating prospect in the wake of Snowflake, which will no doubt have many criminals smelling blood in the water. ",{"data":46051,"content":46052,"nodeType":942},{},[],{"data":46054,"content":46055,"nodeType":868},{},[46056],{"data":46057,"marks":46058,"value":46059,"nodeType":867},{},[],"How can stolen data be abused by attackers? ",{"data":46061,"content":46062,"nodeType":876},{},[46063],{"data":46064,"marks":46065,"value":46066,"nodeType":867},{},[],"It’s pretty obvious that attackers getting access to all of your passwords and session cookies is bad, but there is a clear value hierarchy from a corporate security perspective. So, from highest to lowest risk:",{"data":46068,"content":46069,"nodeType":1629},{},[46070,46085,46100],{"data":46071,"content":46072,"nodeType":1586},{},[46073],{"data":46074,"content":46075,"nodeType":876},{},[46076,46081],{"data":46077,"marks":46078,"value":46080,"nodeType":867},{},[46079],{"type":865},"Stolen session cookies",{"data":46082,"marks":46083,"value":46084,"nodeType":867},{},[]," simply need to be imported into an attacker’s browser to resume an active session on an app. That means access can be gained without needing to enter a username and password, or pass any MFA checks. ",{"data":46086,"content":46087,"nodeType":1586},{},[46088],{"data":46089,"content":46090,"nodeType":876},{},[46091,46096],{"data":46092,"marks":46093,"value":46095,"nodeType":867},{},[46094],{"type":865},"Stolen usernames, passwords",{"data":46097,"marks":46098,"value":46099,"nodeType":867},{},[],", and login page URLs can be used to access any accounts that lack MFA. ",{"data":46101,"content":46102,"nodeType":1586},{},[46103],{"data":46104,"content":46105,"nodeType":876},{},[46106,46111],{"data":46107,"marks":46108,"value":46110,"nodeType":867},{},[46109],{"type":865},"Stolen autofill data",{"data":46112,"marks":46113,"value":46114,"nodeType":867},{},[]," can be used to gather other valuable information that could be useful for impersonating the victim when speaking to social engineering IT support staff, for example to reset or remove MFA.",{"data":46116,"content":46117,"nodeType":876},{},[46118],{"data":46119,"marks":46120,"value":46121,"nodeType":867},{},[],"Naturally, stolen session cookies are the most valuable prize, but they are often valid for only a limited time before the user must re-authenticate, and active sessions can often be terminated by security admins. Unfortunately, it’s not that uncommon for sessions to last for up to a month, or even sometimes indefinitely.",{"data":46123,"content":46124,"nodeType":876},{},[46125],{"data":46126,"marks":46127,"value":46128,"nodeType":867},{},[],"Stolen usernames and passwords are a different story. As the Snowflake breaches demonstrate, passwords can remain valid for years after a breach, particularly in the world of SaaS apps where mandatory password rotation is not as common as for a user’s primary domain account.",{"data":46130,"content":46131,"nodeType":876},{},[46132,46136,46143],{"data":46133,"marks":46134,"value":46135,"nodeType":867},{},[],"There’s also the problem of ",{"data":46137,"content":46138,"nodeType":915},{"uri":2924},[46139],{"data":46140,"marks":46141,"value":2929,"nodeType":867},{},[46142],{"type":913},{"data":46144,"marks":46145,"value":46146,"nodeType":867},{},[]," – where a local login with a username and password (and probably lacking MFA) can exist alongside other, more secure login methods such as SSO. Given the fact that many apps are self-adopted by users, these accounts continue to exist even when an app is subsequently added to SSO via the chosen IdP, meaning they can fly under the radar of security teams. ",{"data":46148,"content":46149,"nodeType":942},{},[],{"data":46151,"content":46152,"nodeType":868},{},[46153],{"data":46154,"marks":46155,"value":46156,"nodeType":867},{},[],"Should you be concerned about infostealers?",{"data":46158,"content":46159,"nodeType":876},{},[46160],{"data":46161,"marks":46162,"value":46163,"nodeType":867},{},[],"It’s commonly thought that infostealers are primarily a concern for unmanaged devices that lack security controls common to corporate IT, such as EDR. But there’s a couple of reasons why corporate users are also at risk:",{"data":46165,"content":46166,"nodeType":1058},{},[46167],{"data":46168,"marks":46169,"value":46170,"nodeType":867},{},[],"EDR can be bypassed",{"data":46172,"content":46173,"nodeType":876},{},[46174,46177,46184],{"data":46175,"marks":46176,"value":41451,"nodeType":867},{},[],{"data":46178,"content":46179,"nodeType":915},{"uri":41454},[46180],{"data":46181,"marks":46182,"value":41460,"nodeType":867},{},[46183],{"type":913},{"data":46185,"marks":46186,"value":1679,"nodeType":867},{},[],{"data":46188,"content":46189,"nodeType":876},{},[46190],{"data":46191,"marks":46192,"value":46193,"nodeType":867},{},[],"Getting total coverage across your endpoint estate is notoriously difficult, if not totally unrealistic. Unless the malware is stopped on execution, then data will inevitably be stolen, and will continue to be taken until stopped (or it self-terminates). And once an attacker has stolen employee credentials or sessions, the credential stuffing and session hijacking attacks that come next won’t touch the endpoint. For those reasons, you can’t rely on EDR as a single line of defense against infostealers.",{"data":46195,"content":46196,"nodeType":1058},{},[46197],{"data":46198,"marks":46199,"value":46200,"nodeType":867},{},[],"Unmanaged devices such as BYOD or third-parties are vulnerable",{"data":46202,"content":46203,"nodeType":876},{},[46204],{"data":46205,"marks":46206,"value":46207,"nodeType":867},{},[],"Companies that support BYOD often have less secure configurations than those with fully managed devices. The same applies to third-party contractors, who often use their own devices to access company systems on a temporary basis. ",{"data":46209,"content":46210,"nodeType":876},{},[46211,46215,46224],{"data":46212,"marks":46213,"value":46214,"nodeType":867},{},[],"This issue was acutely felt in the Snowflake attacks: There is some suggestion that targeting key third-party suppliers – ",{"data":46216,"content":46218,"nodeType":915},{"uri":46217},"https://www.wired.com/story/epam-snowflake-ticketmaster-breach-shinyhunters/",[46219],{"data":46220,"marks":46221,"value":46223,"nodeType":867},{},[46222],{"type":913},"such as EPAM Systems, a software engineering firm and Snowflake ‘Elite Tier Partner’",{"data":46225,"marks":46226,"value":46227,"nodeType":867},{},[]," – yielded some of the access needed. It’s unclear what came first, but it’s possible (likely, even) that EPAM was identified as a target specifically because of its lucrative customer base – third-parties are a known weak point for red teamers, so it would be foolish to assume that attackers don’t also think this way. It’s possible too that EPAM were specifically targeted because of their Snowflake chops – adding another indicator that Snowflake was potentially a premeditated attack inspired by the availability of Snowflake credentials online. ",{"data":46229,"content":46230,"nodeType":1058},{},[46231],{"data":46232,"marks":46233,"value":46234,"nodeType":867},{},[],"Browser profiles can be synced across devices, increasing the blast radius",{"data":46236,"content":46237,"nodeType":876},{},[46238],{"data":46239,"marks":46240,"value":46241,"nodeType":867},{},[],"It’s not uncommon for employees to access their personal email accounts from company devices. When accessing any browser, you are typically prompted to sign in with your account credentials (e.g. your Google account). If a user signs into a browser on a company device with a personal account, you’re usually prompted to sync your account across devices. This usually means that any saved passwords, search history, and settings are shared across devices. ",{"data":46243,"content":46244,"nodeType":876},{},[46245],{"data":46246,"marks":46247,"value":46248,"nodeType":867},{},[],"Naturally, this means that if a personal device is compromised where you’re also logged into the browser profile, then an infostealer will be able to harvest information saved into that profile across devices.",{"data":46250,"content":46251,"nodeType":876},{},[46252],{"data":46253,"marks":46254,"value":46255,"nodeType":867},{},[],"Even when using separate browser profiles for work and personal, it’s easy for the two to converge, or to slip into using the wrong profile. Accessing personal accounts (or at least synchronizing data across accounts) is usually a workplace policy violation, but it’s unfortunately all too common. ",{"data":46257,"content":46258,"nodeType":876},{},[46259,46263,46272],{"data":46260,"marks":46261,"value":46262,"nodeType":867},{},[],"Previous vulnerabilities have exacerbated this problem, such as ",{"data":46264,"content":46266,"nodeType":915},{"uri":46265},"https://thehackernews.com/2024/01/malware-using-google-multilogin-exploit.html",[46267],{"data":46268,"marks":46269,"value":46271,"nodeType":867},{},[46270],{"type":913},"an exploit affecting Google MultiLogin to maintain access to synced accounts even after a password reset",{"data":46273,"marks":46274,"value":5704,"nodeType":867},{},[],{"data":46276,"content":46277,"nodeType":1058},{},[46278],{"data":46279,"marks":46280,"value":46281,"nodeType":867},{},[],"Are infostealers a bigger problem than credential phishing? ",{"data":46283,"content":46284,"nodeType":876},{},[46285],{"data":46286,"marks":46287,"value":46288,"nodeType":867},{},[],"The short answer is: No. The longer answer is: They are both part of the bigger problem of identity attacks, and attackers can wield both approaches simultaneously. ",{"data":46290,"content":46291,"nodeType":876},{},[46292],{"data":46293,"marks":46294,"value":46295,"nodeType":867},{},[],"While they are delivered to victims in similar ways to phishing links, most organizations are arguably better protected against infostealers than modern phishing attacks because endpoint security controls provide another layer of protection, in theory – whereas modern phishing attacks don’t necessarily involve the delivery of malware that executes on the device. ",{"data":46297,"content":46298,"nodeType":876},{},[46299],{"data":46300,"marks":46301,"value":46302,"nodeType":867},{},[],"Infostealers arguably provide more bang for the attacker’s buck, grabbing a stack of credentials and useful data in one go. In contrast, phishing is usually much more targeted, and involves the compromise of a narrower set of credentials – typically focusing on a particular site or app. ",{"data":46304,"content":46305,"nodeType":876},{},[46306,46310,46317,46321,46328],{"data":46307,"marks":46308,"value":46309,"nodeType":867},{},[],"It’s worth focusing on the TTP, not the particular tool being used: The attacker technique here is ",{"data":46311,"content":46312,"nodeType":915},{"uri":42165},[46313],{"data":46314,"marks":46315,"value":42171,"nodeType":867},{},[46316],{"type":913},{"data":46318,"marks":46319,"value":46320,"nodeType":867},{},[],", and subsequently session hijacking by importing the cookie into the attacker’s browser. Both infostealers and ",{"data":46322,"content":46323,"nodeType":915},{"uri":38018},[46324],{"data":46325,"marks":46326,"value":46327,"nodeType":867},{},[],"modern phishing attacks",{"data":46329,"marks":46330,"value":46331,"nodeType":867},{},[]," involve the theft of session tokens, and so are valid means to achieve this end. In fact, there’s nothing to stop threat groups from employing both simultaneously.",{"data":46333,"content":46337,"nodeType":985},{"target":46334},{"sys":46335},{"id":46336,"type":982,"linkType":983},"7fil6aaQDFfJGYUnQ14k10",[],{"data":46339,"content":46340,"nodeType":942},{},[],{"data":46342,"content":46343,"nodeType":868},{},[46344],{"data":46345,"marks":46346,"value":46347,"nodeType":867},{},[],"Infostealers in action",{"data":46349,"content":46350,"nodeType":876},{},[46351],{"data":46352,"marks":46353,"value":46354,"nodeType":867},{},[],"Check out the video demo below to see the attack chain in action from the point of an infostealer compromise, showing session cookie theft, reimporting the cookies into the attacker's browser, and evading policy-based controls in M365. It also shows the targeting of downstream apps that are usually accessed via SSO in the context of both a Microsoft Entra and Okta compromise.",{"data":46356,"content":46360,"nodeType":985},{"target":46357},{"sys":46358},{"id":46359,"type":982,"linkType":983},"4J7LqqjQX2W52AbmcVmjUt",[],{"data":46362,"content":46363,"nodeType":868},{},[46364],{"data":46365,"marks":46366,"value":46367,"nodeType":867},{},[],"What can organizations do about the infostealer threat? ",{"data":46369,"content":46370,"nodeType":876},{},[46371],{"data":46372,"marks":46373,"value":46374,"nodeType":867},{},[],"Security teams should have two main concerns:",{"data":46376,"content":46377,"nodeType":1629},{},[46378,46388],{"data":46379,"content":46380,"nodeType":1586},{},[46381],{"data":46382,"content":46383,"nodeType":876},{},[46384],{"data":46385,"marks":46386,"value":46387,"nodeType":867},{},[],"Data that is already out there from historical data dumps, but is still valid. ",{"data":46389,"content":46390,"nodeType":1586},{},[46391],{"data":46392,"content":46393,"nodeType":876},{},[46394],{"data":46395,"marks":46396,"value":46397,"nodeType":867},{},[],"Data in private channels that attackers could use in the future, that you are blind to. ",{"data":46399,"content":46400,"nodeType":876},{},[46401],{"data":46402,"marks":46403,"value":46404,"nodeType":867},{},[],"As always, the root-cause of the problem is a lack of meaningful visibility of what apps your employees are using (including those outside your IdP) and whether the associated identities are configured securely. ",{"data":46406,"content":46407,"nodeType":876},{},[46408],{"data":46409,"marks":46410,"value":46411,"nodeType":867},{},[],"A layered, defense-in-depth approach is required to resolve the issue, by:",{"data":46413,"content":46414,"nodeType":1629},{},[46415,46425,46435,46445],{"data":46416,"content":46417,"nodeType":1586},{},[46418],{"data":46419,"content":46420,"nodeType":876},{},[46421],{"data":46422,"marks":46423,"value":46424,"nodeType":867},{},[],"Deploying MFA across all your identities and apps, including any local logins that can’t be put behind SSO. ",{"data":46426,"content":46427,"nodeType":1586},{},[46428],{"data":46429,"content":46430,"nodeType":876},{},[46431],{"data":46432,"marks":46433,"value":46434,"nodeType":867},{},[],"Configuring time-limited session lifetimes for all apps to ensure that any stolen session tokens can only be used temporarily. ",{"data":46436,"content":46437,"nodeType":1586},{},[46438],{"data":46439,"content":46440,"nodeType":876},{},[46441],{"data":46442,"marks":46443,"value":46444,"nodeType":867},{},[],"Ensuring that employees don’t access or synchronize personal accounts on their work devices, as well as limiting non-work activities on their work device as much as possible.",{"data":46446,"content":46447,"nodeType":1586},{},[46448],{"data":46449,"content":46450,"nodeType":876},{},[46451],{"data":46452,"marks":46453,"value":46454,"nodeType":867},{},[],"Implementing a robust EDR/MDR solution to detect and respond to malware compromises on user devices. ",{"data":46456,"content":46457,"nodeType":876},{},[46458,46462,46467],{"data":46459,"marks":46460,"value":46461,"nodeType":867},{},[],"Organizations also have the option of investing in a commercial TI feed to detect and report data breaches affecting employees. But in our experience, these feeds contain ",{"data":46463,"marks":46464,"value":46466,"nodeType":867},{},[46465],{"type":865},"a lot ",{"data":46468,"marks":46469,"value":46470,"nodeType":867},{},[],"of false positives – so unless you have password visibility for employee accounts across apps, it’s going to waste a chunk of valuable time for you and your employees.",{"data":46472,"content":46473,"nodeType":876},{},[46474,46478,46486],{"data":46475,"marks":46476,"value":46477,"nodeType":867},{},[],"It would be remiss of us not to mention our recently released ",{"data":46479,"content":46480,"nodeType":915},{"uri":40060},[46481],{"data":46482,"marks":46483,"value":46485,"nodeType":867},{},[46484],{"type":913},"session token theft detection feature",{"data":46487,"marks":46488,"value":46489,"nodeType":867},{},[]," that identifies session token theft by adding telemetry to the user agent string – using the power of our browser agent to create a new high-fidelity signal for security teams. It can also be applied more generally to detect any session taking place in an unmanaged browser – so you can use it to spot unauthorized access to company apps in general, too.  ",{"data":46491,"content":46495,"nodeType":985},{"target":46492},{"sys":46493},{"id":46494,"type":982,"linkType":983},"3XgpqEGzZSD2J0uvnCg5D8",[],{"data":46497,"content":46498,"nodeType":1058},{},[46499],{"data":46500,"marks":46501,"value":46502,"nodeType":867},{},[],"What’s next for infostealers?",{"data":46504,"content":46505,"nodeType":876},{},[46506],{"data":46507,"marks":46508,"value":46509,"nodeType":867},{},[],"All the signs point to the fact that infostealers will continue being a useful tool in the attacker’s arsenal. The Snowflake attacks in particular are both a warning for defenders and encouragement for attackers. It's also a good reminder that while infostealers were once used to harvest things like VPN creds to pivot to the internal network, they're now largely used to target third-party services over the internet. ",{"data":46511,"content":46512,"nodeType":876},{},[46513],{"data":46514,"marks":46515,"value":46516,"nodeType":867},{},[],"To evade EDR, it’s likely that we’ll see a growing number of families and variants used by individual groups, or better ‘enterprise’ capabilities from malware-as-a-service vendors. ",{"data":46518,"content":46519,"nodeType":876},{},[46520,46524,46533,46537,46545],{"data":46521,"marks":46522,"value":46523,"nodeType":867},{},[],"One notable quirk is that, to date, infostealers have not really branched out from targeting browsers. Take the example of password manager apps – you would think this would be an obvious target, right? But, they’re not usually targeted (",{"data":46525,"content":46527,"nodeType":915},{"uri":46526},"https://securitysenses.com/posts/malware-targeting-password-managers",[46528],{"data":46529,"marks":46530,"value":46532,"nodeType":867},{},[46531],{"type":913},"with some exceptions",{"data":46534,"marks":46535,"value":46536,"nodeType":867},{},[],"). And when they do, ",{"data":46538,"content":46539,"nodeType":915},{"uri":46526},[46540],{"data":46541,"marks":46542,"value":46544,"nodeType":867},{},[46543],{"type":913},"they work by eavesdropping on the password manager’s browser extension in action",{"data":46546,"marks":46547,"value":46548,"nodeType":867},{},[]," – meaning they are intercepted one-at-a-time as the user uses them, rather than targeting the password manager directly and exporting the saved passwords all at once. It will be interesting to see whether these capabilities are added in the future. ",{"data":46550,"content":46551,"nodeType":876},{},[46552,46556,46565,46568,46577,46581,46590],{"data":46553,"marks":46554,"value":46555,"nodeType":867},{},[],"On the other hand, there are defensive security developments that could reduce the ability of attackers to leverage things like stolen session tokens, such as ",{"data":46557,"content":46559,"nodeType":915},{"uri":46558},"https://learn.microsoft.com/en-us/entra/identity/conditional-access/concept-token-protection",[46560],{"data":46561,"marks":46562,"value":46564,"nodeType":867},{},[46563],{"type":913},"Microsoft’s token binding feature in Entra",{"data":46566,"marks":46567,"value":14715,"nodeType":867},{},[],{"data":46569,"content":46571,"nodeType":915},{"uri":46570},"https://blog.chromium.org/2024/04/fighting-cookie-theft-using-device.html",[46572],{"data":46573,"marks":46574,"value":46576,"nodeType":867},{},[46575],{"type":913},"Google’s device bound session cookies",{"data":46578,"marks":46579,"value":46580,"nodeType":867},{},[],". Google also released an ",{"data":46582,"content":46584,"nodeType":915},{"uri":46583},"https://security.googleblog.com/2024/07/improving-security-of-chrome-cookies-on.html?m=1",[46585],{"data":46586,"marks":46587,"value":46589,"nodeType":867},{},[46588],{"type":913},"app-bound encryption feature",{"data":46591,"marks":46592,"value":46593,"nodeType":867},{},[],", which adds additional protection against infostealers attempting to steal browser data in Chrome if the underlying Windows device is compromised. ",{"data":46595,"content":46596,"nodeType":876},{},[46597],{"data":46598,"marks":46599,"value":46600,"nodeType":867},{},[],"That said, mature versions of these controls are still years away, and while session cookie theft is a key risk of infostealers, it’s not the only risk – so alternative controls and mitigations remain valuable to security teams in the present. ",{"data":46602,"content":46606,"nodeType":985},{"target":46603},{"sys":46604},{"id":46605,"type":982,"linkType":983},"5loTnpvwGD3kaKMXBp23hZ",[],{"data":46608,"content":46609,"nodeType":876},{},[46610],{"data":46611,"marks":46612,"value":21,"nodeType":867},{},[],{"entries":46614},{"hyperlink":46615,"inline":46616,"block":46617},[],[],[46618,46621,46628,46631],{"sys":46619,"__typename":1697,"type":1698,"ctaText":46620,"buttonLabel":33795,"buttonColour":24251,"buttonUrl":38018},{"id":46336},"Learn more about modern AitM and BitM phishing toolkits",{"sys":46622,"__typename":46623,"title":46624,"youTubeUrl":46625,"imagePlaceholder":46626},{"id":46359},"ExternalVideo","Session hijacking using stolen session cookies","https://www.youtube.com/watch?v=RlSweA5UfYw",{"url":46627,"width":43776,"height":43777},"https://images.ctfassets.net/y1cdw1ablpvd/4ONwBrDgXX7NdfkMoIVu8v/775f0c1646e90220b2df9fe17ec30690/Slide_16_9_-_44__2_.png",{"sys":46629,"__typename":1697,"type":1698,"ctaText":46630,"buttonLabel":33795,"buttonColour":1701,"buttonUrl":40060},{"id":46494},"Learn more about how we use browser telemetry to detect and stop session token theft",{"sys":46632,"__typename":1697,"type":1698,"ctaText":46633,"buttonLabel":46634,"buttonColour":1701,"buttonUrl":46635},{"id":46605},"Check out our on-demand webinar for everything you need to know about infostealers and session hijacking","Watch on-demand","https://pushsecurity.com/resources/video/infostealers-webinar-ondemand/",{"items":46637},[],{},"How infostealers fuel breaches with stolen creds and cookies","2024-07-31T00:00:00.000Z",{"items":46642},[46643,47224,47661],{"__typename":1772,"sys":46644,"content":46646,"title":47210,"synopsis":47211,"hashTags":59,"publishedDate":47212,"slug":47213,"tagsCollection":47214,"authorsCollection":47220},{"id":46645},"11C3shj5SlkS8sAd3AlYDp",{"json":46647},{"data":46648,"content":46649,"nodeType":1680},{},[46650,46669,46688,46695,46701,46708,46715,46722,46729,46738,46757,46764,46771,46778,46784,46791,46823,46830,46837,46844,46851,46857,46864,46871,46878,46909,46915,46922,46929,46960,46966,46973,46980,46987,46994,47000,47006,47013,47020,47027,47033,47040,47047,47054,47061,47080,47096,47102,47109,47116,47122,47129,47148,47154,47161,47188,47195,47202],{"data":46651,"content":46652,"nodeType":876},{},[46653,46657,46665],{"data":46654,"marks":46655,"value":46656,"nodeType":867},{},[],"It’s been well reported that ",{"data":46658,"content":46659,"nodeType":915},{"uri":37788},[46660],{"data":46661,"marks":46662,"value":46664,"nodeType":867},{},[46663],{"type":913},"identity attacks are on the rise",{"data":46666,"marks":46667,"value":46668,"nodeType":867},{},[],", and constantly evolving phishing tools and techniques are a big part of this. In particular, the increasing prevalence of MFA has led to AitM phishing attacks becoming much more common. The threat intelligence industry naturally wants to locate and shutdown all the phishing servers – but the phishers are fighting back.",{"data":46670,"content":46671,"nodeType":876},{},[46672,46676,46684],{"data":46673,"marks":46674,"value":46675,"nodeType":867},{},[],"Before we dive into how AitM phishing kits evade detection, you should check out our earlier blog post on ‘",{"data":46677,"content":46678,"nodeType":915},{"uri":38018},[46679],{"data":46680,"marks":46681,"value":46683,"nodeType":867},{},[46682],{"type":913},"Phishing 2.0 – how phishing toolkits are evolving with AitM",{"data":46685,"marks":46686,"value":46687,"nodeType":867},{},[],"’ if you want to get up to speed with what these toolkits are, and why attackers are using them more regularly. ",{"data":46689,"content":46690,"nodeType":876},{},[46691],{"data":46692,"marks":46693,"value":46694,"nodeType":867},{},[],"In this blog post, we’re going to look at a recent instance of the NakedPages AitM phishing toolkit and some of the steps it takes to frustrate detection and analysis. In particular, we’ll look at how malicious activity is obfuscated through the use of legitimate SaaS services. NakedPages uses a range of different techniques and so serves as a good case study as to how AitM toolkits are being designed to evade detection.",{"data":46696,"content":46700,"nodeType":985},{"target":46697},{"sys":46698},{"id":46699,"type":982,"linkType":983},"2Qcn2nNRXVkdqqxGO8lDZf",[],{"data":46702,"content":46703,"nodeType":876},{},[46704],{"data":46705,"marks":46706,"value":46707,"nodeType":867},{},[],"Before we dive in, it’s useful to keep in mind that while there is a lot of complication here, most of this happens in seconds and is transparent to the intended victim accessing from a real browser.",{"data":46709,"content":46710,"nodeType":868},{},[46711],{"data":46712,"marks":46713,"value":46714,"nodeType":867},{},[],"Step 1: Cloudflare Workers for the initial gateway",{"data":46716,"content":46717,"nodeType":876},{},[46718],{"data":46719,"marks":46720,"value":46721,"nodeType":867},{},[],"A key feature of the NakedPages kit is that it has several stages and redirections and, in order for it to operate as intended, the target has to arrive at the beginning. The first step involves visiting a URL that is simply a Cloudflare Worker. Cloudflare Workers are a serverless execution environment, a bit like AWS lambdas.",{"data":46723,"content":46724,"nodeType":876},{},[46725],{"data":46726,"marks":46727,"value":46728,"nodeType":867},{},[],"The benefit to the attacker is that this gives them a highly reputable primary domain as it is one owned and operated by Cloudflare. Flagging recently registered or uncategorized/rare domains for further analysis won’t work for this. For example, the URL used in this instance was the following:",{"data":46730,"content":46731,"nodeType":876},{},[46732],{"data":46733,"marks":46734,"value":46737,"nodeType":867},{},[46735],{"type":46736},"code","hxxps://226028cc.502f135e3e036e726fba22d4.workers.dev",{"data":46739,"content":46740,"nodeType":876},{},[46741,46745,46754],{"data":46742,"marks":46743,"value":46744,"nodeType":867},{},[],"For other examples of Cloudflare Workers being abused for phishing, ",{"data":46746,"content":46748,"nodeType":915},{"uri":46747},"https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/its-raining-phish-and-scams-how-cloudflare-pages-dev-and-workers-dev-domains-get-abused/",[46749],{"data":46750,"marks":46751,"value":46753,"nodeType":867},{},[46752],{"type":913},"check out this blog post from Trustwave",{"data":46755,"marks":46756,"value":1679,"nodeType":867},{},[],{"data":46758,"content":46759,"nodeType":868},{},[46760],{"data":46761,"marks":46762,"value":46763,"nodeType":867},{},[],"Step 2: Cloudflare Turnstile for bot detection",{"data":46765,"content":46766,"nodeType":876},{},[46767],{"data":46768,"marks":46769,"value":46770,"nodeType":867},{},[],"The only purpose of the Cloudflare Worker is to act as a bot gateway to prevent automated analysis getting further than this point. For this it uses Cloudflare Turnstile. Turnstile is a highly effective tool for detecting the difference between bots and human users as a replacement for CAPTCHAs used by websites across the world. ",{"data":46772,"content":46773,"nodeType":876},{},[46774],{"data":46775,"marks":46776,"value":46777,"nodeType":867},{},[],"If it doesn’t work transparently then you’ll probably see something like this:",{"data":46779,"content":46783,"nodeType":985},{"target":46780},{"sys":46781},{"id":46782,"type":982,"linkType":983},"4XNxLbiZf3xUK1WeFDjjxl",[],{"data":46785,"content":46786,"nodeType":876},{},[46787],{"data":46788,"marks":46789,"value":46790,"nodeType":867},{},[],"However, who else wants to keep out the bots? Well, phishers of course! There are many sandbox environments and other automated platforms out there, visiting every URL they come across in the search for malicious behavior. This stops many of them in their tracks as they never get past the Turnstile check. ",{"data":46792,"content":46793,"nodeType":876},{},[46794,46798,46807,46811,46820],{"data":46795,"marks":46796,"value":46797,"nodeType":867},{},[],"Malicious use of Turnstile use has become much more common now. Examples include other criminal kits ",{"data":46799,"content":46801,"nodeType":915},{"uri":46800},"https://blog.sekoia.io/tycoon-2fa-an-in-depth-analysis-of-the-latest-version-of-the-aitm-phishing-kit/",[46802],{"data":46803,"marks":46804,"value":46806,"nodeType":867},{},[46805],{"type":913},"such as Tycoon",{"data":46808,"marks":46809,"value":46810,"nodeType":867},{},[],", as well as ",{"data":46812,"content":46814,"nodeType":915},{"uri":46813},"https://fin3ss3g0d.net/index.php/2024/04/08/evilgophishs-approach-to-advanced-bot-detection-with-cloudflare-turnstile/",[46815],{"data":46816,"marks":46817,"value":46819,"nodeType":867},{},[46818],{"type":913},"open-source phishing tools focused on red teaming",{"data":46821,"marks":46822,"value":2933,"nodeType":867},{},[],{"data":46824,"content":46825,"nodeType":868},{},[46826],{"data":46827,"marks":46828,"value":46829,"nodeType":867},{},[],"Step 3: Required URL parameters and custom auth headers",{"data":46831,"content":46832,"nodeType":876},{},[46833],{"data":46834,"marks":46835,"value":46836,"nodeType":867},{},[],"If you get past Turnstile, then you’ll finally be redirected to a more conventionally suspicious domain. However, you’ll need to supply the correct URL parameters and headers, or that request might behave differently. ",{"data":46838,"content":46839,"nodeType":876},{},[46840],{"data":46841,"marks":46842,"value":46843,"nodeType":867},{},[],"Suspicious domains can be found and interrogated through other means, such as observing new domain registrations or certificate transparency logs. In this case, the phishers add other steps involving required URL parameters and custom headers. This means that a defender who knows the domain name can’t discover the malicious behavior just by making a simple HTTP(S) request to the domain.",{"data":46845,"content":46846,"nodeType":876},{},[46847],{"data":46848,"marks":46849,"value":46850,"nodeType":867},{},[],"The following code snippet shows how this operates. Bonus points for spotting how they actually forgot to implement their own RSA encryption function and instead send their “encrypted” user agents in clear text:",{"data":46852,"content":46856,"nodeType":985},{"target":46853},{"sys":46854},{"id":46855,"type":982,"linkType":983},"45aif31bot9phquQPkz20p",[],{"data":46858,"content":46859,"nodeType":868},{},[46860],{"data":46861,"marks":46862,"value":46863,"nodeType":867},{},[],"Step 4: Requiring JavaScript execution",{"data":46865,"content":46866,"nodeType":876},{},[46867],{"data":46868,"marks":46869,"value":46870,"nodeType":867},{},[],"Another aspect of the previous step is that it requires JavaScript to execute. That means defensive techniques that simply make HTTP(S) requests and scrape content will not automatically be able to follow the link without allowing JavaScript execution. This forces the use of dynamic sandbox techniques that actually load a DOM, as it’s almost impossible for static analysis to generically solve this problem.",{"data":46872,"content":46873,"nodeType":868},{},[46874],{"data":46875,"marks":46876,"value":46877,"nodeType":867},{},[],"Step 5: Redirecting to legitimate domains",{"data":46879,"content":46880,"nodeType":876},{},[46881,46885,46893,46897,46906],{"data":46882,"marks":46883,"value":46884,"nodeType":867},{},[],"Attackers will also redirect to legitimate domains to mask their activity. Let’s say a defender has visited the attacker’s malicious domain without executing JavaScript or supplying the correct URL parameters. The attacker doesn’t want to activate their malicious phishing behavior at this point, so they need to do something benign instead. In this case, they simply redirect to ",{"data":46886,"content":46888,"nodeType":915},{"uri":46887},"https://example.com",[46889],{"data":46890,"marks":46891,"value":46887,"nodeType":867},{},[46892],{"type":913},{"data":46894,"marks":46895,"value":46896,"nodeType":867},{},[],". Interestingly, ",{"data":46898,"content":46900,"nodeType":915},{"uri":46899},"https://www.youtube.com/watch?v=-W-LxcbUxI4&t=643s",[46901],{"data":46902,"marks":46903,"value":46905,"nodeType":867},{},[46904],{"type":913},"EvilProxy has also been seen redirecting to example.com too",{"data":46907,"marks":46908,"value":40619,"nodeType":867},{},[],{"data":46910,"content":46914,"nodeType":985},{"target":46911},{"sys":46912},{"id":46913,"type":982,"linkType":983},"450Y7W1uXVkKSps5y0xhBe",[],{"data":46916,"content":46917,"nodeType":868},{},[46918],{"data":46919,"marks":46920,"value":46921,"nodeType":867},{},[],"Step 6: HTTP referer header masking",{"data":46923,"content":46924,"nodeType":876},{},[46925],{"data":46926,"marks":46927,"value":46928,"nodeType":867},{},[],"Maintainers of legitimate websites often look at the HTTP referer header to see where they are being linked from. This is often a critical task for businesses, particularly for things like marketing. However, what if employees spot strange redirects coming in from suspicious looking domains like the ones used by this phishing kit? Perhaps they might investigate those domains and/or tip off relevant security vendors and organizations. ",{"data":46930,"content":46931,"nodeType":876},{},[46932,46936,46944,46948,46956],{"data":46933,"marks":46934,"value":46935,"nodeType":867},{},[],"Unless, of course, you were to use a service to mask the HTTP referrer – which is exactly what the phishing kit does in this case. NakedPages makes use of ",{"data":46937,"content":46939,"nodeType":915},{"uri":46938},"https://href.li/",[46940],{"data":46941,"marks":46942,"value":46938,"nodeType":867},{},[46943],{"type":913},{"data":46945,"marks":46946,"value":46947,"nodeType":867},{},[]," as a service to strip the referral to ensure the redirection is performed anonymously. Rather conveniently, it seems the default example that ",{"data":46949,"content":46951,"nodeType":915},{"uri":46950},"https://href.li",[46952],{"data":46953,"marks":46954,"value":46950,"nodeType":867},{},[46955],{"type":913},{"data":46957,"marks":46958,"value":46959,"nodeType":867},{},[]," uses is… example.com:",{"data":46961,"content":46965,"nodeType":985},{"target":46962},{"sys":46963},{"id":46964,"type":982,"linkType":983},"78xFQwTG1r0YWGJ24iEdYP",[],{"data":46967,"content":46968,"nodeType":868},{},[46969],{"data":46970,"marks":46971,"value":46972,"nodeType":867},{},[],"Step 7: Loading balanced domains",{"data":46974,"content":46975,"nodeType":876},{},[46976],{"data":46977,"marks":46978,"value":46979,"nodeType":867},{},[],"You’re probably thinking: Step 7? Surely, if a victim’s browser has finally made it this far then the attackers would just serve up the malicious phishing content at this point, right? Well, we aren’t quite done yet. These initial gateway servers are one of the most important components to keep undetected, as existing phishing campaigns and (as yet unread) emails will be leading to them.",{"data":46981,"content":46982,"nodeType":876},{},[46983],{"data":46984,"marks":46985,"value":46986,"nodeType":867},{},[],"Once we get to the more obviously malicious phishing activity, there is a higher chance of detection and user reports. In this case the phishing kit actually retrieves a new URL to redirect to, along with a suitable JWT authentication parameter. The benefit of this is that when URLs/hostnames get flagged as malicious, blocked or otherwise taken down, the phishing kit can just redirect to other hostnames, and the attacker’s can keep updating with new URLs over time. ",{"data":46988,"content":46989,"nodeType":876},{},[46990],{"data":46991,"marks":46992,"value":46993,"nodeType":867},{},[],"Below we can see an example of the response containing a URL, with a JWT auth parameter:",{"data":46995,"content":46999,"nodeType":985},{"target":46996},{"sys":46997},{"id":46998,"type":982,"linkType":983},"4NpH7V5oEdTASNNJsqCJ47",[],{"data":47001,"content":47005,"nodeType":985},{"target":47002},{"sys":47003},{"id":47004,"type":982,"linkType":983},"7oqkrhNXtyOlJMEz0BZyLo",[],{"data":47007,"content":47008,"nodeType":876},{},[47009],{"data":47010,"marks":47011,"value":47012,"nodeType":867},{},[],"Automating this request in this example brings back around 20 different primary domains used for the final phishing attack. These domains are rotated over time as some are blocked and new ones are created.",{"data":47014,"content":47015,"nodeType":868},{},[47016],{"data":47017,"marks":47018,"value":47019,"nodeType":867},{},[],"Step 8: Breaking login page signatures",{"data":47021,"content":47022,"nodeType":876},{},[47023],{"data":47024,"marks":47025,"value":47026,"nodeType":867},{},[],"If all the previous checks have passed then a victim user is finally presented with a phishing page. The attacker has most closely emulated the sign-on page for live.com for Outlook in this case, though it also has some aspects from a business Microsoft login too, as we can see in the examples below:",{"data":47028,"content":47032,"nodeType":985},{"target":47029},{"sys":47030},{"id":47031,"type":982,"linkType":983},"2Ez0fgAlmkrisdQGWfL6CV",[],{"data":47034,"content":47035,"nodeType":876},{},[47036],{"data":47037,"marks":47038,"value":47039,"nodeType":867},{},[],"However, one obvious change can be seen in the HTML title in the tab header. This normally says something like “Sign in to Outlook” or “Sign in to your account”. In this case, the phishing kit has randomized the HTML title. \n\nOne super easy way to detect websites pretending to be common login pages that have 1:1 cloned the website or are performing full reverse proxy AiTM techniques would be to search for obvious HTML content like this. Not many legitimate websites should have an HTML title of “Sign in to Outlook” other than Microsoft’s own legitimate domains for it, right?",{"data":47041,"content":47042,"nodeType":876},{},[47043],{"data":47044,"marks":47045,"value":47046,"nodeType":867},{},[],"Taking a closer look, we’ll see that the HTML, DOM and JavaScript etc. differ quite significantly from the true login pages, even if the visual appearance is very similar. One reason for this is to make it harder for defenders to simply signature on specific aspects of commonly spoofed login pages.",{"data":47048,"content":47049,"nodeType":868},{},[47050],{"data":47051,"marks":47052,"value":47053,"nodeType":867},{},[],"Step 9: B2B targeting",{"data":47055,"content":47056,"nodeType":876},{},[47057],{"data":47058,"marks":47059,"value":47060,"nodeType":867},{},[],"The final interesting aspect of this particular example is that it modifies its behavior during the login process depending on whether a personal Microsoft account or an organization account is used.",{"data":47062,"content":47063,"nodeType":876},{},[47064,47068,47076],{"data":47065,"marks":47066,"value":47067,"nodeType":867},{},[],"When entering an email address associated with a personal Microsoft account, or picking ‘personal account’ when prompted after entering an email address that is used for both purposes, the server will return a 302 redirect and send the user to ",{"data":47069,"content":47071,"nodeType":915},{"uri":47070},"https://login.live.com/",[47072],{"data":47073,"marks":47074,"value":47070,"nodeType":867},{},[47075],{"type":913},{"data":47077,"marks":47078,"value":47079,"nodeType":867},{},[]," where they can then re-enter their credentials and login to Microsoft legitimately if they continue. This reduces the potential for detection further as no AitM phishing login will actually occur.",{"data":47081,"content":47082,"nodeType":876},{},[47083,47087,47092],{"data":47084,"marks":47085,"value":47086,"nodeType":867},{},[],"On the other hand, when using an organization account the phishing process continues as expected. ",{"data":47088,"marks":47089,"value":47091,"nodeType":867},{},[47090],{"type":865},"This phishing campaign is exclusively targeting corp accounts",{"data":47093,"marks":47094,"value":47095,"nodeType":867},{},[]," and you could almost say it has a B2B (or is that A2B?) rather than B2C business model.  ",{"data":47097,"content":47098,"nodeType":868},{},[47099],{"data":47100,"marks":47101,"value":23563,"nodeType":867},{},[],{"data":47103,"content":47104,"nodeType":876},{},[47105],{"data":47106,"marks":47107,"value":47108,"nodeType":867},{},[],"As you may have guessed from the extremely suspicious domains in use and examples of sloppy coding (like forgetting to implement an encryption function) the NakedPages kit is far from sophisticated. Despite this, the tricks that attackers are using to make detection and analysis more difficult seem to be quite effective when used in a layered model. ",{"data":47110,"content":47111,"nodeType":876},{},[47112],{"data":47113,"marks":47114,"value":47115,"nodeType":867},{},[],"For example, at the time of writing this particular Worker had been up for at least two days and was currently only triggering 1 detection on VirusTotal. ",{"data":47117,"content":47121,"nodeType":985},{"target":47118},{"sys":47119},{"id":47120,"type":982,"linkType":983},"1mIOpDtmgcMasK6dEhRHsm",[],{"data":47123,"content":47124,"nodeType":876},{},[47125],{"data":47126,"marks":47127,"value":47128,"nodeType":867},{},[],"One key takeaway is that it’s near impossible to stay on top of all the phishing servers on the internet. Even the untargeted mass campaigns will initially be missed by TI feeds, let alone the targeted ones. ",{"data":47130,"content":47131,"nodeType":876},{},[47132,47136,47144],{"data":47133,"marks":47134,"value":47135,"nodeType":867},{},[],"The best foot forward for resilience against these attacks is through the use of domain-bound MFA methods like WebAuthn. Common MFA methods like OTPs, SMS, push notifications etc. are routinely bypassed using ",{"data":47137,"content":47138,"nodeType":915},{"uri":38018},[47139],{"data":47140,"marks":47141,"value":47143,"nodeType":867},{},[47142],{"type":913},"AitM techniques that proxy the MFA authentication as well",{"data":47145,"marks":47146,"value":47147,"nodeType":867},{},[],". Even if you are one of the few who use phishing-resistant MFA methods like WebAuthn or other passkeys, the devil is in the detail and we’ve seen MFA downgrade attacks being used to bypass them by choosing a phishable method that’s also active.",{"data":47149,"content":47153,"nodeType":985},{"target":47150},{"sys":47151},{"id":47152,"type":982,"linkType":983},"17lSgRFD6fDzRUn9eOHJg6",[],{"data":47155,"content":47156,"nodeType":868},{},[47157],{"data":47158,"marks":47159,"value":47160,"nodeType":867},{},[],"P.S. How did we detect this?",{"data":47162,"content":47163,"nodeType":876},{},[47164,47168,47173,47177,47185],{"data":47165,"marks":47166,"value":47167,"nodeType":867},{},[],"After all that, you might be wondering how we managed to automate a process to generically pass through all these detection evasion techniques – ",{"data":47169,"marks":47170,"value":47172,"nodeType":867},{},[47171],{"type":865},"well the short answer is: We didn’t.",{"data":47174,"marks":47175,"value":47176,"nodeType":867},{},[]," Instead, we detected the act of an employee ",{"data":47178,"content":47179,"nodeType":915},{"uri":22796},[47180],{"data":47181,"marks":47182,"value":47184,"nodeType":867},{},[47183],{"type":913},"attempting to put their Microsoft password into a website that wasn’t Microsoft",{"data":47186,"marks":47187,"value":1679,"nodeType":867},{},[],{"data":47189,"content":47190,"nodeType":876},{},[47191],{"data":47192,"marks":47193,"value":47194,"nodeType":867},{},[],"The TTP for phishing is effectively “trick someone into putting their valid credentials into the wrong site” – so detecting that behavior directly (the action of entering a legit password into the wrong site) can be a lot simpler and more effective than playing the cat-and-mouse detection → detection-evasion game.",{"data":47196,"content":47197,"nodeType":876},{},[47198],{"data":47199,"marks":47200,"value":47201,"nodeType":867},{},[],"Having said that, if you’re interested, here are the domain IOCs for this campaign:",{"data":47203,"content":47204,"nodeType":876},{},[47205],{"data":47206,"marks":47207,"value":47209,"nodeType":867},{},[47208],{"type":46736},"226028cc[.]502f135e3e036e726fba22d4[.]workers[.]dev\nacevoorgukmembership[.]buzz\nalerteditorroyalsocietyorgnz[.]buzz\nandymarshallsgeniuslocidigestghostiomghostio[.]buzz\nblogresponseinsperitycom[.]buzz\ncampaigneventbritecomnoreply[.]buzz\ncharityexcellencer1technologytrustnewsorg[.]buzz\nclerkenwelldesignweekcomnoreply[.]buzz\nconfirminfothetrainlinecomauto[.]buzz\nhealthestatejournalcomnoreply[.]buzz\nmentalhealthdesignandbuildcomnoreply[.]buzz\nnoreplynotificationswhoopcom[.]buzz\nstepexhibitionscomeventsupport[.]buzz\ntheathletice1theathleticcom[.]buzz\nthekakahoonssubstackcom[.]buzz","How AitM phishing kits evade detection","Taking a closer look at the steps that AitM phishing kits take to hide from the prying eyes of security teams and threat intelligence vendors.","2024-07-23T00:00:00.000Z","how-aitm-phishing-kits-evade-detection",{"items":47215},[47216,47218],{"sys":47217,"name":342},{"id":3240},{"sys":47219,"name":4018},{"id":4017},{"items":47221},[47222],{"fullName":14739,"firstName":14740,"jobTitle":14741,"profilePicture":47223},{"url":14743},{"__typename":1772,"sys":47225,"content":47226,"title":44978,"synopsis":44979,"hashTags":59,"publishedDate":44980,"slug":44981,"tagsCollection":47651,"authorsCollection":47657},{"id":44487},{"json":47227},{"data":47228,"content":47229,"nodeType":1680},{},[47230,47235,47241,47271,47277,47293,47299,47335,47341,47347,47353,47358,47364,47442,47448,47454,47475,47481,47487,47493,47499,47505,47511,47555,47561,47566,47582,47587,47593,47599,47605,47611,47617,47623,47629,47635],{"data":47231,"content":47234,"nodeType":985},{"target":47232},{"sys":47233},{"id":44496,"type":982,"linkType":983},[],{"data":47236,"content":47237,"nodeType":876},{},[47238],{"data":47239,"marks":47240,"value":44504,"nodeType":867},{},[],{"data":47242,"content":47243,"nodeType":1629},{},[47244,47253,47262],{"data":47245,"content":47246,"nodeType":1586},{},[47247],{"data":47248,"content":47249,"nodeType":876},{},[47250],{"data":47251,"marks":47252,"value":44517,"nodeType":867},{},[],{"data":47254,"content":47255,"nodeType":1586},{},[47256],{"data":47257,"content":47258,"nodeType":876},{},[47259],{"data":47260,"marks":47261,"value":44527,"nodeType":867},{},[],{"data":47263,"content":47264,"nodeType":1586},{},[47265],{"data":47266,"content":47267,"nodeType":876},{},[47268],{"data":47269,"marks":47270,"value":44537,"nodeType":867},{},[],{"data":47272,"content":47273,"nodeType":876},{},[47274],{"data":47275,"marks":47276,"value":44544,"nodeType":867},{},[],{"data":47278,"content":47279,"nodeType":876},{},[47280,47283,47290],{"data":47281,"marks":47282,"value":44551,"nodeType":867},{},[],{"data":47284,"content":47285,"nodeType":915},{"uri":44554},[47286],{"data":47287,"marks":47288,"value":44560,"nodeType":867},{},[47289],{"type":913},{"data":47291,"marks":47292,"value":44564,"nodeType":867},{},[],{"data":47294,"content":47295,"nodeType":868},{},[47296],{"data":47297,"marks":47298,"value":44571,"nodeType":867},{},[],{"data":47300,"content":47301,"nodeType":876},{},[47302,47305,47312,47315,47322,47325,47332],{"data":47303,"marks":47304,"value":44578,"nodeType":867},{},[],{"data":47306,"content":47307,"nodeType":915},{"uri":44581},[47308],{"data":47309,"marks":47310,"value":44587,"nodeType":867},{},[47311],{"type":913},{"data":47313,"marks":47314,"value":44591,"nodeType":867},{},[],{"data":47316,"content":47317,"nodeType":915},{"uri":44594},[47318],{"data":47319,"marks":47320,"value":44600,"nodeType":867},{},[47321],{"type":913},{"data":47323,"marks":47324,"value":44604,"nodeType":867},{},[],{"data":47326,"content":47327,"nodeType":915},{"uri":37942},[47328],{"data":47329,"marks":47330,"value":44612,"nodeType":867},{},[47331],{"type":913},{"data":47333,"marks":47334,"value":44616,"nodeType":867},{},[],{"data":47336,"content":47337,"nodeType":876},{},[47338],{"data":47339,"marks":47340,"value":44623,"nodeType":867},{},[],{"data":47342,"content":47343,"nodeType":876},{},[47344],{"data":47345,"marks":47346,"value":44630,"nodeType":867},{},[],{"data":47348,"content":47349,"nodeType":876},{},[47350],{"data":47351,"marks":47352,"value":44637,"nodeType":867},{},[],{"data":47354,"content":47357,"nodeType":985},{"target":47355},{"sys":47356},{"id":41436,"type":982,"linkType":983},[],{"data":47359,"content":47360,"nodeType":876},{},[47361],{"data":47362,"marks":47363,"value":44649,"nodeType":867},{},[],{"data":47365,"content":47366,"nodeType":1629},{},[47367,47386,47405,47424],{"data":47368,"content":47369,"nodeType":1586},{},[47370],{"data":47371,"content":47372,"nodeType":876},{},[47373,47376,47383],{"data":47374,"marks":47375,"value":44662,"nodeType":867},{},[],{"data":47377,"content":47378,"nodeType":915},{"uri":44665},[47379],{"data":47380,"marks":47381,"value":44671,"nodeType":867},{},[47382],{"type":913},{"data":47384,"marks":47385,"value":21,"nodeType":867},{},[],{"data":47387,"content":47388,"nodeType":1586},{},[47389],{"data":47390,"content":47391,"nodeType":876},{},[47392,47395,47402],{"data":47393,"marks":47394,"value":44684,"nodeType":867},{},[],{"data":47396,"content":47397,"nodeType":915},{"uri":44687},[47398],{"data":47399,"marks":47400,"value":44693,"nodeType":867},{},[47401],{"type":913},{"data":47403,"marks":47404,"value":21,"nodeType":867},{},[],{"data":47406,"content":47407,"nodeType":1586},{},[47408],{"data":47409,"content":47410,"nodeType":876},{},[47411,47414,47421],{"data":47412,"marks":47413,"value":44706,"nodeType":867},{},[],{"data":47415,"content":47416,"nodeType":915},{"uri":2177},[47417],{"data":47418,"marks":47419,"value":44714,"nodeType":867},{},[47420],{"type":913},{"data":47422,"marks":47423,"value":21,"nodeType":867},{},[],{"data":47425,"content":47426,"nodeType":1586},{},[47427],{"data":47428,"content":47429,"nodeType":876},{},[47430,47433,47439],{"data":47431,"marks":47432,"value":44727,"nodeType":867},{},[],{"data":47434,"content":47435,"nodeType":915},{"uri":44730},[47436],{"data":47437,"marks":47438,"value":44735,"nodeType":867},{},[],{"data":47440,"marks":47441,"value":21,"nodeType":867},{},[],{"data":47443,"content":47444,"nodeType":868},{},[47445],{"data":47446,"marks":47447,"value":44745,"nodeType":867},{},[],{"data":47449,"content":47450,"nodeType":876},{},[47451],{"data":47452,"marks":47453,"value":44752,"nodeType":867},{},[],{"data":47455,"content":47456,"nodeType":1629},{},[47457,47466],{"data":47458,"content":47459,"nodeType":1586},{},[47460],{"data":47461,"content":47462,"nodeType":876},{},[47463],{"data":47464,"marks":47465,"value":44765,"nodeType":867},{},[],{"data":47467,"content":47468,"nodeType":1586},{},[47469],{"data":47470,"content":47471,"nodeType":876},{},[47472],{"data":47473,"marks":47474,"value":44775,"nodeType":867},{},[],{"data":47476,"content":47477,"nodeType":876},{},[47478],{"data":47479,"marks":47480,"value":44782,"nodeType":867},{},[],{"data":47482,"content":47483,"nodeType":876},{},[47484],{"data":47485,"marks":47486,"value":44789,"nodeType":867},{},[],{"data":47488,"content":47489,"nodeType":868},{},[47490],{"data":47491,"marks":47492,"value":44796,"nodeType":867},{},[],{"data":47494,"content":47495,"nodeType":876},{},[47496],{"data":47497,"marks":47498,"value":44803,"nodeType":867},{},[],{"data":47500,"content":47501,"nodeType":876},{},[47502],{"data":47503,"marks":47504,"value":44810,"nodeType":867},{},[],{"data":47506,"content":47507,"nodeType":876},{},[47508],{"data":47509,"marks":47510,"value":44817,"nodeType":867},{},[],{"data":47512,"content":47513,"nodeType":1629},{},[47514,47523,47532],{"data":47515,"content":47516,"nodeType":1586},{},[47517],{"data":47518,"content":47519,"nodeType":876},{},[47520],{"data":47521,"marks":47522,"value":44830,"nodeType":867},{},[],{"data":47524,"content":47525,"nodeType":1586},{},[47526],{"data":47527,"content":47528,"nodeType":876},{},[47529],{"data":47530,"marks":47531,"value":44840,"nodeType":867},{},[],{"data":47533,"content":47534,"nodeType":1586},{},[47535],{"data":47536,"content":47537,"nodeType":876},{},[47538,47541,47545,47548,47552],{"data":47539,"marks":47540,"value":44850,"nodeType":867},{},[],{"data":47542,"marks":47543,"value":24309,"nodeType":867},{},[47544],{"type":1303},{"data":47546,"marks":47547,"value":44858,"nodeType":867},{},[],{"data":47549,"marks":47550,"value":44863,"nodeType":867},{},[47551],{"type":1303},{"data":47553,"marks":47554,"value":44867,"nodeType":867},{},[],{"data":47556,"content":47557,"nodeType":876},{},[47558],{"data":47559,"marks":47560,"value":44874,"nodeType":867},{},[],{"data":47562,"content":47565,"nodeType":985},{"target":47563},{"sys":47564},{"id":44879,"type":982,"linkType":983},[],{"data":47567,"content":47568,"nodeType":876},{},[47569,47572,47579],{"data":47570,"marks":47571,"value":44887,"nodeType":867},{},[],{"data":47573,"content":47574,"nodeType":915},{"uri":44554},[47575],{"data":47576,"marks":47577,"value":44895,"nodeType":867},{},[47578],{"type":913},{"data":47580,"marks":47581,"value":1679,"nodeType":867},{},[],{"data":47583,"content":47586,"nodeType":985},{"target":47584},{"sys":47585},{"id":44903,"type":982,"linkType":983},[],{"data":47588,"content":47589,"nodeType":868},{},[47590],{"data":47591,"marks":47592,"value":44911,"nodeType":867},{},[],{"data":47594,"content":47595,"nodeType":876},{},[47596],{"data":47597,"marks":47598,"value":44918,"nodeType":867},{},[],{"data":47600,"content":47601,"nodeType":876},{},[47602],{"data":47603,"marks":47604,"value":44925,"nodeType":867},{},[],{"data":47606,"content":47607,"nodeType":876},{},[47608],{"data":47609,"marks":47610,"value":44932,"nodeType":867},{},[],{"data":47612,"content":47613,"nodeType":876},{},[47614],{"data":47615,"marks":47616,"value":44939,"nodeType":867},{},[],{"data":47618,"content":47619,"nodeType":876},{},[47620],{"data":47621,"marks":47622,"value":44946,"nodeType":867},{},[],{"data":47624,"content":47625,"nodeType":876},{},[47626],{"data":47627,"marks":47628,"value":44953,"nodeType":867},{},[],{"data":47630,"content":47631,"nodeType":868},{},[47632],{"data":47633,"marks":47634,"value":25228,"nodeType":867},{},[],{"data":47636,"content":47637,"nodeType":876},{},[47638,47641,47648],{"data":47639,"marks":47640,"value":44966,"nodeType":867},{},[],{"data":47642,"content":47643,"nodeType":915},{"uri":5286},[47644],{"data":47645,"marks":47646,"value":11707,"nodeType":867},{},[47647],{"type":913},{"data":47649,"marks":47650,"value":44977,"nodeType":867},{},[],{"items":47652},[47653,47655],{"sys":47654,"name":342},{"id":3240},{"sys":47656,"name":39245},{"id":39244},{"items":47658},[47659],{"fullName":2714,"firstName":2715,"jobTitle":851,"profilePicture":47660},{"url":2717},{"__typename":1772,"sys":47662,"content":47664,"title":48479,"synopsis":48480,"hashTags":59,"publishedDate":48481,"slug":48482,"tagsCollection":48483,"authorsCollection":48489},{"id":47663},"174u87EYeKMKHzYYxBLlHO",{"json":47665},{"data":47666,"content":47667,"nodeType":1680},{},[47668,47675,47682,47689,47717,47724,47731,47748,47755,47762,47780,47787,47794,47801,47807,47814,47857,47864,47871,47878,47901,47908,47915,47922,47970,47977,47984,47991,47998,48010,48017,48025,48032,48065,48072,48079,48086,48093,48155,48163,48170,48177,48211,48218,48226,48233,48240,48252,48268,48297,48315,48322,48339,48346,48353,48370,48377,48384,48391,48424,48431,48450,48467,48473],{"data":47669,"content":47670,"nodeType":876},{},[47671],{"data":47672,"marks":47673,"value":47674,"nodeType":867},{},[],"Identity attacks like phishing, credential stuffing, and session hijacking are now the leading cause of cyber security breaches, as attackers shift their attention to the sprawl of third-party applications and services that has become the backbone of business IT. ",{"data":47676,"content":47677,"nodeType":876},{},[47678],{"data":47679,"marks":47680,"value":47681,"nodeType":867},{},[],"The attacker’s goal in these attacks is account takeover: logging into a user account to access your company app tenant. From there, the attacker can usually achieve all of their objectives from inside the compromised app, usually involving dumping sensitive data with which to hold the company to ransom, or selling the data on underground criminal marketplaces. ",{"data":47683,"content":47684,"nodeType":876},{},[47685],{"data":47686,"marks":47687,"value":47688,"nodeType":867},{},[],"These attack techniques have been commonplace for over a decade — but the shift in attack context away from attacking endpoints (user devices and servers) to cloud services is seeing something of an identity attack renaissance. ",{"data":47690,"content":47691,"nodeType":876},{},[47692,47695,47702,47706,47713],{"data":47693,"marks":47694,"value":21,"nodeType":867},{},[],{"data":47696,"content":47697,"nodeType":915},{"uri":26236},[47698],{"data":47699,"marks":47700,"value":395,"nodeType":867},{},[47701],{"type":913},{"data":47703,"marks":47704,"value":47705,"nodeType":867},{},[]," are one of the leading factors in successful ",{"data":47707,"content":47708,"nodeType":915},{"uri":42200},[47709],{"data":47710,"marks":47711,"value":37948,"nodeType":867},{},[47712],{"type":913},{"data":47714,"marks":47715,"value":47716,"nodeType":867},{},[]," attacks driving account takeover.",{"data":47718,"content":47719,"nodeType":868},{},[47720],{"data":47721,"marks":47722,"value":47723,"nodeType":867},{},[],"Ghost logins 101",{"data":47725,"content":47726,"nodeType":876},{},[47727],{"data":47728,"marks":47729,"value":47730,"nodeType":867},{},[],"Simply put, ghost logins are often-forgotten alternative login methods that are tricky for security teams to manage and secure — because they don’t know about them. Because of this, they’re likely to possess weak configurations that make them susceptible to account takeover attacks. ",{"data":47732,"content":47733,"nodeType":876},{},[47734,47738,47745],{"data":47735,"marks":47736,"value":47737,"nodeType":867},{},[],"We found that ",{"data":47739,"content":47740,"nodeType":915},{"uri":2912},[47741],{"data":47742,"marks":47743,"value":47744,"nodeType":867},{},[],"ghost logins are present in ~10% of the accounts per organization",{"data":47746,"marks":47747,"value":2933,"nodeType":867},{},[],{"data":47749,"content":47750,"nodeType":1058},{},[47751],{"data":47752,"marks":47753,"value":47754,"nodeType":867},{},[],"Why do ghost logins exist?",{"data":47756,"content":47757,"nodeType":876},{},[47758],{"data":47759,"marks":47760,"value":47761,"nodeType":867},{},[],"Identity management used to be something that was centrally contained and managed using an enterprise identity service like Active Directory. Most users probably only had one or two identities that you really cared about: the one they used to log into their company laptop and domain, and maybe also to log into a VPN. ",{"data":47763,"content":47764,"nodeType":876},{},[47765,47769,47776],{"data":47766,"marks":47767,"value":47768,"nodeType":867},{},[],"Now, there are ",{"data":47770,"content":47771,"nodeType":915},{"uri":2912},[47772],{"data":47773,"marks":47774,"value":47775,"nodeType":867},{},[],"200+ business apps in use per company, creating 1000s of sprawled identities",{"data":47777,"marks":47778,"value":47779,"nodeType":867},{},[]," across an ecosystem of business apps and services accessed over the internet.",{"data":47781,"content":47782,"nodeType":876},{},[47783],{"data":47784,"marks":47785,"value":47786,"nodeType":867},{},[],"Most businesses have tried to solve this problem with single sign on (SSO). The logic being that if you can use a single set of credentials (and therefore, a single identity) to access all of your business apps, and then secure those credentials with MFA, then this problem goes away. However…",{"data":47788,"content":47789,"nodeType":1058},{},[47790],{"data":47791,"marks":47792,"value":47793,"nodeType":867},{},[],"SSO expectations versus reality",{"data":47795,"content":47796,"nodeType":876},{},[47797],{"data":47798,"marks":47799,"value":47800,"nodeType":867},{},[],"Unfortunately, the reality of SSO implementation is flawed. Most apps accept multiple login methods that can be configured — and used — simultaneously (yes, most apps don’t have proper session controls).  ",{"data":47802,"content":47806,"nodeType":985},{"target":47803},{"sys":47804},{"id":47805,"type":982,"linkType":983},"3sOz3HkiyJpY9nFtGCWEOV",[],{"data":47808,"content":47809,"nodeType":876},{},[47810],{"data":47811,"marks":47812,"value":47813,"nodeType":867},{},[],"This is made worse by the fact that:",{"data":47815,"content":47816,"nodeType":1629},{},[47817,47827,47837,47847],{"data":47818,"content":47819,"nodeType":1586},{},[47820],{"data":47821,"content":47822,"nodeType":876},{},[47823],{"data":47824,"marks":47825,"value":47826,"nodeType":867},{},[],"Most apps can't be locked down to restrict which login methods are accepted.",{"data":47828,"content":47829,"nodeType":1586},{},[47830],{"data":47831,"content":47832,"nodeType":876},{},[47833],{"data":47834,"marks":47835,"value":47836,"nodeType":867},{},[],"Users often self-adopt apps, and default to a username and password (and typically miss out MFA). ",{"data":47838,"content":47839,"nodeType":1586},{},[47840],{"data":47841,"content":47842,"nodeType":876},{},[47843],{"data":47844,"marks":47845,"value":47846,"nodeType":867},{},[],"SSO isn’t always possible if you aren’t using a supported IdP — and only one in three apps support SAML, the preferred enterprise-grade protocol.",{"data":47848,"content":47849,"nodeType":1586},{},[47850],{"data":47851,"content":47852,"nodeType":876},{},[47853],{"data":47854,"marks":47855,"value":47856,"nodeType":867},{},[],"Even where SSO is possible, configuring an app for SSO doesn't automatically delete any legacy local logins.",{"data":47858,"content":47859,"nodeType":876},{},[47860],{"data":47861,"marks":47862,"value":47863,"nodeType":867},{},[],"Inevitably, this means that there are many situations in which users will create local accounts — typically with a username and password, and without MFA. This is how ghost logins are born.",{"data":47865,"content":47866,"nodeType":1058},{},[47867],{"data":47868,"marks":47869,"value":47870,"nodeType":867},{},[],"How are ghost logins created? ",{"data":47872,"content":47873,"nodeType":876},{},[47874],{"data":47875,"marks":47876,"value":47877,"nodeType":867},{},[],"Ghost logins can be created in the following ways:",{"data":47879,"content":47880,"nodeType":1629},{},[47881,47891],{"data":47882,"content":47883,"nodeType":1586},{},[47884],{"data":47885,"content":47886,"nodeType":876},{},[47887],{"data":47888,"marks":47889,"value":47890,"nodeType":867},{},[],"A user self-adopts an app, setting up an account with a local username and password. The app is later adopted companywide and brought under SSO. This creates an additional SSO login method, likely as the default, but the local login will continue to exist unless explicitly disabled or deleted. ",{"data":47892,"content":47893,"nodeType":1586},{},[47894],{"data":47895,"content":47896,"nodeType":876},{},[47897],{"data":47898,"marks":47899,"value":47900,"nodeType":867},{},[],"Secondary/backup login methods can often be added later in the app settings after logging in. This includes things like setting up a secondary email to send a login link to, or setting up API access to remove the need to authenticate altogether. ",{"data":47902,"content":47903,"nodeType":876},{},[47904],{"data":47905,"marks":47906,"value":47907,"nodeType":867},{},[],"So, ghost logins are very easily introduced through the normal course of app adoption and use by employees. ",{"data":47909,"content":47910,"nodeType":1058},{},[47911],{"data":47912,"marks":47913,"value":47914,"nodeType":867},{},[],"Why do ghost logins pose a risk? ",{"data":47916,"content":47917,"nodeType":876},{},[47918],{"data":47919,"marks":47920,"value":47921,"nodeType":867},{},[],"Ghost logins pose a risk for a number of reasons, as they: ",{"data":47923,"content":47924,"nodeType":1629},{},[47925,47940,47955],{"data":47926,"content":47927,"nodeType":1586},{},[47928],{"data":47929,"content":47930,"nodeType":876},{},[47931,47936],{"data":47932,"marks":47933,"value":47935,"nodeType":867},{},[47934],{"type":865},"Typically have less secure configurations ",{"data":47937,"marks":47938,"value":47939,"nodeType":867},{},[],"than your preferred login method – and may be missing key controls like MFA.  ",{"data":47941,"content":47942,"nodeType":1586},{},[47943],{"data":47944,"content":47945,"nodeType":876},{},[47946,47951],{"data":47947,"marks":47948,"value":47950,"nodeType":867},{},[47949],{"type":865},"Are effectively shadow logins",{"data":47952,"marks":47953,"value":47954,"nodeType":867},{},[]," – IT/security don’t know about them, and if using an IdP as your primary identity security interface, they won’t necessarily be visible without taking a deeper look at individual apps. ",{"data":47956,"content":47957,"nodeType":1586},{},[47958],{"data":47959,"content":47960,"nodeType":876},{},[47961,47966],{"data":47962,"marks":47963,"value":47965,"nodeType":867},{},[47964],{"type":865},"Can be used simultaneously with SSO",{"data":47967,"marks":47968,"value":47969,"nodeType":867},{},[]," – so you can have an unrestricted number of concurrent sessions with SSO and non SSO logins active at the same time, without the user being kicked out of the previous session.",{"data":47971,"content":47972,"nodeType":876},{},[47973],{"data":47974,"marks":47975,"value":47976,"nodeType":867},{},[],"Ghost logins provide opportunities for attackers to bypass security controls for initial access and persistence in an application (which we’ll come onto in more detail later). They also provide an opportunity for malicious insiders, e.g. a disgruntled employee, to access systems even after SSO access is revoked. If the security team relies on IdP logs to audit app logins, these accounts can go undetected.",{"data":47978,"content":47979,"nodeType":876},{},[47980],{"data":47981,"marks":47982,"value":47983,"nodeType":867},{},[],"To be able to identify them, you’d need to log into the app admin dashboard. But depending on how the app was adopted, you (as a security admin) may not even be an app-level admin — it’s not unusual for individual teams to administer their own apps. And even if you do have access, it’s not always easy (or possible) to gather this level of information about user account configuration. ",{"data":47985,"content":47986,"nodeType":876},{},[47987],{"data":47988,"marks":47989,"value":47990,"nodeType":867},{},[],"It’s very easy to see how these vulnerable login methods can be overlooked by security teams – let’s look at how they can be identified and exploited by attackers. ",{"data":47992,"content":47993,"nodeType":868},{},[47994],{"data":47995,"marks":47996,"value":47997,"nodeType":867},{},[],"How can ghost logins be exploited by attackers?",{"data":47999,"content":48000,"nodeType":876},{},[48001,48006],{"data":48002,"marks":48003,"value":48005,"nodeType":867},{},[48004],{"type":865},"Let’s take an example scenario:",{"data":48007,"marks":48008,"value":48009,"nodeType":867},{},[]," You’re using an IdP solution like Okta or Microsoft/Entra with SAML SSO as the default login method for your core business apps. Via your IdP you require MFA when authenticating to your IdP apps page, and also potentially when signing into an individual connected app. ",{"data":48011,"content":48012,"nodeType":876},{},[48013],{"data":48014,"marks":48015,"value":48016,"nodeType":867},{},[],"However, you only recently introduced your IdP solution, and your users previously accessed this app with a local username and password. Although you asked your users to configure MFA in the app itself, not all of them did. And when you deployed your IdP solution, you didn’t manually unset all the local password-based logins for the apps you connected to it. ",{"data":48018,"content":48019,"nodeType":876},{},[48020],{"data":48021,"marks":48022,"value":48024,"nodeType":867},{},[48023],{"type":865},"Unknown to you, there are now hundreds of local accounts for core business apps which lack MFA. ",{"data":48026,"content":48027,"nodeType":876},{},[48028],{"data":48029,"marks":48030,"value":48031,"nodeType":867},{},[],"There are two main scenarios in which ghost logins can be utilized by an attacker:",{"data":48033,"content":48034,"nodeType":1629},{},[48035,48050],{"data":48036,"content":48037,"nodeType":1586},{},[48038],{"data":48039,"content":48040,"nodeType":876},{},[48041,48046],{"data":48042,"marks":48043,"value":48045,"nodeType":867},{},[48044],{"type":865},"To bypass robustly configured login methods",{"data":48047,"marks":48048,"value":48049,"nodeType":867},{},[]," such as SSO to compromise an app identity during the initial access phase of an attack. ",{"data":48051,"content":48052,"nodeType":1586},{},[48053],{"data":48054,"content":48055,"nodeType":876},{},[48056,48061],{"data":48057,"marks":48058,"value":48060,"nodeType":867},{},[48059],{"type":865},"To create additional login methods for an already compromised account to ensure persistent access",{"data":48062,"marks":48063,"value":48064,"nodeType":867},{},[]," – even if the original compromised login method is revoked or disabled. This could be either the result of compromising an identity belonging to a specific app, or having previously compromised an IdP account (e.g. Okta).",{"data":48066,"content":48067,"nodeType":876},{},[48068],{"data":48069,"marks":48070,"value":48071,"nodeType":867},{},[],"Let's look at these use cases in more detail. ",{"data":48073,"content":48074,"nodeType":1058},{},[48075],{"data":48076,"marks":48077,"value":48078,"nodeType":867},{},[],"Ghost logins for initial access",{"data":48080,"content":48081,"nodeType":876},{},[48082],{"data":48083,"marks":48084,"value":48085,"nodeType":867},{},[],"Arguably the most dangerous use case for ghost logins is to conduct credential attacks against accounts using a username and password. Logins with a weak or guessable password, or a reused password that has appeared in a public data breach dump, are primed for account takeover. ",{"data":48087,"content":48088,"nodeType":876},{},[48089],{"data":48090,"marks":48091,"value":48092,"nodeType":867},{},[],"The cyber crime ecosystem is leaning toward the theft, sale, and use of stolen credentials (not just emails and passwords, but session tokens too). ",{"data":48094,"content":48095,"nodeType":1629},{},[48096,48117,48136],{"data":48097,"content":48098,"nodeType":1586},{},[48099],{"data":48100,"content":48101,"nodeType":876},{},[48102,48106,48114],{"data":48103,"marks":48104,"value":48105,"nodeType":867},{},[],"There are 600 million identity attacks per day, with 99% involving passwords (",{"data":48107,"content":48109,"nodeType":915},{"uri":48108},"https://cdn-dynmedia-1.microsoft.com/is/content/microsoftcorp/microsoft/final/en-us/microsoft-brand/documents/Microsoft%20Digital%20Defense%20Report%202024%20%281%29.pdf",[48110],{"data":48111,"marks":48112,"value":11959,"nodeType":867},{},[48113],{"type":913},{"data":48115,"marks":48116,"value":24243,"nodeType":867},{},[],{"data":48118,"content":48119,"nodeType":1586},{},[48120],{"data":48121,"content":48122,"nodeType":876},{},[48123,48126,48133],{"data":48124,"marks":48125,"value":45640,"nodeType":867},{},[],{"data":48127,"content":48128,"nodeType":915},{"uri":7467},[48129],{"data":48130,"marks":48131,"value":45648,"nodeType":867},{},[48132],{"type":913},{"data":48134,"marks":48135,"value":24243,"nodeType":867},{},[],{"data":48137,"content":48138,"nodeType":1586},{},[48139],{"data":48140,"content":48141,"nodeType":876},{},[48142,48145,48152],{"data":48143,"marks":48144,"value":45576,"nodeType":867},{},[],{"data":48146,"content":48147,"nodeType":915},{"uri":45579},[48148],{"data":48149,"marks":48150,"value":45585,"nodeType":867},{},[48151],{"type":913},{"data":48153,"marks":48154,"value":24243,"nodeType":867},{},[],{"data":48156,"content":48157,"nodeType":876},{},[48158],{"data":48159,"marks":48160,"value":48162,"nodeType":867},{},[48161],{"type":865},"So, it’s easier than ever for attackers to gather breached credentials and weaponize them at scale. ",{"data":48164,"content":48165,"nodeType":876},{},[48166],{"data":48167,"marks":48168,"value":48169,"nodeType":867},{},[],"Realistically, any username and password combination for addresses belonging to a specific organization/domain can be attempted on any app. Breached credential data will often provide a strong indicator of other apps also in use for that organization. And for apps with a custom tenant URL (that cannot be easily guessed) data dumps often helpfully include the URLs for those login pages, too.  ",{"data":48171,"content":48172,"nodeType":876},{},[48173],{"data":48174,"marks":48175,"value":48176,"nodeType":867},{},[],"The risk posed by the massive amounts of leaked credentials available is heightened because: ",{"data":48178,"content":48179,"nodeType":1629},{},[48180,48201],{"data":48181,"content":48182,"nodeType":1586},{},[48183],{"data":48184,"content":48185,"nodeType":876},{},[48186,48190,48197],{"data":48187,"marks":48188,"value":48189,"nodeType":867},{},[],"Many employees reuse passwords, with ",{"data":48191,"content":48192,"nodeType":915},{"uri":2912},[48193],{"data":48194,"marks":48195,"value":48196,"nodeType":867},{},[],"~9% of all accounts using a breached, weak, or reused password",{"data":48198,"marks":48199,"value":48200,"nodeType":867},{},[],". This isn’t just for low-risk apps either, and includes the reuse of highly sensitive IdP creds. ",{"data":48202,"content":48203,"nodeType":1586},{},[48204],{"data":48205,"content":48206,"nodeType":876},{},[48207],{"data":48208,"marks":48209,"value":48210,"nodeType":867},{},[],"Organizations don’t typically rotate or enforce changes to SaaS app passwords in the same way they might for company account/device login connected to Active Directory.  ",{"data":48212,"content":48213,"nodeType":876},{},[48214],{"data":48215,"marks":48216,"value":48217,"nodeType":867},{},[],"Ghost logins aren’t limited to just username and password either. For example, a breached social account such as Facebook or Google can result in a broader compromise if those accounts have been connected to any corporate apps.   ",{"data":48219,"content":48220,"nodeType":876},{},[48221],{"data":48222,"marks":48223,"value":48225,"nodeType":867},{},[48224],{"type":865},"So, exploiting ghost logins can be a highly effective method for attackers to gain initial access to a user account from which to launch further attacks.  ",{"data":48227,"content":48228,"nodeType":1058},{},[48229],{"data":48230,"marks":48231,"value":48232,"nodeType":867},{},[],"Ghost logins for persistence and defense evasion",{"data":48234,"content":48235,"nodeType":876},{},[48236],{"data":48237,"marks":48238,"value":48239,"nodeType":867},{},[],"Now, we’ll take a look at how attackers can leverage ghost logins as part of the later stages of an attack, having already established an initial foothold via account compromise. ",{"data":48241,"content":48242,"nodeType":876},{},[48243,48247],{"data":48244,"marks":48245,"value":48246,"nodeType":867},{},[],"If an organization has a reasonable level of security monitoring in-place (depending on log availability from the particular app vendor), or a victim receives a notification about an unusual login (e.g. from a new device or unusual IP) then access to an account can be short-lived. ",{"data":48248,"marks":48249,"value":48251,"nodeType":867},{},[48250],{"type":865},"However, ghost logins can provide attackers with the tools to maintain persistent access to a compromised account, even if the initial compromised login method is disabled or revoked. ",{"data":48253,"content":48254,"nodeType":876},{},[48255,48259,48264],{"data":48256,"marks":48257,"value":48258,"nodeType":867},{},[],"For example, if a social login is used to access an account, an adversary may be able to configure a separate username/password login, or even (though much less commonly) connect a second social account that the adversary controls. This allows the adversary to maintain persistent access to the user account ",{"data":48260,"marks":48261,"value":48263,"nodeType":867},{},[48262],{"type":865},"even in the event of password changes or MFA changes",{"data":48265,"marks":48266,"value":48267,"nodeType":867},{},[],". The attack will go unnoticed if the victim organization relies on SSO logs for auditing access to SaaS applications because the attack bypasses SSO, as the login remains local to the SaaS app or, in the case of an OIDC SSO login, the adversary’s own social account.",{"data":48269,"content":48270,"nodeType":876},{},[48271,48275,48282,48286,48294],{"data":48272,"marks":48273,"value":48274,"nodeType":867},{},[],"Another quirk is that it’s common for ordinary users to become app-level admins when an app is self-adopted by an individual or team. If an attacker is able to gain control of such an account, it can then be used to target other users without needing to deliver phishing links by hijacking SAML-based authentication. In this scenario, users attempting to sign in using SAML SSO are directed it to an attacker-controlled tenant in a watering hole attack (also known as ",{"data":48276,"content":48277,"nodeType":915},{"uri":22216},[48278],{"data":48279,"marks":48280,"value":22222,"nodeType":867},{},[48281],{"type":913},{"data":48283,"marks":48284,"value":48285,"nodeType":867},{},[],", which you can ",{"data":48287,"content":48288,"nodeType":915},{"uri":5013},[48289],{"data":48290,"marks":48291,"value":48293,"nodeType":867},{},[48292],{"type":913},"read more about in another blog post",{"data":48295,"marks":48296,"value":23136,"nodeType":867},{},[],{"data":48298,"content":48299,"nodeType":876},{},[48300,48304,48312],{"data":48301,"marks":48302,"value":48303,"nodeType":867},{},[],"If you're curious as to how an attacker might be able to compromise an IdP account such as Okta, ",{"data":48305,"content":48306,"nodeType":915},{"uri":38018},[48307],{"data":48308,"marks":48309,"value":48311,"nodeType":867},{},[48310],{"type":913},"you should check out our blog post on AitM and BitM phishing techniques",{"data":48313,"marks":48314,"value":24572,"nodeType":867},{},[],{"data":48316,"content":48317,"nodeType":868},{},[48318],{"data":48319,"marks":48320,"value":48321,"nodeType":867},{},[],"Case study: Snowflake",{"data":48323,"content":48324,"nodeType":876},{},[48325,48328,48335],{"data":48326,"marks":48327,"value":964,"nodeType":867},{},[],{"data":48329,"content":48330,"nodeType":915},{"uri":15290},[48331],{"data":48332,"marks":48333,"value":48334,"nodeType":867},{},[],"recent attacks on 165 Snowflake customers",{"data":48336,"marks":48337,"value":48338,"nodeType":867},{},[],", resulting in hundreds of millions of breached customer records, were the product of a credential stuffing campaign using stolen credentials from infostealer infections dating back to 2020. ",{"data":48340,"content":48341,"nodeType":876},{},[48342],{"data":48343,"marks":48344,"value":48345,"nodeType":867},{},[],"The industry response to Snowflake was typical: check whether Snowflake has been set up for SSO, and if so, job done — we’re protected by MFA.",{"data":48347,"content":48348,"nodeType":876},{},[48349],{"data":48350,"marks":48351,"value":48352,"nodeType":867},{},[],"The reality was that MFA was not — and could not — be centrally enforced for username and password accounts. Even if MFA was applied at the IdP level for SSO logins, it was not enforced for local username and password logins. It needed to be opted-into by the user. ",{"data":48354,"content":48355,"nodeType":876},{},[48356,48360,48367],{"data":48357,"marks":48358,"value":48359,"nodeType":867},{},[],"This meant the most logical thing to do was to disable local accounts. But because Snowflake is essentially a cloud-hosted SQL database, there was no easy-to-use GUI to access local account config data. Once you’d managed to get an admin account with the right permissions, you needed to run various commands to find and unset the accounts. ",{"data":48361,"content":48362,"nodeType":915},{"uri":42382},[48363],{"data":48364,"marks":48365,"value":48366,"nodeType":867},{},[],"But if you didn’t have the exact type of admin account, misleading results would be returned — and even after you had fixed the vulnerability it took hours to update the database. ",{"data":48368,"marks":48369,"value":21,"nodeType":867},{},[],{"data":48371,"content":48372,"nodeType":876},{},[48373],{"data":48374,"marks":48375,"value":48376,"nodeType":867},{},[],"This meant that organizations were exposed to these attacks for a prolonged period, and were left uncertain as to whether they had addressed the vulnerabilities or not. ",{"data":48378,"content":48379,"nodeType":868},{},[48380],{"data":48381,"marks":48382,"value":48383,"nodeType":867},{},[],"Using Push to find and fix ghost logins across your app inventory",{"data":48385,"content":48386,"nodeType":876},{},[48387],{"data":48388,"marks":48389,"value":48390,"nodeType":867},{},[],"Finding and fixing ghost logins is a challenge for most organizations. Since you can’t rely on the view provided by your IdP, you need to:",{"data":48392,"content":48393,"nodeType":1629},{},[48394,48404,48414],{"data":48395,"content":48396,"nodeType":1586},{},[48397],{"data":48398,"content":48399,"nodeType":876},{},[48400],{"data":48401,"marks":48402,"value":48403,"nodeType":867},{},[],"Discover the apps in use across your organization",{"data":48405,"content":48406,"nodeType":1586},{},[48407],{"data":48408,"content":48409,"nodeType":876},{},[48410],{"data":48411,"marks":48412,"value":48413,"nodeType":867},{},[],"Get admin rights, audit each app, and unset any local credentials (enforcing MFA at the app-level too if you can, for good measure)",{"data":48415,"content":48416,"nodeType":1586},{},[48417],{"data":48418,"content":48419,"nodeType":876},{},[48420],{"data":48421,"marks":48422,"value":48423,"nodeType":867},{},[],"Configure the app to prevent local accounts being created (again, if possible)",{"data":48425,"content":48426,"nodeType":876},{},[48427],{"data":48428,"marks":48429,"value":48430,"nodeType":867},{},[],"Not only is this a sisyphean task with continually moving goalposts, but depending on which apps you use, and how they’ve been designed, it may not be possible to remediate every instance of ghost logins. For that reason, it’s important to also invest in your identity threat detection and response capabilities — for when, not if, an account takeover attempt occurs. ",{"data":48432,"content":48433,"nodeType":876},{},[48434,48438,48447],{"data":48435,"marks":48436,"value":48437,"nodeType":867},{},[],"Push helps organizations to defend against ghost logins and other identity threats with a defense-in-depth approach: Using a browser-based agent to generate visibility of all logins (not just via IdP logs) while also detecting, intercepting, and shutting down account takeover attempts via phishing, credential stuffing, and session hijacking. ",{"data":48439,"content":48441,"nodeType":915},{"uri":48440},"https://pushsecurity.com/",[48442],{"data":48443,"marks":48444,"value":48446,"nodeType":867},{},[48445],{"type":913},"Learn more here.",{"data":48448,"marks":48449,"value":21,"nodeType":867},{},[],{"data":48451,"content":48452,"nodeType":876},{},[48453,48457,48464],{"data":48454,"marks":48455,"value":48456,"nodeType":867},{},[],"And if you'd like to learn more about ghost logins and other identity attack techniques, ",{"data":48458,"content":48459,"nodeType":915},{"uri":35095},[48460],{"data":48461,"marks":48462,"value":48463,"nodeType":867},{},[],"check out the SaaS attack matrix on GitHub",{"data":48465,"marks":48466,"value":2933,"nodeType":867},{},[],{"data":48468,"content":48472,"nodeType":985},{"target":48469},{"sys":48470},{"id":48471,"type":982,"linkType":983},"1VMpMgZvx9hgps2OoxCTmF",[],{"data":48474,"content":48475,"nodeType":876},{},[48476],{"data":48477,"marks":48478,"value":21,"nodeType":867},{},[],"Ghost logins: When forgotten identities come back to haunt you","How ghost logins can be used by cyber attackers for account takeover and persistence.","2024-07-10T00:00:00.000Z","ghost-logins-when-forgotten-identities-come-back-to-haunt-you",{"items":48484},[48485,48487],{"sys":48486,"name":4018},{"id":4017},{"sys":48488,"name":342},{"id":3240},{"items":48490},[48491],{"fullName":4022,"firstName":4023,"jobTitle":4024,"profilePicture":48492},{"url":4026},"what-the-rise-of-infostealers-says-about-identity-attacks","blog/what-the-rise-of-infostealers-says-about-identity-attacks",{"json":48496},{"data":48497,"content":48498,"nodeType":1680},{},[48499],{"data":48500,"content":48501,"nodeType":876},{},[48502],{"data":48503,"marks":48504,"value":48505,"nodeType":867},{},[],"Infostealers seem to have become an overnight celebrity, having been previously shrugged off by enterprises with bigger fish to fry. The reality is that infostealers haven’t necessarily changed – but the world that they inhabit and how stolen data is used has.  ","What the rise in popularity of infostealers tells us about the cybercrime ecosystem and the shift toward identity attacks. ",{"id":48508,"publishedAt":48509},"4OrixXXLxRmSDxa7PF9gfM","2026-08-12T11:55:07.366Z",{"items":48511},[48512,48514],{"sys":48513,"name":4018},{"id":4017},{"sys":48515,"name":342},{"id":3240},{"items":48517},[48518,48520,48522,48524,48526,48528,48530,48532,48534,48536,48538,48540,48542,48544,48546,48548,48550,48552,48554],{"sys":48519,"name":279,"slug":280,"tier":31},{"id":276},{"sys":48521,"name":413,"slug":414,"tier":31},{"id":410},{"sys":48523,"name":642,"slug":643,"tier":31},{"id":639},{"sys":48525,"name":342,"slug":343,"tier":31},{"id":339},{"sys":48527,"name":519,"slug":520,"tier":31},{"id":516},{"sys":48529,"name":422,"slug":423,"tier":45},{"id":419},{"sys":48531,"name":333,"slug":334,"tier":45},{"id":330},{"sys":48533,"name":404,"slug":405,"tier":45},{"id":401},{"sys":48535,"name":571,"slug":572,"tier":45},{"id":568},{"sys":48537,"name":395,"slug":396,"tier":45},{"id":392},{"sys":48539,"name":448,"slug":449,"tier":45},{"id":445},{"sys":48541,"name":377,"slug":378,"tier":45},{"id":374},{"sys":48543,"name":528,"slug":529,"tier":45},{"id":525},{"sys":48545,"name":440,"slug":441,"tier":45},{"id":437},{"sys":48547,"name":502,"slug":503,"tier":45},{"id":499},{"sys":48549,"name":457,"slug":458,"tier":45},{"id":454},{"sys":48551,"name":537,"slug":538,"tier":45},{"id":534},{"sys":48553,"name":633,"slug":634,"tier":45},{"id":630},{"sys":48555,"name":607,"slug":608,"tier":45},{"id":604},"boUmh78SvCFSf6ZZgGkEQDAnKYwTjYN1VqCF_IIHTHc",{"id":48558,"title":48559,"authorsCollection":48560,"content":48566,"extension":228,"faqItemsCollection":48761,"faqTitle":59,"featured":6,"hashTags":59,"meta":48763,"metaTitle":48764,"ogImage":59,"postType":48765,"publishedDate":48766,"relatedBlogPostsCollection":48767,"slug":50387,"stem":50388,"subtitle":59,"summary":50389,"synopsis":50400,"sys":50401,"tagsCollection":50404,"topicsCollection":50408,"__hash__":50416},"blog/blog/push-introduces-support-for-arc-browser-securing-users-wherever-they-work.json","Push introduces support for Arc browser, securing users wherever they work",{"items":48561},[48562],{"fullName":48563,"firstName":37665,"jobTitle":851,"socialLinks":59,"profilePicture":48564},"Kevin Diffily",{"url":48565},"https://images.ctfassets.net/y1cdw1ablpvd/5hKAGAnsn4x4FU7VAAjg2h/1b4b0725efb6313423abf861601a2a82/IMG_1215.png",{"json":48567,"links":48749},{"data":48568,"content":48569,"nodeType":1680},{},[48570,48577,48597,48604,48611,48618,48638,48645,48652,48658,48665,48672,48679,48712,48728,48735,48742],{"data":48571,"content":48572,"nodeType":876},{},[48573],{"data":48574,"marks":48575,"value":48576,"nodeType":867},{},[],"Push is committed to developing support for a wide variety of browsers used in the workplace. To date, we’ve supported commonly used browsers like Google Chrome, Safari, Microsoft Edge, Firefox, and Brave. ",{"data":48578,"content":48579,"nodeType":876},{},[48580,48584,48593],{"data":48581,"marks":48582,"value":48583,"nodeType":867},{},[],"Now we’ve introduced support for ",{"data":48585,"content":48587,"nodeType":915},{"uri":48586},"https://arc.net/",[48588],{"data":48589,"marks":48590,"value":48592,"nodeType":867},{},[48591],{"type":913},"Arc",{"data":48594,"marks":48595,"value":48596,"nodeType":867},{},[],", an increasingly popular browser with developers and engineers that integrates standard browsing with its own applications using a sidebar. ",{"data":48598,"content":48599,"nodeType":868},{},[48600],{"data":48601,"marks":48602,"value":48603,"nodeType":867},{},[],"Why develop support for Arc?",{"data":48605,"content":48606,"nodeType":876},{},[48607],{"data":48608,"marks":48609,"value":48610,"nodeType":867},{},[],"As Push continues its quest to stop identity attacks, we are always looking for new ways to deliver our services across the different locales in which our users operate – namely, different browsers. ",{"data":48612,"content":48613,"nodeType":876},{},[48614],{"data":48615,"marks":48616,"value":48617,"nodeType":867},{},[],"Most organizations do not designate a single browser that their employees must use. Our browser agent allows businesses to facilitate user flexibility and enjoy the advantages of their chosen browser(s), without sacrificing security. ",{"data":48619,"content":48620,"nodeType":876},{},[48621,48625,48634],{"data":48622,"marks":48623,"value":48624,"nodeType":867},{},[],"Recently, we’ve seen an uptick in requests for support of Arc, which is a newer browser built using ",{"data":48626,"content":48628,"nodeType":915},{"uri":48627},"https://www.chromium.org/chromium-projects/",[48629],{"data":48630,"marks":48631,"value":48633,"nodeType":867},{},[48632],{"type":913},"Chromium",{"data":48635,"marks":48636,"value":48637,"nodeType":867},{},[],". Arc reimagines the browser, integrating various applications into its interface and bringing nearly all of the user’s functions into a single access point. Its tech-forward nature, customizations, privacy, and fresh take on how UX should work in browsers has proven to be popular with developers, engineers, and other highly tech-savvy early adopters.",{"data":48639,"content":48640,"nodeType":876},{},[48641],{"data":48642,"marks":48643,"value":48644,"nodeType":867},{},[],"Given the increased interest in the browser, we began developing a solution for companies with employees using Arc on work devices. Security teams can enable it with one click within our platform, and it cannot be altered by the end user (though they do have full transparency into the settings via our extension). ",{"data":48646,"content":48647,"nodeType":876},{},[48648],{"data":48649,"marks":48650,"value":48651,"nodeType":867},{},[],"Since Arc is built on Chromium, it inherits a number of Google Chrome’s features – namely, managing security controls at the policy level. Our users can now deploy the Push browser extension to Arc using a managed deployment on MacOS machines.",{"data":48653,"content":48657,"nodeType":985},{"target":48654},{"sys":48655},{"id":48656,"type":982,"linkType":983},"Df7iStjA2mA1ueB8OQjIB",[],{"data":48659,"content":48660,"nodeType":876},{},[48661],{"data":48662,"marks":48663,"value":48664,"nodeType":867},{},[],"This new feature was rolled out in early July to our existing customers, and within days it was more widely enabled in our platform than Safari. Push is committed to the browser as the future of security, and our support for Arc only furthers our effort to meet the needs of our customers and demonstrates our agility in being able to adapt to customer requirements. ",{"data":48666,"content":48667,"nodeType":868},{},[48668],{"data":48669,"marks":48670,"value":48671,"nodeType":867},{},[],"The browser is the best place to stop identity attacks",{"data":48673,"content":48674,"nodeType":876},{},[48675],{"data":48676,"marks":48677,"value":48678,"nodeType":867},{},[],"Since modern work happens in the browser, it’s also the place where identity attacks happen. Being in the browser allows Push to do a few things that other security tools and control points struggle with:",{"data":48680,"content":48681,"nodeType":1629},{},[48682,48692,48702],{"data":48683,"content":48684,"nodeType":1586},{},[48685],{"data":48686,"content":48687,"nodeType":876},{},[48688],{"data":48689,"marks":48690,"value":48691,"nodeType":867},{},[],"Get the broadest visibility across all workforce identities, including unmanaged identities outside your IdP.",{"data":48693,"content":48694,"nodeType":1586},{},[48695],{"data":48696,"content":48697,"nodeType":876},{},[48698],{"data":48699,"marks":48700,"value":48701,"nodeType":867},{},[],"Generate the best telemetry for detecting identity attack TTPs and tools such as AitM and BitM toolkits, and unauthorized sessions using stolen tokens.",{"data":48703,"content":48704,"nodeType":1586},{},[48705],{"data":48706,"content":48707,"nodeType":876},{},[48708],{"data":48709,"marks":48710,"value":48711,"nodeType":867},{},[],"Automatically enforce controls that either stop attacks in real time or block employees from taking risky actions like creating a new identity with a stolen password. ",{"data":48713,"content":48714,"nodeType":876},{},[48715,48718,48725],{"data":48716,"marks":48717,"value":41069,"nodeType":867},{},[],{"data":48719,"content":48720,"nodeType":915},{"uri":27034},[48721],{"data":48722,"marks":48723,"value":41077,"nodeType":867},{},[48724],{"type":913},{"data":48726,"marks":48727,"value":1679,"nodeType":867},{},[],{"data":48729,"content":48730,"nodeType":876},{},[48731],{"data":48732,"marks":48733,"value":48734,"nodeType":867},{},[],"To summarize, the browser is quickly becoming the new OS, so you can think of Push as the equivalent of an EDR agent for defending workforce identities. Naturally, we want to support as many popular browsers as possible so all users can benefit from enhanced identity protection.",{"data":48736,"content":48737,"nodeType":868},{},[48738],{"data":48739,"marks":48740,"value":48741,"nodeType":867},{},[],"Where else are your employees working?",{"data":48743,"content":48744,"nodeType":876},{},[48745],{"data":48746,"marks":48747,"value":48748,"nodeType":867},{},[],"Adding support for Arc isn’t the end of the road. We’re always looking for opportunities to meet our customers where they work. If you’re using a browser that we don’t currently support, let us know – we’d be happy to add it to the roadmap!",{"entries":48750},{"hyperlink":48751,"inline":48752,"block":48753},[],[],[48754],{"sys":48755,"__typename":1688,"title":48756,"caption":59,"layoutMode":59,"file":48757},{"id":48656},"Arc browser configuration",{"url":48758,"width":48759,"height":48760},"https://images.ctfassets.net/y1cdw1ablpvd/7jPSCsFlMhYvCdSM6ytzKL/7a78975c84592082a98507b9062d5565/image1.png",1356,1026,{"items":48762},[],{},"Push adds Arc to its growing list of supported browsers","release-notes","2024-07-25T00:00:00.000Z",{"items":48768},[48769,49206,49895],{"__typename":1772,"sys":48770,"content":48771,"title":44978,"synopsis":44979,"hashTags":59,"publishedDate":44980,"slug":44981,"tagsCollection":49196,"authorsCollection":49202},{"id":44487},{"json":48772},{"data":48773,"content":48774,"nodeType":1680},{},[48775,48780,48786,48816,48822,48838,48844,48880,48886,48892,48898,48903,48909,48987,48993,48999,49020,49026,49032,49038,49044,49050,49056,49100,49106,49111,49127,49132,49138,49144,49150,49156,49162,49168,49174,49180],{"data":48776,"content":48779,"nodeType":985},{"target":48777},{"sys":48778},{"id":44496,"type":982,"linkType":983},[],{"data":48781,"content":48782,"nodeType":876},{},[48783],{"data":48784,"marks":48785,"value":44504,"nodeType":867},{},[],{"data":48787,"content":48788,"nodeType":1629},{},[48789,48798,48807],{"data":48790,"content":48791,"nodeType":1586},{},[48792],{"data":48793,"content":48794,"nodeType":876},{},[48795],{"data":48796,"marks":48797,"value":44517,"nodeType":867},{},[],{"data":48799,"content":48800,"nodeType":1586},{},[48801],{"data":48802,"content":48803,"nodeType":876},{},[48804],{"data":48805,"marks":48806,"value":44527,"nodeType":867},{},[],{"data":48808,"content":48809,"nodeType":1586},{},[48810],{"data":48811,"content":48812,"nodeType":876},{},[48813],{"data":48814,"marks":48815,"value":44537,"nodeType":867},{},[],{"data":48817,"content":48818,"nodeType":876},{},[48819],{"data":48820,"marks":48821,"value":44544,"nodeType":867},{},[],{"data":48823,"content":48824,"nodeType":876},{},[48825,48828,48835],{"data":48826,"marks":48827,"value":44551,"nodeType":867},{},[],{"data":48829,"content":48830,"nodeType":915},{"uri":44554},[48831],{"data":48832,"marks":48833,"value":44560,"nodeType":867},{},[48834],{"type":913},{"data":48836,"marks":48837,"value":44564,"nodeType":867},{},[],{"data":48839,"content":48840,"nodeType":868},{},[48841],{"data":48842,"marks":48843,"value":44571,"nodeType":867},{},[],{"data":48845,"content":48846,"nodeType":876},{},[48847,48850,48857,48860,48867,48870,48877],{"data":48848,"marks":48849,"value":44578,"nodeType":867},{},[],{"data":48851,"content":48852,"nodeType":915},{"uri":44581},[48853],{"data":48854,"marks":48855,"value":44587,"nodeType":867},{},[48856],{"type":913},{"data":48858,"marks":48859,"value":44591,"nodeType":867},{},[],{"data":48861,"content":48862,"nodeType":915},{"uri":44594},[48863],{"data":48864,"marks":48865,"value":44600,"nodeType":867},{},[48866],{"type":913},{"data":48868,"marks":48869,"value":44604,"nodeType":867},{},[],{"data":48871,"content":48872,"nodeType":915},{"uri":37942},[48873],{"data":48874,"marks":48875,"value":44612,"nodeType":867},{},[48876],{"type":913},{"data":48878,"marks":48879,"value":44616,"nodeType":867},{},[],{"data":48881,"content":48882,"nodeType":876},{},[48883],{"data":48884,"marks":48885,"value":44623,"nodeType":867},{},[],{"data":48887,"content":48888,"nodeType":876},{},[48889],{"data":48890,"marks":48891,"value":44630,"nodeType":867},{},[],{"data":48893,"content":48894,"nodeType":876},{},[48895],{"data":48896,"marks":48897,"value":44637,"nodeType":867},{},[],{"data":48899,"content":48902,"nodeType":985},{"target":48900},{"sys":48901},{"id":41436,"type":982,"linkType":983},[],{"data":48904,"content":48905,"nodeType":876},{},[48906],{"data":48907,"marks":48908,"value":44649,"nodeType":867},{},[],{"data":48910,"content":48911,"nodeType":1629},{},[48912,48931,48950,48969],{"data":48913,"content":48914,"nodeType":1586},{},[48915],{"data":48916,"content":48917,"nodeType":876},{},[48918,48921,48928],{"data":48919,"marks":48920,"value":44662,"nodeType":867},{},[],{"data":48922,"content":48923,"nodeType":915},{"uri":44665},[48924],{"data":48925,"marks":48926,"value":44671,"nodeType":867},{},[48927],{"type":913},{"data":48929,"marks":48930,"value":21,"nodeType":867},{},[],{"data":48932,"content":48933,"nodeType":1586},{},[48934],{"data":48935,"content":48936,"nodeType":876},{},[48937,48940,48947],{"data":48938,"marks":48939,"value":44684,"nodeType":867},{},[],{"data":48941,"content":48942,"nodeType":915},{"uri":44687},[48943],{"data":48944,"marks":48945,"value":44693,"nodeType":867},{},[48946],{"type":913},{"data":48948,"marks":48949,"value":21,"nodeType":867},{},[],{"data":48951,"content":48952,"nodeType":1586},{},[48953],{"data":48954,"content":48955,"nodeType":876},{},[48956,48959,48966],{"data":48957,"marks":48958,"value":44706,"nodeType":867},{},[],{"data":48960,"content":48961,"nodeType":915},{"uri":2177},[48962],{"data":48963,"marks":48964,"value":44714,"nodeType":867},{},[48965],{"type":913},{"data":48967,"marks":48968,"value":21,"nodeType":867},{},[],{"data":48970,"content":48971,"nodeType":1586},{},[48972],{"data":48973,"content":48974,"nodeType":876},{},[48975,48978,48984],{"data":48976,"marks":48977,"value":44727,"nodeType":867},{},[],{"data":48979,"content":48980,"nodeType":915},{"uri":44730},[48981],{"data":48982,"marks":48983,"value":44735,"nodeType":867},{},[],{"data":48985,"marks":48986,"value":21,"nodeType":867},{},[],{"data":48988,"content":48989,"nodeType":868},{},[48990],{"data":48991,"marks":48992,"value":44745,"nodeType":867},{},[],{"data":48994,"content":48995,"nodeType":876},{},[48996],{"data":48997,"marks":48998,"value":44752,"nodeType":867},{},[],{"data":49000,"content":49001,"nodeType":1629},{},[49002,49011],{"data":49003,"content":49004,"nodeType":1586},{},[49005],{"data":49006,"content":49007,"nodeType":876},{},[49008],{"data":49009,"marks":49010,"value":44765,"nodeType":867},{},[],{"data":49012,"content":49013,"nodeType":1586},{},[49014],{"data":49015,"content":49016,"nodeType":876},{},[49017],{"data":49018,"marks":49019,"value":44775,"nodeType":867},{},[],{"data":49021,"content":49022,"nodeType":876},{},[49023],{"data":49024,"marks":49025,"value":44782,"nodeType":867},{},[],{"data":49027,"content":49028,"nodeType":876},{},[49029],{"data":49030,"marks":49031,"value":44789,"nodeType":867},{},[],{"data":49033,"content":49034,"nodeType":868},{},[49035],{"data":49036,"marks":49037,"value":44796,"nodeType":867},{},[],{"data":49039,"content":49040,"nodeType":876},{},[49041],{"data":49042,"marks":49043,"value":44803,"nodeType":867},{},[],{"data":49045,"content":49046,"nodeType":876},{},[49047],{"data":49048,"marks":49049,"value":44810,"nodeType":867},{},[],{"data":49051,"content":49052,"nodeType":876},{},[49053],{"data":49054,"marks":49055,"value":44817,"nodeType":867},{},[],{"data":49057,"content":49058,"nodeType":1629},{},[49059,49068,49077],{"data":49060,"content":49061,"nodeType":1586},{},[49062],{"data":49063,"content":49064,"nodeType":876},{},[49065],{"data":49066,"marks":49067,"value":44830,"nodeType":867},{},[],{"data":49069,"content":49070,"nodeType":1586},{},[49071],{"data":49072,"content":49073,"nodeType":876},{},[49074],{"data":49075,"marks":49076,"value":44840,"nodeType":867},{},[],{"data":49078,"content":49079,"nodeType":1586},{},[49080],{"data":49081,"content":49082,"nodeType":876},{},[49083,49086,49090,49093,49097],{"data":49084,"marks":49085,"value":44850,"nodeType":867},{},[],{"data":49087,"marks":49088,"value":24309,"nodeType":867},{},[49089],{"type":1303},{"data":49091,"marks":49092,"value":44858,"nodeType":867},{},[],{"data":49094,"marks":49095,"value":44863,"nodeType":867},{},[49096],{"type":1303},{"data":49098,"marks":49099,"value":44867,"nodeType":867},{},[],{"data":49101,"content":49102,"nodeType":876},{},[49103],{"data":49104,"marks":49105,"value":44874,"nodeType":867},{},[],{"data":49107,"content":49110,"nodeType":985},{"target":49108},{"sys":49109},{"id":44879,"type":982,"linkType":983},[],{"data":49112,"content":49113,"nodeType":876},{},[49114,49117,49124],{"data":49115,"marks":49116,"value":44887,"nodeType":867},{},[],{"data":49118,"content":49119,"nodeType":915},{"uri":44554},[49120],{"data":49121,"marks":49122,"value":44895,"nodeType":867},{},[49123],{"type":913},{"data":49125,"marks":49126,"value":1679,"nodeType":867},{},[],{"data":49128,"content":49131,"nodeType":985},{"target":49129},{"sys":49130},{"id":44903,"type":982,"linkType":983},[],{"data":49133,"content":49134,"nodeType":868},{},[49135],{"data":49136,"marks":49137,"value":44911,"nodeType":867},{},[],{"data":49139,"content":49140,"nodeType":876},{},[49141],{"data":49142,"marks":49143,"value":44918,"nodeType":867},{},[],{"data":49145,"content":49146,"nodeType":876},{},[49147],{"data":49148,"marks":49149,"value":44925,"nodeType":867},{},[],{"data":49151,"content":49152,"nodeType":876},{},[49153],{"data":49154,"marks":49155,"value":44932,"nodeType":867},{},[],{"data":49157,"content":49158,"nodeType":876},{},[49159],{"data":49160,"marks":49161,"value":44939,"nodeType":867},{},[],{"data":49163,"content":49164,"nodeType":876},{},[49165],{"data":49166,"marks":49167,"value":44946,"nodeType":867},{},[],{"data":49169,"content":49170,"nodeType":876},{},[49171],{"data":49172,"marks":49173,"value":44953,"nodeType":867},{},[],{"data":49175,"content":49176,"nodeType":868},{},[49177],{"data":49178,"marks":49179,"value":25228,"nodeType":867},{},[],{"data":49181,"content":49182,"nodeType":876},{},[49183,49186,49193],{"data":49184,"marks":49185,"value":44966,"nodeType":867},{},[],{"data":49187,"content":49188,"nodeType":915},{"uri":5286},[49189],{"data":49190,"marks":49191,"value":11707,"nodeType":867},{},[49192],{"type":913},{"data":49194,"marks":49195,"value":44977,"nodeType":867},{},[],{"items":49197},[49198,49200],{"sys":49199,"name":342},{"id":3240},{"sys":49201,"name":39245},{"id":39244},{"items":49203},[49204],{"fullName":2714,"firstName":2715,"jobTitle":851,"profilePicture":49205},{"url":2717},{"__typename":1772,"sys":49207,"content":49208,"title":39236,"synopsis":39237,"hashTags":59,"publishedDate":39238,"slug":39239,"tagsCollection":49885,"authorsCollection":49891},{"id":38447},{"json":49209},{"data":49210,"content":49211,"nodeType":1680},{},[49212,49217,49223,49265,49271,49277,49290,49296,49302,49371,49377,49382,49388,49394,49407,49413,49419,49439,49459,49464,49481,49487,49493,49520,49526,49532,49537,49554,49560,49566,49572,49578,49583,49600,49606,49612,49618,49624,49629,49646,49652,49658,49663,49680,49686,49692,49698,49740,49746,49807,49820,49825,49831,49837,49843,49849,49864,49870],{"data":49213,"content":49216,"nodeType":985},{"target":49214},{"sys":49215},{"id":38456,"type":982,"linkType":983},[],{"data":49218,"content":49219,"nodeType":876},{},[49220],{"data":49221,"marks":49222,"value":38464,"nodeType":867},{},[],{"data":49224,"content":49225,"nodeType":876},{},[49226,49229,49235,49238,49244,49247,49253,49256,49262],{"data":49227,"marks":49228,"value":38471,"nodeType":867},{},[],{"data":49230,"content":49231,"nodeType":915},{"uri":38474},[49232],{"data":49233,"marks":49234,"value":38479,"nodeType":867},{},[],{"data":49236,"marks":49237,"value":2136,"nodeType":867},{},[],{"data":49239,"content":49240,"nodeType":915},{"uri":38485},[49241],{"data":49242,"marks":49243,"value":38490,"nodeType":867},{},[],{"data":49245,"marks":49246,"value":2136,"nodeType":867},{},[],{"data":49248,"content":49249,"nodeType":915},{"uri":2177},[49250],{"data":49251,"marks":49252,"value":38500,"nodeType":867},{},[],{"data":49254,"marks":49255,"value":2136,"nodeType":867},{},[],{"data":49257,"content":49258,"nodeType":915},{"uri":38506},[49259],{"data":49260,"marks":49261,"value":38511,"nodeType":867},{},[],{"data":49263,"marks":49264,"value":38515,"nodeType":867},{},[],{"data":49266,"content":49267,"nodeType":876},{},[49268],{"data":49269,"marks":49270,"value":38522,"nodeType":867},{},[],{"data":49272,"content":49273,"nodeType":876},{},[49274],{"data":49275,"marks":49276,"value":38529,"nodeType":867},{},[],{"data":49278,"content":49279,"nodeType":876},{},[49280,49283,49287],{"data":49281,"marks":49282,"value":38536,"nodeType":867},{},[],{"data":49284,"marks":49285,"value":38541,"nodeType":867},{},[49286],{"type":865},{"data":49288,"marks":49289,"value":1679,"nodeType":867},{},[],{"data":49291,"content":49292,"nodeType":876},{},[49293],{"data":49294,"marks":49295,"value":38551,"nodeType":867},{},[],{"data":49297,"content":49298,"nodeType":876},{},[49299],{"data":49300,"marks":49301,"value":38558,"nodeType":867},{},[],{"data":49303,"content":49304,"nodeType":1629},{},[49305,49330],{"data":49306,"content":49307,"nodeType":1586},{},[49308],{"data":49309,"content":49310,"nodeType":876},{},[49311,49315,49318,49327],{"data":49312,"marks":49313,"value":38572,"nodeType":867},{},[49314],{"type":865},{"data":49316,"marks":49317,"value":38576,"nodeType":867},{},[],{"data":49319,"content":49322,"nodeType":17452},{"target":49320},{"sys":49321},{"id":38581,"type":982,"linkType":983},[49323],{"data":49324,"marks":49325,"value":25043,"nodeType":867},{},[49326],{"type":865},{"data":49328,"marks":49329,"value":38590,"nodeType":867},{},[],{"data":49331,"content":49332,"nodeType":1586},{},[49333],{"data":49334,"content":49335,"nodeType":876},{},[49336,49340,49343,49349,49352,49358,49361,49368],{"data":49337,"marks":49338,"value":38601,"nodeType":867},{},[49339],{"type":865},{"data":49341,"marks":49342,"value":38605,"nodeType":867},{},[],{"data":49344,"content":49345,"nodeType":915},{"uri":38608},[49346],{"data":49347,"marks":49348,"value":38613,"nodeType":867},{},[],{"data":49350,"marks":49351,"value":5136,"nodeType":867},{},[],{"data":49353,"content":49354,"nodeType":915},{"uri":38619},[49355],{"data":49356,"marks":49357,"value":38624,"nodeType":867},{},[],{"data":49359,"marks":49360,"value":38628,"nodeType":867},{},[],{"data":49362,"content":49363,"nodeType":915},{"uri":38631},[49364],{"data":49365,"marks":49366,"value":38637,"nodeType":867},{},[49367],{"type":865},{"data":49369,"marks":49370,"value":38641,"nodeType":867},{},[],{"data":49372,"content":49373,"nodeType":876},{},[49374],{"data":49375,"marks":49376,"value":38648,"nodeType":867},{},[],{"data":49378,"content":49381,"nodeType":985},{"target":49379},{"sys":49380},{"id":38653,"type":982,"linkType":983},[],{"data":49383,"content":49384,"nodeType":868},{},[49385],{"data":49386,"marks":49387,"value":38661,"nodeType":867},{},[],{"data":49389,"content":49390,"nodeType":876},{},[49391],{"data":49392,"marks":49393,"value":38668,"nodeType":867},{},[],{"data":49395,"content":49396,"nodeType":876},{},[49397,49400,49404],{"data":49398,"marks":49399,"value":38675,"nodeType":867},{},[],{"data":49401,"marks":49402,"value":25043,"nodeType":867},{},[49403],{"type":865},{"data":49405,"marks":49406,"value":38683,"nodeType":867},{},[],{"data":49408,"content":49409,"nodeType":876},{},[49410],{"data":49411,"marks":49412,"value":38690,"nodeType":867},{},[],{"data":49414,"content":49415,"nodeType":1058},{},[49416],{"data":49417,"marks":49418,"value":38697,"nodeType":867},{},[],{"data":49420,"content":49421,"nodeType":876},{},[49422,49425,49429,49432,49436],{"data":49423,"marks":49424,"value":38704,"nodeType":867},{},[],{"data":49426,"marks":49427,"value":38709,"nodeType":867},{},[49428],{"type":865},{"data":49430,"marks":49431,"value":1174,"nodeType":867},{},[],{"data":49433,"marks":49434,"value":38717,"nodeType":867},{},[49435],{"type":865},{"data":49437,"marks":49438,"value":1679,"nodeType":867},{},[],{"data":49440,"content":49441,"nodeType":876},{},[49442,49445,49449,49452,49456],{"data":49443,"marks":49444,"value":38727,"nodeType":867},{},[],{"data":49446,"marks":49447,"value":38732,"nodeType":867},{},[49448],{"type":865},{"data":49450,"marks":49451,"value":21631,"nodeType":867},{},[],{"data":49453,"marks":49454,"value":38740,"nodeType":867},{},[49455],{"type":865},{"data":49457,"marks":49458,"value":38744,"nodeType":867},{},[],{"data":49460,"content":49463,"nodeType":985},{"target":49461},{"sys":49462},{"id":38749,"type":982,"linkType":983},[],{"data":49465,"content":49466,"nodeType":876},{},[49467,49470,49478],{"data":49468,"marks":49469,"value":38757,"nodeType":867},{},[],{"data":49471,"content":49474,"nodeType":17452},{"target":49472},{"sys":49473},{"id":38762,"type":982,"linkType":983},[49475],{"data":49476,"marks":49477,"value":38767,"nodeType":867},{},[],{"data":49479,"marks":49480,"value":21,"nodeType":867},{},[],{"data":49482,"content":49483,"nodeType":1058},{},[49484],{"data":49485,"marks":49486,"value":38777,"nodeType":867},{},[],{"data":49488,"content":49489,"nodeType":876},{},[49490],{"data":49491,"marks":49492,"value":38784,"nodeType":867},{},[],{"data":49494,"content":49495,"nodeType":876},{},[49496,49499,49503,49506,49510,49513,49517],{"data":49497,"marks":49498,"value":38791,"nodeType":867},{},[],{"data":49500,"marks":49501,"value":38732,"nodeType":867},{},[49502],{"type":865},{"data":49504,"marks":49505,"value":21631,"nodeType":867},{},[],{"data":49507,"marks":49508,"value":38740,"nodeType":867},{},[49509],{"type":865},{"data":49511,"marks":49512,"value":38806,"nodeType":867},{},[],{"data":49514,"marks":49515,"value":38811,"nodeType":867},{},[49516],{"type":865},{"data":49518,"marks":49519,"value":38815,"nodeType":867},{},[],{"data":49521,"content":49522,"nodeType":876},{},[49523],{"data":49524,"marks":49525,"value":38822,"nodeType":867},{},[],{"data":49527,"content":49528,"nodeType":876},{},[49529],{"data":49530,"marks":49531,"value":38829,"nodeType":867},{},[],{"data":49533,"content":49536,"nodeType":985},{"target":49534},{"sys":49535},{"id":38834,"type":982,"linkType":983},[],{"data":49538,"content":49539,"nodeType":876},{},[49540,49543,49551],{"data":49541,"marks":49542,"value":38757,"nodeType":867},{},[],{"data":49544,"content":49547,"nodeType":17452},{"target":49545},{"sys":49546},{"id":38846,"type":982,"linkType":983},[49548],{"data":49549,"marks":49550,"value":38777,"nodeType":867},{},[],{"data":49552,"marks":49553,"value":21,"nodeType":867},{},[],{"data":49555,"content":49556,"nodeType":1058},{},[49557],{"data":49558,"marks":49559,"value":38860,"nodeType":867},{},[],{"data":49561,"content":49562,"nodeType":876},{},[49563],{"data":49564,"marks":49565,"value":38867,"nodeType":867},{},[],{"data":49567,"content":49568,"nodeType":876},{},[49569],{"data":49570,"marks":49571,"value":38874,"nodeType":867},{},[],{"data":49573,"content":49574,"nodeType":876},{},[49575],{"data":49576,"marks":49577,"value":38881,"nodeType":867},{},[],{"data":49579,"content":49582,"nodeType":985},{"target":49580},{"sys":49581},{"id":38886,"type":982,"linkType":983},[],{"data":49584,"content":49585,"nodeType":876},{},[49586,49589,49597],{"data":49587,"marks":49588,"value":38757,"nodeType":867},{},[],{"data":49590,"content":49593,"nodeType":17452},{"target":49591},{"sys":49592},{"id":38898,"type":982,"linkType":983},[49594],{"data":49595,"marks":49596,"value":38860,"nodeType":867},{},[],{"data":49598,"marks":49599,"value":21,"nodeType":867},{},[],{"data":49601,"content":49602,"nodeType":1058},{},[49603],{"data":49604,"marks":49605,"value":38912,"nodeType":867},{},[],{"data":49607,"content":49608,"nodeType":876},{},[49609],{"data":49610,"marks":49611,"value":38919,"nodeType":867},{},[],{"data":49613,"content":49614,"nodeType":876},{},[49615],{"data":49616,"marks":49617,"value":38926,"nodeType":867},{},[],{"data":49619,"content":49620,"nodeType":876},{},[49621],{"data":49622,"marks":49623,"value":38933,"nodeType":867},{},[],{"data":49625,"content":49628,"nodeType":985},{"target":49626},{"sys":49627},{"id":38938,"type":982,"linkType":983},[],{"data":49630,"content":49631,"nodeType":876},{},[49632,49635,49643],{"data":49633,"marks":49634,"value":38757,"nodeType":867},{},[],{"data":49636,"content":49639,"nodeType":17452},{"target":49637},{"sys":49638},{"id":38950,"type":982,"linkType":983},[49640],{"data":49641,"marks":49642,"value":38955,"nodeType":867},{},[],{"data":49644,"marks":49645,"value":21,"nodeType":867},{},[],{"data":49647,"content":49648,"nodeType":1058},{},[49649],{"data":49650,"marks":49651,"value":38965,"nodeType":867},{},[],{"data":49653,"content":49654,"nodeType":876},{},[49655],{"data":49656,"marks":49657,"value":38972,"nodeType":867},{},[],{"data":49659,"content":49662,"nodeType":985},{"target":49660},{"sys":49661},{"id":38977,"type":982,"linkType":983},[],{"data":49664,"content":49665,"nodeType":876},{},[49666,49669,49677],{"data":49667,"marks":49668,"value":38757,"nodeType":867},{},[],{"data":49670,"content":49673,"nodeType":17452},{"target":49671},{"sys":49672},{"id":38989,"type":982,"linkType":983},[49674],{"data":49675,"marks":49676,"value":38994,"nodeType":867},{},[],{"data":49678,"marks":49679,"value":21,"nodeType":867},{},[],{"data":49681,"content":49682,"nodeType":868},{},[49683],{"data":49684,"marks":49685,"value":39004,"nodeType":867},{},[],{"data":49687,"content":49688,"nodeType":876},{},[49689],{"data":49690,"marks":49691,"value":39011,"nodeType":867},{},[],{"data":49693,"content":49694,"nodeType":876},{},[49695],{"data":49696,"marks":49697,"value":39018,"nodeType":867},{},[],{"data":49699,"content":49700,"nodeType":1629},{},[49701,49714,49727],{"data":49702,"content":49703,"nodeType":1586},{},[49704],{"data":49705,"content":49706,"nodeType":876},{},[49707,49711],{"data":49708,"marks":49709,"value":39032,"nodeType":867},{},[49710],{"type":865},{"data":49712,"marks":49713,"value":39036,"nodeType":867},{},[],{"data":49715,"content":49716,"nodeType":1586},{},[49717],{"data":49718,"content":49719,"nodeType":876},{},[49720,49724],{"data":49721,"marks":49722,"value":39047,"nodeType":867},{},[49723],{"type":865},{"data":49725,"marks":49726,"value":39051,"nodeType":867},{},[],{"data":49728,"content":49729,"nodeType":1586},{},[49730],{"data":49731,"content":49732,"nodeType":876},{},[49733,49737],{"data":49734,"marks":49735,"value":39062,"nodeType":867},{},[49736],{"type":865},{"data":49738,"marks":49739,"value":39066,"nodeType":867},{},[],{"data":49741,"content":49742,"nodeType":876},{},[49743],{"data":49744,"marks":49745,"value":39073,"nodeType":867},{},[],{"data":49747,"content":49748,"nodeType":1629},{},[49749,49765,49781,49794],{"data":49750,"content":49751,"nodeType":1586},{},[49752],{"data":49753,"content":49754,"nodeType":876},{},[49755,49758,49762],{"data":49756,"marks":49757,"value":39086,"nodeType":867},{},[],{"data":49759,"marks":49760,"value":39091,"nodeType":867},{},[49761],{"type":865},{"data":49763,"marks":49764,"value":39095,"nodeType":867},{},[],{"data":49766,"content":49767,"nodeType":1586},{},[49768],{"data":49769,"content":49770,"nodeType":876},{},[49771,49774,49778],{"data":49772,"marks":49773,"value":39105,"nodeType":867},{},[],{"data":49775,"marks":49776,"value":39110,"nodeType":867},{},[49777],{"type":865},{"data":49779,"marks":49780,"value":39114,"nodeType":867},{},[],{"data":49782,"content":49783,"nodeType":1586},{},[49784],{"data":49785,"content":49786,"nodeType":876},{},[49787,49791],{"data":49788,"marks":49789,"value":39125,"nodeType":867},{},[49790],{"type":865},{"data":49792,"marks":49793,"value":39129,"nodeType":867},{},[],{"data":49795,"content":49796,"nodeType":1586},{},[49797],{"data":49798,"content":49799,"nodeType":876},{},[49800,49804],{"data":49801,"marks":49802,"value":39140,"nodeType":867},{},[49803],{"type":865},{"data":49805,"marks":49806,"value":39144,"nodeType":867},{},[],{"data":49808,"content":49809,"nodeType":876},{},[49810,49813,49817],{"data":49811,"marks":49812,"value":39151,"nodeType":867},{},[],{"data":49814,"marks":49815,"value":38637,"nodeType":867},{},[49816],{"type":865},{"data":49818,"marks":49819,"value":39159,"nodeType":867},{},[],{"data":49821,"content":49824,"nodeType":985},{"target":49822},{"sys":49823},{"id":39164,"type":982,"linkType":983},[],{"data":49826,"content":49827,"nodeType":876},{},[49828],{"data":49829,"marks":49830,"value":39172,"nodeType":867},{},[],{"data":49832,"content":49833,"nodeType":868},{},[49834],{"data":49835,"marks":49836,"value":39179,"nodeType":867},{},[],{"data":49838,"content":49839,"nodeType":876},{},[49840],{"data":49841,"marks":49842,"value":39186,"nodeType":867},{},[],{"data":49844,"content":49845,"nodeType":876},{},[49846],{"data":49847,"marks":49848,"value":39193,"nodeType":867},{},[],{"data":49850,"content":49851,"nodeType":876},{},[49852,49855,49861],{"data":49853,"marks":49854,"value":39200,"nodeType":867},{},[],{"data":49856,"content":49857,"nodeType":915},{"uri":38619},[49858],{"data":49859,"marks":49860,"value":39207,"nodeType":867},{},[],{"data":49862,"marks":49863,"value":39211,"nodeType":867},{},[],{"data":49865,"content":49866,"nodeType":868},{},[49867],{"data":49868,"marks":49869,"value":25228,"nodeType":867},{},[],{"data":49871,"content":49872,"nodeType":876},{},[49873,49876,49882],{"data":49874,"marks":49875,"value":39224,"nodeType":867},{},[],{"data":49877,"content":49878,"nodeType":915},{"uri":39227},[49879],{"data":49880,"marks":49881,"value":11707,"nodeType":867},{},[],{"data":49883,"marks":49884,"value":39235,"nodeType":867},{},[],{"items":49886},[49887,49889],{"sys":49888,"name":39245},{"id":39244},{"sys":49890,"name":342},{"id":3240},{"items":49892},[49893],{"fullName":2714,"firstName":2715,"jobTitle":851,"profilePicture":49894},{"url":2717},{"__typename":1772,"sys":49896,"content":49898,"title":50373,"synopsis":50374,"hashTags":59,"publishedDate":50375,"slug":50376,"tagsCollection":50377,"authorsCollection":50383},{"id":49897},"7yCGcUryKQGOHYHRtipn6W",{"json":49899},{"data":49900,"content":49901,"nodeType":1680},{},[49902,49909,49916,49923,49930,49937,49944,49951,49958,49965,49983,50001,50008,50015,50035,50042,50054,50097,50104,50123,50131,50138,50145,50152,50159,50166,50231,50238,50243,50250,50257,50264,50271,50291,50298,50305,50312,50319,50326,50333,50340,50347,50354,50360,50366],{"data":49903,"content":49904,"nodeType":876},{},[49905],{"data":49906,"marks":49907,"value":49908,"nodeType":867},{},[],"User web activity can be a rich source of attack detection data. To this end, most organizations today ingest some form of network traffic data for security monitoring purposes. ",{"data":49910,"content":49911,"nodeType":876},{},[49912],{"data":49913,"marks":49914,"value":49915,"nodeType":867},{},[],"Typically, network traffic data is gathered by analyzing web proxy and/or DNS logs. But, we regularly speak to organizations that are frustrated with the challenge of piecing together web traffic data, without understanding the opportunity presented by the alternatives.",{"data":49917,"content":49918,"nodeType":876},{},[49919],{"data":49920,"marks":49921,"value":49922,"nodeType":867},{},[],"Even with proxies that can terminate TLS-encrypted datastreams, it’s difficult for even expert security teams to collect and analyze any meaningful data from web proxy logs. While the kind of data needed might be technically possible to extract, the process of reconstructing proxy data to analyze the specific data points that you really need, at scale, is prohibitively complicated.",{"data":49924,"content":49925,"nodeType":876},{},[49926],{"data":49927,"marks":49928,"value":49929,"nodeType":867},{},[],"The old “needle in a haystack” adage is very apt here! Rather than trying to piece together half-broken data – overlaying noisy proxy logs with other sources such as app and IdP telemetry – we think that the browser presents a much simpler way of analyzing relevant data points, particularly when it comes to identity attacks. ",{"data":49931,"content":49932,"nodeType":876},{},[49933],{"data":49934,"marks":49935,"value":49936,"nodeType":867},{},[],"Before we get on to detection opportunities in the browser, let’s take a deeper look at the web proxy situation.",{"data":49938,"content":49939,"nodeType":868},{},[49940],{"data":49941,"marks":49942,"value":49943,"nodeType":867},{},[],"Detection based on web proxy – how does it work and what are the limitations?",{"data":49945,"content":49946,"nodeType":876},{},[49947],{"data":49948,"marks":49949,"value":49950,"nodeType":867},{},[],"Web proxies generate common data points that can be used for threat detection, particularly when looking for indicators of an endpoint compromise. They work by inspecting network traffic to and from the endpoint, which includes web activity in the browser. ",{"data":49952,"content":49953,"nodeType":876},{},[49954],{"data":49955,"marks":49956,"value":49957,"nodeType":867},{},[],"The classic use case would be inspecting traffic from an endpoint to networked servers and devices, either on the local network or over the internet (e.g. via VPN), to detect signs of suspicious/malicious behavior from the device (indicating a potential compromise). Data is then shipped to a central proxy server where it can be analyzed for indicators of malicious activity. ",{"data":49959,"content":49960,"nodeType":876},{},[49961],{"data":49962,"marks":49963,"value":49964,"nodeType":867},{},[],"The traditional proxy setup has a number of limitations: ",{"data":49966,"content":49967,"nodeType":1629},{},[49968],{"data":49969,"content":49970,"nodeType":1586},{},[49971],{"data":49972,"content":49973,"nodeType":876},{},[49974,49979],{"data":49975,"marks":49976,"value":49978,"nodeType":867},{},[49977],{"type":865},"The proxy needs to be in a position to intercept traffic.",{"data":49980,"marks":49981,"value":49982,"nodeType":867},{},[]," It may only be active when a user is in the office, on a VPN and/or for external web traffic only. It might not work if a user is on their home or other other Wi-Fi – e.g. when working from Starbucks, or visiting a customer site, which isn’t an ideal setup in the era of remote working.  ",{"data":49984,"content":49985,"nodeType":1629},{},[49986],{"data":49987,"content":49988,"nodeType":1586},{},[49989],{"data":49990,"content":49991,"nodeType":876},{},[49992,49997],{"data":49993,"marks":49994,"value":49996,"nodeType":867},{},[49995],{"type":865},"Most web traffic is protected by TLS – so a proxy has to decrypt this to inspect what’s inside.",{"data":49998,"marks":49999,"value":50000,"nodeType":867},{},[]," At the very least you’re going to need to deploy a CA cert to every endpoint. But, some websites use things like certificate pinning or other SSL-enforcement controls to straight up prevent this. Unless you’re doing TLS-termination at scale with a COTS solution, then the ability to do proxy-based monitoring is seriously limited. ",{"data":50002,"content":50003,"nodeType":1058},{},[50004],{"data":50005,"marks":50006,"value":50007,"nodeType":867},{},[],"Proxies under the hood",{"data":50009,"content":50010,"nodeType":876},{},[50011],{"data":50012,"marks":50013,"value":50014,"nodeType":867},{},[],"Let’s pop the hood and take a look at the data you can collect using a web proxy that is useful for threat detection. ",{"data":50016,"content":50017,"nodeType":876},{},[50018,50022,50031],{"data":50019,"marks":50020,"value":50021,"nodeType":867},{},[],"Typically, you’re looking at data points such as domain names or IP addresses. If the proxy is terminating TLS, you might also have web URLs, the type of web content accessed, and other HTTP-level metadata. Higher level data like file uploads/downloads can sometimes be reconstructed when using very vanilla methods. More advanced proxies might run or open downloaded files in a sandbox for dynamic analysis to identify potentially malicious properties, which has ",{"data":50023,"content":50025,"nodeType":915},{"uri":50024},"https://www.cyfirma.com/research/html-smuggling-a-stealthier-approach-to-deliver-malware/",[50026],{"data":50027,"marks":50028,"value":50030,"nodeType":867},{},[50029],{"type":913},"given rise to techniques like HTML smuggling",{"data":50032,"marks":50033,"value":50034,"nodeType":867},{},[]," to hide these file downloads from advanced proxies. ",{"data":50036,"content":50037,"nodeType":876},{},[50038],{"data":50039,"marks":50040,"value":50041,"nodeType":867},{},[],"In practice this means that you might see that an endpoint at IP address X accessed google.com. If it’s an authenticated proxy, you might see the user of the endpoint as well. Using this data, it’s possible to see which endpoint’s owner accessed the web domain, but not the identity/account they used, or whether they actually logged in at all. So for the majority of in-house proxy setups not doing TLS-termination… that’s it. Even then, without decrypting TLS you can’t be sure you’re seeing the actual/final domain because of technologies like domain fronting that are commonly implemented in modern CDNs. ",{"data":50043,"content":50044,"nodeType":876},{},[50045,50049],{"data":50046,"marks":50047,"value":50048,"nodeType":867},{},[],"With TLS termination, it’s possible to see a lot more by inspecting/unpacking the HTTP data. At this point there are two possible approaches: Manual analysis after the fact, or automated analysis on the fly. ",{"data":50050,"marks":50051,"value":50053,"nodeType":867},{},[50052],{"type":865},"Unfortunately, there are problems with both options. ",{"data":50055,"content":50056,"nodeType":1629},{},[50057,50077],{"data":50058,"content":50059,"nodeType":1586},{},[50060],{"data":50061,"content":50062,"nodeType":876},{},[50063,50068,50072],{"data":50064,"marks":50065,"value":50067,"nodeType":867},{},[50066],{"type":865},"There is too much HTTP data to store and manually analyze everything:",{"data":50069,"marks":50070,"value":50071,"nodeType":867},{},[]," Usually, organizations limit the data being stored to specific metadata as opposed to trying to store everything (terabytes of data per day), which would be impossibly expensive to store (and also to build the server infrastructure required to index and search it – effectively a mini-datacenter). ",{"data":50073,"marks":50074,"value":50076,"nodeType":867},{},[50075],{"type":1303},"Not to mention that storing detailed HTTP body data presents a significant security risk, as it includes valid session tokens/cookies for all your identities…  ",{"data":50078,"content":50079,"nodeType":1586},{},[50080],{"data":50081,"content":50082,"nodeType":876},{},[50083,50088,50092],{"data":50084,"marks":50085,"value":50087,"nodeType":867},{},[50086],{"type":865},"Each web app is custom, making automated analysis (virtually) impossible:",{"data":50089,"marks":50090,"value":50091,"nodeType":867},{},[]," Proxy-based solutions have to reconstruct the data after TLS encryption. HTTP data is usually stored in large application JSON/XML objects or even in totally custom encoding – per each app. This means that complex, custom code is required per each app to be able to perform automated analysis. When businesses today are using hundreds of apps on average, ",{"data":50093,"marks":50094,"value":50096,"nodeType":867},{},[50095],{"type":865},"automating this process is not feasible as it requires constant reverse engineering of every web app. ",{"data":50098,"content":50099,"nodeType":876},{},[50100],{"data":50101,"marks":50102,"value":50103,"nodeType":867},{},[],"So what does this mean? Well, even organizations with a TLS-terminating proxy are limited to manual analysis of select metadata after-the-fact, which massively reduces its utility. You could sink a day or more’s analysis into gathering a small amount of useful data, for example whether a URL was accessed, but not necessarily which device/user, or what account/creds were used to log in). This means you’re probably going to use proxy data to aid in the investigation of a known incident rather than anything proactive. ",{"data":50105,"content":50106,"nodeType":876},{},[50107,50112,50118],{"data":50108,"marks":50109,"value":50111,"nodeType":867},{},[50110],{"type":865},"It might be ",{"data":50113,"marks":50114,"value":50117,"nodeType":867},{},[50115,50116],{"type":1303},{"type":865},"theoretically",{"data":50119,"marks":50120,"value":50122,"nodeType":867},{},[50121],{"type":865}," possible to sift through decrypted HTTP data to identify and correlate identities and actions, effectively reconstructing web pages from the network traffic automatically and on the fly (in the same way that it’s theoretically possible to remove my head and transplant it onto your body), but is it practical or reasonable for most organizations to do this? No. ",{"data":50124,"content":50125,"nodeType":868},{},[50126],{"data":50127,"marks":50128,"value":50130,"nodeType":867},{},[50129],{"type":865},"Browser data: a better alternative?",{"data":50132,"content":50133,"nodeType":876},{},[50134],{"data":50135,"marks":50136,"value":50137,"nodeType":867},{},[],"One way of overcoming some of the limitations of the classic web proxy setup is to use a browser-based solution. It’s much easier to collect data at the browser level before it’s encrypted. ",{"data":50139,"content":50140,"nodeType":876},{},[50141],{"data":50142,"marks":50143,"value":50144,"nodeType":867},{},[],"A browser agent isn’t just a proxy for pre-TLS HTML data, though. In the browser, you’re able to dynamically interact with the DOM or the rendered web application, including its JS code. This makes it easy to find, for example, input fields for usernames and passwords. You can see what information the user is inputting and where, without needing to figure out how the data is encoded and sent back to the app. These are fairly generic fields that can be identified across your suite of apps without needing complex custom code. To put it in perspective, approximately 10 login cases cover the entirety of the SaaS apps we support (~1000). Using a proxy-based solution, each of these would require custom development.   ",{"data":50146,"content":50147,"nodeType":876},{},[50148],{"data":50149,"marks":50150,"value":50151,"nodeType":867},{},[],"While it's technically possible to keep track of multiple sessions for thousands of users across hundreds of apps via proxy, it’s no mean feat – made much easier when each extension is tracking one user, in one browser, and even knows the browser tab it’s running in. You also get additional context at the identity layer such as the email address, authentication protocol, and credentials used, neatly mapped to that specific user and browser profile – no more trying to link the owner of an IP address to log events!",{"data":50153,"content":50154,"nodeType":876},{},[50155],{"data":50156,"marks":50157,"value":50158,"nodeType":867},{},[],"The browser also has the added benefit of being a natural enforcement point. You can collect and analyze data dynamically, and produce an immediate response – rather than taking info away, analyzing it, and coming back with a detection minutes or hours later (and potentially prompting a manual response). ",{"data":50160,"content":50161,"nodeType":876},{},[50162],{"data":50163,"marks":50164,"value":50165,"nodeType":867},{},[],"Let’s look at a couple of examples based on how we’re using our browser agent to detect and block identity attacks. ",{"data":50167,"content":50168,"nodeType":1629},{},[50169,50190,50210],{"data":50170,"content":50171,"nodeType":1586},{},[50172],{"data":50173,"content":50174,"nodeType":876},{},[50175,50178,50186],{"data":50176,"marks":50177,"value":21,"nodeType":867},{},[],{"data":50179,"content":50180,"nodeType":915},{"uri":22796},[50181],{"data":50182,"marks":50183,"value":50185,"nodeType":867},{},[50184],{"type":913},"Pinning passwords to the legitimate site they are linked with",{"data":50187,"marks":50188,"value":50189,"nodeType":867},{},[],". This is made possible by interacting with the DOM to observe passwords being entered – enabling the Push agent to intercept and block before an HTTP network request can even be made. ",{"data":50191,"content":50192,"nodeType":1586},{},[50193],{"data":50194,"content":50195,"nodeType":876},{},[50196,50199,50206],{"data":50197,"marks":50198,"value":21,"nodeType":867},{},[],{"data":50200,"content":50201,"nodeType":915},{"uri":40019},[50202],{"data":50203,"marks":50204,"value":50205,"nodeType":867},{},[],"Detecting and blocking malicious phishing tools",{"data":50207,"marks":50208,"value":50209,"nodeType":867},{},[]," running on websites by observing behavioral attributes in the browser, such as Javascript calls being made or data structures saved to local storage.",{"data":50211,"content":50212,"nodeType":1586},{},[50213],{"data":50214,"content":50215,"nodeType":876},{},[50216,50219,50227],{"data":50217,"marks":50218,"value":21,"nodeType":867},{},[],{"data":50220,"content":50222,"nodeType":915},{"uri":50221},"https://pushsecurity.com/blog/manage-third-party-data-access/",[50223],{"data":50224,"marks":50225,"value":50226,"nodeType":867},{},[],"Observing users signing up to and using risky apps",{"data":50228,"marks":50229,"value":50230,"nodeType":867},{},[],", or changing or removing authentication methods, MFA methods, and configuration methods, which could indicate account takeover. ",{"data":50232,"content":50233,"nodeType":876},{},[50234],{"data":50235,"marks":50236,"value":50237,"nodeType":867},{},[],"It’s always useful to refer back to the concept of the Pyramid of Pain in these situations. The opportunities to detect and block in the browser tend to align with indicators at the apex of the pyramid, meaning they are a significant obstruction for attackers – and difficult to circumvent. This contrasts the indicators aligned with proxy-based solutions, which are much easier to bypass through, for example, IP masking using residential proxy networks, or changing the domains and URLs used for phishing campaigns.  ",{"data":50239,"content":50242,"nodeType":985},{"target":50240},{"sys":50241},{"id":40799,"type":982,"linkType":983},[],{"data":50244,"content":50245,"nodeType":876},{},[50246],{"data":50247,"marks":50248,"value":50249,"nodeType":867},{},[],"In summary: Browser data provides high-fidelity indicators of malicious activity, without the complications of proxy-based approaches. The scope for response in the browser is significant and immediate, meaning it’s a great enforcement point for security controls to be able to disrupt attacks. ",{"data":50251,"content":50252,"nodeType":868},{},[50253],{"data":50254,"marks":50255,"value":50256,"nodeType":867},{},[],"Won’t my app and IdP logs cover this?",{"data":50258,"content":50259,"nodeType":876},{},[50260],{"data":50261,"marks":50262,"value":50263,"nodeType":867},{},[],"App and IdP logs are useful (when you can get them), but neither give you the full picture. ",{"data":50265,"content":50266,"nodeType":1058},{},[50267],{"data":50268,"marks":50269,"value":50270,"nodeType":867},{},[],"App logs are limited in availability, scope, and ease of ingestion ",{"data":50272,"content":50273,"nodeType":876},{},[50274,50278,50287],{"data":50275,"marks":50276,"value":50277,"nodeType":867},{},[],"When relying on app logs, you’re naturally constrained by the app provider. Many smaller apps provide no security logging, while others ",{"data":50279,"content":50281,"nodeType":915},{"uri":50280},"https://audit-logs.tax/",[50282],{"data":50283,"marks":50284,"value":50286,"nodeType":867},{},[50285],{"type":913},"lock security logging behind the premium tier subscription",{"data":50288,"marks":50289,"value":50290,"nodeType":867},{},[],". When logs are available, you’re limited to the events that the third-party deems suitable to log. ",{"data":50292,"content":50293,"nodeType":876},{},[50294],{"data":50295,"marks":50296,"value":50297,"nodeType":867},{},[],"Out of the 100 most popular apps we see across our customers, and perhaps the few dozen or so that are security critical, only a small handful provide any useful logging. This means, naturally, that the majority of apps do not. ",{"data":50299,"content":50300,"nodeType":876},{},[50301],{"data":50302,"marks":50303,"value":50304,"nodeType":867},{},[],"To top it all off, the process of extracting these logs and feeding them into your SIEM (or equivalent) is also not straightforward. The lack of out-of-the-box connectors for many apps means that complex custom architectures are required for collecting data. Some vendors place constraints on the format and mechanism for extracting logs which can make ingestion difficult to feed reliable detections – even before any meaningful analysis of the data can take place. ",{"data":50306,"content":50307,"nodeType":876},{},[50308],{"data":50309,"marks":50310,"value":50311,"nodeType":867},{},[],"Until application security logs are made widely available (and at no additional cost) it’s unlikely you’re going to be able to get the visibility you need from app logs, for every app your employees use (though of course there are exceptions – and we hope to see more vendors in future treating security as a minimum requirement, not a chargeable addon). ",{"data":50313,"content":50314,"nodeType":1058},{},[50315],{"data":50316,"marks":50317,"value":50318,"nodeType":867},{},[],"IdP logs cover only SSO integrated apps and are limited in scope",{"data":50320,"content":50321,"nodeType":876},{},[50322],{"data":50323,"marks":50324,"value":50325,"nodeType":867},{},[],"You might think, “but all of our business apps are behind SSO, right?” In reality, only about 1 in 3 apps support SSO (and even fewer at the ‘free’ tier). And in practice, our data shows us that only 1 in 5 apps on average are actually behind SSO per organization. The theoretical security benefit of IdP logs is that they provide context, a foundation for the user’s activity across (and between) a suite of apps. But because of the lack of coverage, this isn’t the case. ",{"data":50327,"content":50328,"nodeType":876},{},[50329],{"data":50330,"marks":50331,"value":50332,"nodeType":867},{},[],"IdP logs are naturally focused on authentication, and so don’t compensate for any gaps in app logging. Naturally, they are only able to observe what happens on the IdP side – and so are blind to client side attacks like phishing (which we’ve already shown the browser provides superior visibility of compared to typical alternatives like proxy logs).   ",{"data":50334,"content":50335,"nodeType":1058},{},[50336],{"data":50337,"marks":50338,"value":50339,"nodeType":867},{},[],"Browser is best for stopping identity attacks",{"data":50341,"content":50342,"nodeType":876},{},[50343],{"data":50344,"marks":50345,"value":50346,"nodeType":867},{},[],"This is where the browser comes in. Think of your browser as your source of truth, a broad data baseline for user activity where the browser provides complete context of the browser profile, employee, accounts, credentials, auth methods, and MFA types – as well as employee interaction with web sites.",{"data":50348,"content":50349,"nodeType":876},{},[50350],{"data":50351,"marks":50352,"value":50353,"nodeType":867},{},[],"The TL;DR is that your visibility in the browser is theoretically limitless. Every page loaded (and its source, javascript state, local storage), every user interaction can be observed. And best of all, this analysis is done securely in the browser and only the results of detections are reported back, rather than decrypting the entire raw traffic stream including all session data in an additional centralized system. ",{"data":50355,"content":50359,"nodeType":985},{"target":50356},{"sys":50357},{"id":50358,"type":982,"linkType":983},"5jPCGPO1tnIkoI7MKW4oUi",[],{"data":50361,"content":50362,"nodeType":868},{},[50363],{"data":50364,"marks":50365,"value":23563,"nodeType":867},{},[],{"data":50367,"content":50368,"nodeType":876},{},[50369],{"data":50370,"marks":50371,"value":50372,"nodeType":867},{},[],"As an industry, we need to start looking at browser-based detection and response as the next logical evolution to stop identity attacks. There are clear parallels with the emergence of EDR – which came about because existing endpoint log sources were not sufficient. Today, we wouldn’t dream of trying to detect and respond to endpoint-based attacks without EDR – it’s time we started thinking about cloud identity attacks and the browser in the same way.  ","The web proxy is dead… long live the browser extension!","Right now the majority of detections for identity attacks rely on web proxy telemetry. Here’s why the browser can be a better alternative.","2024-06-11T00:00:00.000Z","the-web-proxy-is-dead-long-live-the-browser-extension",{"items":50378},[50379,50381],{"sys":50380,"name":342},{"id":3240},{"sys":50382,"name":4018},{"id":4017},{"items":50384},[50385],{"fullName":4022,"firstName":4023,"jobTitle":4024,"profilePicture":50386},{"url":4026},"push-introduces-support-for-arc-browser-securing-users-wherever-they-work","blog/push-introduces-support-for-arc-browser-securing-users-wherever-they-work",{"json":50390},{"data":50391,"content":50392,"nodeType":1680},{},[50393],{"data":50394,"content":50395,"nodeType":876},{},[50396],{"data":50397,"marks":50398,"value":50399,"nodeType":867},{},[],"As Push continues its quest to stop identity attacks, we are always looking for new ways to deliver our services across the different locales in which our users operate – namely, different browsers used in the workplace. ","We're adding support for Arc, an increasingly popular browser with developers and engineers.",{"id":50402,"publishedAt":50403},"2KBAkKHQfg4VJXIQDt64mm","2026-08-12T11:57:12.931Z",{"items":50405},[50406],{"sys":50407,"name":39245},{"id":39244},{"items":50409},[50410,50412,50414],{"sys":50411,"name":297,"slug":298,"tier":31},{"id":294},{"sys":50413,"name":413,"slug":414,"tier":31},{"id":410},{"sys":50415,"name":377,"slug":378,"tier":45},{"id":374},"X9GGDPLk9iGZ8wHv4BvQQepSZ6Jy8Oclc0qgsazwqqU",{"id":50418,"title":50419,"authorsCollection":50420,"content":50425,"extension":228,"faqItemsCollection":51813,"faqTitle":59,"featured":6,"hashTags":59,"meta":51815,"metaTitle":51816,"ogImage":59,"postType":1767,"publishedDate":51817,"relatedBlogPostsCollection":51818,"slug":56199,"stem":56200,"subtitle":59,"summary":56201,"synopsis":56219,"sys":56220,"tagsCollection":56223,"topicsCollection":56229,"__hash__":56275},"blog/blog/5-reasons-why-push-security-shouldnt-exist.json","5 reasons why Push Security shouldn’t exist",{"items":50421},[50422],{"fullName":4022,"firstName":4023,"jobTitle":4024,"socialLinks":50423,"profilePicture":50424},[21074],{"url":4026},{"json":50426,"links":51788},{"data":50427,"content":50428,"nodeType":1680},{},[50429,50449,50455,50462,50469,50490,50497,50500,50507,50514,50521,50528,50615,50622,50712,50720,50727,50734,50742,50745,50752,50759,50766,50795,50828,50857,50864,50871,50901,50908,50940,50947,50975,50982,50989,51016,51028,51035,51054,51085,51097,51100,51107,51127,51139,51157,51172,51179,51197,51227,51246,51253,51260,51278,51285,51293,51296,51303,51310,51348,51356,51363,51370,51377,51462,51486,51493,51500,51512,51531,51543,51546,51553,51560,51623,51641,51646,51649,51656,51685,51692,51699,51777,51782],{"data":50430,"content":50431,"nodeType":876},{},[50432,50436,50445],{"data":50433,"marks":50434,"value":50435,"nodeType":867},{},[],"If you caught ",{"data":50437,"content":50439,"nodeType":915},{"uri":50438},"https://cisoseries.com/securing-identities-in-the-cloud/",[50440],{"data":50441,"marks":50442,"value":50444,"nodeType":867},{},[50443],{"type":913},"our CEO Adam’s recent appearance on the Defense in Depth podcast",{"data":50446,"marks":50447,"value":50448,"nodeType":867},{},[]," you’ll have heard some top-tier banter between Geoff and David on the problem of identity security – and how, in Geoff’s words, “way too many people” think they’ve got it covered when it comes to identity attacks.",{"data":50450,"content":50454,"nodeType":985},{"target":50451},{"sys":50452},{"id":50453,"type":982,"linkType":983},"UcfFq2lOiMMJKaDfaNBqx",[],{"data":50456,"content":50457,"nodeType":876},{},[50458],{"data":50459,"marks":50460,"value":50461,"nodeType":867},{},[],"At Push, we’re constantly exploring the limits of controls against the latest threats. But naturally, security teams with hundreds of priorities can’t afford to dedicate the same amount of research time to this problem that we can. This means we come across a lot of common misconceptions about how controls like MFA, SSO and EDR perform against current identity attack techniques. ",{"data":50463,"content":50464,"nodeType":876},{},[50465],{"data":50466,"marks":50467,"value":50468,"nodeType":867},{},[],"These common misconceptions are severely impacting the ability of security teams to plan for, and defend against, identity-based attacks – giving attackers the window of opportunity they need to continue exploiting people and businesses. ",{"data":50470,"content":50471,"nodeType":876},{},[50472,50476,50481,50485],{"data":50473,"marks":50474,"value":50475,"nodeType":867},{},[],"So, we hope that this allows you a clearer perspective when building your identity security strategy, with a realistic view of what a particular control will give you – and what it won’t. ",{"data":50477,"marks":50478,"value":50480,"nodeType":867},{},[50479],{"type":865},"That isn’t to say you should discard any of these controls; they all have an important part to play! ",{"data":50482,"marks":50483,"value":50484,"nodeType":867},{},[],"But, it’s important to be aware of their limitations to be able to build a resilient security model, ",{"data":50486,"marks":50487,"value":50489,"nodeType":867},{},[50488],{"type":865},"with strategic defense in depth to compensate for known weaknesses. ",{"data":50491,"content":50492,"nodeType":876},{},[50493],{"data":50494,"marks":50495,"value":50496,"nodeType":867},{},[],"Without further ado, here are the top reasons why Push Security shouldn’t exist. ",{"data":50498,"content":50499,"nodeType":942},{},[],{"data":50501,"content":50502,"nodeType":868},{},[50503],{"data":50504,"marks":50505,"value":50506,"nodeType":867},{},[],"Reason 1: “Browser-based attacks aren’t a priority”",{"data":50508,"content":50509,"nodeType":876},{},[50510],{"data":50511,"marks":50512,"value":50513,"nodeType":867},{},[],"Particularly in the current economic climate, with many security teams feeling the squeeze, organizations often haven’t budgeted (mentally or financially) for a new kind of threat to factor into their modelling. ",{"data":50515,"content":50516,"nodeType":876},{},[50517],{"data":50518,"marks":50519,"value":50520,"nodeType":867},{},[],"We get it, now isn’t a great time to be tackling a new problem. Getting the budget to do the same as last year is difficult enough, never mind adding something new. ",{"data":50522,"content":50523,"nodeType":876},{},[50524],{"data":50525,"marks":50526,"value":50527,"nodeType":867},{},[],"But, there’s clear evidence that we're facing something a new kind of security problem. Modern attacks are consciously evading the network and endpoint, and are increasingly playing out entirely over the internet in the form of account takeover. ",{"data":50529,"content":50530,"nodeType":1629},{},[50531,50552,50572,50594],{"data":50532,"content":50533,"nodeType":1586},{},[50534],{"data":50535,"content":50536,"nodeType":876},{},[50537,50541,50548],{"data":50538,"marks":50539,"value":50540,"nodeType":867},{},[],"Stolen creds are the #1 breach vector in 79% of web app attacks (",{"data":50542,"content":50543,"nodeType":915},{"uri":7467},[50544],{"data":50545,"marks":50546,"value":45648,"nodeType":867},{},[50547],{"type":913},{"data":50549,"marks":50550,"value":50551,"nodeType":867},{},[],").  ",{"data":50553,"content":50554,"nodeType":1586},{},[50555],{"data":50556,"content":50557,"nodeType":876},{},[50558,50562,50569],{"data":50559,"marks":50560,"value":50561,"nodeType":867},{},[],"147,000 token replay attacks in 2023, 111% increase year-over-year (",{"data":50563,"content":50564,"nodeType":915},{"uri":44730},[50565],{"data":50566,"marks":50567,"value":11959,"nodeType":867},{},[50568],{"type":913},{"data":50570,"marks":50571,"value":23136,"nodeType":867},{},[],{"data":50573,"content":50574,"nodeType":1586},{},[50575],{"data":50576,"content":50577,"nodeType":876},{},[50578,50582,50591],{"data":50579,"marks":50580,"value":50581,"nodeType":867},{},[],"80% of attacks involve identity and compromised credentials (",{"data":50583,"content":50585,"nodeType":915},{"uri":50584},"https://www.crowdstrike.com/blog/relentless-threat-activity-puts-identities-in-the-crosshairs/",[50586],{"data":50587,"marks":50588,"value":50590,"nodeType":867},{},[50589],{"type":913},"Crowdstrike",{"data":50592,"marks":50593,"value":50551,"nodeType":867},{},[],{"data":50595,"content":50596,"nodeType":1586},{},[50597],{"data":50598,"content":50599,"nodeType":876},{},[50600,50604,50612],{"data":50601,"marks":50602,"value":50603,"nodeType":867},{},[],"4,000 password-based attacks per second observed (",{"data":50605,"content":50607,"nodeType":915},{"uri":50606},"https://www.microsoft.com/en-us/security/security-insider/microsoft-digital-defense-report-2023",[50608],{"data":50609,"marks":50610,"value":11959,"nodeType":867},{},[50611],{"type":913},{"data":50613,"marks":50614,"value":24243,"nodeType":867},{},[],{"data":50616,"content":50617,"nodeType":876},{},[50618],{"data":50619,"marks":50620,"value":50621,"nodeType":867},{},[],"It’s also telling that the cyber crime ecosystem itself seems to be leaning toward the theft, sale, and use of stolen credentials (not just emails and passwords, but session tokens too). ",{"data":50623,"content":50624,"nodeType":1629},{},[50625,50646,50668,50690],{"data":50626,"content":50627,"nodeType":1586},{},[50628],{"data":50629,"content":50630,"nodeType":876},{},[50631,50634,50642],{"data":50632,"marks":50633,"value":21,"nodeType":867},{},[],{"data":50635,"content":50636,"nodeType":915},{"uri":7467},[50637],{"data":50638,"marks":50639,"value":50641,"nodeType":867},{},[50640],{"type":913},"According to the 2024 DBIR",{"data":50643,"marks":50644,"value":50645,"nodeType":867},{},[],", more than 1000 credentials appear on criminal forums and marketplaces every day, with the majority (65%) appearing less than a day after first being discovered. ",{"data":50647,"content":50648,"nodeType":1586},{},[50649],{"data":50650,"content":50651,"nodeType":876},{},[50652,50656,50664],{"data":50653,"marks":50654,"value":50655,"nodeType":867},{},[],"In June, ",{"data":50657,"content":50658,"nodeType":915},{"uri":45994},[50659],{"data":50660,"marks":50661,"value":50663,"nodeType":867},{},[50662],{"type":913},"Troy Hunt at Have I Been Pwned (HIBP) wrote about the impact of channels like Telegram",{"data":50665,"marks":50666,"value":50667,"nodeType":867},{},[]," and the sale of combolists (username, password, login portal URL), after being sent 122GB of data scraped out of thousands of Telegram channels, containing 361M unique email addresses (of which 151M had never been seen in HIBP before). ",{"data":50669,"content":50670,"nodeType":1586},{},[50671],{"data":50672,"content":50673,"nodeType":876},{},[50674,50678,50687],{"data":50675,"marks":50676,"value":50677,"nodeType":867},{},[],"In July, ",{"data":50679,"content":50681,"nodeType":915},{"uri":50680},"https://cybernews.com/security/rockyou2024-largest-password-compilation-leak/",[50682],{"data":50683,"marks":50684,"value":50686,"nodeType":867},{},[50685],{"type":913},"10 billion passwords were leaked in the RockYou2024 compilation",{"data":50688,"marks":50689,"value":5704,"nodeType":867},{},[],{"data":50691,"content":50692,"nodeType":1586},{},[50693],{"data":50694,"content":50695,"nodeType":876},{},[50696,50700,50708],{"data":50697,"marks":50698,"value":50699,"nodeType":867},{},[],"And ultimately, ",{"data":50701,"content":50702,"nodeType":915},{"uri":37788},[50703],{"data":50704,"marks":50705,"value":50707,"nodeType":867},{},[50706],{"type":913},"high-profile breaches",{"data":50709,"marks":50710,"value":50711,"nodeType":867},{},[]," of Snowflake customers, Microsoft, Okta, and others reinforce the threat behind the numbers, all of which are the result of identity attacks. ",{"data":50713,"content":50714,"nodeType":876},{},[50715],{"data":50716,"marks":50717,"value":50719,"nodeType":867},{},[50718],{"type":865},"So, if a business uses any third-party provided web applications or services, then its workforce identities are the lowest-hanging fruit for attackers to pick, and the risk of account takeover should be high up on the risk register. ",{"data":50721,"content":50722,"nodeType":876},{},[50723],{"data":50724,"marks":50725,"value":50726,"nodeType":867},{},[],"Yes, it’s tough to redo budgets on the fly or rip up a five year plan. But, asymmetrical cyber TTPs have always sought to undermine the best laid plans of CISOs – attackers usually look in the places that defenders aren't. ",{"data":50728,"content":50729,"nodeType":876},{},[50730],{"data":50731,"marks":50732,"value":50733,"nodeType":867},{},[],"When looking at the evidence, is securing the identity attack surface really a lower priority than adding a CASB, CSPM, or shiny new AI tool? Even when we look at historical recurring spend on things like EDR or vulnerability management, it’s arguable that the risk of identity attacks has overtaken software-based exploits for many organizations whose traditional networks are shrinking, while their cloud app estate grows. ",{"data":50735,"content":50736,"nodeType":876},{},[50737],{"data":50738,"marks":50739,"value":50741,"nodeType":867},{},[50740],{"type":865},"It’s important to consider what’s right for your business, but the evidence shows us that securing the identity attack surface promises real risk reduction in the face of a genuine threat. ",{"data":50743,"content":50744,"nodeType":942},{},[],{"data":50746,"content":50747,"nodeType":868},{},[50748],{"data":50749,"marks":50750,"value":50751,"nodeType":867},{},[],"Reason 2: “Our business apps are all behind SSO”",{"data":50753,"content":50754,"nodeType":876},{},[50755],{"data":50756,"marks":50757,"value":50758,"nodeType":867},{},[],"SSO is often seen as a utopia where each employee has a single, secure digital identity that is used to access all of their work applications. When businesses are using SSO, we usually hear:",{"data":50760,"content":50761,"nodeType":1058},{},[50762],{"data":50763,"marks":50764,"value":50765,"nodeType":867},{},[],"“Everything is behind SSO, there are no apps outside of it.”",{"data":50767,"content":50768,"nodeType":876},{},[50769,50773,50782,50786,50791],{"data":50770,"marks":50771,"value":50772,"nodeType":867},{},[],"Unfortunately, organizations are always using more apps than they realize. The impact of ",{"data":50774,"content":50776,"nodeType":915},{"uri":50775},"https://productled.com/blog/product-led-growth-definition",[50777],{"data":50778,"marks":50779,"value":50781,"nodeType":867},{},[50780],{"type":913},"product-led growth",{"data":50783,"marks":50784,"value":50785,"nodeType":867},{},[]," on the self adoption of cloud services is well documented, and we see that ",{"data":50787,"marks":50788,"value":50790,"nodeType":867},{},[50789],{"type":865},"even SMEs typically have 100+ apps in their estate",{"data":50792,"marks":50793,"value":50794,"nodeType":867},{},[],", and the number of apps per business continues to grow year on year. ",{"data":50796,"content":50797,"nodeType":876},{},[50798,50802,50807,50811,50815,50819,50824],{"data":50799,"marks":50800,"value":50801,"nodeType":867},{},[],"So, while every ",{"data":50803,"marks":50804,"value":50806,"nodeType":867},{},[50805],{"type":865},"known ",{"data":50808,"marks":50809,"value":50810,"nodeType":867},{},[],"app",{"data":50812,"marks":50813,"value":2136,"nodeType":867},{},[50814],{"type":865},{"data":50816,"marks":50817,"value":50818,"nodeType":867},{},[],"might be behind SSO, this still leaves tens or hundreds of ",{"data":50820,"marks":50821,"value":50823,"nodeType":867},{},[50822],{"type":865},"unknown",{"data":50825,"marks":50826,"value":50827,"nodeType":867},{},[]," apps, with thousands of associated identities. ",{"data":50829,"content":50830,"nodeType":876},{},[50831,50835,50840,50844,50853],{"data":50832,"marks":50833,"value":50834,"nodeType":867},{},[],"But even if you did know about every app, the fact of the matter is ",{"data":50836,"marks":50837,"value":50839,"nodeType":867},{},[50838],{"type":865},"that fewer than 1 in 3 apps actually support SAML SSO",{"data":50841,"marks":50842,"value":50843,"nodeType":867},{},[],", and many of those ",{"data":50845,"content":50847,"nodeType":915},{"uri":50846},"https://sso.tax/",[50848],{"data":50849,"marks":50850,"value":50852,"nodeType":867},{},[50851],{"type":913},"only at the premium tier",{"data":50854,"marks":50855,"value":50856,"nodeType":867},{},[],". Our data shows that the proportion of apps actually behind SSO is even lower, at 1 in 5. So getting everything behind SSO just isn’t a realistic goal for any organization. ",{"data":50858,"content":50859,"nodeType":1058},{},[50860],{"data":50861,"marks":50862,"value":50863,"nodeType":867},{},[],"“Everything important is behind SSO, and the apps that aren’t don’t pose a risk.” ",{"data":50865,"content":50866,"nodeType":876},{},[50867],{"data":50868,"marks":50869,"value":50870,"nodeType":867},{},[],"There’s often a view that if it wasn’t centrally procured, IT wasn’t involved, and it’s not behind SSO, then it’s just not a concern. But apps can have complex integrations and permissions that increase the potential blast radius of an app compromise. ",{"data":50872,"content":50873,"nodeType":876},{},[50874,50878,50886,50890,50897],{"data":50875,"marks":50876,"value":50877,"nodeType":867},{},[],"We’ve published ",{"data":50879,"content":50880,"nodeType":915},{"uri":15408},[50881],{"data":50882,"marks":50883,"value":50885,"nodeType":867},{},[50884],{"type":913},"extensive research on SaaS-native attack techniques",{"data":50887,"marks":50888,"value":50889,"nodeType":867},{},[]," and documented many of the scenarios in which attackers can expand from hijacking a single SaaS app with a small number of users into a larger-scale compromise, for example through ",{"data":50891,"content":50892,"nodeType":915},{"uri":5013},[50893],{"data":50894,"marks":50895,"value":22222,"nodeType":867},{},[50896],{"type":913},{"data":50898,"marks":50899,"value":50900,"nodeType":867},{},[],": Modifying SAML for a compromised app to redirect users to a malicious domain during the authentication process that proxies a legitimate authentication service (e.g. Google, Okta or Microsoft) – effectively acting as a watering hole for further credential harvesting. ",{"data":50902,"content":50903,"nodeType":876},{},[50904],{"data":50905,"marks":50906,"value":50907,"nodeType":867},{},[],"Also, the value of an app is not necessarily tied to the number of users it has in the business. A sales and marketing app can contain huge amounts of sensitive data, as can developer apps – just look at Snowflake! It only takes a single account to be created, a single integration to be set up, to result in a major data breach down the line. ",{"data":50909,"content":50910,"nodeType":876},{},[50911,50915,50924,50927,50936],{"data":50912,"marks":50913,"value":50914,"nodeType":867},{},[],"You can check out our ",{"data":50916,"content":50918,"nodeType":915},{"uri":50917},"https://pushsecurity.com/blog/",[50919],{"data":50920,"marks":50921,"value":50923,"nodeType":867},{},[50922],{"type":913},"blog page",{"data":50925,"marks":50926,"value":21631,"nodeType":867},{},[],{"data":50928,"content":50930,"nodeType":915},{"uri":50929},"https://www.youtube.com/watch?v=xZIQd_0v9sE&t=12s",[50931],{"data":50932,"marks":50933,"value":50935,"nodeType":867},{},[50934],{"type":913},"watch one of our videos",{"data":50937,"marks":50938,"value":50939,"nodeType":867},{},[]," for more information.   ",{"data":50941,"content":50942,"nodeType":1058},{},[50943],{"data":50944,"marks":50945,"value":50946,"nodeType":867},{},[],"Ghost logins: A nightmare for SSO, dreamy for attackers",{"data":50948,"content":50949,"nodeType":876},{},[50950,50954,50959,50963,50971],{"data":50951,"marks":50952,"value":50953,"nodeType":867},{},[],"You might already be feeling a bit deflated that SSO isn’t going to give you everything you wanted, and we’re sorry to be the bearer of bad news. Unfortunately, ",{"data":50955,"marks":50956,"value":50958,"nodeType":867},{},[50957],{"type":865},"even if you are using SSO, additional login methods can still exist alongside SSO",{"data":50960,"marks":50961,"value":50962,"nodeType":867},{},[],". We call these ",{"data":50964,"content":50965,"nodeType":915},{"uri":26236},[50966],{"data":50967,"marks":50968,"value":2929,"nodeType":867},{},[50969,50970],{"type":913},{"type":865},{"data":50972,"marks":50973,"value":5704,"nodeType":867},{},[50974],{"type":865},{"data":50976,"content":50977,"nodeType":876},{},[50978],{"data":50979,"marks":50980,"value":50981,"nodeType":867},{},[],"Ghost logins are effectively any alternative login method. In addition to SSO, you could have a local password, a social login (e.g., login with Google, Facebook, etc.), backup emails, or API-based login methods. ",{"data":50983,"content":50984,"nodeType":876},{},[50985],{"data":50986,"marks":50987,"value":50988,"nodeType":867},{},[],"Multiple methods are often enabled by default and need to be explicitly disabled at the app level. Further, migrating an existing app to SSO doesn’t automatically remove local accounts, but effectively adds an SSO layer on top. ",{"data":50990,"content":50991,"nodeType":876},{},[50992,50996,51001,51005,51013],{"data":50993,"marks":50994,"value":50995,"nodeType":867},{},[],"The final problem here is that because MFA is applied separately at the app level and SSO level, ",{"data":50997,"marks":50998,"value":51000,"nodeType":867},{},[50999],{"type":865},"you can have local logins without MFA, at the same time as SSO logins with MFA — that can be used concurrently.",{"data":51002,"marks":51003,"value":51004,"nodeType":867},{},[]," This was acutely felt during the recent Snowflake breaches, ",{"data":51006,"content":51007,"nodeType":915},{"uri":42382},[51008],{"data":51009,"marks":51010,"value":51012,"nodeType":867},{},[51011],{"type":913},"where in-app identification and disabling of non-SSO logins proved to be particularly error-prone",{"data":51014,"marks":51015,"value":24572,"nodeType":867},{},[],{"data":51017,"content":51018,"nodeType":876},{},[51019,51023],{"data":51020,"marks":51021,"value":51022,"nodeType":867},{},[],"The result here is that credential stuffing attacks can still prove successful against your SSO-joined apps if local logins exist, and MFA hasn’t been specifically set at the app level. ",{"data":51024,"marks":51025,"value":51027,"nodeType":867},{},[51026],{"type":865},"And unless you’ve specifically disabled them and unset every non-SSO login for every app, they probably do. ",{"data":51029,"content":51030,"nodeType":1058},{},[51031],{"data":51032,"marks":51033,"value":51034,"nodeType":867},{},[],"The verdict: SSO is great, but it's no silver bullet",{"data":51036,"content":51037,"nodeType":876},{},[51038,51042,51050],{"data":51039,"marks":51040,"value":51041,"nodeType":867},{},[],"While SSO is invariably a beneficial security control, ",{"data":51043,"content":51045,"nodeType":915},{"uri":51044},"https://pushsecurity.com/blog/ghost-logins-when-forgotten-identities-come-back-to-haunt-you/#id-how-can-ghost-logins-be-abused-by-attackers_id-ghost-logins-for-persistence-and-defense-evasion",[51046],{"data":51047,"marks":51048,"value":51049,"nodeType":867},{},[],"attackers can also naturally exploit it to gain access to a large number of downstream applications",{"data":51051,"marks":51052,"value":51053,"nodeType":867},{},[],". If you compromise an IdP account like Okta, you can then access any connected app, often without requiring any further authentication.",{"data":51055,"content":51056,"nodeType":876},{},[51057,51061,51070,51073,51082],{"data":51058,"marks":51059,"value":51060,"nodeType":867},{},[],"We’ve seen this recently, with an ",{"data":51062,"content":51064,"nodeType":915},{"uri":51063},"https://www.bleepingcomputer.com/news/security/okta-warns-of-unprecedented-credential-stuffing-attacks-on-customers/",[51065],{"data":51066,"marks":51067,"value":51069,"nodeType":867},{},[51068],{"type":913},"unprecedented spike in credential stuffing attacks reported by Okta",{"data":51071,"marks":51072,"value":46810,"nodeType":867},{},[],{"data":51074,"content":51076,"nodeType":915},{"uri":51075},"https://www.bleepingcomputer.com/news/security/okta-warns-of-credential-stuffing-attacks-targeting-its-cors-feature/",[51077],{"data":51078,"marks":51079,"value":51081,"nodeType":867},{},[51080],{"type":913},"attacks looking to exploit Okta’s CORS feature",{"data":51083,"marks":51084,"value":5704,"nodeType":867},{},[],{"data":51086,"content":51087,"nodeType":876},{},[51088,51093],{"data":51089,"marks":51090,"value":51092,"nodeType":867},{},[51091],{"type":865},"Ultimately, the promised land of a 1:1 employee to identity ratio just isn’t realistic. ",{"data":51094,"marks":51095,"value":51096,"nodeType":867},{},[],"So while SSO is a big part of the solution to identity attacks, it’s not a silver bullet.   ",{"data":51098,"content":51099,"nodeType":942},{},[],{"data":51101,"content":51102,"nodeType":868},{},[51103],{"data":51104,"marks":51105,"value":51106,"nodeType":867},{},[],"Reason 3: “We’ve got MFA deployed everywhere”",{"data":51108,"content":51109,"nodeType":876},{},[51110,51114,51123],{"data":51111,"marks":51112,"value":51113,"nodeType":867},{},[],"Microsoft famously stated that ",{"data":51115,"content":51117,"nodeType":915},{"uri":51116},"https://www.microsoft.com/en-us/security/security-insider/microsoft-digital-defense-report-2023#:~:text=Outlier%20attacks%20make%20up%20just,of%20compromise%20by%2099.2%20percent.",[51118],{"data":51119,"marks":51120,"value":51122,"nodeType":867},{},[51121],{"type":913},"MFA reduces the risk of compromise by 99.2%",{"data":51124,"marks":51125,"value":51126,"nodeType":867},{},[],". But this doesn’t mean that it stops 99% of attacks. Or, that it should make up 99% of your defense. ",{"data":51128,"content":51129,"nodeType":876},{},[51130,51134],{"data":51131,"marks":51132,"value":51133,"nodeType":867},{},[],"MFA unarguably raises the bar for attackers, even if that bar is still pretty low. Naturally, accounts without MFA are an easier target. ",{"data":51135,"marks":51136,"value":51138,"nodeType":867},{},[51137],{"type":865},"But the problem is that MFA isn’t an enterprise-wide castle wall. It’s more like a row of hurdles with gaps in-between. ",{"data":51140,"content":51141,"nodeType":876},{},[51142,51146,51154],{"data":51143,"marks":51144,"value":51145,"nodeType":867},{},[],"MFA is usually handled separately at the SSO level and app level. For apps that are self-adopted by end users, they can't be relied on to add in a security control that will introduce friction to their user experience. Building on the aforementioned ghost logins, even if MFA is adopted at the SSO level, local logins can exist without MFA unless also applied at the app level. ",{"data":51147,"content":51148,"nodeType":915},{"uri":42382},[51149],{"data":51150,"marks":51151,"value":51153,"nodeType":867},{},[51152],{"type":913},"The recent Snowflake breach is a perfect example of this problem",{"data":51155,"marks":51156,"value":5704,"nodeType":867},{},[],{"data":51158,"content":51159,"nodeType":876},{},[51160,51164,51169],{"data":51161,"marks":51162,"value":51163,"nodeType":867},{},[],"Because of this, ",{"data":51165,"marks":51166,"value":51168,"nodeType":867},{},[51167],{"type":865},"we find that only around 1 in 3 identities actually have MFA enabled",{"data":51170,"marks":51171,"value":5704,"nodeType":867},{},[],{"data":51173,"content":51174,"nodeType":1058},{},[51175],{"data":51176,"marks":51177,"value":51178,"nodeType":867},{},[],"\"MFA protects us against phishing attacks\"",{"data":51180,"content":51181,"nodeType":876},{},[51182,51186,51193],{"data":51183,"marks":51184,"value":51185,"nodeType":867},{},[],"Even where MFA is deployed, most MFA methods are proven to be phishable or otherwise bypassable. SMS and push-based MFA are susceptible to well known bypasses including SIM swapping and ",{"data":51187,"content":51188,"nodeType":915},{"uri":38031},[51189],{"data":51190,"marks":51191,"value":38036,"nodeType":867},{},[51192],{"type":913},{"data":51194,"marks":51195,"value":51196,"nodeType":867},{},[]," attacks. TOTP is a little better, but still vulnerable. ",{"data":51198,"content":51199,"nodeType":876},{},[51200,51204,51212,51216,51224],{"data":51201,"marks":51202,"value":51203,"nodeType":867},{},[],"Many attacks are simply cutting out the middleman and focusing on ",{"data":51205,"content":51206,"nodeType":915},{"uri":42165},[51207],{"data":51208,"marks":51209,"value":51211,"nodeType":867},{},[51210],{"type":913},"using stolen session tokens",{"data":51213,"marks":51214,"value":51215,"nodeType":867},{},[]," to bypass MFA. The most common method for this is via infostealers, which typically scrape all credentials (e.g. usernames, passwords, login pages, session tokens) as well as other information stored in the browser of an infected device. ",{"data":51217,"content":51218,"nodeType":915},{"uri":46217},[51219],{"data":51220,"marks":51221,"value":51223,"nodeType":867},{},[51222],{"type":913},"Infostealers played a major role in the recent Snowflake breach",{"data":51225,"marks":51226,"value":5704,"nodeType":867},{},[],{"data":51228,"content":51229,"nodeType":876},{},[51230,51234,51242],{"data":51231,"marks":51232,"value":51233,"nodeType":867},{},[],"Additionally, ",{"data":51235,"content":51236,"nodeType":915},{"uri":38018},[51237],{"data":51238,"marks":51239,"value":51241,"nodeType":867},{},[51240],{"type":913},"modern phishing techniques like adversary-in-the-middle (AitM) and browser-in-the-middle (BitM)",{"data":51243,"marks":51244,"value":51245,"nodeType":867},{},[]," see the attacker steal the live session and associated tokens from the victim, with the victim prompted to complete the MFA process as part of the attack. ",{"data":51247,"content":51248,"nodeType":1058},{},[51249],{"data":51250,"marks":51251,"value":51252,"nodeType":867},{},[],"“We’re using passkeys”",{"data":51254,"content":51255,"nodeType":876},{},[51256],{"data":51257,"marks":51258,"value":51259,"nodeType":867},{},[],"Great! Passkey users are in a better position than 99% of other businesses. Passkeys are widely accepted to be phishing resistant – at least for now, although as more businesses use them, new ways of getting around them will no doubt be discovered by attackers. ",{"data":51261,"content":51262,"nodeType":876},{},[51263,51267,51275],{"data":51264,"marks":51265,"value":51266,"nodeType":867},{},[],"But, MFA downgrade attacks are possible. There are often backup MFA methods set that can be selected by canceling the authentication prompt and selecting a different method. Even when these aren’t selectable, ",{"data":51268,"content":51269,"nodeType":915},{"uri":26138},[51270],{"data":51271,"marks":51272,"value":51274,"nodeType":867},{},[51273],{"type":913},"researchers have demonstrated ways of downgrading authentication to use a phishable method",{"data":51276,"marks":51277,"value":5704,"nodeType":867},{},[],{"data":51279,"content":51280,"nodeType":876},{},[51281],{"data":51282,"marks":51283,"value":51284,"nodeType":867},{},[],"Most apps are designed primarily for user flexibility, not security. And backup methods have a legitimate use-case – what if the authenticator device is lost or stops working? If passkeys are the only authentication method, you just got locked out of all of your accounts. But at least no hackers can access them either, right?",{"data":51286,"content":51287,"nodeType":876},{},[51288],{"data":51289,"marks":51290,"value":51292,"nodeType":867},{},[51291],{"type":865},"Like SSO, unless backup MFA methods are disabled for all identities and apps, and all users have enabled MFA across all their accounts and login methods, this isn’t a silver bullet either.  ",{"data":51294,"content":51295,"nodeType":942},{},[],{"data":51297,"content":51298,"nodeType":868},{},[51299],{"data":51300,"marks":51301,"value":51302,"nodeType":867},{},[],"Reason 4: “We’ve got anti-phishing controls already”",{"data":51304,"content":51305,"nodeType":876},{},[51306],{"data":51307,"marks":51308,"value":51309,"nodeType":867},{},[],"Identity attacks have evolved significantly in recent years, as have the environments being targeted by attackers with the shift to cloud services and decentralized business IT. Unfortunately, traditional anti-phishing controls weren’t designed for this reality. ",{"data":51311,"content":51312,"nodeType":1629},{},[51313,51333],{"data":51314,"content":51315,"nodeType":1586},{},[51316],{"data":51317,"content":51318,"nodeType":876},{},[51319,51324,51329],{"data":51320,"marks":51321,"value":51323,"nodeType":867},{},[51322],{"type":865},"A",{"data":51325,"marks":51326,"value":51328,"nodeType":867},{},[51327],{"type":865},"ttacks used to be focused on a single VPN/webmail endpoint ",{"data":51330,"marks":51331,"value":51332,"nodeType":867},{},[],"that was naturally easier to protect than 100+ SaaS apps (especially if the security team isn’t even aware of them). Attackers now have 1000s of sprawled identities to target per enterprise, increasing the chance that weak or reused passwords will be found. ",{"data":51334,"content":51335,"nodeType":1586},{},[51336],{"data":51337,"content":51338,"nodeType":876},{},[51339,51344],{"data":51340,"marks":51341,"value":51343,"nodeType":867},{},[51342],{"type":865},"Likewise, security teams only needed to care about a small set of credentials ",{"data":51345,"marks":51346,"value":51347,"nodeType":867},{},[],"relating to user directory accounts and VPN/remote access tooling used to tunnel into the corporate network. Now, business functions and data are dispersed across cloud apps rather than being neatly contained in on-prem apps and databases.",{"data":51349,"content":51350,"nodeType":876},{},[51351],{"data":51352,"marks":51353,"value":51355,"nodeType":867},{},[51354],{"type":865},"Now, attackers have more platforms on which to phish your users, more credentials to choose from, and more apps to spray them across, while security teams have a much larger surface to defend.",{"data":51357,"content":51358,"nodeType":1058},{},[51359],{"data":51360,"marks":51361,"value":51362,"nodeType":867},{},[],"“Our email and content filtering controls stop phishing attacks”",{"data":51364,"content":51365,"nodeType":876},{},[51366],{"data":51367,"marks":51368,"value":51369,"nodeType":867},{},[],"Existing phishing prevention solutions have tried to solve the problem by protecting the inbox, a common (but not the only) attack vector, or by blocking lists of known-bad domains. ",{"data":51371,"content":51372,"nodeType":876},{},[51373],{"data":51374,"marks":51375,"value":51376,"nodeType":867},{},[],"But, these approaches have major shortcomings:",{"data":51378,"content":51379,"nodeType":1629},{},[51380,51420,51435],{"data":51381,"content":51382,"nodeType":1586},{},[51383],{"data":51384,"content":51385,"nodeType":876},{},[51386,51391,51395,51404,51407,51416],{"data":51387,"marks":51388,"value":51390,"nodeType":867},{},[51389],{"type":865},"Incomplete coverage: ",{"data":51392,"marks":51393,"value":51394,"nodeType":867},{},[],"Email-based phishing prevention tools can catch general spray-and-pray email phishing campaigns, but it only takes a small amount of tailoring to fly under their radar. The use of LLM tools to tailor phishing emails for their intended victims already makes this possible at scale. Email-based tools also fail to cover phishing attacks beyond the inbox, such as ",{"data":51396,"content":51398,"nodeType":915},{"uri":51397},"https://pushsecurity.com/blog/slack-phishing-for-initial-access/",[51399],{"data":51400,"marks":51401,"value":51403,"nodeType":867},{},[51402],{"type":913},"Slack",{"data":51405,"marks":51406,"value":1174,"nodeType":867},{},[],{"data":51408,"content":51410,"nodeType":915},{"uri":51409},"https://pushsecurity.com/blog/phishing-microsoft-teams-for-initial-access/",[51411],{"data":51412,"marks":51413,"value":51415,"nodeType":867},{},[51414],{"type":913},"Teams",{"data":51417,"marks":51418,"value":51419,"nodeType":867},{},[]," phishing.",{"data":51421,"content":51422,"nodeType":1586},{},[51423],{"data":51424,"content":51425,"nodeType":876},{},[51426,51431],{"data":51427,"marks":51428,"value":51430,"nodeType":867},{},[51429],{"type":865},"Expired intel: ",{"data":51432,"marks":51433,"value":51434,"nodeType":867},{},[],"Tools that rely on known-bad domains always have an incomplete picture because a domain must be reported as malicious in order to get added to a blocklist. Meanwhile, attackers can spin up new sites or host phishing pages on existing sites by exploiting vulnerabilities in them, bypassing rules around preventing visits to newly registered domains. It’s like trying to hit a moving target.",{"data":51436,"content":51437,"nodeType":1586},{},[51438],{"data":51439,"content":51440,"nodeType":876},{},[51441,51446,51450,51458],{"data":51442,"marks":51443,"value":51445,"nodeType":867},{},[51444],{"type":865},"Web-based obfuscation: ",{"data":51447,"marks":51448,"value":51449,"nodeType":867},{},[],"Attacker tools and malicious implants running on webpages are constantly evolving to evade fingerprinting, and attackers are using techniques like ",{"data":51451,"content":51452,"nodeType":915},{"uri":50024},[51453],{"data":51454,"marks":51455,"value":51457,"nodeType":867},{},[51456],{"type":913},"HTML smuggling",{"data":51459,"marks":51460,"value":51461,"nodeType":867},{},[]," to get around web-based controls put in place by developers. ",{"data":51463,"content":51464,"nodeType":876},{},[51465,51469,51474,51478,51483],{"data":51466,"marks":51467,"value":51468,"nodeType":867},{},[],"Even if these controls are sometimes successful, attackers have reliably demonstrated ways to get around them, ",{"data":51470,"marks":51471,"value":51473,"nodeType":867},{},[51472],{"type":865},"it really is a cat-and-mouse game at this point",{"data":51475,"marks":51476,"value":51477,"nodeType":867},{},[],". There usually needs to be a compromise before the attacker's infrastructure or tooling can be tagged and blocked, but ",{"data":51479,"marks":51480,"value":51482,"nodeType":867},{},[51481],{"type":865},"they evolve so rapidly that defenders are always one step behind",{"data":51484,"marks":51485,"value":5704,"nodeType":867},{},[],{"data":51487,"content":51488,"nodeType":1058},{},[51489],{"data":51490,"marks":51491,"value":51492,"nodeType":867},{},[],"“All our employees use a password manager”",{"data":51494,"content":51495,"nodeType":876},{},[51496],{"data":51497,"marks":51498,"value":51499,"nodeType":867},{},[],"Password managers are increasingly necessary due to the large number of credentials that users now have to juggle. Since the majority of apps don’t support SAML SSO, the need for separate credentials per app isn’t going away any time soon. ",{"data":51501,"content":51502,"nodeType":876},{},[51503,51507],{"data":51504,"marks":51505,"value":51506,"nodeType":867},{},[],"We often find 2 or more password managers in use per organization (not exactly optimal), but despite increased password manager adoption we see consistently high levels of password reuse, ",{"data":51508,"marks":51509,"value":51511,"nodeType":867},{},[51510],{"type":865},"with 1 in 3 users reusing passwords – including their sensitive IdP credentials. ",{"data":51513,"content":51514,"nodeType":876},{},[51515,51519,51527],{"data":51516,"marks":51517,"value":51518,"nodeType":867},{},[],"High levels of password reuse shows us that password managers don’t automatically result in secure employee behaviors, while widespread credential reuse significantly increases exposure to ",{"data":51520,"content":51521,"nodeType":915},{"uri":37942},[51522],{"data":51523,"marks":51524,"value":51526,"nodeType":867},{},[51525],{"type":913},"credential stuffing attacks",{"data":51528,"marks":51529,"value":51530,"nodeType":867},{},[]," where attackers spray known username and password combinations across a range of app login pages.  ",{"data":51532,"content":51533,"nodeType":876},{},[51534,51539],{"data":51535,"marks":51536,"value":51538,"nodeType":867},{},[51537],{"type":865},"Generally, businesses have very limited visibility into employee password data",{"data":51540,"marks":51541,"value":51542,"nodeType":867},{},[]," to be able to enforce good practice or accurately respond to data breaches involving credential dumps, even if employees are using a password manager (or several, as the case may be).  ",{"data":51544,"content":51545,"nodeType":942},{},[],{"data":51547,"content":51548,"nodeType":868},{},[51549],{"data":51550,"marks":51551,"value":51552,"nodeType":867},{},[],"Reason 5: “We’ve got all the security data we need”",{"data":51554,"content":51555,"nodeType":876},{},[51556],{"data":51557,"marks":51558,"value":51559,"nodeType":867},{},[],"Organizations looking to protect themselves from modern identity attacks suffer from a pretty substantial telemetry gap. ",{"data":51561,"content":51562,"nodeType":1629},{},[51563,51578,51593,51608],{"data":51564,"content":51565,"nodeType":1586},{},[51566],{"data":51567,"content":51568,"nodeType":876},{},[51569,51574],{"data":51570,"marks":51571,"value":51573,"nodeType":867},{},[51572],{"type":865},"Endpoint logs ",{"data":51575,"marks":51576,"value":51577,"nodeType":867},{},[],"won’t show anything meaningful because most identity attacks don’t need to target the endpoint – no malware is deployed, everything happens in the browser, over the internet. ",{"data":51579,"content":51580,"nodeType":1586},{},[51581],{"data":51582,"content":51583,"nodeType":876},{},[51584,51589],{"data":51585,"marks":51586,"value":51588,"nodeType":867},{},[51587],{"type":865},"Application logs",{"data":51590,"marks":51591,"value":51592,"nodeType":867},{},[]," are limited in availability, scope, and ease of ingestion, with most app vendors providing substandard logging, and requiring complex custom integrations to get what little data is available. ",{"data":51594,"content":51595,"nodeType":1586},{},[51596],{"data":51597,"content":51598,"nodeType":876},{},[51599,51604],{"data":51600,"marks":51601,"value":51603,"nodeType":867},{},[51602],{"type":865},"Network logs",{"data":51605,"marks":51606,"value":51607,"nodeType":867},{},[]," (such as via web proxy) struggle to gather and piece together identity data points at-scale, across different apps, due to the sheer volume and broken format of the data post-TLS-termination. ",{"data":51609,"content":51610,"nodeType":1586},{},[51611],{"data":51612,"content":51613,"nodeType":876},{},[51614,51619],{"data":51615,"marks":51616,"value":51618,"nodeType":867},{},[51617],{"type":865},"Identity provider logs",{"data":51620,"marks":51621,"value":51622,"nodeType":867},{},[]," naturally only cover SSO integrated apps (and therefore don’t cover ⅔ of your business apps) and look exclusively at authentication, and so are blind to client side attacks like phishing. ",{"data":51624,"content":51625,"nodeType":876},{},[51626,51630,51638],{"data":51627,"marks":51628,"value":51629,"nodeType":867},{},[],"Unless you’re ingesting data from a browser-based solution like Push, it’s unlikely you have a full monitoring visibility of your identity attack surface. ",{"data":51631,"content":51632,"nodeType":915},{"uri":27034},[51633],{"data":51634,"marks":51635,"value":51637,"nodeType":867},{},[51636],{"type":913},"Read more on the value of browser telemetry here. ",{"data":51639,"marks":51640,"value":21,"nodeType":867},{},[],{"data":51642,"content":51645,"nodeType":985},{"target":51643},{"sys":51644},{"id":50358,"type":982,"linkType":983},[],{"data":51647,"content":51648,"nodeType":942},{},[],{"data":51650,"content":51651,"nodeType":868},{},[51652],{"data":51653,"marks":51654,"value":51655,"nodeType":867},{},[],"Maybe there’s a reason for Push to exist after all!",{"data":51657,"content":51658,"nodeType":876},{},[51659,51664,51668,51673,51676,51681],{"data":51660,"marks":51661,"value":51663,"nodeType":867},{},[51662],{"type":865},"The key takeaway here is that there are no quick fixes or silver bullets. ",{"data":51665,"marks":51666,"value":51667,"nodeType":867},{},[],"Things like SSO, MFA, and password managers are all part of the solution, ",{"data":51669,"marks":51670,"value":51672,"nodeType":867},{},[51671],{"type":865},"but",{"data":51674,"marks":51675,"value":2136,"nodeType":867},{},[],{"data":51677,"marks":51678,"value":51680,"nodeType":867},{},[51679],{"type":865},"aren’t set-and-forget controls",{"data":51682,"marks":51683,"value":51684,"nodeType":867},{},[],". They need to be continually monitored and maintained to ensure they remain effective.",{"data":51686,"content":51687,"nodeType":876},{},[51688],{"data":51689,"marks":51690,"value":51691,"nodeType":867},{},[],"Push stops identity attacks by continually finding and fixing identity vulnerabilities, providing deep context to manage the identity attack surface without looking through blinkers at the IdP or individual apps. ",{"data":51693,"content":51694,"nodeType":876},{},[51695],{"data":51696,"marks":51697,"value":51698,"nodeType":867},{},[],"Push helps businesses to get the most out of their identity controls (and bridge the gaps they leave) by:",{"data":51700,"content":51701,"nodeType":1629},{},[51702,51717,51732,51747,51762],{"data":51703,"content":51704,"nodeType":1586},{},[51705],{"data":51706,"content":51707,"nodeType":876},{},[51708,51713],{"data":51709,"marks":51710,"value":51712,"nodeType":867},{},[51711],{"type":865},"Locating all business apps",{"data":51714,"marks":51715,"value":51716,"nodeType":867},{},[],", not just those plugged into your IdP, so they can be put behind SSO (where possible) or at least securely managed and configured.",{"data":51718,"content":51719,"nodeType":1586},{},[51720],{"data":51721,"content":51722,"nodeType":876},{},[51723,51728],{"data":51724,"marks":51725,"value":51727,"nodeType":867},{},[51726],{"type":865},"Identifying all workforce identities, associated login types, and MFA methods",{"data":51729,"marks":51730,"value":51731,"nodeType":867},{},[]," to more clearly pinpoint gaps, harden identities, and remediate vulnerabilities like ghost logins.",{"data":51733,"content":51734,"nodeType":1586},{},[51735],{"data":51736,"content":51737,"nodeType":876},{},[51738,51743],{"data":51739,"marks":51740,"value":51742,"nodeType":867},{},[51741],{"type":865},"Stopping account takeover attempts",{"data":51744,"marks":51745,"value":51746,"nodeType":867},{},[]," by detecting and blocking AitM and BitM phishing toolkits running on webpages, blocking sensitive credential reuse to prevent credential phishing, and identifying stolen sessions running in attacker browsers. ",{"data":51748,"content":51749,"nodeType":1586},{},[51750],{"data":51751,"content":51752,"nodeType":876},{},[51753,51758],{"data":51754,"marks":51755,"value":51757,"nodeType":867},{},[51756],{"type":865},"Preventing password-based attacks",{"data":51759,"marks":51760,"value":51761,"nodeType":867},{},[]," by detecting the use of weak, reused, and breached passwords across the app estate.  ",{"data":51763,"content":51764,"nodeType":1586},{},[51765],{"data":51766,"content":51767,"nodeType":876},{},[51768,51773],{"data":51769,"marks":51770,"value":51772,"nodeType":867},{},[51771],{"type":865},"Providing unique telemetry in the browser",{"data":51774,"marks":51775,"value":51776,"nodeType":867},{},[]," to build both proactive and reactive security operations workflows, or add missing context to other data sources, such as IdP, application, or endpoint logs.",{"data":51778,"content":51781,"nodeType":985},{"target":51779},{"sys":51780},{"id":38137,"type":982,"linkType":983},[],{"data":51783,"content":51784,"nodeType":876},{},[51785],{"data":51786,"marks":51787,"value":21,"nodeType":867},{},[],{"entries":51789},{"hyperlink":51790,"inline":51791,"block":51792},[],[],[51793,51800,51808],{"sys":51794,"__typename":1688,"title":51795,"caption":51796,"layoutMode":59,"file":51797},{"id":50453},"Nobody has any identity problems, right?","Push Security’s cheekiest advisor, Geoff Belknap.",{"url":51798,"width":51799,"height":51799},"https://images.ctfassets.net/y1cdw1ablpvd/28qcLq225o8kusjQQQUnCC/98b10fe4f9e6916eb7657f60ab869062/Geoff_Ad__1_.png",1210,{"sys":51801,"__typename":1688,"title":51802,"caption":51803,"layoutMode":59,"file":51804},{"id":50358},"Telemetry comparison table","The browser presents a significant advantage over other sources of identity attack data.",{"url":51805,"width":51806,"height":51807},"https://images.ctfassets.net/y1cdw1ablpvd/4feAEpfP6tetyTjcLIopwG/5bec8c8c10e6e328ebe258bc59bc3cb6/Frame_627570__7_.png",2444,894,{"sys":51809,"__typename":1697,"type":51810,"ctaText":51811,"buttonLabel":51812,"buttonColour":1701,"buttonUrl":59},{"id":38137},"Demo","Book a demo to see how Push stops account takeover","Book demo",{"items":51814},[],{},"Tackling common browser & identity security misconceptions","2024-07-11T00:00:00.000Z",{"items":51819},[51820,54780,55469],{"__typename":1772,"sys":51821,"content":51822,"title":54766,"synopsis":54767,"hashTags":59,"publishedDate":54768,"slug":54769,"tagsCollection":54770,"authorsCollection":54776},{"id":45037},{"json":51823},{"data":51824,"content":51825,"nodeType":1680},{},[51826,51833,51865,51872,51878,51885,51905,51928,51935,51942,51966,51982,51989,52001,52008,52011,52018,52025,52041,52053,52064,52094,52097,52104,52122,52129,52137,52232,52239,52377,52384,52502,52509,52516,52687,52694,52701,52784,52787,52794,52801,52808,52871,52878,52911,52918,52961,52967,52973,53206,53212,53220,53227,53230,53237,53244,53251,53304,53311,53354,53361,53394,53400,53406,53572,53578,53586,53593,53601,53608,53616,53623,53626,53633,53640,53647,53710,53717,53750,53757,53790,53796,53802,53908,53911,53918,53925,53932,53995,54002,54035,54042,54075,54081,54087,54261,54264,54271,54278,54285,54358,54365,54398,54405,54438,54444,54450,54680,54683,54690,54697,54704,54711,54714,54721,54728,54735,54738,54745,54752,54759],{"data":51827,"content":51828,"nodeType":868},{},[51829],{"data":51830,"marks":51831,"value":51832,"nodeType":867},{},[],"Browser-based Identity attacks on the rise?",{"data":51834,"content":51835,"nodeType":876},{},[51836,51840,51849,51853,51862],{"data":51837,"marks":51838,"value":51839,"nodeType":867},{},[],"Identity has been recorded as the #1 cyber attack vector since forever. You don’t have to look particularly hard to find statistics to support this. In 2023, one source reports that ",{"data":51841,"content":51843,"nodeType":915},{"uri":51842},"https://www.csoonline.com/article/648894/identity-based-security-threats-are-growing-rapidly-report.html",[51844],{"data":51845,"marks":51846,"value":51848,"nodeType":867},{},[51847],{"type":913},"4/5 breaches involved identity and compromised credentials",{"data":51850,"marks":51851,"value":51852,"nodeType":867},{},[],", while another suggests that ",{"data":51854,"content":51856,"nodeType":915},{"uri":51855},"https://rakgarg.substack.com/p/identity-crisis-the-biggest-prize",[51857],{"data":51858,"marks":51859,"value":51861,"nodeType":867},{},[51860],{"type":913},"75% of breaches are caused by mismanaged identity, access, or privileges",{"data":51863,"marks":51864,"value":1679,"nodeType":867},{},[],{"data":51866,"content":51867,"nodeType":876},{},[51868],{"data":51869,"marks":51870,"value":51871,"nodeType":867},{},[],"Phishing, social engineering, credential stuffing, and business email compromise have morphed into a homogenous understanding of identity threats that are generally tackled through a combination of email security tooling, content access controls, and user awareness. ",{"data":51873,"content":51877,"nodeType":985},{"target":51874},{"sys":51875},{"id":51876,"type":982,"linkType":983},"5NRWvCl0xsoWcpgHbcQIkf",[],{"data":51879,"content":51880,"nodeType":876},{},[51881],{"data":51882,"marks":51883,"value":51884,"nodeType":867},{},[],"The fact that such attacks have been reported as the top security threat for so long probably means that people pay less attention to identity threats. Ransomware grabs the headlines, and rightly so in many cases, but phishing feels like a “known known” that we have a plan for (even if the plan often fails). ",{"data":51886,"content":51887,"nodeType":876},{},[51888,51892,51901],{"data":51889,"marks":51890,"value":51891,"nodeType":867},{},[],"In fact, there’s a problem with messaging generally. The ",{"data":51893,"content":51895,"nodeType":915},{"uri":51894},"https://www.verizon.com/business/resources/T78/reports/data-breach-investigation-report_2015.pdf",[51896],{"data":51897,"marks":51898,"value":51900,"nodeType":867},{},[51899],{"type":913},"2015 Verizon DBIR",{"data":51902,"marks":51903,"value":51904,"nodeType":867},{},[]," contains plenty of stats that still ring largely true today. For example:",{"data":51906,"content":51907,"nodeType":1629},{},[51908,51918],{"data":51909,"content":51910,"nodeType":1586},{},[51911],{"data":51912,"content":51913,"nodeType":876},{},[51914],{"data":51915,"marks":51916,"value":51917,"nodeType":867},{},[],"In the 2013 DBIR, phishing was associated with over 95% of incidents attributed to state sponsored actors, and for two years running, more than two-thirds of incidents have featured phishing",{"data":51919,"content":51920,"nodeType":1586},{},[51921],{"data":51922,"content":51923,"nodeType":876},{},[51924],{"data":51925,"marks":51926,"value":51927,"nodeType":867},{},[],"In 60% of cases, attackers are able to compromise an organization within minutes",{"data":51929,"content":51930,"nodeType":876},{},[51931],{"data":51932,"marks":51933,"value":51934,"nodeType":867},{},[],"Remove the dates and a lot of the report still stands up. ",{"data":51936,"content":51937,"nodeType":1058},{},[51938],{"data":51939,"marks":51940,"value":51941,"nodeType":867},{},[],"Bad then, worse now",{"data":51943,"content":51944,"nodeType":876},{},[51945,51949,51954,51958,51963],{"data":51946,"marks":51947,"value":51948,"nodeType":867},{},[],"But browser-based identity attacks ",{"data":51950,"marks":51951,"value":51953,"nodeType":867},{},[51952],{"type":865},"are",{"data":51955,"marks":51956,"value":51957,"nodeType":867},{},[]," worse than they used to be. Yes, credential stuffing, phishing, and SIM swapping may not be the most sophisticated attacks, but they remain as effective as ever. ",{"data":51959,"marks":51960,"value":51962,"nodeType":867},{},[51961],{"type":1303},"As the saying goes, if it ain’t broke — don’t fix it.",{"data":51964,"marks":51965,"value":2167,"nodeType":867},{},[],{"data":51967,"content":51968,"nodeType":876},{},[51969,51973,51978],{"data":51970,"marks":51971,"value":51972,"nodeType":867},{},[],"Recent attacks have moved toward a broader targeting of the ",{"data":51974,"marks":51975,"value":51977,"nodeType":867},{},[51976],{"type":865},"identity infrastructure",{"data":51979,"marks":51980,"value":51981,"nodeType":867},{},[],". While phishing and social engineering was once primarily a delivery mechanism for malicious payloads to be executed on endpoint, it is now used to harvest credentials and secrets for identity-based attacks against cloud apps and services. ",{"data":51983,"content":51984,"nodeType":876},{},[51985],{"data":51986,"marks":51987,"value":51988,"nodeType":867},{},[],"And because businesses have migrated to more cloud-based services and infrastructure, the compromise of an identity now has different consequences.",{"data":51990,"content":51991,"nodeType":876},{},[51992,51996],{"data":51993,"marks":51994,"value":51995,"nodeType":867},{},[],"The data and functionality that attackers seek has moved off endpoints and internal networks and onto cloud systems and SaaS applications, which organizations are using in large numbers (tens to hundreds). The modern way of working means that applications are more often than not directly exposed to the internet — and the only thing needed to access these apps are identities. ",{"data":51997,"marks":51998,"value":52000,"nodeType":867},{},[51999],{"type":865},"Naturally, it's much harder to stop credential stuffing attacks against 100 SaaS apps than the single centralized external VPN/webmail endpoint of yesteryear. ",{"data":52002,"content":52003,"nodeType":876},{},[52004],{"data":52005,"marks":52006,"value":52007,"nodeType":867},{},[],"It’s clear that stats alone don’t adequately capture the identity threat. So we have to look beyond the numbers to find out why. ",{"data":52009,"content":52010,"nodeType":942},{},[],{"data":52012,"content":52013,"nodeType":868},{},[52014],{"data":52015,"marks":52016,"value":52017,"nodeType":867},{},[],"Using this resource",{"data":52019,"content":52020,"nodeType":876},{},[52021],{"data":52022,"marks":52023,"value":52024,"nodeType":867},{},[],"To cut through some of the noise, we’ve compiled this list of reported attacks and explored what they mean for the identity threat landscape. ",{"data":52026,"content":52027,"nodeType":876},{},[52028,52032,52037],{"data":52029,"marks":52030,"value":52031,"nodeType":867},{},[],"This is not intended to be an exhaustive list of all attacks involving the compromise of digital identities (the list would be endless!). Nor is it something you should read all in one go (unless you ",{"data":52033,"marks":52034,"value":52036,"nodeType":867},{},[52035],{"type":1303},"really",{"data":52038,"marks":52039,"value":52040,"nodeType":867},{},[]," want to, we won’t stop you). We want it to be a resource that you can refer back to, that we will continue to update as new attacks are recorded. ",{"data":52042,"content":52043,"nodeType":876},{},[52044,52048],{"data":52045,"marks":52046,"value":52047,"nodeType":867},{},[],"In this context we define identity attacks as ",{"data":52049,"marks":52050,"value":52052,"nodeType":867},{},[52051],{"type":865},"attacks targeting cloud identities and their associated identity management systems, protocols, applications, and infrastructure. ",{"data":52054,"content":52055,"nodeType":876},{},[52056,52060],{"data":52057,"marks":52058,"value":52059,"nodeType":867},{},[],"The attacks recorded below are high profile examples of browser-based identity attacks",{"data":52061,"marks":52062,"value":52063,"nodeType":867},{},[]," that demonstrate how threat actors are leveraging the cloud identity plane to evade established cyber defenses and traverse new attack paths to achieve their goals. We’ve focused on attacks targeting identity infrastructure itself that are notable for their bypassing of traditional environments and established controls (e.g. Networkless or SaaS-to-SaaS attack paths). ",{"data":52065,"content":52066,"nodeType":876},{},[52067,52071,52078,52082,52091],{"data":52068,"marks":52069,"value":52070,"nodeType":867},{},[],"As with all publicly disclosed breaches, the level of detail and transparency we see varies. Where possible, we've mapped the threat actor Tactics, Techniques and Procedures to our ",{"data":52072,"content":52073,"nodeType":915},{"uri":5720},[52074],{"data":52075,"marks":52076,"value":5905,"nodeType":867},{},[52077],{"type":913},{"data":52079,"marks":52080,"value":52081,"nodeType":867},{},[]," (previously the SaaS Attack Matrix). To learn more about SaaS attack techniques ",{"data":52083,"content":52085,"nodeType":915},{"uri":52084},"https://pushsecurity.com/blog/saas-attack-techniques/#id-problems-with-observing-saas-attacks",[52086],{"data":52087,"marks":52088,"value":52090,"nodeType":867},{},[52089],{"type":913},"read the blog",{"data":52092,"marks":52093,"value":2933,"nodeType":867},{},[],{"data":52095,"content":52096,"nodeType":942},{},[],{"data":52098,"content":52099,"nodeType":868},{},[52100],{"data":52101,"marks":52102,"value":52103,"nodeType":867},{},[],"Snowflake – June 2024",{"data":52105,"content":52106,"nodeType":876},{},[52107,52111,52119],{"data":52108,"marks":52109,"value":52110,"nodeType":867},{},[],"The threat group known as ShinyHunters (also tracked as UNC5537) has claimed responsibility for breaching multiple organizations using Snowflake, a cloud-based data warehousing and analytics platform. The breach stems from the historical compromise of credentials used to access customer-specific Snowflake tenants, via infostealer infections. These credentials were used as part of a targeted campaign against Snowflake customers, which was exacerbated by the widespread absence of MFA due to the lack of MFA enforcement by default. At the time of writing, approximately 165 customers have been impacted globally ",{"data":52112,"content":52113,"nodeType":915},{"uri":16024},[52114],{"data":52115,"marks":52116,"value":52118,"nodeType":867},{},[52117],{"type":913},"according to a report by Mandiant",{"data":52120,"marks":52121,"value":5704,"nodeType":867},{},[],{"data":52123,"content":52124,"nodeType":1058},{},[52125],{"data":52126,"marks":52127,"value":52128,"nodeType":867},{},[],"How did Snowflake get breached?",{"data":52130,"content":52131,"nodeType":876},{},[52132],{"data":52133,"marks":52134,"value":52136,"nodeType":867},{},[52135],{"type":1303},"It’s worth noting that customers/users of Snowflake were breached via their Snowflake tenants, and no central breach of Snowflake's own systems occurred.",{"data":52138,"content":52139,"nodeType":1629},{},[52140,52150,52172,52182,52192,52202,52212,52222],{"data":52141,"content":52142,"nodeType":1586},{},[52143],{"data":52144,"content":52145,"nodeType":876},{},[52146],{"data":52147,"marks":52148,"value":52149,"nodeType":867},{},[],"Snowflake users were infected with infostealer malware that harvested credentials from user devices over an extended period. The threat actor used Snowflake customer credentials that were previously exposed via several infostealer malware variants, including; VIDAR, RISEPRO, REDLINE, RACOON STEALER, LUMMA and METASTEALER.",{"data":52151,"content":52152,"nodeType":1586},{},[52153],{"data":52154,"content":52155,"nodeType":876},{},[52156,52160,52168],{"data":52157,"marks":52158,"value":52159,"nodeType":867},{},[],"Credentials appeared on criminal marketplaces e.g. dark web forums and ",{"data":52161,"content":52162,"nodeType":915},{"uri":45994},[52163],{"data":52164,"marks":52165,"value":52167,"nodeType":867},{},[52166],{"type":913},"Telegram channels",{"data":52169,"marks":52170,"value":52171,"nodeType":867},{},[]," as combolists (username, password, and login portal combinations). ",{"data":52173,"content":52174,"nodeType":1586},{},[52175],{"data":52176,"content":52177,"nodeType":876},{},[52178],{"data":52179,"marks":52180,"value":52181,"nodeType":867},{},[],"Criminal groups (either ShinyHunters or another organization) saw the potential in targeting Snowflake users, based on the availability of credentials, number of customer organizations, and the value of the data that can be accessed in Snowflake. ",{"data":52183,"content":52184,"nodeType":1586},{},[52185],{"data":52186,"content":52187,"nodeType":876},{},[52188],{"data":52189,"marks":52190,"value":52191,"nodeType":867},{},[],"ShinyHunters embarked on a large-scale campaign targeting Snowflake customer accounts using previously breached credentials. ",{"data":52193,"content":52194,"nodeType":1586},{},[52195],{"data":52196,"content":52197,"nodeType":876},{},[52198],{"data":52199,"marks":52200,"value":52201,"nodeType":867},{},[],"ShinyHunters accessed user accounts that lacked MFA, belonging to approximately 165 Snowflake customers. ",{"data":52203,"content":52204,"nodeType":1586},{},[52205],{"data":52206,"content":52207,"nodeType":876},{},[52208],{"data":52209,"marks":52210,"value":52211,"nodeType":867},{},[],"ShinyHunters used SQL-based reconnaissance, staging, and data exfiltration techniques, expedited by custom hacker tooling developed specifically for Snowflake, to conduct attacks at scale.",{"data":52213,"content":52214,"nodeType":1586},{},[52215],{"data":52216,"content":52217,"nodeType":876},{},[52218],{"data":52219,"marks":52220,"value":52221,"nodeType":867},{},[],"ShinyHunters acquired massive quantities of Snowflake data based on the information that each customer stored in Snowflake or connected apps. The most sensitive data declared so far pertains to end-customers of each victim, for example PII, bank account and card information, etc.  ",{"data":52223,"content":52224,"nodeType":1586},{},[52225],{"data":52226,"content":52227,"nodeType":876},{},[52228],{"data":52229,"marks":52230,"value":52231,"nodeType":867},{},[],"ShinyHunters began attempts to extort Snowflake and end-customers using the data acquired. ",{"data":52233,"content":52234,"nodeType":1058},{},[52235],{"data":52236,"marks":52237,"value":52238,"nodeType":867},{},[],"What was the impact of the Snowflake breach?",{"data":52240,"content":52241,"nodeType":1629},{},[52242,52261,52292,52320,52339,52358],{"data":52243,"content":52244,"nodeType":1586},{},[52245],{"data":52246,"content":52247,"nodeType":876},{},[52248,52252,52257],{"data":52249,"marks":52250,"value":52251,"nodeType":867},{},[],"Approximately ",{"data":52253,"marks":52254,"value":52256,"nodeType":867},{},[52255],{"type":865},"165 victims were identified by Mandiant",{"data":52258,"marks":52259,"value":52260,"nodeType":867},{},[],". Organizations are gradually coming forward to declare the breach and release customer communications accordingly, but not all victims have been named.",{"data":52262,"content":52263,"nodeType":1586},{},[52264],{"data":52265,"content":52266,"nodeType":876},{},[52267,52271,52276,52280,52288],{"data":52268,"marks":52269,"value":52270,"nodeType":867},{},[],"Based on the figures being suggested so far, the impact upon end-customers is huge, with the data of ",{"data":52272,"marks":52273,"value":52275,"nodeType":867},{},[52274],{"type":865},"hundreds of millions of people exposed",{"data":52277,"marks":52278,"value":52279,"nodeType":867},{},[],", and has been touted by some news outlets as ‘",{"data":52281,"content":52282,"nodeType":915},{"uri":40317},[52283],{"data":52284,"marks":52285,"value":52287,"nodeType":867},{},[52286],{"type":913},"one of the biggest breaches ever",{"data":52289,"marks":52290,"value":52291,"nodeType":867},{},[],"’.  ",{"data":52293,"content":52294,"nodeType":1586},{},[52295],{"data":52296,"content":52297,"nodeType":876},{},[52298,52302,52307,52311,52316],{"data":52299,"marks":52300,"value":52301,"nodeType":867},{},[],"The impact on the affected businesses is largely unknown at this stage. It’s clear that the victims will suffer ",{"data":52303,"marks":52304,"value":52306,"nodeType":867},{},[52305],{"type":865},"reputational damage",{"data":52308,"marks":52309,"value":52310,"nodeType":867},{},[]," based on the extent of their individual breaches, and possibly face other ",{"data":52312,"marks":52313,"value":52315,"nodeType":867},{},[52314],{"type":865},"penalties and sanctions",{"data":52317,"marks":52318,"value":52319,"nodeType":867},{},[]," if they are found to be at fault by their respective regulators and/or national information security authorities. ",{"data":52321,"content":52322,"nodeType":1586},{},[52323],{"data":52324,"content":52325,"nodeType":876},{},[52326,52330,52335],{"data":52327,"marks":52328,"value":52329,"nodeType":867},{},[],"The impact upon individuals will be significant, with high potential for further targeting in terms of ",{"data":52331,"marks":52332,"value":52334,"nodeType":867},{},[52333],{"type":865},"identity theft, blackmail, financial crime",{"data":52336,"marks":52337,"value":52338,"nodeType":867},{},[],", etc.  ",{"data":52340,"content":52341,"nodeType":1586},{},[52342],{"data":52343,"content":52344,"nodeType":876},{},[52345,52349,52354],{"data":52346,"marks":52347,"value":52348,"nodeType":867},{},[],"It is unclear what data has been exposed in addition to personal data affecting end-customers. If other sensitive commercial or business data pertaining to ",{"data":52350,"marks":52351,"value":52353,"nodeType":867},{},[52352],{"type":865},"Intellectual Property",{"data":52355,"marks":52356,"value":52357,"nodeType":867},{},[]," has been exposed then this data may also be sold on via other nefarious channels, with a potential future impact.",{"data":52359,"content":52360,"nodeType":1586},{},[52361],{"data":52362,"content":52363,"nodeType":876},{},[52364,52368,52373],{"data":52365,"marks":52366,"value":52367,"nodeType":867},{},[],"Given the lack of MFA for the compromised accounts, there has been a general criticism of the ‘opt-in’ nature of MFA for SaaS services, with many security professionals suggesting that ",{"data":52369,"marks":52370,"value":52372,"nodeType":867},{},[52371],{"type":865},"Snowflake should enforce MFA by default",{"data":52374,"marks":52375,"value":52376,"nodeType":867},{},[]," given the critical nature of the service. ",{"data":52378,"content":52379,"nodeType":1058},{},[52380],{"data":52381,"marks":52382,"value":52383,"nodeType":867},{},[],"What stands out in the Snowflake breach?",{"data":52385,"content":52386,"nodeType":1629},{},[52387,52406,52447,52474],{"data":52388,"content":52389,"nodeType":1586},{},[52390],{"data":52391,"content":52392,"nodeType":876},{},[52393,52397,52402],{"data":52394,"marks":52395,"value":52396,"nodeType":867},{},[],"The breach ",{"data":52398,"marks":52399,"value":52401,"nodeType":867},{},[52400],{"type":865},"was achieved by using stolen credentials dating back as far as 2020",{"data":52403,"marks":52404,"value":52405,"nodeType":867},{},[],", that had not been rotated or changed. This indicates that many of the credentials used were not necessarily the result of any recent data sharing. This highlights the potential risk of breached credentials already in the public domain; particularly in the case of cloud services that may not be subject to the same levels of credential hygiene as other traditional network logins. ",{"data":52407,"content":52408,"nodeType":1586},{},[52409],{"data":52410,"content":52411,"nodeType":876},{},[52412,52416,52424,52427,52432,52436,52444],{"data":52413,"marks":52414,"value":52415,"nodeType":867},{},[],"Much of the industry response has focused on ensuring that accounts are using SSO (and therefore are protected by MFA at the IdP level). However, due to the existence of ",{"data":52417,"content":52419,"nodeType":915},{"uri":52418},"https://pushsecurity.com/resources/browser-identity-attacks-matrix/ghost-logins",[52420],{"data":52421,"marks":52422,"value":2929,"nodeType":867},{},[52423],{"type":913},{"data":52425,"marks":52426,"value":5136,"nodeType":867},{},[],{"data":52428,"marks":52429,"value":52431,"nodeType":867},{},[52430],{"type":865},"local logins without MFA can exist simultaneously with the SSO login unless expressly disabled",{"data":52433,"marks":52434,"value":52435,"nodeType":867},{},[],". Organizations using Snowflake that are looking to lock down their accounts can ",{"data":52437,"content":52438,"nodeType":915},{"uri":42382},[52439],{"data":52440,"marks":52441,"value":52443,"nodeType":867},{},[52442],{"type":913},"watch our recent demo of how to effectively remediate this vulnerability in Snowflake",{"data":52445,"marks":52446,"value":24572,"nodeType":867},{},[],{"data":52448,"content":52449,"nodeType":1586},{},[52450],{"data":52451,"content":52452,"nodeType":876},{},[52453,52458,52462,52470],{"data":52454,"marks":52455,"value":52457,"nodeType":867},{},[52456],{"type":865},"80% of the credentials were gathered through infostealer malware",{"data":52459,"marks":52460,"value":52461,"nodeType":867},{},[],". Typically, this occurs when unmanaged devices are used to access company resources, or personal browser profiles are synchronized on both work and personal devices. Malware deployed to an insecure personal device can then access and steal credentials for company resources. This situation usually occurs when working with third-party contractors on a BYOD basis; ",{"data":52463,"content":52464,"nodeType":915},{"uri":46217},[52465],{"data":52466,"marks":52467,"value":52469,"nodeType":867},{},[52468],{"type":913},"a recent article indicates that Ukraine-based EPAM Systems",{"data":52471,"marks":52472,"value":52473,"nodeType":867},{},[],", an engineering and digital service provider and “Elite Tier Partner” of Snowflake, was one such organization breached in this way. Organizations consuming Snowflake-related services from EPAM were then subsequently affected, as the compromise of EPAM users granted access to a large number of Snowflake credentials for various company tenants.  ",{"data":52475,"content":52476,"nodeType":1586},{},[52477],{"data":52478,"content":52479,"nodeType":876},{},[52480,52484,52489,52493,52498],{"data":52481,"marks":52482,"value":52483,"nodeType":867},{},[],"While attacker activity has focused on Snowflake to date, the success of this attack will signal the potential for further credential based attacks against similar apps. ",{"data":52485,"marks":52486,"value":52488,"nodeType":867},{},[52487],{"type":865},"There may already be a 'Snowflake 2.0' among the credentials already available online",{"data":52490,"marks":52491,"value":52492,"nodeType":867},{},[],". Further, credentials can be used against a wide range of apps to capitalize on potential ",{"data":52494,"marks":52495,"value":52497,"nodeType":867},{},[52496],{"type":865},"password reuse (which we see for 1 in 3 employees)",{"data":52499,"marks":52500,"value":52501,"nodeType":867},{},[],", so the exact creds for a particular app don’t have to be explicitly breached, so long as the domain for the login portal can be guessed or has been exposed elsewhere.   ",{"data":52503,"content":52504,"nodeType":1058},{},[52505],{"data":52506,"marks":52507,"value":52508,"nodeType":867},{},[],"Browser & Identity Attacks Matrix mapping",{"data":52510,"content":52511,"nodeType":876},{},[52512],{"data":52513,"marks":52514,"value":52515,"nodeType":867},{},[],"For more information on each TTP please navigate to the entries linked in the table below. ",{"data":52517,"content":52518,"nodeType":7904},{},[52519,52562,52624],{"data":52520,"content":52521,"nodeType":7640},{},[52522,52532,52542,52552],{"data":52523,"content":52524,"nodeType":20313},{},[52525],{"data":52526,"content":52527,"nodeType":876},{},[52528],{"data":52529,"marks":52530,"value":52531,"nodeType":867},{},[],"ID",{"data":52533,"content":52534,"nodeType":20313},{},[52535],{"data":52536,"content":52537,"nodeType":876},{},[52538],{"data":52539,"marks":52540,"value":52541,"nodeType":867},{},[],"Name",{"data":52543,"content":52544,"nodeType":20313},{},[52545],{"data":52546,"content":52547,"nodeType":876},{},[52548],{"data":52549,"marks":52550,"value":52551,"nodeType":867},{},[],"Stage",{"data":52553,"content":52554,"nodeType":20313},{},[52555],{"data":52556,"content":52557,"nodeType":876},{},[52558],{"data":52559,"marks":52560,"value":52561,"nodeType":867},{},[],"Description",{"data":52563,"content":52564,"nodeType":7640},{},[52565,52585,52604,52614],{"data":52566,"content":52567,"nodeType":7628},{},[52568],{"data":52569,"content":52570,"nodeType":876},{},[52571,52574,52582],{"data":52572,"marks":52573,"value":21,"nodeType":867},{},[],{"data":52575,"content":52576,"nodeType":915},{"uri":26236},[52577],{"data":52578,"marks":52579,"value":52581,"nodeType":867},{},[52580],{"type":913},"SAT1017",{"data":52583,"marks":52584,"value":21,"nodeType":867},{},[],{"data":52586,"content":52587,"nodeType":7628},{},[52588],{"data":52589,"content":52590,"nodeType":876},{},[52591,52594,52601],{"data":52592,"marks":52593,"value":21,"nodeType":867},{},[],{"data":52595,"content":52596,"nodeType":915},{"uri":52418},[52597],{"data":52598,"marks":52599,"value":395,"nodeType":867},{},[52600],{"type":913},{"data":52602,"marks":52603,"value":21,"nodeType":867},{},[],{"data":52605,"content":52606,"nodeType":7628},{},[52607],{"data":52608,"content":52609,"nodeType":876},{},[52610],{"data":52611,"marks":52612,"value":52613,"nodeType":867},{},[],"Initial Access; Persistence; Defense Evasion",{"data":52615,"content":52616,"nodeType":7628},{},[52617],{"data":52618,"content":52619,"nodeType":876},{},[52620],{"data":52621,"marks":52622,"value":52623,"nodeType":867},{},[],"Abusing non-SSO additional login methods such as password-based authentication (local to the SaaS app), social logins, API access, etc. ",{"data":52625,"content":52626,"nodeType":7640},{},[52627,52647,52667,52677],{"data":52628,"content":52629,"nodeType":7628},{},[52630],{"data":52631,"content":52632,"nodeType":876},{},[52633,52636,52644],{"data":52634,"marks":52635,"value":21,"nodeType":867},{},[],{"data":52637,"content":52638,"nodeType":915},{"uri":42165},[52639],{"data":52640,"marks":52641,"value":52643,"nodeType":867},{},[52642],{"type":913},"SAT1044",{"data":52645,"marks":52646,"value":21,"nodeType":867},{},[],{"data":52648,"content":52649,"nodeType":7628},{},[52650],{"data":52651,"content":52652,"nodeType":876},{},[52653,52656,52664],{"data":52654,"marks":52655,"value":21,"nodeType":867},{},[],{"data":52657,"content":52659,"nodeType":915},{"uri":52658},"https://pushsecurity.com/resources/browser-identity-attacks-matrix/session-cookie-theft",[52660],{"data":52661,"marks":52662,"value":42575,"nodeType":867},{},[52663],{"type":913},{"data":52665,"marks":52666,"value":21,"nodeType":867},{},[],{"data":52668,"content":52669,"nodeType":7628},{},[52670],{"data":52671,"content":52672,"nodeType":876},{},[52673],{"data":52674,"marks":52675,"value":52676,"nodeType":867},{},[],"Lateral Movement; Defense Evasion",{"data":52678,"content":52679,"nodeType":7628},{},[52680],{"data":52681,"content":52682,"nodeType":876},{},[52683],{"data":52684,"marks":52685,"value":52686,"nodeType":867},{},[],"Session cookies are used to pivot from an endpoint compromise and laterally move to downstream SaaS applications.",{"data":52688,"content":52689,"nodeType":1058},{},[52690],{"data":52691,"marks":52692,"value":52693,"nodeType":867},{},[],"Related breaches",{"data":52695,"content":52696,"nodeType":876},{},[52697],{"data":52698,"marks":52699,"value":52700,"nodeType":867},{},[],"Named victims are listed below:",{"data":52702,"content":52703,"nodeType":1629},{},[52704,52714,52724,52734,52744,52754,52764,52774],{"data":52705,"content":52706,"nodeType":1586},{},[52707],{"data":52708,"content":52709,"nodeType":876},{},[52710],{"data":52711,"marks":52712,"value":52713,"nodeType":867},{},[],"Ticketmaster",{"data":52715,"content":52716,"nodeType":1586},{},[52717],{"data":52718,"content":52719,"nodeType":876},{},[52720],{"data":52721,"marks":52722,"value":52723,"nodeType":867},{},[],"Santander",{"data":52725,"content":52726,"nodeType":1586},{},[52727],{"data":52728,"content":52729,"nodeType":876},{},[52730],{"data":52731,"marks":52732,"value":52733,"nodeType":867},{},[],"Neiman Marcus",{"data":52735,"content":52736,"nodeType":1586},{},[52737],{"data":52738,"content":52739,"nodeType":876},{},[52740],{"data":52741,"marks":52742,"value":52743,"nodeType":867},{},[],"Los Angeles Unified",{"data":52745,"content":52746,"nodeType":1586},{},[52747],{"data":52748,"content":52749,"nodeType":876},{},[52750],{"data":52751,"marks":52752,"value":52753,"nodeType":867},{},[],"Pure Storage",{"data":52755,"content":52756,"nodeType":1586},{},[52757],{"data":52758,"content":52759,"nodeType":876},{},[52760],{"data":52761,"marks":52762,"value":52763,"nodeType":867},{},[],"Advance Auto Parts",{"data":52765,"content":52766,"nodeType":1586},{},[52767],{"data":52768,"content":52769,"nodeType":876},{},[52770],{"data":52771,"marks":52772,"value":52773,"nodeType":867},{},[],"Truist Bank",{"data":52775,"content":52776,"nodeType":1586},{},[52777],{"data":52778,"content":52779,"nodeType":876},{},[52780],{"data":52781,"marks":52782,"value":52783,"nodeType":867},{},[],"Lending Tree",{"data":52785,"content":52786,"nodeType":942},{},[],{"data":52788,"content":52789,"nodeType":868},{},[52790],{"data":52791,"marks":52792,"value":52793,"nodeType":867},{},[],"Microsoft — January 2024",{"data":52795,"content":52796,"nodeType":876},{},[52797],{"data":52798,"marks":52799,"value":52800,"nodeType":867},{},[],"The threat group known as APT29 (also known as “The Dukes”, “Cozy Bear”, and labeled “Midnight Blizzard” by Microsoft) executed a cleverly executed password-guessing attack to compromise test cloud identities that were also lacking MFA. Attackers then leveraged this access to compromise some OAuth applications that allowed lateral movement to Microsoft’s corporate environment and the creation of other malicious OAuth applications to achieve persistence.",{"data":52802,"content":52803,"nodeType":1058},{},[52804],{"data":52805,"marks":52806,"value":52807,"nodeType":867},{},[],"How did Microsoft get breached?",{"data":52809,"content":52810,"nodeType":1629},{},[52811,52821,52831,52841,52851,52861],{"data":52812,"content":52813,"nodeType":1586},{},[52814],{"data":52815,"content":52816,"nodeType":876},{},[52817],{"data":52818,"marks":52819,"value":52820,"nodeType":867},{},[],"APT29 utilized password spraying / credential stuffing attacks to compromise test cloud identities that were also lacking MFA, attached to a non-production test tenant.",{"data":52822,"content":52823,"nodeType":1586},{},[52824],{"data":52825,"content":52826,"nodeType":876},{},[52827],{"data":52828,"marks":52829,"value":52830,"nodeType":867},{},[],"APT29 leveraged their initial access to the test tenant to identify and compromise a test OAuth application that had access to the Microsoft corporate environment by leveraging permissive Entra ID roles in the test tenant.",{"data":52832,"content":52833,"nodeType":1586},{},[52834],{"data":52835,"content":52836,"nodeType":876},{},[52837],{"data":52838,"marks":52839,"value":52840,"nodeType":867},{},[],"APT29 used the existing configurations to access the Microsoft corporate Entra ID tenant whereupon the app registration from the test tenant was installed as a service principal in the corporate tenant, granting the equivalent of global admin rights.",{"data":52842,"content":52843,"nodeType":1586},{},[52844],{"data":52845,"content":52846,"nodeType":876},{},[52847],{"data":52848,"marks":52849,"value":52850,"nodeType":867},{},[],"Using these new permissions, APT29 registered additional malicious OAuth applications in the Microsoft corporate environment, and created a new user in the Microsoft corporate tenant to grant consent to the new malicious OAuth apps, thereby achieving persistent access to the environment.",{"data":52852,"content":52853,"nodeType":1586},{},[52854],{"data":52855,"content":52856,"nodeType":876},{},[52857],{"data":52858,"marks":52859,"value":52860,"nodeType":867},{},[],"APT29 leveraged the elevated (maximum) privileges assigned to the ‘test’ app service principal to grant app roles to other newly created app service principals, granting them the Office 365 Exchange Online full_access_as_app role in the corporate tenant, which allows access to mailboxes.",{"data":52862,"content":52863,"nodeType":1586},{},[52864],{"data":52865,"content":52866,"nodeType":876},{},[52867],{"data":52868,"marks":52869,"value":52870,"nodeType":867},{},[],"APT29 leveraged these malicious OAuth applications to authenticate to Microsoft Exchange Online and target Microsoft corporate email accounts.",{"data":52872,"content":52873,"nodeType":1058},{},[52874],{"data":52875,"marks":52876,"value":52877,"nodeType":867},{},[],"What was the impact of the Microsoft breach?",{"data":52879,"content":52880,"nodeType":1629},{},[52881,52891,52901],{"data":52882,"content":52883,"nodeType":1586},{},[52884],{"data":52885,"content":52886,"nodeType":876},{},[52887],{"data":52888,"marks":52889,"value":52890,"nodeType":867},{},[],"APT29 had access to Microsoft corporate email accounts, including members of the senior leadership team and employees in the cybersecurity, legal, and other functions, resulting in sensitive data leakage.",{"data":52892,"content":52893,"nodeType":1586},{},[52894],{"data":52895,"content":52896,"nodeType":876},{},[52897],{"data":52898,"marks":52899,"value":52900,"nodeType":867},{},[],"Microsoft has not disclosed any further impacts at this time, but it is likely that the adversary had complete, unmitigated control of the Microsoft corporate tenant for a period of time, with global administrator level access.",{"data":52902,"content":52903,"nodeType":1586},{},[52904],{"data":52905,"content":52906,"nodeType":876},{},[52907],{"data":52908,"marks":52909,"value":52910,"nodeType":867},{},[],"Since the initial attack there has been evidence of continued targeting, with password spraying attacks reportedly increasing tenfold, likely informed by stolen information.",{"data":52912,"content":52913,"nodeType":1058},{},[52914],{"data":52915,"marks":52916,"value":52917,"nodeType":867},{},[],"What stands out in the Microsoft breach?",{"data":52919,"content":52920,"nodeType":1629},{},[52921,52931,52941,52951],{"data":52922,"content":52923,"nodeType":1586},{},[52924],{"data":52925,"content":52926,"nodeType":876},{},[52927],{"data":52928,"marks":52929,"value":52930,"nodeType":867},{},[],"The attack was covert and targeted, with APT29 tailoring the attack to a limited number of accounts and using a low number of attempts to evade detection and avoid account blocks based on the volume of failures.",{"data":52932,"content":52933,"nodeType":1586},{},[52934],{"data":52935,"content":52936,"nodeType":876},{},[52937],{"data":52938,"marks":52939,"value":52940,"nodeType":867},{},[],"APT29 used residential proxy networks when interacting with the compromised tenant and, subsequently, with Exchange Online to obfuscate the source of their attack and avoid impossible travel detections. ",{"data":52942,"content":52943,"nodeType":1586},{},[52944],{"data":52945,"content":52946,"nodeType":876},{},[52947],{"data":52948,"marks":52949,"value":52950,"nodeType":867},{},[],"APT29 demonstrated mature and in-depth understanding of cloud infrastructure, protocols, and workflows, particularly in terms of privilege escalation and lateral movement.",{"data":52952,"content":52953,"nodeType":1586},{},[52954],{"data":52955,"content":52956,"nodeType":876},{},[52957],{"data":52958,"marks":52959,"value":52960,"nodeType":867},{},[],"If even Microsoft (an organization with pretty much unrivaled security resources) can’t ensure that all their accounts are protected by MFA and that there are no weak links between test/dev and prod systems, this should be a wake-up call for any company that thinks their MFA implementation is flawless. ",{"data":52962,"content":52963,"nodeType":1058},{},[52964],{"data":52965,"marks":52966,"value":52508,"nodeType":867},{},[],{"data":52968,"content":52969,"nodeType":876},{},[52970],{"data":52971,"marks":52972,"value":52515,"nodeType":867},{},[],{"data":52974,"content":52975,"nodeType":7904},{},[52976,53016,53079,53142],{"data":52977,"content":52978,"nodeType":7640},{},[52979,52988,52998,53007],{"data":52980,"content":52981,"nodeType":20313},{},[52982],{"data":52983,"content":52984,"nodeType":876},{},[52985],{"data":52986,"marks":52987,"value":52531,"nodeType":867},{},[],{"data":52989,"content":52990,"nodeType":20313},{},[52991],{"data":52992,"content":52993,"nodeType":876},{},[52994],{"data":52995,"marks":52996,"value":52997,"nodeType":867},{},[],"Technique",{"data":52999,"content":53000,"nodeType":20313},{},[53001],{"data":53002,"content":53003,"nodeType":876},{},[53004],{"data":53005,"marks":53006,"value":52551,"nodeType":867},{},[],{"data":53008,"content":53009,"nodeType":20313},{},[53010],{"data":53011,"content":53012,"nodeType":876},{},[53013],{"data":53014,"marks":53015,"value":52561,"nodeType":867},{},[],{"data":53017,"content":53018,"nodeType":7640},{},[53019,53039,53059,53069],{"data":53020,"content":53021,"nodeType":7628},{},[53022],{"data":53023,"content":53024,"nodeType":876},{},[53025,53028,53036],{"data":53026,"marks":53027,"value":21,"nodeType":867},{},[],{"data":53029,"content":53030,"nodeType":915},{"uri":42200},[53031],{"data":53032,"marks":53033,"value":53035,"nodeType":867},{},[53034],{"type":913},"SAT1011",{"data":53037,"marks":53038,"value":21,"nodeType":867},{},[],{"data":53040,"content":53041,"nodeType":7628},{},[53042],{"data":53043,"content":53044,"nodeType":876},{},[53045,53048,53056],{"data":53046,"marks":53047,"value":21,"nodeType":867},{},[],{"data":53049,"content":53051,"nodeType":915},{"uri":53050},"https://pushsecurity.com/resources/browser-identity-attacks-matrix/credential-stuffing",[53052],{"data":53053,"marks":53054,"value":333,"nodeType":867},{},[53055],{"type":913},{"data":53057,"marks":53058,"value":21,"nodeType":867},{},[],{"data":53060,"content":53061,"nodeType":7628},{},[53062],{"data":53063,"content":53064,"nodeType":876},{},[53065],{"data":53066,"marks":53067,"value":53068,"nodeType":867},{},[],"Initial Access",{"data":53070,"content":53071,"nodeType":7628},{},[53072],{"data":53073,"content":53074,"nodeType":876},{},[53075],{"data":53076,"marks":53077,"value":53078,"nodeType":867},{},[],"Attempt to authenticate to a SaaS account by guessing a large number of passwords ",{"data":53080,"content":53081,"nodeType":7640},{},[53082,53102,53122,53132],{"data":53083,"content":53084,"nodeType":7628},{},[53085],{"data":53086,"content":53087,"nodeType":876},{},[53088,53091,53099],{"data":53089,"marks":53090,"value":21,"nodeType":867},{},[],{"data":53092,"content":53093,"nodeType":915},{"uri":42795},[53094],{"data":53095,"marks":53096,"value":53098,"nodeType":867},{},[53097],{"type":913},"SAT1027",{"data":53100,"marks":53101,"value":21,"nodeType":867},{},[],{"data":53103,"content":53104,"nodeType":7628},{},[53105],{"data":53106,"content":53107,"nodeType":876},{},[53108,53111,53119],{"data":53109,"marks":53110,"value":21,"nodeType":867},{},[],{"data":53112,"content":53114,"nodeType":915},{"uri":53113},"https://pushsecurity.com/resources/browser-identity-attacks-matrix/oauth-tokens",[53115],{"data":53116,"marks":53117,"value":42801,"nodeType":867},{},[53118],{"type":913},{"data":53120,"marks":53121,"value":21,"nodeType":867},{},[],{"data":53123,"content":53124,"nodeType":7628},{},[53125],{"data":53126,"content":53127,"nodeType":876},{},[53128],{"data":53129,"marks":53130,"value":53131,"nodeType":867},{},[],"Execution; Persistence; Defense Evasion",{"data":53133,"content":53134,"nodeType":7628},{},[53135],{"data":53136,"content":53137,"nodeType":876},{},[53138],{"data":53139,"marks":53140,"value":53141,"nodeType":867},{},[],"Use a malicious OAuth app to create an OAuth token, using arbitrary permissions to maintain long-term programmatic access to a compromised user account.",{"data":53143,"content":53144,"nodeType":7640},{},[53145,53165,53186,53196],{"data":53146,"content":53147,"nodeType":7628},{},[53148],{"data":53149,"content":53150,"nodeType":876},{},[53151,53154,53162],{"data":53152,"marks":53153,"value":21,"nodeType":867},{},[],{"data":53155,"content":53156,"nodeType":915},{"uri":43027},[53157],{"data":53158,"marks":53159,"value":53161,"nodeType":867},{},[53160],{"type":913},"SAT1001",{"data":53163,"marks":53164,"value":21,"nodeType":867},{},[],{"data":53166,"content":53167,"nodeType":7628},{},[53168],{"data":53169,"content":53170,"nodeType":876},{},[53171,53174,53183],{"data":53172,"marks":53173,"value":21,"nodeType":867},{},[],{"data":53175,"content":53177,"nodeType":915},{"uri":53176},"https://pushsecurity.com/resources/browser-identity-attacks-matrix/abuse-existing-oauth-integrations",[53178],{"data":53179,"marks":53180,"value":53182,"nodeType":867},{},[53181],{"type":913},"Abuse existing OAuth integrations",{"data":53184,"marks":53185,"value":21,"nodeType":867},{},[],{"data":53187,"content":53188,"nodeType":7628},{},[53189],{"data":53190,"content":53191,"nodeType":876},{},[53192],{"data":53193,"marks":53194,"value":53195,"nodeType":867},{},[],"Privilege Escalation;\nLateral Movement",{"data":53197,"content":53198,"nodeType":7628},{},[53199],{"data":53200,"content":53201,"nodeType":876},{},[53202],{"data":53203,"marks":53204,"value":53205,"nodeType":867},{},[],"If an adversary compromises a SaaS account integrated with other apps, they can escalate privileges and move laterally to other apps.",{"data":53207,"content":53208,"nodeType":1058},{},[53209],{"data":53210,"marks":53211,"value":52693,"nodeType":867},{},[],{"data":53213,"content":53214,"nodeType":876},{},[53215],{"data":53216,"marks":53217,"value":53219,"nodeType":867},{},[53218],{"type":865},"Hewlett Packard Enterprise (HPE) — May 2023",{"data":53221,"content":53222,"nodeType":876},{},[53223],{"data":53224,"marks":53225,"value":53226,"nodeType":867},{},[],"At the time of the Microsoft breach becoming public knowledge, HPE disclosed that they had become aware of a historical incident in Dec 2023, involving unauthorized access to and exfiltration of a limited number of SharePoint files as early as May 2023. Hackers accessed and exfiltrated data from HPE mailboxes belonging to individuals in the cybersecurity, go-to-market, business segments, and other functions. No further information is available on the techniques used or impact of the breach. ",{"data":53228,"content":53229,"nodeType":942},{},[],{"data":53231,"content":53232,"nodeType":868},{},[53233],{"data":53234,"marks":53235,"value":53236,"nodeType":867},{},[],"Okta — October 2023",{"data":53238,"content":53239,"nodeType":876},{},[53240],{"data":53241,"marks":53242,"value":53243,"nodeType":867},{},[],"An unknown threat group compromised an Okta employee's personal Google account that was being used on a company-managed device, granting the threat actor access to a service account for Okta’s customer support system, that included session tokens for 134 customers. This was then used to hijack the legitimate Okta sessions of five customers. ",{"data":53245,"content":53246,"nodeType":1058},{},[53247],{"data":53248,"marks":53249,"value":53250,"nodeType":867},{},[],"How did Okta get breached?",{"data":53252,"content":53253,"nodeType":1629},{},[53254,53264,53274,53284,53294],{"data":53255,"content":53256,"nodeType":1586},{},[53257],{"data":53258,"content":53259,"nodeType":876},{},[53260],{"data":53261,"marks":53262,"value":53263,"nodeType":867},{},[],"The threat actor compromised a personal Google account that the user had accessed from their Okta-managed work device by signing into their personal profile from the Chrome browser.",{"data":53265,"content":53266,"nodeType":1586},{},[53267],{"data":53268,"content":53269,"nodeType":876},{},[53270],{"data":53271,"marks":53272,"value":53273,"nodeType":867},{},[],"The personal account credentials are likely to have been compromised in a historical data breach and did not have MFA enabled.",{"data":53275,"content":53276,"nodeType":1586},{},[53277],{"data":53278,"content":53279,"nodeType":876},{},[53280],{"data":53281,"marks":53282,"value":53283,"nodeType":867},{},[],"The username and password of a service account for Okta’s customer support system had been saved into the employee’s personal Google account and was therefore compromised.",{"data":53285,"content":53286,"nodeType":1586},{},[53287],{"data":53288,"content":53289,"nodeType":876},{},[53290],{"data":53291,"marks":53292,"value":53293,"nodeType":867},{},[],"The threat actor was able to access the service account by logging in using the stolen credentials, which again likely did not have MFA deployed as a service account.",{"data":53295,"content":53296,"nodeType":1586},{},[53297],{"data":53298,"content":53299,"nodeType":876},{},[53300],{"data":53301,"marks":53302,"value":53303,"nodeType":867},{},[],"The threat actor was able to use session tokens in the HAR files to impersonate staff and hijack the legitimate Okta sessions of five customers, including 1Password, BeyondTrust, and Cloudflare.",{"data":53305,"content":53306,"nodeType":1058},{},[53307],{"data":53308,"marks":53309,"value":53310,"nodeType":867},{},[],"What was the impact of the Okta breach?",{"data":53312,"content":53313,"nodeType":1629},{},[53314,53324,53334,53344],{"data":53315,"content":53316,"nodeType":1586},{},[53317],{"data":53318,"content":53319,"nodeType":876},{},[53320],{"data":53321,"marks":53322,"value":53323,"nodeType":867},{},[],"The threat actor gained unauthorized access to files inside Okta’s customer support system associated with 134 Okta customers.",{"data":53325,"content":53326,"nodeType":1586},{},[53327],{"data":53328,"content":53329,"nodeType":876},{},[53330],{"data":53331,"marks":53332,"value":53333,"nodeType":867},{},[],"The threat actor was able to use these session tokens to hijack the legitimate Okta sessions of 5 (publicly disclosed) customers.",{"data":53335,"content":53336,"nodeType":1586},{},[53337],{"data":53338,"content":53339,"nodeType":876},{},[53340],{"data":53341,"marks":53342,"value":53343,"nodeType":867},{},[],"Okta originally claimed the breach had impacted only 1% of customers, but later found that a report run and downloaded by the threat actor contained the names and email addresses of all 18,400 Okta customer support users, as well as some Okta employee information, meaning 100% of customer support users were impacted.",{"data":53345,"content":53346,"nodeType":1586},{},[53347],{"data":53348,"content":53349,"nodeType":876},{},[53350],{"data":53351,"marks":53352,"value":53353,"nodeType":867},{},[],"Okta users are at higher risk of phishing and credential stuffing attacks based on the data stolen by the threat actor, increasing the importance of robust MFA implementation.",{"data":53355,"content":53356,"nodeType":1058},{},[53357],{"data":53358,"marks":53359,"value":53360,"nodeType":867},{},[],"What stands out in the Okta breach?",{"data":53362,"content":53363,"nodeType":1629},{},[53364,53374,53384],{"data":53365,"content":53366,"nodeType":1586},{},[53367],{"data":53368,"content":53369,"nodeType":876},{},[53370],{"data":53371,"marks":53372,"value":53373,"nodeType":867},{},[],"This attack demonstrates the risk associated with cloud Identity Providers and the potential goldmine that they are to attackers. Much in the same way that the manufacturers of physical and virtual network appliances are continuously probed for software vulnerabilities, cloud IdPs like Okta present a huge potential opportunity, both in terms of targeting specific organizational instances as well as the Okta organization. This attack showcases the possibility of third-party supply chain attacks to target downstream organizations using IdP services. ",{"data":53375,"content":53376,"nodeType":1586},{},[53377],{"data":53378,"content":53379,"nodeType":876},{},[53380],{"data":53381,"marks":53382,"value":53383,"nodeType":867},{},[],"Similar to the Microsoft breach, gaps were discovered and exploited in Okta’s MFA coverage and implementation, highlighting that there are gaps in even the most mature organizations. ",{"data":53385,"content":53386,"nodeType":1586},{},[53387],{"data":53388,"content":53389,"nodeType":876},{},[53390],{"data":53391,"marks":53392,"value":53393,"nodeType":867},{},[],"The subsequent attack on Cloudflare (see below) and the scale of the recovery effort demonstrates the significant operational overhead in responding to and recovering from a breach of identity infrastructure, with a similar or greater scale than a traditional Active Directory compromise. While addressing the incident, Cloudflare's staff rotated all production credentials (over 5,000 unique ones), physically segmented test and staging systems, performed forensic triage on 4,893 systems, reimaged and rebooted all systems on the company's global network, including all Atlassian servers (Jira, Confluence, and Bitbucket) and machines accessed by the threat actor. All equipment in Cloudflare's Brazil data center, which was unsuccessfully targeted by the threat actor, was later returned to the manufacturers to ensure that the data center was secure.",{"data":53395,"content":53396,"nodeType":1058},{},[53397],{"data":53398,"marks":53399,"value":52508,"nodeType":867},{},[],{"data":53401,"content":53402,"nodeType":876},{},[53403],{"data":53404,"marks":53405,"value":52515,"nodeType":867},{},[],{"data":53407,"content":53408,"nodeType":7904},{},[53409,53448,53507],{"data":53410,"content":53411,"nodeType":7640},{},[53412,53421,53430,53439],{"data":53413,"content":53414,"nodeType":20313},{},[53415],{"data":53416,"content":53417,"nodeType":876},{},[53418],{"data":53419,"marks":53420,"value":52531,"nodeType":867},{},[],{"data":53422,"content":53423,"nodeType":20313},{},[53424],{"data":53425,"content":53426,"nodeType":876},{},[53427],{"data":53428,"marks":53429,"value":52997,"nodeType":867},{},[],{"data":53431,"content":53432,"nodeType":20313},{},[53433],{"data":53434,"content":53435,"nodeType":876},{},[53436],{"data":53437,"marks":53438,"value":52551,"nodeType":867},{},[],{"data":53440,"content":53441,"nodeType":20313},{},[53442],{"data":53443,"content":53444,"nodeType":876},{},[53445],{"data":53446,"marks":53447,"value":52561,"nodeType":867},{},[],{"data":53449,"content":53450,"nodeType":7640},{},[53451,53470,53489,53498],{"data":53452,"content":53453,"nodeType":7628},{},[53454],{"data":53455,"content":53456,"nodeType":876},{},[53457,53460,53467],{"data":53458,"marks":53459,"value":21,"nodeType":867},{},[],{"data":53461,"content":53462,"nodeType":915},{"uri":42200},[53463],{"data":53464,"marks":53465,"value":53035,"nodeType":867},{},[53466],{"type":913},{"data":53468,"marks":53469,"value":21,"nodeType":867},{},[],{"data":53471,"content":53472,"nodeType":7628},{},[53473],{"data":53474,"content":53475,"nodeType":876},{},[53476,53479,53486],{"data":53477,"marks":53478,"value":21,"nodeType":867},{},[],{"data":53480,"content":53481,"nodeType":915},{"uri":53050},[53482],{"data":53483,"marks":53484,"value":333,"nodeType":867},{},[53485],{"type":913},{"data":53487,"marks":53488,"value":21,"nodeType":867},{},[],{"data":53490,"content":53491,"nodeType":7628},{},[53492],{"data":53493,"content":53494,"nodeType":876},{},[53495],{"data":53496,"marks":53497,"value":53068,"nodeType":867},{},[],{"data":53499,"content":53500,"nodeType":7628},{},[53501],{"data":53502,"content":53503,"nodeType":876},{},[53504],{"data":53505,"marks":53506,"value":53078,"nodeType":867},{},[],{"data":53508,"content":53509,"nodeType":7640},{},[53510,53531,53552,53562],{"data":53511,"content":53512,"nodeType":7628},{},[53513],{"data":53514,"content":53515,"nodeType":876},{},[53516,53519,53528],{"data":53517,"marks":53518,"value":21,"nodeType":867},{},[],{"data":53520,"content":53522,"nodeType":915},{"uri":53521},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/password_scraping/description.md",[53523],{"data":53524,"marks":53525,"value":53527,"nodeType":867},{},[53526],{"type":913},"SAT1028",{"data":53529,"marks":53530,"value":21,"nodeType":867},{},[],{"data":53532,"content":53533,"nodeType":7628},{},[53534],{"data":53535,"content":53536,"nodeType":876},{},[53537,53540,53549],{"data":53538,"marks":53539,"value":21,"nodeType":867},{},[],{"data":53541,"content":53543,"nodeType":915},{"uri":53542},"https://pushsecurity.com/resources/browser-identity-attacks-matrix/password-scraping",[53544],{"data":53545,"marks":53546,"value":53548,"nodeType":867},{},[53547],{"type":913},"Password Scraping",{"data":53550,"marks":53551,"value":21,"nodeType":867},{},[],{"data":53553,"content":53554,"nodeType":7628},{},[53555],{"data":53556,"content":53557,"nodeType":876},{},[53558],{"data":53559,"marks":53560,"value":53561,"nodeType":867},{},[],"Credential Access",{"data":53563,"content":53564,"nodeType":7628},{},[53565],{"data":53566,"content":53567,"nodeType":876},{},[53568],{"data":53569,"marks":53570,"value":53571,"nodeType":867},{},[],"Collection of credentials and secrets from repositories e.g. password managers, SaaS file stores, etc.",{"data":53573,"content":53574,"nodeType":1058},{},[53575],{"data":53576,"marks":53577,"value":52693,"nodeType":867},{},[],{"data":53579,"content":53580,"nodeType":876},{},[53581],{"data":53582,"marks":53583,"value":53585,"nodeType":867},{},[53584],{"type":865},"Cloudflare — November 2023",{"data":53587,"content":53588,"nodeType":876},{},[53589],{"data":53590,"marks":53591,"value":53592,"nodeType":867},{},[],"The threat actor used tokens and credentials that had not been rotated to breach Cloudflare’s internal Atlassian server and access its Confluence wiki, Jira bug database, and Bitbucket source code management system. The threat actor first gained access to Cloudflare's self-hosted Atlassian server and then accessed the company's Confluence and Jira systems following a reconnaissance stage. Cloudflare says that this breach did not impact customer data or systems or the provision of services.",{"data":53594,"content":53595,"nodeType":876},{},[53596],{"data":53597,"marks":53598,"value":53600,"nodeType":867},{},[53599],{"type":865},"1Password — October 2023",{"data":53602,"content":53603,"nodeType":876},{},[53604],{"data":53605,"marks":53606,"value":53607,"nodeType":867},{},[],"1Password reported unsolicited activity in their Okta environment which was traced to a suspicious IP address. Later it was confirmed that an threat actor had accessed 1Password’s Okta environment using administrative privileges. They attempted to access the IT team member’s user dashboard, but that attempt was blocked by Okta. They also requested a report of administrative users, which was identified as suspicious and triggered an investigation. 1Password says it terminated the activity, investigated, and found no compromise of user data or other sensitive systems, either employee-facing or user-facing.",{"data":53609,"content":53610,"nodeType":876},{},[53611],{"data":53612,"marks":53613,"value":53615,"nodeType":867},{},[53614],{"type":865},"BeyondTrust - October 2023",{"data":53617,"content":53618,"nodeType":876},{},[53619],{"data":53620,"marks":53621,"value":53622,"nodeType":867},{},[],"BeyondTrust security teams detected an identity-centric attack on an in-house Okta administrator account. BeyondTrust blocked all access to the threat actor, and verified that they did not gain access to any systems. BeyondTrust has confirmed that there was no additional exposure to our internal systems or BeyondTrust’s customers.",{"data":53624,"content":53625,"nodeType":942},{},[],{"data":53627,"content":53628,"nodeType":868},{},[53629],{"data":53630,"marks":53631,"value":53632,"nodeType":867},{},[],"MGM Resorts — September 2023",{"data":53634,"content":53635,"nodeType":876},{},[53636],{"data":53637,"marks":53638,"value":53639,"nodeType":867},{},[],"The threat group known as Scattered Spider socially engineered MGM help desk personnel to grant ‘super admin’ access to the Okta tenant, which was then used to steal data and deploy ransomware, resulting in significant business disruption. ",{"data":53641,"content":53642,"nodeType":1058},{},[53643],{"data":53644,"marks":53645,"value":53646,"nodeType":867},{},[],"How did MGM get breached?",{"data":53648,"content":53649,"nodeType":1629},{},[53650,53660,53670,53680,53690,53700],{"data":53651,"content":53652,"nodeType":1586},{},[53653],{"data":53654,"content":53655,"nodeType":876},{},[53656],{"data":53657,"marks":53658,"value":53659,"nodeType":867},{},[],"Scattered Spider researched MGM employees on LinkedIn to identify individuals likely to have privileged Okta access, specifically Super Administrator privileges. ",{"data":53661,"content":53662,"nodeType":1586},{},[53663],{"data":53664,"content":53665,"nodeType":876},{},[53666],{"data":53667,"marks":53668,"value":53669,"nodeType":867},{},[],"Scattered Spider contacted the IT help desk impersonating an employee with a privileged account asking for an authentication reset (password and MFA).",{"data":53671,"content":53672,"nodeType":1586},{},[53673],{"data":53674,"content":53675,"nodeType":876},{},[53676],{"data":53677,"marks":53678,"value":53679,"nodeType":867},{},[],"With privileged access, the compromised Super Administrator accounts were used to assign higher privileges to other accounts, circumventing MFA by removing enrolled authenticators and/or removing MFA from authentication policies.",{"data":53681,"content":53682,"nodeType":1586},{},[53683],{"data":53684,"content":53685,"nodeType":876},{},[53686],{"data":53687,"marks":53688,"value":53689,"nodeType":867},{},[],"Scattered Spider registered a second, attacker-controlled IdP via Org2Org using inbound federation, granting the ability to impersonate users and access applications on their behalf. By matching the username of target accounts in the second IdP to the original, the attacker was able to SSO into target applications. ",{"data":53691,"content":53692,"nodeType":1586},{},[53693],{"data":53694,"content":53695,"nodeType":876},{},[53696],{"data":53697,"marks":53698,"value":53699,"nodeType":867},{},[],"Through inbound federation, Scattered Spider obtained global admin rights in Azure, effectively granting full control over connected systems and granting domain admin privileges in target environments.",{"data":53701,"content":53702,"nodeType":1586},{},[53703],{"data":53704,"content":53705,"nodeType":876},{},[53706],{"data":53707,"marks":53708,"value":53709,"nodeType":867},{},[],"Scattered Spider deployed encryption software to around 100 ESXi servers and exfiltrated data, disrupting core business operations.",{"data":53711,"content":53712,"nodeType":1058},{},[53713],{"data":53714,"marks":53715,"value":53716,"nodeType":867},{},[],"What was the impact of the MGM breach?",{"data":53718,"content":53719,"nodeType":1629},{},[53720,53730,53740],{"data":53721,"content":53722,"nodeType":1586},{},[53723],{"data":53724,"content":53725,"nodeType":876},{},[53726],{"data":53727,"marks":53728,"value":53729,"nodeType":867},{},[],"Led to a 36-hour outage of multiple MGM IT systems and affected a number of its casinos on the Las Vegas strip, including the Bellagio, Excalibur, Luxor, Mandalay Bay and New York New York.",{"data":53731,"content":53732,"nodeType":1586},{},[53733],{"data":53734,"content":53735,"nodeType":876},{},[53736],{"data":53737,"marks":53738,"value":53739,"nodeType":867},{},[],"Personal data compromise of an unspecified number of customers including various contact information, dates of births, genders, driver’s license numbers, social security numbers, and passport information. ",{"data":53741,"content":53742,"nodeType":1586},{},[53743],{"data":53744,"content":53745,"nodeType":876},{},[53746],{"data":53747,"marks":53748,"value":53749,"nodeType":867},{},[],"MGM reported that the attack would cause a $100 million hit to its third-quarter results, including $10 million in one-time cyber security consulting fees. ",{"data":53751,"content":53752,"nodeType":1058},{},[53753],{"data":53754,"marks":53755,"value":53756,"nodeType":867},{},[],"What stands out in the MGM breach?",{"data":53758,"content":53759,"nodeType":1629},{},[53760,53770,53780],{"data":53761,"content":53762,"nodeType":1586},{},[53763],{"data":53764,"content":53765,"nodeType":876},{},[53766],{"data":53767,"marks":53768,"value":53769,"nodeType":867},{},[],"The MGM breach demonstrates how financially motivated organized criminal groups are specifically targeting the identity infrastructure of an organization (e.g. the chosen IdP solution) and leveraging cloud-native functionality. ",{"data":53771,"content":53772,"nodeType":1586},{},[53773],{"data":53774,"content":53775,"nodeType":876},{},[53776],{"data":53777,"marks":53778,"value":53779,"nodeType":867},{},[],"The MGM breach is notable for being a hybrid attack that ended in what has become a typical “actions on objective” for ransomware operators and their affiliates - the propagation of malware and encryption of core business servers. In this way attackers are leveraging the newer functionality that cloud services provide them to target non-cloud/on-premise resources. This potentially indicates that attackers see cloud applications and services as the path of least resistance to achieving their goals, exploiting more limited security team visibility and understanding of these services compared to more traditional (now well protected) targets. ",{"data":53781,"content":53782,"nodeType":1586},{},[53783],{"data":53784,"content":53785,"nodeType":876},{},[53786],{"data":53787,"marks":53788,"value":53789,"nodeType":867},{},[],"While attackers were focused on taking control of the cloud IdP, the initial access vector was notable for being a more traditional method (vishing) to bypass the need to acquire credentials (password and MFA token). This type of technique remains consistently effective, regardless of the technology landscape and whether MFA is correctly implemented or not.    ",{"data":53791,"content":53792,"nodeType":1058},{},[53793],{"data":53794,"marks":53795,"value":52508,"nodeType":867},{},[],{"data":53797,"content":53798,"nodeType":876},{},[53799],{"data":53800,"marks":53801,"value":52515,"nodeType":867},{},[],{"data":53803,"content":53804,"nodeType":7904},{},[53805,53844],{"data":53806,"content":53807,"nodeType":7640},{},[53808,53817,53826,53835],{"data":53809,"content":53810,"nodeType":20313},{},[53811],{"data":53812,"content":53813,"nodeType":876},{},[53814],{"data":53815,"marks":53816,"value":52531,"nodeType":867},{},[],{"data":53818,"content":53819,"nodeType":20313},{},[53820],{"data":53821,"content":53822,"nodeType":876},{},[53823],{"data":53824,"marks":53825,"value":52997,"nodeType":867},{},[],{"data":53827,"content":53828,"nodeType":20313},{},[53829],{"data":53830,"content":53831,"nodeType":876},{},[53832],{"data":53833,"marks":53834,"value":52551,"nodeType":867},{},[],{"data":53836,"content":53837,"nodeType":20313},{},[53838],{"data":53839,"content":53840,"nodeType":876},{},[53841],{"data":53842,"marks":53843,"value":52561,"nodeType":867},{},[],{"data":53845,"content":53846,"nodeType":7640},{},[53847,53867,53888,53898],{"data":53848,"content":53849,"nodeType":7628},{},[53850],{"data":53851,"content":53852,"nodeType":876},{},[53853,53856,53864],{"data":53854,"marks":53855,"value":21,"nodeType":867},{},[],{"data":53857,"content":53858,"nodeType":915},{"uri":27840},[53859],{"data":53860,"marks":53861,"value":53863,"nodeType":867},{},[53862],{"type":913},"SAT1041",{"data":53865,"marks":53866,"value":21,"nodeType":867},{},[],{"data":53868,"content":53869,"nodeType":7628},{},[53870],{"data":53871,"content":53872,"nodeType":876},{},[53873,53876,53885],{"data":53874,"marks":53875,"value":21,"nodeType":867},{},[],{"data":53877,"content":53879,"nodeType":915},{"uri":53878},"https://pushsecurity.com/resources/browser-identity-attacks-matrix/inbound-federation",[53880],{"data":53881,"marks":53882,"value":53884,"nodeType":867},{},[53883],{"type":913},"Inbound Federation",{"data":53886,"marks":53887,"value":21,"nodeType":867},{},[],{"data":53889,"content":53890,"nodeType":7628},{},[53891],{"data":53892,"content":53893,"nodeType":876},{},[53894],{"data":53895,"marks":53896,"value":53897,"nodeType":867},{},[],"Persistence; Lateral Movement",{"data":53899,"content":53900,"nodeType":7628},{},[53901],{"data":53902,"content":53903,"nodeType":876},{},[53904],{"data":53905,"marks":53906,"value":53907,"nodeType":867},{},[],"Inbound federation allows users to login to a target identity provider by authenticating with a source identity provider",{"data":53909,"content":53910,"nodeType":942},{},[],{"data":53912,"content":53913,"nodeType":868},{},[53914],{"data":53915,"marks":53916,"value":53917,"nodeType":867},{},[],"Retool — August 2023",{"data":53919,"content":53920,"nodeType":876},{},[53921],{"data":53922,"marks":53923,"value":53924,"nodeType":867},{},[],"Software development company Retool disclosed that the accounts of 27 of its cloud customers were compromised following a targeted SMS-based social engineering attack, which was enabled by Google Authenticator’s default synchronization of MFA tokens with the associated Google account.  ",{"data":53926,"content":53927,"nodeType":1058},{},[53928],{"data":53929,"marks":53930,"value":53931,"nodeType":867},{},[],"How did Retool get breached?",{"data":53933,"content":53934,"nodeType":1629},{},[53935,53945,53955,53965,53975,53985],{"data":53936,"content":53937,"nodeType":1586},{},[53938],{"data":53939,"content":53940,"nodeType":876},{},[53941],{"data":53942,"marks":53943,"value":53944,"nodeType":867},{},[],"The threat actor launched a targeted SMS-based phishing campaign against Retool employees with a custom lure relating to their workplace healthcare coverage.",{"data":53946,"content":53947,"nodeType":1586},{},[53948],{"data":53949,"content":53950,"nodeType":876},{},[53951],{"data":53952,"marks":53953,"value":53954,"nodeType":867},{},[],"The timing coincided with a recently announced migration of logins to Okta, and the message contained a url disguised to look like their internal identity portal.",{"data":53956,"content":53957,"nodeType":1586},{},[53958],{"data":53959,"content":53960,"nodeType":876},{},[53961],{"data":53962,"marks":53963,"value":53964,"nodeType":867},{},[],"After logging into the fake portal – which included an MFA form – the threat actor called the employee impersonating an IT team member, deepfaking the IT employee’s real voice and using real information about the company to build trust.",{"data":53966,"content":53967,"nodeType":1586},{},[53968],{"data":53969,"content":53970,"nodeType":876},{},[53971],{"data":53972,"marks":53973,"value":53974,"nodeType":867},{},[],"The phished employee shared an MFA OTP token which allowed the threat actor to add their own personal device to the employee’s Okta account and enabled their own Okta MFA from that point forward.",{"data":53976,"content":53977,"nodeType":1586},{},[53978],{"data":53979,"content":53980,"nodeType":876},{},[53981],{"data":53982,"marks":53983,"value":53984,"nodeType":867},{},[],"Due to the Google Authenticator synchronization feature that syncs MFA codes to the cloud by default, meaning that access to a Google account immediately gave access to all MFA tokens held within that account.",{"data":53986,"content":53987,"nodeType":1586},{},[53988],{"data":53989,"content":53990,"nodeType":876},{},[53991],{"data":53992,"marks":53993,"value":53994,"nodeType":867},{},[],"This enabled the threat actor to take over a number of identities associated with a range of target apps and change the credentials.",{"data":53996,"content":53997,"nodeType":1058},{},[53998],{"data":53999,"marks":54000,"value":54001,"nodeType":867},{},[],"What was the impact of the Retool breach?",{"data":54003,"content":54004,"nodeType":1629},{},[54005,54015,54025],{"data":54006,"content":54007,"nodeType":1586},{},[54008],{"data":54009,"content":54010,"nodeType":876},{},[54011],{"data":54012,"marks":54013,"value":54014,"nodeType":867},{},[],"A total of 27 customers were impacted, with the threat actor specifically targeting customers in the Crypto industry.",{"data":54016,"content":54017,"nodeType":1586},{},[54018],{"data":54019,"content":54020,"nodeType":876},{},[54021],{"data":54022,"marks":54023,"value":54024,"nodeType":867},{},[],"After taking over the accounts, the threat actor was observed gathering information and exploring the Retool apps.",{"data":54026,"content":54027,"nodeType":1586},{},[54028],{"data":54029,"content":54030,"nodeType":876},{},[54031],{"data":54032,"marks":54033,"value":54034,"nodeType":867},{},[],"After learning of the attack, Retool revoked all internal authenticated sessions (Okta, GSuite, etc.) for employees, locked down access to the affected accounts, notified the affected customers, and restored their accounts to their original state.",{"data":54036,"content":54037,"nodeType":1058},{},[54038],{"data":54039,"marks":54040,"value":54041,"nodeType":867},{},[],"What stands out in the Retool breach?",{"data":54043,"content":54044,"nodeType":1629},{},[54045,54055,54065],{"data":54046,"content":54047,"nodeType":1586},{},[54048],{"data":54049,"content":54050,"nodeType":876},{},[54051],{"data":54052,"marks":54053,"value":54054,"nodeType":867},{},[],"Like the MGM breach, the Retool breach demonstrates how financially motivated organized criminal groups are specifically targeting the identity infrastructure of an organization (e.g. the chosen IdP solution) and leveraging cloud-native functionality. ",{"data":54056,"content":54057,"nodeType":1586},{},[54058],{"data":54059,"content":54060,"nodeType":876},{},[54061],{"data":54062,"marks":54063,"value":54064,"nodeType":867},{},[],"A further similarity with the MGM breach, while attackers were focused on taking control of the cloud IdP, the initial access vector was notable for being a more traditional method (SMS phishing in this case) to bypass the need to acquire credentials (password and MFA token). This type of technique remains consistently effective, regardless of the technology landscape and whether MFA is correctly implemented or not.    ",{"data":54066,"content":54067,"nodeType":1586},{},[54068],{"data":54069,"content":54070,"nodeType":876},{},[54071],{"data":54072,"marks":54073,"value":54074,"nodeType":867},{},[],"In this case, the attacker abused inherent weaknesses in Google Authenticator, which came under fire following the breach for its default synchronization of MFA codes to the cloud when connected to an account, in order to move laterally and compromise other target apps. ",{"data":54076,"content":54077,"nodeType":1058},{},[54078],{"data":54079,"marks":54080,"value":52508,"nodeType":867},{},[],{"data":54082,"content":54083,"nodeType":876},{},[54084],{"data":54085,"marks":54086,"value":52515,"nodeType":867},{},[],{"data":54088,"content":54089,"nodeType":7904},{},[54090,54129,54194],{"data":54091,"content":54092,"nodeType":7640},{},[54093,54102,54111,54120],{"data":54094,"content":54095,"nodeType":20313},{},[54096],{"data":54097,"content":54098,"nodeType":876},{},[54099],{"data":54100,"marks":54101,"value":52531,"nodeType":867},{},[],{"data":54103,"content":54104,"nodeType":20313},{},[54105],{"data":54106,"content":54107,"nodeType":876},{},[54108],{"data":54109,"marks":54110,"value":52997,"nodeType":867},{},[],{"data":54112,"content":54113,"nodeType":20313},{},[54114],{"data":54115,"content":54116,"nodeType":876},{},[54117],{"data":54118,"marks":54119,"value":52551,"nodeType":867},{},[],{"data":54121,"content":54122,"nodeType":20313},{},[54123],{"data":54124,"content":54125,"nodeType":876},{},[54126],{"data":54127,"marks":54128,"value":52561,"nodeType":867},{},[],{"data":54130,"content":54131,"nodeType":7640},{},[54132,54153,54175,54184],{"data":54133,"content":54134,"nodeType":7628},{},[54135],{"data":54136,"content":54137,"nodeType":876},{},[54138,54142,54150],{"data":54139,"marks":54140,"value":21,"nodeType":867},{},[54141],{"type":913},{"data":54143,"content":54144,"nodeType":915},{"uri":42153},[54145],{"data":54146,"marks":54147,"value":54149,"nodeType":867},{},[54148],{"type":913},"SAT1042",{"data":54151,"marks":54152,"value":21,"nodeType":867},{},[],{"data":54154,"content":54155,"nodeType":7628},{},[54156],{"data":54157,"content":54158,"nodeType":876},{},[54159,54163,54172],{"data":54160,"marks":54161,"value":21,"nodeType":867},{},[54162],{"type":913},{"data":54164,"content":54166,"nodeType":915},{"uri":54165},"https://pushsecurity.com/resources/browser-identity-attacks-matrix/aitm-phishing",[54167],{"data":54168,"marks":54169,"value":54171,"nodeType":867},{},[54170],{"type":913},"AiTM Phishing",{"data":54173,"marks":54174,"value":21,"nodeType":867},{},[],{"data":54176,"content":54177,"nodeType":7628},{},[54178],{"data":54179,"content":54180,"nodeType":876},{},[54181],{"data":54182,"marks":54183,"value":53068,"nodeType":867},{},[],{"data":54185,"content":54186,"nodeType":7628},{},[54187],{"data":54188,"content":54189,"nodeType":876},{},[54190],{"data":54191,"marks":54192,"value":54193,"nodeType":867},{},[],"Attacker-in-the-Middle (AiTM) phishing uses dedicated tooling to act as a web proxy between the victim and a legitimate login portal for an application the victim has access to, principally to make it easier to defeat MFA protection.",{"data":54195,"content":54196,"nodeType":7640},{},[54197,54218,54241,54251],{"data":54198,"content":54199,"nodeType":7628},{},[54200],{"data":54201,"content":54202,"nodeType":876},{},[54203,54206,54215],{"data":54204,"marks":54205,"value":21,"nodeType":867},{},[],{"data":54207,"content":54209,"nodeType":915},{"uri":54208},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/device_enrollment/description.md",[54210],{"data":54211,"marks":54212,"value":54214,"nodeType":867},{},[54213],{"type":913},"SAT1043",{"data":54216,"marks":54217,"value":21,"nodeType":867},{},[],{"data":54219,"content":54220,"nodeType":7628},{},[54221],{"data":54222,"content":54223,"nodeType":876},{},[54224,54228,54237],{"data":54225,"marks":54226,"value":21,"nodeType":867},{},[54227],{"type":913},{"data":54229,"content":54231,"nodeType":915},{"uri":54230},"https://pushsecurity.com/resources/browser-identity-attacks-matrix/device-enrollment",[54232],{"data":54233,"marks":54234,"value":54236,"nodeType":867},{},[54235],{"type":913},"Device Enrollment",{"data":54238,"marks":54239,"value":21,"nodeType":867},{},[54240],{"type":913},{"data":54242,"content":54243,"nodeType":7628},{},[54244],{"data":54245,"content":54246,"nodeType":876},{},[54247],{"data":54248,"marks":54249,"value":54250,"nodeType":867},{},[],"Initial Access; Persistence",{"data":54252,"content":54253,"nodeType":7628},{},[54254],{"data":54255,"content":54256,"nodeType":876},{},[54257],{"data":54258,"marks":54259,"value":54260,"nodeType":867},{},[],"Enrollment of a new MFA device in order to allow an adversary to complete MFA challenges for future authentication. ",{"data":54262,"content":54263,"nodeType":942},{},[],{"data":54265,"content":54266,"nodeType":868},{},[54267],{"data":54268,"marks":54269,"value":54270,"nodeType":867},{},[],"GitHub / Heroku / Travis-CI / npm — April 2022",{"data":54272,"content":54273,"nodeType":876},{},[54274],{"data":54275,"marks":54276,"value":54277,"nodeType":867},{},[],"An unknown threat actor used stolen OAuth user tokens (issued to Heroku and Travis-CI) to download data from private repositories. The threat actor then compromised an internal Heroku customer database as well as accessed and stole data from dozens of downstream organizations using Heroku and Travis-CI-maintained OAuth apps.",{"data":54279,"content":54280,"nodeType":1058},{},[54281],{"data":54282,"marks":54283,"value":54284,"nodeType":867},{},[],"How did they get breached?",{"data":54286,"content":54287,"nodeType":1629},{},[54288,54298,54308,54318,54328,54338,54348],{"data":54289,"content":54290,"nodeType":1586},{},[54291],{"data":54292,"content":54293,"nodeType":876},{},[54294],{"data":54295,"marks":54296,"value":54297,"nodeType":867},{},[],"The threat actor obtained access to two third-party OAuth integrators, Heroku and Travis-CI, accessing databases and downloading stored customer GitHub integration OAuth tokens. These tokens had earlier been used by Travis-CI and Heroku OAuth applications to integrate with GitHub to deploy applications.",{"data":54299,"content":54300,"nodeType":1586},{},[54301],{"data":54302,"content":54303,"nodeType":876},{},[54304],{"data":54305,"marks":54306,"value":54307,"nodeType":867},{},[],"Access to the environment was gained by leveraging a compromised token for a Heroku machine account, but it is not disclosed how the threat actor achieved this. ",{"data":54309,"content":54310,"nodeType":1586},{},[54311],{"data":54312,"content":54313,"nodeType":876},{},[54314],{"data":54315,"marks":54316,"value":54317,"nodeType":867},{},[],"The threat actor authenticated to the GitHub API using the stolen OAuth tokens issued to Heroku and Travis CI.",{"data":54319,"content":54320,"nodeType":1586},{},[54321],{"data":54322,"content":54323,"nodeType":876},{},[54324],{"data":54325,"marks":54326,"value":54327,"nodeType":867},{},[],"For users who had the affected Heroku or Travis CI OAuth apps authorized in their GitHub accounts, the threat actor listed all the user's organizations.",{"data":54329,"content":54330,"nodeType":1586},{},[54331],{"data":54332,"content":54333,"nodeType":876},{},[54334],{"data":54335,"marks":54336,"value":54337,"nodeType":867},{},[],"The threat actor then selected targets based on the listed organizations.",{"data":54339,"content":54340,"nodeType":1586},{},[54341],{"data":54342,"content":54343,"nodeType":876},{},[54344],{"data":54345,"marks":54346,"value":54347,"nodeType":867},{},[],"The threat actor listed the private repositories for user accounts of interest and proceeded to clone private repositories of interest.",{"data":54349,"content":54350,"nodeType":1586},{},[54351],{"data":54352,"content":54353,"nodeType":876},{},[54354],{"data":54355,"marks":54356,"value":54357,"nodeType":867},{},[],"GitHub identified unauthorized access to their npm production infrastructure using a compromised AWS API key, obtained by the threat actor when they downloaded a set of private npm repositories using a stolen OAuth token from one of the two affected third-party OAuth applications.",{"data":54359,"content":54360,"nodeType":1058},{},[54361],{"data":54362,"marks":54363,"value":54364,"nodeType":867},{},[],"What was the impact?",{"data":54366,"content":54367,"nodeType":1629},{},[54368,54378,54388],{"data":54369,"content":54370,"nodeType":1586},{},[54371],{"data":54372,"content":54373,"nodeType":876},{},[54374],{"data":54375,"marks":54376,"value":54377,"nodeType":867},{},[],"By stealing these OAuth tokens, the threat actor could access and download data from GitHub repositories belonging to those who authorized the compromised Heroku or Travis CI OAuth apps with their accounts. ",{"data":54379,"content":54380,"nodeType":1586},{},[54381],{"data":54382,"content":54383,"nodeType":876},{},[54384],{"data":54385,"marks":54386,"value":54387,"nodeType":867},{},[],"The threat actor was able to mine the downloaded private repositories for secrets that could be used to pivot to other infrastructure, stealing data from dozens of organizations. ",{"data":54389,"content":54390,"nodeType":1586},{},[54391],{"data":54392,"content":54393,"nodeType":876},{},[54394],{"data":54395,"marks":54396,"value":54397,"nodeType":867},{},[],"In addition to user repo’s downstream, the compromised token for a Heroku machine account obtained by threat actors also allowed unauthorized access into Heroku's internal database of customer accounts, enabling the threat actor to extract the hashed and salted passwords. ",{"data":54399,"content":54400,"nodeType":1058},{},[54401],{"data":54402,"marks":54403,"value":54404,"nodeType":867},{},[],"What stands out in the Github breach?",{"data":54406,"content":54407,"nodeType":1629},{},[54408,54418,54428],{"data":54409,"content":54410,"nodeType":1586},{},[54411],{"data":54412,"content":54413,"nodeType":876},{},[54414],{"data":54415,"marks":54416,"value":54417,"nodeType":867},{},[],"Similar to the Okta breach, this attack showcases the possibility of third-party supply chain attacks to target downstream organizations using cloud SaaS services. In this case, targeting OAuth integrators as opposed to IdP providers, but with a similar goal and impact of compromising the real target organizations downstream. ",{"data":54419,"content":54420,"nodeType":1586},{},[54421],{"data":54422,"content":54423,"nodeType":876},{},[54424],{"data":54425,"marks":54426,"value":54427,"nodeType":867},{},[],"Applications like Github are an obvious target for attackers due to their widespread adoption. There have been numerous attacks leveraging Github as the vehicle for attacks by compromising repo’s to insert malicious code, or registering malicious copycat repo’s to dupe users into using them. ",{"data":54429,"content":54430,"nodeType":1586},{},[54431],{"data":54432,"content":54433,"nodeType":876},{},[54434],{"data":54435,"marks":54436,"value":54437,"nodeType":867},{},[],"Unlike the attacks abusing the functionality of Github (repo poisoning) which target the legitimate developer processes when using the app, this attack could have been prevented at the identity layer before the attacker was able to breach the Heroku/Travis-CI accounts. ",{"data":54439,"content":54440,"nodeType":1058},{},[54441],{"data":54442,"marks":54443,"value":52508,"nodeType":867},{},[],{"data":54445,"content":54446,"nodeType":876},{},[54447],{"data":54448,"marks":54449,"value":52515,"nodeType":867},{},[],{"data":54451,"content":54452,"nodeType":7904},{},[54453,54492,54552,54615],{"data":54454,"content":54455,"nodeType":7640},{},[54456,54465,54474,54483],{"data":54457,"content":54458,"nodeType":20313},{},[54459],{"data":54460,"content":54461,"nodeType":876},{},[54462],{"data":54463,"marks":54464,"value":52531,"nodeType":867},{},[],{"data":54466,"content":54467,"nodeType":20313},{},[54468],{"data":54469,"content":54470,"nodeType":876},{},[54471],{"data":54472,"marks":54473,"value":52997,"nodeType":867},{},[],{"data":54475,"content":54476,"nodeType":20313},{},[54477],{"data":54478,"content":54479,"nodeType":876},{},[54480],{"data":54481,"marks":54482,"value":52551,"nodeType":867},{},[],{"data":54484,"content":54485,"nodeType":20313},{},[54486],{"data":54487,"content":54488,"nodeType":876},{},[54489],{"data":54490,"marks":54491,"value":52561,"nodeType":867},{},[],{"data":54493,"content":54494,"nodeType":7640},{},[54495,54514,54533,54543],{"data":54496,"content":54497,"nodeType":7628},{},[54498],{"data":54499,"content":54500,"nodeType":876},{},[54501,54504,54511],{"data":54502,"marks":54503,"value":21,"nodeType":867},{},[],{"data":54505,"content":54506,"nodeType":915},{"uri":43027},[54507],{"data":54508,"marks":54509,"value":53161,"nodeType":867},{},[54510],{"type":913},{"data":54512,"marks":54513,"value":21,"nodeType":867},{},[],{"data":54515,"content":54516,"nodeType":7628},{},[54517],{"data":54518,"content":54519,"nodeType":876},{},[54520,54523,54530],{"data":54521,"marks":54522,"value":21,"nodeType":867},{},[],{"data":54524,"content":54525,"nodeType":915},{"uri":53176},[54526],{"data":54527,"marks":54528,"value":53182,"nodeType":867},{},[54529],{"type":913},{"data":54531,"marks":54532,"value":21,"nodeType":867},{},[],{"data":54534,"content":54535,"nodeType":7628},{},[54536],{"data":54537,"content":54538,"nodeType":876},{},[54539],{"data":54540,"marks":54541,"value":54542,"nodeType":867},{},[],"Privilege Escalation; Lateral Movement",{"data":54544,"content":54545,"nodeType":7628},{},[54546],{"data":54547,"content":54548,"nodeType":876},{},[54549],{"data":54550,"marks":54551,"value":53205,"nodeType":867},{},[],{"data":54553,"content":54554,"nodeType":7640},{},[54555,54575,54595,54605],{"data":54556,"content":54557,"nodeType":7628},{},[54558],{"data":54559,"content":54560,"nodeType":876},{},[54561,54564,54572],{"data":54562,"marks":54563,"value":21,"nodeType":867},{},[],{"data":54565,"content":54566,"nodeType":915},{"uri":26258},[54567],{"data":54568,"marks":54569,"value":54571,"nodeType":867},{},[54570],{"type":913},"SAT1004",{"data":54573,"marks":54574,"value":21,"nodeType":867},{},[],{"data":54576,"content":54577,"nodeType":7628},{},[54578],{"data":54579,"content":54580,"nodeType":876},{},[54581,54584,54592],{"data":54582,"marks":54583,"value":21,"nodeType":867},{},[],{"data":54585,"content":54587,"nodeType":915},{"uri":54586},"https://pushsecurity.com/resources/browser-identity-attacks-matrix/api-keys",[54588],{"data":54589,"marks":54590,"value":42812,"nodeType":867},{},[54591],{"type":913},{"data":54593,"marks":54594,"value":21,"nodeType":867},{},[],{"data":54596,"content":54597,"nodeType":7628},{},[54598],{"data":54599,"content":54600,"nodeType":876},{},[54601],{"data":54602,"marks":54603,"value":54604,"nodeType":867},{},[],"Persistence; Defense Evasion",{"data":54606,"content":54607,"nodeType":7628},{},[54608],{"data":54609,"content":54610,"nodeType":876},{},[54611],{"data":54612,"marks":54613,"value":54614,"nodeType":867},{},[],"An adversary that has compromised an account could then read existing API keys from the app settings, if the app allows this, or create a new API key.",{"data":54616,"content":54617,"nodeType":7640},{},[54618,54639,54660,54670],{"data":54619,"content":54620,"nodeType":7628},{},[54621],{"data":54622,"content":54623,"nodeType":876},{},[54624,54627,54636],{"data":54625,"marks":54626,"value":21,"nodeType":867},{},[],{"data":54628,"content":54630,"nodeType":915},{"uri":54629},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/app_directory_lookup/description.md#app-directory-lookup",[54631],{"data":54632,"marks":54633,"value":54635,"nodeType":867},{},[54634],{"type":913},"SAT1006",{"data":54637,"marks":54638,"value":21,"nodeType":867},{},[],{"data":54640,"content":54641,"nodeType":7628},{},[54642],{"data":54643,"content":54644,"nodeType":876},{},[54645,54648,54657],{"data":54646,"marks":54647,"value":21,"nodeType":867},{},[],{"data":54649,"content":54651,"nodeType":915},{"uri":54650},"https://pushsecurity.com/resources/browser-identity-attacks-matrix/app-directory-lookup",[54652],{"data":54653,"marks":54654,"value":54656,"nodeType":867},{},[54655],{"type":913},"App directory lookup",{"data":54658,"marks":54659,"value":21,"nodeType":867},{},[],{"data":54661,"content":54662,"nodeType":7628},{},[54663],{"data":54664,"content":54665,"nodeType":876},{},[54666],{"data":54667,"marks":54668,"value":54669,"nodeType":867},{},[],"Discovery",{"data":54671,"content":54672,"nodeType":7628},{},[54673],{"data":54674,"content":54675,"nodeType":876},{},[54676],{"data":54677,"marks":54678,"value":54679,"nodeType":867},{},[],"An adversary who has gained a foothold via a SaaS app could download the list of users accessible to them in order to better target attacks against other users.",{"data":54681,"content":54682,"nodeType":942},{},[],{"data":54684,"content":54685,"nodeType":868},{},[54686],{"data":54687,"marks":54688,"value":54689,"nodeType":867},{},[],"Other notable attacks",{"data":54691,"content":54692,"nodeType":1058},{},[54693],{"data":54694,"marks":54695,"value":54696,"nodeType":867},{},[],"SEC X hack — January 2024",{"data":54698,"content":54699,"nodeType":876},{},[54700],{"data":54701,"marks":54702,"value":54703,"nodeType":867},{},[],"The X account for the U.S. Securities and Exchange Commission was victim to a SIM swapping attack, whereupon the attacker used the social media platform to issue a fake announcement on the approval of Bitcoin ETFs on security exchanges.",{"data":54705,"content":54706,"nodeType":876},{},[54707],{"data":54708,"marks":54709,"value":54710,"nodeType":867},{},[],"Once the threat actors controlled the number, they reset the password for the @SECGov account, and created the fake announcement. The SEC also confirmed that multi-factor authentication was not enabled on the account, as they had asked X support to disable it when they encountered problems logging into the account.",{"data":54712,"content":54713,"nodeType":942},{},[],{"data":54715,"content":54716,"nodeType":1058},{},[54717],{"data":54718,"marks":54719,"value":54720,"nodeType":867},{},[],"Mandiant X hack — January 2024",{"data":54722,"content":54723,"nodeType":876},{},[54724],{"data":54725,"marks":54726,"value":54727,"nodeType":867},{},[],"The X account for Mandiant was hacked by a Drainer-as-a-Service (DaaS) gang in a brute force attack. MFA was not enabled on the account. The threat actor used the social media account to share links redirecting to a phishing page to steal cryptocurrency. ",{"data":54729,"content":54730,"nodeType":876},{},[54731],{"data":54732,"marks":54733,"value":54734,"nodeType":867},{},[],"The attacker used a wallet drainer dubbed CLINKSINK. This same drainer has been used since December to steal funds and tokens from users of Solana cryptocurrency as part of a large-scale campaign involving at least 35 affiliate IDs linked to a shared DaaS.",{"data":54736,"content":54737,"nodeType":942},{},[],{"data":54739,"content":54740,"nodeType":1058},{},[54741],{"data":54742,"marks":54743,"value":54744,"nodeType":867},{},[],"23andMe data breach — April 2023",{"data":54746,"content":54747,"nodeType":876},{},[54748],{"data":54749,"marks":54750,"value":54751,"nodeType":867},{},[],"Genetic testing provider 23andMe confirmed that hackers downloaded the data of 6.9 million people of the existing 14 million customers after breaching around 14,000 user accounts. ",{"data":54753,"content":54754,"nodeType":876},{},[54755],{"data":54756,"marks":54757,"value":54758,"nodeType":867},{},[],"The attacker stole health reports and raw genotype data of customers affected by a credential stuffing attack that went unnoticed for five months, from April 29 to September 27. ",{"data":54760,"content":54761,"nodeType":876},{},[54762],{"data":54763,"marks":54764,"value":54765,"nodeType":867},{},[],"The credentials used by the attackers to breach the customers' accounts were stolen in other data breaches or used on previously compromised online platforms, and targeted accounts without MFA. ","Tracking identity-based attacks in the wild","To help organizations keep track of how browser-based identity attacks are evolving, we've put together this index of recent breaches.","2024-03-21T00:00:00.000Z","identity-attacks-in-the-wild",{"items":54771},[54772,54774],{"sys":54773,"name":4018},{"id":4017},{"sys":54775,"name":342},{"id":3240},{"items":54777},[54778],{"fullName":4022,"firstName":4023,"jobTitle":4024,"profilePicture":54779},{"url":4026},{"__typename":1772,"sys":54781,"content":54782,"title":39236,"synopsis":39237,"hashTags":59,"publishedDate":39238,"slug":39239,"tagsCollection":55459,"authorsCollection":55465},{"id":38447},{"json":54783},{"data":54784,"content":54785,"nodeType":1680},{},[54786,54791,54797,54839,54845,54851,54864,54870,54876,54945,54951,54956,54962,54968,54981,54987,54993,55013,55033,55038,55055,55061,55067,55094,55100,55106,55111,55128,55134,55140,55146,55152,55157,55174,55180,55186,55192,55198,55203,55220,55226,55232,55237,55254,55260,55266,55272,55314,55320,55381,55394,55399,55405,55411,55417,55423,55438,55444],{"data":54787,"content":54790,"nodeType":985},{"target":54788},{"sys":54789},{"id":38456,"type":982,"linkType":983},[],{"data":54792,"content":54793,"nodeType":876},{},[54794],{"data":54795,"marks":54796,"value":38464,"nodeType":867},{},[],{"data":54798,"content":54799,"nodeType":876},{},[54800,54803,54809,54812,54818,54821,54827,54830,54836],{"data":54801,"marks":54802,"value":38471,"nodeType":867},{},[],{"data":54804,"content":54805,"nodeType":915},{"uri":38474},[54806],{"data":54807,"marks":54808,"value":38479,"nodeType":867},{},[],{"data":54810,"marks":54811,"value":2136,"nodeType":867},{},[],{"data":54813,"content":54814,"nodeType":915},{"uri":38485},[54815],{"data":54816,"marks":54817,"value":38490,"nodeType":867},{},[],{"data":54819,"marks":54820,"value":2136,"nodeType":867},{},[],{"data":54822,"content":54823,"nodeType":915},{"uri":2177},[54824],{"data":54825,"marks":54826,"value":38500,"nodeType":867},{},[],{"data":54828,"marks":54829,"value":2136,"nodeType":867},{},[],{"data":54831,"content":54832,"nodeType":915},{"uri":38506},[54833],{"data":54834,"marks":54835,"value":38511,"nodeType":867},{},[],{"data":54837,"marks":54838,"value":38515,"nodeType":867},{},[],{"data":54840,"content":54841,"nodeType":876},{},[54842],{"data":54843,"marks":54844,"value":38522,"nodeType":867},{},[],{"data":54846,"content":54847,"nodeType":876},{},[54848],{"data":54849,"marks":54850,"value":38529,"nodeType":867},{},[],{"data":54852,"content":54853,"nodeType":876},{},[54854,54857,54861],{"data":54855,"marks":54856,"value":38536,"nodeType":867},{},[],{"data":54858,"marks":54859,"value":38541,"nodeType":867},{},[54860],{"type":865},{"data":54862,"marks":54863,"value":1679,"nodeType":867},{},[],{"data":54865,"content":54866,"nodeType":876},{},[54867],{"data":54868,"marks":54869,"value":38551,"nodeType":867},{},[],{"data":54871,"content":54872,"nodeType":876},{},[54873],{"data":54874,"marks":54875,"value":38558,"nodeType":867},{},[],{"data":54877,"content":54878,"nodeType":1629},{},[54879,54904],{"data":54880,"content":54881,"nodeType":1586},{},[54882],{"data":54883,"content":54884,"nodeType":876},{},[54885,54889,54892,54901],{"data":54886,"marks":54887,"value":38572,"nodeType":867},{},[54888],{"type":865},{"data":54890,"marks":54891,"value":38576,"nodeType":867},{},[],{"data":54893,"content":54896,"nodeType":17452},{"target":54894},{"sys":54895},{"id":38581,"type":982,"linkType":983},[54897],{"data":54898,"marks":54899,"value":25043,"nodeType":867},{},[54900],{"type":865},{"data":54902,"marks":54903,"value":38590,"nodeType":867},{},[],{"data":54905,"content":54906,"nodeType":1586},{},[54907],{"data":54908,"content":54909,"nodeType":876},{},[54910,54914,54917,54923,54926,54932,54935,54942],{"data":54911,"marks":54912,"value":38601,"nodeType":867},{},[54913],{"type":865},{"data":54915,"marks":54916,"value":38605,"nodeType":867},{},[],{"data":54918,"content":54919,"nodeType":915},{"uri":38608},[54920],{"data":54921,"marks":54922,"value":38613,"nodeType":867},{},[],{"data":54924,"marks":54925,"value":5136,"nodeType":867},{},[],{"data":54927,"content":54928,"nodeType":915},{"uri":38619},[54929],{"data":54930,"marks":54931,"value":38624,"nodeType":867},{},[],{"data":54933,"marks":54934,"value":38628,"nodeType":867},{},[],{"data":54936,"content":54937,"nodeType":915},{"uri":38631},[54938],{"data":54939,"marks":54940,"value":38637,"nodeType":867},{},[54941],{"type":865},{"data":54943,"marks":54944,"value":38641,"nodeType":867},{},[],{"data":54946,"content":54947,"nodeType":876},{},[54948],{"data":54949,"marks":54950,"value":38648,"nodeType":867},{},[],{"data":54952,"content":54955,"nodeType":985},{"target":54953},{"sys":54954},{"id":38653,"type":982,"linkType":983},[],{"data":54957,"content":54958,"nodeType":868},{},[54959],{"data":54960,"marks":54961,"value":38661,"nodeType":867},{},[],{"data":54963,"content":54964,"nodeType":876},{},[54965],{"data":54966,"marks":54967,"value":38668,"nodeType":867},{},[],{"data":54969,"content":54970,"nodeType":876},{},[54971,54974,54978],{"data":54972,"marks":54973,"value":38675,"nodeType":867},{},[],{"data":54975,"marks":54976,"value":25043,"nodeType":867},{},[54977],{"type":865},{"data":54979,"marks":54980,"value":38683,"nodeType":867},{},[],{"data":54982,"content":54983,"nodeType":876},{},[54984],{"data":54985,"marks":54986,"value":38690,"nodeType":867},{},[],{"data":54988,"content":54989,"nodeType":1058},{},[54990],{"data":54991,"marks":54992,"value":38697,"nodeType":867},{},[],{"data":54994,"content":54995,"nodeType":876},{},[54996,54999,55003,55006,55010],{"data":54997,"marks":54998,"value":38704,"nodeType":867},{},[],{"data":55000,"marks":55001,"value":38709,"nodeType":867},{},[55002],{"type":865},{"data":55004,"marks":55005,"value":1174,"nodeType":867},{},[],{"data":55007,"marks":55008,"value":38717,"nodeType":867},{},[55009],{"type":865},{"data":55011,"marks":55012,"value":1679,"nodeType":867},{},[],{"data":55014,"content":55015,"nodeType":876},{},[55016,55019,55023,55026,55030],{"data":55017,"marks":55018,"value":38727,"nodeType":867},{},[],{"data":55020,"marks":55021,"value":38732,"nodeType":867},{},[55022],{"type":865},{"data":55024,"marks":55025,"value":21631,"nodeType":867},{},[],{"data":55027,"marks":55028,"value":38740,"nodeType":867},{},[55029],{"type":865},{"data":55031,"marks":55032,"value":38744,"nodeType":867},{},[],{"data":55034,"content":55037,"nodeType":985},{"target":55035},{"sys":55036},{"id":38749,"type":982,"linkType":983},[],{"data":55039,"content":55040,"nodeType":876},{},[55041,55044,55052],{"data":55042,"marks":55043,"value":38757,"nodeType":867},{},[],{"data":55045,"content":55048,"nodeType":17452},{"target":55046},{"sys":55047},{"id":38762,"type":982,"linkType":983},[55049],{"data":55050,"marks":55051,"value":38767,"nodeType":867},{},[],{"data":55053,"marks":55054,"value":21,"nodeType":867},{},[],{"data":55056,"content":55057,"nodeType":1058},{},[55058],{"data":55059,"marks":55060,"value":38777,"nodeType":867},{},[],{"data":55062,"content":55063,"nodeType":876},{},[55064],{"data":55065,"marks":55066,"value":38784,"nodeType":867},{},[],{"data":55068,"content":55069,"nodeType":876},{},[55070,55073,55077,55080,55084,55087,55091],{"data":55071,"marks":55072,"value":38791,"nodeType":867},{},[],{"data":55074,"marks":55075,"value":38732,"nodeType":867},{},[55076],{"type":865},{"data":55078,"marks":55079,"value":21631,"nodeType":867},{},[],{"data":55081,"marks":55082,"value":38740,"nodeType":867},{},[55083],{"type":865},{"data":55085,"marks":55086,"value":38806,"nodeType":867},{},[],{"data":55088,"marks":55089,"value":38811,"nodeType":867},{},[55090],{"type":865},{"data":55092,"marks":55093,"value":38815,"nodeType":867},{},[],{"data":55095,"content":55096,"nodeType":876},{},[55097],{"data":55098,"marks":55099,"value":38822,"nodeType":867},{},[],{"data":55101,"content":55102,"nodeType":876},{},[55103],{"data":55104,"marks":55105,"value":38829,"nodeType":867},{},[],{"data":55107,"content":55110,"nodeType":985},{"target":55108},{"sys":55109},{"id":38834,"type":982,"linkType":983},[],{"data":55112,"content":55113,"nodeType":876},{},[55114,55117,55125],{"data":55115,"marks":55116,"value":38757,"nodeType":867},{},[],{"data":55118,"content":55121,"nodeType":17452},{"target":55119},{"sys":55120},{"id":38846,"type":982,"linkType":983},[55122],{"data":55123,"marks":55124,"value":38777,"nodeType":867},{},[],{"data":55126,"marks":55127,"value":21,"nodeType":867},{},[],{"data":55129,"content":55130,"nodeType":1058},{},[55131],{"data":55132,"marks":55133,"value":38860,"nodeType":867},{},[],{"data":55135,"content":55136,"nodeType":876},{},[55137],{"data":55138,"marks":55139,"value":38867,"nodeType":867},{},[],{"data":55141,"content":55142,"nodeType":876},{},[55143],{"data":55144,"marks":55145,"value":38874,"nodeType":867},{},[],{"data":55147,"content":55148,"nodeType":876},{},[55149],{"data":55150,"marks":55151,"value":38881,"nodeType":867},{},[],{"data":55153,"content":55156,"nodeType":985},{"target":55154},{"sys":55155},{"id":38886,"type":982,"linkType":983},[],{"data":55158,"content":55159,"nodeType":876},{},[55160,55163,55171],{"data":55161,"marks":55162,"value":38757,"nodeType":867},{},[],{"data":55164,"content":55167,"nodeType":17452},{"target":55165},{"sys":55166},{"id":38898,"type":982,"linkType":983},[55168],{"data":55169,"marks":55170,"value":38860,"nodeType":867},{},[],{"data":55172,"marks":55173,"value":21,"nodeType":867},{},[],{"data":55175,"content":55176,"nodeType":1058},{},[55177],{"data":55178,"marks":55179,"value":38912,"nodeType":867},{},[],{"data":55181,"content":55182,"nodeType":876},{},[55183],{"data":55184,"marks":55185,"value":38919,"nodeType":867},{},[],{"data":55187,"content":55188,"nodeType":876},{},[55189],{"data":55190,"marks":55191,"value":38926,"nodeType":867},{},[],{"data":55193,"content":55194,"nodeType":876},{},[55195],{"data":55196,"marks":55197,"value":38933,"nodeType":867},{},[],{"data":55199,"content":55202,"nodeType":985},{"target":55200},{"sys":55201},{"id":38938,"type":982,"linkType":983},[],{"data":55204,"content":55205,"nodeType":876},{},[55206,55209,55217],{"data":55207,"marks":55208,"value":38757,"nodeType":867},{},[],{"data":55210,"content":55213,"nodeType":17452},{"target":55211},{"sys":55212},{"id":38950,"type":982,"linkType":983},[55214],{"data":55215,"marks":55216,"value":38955,"nodeType":867},{},[],{"data":55218,"marks":55219,"value":21,"nodeType":867},{},[],{"data":55221,"content":55222,"nodeType":1058},{},[55223],{"data":55224,"marks":55225,"value":38965,"nodeType":867},{},[],{"data":55227,"content":55228,"nodeType":876},{},[55229],{"data":55230,"marks":55231,"value":38972,"nodeType":867},{},[],{"data":55233,"content":55236,"nodeType":985},{"target":55234},{"sys":55235},{"id":38977,"type":982,"linkType":983},[],{"data":55238,"content":55239,"nodeType":876},{},[55240,55243,55251],{"data":55241,"marks":55242,"value":38757,"nodeType":867},{},[],{"data":55244,"content":55247,"nodeType":17452},{"target":55245},{"sys":55246},{"id":38989,"type":982,"linkType":983},[55248],{"data":55249,"marks":55250,"value":38994,"nodeType":867},{},[],{"data":55252,"marks":55253,"value":21,"nodeType":867},{},[],{"data":55255,"content":55256,"nodeType":868},{},[55257],{"data":55258,"marks":55259,"value":39004,"nodeType":867},{},[],{"data":55261,"content":55262,"nodeType":876},{},[55263],{"data":55264,"marks":55265,"value":39011,"nodeType":867},{},[],{"data":55267,"content":55268,"nodeType":876},{},[55269],{"data":55270,"marks":55271,"value":39018,"nodeType":867},{},[],{"data":55273,"content":55274,"nodeType":1629},{},[55275,55288,55301],{"data":55276,"content":55277,"nodeType":1586},{},[55278],{"data":55279,"content":55280,"nodeType":876},{},[55281,55285],{"data":55282,"marks":55283,"value":39032,"nodeType":867},{},[55284],{"type":865},{"data":55286,"marks":55287,"value":39036,"nodeType":867},{},[],{"data":55289,"content":55290,"nodeType":1586},{},[55291],{"data":55292,"content":55293,"nodeType":876},{},[55294,55298],{"data":55295,"marks":55296,"value":39047,"nodeType":867},{},[55297],{"type":865},{"data":55299,"marks":55300,"value":39051,"nodeType":867},{},[],{"data":55302,"content":55303,"nodeType":1586},{},[55304],{"data":55305,"content":55306,"nodeType":876},{},[55307,55311],{"data":55308,"marks":55309,"value":39062,"nodeType":867},{},[55310],{"type":865},{"data":55312,"marks":55313,"value":39066,"nodeType":867},{},[],{"data":55315,"content":55316,"nodeType":876},{},[55317],{"data":55318,"marks":55319,"value":39073,"nodeType":867},{},[],{"data":55321,"content":55322,"nodeType":1629},{},[55323,55339,55355,55368],{"data":55324,"content":55325,"nodeType":1586},{},[55326],{"data":55327,"content":55328,"nodeType":876},{},[55329,55332,55336],{"data":55330,"marks":55331,"value":39086,"nodeType":867},{},[],{"data":55333,"marks":55334,"value":39091,"nodeType":867},{},[55335],{"type":865},{"data":55337,"marks":55338,"value":39095,"nodeType":867},{},[],{"data":55340,"content":55341,"nodeType":1586},{},[55342],{"data":55343,"content":55344,"nodeType":876},{},[55345,55348,55352],{"data":55346,"marks":55347,"value":39105,"nodeType":867},{},[],{"data":55349,"marks":55350,"value":39110,"nodeType":867},{},[55351],{"type":865},{"data":55353,"marks":55354,"value":39114,"nodeType":867},{},[],{"data":55356,"content":55357,"nodeType":1586},{},[55358],{"data":55359,"content":55360,"nodeType":876},{},[55361,55365],{"data":55362,"marks":55363,"value":39125,"nodeType":867},{},[55364],{"type":865},{"data":55366,"marks":55367,"value":39129,"nodeType":867},{},[],{"data":55369,"content":55370,"nodeType":1586},{},[55371],{"data":55372,"content":55373,"nodeType":876},{},[55374,55378],{"data":55375,"marks":55376,"value":39140,"nodeType":867},{},[55377],{"type":865},{"data":55379,"marks":55380,"value":39144,"nodeType":867},{},[],{"data":55382,"content":55383,"nodeType":876},{},[55384,55387,55391],{"data":55385,"marks":55386,"value":39151,"nodeType":867},{},[],{"data":55388,"marks":55389,"value":38637,"nodeType":867},{},[55390],{"type":865},{"data":55392,"marks":55393,"value":39159,"nodeType":867},{},[],{"data":55395,"content":55398,"nodeType":985},{"target":55396},{"sys":55397},{"id":39164,"type":982,"linkType":983},[],{"data":55400,"content":55401,"nodeType":876},{},[55402],{"data":55403,"marks":55404,"value":39172,"nodeType":867},{},[],{"data":55406,"content":55407,"nodeType":868},{},[55408],{"data":55409,"marks":55410,"value":39179,"nodeType":867},{},[],{"data":55412,"content":55413,"nodeType":876},{},[55414],{"data":55415,"marks":55416,"value":39186,"nodeType":867},{},[],{"data":55418,"content":55419,"nodeType":876},{},[55420],{"data":55421,"marks":55422,"value":39193,"nodeType":867},{},[],{"data":55424,"content":55425,"nodeType":876},{},[55426,55429,55435],{"data":55427,"marks":55428,"value":39200,"nodeType":867},{},[],{"data":55430,"content":55431,"nodeType":915},{"uri":38619},[55432],{"data":55433,"marks":55434,"value":39207,"nodeType":867},{},[],{"data":55436,"marks":55437,"value":39211,"nodeType":867},{},[],{"data":55439,"content":55440,"nodeType":868},{},[55441],{"data":55442,"marks":55443,"value":25228,"nodeType":867},{},[],{"data":55445,"content":55446,"nodeType":876},{},[55447,55450,55456],{"data":55448,"marks":55449,"value":39224,"nodeType":867},{},[],{"data":55451,"content":55452,"nodeType":915},{"uri":39227},[55453],{"data":55454,"marks":55455,"value":11707,"nodeType":867},{},[],{"data":55457,"marks":55458,"value":39235,"nodeType":867},{},[],{"items":55460},[55461,55463],{"sys":55462,"name":39245},{"id":39244},{"sys":55464,"name":342},{"id":3240},{"items":55466},[55467],{"fullName":2714,"firstName":2715,"jobTitle":851,"profilePicture":55468},{"url":2717},{"__typename":1772,"sys":55470,"content":55471,"title":48479,"synopsis":48480,"hashTags":59,"publishedDate":48481,"slug":48482,"tagsCollection":56189,"authorsCollection":56195},{"id":47663},{"json":55472},{"data":55473,"content":55474,"nodeType":1680},{},[55475,55481,55487,55493,55519,55525,55531,55546,55552,55558,55573,55579,55585,55591,55596,55602,55641,55647,55653,55659,55680,55686,55692,55698,55740,55746,55752,55758,55764,55774,55780,55787,55793,55822,55828,55834,55840,55846,55906,55913,55919,55925,55955,55961,55968,55974,55980,55990,56003,56029,56045,56051,56066,56072,56078,56093,56099,56105,56111,56141,56147,56163,56178,56183],{"data":55476,"content":55477,"nodeType":876},{},[55478],{"data":55479,"marks":55480,"value":47674,"nodeType":867},{},[],{"data":55482,"content":55483,"nodeType":876},{},[55484],{"data":55485,"marks":55486,"value":47681,"nodeType":867},{},[],{"data":55488,"content":55489,"nodeType":876},{},[55490],{"data":55491,"marks":55492,"value":47688,"nodeType":867},{},[],{"data":55494,"content":55495,"nodeType":876},{},[55496,55499,55506,55509,55516],{"data":55497,"marks":55498,"value":21,"nodeType":867},{},[],{"data":55500,"content":55501,"nodeType":915},{"uri":26236},[55502],{"data":55503,"marks":55504,"value":395,"nodeType":867},{},[55505],{"type":913},{"data":55507,"marks":55508,"value":47705,"nodeType":867},{},[],{"data":55510,"content":55511,"nodeType":915},{"uri":42200},[55512],{"data":55513,"marks":55514,"value":37948,"nodeType":867},{},[55515],{"type":913},{"data":55517,"marks":55518,"value":47716,"nodeType":867},{},[],{"data":55520,"content":55521,"nodeType":868},{},[55522],{"data":55523,"marks":55524,"value":47723,"nodeType":867},{},[],{"data":55526,"content":55527,"nodeType":876},{},[55528],{"data":55529,"marks":55530,"value":47730,"nodeType":867},{},[],{"data":55532,"content":55533,"nodeType":876},{},[55534,55537,55543],{"data":55535,"marks":55536,"value":47737,"nodeType":867},{},[],{"data":55538,"content":55539,"nodeType":915},{"uri":2912},[55540],{"data":55541,"marks":55542,"value":47744,"nodeType":867},{},[],{"data":55544,"marks":55545,"value":2933,"nodeType":867},{},[],{"data":55547,"content":55548,"nodeType":1058},{},[55549],{"data":55550,"marks":55551,"value":47754,"nodeType":867},{},[],{"data":55553,"content":55554,"nodeType":876},{},[55555],{"data":55556,"marks":55557,"value":47761,"nodeType":867},{},[],{"data":55559,"content":55560,"nodeType":876},{},[55561,55564,55570],{"data":55562,"marks":55563,"value":47768,"nodeType":867},{},[],{"data":55565,"content":55566,"nodeType":915},{"uri":2912},[55567],{"data":55568,"marks":55569,"value":47775,"nodeType":867},{},[],{"data":55571,"marks":55572,"value":47779,"nodeType":867},{},[],{"data":55574,"content":55575,"nodeType":876},{},[55576],{"data":55577,"marks":55578,"value":47786,"nodeType":867},{},[],{"data":55580,"content":55581,"nodeType":1058},{},[55582],{"data":55583,"marks":55584,"value":47793,"nodeType":867},{},[],{"data":55586,"content":55587,"nodeType":876},{},[55588],{"data":55589,"marks":55590,"value":47800,"nodeType":867},{},[],{"data":55592,"content":55595,"nodeType":985},{"target":55593},{"sys":55594},{"id":47805,"type":982,"linkType":983},[],{"data":55597,"content":55598,"nodeType":876},{},[55599],{"data":55600,"marks":55601,"value":47813,"nodeType":867},{},[],{"data":55603,"content":55604,"nodeType":1629},{},[55605,55614,55623,55632],{"data":55606,"content":55607,"nodeType":1586},{},[55608],{"data":55609,"content":55610,"nodeType":876},{},[55611],{"data":55612,"marks":55613,"value":47826,"nodeType":867},{},[],{"data":55615,"content":55616,"nodeType":1586},{},[55617],{"data":55618,"content":55619,"nodeType":876},{},[55620],{"data":55621,"marks":55622,"value":47836,"nodeType":867},{},[],{"data":55624,"content":55625,"nodeType":1586},{},[55626],{"data":55627,"content":55628,"nodeType":876},{},[55629],{"data":55630,"marks":55631,"value":47846,"nodeType":867},{},[],{"data":55633,"content":55634,"nodeType":1586},{},[55635],{"data":55636,"content":55637,"nodeType":876},{},[55638],{"data":55639,"marks":55640,"value":47856,"nodeType":867},{},[],{"data":55642,"content":55643,"nodeType":876},{},[55644],{"data":55645,"marks":55646,"value":47863,"nodeType":867},{},[],{"data":55648,"content":55649,"nodeType":1058},{},[55650],{"data":55651,"marks":55652,"value":47870,"nodeType":867},{},[],{"data":55654,"content":55655,"nodeType":876},{},[55656],{"data":55657,"marks":55658,"value":47877,"nodeType":867},{},[],{"data":55660,"content":55661,"nodeType":1629},{},[55662,55671],{"data":55663,"content":55664,"nodeType":1586},{},[55665],{"data":55666,"content":55667,"nodeType":876},{},[55668],{"data":55669,"marks":55670,"value":47890,"nodeType":867},{},[],{"data":55672,"content":55673,"nodeType":1586},{},[55674],{"data":55675,"content":55676,"nodeType":876},{},[55677],{"data":55678,"marks":55679,"value":47900,"nodeType":867},{},[],{"data":55681,"content":55682,"nodeType":876},{},[55683],{"data":55684,"marks":55685,"value":47907,"nodeType":867},{},[],{"data":55687,"content":55688,"nodeType":1058},{},[55689],{"data":55690,"marks":55691,"value":47914,"nodeType":867},{},[],{"data":55693,"content":55694,"nodeType":876},{},[55695],{"data":55696,"marks":55697,"value":47921,"nodeType":867},{},[],{"data":55699,"content":55700,"nodeType":1629},{},[55701,55714,55727],{"data":55702,"content":55703,"nodeType":1586},{},[55704],{"data":55705,"content":55706,"nodeType":876},{},[55707,55711],{"data":55708,"marks":55709,"value":47935,"nodeType":867},{},[55710],{"type":865},{"data":55712,"marks":55713,"value":47939,"nodeType":867},{},[],{"data":55715,"content":55716,"nodeType":1586},{},[55717],{"data":55718,"content":55719,"nodeType":876},{},[55720,55724],{"data":55721,"marks":55722,"value":47950,"nodeType":867},{},[55723],{"type":865},{"data":55725,"marks":55726,"value":47954,"nodeType":867},{},[],{"data":55728,"content":55729,"nodeType":1586},{},[55730],{"data":55731,"content":55732,"nodeType":876},{},[55733,55737],{"data":55734,"marks":55735,"value":47965,"nodeType":867},{},[55736],{"type":865},{"data":55738,"marks":55739,"value":47969,"nodeType":867},{},[],{"data":55741,"content":55742,"nodeType":876},{},[55743],{"data":55744,"marks":55745,"value":47976,"nodeType":867},{},[],{"data":55747,"content":55748,"nodeType":876},{},[55749],{"data":55750,"marks":55751,"value":47983,"nodeType":867},{},[],{"data":55753,"content":55754,"nodeType":876},{},[55755],{"data":55756,"marks":55757,"value":47990,"nodeType":867},{},[],{"data":55759,"content":55760,"nodeType":868},{},[55761],{"data":55762,"marks":55763,"value":47997,"nodeType":867},{},[],{"data":55765,"content":55766,"nodeType":876},{},[55767,55771],{"data":55768,"marks":55769,"value":48005,"nodeType":867},{},[55770],{"type":865},{"data":55772,"marks":55773,"value":48009,"nodeType":867},{},[],{"data":55775,"content":55776,"nodeType":876},{},[55777],{"data":55778,"marks":55779,"value":48016,"nodeType":867},{},[],{"data":55781,"content":55782,"nodeType":876},{},[55783],{"data":55784,"marks":55785,"value":48024,"nodeType":867},{},[55786],{"type":865},{"data":55788,"content":55789,"nodeType":876},{},[55790],{"data":55791,"marks":55792,"value":48031,"nodeType":867},{},[],{"data":55794,"content":55795,"nodeType":1629},{},[55796,55809],{"data":55797,"content":55798,"nodeType":1586},{},[55799],{"data":55800,"content":55801,"nodeType":876},{},[55802,55806],{"data":55803,"marks":55804,"value":48045,"nodeType":867},{},[55805],{"type":865},{"data":55807,"marks":55808,"value":48049,"nodeType":867},{},[],{"data":55810,"content":55811,"nodeType":1586},{},[55812],{"data":55813,"content":55814,"nodeType":876},{},[55815,55819],{"data":55816,"marks":55817,"value":48060,"nodeType":867},{},[55818],{"type":865},{"data":55820,"marks":55821,"value":48064,"nodeType":867},{},[],{"data":55823,"content":55824,"nodeType":876},{},[55825],{"data":55826,"marks":55827,"value":48071,"nodeType":867},{},[],{"data":55829,"content":55830,"nodeType":1058},{},[55831],{"data":55832,"marks":55833,"value":48078,"nodeType":867},{},[],{"data":55835,"content":55836,"nodeType":876},{},[55837],{"data":55838,"marks":55839,"value":48085,"nodeType":867},{},[],{"data":55841,"content":55842,"nodeType":876},{},[55843],{"data":55844,"marks":55845,"value":48092,"nodeType":867},{},[],{"data":55847,"content":55848,"nodeType":1629},{},[55849,55868,55887],{"data":55850,"content":55851,"nodeType":1586},{},[55852],{"data":55853,"content":55854,"nodeType":876},{},[55855,55858,55865],{"data":55856,"marks":55857,"value":48105,"nodeType":867},{},[],{"data":55859,"content":55860,"nodeType":915},{"uri":48108},[55861],{"data":55862,"marks":55863,"value":11959,"nodeType":867},{},[55864],{"type":913},{"data":55866,"marks":55867,"value":24243,"nodeType":867},{},[],{"data":55869,"content":55870,"nodeType":1586},{},[55871],{"data":55872,"content":55873,"nodeType":876},{},[55874,55877,55884],{"data":55875,"marks":55876,"value":45640,"nodeType":867},{},[],{"data":55878,"content":55879,"nodeType":915},{"uri":7467},[55880],{"data":55881,"marks":55882,"value":45648,"nodeType":867},{},[55883],{"type":913},{"data":55885,"marks":55886,"value":24243,"nodeType":867},{},[],{"data":55888,"content":55889,"nodeType":1586},{},[55890],{"data":55891,"content":55892,"nodeType":876},{},[55893,55896,55903],{"data":55894,"marks":55895,"value":45576,"nodeType":867},{},[],{"data":55897,"content":55898,"nodeType":915},{"uri":45579},[55899],{"data":55900,"marks":55901,"value":45585,"nodeType":867},{},[55902],{"type":913},{"data":55904,"marks":55905,"value":24243,"nodeType":867},{},[],{"data":55907,"content":55908,"nodeType":876},{},[55909],{"data":55910,"marks":55911,"value":48162,"nodeType":867},{},[55912],{"type":865},{"data":55914,"content":55915,"nodeType":876},{},[55916],{"data":55917,"marks":55918,"value":48169,"nodeType":867},{},[],{"data":55920,"content":55921,"nodeType":876},{},[55922],{"data":55923,"marks":55924,"value":48176,"nodeType":867},{},[],{"data":55926,"content":55927,"nodeType":1629},{},[55928,55946],{"data":55929,"content":55930,"nodeType":1586},{},[55931],{"data":55932,"content":55933,"nodeType":876},{},[55934,55937,55943],{"data":55935,"marks":55936,"value":48189,"nodeType":867},{},[],{"data":55938,"content":55939,"nodeType":915},{"uri":2912},[55940],{"data":55941,"marks":55942,"value":48196,"nodeType":867},{},[],{"data":55944,"marks":55945,"value":48200,"nodeType":867},{},[],{"data":55947,"content":55948,"nodeType":1586},{},[55949],{"data":55950,"content":55951,"nodeType":876},{},[55952],{"data":55953,"marks":55954,"value":48210,"nodeType":867},{},[],{"data":55956,"content":55957,"nodeType":876},{},[55958],{"data":55959,"marks":55960,"value":48217,"nodeType":867},{},[],{"data":55962,"content":55963,"nodeType":876},{},[55964],{"data":55965,"marks":55966,"value":48225,"nodeType":867},{},[55967],{"type":865},{"data":55969,"content":55970,"nodeType":1058},{},[55971],{"data":55972,"marks":55973,"value":48232,"nodeType":867},{},[],{"data":55975,"content":55976,"nodeType":876},{},[55977],{"data":55978,"marks":55979,"value":48239,"nodeType":867},{},[],{"data":55981,"content":55982,"nodeType":876},{},[55983,55986],{"data":55984,"marks":55985,"value":48246,"nodeType":867},{},[],{"data":55987,"marks":55988,"value":48251,"nodeType":867},{},[55989],{"type":865},{"data":55991,"content":55992,"nodeType":876},{},[55993,55996,56000],{"data":55994,"marks":55995,"value":48258,"nodeType":867},{},[],{"data":55997,"marks":55998,"value":48263,"nodeType":867},{},[55999],{"type":865},{"data":56001,"marks":56002,"value":48267,"nodeType":867},{},[],{"data":56004,"content":56005,"nodeType":876},{},[56006,56009,56016,56019,56026],{"data":56007,"marks":56008,"value":48274,"nodeType":867},{},[],{"data":56010,"content":56011,"nodeType":915},{"uri":22216},[56012],{"data":56013,"marks":56014,"value":22222,"nodeType":867},{},[56015],{"type":913},{"data":56017,"marks":56018,"value":48285,"nodeType":867},{},[],{"data":56020,"content":56021,"nodeType":915},{"uri":5013},[56022],{"data":56023,"marks":56024,"value":48293,"nodeType":867},{},[56025],{"type":913},{"data":56027,"marks":56028,"value":23136,"nodeType":867},{},[],{"data":56030,"content":56031,"nodeType":876},{},[56032,56035,56042],{"data":56033,"marks":56034,"value":48303,"nodeType":867},{},[],{"data":56036,"content":56037,"nodeType":915},{"uri":38018},[56038],{"data":56039,"marks":56040,"value":48311,"nodeType":867},{},[56041],{"type":913},{"data":56043,"marks":56044,"value":24572,"nodeType":867},{},[],{"data":56046,"content":56047,"nodeType":868},{},[56048],{"data":56049,"marks":56050,"value":48321,"nodeType":867},{},[],{"data":56052,"content":56053,"nodeType":876},{},[56054,56057,56063],{"data":56055,"marks":56056,"value":964,"nodeType":867},{},[],{"data":56058,"content":56059,"nodeType":915},{"uri":15290},[56060],{"data":56061,"marks":56062,"value":48334,"nodeType":867},{},[],{"data":56064,"marks":56065,"value":48338,"nodeType":867},{},[],{"data":56067,"content":56068,"nodeType":876},{},[56069],{"data":56070,"marks":56071,"value":48345,"nodeType":867},{},[],{"data":56073,"content":56074,"nodeType":876},{},[56075],{"data":56076,"marks":56077,"value":48352,"nodeType":867},{},[],{"data":56079,"content":56080,"nodeType":876},{},[56081,56084,56090],{"data":56082,"marks":56083,"value":48359,"nodeType":867},{},[],{"data":56085,"content":56086,"nodeType":915},{"uri":42382},[56087],{"data":56088,"marks":56089,"value":48366,"nodeType":867},{},[],{"data":56091,"marks":56092,"value":21,"nodeType":867},{},[],{"data":56094,"content":56095,"nodeType":876},{},[56096],{"data":56097,"marks":56098,"value":48376,"nodeType":867},{},[],{"data":56100,"content":56101,"nodeType":868},{},[56102],{"data":56103,"marks":56104,"value":48383,"nodeType":867},{},[],{"data":56106,"content":56107,"nodeType":876},{},[56108],{"data":56109,"marks":56110,"value":48390,"nodeType":867},{},[],{"data":56112,"content":56113,"nodeType":1629},{},[56114,56123,56132],{"data":56115,"content":56116,"nodeType":1586},{},[56117],{"data":56118,"content":56119,"nodeType":876},{},[56120],{"data":56121,"marks":56122,"value":48403,"nodeType":867},{},[],{"data":56124,"content":56125,"nodeType":1586},{},[56126],{"data":56127,"content":56128,"nodeType":876},{},[56129],{"data":56130,"marks":56131,"value":48413,"nodeType":867},{},[],{"data":56133,"content":56134,"nodeType":1586},{},[56135],{"data":56136,"content":56137,"nodeType":876},{},[56138],{"data":56139,"marks":56140,"value":48423,"nodeType":867},{},[],{"data":56142,"content":56143,"nodeType":876},{},[56144],{"data":56145,"marks":56146,"value":48430,"nodeType":867},{},[],{"data":56148,"content":56149,"nodeType":876},{},[56150,56153,56160],{"data":56151,"marks":56152,"value":48437,"nodeType":867},{},[],{"data":56154,"content":56155,"nodeType":915},{"uri":48440},[56156],{"data":56157,"marks":56158,"value":48446,"nodeType":867},{},[56159],{"type":913},{"data":56161,"marks":56162,"value":21,"nodeType":867},{},[],{"data":56164,"content":56165,"nodeType":876},{},[56166,56169,56175],{"data":56167,"marks":56168,"value":48456,"nodeType":867},{},[],{"data":56170,"content":56171,"nodeType":915},{"uri":35095},[56172],{"data":56173,"marks":56174,"value":48463,"nodeType":867},{},[],{"data":56176,"marks":56177,"value":2933,"nodeType":867},{},[],{"data":56179,"content":56182,"nodeType":985},{"target":56180},{"sys":56181},{"id":48471,"type":982,"linkType":983},[],{"data":56184,"content":56185,"nodeType":876},{},[56186],{"data":56187,"marks":56188,"value":21,"nodeType":867},{},[],{"items":56190},[56191,56193],{"sys":56192,"name":4018},{"id":4017},{"sys":56194,"name":342},{"id":3240},{"items":56196},[56197],{"fullName":4022,"firstName":4023,"jobTitle":4024,"profilePicture":56198},{"url":4026},"5-reasons-why-push-security-shouldnt-exist","blog/5-reasons-why-push-security-shouldnt-exist",{"json":56202},{"data":56203,"content":56204,"nodeType":1680},{},[56205,56212],{"data":56206,"content":56207,"nodeType":876},{},[56208],{"data":56209,"marks":56210,"value":56211,"nodeType":867},{},[],"If current security controls worked perfectly, Push wouldn't need to exist – unfortunately, they don't, so here we are!",{"data":56213,"content":56214,"nodeType":876},{},[56215],{"data":56216,"marks":56217,"value":56218,"nodeType":867},{},[],"In this article, we break down common misconceptions about identity controls like MFA, SSO, passkeys, and password managers, exploring some of the gaps they leave and how to fill them to achieve defense in depth.","Breaking down common misconceptions about identity threats and controls like MFA, SSO, passkeys, password managers, and more.",{"id":56221,"publishedAt":56222},"1fp5aOCIcGHDbdQ0amCYOf","2026-08-12T11:55:11.772Z",{"items":56224},[56225,56227],{"sys":56226,"name":342},{"id":3240},{"sys":56228,"name":297},{"id":2706},{"items":56230},[56231,56233,56235,56237,56239,56241,56243,56245,56247,56249,56251,56253,56255,56257,56259,56261,56263,56265,56267,56269,56271,56273],{"sys":56232,"name":413,"slug":414,"tier":31},{"id":410},{"sys":56234,"name":297,"slug":298,"tier":31},{"id":294},{"sys":56236,"name":279,"slug":280,"tier":31},{"id":276},{"sys":56238,"name":519,"slug":520,"tier":31},{"id":516},{"sys":56240,"name":545,"slug":546,"tier":31},{"id":542},{"sys":56242,"name":342,"slug":343,"tier":31},{"id":339},{"sys":56244,"name":395,"slug":396,"tier":45},{"id":392},{"sys":56246,"name":457,"slug":458,"tier":45},{"id":454},{"sys":56248,"name":466,"slug":467,"tier":45},{"id":463},{"sys":56250,"name":333,"slug":334,"tier":45},{"id":330},{"sys":56252,"name":589,"slug":590,"tier":45},{"id":586},{"sys":56254,"name":261,"slug":262,"tier":45},{"id":258},{"sys":56256,"name":571,"slug":572,"tier":45},{"id":568},{"sys":56258,"name":422,"slug":423,"tier":45},{"id":419},{"sys":56260,"name":502,"slug":503,"tier":45},{"id":499},{"sys":56262,"name":493,"slug":494,"tier":45},{"id":490},{"sys":56264,"name":404,"slug":405,"tier":45},{"id":401},{"sys":56266,"name":377,"slug":378,"tier":45},{"id":374},{"sys":56268,"name":624,"slug":625,"tier":45},{"id":621},{"sys":56270,"name":306,"slug":307,"tier":45},{"id":303},{"sys":56272,"name":598,"slug":599,"tier":45},{"id":595},{"sys":56274,"name":475,"slug":476,"tier":45},{"id":472},"7ekz7o6jH_LJs1GGrGDh2SvoDhuQmK1UIytQMiVACOw",{"id":56277,"title":44978,"authorsCollection":56278,"content":56282,"extension":228,"faqItemsCollection":56740,"faqTitle":59,"featured":6,"hashTags":59,"meta":56742,"metaTitle":56743,"ogImage":59,"postType":24263,"publishedDate":44980,"relatedBlogPostsCollection":56744,"slug":44981,"stem":57929,"subtitle":59,"summary":57930,"synopsis":44979,"sys":57941,"tagsCollection":57943,"topicsCollection":57949,"__hash__":57973},"blog/blog/introducing-session-token-theft-detection-why-browser-is-best.json",{"items":56279},[56280],{"fullName":2714,"firstName":2715,"jobTitle":851,"socialLinks":59,"profilePicture":56281},{"url":2717},{"json":56283,"links":56707},{"data":56284,"content":56285,"nodeType":1680},{},[56286,56291,56297,56327,56333,56349,56355,56391,56397,56403,56409,56414,56420,56498,56504,56510,56531,56537,56543,56549,56555,56561,56567,56611,56617,56622,56638,56643,56649,56655,56661,56667,56673,56679,56685,56691],{"data":56287,"content":56290,"nodeType":985},{"target":56288},{"sys":56289},{"id":44496,"type":982,"linkType":983},[],{"data":56292,"content":56293,"nodeType":876},{},[56294],{"data":56295,"marks":56296,"value":44504,"nodeType":867},{},[],{"data":56298,"content":56299,"nodeType":1629},{},[56300,56309,56318],{"data":56301,"content":56302,"nodeType":1586},{},[56303],{"data":56304,"content":56305,"nodeType":876},{},[56306],{"data":56307,"marks":56308,"value":44517,"nodeType":867},{},[],{"data":56310,"content":56311,"nodeType":1586},{},[56312],{"data":56313,"content":56314,"nodeType":876},{},[56315],{"data":56316,"marks":56317,"value":44527,"nodeType":867},{},[],{"data":56319,"content":56320,"nodeType":1586},{},[56321],{"data":56322,"content":56323,"nodeType":876},{},[56324],{"data":56325,"marks":56326,"value":44537,"nodeType":867},{},[],{"data":56328,"content":56329,"nodeType":876},{},[56330],{"data":56331,"marks":56332,"value":44544,"nodeType":867},{},[],{"data":56334,"content":56335,"nodeType":876},{},[56336,56339,56346],{"data":56337,"marks":56338,"value":44551,"nodeType":867},{},[],{"data":56340,"content":56341,"nodeType":915},{"uri":44554},[56342],{"data":56343,"marks":56344,"value":44560,"nodeType":867},{},[56345],{"type":913},{"data":56347,"marks":56348,"value":44564,"nodeType":867},{},[],{"data":56350,"content":56351,"nodeType":868},{},[56352],{"data":56353,"marks":56354,"value":44571,"nodeType":867},{},[],{"data":56356,"content":56357,"nodeType":876},{},[56358,56361,56368,56371,56378,56381,56388],{"data":56359,"marks":56360,"value":44578,"nodeType":867},{},[],{"data":56362,"content":56363,"nodeType":915},{"uri":44581},[56364],{"data":56365,"marks":56366,"value":44587,"nodeType":867},{},[56367],{"type":913},{"data":56369,"marks":56370,"value":44591,"nodeType":867},{},[],{"data":56372,"content":56373,"nodeType":915},{"uri":44594},[56374],{"data":56375,"marks":56376,"value":44600,"nodeType":867},{},[56377],{"type":913},{"data":56379,"marks":56380,"value":44604,"nodeType":867},{},[],{"data":56382,"content":56383,"nodeType":915},{"uri":37942},[56384],{"data":56385,"marks":56386,"value":44612,"nodeType":867},{},[56387],{"type":913},{"data":56389,"marks":56390,"value":44616,"nodeType":867},{},[],{"data":56392,"content":56393,"nodeType":876},{},[56394],{"data":56395,"marks":56396,"value":44623,"nodeType":867},{},[],{"data":56398,"content":56399,"nodeType":876},{},[56400],{"data":56401,"marks":56402,"value":44630,"nodeType":867},{},[],{"data":56404,"content":56405,"nodeType":876},{},[56406],{"data":56407,"marks":56408,"value":44637,"nodeType":867},{},[],{"data":56410,"content":56413,"nodeType":985},{"target":56411},{"sys":56412},{"id":41436,"type":982,"linkType":983},[],{"data":56415,"content":56416,"nodeType":876},{},[56417],{"data":56418,"marks":56419,"value":44649,"nodeType":867},{},[],{"data":56421,"content":56422,"nodeType":1629},{},[56423,56442,56461,56480],{"data":56424,"content":56425,"nodeType":1586},{},[56426],{"data":56427,"content":56428,"nodeType":876},{},[56429,56432,56439],{"data":56430,"marks":56431,"value":44662,"nodeType":867},{},[],{"data":56433,"content":56434,"nodeType":915},{"uri":44665},[56435],{"data":56436,"marks":56437,"value":44671,"nodeType":867},{},[56438],{"type":913},{"data":56440,"marks":56441,"value":21,"nodeType":867},{},[],{"data":56443,"content":56444,"nodeType":1586},{},[56445],{"data":56446,"content":56447,"nodeType":876},{},[56448,56451,56458],{"data":56449,"marks":56450,"value":44684,"nodeType":867},{},[],{"data":56452,"content":56453,"nodeType":915},{"uri":44687},[56454],{"data":56455,"marks":56456,"value":44693,"nodeType":867},{},[56457],{"type":913},{"data":56459,"marks":56460,"value":21,"nodeType":867},{},[],{"data":56462,"content":56463,"nodeType":1586},{},[56464],{"data":56465,"content":56466,"nodeType":876},{},[56467,56470,56477],{"data":56468,"marks":56469,"value":44706,"nodeType":867},{},[],{"data":56471,"content":56472,"nodeType":915},{"uri":2177},[56473],{"data":56474,"marks":56475,"value":44714,"nodeType":867},{},[56476],{"type":913},{"data":56478,"marks":56479,"value":21,"nodeType":867},{},[],{"data":56481,"content":56482,"nodeType":1586},{},[56483],{"data":56484,"content":56485,"nodeType":876},{},[56486,56489,56495],{"data":56487,"marks":56488,"value":44727,"nodeType":867},{},[],{"data":56490,"content":56491,"nodeType":915},{"uri":44730},[56492],{"data":56493,"marks":56494,"value":44735,"nodeType":867},{},[],{"data":56496,"marks":56497,"value":21,"nodeType":867},{},[],{"data":56499,"content":56500,"nodeType":868},{},[56501],{"data":56502,"marks":56503,"value":44745,"nodeType":867},{},[],{"data":56505,"content":56506,"nodeType":876},{},[56507],{"data":56508,"marks":56509,"value":44752,"nodeType":867},{},[],{"data":56511,"content":56512,"nodeType":1629},{},[56513,56522],{"data":56514,"content":56515,"nodeType":1586},{},[56516],{"data":56517,"content":56518,"nodeType":876},{},[56519],{"data":56520,"marks":56521,"value":44765,"nodeType":867},{},[],{"data":56523,"content":56524,"nodeType":1586},{},[56525],{"data":56526,"content":56527,"nodeType":876},{},[56528],{"data":56529,"marks":56530,"value":44775,"nodeType":867},{},[],{"data":56532,"content":56533,"nodeType":876},{},[56534],{"data":56535,"marks":56536,"value":44782,"nodeType":867},{},[],{"data":56538,"content":56539,"nodeType":876},{},[56540],{"data":56541,"marks":56542,"value":44789,"nodeType":867},{},[],{"data":56544,"content":56545,"nodeType":868},{},[56546],{"data":56547,"marks":56548,"value":44796,"nodeType":867},{},[],{"data":56550,"content":56551,"nodeType":876},{},[56552],{"data":56553,"marks":56554,"value":44803,"nodeType":867},{},[],{"data":56556,"content":56557,"nodeType":876},{},[56558],{"data":56559,"marks":56560,"value":44810,"nodeType":867},{},[],{"data":56562,"content":56563,"nodeType":876},{},[56564],{"data":56565,"marks":56566,"value":44817,"nodeType":867},{},[],{"data":56568,"content":56569,"nodeType":1629},{},[56570,56579,56588],{"data":56571,"content":56572,"nodeType":1586},{},[56573],{"data":56574,"content":56575,"nodeType":876},{},[56576],{"data":56577,"marks":56578,"value":44830,"nodeType":867},{},[],{"data":56580,"content":56581,"nodeType":1586},{},[56582],{"data":56583,"content":56584,"nodeType":876},{},[56585],{"data":56586,"marks":56587,"value":44840,"nodeType":867},{},[],{"data":56589,"content":56590,"nodeType":1586},{},[56591],{"data":56592,"content":56593,"nodeType":876},{},[56594,56597,56601,56604,56608],{"data":56595,"marks":56596,"value":44850,"nodeType":867},{},[],{"data":56598,"marks":56599,"value":24309,"nodeType":867},{},[56600],{"type":1303},{"data":56602,"marks":56603,"value":44858,"nodeType":867},{},[],{"data":56605,"marks":56606,"value":44863,"nodeType":867},{},[56607],{"type":1303},{"data":56609,"marks":56610,"value":44867,"nodeType":867},{},[],{"data":56612,"content":56613,"nodeType":876},{},[56614],{"data":56615,"marks":56616,"value":44874,"nodeType":867},{},[],{"data":56618,"content":56621,"nodeType":985},{"target":56619},{"sys":56620},{"id":44879,"type":982,"linkType":983},[],{"data":56623,"content":56624,"nodeType":876},{},[56625,56628,56635],{"data":56626,"marks":56627,"value":44887,"nodeType":867},{},[],{"data":56629,"content":56630,"nodeType":915},{"uri":44554},[56631],{"data":56632,"marks":56633,"value":44895,"nodeType":867},{},[56634],{"type":913},{"data":56636,"marks":56637,"value":1679,"nodeType":867},{},[],{"data":56639,"content":56642,"nodeType":985},{"target":56640},{"sys":56641},{"id":44903,"type":982,"linkType":983},[],{"data":56644,"content":56645,"nodeType":868},{},[56646],{"data":56647,"marks":56648,"value":44911,"nodeType":867},{},[],{"data":56650,"content":56651,"nodeType":876},{},[56652],{"data":56653,"marks":56654,"value":44918,"nodeType":867},{},[],{"data":56656,"content":56657,"nodeType":876},{},[56658],{"data":56659,"marks":56660,"value":44925,"nodeType":867},{},[],{"data":56662,"content":56663,"nodeType":876},{},[56664],{"data":56665,"marks":56666,"value":44932,"nodeType":867},{},[],{"data":56668,"content":56669,"nodeType":876},{},[56670],{"data":56671,"marks":56672,"value":44939,"nodeType":867},{},[],{"data":56674,"content":56675,"nodeType":876},{},[56676],{"data":56677,"marks":56678,"value":44946,"nodeType":867},{},[],{"data":56680,"content":56681,"nodeType":876},{},[56682],{"data":56683,"marks":56684,"value":44953,"nodeType":867},{},[],{"data":56686,"content":56687,"nodeType":868},{},[56688],{"data":56689,"marks":56690,"value":25228,"nodeType":867},{},[],{"data":56692,"content":56693,"nodeType":876},{},[56694,56697,56704],{"data":56695,"marks":56696,"value":44966,"nodeType":867},{},[],{"data":56698,"content":56699,"nodeType":915},{"uri":5286},[56700],{"data":56701,"marks":56702,"value":11707,"nodeType":867},{},[56703],{"type":913},{"data":56705,"marks":56706,"value":44977,"nodeType":867},{},[],{"entries":56708},{"hyperlink":56709,"inline":56710,"block":56711},[],[],[56712,56720,56726,56733],{"sys":56713,"__typename":46623,"title":56714,"youTubeUrl":56715,"imagePlaceholder":56716},{"id":44496},"Introducing session token theft detection with Push","https://www.youtube.com/watch?v=p4UCfeTs_po",{"url":56717,"width":56718,"height":56719},"https://images.ctfassets.net/y1cdw1ablpvd/3HHLFnvZ0hkovL7MJMGQN2/d82ab3a6757201d2cf9869ade89c9091/Screenshot_2024-08-15_at_07.15.04.png",3358,1888,{"sys":56721,"__typename":1688,"title":56722,"caption":56722,"layoutMode":59,"file":56723},{"id":41436},"The 2024 Sophos Threat Report shows the prevalence of info stealer malware.",{"url":56724,"width":16,"height":56725},"https://images.ctfassets.net/y1cdw1ablpvd/ntLmjUBbgKFILEraHAiLC/dbefc5df68c0260dd6301237af4ba49a/image3.png",432,{"sys":56727,"__typename":1688,"title":56728,"caption":56729,"layoutMode":59,"file":56730},{"id":44879},"Illustration of detected session activity showing the missing Push marker","Illustration of detected session activity showing the missing Push marker.",{"url":56731,"width":33790,"height":56732},"https://images.ctfassets.net/y1cdw1ablpvd/7CDurJgGW12KszlFzOr68K/482d37d80bc5f76ba70e6b8d3161e9bd/image1.png",398,{"sys":56734,"__typename":1688,"title":56735,"caption":56735,"layoutMode":59,"file":56736},{"id":44903},"Sample syntax for querying session theft in a SIEM.",{"url":56737,"width":56738,"height":56739},"https://images.ctfassets.net/y1cdw1ablpvd/1eutG6NRlAHZB3w335MJzR/7708168c4ae2a28e4f2470e5f49e8138/image2.png",735,115,{"items":56741},[],{},"Detecting session token theft using Push browser telemetry",{"items":56745},[56746,57143,57565],{"__typename":1772,"sys":56747,"content":56749,"title":57129,"synopsis":57130,"hashTags":59,"publishedDate":57131,"slug":57132,"tagsCollection":57133,"authorsCollection":57139},{"id":56748},"4pXsh0RffPhT783P6CNlOA",{"json":56750},{"data":56751,"content":56752,"nodeType":1680},{},[56753,56760,56767,56773,56780,56787,56794,56801,56808,56815,56878,56884,56891,56898,56914,56921,56928,56935,56942,56949,56956,56966,56973,56979,56986,56993,57000,57007,57014,57020,57027,57047,57054,57061,57068,57111],{"data":56754,"content":56755,"nodeType":876},{},[56756],{"data":56757,"marks":56758,"value":56759,"nodeType":867},{},[],"When the media reports that a popular third-party service provider has suffered a breach and stolen credentials are being sold online, it’s inevitable for your security team to get asked, “Are we affected by this?”",{"data":56761,"content":56762,"nodeType":876},{},[56763],{"data":56764,"marks":56765,"value":56766,"nodeType":867},{},[],"Push helps its customers to answer this question in seconds and with absolute certainty. Here’s how.",{"data":56768,"content":56772,"nodeType":985},{"target":56769},{"sys":56770},{"id":56771,"type":982,"linkType":983},"56lMG3VskDDU1dUHzgQxFK",[],{"data":56774,"content":56775,"nodeType":868},{},[56776],{"data":56777,"marks":56778,"value":56779,"nodeType":867},{},[],"Step 1: Are we using the breached service?",{"data":56781,"content":56782,"nodeType":876},{},[56783],{"data":56784,"marks":56785,"value":56786,"nodeType":867},{},[],"If this service is IT-managed in your organization, then you can probably answer this relatively quickly – at least for the tenant that is IT-managed. If it’s not, then you're going to need to check. ",{"data":56788,"content":56789,"nodeType":876},{},[56790],{"data":56791,"marks":56792,"value":56793,"nodeType":867},{},[],"That’s because end-users increasingly create SaaS accounts and tenants themselves without going through IT. When a third-party data breach hits the headlines, security teams are often surprised to find out that they have people in their organizations using that service.",{"data":56795,"content":56796,"nodeType":876},{},[56797],{"data":56798,"marks":56799,"value":56800,"nodeType":867},{},[],"Push uses a browser agent to track every login to every application made by your employees. It offers ground truth for answering questions like: Are we using the service? Who in the business is using it, and how are they accessing it?",{"data":56802,"content":56803,"nodeType":876},{},[56804],{"data":56805,"marks":56806,"value":56807,"nodeType":867},{},[],"Push can also highlight issues like missing MFA and if an employee is re-using the same password across multiple services — vital information if user credentials for the breached service have been leaked.",{"data":56809,"content":56810,"nodeType":876},{},[56811],{"data":56812,"marks":56813,"value":56814,"nodeType":867},{},[],"There are other data sources that can be used, but they all have their drawbacks:    ",{"data":56816,"content":56817,"nodeType":1629},{},[56818,56833,56848,56863],{"data":56819,"content":56820,"nodeType":1586},{},[56821],{"data":56822,"content":56823,"nodeType":876},{},[56824,56829],{"data":56825,"marks":56826,"value":56828,"nodeType":867},{},[56827],{"type":865},"Network or SWG",{"data":56830,"marks":56831,"value":56832,"nodeType":867},{},[]," can show you whose endpoints accessed an app website, but not if they've ever logged into the app.",{"data":56834,"content":56835,"nodeType":1586},{},[56836],{"data":56837,"content":56838,"nodeType":876},{},[56839,56844],{"data":56840,"marks":56841,"value":56843,"nodeType":867},{},[56842],{"type":865},"IdP",{"data":56845,"marks":56846,"value":56847,"nodeType":867},{},[]," can show you that you're using an app if it’s accessed using SSO, but if that’s the case then you already know about it. It won’t show you non-SSO apps, tenants, or accounts that are more likely to be compromised using stolen credentials.",{"data":56849,"content":56850,"nodeType":1586},{},[56851],{"data":56852,"content":56853,"nodeType":876},{},[56854,56859],{"data":56855,"marks":56856,"value":56858,"nodeType":867},{},[56857],{"type":865},"Email",{"data":56860,"marks":56861,"value":56862,"nodeType":867},{},[]," can be used to quickly tell you if employees have received email from an app – indicating an account might exist – but won’t tell you if they signed up using personal email, when they last logged in or if they are using the same password for everything.",{"data":56864,"content":56865,"nodeType":1586},{},[56866],{"data":56867,"content":56868,"nodeType":876},{},[56869,56874],{"data":56870,"marks":56871,"value":56873,"nodeType":867},{},[56872],{"type":865},"Finance / contract records",{"data":56875,"marks":56876,"value":56877,"nodeType":867},{},[]," take time to search through and will only cover the services you pay for (many SaaS products offer a free tier). Obviously these records won’t tell you anything about vulnerable accounts.  \n",{"data":56879,"content":56883,"nodeType":985},{"target":56880},{"sys":56881},{"id":56882,"type":982,"linkType":983},"3pLEarsM0oltdxGlkHATbB",[],{"data":56885,"content":56886,"nodeType":868},{},[56887],{"data":56888,"marks":56889,"value":56890,"nodeType":867},{},[],"Step 2: Are any of our accounts currently vulnerable to account takeover through stolen creds?",{"data":56892,"content":56893,"nodeType":876},{},[56894],{"data":56895,"marks":56896,"value":56897,"nodeType":867},{},[],"If credentials are being sold on the dark web for a service your employees use, then you need to quickly determine whether any workforce accounts can be accessed using just the stolen credentials. In other words, are any of these accounts using a leaked password and/or missing MFA?",{"data":56899,"content":56900,"nodeType":876},{},[56901,56905,56910],{"data":56902,"marks":56903,"value":56904,"nodeType":867},{},[],"At this point, you might reach for your IdP and make sure that MFA is enforced for all logins to the affected app. But that’s only going to cover apps and tenants already using SSO. To make things more complicated, most apps still allow username and password logins in addition to SSO logins. You need to see accounts with SSO logins ",{"data":56906,"marks":56907,"value":56909,"nodeType":867},{},[56908],{"type":1303},"and",{"data":56911,"marks":56912,"value":56913,"nodeType":867},{},[]," local logins. ",{"data":56915,"content":56916,"nodeType":876},{},[56917],{"data":56918,"marks":56919,"value":56920,"nodeType":867},{},[],"The data that Push collects in the browser provides rich web app context. That means Push shows you how your employees are authenticating on every app, whether it’s password, OIDC, or SAML. ",{"data":56922,"content":56923,"nodeType":876},{},[56924],{"data":56925,"marks":56926,"value":56927,"nodeType":867},{},[],"When you search for a breached third-party service in Push, you’ll see which employees are using usernames and passwords but missing MFA on their accounts. You can then prioritize these accounts for password resets and enabling MFA to stop any stolen credentials from being used to access those accounts. ",{"data":56929,"content":56930,"nodeType":876},{},[56931],{"data":56932,"marks":56933,"value":56934,"nodeType":867},{},[],"As well as highlighting accounts missing MFA, Push fingerprints every password using a shortened salted hash and checks in the browser whether it has been leaked and/or is easily guessable. Armed with this information, you can quickly get these vulnerabilities fixed to reduce the likelihood of an account takeover.",{"data":56936,"content":56937,"nodeType":868},{},[56938],{"data":56939,"marks":56940,"value":56941,"nodeType":867},{},[],"Step 3: Are the stolen credentials being used anywhere else? ",{"data":56943,"content":56944,"nodeType":876},{},[56945],{"data":56946,"marks":56947,"value":56948,"nodeType":867},{},[],"The next consideration is whether the stolen credentials can be used by an attacker in a credential-stuffing attack to compromise accounts on other applications. ",{"data":56950,"content":56951,"nodeType":876},{},[56952],{"data":56953,"marks":56954,"value":56955,"nodeType":867},{},[],"This is an important, and often overlooked, ring of the third-party data breach blast radius. ",{"data":56957,"content":56958,"nodeType":3804},{},[56959],{"data":56960,"content":56961,"nodeType":876},{},[56962],{"data":56963,"marks":56964,"value":56965,"nodeType":867},{},[],"Here at Push, we see that on average 1 in 3 users in every business reuse passwords across multiple accounts.",{"data":56967,"content":56968,"nodeType":876},{},[56969],{"data":56970,"marks":56971,"value":56972,"nodeType":867},{},[],"The password checks performed by Push also identify password reuse between applications. So if there’s a chance that a password has been stolen as part of the third-party data breach, you can make sure it’s changed across all applications. ",{"data":56974,"content":56978,"nodeType":985},{"target":56975},{"sys":56976},{"id":56977,"type":982,"linkType":983},"X9axqTO6dWEe1Jy49hAyG",[],{"data":56980,"content":56981,"nodeType":868},{},[56982],{"data":56983,"marks":56984,"value":56985,"nodeType":867},{},[],"Take action before breaches hit the headlines",{"data":56987,"content":56988,"nodeType":876},{},[56989],{"data":56990,"marks":56991,"value":56992,"nodeType":867},{},[],"The workflow described above takes seconds to perform in Push. It enables you to quickly investigate a third-party data breach to determine if you could have been impacted, and if so, to take targeted action to mitigate the risks. ",{"data":56994,"content":56995,"nodeType":876},{},[56996],{"data":56997,"marks":56998,"value":56999,"nodeType":867},{},[],"That said, no one enjoys scrambling to respond to these kinds of incidents. If you use Push, you can actually get out ahead of these issues so you’re not stuck having to react.",{"data":57001,"content":57002,"nodeType":876},{},[57003],{"data":57004,"marks":57005,"value":57006,"nodeType":867},{},[],"Push integrates stolen account threat intelligence and alerts you when employees are currently using the same password that’s being sold on the dark web. This allows you to take action at the earliest possible opportunity and harden vulnerable accounts before any data breach is reported in the media. ",{"data":57008,"content":57009,"nodeType":876},{},[57010],{"data":57011,"marks":57012,"value":57013,"nodeType":867},{},[],"What this means for you is that next time you’re asked, “Does this affect us?” you can say you dealt with any issues way before it landed in the headlines. ",{"data":57015,"content":57019,"nodeType":985},{"target":57016},{"sys":57017},{"id":57018,"type":982,"linkType":983},"2vFMyWtMlxzTqqtvCPmlGW",[],{"data":57021,"content":57022,"nodeType":1058},{},[57023],{"data":57024,"marks":57025,"value":57026,"nodeType":867},{},[],"Do we need to log in to another security tool to do this?",{"data":57028,"content":57029,"nodeType":876},{},[57030,57034,57043],{"data":57031,"marks":57032,"value":57033,"nodeType":867},{},[],"No. Using the ",{"data":57035,"content":57037,"nodeType":915},{"uri":57036},"https://pushsecurity.com/help/audience/administrators/docs/getting-started/#api-and-webhooks",[57038],{"data":57039,"marks":57040,"value":57042,"nodeType":867},{},[57041],{"type":913},"Push API",{"data":57044,"marks":57045,"value":57046,"nodeType":867},{},[],", you can quickly gather relevant data to support the response to a third-party data breach in your SIEM or XDR solution.",{"data":57048,"content":57049,"nodeType":1058},{},[57050],{"data":57051,"marks":57052,"value":57053,"nodeType":867},{},[],"Why not eliminate the risk of password-based attacks altogether? ",{"data":57055,"content":57056,"nodeType":876},{},[57057],{"data":57058,"marks":57059,"value":57060,"nodeType":867},{},[],"Push gives you the ability to react quickly and decisively to a third-party data breach. But it also enables you to take proactive steps to eliminate the risk of password-based attacks altogether so stolen credentials from third-party data breaches no longer pose a threat to your business. ",{"data":57062,"content":57063,"nodeType":876},{},[57064],{"data":57065,"marks":57066,"value":57067,"nodeType":867},{},[],"Push does this by:",{"data":57069,"content":57070,"nodeType":1629},{},[57071,57081,57091,57101],{"data":57072,"content":57073,"nodeType":1586},{},[57074],{"data":57075,"content":57076,"nodeType":876},{},[57077],{"data":57078,"marks":57079,"value":57080,"nodeType":867},{},[],"Stopping your employees from creating accounts with leaked, weak and reused passwords.",{"data":57082,"content":57083,"nodeType":1586},{},[57084],{"data":57085,"content":57086,"nodeType":876},{},[57087],{"data":57088,"marks":57089,"value":57090,"nodeType":867},{},[],"Pinning passwords to individual apps. ",{"data":57092,"content":57093,"nodeType":1586},{},[57094],{"data":57095,"content":57096,"nodeType":876},{},[57097],{"data":57098,"marks":57099,"value":57100,"nodeType":867},{},[],"Helping you to get all apps and accounts behind SSO.",{"data":57102,"content":57103,"nodeType":1586},{},[57104],{"data":57105,"content":57106,"nodeType":876},{},[57107],{"data":57108,"marks":57109,"value":57110,"nodeType":867},{},[],"Blocking phishing attacks against your employees so their credentials aren’t stolen.",{"data":57112,"content":57113,"nodeType":876},{},[57114,57118,57125],{"data":57115,"marks":57116,"value":57117,"nodeType":867},{},[],"If you want to find out more about how Push can help you mitigate the risks of employee credentials being stolen in the third-party data breach, then ",{"data":57119,"content":57120,"nodeType":915},{"uri":5286},[57121],{"data":57122,"marks":57123,"value":11707,"nodeType":867},{},[57124],{"type":913},{"data":57126,"marks":57127,"value":57128,"nodeType":867},{},[]," and we’ll be happy to show you. ","Investigating and responding to a third-party data breach using Push","How to use Push to investigate and respond to a third-party data breach, which results in credentials being stolen and sold on criminal marketplaces.  ","2024-06-13T00:00:00.000Z","investigating-and-responding-to-a-third-party-data-breach-using-push",{"items":57134},[57135,57137],{"sys":57136,"name":342},{"id":3240},{"sys":57138,"name":297},{"id":2706},{"items":57140},[57141],{"fullName":4089,"firstName":4090,"jobTitle":851,"profilePicture":57142},{"url":4094},{"__typename":1772,"sys":57144,"content":57145,"title":50373,"synopsis":50374,"hashTags":59,"publishedDate":50375,"slug":50376,"tagsCollection":57555,"authorsCollection":57561},{"id":49897},{"json":57146},{"data":57147,"content":57148,"nodeType":1680},{},[57149,57155,57161,57167,57173,57179,57185,57191,57197,57203,57219,57235,57241,57247,57263,57269,57279,57316,57322,57338,57345,57351,57357,57363,57369,57375,57433,57439,57444,57450,57456,57462,57468,57484,57490,57496,57502,57508,57514,57520,57526,57532,57538,57543,57549],{"data":57150,"content":57151,"nodeType":876},{},[57152],{"data":57153,"marks":57154,"value":49908,"nodeType":867},{},[],{"data":57156,"content":57157,"nodeType":876},{},[57158],{"data":57159,"marks":57160,"value":49915,"nodeType":867},{},[],{"data":57162,"content":57163,"nodeType":876},{},[57164],{"data":57165,"marks":57166,"value":49922,"nodeType":867},{},[],{"data":57168,"content":57169,"nodeType":876},{},[57170],{"data":57171,"marks":57172,"value":49929,"nodeType":867},{},[],{"data":57174,"content":57175,"nodeType":876},{},[57176],{"data":57177,"marks":57178,"value":49936,"nodeType":867},{},[],{"data":57180,"content":57181,"nodeType":868},{},[57182],{"data":57183,"marks":57184,"value":49943,"nodeType":867},{},[],{"data":57186,"content":57187,"nodeType":876},{},[57188],{"data":57189,"marks":57190,"value":49950,"nodeType":867},{},[],{"data":57192,"content":57193,"nodeType":876},{},[57194],{"data":57195,"marks":57196,"value":49957,"nodeType":867},{},[],{"data":57198,"content":57199,"nodeType":876},{},[57200],{"data":57201,"marks":57202,"value":49964,"nodeType":867},{},[],{"data":57204,"content":57205,"nodeType":1629},{},[57206],{"data":57207,"content":57208,"nodeType":1586},{},[57209],{"data":57210,"content":57211,"nodeType":876},{},[57212,57216],{"data":57213,"marks":57214,"value":49978,"nodeType":867},{},[57215],{"type":865},{"data":57217,"marks":57218,"value":49982,"nodeType":867},{},[],{"data":57220,"content":57221,"nodeType":1629},{},[57222],{"data":57223,"content":57224,"nodeType":1586},{},[57225],{"data":57226,"content":57227,"nodeType":876},{},[57228,57232],{"data":57229,"marks":57230,"value":49996,"nodeType":867},{},[57231],{"type":865},{"data":57233,"marks":57234,"value":50000,"nodeType":867},{},[],{"data":57236,"content":57237,"nodeType":1058},{},[57238],{"data":57239,"marks":57240,"value":50007,"nodeType":867},{},[],{"data":57242,"content":57243,"nodeType":876},{},[57244],{"data":57245,"marks":57246,"value":50014,"nodeType":867},{},[],{"data":57248,"content":57249,"nodeType":876},{},[57250,57253,57260],{"data":57251,"marks":57252,"value":50021,"nodeType":867},{},[],{"data":57254,"content":57255,"nodeType":915},{"uri":50024},[57256],{"data":57257,"marks":57258,"value":50030,"nodeType":867},{},[57259],{"type":913},{"data":57261,"marks":57262,"value":50034,"nodeType":867},{},[],{"data":57264,"content":57265,"nodeType":876},{},[57266],{"data":57267,"marks":57268,"value":50041,"nodeType":867},{},[],{"data":57270,"content":57271,"nodeType":876},{},[57272,57275],{"data":57273,"marks":57274,"value":50048,"nodeType":867},{},[],{"data":57276,"marks":57277,"value":50053,"nodeType":867},{},[57278],{"type":865},{"data":57280,"content":57281,"nodeType":1629},{},[57282,57299],{"data":57283,"content":57284,"nodeType":1586},{},[57285],{"data":57286,"content":57287,"nodeType":876},{},[57288,57292,57295],{"data":57289,"marks":57290,"value":50067,"nodeType":867},{},[57291],{"type":865},{"data":57293,"marks":57294,"value":50071,"nodeType":867},{},[],{"data":57296,"marks":57297,"value":50076,"nodeType":867},{},[57298],{"type":1303},{"data":57300,"content":57301,"nodeType":1586},{},[57302],{"data":57303,"content":57304,"nodeType":876},{},[57305,57309,57312],{"data":57306,"marks":57307,"value":50087,"nodeType":867},{},[57308],{"type":865},{"data":57310,"marks":57311,"value":50091,"nodeType":867},{},[],{"data":57313,"marks":57314,"value":50096,"nodeType":867},{},[57315],{"type":865},{"data":57317,"content":57318,"nodeType":876},{},[57319],{"data":57320,"marks":57321,"value":50103,"nodeType":867},{},[],{"data":57323,"content":57324,"nodeType":876},{},[57325,57329,57334],{"data":57326,"marks":57327,"value":50111,"nodeType":867},{},[57328],{"type":865},{"data":57330,"marks":57331,"value":50117,"nodeType":867},{},[57332,57333],{"type":1303},{"type":865},{"data":57335,"marks":57336,"value":50122,"nodeType":867},{},[57337],{"type":865},{"data":57339,"content":57340,"nodeType":868},{},[57341],{"data":57342,"marks":57343,"value":50130,"nodeType":867},{},[57344],{"type":865},{"data":57346,"content":57347,"nodeType":876},{},[57348],{"data":57349,"marks":57350,"value":50137,"nodeType":867},{},[],{"data":57352,"content":57353,"nodeType":876},{},[57354],{"data":57355,"marks":57356,"value":50144,"nodeType":867},{},[],{"data":57358,"content":57359,"nodeType":876},{},[57360],{"data":57361,"marks":57362,"value":50151,"nodeType":867},{},[],{"data":57364,"content":57365,"nodeType":876},{},[57366],{"data":57367,"marks":57368,"value":50158,"nodeType":867},{},[],{"data":57370,"content":57371,"nodeType":876},{},[57372],{"data":57373,"marks":57374,"value":50165,"nodeType":867},{},[],{"data":57376,"content":57377,"nodeType":1629},{},[57378,57397,57415],{"data":57379,"content":57380,"nodeType":1586},{},[57381],{"data":57382,"content":57383,"nodeType":876},{},[57384,57387,57394],{"data":57385,"marks":57386,"value":21,"nodeType":867},{},[],{"data":57388,"content":57389,"nodeType":915},{"uri":22796},[57390],{"data":57391,"marks":57392,"value":50185,"nodeType":867},{},[57393],{"type":913},{"data":57395,"marks":57396,"value":50189,"nodeType":867},{},[],{"data":57398,"content":57399,"nodeType":1586},{},[57400],{"data":57401,"content":57402,"nodeType":876},{},[57403,57406,57412],{"data":57404,"marks":57405,"value":21,"nodeType":867},{},[],{"data":57407,"content":57408,"nodeType":915},{"uri":40019},[57409],{"data":57410,"marks":57411,"value":50205,"nodeType":867},{},[],{"data":57413,"marks":57414,"value":50209,"nodeType":867},{},[],{"data":57416,"content":57417,"nodeType":1586},{},[57418],{"data":57419,"content":57420,"nodeType":876},{},[57421,57424,57430],{"data":57422,"marks":57423,"value":21,"nodeType":867},{},[],{"data":57425,"content":57426,"nodeType":915},{"uri":50221},[57427],{"data":57428,"marks":57429,"value":50226,"nodeType":867},{},[],{"data":57431,"marks":57432,"value":50230,"nodeType":867},{},[],{"data":57434,"content":57435,"nodeType":876},{},[57436],{"data":57437,"marks":57438,"value":50237,"nodeType":867},{},[],{"data":57440,"content":57443,"nodeType":985},{"target":57441},{"sys":57442},{"id":40799,"type":982,"linkType":983},[],{"data":57445,"content":57446,"nodeType":876},{},[57447],{"data":57448,"marks":57449,"value":50249,"nodeType":867},{},[],{"data":57451,"content":57452,"nodeType":868},{},[57453],{"data":57454,"marks":57455,"value":50256,"nodeType":867},{},[],{"data":57457,"content":57458,"nodeType":876},{},[57459],{"data":57460,"marks":57461,"value":50263,"nodeType":867},{},[],{"data":57463,"content":57464,"nodeType":1058},{},[57465],{"data":57466,"marks":57467,"value":50270,"nodeType":867},{},[],{"data":57469,"content":57470,"nodeType":876},{},[57471,57474,57481],{"data":57472,"marks":57473,"value":50277,"nodeType":867},{},[],{"data":57475,"content":57476,"nodeType":915},{"uri":50280},[57477],{"data":57478,"marks":57479,"value":50286,"nodeType":867},{},[57480],{"type":913},{"data":57482,"marks":57483,"value":50290,"nodeType":867},{},[],{"data":57485,"content":57486,"nodeType":876},{},[57487],{"data":57488,"marks":57489,"value":50297,"nodeType":867},{},[],{"data":57491,"content":57492,"nodeType":876},{},[57493],{"data":57494,"marks":57495,"value":50304,"nodeType":867},{},[],{"data":57497,"content":57498,"nodeType":876},{},[57499],{"data":57500,"marks":57501,"value":50311,"nodeType":867},{},[],{"data":57503,"content":57504,"nodeType":1058},{},[57505],{"data":57506,"marks":57507,"value":50318,"nodeType":867},{},[],{"data":57509,"content":57510,"nodeType":876},{},[57511],{"data":57512,"marks":57513,"value":50325,"nodeType":867},{},[],{"data":57515,"content":57516,"nodeType":876},{},[57517],{"data":57518,"marks":57519,"value":50332,"nodeType":867},{},[],{"data":57521,"content":57522,"nodeType":1058},{},[57523],{"data":57524,"marks":57525,"value":50339,"nodeType":867},{},[],{"data":57527,"content":57528,"nodeType":876},{},[57529],{"data":57530,"marks":57531,"value":50346,"nodeType":867},{},[],{"data":57533,"content":57534,"nodeType":876},{},[57535],{"data":57536,"marks":57537,"value":50353,"nodeType":867},{},[],{"data":57539,"content":57542,"nodeType":985},{"target":57540},{"sys":57541},{"id":50358,"type":982,"linkType":983},[],{"data":57544,"content":57545,"nodeType":868},{},[57546],{"data":57547,"marks":57548,"value":23563,"nodeType":867},{},[],{"data":57550,"content":57551,"nodeType":876},{},[57552],{"data":57553,"marks":57554,"value":50372,"nodeType":867},{},[],{"items":57556},[57557,57559],{"sys":57558,"name":342},{"id":3240},{"sys":57560,"name":4018},{"id":4017},{"items":57562},[57563],{"fullName":4022,"firstName":4023,"jobTitle":4024,"profilePicture":57564},{"url":4026},{"__typename":1772,"sys":57566,"content":57567,"title":45401,"synopsis":45402,"hashTags":59,"publishedDate":45403,"slug":45404,"tagsCollection":57919,"authorsCollection":57925},{"id":44994},{"json":57568},{"data":57569,"content":57570,"nodeType":1680},{},[57571,57576,57593,57610,57625,57642,57663,57669,57686,57703,57709,57714,57720,57726,57732,57738,57744,57750,57756,57762,57768,57785,57791,57796,57816,57822,57837,57842,57859,57865,57871,57877,57883,57898,57904],{"data":57572,"content":57575,"nodeType":985},{"target":57573},{"sys":57574},{"id":45003,"type":982,"linkType":983},[],{"data":57577,"content":57578,"nodeType":876},{},[57579,57582,57590],{"data":57580,"marks":57581,"value":45011,"nodeType":867},{},[],{"data":57583,"content":57586,"nodeType":17452},{"target":57584},{"sys":57585},{"id":45016,"type":982,"linkType":983},[57587],{"data":57588,"marks":57589,"value":45021,"nodeType":867},{},[],{"data":57591,"marks":57592,"value":45025,"nodeType":867},{},[],{"data":57594,"content":57595,"nodeType":876},{},[57596,57599,57607],{"data":57597,"marks":57598,"value":45032,"nodeType":867},{},[],{"data":57600,"content":57603,"nodeType":17452},{"target":57601},{"sys":57602},{"id":45037,"type":982,"linkType":983},[57604],{"data":57605,"marks":57606,"value":45042,"nodeType":867},{},[],{"data":57608,"marks":57609,"value":45046,"nodeType":867},{},[],{"data":57611,"content":57612,"nodeType":876},{},[57613,57616,57622],{"data":57614,"marks":57615,"value":45053,"nodeType":867},{},[],{"data":57617,"content":57618,"nodeType":915},{"uri":38506},[57619],{"data":57620,"marks":57621,"value":45060,"nodeType":867},{},[],{"data":57623,"marks":57624,"value":45064,"nodeType":867},{},[],{"data":57626,"content":57627,"nodeType":876},{},[57628,57631,57639],{"data":57629,"marks":57630,"value":45071,"nodeType":867},{},[],{"data":57632,"content":57635,"nodeType":17452},{"target":57633},{"sys":57634},{"id":45016,"type":982,"linkType":983},[57636],{"data":57637,"marks":57638,"value":45080,"nodeType":867},{},[],{"data":57640,"marks":57641,"value":45084,"nodeType":867},{},[],{"data":57643,"content":57644,"nodeType":1629},{},[57645,57654],{"data":57646,"content":57647,"nodeType":1586},{},[57648],{"data":57649,"content":57650,"nodeType":876},{},[57651],{"data":57652,"marks":57653,"value":45097,"nodeType":867},{},[],{"data":57655,"content":57656,"nodeType":1586},{},[57657],{"data":57658,"content":57659,"nodeType":876},{},[57660],{"data":57661,"marks":57662,"value":45107,"nodeType":867},{},[],{"data":57664,"content":57665,"nodeType":876},{},[57666],{"data":57667,"marks":57668,"value":45114,"nodeType":867},{},[],{"data":57670,"content":57671,"nodeType":876},{},[57672,57675,57683],{"data":57673,"marks":57674,"value":45121,"nodeType":867},{},[],{"data":57676,"content":57679,"nodeType":17452},{"target":57677},{"sys":57678},{"id":38762,"type":982,"linkType":983},[57680],{"data":57681,"marks":57682,"value":45130,"nodeType":867},{},[],{"data":57684,"marks":57685,"value":45134,"nodeType":867},{},[],{"data":57687,"content":57688,"nodeType":876},{},[57689,57692,57700],{"data":57690,"marks":57691,"value":45141,"nodeType":867},{},[],{"data":57693,"content":57696,"nodeType":17452},{"target":57694},{"sys":57695},{"id":45146,"type":982,"linkType":983},[57697],{"data":57698,"marks":57699,"value":45151,"nodeType":867},{},[],{"data":57701,"marks":57702,"value":45155,"nodeType":867},{},[],{"data":57704,"content":57705,"nodeType":876},{},[57706],{"data":57707,"marks":57708,"value":45162,"nodeType":867},{},[],{"data":57710,"content":57713,"nodeType":985},{"target":57711},{"sys":57712},{"id":45167,"type":982,"linkType":983},[],{"data":57715,"content":57716,"nodeType":868},{},[57717],{"data":57718,"marks":57719,"value":45175,"nodeType":867},{},[],{"data":57721,"content":57722,"nodeType":876},{},[57723],{"data":57724,"marks":57725,"value":45182,"nodeType":867},{},[],{"data":57727,"content":57728,"nodeType":876},{},[57729],{"data":57730,"marks":57731,"value":45189,"nodeType":867},{},[],{"data":57733,"content":57734,"nodeType":876},{},[57735],{"data":57736,"marks":57737,"value":45196,"nodeType":867},{},[],{"data":57739,"content":57740,"nodeType":876},{},[57741],{"data":57742,"marks":57743,"value":45203,"nodeType":867},{},[],{"data":57745,"content":57746,"nodeType":876},{},[57747],{"data":57748,"marks":57749,"value":45210,"nodeType":867},{},[],{"data":57751,"content":57752,"nodeType":876},{},[57753],{"data":57754,"marks":57755,"value":45217,"nodeType":867},{},[],{"data":57757,"content":57758,"nodeType":868},{},[57759],{"data":57760,"marks":57761,"value":45224,"nodeType":867},{},[],{"data":57763,"content":57764,"nodeType":876},{},[57765],{"data":57766,"marks":57767,"value":45231,"nodeType":867},{},[],{"data":57769,"content":57770,"nodeType":876},{},[57771,57774,57782],{"data":57772,"marks":57773,"value":45238,"nodeType":867},{},[],{"data":57775,"content":57778,"nodeType":17452},{"target":57776},{"sys":57777},{"id":38581,"type":982,"linkType":983},[57779],{"data":57780,"marks":57781,"value":45247,"nodeType":867},{},[],{"data":57783,"marks":57784,"value":45251,"nodeType":867},{},[],{"data":57786,"content":57787,"nodeType":876},{},[57788],{"data":57789,"marks":57790,"value":45258,"nodeType":867},{},[],{"data":57792,"content":57795,"nodeType":985},{"target":57793},{"sys":57794},{"id":45263,"type":982,"linkType":983},[],{"data":57797,"content":57798,"nodeType":876},{},[57799,57802,57806,57809,57813],{"data":57800,"marks":57801,"value":45271,"nodeType":867},{},[],{"data":57803,"marks":57804,"value":38740,"nodeType":867},{},[57805],{"type":865},{"data":57807,"marks":57808,"value":45279,"nodeType":867},{},[],{"data":57810,"marks":57811,"value":38732,"nodeType":867},{},[57812],{"type":865},{"data":57814,"marks":57815,"value":45287,"nodeType":867},{},[],{"data":57817,"content":57818,"nodeType":876},{},[57819],{"data":57820,"marks":57821,"value":45294,"nodeType":867},{},[],{"data":57823,"content":57824,"nodeType":876},{},[57825,57828,57834],{"data":57826,"marks":57827,"value":41371,"nodeType":867},{},[],{"data":57829,"content":57830,"nodeType":915},{"uri":38608},[57831],{"data":57832,"marks":57833,"value":41188,"nodeType":867},{},[],{"data":57835,"marks":57836,"value":41381,"nodeType":867},{},[],{"data":57838,"content":57841,"nodeType":985},{"target":57839},{"sys":57840},{"id":45314,"type":982,"linkType":983},[],{"data":57843,"content":57844,"nodeType":876},{},[57845,57848,57856],{"data":57846,"marks":57847,"value":45322,"nodeType":867},{},[],{"data":57849,"content":57852,"nodeType":17452},{"target":57850},{"sys":57851},{"id":38846,"type":982,"linkType":983},[57853],{"data":57854,"marks":57855,"value":38777,"nodeType":867},{},[],{"data":57857,"marks":57858,"value":45334,"nodeType":867},{},[],{"data":57860,"content":57861,"nodeType":876},{},[57862],{"data":57863,"marks":57864,"value":45341,"nodeType":867},{},[],{"data":57866,"content":57867,"nodeType":876},{},[57868],{"data":57869,"marks":57870,"value":45348,"nodeType":867},{},[],{"data":57872,"content":57873,"nodeType":868},{},[57874],{"data":57875,"marks":57876,"value":15458,"nodeType":867},{},[],{"data":57878,"content":57879,"nodeType":876},{},[57880],{"data":57881,"marks":57882,"value":45361,"nodeType":867},{},[],{"data":57884,"content":57885,"nodeType":876},{},[57886,57889,57895],{"data":57887,"marks":57888,"value":45368,"nodeType":867},{},[],{"data":57890,"content":57891,"nodeType":915},{"uri":45371},[57892],{"data":57893,"marks":57894,"value":45376,"nodeType":867},{},[],{"data":57896,"marks":57897,"value":1679,"nodeType":867},{},[],{"data":57899,"content":57900,"nodeType":868},{},[57901],{"data":57902,"marks":57903,"value":25228,"nodeType":867},{},[],{"data":57905,"content":57906,"nodeType":876},{},[57907,57910,57916],{"data":57908,"marks":57909,"value":44966,"nodeType":867},{},[],{"data":57911,"content":57912,"nodeType":915},{"uri":5286},[57913],{"data":57914,"marks":57915,"value":11707,"nodeType":867},{},[],{"data":57917,"marks":57918,"value":44977,"nodeType":867},{},[],{"items":57920},[57921,57923],{"sys":57922,"name":39245},{"id":39244},{"sys":57924,"name":342},{"id":3240},{"items":57926},[57927],{"fullName":2714,"firstName":2715,"jobTitle":851,"profilePicture":57928},{"url":2717},"blog/introducing-session-token-theft-detection-why-browser-is-best",{"json":57931},{"data":57932,"content":57933,"nodeType":1680},{},[57934],{"data":57935,"content":57936,"nodeType":876},{},[57937],{"data":57938,"marks":57939,"value":57940,"nodeType":867},{},[],"Push identifies session token theft by adding telemetry to the user agent string – using the power of our browser agent to create a new high-fidelity signal for your security team.",{"id":44487,"publishedAt":57942},"2026-08-12T11:55:17.569Z",{"items":57944},[57945,57947],{"sys":57946,"name":342},{"id":3240},{"sys":57948,"name":39245},{"id":39244},{"items":57950},[57951,57953,57955,57957,57959,57961,57963,57965,57967,57969,57971],{"sys":57952,"name":279,"slug":280,"tier":31},{"id":276},{"sys":57954,"name":342,"slug":343,"tier":31},{"id":339},{"sys":57956,"name":413,"slug":414,"tier":31},{"id":410},{"sys":57958,"name":297,"slug":298,"tier":31},{"id":294},{"sys":57960,"name":571,"slug":572,"tier":45},{"id":568},{"sys":57962,"name":422,"slug":423,"tier":45},{"id":419},{"sys":57964,"name":404,"slug":405,"tier":45},{"id":401},{"sys":57966,"name":351,"slug":352,"tier":45},{"id":348},{"sys":57968,"name":466,"slug":467,"tier":45},{"id":463},{"sys":57970,"name":598,"slug":599,"tier":45},{"id":595},{"sys":57972,"name":377,"slug":378,"tier":45},{"id":374},"6NALxwByZU7T83nPujij4fs17n2Hsv8JXM23iqDL5Zs",{"id":57975,"title":45401,"authorsCollection":57976,"content":57980,"extension":228,"faqItemsCollection":58388,"faqTitle":59,"featured":6,"hashTags":59,"meta":58390,"metaTitle":58391,"ogImage":59,"postType":24263,"publishedDate":45403,"relatedBlogPostsCollection":58392,"slug":45404,"stem":60208,"subtitle":59,"summary":60209,"synopsis":45402,"sys":60220,"tagsCollection":60222,"topicsCollection":60228,"__hash__":60256},"blog/blog/introducing-aitm-phishing-toolkit-detection-powered-by-the-push-browser.json",{"items":57977},[57978],{"fullName":2714,"firstName":2715,"jobTitle":851,"socialLinks":59,"profilePicture":57979},{"url":2717},{"json":57981,"links":58332},{"data":57982,"content":57983,"nodeType":1680},{},[57984,57989,58006,58023,58038,58055,58076,58082,58099,58116,58122,58127,58133,58139,58145,58151,58157,58163,58169,58175,58181,58198,58204,58209,58229,58235,58250,58255,58272,58278,58284,58290,58296,58311,58317],{"data":57985,"content":57988,"nodeType":985},{"target":57986},{"sys":57987},{"id":45003,"type":982,"linkType":983},[],{"data":57990,"content":57991,"nodeType":876},{},[57992,57995,58003],{"data":57993,"marks":57994,"value":45011,"nodeType":867},{},[],{"data":57996,"content":57999,"nodeType":17452},{"target":57997},{"sys":57998},{"id":45016,"type":982,"linkType":983},[58000],{"data":58001,"marks":58002,"value":45021,"nodeType":867},{},[],{"data":58004,"marks":58005,"value":45025,"nodeType":867},{},[],{"data":58007,"content":58008,"nodeType":876},{},[58009,58012,58020],{"data":58010,"marks":58011,"value":45032,"nodeType":867},{},[],{"data":58013,"content":58016,"nodeType":17452},{"target":58014},{"sys":58015},{"id":45037,"type":982,"linkType":983},[58017],{"data":58018,"marks":58019,"value":45042,"nodeType":867},{},[],{"data":58021,"marks":58022,"value":45046,"nodeType":867},{},[],{"data":58024,"content":58025,"nodeType":876},{},[58026,58029,58035],{"data":58027,"marks":58028,"value":45053,"nodeType":867},{},[],{"data":58030,"content":58031,"nodeType":915},{"uri":38506},[58032],{"data":58033,"marks":58034,"value":45060,"nodeType":867},{},[],{"data":58036,"marks":58037,"value":45064,"nodeType":867},{},[],{"data":58039,"content":58040,"nodeType":876},{},[58041,58044,58052],{"data":58042,"marks":58043,"value":45071,"nodeType":867},{},[],{"data":58045,"content":58048,"nodeType":17452},{"target":58046},{"sys":58047},{"id":45016,"type":982,"linkType":983},[58049],{"data":58050,"marks":58051,"value":45080,"nodeType":867},{},[],{"data":58053,"marks":58054,"value":45084,"nodeType":867},{},[],{"data":58056,"content":58057,"nodeType":1629},{},[58058,58067],{"data":58059,"content":58060,"nodeType":1586},{},[58061],{"data":58062,"content":58063,"nodeType":876},{},[58064],{"data":58065,"marks":58066,"value":45097,"nodeType":867},{},[],{"data":58068,"content":58069,"nodeType":1586},{},[58070],{"data":58071,"content":58072,"nodeType":876},{},[58073],{"data":58074,"marks":58075,"value":45107,"nodeType":867},{},[],{"data":58077,"content":58078,"nodeType":876},{},[58079],{"data":58080,"marks":58081,"value":45114,"nodeType":867},{},[],{"data":58083,"content":58084,"nodeType":876},{},[58085,58088,58096],{"data":58086,"marks":58087,"value":45121,"nodeType":867},{},[],{"data":58089,"content":58092,"nodeType":17452},{"target":58090},{"sys":58091},{"id":38762,"type":982,"linkType":983},[58093],{"data":58094,"marks":58095,"value":45130,"nodeType":867},{},[],{"data":58097,"marks":58098,"value":45134,"nodeType":867},{},[],{"data":58100,"content":58101,"nodeType":876},{},[58102,58105,58113],{"data":58103,"marks":58104,"value":45141,"nodeType":867},{},[],{"data":58106,"content":58109,"nodeType":17452},{"target":58107},{"sys":58108},{"id":45146,"type":982,"linkType":983},[58110],{"data":58111,"marks":58112,"value":45151,"nodeType":867},{},[],{"data":58114,"marks":58115,"value":45155,"nodeType":867},{},[],{"data":58117,"content":58118,"nodeType":876},{},[58119],{"data":58120,"marks":58121,"value":45162,"nodeType":867},{},[],{"data":58123,"content":58126,"nodeType":985},{"target":58124},{"sys":58125},{"id":45167,"type":982,"linkType":983},[],{"data":58128,"content":58129,"nodeType":868},{},[58130],{"data":58131,"marks":58132,"value":45175,"nodeType":867},{},[],{"data":58134,"content":58135,"nodeType":876},{},[58136],{"data":58137,"marks":58138,"value":45182,"nodeType":867},{},[],{"data":58140,"content":58141,"nodeType":876},{},[58142],{"data":58143,"marks":58144,"value":45189,"nodeType":867},{},[],{"data":58146,"content":58147,"nodeType":876},{},[58148],{"data":58149,"marks":58150,"value":45196,"nodeType":867},{},[],{"data":58152,"content":58153,"nodeType":876},{},[58154],{"data":58155,"marks":58156,"value":45203,"nodeType":867},{},[],{"data":58158,"content":58159,"nodeType":876},{},[58160],{"data":58161,"marks":58162,"value":45210,"nodeType":867},{},[],{"data":58164,"content":58165,"nodeType":876},{},[58166],{"data":58167,"marks":58168,"value":45217,"nodeType":867},{},[],{"data":58170,"content":58171,"nodeType":868},{},[58172],{"data":58173,"marks":58174,"value":45224,"nodeType":867},{},[],{"data":58176,"content":58177,"nodeType":876},{},[58178],{"data":58179,"marks":58180,"value":45231,"nodeType":867},{},[],{"data":58182,"content":58183,"nodeType":876},{},[58184,58187,58195],{"data":58185,"marks":58186,"value":45238,"nodeType":867},{},[],{"data":58188,"content":58191,"nodeType":17452},{"target":58189},{"sys":58190},{"id":38581,"type":982,"linkType":983},[58192],{"data":58193,"marks":58194,"value":45247,"nodeType":867},{},[],{"data":58196,"marks":58197,"value":45251,"nodeType":867},{},[],{"data":58199,"content":58200,"nodeType":876},{},[58201],{"data":58202,"marks":58203,"value":45258,"nodeType":867},{},[],{"data":58205,"content":58208,"nodeType":985},{"target":58206},{"sys":58207},{"id":45263,"type":982,"linkType":983},[],{"data":58210,"content":58211,"nodeType":876},{},[58212,58215,58219,58222,58226],{"data":58213,"marks":58214,"value":45271,"nodeType":867},{},[],{"data":58216,"marks":58217,"value":38740,"nodeType":867},{},[58218],{"type":865},{"data":58220,"marks":58221,"value":45279,"nodeType":867},{},[],{"data":58223,"marks":58224,"value":38732,"nodeType":867},{},[58225],{"type":865},{"data":58227,"marks":58228,"value":45287,"nodeType":867},{},[],{"data":58230,"content":58231,"nodeType":876},{},[58232],{"data":58233,"marks":58234,"value":45294,"nodeType":867},{},[],{"data":58236,"content":58237,"nodeType":876},{},[58238,58241,58247],{"data":58239,"marks":58240,"value":41371,"nodeType":867},{},[],{"data":58242,"content":58243,"nodeType":915},{"uri":38608},[58244],{"data":58245,"marks":58246,"value":41188,"nodeType":867},{},[],{"data":58248,"marks":58249,"value":41381,"nodeType":867},{},[],{"data":58251,"content":58254,"nodeType":985},{"target":58252},{"sys":58253},{"id":45314,"type":982,"linkType":983},[],{"data":58256,"content":58257,"nodeType":876},{},[58258,58261,58269],{"data":58259,"marks":58260,"value":45322,"nodeType":867},{},[],{"data":58262,"content":58265,"nodeType":17452},{"target":58263},{"sys":58264},{"id":38846,"type":982,"linkType":983},[58266],{"data":58267,"marks":58268,"value":38777,"nodeType":867},{},[],{"data":58270,"marks":58271,"value":45334,"nodeType":867},{},[],{"data":58273,"content":58274,"nodeType":876},{},[58275],{"data":58276,"marks":58277,"value":45341,"nodeType":867},{},[],{"data":58279,"content":58280,"nodeType":876},{},[58281],{"data":58282,"marks":58283,"value":45348,"nodeType":867},{},[],{"data":58285,"content":58286,"nodeType":868},{},[58287],{"data":58288,"marks":58289,"value":15458,"nodeType":867},{},[],{"data":58291,"content":58292,"nodeType":876},{},[58293],{"data":58294,"marks":58295,"value":45361,"nodeType":867},{},[],{"data":58297,"content":58298,"nodeType":876},{},[58299,58302,58308],{"data":58300,"marks":58301,"value":45368,"nodeType":867},{},[],{"data":58303,"content":58304,"nodeType":915},{"uri":45371},[58305],{"data":58306,"marks":58307,"value":45376,"nodeType":867},{},[],{"data":58309,"marks":58310,"value":1679,"nodeType":867},{},[],{"data":58312,"content":58313,"nodeType":868},{},[58314],{"data":58315,"marks":58316,"value":25228,"nodeType":867},{},[],{"data":58318,"content":58319,"nodeType":876},{},[58320,58323,58329],{"data":58321,"marks":58322,"value":44966,"nodeType":867},{},[],{"data":58324,"content":58325,"nodeType":915},{"uri":5286},[58326],{"data":58327,"marks":58328,"value":11707,"nodeType":867},{},[],{"data":58330,"marks":58331,"value":44977,"nodeType":867},{},[],{"entries":58333},{"inline":58334,"hyperlink":58335,"block":58362},[],[58336,58339,58341,58347,58351,58357],{"sys":58337,"__typename":1772,"title":46683,"slug":58338},{"id":45016},"phishing-2-0-how-phishing-toolkits-are-evolving-with-aitm",{"sys":58340,"__typename":1772,"title":54766,"slug":54769},{"id":45037},{"sys":58342,"__typename":58343,"title":58344,"slug":58345,"articleId":58346},{"id":38762},"HelpArticle","Can I use Push to detect phishing tools like Evilginx, Modlishka, NakedPages, or Muraena?","can-i-use-push-to-detect-phishing-tools-like-evilnovnc-and-evilginx",10113,{"sys":58348,"__typename":1772,"title":58349,"slug":58350},{"id":45146},"Introducing SSO Password Protection: Stop employees’ IdP credentials being exposed or phished","introducing-sso-password-protection",{"sys":58352,"__typename":58353,"linkedFromParent":59,"title":58354,"slug":58355,"audience":58356},{"id":38581},"DocumentationPage","Manage security controls","manage-security-controls","administrators",{"sys":58358,"__typename":58343,"title":58359,"slug":58360,"articleId":58361},{"id":38846},"How does Push protect passwords from being reused or phished?","how-does-push-detect-and-prevent-phishing-attacks",10109,[58363,58371,58375,58381],{"sys":58364,"__typename":46623,"title":58365,"youTubeUrl":58366,"imagePlaceholder":58367},{"id":45003},"Introducing phishing toolkit detection with Push: Detect AitM and BitM toolkits","https://www.youtube.com/watch?v=em8H0VOezqM",{"url":58368,"width":58369,"height":58370},"https://images.ctfassets.net/y1cdw1ablpvd/44uW8syU7RcxSx5kI2y0yO/469cb925808f74196b57b6ae209888de/Screenshot_2024-08-15_at_07.11.23.png",3372,1898,{"sys":58372,"__typename":1697,"type":1698,"ctaText":58373,"buttonLabel":58374,"buttonColour":24251,"buttonUrl":41343},{"id":45167},"Learn more about AitM phishing toolkits in our on-demand webinar","Watch Now",{"sys":58376,"__typename":1688,"title":58377,"caption":58378,"layoutMode":59,"file":58379},{"id":45263},"Phishing toolkit block page - KB 10113","Customizable block page",{"url":58380,"width":33790,"height":33791},"https://images.ctfassets.net/y1cdw1ablpvd/7hGVqcQYa0xqDQa8uVBFim/665e8f7141bd272ea7b88ecf6a28de67/phishing_tool_blockpage.png",{"sys":58382,"__typename":1688,"title":58383,"caption":59,"layoutMode":59,"file":58384},{"id":45314},"Evilginx and EvilnoVNC",{"url":58385,"width":58386,"height":58387},"https://images.ctfassets.net/y1cdw1ablpvd/5x785N81GKYzByJoSNIYE0/12da45107348238316b9c5d6350b9d05/Image1__4_-min.png",1336,977,{"items":58389},[],{},"Detect and block phishing tools with the Push browser agent",{"items":58393},[58394,59226,59668],{"__typename":1772,"sys":58395,"content":58396,"title":46683,"synopsis":59214,"hashTags":59,"publishedDate":59215,"slug":58338,"tagsCollection":59216,"authorsCollection":59222},{"id":45016},{"json":58397},{"data":58398,"content":58399,"nodeType":1680},{},[58400,58407,58414,58421,58428,58435,58442,58449,58456,58463,58469,58476,58483,58490,58539,58546,58553,58572,58579,58586,58593,58626,58642,58649,58656,58663,58670,58677,58684,58704,58722,58826,58833,58851,58858,58865,58872,58878,58885,58892,58899,58931,58938,58945,58978,58985,58992,59088,59105,59111,59118,59125,59132,59186,59193,59196,59203,59208],{"data":58401,"content":58402,"nodeType":876},{},[58403],{"data":58404,"marks":58405,"value":58406,"nodeType":867},{},[],"Phishing attacks have always been a go-to technique for both red teamers and real-world threat actors alike. Whether focused on harvesting creds or running malicious payloads, phishing has continued to be adapted to circumvent defenses and has remained highly effective due to this.",{"data":58408,"content":58409,"nodeType":876},{},[58410],{"data":58411,"marks":58412,"value":58413,"nodeType":867},{},[],"As MFA has become more common, classic password harvesting focused phishing attacks have become less effective. Typically, for a full account compromise, an MFA push notification or a one-time passcode (OTP) needs to be entered at the time of login. This means harvesting passwords and using them later is no longer effective alone, because an MFA factor is still required each time a valid login is performed.",{"data":58415,"content":58416,"nodeType":876},{},[58417],{"data":58418,"marks":58419,"value":58420,"nodeType":867},{},[],"Adversary-in-the-Middle (AitM) phishing is a newer variant of phishing that allows attackers to circumvent MFA protection. In this article, we’re going to look at what AitM phishing is, how it works, and what you can do about it.",{"data":58422,"content":58423,"nodeType":868},{},[58424],{"data":58425,"marks":58426,"value":58427,"nodeType":867},{},[],"What is AitM phishing?",{"data":58429,"content":58430,"nodeType":876},{},[58431],{"data":58432,"marks":58433,"value":58434,"nodeType":867},{},[],"AitM phishing is a technique that uses dedicated tooling to act as a proxy between the target and a legitimate login portal for an application, principally to make it easier to defeat MFA protection. ",{"data":58436,"content":58437,"nodeType":876},{},[58438],{"data":58439,"marks":58440,"value":58441,"nodeType":867},{},[],"While any login portal can be a target, attackers typically look for SSO login portals such as Microsoft Entra, Okta, or Google Workspace. This allows the target to log in successfully with a legitimate service they use and even continue to interact with it, while providing additional access to connected SSO apps if the attack is successful. ",{"data":58443,"content":58444,"nodeType":876},{},[58445],{"data":58446,"marks":58447,"value":58448,"nodeType":867},{},[],"As it’s a proxy to the real application, the page will appear exactly as the user expects, because they are logging into the legitimate site – just taking a detour via the attacker’s device. For example, if accessing their webmail, the user will see all their real emails; if accessing their cloud file store then all their real files will be present, etc. This gives the method an increased sense of authenticity and makes the compromise less obvious to the user. However, because the attacker is sitting in the middle of this connection, they are able to observe all interactions and also take control of the authenticated session to gain control of the user account. ",{"data":58450,"content":58451,"nodeType":876},{},[58452],{"data":58453,"marks":58454,"value":58455,"nodeType":867},{},[],"While this access is technically temporary, since the attacker is unable to re-authenticate in future without additional MFA prompts, in practice authenticated sessions can often last as long as 30 days or more if kept active. Additionally, there are a wide range of persistence techniques that allow an attacker to maintain some level of access to the user account and/or targeted application indefinitely. ",{"data":58457,"content":58458,"nodeType":876},{},[58459],{"data":58460,"marks":58461,"value":58462,"nodeType":867},{},[],"We’ll revisit this point later, but for now let’s consider the two main techniques that are used to implement AitM phishing: Reverse web proxies and Browser-in-the-Middle techniques.",{"data":58464,"content":58468,"nodeType":985},{"target":58465},{"sys":58466},{"id":58467,"type":982,"linkType":983},"6WEolDcviadCgAW4dCgTPW",[],{"data":58470,"content":58471,"nodeType":1058},{},[58472],{"data":58473,"marks":58474,"value":58475,"nodeType":867},{},[],"Reverse web proxy techniques",{"data":58477,"content":58478,"nodeType":876},{},[58479],{"data":58480,"marks":58481,"value":58482,"nodeType":867},{},[],"One common AitM phishing approach is to use tooling that acts as a reverse web proxy. For example, let’s say a victim is tricked into visiting a malicious domain. Under the hood, HTTP requests are passed between the victim’s browser and the real site via the malicious site. When the malicious site receives an HTTP request, it forwards this request on to the legitimate site it is impersonating, receives the response, and then forwards that on to the victim. ",{"data":58484,"content":58485,"nodeType":876},{},[58486],{"data":58487,"marks":58488,"value":58489,"nodeType":867},{},[],"In practice, there are many technical challenges, such as rewriting all links and references to the impersonated site to ensure everything continues to be sent to the attacker. However, at a high level, it really is just acting as a reverse web proxy.",{"data":58491,"content":58492,"nodeType":876},{},[58493,58497,58504,58507,58514,58518,58525,58529,58536],{"data":58494,"marks":58495,"value":58496,"nodeType":867},{},[],"This is arguably the most scalable and reliable approach from an attacker’s point of view. Open-source tools that demonstrate this method include ",{"data":58498,"content":58499,"nodeType":915},{"uri":41285},[58500],{"data":58501,"marks":58502,"value":41290,"nodeType":867},{},[58503],{"type":913},{"data":58505,"marks":58506,"value":5136,"nodeType":867},{},[],{"data":58508,"content":58509,"nodeType":915},{"uri":41296},[58510],{"data":58511,"marks":58512,"value":41301,"nodeType":867},{},[58513],{"type":913},{"data":58515,"marks":58516,"value":58517,"nodeType":867},{},[],", and the ever popular ",{"data":58519,"content":58520,"nodeType":915},{"uri":41307},[58521],{"data":58522,"marks":58523,"value":41312,"nodeType":867},{},[58524],{"type":913},{"data":58526,"marks":58527,"value":58528,"nodeType":867},{},[],". In the criminal world, there are also similar private toolsets available that have been used in many breaches in the past. A good example of this would be ",{"data":58530,"content":58531,"nodeType":915},{"uri":41318},[58532],{"data":58533,"marks":58534,"value":41323,"nodeType":867},{},[58535],{"type":913},{"data":58537,"marks":58538,"value":1679,"nodeType":867},{},[],{"data":58540,"content":58541,"nodeType":876},{},[58542],{"data":58543,"marks":58544,"value":58545,"nodeType":867},{},[],"One downside to this approach is that there are controls that can be put in place to block it. For example, application developers can hide obfuscated JavaScript code that will fail if the correct value is not produced, checking that the origin matches the expected (legitimate) domains or contains encrypted tokens including this material sent as part of the login process. ",{"data":58547,"content":58548,"nodeType":876},{},[58549],{"data":58550,"marks":58551,"value":58552,"nodeType":867},{},[],"While your average small website is not going to be implementing such checks, major identity providers have a strong vested interest in evolving their defenses to block these techniques. At this point, it’s a cat-and-mouse game. ",{"data":58554,"content":58555,"nodeType":876},{},[58556,58560,58569],{"data":58557,"marks":58558,"value":58559,"nodeType":867},{},[],"If you want to know more about this space, then definitely check out ",{"data":58561,"content":58563,"nodeType":915},{"uri":58562},"https://www.youtube.com/watch?v=C-Fh4sIdY8c",[58564],{"data":58565,"marks":58566,"value":58568,"nodeType":867},{},[58567],{"type":913},"Kuba Gretzky’s talk on this at x33fcon",{"data":58570,"marks":58571,"value":24572,"nodeType":867},{},[],{"data":58573,"content":58574,"nodeType":1058},{},[58575],{"data":58576,"marks":58577,"value":58578,"nodeType":867},{},[],"Browser-in-the-Middle (BitM) techniques ",{"data":58580,"content":58581,"nodeType":876},{},[58582],{"data":58583,"marks":58584,"value":58585,"nodeType":867},{},[],"Another common approach is known as Browser-in-the-Middle (BitM). Rather than act as a reverse web proxy, this technique tricks a target into directly controlling the attacker’s own browser remotely using desktop screen sharing and control approaches, much like VNC and RDP. This enables the attacker to harvest not just the username and password, but all other associated secrets and tokens that go along with the login. ",{"data":58587,"content":58588,"nodeType":876},{},[58589],{"data":58590,"marks":58591,"value":58592,"nodeType":867},{},[],"In this case, the victim isn’t interacting with a fake website clone or proxy. They are literally remotely controlling the attacker’s browser to log in to the legitimate application without realizing. This is the virtual equivalent of an attacker handing their laptop to their victim, asking them to login to Okta for them, and then taking their laptop back afterwards. Thanks very much!",{"data":58594,"content":58595,"nodeType":876},{},[58596,58600,58609,58613,58622],{"data":58597,"marks":58598,"value":58599,"nodeType":867},{},[],"Practically speaking, the most common approach for implementing this technique is using the open-source project noVNC, which is a JavaScript-based VNC client that allows VNC to be used in the browser. Probably the most well-known example of an offensive tool implementing this is ",{"data":58601,"content":58603,"nodeType":915},{"uri":58602},"https://github.com/JoelGMSec/EvilnoVNC",[58604],{"data":58605,"marks":58606,"value":58608,"nodeType":867},{},[58607],{"type":913},"EvilnoVNC",{"data":58610,"marks":58611,"value":58612,"nodeType":867},{},[],", which spins up Docker instances of VNC and proxies access to them, while also logging keystrokes and cookies to facilitate account compromise. Tools like ",{"data":58614,"content":58616,"nodeType":915},{"uri":58615},"https://posts.specterops.io/phishing-with-dynamite-7d33d8fac038",[58617],{"data":58618,"marks":58619,"value":58621,"nodeType":867},{},[58620],{"type":913},"Cuddlephish",{"data":58623,"marks":58624,"value":58625,"nodeType":867},{},[]," offer similar functionality using WebRTC. ",{"data":58627,"content":58628,"nodeType":876},{},[58629,58633,58638],{"data":58630,"marks":58631,"value":58632,"nodeType":867},{},[],"The advantage of this approach is that ",{"data":58634,"marks":58635,"value":58637,"nodeType":867},{},[58636],{"type":865},"it is incredibly difficult for the target websites to do anything to stop it",{"data":58639,"marks":58640,"value":58641,"nodeType":867},{},[],". From their perspective, all they see is a legitimate browser accessing their website and logging in. None of the JavaScript tricks for checking the origin will work. They aren’t in a position to be able to see that the browser is secretly being controlled remotely by the victim user without their knowledge. ",{"data":58643,"content":58644,"nodeType":876},{},[58645],{"data":58646,"marks":58647,"value":58648,"nodeType":867},{},[],"On the downside, while noVNC can be extremely convincing, the illusion can sometimes be broken due to it not behaving exactly like a real website would due it being a graphical rendering. For example, something as simple as resizing the browser window can introduce render resolution issues. It’s also more difficult to scale for attacking large numbers of users than a reverse proxy technique.",{"data":58650,"content":58651,"nodeType":876},{},[58652],{"data":58653,"marks":58654,"value":58655,"nodeType":867},{},[],"Footnote: BitM is not to be confused with Browser-in-the-Browser (BitB), which is more of a malicious pop-up (think when a login button spawns a new browser window). ",{"data":58657,"content":58658,"nodeType":868},{},[58659],{"data":58660,"marks":58661,"value":58662,"nodeType":867},{},[],"Beyond initial access",{"data":58664,"content":58665,"nodeType":876},{},[58666],{"data":58667,"marks":58668,"value":58669,"nodeType":867},{},[],"So maybe you’re thinking now “OK, sounds kinda bad, but I’m not that worried. Maybe some user accounts get compromised by this method despite all my MFA protections, but at least the attacker only has temporary access, right?” ",{"data":58671,"content":58672,"nodeType":876},{},[58673],{"data":58674,"marks":58675,"value":58676,"nodeType":867},{},[],"In theory, access is temporary as sessions time out. And if spotted, the security team can respond by killing the authenticated sessions and forcing password changes for the compromised users. Then the attacker is back to square one, right? Their session is lost, they still don’t have MFA, and even the password they keylogged has now been changed.",{"data":58678,"content":58679,"nodeType":876},{},[58680],{"data":58681,"marks":58682,"value":58683,"nodeType":867},{},[],"In practice, it’s not this simple. We mentioned earlier how SSO portals are often the most common targets for these attacks. For most modern organizations, this means their core identity provider, which just so happens to be the gateway to accessing many other web applications, whether internal applications or a multitude of SaaS applications. ",{"data":58685,"content":58686,"nodeType":876},{},[58687,58691,58700],{"data":58688,"marks":58689,"value":58690,"nodeType":867},{},[],"Let’s consider the example of an organization using Okta where their Okta login portal has been used as the target for AitM phishing. A smart attacker is going to immediately leverage this access to establish authenticated sessions on every single application that Okta provides the user access to. They are also going to ",{"data":58692,"content":58694,"nodeType":915},{"uri":58693},"https://pushsecurity.com/blog/okta-swa/",[58695],{"data":58696,"marks":58697,"value":58699,"nodeType":867},{},[58698],{"type":913},"abuse Okta SWA",{"data":58701,"marks":58702,"value":58703,"nodeType":867},{},[]," to steal valid credentials for whichever applications support this method. And if that’s not enough, there are a variety of simple methods to achieve persistence on most downstream SaaS applications and sometimes even identity providers themselves.",{"data":58705,"content":58706,"nodeType":876},{},[58707,58711,58718],{"data":58708,"marks":58709,"value":58710,"nodeType":867},{},[],"While the full details of these persistence attacks are outside the scope of this article, more details on some key attacks can be found in a resource we created called the ",{"data":58712,"content":58713,"nodeType":915},{"uri":15408},[58714],{"data":58715,"marks":58716,"value":28048,"nodeType":867},{},[58717],{"type":913},{"data":58719,"marks":58720,"value":58721,"nodeType":867},{},[],". Some of the most common techniques that apply here are: ",{"data":58723,"content":58724,"nodeType":1629},{},[58725,58745,58766,58786,58806],{"data":58726,"content":58727,"nodeType":1586},{},[58728],{"data":58729,"content":58730,"nodeType":876},{},[58731,58734,58742],{"data":58732,"marks":58733,"value":21,"nodeType":867},{},[],{"data":58735,"content":58736,"nodeType":915},{"uri":26258},[58737],{"data":58738,"marks":58739,"value":58741,"nodeType":867},{},[58740],{"type":913},"SAT1004 - API keys",{"data":58743,"marks":58744,"value":21,"nodeType":867},{},[],{"data":58746,"content":58747,"nodeType":1586},{},[58748],{"data":58749,"content":58750,"nodeType":876},{},[58751,58754,58763],{"data":58752,"marks":58753,"value":21,"nodeType":867},{},[],{"data":58755,"content":58757,"nodeType":915},{"uri":58756},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/link_sharing/description.md",[58758],{"data":58759,"marks":58760,"value":58762,"nodeType":867},{},[58761],{"type":913},"SAT1022 - Link sharing",{"data":58764,"marks":58765,"value":21,"nodeType":867},{},[],{"data":58767,"content":58768,"nodeType":1586},{},[58769],{"data":58770,"content":58771,"nodeType":876},{},[58772,58775,58783],{"data":58773,"marks":58774,"value":21,"nodeType":867},{},[],{"data":58776,"content":58777,"nodeType":915},{"uri":26236},[58778],{"data":58779,"marks":58780,"value":58782,"nodeType":867},{},[58781],{"type":913},"SAT1017 - Ghost logins",{"data":58784,"marks":58785,"value":21,"nodeType":867},{},[],{"data":58787,"content":58788,"nodeType":1586},{},[58789],{"data":58790,"content":58791,"nodeType":876},{},[58792,58795,58803],{"data":58793,"marks":58794,"value":21,"nodeType":867},{},[],{"data":58796,"content":58797,"nodeType":915},{"uri":42795},[58798],{"data":58799,"marks":58800,"value":58802,"nodeType":867},{},[58801],{"type":913},"SAT1027 - OAuth tokens",{"data":58804,"marks":58805,"value":21,"nodeType":867},{},[],{"data":58807,"content":58808,"nodeType":1586},{},[58809],{"data":58810,"content":58811,"nodeType":876},{},[58812,58815,58823],{"data":58813,"marks":58814,"value":21,"nodeType":867},{},[],{"data":58816,"content":58817,"nodeType":915},{"uri":42265},[58818],{"data":58819,"marks":58820,"value":58822,"nodeType":867},{},[58821],{"type":913},"SAT1033 - Shadow workflows",{"data":58824,"marks":58825,"value":21,"nodeType":867},{},[],{"data":58827,"content":58828,"nodeType":876},{},[58829],{"data":58830,"marks":58831,"value":58832,"nodeType":867},{},[],"Suddenly, containing the breach just got a LOT more complicated.",{"data":58834,"content":58835,"nodeType":876},{},[58836,58840,58847],{"data":58837,"marks":58838,"value":58839,"nodeType":867},{},[],"It’s not just application-level lateral movement and persistence to worry about, though. It’s possible the attacker can start moving laterally across other user accounts. If they have selected their targets well, they might even find they have admin access to some downstream SaaS application that has been configured for SAML logins using Okta. For example, maybe they compromise a finance employee who has admin access to their business expenses SaaS application. Then the attacker might be able to use a new technique like ",{"data":58841,"content":58842,"nodeType":915},{"uri":22216},[58843],{"data":58844,"marks":58845,"value":22222,"nodeType":867},{},[58846],{"type":913},{"data":58848,"marks":58849,"value":58850,"nodeType":867},{},[]," to start attacking other users in a watering hole attack to achieve lateral movement.",{"data":58852,"content":58853,"nodeType":868},{},[58854],{"data":58855,"marks":58856,"value":58857,"nodeType":867},{},[],"Video demo – chaining it all together",{"data":58859,"content":58860,"nodeType":876},{},[58861],{"data":58862,"marks":58863,"value":58864,"nodeType":867},{},[],"OK, so we’ve just jumped from an account compromise for initial access using an AitM phishing attack to bringing up a huge number of other connected techniques. Let’s look at a quick video demonstration of an AitM phishing attack chained together with post-exploitation steps for persistence and lateral movement so we can see how it all fits together.",{"data":58866,"content":58867,"nodeType":876},{},[58868],{"data":58869,"marks":58870,"value":58871,"nodeType":867},{},[],"In this case, we’ll use EvilnoVNC targeting Okta as the core example for the AitM phishing attack:",{"data":58873,"content":58877,"nodeType":985},{"target":58874},{"sys":58875},{"id":58876,"type":982,"linkType":983},"QGTEWzmOL1vrgjXPuV4Gg",[],{"data":58879,"content":58880,"nodeType":876},{},[58881],{"data":58882,"marks":58883,"value":58884,"nodeType":867},{},[],"We can see here that AitM phishing attacks are not only highly effective even in the presence of MFA, but that post-exploitation steps have become so numerous that effective response and containment for even a low-privileged user account are now a significant challenge.",{"data":58886,"content":58887,"nodeType":868},{},[58888],{"data":58889,"marks":58890,"value":58891,"nodeType":867},{},[],"Post-exploitation automation is coming",{"data":58893,"content":58894,"nodeType":876},{},[58895],{"data":58896,"marks":58897,"value":58898,"nodeType":867},{},[],"There is a saying that attacks only become more effective over time. In the past, toolsets like Metasploit and Cobalt Strike became increasingly focused on post-exploitation and automation to enable much more sophisticated compromises.",{"data":58900,"content":58901,"nodeType":876},{},[58902,58906,58918,58922,58927],{"data":58903,"marks":58904,"value":58905,"nodeType":867},{},[],"As AitM becomes increasingly popular (for example, researchers at Lab539 have reported ",{"data":58907,"content":58908,"nodeType":915},{"uri":38506},[58909,58914],{"data":58910,"marks":58911,"value":58913,"nodeType":867},{},[58912],{"type":913},"a significant ramp up in attacker infrastructure linked to AitM campaigns",{"data":58915,"marks":58916,"value":58917,"nodeType":867},{},[],")",{"data":58919,"marks":58920,"value":58921,"nodeType":867},{},[]," it’s only a matter of time now before we see AitM phishing frameworks moving in the same direction and performing many of the lateral movement and persistence steps we saw above – automatically on every successful account compromise. The threat will increase ",{"data":58923,"marks":58924,"value":58926,"nodeType":867},{},[58925],{"type":865},"significantly",{"data":58928,"marks":58929,"value":58930,"nodeType":867},{},[]," when this becomes the case.",{"data":58932,"content":58933,"nodeType":868},{},[58934],{"data":58935,"marks":58936,"value":58937,"nodeType":867},{},[],"Impact summary",{"data":58939,"content":58940,"nodeType":876},{},[58941],{"data":58942,"marks":58943,"value":58944,"nodeType":867},{},[],"We’ve covered a lot of ground here, so let’s take a step back and consider the key points of impact:",{"data":58946,"content":58947,"nodeType":1629},{},[58948,58958,58968],{"data":58949,"content":58950,"nodeType":1586},{},[58951],{"data":58952,"content":58953,"nodeType":876},{},[58954],{"data":58955,"marks":58956,"value":58957,"nodeType":867},{},[],"AitM phishing techniques are highly effective and increasingly common, and can bypass most common forms of MFA.",{"data":58959,"content":58960,"nodeType":1586},{},[58961],{"data":58962,"content":58963,"nodeType":876},{},[58964],{"data":58965,"marks":58966,"value":58967,"nodeType":867},{},[],"These techniques are being used by real threat actors and red teamers alike, with both criminal and open-source tools available for performing these attacks.",{"data":58969,"content":58970,"nodeType":1586},{},[58971],{"data":58972,"content":58973,"nodeType":876},{},[58974],{"data":58975,"marks":58976,"value":58977,"nodeType":867},{},[],"There are many options for lateral movement and persistence after an account compromise, so simple containment actions like password resets for SSO credentials are not nearly enough to contain a knowledgeable attacker.",{"data":58979,"content":58980,"nodeType":868},{},[58981],{"data":58982,"marks":58983,"value":58984,"nodeType":867},{},[],"What can blue teams do about it?",{"data":58986,"content":58987,"nodeType":876},{},[58988],{"data":58989,"marks":58990,"value":58991,"nodeType":867},{},[],"It’s important that organizations develop their capability to detect and respond to AitM attacks. Possible approaches include:",{"data":58993,"content":58994,"nodeType":1629},{},[58995,59010,59045,59073],{"data":58996,"content":58997,"nodeType":1586},{},[58998],{"data":58999,"content":59000,"nodeType":876},{},[59001,59006],{"data":59002,"marks":59003,"value":59005,"nodeType":867},{},[59004],{"type":865},"Move to FIDO MFA where possible",{"data":59007,"marks":59008,"value":59009,"nodeType":867},{},[]," (though, if no more susceptible backup methods are enabled, this does introduce operational challenges if passkeys are lost).",{"data":59011,"content":59012,"nodeType":1586},{},[59013],{"data":59014,"content":59015,"nodeType":876},{},[59016,59021,59024,59029,59033,59042],{"data":59017,"marks":59018,"value":59020,"nodeType":867},{},[59019],{"type":865},"Detect and block known-bad malicious",{"data":59022,"marks":59023,"value":2136,"nodeType":867},{},[],{"data":59025,"marks":59026,"value":59028,"nodeType":867},{},[59027],{"type":865},"sites",{"data":59030,"marks":59031,"value":59032,"nodeType":867},{},[]," used in phishing campaigns. There are many threat intelligence feeds that can be ingested to achieve this. Usually, a domain has to be used in a malicious campaign before it can be catalogued – meaning there's typically a window of opportunity before the infrastructure is burned. That said, security researchers at Lab539 (yes, another shout out) have developed a way of identifying sites running AitM tooling – even before they are used for the first time. ",{"data":59034,"content":59036,"nodeType":915},{"uri":59035},"https://www.lab539.com/aitm",[59037],{"data":59038,"marks":59039,"value":59041,"nodeType":867},{},[59040],{"type":913},"You can sign up to get access to their feed here.",{"data":59043,"marks":59044,"value":21,"nodeType":867},{},[],{"data":59046,"content":59047,"nodeType":1586},{},[59048],{"data":59049,"content":59050,"nodeType":876},{},[59051,59056,59060,59069],{"data":59052,"marks":59053,"value":59055,"nodeType":867},{},[59054],{"type":865},"Introduce controls to detect phishing toolkits and cloned websites",{"data":59057,"marks":59058,"value":59059,"nodeType":867},{},[],". You can never rely on blocking malicious sites via TI feeds alone, so additional layers of defence are required. Push customers benefit from detection of AitM toolkits like Evilginx and EvilNoVNC in the browser (more to come on this soon!), while Thinkst Canary has developed ",{"data":59061,"content":59063,"nodeType":915},{"uri":59062},"https://blog.thinkst.com/2024/01/defending-against-the-attack-of-the-cloned-websites.html",[59064],{"data":59065,"marks":59066,"value":59068,"nodeType":867},{},[59067],{"type":913},"methods of detecting whenever your website or login portal is cloned",{"data":59070,"marks":59071,"value":59072,"nodeType":867},{},[]," – very cool.  ",{"data":59074,"content":59075,"nodeType":1586},{},[59076],{"data":59077,"content":59078,"nodeType":876},{},[59079,59084],{"data":59080,"marks":59081,"value":59083,"nodeType":867},{},[59082],{"type":865},"Update IR playbooks to to deal with SSO account compromise,",{"data":59085,"marks":59086,"value":59087,"nodeType":867},{},[]," factoring in lateral movement and persistence across cloud apps. This really necessitates that you understand what business apps your organization is using, how they are accessed (e.g. SSO or username and password) and what functionality exists that could be abused by an attacker. ",{"data":59089,"content":59090,"nodeType":876},{},[59091,59095,59102],{"data":59092,"marks":59093,"value":59094,"nodeType":867},{},[],"If you want to know more about how Push detects and blocks phishing tools in the browser, you can ",{"data":59096,"content":59097,"nodeType":915},{"uri":40019},[59098],{"data":59099,"marks":59100,"value":59101,"nodeType":867},{},[],"check out our article here",{"data":59103,"marks":59104,"value":2933,"nodeType":867},{},[],{"data":59106,"content":59107,"nodeType":868},{},[59108],{"data":59109,"marks":59110,"value":23563,"nodeType":867},{},[],{"data":59112,"content":59113,"nodeType":876},{},[59114],{"data":59115,"marks":59116,"value":59117,"nodeType":867},{},[],"We’ve seen in this article how there are multiple ways to perform AitM phishing attacks and how they can be extremely effective at targeting users even when their accounts are protected by MFA.  ",{"data":59119,"content":59120,"nodeType":876},{},[59121],{"data":59122,"marks":59123,"value":59124,"nodeType":867},{},[],"Very few organizations are universally using phishing-resistant MFA, such as FIDO-based methods, and even those that do often have fallback options to handle situations where they cannot be used and/or tokens malfunction or are lost. Therefore, the vast majority of organizations are at risk of AitM phishing attacks.",{"data":59126,"content":59127,"nodeType":876},{},[59128],{"data":59129,"marks":59130,"value":59131,"nodeType":867},{},[],"To make things worse, there are lateral movement and persistence techniques that can be exploited to greatly extend the depth of compromise even for a single low-privilege user account. This makes response and containment a significant challenge.",{"data":59133,"content":59134,"nodeType":876},{},[59135,59139,59146,59149,59157,59161,59169,59173,59182],{"data":59136,"marks":59137,"value":59138,"nodeType":867},{},[],"Phishing attacks are clearly evolving. Phishing attacks are no longer limited to email-based delivery mechanisms or being hosted on custom domains. There are many options now for delivering phishing attacks using ",{"data":59140,"content":59141,"nodeType":915},{"uri":51397},[59142],{"data":59143,"marks":59144,"value":51403,"nodeType":867},{},[59145],{"type":913},{"data":59147,"marks":59148,"value":21631,"nodeType":867},{},[],{"data":59150,"content":59151,"nodeType":915},{"uri":51409},[59152],{"data":59153,"marks":59154,"value":59156,"nodeType":867},{},[59155],{"type":913},"Microsoft Teams",{"data":59158,"marks":59159,"value":59160,"nodeType":867},{},[],", using ",{"data":59162,"content":59163,"nodeType":915},{"uri":5013},[59164],{"data":59165,"marks":59166,"value":59168,"nodeType":867},{},[59167],{"type":913},"SAMLjacking attacks",{"data":59170,"marks":59171,"value":59172,"nodeType":867},{},[]," to host the initial landing page on legitimate SaaS web domains or even using ",{"data":59174,"content":59176,"nodeType":915},{"uri":59175},"https://pushsecurity.com/blog/oktajacking/",[59177],{"data":59178,"marks":59179,"value":59181,"nodeType":867},{},[59180],{"type":913},"Okta to keylog credentials",{"data":59183,"marks":59184,"value":59185,"nodeType":867},{},[]," on behalf of the attacker. ",{"data":59187,"content":59188,"nodeType":876},{},[59189],{"data":59190,"marks":59191,"value":59192,"nodeType":867},{},[],"Increasingly, we should expect to see AitM toolkits being used as a standard part of phishing campaigns, and featured in Initial Access Broker tooling – AitM will effectively supersede legacy phishing methods in line with MFA adoption. Rather, it already is. ",{"data":59194,"content":59195,"nodeType":942},{},[],{"data":59197,"content":59198,"nodeType":876},{},[59199],{"data":59200,"marks":59201,"value":59202,"nodeType":867},{},[],"If you're interested in seeing some more AitM tools in action, you can watch our recent webinar on-demand via the link below. ",{"data":59204,"content":59207,"nodeType":985},{"target":59205},{"sys":59206},{"id":58467,"type":982,"linkType":983},[],{"data":59209,"content":59210,"nodeType":876},{},[59211],{"data":59212,"marks":59213,"value":21,"nodeType":867},{},[],"Attackers are using Adversary in the Middle (AitM) phishing toolkits to bypass MFA. We look at what AitM is, how it works, and what you can do about it.","2024-05-23T00:00:00.000Z",{"items":59217},[59218,59220],{"sys":59219,"name":4018},{"id":4017},{"sys":59221,"name":342},{"id":3240},{"items":59223},[59224],{"fullName":14739,"firstName":14740,"jobTitle":14741,"profilePicture":59225},{"url":14743},{"__typename":1772,"sys":59227,"content":59229,"title":59652,"synopsis":59653,"hashTags":59,"publishedDate":59654,"slug":59655,"tagsCollection":59656,"authorsCollection":59660},{"id":59228},"liumWpzvwXGmwbtKrvJdO",{"json":59230},{"data":59231,"content":59232,"nodeType":1680},{},[59233,59240,59299,59306,59322,59336,59343,59349,59367,59374,59390,59397,59403,59420,59427,59452,59467,59484,59491,59506,59522,59528,59545,59552,59577,59583,59600,59607,59637],{"data":59234,"content":59235,"nodeType":1058},{},[59236],{"data":59237,"marks":59238,"value":59239,"nodeType":867},{},[],"What’s new this month:",{"data":59241,"content":59242,"nodeType":1629},{},[59243,59252,59261,59270,59279,59289],{"data":59244,"content":59245,"nodeType":1586},{},[59246],{"data":59247,"content":59248,"nodeType":876},{},[59249],{"data":59250,"marks":59251,"value":38777,"nodeType":867},{},[],{"data":59253,"content":59254,"nodeType":1586},{},[59255],{"data":59256,"content":59257,"nodeType":876},{},[59258],{"data":59259,"marks":59260,"value":38697,"nodeType":867},{},[],{"data":59262,"content":59263,"nodeType":1586},{},[59264],{"data":59265,"content":59266,"nodeType":876},{},[59267],{"data":59268,"marks":59269,"value":38912,"nodeType":867},{},[],{"data":59271,"content":59272,"nodeType":1586},{},[59273],{"data":59274,"content":59275,"nodeType":876},{},[59276],{"data":59277,"marks":59278,"value":38860,"nodeType":867},{},[],{"data":59280,"content":59281,"nodeType":1586},{},[59282],{"data":59283,"content":59284,"nodeType":876},{},[59285],{"data":59286,"marks":59287,"value":59288,"nodeType":867},{},[],"Require a reason for app usage",{"data":59290,"content":59291,"nodeType":1586},{},[59292],{"data":59293,"content":59294,"nodeType":876},{},[59295],{"data":59296,"marks":59297,"value":59298,"nodeType":867},{},[],"Expanded API and webhooks options",{"data":59300,"content":59301,"nodeType":1058},{},[59302],{"data":59303,"marks":59304,"value":59305,"nodeType":867},{},[],"Prevent SSO password reuse",{"data":59307,"content":59308,"nodeType":876},{},[59309,59313,59318],{"data":59310,"marks":59311,"value":59312,"nodeType":867},{},[],"Instead of trying to detect phishing websites and domains that constantly change, Push can now ",{"data":59314,"marks":59315,"value":59317,"nodeType":867},{},[59316],{"type":865},"detect (and block!) SSO password reuse",{"data":59319,"marks":59320,"value":59321,"nodeType":867},{},[]," based on directly observing user behavior in the browser.",{"data":59323,"content":59324,"nodeType":876},{},[59325,59328,59332],{"data":59326,"marks":59327,"value":25505,"nodeType":867},{},[],{"data":59329,"marks":59330,"value":38777,"nodeType":867},{},[59331],{"type":865},{"data":59333,"marks":59334,"value":59335,"nodeType":867},{},[]," feature detects and blocks when a user enters their identity provider password on a webpage that does not belong to the IdP (e.g. Okta, Google Workspace, Microsoft 365, etc.)",{"data":59337,"content":59338,"nodeType":876},{},[59339],{"data":59340,"marks":59341,"value":59342,"nodeType":867},{},[],"You can choose to warn or block SSO password reuse and customize the message that end-users see.",{"data":59344,"content":59348,"nodeType":985},{"target":59345},{"sys":59346},{"id":59347,"type":982,"linkType":983},"74l82HIeaumFX4u9AMjj79",[],{"data":59350,"content":59351,"nodeType":876},{},[59352,59355,59364],{"data":59353,"marks":59354,"value":21,"nodeType":867},{},[],{"data":59356,"content":59359,"nodeType":17452},{"target":59357},{"sys":59358},{"id":45146,"type":982,"linkType":983},[59360],{"data":59361,"marks":59362,"value":59363,"nodeType":867},{},[],"See how it works",{"data":59365,"marks":59366,"value":21,"nodeType":867},{},[],{"data":59368,"content":59369,"nodeType":1058},{},[59370],{"data":59371,"marks":59372,"value":59373,"nodeType":867},{},[],"Detect Adversary-in-the-Middle phishing toolkits",{"data":59375,"content":59376,"nodeType":876},{},[59377,59381,59386],{"data":59378,"marks":59379,"value":59380,"nodeType":867},{},[],"The Push browser agent can now ",{"data":59382,"marks":59383,"value":59385,"nodeType":867},{},[59384],{"type":865},"detect when employees visit websites that are using phishing toolkits",{"data":59387,"marks":59388,"value":59389,"nodeType":867},{},[]," such as EvilNoVNC and Evilginx. These tools can mimic legitimate login screens in order to steal credentials and bypass MFA.",{"data":59391,"content":59392,"nodeType":876},{},[59393],{"data":59394,"marks":59395,"value":59396,"nodeType":867},{},[],"Send detections to your SIEM or similar monitoring tool and add malicious sites to a blocklist in Push.",{"data":59398,"content":59402,"nodeType":985},{"target":59399},{"sys":59400},{"id":59401,"type":982,"linkType":983},"450I6V31ET3EbfgMiVBPBR",[],{"data":59404,"content":59405,"nodeType":876},{},[59406,59409,59417],{"data":59407,"marks":59408,"value":21,"nodeType":867},{},[],{"data":59410,"content":59413,"nodeType":17452},{"target":59411},{"sys":59412},{"id":38762,"type":982,"linkType":983},[59414],{"data":59415,"marks":59416,"value":18329,"nodeType":867},{},[],{"data":59418,"marks":59419,"value":21,"nodeType":867},{},[],{"data":59421,"content":59422,"nodeType":1058},{},[59423],{"data":59424,"marks":59425,"value":59426,"nodeType":867},{},[],"Identify session token theft ",{"data":59428,"content":59429,"nodeType":876},{},[59430,59434,59439,59443,59448],{"data":59431,"marks":59432,"value":59433,"nodeType":867},{},[],"You can now use the Push browser agent to ",{"data":59435,"marks":59436,"value":59438,"nodeType":867},{},[59437],{"type":865},"inject a unique marker to the user agent string",{"data":59440,"marks":59441,"value":59442,"nodeType":867},{},[]," of sessions that occur in browsers enrolled in Push. By analyzing logs from your identity provider (e.g. Okta, Microsoft 365, etc.) or other app, you can use the marker to help you ",{"data":59444,"marks":59445,"value":59447,"nodeType":867},{},[59446],{"type":865},"find suspicious activity that indicates a stolen session cookie",{"data":59449,"marks":59450,"value":59451,"nodeType":867},{},[]," in use.",{"data":59453,"content":59454,"nodeType":876},{},[59455,59459,59464],{"data":59456,"marks":59457,"value":59458,"nodeType":867},{},[],"Detecting session hijacking is extremely difficult when relying on device-based monitoring using EDR and network traffic. But by giving legitimate sessions a stamp of approval using the Push browser agent, you can easily ",{"data":59460,"marks":59461,"value":59463,"nodeType":867},{},[59462],{"type":865},"identify access to apps from untrusted devices",{"data":59465,"marks":59466,"value":1679,"nodeType":867},{},[],{"data":59468,"content":59469,"nodeType":876},{},[59470,59473,59481],{"data":59471,"marks":59472,"value":21,"nodeType":867},{},[],{"data":59474,"content":59477,"nodeType":17452},{"target":59475},{"sys":59476},{"id":38950,"type":982,"linkType":983},[59478],{"data":59479,"marks":59480,"value":59363,"nodeType":867},{},[],{"data":59482,"marks":59483,"value":21,"nodeType":867},{},[],{"data":59485,"content":59486,"nodeType":1058},{},[59487],{"data":59488,"marks":59489,"value":59490,"nodeType":867},{},[],"Configure a custom blocklist of URLs",{"data":59492,"content":59493,"nodeType":876},{},[59494,59498,59502],{"data":59495,"marks":59496,"value":59497,"nodeType":867},{},[],"Prevent employees from visiting malicious sites you detect by configuring a custom blocklist of URLs in Push using the ",{"data":59499,"marks":59500,"value":38860,"nodeType":867},{},[59501],{"type":865},{"data":59503,"marks":59504,"value":59505,"nodeType":867},{},[]," feature. You can customize the message shown to end-users by adding your own links and instructions. Use Push’s REST API to programmatically manage URL blocking as part of responding to a phishing incident.",{"data":59507,"content":59508,"nodeType":876},{},[59509,59513,59518],{"data":59510,"marks":59511,"value":59512,"nodeType":867},{},[],"You can use this alongside other Push features like phishing tool detection to ",{"data":59514,"marks":59515,"value":59517,"nodeType":867},{},[59516],{"type":865},"block access to known-bad sites",{"data":59519,"marks":59520,"value":59521,"nodeType":867},{},[]," you find. ",{"data":59523,"content":59527,"nodeType":985},{"target":59524},{"sys":59525},{"id":59526,"type":982,"linkType":983},"1S7cuS7qo5jTcEg7RPPZu6",[],{"data":59529,"content":59530,"nodeType":876},{},[59531,59534,59542],{"data":59532,"marks":59533,"value":21,"nodeType":867},{},[],{"data":59535,"content":59538,"nodeType":17452},{"target":59536},{"sys":59537},{"id":38898,"type":982,"linkType":983},[59539],{"data":59540,"marks":59541,"value":18329,"nodeType":867},{},[],{"data":59543,"marks":59544,"value":21,"nodeType":867},{},[],{"data":59546,"content":59547,"nodeType":1058},{},[59548],{"data":59549,"marks":59550,"value":59551,"nodeType":867},{},[],"Require end-users to submit a reason when using an app",{"data":59553,"content":59554,"nodeType":876},{},[59555,59559,59564,59568,59573],{"data":59556,"marks":59557,"value":59558,"nodeType":867},{},[],"We’ve expanded our popular app banners feature to include a ",{"data":59560,"marks":59561,"value":59563,"nodeType":867},{},[59562],{"type":865},"Reason",{"data":59565,"marks":59566,"value":59567,"nodeType":867},{},[]," mode that allows you to configure a custom message and require employees to submit a reason ",{"data":59569,"marks":59570,"value":59572,"nodeType":867},{},[59571],{"type":865},"why they need to use a specific app",{"data":59574,"marks":59575,"value":59576,"nodeType":867},{},[]," before they can proceed to log in.",{"data":59578,"content":59582,"nodeType":985},{"target":59579},{"sys":59580},{"id":59581,"type":982,"linkType":983},"6Q7kU16LZdTm8RsyLy660J",[],{"data":59584,"content":59585,"nodeType":876},{},[59586,59589,59597],{"data":59587,"marks":59588,"value":21,"nodeType":867},{},[],{"data":59590,"content":59593,"nodeType":17452},{"target":59591},{"sys":59592},{"id":38989,"type":982,"linkType":983},[59594],{"data":59595,"marks":59596,"value":18329,"nodeType":867},{},[],{"data":59598,"marks":59599,"value":21,"nodeType":867},{},[],{"data":59601,"content":59602,"nodeType":1058},{},[59603],{"data":59604,"marks":59605,"value":59606,"nodeType":867},{},[],"Monitor ‘other apps’ list via Push API and webhooks",{"data":59608,"content":59609,"nodeType":876},{},[59610,59614,59619,59623,59633],{"data":59611,"marks":59612,"value":59613,"nodeType":867},{},[],"You can now keep a closer eye on ",{"data":59615,"marks":59616,"value":59618,"nodeType":867},{},[59617],{"type":865},"all new observed cloud apps",{"data":59620,"marks":59621,"value":59622,"nodeType":867},{},[]," by using the Push API and webhooks to notify you of new entries on the ",{"data":59624,"content":59628,"nodeType":17452},{"target":59625},{"sys":59626},{"id":59627,"type":982,"linkType":983},"WciLKam7PCkbAASOdfiEw",[59629],{"data":59630,"marks":59631,"value":59632,"nodeType":867},{},[],"“other apps” list",{"data":59634,"marks":59635,"value":59636,"nodeType":867},{},[]," or to retrieve specific details about accounts on these apps. The “other apps” list consists of apps accessed by employees that Push doesn’t recognize as work apps but that may still be relevant to your operations. ",{"data":59638,"content":59639,"nodeType":876},{},[59640,59643,59649],{"data":59641,"marks":59642,"value":21,"nodeType":867},{},[],{"data":59644,"content":59645,"nodeType":915},{"uri":38608},[59646],{"data":59647,"marks":59648,"value":18329,"nodeType":867},{},[],{"data":59650,"marks":59651,"value":17328,"nodeType":867},{},[],"Product release: May 2024","Here’s what’s new on the Push platform for May 2024.","2024-05-22T00:00:00.000Z","product-release-may-2024",{"items":59657},[59658],{"sys":59659,"name":39245},{"id":39244},{"items":59661},[59662],{"fullName":59663,"firstName":59664,"jobTitle":59665,"profilePicture":59666},"Andy Waugh","Andy","VP Product",{"url":59667},"https://images.ctfassets.net/y1cdw1ablpvd/3Rf76rJn6S9inMb4dUnAIJ/0a787f8141d05b95300e2fe77c4493fa/DSC_6868.jpg",{"__typename":1772,"sys":59669,"content":59670,"title":58349,"synopsis":60196,"hashTags":59,"publishedDate":60197,"slug":58350,"tagsCollection":60198,"authorsCollection":60204},{"id":45146},{"json":59671},{"data":59672,"content":59673,"nodeType":1680},{},[59674,59680,59686,59693,59700,59715,59748,59755,59763,59768,59783,59791,59797,59804,59811,59818,59825,59833,59840,59855,59871,59876,59883,59901,59919,59926,59949,59956,59979,59995,60002,60021,60028,60101,60108,60124,60131,60138,60145,60152,60168,60174,60180],{"data":59675,"content":59676,"nodeType":876},{},[59677],{"data":59678,"marks":59679,"value":21,"nodeType":867},{},[],{"data":59681,"content":59685,"nodeType":985},{"target":59682},{"sys":59683},{"id":59684,"type":982,"linkType":983},"5cseu1Cre2FrSQrIhSFxQw",[],{"data":59687,"content":59688,"nodeType":876},{},[59689],{"data":59690,"marks":59691,"value":59692,"nodeType":867},{},[],"Reliably detecting phishing sites is like trying to hit a moving target, as malicious websites and domains emerge, get taken down, and re-emerge continuously across the sprawl of the web.",{"data":59694,"content":59695,"nodeType":876},{},[59696],{"data":59697,"marks":59698,"value":59699,"nodeType":867},{},[],"Existing phishing prevention solutions have tried to solve the problem by protecting the inbox, a common (but not the only) attack vector, or by chasing lists of known-bad domains.",{"data":59701,"content":59702,"nodeType":876},{},[59703,59707,59712],{"data":59704,"marks":59705,"value":59706,"nodeType":867},{},[],"But these approaches have ",{"data":59708,"marks":59709,"value":59711,"nodeType":867},{},[59710],{"type":865},"two major shortcomings",{"data":59713,"marks":59714,"value":40619,"nodeType":867},{},[],{"data":59716,"content":59717,"nodeType":1629},{},[59718,59733],{"data":59719,"content":59720,"nodeType":1586},{},[59721],{"data":59722,"content":59723,"nodeType":876},{},[59724,59729],{"data":59725,"marks":59726,"value":59728,"nodeType":867},{},[59727],{"type":865},"Lack of coverage:",{"data":59730,"marks":59731,"value":59732,"nodeType":867},{},[]," Email-based phishing prevention tools can catch general spray-and-pray email phishing campaigns, but it only takes a small amount of tailoring to fly under their radar. The use of LLM tools to tailor phishing emails for their intended victims already makes this possible at scale. Email-based tools also fail to cover phishing attacks beyond the inbox, such as Slack and Teams phishing.",{"data":59734,"content":59735,"nodeType":1586},{},[59736],{"data":59737,"content":59738,"nodeType":876},{},[59739,59744],{"data":59740,"marks":59741,"value":59743,"nodeType":867},{},[59742],{"type":865},"Expired intel:",{"data":59745,"marks":59746,"value":59747,"nodeType":867},{},[]," Tools that rely on known-bad domains always have an incomplete picture because a domain must be reported as malicious in order to get added to a blocklist. Meanwhile, attackers can spin up new sites or host phishing pages on existing sites by exploiting vulnerabilities in them, bypassing rules around preventing visits to newly registered domains. ",{"data":59749,"content":59750,"nodeType":876},{},[59751],{"data":59752,"marks":59753,"value":59754,"nodeType":867},{},[],"Using Push’s unique vantage point in the browser, we set out to attack this problem from a new angle. ",{"data":59756,"content":59757,"nodeType":876},{},[59758],{"data":59759,"marks":59760,"value":59762,"nodeType":867},{},[59761],{"type":865},"Instead of trying to detect phishing websites and domains that constantly change, we can now detect (and block!) phishing attempts based on directly observing user behavior in the browser.",{"data":59764,"content":59767,"nodeType":985},{"target":59765},{"sys":59766},{"id":57018,"type":982,"linkType":983},[],{"data":59769,"content":59770,"nodeType":876},{},[59771,59775,59779],{"data":59772,"marks":59773,"value":59774,"nodeType":867},{},[],"Our latest feature, ",{"data":59776,"marks":59777,"value":38777,"nodeType":867},{},[59778],{"type":865},{"data":59780,"marks":59781,"value":59782,"nodeType":867},{},[],", detects and blocks when a user enters their identity provider password on a webpage that does not belong to the IdP (e.g Okta, Google Workspace, Microsoft 365, etc.).",{"data":59784,"content":59785,"nodeType":876},{},[59786],{"data":59787,"marks":59788,"value":59790,"nodeType":867},{},[59789],{"type":865},"This means that even if that employee was the first person to get phished using a new attacker site, Push still detects it and blocks it.",{"data":59792,"content":59796,"nodeType":985},{"target":59793},{"sys":59794},{"id":59795,"type":982,"linkType":983},"4eCSQGec7mozFLDucNMO7m",[],{"data":59798,"content":59799,"nodeType":1058},{},[59800],{"data":59801,"marks":59802,"value":59803,"nodeType":867},{},[],"How does it work?",{"data":59805,"content":59806,"nodeType":876},{},[59807],{"data":59808,"marks":59809,"value":59810,"nodeType":867},{},[],"Instead of detecting a phishing page based on a known-bad signature, the Push browser agent dynamically inspects user behavior and the attributes of the page itself.",{"data":59812,"content":59813,"nodeType":876},{},[59814],{"data":59815,"marks":59816,"value":59817,"nodeType":867},{},[],"The browser agent works by observing all logins and generating a salted partial hash of the user’s password, known as a fingerprint. This fingerprint is then stored locally to allow Push to perform comparisons. ",{"data":59819,"content":59820,"nodeType":876},{},[59821],{"data":59822,"marks":59823,"value":59824,"nodeType":867},{},[],"To detect potential phishing attacks, the browser agent compares the observed password fingerprint to known fingerprints for identity provider passwords that already exist in local storage. ",{"data":59826,"content":59827,"nodeType":876},{},[59828],{"data":59829,"marks":59830,"value":59832,"nodeType":867},{},[59831],{"type":865},"If an employee enters a known IdP password on a webpage that Push doesn’t recognize, Push blocks it. ",{"data":59834,"content":59835,"nodeType":876},{},[59836],{"data":59837,"marks":59838,"value":59839,"nodeType":867},{},[],"Once you’ve discovered a malicious site, use Push’s companion feature, URL blocking, to add the domain to a blocklist and prevent your other end-users from visiting the site. ",{"data":59841,"content":59842,"nodeType":876},{},[59843,59846,59852],{"data":59844,"marks":59845,"value":41181,"nodeType":867},{},[],{"data":59847,"content":59848,"nodeType":915},{"uri":38608},[59849],{"data":59850,"marks":59851,"value":41188,"nodeType":867},{},[],{"data":59853,"marks":59854,"value":41192,"nodeType":867},{},[],{"data":59856,"content":59857,"nodeType":876},{},[59858,59862,59867],{"data":59859,"marks":59860,"value":59861,"nodeType":867},{},[],"Push administrators can configure SSO password protection in Monitor, Warn, or Block modes to first observe how often employees are re-using IdP credentials on other sites, eliminating any false positives by adding them to an ignore list, and then turning on Warn or Block to ",{"data":59863,"marks":59864,"value":59866,"nodeType":867},{},[59865],{"type":865},"show a custom message",{"data":59868,"marks":59869,"value":59870,"nodeType":867},{},[]," that either provides a speedbump for users (“Are you sure this isn’t a phishing site?”) or prevents them from logging in altogether.",{"data":59872,"content":59875,"nodeType":985},{"target":59873},{"sys":59874},{"id":59347,"type":982,"linkType":983},[],{"data":59877,"content":59878,"nodeType":876},{},[59879],{"data":59880,"marks":59881,"value":59882,"nodeType":867},{},[],"Supported identity providers include Okta, Microsoft 365, Google Workspace, JumpCloud, Duo and Ping Identity. ",{"data":59884,"content":59885,"nodeType":876},{},[59886,59890,59897],{"data":59887,"marks":59888,"value":59889,"nodeType":867},{},[],"You can also ",{"data":59891,"content":59892,"nodeType":915},{"uri":38619},[59893],{"data":59894,"marks":59895,"value":59896,"nodeType":867},{},[],"get alerted",{"data":59898,"marks":59899,"value":59900,"nodeType":867},{},[]," via webhook when Push detects a suspected phishing event.",{"data":59902,"content":59903,"nodeType":876},{},[59904,59908,59916],{"data":59905,"marks":59906,"value":59907,"nodeType":867},{},[],"Learn more about how it works and the end-user experience in our ",{"data":59909,"content":59912,"nodeType":17452},{"target":59910},{"sys":59911},{"id":38846,"type":982,"linkType":983},[59913],{"data":59914,"marks":59915,"value":22855,"nodeType":867},{},[],{"data":59917,"marks":59918,"value":1679,"nodeType":867},{},[],{"data":59920,"content":59921,"nodeType":1058},{},[59922],{"data":59923,"marks":59924,"value":59925,"nodeType":867},{},[],"But what about … ",{"data":59927,"content":59928,"nodeType":876},{},[59929,59933,59937,59940,59945],{"data":59930,"marks":59931,"value":59932,"nodeType":867},{},[],"Yes, we believe ",{"data":59934,"marks":59935,"value":457,"nodeType":867},{},[59936],{"type":865},{"data":59938,"marks":59939,"value":1174,"nodeType":867},{},[],{"data":59941,"marks":59942,"value":59944,"nodeType":867},{},[59943],{"type":865},"conditional access policies",{"data":59946,"marks":59947,"value":59948,"nodeType":867},{},[]," are important parts of a defense-in-depth strategy against phishing — in addition to protecting IdP credentials directly in the browser.",{"data":59950,"content":59951,"nodeType":876},{},[59952],{"data":59953,"marks":59954,"value":59955,"nodeType":867},{},[],"Here’s why MFA and conditional access policies aren’t enough:",{"data":59957,"content":59958,"nodeType":1629},{},[59959,59969],{"data":59960,"content":59961,"nodeType":1586},{},[59962],{"data":59963,"content":59964,"nodeType":876},{},[59965],{"data":59966,"marks":59967,"value":59968,"nodeType":867},{},[],"MFA is not infallible and not all MFA methods are created equal. Methods such as SMS, TOTP, or even push notifications are phishable. Even if your employees are also using more phishing-resistant forms of MFA, such as WebAuthn, it’s common for accounts to use multiple MFA methods and an attacker need only target the weakest one. An attacker in possession of an SSO password also has leverage to socially engineer an authentication reset, including an MFA reset.",{"data":59970,"content":59971,"nodeType":1586},{},[59972],{"data":59973,"content":59974,"nodeType":876},{},[59975],{"data":59976,"marks":59977,"value":59978,"nodeType":867},{},[],"It’s worryingly common for us to deploy Push and find that a customer’s conditional access policies aren’t implemented as they are designed to be. The most common reason is that admins have to create so many exceptions to allow for real-world situations that policies become complex and full of gaps.",{"data":59980,"content":59981,"nodeType":876},{},[59982,59986,59991],{"data":59983,"marks":59984,"value":59985,"nodeType":867},{},[],"And of course, protecting ",{"data":59987,"marks":59988,"value":59990,"nodeType":867},{},[59989],{"type":1303},"all",{"data":59992,"marks":59993,"value":59994,"nodeType":867},{},[]," your organization’s passwords is important. In fact, we’re currently developing this feature further so it will do just that! We focus here on IdP passwords because they’re a higher-value target for attackers — and the frequent target of recent real-world attacks.",{"data":59996,"content":59997,"nodeType":1058},{},[59998],{"data":59999,"marks":60000,"value":60001,"nodeType":867},{},[],"Why IdP accounts?",{"data":60003,"content":60004,"nodeType":876},{},[60005,60009,60017],{"data":60006,"marks":60007,"value":60008,"nodeType":867},{},[],"IdP accounts have been targeted in several high-profile recent attacks, like those carried out by Scattered Spider against MGM resorts and in the Retool breach. You can read more about them in our ",{"data":60010,"content":60013,"nodeType":17452},{"target":60011},{"sys":60012},{"id":45037,"type":982,"linkType":983},[60014],{"data":60015,"marks":60016,"value":40917,"nodeType":867},{},[],{"data":60018,"marks":60019,"value":60020,"nodeType":867},{},[]," blog article.",{"data":60022,"content":60023,"nodeType":876},{},[60024],{"data":60025,"marks":60026,"value":60027,"nodeType":867},{},[],"In the cloud-first world, a compromised IdP account is like a compromised user workstation. It gives an attacker a solid initial foothold from which they can operate:",{"data":60029,"content":60030,"nodeType":1629},{},[60031,60053],{"data":60032,"content":60033,"nodeType":1586},{},[60034],{"data":60035,"content":60036,"nodeType":876},{},[60037,60041,60050],{"data":60038,"marks":60039,"value":60040,"nodeType":867},{},[],"They instantly get access to all the apps the compromised user was accessing with SSO. It’s easy to move laterally to sensitive apps or to apps where the user has admin privileges. This obviously enables an attacker to directly exfiltrate data from these apps or to use them maliciously, as in the ",{"data":60042,"content":60045,"nodeType":17452},{"target":60043},{"sys":60044},{"id":45037,"type":982,"linkType":983},[60046],{"data":60047,"marks":60048,"value":60049,"nodeType":867},{},[],"Mandiant and SEC Twitter/X breaches",{"data":60051,"marks":60052,"value":1679,"nodeType":867},{},[],{"data":60054,"content":60055,"nodeType":1586},{},[60056],{"data":60057,"content":60058,"nodeType":876},{},[60059,60063,60072,60076,60085,60088,60097],{"data":60060,"marks":60061,"value":60062,"nodeType":867},{},[],"Assuming an attacker hasn’t initially gotten access to a privileged IdP account, they can escalate their privileges by performing ",{"data":60064,"content":60068,"nodeType":17452},{"target":60065},{"sys":60066},{"id":60067,"type":982,"linkType":983},"3F96pyn4qqkbVctSOH69vm",[60069],{"data":60070,"marks":60071,"value":22222,"nodeType":867},{},[],{"data":60073,"marks":60074,"value":60075,"nodeType":867},{},[]," on any low-risk app where the user is an admin or by using apps like ",{"data":60077,"content":60081,"nodeType":17452},{"target":60078},{"sys":60079},{"id":60080,"type":982,"linkType":983},"2rjLrCo6KWwLicfpV2qTOZ",[60082],{"data":60083,"marks":60084,"value":51403,"nodeType":867},{},[],{"data":60086,"marks":60087,"value":1174,"nodeType":867},{},[],{"data":60089,"content":60093,"nodeType":17452},{"target":60090},{"sys":60091},{"id":60092,"type":982,"linkType":983},"2cv7Yq1DQpm1Mho7fKDs44",[60094],{"data":60095,"marks":60096,"value":51415,"nodeType":867},{},[],{"data":60098,"marks":60099,"value":60100,"nodeType":867},{},[]," to phish higher-privilege users.",{"data":60102,"content":60103,"nodeType":1058},{},[60104],{"data":60105,"marks":60106,"value":60107,"nodeType":867},{},[],"It also protects against credential stuffing attacks",{"data":60109,"content":60110,"nodeType":876},{},[60111,60115,60120],{"data":60112,"marks":60113,"value":60114,"nodeType":867},{},[],"As well as protecting your users against phishing, the SSO password protection feature can prevent credential stuffing attacks succeeding against your IdP instance. How? By stopping your employees from reusing their SSO password on other apps.  \nPush monitors the identities of thousands of employees. Around ",{"data":60116,"marks":60117,"value":60119,"nodeType":867},{},[60118],{"type":865},"1 in 3 of them reuse passwords",{"data":60121,"marks":60122,"value":60123,"nodeType":867},{},[]," across multiple accounts. ",{"data":60125,"content":60126,"nodeType":876},{},[60127],{"data":60128,"marks":60129,"value":60130,"nodeType":867},{},[],"Employees know that their SSO password is one they’ll need to use a lot, and so they tend to choose one they know they will remember, because they are already using it successfully. That’s why we see higher levels of password reuse on IdP apps in particular.",{"data":60132,"content":60133,"nodeType":876},{},[60134],{"data":60135,"marks":60136,"value":60137,"nodeType":867},{},[],"Every time an SSO password is reused on another app, its exposure increases, along with the likelihood of it falling into the wrong hands. This can happen when another app experiences a breach and credentials are stolen. Or alternatively, when an attacker steals credentials in a phishing attack aimed at users of other apps where the password is being reused.",{"data":60139,"content":60140,"nodeType":876},{},[60141],{"data":60142,"marks":60143,"value":60144,"nodeType":867},{},[],"Armed with stolen credentials, an attacker can spray them across common cloud apps and see what additional accounts they can gain access to. IdP apps will be high on the list of cloud apps attackers will try because they provide much more in the way of access than a general SaaS user account.",{"data":60146,"content":60147,"nodeType":876},{},[60148],{"data":60149,"marks":60150,"value":60151,"nodeType":867},{},[],"You might be wondering if this feature can also be used to stop other password attacks such as password spraying and brute-forcing attacks. While this specific feature does not, Push’s other features do. ",{"data":60153,"content":60154,"nodeType":876},{},[60155,60159,60164],{"data":60156,"marks":60157,"value":60158,"nodeType":867},{},[],"These include ",{"data":60160,"marks":60161,"value":60163,"nodeType":867},{},[60162],{"type":865},"in-browser guidance",{"data":60165,"marks":60166,"value":60167,"nodeType":867},{},[]," that stops users from creating and using easily guessable passwords as well as Push’s ability to detect when employees are not registered for MFA (and whether the methods they are using are phishing-resistant or not).",{"data":60169,"content":60173,"nodeType":985},{"target":60170},{"sys":60171},{"id":60172,"type":982,"linkType":983},"uy6utpRA35spZFM7Da4Nt",[],{"data":60175,"content":60176,"nodeType":1058},{},[60177],{"data":60178,"marks":60179,"value":25228,"nodeType":867},{},[],{"data":60181,"content":60182,"nodeType":876},{},[60183,60186,60192],{"data":60184,"marks":60185,"value":44966,"nodeType":867},{},[],{"data":60187,"content":60188,"nodeType":915},{"uri":5286},[60189],{"data":60190,"marks":60191,"value":11707,"nodeType":867},{},[],{"data":60193,"marks":60194,"value":60195,"nodeType":867},{},[],". We’ll be happy to show you this feature, along with how we discover all the apps your employees are using and how we detect vulnerable identities.","Use the Push browser agent’s unique vantage point to protect SSO credentials by blocking employees from entering their password into any other site. ","2024-04-29T00:00:00.000Z",{"items":60199},[60200,60202],{"sys":60201,"name":342},{"id":3240},{"sys":60203,"name":39245},{"id":39244},{"items":60205},[60206],{"fullName":4089,"firstName":4090,"jobTitle":851,"profilePicture":60207},{"url":4094},"blog/introducing-aitm-phishing-toolkit-detection-powered-by-the-push-browser",{"json":60210},{"data":60211,"content":60212,"nodeType":1680},{},[60213],{"data":60214,"content":60215,"nodeType":876},{},[60216],{"data":60217,"marks":60218,"value":60219,"nodeType":867},{},[],"Push analyzes behavioral attributes of malware to identify advanced phishing tools like Evilginx and NakedPages in use on websites and immediately block end-users from visiting them.",{"id":44994,"publishedAt":60221},"2026-08-12T11:57:14.270Z",{"items":60223},[60224,60226],{"sys":60225,"name":39245},{"id":39244},{"sys":60227,"name":342},{"id":3240},{"items":60229},[60230,60232,60234,60236,60238,60240,60242,60244,60246,60248,60250,60252,60254],{"sys":60231,"name":519,"slug":520,"tier":31},{"id":516},{"sys":60233,"name":279,"slug":280,"tier":31},{"id":276},{"sys":60235,"name":342,"slug":343,"tier":31},{"id":339},{"sys":60237,"name":297,"slug":298,"tier":31},{"id":294},{"sys":60239,"name":413,"slug":414,"tier":31},{"id":410},{"sys":60241,"name":261,"slug":262,"tier":45},{"id":258},{"sys":60243,"name":511,"slug":512,"tier":45},{"id":508},{"sys":60245,"name":466,"slug":467,"tier":45},{"id":463},{"sys":60247,"name":324,"slug":325,"tier":45},{"id":321},{"sys":60249,"name":351,"slug":352,"tier":45},{"id":348},{"sys":60251,"name":377,"slug":378,"tier":45},{"id":374},{"sys":60253,"name":598,"slug":599,"tier":45},{"id":595},{"sys":60255,"name":404,"slug":405,"tier":45},{"id":401},"qlmXy5FkADS7F25sxNmLMjPboPGE79KlfxoABFCLuFI",{"id":60258,"title":60259,"authorsCollection":60260,"content":60266,"extension":228,"faqItemsCollection":60980,"faqTitle":59,"featured":6,"hashTags":59,"meta":60982,"metaTitle":60983,"ogImage":60984,"postType":1767,"publishedDate":60986,"relatedBlogPostsCollection":60987,"slug":62121,"stem":62122,"subtitle":59,"summary":62123,"synopsis":62140,"sys":62141,"tagsCollection":62144,"topicsCollection":62150,"__hash__":62184},"blog/blog/5-ways-to-defeat-identity-based-attacks.json","5 ways to defeat identity-based attacks",{"items":60261},[60262],{"fullName":28592,"firstName":28593,"jobTitle":28594,"socialLinks":60263,"profilePicture":60265},[60264],"https://www.linkedin.com/in/jacques-louw-o-62608594/",{"url":28596},{"json":60267,"links":60951},{"data":60268,"content":60269,"nodeType":1680},{},[60270,60277,60284,60291,60298,60305,60312,60318,60325,60331,60338,60345,60361,60368,60375,60382,60389,60396,60403,60410,60416,60423,60430,60437,60444,60450,60458,60465,60472,60479,60486,60494,60501,60507,60514,60521,60544,60551,60584,60591,60607,60615,60622,60629,60636,60643,60696,60703,60709,60716,60723,60730,60738,60745,60752,60759,60788,60795,60828,60835,60842,60849,60856,60864,60871,60878,60885,60892,60899,60906,60913,60920,60939,60945],{"data":60271,"content":60272,"nodeType":868},{},[60273],{"data":60274,"marks":60275,"value":60276,"nodeType":867},{},[],"What is in an identity?",{"data":60278,"content":60279,"nodeType":876},{},[60280],{"data":60281,"marks":60282,"value":60283,"nodeType":867},{},[],"Like real identities, digital identities are a little hard to define. Formally it’s a mapping of a human into the digital world, but more often this term is used as synonymous with a credential (e.g. a username and password, a Multi-Factor Authentication (MFA) device, or a fingerprint) - the thing you use to prove you own the identity in an authentication process. When people say an identity is breached, they typically mean the credentials have been stolen.",{"data":60285,"content":60286,"nodeType":876},{},[60287],{"data":60288,"marks":60289,"value":60290,"nodeType":867},{},[],"This is a useful simplification, but bear in mind that reality is a bit more complex. For example - identities are typically tied to an account on an application (you want to login to Slack, Slack knows your password), but can also trust a third party (an Identity Provider or IdP) to authenticate an identity on your behalf in what’s known as federation (“login with Google” on Slack).",{"data":60292,"content":60293,"nodeType":876},{},[60294],{"data":60295,"marks":60296,"value":60297,"nodeType":867},{},[],"Surprisingly, it’s very common for modern apps to allow a user to authenticate to the same account using a local credential (a username and password) and a federated identity (e.g. the “login with Google” or “login with Microsoft” buttons) interchangeably.",{"data":60299,"content":60300,"nodeType":876},{},[60301],{"data":60302,"marks":60303,"value":60304,"nodeType":867},{},[],"That’s how you could wind up with multiple identities tied to a single account, or multiple accounts tied to a single federated identity. This is exactly what you see for real users - and every weird in-between case to boot.",{"data":60306,"content":60307,"nodeType":868},{},[60308],{"data":60309,"marks":60310,"value":60311,"nodeType":867},{},[],"The “new perimeter” … from a red-teamer’s perspective",{"data":60313,"content":60314,"nodeType":876},{},[60315],{"data":60316,"marks":60317,"value":21,"nodeType":867},{},[],{"data":60319,"content":60320,"nodeType":876},{},[60321],{"data":60322,"marks":60323,"value":60324,"nodeType":867},{},[],"To see how identities are the new thing, it helps to see how we got here.",{"data":60326,"content":60327,"nodeType":1058},{},[60328],{"data":60329,"marks":60330,"value":39330,"nodeType":867},{},[],{"data":60332,"content":60333,"nodeType":876},{},[60334],{"data":60335,"marks":60336,"value":60337,"nodeType":867},{},[],"A couple of decades ago, I was just getting started as a red-teamer or penetration tester, or whatever you want to call it. The job is to do what real attackers do so clients could understand the attack techniques and better defend against them. The most stressful part of each project was the first step - getting initial access to the target - getting past their perimeter and into the (usually) soft internals.",{"data":60339,"content":60340,"nodeType":876},{},[60341],{"data":60342,"marks":60343,"value":60344,"nodeType":867},{},[],"A security perimeter is a boundary at which controls can be enforced. From an offensive perspective, a security perimeter is the same as an attack surface: where you can target initial attacks to gain a foothold, from which you can launch further attacks. I use perimeter and attack surface interchangeably going forward.",{"data":60346,"content":60347,"nodeType":876},{},[60348,60352,60357],{"data":60349,"marks":60350,"value":60351,"nodeType":867},{},[],"A perimeter can be physical, like a wall around a house, or virtual like the network boundary between an internal network and the internet where controls are things like firewalls. A couple of decades ago this internet network boundary was ",{"data":60353,"marks":60354,"value":60356,"nodeType":867},{},[60355],{"type":1303},"the",{"data":60358,"marks":60359,"value":60360,"nodeType":867},{},[]," perimeter. As any decent red-teamer during this era, we had a pretty well-oiled process of mapping a client’s external network, scanning it for services, and then identifying and exploiting known vulnerabilities in those services. With this foothold on a target network, we could pivot to other, more sensitive internal systems.",{"data":60362,"content":60363,"nodeType":876},{},[60364],{"data":60365,"marks":60366,"value":60367,"nodeType":867},{},[],"Blue teams started having success with automated vulnerability scanning and patching programs, during this time. Then red teams responded by focusing on finding new vulnerabilities, especially in custom code like web applications. I fondly remember using techniques like xp_cmdshell with SQL injection to get access to breach perimeter systems and get access to internal networks. As DMZs, SDLC, vuln scanning and a dozen other tactics became generally adopted things improved to the point where those standard red-team playbooks weren’t working anymore. ",{"data":60369,"content":60370,"nodeType":1058},{},[60371],{"data":60372,"marks":60373,"value":60374,"nodeType":867},{},[],"The shift to targeting users and their endpoints",{"data":60376,"content":60377,"nodeType":876},{},[60378],{"data":60379,"marks":60380,"value":60381,"nodeType":867},{},[],"About a decade ago, attackers realized it was easier to breach the perimeter and gain access to internal networks by simply targeting users with endpoints directly connected to the internal network. At the time the main techniques were email phishing and malicious web pages delivering exploits or straight malware. We put down Burp and our other web app testing tools and started spending our time crafting phishing emails with malicious macro-laden Microsoft Office documents for that initial entrypoint.",{"data":60383,"content":60384,"nodeType":876},{},[60385],{"data":60386,"marks":60387,"value":60388,"nodeType":867},{},[],"Defenders were on the back foot and even back then the “train your employees to spot attacks” advice felt as totally unrealistic as it’s now proved to be. The zeitgeist suggested, \"Attackers only need to succeed once; defenders must succeed every time.\" Defenders were blind and the focus was firmly on detection. Much much better telemetry was needed, which spawned the endpoint detection and response (EDR) revolution. ",{"data":60390,"content":60391,"nodeType":876},{},[60392],{"data":60393,"marks":60394,"value":60395,"nodeType":867},{},[],"EDR required immediate changes to red team tactics, and together with better endpoint security defaults, automatic OS updates (that actually started working) and memory exploit protections (things like DEP and ASLR) the timelines for successful attacks were stretching a lot.",{"data":60397,"content":60398,"nodeType":1058},{},[60399],{"data":60400,"marks":60401,"value":60402,"nodeType":867},{},[],"The modern perimeter",{"data":60404,"content":60405,"nodeType":876},{},[60406],{"data":60407,"marks":60408,"value":60409,"nodeType":867},{},[],"Attackers have had to change tactics yet again, due to the rising cost of attacking endpoints and the fact that data has moved off endpoints and internal networks and onto cloud systems or Software as a Service (SaaS) applications.",{"data":60411,"content":60415,"nodeType":985},{"target":60412},{"sys":60413},{"id":60414,"type":982,"linkType":983},"79wGG37CY7aBdRrdjO5eQY",[],{"data":60417,"content":60418,"nodeType":876},{},[60419],{"data":60420,"marks":60421,"value":60422,"nodeType":867},{},[],"Identities have always existed as a target for attackers and were a critical part of the kill chain, but they used to be protected by some other perimeter, be that a network perimeter or an endpoint perimeter. ",{"data":60424,"content":60425,"nodeType":876},{},[60426],{"data":60427,"marks":60428,"value":60429,"nodeType":867},{},[],"This has fundamentally changed as modern work applications are now directly exposed to the internet  - and the only thing needed to access these apps are identities. That means identities are now no longer the second or third target but the initial target, the new perimeter.",{"data":60431,"content":60432,"nodeType":868},{},[60433],{"data":60434,"marks":60435,"value":60436,"nodeType":867},{},[],"Securing the (identity) perimeter",{"data":60438,"content":60439,"nodeType":876},{},[60440],{"data":60441,"marks":60442,"value":60443,"nodeType":867},{},[],"To understand how we can protect this new perimeter, I’ll discuss the general approach to securing any perimeter, and then how this applies to the identity attack surface.",{"data":60445,"content":60449,"nodeType":985},{"target":60446},{"sys":60447},{"id":60448,"type":982,"linkType":983},"c0YSk60vVULBPorLkkBPL",[],{"data":60451,"content":60452,"nodeType":1058},{},[60453],{"data":60454,"marks":60455,"value":60457,"nodeType":867},{},[60456],{"type":865},"1. Map your perimeter",{"data":60459,"content":60460,"nodeType":876},{},[60461],{"data":60462,"marks":60463,"value":60464,"nodeType":867},{},[],"It’s impossible to secure what you don’t know about. Whether your perimeter is made of network services, user endpoints or identities, you must know what they are before you can implement controls to protect them, and crucially, verify those controls are effective.",{"data":60466,"content":60467,"nodeType":876},{},[60468],{"data":60469,"marks":60470,"value":60471,"nodeType":867},{},[],"In a traditional network setting, you might ask IT to inventory public network ranges, domains you own, and internet facing servers and services to get visibility into your attack surface. This is a pretty complex task and lots of the static inventory will quickly become outdated and incomplete. That’s why many orgs will perform network discovery activities to find internet-exposed network services, using anything from basic network scans to find onsite or self-hosted services to querying APIs in cloud infrastructure platforms (like AWS or Azure).",{"data":60473,"content":60474,"nodeType":876},{},[60475],{"data":60476,"marks":60477,"value":60478,"nodeType":867},{},[],"There are parallels in the identity perimeter space, like querying Identity Providers (IdPs like Entra/AzureAD or Okta) for federated identities to map the attack surface. Unfortunately there is no equivalent to scanning your public network ranges for identities, since you can’t scan or query an app to find accounts on your domain (would that we could!). This problem is compounded by the fact that while IT and developers are typically the only ones that can create and expose new network services, most apps allow any employee to create a new identity by signing up to a free account outside your SSO solution.",{"data":60480,"content":60481,"nodeType":876},{},[60482],{"data":60483,"marks":60484,"value":60485,"nodeType":867},{},[],"Knowing your perimeter without a technical solution is going to be a very hit and miss affair. To have confidence that you understand your identity perimeter, you need an inventory solution that can discover SSO identities (the easy part), as well as identities created outside SSO, like local accounts those employees created just by signing up. To secure identities it’s not enough to know that an employee is accessing an app website, you need to know if they are logged in and what identity they are using (is the username a company email or personal gmail?) or you’ll be dealing with endless false positives.",{"data":60487,"content":60488,"nodeType":1058},{},[60489],{"data":60490,"marks":60491,"value":60493,"nodeType":867},{},[60492],{"type":865},"2. Reduce the size of your attack surface",{"data":60495,"content":60496,"nodeType":876},{},[60497],{"data":60498,"marks":60499,"value":60500,"nodeType":867},{},[],"Once you have an idea of what makes up your perimeter, it’s generally a good idea to make it as small as possible. If you halve the number of network services an attacker can target, that means you can spend twice as long per service to secure the ones that remain - the same goes for identities!",{"data":60502,"content":60506,"nodeType":985},{"target":60503},{"sys":60504},{"id":60505,"type":982,"linkType":983},"2XZ5vADLzuEnc2aAdZrkbO",[],{"data":60508,"content":60509,"nodeType":876},{},[60510],{"data":60511,"marks":60512,"value":60513,"nodeType":867},{},[],"To start this process, remove unused or unnecessary targets from the perimeter. ",{"data":60515,"content":60516,"nodeType":876},{},[60517],{"data":60518,"marks":60519,"value":60520,"nodeType":867},{},[],"On a network perimeter that might mean:",{"data":60522,"content":60523,"nodeType":1629},{},[60524,60534],{"data":60525,"content":60526,"nodeType":1586},{},[60527],{"data":60528,"content":60529,"nodeType":876},{},[60530],{"data":60531,"marks":60532,"value":60533,"nodeType":867},{},[],"Shutting down unused servers or",{"data":60535,"content":60536,"nodeType":1586},{},[60537],{"data":60538,"content":60539,"nodeType":876},{},[60540],{"data":60541,"marks":60542,"value":60543,"nodeType":867},{},[],"Firewalling services that don’t need to be exposed to the internet.",{"data":60545,"content":60546,"nodeType":876},{},[60547],{"data":60548,"marks":60549,"value":60550,"nodeType":867},{},[],"In the identity space, you might:",{"data":60552,"content":60553,"nodeType":1629},{},[60554,60564,60574],{"data":60555,"content":60556,"nodeType":1586},{},[60557],{"data":60558,"content":60559,"nodeType":876},{},[60560],{"data":60561,"marks":60562,"value":60563,"nodeType":867},{},[],"Make sure new accounts use existing federated identities,",{"data":60565,"content":60566,"nodeType":1586},{},[60567],{"data":60568,"content":60569,"nodeType":876},{},[60570],{"data":60571,"marks":60572,"value":60573,"nodeType":867},{},[],"Delete or disable unused SSO identities on your IdP, or ",{"data":60575,"content":60576,"nodeType":1586},{},[60577],{"data":60578,"content":60579,"nodeType":876},{},[60580],{"data":60581,"marks":60582,"value":60583,"nodeType":867},{},[],"Manually delete unnecessary user accounts on work apps.",{"data":60585,"content":60586,"nodeType":876},{},[60587],{"data":60588,"marks":60589,"value":60590,"nodeType":867},{},[],"Manually deleting an unmanaged local identity on an app, e.g. after an employee leaves your org, is a (very) non-trivial task. This is because you often don’t known of the accounts and don't have access to manage the account (the IT or security team aren’t admin on the app tenant where it exists). You might have access to the user’s mailbox and be able to get access to the account by going through an account recovery flow and delete the account that way - but this is very time consuming and even more difficult if the user enabled MFA (which is what you want them to do!).",{"data":60592,"content":60593,"nodeType":876},{},[60594,60598,60603],{"data":60595,"marks":60596,"value":60597,"nodeType":867},{},[],"Given the difficulty of managing these accounts, a better strategy is to ",{"data":60599,"marks":60600,"value":60602,"nodeType":867},{},[60601],{"type":865},"make sure they never exist in the first place",{"data":60604,"marks":60605,"value":60606,"nodeType":867},{},[],". If you find you have lots of identities on an app you may decide the risk warrants IT effort and you can take over management of the app and integrate it with your IdP solution - or ask employees to use an alternative app instead. You can also use browser-based technical controls to prevent users from creating local identities in the first place.",{"data":60608,"content":60609,"nodeType":1058},{},[60610],{"data":60611,"marks":60612,"value":60614,"nodeType":867},{},[60613],{"type":865},"3. Harden the perimeter",{"data":60616,"content":60617,"nodeType":876},{},[60618],{"data":60619,"marks":60620,"value":60621,"nodeType":867},{},[],"Once you’ve made the perimeter as small as possible, the next step is to make it more difficult to breach that perimeter. Similar to the other objectives, but especially here, there are two sides to this. First the implementation; you have processes, configuration standards, and tools to make sure network services are updated and securely configured. Virtually no one achieves success simply through implementing good processes, you must continually verify that these processes work and that it continues to work.",{"data":60623,"content":60624,"nodeType":876},{},[60625],{"data":60626,"marks":60627,"value":60628,"nodeType":867},{},[],"To verify network controls are in place and working you do something like vulnerability scanning, where you check the perimeter for known vulnerabilities that an attacker could exploit and gain a foothold on your internal network. You might even have a risk profile that means you are concerned about more targeted attacks and hire pentesters or run a bug-bounty program to find weaknesses that can’t be automatically discovered. Very few organizations with an external network of any significant size perform a vulnerability scan for the first time - even a low-quality automated one - and find no serious issues. ",{"data":60630,"content":60631,"nodeType":876},{},[60632],{"data":60633,"marks":60634,"value":60635,"nodeType":867},{},[],"In the identity space, the status-quo is to be content with making policies and implementing and configuring an SSO system without explicit verification that it works as it should. We should be following the same level of verification processes for the identity perimeter as we do/did for the endpoint and network perimeter. ",{"data":60637,"content":60638,"nodeType":876},{},[60639],{"data":60640,"marks":60641,"value":60642,"nodeType":867},{},[],"In this case, the vulnerabilities we are looking for aren’t unpatched systems or zero-days. Instead, we’re looking for:",{"data":60644,"content":60645,"nodeType":1629},{},[60646,60656,60666,60676,60686],{"data":60647,"content":60648,"nodeType":1586},{},[60649],{"data":60650,"content":60651,"nodeType":876},{},[60652],{"data":60653,"marks":60654,"value":60655,"nodeType":867},{},[],"Accounts without MFA, ",{"data":60657,"content":60658,"nodeType":1586},{},[60659],{"data":60660,"content":60661,"nodeType":876},{},[60662],{"data":60663,"marks":60664,"value":60665,"nodeType":867},{},[],"Those using weak MFA methods that make them phish-able,",{"data":60667,"content":60668,"nodeType":1586},{},[60669],{"data":60670,"content":60671,"nodeType":876},{},[60672],{"data":60673,"marks":60674,"value":60675,"nodeType":867},{},[],"Employees re-using the same password across multiple accounts, ",{"data":60677,"content":60678,"nodeType":1586},{},[60679],{"data":60680,"content":60681,"nodeType":876},{},[60682],{"data":60683,"marks":60684,"value":60685,"nodeType":867},{},[],"Passwords that exist in public breach dumps,",{"data":60687,"content":60688,"nodeType":1586},{},[60689],{"data":60690,"content":60691,"nodeType":876},{},[60692],{"data":60693,"marks":60694,"value":60695,"nodeType":867},{},[],"Identities that should be in SSO but aren’t.",{"data":60697,"content":60698,"nodeType":876},{},[60699],{"data":60700,"marks":60701,"value":60702,"nodeType":867},{},[],"It’s not yet standard practice to test or verify that identity controls are in place, but if the past has taught us anything it soon will be. You'd be surprised how many times we find that the MFA policies security teams thought they had in place, actually aren't.",{"data":60704,"content":60708,"nodeType":985},{"target":60705},{"sys":60706},{"id":60707,"type":982,"linkType":983},"4w5UZcf5hJ7ADuoT5W2tkC",[],{"data":60710,"content":60711,"nodeType":876},{},[60712],{"data":60713,"marks":60714,"value":60715,"nodeType":867},{},[],"Part of the reason for this lack of verification is due to lack of awareness. While identities used to be an internal thing that we protected with the network perimeter, online identities today are external and have slowly become the perimeter, almost without anyone noticing. While online identities are external, they are absolutely part of your attack surface and must be controlled and hardened to some extent.",{"data":60717,"content":60718,"nodeType":876},{},[60719],{"data":60720,"marks":60721,"value":60722,"nodeType":867},{},[],"Verifying controls is also really difficult, which is another reason we may not be making it a crucial step in the process. Customers feel that SSO solutions are security solutions and using security tools on security tools feel wrong. But it’s no different to vuln-scanning to ensure your firewalls are patched and don’t have default passwords. ",{"data":60724,"content":60725,"nodeType":876},{},[60726],{"data":60727,"marks":60728,"value":60729,"nodeType":867},{},[],"Verification can also be legally challenging because it’s not yet clear whether pentesters or red teamers are allowed to target online identities during assessments. Often these assets aren’t considered in scope during client assessments. This means these vulnerabilities rarely end up in pentest reports and therefore don’t enter many organization’s security or risk management processes. Since you own the identities (even on a third party identity solution or app) and are allowed to grant permission to the red team to use these identities, it seems to me that adding identities to the scope is distinct from bug hunting or vulnerability research on these apps (which is the legally challenging aspect). I would strongly recommend that you discuss including online identities with the red team as part of your next pentest.",{"data":60731,"content":60732,"nodeType":1058},{},[60733],{"data":60734,"marks":60735,"value":60737,"nodeType":867},{},[60736],{"type":865},"4. Limit breach impact",{"data":60739,"content":60740,"nodeType":876},{},[60741],{"data":60742,"marks":60743,"value":60744,"nodeType":867},{},[],"The unfortunate reality is that regardless of what we do to harden a perimeter, there will always be a chance that breaches occur. The goal is to reduce that risk by minimizing the attack surface and hardening identities. ",{"data":60746,"content":60747,"nodeType":876},{},[60748],{"data":60749,"marks":60750,"value":60751,"nodeType":867},{},[],"When an attacker does get a foothold (by compromising an identity, for instance) you need to to restrict their further actions. Risk involves both the likelihood and the impact of an event. Previously, we focused on reducing the likelihood of breaches. Now, we're also aiming to lessen the impact if they do occur.",{"data":60753,"content":60754,"nodeType":876},{},[60755],{"data":60756,"marks":60757,"value":60758,"nodeType":867},{},[],"In our network perimeter story, we might think of using a DMZ network to restrict network access for systems exposed to the internet. A common example of a failure to limit impact on a Windows endpoint breach is having service accounts on all endpoints with Domain Administrator permission - which effectively turns a breach of any endpoint very quickly into a breach of every endpoint.",{"data":60760,"content":60761,"nodeType":876},{},[60762,60766,60774,60778,60784],{"data":60763,"marks":60764,"value":60765,"nodeType":867},{},[],"In an identity context, we need to think not only of the direct effect of an identity compromise (e.g. what data can this account read), but also of further lateral movement attacks. Consider this ",{"data":60767,"content":60768,"nodeType":915},{"uri":59175},[60769],{"data":60770,"marks":60771,"value":60773,"nodeType":867},{},[60772],{"type":913},"Oktajacking",{"data":60775,"marks":60776,"value":60777,"nodeType":867},{},[]," case study where a breached identity with admin permissions on an otherwise low-risk app which is connected to SSO can be used to perform a ",{"data":60779,"content":60780,"nodeType":915},{"uri":22216},[60781],{"data":60782,"marks":60783,"value":22222,"nodeType":867},{},[],{"data":60785,"marks":60786,"value":60787,"nodeType":867},{},[]," attack that compromises SSO credentials for all other users of the same low-risk app.",{"data":60789,"content":60790,"nodeType":876},{},[60791],{"data":60792,"marks":60793,"value":60794,"nodeType":867},{},[],"In contrast to traditional network or endpoint breaches, identity breaches are scoped to the permissions that the compromised account has. If an identity is compromised, whatever that identity is authorized to do is the scope of the breach. For example:",{"data":60796,"content":60797,"nodeType":1629},{},[60798,60808],{"data":60799,"content":60800,"nodeType":1586},{},[60801],{"data":60802,"content":60803,"nodeType":876},{},[60804],{"data":60805,"marks":60806,"value":60807,"nodeType":867},{},[],"If an identity with read access to a code repository was breached you might consider that all the source code (hopefully no secrets!) they had read access to was taken unless you can prove otherwise. This is often more difficult than you expect - last time I checked Github (by far the world's most popular source code repository app) logs didn’t include, for example, zipped repo downloads. ",{"data":60809,"content":60810,"nodeType":1586},{},[60811],{"data":60812,"content":60813,"nodeType":876},{},[60814,60818,60825],{"data":60815,"marks":60816,"value":60817,"nodeType":867},{},[],"If an identity with write permission was compromised, you would also need to check all commits/changes to ensure no code was backdoored. The same applies for other apps - think of an identity with write access to a wiki being used to ",{"data":60819,"content":60820,"nodeType":915},{"uri":42831},[60821],{"data":60822,"marks":60823,"value":60824,"nodeType":867},{},[],"drop links to phishing pages",{"data":60826,"marks":60827,"value":1679,"nodeType":867},{},[],{"data":60829,"content":60830,"nodeType":876},{},[60831],{"data":60832,"marks":60833,"value":60834,"nodeType":867},{},[],"For primary cloud collaboration platforms with complex data types (think O365 or Google Workspace) your IT team is likely already managing policies to limit the data that a user can read. For primary cloud hosting platforms your DevOps teams are likely maintaining policies to manage privileged access to production systems. The situation is typically very different for the few dozen high risk “core apps” beyond the 2 or 3 apps that receive a lot of attention and have dedicated teams.",{"data":60836,"content":60837,"nodeType":876},{},[60838],{"data":60839,"marks":60840,"value":60841,"nodeType":867},{},[],"Starting to review roles and permissions across the few dozen or so high-risk apps that are not as actively managed (or more likely self-managed by the teams using them) is a good way to start addressing the residual risk. The good news here is that most modern work apps use a much simpler permission model based largely around predefined roles like Owner, Admin, or Employee or similar variations. This means less flexibility, but also makes it a lot easier to manage permissions for identities on these apps - on balance, a good trade!",{"data":60843,"content":60844,"nodeType":876},{},[60845],{"data":60846,"marks":60847,"value":60848,"nodeType":867},{},[],"Consider this as part of your identity and access management review process. Something that used to be scoped around Active Directory group membership, but in a modern online identity context, now must be applied across many different work apps. ",{"data":60850,"content":60851,"nodeType":876},{},[60852],{"data":60853,"marks":60854,"value":60855,"nodeType":867},{},[],"Unless you want to try to get access to each tenant of each app and normalize this data into a mega-spreadsheet, you need access to this data in your identity inventory. This is an especially big challenge as teams find many of the apps they care about support authentication through SSO, but not authorization.",{"data":60857,"content":60858,"nodeType":1058},{},[60859],{"data":60860,"marks":60861,"value":60863,"nodeType":867},{},[60862],{"type":865},"5. Detect and respond to attacks",{"data":60865,"content":60866,"nodeType":876},{},[60867],{"data":60868,"marks":60869,"value":60870,"nodeType":867},{},[],"Your last line of defense in protecting a perimeter is to monitor for attacks. It’s typically when controls and detections fail that breaches end in the news. ",{"data":60872,"content":60873,"nodeType":876},{},[60874],{"data":60875,"marks":60876,"value":60877,"nodeType":867},{},[],"Telemetry is the core building block of attack detection. Typically, you might ingest audit or event logs into a SIEM system. To detect attacks against identities, you’ll typically want to start with telemetry from SSO or IdP logs. These will provide some minimal coverage of many of the IT managed apps, but unfortunately attacks are more likely to happen on apps that aren’t SSO integrated, so we need a strategy to cover these as well. An identity inventory is a critical starting point to identify non-SSO apps from which you can collect event logs, as well as giving you visibility of the identities that are not covered.",{"data":60879,"content":60880,"nodeType":876},{},[60881],{"data":60882,"marks":60883,"value":60884,"nodeType":867},{},[],"Monitoring breaches for hosted work apps is different from other domains, largely because you are almost totally reliant on the app vendor to produce the telemetry. Unfortunately (I suspect primarily due to lack of customer demand), many apps don’t offer any centralized logging functionality at all, and those that do offer limited audit logs, or only do so on the top tier “enterprise” license plans. ",{"data":60886,"content":60887,"nodeType":876},{},[60888],{"data":60889,"marks":60890,"value":60891,"nodeType":867},{},[],"In the network or endpoint world, when you need more telemetry you have all the access you need to install software or hardware to generate that additional telemetry. You could put a network monitoring appliance in-line with your internet gateways or install an endpoint (EDR) agent to generate more telemetry than your router or endpoint OS will generate. You can add a proxy in front of an app for your users, but (except for a very small number of highly configurable apps) you can’t make attackers go through your proxy.",{"data":60893,"content":60894,"nodeType":876},{},[60895],{"data":60896,"marks":60897,"value":60898,"nodeType":867},{},[],"What you can do, however, is generate additional telemetry on what happens to your employee’s identities in the browser. This is possible through browser extensions which can be managed through the enterprise management features available for all mainstream browsers (Chrome, Edge, Firefox, Safari, Brave etc. etc.). This is incredibly powerful, and useful in directly detecting a range of identity attacks like phishing (is an employee trying to enter an SSO password into an app that isn’t the SSO login page?), but also through correlations with existing application or IdP logs that indicate account takeover (e.g. has there been a login event that wasn’t observed through the employee’s browser as well).",{"data":60900,"content":60901,"nodeType":868},{},[60902],{"data":60903,"marks":60904,"value":60905,"nodeType":867},{},[],"Same, but different",{"data":60907,"content":60908,"nodeType":876},{},[60909],{"data":60910,"marks":60911,"value":60912,"nodeType":867},{},[],"Whether we’re looking at the Verizon DBIR or just keeping up with security news, it’s clear that identity-based attacks are already responsible for a significant number of breaches. Attackers have started shifting their focus and security teams need to recognize this shift and adapt.",{"data":60914,"content":60915,"nodeType":876},{},[60916],{"data":60917,"marks":60918,"value":60919,"nodeType":867},{},[],"This doesn’t require that we fundamentally rethink security or anything that radical, just that we apply what we’ve learned over the last couple of decades to this new domain. There are some new technologies and protocols to understand, new tools are needed, but the fundamentals like authentication and authorization are already familiar to any security professional. ",{"data":60921,"content":60922,"nodeType":876},{},[60923,60927,60935],{"data":60924,"marks":60925,"value":60926,"nodeType":867},{},[],"If you follow what I’ve outlined here, a lot of the decisions we’ve made with building Push will make perfect sense. For example, you can’t make API integrations with apps to find identities when you don’t know about the apps or identities yet, so we needed a unique new data source. We use our own custom-built browser extension that’s force-deployed to your workforce, so we can observe employee identities as they are used in the browser. This gives us some pretty unique capabilities. If you found this interesting, follow us on ",{"data":60928,"content":60930,"nodeType":915},{"uri":60929},"https://www.linkedin.com/company/push-security",[60931],{"data":60932,"marks":60933,"value":60934,"nodeType":867},{},[],"Linkedin",{"data":60936,"marks":60937,"value":60938,"nodeType":867},{},[]," for more detailed blogs as we unpack this topic.",{"data":60940,"content":60944,"nodeType":985},{"target":60941},{"sys":60942},{"id":60943,"type":982,"linkType":983},"H7m9DHmbE945FO193oLYP",[],{"data":60946,"content":60947,"nodeType":876},{},[60948],{"data":60949,"marks":60950,"value":21,"nodeType":867},{},[],{"entries":60952},{"hyperlink":60953,"inline":60954,"block":60955},[],[],[60956,60962,60967,60973,60977],{"sys":60957,"__typename":1688,"title":60958,"caption":59,"layoutMode":59,"file":60959},{"id":60414},"Identity Security Attack Graphic",{"url":60960,"width":60961,"height":33790},"https://images.ctfassets.net/y1cdw1ablpvd/4x0xxIRhYLw1v8NyXfSIKG/e10b949c8d5694239dc3d9e0a0e9d7a2/IdentitySecurity101_A.png",2560,{"sys":60963,"__typename":1688,"title":60436,"caption":59,"layoutMode":59,"file":60964},{"id":60448},{"url":60965,"width":60966,"height":43768},"https://images.ctfassets.net/y1cdw1ablpvd/3vdIRlCwvBIk9RVpjRXojS/8092a8c05abb75206373e55340bbd07e/IdentitySecurity101_B.png",1280,{"sys":60968,"__typename":60969,"background":60970,"text":60972},{"id":60505},"CalloutWidget",[60971],"Sea Blue","“If you halve the number of network services an attacker can target, that means you can spend twice as long per service to secure the ones that remain - the same goes for identities!”",{"sys":60974,"__typename":60969,"background":60975,"text":60976},{"id":60707},[60971],"It’s not yet standard practice to test or verify that identity controls are in place, but if the past has taught us anything it soon will be.",{"sys":60978,"__typename":1697,"type":51810,"ctaText":60979,"buttonLabel":30223,"buttonColour":1701,"buttonUrl":59},{"id":60943},"Push maps your identity attack surface, hardens and minimizes it, helps you reduce impact and provides a unique telemetry source to help you detect and respond to identity attacks.",{"items":60981},[],{},"Push Security: 5 Ways to Defeat Identity-Based Attacks",{"url":60985},"https://images.ctfassets.net/y1cdw1ablpvd/4fNcMVZPgTYGgMRk7Wn0pd/9195a26bf242fa006e61ba45778f248f/Identity-Based-Attacks.png","2024-02-26T00:00:00.000Z",{"items":60988},[60989,61785],{"__typename":1772,"sys":60990,"content":60992,"title":61771,"synopsis":61772,"hashTags":59,"publishedDate":61773,"slug":61774,"tagsCollection":61775,"authorsCollection":61781},{"id":60991},"6VZQJzQ2FNetGNMEjiuXB2",{"json":60993},{"data":60994,"content":60995,"nodeType":1680},{},[60996,61003,61010,61017,61024,61031,61038,61044,61061,61068,61111,61118,61125,61165,61185,61192,61199,61206,61226,61244,61251,61284,61291,61311,61318,61325,61355,61375,61382,61387,61394,61401,61408,61415,61422,61429,61436,61443,61450,61457,61464,61471,61487,61494,61563,61570,61577,61606,61621,61628,61635,61642,61675,61695,61702,61709,61716,61723,61742,61759,61765],{"data":60997,"content":60998,"nodeType":876},{},[60999],{"data":61000,"marks":61001,"value":61002,"nodeType":867},{},[],"Our goal at Push is simple — to stop identity attacks. Today, the vast majority of identity vulnerabilities exist in the context of SaaS apps. ",{"data":61004,"content":61005,"nodeType":876},{},[61006],{"data":61007,"marks":61008,"value":61009,"nodeType":867},{},[],"The reasons for this are clear: Security teams have reduced central oversight and control over SaaS apps than they are used to, these apps exist in large numbers per company, and the identities that are used to access these apps are... complicated, to say the least. Securing hundreds of apps, with thousands of associated identities, is therefore no mean feat. ",{"data":61011,"content":61012,"nodeType":876},{},[61013],{"data":61014,"marks":61015,"value":61016,"nodeType":867},{},[],"Securing SaaS use means building controls that are easy to use, easy to understand — and ultimately effective. Not just effective against the hand-wavy concept of “SaaS attacks,” but specific techniques — the most common techniques that are likely to cause real damage.",{"data":61018,"content":61019,"nodeType":876},{},[61020],{"data":61021,"marks":61022,"value":61023,"nodeType":867},{},[],"To talk about this, we need to have a shared understanding of what these techniques are. To get that conversation going, we’ve pulled together all the techniques we're aware of, and our research team has even added a bunch of new ones.",{"data":61025,"content":61026,"nodeType":868},{},[61027],{"data":61028,"marks":61029,"value":61030,"nodeType":867},{},[],"The SaaS attack matrix",{"data":61032,"content":61033,"nodeType":876},{},[61034],{"data":61035,"marks":61036,"value":61037,"nodeType":867},{},[],"We’ve taken inspiration from the MITRE ATT&CK framework (certainly intended as the sincerest form of flattery), but wanted to make a conscious break away from the endpoint-focused ATT&CK techniques and instead focus on techniques that are SaaS-specific. In fact, these techniques don’t touch endpoints (so they bypass EDR) or customer networks (so they bypass network detection) — so we’re calling them networkless attacks.",{"data":61039,"content":61043,"nodeType":985},{"target":61040},{"sys":61041},{"id":61042,"type":982,"linkType":983},"768Zv5gTVHyu5rbzJAzL4F",[],{"data":61045,"content":61046,"nodeType":876},{},[61047,61051,61058],{"data":61048,"marks":61049,"value":61050,"nodeType":867},{},[],"You can find more detailed descriptions of these techniques (and hopefully PRs for some we missed) on ",{"data":61052,"content":61053,"nodeType":915},{"uri":15408},[61054],{"data":61055,"marks":61056,"value":14515,"nodeType":867},{},[61057],{"type":913},{"data":61059,"marks":61060,"value":1679,"nodeType":867},{},[],{"data":61062,"content":61063,"nodeType":876},{},[61064],{"data":61065,"marks":61066,"value":61067,"nodeType":867},{},[],"Since we’re not targeting endpoints, let’s talk about the new targets: The accounts/identities on SaaS apps. We found it was useful to think about these identities not as standalone isolated islands — but much more like a graph; less a single web-server on the internet and more like many Windows endpoints on an Active Directory. ",{"data":61069,"content":61070,"nodeType":876},{},[61071,61075,61083,61086,61095,61099,61107],{"data":61072,"marks":61073,"value":61074,"nodeType":867},{},[],"You can leverage this access to an identity on a trusted platform to target (so laterally move or escalate privilege to) other users or identities. For example, attacks like using access to SaaS apps to ",{"data":61076,"content":61077,"nodeType":915},{"uri":35191},[61078],{"data":61079,"marks":61080,"value":61082,"nodeType":867},{},[61081],{"type":913},"phish other employees through comments",{"data":61084,"marks":61085,"value":1174,"nodeType":867},{},[],{"data":61087,"content":61089,"nodeType":915},{"uri":61088},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/im_user_spoofing/description.md",[61090],{"data":61091,"marks":61092,"value":61094,"nodeType":867},{},[61093],{"type":913},"spoofing users on IM platforms",{"data":61096,"marks":61097,"value":61098,"nodeType":867},{},[]," to social engineer them there — or perhaps ",{"data":61100,"content":61101,"nodeType":915},{"uri":42831},[61102],{"data":61103,"marks":61104,"value":61106,"nodeType":867},{},[61105],{"type":913},"backdooring links",{"data":61108,"marks":61109,"value":61110,"nodeType":867},{},[]," in documents.",{"data":61112,"content":61113,"nodeType":876},{},[61114],{"data":61115,"marks":61116,"value":61117,"nodeType":867},{},[],"In this case, unusually, it’s not the data in these hundreds of SaaS apps that create risk, and you need to consider low-risk (from a data perspective) apps as a vector to pivot to higher-risk apps in your estate.",{"data":61119,"content":61120,"nodeType":1058},{},[61121],{"data":61122,"marks":61123,"value":61124,"nodeType":867},{},[],"Initial access and poisoned tenants",{"data":61126,"content":61127,"nodeType":876},{},[61128,61132,61139,61142,61149,61153,61161],{"data":61129,"marks":61130,"value":61131,"nodeType":867},{},[],"Attacks like ",{"data":61133,"content":61134,"nodeType":915},{"uri":42200},[61135],{"data":61136,"marks":61137,"value":37948,"nodeType":867},{},[61138],{"type":913},{"data":61140,"marks":61141,"value":1174,"nodeType":867},{},[],{"data":61143,"content":61144,"nodeType":915},{"uri":42211},[61145],{"data":61146,"marks":61147,"value":42216,"nodeType":867},{},[61148],{"type":913},{"data":61150,"marks":61151,"value":61152,"nodeType":867},{},[]," that get you initial access to SaaS apps are fairly well known — because they work and are widely used. We’re also starting to see tools and attacks that suggest that ",{"data":61154,"content":61155,"nodeType":915},{"uri":42879},[61156],{"data":61157,"marks":61158,"value":61160,"nodeType":867},{},[61159],{"type":913},"phishing employees through these IM apps",{"data":61162,"marks":61163,"value":61164,"nodeType":867},{},[]," is about to go mainstream.",{"data":61166,"content":61167,"nodeType":876},{},[61168,61172,61181],{"data":61169,"marks":61170,"value":61171,"nodeType":867},{},[],"Another interesting attack is a spin on the classic waterhole attack called a ",{"data":61173,"content":61175,"nodeType":915},{"uri":61174},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/poisoned_tenants/description.md",[61176],{"data":61177,"marks":61178,"value":61180,"nodeType":867},{},[61179],{"type":913},"poisoned tenant",{"data":61182,"marks":61183,"value":61184,"nodeType":867},{},[],". Rather than attacking a customer tenant for a SaaS app, the attacker lures employees into joining an attacker-controlled tenant. ",{"data":61186,"content":61187,"nodeType":876},{},[61188],{"data":61189,"marks":61190,"value":61191,"nodeType":867},{},[],"SaaS apps allow anyone to name app tenants (a.k.a. spaces, teams, or instances) anything they like — including your company name. Attackers send invites to your employees from within the app with a customized message explaining why they should join this new tenant (or sign up to the app if they are not already a user). ",{"data":61193,"content":61194,"nodeType":876},{},[61195],{"data":61196,"marks":61197,"value":61198,"nodeType":867},{},[],"Attackers might even pay for premium licenses in the app to further entice employees to join. The attacker then waits for the employee to upload sensitive data or create integrations with other company apps containing crown jewels.",{"data":61200,"content":61201,"nodeType":1058},{},[61202],{"data":61203,"marks":61204,"value":61205,"nodeType":867},{},[],"Living-off-the-(SaaS)-land to persist and avoid detection",{"data":61207,"content":61208,"nodeType":876},{},[61209,61213,61222],{"data":61210,"marks":61211,"value":61212,"nodeType":867},{},[],"In the endpoint world, a favorite technique is the use of legit OS utilities or ",{"data":61214,"content":61216,"nodeType":915},{"uri":61215},"https://lolbas-project.github.io",[61217],{"data":61218,"marks":61219,"value":61221,"nodeType":867},{},[61220],{"type":913},"LOLBaS",{"data":61223,"marks":61224,"value":61225,"nodeType":867},{},[]," (Living-Off-the-Land Binaries and Scripts), which are often signed Microsoft utilities. Perhaps the most well-known example is executing scripts through PowerShell rather than building custom malware. That isn’t as useful these days, but there was a time when PowerShell was routinely used to bypass AV, EDR, and even app allow-listing.",{"data":61227,"content":61228,"nodeType":876},{},[61229,61233,61240],{"data":61230,"marks":61231,"value":61232,"nodeType":867},{},[],"In that same living-off-the-land mindset, an attacker trying to maintain access to each SaaS app they compromise using custom OAuth integration apps might instead choose to use legit SaaS apps that specialize in workflow automation to create ",{"data":61234,"content":61235,"nodeType":915},{"uri":42265},[61236],{"data":61237,"marks":61238,"value":42789,"nodeType":867},{},[61239],{"type":913},{"data":61241,"marks":61242,"value":61243,"nodeType":867},{},[],". Utilizing legit SaaS apps also means they can hide in plain sight from incident responders, instead of having to rely on unverified or unpublished integrations.",{"data":61245,"content":61246,"nodeType":876},{},[61247],{"data":61248,"marks":61249,"value":61250,"nodeType":867},{},[],"Perhaps the best example here is using a well-known automation app like Zapier, which claims to have more than 5,000 integrations. These integrations are often verified, approved, and connected to a trusted vendor (Zapier). An attacker might create workflows to:",{"data":61252,"content":61253,"nodeType":1629},{},[61254,61264,61274],{"data":61255,"content":61256,"nodeType":1586},{},[61257],{"data":61258,"content":61259,"nodeType":876},{},[61260],{"data":61261,"marks":61262,"value":61263,"nodeType":867},{},[],"Do daily data exfiltration from a victim’s data lake.",{"data":61265,"content":61266,"nodeType":1586},{},[61267],{"data":61268,"content":61269,"nodeType":876},{},[61270],{"data":61271,"marks":61272,"value":61273,"nodeType":867},{},[],"Configure a webhook that adds malicious accounts to a Github repo on demand.",{"data":61275,"content":61276,"nodeType":1586},{},[61277],{"data":61278,"content":61279,"nodeType":876},{},[61280],{"data":61281,"marks":61282,"value":61283,"nodeType":867},{},[],"Automatically find and replace bank account numbers in emails to the finance team.",{"data":61285,"content":61286,"nodeType":876},{},[61287],{"data":61288,"marks":61289,"value":61290,"nodeType":867},{},[],"All appear as legitimate Zapier integrations. But, before you put in alerts specifically for Zapier, know that it’s one of dozens of apps that support these kinds of offensive workflows.",{"data":61292,"content":61293,"nodeType":876},{},[61294,61298,61307],{"data":61295,"marks":61296,"value":61297,"nodeType":867},{},[],"A sneaky attacker might go further and use an ",{"data":61299,"content":61301,"nodeType":915},{"uri":61300},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/evil_twin_integrations/description.md",[61302],{"data":61303,"marks":61304,"value":61306,"nodeType":867},{},[61305],{"type":913},"evil twin integration",{"data":61308,"marks":61309,"value":61310,"nodeType":867},{},[]," to make another instance of an existing integration — making this backdoor almost impossible to discover.",{"data":61312,"content":61313,"nodeType":1058},{},[61314],{"data":61315,"marks":61316,"value":61317,"nodeType":867},{},[],"Features or vulnerabilities?",{"data":61319,"content":61320,"nodeType":876},{},[61321],{"data":61322,"marks":61323,"value":61324,"nodeType":867},{},[],"When looking for attack techniques, you’re typically going after features that have weaknesses you can abuse rather than bugs in a single app that will be patched. ",{"data":61326,"content":61327,"nodeType":876},{},[61328,61332,61341,61344,61351],{"data":61329,"marks":61330,"value":61331,"nodeType":867},{},[],"It’s pretty common for SaaS apps to skip email verification or allow multiple simultaneous authentication methods. Both of these are conscious design choices in the name of lowering the friction of account creation and reducing customer support. However, these features make techniques like ",{"data":61333,"content":61335,"nodeType":915},{"uri":61334},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/account_ambushing/description.md",[61336],{"data":61337,"marks":61338,"value":61340,"nodeType":867},{},[61339],{"type":913},"account ambushing",{"data":61342,"marks":61343,"value":1174,"nodeType":867},{},[],{"data":61345,"content":61346,"nodeType":915},{"uri":26236},[61347],{"data":61348,"marks":61349,"value":2929,"nodeType":867},{},[61350],{"type":913},{"data":61352,"marks":61353,"value":61354,"nodeType":867},{},[]," possible. If these attacks become widespread, these might come to be seen more as bugs rather than a positive feature for users.",{"data":61356,"content":61357,"nodeType":876},{},[61358,61362,61371],{"data":61359,"marks":61360,"value":61361,"nodeType":867},{},[],"In other cases, the bugs are serious enough and hard enough to patch that they’re worth noting as a technique. The recently disclosed (and perfectly named) ",{"data":61363,"content":61365,"nodeType":915},{"uri":61364},"https://www.descope.com/blog/post/noauth",[61366],{"data":61367,"marks":61368,"value":61370,"nodeType":867},{},[61369],{"type":913},"nOAuth",{"data":61372,"marks":61373,"value":61374,"nodeType":867},{},[]," bug fits this bill. ",{"data":61376,"content":61377,"nodeType":876},{},[61378],{"data":61379,"marks":61380,"value":61381,"nodeType":867},{},[],"The bug arises from a confusion between an email identity and email metadata field in Microsoft integrations and without a central fix from MS (the fix isn’t trivial), these bugs are likely to be discovered and re-occur on third-party OAuth apps for a while to come.",{"data":61383,"content":61386,"nodeType":985},{"target":61384},{"sys":61385},{"id":38653,"type":982,"linkType":983},[],{"data":61388,"content":61389,"nodeType":868},{},[61390],{"data":61391,"marks":61392,"value":61393,"nodeType":867},{},[],"The SaaS market is driving these offensive techniques",{"data":61395,"content":61396,"nodeType":876},{},[61397],{"data":61398,"marks":61399,"value":61400,"nodeType":867},{},[],"SaaS apps are basically web apps that are run in the cloud and accessed from endpoints, so then WebApp, endpoint, and cloud security should cover all of SaaS, right? ",{"data":61402,"content":61403,"nodeType":876},{},[61404],{"data":61405,"marks":61406,"value":61407,"nodeType":867},{},[],"That was our assumption when we started, but what we found instead was that SaaS marketing practices are driving a lot of pretty interesting techniques that you don’t run into in standalone web apps.",{"data":61409,"content":61410,"nodeType":1058},{},[61411],{"data":61412,"marks":61413,"value":61414,"nodeType":867},{},[],"Modern SaaS is easy to adopt, easy to use, low friction, low cost, low overhead",{"data":61416,"content":61417,"nodeType":876},{},[61418],{"data":61419,"marks":61420,"value":61421,"nodeType":867},{},[],"Making apps easy to sign up for and low effort to support means you need to make some interesting choices when it comes to designing account creation and recovery flows. ",{"data":61423,"content":61424,"nodeType":876},{},[61425],{"data":61426,"marks":61427,"value":61428,"nodeType":867},{},[],"Many apps allow users to sign into apps using multiple methods, easily invite collaborators (internal and external) and avoid any additional friction during the signup process. ",{"data":61430,"content":61431,"nodeType":876},{},[61432],{"data":61433,"marks":61434,"value":61435,"nodeType":867},{},[],"For example, many apps avoid verifying new account email addresses. This is not laziness, these are conscious design choices — not driven by security clearly, but not accidents.",{"data":61437,"content":61438,"nodeType":1058},{},[61439],{"data":61440,"marks":61441,"value":61442,"nodeType":867},{},[],"Modern SaaS is highly integrated",{"data":61444,"content":61445,"nodeType":876},{},[61446],{"data":61447,"marks":61448,"value":61449,"nodeType":867},{},[],"Most SaaS apps are trying to build app marketplaces or perform well in other apps' marketplaces (often both), and it’s rare these days to find apps that don’t integrate with other apps. ",{"data":61451,"content":61452,"nodeType":876},{},[61453],{"data":61454,"marks":61455,"value":61456,"nodeType":867},{},[],"OAuth has become the de facto standard protocol for doing this, and most users have become quite used to approving OAuth2.0 consent flows. These integrations have opened up lots of incredibly useful doors for attackers to persist access and move laterally across SaaS apps that few incident response teams have run into yet. These tokens don’t expire when you reset passwords, aren’t protected by MFA, and actions they performed are rarely logged. ",{"data":61458,"content":61459,"nodeType":876},{},[61460],{"data":61461,"marks":61462,"value":61463,"nodeType":867},{},[],"These are not bugs or oversights but rather a consequence of how these APIs are intended to be used (by machines, not human adversaries).",{"data":61465,"content":61466,"nodeType":868},{},[61467],{"data":61468,"marks":61469,"value":61470,"nodeType":867},{},[],"Problems with observing SaaS attacks ",{"data":61472,"content":61473,"nodeType":876},{},[61474,61478,61483],{"data":61475,"marks":61476,"value":61477,"nodeType":867},{},[],"This research begs one question above others: ",{"data":61479,"marks":61480,"value":61482,"nodeType":867},{},[61481],{"type":1303},"“Are we seeing these attacks in the wild?",{"data":61484,"marks":61485,"value":61486,"nodeType":867},{},[],"” ",{"data":61488,"content":61489,"nodeType":1058},{},[61490],{"data":61491,"marks":61492,"value":61493,"nodeType":867},{},[],"Yes, definitely",{"data":61495,"content":61496,"nodeType":876},{},[61497,61501,61510,61513,61522,61526,61535,61538,61546,61550,61559],{"data":61498,"marks":61499,"value":61500,"nodeType":867},{},[],"For some of the better-known techniques, like credential stuffing and email phishing, the answer is an easy yes. Stats from ",{"data":61502,"content":61504,"nodeType":915},{"uri":61503},"https://www.microsoft.com/en-us/security/blog/2023/05/04/how-microsoft-can-help-you-go-passwordless-this-world-password-day/",[61505],{"data":61506,"marks":61507,"value":61509,"nodeType":867},{},[61508],{"type":913},"Microsoft (1,287 password attacks every second)",{"data":61511,"marks":61512,"value":1174,"nodeType":867},{},[],{"data":61514,"content":61516,"nodeType":915},{"uri":61515},"https://auth0.com/blog/top-insights-from-our-2022-state-of-secure-identity-report/",[61517],{"data":61518,"marks":61519,"value":61521,"nodeType":867},{},[61520],{"type":913},"Auth0 (a third of their traffic is credential stuffing)",{"data":61523,"marks":61524,"value":61525,"nodeType":867},{},[]," speaks volumes. Other sources like the ",{"data":61527,"content":61529,"nodeType":915},{"uri":61528},"https://www.gov.uk/government/statistics/cyber-security-breaches-survey-2022/cyber-security-breaches-survey-2022",[61530],{"data":61531,"marks":61532,"value":61534,"nodeType":867},{},[61533],{"type":913},"NCSC's Cyber Security Breaches Survey 2022",{"data":61536,"marks":61537,"value":25906,"nodeType":867},{},[],{"data":61539,"content":61540,"nodeType":915},{"uri":2177},[61541],{"data":61542,"marks":61543,"value":61545,"nodeType":867},{},[61544],{"type":913},"Verizon 2023 Data Breach Investigations Report",{"data":61547,"marks":61548,"value":61549,"nodeType":867},{},[]," suggest that phishing is also a major cause of SaaS breaches. Anecdotal reports from colleagues in the Incident Response field suggest that malicious mail forwarding rules are seen a lot, something which is supported by the ",{"data":61551,"content":61553,"nodeType":915},{"uri":61552},"https://expel.com/expel-quarterly-threat-report/",[61554],{"data":61555,"marks":61556,"value":61558,"nodeType":867},{},[61557],{"type":913},"Expel Quarterly Threat Report for Q1 2023",{"data":61560,"marks":61561,"value":61562,"nodeType":867},{},[]," (see page 6).",{"data":61564,"content":61565,"nodeType":876},{},[61566],{"data":61567,"marks":61568,"value":61569,"nodeType":867},{},[],"The takeaway is that the current focus for defenders should be to ensure users have good phishing-resistant account security in place — make sure you have basics like strong unique passwords and MFA in place across your entire SaaS estate.",{"data":61571,"content":61572,"nodeType":1058},{},[61573],{"data":61574,"marks":61575,"value":61576,"nodeType":867},{},[],"For newer OAuth attacks, it’s a lot less clear …",{"data":61578,"content":61579,"nodeType":876},{},[61580,61584,61589,61593,61602],{"data":61581,"marks":61582,"value":61583,"nodeType":867},{},[],"Other techniques like consent phishing have been discussed in some breach disclosures like the ",{"data":61585,"marks":61586,"value":61588,"nodeType":867},{},[61587],{"type":913},"2020 SANS breach",{"data":61590,"marks":61591,"value":61592,"nodeType":867},{},[],". These OAuth techniques also pop up in the news (for example, the ",{"data":61594,"content":61596,"nodeType":915},{"uri":61595},"https://www.bleepingcomputer.com/news/security/github-how-stolen-oauth-tokens-helped-breach-dozens-of-orgs/",[61597],{"data":61598,"marks":61599,"value":61601,"nodeType":867},{},[61600],{"type":913},"2022 Github/Heroku/Travis-CI breach",{"data":61603,"marks":61604,"value":61605,"nodeType":867},{},[]," where GitHub accounts were breached using stolen Heroku and Travis-CI OAuth tokens). ",{"data":61607,"content":61608,"nodeType":876},{},[61609,61613,61618],{"data":61610,"marks":61611,"value":61612,"nodeType":867},{},[],"That said, none of these techniques come up as frequently as their usefulness would suggest. This means one of two things: ",{"data":61614,"marks":61615,"value":61617,"nodeType":867},{},[61616],{"type":1303},"Either attackers aren’t yet using them widely, or they are and we aren’t detecting them",{"data":61619,"marks":61620,"value":1679,"nodeType":867},{},[],{"data":61622,"content":61623,"nodeType":876},{},[61624],{"data":61625,"marks":61626,"value":61627,"nodeType":867},{},[],"There is certainly a case to be made that attackers simply don’t need these newer techniques yet. Many organizations don’t have a way of discovering SaaS use in their organization yet, never mind breached accounts, so new persistence techniques might be a bit more than necessary at the moment.",{"data":61629,"content":61630,"nodeType":1058},{},[61631],{"data":61632,"marks":61633,"value":61634,"nodeType":867},{},[],"But would we know if it was happening?",{"data":61636,"content":61637,"nodeType":876},{},[61638],{"data":61639,"marks":61640,"value":61641,"nodeType":867},{},[],"On the other hand, there is certainly the possibility that these attacks are increasingly used, but are simply not being discovered. A strong argument in favor of this view is the difficulty in investigating these attacks. Very few SaaS apps provide enough logging capability to discover these attacks as a customer. This is true even for the biggest, most mature apps like Office 365 and Google Workspace unless you are on top license tiers. This is doubly true for attacks that use OAuth, with many apps providing no insight or details into actions made using OAuth-authenticated APIs. ",{"data":61643,"content":61644,"nodeType":876},{},[61645,61649,61658,61662,61671],{"data":61646,"marks":61647,"value":61648,"nodeType":867},{},[],"This suggests only the SaaS providers for these apps are really in a position to discover and investigate them. This does ring true when you consider that ",{"data":61650,"content":61652,"nodeType":915},{"uri":61651},"https://blog.heroku.com/april-2022-incident-review",[61653],{"data":61654,"marks":61655,"value":61657,"nodeType":867},{},[61656],{"type":913},"Heroku",{"data":61659,"marks":61660,"value":61661,"nodeType":867},{},[]," relied heavily on Github during the investigation (and in one case even the detection of) their 2022 breaches, and the same seems true for a similar breach affecting ",{"data":61663,"content":61665,"nodeType":915},{"uri":61664},"https://circleci.com/blog/jan-4-2023-incident-report/",[61666],{"data":61667,"marks":61668,"value":61670,"nodeType":867},{},[61669],{"type":913},"CircleCI",{"data":61672,"marks":61673,"value":61674,"nodeType":867},{},[]," later that year. Github and CircleCI’s customers prompted the investigation after seeing strange behavior, but Github had access to the logs to investigate. It’s difficult to imagine that most or even many SaaS vendors have the resources or inclination to run these investigations effectively as GitHub appears to have.",{"data":61676,"content":61677,"nodeType":876},{},[61678,61682,61692],{"data":61679,"marks":61680,"value":61681,"nodeType":867},{},[],"So, are these attacks happening in the real world? My best guess is it’s a little bit of column A and a little bit of column B — there are likely not so many of these attacks happening yet, and when they do, I suspect the vast majority go undetected. ",{"data":61683,"content":61685,"nodeType":915},{"uri":61684},"https://www.youtube.com/watch?v=j95kNwZw8YY",[61686],{"data":61687,"marks":61688,"value":61691,"nodeType":867},{},[61689,61690],{"type":913},{"type":1303},"But that’s just like my opinion, man.",{"data":61693,"marks":61694,"value":21,"nodeType":867},{},[],{"data":61696,"content":61697,"nodeType":876},{},[61698],{"data":61699,"marks":61700,"value":61701,"nodeType":867},{},[],"This is part of the reason we think enabling red teamers to try these techniques in anger is useful — this is the time-proven way to understand these risks.",{"data":61703,"content":61704,"nodeType":868},{},[61705],{"data":61706,"marks":61707,"value":61708,"nodeType":867},{},[],"What’s next?",{"data":61710,"content":61711,"nodeType":876},{},[61712],{"data":61713,"marks":61714,"value":61715,"nodeType":867},{},[],"We’ve barely scratched the surface, but perhaps there is enough here to get the discussion going. From past experience, discussion may not be enough, and it’s likely that live offensive work like penetration tests or more likely red team exercises will be required to make the risks of using these techniques real for the wider security community. ",{"data":61717,"content":61718,"nodeType":876},{},[61719],{"data":61720,"marks":61721,"value":61722,"nodeType":867},{},[],"After all, seeing is believing. We think some more practical examples and tools to help red  teamers use these techniques on engagements will help drive awareness forward, so we’ll be looking to build out this content.",{"data":61724,"content":61725,"nodeType":876},{},[61726,61730,61739],{"data":61727,"marks":61728,"value":61729,"nodeType":867},{},[],"We’ve started with pure networkless attacks that don’t touch customer networks or endpoints, but there are many useful techniques to connect the old endpoint world to the SaaS world. Consider stealing OAuth tokens from a thick client on an endpoint, or using a ",{"data":61731,"content":61733,"nodeType":915},{"uri":61732},"https://github.blog/2023-07-18-security-alert-social-engineering-campaign-targets-technology-industry-employees/",[61734],{"data":61735,"marks":61736,"value":61738,"nodeType":867},{},[61737],{"type":913},"backdoored GitHub repo to get code execution on endpoints",{"data":61740,"marks":61741,"value":1679,"nodeType":867},{},[],{"data":61743,"content":61744,"nodeType":876},{},[61745,61749,61756],{"data":61746,"marks":61747,"value":61748,"nodeType":867},{},[],"Help us all better understand how widespread these attacks are by sharing some war stories. We’d love some comments, discussions, or PRs on ",{"data":61750,"content":61751,"nodeType":915},{"uri":15408},[61752],{"data":61753,"marks":61754,"value":14515,"nodeType":867},{},[61755],{"type":913},{"data":61757,"marks":61758,"value":43095,"nodeType":867},{},[],{"data":61760,"content":61764,"nodeType":985},{"target":61761},{"sys":61762},{"id":61763,"type":982,"linkType":983},"2y0INxqAi594O7rCAVKhTI",[],{"data":61766,"content":61767,"nodeType":876},{},[61768],{"data":61769,"marks":61770,"value":21,"nodeType":867},{},[],"Let’s talk about SaaS attack techniques","Offensive security drives defensive security. We're sharing a collection of SaaS attack techniques to help defenders understand the threats they face.","2023-07-27T00:00:00.000Z","saas-attack-techniques",{"items":61776},[61777,61779],{"sys":61778,"name":4018},{"id":4017},{"sys":61780,"name":342},{"id":3240},{"items":61782},[61783],{"fullName":28592,"firstName":28593,"jobTitle":28594,"profilePicture":61784},{"url":28596},{"__typename":1772,"sys":61786,"content":61788,"title":62108,"synopsis":61805,"hashTags":59,"publishedDate":62109,"slug":62110,"tagsCollection":62111,"authorsCollection":62117},{"id":61787},"3m48a0kFoN8gh0IZQBup5U",{"json":61789},{"data":61790,"content":61791,"nodeType":1680},{},[61792,61798,61806,61818,61825,61832,61875,61881,61888,61895,61902,61909,61934,61941,61947,62019,62026,62033,62040,62046,62053,62060,62066,62073,62080,62086,62092],{"data":61793,"content":61797,"nodeType":985},{"target":61794},{"sys":61795},{"id":61796,"type":982,"linkType":983},"3OXZccsHUbm5vXq1Ouv9H8",[],{"data":61799,"content":61800,"nodeType":876},{},[61801],{"data":61802,"marks":61803,"value":61805,"nodeType":867},{},[61804],{"type":865},"Don’t leave it up to your employees to figure out how to use cloud apps securely. Guide them directly in their browsers when they access their apps.",{"data":61807,"content":61808,"nodeType":876},{},[61809,61813],{"data":61810,"marks":61811,"value":61812,"nodeType":867},{},[],"That’s the concept behind our latest feature, in-browser app banners. They allow you to",{"data":61814,"marks":61815,"value":61817,"nodeType":867},{},[61816],{"type":865}," create custom messages that guide employees to follow your security policies on the apps they use for work.",{"data":61819,"content":61820,"nodeType":876},{},[61821],{"data":61822,"marks":61823,"value":61824,"nodeType":867},{},[],"For example, at the top of this page you can see an app banner that tells employees using ChatGPT not to put company or customer data into the app, and provides a link to the company’s GenAI policy:",{"data":61826,"content":61827,"nodeType":876},{},[61828],{"data":61829,"marks":61830,"value":61831,"nodeType":867},{},[],"The banners are fully customizable, so you can enter whatever text you like. Here are a few ideas to get you started:",{"data":61833,"content":61834,"nodeType":1629},{},[61835,61845,61855,61865],{"data":61836,"content":61837,"nodeType":1586},{},[61838],{"data":61839,"content":61840,"nodeType":876},{},[61841],{"data":61842,"marks":61843,"value":61844,"nodeType":867},{},[],"Encourage employees to use an approved app over a new, unsupported alternative.",{"data":61846,"content":61847,"nodeType":1586},{},[61848],{"data":61849,"content":61850,"nodeType":876},{},[61851],{"data":61852,"marks":61853,"value":61854,"nodeType":867},{},[],"Remind employees not to enter sensitive information into ChatGPT or other GenAI tools.",{"data":61856,"content":61857,"nodeType":1586},{},[61858],{"data":61859,"content":61860,"nodeType":876},{},[61861],{"data":61862,"marks":61863,"value":61864,"nodeType":867},{},[],"Tell employees not to use an app until it can be reviewed by the security team.",{"data":61866,"content":61867,"nodeType":1586},{},[61868],{"data":61869,"content":61870,"nodeType":876},{},[61871],{"data":61872,"marks":61873,"value":61874,"nodeType":867},{},[],"Ask employees to use their federated identity on apps supporting SSO.",{"data":61876,"content":61880,"nodeType":985},{"target":61877},{"sys":61878},{"id":61879,"type":982,"linkType":983},"6XuJbfjhrr9JDKY6fcD5hZ",[],{"data":61882,"content":61883,"nodeType":868},{},[61884],{"data":61885,"marks":61886,"value":61887,"nodeType":867},{},[],"Why did we build it?",{"data":61889,"content":61890,"nodeType":876},{},[61891],{"data":61892,"marks":61893,"value":61894,"nodeType":867},{},[],"We co-created this feature with our customers. They wanted a more flexible and nuanced way of managing the risks associated with using SaaS apps than just allowlisting or blocklisting apps. ",{"data":61896,"content":61897,"nodeType":876},{},[61898],{"data":61899,"marks":61900,"value":61901,"nodeType":867},{},[],"That means guiding employees to use apps more safely rather than just blocking new tools by default.",{"data":61903,"content":61904,"nodeType":876},{},[61905],{"data":61906,"marks":61907,"value":61908,"nodeType":867},{},[],"Now don’t get us wrong — there’s a time and a place for blocking. But for most organizations, there are more scenarios when it's better to help employees do something safely. ",{"data":61910,"content":61911,"nodeType":876},{},[61912,61916,61921,61925,61930],{"data":61913,"marks":61914,"value":61915,"nodeType":867},{},[],"That’s the reason why we ",{"data":61917,"marks":61918,"value":61920,"nodeType":867},{},[61919],{"type":1303},"wanted",{"data":61922,"marks":61923,"value":61924,"nodeType":867},{},[]," to build the feature. The reason we were ",{"data":61926,"marks":61927,"value":61929,"nodeType":867},{},[61928],{"type":1303},"able",{"data":61931,"marks":61932,"value":61933,"nodeType":867},{},[]," to build it is because Push’s superpower is a browser extension that detects signups and logins to supported and unsupported apps, and then helps you manage and secure accounts and identities on all of them. ",{"data":61935,"content":61936,"nodeType":876},{},[61937],{"data":61938,"marks":61939,"value":61940,"nodeType":867},{},[],"The Push browser extension gets you the closest to the user, providing the ideal platform for security teams to guide employees at exactly the right time and place — when they’re accessing an app in their browser.",{"data":61942,"content":61943,"nodeType":868},{},[61944],{"data":61945,"marks":61946,"value":59803,"nodeType":867},{},[],{"data":61948,"content":61949,"nodeType":62018},{},[61950,61960,61970,61989,62008],{"data":61951,"content":61952,"nodeType":1586},{},[61953],{"data":61954,"content":61955,"nodeType":876},{},[61956],{"data":61957,"marks":61958,"value":61959,"nodeType":867},{},[],"You can configure an app banner in less than 1 minute. Here are the 4 steps, or just scroll down to the demos below to see for yourself. ",{"data":61961,"content":61962,"nodeType":1586},{},[61963],{"data":61964,"content":61965,"nodeType":876},{},[61966],{"data":61967,"marks":61968,"value":61969,"nodeType":867},{},[],"Find an app in your app inventory on the Push platform.",{"data":61971,"content":61972,"nodeType":1586},{},[61973],{"data":61974,"content":61975,"nodeType":876},{},[61976,61980,61985],{"data":61977,"marks":61978,"value":61979,"nodeType":867},{},[],"Hit ",{"data":61981,"marks":61982,"value":61984,"nodeType":867},{},[61983],{"type":865},"Configure on the app details slideout",{"data":61986,"marks":61987,"value":61988,"nodeType":867},{},[],", and then add your custom banner message. ",{"data":61990,"content":61991,"nodeType":1586},{},[61992],{"data":61993,"content":61994,"nodeType":876},{},[61995,61999,62004],{"data":61996,"marks":61997,"value":61998,"nodeType":867},{},[],"Use the ",{"data":62000,"marks":62001,"value":62003,"nodeType":867},{},[62002],{"type":865},"Preview",{"data":62005,"marks":62006,"value":62007,"nodeType":867},{},[]," button to see what it will look like. ",{"data":62009,"content":62010,"nodeType":1586},{},[62011],{"data":62012,"content":62013,"nodeType":876},{},[62014],{"data":62015,"marks":62016,"value":62017,"nodeType":867},{},[],"Then once you're happy, save it to enable it on the signup and login pages for that app. Now your banner will appear every time an employee accesses the app using a browser with the Push browser extension on it. ","ordered-list",{"data":62020,"content":62021,"nodeType":868},{},[62022],{"data":62023,"marks":62024,"value":62025,"nodeType":867},{},[],"Use case inspo",{"data":62027,"content":62028,"nodeType":1058},{},[62029],{"data":62030,"marks":62031,"value":62032,"nodeType":867},{},[],"Help employees use ChatGPT and GenAI apps safely",{"data":62034,"content":62035,"nodeType":876},{},[62036],{"data":62037,"marks":62038,"value":62039,"nodeType":867},{},[],"Lots of security teams we speak to are happy for their employees to use GenAI apps like ChatGPT, as long as no sensitive data goes into them. Here we create a banner telling employees not to share sensitive information and to read the GenAI policy to understand how to use apps like this securely.",{"data":62041,"content":62045,"nodeType":985},{"target":62042},{"sys":62043},{"id":62044,"type":982,"linkType":983},"N6E38qUzEe8fNvpoJwBXH",[],{"data":62047,"content":62048,"nodeType":1058},{},[62049],{"data":62050,"marks":62051,"value":62052,"nodeType":867},{},[],"Guide your employees toward approved apps and prevent SaaS sprawl",{"data":62054,"content":62055,"nodeType":876},{},[62056],{"data":62057,"marks":62058,"value":62059,"nodeType":867},{},[],"You’ll probably prefer that your employees use approved and supported apps, and not to self-adopt new duplicate apps that contribute to SaaS sprawl. Here we use a banner to tell employees to use an approved file-sharing app.",{"data":62061,"content":62065,"nodeType":985},{"target":62062},{"sys":62063},{"id":62064,"type":982,"linkType":983},"2VhggiMOWCu9ZXqh4U7pZ9",[],{"data":62067,"content":62068,"nodeType":1058},{},[62069],{"data":62070,"marks":62071,"value":62072,"nodeType":867},{},[],"Encourage employees to use their federated identities instead of creating shadow identities",{"data":62074,"content":62075,"nodeType":876},{},[62076],{"data":62077,"marks":62078,"value":62079,"nodeType":867},{},[],"If you’ve invested in an SSO solution like Okta, you probably want to get as many of your apps and accounts behind it as possible. This banner tells employees to access the app using their Okta federated identity rather than using or creating a local account. ",{"data":62081,"content":62085,"nodeType":985},{"target":62082},{"sys":62083},{"id":62084,"type":982,"linkType":983},"6cJcIJ8GpsioU6JQs3afxy",[],{"data":62087,"content":62088,"nodeType":868},{},[62089],{"data":62090,"marks":62091,"value":25228,"nodeType":867},{},[],{"data":62093,"content":62094,"nodeType":876},{},[62095,62098,62104],{"data":62096,"marks":62097,"value":44966,"nodeType":867},{},[],{"data":62099,"content":62100,"nodeType":915},{"uri":5286},[62101],{"data":62102,"marks":62103,"value":11707,"nodeType":867},{},[],{"data":62105,"marks":62106,"value":62107,"nodeType":867},{},[],". We’ll be happy to show you this feature along with how we discover all the apps your employees are using and how we detect vulnerable identities. ","Introducing in-browser app banners: Set guardrails for cloud apps","2024-02-06T00:00:00.000Z","introducing-in-browser-app-banners-set-guardrails-for-cloud-apps",{"items":62112},[62113,62115],{"sys":62114,"name":297},{"id":2706},{"sys":62116,"name":39245},{"id":39244},{"items":62118},[62119],{"fullName":4089,"firstName":4090,"jobTitle":851,"profilePicture":62120},{"url":4094},"5-ways-to-defeat-identity-based-attacks","blog/5-ways-to-defeat-identity-based-attacks",{"json":62124},{"data":62125,"content":62126,"nodeType":1680},{},[62127,62134],{"data":62128,"content":62129,"nodeType":876},{},[62130],{"data":62131,"marks":62132,"value":62133,"nodeType":867},{},[],"In today's digital world, identities are the new frontier for attackers seeking to breach organizational perimeters. As the attack surface evolves, so too must our strategies for defending against threats. Below are five key tactics to bolster your defenses and thwart identity-based attacks.",{"data":62135,"content":62136,"nodeType":876},{},[62137],{"data":62138,"marks":62139,"value":21,"nodeType":867},{},[],"In this blog post we will cover what identities are, how we secure perimeters in general, and and how this maps to the identity space.\n",{"id":62142,"publishedAt":62143},"6rflXTFCRMvmM8JU8ZPSCt","2026-08-13T09:35:17.592Z",{"items":62145},[62146,62148],{"sys":62147,"name":297},{"id":2706},{"sys":62149,"name":342},{"id":3240},{"items":62151},[62152,62154,62156,62158,62160,62162,62164,62166,62168,62170,62172,62174,62176,62178,62180,62182],{"sys":62153,"name":413,"slug":414,"tier":31},{"id":410},{"sys":62155,"name":297,"slug":298,"tier":31},{"id":294},{"sys":62157,"name":279,"slug":280,"tier":31},{"id":276},{"sys":62159,"name":342,"slug":343,"tier":31},{"id":339},{"sys":62161,"name":642,"slug":643,"tier":31},{"id":639},{"sys":62163,"name":545,"slug":546,"tier":31},{"id":542},{"sys":62165,"name":519,"slug":520,"tier":31},{"id":516},{"sys":62167,"name":404,"slug":405,"tier":45},{"id":401},{"sys":62169,"name":457,"slug":458,"tier":45},{"id":454},{"sys":62171,"name":502,"slug":503,"tier":45},{"id":499},{"sys":62173,"name":333,"slug":334,"tier":45},{"id":330},{"sys":62175,"name":324,"slug":325,"tier":45},{"id":321},{"sys":62177,"name":395,"slug":396,"tier":45},{"id":392},{"sys":62179,"name":484,"slug":485,"tier":45},{"id":481},{"sys":62181,"name":377,"slug":378,"tier":45},{"id":374},{"sys":62183,"name":589,"slug":590,"tier":45},{"id":586},"x99zaD4EVCYXTHcUTO7CXoPmpf4jFF3hUI-D9JUGi2Q",{"id":62186,"title":61771,"authorsCollection":62187,"content":62192,"extension":228,"faqItemsCollection":62877,"faqTitle":59,"featured":6,"hashTags":59,"meta":62879,"metaTitle":62880,"ogImage":59,"postType":21733,"publishedDate":61773,"relatedBlogPostsCollection":62881,"slug":61774,"stem":66928,"subtitle":59,"summary":66929,"synopsis":61772,"sys":66939,"tagsCollection":66941,"topicsCollection":66947,"__hash__":66977},"blog/blog/saas-attack-techniques.json",{"items":62188},[62189],{"fullName":28592,"firstName":28593,"jobTitle":28594,"socialLinks":62190,"profilePicture":62191},[60264],{"url":28596},{"json":62193,"links":62855},{"data":62194,"content":62195,"nodeType":1680},{},[62196,62202,62208,62214,62220,62226,62232,62237,62253,62259,62295,62301,62307,62343,62359,62365,62371,62377,62393,62409,62415,62445,62451,62467,62473,62479,62505,62521,62527,62532,62538,62544,62550,62556,62562,62568,62574,62580,62586,62592,62598,62604,62617,62623,62679,62685,62691,62714,62727,62733,62739,62745,62771,62788,62794,62800,62806,62812,62828,62844,62849],{"data":62197,"content":62198,"nodeType":876},{},[62199],{"data":62200,"marks":62201,"value":61002,"nodeType":867},{},[],{"data":62203,"content":62204,"nodeType":876},{},[62205],{"data":62206,"marks":62207,"value":61009,"nodeType":867},{},[],{"data":62209,"content":62210,"nodeType":876},{},[62211],{"data":62212,"marks":62213,"value":61016,"nodeType":867},{},[],{"data":62215,"content":62216,"nodeType":876},{},[62217],{"data":62218,"marks":62219,"value":61023,"nodeType":867},{},[],{"data":62221,"content":62222,"nodeType":868},{},[62223],{"data":62224,"marks":62225,"value":61030,"nodeType":867},{},[],{"data":62227,"content":62228,"nodeType":876},{},[62229],{"data":62230,"marks":62231,"value":61037,"nodeType":867},{},[],{"data":62233,"content":62236,"nodeType":985},{"target":62234},{"sys":62235},{"id":61042,"type":982,"linkType":983},[],{"data":62238,"content":62239,"nodeType":876},{},[62240,62243,62250],{"data":62241,"marks":62242,"value":61050,"nodeType":867},{},[],{"data":62244,"content":62245,"nodeType":915},{"uri":15408},[62246],{"data":62247,"marks":62248,"value":14515,"nodeType":867},{},[62249],{"type":913},{"data":62251,"marks":62252,"value":1679,"nodeType":867},{},[],{"data":62254,"content":62255,"nodeType":876},{},[62256],{"data":62257,"marks":62258,"value":61067,"nodeType":867},{},[],{"data":62260,"content":62261,"nodeType":876},{},[62262,62265,62272,62275,62282,62285,62292],{"data":62263,"marks":62264,"value":61074,"nodeType":867},{},[],{"data":62266,"content":62267,"nodeType":915},{"uri":35191},[62268],{"data":62269,"marks":62270,"value":61082,"nodeType":867},{},[62271],{"type":913},{"data":62273,"marks":62274,"value":1174,"nodeType":867},{},[],{"data":62276,"content":62277,"nodeType":915},{"uri":61088},[62278],{"data":62279,"marks":62280,"value":61094,"nodeType":867},{},[62281],{"type":913},{"data":62283,"marks":62284,"value":61098,"nodeType":867},{},[],{"data":62286,"content":62287,"nodeType":915},{"uri":42831},[62288],{"data":62289,"marks":62290,"value":61106,"nodeType":867},{},[62291],{"type":913},{"data":62293,"marks":62294,"value":61110,"nodeType":867},{},[],{"data":62296,"content":62297,"nodeType":876},{},[62298],{"data":62299,"marks":62300,"value":61117,"nodeType":867},{},[],{"data":62302,"content":62303,"nodeType":1058},{},[62304],{"data":62305,"marks":62306,"value":61124,"nodeType":867},{},[],{"data":62308,"content":62309,"nodeType":876},{},[62310,62313,62320,62323,62330,62333,62340],{"data":62311,"marks":62312,"value":61131,"nodeType":867},{},[],{"data":62314,"content":62315,"nodeType":915},{"uri":42200},[62316],{"data":62317,"marks":62318,"value":37948,"nodeType":867},{},[62319],{"type":913},{"data":62321,"marks":62322,"value":1174,"nodeType":867},{},[],{"data":62324,"content":62325,"nodeType":915},{"uri":42211},[62326],{"data":62327,"marks":62328,"value":42216,"nodeType":867},{},[62329],{"type":913},{"data":62331,"marks":62332,"value":61152,"nodeType":867},{},[],{"data":62334,"content":62335,"nodeType":915},{"uri":42879},[62336],{"data":62337,"marks":62338,"value":61160,"nodeType":867},{},[62339],{"type":913},{"data":62341,"marks":62342,"value":61164,"nodeType":867},{},[],{"data":62344,"content":62345,"nodeType":876},{},[62346,62349,62356],{"data":62347,"marks":62348,"value":61171,"nodeType":867},{},[],{"data":62350,"content":62351,"nodeType":915},{"uri":61174},[62352],{"data":62353,"marks":62354,"value":61180,"nodeType":867},{},[62355],{"type":913},{"data":62357,"marks":62358,"value":61184,"nodeType":867},{},[],{"data":62360,"content":62361,"nodeType":876},{},[62362],{"data":62363,"marks":62364,"value":61191,"nodeType":867},{},[],{"data":62366,"content":62367,"nodeType":876},{},[62368],{"data":62369,"marks":62370,"value":61198,"nodeType":867},{},[],{"data":62372,"content":62373,"nodeType":1058},{},[62374],{"data":62375,"marks":62376,"value":61205,"nodeType":867},{},[],{"data":62378,"content":62379,"nodeType":876},{},[62380,62383,62390],{"data":62381,"marks":62382,"value":61212,"nodeType":867},{},[],{"data":62384,"content":62385,"nodeType":915},{"uri":61215},[62386],{"data":62387,"marks":62388,"value":61221,"nodeType":867},{},[62389],{"type":913},{"data":62391,"marks":62392,"value":61225,"nodeType":867},{},[],{"data":62394,"content":62395,"nodeType":876},{},[62396,62399,62406],{"data":62397,"marks":62398,"value":61232,"nodeType":867},{},[],{"data":62400,"content":62401,"nodeType":915},{"uri":42265},[62402],{"data":62403,"marks":62404,"value":42789,"nodeType":867},{},[62405],{"type":913},{"data":62407,"marks":62408,"value":61243,"nodeType":867},{},[],{"data":62410,"content":62411,"nodeType":876},{},[62412],{"data":62413,"marks":62414,"value":61250,"nodeType":867},{},[],{"data":62416,"content":62417,"nodeType":1629},{},[62418,62427,62436],{"data":62419,"content":62420,"nodeType":1586},{},[62421],{"data":62422,"content":62423,"nodeType":876},{},[62424],{"data":62425,"marks":62426,"value":61263,"nodeType":867},{},[],{"data":62428,"content":62429,"nodeType":1586},{},[62430],{"data":62431,"content":62432,"nodeType":876},{},[62433],{"data":62434,"marks":62435,"value":61273,"nodeType":867},{},[],{"data":62437,"content":62438,"nodeType":1586},{},[62439],{"data":62440,"content":62441,"nodeType":876},{},[62442],{"data":62443,"marks":62444,"value":61283,"nodeType":867},{},[],{"data":62446,"content":62447,"nodeType":876},{},[62448],{"data":62449,"marks":62450,"value":61290,"nodeType":867},{},[],{"data":62452,"content":62453,"nodeType":876},{},[62454,62457,62464],{"data":62455,"marks":62456,"value":61297,"nodeType":867},{},[],{"data":62458,"content":62459,"nodeType":915},{"uri":61300},[62460],{"data":62461,"marks":62462,"value":61306,"nodeType":867},{},[62463],{"type":913},{"data":62465,"marks":62466,"value":61310,"nodeType":867},{},[],{"data":62468,"content":62469,"nodeType":1058},{},[62470],{"data":62471,"marks":62472,"value":61317,"nodeType":867},{},[],{"data":62474,"content":62475,"nodeType":876},{},[62476],{"data":62477,"marks":62478,"value":61324,"nodeType":867},{},[],{"data":62480,"content":62481,"nodeType":876},{},[62482,62485,62492,62495,62502],{"data":62483,"marks":62484,"value":61331,"nodeType":867},{},[],{"data":62486,"content":62487,"nodeType":915},{"uri":61334},[62488],{"data":62489,"marks":62490,"value":61340,"nodeType":867},{},[62491],{"type":913},{"data":62493,"marks":62494,"value":1174,"nodeType":867},{},[],{"data":62496,"content":62497,"nodeType":915},{"uri":26236},[62498],{"data":62499,"marks":62500,"value":2929,"nodeType":867},{},[62501],{"type":913},{"data":62503,"marks":62504,"value":61354,"nodeType":867},{},[],{"data":62506,"content":62507,"nodeType":876},{},[62508,62511,62518],{"data":62509,"marks":62510,"value":61361,"nodeType":867},{},[],{"data":62512,"content":62513,"nodeType":915},{"uri":61364},[62514],{"data":62515,"marks":62516,"value":61370,"nodeType":867},{},[62517],{"type":913},{"data":62519,"marks":62520,"value":61374,"nodeType":867},{},[],{"data":62522,"content":62523,"nodeType":876},{},[62524],{"data":62525,"marks":62526,"value":61381,"nodeType":867},{},[],{"data":62528,"content":62531,"nodeType":985},{"target":62529},{"sys":62530},{"id":38653,"type":982,"linkType":983},[],{"data":62533,"content":62534,"nodeType":868},{},[62535],{"data":62536,"marks":62537,"value":61393,"nodeType":867},{},[],{"data":62539,"content":62540,"nodeType":876},{},[62541],{"data":62542,"marks":62543,"value":61400,"nodeType":867},{},[],{"data":62545,"content":62546,"nodeType":876},{},[62547],{"data":62548,"marks":62549,"value":61407,"nodeType":867},{},[],{"data":62551,"content":62552,"nodeType":1058},{},[62553],{"data":62554,"marks":62555,"value":61414,"nodeType":867},{},[],{"data":62557,"content":62558,"nodeType":876},{},[62559],{"data":62560,"marks":62561,"value":61421,"nodeType":867},{},[],{"data":62563,"content":62564,"nodeType":876},{},[62565],{"data":62566,"marks":62567,"value":61428,"nodeType":867},{},[],{"data":62569,"content":62570,"nodeType":876},{},[62571],{"data":62572,"marks":62573,"value":61435,"nodeType":867},{},[],{"data":62575,"content":62576,"nodeType":1058},{},[62577],{"data":62578,"marks":62579,"value":61442,"nodeType":867},{},[],{"data":62581,"content":62582,"nodeType":876},{},[62583],{"data":62584,"marks":62585,"value":61449,"nodeType":867},{},[],{"data":62587,"content":62588,"nodeType":876},{},[62589],{"data":62590,"marks":62591,"value":61456,"nodeType":867},{},[],{"data":62593,"content":62594,"nodeType":876},{},[62595],{"data":62596,"marks":62597,"value":61463,"nodeType":867},{},[],{"data":62599,"content":62600,"nodeType":868},{},[62601],{"data":62602,"marks":62603,"value":61470,"nodeType":867},{},[],{"data":62605,"content":62606,"nodeType":876},{},[62607,62610,62614],{"data":62608,"marks":62609,"value":61477,"nodeType":867},{},[],{"data":62611,"marks":62612,"value":61482,"nodeType":867},{},[62613],{"type":1303},{"data":62615,"marks":62616,"value":61486,"nodeType":867},{},[],{"data":62618,"content":62619,"nodeType":1058},{},[62620],{"data":62621,"marks":62622,"value":61493,"nodeType":867},{},[],{"data":62624,"content":62625,"nodeType":876},{},[62626,62629,62636,62639,62646,62649,62656,62659,62666,62669,62676],{"data":62627,"marks":62628,"value":61500,"nodeType":867},{},[],{"data":62630,"content":62631,"nodeType":915},{"uri":61503},[62632],{"data":62633,"marks":62634,"value":61509,"nodeType":867},{},[62635],{"type":913},{"data":62637,"marks":62638,"value":1174,"nodeType":867},{},[],{"data":62640,"content":62641,"nodeType":915},{"uri":61515},[62642],{"data":62643,"marks":62644,"value":61521,"nodeType":867},{},[62645],{"type":913},{"data":62647,"marks":62648,"value":61525,"nodeType":867},{},[],{"data":62650,"content":62651,"nodeType":915},{"uri":61528},[62652],{"data":62653,"marks":62654,"value":61534,"nodeType":867},{},[62655],{"type":913},{"data":62657,"marks":62658,"value":25906,"nodeType":867},{},[],{"data":62660,"content":62661,"nodeType":915},{"uri":2177},[62662],{"data":62663,"marks":62664,"value":61545,"nodeType":867},{},[62665],{"type":913},{"data":62667,"marks":62668,"value":61549,"nodeType":867},{},[],{"data":62670,"content":62671,"nodeType":915},{"uri":61552},[62672],{"data":62673,"marks":62674,"value":61558,"nodeType":867},{},[62675],{"type":913},{"data":62677,"marks":62678,"value":61562,"nodeType":867},{},[],{"data":62680,"content":62681,"nodeType":876},{},[62682],{"data":62683,"marks":62684,"value":61569,"nodeType":867},{},[],{"data":62686,"content":62687,"nodeType":1058},{},[62688],{"data":62689,"marks":62690,"value":61576,"nodeType":867},{},[],{"data":62692,"content":62693,"nodeType":876},{},[62694,62697,62701,62704,62711],{"data":62695,"marks":62696,"value":61583,"nodeType":867},{},[],{"data":62698,"marks":62699,"value":61588,"nodeType":867},{},[62700],{"type":913},{"data":62702,"marks":62703,"value":61592,"nodeType":867},{},[],{"data":62705,"content":62706,"nodeType":915},{"uri":61595},[62707],{"data":62708,"marks":62709,"value":61601,"nodeType":867},{},[62710],{"type":913},{"data":62712,"marks":62713,"value":61605,"nodeType":867},{},[],{"data":62715,"content":62716,"nodeType":876},{},[62717,62720,62724],{"data":62718,"marks":62719,"value":61612,"nodeType":867},{},[],{"data":62721,"marks":62722,"value":61617,"nodeType":867},{},[62723],{"type":1303},{"data":62725,"marks":62726,"value":1679,"nodeType":867},{},[],{"data":62728,"content":62729,"nodeType":876},{},[62730],{"data":62731,"marks":62732,"value":61627,"nodeType":867},{},[],{"data":62734,"content":62735,"nodeType":1058},{},[62736],{"data":62737,"marks":62738,"value":61634,"nodeType":867},{},[],{"data":62740,"content":62741,"nodeType":876},{},[62742],{"data":62743,"marks":62744,"value":61641,"nodeType":867},{},[],{"data":62746,"content":62747,"nodeType":876},{},[62748,62751,62758,62761,62768],{"data":62749,"marks":62750,"value":61648,"nodeType":867},{},[],{"data":62752,"content":62753,"nodeType":915},{"uri":61651},[62754],{"data":62755,"marks":62756,"value":61657,"nodeType":867},{},[62757],{"type":913},{"data":62759,"marks":62760,"value":61661,"nodeType":867},{},[],{"data":62762,"content":62763,"nodeType":915},{"uri":61664},[62764],{"data":62765,"marks":62766,"value":61670,"nodeType":867},{},[62767],{"type":913},{"data":62769,"marks":62770,"value":61674,"nodeType":867},{},[],{"data":62772,"content":62773,"nodeType":876},{},[62774,62777,62785],{"data":62775,"marks":62776,"value":61681,"nodeType":867},{},[],{"data":62778,"content":62779,"nodeType":915},{"uri":61684},[62780],{"data":62781,"marks":62782,"value":61691,"nodeType":867},{},[62783,62784],{"type":913},{"type":1303},{"data":62786,"marks":62787,"value":21,"nodeType":867},{},[],{"data":62789,"content":62790,"nodeType":876},{},[62791],{"data":62792,"marks":62793,"value":61701,"nodeType":867},{},[],{"data":62795,"content":62796,"nodeType":868},{},[62797],{"data":62798,"marks":62799,"value":61708,"nodeType":867},{},[],{"data":62801,"content":62802,"nodeType":876},{},[62803],{"data":62804,"marks":62805,"value":61715,"nodeType":867},{},[],{"data":62807,"content":62808,"nodeType":876},{},[62809],{"data":62810,"marks":62811,"value":61722,"nodeType":867},{},[],{"data":62813,"content":62814,"nodeType":876},{},[62815,62818,62825],{"data":62816,"marks":62817,"value":61729,"nodeType":867},{},[],{"data":62819,"content":62820,"nodeType":915},{"uri":61732},[62821],{"data":62822,"marks":62823,"value":61738,"nodeType":867},{},[62824],{"type":913},{"data":62826,"marks":62827,"value":1679,"nodeType":867},{},[],{"data":62829,"content":62830,"nodeType":876},{},[62831,62834,62841],{"data":62832,"marks":62833,"value":61748,"nodeType":867},{},[],{"data":62835,"content":62836,"nodeType":915},{"uri":15408},[62837],{"data":62838,"marks":62839,"value":14515,"nodeType":867},{},[62840],{"type":913},{"data":62842,"marks":62843,"value":43095,"nodeType":867},{},[],{"data":62845,"content":62848,"nodeType":985},{"target":62846},{"sys":62847},{"id":61763,"type":982,"linkType":983},[],{"data":62850,"content":62851,"nodeType":876},{},[62852],{"data":62853,"marks":62854,"value":21,"nodeType":867},{},[],{"entries":62856},{"hyperlink":62857,"inline":62858,"block":62859},[],[],[62860,62868,62872],{"sys":62861,"__typename":1688,"title":14765,"caption":62862,"layoutMode":62863,"file":62864},{"id":61042},"SaaS attack matrix demonstrated networkless attacks that bypass EDR and network detection","Centre aligned",{"url":62865,"width":62866,"height":62867},"https://images.ctfassets.net/y1cdw1ablpvd/3UQoGrBeM5nF6Hya80S92f/541273f45d41a07363dff5523d284cdf/Screenshot_2024-06-05_at_09.56.39.png",2278,1034,{"sys":62869,"__typename":1697,"type":51810,"ctaText":62870,"buttonLabel":62871,"buttonColour":1701,"buttonUrl":59},{"id":38653},"Learn how Push can help you secure identities across your org","Book a demo!",{"sys":62873,"__typename":1697,"type":37820,"ctaText":62874,"buttonLabel":62875,"buttonColour":62876,"buttonUrl":59},{"id":61763},"See more original research and technical content from Push","Follow us on LinkedIn","orange",{"items":62878},[],{},"SaaS attack techniques",{"items":62882},[62883,63778,64245],{"__typename":1772,"sys":62884,"content":62886,"title":63765,"synopsis":62896,"hashTags":59,"publishedDate":63766,"slug":63767,"tagsCollection":63768,"authorsCollection":63774},{"id":62885},"7ygI4NLJ2zpuiVwAlggkTG",{"json":62887},{"data":62888,"content":62889,"nodeType":1680},{},[62890,62897,62904,62935,62942,62949,62968,62975,62982,62989,63017,63024,63031,63047,63054,63061,63094,63101,63108,63115,63122,63129,63135,63142,63149,63156,63164,63171,63191,63198,63205,63212,63219,63226,63233,63240,63247,63254,63260,63267,63286,63293,63312,63318,63324,63330,63337,63344,63351,63357,63363,63370,63377,63384,63391,63398,63404,63424,63443,63450,63456,63462,63469,63476,63483,63490,63513,63519,63525,63532,63539,63546,63557,63563,63570,63576,63582,63589,63596,63603,63609,63615,63622,63629,63745,63751,63758],{"data":62891,"content":62892,"nodeType":876},{},[62893],{"data":62894,"marks":62895,"value":62896,"nodeType":867},{},[],"In this article, we’re going to demonstrate how combining two of our favorite new SaaS attack techniques makes a simple, but very stealthy persistence approach.",{"data":62898,"content":62899,"nodeType":876},{},[62900],{"data":62901,"marks":62902,"value":62903,"nodeType":867},{},[],"—----",{"data":62905,"content":62906,"nodeType":876},{},[62907,62911,62918,62922,62932],{"data":62908,"marks":62909,"value":62910,"nodeType":867},{},[],"This is the second post in a series on attack chains formed by combining techniques in the ",{"data":62912,"content":62913,"nodeType":915},{"uri":15408},[62914],{"data":62915,"marks":62916,"value":14765,"nodeType":867},{},[62917],{"type":913},{"data":62919,"marks":62920,"value":62921,"nodeType":867},{},[],". Last post we wrote about ",{"data":62923,"content":62926,"nodeType":17452},{"target":62924},{"sys":62925},{"id":60067,"type":982,"linkType":983},[62927],{"data":62928,"marks":62929,"value":62931,"nodeType":867},{},[62930],{"type":913},"SAMLjacking a poisoned tenant",{"data":62933,"marks":62934,"value":5704,"nodeType":867},{},[],{"data":62936,"content":62937,"nodeType":876},{},[62938],{"data":62939,"marks":62940,"value":62941,"nodeType":867},{},[],"This time we’ll be looking at combining shadow workflows with an evil twin integration for an especially sneaky and flexible method of persistence. We’ll be using Zapier integrating with Azure as our primary example. ",{"data":62943,"content":62944,"nodeType":868},{},[62945],{"data":62946,"marks":62947,"value":62948,"nodeType":867},{},[],"What is a shadow workflow?",{"data":62950,"content":62951,"nodeType":876},{},[62952,62956,62964],{"data":62953,"marks":62954,"value":62955,"nodeType":867},{},[],"A ",{"data":62957,"content":62958,"nodeType":915},{"uri":42265},[62959],{"data":62960,"marks":62961,"value":62963,"nodeType":867},{},[62962],{"type":913},"shadow workflow ",{"data":62965,"marks":62966,"value":62967,"nodeType":867},{},[],"is a technique for using SaaS automation apps to provide a code execution-like method for conducting malicious actions from a legitimate source using OAuth integrations. This could be a daily export of files from shared cloud drives, automatic forwarding and deleting of emails, cloning instant messages, exporting user directories — basically anything that is possible using the target app’s API. ",{"data":62969,"content":62970,"nodeType":876},{},[62971],{"data":62972,"marks":62973,"value":62974,"nodeType":867},{},[],"The fact automation apps utilize OAuth integrations means they also function as a very effective method of maintaining persistence. Think of shadow workflows as the offensive PowerShell of the SaaS world. ",{"data":62976,"content":62977,"nodeType":868},{},[62978],{"data":62979,"marks":62980,"value":62981,"nodeType":867},{},[],"What’s an evil twin integration?",{"data":62983,"content":62984,"nodeType":876},{},[62985],{"data":62986,"marks":62987,"value":62988,"nodeType":867},{},[],"Creating a new OAuth integration, even if using a legitimate SaaS application, could be viewed as suspicious if seen by a security team or the affected user. This is especially true if an account compromise is discovered and an IR team sees a consent for a new OAuth integration in the log that the compromised user does not recognize. ",{"data":62990,"content":62991,"nodeType":876},{},[62992,62996,63003,63007,63013],{"data":62993,"marks":62994,"value":62995,"nodeType":867},{},[],"An ",{"data":62997,"content":62998,"nodeType":915},{"uri":61300},[62999],{"data":63000,"marks":63001,"value":61306,"nodeType":867},{},[63002],{"type":913},{"data":63004,"marks":63005,"value":63006,"nodeType":867},{},[],", however, reduces the chances of discovery by reusing an existing ",{"data":63008,"marks":63009,"value":63012,"nodeType":867},{},[63010,63011],{"type":1303},{"type":865},"legitimate",{"data":63014,"marks":63015,"value":63016,"nodeType":867},{},[]," integration for malicious purposes.",{"data":63018,"content":63019,"nodeType":868},{},[63020],{"data":63021,"marks":63022,"value":63023,"nodeType":867},{},[],"What’s the benefit of combining them?",{"data":63025,"content":63026,"nodeType":876},{},[63027],{"data":63028,"marks":63029,"value":63030,"nodeType":867},{},[],"While shadow workflows are incredibly powerful on their own, as malicious use of OAuth integrations becomes more common, security teams will start regularly checking for new, or unknown, integrations in response to security incidents. While automation apps are legitimate SaaS services, shadow workflow attacks could still raise question marks during incident response if it’s connected shortly after a compromise and/or if the affected user has no knowledge of it. ",{"data":63032,"content":63033,"nodeType":876},{},[63034,63038,63043],{"data":63035,"marks":63036,"value":63037,"nodeType":867},{},[],"Additionally, as use of security tools that ",{"data":63039,"marks":63040,"value":63042,"nodeType":867},{},[63041],{"type":913},"provide visibility of OAuth integrations",{"data":63044,"marks":63045,"value":63046,"nodeType":867},{},[]," (check out our product) increases, it will become increasingly dangerous for an adversary to create a new OAuth integration. That’s because the target user and possibly even security teams may be notified.",{"data":63048,"content":63049,"nodeType":876},{},[63050],{"data":63051,"marks":63052,"value":63053,"nodeType":867},{},[],"This leads us on to evil twin integrations. Their power is in making use of existing integrations so they can avoid appearing as a new integration and getting flagged or sending alerts to security teams. That makes them much stealthier and increases the likelihood of a successful attack. ",{"data":63055,"content":63056,"nodeType":876},{},[63057],{"data":63058,"marks":63059,"value":63060,"nodeType":867},{},[],"There are three possibilities here that lead to two different levels of stealth for the attack:",{"data":63062,"content":63063,"nodeType":62018},{},[63064,63074,63084],{"data":63065,"content":63066,"nodeType":1586},{},[63067],{"data":63068,"content":63069,"nodeType":876},{},[63070],{"data":63071,"marks":63072,"value":63073,"nodeType":867},{},[],"Medium stealth option: Making use of an automation app used legitimately by the organization, but not by the target user, specifically",{"data":63075,"content":63076,"nodeType":1586},{},[63077],{"data":63078,"content":63079,"nodeType":876},{},[63080],{"data":63081,"marks":63082,"value":63083,"nodeType":867},{},[],"High stealth option 1: Making use of an automation app used legitimately by the target user themselves",{"data":63085,"content":63086,"nodeType":1586},{},[63087],{"data":63088,"content":63089,"nodeType":876},{},[63090],{"data":63091,"marks":63092,"value":63093,"nodeType":867},{},[],"High stealth option 2: Making use of an automation app that has been granted admin consent",{"data":63095,"content":63096,"nodeType":1058},{},[63097],{"data":63098,"marks":63099,"value":63100,"nodeType":867},{},[],"Medium stealth option: Pre-existing use by organization",{"data":63102,"content":63103,"nodeType":876},{},[63104],{"data":63105,"marks":63106,"value":63107,"nodeType":867},{},[],"This option is by far the most likely option to be applicable in a real-world situation. Here’s how it works:",{"data":63109,"content":63110,"nodeType":876},{},[63111],{"data":63112,"marks":63113,"value":63114,"nodeType":867},{},[],"The consent for the targeted user will be new and will generate an audit event to show that, but the integration itself will not be new inside the organization and may even be formally approved by the security team already. This will help evade general detection mechanisms as it won’t be seen as a brand new integration at the organization level that requires careful scrutiny. It’s much harder to evaluate new consents on a per-user basis for existing integrations if the organization is of any significant size.",{"data":63116,"content":63117,"nodeType":876},{},[63118],{"data":63119,"marks":63120,"value":63121,"nodeType":867},{},[],"The downside, however, is that this attack stands a greater chance of detection if notifications are delivered directly to the affected user. Alternatively, if the original compromise is discovered, incident responders are more likely to discover this consent during an investigation. That’s because the affected user would know they aren’t using the automation app and incident responders are likely to explore logs showing consents to new OAuth integrations and permissions shortly after a successful compromise.",{"data":63123,"content":63124,"nodeType":876},{},[63125],{"data":63126,"marks":63127,"value":63128,"nodeType":867},{},[],"Using Azure as an example, while no new service principal is created in this case, the audit logs still show a new consent for the targeted user to the existing Zapier app: ",{"data":63130,"content":63134,"nodeType":985},{"target":63131},{"sys":63132},{"id":63133,"type":982,"linkType":983},"7m0E0sOulc348jhQguQLb1",[],{"data":63136,"content":63137,"nodeType":1058},{},[63138],{"data":63139,"marks":63140,"value":63141,"nodeType":867},{},[],"High stealth option 1: Pre-existing use by targeted user",{"data":63143,"content":63144,"nodeType":876},{},[63145],{"data":63146,"marks":63147,"value":63148,"nodeType":867},{},[],"This is the holy grail option, but is likely to require more luck in the real world. It requires that the target user is already using an automation app, which the adversary could compromise and utilize. If the compromised user has already consented to permissions useful to the adversary, such as access to sensitive data like email and file stores, then new malicious workflows can be created without requiring the user to consent to new permissions. ",{"data":63150,"content":63151,"nodeType":876},{},[63152],{"data":63153,"marks":63154,"value":63155,"nodeType":867},{},[],"Consequently, there will be no new integration observed at the organization level, no new user-specific consents for sensitive permissions and the target user would indicate they’re just using a legitimate app if questioned by incident responders. ",{"data":63157,"content":63158,"nodeType":876},{},[63159],{"data":63160,"marks":63161,"value":63163,"nodeType":867},{},[63162],{"type":865},"None of the three audit log entries shown above would be present in this scenario either.",{"data":63165,"content":63166,"nodeType":1058},{},[63167],{"data":63168,"marks":63169,"value":63170,"nodeType":867},{},[],"High stealth option 2: Azure admin consented app",{"data":63172,"content":63173,"nodeType":876},{},[63174,63178,63187],{"data":63175,"marks":63176,"value":63177,"nodeType":867},{},[],"There is a mixed scenario when permissions for an automation app (or any app you want to use for an evil twin integration) have been granted tenant-wide ",{"data":63179,"content":63181,"nodeType":915},{"uri":63180},"https://learn.microsoft.com/en-us/azure/active-directory/manage-apps/user-admin-consent-overview#admin-consent",[63182],{"data":63183,"marks":63184,"value":63186,"nodeType":867},{},[63185],{"type":913},"admin consent in Azure",{"data":63188,"marks":63189,"value":63190,"nodeType":867},{},[],". In this case, the administrator has effectively consented to permissions for all users, even if they aren’t currently active users of the app. ",{"data":63192,"content":63193,"nodeType":876},{},[63194],{"data":63195,"marks":63196,"value":63197,"nodeType":867},{},[],"This means when a new user integrates the app, it does not generate a new permission grant since it is effectively already granted. Consequently, the three log entries shown above would not be present in this scenario even if integrating the app for a user that has never used it before.",{"data":63199,"content":63200,"nodeType":876},{},[63201],{"data":63202,"marks":63203,"value":63204,"nodeType":867},{},[],"This gives the best level of flexibility for an adversary as they can avoid generating new permission grant logs for any user. However, it's not quite as stealthy as when the targeted user already makes use of the app as there is no history of legitimate app logins or activity for the user prior to the compromise to blend in with.",{"data":63206,"content":63207,"nodeType":868},{},[63208],{"data":63209,"marks":63210,"value":63211,"nodeType":867},{},[],"An example attack - Zapier",{"data":63213,"content":63214,"nodeType":876},{},[63215],{"data":63216,"marks":63217,"value":63218,"nodeType":867},{},[],"In this case, we’re going to use Zapier as our automation app example and Azure as the primary target for integrations and there will be no admin consent involved. We’ll also be using Google Workspace for data exfiltration. There are many other examples we could have used here, though - Make.com, IFTTT, Retool, Tines, Microsoft Power Automate and many other SaaS apps have powerful automation and integration capabilities and could be used for similar purposes. ",{"data":63220,"content":63221,"nodeType":876},{},[63222],{"data":63223,"marks":63224,"value":63225,"nodeType":867},{},[],"Azure and Google Workspace are also obvious juicy targets for integrations, but automation apps support integrations with vast numbers of other SaaS applications,so there are many possible targets.",{"data":63227,"content":63228,"nodeType":876},{},[63229],{"data":63230,"marks":63231,"value":63232,"nodeType":867},{},[],"So, let’s say we’ve compromised a target user’s Azure account. Perhaps we have conducted a successful credential stuffing attack, a phishing attack including MFA code proxying or even achieved a traditional endpoint compromise and have stolen the user’s session tokens.",{"data":63234,"content":63235,"nodeType":876},{},[63236],{"data":63237,"marks":63238,"value":63239,"nodeType":867},{},[],"Whatever the case, we have temporary control of the user’s account, either until the session expires or the user changes their password. If the original compromise is detected, that could happen quickly, so we want to conduct some malicious actions to make use of the access while we have it and to also gain persistence so we maintain our access beyond a password change.",{"data":63241,"content":63242,"nodeType":876},{},[63243],{"data":63244,"marks":63245,"value":63246,"nodeType":867},{},[],"We want to use an automation app, but we’d prefer to be as stealthy as possible by also making it an evil twin integration. We’d like to see if the target user has existing integrations with any apps we’d like to use - especially an automation app for that high stealth option we mentioned above. ",{"data":63248,"content":63249,"nodeType":876},{},[63250],{"data":63251,"marks":63252,"value":63253,"nodeType":867},{},[],"We’ve created a video demo of the full attack below. A step by step write up with more detail then follows:",{"data":63255,"content":63259,"nodeType":985},{"target":63256},{"sys":63257},{"id":63258,"type":982,"linkType":983},"E1ZHBcjGLZAno0SRtJ3d3",[],{"data":63261,"content":63262,"nodeType":868},{},[63263],{"data":63264,"marks":63265,"value":63266,"nodeType":867},{},[],"Step 1 - Enumerating potential targets",{"data":63268,"content":63269,"nodeType":876},{},[63270,63274,63282],{"data":63271,"marks":63272,"value":63273,"nodeType":867},{},[],"We could perform something as simple as an email search for evidence of sign-ups, but that won’t necessarily show us if actual OAuth integrations have been configured and what permissions are in use. What we really need is a way to perform an ",{"data":63275,"content":63276,"nodeType":915},{"uri":42950},[63277],{"data":63278,"marks":63279,"value":63281,"nodeType":867},{},[63280],{"type":913},"OAuth token enumeration",{"data":63283,"marks":63284,"value":63285,"nodeType":867},{},[]," attack.",{"data":63287,"content":63288,"nodeType":1058},{},[63289],{"data":63290,"marks":63291,"value":63292,"nodeType":867},{},[],"The first method: myapps.microsoft.com",{"data":63294,"content":63295,"nodeType":876},{},[63296,63300,63308],{"data":63297,"marks":63298,"value":63299,"nodeType":867},{},[],"Make use of ",{"data":63301,"content":63303,"nodeType":915},{"uri":63302},"https://myapps.microsoft.com",[63304],{"data":63305,"marks":63306,"value":63302,"nodeType":867},{},[63307],{"type":913},{"data":63309,"marks":63310,"value":63311,"nodeType":867},{},[]," to see which apps are listed and which permissions have been granted. We can see Zapier is in use and the user has granted it access to their email and files, making it a great target.",{"data":63313,"content":63317,"nodeType":985},{"target":63314},{"sys":63315},{"id":63316,"type":982,"linkType":983},"6dDez7xRZjliEJR6DAkWHa",[],{"data":63319,"content":63323,"nodeType":985},{"target":63320},{"sys":63321},{"id":63322,"type":982,"linkType":983},"7M0imWv4n3z1RYQu3AdMF5",[],{"data":63325,"content":63329,"nodeType":985},{"target":63326},{"sys":63327},{"id":63328,"type":982,"linkType":983},"3fwFBK03tc5g064k0IyADO",[],{"data":63331,"content":63332,"nodeType":1058},{},[63333],{"data":63334,"marks":63335,"value":63336,"nodeType":867},{},[],"The second method: Microsoft’s graph API",{"data":63338,"content":63339,"nodeType":876},{},[63340],{"data":63341,"marks":63342,"value":63343,"nodeType":867},{},[],"\nMicrosoft’s graph API doesn’t make it possible to list out service principals without admin permissions, but you can enumerate individual OAuth permission grants and app role assignments for your own user account. ",{"data":63345,"content":63346,"nodeType":876},{},[63347],{"data":63348,"marks":63349,"value":63350,"nodeType":867},{},[],"The client ID listed for permission grants is actually the tenant-specific service principal ID, rather than the globally unique OAuth app ID, but the app role assignments call gives us the app display name. We can match up the IDs from the app role assignments with the OAuth permission grants to see which permissions have been granted to the given app. ",{"data":63352,"content":63356,"nodeType":985},{"target":63353},{"sys":63354},{"id":63355,"type":982,"linkType":983},"519mlRMbaZYBAVdSADwop7",[],{"data":63358,"content":63362,"nodeType":985},{"target":63359},{"sys":63360},{"id":63361,"type":982,"linkType":983},"3g4WBQBEvqx5mXXnZzZzUG",[],{"data":63364,"content":63365,"nodeType":868},{},[63366],{"data":63367,"marks":63368,"value":63369,"nodeType":867},{},[],"Step 2 - Create shadow workflows",{"data":63371,"content":63372,"nodeType":876},{},[63373],{"data":63374,"marks":63375,"value":63376,"nodeType":867},{},[],"Ok, so we’ve figured out the user already makes use of Zapier and they’ve even already granted access to their email and files - that’s a juicy target we can’t turn down! So the next step is to create our own malicious workflows, or shadow workflows if you will, to get Zapier to do our dirty work for us.",{"data":63378,"content":63379,"nodeType":876},{},[63380],{"data":63381,"marks":63382,"value":63383,"nodeType":867},{},[],"First of all, we’ll see if we can scope out the user’s existing Zapier account to better understand the setup. Then we’ll create a new Zapier account and link it to the target user’s account that we’ve compromised. Here’s how that would work:",{"data":63385,"content":63386,"nodeType":1058},{},[63387],{"data":63388,"marks":63389,"value":63390,"nodeType":867},{},[],"Scope out the existing Zapier account",{"data":63392,"content":63393,"nodeType":876},{},[63394],{"data":63395,"marks":63396,"value":63397,"nodeType":867},{},[],"If the user uses SSO or social logins then we can login directly and, since we now control their Azure account, we can just log directly into their Zapier account!",{"data":63399,"content":63403,"nodeType":985},{"target":63400},{"sys":63401},{"id":63402,"type":982,"linkType":983},"5IgmxUEm6n19OBL1cSZVkr",[],{"data":63405,"content":63406,"nodeType":876},{},[63407,63411,63420],{"data":63408,"marks":63409,"value":63410,"nodeType":867},{},[],"Alternatively, if they have created a standard password account, then we might already know the password if it’s the same used for their Azure account. Otherwise, we could potentially make use of an ",{"data":63412,"content":63414,"nodeType":915},{"uri":63413},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/account_recovery/description.md",[63415],{"data":63416,"marks":63417,"value":63419,"nodeType":867},{},[63418],{"type":913},"account recovery",{"data":63421,"marks":63422,"value":63423,"nodeType":867},{},[]," attack to gain access.",{"data":63425,"content":63426,"nodeType":876},{},[63427,63431,63439],{"data":63428,"marks":63429,"value":63430,"nodeType":867},{},[],"Once we have logged into their account, we can see their existing workflows and integrations. Technically, we could backdoor these or create new ones - a form of an ",{"data":63432,"content":63433,"nodeType":915},{"uri":43027},[63434],{"data":63435,"marks":63436,"value":63438,"nodeType":867},{},[63437],{"type":913},"abuse existing OAuth integrations",{"data":63440,"marks":63441,"value":63442,"nodeType":867},{},[]," attack. However, that runs the risk of the user discovering our shadow workflows and also almost certainly being locked out of the account during the next password change. ",{"data":63444,"content":63445,"nodeType":876},{},[63446],{"data":63447,"marks":63448,"value":63449,"nodeType":867},{},[],"Instead, we can stick to an evil twin integration from our own Zapier account, which we’ll create later.",{"data":63451,"content":63455,"nodeType":985},{"target":63452},{"sys":63453},{"id":63454,"type":982,"linkType":983},"2vhyTcVLq27QVa2HFFWBhH",[],{"data":63457,"content":63461,"nodeType":985},{"target":63458},{"sys":63459},{"id":63460,"type":982,"linkType":983},"3jPSdBPSQgigA4yKK1udCV",[],{"data":63463,"content":63464,"nodeType":876},{},[63465],{"data":63466,"marks":63467,"value":63468,"nodeType":867},{},[],"Now we can see what the user was actually using Zapier for — they’ve set up an integration with both Outlook and OneDrive so they can forward emails related to their business expenses to a folder in their OneDrive. Probably a time-saving hack, which we can take advantage of since it won’t be unusual to see Zapier regularly accessing their Outlook and OneDrive. That means our attack will be extra stealthy.",{"data":63470,"content":63471,"nodeType":1058},{},[63472],{"data":63473,"marks":63474,"value":63475,"nodeType":867},{},[],"Create our own malicious Zapier account",{"data":63477,"content":63478,"nodeType":876},{},[63479],{"data":63480,"marks":63481,"value":63482,"nodeType":867},{},[],"Given in this case we, at least temporarily, control the user’s Azure account there is nothing stopping us connecting this to our own malicious Zapier account completely separately from the user’s legitimate Zapier account. We then maintain full control over the Zapier account and the user will not be able to discover our shadow workflows as they won’t have any knowledge of our Zapier account: ",{"data":63484,"content":63485,"nodeType":876},{},[63486],{"data":63487,"marks":63488,"value":63489,"nodeType":867},{},[],"Let’s create our own shadow workflows:",{"data":63491,"content":63492,"nodeType":1629},{},[63493,63503],{"data":63494,"content":63495,"nodeType":1586},{},[63496],{"data":63497,"content":63498,"nodeType":876},{},[63499],{"data":63500,"marks":63501,"value":63502,"nodeType":867},{},[],"One that sends every new OneDrive file to our own separate Google Drive account. This allows us to maintain a complete view of the user’s files into the future. ",{"data":63504,"content":63505,"nodeType":1586},{},[63506],{"data":63507,"content":63508,"nodeType":876},{},[63509],{"data":63510,"marks":63511,"value":63512,"nodeType":867},{},[],"And one to forward every new Outlook email to our own GMail account.",{"data":63514,"content":63518,"nodeType":985},{"target":63515},{"sys":63516},{"id":63517,"type":982,"linkType":983},"6eK8uNjPnkrfVjgFzl03SM",[],{"data":63520,"content":63524,"nodeType":985},{"target":63521},{"sys":63522},{"id":63523,"type":982,"linkType":983},"6xJvuS374tbflAoNmhnqYP",[],{"data":63526,"content":63527,"nodeType":876},{},[63528],{"data":63529,"marks":63530,"value":63531,"nodeType":867},{},[],"We can now see we are logged in with a separate GMail account, but have created shadow workflows to forward emails from the user’s Outlook to our GMail account and harvest files from their OneDrive to our Google Drive.",{"data":63533,"content":63534,"nodeType":876},{},[63535],{"data":63536,"marks":63537,"value":63538,"nodeType":867},{},[],"The major benefit of creating our own Zapier account for an evil twin integration is that once we are locked out of the target user’s account via a password change or otherwise, not only do our existing shadow workflows continue to operate via OAuth, but we are able to create new shadow workflows and reuse the existing OAuth connections. That’s the power of having full control of the Zapier account. ",{"data":63540,"content":63541,"nodeType":876},{},[63542],{"data":63543,"marks":63544,"value":63545,"nodeType":867},{},[],"One small downside to this approach is that creating the new OAuth integrations inside a new Zapier account generates an interactive login event for the Zapier integrations from the adversary’s IP address. This occurs due to creating integrations from the new Zapier account, but because the user has already consented to all the relevant permissions for Zapier’s own OAuth apps there are no audit logs for new consents or applications, just the login event itself. ",{"data":63547,"content":63548,"nodeType":876},{},[63549,63553],{"data":63550,"marks":63551,"value":63552,"nodeType":867},{},[],"However, determining that a successful login to an app a user legitimately uses is actually malicious in this case is obviously extremely difficult to build detection logic for.   ",{"data":63554,"marks":63555,"value":2167,"nodeType":867},{},[63556],{"type":1303},{"data":63558,"content":63562,"nodeType":985},{"target":63559},{"sys":63560},{"id":63561,"type":982,"linkType":983},"1oZBtlL8rNl7TjmfJqRjUG",[],{"data":63564,"content":63565,"nodeType":876},{},[63566],{"data":63567,"marks":63568,"value":63569,"nodeType":867},{},[],"Beyond the initial login events, the only evidence of malicious activity in the future will be from the activity logs showing the actions conducted by our shadow workflows every time they are triggered to run. For example, the following screenshots show that the Zapier Todo app (ClientAppId 29246358-1970-4d6d-bc75-acf34edc758b) has been seen both uploading a file and downloading a file: \n",{"data":63571,"content":63575,"nodeType":985},{"target":63572},{"sys":63573},{"id":63574,"type":982,"linkType":983},"2vYOSilB5W05aIHw2ZKqdC",[],{"data":63577,"content":63581,"nodeType":985},{"target":63578},{"sys":63579},{"id":63580,"type":982,"linkType":983},"2fFwrdFO25BwY4vI7EKMA0",[],{"data":63583,"content":63584,"nodeType":876},{},[63585],{"data":63586,"marks":63587,"value":63588,"nodeType":867},{},[],"The file upload in this case relates to the legitimate workflow and the file download relates to the shadow workflow. The IP addresses relate to Zapier’s legitimate infrastructure so really only a very thorough and specific investigation is going to be able to uncover that one of these events is malicious.",{"data":63590,"content":63591,"nodeType":868},{},[63592],{"data":63593,"marks":63594,"value":63595,"nodeType":867},{},[],"Step 3 - Profit",{"data":63597,"content":63598,"nodeType":876},{},[63599],{"data":63600,"marks":63601,"value":63602,"nodeType":867},{},[],"Now we just need to sit back and let our shadow workflows do the work for us, 24/7 and from Zapier’s infrastructure via a legitimate OAuth integration. Here we can see files the user created in OneDrive and emails they received in Outlook mirrored to our own GMail and Google Drive via the magic of shadow workflows.",{"data":63604,"content":63608,"nodeType":985},{"target":63605},{"sys":63606},{"id":63607,"type":982,"linkType":983},"4lJBrdJLEVnhBUjgtGo8T1",[],{"data":63610,"content":63614,"nodeType":985},{"target":63611},{"sys":63612},{"id":63613,"type":982,"linkType":983},"azQ3IO0n4Idih5LDwOogV",[],{"data":63616,"content":63617,"nodeType":868},{},[63618],{"data":63619,"marks":63620,"value":63621,"nodeType":867},{},[],"Impact",{"data":63623,"content":63624,"nodeType":876},{},[63625],{"data":63626,"marks":63627,"value":63628,"nodeType":867},{},[],"Ok, we’ve covered a lot of ground here so it’s worth taking a step back and considering the key impact points of this attack chain:",{"data":63630,"content":63631,"nodeType":1629},{},[63632,63642,63652,63662,63672,63725,63735],{"data":63633,"content":63634,"nodeType":1586},{},[63635],{"data":63636,"content":63637,"nodeType":876},{},[63638],{"data":63639,"marks":63640,"value":63641,"nodeType":867},{},[],"An adversary who has gained (temporary) access to a user account that supports OAuth integrations can use shadow workflows to execute malicious actions and to maintain persistence",{"data":63643,"content":63644,"nodeType":1586},{},[63645],{"data":63646,"content":63647,"nodeType":876},{},[63648],{"data":63649,"marks":63650,"value":63651,"nodeType":867},{},[],"This access will continue even if the user changes their password or resets MFA",{"data":63653,"content":63654,"nodeType":1586},{},[63655],{"data":63656,"content":63657,"nodeType":876},{},[63658],{"data":63659,"marks":63660,"value":63661,"nodeType":867},{},[],"Not only do existing shadow workflows continue to work after password changes, an adversary can continue to create new ones and reuse the existing integrations.",{"data":63663,"content":63664,"nodeType":1586},{},[63665],{"data":63666,"content":63667,"nodeType":876},{},[63668],{"data":63669,"marks":63670,"value":63671,"nodeType":867},{},[],"Any relevant logs will show access via legitimate IP addresses and OAuth integrations for SaaS automation apps ",{"data":63673,"content":63674,"nodeType":1586},{},[63675,63682],{"data":63676,"content":63677,"nodeType":876},{},[63678],{"data":63679,"marks":63680,"value":63681,"nodeType":867},{},[],"Automation apps are so flexible that an adversary can do pretty much anything - it’s basically the offensive PowerShell of the SaaS world. Just some examples:",{"data":63683,"content":63684,"nodeType":1629},{},[63685,63695,63705,63715],{"data":63686,"content":63687,"nodeType":1586},{},[63688],{"data":63689,"content":63690,"nodeType":876},{},[63691],{"data":63692,"marks":63693,"value":63694,"nodeType":867},{},[],"Monitor all emails and files the user creates",{"data":63696,"content":63697,"nodeType":1586},{},[63698],{"data":63699,"content":63700,"nodeType":876},{},[63701],{"data":63702,"marks":63703,"value":63704,"nodeType":867},{},[],"Delete email security alerts before the user sees them",{"data":63706,"content":63707,"nodeType":1586},{},[63708],{"data":63709,"content":63710,"nodeType":876},{},[63711],{"data":63712,"marks":63713,"value":63714,"nodeType":867},{},[],"Intercept password reset and passwordless login emails to access other apps",{"data":63716,"content":63717,"nodeType":1586},{},[63718],{"data":63719,"content":63720,"nodeType":876},{},[63721],{"data":63722,"marks":63723,"value":63724,"nodeType":867},{},[],"Monitor instant messaging apps and use it to send targeted internal social engineering emails",{"data":63726,"content":63727,"nodeType":1586},{},[63728],{"data":63729,"content":63730,"nodeType":876},{},[63731],{"data":63732,"marks":63733,"value":63734,"nodeType":867},{},[],"If targeted users are already using automation apps legitimately, it’s even more stealthy - you won’t even see any new integrations or permission grants appear as the user will have already granted these legitimately.",{"data":63736,"content":63737,"nodeType":1586},{},[63738],{"data":63739,"content":63740,"nodeType":876},{},[63741],{"data":63742,"marks":63743,"value":63744,"nodeType":867},{},[],"If admin consent has been granted to the automation app, any user can be targeted without generating new permission grant logs even if they have never used the app.",{"data":63746,"content":63747,"nodeType":868},{},[63748],{"data":63749,"marks":63750,"value":23563,"nodeType":867},{},[],{"data":63752,"content":63753,"nodeType":876},{},[63754],{"data":63755,"marks":63756,"value":63757,"nodeType":867},{},[],"We have seen how two new SaaS-focused attack techniques can be combined into one more effective attack chain - in this case, a particularly nasty and stealthy persistence technique. This shows how even if a user compromise is detected very early, with password and MFA resets immediately issued, adversaries can maintain control over the account regardless.",{"data":63759,"content":63760,"nodeType":876},{},[63761],{"data":63762,"marks":63763,"value":63764,"nodeType":867},{},[],"This shows how even legitimate SaaS applications have incredibly powerful offensive use cases and very careful attention needs to be paid to integrations with highly sensitive permissions, even when they are approved and vetted applications. Incident response teams especially need to be well aware of these techniques when investigating potential user account compromises as persistence approaches can extend much further than endpoint implants and stolen passwords.","The shadow workflow’s evil twin: A nearly invisible attack chain","2023-09-11T00:00:00.000Z","nearly-invisible-attack-chain",{"items":63769},[63770,63772],{"sys":63771,"name":4018},{"id":4017},{"sys":63773,"name":342},{"id":3240},{"items":63775},[63776],{"fullName":14739,"firstName":14740,"jobTitle":14741,"profilePicture":63777},{"url":14743},{"__typename":1772,"sys":63779,"content":63780,"title":62931,"synopsis":64232,"hashTags":59,"publishedDate":64233,"slug":64234,"tagsCollection":64235,"authorsCollection":64241},{"id":60067},{"json":63781},{"data":63782,"content":63783,"nodeType":1680},{},[63784,63802,63809,63816,63823,63841,63848,63865,63871,63878,63885,63892,63899,63906,63913,63933,63940,63947,63953,63960,63967,63974,63980,63986,63992,63999,64006,64012,64019,64026,64033,64039,64046,64053,64060,64067,64074,64080,64087,64094,64100,64107,64114,64120,64126,64133,64198,64205,64211,64218,64225],{"data":63785,"content":63786,"nodeType":876},{},[63787,63791,63798],{"data":63788,"marks":63789,"value":63790,"nodeType":867},{},[],"We published the ",{"data":63792,"content":63793,"nodeType":915},{"uri":15408},[63794],{"data":63795,"marks":63796,"value":14765,"nodeType":867},{},[63797],{"type":913},{"data":63799,"marks":63800,"value":63801,"nodeType":867},{},[]," on GitHub, which is an open-source research project to demonstrate the multitude of attacks that are possible against SaaS-native and hybrid SaaS organizations. On release day it contained 38 different techniques. ",{"data":63803,"content":63804,"nodeType":876},{},[63805],{"data":63806,"marks":63807,"value":63808,"nodeType":867},{},[],"However, we know it’s not just individual attack techniques and the phases of the cyber kill chain that matter - it’s also how you chain attacks together. Two lower risk vulnerabilities chained together could be a critical issue.",{"data":63810,"content":63811,"nodeType":876},{},[63812],{"data":63813,"marks":63814,"value":63815,"nodeType":867},{},[],"In this article, we’re going to demonstrate that by combining two of our favorite new SaaS attack techniques, poisoned tenants and SAMLjacking, you can make a simple, but effective attack chain.",{"data":63817,"content":63818,"nodeType":868},{},[63819],{"data":63820,"marks":63821,"value":63822,"nodeType":867},{},[],"What is a poisoned tenant?",{"data":63824,"content":63825,"nodeType":876},{},[63826,63829,63837],{"data":63827,"marks":63828,"value":21,"nodeType":867},{},[],{"data":63830,"content":63831,"nodeType":915},{"uri":61174},[63832],{"data":63833,"marks":63834,"value":63836,"nodeType":867},{},[63835],{"type":913},"Poisoned tenants",{"data":63838,"marks":63839,"value":63840,"nodeType":867},{},[]," involve an adversary registering a tenant for a SaaS app they control and tricking target users to join it, often using built-in invite functionality. The end goal is to have some target users actively using a tenant you (as the adversary) control.",{"data":63842,"content":63843,"nodeType":868},{},[63844],{"data":63845,"marks":63846,"value":63847,"nodeType":867},{},[],"What the hell is SAMLjacking?",{"data":63849,"content":63850,"nodeType":876},{},[63851,63854,63861],{"data":63852,"marks":63853,"value":21,"nodeType":867},{},[],{"data":63855,"content":63856,"nodeType":915},{"uri":22216},[63857],{"data":63858,"marks":63859,"value":22222,"nodeType":867},{},[63860],{"type":913},{"data":63862,"marks":63863,"value":63864,"nodeType":867},{},[]," is where an attacker makes use of SAML SSO configuration settings for a SaaS tenant they control in order to redirect users to a malicious link of their choosing during the authentication process. This can be highly effective for phishing as the original URL will be a legitimate SaaS URL and users are expecting to provide credentials.",{"data":63866,"content":63867,"nodeType":868},{},[63868],{"data":63869,"marks":63870,"value":63023,"nodeType":867},{},[],{"data":63872,"content":63873,"nodeType":876},{},[63874],{"data":63875,"marks":63876,"value":63877,"nodeType":867},{},[],"A poisoned tenant on its own could be an epic supply chain attack if you get really lucky. Imagine discovering an organization was wanting to migrate to Slack and then catching some key teams with a Slack poisoned tenant and gradually getting the whole organization migrated over. You’d have a goldmine of information as an administrator of the platform.",{"data":63879,"content":63880,"nodeType":876},{},[63881],{"data":63882,"marks":63883,"value":63884,"nodeType":867},{},[],"However, it might be hard to trick a whole organization into using an attacker controlled slack instance without anyone realizing, but it could be a lot easier to successfully invite e.g. a marketing team into using/adopting a new marketing app that helps them do SEO. This might be easier to perform, but it doesn't really give the attacker valuable data in the poisoned tenant of the marketing app, so it seems a bit pointless.",{"data":63886,"content":63887,"nodeType":876},{},[63888],{"data":63889,"marks":63890,"value":63891,"nodeType":867},{},[],"On the other hand, what about SAMLjacking? It’s a great technique on its own, but you still need to get users to login to the app. Sure, you’ll be sending them a legitimate SaaS URL with a valid TLS certificate etc and so it’s going to pass the sniff test for many people and also bypass email security appliances and similar security tools. However, you’re still effectively phishing them for credentials, the one thing we train users to be most suspicious about, so there is still a possibility they will spot the attack. ",{"data":63893,"content":63894,"nodeType":876},{},[63895],{"data":63896,"marks":63897,"value":63898,"nodeType":867},{},[],"But what if you could combine these techniques so that a poisoned tenant didn’t need to be a big, juicy target to be useful and a SAMLjacking attack didn’t even necessarily require phishing someone directly? What if the attack could be successful just from a target accessing their own bookmarks or open tabs for an app they already use?",{"data":63900,"content":63901,"nodeType":876},{},[63902],{"data":63903,"marks":63904,"value":63905,"nodeType":867},{},[],"In a combination scenario, a user doesn't need to be phished for SAMLjacking. One day they go back to their tab and it's logged out and they get SAMLjacked while logging back in. They don't have to click a link in an email. That’s what we are talking about here, so let’s consider an example of this making use of the SaaS-based wiki, Nuclino.",{"data":63907,"content":63908,"nodeType":868},{},[63909],{"data":63910,"marks":63911,"value":63912,"nodeType":867},{},[],"An example attack - Nuclino",{"data":63914,"content":63915,"nodeType":876},{},[63916,63920,63929],{"data":63917,"marks":63918,"value":63919,"nodeType":867},{},[],"Before moving on, I’d just like to point out that this isn’t a vulnerability with ",{"data":63921,"content":63923,"nodeType":915},{"uri":63922},"https://www.nuclino.com/",[63924],{"data":63925,"marks":63926,"value":63928,"nodeType":867},{},[63927],{"type":913},"Nuclino",{"data":63930,"marks":63931,"value":63932,"nodeType":867},{},[]," per se and it won’t be limited to Nuclino either. I’ve used Nuclino as an example because it’s a great wiki platform we use at Push Security, so I’m familiar with it. ",{"data":63934,"content":63935,"nodeType":876},{},[63936],{"data":63937,"marks":63938,"value":63939,"nodeType":867},{},[],"It also allows custom SAML authentication, both as part of its free trial and as part of its lowest tier paid plan. This should be commended as many SaaS apps don’t support SAML or other forms of SSO, and many of those that do charge a huge premium via enterprise plans to gain access to it. We love you Nuclino, sorry!",{"data":63941,"content":63942,"nodeType":876},{},[63943],{"data":63944,"marks":63945,"value":63946,"nodeType":867},{},[],"We'll take a walkthrough of how the attack chain works now. However, if you'd like to jump straight to a demo of the attack then checkout the video here:",{"data":63948,"content":63952,"nodeType":985},{"target":63949},{"sys":63950},{"id":63951,"type":982,"linkType":983},"3y6ZMPPsbh6PYlQ7IOxOzS",[],{"data":63954,"content":63955,"nodeType":876},{},[63956],{"data":63957,"marks":63958,"value":63959,"nodeType":867},{},[],"Next, we'll do a full walkthrough of the attack.",{"data":63961,"content":63962,"nodeType":1058},{},[63963],{"data":63964,"marks":63965,"value":63966,"nodeType":867},{},[],"Step 1 - Setup a poisoned tenant and invite target users",{"data":63968,"content":63969,"nodeType":876},{},[63970],{"data":63971,"marks":63972,"value":63973,"nodeType":867},{},[],"The first step for an adversary is to set up their poisoned tenant and then make use of the invite functionality to target some employees of the target organization. With Nuclino, you can either do this by sending sharing links directly to the target or invite them through the Nuclino app, and it will send out legit email invitations on your behalf.",{"data":63975,"content":63979,"nodeType":985},{"target":63976},{"sys":63977},{"id":63978,"type":982,"linkType":983},"740nQhGSFp2nFU1b4DP7Mp",[],{"data":63981,"content":63985,"nodeType":985},{"target":63982},{"sys":63983},{"id":63984,"type":982,"linkType":983},"4GFL1L7Mmp3nnBODwC9SbH",[],{"data":63987,"content":63991,"nodeType":985},{"target":63988},{"sys":63989},{"id":63990,"type":982,"linkType":983},"7KUWKFFlDyvBVoM3MEhPwR",[],{"data":63993,"content":63994,"nodeType":1058},{},[63995],{"data":63996,"marks":63997,"value":63998,"nodeType":867},{},[],"Step 2 - Target responds to the invitation or later signs up for Nuclino",{"data":64000,"content":64001,"nodeType":876},{},[64002],{"data":64003,"marks":64004,"value":64005,"nodeType":867},{},[],"The interesting thing here is that whether the target signs up for Nuclino directly from the joining link or they sign up for an account separately in future, they get mapped to the workspace they have been invited to by default.",{"data":64007,"content":64011,"nodeType":985},{"target":64008},{"sys":64009},{"id":64010,"type":982,"linkType":983},"2GlTHcT1cpQ44jb5lN9dr4",[],{"data":64013,"content":64014,"nodeType":1058},{},[64015],{"data":64016,"marks":64017,"value":64018,"nodeType":867},{},[],"Step 3 - Configure a malicious SAML server",{"data":64020,"content":64021,"nodeType":876},{},[64022],{"data":64023,"marks":64024,"value":64025,"nodeType":867},{},[],"Once the adversary has a critical mass of users on their poisoned tenant, they can later engage the SAMLjacking attack. ",{"data":64027,"content":64028,"nodeType":876},{},[64029],{"data":64030,"marks":64031,"value":64032,"nodeType":867},{},[],"To do this, they need to configure a custom SAML server. You can point this to a fake authentication provider they control that mirrors the appearance of the SSO provider the target users are accustomed to using in order to capture credentials.",{"data":64034,"content":64038,"nodeType":985},{"target":64035},{"sys":64036},{"id":64037,"type":982,"linkType":983},"1RbhUTZd5Ak4UvjiZhub4V",[],{"data":64040,"content":64041,"nodeType":876},{},[64042],{"data":64043,"marks":64044,"value":64045,"nodeType":867},{},[],"If you toggle the setting to require SSO, existing users will be sent emails prompting them to link their accounts to SSO. That leads to two possible paths to a user compromise.",{"data":64047,"content":64048,"nodeType":868},{},[64049],{"data":64050,"marks":64051,"value":64052,"nodeType":867},{},[],"Paths to user compromise ",{"data":64054,"content":64055,"nodeType":1058},{},[64056],{"data":64057,"marks":64058,"value":64059,"nodeType":867},{},[],"The first possibility",{"data":64061,"content":64062,"nodeType":876},{},[64063],{"data":64064,"marks":64065,"value":64066,"nodeType":867},{},[],"This compromise occurs when the target sees the email that SSO has been configured and clicks the link in order to link their account to SSO. A smart adversary may improve the social engineering quality with an email sent out in advance informing users that the internal security team has requested Nuclino be linked to SSO. This makes the target expect the email and consider it legitimate. ",{"data":64068,"content":64069,"nodeType":876},{},[64070],{"data":64071,"marks":64072,"value":64073,"nodeType":867},{},[],"Even though the email is an official email from Nuclino and the link contained is an official Nuclino URL, it will immediately redirect to the malicious SAML server that has been configured, where credentials can then be captured.",{"data":64075,"content":64079,"nodeType":985},{"target":64076},{"sys":64077},{"id":64078,"type":982,"linkType":983},"6zWiAfBx7aaUeo6t04AtUl",[],{"data":64081,"content":64082,"nodeType":1058},{},[64083],{"data":64084,"marks":64085,"value":64086,"nodeType":867},{},[],"Second compromise possibility",{"data":64088,"content":64089,"nodeType":876},{},[64090],{"data":64091,"marks":64092,"value":64093,"nodeType":867},{},[],"If the user ignores the email, the other potential outcome occurs when their session expires and they need to login again to regain access. This is similar to a watering hole attack. When their session expires, the target’s open tabs or bookmarks will redirect back to the workspace specific login page, which will now look like this:",{"data":64095,"content":64099,"nodeType":985},{"target":64096},{"sys":64097},{"id":64098,"type":982,"linkType":983},"580CvVtdyEpqdiK8T1lSfQ",[],{"data":64101,"content":64102,"nodeType":876},{},[64103],{"data":64104,"marks":64105,"value":64106,"nodeType":867},{},[],"Clicking the button to login with SSO will immediately redirect to the malicious SAML server and launch the attack. Alternatively, if the target attempts to login without SSO, the login will fail with an error message telling them to login with SSO.",{"data":64108,"content":64109,"nodeType":876},{},[64110],{"data":64111,"marks":64112,"value":64113,"nodeType":867},{},[],"Either way, once the SAMLjacking has taken effect, they’ll be faced with a familiar-looking SSO login page from a trusted source at a point they are expecting to enter their credentials - something even the most paranoid of users could easily fall for unknowingly. ",{"data":64115,"content":64119,"nodeType":985},{"target":64116},{"sys":64117},{"id":64118,"type":982,"linkType":983},"5eFctGgFywtmhhjaXVraqN",[],{"data":64121,"content":64122,"nodeType":868},{},[64123],{"data":64124,"marks":64125,"value":63621,"nodeType":867},{},[],{"data":64127,"content":64128,"nodeType":876},{},[64129],{"data":64130,"marks":64131,"value":64132,"nodeType":867},{},[],"At this point, having compromised multiple user’s Google credentials, an adversary has a lot of options available:",{"data":64134,"content":64135,"nodeType":1629},{},[64136,64146,64156,64178],{"data":64137,"content":64138,"nodeType":1586},{},[64139],{"data":64140,"content":64141,"nodeType":876},{},[64142],{"data":64143,"marks":64144,"value":64145,"nodeType":867},{},[],"Access all data in Google apps like GMail, Google Drive etc",{"data":64147,"content":64148,"nodeType":1586},{},[64149],{"data":64150,"content":64151,"nodeType":876},{},[64152],{"data":64153,"marks":64154,"value":64155,"nodeType":867},{},[],"Access other SaaS apps that use SSO with the same Google account",{"data":64157,"content":64158,"nodeType":1586},{},[64159],{"data":64160,"content":64161,"nodeType":876},{},[64162,64166,64175],{"data":64163,"marks":64164,"value":64165,"nodeType":867},{},[],"Access other SaaS apps that use ",{"data":64167,"content":64169,"nodeType":915},{"uri":64168},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/passwordless_logins/description.md",[64170],{"data":64171,"marks":64172,"value":64174,"nodeType":867},{},[64173],{"type":913},"passwordless logins",{"data":64176,"marks":64177,"value":21,"nodeType":867},{},[],{"data":64179,"content":64180,"nodeType":1586},{},[64181],{"data":64182,"content":64183,"nodeType":876},{},[64184,64188,64195],{"data":64185,"marks":64186,"value":64187,"nodeType":867},{},[],"Access other SaaS apps via email ",{"data":64189,"content":64190,"nodeType":915},{"uri":63413},[64191],{"data":64192,"marks":64193,"value":63419,"nodeType":867},{},[64194],{"type":913},{"data":64196,"marks":64197,"value":21,"nodeType":867},{},[],{"data":64199,"content":64200,"nodeType":876},{},[64201],{"data":64202,"marks":64203,"value":64204,"nodeType":867},{},[],"Essentially, this can potentially lead to a compromise of every SaaS application accessible by the compromised user - all from the use of a poisoned tenant for an app with no particularly sensitive data or permissions.",{"data":64206,"content":64207,"nodeType":1058},{},[64208],{"data":64209,"marks":64210,"value":23563,"nodeType":867},{},[],{"data":64212,"content":64213,"nodeType":876},{},[64214],{"data":64215,"marks":64216,"value":64217,"nodeType":867},{},[],"We have seen how two new SaaS-focused attack techniques can be combined into one more effective attack chain. This shows how a successful poisoned tenant attack for even a low risk app can still be a significant threat when combined with a SAMLjacking attack. ",{"data":64219,"content":64220,"nodeType":876},{},[64221],{"data":64222,"marks":64223,"value":64224,"nodeType":867},{},[],"This demonstrates even the least sensitive edge cases of SaaS sprawl can represent a vector to laterally move to compromise much more valuable assets. History taught us that protecting core production assets was not enough. Adversaries often achieved compromises via test systems and unsecured development resources. What we are seeing now is that this parallel exists in the SaaS-native world too. Therefore, we need to be protecting all SaaS resources with greater vigilance than their standalone sensitivity would indicate.",{"data":64226,"content":64227,"nodeType":876},{},[64228],{"data":64229,"marks":64230,"value":64231,"nodeType":867},{},[],"So what can be done about it? Well, like much in security, there is no silver bullet solution to this issue. SaaS apps are here to stay and are designed to be flexible, easy to sign up for and use. The key first step is always to get good visibility into the SaaS sprawl across your organization. If certain employees or teams start making use of a new SaaS app (or a new tenant for an existing one), that’s probably something your security team should be aware of so they can make sure it’s legitimate and being used as securely as possible. ","In this article, we’re going to demo combining two of our favorite new SaaS attack techniques to make a simple, but effective attack chain.\n","2023-08-17T00:00:00.000Z","samljacking-a-poisoned-tenant",{"items":64236},[64237,64239],{"sys":64238,"name":4018},{"id":4017},{"sys":64240,"name":342},{"id":3240},{"items":64242},[64243],{"fullName":14739,"firstName":14740,"jobTitle":14741,"profilePicture":64244},{"url":14743},{"__typename":1772,"sys":64246,"content":64247,"title":54766,"synopsis":54767,"hashTags":59,"publishedDate":54768,"slug":54769,"tagsCollection":66918,"authorsCollection":66924},{"id":45037},{"json":64248},{"data":64249,"content":64250,"nodeType":1680},{},[64251,64257,64283,64289,64294,64300,64316,64337,64343,64349,64369,64382,64388,64398,64404,64407,64413,64419,64432,64442,64451,64477,64480,64486,64502,64508,64515,64600,64606,64722,64728,64829,64835,64841,65001,65007,65013,65088,65091,65097,65103,65109,65166,65172,65202,65208,65247,65253,65259,65478,65484,65491,65497,65500,65506,65512,65518,65566,65572,65611,65617,65647,65653,65659,65819,65825,65832,65838,65845,65851,65858,65864,65867,65873,65879,65885,65942,65948,65978,65984,66014,66020,66026,66127,66130,66136,66142,66148,66205,66211,66241,66247,66277,66283,66289,66453,66456,66462,66468,66474,66540,66546,66576,66582,66612,66618,66624,66843,66846,66852,66858,66864,66870,66873,66879,66885,66891,66894,66900,66906,66912],{"data":64252,"content":64253,"nodeType":868},{},[64254],{"data":64255,"marks":64256,"value":51832,"nodeType":867},{},[],{"data":64258,"content":64259,"nodeType":876},{},[64260,64263,64270,64273,64280],{"data":64261,"marks":64262,"value":51839,"nodeType":867},{},[],{"data":64264,"content":64265,"nodeType":915},{"uri":51842},[64266],{"data":64267,"marks":64268,"value":51848,"nodeType":867},{},[64269],{"type":913},{"data":64271,"marks":64272,"value":51852,"nodeType":867},{},[],{"data":64274,"content":64275,"nodeType":915},{"uri":51855},[64276],{"data":64277,"marks":64278,"value":51861,"nodeType":867},{},[64279],{"type":913},{"data":64281,"marks":64282,"value":1679,"nodeType":867},{},[],{"data":64284,"content":64285,"nodeType":876},{},[64286],{"data":64287,"marks":64288,"value":51871,"nodeType":867},{},[],{"data":64290,"content":64293,"nodeType":985},{"target":64291},{"sys":64292},{"id":51876,"type":982,"linkType":983},[],{"data":64295,"content":64296,"nodeType":876},{},[64297],{"data":64298,"marks":64299,"value":51884,"nodeType":867},{},[],{"data":64301,"content":64302,"nodeType":876},{},[64303,64306,64313],{"data":64304,"marks":64305,"value":51891,"nodeType":867},{},[],{"data":64307,"content":64308,"nodeType":915},{"uri":51894},[64309],{"data":64310,"marks":64311,"value":51900,"nodeType":867},{},[64312],{"type":913},{"data":64314,"marks":64315,"value":51904,"nodeType":867},{},[],{"data":64317,"content":64318,"nodeType":1629},{},[64319,64328],{"data":64320,"content":64321,"nodeType":1586},{},[64322],{"data":64323,"content":64324,"nodeType":876},{},[64325],{"data":64326,"marks":64327,"value":51917,"nodeType":867},{},[],{"data":64329,"content":64330,"nodeType":1586},{},[64331],{"data":64332,"content":64333,"nodeType":876},{},[64334],{"data":64335,"marks":64336,"value":51927,"nodeType":867},{},[],{"data":64338,"content":64339,"nodeType":876},{},[64340],{"data":64341,"marks":64342,"value":51934,"nodeType":867},{},[],{"data":64344,"content":64345,"nodeType":1058},{},[64346],{"data":64347,"marks":64348,"value":51941,"nodeType":867},{},[],{"data":64350,"content":64351,"nodeType":876},{},[64352,64355,64359,64362,64366],{"data":64353,"marks":64354,"value":51948,"nodeType":867},{},[],{"data":64356,"marks":64357,"value":51953,"nodeType":867},{},[64358],{"type":865},{"data":64360,"marks":64361,"value":51957,"nodeType":867},{},[],{"data":64363,"marks":64364,"value":51962,"nodeType":867},{},[64365],{"type":1303},{"data":64367,"marks":64368,"value":2167,"nodeType":867},{},[],{"data":64370,"content":64371,"nodeType":876},{},[64372,64375,64379],{"data":64373,"marks":64374,"value":51972,"nodeType":867},{},[],{"data":64376,"marks":64377,"value":51977,"nodeType":867},{},[64378],{"type":865},{"data":64380,"marks":64381,"value":51981,"nodeType":867},{},[],{"data":64383,"content":64384,"nodeType":876},{},[64385],{"data":64386,"marks":64387,"value":51988,"nodeType":867},{},[],{"data":64389,"content":64390,"nodeType":876},{},[64391,64394],{"data":64392,"marks":64393,"value":51995,"nodeType":867},{},[],{"data":64395,"marks":64396,"value":52000,"nodeType":867},{},[64397],{"type":865},{"data":64399,"content":64400,"nodeType":876},{},[64401],{"data":64402,"marks":64403,"value":52007,"nodeType":867},{},[],{"data":64405,"content":64406,"nodeType":942},{},[],{"data":64408,"content":64409,"nodeType":868},{},[64410],{"data":64411,"marks":64412,"value":52017,"nodeType":867},{},[],{"data":64414,"content":64415,"nodeType":876},{},[64416],{"data":64417,"marks":64418,"value":52024,"nodeType":867},{},[],{"data":64420,"content":64421,"nodeType":876},{},[64422,64425,64429],{"data":64423,"marks":64424,"value":52031,"nodeType":867},{},[],{"data":64426,"marks":64427,"value":52036,"nodeType":867},{},[64428],{"type":1303},{"data":64430,"marks":64431,"value":52040,"nodeType":867},{},[],{"data":64433,"content":64434,"nodeType":876},{},[64435,64438],{"data":64436,"marks":64437,"value":52047,"nodeType":867},{},[],{"data":64439,"marks":64440,"value":52052,"nodeType":867},{},[64441],{"type":865},{"data":64443,"content":64444,"nodeType":876},{},[64445,64448],{"data":64446,"marks":64447,"value":52059,"nodeType":867},{},[],{"data":64449,"marks":64450,"value":52063,"nodeType":867},{},[],{"data":64452,"content":64453,"nodeType":876},{},[64454,64457,64464,64467,64474],{"data":64455,"marks":64456,"value":52070,"nodeType":867},{},[],{"data":64458,"content":64459,"nodeType":915},{"uri":5720},[64460],{"data":64461,"marks":64462,"value":5905,"nodeType":867},{},[64463],{"type":913},{"data":64465,"marks":64466,"value":52081,"nodeType":867},{},[],{"data":64468,"content":64469,"nodeType":915},{"uri":52084},[64470],{"data":64471,"marks":64472,"value":52090,"nodeType":867},{},[64473],{"type":913},{"data":64475,"marks":64476,"value":2933,"nodeType":867},{},[],{"data":64478,"content":64479,"nodeType":942},{},[],{"data":64481,"content":64482,"nodeType":868},{},[64483],{"data":64484,"marks":64485,"value":52103,"nodeType":867},{},[],{"data":64487,"content":64488,"nodeType":876},{},[64489,64492,64499],{"data":64490,"marks":64491,"value":52110,"nodeType":867},{},[],{"data":64493,"content":64494,"nodeType":915},{"uri":16024},[64495],{"data":64496,"marks":64497,"value":52118,"nodeType":867},{},[64498],{"type":913},{"data":64500,"marks":64501,"value":5704,"nodeType":867},{},[],{"data":64503,"content":64504,"nodeType":1058},{},[64505],{"data":64506,"marks":64507,"value":52128,"nodeType":867},{},[],{"data":64509,"content":64510,"nodeType":876},{},[64511],{"data":64512,"marks":64513,"value":52136,"nodeType":867},{},[64514],{"type":1303},{"data":64516,"content":64517,"nodeType":1629},{},[64518,64527,64546,64555,64564,64573,64582,64591],{"data":64519,"content":64520,"nodeType":1586},{},[64521],{"data":64522,"content":64523,"nodeType":876},{},[64524],{"data":64525,"marks":64526,"value":52149,"nodeType":867},{},[],{"data":64528,"content":64529,"nodeType":1586},{},[64530],{"data":64531,"content":64532,"nodeType":876},{},[64533,64536,64543],{"data":64534,"marks":64535,"value":52159,"nodeType":867},{},[],{"data":64537,"content":64538,"nodeType":915},{"uri":45994},[64539],{"data":64540,"marks":64541,"value":52167,"nodeType":867},{},[64542],{"type":913},{"data":64544,"marks":64545,"value":52171,"nodeType":867},{},[],{"data":64547,"content":64548,"nodeType":1586},{},[64549],{"data":64550,"content":64551,"nodeType":876},{},[64552],{"data":64553,"marks":64554,"value":52181,"nodeType":867},{},[],{"data":64556,"content":64557,"nodeType":1586},{},[64558],{"data":64559,"content":64560,"nodeType":876},{},[64561],{"data":64562,"marks":64563,"value":52191,"nodeType":867},{},[],{"data":64565,"content":64566,"nodeType":1586},{},[64567],{"data":64568,"content":64569,"nodeType":876},{},[64570],{"data":64571,"marks":64572,"value":52201,"nodeType":867},{},[],{"data":64574,"content":64575,"nodeType":1586},{},[64576],{"data":64577,"content":64578,"nodeType":876},{},[64579],{"data":64580,"marks":64581,"value":52211,"nodeType":867},{},[],{"data":64583,"content":64584,"nodeType":1586},{},[64585],{"data":64586,"content":64587,"nodeType":876},{},[64588],{"data":64589,"marks":64590,"value":52221,"nodeType":867},{},[],{"data":64592,"content":64593,"nodeType":1586},{},[64594],{"data":64595,"content":64596,"nodeType":876},{},[64597],{"data":64598,"marks":64599,"value":52231,"nodeType":867},{},[],{"data":64601,"content":64602,"nodeType":1058},{},[64603],{"data":64604,"marks":64605,"value":52238,"nodeType":867},{},[],{"data":64607,"content":64608,"nodeType":1629},{},[64609,64625,64651,64674,64690,64706],{"data":64610,"content":64611,"nodeType":1586},{},[64612],{"data":64613,"content":64614,"nodeType":876},{},[64615,64618,64622],{"data":64616,"marks":64617,"value":52251,"nodeType":867},{},[],{"data":64619,"marks":64620,"value":52256,"nodeType":867},{},[64621],{"type":865},{"data":64623,"marks":64624,"value":52260,"nodeType":867},{},[],{"data":64626,"content":64627,"nodeType":1586},{},[64628],{"data":64629,"content":64630,"nodeType":876},{},[64631,64634,64638,64641,64648],{"data":64632,"marks":64633,"value":52270,"nodeType":867},{},[],{"data":64635,"marks":64636,"value":52275,"nodeType":867},{},[64637],{"type":865},{"data":64639,"marks":64640,"value":52279,"nodeType":867},{},[],{"data":64642,"content":64643,"nodeType":915},{"uri":40317},[64644],{"data":64645,"marks":64646,"value":52287,"nodeType":867},{},[64647],{"type":913},{"data":64649,"marks":64650,"value":52291,"nodeType":867},{},[],{"data":64652,"content":64653,"nodeType":1586},{},[64654],{"data":64655,"content":64656,"nodeType":876},{},[64657,64660,64664,64667,64671],{"data":64658,"marks":64659,"value":52301,"nodeType":867},{},[],{"data":64661,"marks":64662,"value":52306,"nodeType":867},{},[64663],{"type":865},{"data":64665,"marks":64666,"value":52310,"nodeType":867},{},[],{"data":64668,"marks":64669,"value":52315,"nodeType":867},{},[64670],{"type":865},{"data":64672,"marks":64673,"value":52319,"nodeType":867},{},[],{"data":64675,"content":64676,"nodeType":1586},{},[64677],{"data":64678,"content":64679,"nodeType":876},{},[64680,64683,64687],{"data":64681,"marks":64682,"value":52329,"nodeType":867},{},[],{"data":64684,"marks":64685,"value":52334,"nodeType":867},{},[64686],{"type":865},{"data":64688,"marks":64689,"value":52338,"nodeType":867},{},[],{"data":64691,"content":64692,"nodeType":1586},{},[64693],{"data":64694,"content":64695,"nodeType":876},{},[64696,64699,64703],{"data":64697,"marks":64698,"value":52348,"nodeType":867},{},[],{"data":64700,"marks":64701,"value":52353,"nodeType":867},{},[64702],{"type":865},{"data":64704,"marks":64705,"value":52357,"nodeType":867},{},[],{"data":64707,"content":64708,"nodeType":1586},{},[64709],{"data":64710,"content":64711,"nodeType":876},{},[64712,64715,64719],{"data":64713,"marks":64714,"value":52367,"nodeType":867},{},[],{"data":64716,"marks":64717,"value":52372,"nodeType":867},{},[64718],{"type":865},{"data":64720,"marks":64721,"value":52376,"nodeType":867},{},[],{"data":64723,"content":64724,"nodeType":1058},{},[64725],{"data":64726,"marks":64727,"value":52383,"nodeType":867},{},[],{"data":64729,"content":64730,"nodeType":1629},{},[64731,64747,64783,64806],{"data":64732,"content":64733,"nodeType":1586},{},[64734],{"data":64735,"content":64736,"nodeType":876},{},[64737,64740,64744],{"data":64738,"marks":64739,"value":52396,"nodeType":867},{},[],{"data":64741,"marks":64742,"value":52401,"nodeType":867},{},[64743],{"type":865},{"data":64745,"marks":64746,"value":52405,"nodeType":867},{},[],{"data":64748,"content":64749,"nodeType":1586},{},[64750],{"data":64751,"content":64752,"nodeType":876},{},[64753,64756,64763,64766,64770,64773,64780],{"data":64754,"marks":64755,"value":52415,"nodeType":867},{},[],{"data":64757,"content":64758,"nodeType":915},{"uri":52418},[64759],{"data":64760,"marks":64761,"value":2929,"nodeType":867},{},[64762],{"type":913},{"data":64764,"marks":64765,"value":5136,"nodeType":867},{},[],{"data":64767,"marks":64768,"value":52431,"nodeType":867},{},[64769],{"type":865},{"data":64771,"marks":64772,"value":52435,"nodeType":867},{},[],{"data":64774,"content":64775,"nodeType":915},{"uri":42382},[64776],{"data":64777,"marks":64778,"value":52443,"nodeType":867},{},[64779],{"type":913},{"data":64781,"marks":64782,"value":24572,"nodeType":867},{},[],{"data":64784,"content":64785,"nodeType":1586},{},[64786],{"data":64787,"content":64788,"nodeType":876},{},[64789,64793,64796,64803],{"data":64790,"marks":64791,"value":52457,"nodeType":867},{},[64792],{"type":865},{"data":64794,"marks":64795,"value":52461,"nodeType":867},{},[],{"data":64797,"content":64798,"nodeType":915},{"uri":46217},[64799],{"data":64800,"marks":64801,"value":52469,"nodeType":867},{},[64802],{"type":913},{"data":64804,"marks":64805,"value":52473,"nodeType":867},{},[],{"data":64807,"content":64808,"nodeType":1586},{},[64809],{"data":64810,"content":64811,"nodeType":876},{},[64812,64815,64819,64822,64826],{"data":64813,"marks":64814,"value":52483,"nodeType":867},{},[],{"data":64816,"marks":64817,"value":52488,"nodeType":867},{},[64818],{"type":865},{"data":64820,"marks":64821,"value":52492,"nodeType":867},{},[],{"data":64823,"marks":64824,"value":52497,"nodeType":867},{},[64825],{"type":865},{"data":64827,"marks":64828,"value":52501,"nodeType":867},{},[],{"data":64830,"content":64831,"nodeType":1058},{},[64832],{"data":64833,"marks":64834,"value":52508,"nodeType":867},{},[],{"data":64836,"content":64837,"nodeType":876},{},[64838],{"data":64839,"marks":64840,"value":52515,"nodeType":867},{},[],{"data":64842,"content":64843,"nodeType":7904},{},[64844,64883,64942],{"data":64845,"content":64846,"nodeType":7640},{},[64847,64856,64865,64874],{"data":64848,"content":64849,"nodeType":20313},{},[64850],{"data":64851,"content":64852,"nodeType":876},{},[64853],{"data":64854,"marks":64855,"value":52531,"nodeType":867},{},[],{"data":64857,"content":64858,"nodeType":20313},{},[64859],{"data":64860,"content":64861,"nodeType":876},{},[64862],{"data":64863,"marks":64864,"value":52541,"nodeType":867},{},[],{"data":64866,"content":64867,"nodeType":20313},{},[64868],{"data":64869,"content":64870,"nodeType":876},{},[64871],{"data":64872,"marks":64873,"value":52551,"nodeType":867},{},[],{"data":64875,"content":64876,"nodeType":20313},{},[64877],{"data":64878,"content":64879,"nodeType":876},{},[64880],{"data":64881,"marks":64882,"value":52561,"nodeType":867},{},[],{"data":64884,"content":64885,"nodeType":7640},{},[64886,64905,64924,64933],{"data":64887,"content":64888,"nodeType":7628},{},[64889],{"data":64890,"content":64891,"nodeType":876},{},[64892,64895,64902],{"data":64893,"marks":64894,"value":21,"nodeType":867},{},[],{"data":64896,"content":64897,"nodeType":915},{"uri":26236},[64898],{"data":64899,"marks":64900,"value":52581,"nodeType":867},{},[64901],{"type":913},{"data":64903,"marks":64904,"value":21,"nodeType":867},{},[],{"data":64906,"content":64907,"nodeType":7628},{},[64908],{"data":64909,"content":64910,"nodeType":876},{},[64911,64914,64921],{"data":64912,"marks":64913,"value":21,"nodeType":867},{},[],{"data":64915,"content":64916,"nodeType":915},{"uri":52418},[64917],{"data":64918,"marks":64919,"value":395,"nodeType":867},{},[64920],{"type":913},{"data":64922,"marks":64923,"value":21,"nodeType":867},{},[],{"data":64925,"content":64926,"nodeType":7628},{},[64927],{"data":64928,"content":64929,"nodeType":876},{},[64930],{"data":64931,"marks":64932,"value":52613,"nodeType":867},{},[],{"data":64934,"content":64935,"nodeType":7628},{},[64936],{"data":64937,"content":64938,"nodeType":876},{},[64939],{"data":64940,"marks":64941,"value":52623,"nodeType":867},{},[],{"data":64943,"content":64944,"nodeType":7640},{},[64945,64964,64983,64992],{"data":64946,"content":64947,"nodeType":7628},{},[64948],{"data":64949,"content":64950,"nodeType":876},{},[64951,64954,64961],{"data":64952,"marks":64953,"value":21,"nodeType":867},{},[],{"data":64955,"content":64956,"nodeType":915},{"uri":42165},[64957],{"data":64958,"marks":64959,"value":52643,"nodeType":867},{},[64960],{"type":913},{"data":64962,"marks":64963,"value":21,"nodeType":867},{},[],{"data":64965,"content":64966,"nodeType":7628},{},[64967],{"data":64968,"content":64969,"nodeType":876},{},[64970,64973,64980],{"data":64971,"marks":64972,"value":21,"nodeType":867},{},[],{"data":64974,"content":64975,"nodeType":915},{"uri":52658},[64976],{"data":64977,"marks":64978,"value":42575,"nodeType":867},{},[64979],{"type":913},{"data":64981,"marks":64982,"value":21,"nodeType":867},{},[],{"data":64984,"content":64985,"nodeType":7628},{},[64986],{"data":64987,"content":64988,"nodeType":876},{},[64989],{"data":64990,"marks":64991,"value":52676,"nodeType":867},{},[],{"data":64993,"content":64994,"nodeType":7628},{},[64995],{"data":64996,"content":64997,"nodeType":876},{},[64998],{"data":64999,"marks":65000,"value":52686,"nodeType":867},{},[],{"data":65002,"content":65003,"nodeType":1058},{},[65004],{"data":65005,"marks":65006,"value":52693,"nodeType":867},{},[],{"data":65008,"content":65009,"nodeType":876},{},[65010],{"data":65011,"marks":65012,"value":52700,"nodeType":867},{},[],{"data":65014,"content":65015,"nodeType":1629},{},[65016,65025,65034,65043,65052,65061,65070,65079],{"data":65017,"content":65018,"nodeType":1586},{},[65019],{"data":65020,"content":65021,"nodeType":876},{},[65022],{"data":65023,"marks":65024,"value":52713,"nodeType":867},{},[],{"data":65026,"content":65027,"nodeType":1586},{},[65028],{"data":65029,"content":65030,"nodeType":876},{},[65031],{"data":65032,"marks":65033,"value":52723,"nodeType":867},{},[],{"data":65035,"content":65036,"nodeType":1586},{},[65037],{"data":65038,"content":65039,"nodeType":876},{},[65040],{"data":65041,"marks":65042,"value":52733,"nodeType":867},{},[],{"data":65044,"content":65045,"nodeType":1586},{},[65046],{"data":65047,"content":65048,"nodeType":876},{},[65049],{"data":65050,"marks":65051,"value":52743,"nodeType":867},{},[],{"data":65053,"content":65054,"nodeType":1586},{},[65055],{"data":65056,"content":65057,"nodeType":876},{},[65058],{"data":65059,"marks":65060,"value":52753,"nodeType":867},{},[],{"data":65062,"content":65063,"nodeType":1586},{},[65064],{"data":65065,"content":65066,"nodeType":876},{},[65067],{"data":65068,"marks":65069,"value":52763,"nodeType":867},{},[],{"data":65071,"content":65072,"nodeType":1586},{},[65073],{"data":65074,"content":65075,"nodeType":876},{},[65076],{"data":65077,"marks":65078,"value":52773,"nodeType":867},{},[],{"data":65080,"content":65081,"nodeType":1586},{},[65082],{"data":65083,"content":65084,"nodeType":876},{},[65085],{"data":65086,"marks":65087,"value":52783,"nodeType":867},{},[],{"data":65089,"content":65090,"nodeType":942},{},[],{"data":65092,"content":65093,"nodeType":868},{},[65094],{"data":65095,"marks":65096,"value":52793,"nodeType":867},{},[],{"data":65098,"content":65099,"nodeType":876},{},[65100],{"data":65101,"marks":65102,"value":52800,"nodeType":867},{},[],{"data":65104,"content":65105,"nodeType":1058},{},[65106],{"data":65107,"marks":65108,"value":52807,"nodeType":867},{},[],{"data":65110,"content":65111,"nodeType":1629},{},[65112,65121,65130,65139,65148,65157],{"data":65113,"content":65114,"nodeType":1586},{},[65115],{"data":65116,"content":65117,"nodeType":876},{},[65118],{"data":65119,"marks":65120,"value":52820,"nodeType":867},{},[],{"data":65122,"content":65123,"nodeType":1586},{},[65124],{"data":65125,"content":65126,"nodeType":876},{},[65127],{"data":65128,"marks":65129,"value":52830,"nodeType":867},{},[],{"data":65131,"content":65132,"nodeType":1586},{},[65133],{"data":65134,"content":65135,"nodeType":876},{},[65136],{"data":65137,"marks":65138,"value":52840,"nodeType":867},{},[],{"data":65140,"content":65141,"nodeType":1586},{},[65142],{"data":65143,"content":65144,"nodeType":876},{},[65145],{"data":65146,"marks":65147,"value":52850,"nodeType":867},{},[],{"data":65149,"content":65150,"nodeType":1586},{},[65151],{"data":65152,"content":65153,"nodeType":876},{},[65154],{"data":65155,"marks":65156,"value":52860,"nodeType":867},{},[],{"data":65158,"content":65159,"nodeType":1586},{},[65160],{"data":65161,"content":65162,"nodeType":876},{},[65163],{"data":65164,"marks":65165,"value":52870,"nodeType":867},{},[],{"data":65167,"content":65168,"nodeType":1058},{},[65169],{"data":65170,"marks":65171,"value":52877,"nodeType":867},{},[],{"data":65173,"content":65174,"nodeType":1629},{},[65175,65184,65193],{"data":65176,"content":65177,"nodeType":1586},{},[65178],{"data":65179,"content":65180,"nodeType":876},{},[65181],{"data":65182,"marks":65183,"value":52890,"nodeType":867},{},[],{"data":65185,"content":65186,"nodeType":1586},{},[65187],{"data":65188,"content":65189,"nodeType":876},{},[65190],{"data":65191,"marks":65192,"value":52900,"nodeType":867},{},[],{"data":65194,"content":65195,"nodeType":1586},{},[65196],{"data":65197,"content":65198,"nodeType":876},{},[65199],{"data":65200,"marks":65201,"value":52910,"nodeType":867},{},[],{"data":65203,"content":65204,"nodeType":1058},{},[65205],{"data":65206,"marks":65207,"value":52917,"nodeType":867},{},[],{"data":65209,"content":65210,"nodeType":1629},{},[65211,65220,65229,65238],{"data":65212,"content":65213,"nodeType":1586},{},[65214],{"data":65215,"content":65216,"nodeType":876},{},[65217],{"data":65218,"marks":65219,"value":52930,"nodeType":867},{},[],{"data":65221,"content":65222,"nodeType":1586},{},[65223],{"data":65224,"content":65225,"nodeType":876},{},[65226],{"data":65227,"marks":65228,"value":52940,"nodeType":867},{},[],{"data":65230,"content":65231,"nodeType":1586},{},[65232],{"data":65233,"content":65234,"nodeType":876},{},[65235],{"data":65236,"marks":65237,"value":52950,"nodeType":867},{},[],{"data":65239,"content":65240,"nodeType":1586},{},[65241],{"data":65242,"content":65243,"nodeType":876},{},[65244],{"data":65245,"marks":65246,"value":52960,"nodeType":867},{},[],{"data":65248,"content":65249,"nodeType":1058},{},[65250],{"data":65251,"marks":65252,"value":52508,"nodeType":867},{},[],{"data":65254,"content":65255,"nodeType":876},{},[65256],{"data":65257,"marks":65258,"value":52515,"nodeType":867},{},[],{"data":65260,"content":65261,"nodeType":7904},{},[65262,65301,65360,65419],{"data":65263,"content":65264,"nodeType":7640},{},[65265,65274,65283,65292],{"data":65266,"content":65267,"nodeType":20313},{},[65268],{"data":65269,"content":65270,"nodeType":876},{},[65271],{"data":65272,"marks":65273,"value":52531,"nodeType":867},{},[],{"data":65275,"content":65276,"nodeType":20313},{},[65277],{"data":65278,"content":65279,"nodeType":876},{},[65280],{"data":65281,"marks":65282,"value":52997,"nodeType":867},{},[],{"data":65284,"content":65285,"nodeType":20313},{},[65286],{"data":65287,"content":65288,"nodeType":876},{},[65289],{"data":65290,"marks":65291,"value":52551,"nodeType":867},{},[],{"data":65293,"content":65294,"nodeType":20313},{},[65295],{"data":65296,"content":65297,"nodeType":876},{},[65298],{"data":65299,"marks":65300,"value":52561,"nodeType":867},{},[],{"data":65302,"content":65303,"nodeType":7640},{},[65304,65323,65342,65351],{"data":65305,"content":65306,"nodeType":7628},{},[65307],{"data":65308,"content":65309,"nodeType":876},{},[65310,65313,65320],{"data":65311,"marks":65312,"value":21,"nodeType":867},{},[],{"data":65314,"content":65315,"nodeType":915},{"uri":42200},[65316],{"data":65317,"marks":65318,"value":53035,"nodeType":867},{},[65319],{"type":913},{"data":65321,"marks":65322,"value":21,"nodeType":867},{},[],{"data":65324,"content":65325,"nodeType":7628},{},[65326],{"data":65327,"content":65328,"nodeType":876},{},[65329,65332,65339],{"data":65330,"marks":65331,"value":21,"nodeType":867},{},[],{"data":65333,"content":65334,"nodeType":915},{"uri":53050},[65335],{"data":65336,"marks":65337,"value":333,"nodeType":867},{},[65338],{"type":913},{"data":65340,"marks":65341,"value":21,"nodeType":867},{},[],{"data":65343,"content":65344,"nodeType":7628},{},[65345],{"data":65346,"content":65347,"nodeType":876},{},[65348],{"data":65349,"marks":65350,"value":53068,"nodeType":867},{},[],{"data":65352,"content":65353,"nodeType":7628},{},[65354],{"data":65355,"content":65356,"nodeType":876},{},[65357],{"data":65358,"marks":65359,"value":53078,"nodeType":867},{},[],{"data":65361,"content":65362,"nodeType":7640},{},[65363,65382,65401,65410],{"data":65364,"content":65365,"nodeType":7628},{},[65366],{"data":65367,"content":65368,"nodeType":876},{},[65369,65372,65379],{"data":65370,"marks":65371,"value":21,"nodeType":867},{},[],{"data":65373,"content":65374,"nodeType":915},{"uri":42795},[65375],{"data":65376,"marks":65377,"value":53098,"nodeType":867},{},[65378],{"type":913},{"data":65380,"marks":65381,"value":21,"nodeType":867},{},[],{"data":65383,"content":65384,"nodeType":7628},{},[65385],{"data":65386,"content":65387,"nodeType":876},{},[65388,65391,65398],{"data":65389,"marks":65390,"value":21,"nodeType":867},{},[],{"data":65392,"content":65393,"nodeType":915},{"uri":53113},[65394],{"data":65395,"marks":65396,"value":42801,"nodeType":867},{},[65397],{"type":913},{"data":65399,"marks":65400,"value":21,"nodeType":867},{},[],{"data":65402,"content":65403,"nodeType":7628},{},[65404],{"data":65405,"content":65406,"nodeType":876},{},[65407],{"data":65408,"marks":65409,"value":53131,"nodeType":867},{},[],{"data":65411,"content":65412,"nodeType":7628},{},[65413],{"data":65414,"content":65415,"nodeType":876},{},[65416],{"data":65417,"marks":65418,"value":53141,"nodeType":867},{},[],{"data":65420,"content":65421,"nodeType":7640},{},[65422,65441,65460,65469],{"data":65423,"content":65424,"nodeType":7628},{},[65425],{"data":65426,"content":65427,"nodeType":876},{},[65428,65431,65438],{"data":65429,"marks":65430,"value":21,"nodeType":867},{},[],{"data":65432,"content":65433,"nodeType":915},{"uri":43027},[65434],{"data":65435,"marks":65436,"value":53161,"nodeType":867},{},[65437],{"type":913},{"data":65439,"marks":65440,"value":21,"nodeType":867},{},[],{"data":65442,"content":65443,"nodeType":7628},{},[65444],{"data":65445,"content":65446,"nodeType":876},{},[65447,65450,65457],{"data":65448,"marks":65449,"value":21,"nodeType":867},{},[],{"data":65451,"content":65452,"nodeType":915},{"uri":53176},[65453],{"data":65454,"marks":65455,"value":53182,"nodeType":867},{},[65456],{"type":913},{"data":65458,"marks":65459,"value":21,"nodeType":867},{},[],{"data":65461,"content":65462,"nodeType":7628},{},[65463],{"data":65464,"content":65465,"nodeType":876},{},[65466],{"data":65467,"marks":65468,"value":53195,"nodeType":867},{},[],{"data":65470,"content":65471,"nodeType":7628},{},[65472],{"data":65473,"content":65474,"nodeType":876},{},[65475],{"data":65476,"marks":65477,"value":53205,"nodeType":867},{},[],{"data":65479,"content":65480,"nodeType":1058},{},[65481],{"data":65482,"marks":65483,"value":52693,"nodeType":867},{},[],{"data":65485,"content":65486,"nodeType":876},{},[65487],{"data":65488,"marks":65489,"value":53219,"nodeType":867},{},[65490],{"type":865},{"data":65492,"content":65493,"nodeType":876},{},[65494],{"data":65495,"marks":65496,"value":53226,"nodeType":867},{},[],{"data":65498,"content":65499,"nodeType":942},{},[],{"data":65501,"content":65502,"nodeType":868},{},[65503],{"data":65504,"marks":65505,"value":53236,"nodeType":867},{},[],{"data":65507,"content":65508,"nodeType":876},{},[65509],{"data":65510,"marks":65511,"value":53243,"nodeType":867},{},[],{"data":65513,"content":65514,"nodeType":1058},{},[65515],{"data":65516,"marks":65517,"value":53250,"nodeType":867},{},[],{"data":65519,"content":65520,"nodeType":1629},{},[65521,65530,65539,65548,65557],{"data":65522,"content":65523,"nodeType":1586},{},[65524],{"data":65525,"content":65526,"nodeType":876},{},[65527],{"data":65528,"marks":65529,"value":53263,"nodeType":867},{},[],{"data":65531,"content":65532,"nodeType":1586},{},[65533],{"data":65534,"content":65535,"nodeType":876},{},[65536],{"data":65537,"marks":65538,"value":53273,"nodeType":867},{},[],{"data":65540,"content":65541,"nodeType":1586},{},[65542],{"data":65543,"content":65544,"nodeType":876},{},[65545],{"data":65546,"marks":65547,"value":53283,"nodeType":867},{},[],{"data":65549,"content":65550,"nodeType":1586},{},[65551],{"data":65552,"content":65553,"nodeType":876},{},[65554],{"data":65555,"marks":65556,"value":53293,"nodeType":867},{},[],{"data":65558,"content":65559,"nodeType":1586},{},[65560],{"data":65561,"content":65562,"nodeType":876},{},[65563],{"data":65564,"marks":65565,"value":53303,"nodeType":867},{},[],{"data":65567,"content":65568,"nodeType":1058},{},[65569],{"data":65570,"marks":65571,"value":53310,"nodeType":867},{},[],{"data":65573,"content":65574,"nodeType":1629},{},[65575,65584,65593,65602],{"data":65576,"content":65577,"nodeType":1586},{},[65578],{"data":65579,"content":65580,"nodeType":876},{},[65581],{"data":65582,"marks":65583,"value":53323,"nodeType":867},{},[],{"data":65585,"content":65586,"nodeType":1586},{},[65587],{"data":65588,"content":65589,"nodeType":876},{},[65590],{"data":65591,"marks":65592,"value":53333,"nodeType":867},{},[],{"data":65594,"content":65595,"nodeType":1586},{},[65596],{"data":65597,"content":65598,"nodeType":876},{},[65599],{"data":65600,"marks":65601,"value":53343,"nodeType":867},{},[],{"data":65603,"content":65604,"nodeType":1586},{},[65605],{"data":65606,"content":65607,"nodeType":876},{},[65608],{"data":65609,"marks":65610,"value":53353,"nodeType":867},{},[],{"data":65612,"content":65613,"nodeType":1058},{},[65614],{"data":65615,"marks":65616,"value":53360,"nodeType":867},{},[],{"data":65618,"content":65619,"nodeType":1629},{},[65620,65629,65638],{"data":65621,"content":65622,"nodeType":1586},{},[65623],{"data":65624,"content":65625,"nodeType":876},{},[65626],{"data":65627,"marks":65628,"value":53373,"nodeType":867},{},[],{"data":65630,"content":65631,"nodeType":1586},{},[65632],{"data":65633,"content":65634,"nodeType":876},{},[65635],{"data":65636,"marks":65637,"value":53383,"nodeType":867},{},[],{"data":65639,"content":65640,"nodeType":1586},{},[65641],{"data":65642,"content":65643,"nodeType":876},{},[65644],{"data":65645,"marks":65646,"value":53393,"nodeType":867},{},[],{"data":65648,"content":65649,"nodeType":1058},{},[65650],{"data":65651,"marks":65652,"value":52508,"nodeType":867},{},[],{"data":65654,"content":65655,"nodeType":876},{},[65656],{"data":65657,"marks":65658,"value":52515,"nodeType":867},{},[],{"data":65660,"content":65661,"nodeType":7904},{},[65662,65701,65760],{"data":65663,"content":65664,"nodeType":7640},{},[65665,65674,65683,65692],{"data":65666,"content":65667,"nodeType":20313},{},[65668],{"data":65669,"content":65670,"nodeType":876},{},[65671],{"data":65672,"marks":65673,"value":52531,"nodeType":867},{},[],{"data":65675,"content":65676,"nodeType":20313},{},[65677],{"data":65678,"content":65679,"nodeType":876},{},[65680],{"data":65681,"marks":65682,"value":52997,"nodeType":867},{},[],{"data":65684,"content":65685,"nodeType":20313},{},[65686],{"data":65687,"content":65688,"nodeType":876},{},[65689],{"data":65690,"marks":65691,"value":52551,"nodeType":867},{},[],{"data":65693,"content":65694,"nodeType":20313},{},[65695],{"data":65696,"content":65697,"nodeType":876},{},[65698],{"data":65699,"marks":65700,"value":52561,"nodeType":867},{},[],{"data":65702,"content":65703,"nodeType":7640},{},[65704,65723,65742,65751],{"data":65705,"content":65706,"nodeType":7628},{},[65707],{"data":65708,"content":65709,"nodeType":876},{},[65710,65713,65720],{"data":65711,"marks":65712,"value":21,"nodeType":867},{},[],{"data":65714,"content":65715,"nodeType":915},{"uri":42200},[65716],{"data":65717,"marks":65718,"value":53035,"nodeType":867},{},[65719],{"type":913},{"data":65721,"marks":65722,"value":21,"nodeType":867},{},[],{"data":65724,"content":65725,"nodeType":7628},{},[65726],{"data":65727,"content":65728,"nodeType":876},{},[65729,65732,65739],{"data":65730,"marks":65731,"value":21,"nodeType":867},{},[],{"data":65733,"content":65734,"nodeType":915},{"uri":53050},[65735],{"data":65736,"marks":65737,"value":333,"nodeType":867},{},[65738],{"type":913},{"data":65740,"marks":65741,"value":21,"nodeType":867},{},[],{"data":65743,"content":65744,"nodeType":7628},{},[65745],{"data":65746,"content":65747,"nodeType":876},{},[65748],{"data":65749,"marks":65750,"value":53068,"nodeType":867},{},[],{"data":65752,"content":65753,"nodeType":7628},{},[65754],{"data":65755,"content":65756,"nodeType":876},{},[65757],{"data":65758,"marks":65759,"value":53078,"nodeType":867},{},[],{"data":65761,"content":65762,"nodeType":7640},{},[65763,65782,65801,65810],{"data":65764,"content":65765,"nodeType":7628},{},[65766],{"data":65767,"content":65768,"nodeType":876},{},[65769,65772,65779],{"data":65770,"marks":65771,"value":21,"nodeType":867},{},[],{"data":65773,"content":65774,"nodeType":915},{"uri":53521},[65775],{"data":65776,"marks":65777,"value":53527,"nodeType":867},{},[65778],{"type":913},{"data":65780,"marks":65781,"value":21,"nodeType":867},{},[],{"data":65783,"content":65784,"nodeType":7628},{},[65785],{"data":65786,"content":65787,"nodeType":876},{},[65788,65791,65798],{"data":65789,"marks":65790,"value":21,"nodeType":867},{},[],{"data":65792,"content":65793,"nodeType":915},{"uri":53542},[65794],{"data":65795,"marks":65796,"value":53548,"nodeType":867},{},[65797],{"type":913},{"data":65799,"marks":65800,"value":21,"nodeType":867},{},[],{"data":65802,"content":65803,"nodeType":7628},{},[65804],{"data":65805,"content":65806,"nodeType":876},{},[65807],{"data":65808,"marks":65809,"value":53561,"nodeType":867},{},[],{"data":65811,"content":65812,"nodeType":7628},{},[65813],{"data":65814,"content":65815,"nodeType":876},{},[65816],{"data":65817,"marks":65818,"value":53571,"nodeType":867},{},[],{"data":65820,"content":65821,"nodeType":1058},{},[65822],{"data":65823,"marks":65824,"value":52693,"nodeType":867},{},[],{"data":65826,"content":65827,"nodeType":876},{},[65828],{"data":65829,"marks":65830,"value":53585,"nodeType":867},{},[65831],{"type":865},{"data":65833,"content":65834,"nodeType":876},{},[65835],{"data":65836,"marks":65837,"value":53592,"nodeType":867},{},[],{"data":65839,"content":65840,"nodeType":876},{},[65841],{"data":65842,"marks":65843,"value":53600,"nodeType":867},{},[65844],{"type":865},{"data":65846,"content":65847,"nodeType":876},{},[65848],{"data":65849,"marks":65850,"value":53607,"nodeType":867},{},[],{"data":65852,"content":65853,"nodeType":876},{},[65854],{"data":65855,"marks":65856,"value":53615,"nodeType":867},{},[65857],{"type":865},{"data":65859,"content":65860,"nodeType":876},{},[65861],{"data":65862,"marks":65863,"value":53622,"nodeType":867},{},[],{"data":65865,"content":65866,"nodeType":942},{},[],{"data":65868,"content":65869,"nodeType":868},{},[65870],{"data":65871,"marks":65872,"value":53632,"nodeType":867},{},[],{"data":65874,"content":65875,"nodeType":876},{},[65876],{"data":65877,"marks":65878,"value":53639,"nodeType":867},{},[],{"data":65880,"content":65881,"nodeType":1058},{},[65882],{"data":65883,"marks":65884,"value":53646,"nodeType":867},{},[],{"data":65886,"content":65887,"nodeType":1629},{},[65888,65897,65906,65915,65924,65933],{"data":65889,"content":65890,"nodeType":1586},{},[65891],{"data":65892,"content":65893,"nodeType":876},{},[65894],{"data":65895,"marks":65896,"value":53659,"nodeType":867},{},[],{"data":65898,"content":65899,"nodeType":1586},{},[65900],{"data":65901,"content":65902,"nodeType":876},{},[65903],{"data":65904,"marks":65905,"value":53669,"nodeType":867},{},[],{"data":65907,"content":65908,"nodeType":1586},{},[65909],{"data":65910,"content":65911,"nodeType":876},{},[65912],{"data":65913,"marks":65914,"value":53679,"nodeType":867},{},[],{"data":65916,"content":65917,"nodeType":1586},{},[65918],{"data":65919,"content":65920,"nodeType":876},{},[65921],{"data":65922,"marks":65923,"value":53689,"nodeType":867},{},[],{"data":65925,"content":65926,"nodeType":1586},{},[65927],{"data":65928,"content":65929,"nodeType":876},{},[65930],{"data":65931,"marks":65932,"value":53699,"nodeType":867},{},[],{"data":65934,"content":65935,"nodeType":1586},{},[65936],{"data":65937,"content":65938,"nodeType":876},{},[65939],{"data":65940,"marks":65941,"value":53709,"nodeType":867},{},[],{"data":65943,"content":65944,"nodeType":1058},{},[65945],{"data":65946,"marks":65947,"value":53716,"nodeType":867},{},[],{"data":65949,"content":65950,"nodeType":1629},{},[65951,65960,65969],{"data":65952,"content":65953,"nodeType":1586},{},[65954],{"data":65955,"content":65956,"nodeType":876},{},[65957],{"data":65958,"marks":65959,"value":53729,"nodeType":867},{},[],{"data":65961,"content":65962,"nodeType":1586},{},[65963],{"data":65964,"content":65965,"nodeType":876},{},[65966],{"data":65967,"marks":65968,"value":53739,"nodeType":867},{},[],{"data":65970,"content":65971,"nodeType":1586},{},[65972],{"data":65973,"content":65974,"nodeType":876},{},[65975],{"data":65976,"marks":65977,"value":53749,"nodeType":867},{},[],{"data":65979,"content":65980,"nodeType":1058},{},[65981],{"data":65982,"marks":65983,"value":53756,"nodeType":867},{},[],{"data":65985,"content":65986,"nodeType":1629},{},[65987,65996,66005],{"data":65988,"content":65989,"nodeType":1586},{},[65990],{"data":65991,"content":65992,"nodeType":876},{},[65993],{"data":65994,"marks":65995,"value":53769,"nodeType":867},{},[],{"data":65997,"content":65998,"nodeType":1586},{},[65999],{"data":66000,"content":66001,"nodeType":876},{},[66002],{"data":66003,"marks":66004,"value":53779,"nodeType":867},{},[],{"data":66006,"content":66007,"nodeType":1586},{},[66008],{"data":66009,"content":66010,"nodeType":876},{},[66011],{"data":66012,"marks":66013,"value":53789,"nodeType":867},{},[],{"data":66015,"content":66016,"nodeType":1058},{},[66017],{"data":66018,"marks":66019,"value":52508,"nodeType":867},{},[],{"data":66021,"content":66022,"nodeType":876},{},[66023],{"data":66024,"marks":66025,"value":52515,"nodeType":867},{},[],{"data":66027,"content":66028,"nodeType":7904},{},[66029,66068],{"data":66030,"content":66031,"nodeType":7640},{},[66032,66041,66050,66059],{"data":66033,"content":66034,"nodeType":20313},{},[66035],{"data":66036,"content":66037,"nodeType":876},{},[66038],{"data":66039,"marks":66040,"value":52531,"nodeType":867},{},[],{"data":66042,"content":66043,"nodeType":20313},{},[66044],{"data":66045,"content":66046,"nodeType":876},{},[66047],{"data":66048,"marks":66049,"value":52997,"nodeType":867},{},[],{"data":66051,"content":66052,"nodeType":20313},{},[66053],{"data":66054,"content":66055,"nodeType":876},{},[66056],{"data":66057,"marks":66058,"value":52551,"nodeType":867},{},[],{"data":66060,"content":66061,"nodeType":20313},{},[66062],{"data":66063,"content":66064,"nodeType":876},{},[66065],{"data":66066,"marks":66067,"value":52561,"nodeType":867},{},[],{"data":66069,"content":66070,"nodeType":7640},{},[66071,66090,66109,66118],{"data":66072,"content":66073,"nodeType":7628},{},[66074],{"data":66075,"content":66076,"nodeType":876},{},[66077,66080,66087],{"data":66078,"marks":66079,"value":21,"nodeType":867},{},[],{"data":66081,"content":66082,"nodeType":915},{"uri":27840},[66083],{"data":66084,"marks":66085,"value":53863,"nodeType":867},{},[66086],{"type":913},{"data":66088,"marks":66089,"value":21,"nodeType":867},{},[],{"data":66091,"content":66092,"nodeType":7628},{},[66093],{"data":66094,"content":66095,"nodeType":876},{},[66096,66099,66106],{"data":66097,"marks":66098,"value":21,"nodeType":867},{},[],{"data":66100,"content":66101,"nodeType":915},{"uri":53878},[66102],{"data":66103,"marks":66104,"value":53884,"nodeType":867},{},[66105],{"type":913},{"data":66107,"marks":66108,"value":21,"nodeType":867},{},[],{"data":66110,"content":66111,"nodeType":7628},{},[66112],{"data":66113,"content":66114,"nodeType":876},{},[66115],{"data":66116,"marks":66117,"value":53897,"nodeType":867},{},[],{"data":66119,"content":66120,"nodeType":7628},{},[66121],{"data":66122,"content":66123,"nodeType":876},{},[66124],{"data":66125,"marks":66126,"value":53907,"nodeType":867},{},[],{"data":66128,"content":66129,"nodeType":942},{},[],{"data":66131,"content":66132,"nodeType":868},{},[66133],{"data":66134,"marks":66135,"value":53917,"nodeType":867},{},[],{"data":66137,"content":66138,"nodeType":876},{},[66139],{"data":66140,"marks":66141,"value":53924,"nodeType":867},{},[],{"data":66143,"content":66144,"nodeType":1058},{},[66145],{"data":66146,"marks":66147,"value":53931,"nodeType":867},{},[],{"data":66149,"content":66150,"nodeType":1629},{},[66151,66160,66169,66178,66187,66196],{"data":66152,"content":66153,"nodeType":1586},{},[66154],{"data":66155,"content":66156,"nodeType":876},{},[66157],{"data":66158,"marks":66159,"value":53944,"nodeType":867},{},[],{"data":66161,"content":66162,"nodeType":1586},{},[66163],{"data":66164,"content":66165,"nodeType":876},{},[66166],{"data":66167,"marks":66168,"value":53954,"nodeType":867},{},[],{"data":66170,"content":66171,"nodeType":1586},{},[66172],{"data":66173,"content":66174,"nodeType":876},{},[66175],{"data":66176,"marks":66177,"value":53964,"nodeType":867},{},[],{"data":66179,"content":66180,"nodeType":1586},{},[66181],{"data":66182,"content":66183,"nodeType":876},{},[66184],{"data":66185,"marks":66186,"value":53974,"nodeType":867},{},[],{"data":66188,"content":66189,"nodeType":1586},{},[66190],{"data":66191,"content":66192,"nodeType":876},{},[66193],{"data":66194,"marks":66195,"value":53984,"nodeType":867},{},[],{"data":66197,"content":66198,"nodeType":1586},{},[66199],{"data":66200,"content":66201,"nodeType":876},{},[66202],{"data":66203,"marks":66204,"value":53994,"nodeType":867},{},[],{"data":66206,"content":66207,"nodeType":1058},{},[66208],{"data":66209,"marks":66210,"value":54001,"nodeType":867},{},[],{"data":66212,"content":66213,"nodeType":1629},{},[66214,66223,66232],{"data":66215,"content":66216,"nodeType":1586},{},[66217],{"data":66218,"content":66219,"nodeType":876},{},[66220],{"data":66221,"marks":66222,"value":54014,"nodeType":867},{},[],{"data":66224,"content":66225,"nodeType":1586},{},[66226],{"data":66227,"content":66228,"nodeType":876},{},[66229],{"data":66230,"marks":66231,"value":54024,"nodeType":867},{},[],{"data":66233,"content":66234,"nodeType":1586},{},[66235],{"data":66236,"content":66237,"nodeType":876},{},[66238],{"data":66239,"marks":66240,"value":54034,"nodeType":867},{},[],{"data":66242,"content":66243,"nodeType":1058},{},[66244],{"data":66245,"marks":66246,"value":54041,"nodeType":867},{},[],{"data":66248,"content":66249,"nodeType":1629},{},[66250,66259,66268],{"data":66251,"content":66252,"nodeType":1586},{},[66253],{"data":66254,"content":66255,"nodeType":876},{},[66256],{"data":66257,"marks":66258,"value":54054,"nodeType":867},{},[],{"data":66260,"content":66261,"nodeType":1586},{},[66262],{"data":66263,"content":66264,"nodeType":876},{},[66265],{"data":66266,"marks":66267,"value":54064,"nodeType":867},{},[],{"data":66269,"content":66270,"nodeType":1586},{},[66271],{"data":66272,"content":66273,"nodeType":876},{},[66274],{"data":66275,"marks":66276,"value":54074,"nodeType":867},{},[],{"data":66278,"content":66279,"nodeType":1058},{},[66280],{"data":66281,"marks":66282,"value":52508,"nodeType":867},{},[],{"data":66284,"content":66285,"nodeType":876},{},[66286],{"data":66287,"marks":66288,"value":52515,"nodeType":867},{},[],{"data":66290,"content":66291,"nodeType":7904},{},[66292,66331,66392],{"data":66293,"content":66294,"nodeType":7640},{},[66295,66304,66313,66322],{"data":66296,"content":66297,"nodeType":20313},{},[66298],{"data":66299,"content":66300,"nodeType":876},{},[66301],{"data":66302,"marks":66303,"value":52531,"nodeType":867},{},[],{"data":66305,"content":66306,"nodeType":20313},{},[66307],{"data":66308,"content":66309,"nodeType":876},{},[66310],{"data":66311,"marks":66312,"value":52997,"nodeType":867},{},[],{"data":66314,"content":66315,"nodeType":20313},{},[66316],{"data":66317,"content":66318,"nodeType":876},{},[66319],{"data":66320,"marks":66321,"value":52551,"nodeType":867},{},[],{"data":66323,"content":66324,"nodeType":20313},{},[66325],{"data":66326,"content":66327,"nodeType":876},{},[66328],{"data":66329,"marks":66330,"value":52561,"nodeType":867},{},[],{"data":66332,"content":66333,"nodeType":7640},{},[66334,66354,66374,66383],{"data":66335,"content":66336,"nodeType":7628},{},[66337],{"data":66338,"content":66339,"nodeType":876},{},[66340,66344,66351],{"data":66341,"marks":66342,"value":21,"nodeType":867},{},[66343],{"type":913},{"data":66345,"content":66346,"nodeType":915},{"uri":42153},[66347],{"data":66348,"marks":66349,"value":54149,"nodeType":867},{},[66350],{"type":913},{"data":66352,"marks":66353,"value":21,"nodeType":867},{},[],{"data":66355,"content":66356,"nodeType":7628},{},[66357],{"data":66358,"content":66359,"nodeType":876},{},[66360,66364,66371],{"data":66361,"marks":66362,"value":21,"nodeType":867},{},[66363],{"type":913},{"data":66365,"content":66366,"nodeType":915},{"uri":54165},[66367],{"data":66368,"marks":66369,"value":54171,"nodeType":867},{},[66370],{"type":913},{"data":66372,"marks":66373,"value":21,"nodeType":867},{},[],{"data":66375,"content":66376,"nodeType":7628},{},[66377],{"data":66378,"content":66379,"nodeType":876},{},[66380],{"data":66381,"marks":66382,"value":53068,"nodeType":867},{},[],{"data":66384,"content":66385,"nodeType":7628},{},[66386],{"data":66387,"content":66388,"nodeType":876},{},[66389],{"data":66390,"marks":66391,"value":54193,"nodeType":867},{},[],{"data":66393,"content":66394,"nodeType":7640},{},[66395,66414,66435,66444],{"data":66396,"content":66397,"nodeType":7628},{},[66398],{"data":66399,"content":66400,"nodeType":876},{},[66401,66404,66411],{"data":66402,"marks":66403,"value":21,"nodeType":867},{},[],{"data":66405,"content":66406,"nodeType":915},{"uri":54208},[66407],{"data":66408,"marks":66409,"value":54214,"nodeType":867},{},[66410],{"type":913},{"data":66412,"marks":66413,"value":21,"nodeType":867},{},[],{"data":66415,"content":66416,"nodeType":7628},{},[66417],{"data":66418,"content":66419,"nodeType":876},{},[66420,66424,66431],{"data":66421,"marks":66422,"value":21,"nodeType":867},{},[66423],{"type":913},{"data":66425,"content":66426,"nodeType":915},{"uri":54230},[66427],{"data":66428,"marks":66429,"value":54236,"nodeType":867},{},[66430],{"type":913},{"data":66432,"marks":66433,"value":21,"nodeType":867},{},[66434],{"type":913},{"data":66436,"content":66437,"nodeType":7628},{},[66438],{"data":66439,"content":66440,"nodeType":876},{},[66441],{"data":66442,"marks":66443,"value":54250,"nodeType":867},{},[],{"data":66445,"content":66446,"nodeType":7628},{},[66447],{"data":66448,"content":66449,"nodeType":876},{},[66450],{"data":66451,"marks":66452,"value":54260,"nodeType":867},{},[],{"data":66454,"content":66455,"nodeType":942},{},[],{"data":66457,"content":66458,"nodeType":868},{},[66459],{"data":66460,"marks":66461,"value":54270,"nodeType":867},{},[],{"data":66463,"content":66464,"nodeType":876},{},[66465],{"data":66466,"marks":66467,"value":54277,"nodeType":867},{},[],{"data":66469,"content":66470,"nodeType":1058},{},[66471],{"data":66472,"marks":66473,"value":54284,"nodeType":867},{},[],{"data":66475,"content":66476,"nodeType":1629},{},[66477,66486,66495,66504,66513,66522,66531],{"data":66478,"content":66479,"nodeType":1586},{},[66480],{"data":66481,"content":66482,"nodeType":876},{},[66483],{"data":66484,"marks":66485,"value":54297,"nodeType":867},{},[],{"data":66487,"content":66488,"nodeType":1586},{},[66489],{"data":66490,"content":66491,"nodeType":876},{},[66492],{"data":66493,"marks":66494,"value":54307,"nodeType":867},{},[],{"data":66496,"content":66497,"nodeType":1586},{},[66498],{"data":66499,"content":66500,"nodeType":876},{},[66501],{"data":66502,"marks":66503,"value":54317,"nodeType":867},{},[],{"data":66505,"content":66506,"nodeType":1586},{},[66507],{"data":66508,"content":66509,"nodeType":876},{},[66510],{"data":66511,"marks":66512,"value":54327,"nodeType":867},{},[],{"data":66514,"content":66515,"nodeType":1586},{},[66516],{"data":66517,"content":66518,"nodeType":876},{},[66519],{"data":66520,"marks":66521,"value":54337,"nodeType":867},{},[],{"data":66523,"content":66524,"nodeType":1586},{},[66525],{"data":66526,"content":66527,"nodeType":876},{},[66528],{"data":66529,"marks":66530,"value":54347,"nodeType":867},{},[],{"data":66532,"content":66533,"nodeType":1586},{},[66534],{"data":66535,"content":66536,"nodeType":876},{},[66537],{"data":66538,"marks":66539,"value":54357,"nodeType":867},{},[],{"data":66541,"content":66542,"nodeType":1058},{},[66543],{"data":66544,"marks":66545,"value":54364,"nodeType":867},{},[],{"data":66547,"content":66548,"nodeType":1629},{},[66549,66558,66567],{"data":66550,"content":66551,"nodeType":1586},{},[66552],{"data":66553,"content":66554,"nodeType":876},{},[66555],{"data":66556,"marks":66557,"value":54377,"nodeType":867},{},[],{"data":66559,"content":66560,"nodeType":1586},{},[66561],{"data":66562,"content":66563,"nodeType":876},{},[66564],{"data":66565,"marks":66566,"value":54387,"nodeType":867},{},[],{"data":66568,"content":66569,"nodeType":1586},{},[66570],{"data":66571,"content":66572,"nodeType":876},{},[66573],{"data":66574,"marks":66575,"value":54397,"nodeType":867},{},[],{"data":66577,"content":66578,"nodeType":1058},{},[66579],{"data":66580,"marks":66581,"value":54404,"nodeType":867},{},[],{"data":66583,"content":66584,"nodeType":1629},{},[66585,66594,66603],{"data":66586,"content":66587,"nodeType":1586},{},[66588],{"data":66589,"content":66590,"nodeType":876},{},[66591],{"data":66592,"marks":66593,"value":54417,"nodeType":867},{},[],{"data":66595,"content":66596,"nodeType":1586},{},[66597],{"data":66598,"content":66599,"nodeType":876},{},[66600],{"data":66601,"marks":66602,"value":54427,"nodeType":867},{},[],{"data":66604,"content":66605,"nodeType":1586},{},[66606],{"data":66607,"content":66608,"nodeType":876},{},[66609],{"data":66610,"marks":66611,"value":54437,"nodeType":867},{},[],{"data":66613,"content":66614,"nodeType":1058},{},[66615],{"data":66616,"marks":66617,"value":52508,"nodeType":867},{},[],{"data":66619,"content":66620,"nodeType":876},{},[66621],{"data":66622,"marks":66623,"value":52515,"nodeType":867},{},[],{"data":66625,"content":66626,"nodeType":7904},{},[66627,66666,66725,66784],{"data":66628,"content":66629,"nodeType":7640},{},[66630,66639,66648,66657],{"data":66631,"content":66632,"nodeType":20313},{},[66633],{"data":66634,"content":66635,"nodeType":876},{},[66636],{"data":66637,"marks":66638,"value":52531,"nodeType":867},{},[],{"data":66640,"content":66641,"nodeType":20313},{},[66642],{"data":66643,"content":66644,"nodeType":876},{},[66645],{"data":66646,"marks":66647,"value":52997,"nodeType":867},{},[],{"data":66649,"content":66650,"nodeType":20313},{},[66651],{"data":66652,"content":66653,"nodeType":876},{},[66654],{"data":66655,"marks":66656,"value":52551,"nodeType":867},{},[],{"data":66658,"content":66659,"nodeType":20313},{},[66660],{"data":66661,"content":66662,"nodeType":876},{},[66663],{"data":66664,"marks":66665,"value":52561,"nodeType":867},{},[],{"data":66667,"content":66668,"nodeType":7640},{},[66669,66688,66707,66716],{"data":66670,"content":66671,"nodeType":7628},{},[66672],{"data":66673,"content":66674,"nodeType":876},{},[66675,66678,66685],{"data":66676,"marks":66677,"value":21,"nodeType":867},{},[],{"data":66679,"content":66680,"nodeType":915},{"uri":43027},[66681],{"data":66682,"marks":66683,"value":53161,"nodeType":867},{},[66684],{"type":913},{"data":66686,"marks":66687,"value":21,"nodeType":867},{},[],{"data":66689,"content":66690,"nodeType":7628},{},[66691],{"data":66692,"content":66693,"nodeType":876},{},[66694,66697,66704],{"data":66695,"marks":66696,"value":21,"nodeType":867},{},[],{"data":66698,"content":66699,"nodeType":915},{"uri":53176},[66700],{"data":66701,"marks":66702,"value":53182,"nodeType":867},{},[66703],{"type":913},{"data":66705,"marks":66706,"value":21,"nodeType":867},{},[],{"data":66708,"content":66709,"nodeType":7628},{},[66710],{"data":66711,"content":66712,"nodeType":876},{},[66713],{"data":66714,"marks":66715,"value":54542,"nodeType":867},{},[],{"data":66717,"content":66718,"nodeType":7628},{},[66719],{"data":66720,"content":66721,"nodeType":876},{},[66722],{"data":66723,"marks":66724,"value":53205,"nodeType":867},{},[],{"data":66726,"content":66727,"nodeType":7640},{},[66728,66747,66766,66775],{"data":66729,"content":66730,"nodeType":7628},{},[66731],{"data":66732,"content":66733,"nodeType":876},{},[66734,66737,66744],{"data":66735,"marks":66736,"value":21,"nodeType":867},{},[],{"data":66738,"content":66739,"nodeType":915},{"uri":26258},[66740],{"data":66741,"marks":66742,"value":54571,"nodeType":867},{},[66743],{"type":913},{"data":66745,"marks":66746,"value":21,"nodeType":867},{},[],{"data":66748,"content":66749,"nodeType":7628},{},[66750],{"data":66751,"content":66752,"nodeType":876},{},[66753,66756,66763],{"data":66754,"marks":66755,"value":21,"nodeType":867},{},[],{"data":66757,"content":66758,"nodeType":915},{"uri":54586},[66759],{"data":66760,"marks":66761,"value":42812,"nodeType":867},{},[66762],{"type":913},{"data":66764,"marks":66765,"value":21,"nodeType":867},{},[],{"data":66767,"content":66768,"nodeType":7628},{},[66769],{"data":66770,"content":66771,"nodeType":876},{},[66772],{"data":66773,"marks":66774,"value":54604,"nodeType":867},{},[],{"data":66776,"content":66777,"nodeType":7628},{},[66778],{"data":66779,"content":66780,"nodeType":876},{},[66781],{"data":66782,"marks":66783,"value":54614,"nodeType":867},{},[],{"data":66785,"content":66786,"nodeType":7640},{},[66787,66806,66825,66834],{"data":66788,"content":66789,"nodeType":7628},{},[66790],{"data":66791,"content":66792,"nodeType":876},{},[66793,66796,66803],{"data":66794,"marks":66795,"value":21,"nodeType":867},{},[],{"data":66797,"content":66798,"nodeType":915},{"uri":54629},[66799],{"data":66800,"marks":66801,"value":54635,"nodeType":867},{},[66802],{"type":913},{"data":66804,"marks":66805,"value":21,"nodeType":867},{},[],{"data":66807,"content":66808,"nodeType":7628},{},[66809],{"data":66810,"content":66811,"nodeType":876},{},[66812,66815,66822],{"data":66813,"marks":66814,"value":21,"nodeType":867},{},[],{"data":66816,"content":66817,"nodeType":915},{"uri":54650},[66818],{"data":66819,"marks":66820,"value":54656,"nodeType":867},{},[66821],{"type":913},{"data":66823,"marks":66824,"value":21,"nodeType":867},{},[],{"data":66826,"content":66827,"nodeType":7628},{},[66828],{"data":66829,"content":66830,"nodeType":876},{},[66831],{"data":66832,"marks":66833,"value":54669,"nodeType":867},{},[],{"data":66835,"content":66836,"nodeType":7628},{},[66837],{"data":66838,"content":66839,"nodeType":876},{},[66840],{"data":66841,"marks":66842,"value":54679,"nodeType":867},{},[],{"data":66844,"content":66845,"nodeType":942},{},[],{"data":66847,"content":66848,"nodeType":868},{},[66849],{"data":66850,"marks":66851,"value":54689,"nodeType":867},{},[],{"data":66853,"content":66854,"nodeType":1058},{},[66855],{"data":66856,"marks":66857,"value":54696,"nodeType":867},{},[],{"data":66859,"content":66860,"nodeType":876},{},[66861],{"data":66862,"marks":66863,"value":54703,"nodeType":867},{},[],{"data":66865,"content":66866,"nodeType":876},{},[66867],{"data":66868,"marks":66869,"value":54710,"nodeType":867},{},[],{"data":66871,"content":66872,"nodeType":942},{},[],{"data":66874,"content":66875,"nodeType":1058},{},[66876],{"data":66877,"marks":66878,"value":54720,"nodeType":867},{},[],{"data":66880,"content":66881,"nodeType":876},{},[66882],{"data":66883,"marks":66884,"value":54727,"nodeType":867},{},[],{"data":66886,"content":66887,"nodeType":876},{},[66888],{"data":66889,"marks":66890,"value":54734,"nodeType":867},{},[],{"data":66892,"content":66893,"nodeType":942},{},[],{"data":66895,"content":66896,"nodeType":1058},{},[66897],{"data":66898,"marks":66899,"value":54744,"nodeType":867},{},[],{"data":66901,"content":66902,"nodeType":876},{},[66903],{"data":66904,"marks":66905,"value":54751,"nodeType":867},{},[],{"data":66907,"content":66908,"nodeType":876},{},[66909],{"data":66910,"marks":66911,"value":54758,"nodeType":867},{},[],{"data":66913,"content":66914,"nodeType":876},{},[66915],{"data":66916,"marks":66917,"value":54765,"nodeType":867},{},[],{"items":66919},[66920,66922],{"sys":66921,"name":4018},{"id":4017},{"sys":66923,"name":342},{"id":3240},{"items":66925},[66926],{"fullName":4022,"firstName":4023,"jobTitle":4024,"profilePicture":66927},{"url":4026},"blog/saas-attack-techniques",{"json":66930},{"data":66931,"content":66932,"nodeType":1680},{},[66933],{"data":66934,"content":66935,"nodeType":876},{},[66936],{"data":66937,"marks":66938,"value":61772,"nodeType":867},{},[],{"id":60991,"publishedAt":66940},"2026-08-12T11:56:09.096Z",{"items":66942},[66943,66945],{"sys":66944,"name":4018},{"id":4017},{"sys":66946,"name":342},{"id":3240},{"items":66948},[66949,66951,66953,66955,66957,66959,66961,66963,66965,66967,66969,66971,66973,66975],{"sys":66950,"name":279,"slug":280,"tier":31},{"id":276},{"sys":66952,"name":413,"slug":414,"tier":31},{"id":410},{"sys":66954,"name":545,"slug":546,"tier":31},{"id":542},{"sys":66956,"name":642,"slug":643,"tier":31},{"id":639},{"sys":66958,"name":342,"slug":343,"tier":31},{"id":339},{"sys":66960,"name":404,"slug":405,"tier":45},{"id":401},{"sys":66962,"name":484,"slug":485,"tier":45},{"id":481},{"sys":66964,"name":324,"slug":325,"tier":45},{"id":321},{"sys":66966,"name":333,"slug":334,"tier":45},{"id":330},{"sys":66968,"name":395,"slug":396,"tier":45},{"id":392},{"sys":66970,"name":607,"slug":608,"tier":45},{"id":604},{"sys":66972,"name":431,"slug":432,"tier":45},{"id":428},{"sys":66974,"name":377,"slug":378,"tier":45},{"id":374},{"sys":66976,"name":475,"slug":476,"tier":45},{"id":472},"0szC1VTC1eFfVaNqA8iSM9qG0Z5QA_j3akEjwUCQQ5M",{"id":66979,"title":66980,"authorsCollection":66981,"content":66989,"extension":228,"faqItemsCollection":67663,"faqTitle":59,"featured":6,"hashTags":59,"meta":67665,"metaTitle":67666,"ogImage":59,"postType":1767,"publishedDate":67667,"relatedBlogPostsCollection":67668,"slug":68342,"stem":68343,"subtitle":59,"summary":68344,"synopsis":68355,"sys":68356,"tagsCollection":68359,"topicsCollection":68365,"__hash__":68395},"blog/blog/embrace-saas-to-move-faster-than-your-competitors.json","Embrace SaaS to move faster than your competitors",{"items":66982},[66983],{"fullName":66984,"firstName":66985,"jobTitle":66986,"socialLinks":59,"profilePicture":66987},"Sally Soulliere","Sally","Head of Brand & Content",{"url":66988},"https://images.ctfassets.net/y1cdw1ablpvd/7Gh4SbbEj6Zsbd6OzGto8Q/885041a4ddeccc5ef3045c0e22975ef4/T016S22KZ96-U036FPETQRH-330f87708d26-192.jpeg",{"json":66990,"links":67658},{"data":66991,"content":66992,"nodeType":1680},{},[66993,67000,67007,67013,67020,67037,67044,67082,67089,67095,67132,67148,67155,67161,67167,67184,67201,67208,67241,67247,67264,67270,67276,67302,67318,67324,67330,67337,67344,67350,67357,67364,67371,67377,67384,67390,67396,67402,67416,67422,67479,67486,67493,67518,67532,67539,67545,67552,67579,67597,67604,67610,67617,67624,67641],{"data":66994,"content":66995,"nodeType":876},{},[66996],{"data":66997,"marks":66998,"value":66999,"nodeType":867},{},[],"Our goal at Push is simple - to reduce the risk of using SaaS apps at work. Doing this well means building controls that are easy to use, easy to understand - and ultimately effective. Not just effective against the hand-wavy concept of “SaaS attacks” but specific techniques –the most common techniques that are likely to cause real damage.",{"data":67001,"content":67002,"nodeType":876},{},[67003],{"data":67004,"marks":67005,"value":67006,"nodeType":867},{},[],"To talk about this, we need to have a shared understanding of what these techniques are. To get that conversation going we’ve pulled together all the techniques we're aware of, and our research team has even added a bunch of new ones.",{"data":67008,"content":67009,"nodeType":868},{},[67010],{"data":67011,"marks":67012,"value":61030,"nodeType":867},{},[],{"data":67014,"content":67015,"nodeType":876},{},[67016],{"data":67017,"marks":67018,"value":67019,"nodeType":867},{},[],"We’ve taken inspiration from the MITRE ATT&CK framework (certainly intended as the sincerest form of flattery), but wanted to make a conscious break away from the endpoint-focused ATT&CK techniques and instead focus on techniques that are SaaS-specific. In fact, these techniques don’t touch endpoints (so they bypass EDR) or customer networks (so  they bypass network detection) - so we’re calling them networkless attacks.",{"data":67021,"content":67022,"nodeType":876},{},[67023,67027,67034],{"data":67024,"marks":67025,"value":67026,"nodeType":867},{},[],"You can find more detailed descriptions of these techniques (and hopefully PR’s for some we missed) on ",{"data":67028,"content":67029,"nodeType":915},{"uri":15408},[67030],{"data":67031,"marks":67032,"value":14515,"nodeType":867},{},[67033],{"type":913},{"data":67035,"marks":67036,"value":21,"nodeType":867},{},[],{"data":67038,"content":67039,"nodeType":876},{},[67040],{"data":67041,"marks":67042,"value":67043,"nodeType":867},{},[],"Since we’re not targeting endpoints, let’s talk about the new targets: the accounts/identities on SaaS apps. We found it was useful to not think about these identities as stand-alone isolated islands - they are much more like a graph; less a single web-server on the internet and more like many Windows endpoints on an Active Directory. ",{"data":67045,"content":67046,"nodeType":876},{},[67047,67051,67058,67061,67068,67072,67079],{"data":67048,"marks":67049,"value":67050,"nodeType":867},{},[],"You can leverage this access to an identity on a trusted platform to target (so laterally more or escalate privilege to) other users or identities. For example, attacks like using access to SaaS apps to ",{"data":67052,"content":67053,"nodeType":915},{"uri":35191},[67054],{"data":67055,"marks":67056,"value":61082,"nodeType":867},{},[67057],{"type":913},{"data":67059,"marks":67060,"value":1174,"nodeType":867},{},[],{"data":67062,"content":67063,"nodeType":915},{"uri":61088},[67064],{"data":67065,"marks":67066,"value":61094,"nodeType":867},{},[67067],{"type":913},{"data":67069,"marks":67070,"value":67071,"nodeType":867},{},[]," to social engineer them there - or perhaps ",{"data":67073,"content":67074,"nodeType":915},{"uri":42831},[67075],{"data":67076,"marks":67077,"value":61106,"nodeType":867},{},[67078],{"type":913},{"data":67080,"marks":67081,"value":61110,"nodeType":867},{},[],{"data":67083,"content":67084,"nodeType":876},{},[67085],{"data":67086,"marks":67087,"value":67088,"nodeType":867},{},[],"In this case, unusually, it’s not the data in these hundreds of SaaS apps that create risk, and you need to consider low-risk (from a data perspective) apps as a vector to pivot to higher risk apps in your estate.",{"data":67090,"content":67091,"nodeType":1058},{},[67092],{"data":67093,"marks":67094,"value":61124,"nodeType":867},{},[],{"data":67096,"content":67097,"nodeType":876},{},[67098,67101,67108,67111,67118,67122,67129],{"data":67099,"marks":67100,"value":61131,"nodeType":867},{},[],{"data":67102,"content":67103,"nodeType":915},{"uri":42200},[67104],{"data":67105,"marks":67106,"value":37948,"nodeType":867},{},[67107],{"type":913},{"data":67109,"marks":67110,"value":1174,"nodeType":867},{},[],{"data":67112,"content":67113,"nodeType":915},{"uri":42211},[67114],{"data":67115,"marks":67116,"value":42216,"nodeType":867},{},[67117],{"type":913},{"data":67119,"marks":67120,"value":67121,"nodeType":867},{},[]," that get you initial access to SaaS apps are fairly well known - because they work and are widely used. We’re also starting to see tools and attacks that suggest ",{"data":67123,"content":67124,"nodeType":915},{"uri":42879},[67125],{"data":67126,"marks":67127,"value":61160,"nodeType":867},{},[67128],{"type":913},{"data":67130,"marks":67131,"value":61164,"nodeType":867},{},[],{"data":67133,"content":67134,"nodeType":876},{},[67135,67138,67145],{"data":67136,"marks":67137,"value":61171,"nodeType":867},{},[],{"data":67139,"content":67140,"nodeType":915},{"uri":61174},[67141],{"data":67142,"marks":67143,"value":61180,"nodeType":867},{},[67144],{"type":913},{"data":67146,"marks":67147,"value":61184,"nodeType":867},{},[],{"data":67149,"content":67150,"nodeType":876},{},[67151],{"data":67152,"marks":67153,"value":67154,"nodeType":867},{},[],"SaaS apps allow anyone to name app tenants (a.k.a. spaces, teams, or instances) anything they like - including your company name. Attackers send invites to your employees from within the app with a customized message explaining why they should join this new tenant (or sign up to the app if they are not already a user). ",{"data":67156,"content":67157,"nodeType":876},{},[67158],{"data":67159,"marks":67160,"value":61198,"nodeType":867},{},[],{"data":67162,"content":67163,"nodeType":1058},{},[67164],{"data":67165,"marks":67166,"value":61205,"nodeType":867},{},[],{"data":67168,"content":67169,"nodeType":876},{},[67170,67173,67180],{"data":67171,"marks":67172,"value":61212,"nodeType":867},{},[],{"data":67174,"content":67175,"nodeType":915},{"uri":61215},[67176],{"data":67177,"marks":67178,"value":61221,"nodeType":867},{},[67179],{"type":913},{"data":67181,"marks":67182,"value":67183,"nodeType":867},{},[]," (Living-Off-the-Land Binaries and Scripts), which are often signed Microsoft utilities. Perhaps the most well-known example is executing scripts through PowerShell rather than building custom malware. That isn’t as useful these days but there was a time when PowerShell was routinely used to bypass AV, EDR, and even app allow-listing.",{"data":67185,"content":67186,"nodeType":876},{},[67187,67191,67198],{"data":67188,"marks":67189,"value":67190,"nodeType":867},{},[],"In that same living-off-the-land mindset, an attacker trying to maintain access to each SaaS app they compromise using custom OAuth integration apps, might instead choose to use legit SaaS apps that specialize in workflow automation to create ",{"data":67192,"content":67193,"nodeType":915},{"uri":42265},[67194],{"data":67195,"marks":67196,"value":42789,"nodeType":867},{},[67197],{"type":913},{"data":67199,"marks":67200,"value":61243,"nodeType":867},{},[],{"data":67202,"content":67203,"nodeType":876},{},[67204],{"data":67205,"marks":67206,"value":67207,"nodeType":867},{},[],"Perhaps the best example here is using a well-known automation app like Zapier, which claims to have more than 5000 integrations. These integrations are often verified, approved, and connected to a trusted vendor (Zapier). An attacker might create workflows to:",{"data":67209,"content":67210,"nodeType":1629},{},[67211,67221,67231],{"data":67212,"content":67213,"nodeType":1586},{},[67214],{"data":67215,"content":67216,"nodeType":876},{},[67217],{"data":67218,"marks":67219,"value":67220,"nodeType":867},{},[],"do daily data exfiltration from a victim’s data lake",{"data":67222,"content":67223,"nodeType":1586},{},[67224],{"data":67225,"content":67226,"nodeType":876},{},[67227],{"data":67228,"marks":67229,"value":67230,"nodeType":867},{},[],"configure a webhook which adds malicious accounts to a github repo on demand",{"data":67232,"content":67233,"nodeType":1586},{},[67234],{"data":67235,"content":67236,"nodeType":876},{},[67237],{"data":67238,"marks":67239,"value":67240,"nodeType":867},{},[],"automatically find and replace bank account numbers in emails to the finance team",{"data":67242,"content":67243,"nodeType":876},{},[67244],{"data":67245,"marks":67246,"value":61290,"nodeType":867},{},[],{"data":67248,"content":67249,"nodeType":876},{},[67250,67253,67260],{"data":67251,"marks":67252,"value":61297,"nodeType":867},{},[],{"data":67254,"content":67255,"nodeType":915},{"uri":61300},[67256],{"data":67257,"marks":67258,"value":61306,"nodeType":867},{},[67259],{"type":913},{"data":67261,"marks":67262,"value":67263,"nodeType":867},{},[]," to make another instance of an existing integration - making this backdoor almost impossible to discover.",{"data":67265,"content":67266,"nodeType":1058},{},[67267],{"data":67268,"marks":67269,"value":61317,"nodeType":867},{},[],{"data":67271,"content":67272,"nodeType":876},{},[67273],{"data":67274,"marks":67275,"value":61324,"nodeType":867},{},[],{"data":67277,"content":67278,"nodeType":876},{},[67279,67282,67289,67292,67299],{"data":67280,"marks":67281,"value":61331,"nodeType":867},{},[],{"data":67283,"content":67284,"nodeType":915},{"uri":61334},[67285],{"data":67286,"marks":67287,"value":61340,"nodeType":867},{},[67288],{"type":913},{"data":67290,"marks":67291,"value":1174,"nodeType":867},{},[],{"data":67293,"content":67294,"nodeType":915},{"uri":26236},[67295],{"data":67296,"marks":67297,"value":2929,"nodeType":867},{},[67298],{"type":913},{"data":67300,"marks":67301,"value":61354,"nodeType":867},{},[],{"data":67303,"content":67304,"nodeType":876},{},[67305,67308,67315],{"data":67306,"marks":67307,"value":61361,"nodeType":867},{},[],{"data":67309,"content":67310,"nodeType":915},{"uri":61364},[67311],{"data":67312,"marks":67313,"value":61370,"nodeType":867},{},[67314],{"type":913},{"data":67316,"marks":67317,"value":61374,"nodeType":867},{},[],{"data":67319,"content":67320,"nodeType":876},{},[67321],{"data":67322,"marks":67323,"value":61381,"nodeType":867},{},[],{"data":67325,"content":67326,"nodeType":868},{},[67327],{"data":67328,"marks":67329,"value":61393,"nodeType":867},{},[],{"data":67331,"content":67332,"nodeType":876},{},[67333],{"data":67334,"marks":67335,"value":67336,"nodeType":867},{},[],"SaaS apps are basically webapps that are run in the cloud and accessed from endpoints, so then WebApp, endpoint, and cloud security should cover all of SaaS, right? ",{"data":67338,"content":67339,"nodeType":876},{},[67340],{"data":67341,"marks":67342,"value":67343,"nodeType":867},{},[],"That was our assumption when we started, but what we found instead was that SaaS marketing  best practices are driving a lot of pretty interesting techniques that you don’t run into in standalone web apps.",{"data":67345,"content":67346,"nodeType":1058},{},[67347],{"data":67348,"marks":67349,"value":61414,"nodeType":867},{},[],{"data":67351,"content":67352,"nodeType":876},{},[67353],{"data":67354,"marks":67355,"value":67356,"nodeType":867},{},[],"Making apps easy to sign-up for and low effort to support means you need to make some interesting choices when it comes to designing account creation and recovery flows. ",{"data":67358,"content":67359,"nodeType":876},{},[67360],{"data":67361,"marks":67362,"value":67363,"nodeType":867},{},[],"Many apps allow users to sign into apps using multiple methods, easily invite collaborators (internal and external) and avoid any additional friction during the sign up process. ",{"data":67365,"content":67366,"nodeType":876},{},[67367],{"data":67368,"marks":67369,"value":67370,"nodeType":867},{},[],"For example, many apps avoid verifying new account email addresses. This is not laziness, these are conscious design choices - not driven by security clearly, but not accidents.",{"data":67372,"content":67373,"nodeType":1058},{},[67374],{"data":67375,"marks":67376,"value":61442,"nodeType":867},{},[],{"data":67378,"content":67379,"nodeType":876},{},[67380],{"data":67381,"marks":67382,"value":67383,"nodeType":867},{},[],"Most SaaS apps are trying to build app marketplaces or perform well in other app’s marketplaces (often both) and it’s rare these days to find apps that don’t integrate with other apps. ",{"data":67385,"content":67386,"nodeType":876},{},[67387],{"data":67388,"marks":67389,"value":61456,"nodeType":867},{},[],{"data":67391,"content":67392,"nodeType":876},{},[67393],{"data":67394,"marks":67395,"value":61463,"nodeType":867},{},[],{"data":67397,"content":67398,"nodeType":868},{},[67399],{"data":67400,"marks":67401,"value":61470,"nodeType":867},{},[],{"data":67403,"content":67404,"nodeType":876},{},[67405,67409,67413],{"data":67406,"marks":67407,"value":67408,"nodeType":867},{},[],"This research begs one question above others - ",{"data":67410,"marks":67411,"value":61482,"nodeType":867},{},[67412],{"type":1303},{"data":67414,"marks":67415,"value":61486,"nodeType":867},{},[],{"data":67417,"content":67418,"nodeType":1058},{},[67419],{"data":67420,"marks":67421,"value":61493,"nodeType":867},{},[],{"data":67423,"content":67424,"nodeType":876},{},[67425,67429,67436,67439,67446,67449,67456,67459,67466,67469,67476],{"data":67426,"marks":67427,"value":67428,"nodeType":867},{},[],"For some of the better known techniques, like credential stuffing and email phishing, the answer is an easy yes. Stats from ",{"data":67430,"content":67431,"nodeType":915},{"uri":61503},[67432],{"data":67433,"marks":67434,"value":61509,"nodeType":867},{},[67435],{"type":913},{"data":67437,"marks":67438,"value":1174,"nodeType":867},{},[],{"data":67440,"content":67441,"nodeType":915},{"uri":61515},[67442],{"data":67443,"marks":67444,"value":61521,"nodeType":867},{},[67445],{"type":913},{"data":67447,"marks":67448,"value":61525,"nodeType":867},{},[],{"data":67450,"content":67451,"nodeType":915},{"uri":61528},[67452],{"data":67453,"marks":67454,"value":61534,"nodeType":867},{},[67455],{"type":913},{"data":67457,"marks":67458,"value":25906,"nodeType":867},{},[],{"data":67460,"content":67461,"nodeType":915},{"uri":2177},[67462],{"data":67463,"marks":67464,"value":61545,"nodeType":867},{},[67465],{"type":913},{"data":67467,"marks":67468,"value":61549,"nodeType":867},{},[],{"data":67470,"content":67471,"nodeType":915},{"uri":61552},[67472],{"data":67473,"marks":67474,"value":61558,"nodeType":867},{},[67475],{"type":913},{"data":67477,"marks":67478,"value":61562,"nodeType":867},{},[],{"data":67480,"content":67481,"nodeType":876},{},[67482],{"data":67483,"marks":67484,"value":67485,"nodeType":867},{},[],"The takeaway is that the current focus for defenders should be to ensure users have good phishing-resistant account security in place - make sure you have basics like strong unique passwords and MFA in place across your entire SaaS estate.",{"data":67487,"content":67488,"nodeType":1058},{},[67489],{"data":67490,"marks":67491,"value":67492,"nodeType":867},{},[],"For newer OAuth attacks it’s a lot less clear…",{"data":67494,"content":67495,"nodeType":876},{},[67496,67500,67505,67508,67515],{"data":67497,"marks":67498,"value":67499,"nodeType":867},{},[],"Other techniques like consent phishing, and have been discussed in some breach disclosures like the ",{"data":67501,"marks":67502,"value":67504,"nodeType":867},{},[67503],{"type":913},"2020 Sans breach",{"data":67506,"marks":67507,"value":61592,"nodeType":867},{},[],{"data":67509,"content":67510,"nodeType":915},{"uri":61595},[67511],{"data":67512,"marks":67513,"value":61601,"nodeType":867},{},[67514],{"type":913},{"data":67516,"marks":67517,"value":61605,"nodeType":867},{},[],{"data":67519,"content":67520,"nodeType":876},{},[67521,67524,67529],{"data":67522,"marks":67523,"value":61612,"nodeType":867},{},[],{"data":67525,"marks":67526,"value":67528,"nodeType":867},{},[67527],{"type":1303},"either attackers aren’t yet using them widely or they are and we aren’t detecting them",{"data":67530,"marks":67531,"value":1679,"nodeType":867},{},[],{"data":67533,"content":67534,"nodeType":876},{},[67535],{"data":67536,"marks":67537,"value":67538,"nodeType":867},{},[],"There is certainly a case to be made that attackers simply don’t need these newer techniques yet. Many organizations don’t have a way of discovering SaaS use in their organization yet, nevermind breached accounts, so new persistence techniques might be a bit more than necessary at the moment.",{"data":67540,"content":67541,"nodeType":1058},{},[67542],{"data":67543,"marks":67544,"value":61634,"nodeType":867},{},[],{"data":67546,"content":67547,"nodeType":876},{},[67548],{"data":67549,"marks":67550,"value":67551,"nodeType":867},{},[],"On the other hand, there is certainly the possibility that these attacks are increasingly used, but are simply not being discovered. A strong argument in favor of this view is the difficulty in investigating these attacks. Very few SaaS apps provide enough logging capability to discover these attacks as a customer, this is true even for the biggest, most mature apps like Office 365 and Google Workspace unless you are on top license tiers. This is doubly true for attacks that use OAuth, with many apps providing no insight or details into actions made using OAuth-authenticated APIs. ",{"data":67553,"content":67554,"nodeType":876},{},[67555,67558,67565,67569,67576],{"data":67556,"marks":67557,"value":61648,"nodeType":867},{},[],{"data":67559,"content":67560,"nodeType":915},{"uri":61651},[67561],{"data":67562,"marks":67563,"value":61657,"nodeType":867},{},[67564],{"type":913},{"data":67566,"marks":67567,"value":67568,"nodeType":867},{},[]," relied heavily on Github during the investigation (and in one case even the detection of) their 2022 breaches, and the same  seems true for a similar breach affecting ",{"data":67570,"content":67571,"nodeType":915},{"uri":61664},[67572],{"data":67573,"marks":67574,"value":61670,"nodeType":867},{},[67575],{"type":913},{"data":67577,"marks":67578,"value":61674,"nodeType":867},{},[],{"data":67580,"content":67581,"nodeType":876},{},[67582,67586,67594],{"data":67583,"marks":67584,"value":67585,"nodeType":867},{},[],"So, are these attacks happening in the real world? My best guess is it’s a little bit of column A and a little bit of column B – there are likely not so many of these attacks happening yet, and when they do I suspect the vast majority go undetected. ",{"data":67587,"content":67588,"nodeType":915},{"uri":61684},[67589],{"data":67590,"marks":67591,"value":61691,"nodeType":867},{},[67592,67593],{"type":913},{"type":1303},{"data":67595,"marks":67596,"value":21,"nodeType":867},{},[],{"data":67598,"content":67599,"nodeType":876},{},[67600],{"data":67601,"marks":67602,"value":67603,"nodeType":867},{},[],"This is part of the reason we think enabling red-teamers to try these techniques in anger is useful - this is the time-proven way to understand these risks.",{"data":67605,"content":67606,"nodeType":868},{},[67607],{"data":67608,"marks":67609,"value":61708,"nodeType":867},{},[],{"data":67611,"content":67612,"nodeType":876},{},[67613],{"data":67614,"marks":67615,"value":67616,"nodeType":867},{},[],"We’ve barely scratched the surface, but perhaps there is enough here to get the discussion going. From past experience, discussion may not be enough, and it’s likely that live offensive work like penetration tests or more likely red-team exercises will be required to make the risks of using these techniques real for the wider security community. ",{"data":67618,"content":67619,"nodeType":876},{},[67620],{"data":67621,"marks":67622,"value":67623,"nodeType":867},{},[],"After all, seeing is believing. We think some more practical examples and tools to help red- teamers use these techniques on engagements will help drive awareness forward so we’ll be looking to build out this content.",{"data":67625,"content":67626,"nodeType":876},{},[67627,67630,67638],{"data":67628,"marks":67629,"value":61729,"nodeType":867},{},[],{"data":67631,"content":67632,"nodeType":915},{"uri":61732},[67633],{"data":67634,"marks":67635,"value":67637,"nodeType":867},{},[67636],{"type":913},"backdoored github repo to get code execution on endpoints",{"data":67639,"marks":67640,"value":1679,"nodeType":867},{},[],{"data":67642,"content":67643,"nodeType":876},{},[67644,67648,67655],{"data":67645,"marks":67646,"value":67647,"nodeType":867},{},[],"Help us all better understand how widespread these attacks are by sharing some war stories - blueteams, have you seen these attacks in IR investigations? Red-teamers, have tried these or similar techniques against SaaS? Even better, we’d love some comments, discussions, or PRs on ",{"data":67649,"content":67650,"nodeType":915},{"uri":15408},[67651],{"data":67652,"marks":67653,"value":14515,"nodeType":867},{},[67654],{"type":913},{"data":67656,"marks":67657,"value":43095,"nodeType":867},{},[],{"entries":67659},{"hyperlink":67660,"block":67661,"inline":67662},[],[],[],{"items":67664},[],{},"Move faster than competitors by embracing SaaS","2023-04-21T00:00:00.000Z",{"items":67669},[67670,67998],{"__typename":1772,"sys":67671,"content":67673,"title":67982,"synopsis":67983,"hashTags":59,"publishedDate":67984,"slug":67985,"tagsCollection":67986,"authorsCollection":67994},{"id":67672},"2cLFeaDTWWdZ8G8U12qmiZ",{"json":67674},{"data":67675,"content":67676,"nodeType":1680},{},[67677,67684,67691,67698,67705,67712,67719,67726,67733,67740,67747,67754,67778,67798,67805,67812,67819,67882,67903,67922,67929,67936,67943,67949,67956,67963],{"data":67678,"content":67679,"nodeType":868},{},[67680],{"data":67681,"marks":67682,"value":67683,"nodeType":867},{},[],"Prevention isn’t always the answer",{"data":67685,"content":67686,"nodeType":876},{},[67687],{"data":67688,"marks":67689,"value":67690,"nodeType":867},{},[],"As a security team, our job is to help our company achieve its goals by taking risks securely. Simply using a computer represents a risk over the more traditional pen and paper, but the productivity gains clearly outweigh the risk; so the security team ensures the business takes that risk securely. Outright prevention - i.e. not using a computer - in this case, makes no sense.",{"data":67692,"content":67693,"nodeType":876},{},[67694],{"data":67695,"marks":67696,"value":67697,"nodeType":867},{},[],"Of course, within how the computer operates we might choose to prevent some functionality in the name of security, but the principle remains the same - prevention usually requires a trade-off against productivity.",{"data":67699,"content":67700,"nodeType":868},{},[67701],{"data":67702,"marks":67703,"value":67704,"nodeType":867},{},[],"Detection, but at the cost of privacy",{"data":67706,"content":67707,"nodeType":876},{},[67708],{"data":67709,"marks":67710,"value":67711,"nodeType":867},{},[],"When a base level of security became more common (through better awareness, accessible knowledge, and sensible vendor defaults), attackers shifted to using techniques that couldn’t be prevented because the business relied on the underlying tools - a malicious Word doc, a sneaky PowerShell script, a dodgy PDF.",{"data":67713,"content":67714,"nodeType":876},{},[67715],{"data":67716,"marks":67717,"value":67718,"nodeType":867},{},[],"Now prevention wasn’t an option, the security team had to monitor usage for malicious activity. But monitoring comes at a cost. To detect when malicious activity happens, the security team needs to monitor all activity, including legitimate activity. So, while a detection approach doesn’t restrict what a user can do, it comes at the cost of their privacy.",{"data":67720,"content":67721,"nodeType":868},{},[67722],{"data":67723,"marks":67724,"value":67725,"nodeType":867},{},[],"Building trust with your users",{"data":67727,"content":67728,"nodeType":876},{},[67729],{"data":67730,"marks":67731,"value":67732,"nodeType":867},{},[],"In either case, when introducing security controls you should aim to justify and explain this decision to your users, remembering that security’s job is to help them do their jobs securely - it shouldn’t be for them to figure out how to do their jobs within the confines of what the security team has decided is OK. A security team should be more like the secret service, than the prison service.",{"data":67734,"content":67735,"nodeType":876},{},[67736],{"data":67737,"marks":67738,"value":67739,"nodeType":867},{},[],"Although, of course, many employees won’t have much interest in the motivations of their IT/security team, maintaining this attitude will help you build and keep trust with them. With trust in hand, employees will be less likely to try to work around your controls.",{"data":67741,"content":67742,"nodeType":868},{},[67743],{"data":67744,"marks":67745,"value":67746,"nodeType":867},{},[],"SaaS - the new frontier",{"data":67748,"content":67749,"nodeType":876},{},[67750],{"data":67751,"marks":67752,"value":67753,"nodeType":867},{},[],"In recent years, our computers are mostly just windows to the Internet - many users access their email, video conferencing, productivity suites and more via their browser (or Electron apps pretending they aren’t browsers).",{"data":67755,"content":67756,"nodeType":876},{},[67757,67761,67766,67770,67774],{"data":67758,"marks":67759,"value":67760,"nodeType":867},{},[],"And, as is often the way, we’re relearning the same lessons as before. Should employees be ",{"data":67762,"marks":67763,"value":67765,"nodeType":867},{},[67764],{"type":1303},"allowed",{"data":67767,"marks":67768,"value":67769,"nodeType":867},{},[]," to sign up for and use arbitrary SaaS platforms? Should employees be ",{"data":67771,"marks":67772,"value":67765,"nodeType":867},{},[67773],{"type":1303},{"data":67775,"marks":67776,"value":67777,"nodeType":867},{},[]," to add arbitrary apps into Microsoft 365, Google Workspace, or other SaaS platforms?",{"data":67779,"content":67780,"nodeType":876},{},[67781,67785,67794],{"data":67782,"marks":67783,"value":67784,"nodeType":867},{},[],"Regardless of your answer, your coworkers have already spoken and it’s almost certainly already happening. A ",{"data":67786,"content":67788,"nodeType":915},{"uri":67787},"https://track.g2.com/resources/shadow-it-statistics",[67789],{"data":67790,"marks":67791,"value":67793,"nodeType":867},{},[67792],{"type":913},"report from G2",{"data":67795,"marks":67796,"value":67797,"nodeType":867},{},[]," stated that 80% of workers admit to using SaaS applications at work without getting approval from IT. If you want to enable your colleagues’ productivity, prevention, it would seem, isn’t an option.",{"data":67799,"content":67800,"nodeType":868},{},[67801],{"data":67802,"marks":67803,"value":67804,"nodeType":867},{},[],"The risks of SaaS",{"data":67806,"content":67807,"nodeType":876},{},[67808],{"data":67809,"marks":67810,"value":67811,"nodeType":867},{},[],"So how do we secure the company in this new way of working? We still have plenty to consider.",{"data":67813,"content":67814,"nodeType":876},{},[67815],{"data":67816,"marks":67817,"value":67818,"nodeType":867},{},[],"We can start thinking about SaaS not just as an allow or not to allow, but taking a more flexible and pragmatic approach, asking questions like::",{"data":67820,"content":67821,"nodeType":1629},{},[67822,67832,67842,67852,67862,67872],{"data":67823,"content":67824,"nodeType":1586},{},[67825],{"data":67826,"content":67827,"nodeType":876},{},[67828],{"data":67829,"marks":67830,"value":67831,"nodeType":867},{},[],"What kind of data users are entering into these third-party platforms?",{"data":67833,"content":67834,"nodeType":1586},{},[67835],{"data":67836,"content":67837,"nodeType":876},{},[67838],{"data":67839,"marks":67840,"value":67841,"nodeType":867},{},[],"How much do we trust the controls the third-party has in place?",{"data":67843,"content":67844,"nodeType":1586},{},[67845],{"data":67846,"content":67847,"nodeType":876},{},[67848],{"data":67849,"marks":67850,"value":67851,"nodeType":867},{},[],"Are those controls appropriate for the data? ",{"data":67853,"content":67854,"nodeType":1586},{},[67855],{"data":67856,"content":67857,"nodeType":876},{},[67858],{"data":67859,"marks":67860,"value":67861,"nodeType":867},{},[],"Is this platform redundant with the other services we use (e.g. “we use Google Drive, not Dropbox”)? ",{"data":67863,"content":67864,"nodeType":1586},{},[67865],{"data":67866,"content":67867,"nodeType":876},{},[67868],{"data":67869,"marks":67870,"value":67871,"nodeType":867},{},[],"Does IT or security need to manage accounts for joiners/leavers?",{"data":67873,"content":67874,"nodeType":1586},{},[67875],{"data":67876,"content":67877,"nodeType":876},{},[67878],{"data":67879,"marks":67880,"value":67881,"nodeType":867},{},[],"Does this platform impact our compliance? (e.g. does storing this data on this platform compromise our GDPR status?)",{"data":67883,"content":67884,"nodeType":876},{},[67885,67889,67899],{"data":67886,"marks":67887,"value":67888,"nodeType":867},{},[],"No one said it would be easy 🙃 and it’s easy to see why many organizations initially opt to simply try to block users from using such systems. Assessing each application can be daunting using traditional third-party security assessment techniques - we’ve written a ",{"data":67890,"content":67894,"nodeType":17452},{"target":67891},{"sys":67892},{"id":67893,"type":982,"linkType":983},"3PqX7fLrTIYhWjbEhHSRHG",[67895],{"data":67896,"marks":67897,"value":67898,"nodeType":867},{},[],"short guide",{"data":67900,"marks":67901,"value":67902,"nodeType":867},{},[]," on how to approach security auditing in a world of SaaS, which you might find useful.",{"data":67904,"content":67905,"nodeType":876},{},[67906,67910,67918],{"data":67907,"marks":67908,"value":67909,"nodeType":867},{},[],"But the first step in managing this new world is through visibility. Knowing the problem is half the battle and we published ",{"data":67911,"content":67913,"nodeType":915},{"uri":67912},"https://pushsecurity.com/blog/rolling-your-own-saas-discovery/",[67914],{"data":67915,"marks":67916,"value":67917,"nodeType":867},{},[],"an article",{"data":67919,"marks":67920,"value":67921,"nodeType":867},{},[]," about how to manually find the SaaS apps your employees are using. The problem is, a lot of them are either error-prone or quite invasive, potentially collecting your users private activity. In the trade-off of security versus privacy, we think that’s a bit too far and will likely damage the trust you’ve built with your coworkers.",{"data":67923,"content":67924,"nodeType":868},{},[67925],{"data":67926,"marks":67927,"value":67928,"nodeType":867},{},[],"Monitoring SaaS use without compromising privacy",{"data":67930,"content":67931,"nodeType":876},{},[67932],{"data":67933,"marks":67934,"value":67935,"nodeType":867},{},[],"Our approach at Push is to deploy our browser extension to our users’ browsers which is configured with the domains we use for work (e.g. @pushsecurity.com). The browser extension only monitors logins where an @pushsecurity.com email address is used, which we can reasonably assume means the platform is being used for work reasons.",{"data":67937,"content":67938,"nodeType":876},{},[67939],{"data":67940,"marks":67941,"value":67942,"nodeType":867},{},[],"We share this with employees up front during the onboarding process and, if you click on the browser extension, it also lets you know which domains it’s monitoring:",{"data":67944,"content":67948,"nodeType":985},{"target":67945},{"sys":67946},{"id":67947,"type":982,"linkType":983},"6z1apzuDIaXXN7xIAHEUku",[],{"data":67950,"content":67951,"nodeType":876},{},[67952],{"data":67953,"marks":67954,"value":67955,"nodeType":867},{},[],"This helps our users understand why we are monitoring which SaaS they’re using which in turn makes them aware of the risk we are managing and why.",{"data":67957,"content":67958,"nodeType":876},{},[67959],{"data":67960,"marks":67961,"value":67962,"nodeType":867},{},[],"With this approach we’ve built a comprehensive picture of which SaaS platforms our team is using which has helped us understand where our data lives and which platforms need extra attention to ensure we have all the right controls in place. When our users use a new platform we can reach out to them at the start of their journey to understand what they’re trying to achieve and how we can help them do it securely.",{"data":67964,"content":67965,"nodeType":876},{},[67966,67969,67978],{"data":67967,"marks":67968,"value":21,"nodeType":867},{},[],{"data":67970,"content":67972,"nodeType":915},{"uri":67971},"https://pushsecurity.com/features/saas-discovery",[67973],{"data":67974,"marks":67975,"value":67977,"nodeType":867},{},[67976],{"type":913},"Learn more about how Push can discover SaaS apps your employees are using",{"data":67979,"marks":67980,"value":67981,"nodeType":867},{},[]," without compromising their privacy. ","How to discover SaaS use without invading employee privacy","Learn how to manage SaaS in a way that keeps employees productive and doesn't compromise privacy.","2022-08-22T00:00:00.000Z","how-to-discover-saas-use-without-invading-employee-privacy",{"items":67987},[67988,67992],{"sys":67989,"name":67991},{"id":67990},"3SA5H01UkKauuiTdt0KC6q","Shadow IT",{"sys":67993,"name":2710},{"id":2709},{"items":67995},[67996],{"fullName":59663,"firstName":59664,"jobTitle":59665,"profilePicture":67997},{"url":59667},{"__typename":1772,"sys":67999,"content":68001,"title":68328,"synopsis":68329,"hashTags":59,"publishedDate":68330,"slug":68331,"tagsCollection":68332,"authorsCollection":68338},{"id":68000},"4LOMe7ez5adQtwbPireIBc",{"json":68002},{"data":68003,"content":68004,"nodeType":1680},{},[68005,68012,68033,68040,68047,68054,68061,68068,68075,68082,68089,68096,68103,68110,68117,68133,68140,68147,68154,68161,68168,68175,68193,68200,68207,68214,68220,68227,68235,68268,68276,68309],{"data":68006,"content":68007,"nodeType":876},{},[68008],{"data":68009,"marks":68010,"value":68011,"nodeType":867},{},[],"As part of your larger cloud security strategy, you’ve likely been asked to focus on how to secure SaaS apps used in your company. The first step to securing SaaS is getting a real sense of what platforms employees are actually using, beyond those that you already know about. Since SaaS is so easy for employees to adopt and start using without any input from IT and security, they’re likely using hundreds of SaaS apps that aren’t even on your radar. The first step in securing something is getting full visibility into what you even need to secure in the first place. ",{"data":68013,"content":68014,"nodeType":876},{},[68015,68019,68029],{"data":68016,"marks":68017,"value":68018,"nodeType":867},{},[],"To help guide folks through how you might do SaaS discovery on your own, we wrote an ",{"data":68020,"content":68024,"nodeType":17452},{"target":68021},{"sys":68022},{"id":68023,"type":982,"linkType":983},"45iZ69EdPF4629gZ6yf7p5",[68025],{"data":68026,"marks":68027,"value":68028,"nodeType":867},{},[],"article",{"data":68030,"marks":68031,"value":68032,"nodeType":867},{},[]," about how to manually find what apps employees are using. In it, we explored how to analyze data that you already have on hand to find the unknown apps (shadow IT) used within your business. That’s a pretty significant manual effort, though, and most security teams don’t have the resources to do it. Plus, while these manual attempts can chip away at the SaaS discovery process, none are great at giving you a comprehensive view of SaaS use, nor do they keep up with the constant influx of apps employees are signing up for daily. ",{"data":68034,"content":68035,"nodeType":876},{},[68036],{"data":68037,"marks":68038,"value":68039,"nodeType":867},{},[],"To get truly broad coverage of what SaaS employees are using, you need a large dataset of SaaS apps, the domains associated with them, and this dataset must constantly be updated and expanded to include new apps that are launched every day. ",{"data":68041,"content":68042,"nodeType":876},{},[68043],{"data":68044,"marks":68045,"value":68046,"nodeType":867},{},[],"Unless you can find such a dataset, you must create it. And creating a constantly updated dataset is no small undertaking. That’s why there are so many off-the-shelf solutions and tools that focus solely on SaaS discovery these days. Many say that they are full-scale SaaS security platforms, but what that means isn’t always clear, even after reading product marketing materials. If you were to look at a venn diagram of “SaaS security platforms,” you’d have a giant mess of interlocking circles, with some shared activities amongst all (or most) tools and then vastly different features from that core functionality.",{"data":68048,"content":68049,"nodeType":876},{},[68050],{"data":68051,"marks":68052,"value":68053,"nodeType":867},{},[],"How “good” they are at SaaS discovery really depends on what data they’re using, what they have access to within your environment, the quality of their proprietary datasets (breadth, depth, and timeliness of that data), and how they work with your existing data and tools. To help navigate this mess, we’re sharing some pros and cons of the categories of commercial tools on the market.",{"data":68055,"content":68056,"nodeType":876},{},[68057],{"data":68058,"marks":68059,"value":68060,"nodeType":867},{},[],"To determine which solution you need, you need to consider your tech stack, your specific needs, your risk tolerance, and your short and long term objectives. In this article, we’ll break down some major use cases and match them up with what solutions make the most sense to address them.",{"data":68062,"content":68063,"nodeType":1058},{},[68064],{"data":68065,"marks":68066,"value":68067,"nodeType":867},{},[],"You’re a large enterprise interested in securing core SaaS platforms",{"data":68069,"content":68070,"nodeType":876},{},[68071],{"data":68072,"marks":68073,"value":68074,"nodeType":867},{},[],"\nWorking to only secure 20 or so core applications that have already been sanctioned by the security team? A cloud security posture management (CSPM) or SaaS security posture management (SSPM) solution might be the answer you’re looking for, particularly if you’re on the highest tier license for those apps. ",{"data":68076,"content":68077,"nodeType":876},{},[68078],{"data":68079,"marks":68080,"value":68081,"nodeType":867},{},[],"You can make the most of these tools during in-depth investigations or threat hunting exercises. Leverage them to enforce custom SaaS or cloud app policies as well. The caveat with this one is that you’ll need a fairly sophisticated security team to manage, customize, and run SSPM and CSPM tools.",{"data":68083,"content":68084,"nodeType":876},{},[68085],{"data":68086,"marks":68087,"value":68088,"nodeType":867},{},[],"An ideal environment for these solutions is one that has a full SOC capability so that you extend your existing security monitoring and threat hunting coverage into these core SaaS platforms. You’ll be able to secure a small handful of your business critical applications as long as they’re large and well-established platforms. ",{"data":68090,"content":68091,"nodeType":876},{},[68092],{"data":68093,"marks":68094,"value":68095,"nodeType":867},{},[],"The reason you’ll need top-level licenses and well-established SaaS platforms to make these solutions work is because they rely on API data from those SaaS platforms. Those mature APIs provide necessary information about those core apps that CSPMs and SSPMs use to provide security insights you need to manage the risks. Unfortunately, they won’t cover the dozens of smaller SaaS apps most organizations use, and are normally only available on top license tiers.",{"data":68097,"content":68098,"nodeType":1058},{},[68099],{"data":68100,"marks":68101,"value":68102,"nodeType":867},{},[],"You’re a more traditional, on-prem enterprise interested in blocking unsanctioned SaaS",{"data":68104,"content":68105,"nodeType":876},{},[68106],{"data":68107,"marks":68108,"value":68109,"nodeType":867},{},[],"If your environment is traditional on-site internal networks and you have mature gateway monitoring technology in place already, a cloud access security broker (CASB) may be your best path to securing cloud apps. CASBs work best if you have no employees working from home or on the road or you’re forcing employees to only access work platforms and internet browsers through your corporate VPN.",{"data":68111,"content":68112,"nodeType":876},{},[68113],{"data":68114,"marks":68115,"value":68116,"nodeType":867},{},[],"CASBs typically pull network data such as DNS, SASE, VPN, proxy, and firewall logs. They may also require that you install an agent on each employees’ devices if you want coverage when they are out of the office. ",{"data":68118,"content":68119,"nodeType":876},{},[68120,68124,68129],{"data":68121,"marks":68122,"value":68123,"nodeType":867},{},[],"With those data sources, they provide good aggregate information about SaaS platforms that are accessed. What they ",{"data":68125,"marks":68126,"value":68128,"nodeType":867},{},[68127],{"type":1303},"can’t do well",{"data":68130,"marks":68131,"value":68132,"nodeType":867},{},[]," is provide any insight into how the SaaS app is being used, by which employees (you typically get IP addresses not user names), and for what purpose - as an example, they are typically not able to tell the difference between opening a SaaS product’s homepage, or actually logging into the application - so you are going to have a fairly large number of false positives. ",{"data":68134,"content":68135,"nodeType":876},{},[68136],{"data":68137,"marks":68138,"value":68139,"nodeType":867},{},[],"A CASB also really makes sense if you’re forced into complying with strict regulatory requirements to block everything until you’re able to do an in-depth due diligence process on each app. If your goal (or need) is to block access to unknown, unvetted, or unsanctioned SaaS at the network level with no exceptions, a CASB might be for you.",{"data":68141,"content":68142,"nodeType":1058},{},[68143],{"data":68144,"marks":68145,"value":68146,"nodeType":867},{},[],"You’re a cloud-native company who wants to enable SaaS without introducing too much risk",{"data":68148,"content":68149,"nodeType":876},{},[68150],{"data":68151,"marks":68152,"value":68153,"nodeType":867},{},[],"For cloud-native companies that need better coverage, and are looking for more nuanced controls than network-level blocking, a solution that discovers and secures SaaS through the browser is the way to go. Since employees access SaaS through their browser, it’s a logical step to collect data about who is using what apps through a browser extension. ",{"data":68155,"content":68156,"nodeType":876},{},[68157],{"data":68158,"marks":68159,"value":68160,"nodeType":867},{},[],"The browser approach lets you do true SaaS discovery - so you can find what employees are actually using (not just accessing) and then go about securing those apps. You also don’t need to do much in terms of managing a browser-based solution once it’s set up. It simply runs in the background and surfaces employee SaaS use data into a dashboard. ",{"data":68162,"content":68163,"nodeType":876},{},[68164],{"data":68165,"marks":68166,"value":68167,"nodeType":867},{},[],"By combining browser-level data and robust security APIs from those core business platforms that SSPMs typically tap into, you can get broad visibility of SaaS use in your company for those large in number, but less mature, more up-and-coming apps, and the depth of security data you need for those few core apps that most employees are using. ",{"data":68169,"content":68170,"nodeType":876},{},[68171],{"data":68172,"marks":68173,"value":68174,"nodeType":867},{},[],"The other key benefit of a browser-based approach for SaaS discovery is that you can get incredibly powerful data about who is using the app, how they’re using it, if they’re using security features such as MFA, if they’re reusing passwords across multiple apps, if they’re sharing passwords, when they’ve used it last, and so on. That data is critical when it comes to securing SaaS because the devil truly is in the details. ",{"data":68176,"content":68177,"nodeType":876},{},[68178,68182,68190],{"data":68179,"marks":68180,"value":68181,"nodeType":867},{},[],"If we’ve piqued your interest and you’re curious to see what we can discover about SaaS in your business, ",{"data":68183,"content":68185,"nodeType":915},{"uri":68184},"https://login.pushsecurity.com/",[68186],{"data":68187,"marks":68188,"value":68189,"nodeType":867},{},[],"try the free browser extension",{"data":68191,"marks":68192,"value":5704,"nodeType":867},{},[],{"data":68194,"content":68195,"nodeType":1058},{},[68196],{"data":68197,"marks":68198,"value":68199,"nodeType":867},{},[],"Consider their data sources  ",{"data":68201,"content":68202,"nodeType":876},{},[68203],{"data":68204,"marks":68205,"value":68206,"nodeType":867},{},[],"The critical thing to understand when you’re evaluating if a solution will work for you would be understanding what their data sources are, what weaknesses those data sources inherently have, and what aligns best with your goals. We’ve tried to surface some of that information within the use cases in this article.",{"data":68208,"content":68209,"nodeType":876},{},[68210],{"data":68211,"marks":68212,"value":68213,"nodeType":867},{},[],"So if you’re looking at an EDR that says they can discover SaaS usage, they’ll likely be leveraging endpoint data to detect SaaS use. If you’re looking at CASBs that integrate with your proxy, they’re probably looking at network level data – you get the idea.  ",{"data":68215,"content":68216,"nodeType":1058},{},[68217],{"data":68218,"marks":68219,"value":23563,"nodeType":867},{},[],{"data":68221,"content":68222,"nodeType":876},{},[68223],{"data":68224,"marks":68225,"value":68226,"nodeType":867},{},[],"To wrap this up, we’re going to summarize some key points and provide some questions to ask yourself, your team, or even the vendor of the solution you’re evaluating, as you consider what combination of efforts or what tool is right for you. ",{"data":68228,"content":68229,"nodeType":876},{},[68230],{"data":68231,"marks":68232,"value":68234,"nodeType":867},{},[68233],{"type":865},"Does this solution provide SaaS discovery?",{"data":68236,"content":68237,"nodeType":1629},{},[68238,68248,68258],{"data":68239,"content":68240,"nodeType":1586},{},[68241],{"data":68242,"content":68243,"nodeType":876},{},[68244],{"data":68245,"marks":68246,"value":68247,"nodeType":867},{},[],"Will this tool find what SaaS apps employees are using, including those you don’t already know about? If so, how? ",{"data":68249,"content":68250,"nodeType":1586},{},[68251],{"data":68252,"content":68253,"nodeType":876},{},[68254],{"data":68255,"marks":68256,"value":68257,"nodeType":867},{},[],"Will the tool be able to differentiate between a user visiting a SaaS website, and actually logging into the app? How will it determine who the user is?",{"data":68259,"content":68260,"nodeType":1586},{},[68261],{"data":68262,"content":68263,"nodeType":876},{},[68264],{"data":68265,"marks":68266,"value":68267,"nodeType":867},{},[],"If the tool doesn’t provide you with SaaS discovery (finding Shadow IT and the apps employees are using that aren’t on your radar), how will you deal with those apps employees are using without your knowledge?",{"data":68269,"content":68270,"nodeType":876},{},[68271],{"data":68272,"marks":68273,"value":68275,"nodeType":867},{},[68274],{"type":865},"Does the tool provide enough context so you can manage SaaS risk?",{"data":68277,"content":68278,"nodeType":1629},{},[68279,68289,68299],{"data":68280,"content":68281,"nodeType":1586},{},[68282],{"data":68283,"content":68284,"nodeType":876},{},[68285],{"data":68286,"marks":68287,"value":68288,"nodeType":867},{},[],"Are you getting context about how your users are using apps (are they logging in with social logins or passwords, do they have MFA enabled, are they admins on the app, etc.), or is it only providing generic information about the app?",{"data":68290,"content":68291,"nodeType":1586},{},[68292],{"data":68293,"content":68294,"nodeType":876},{},[68295],{"data":68296,"marks":68297,"value":68298,"nodeType":867},{},[],"How will you engage employees that already rely on these SaaS platforms, or want to adopt new apps, can you handle that though email or in-person - or do you need something more scalable?",{"data":68300,"content":68301,"nodeType":1586},{},[68302],{"data":68303,"content":68304,"nodeType":876},{},[68305],{"data":68306,"marks":68307,"value":68308,"nodeType":867},{},[],"Do you need the ability to apply progressive controls, or simply need the ability to block apps entirely?",{"data":68310,"content":68311,"nodeType":876},{},[68312,68316,68324],{"data":68313,"marks":68314,"value":68315,"nodeType":867},{},[],"\nIf you aren’t sure about these questions, why not consider what a ",{"data":68317,"content":68319,"nodeType":915},{"uri":68318},"/product",[68320],{"data":68321,"marks":68322,"value":68323,"nodeType":867},{},[],"user-powered security approach",{"data":68325,"marks":68326,"value":68327,"nodeType":867},{},[]," might look like for your organization.","How to find the right SaaS security solution for your organization ","In this guide, we’ll break down some major SaaS use cases and match them up with solutions that can address them, covering pros and cons for each.\n","2022-07-25T00:00:00.000Z","how-to-find-the-right-saas-security-solution-for-your-organization",{"items":68333},[68334,68336],{"sys":68335,"name":67991},{"id":67990},{"sys":68337,"name":2710},{"id":2709},{"items":68339},[68340],{"fullName":28592,"firstName":28593,"jobTitle":28594,"profilePicture":68341},{"url":28596},"embrace-saas-to-move-faster-than-your-competitors","blog/embrace-saas-to-move-faster-than-your-competitors",{"json":68345},{"data":68346,"content":68347,"nodeType":1680},{},[68348],{"data":68349,"content":68350,"nodeType":876},{},[68351],{"data":68352,"marks":68353,"value":68354,"nodeType":867},{},[],"One of the questions we hear all the time is, “Can’t I just block my employees from using SaaS that my team hasn’t already vetted and approved?” And the answer is “Yes, you can. You can certainly block the apps we find your employees using, but the real question is ‘Should you?’”","Look at enabling SaaS from a broader understanding of the business and not just the impact to security",{"id":68357,"publishedAt":68358},"6tC3Xqkq7kdTMOvqLMEafp","2026-08-12T11:56:23.643Z",{"items":68360},[68361,68363],{"sys":68362,"name":67991},{"id":67990},{"sys":68364,"name":297},{"id":2706},{"items":68366},[68367,68369,68371,68373,68375,68377,68379,68381,68383,68385,68387,68389,68391,68393],{"sys":68368,"name":279,"slug":280,"tier":31},{"id":276},{"sys":68370,"name":413,"slug":414,"tier":31},{"id":410},{"sys":68372,"name":545,"slug":546,"tier":31},{"id":542},{"sys":68374,"name":642,"slug":643,"tier":31},{"id":639},{"sys":68376,"name":404,"slug":405,"tier":45},{"id":401},{"sys":68378,"name":484,"slug":485,"tier":45},{"id":481},{"sys":68380,"name":324,"slug":325,"tier":45},{"id":321},{"sys":68382,"name":333,"slug":334,"tier":45},{"id":330},{"sys":68384,"name":395,"slug":396,"tier":45},{"id":392},{"sys":68386,"name":607,"slug":608,"tier":45},{"id":604},{"sys":68388,"name":431,"slug":432,"tier":45},{"id":428},{"sys":68390,"name":377,"slug":378,"tier":45},{"id":374},{"sys":68392,"name":475,"slug":476,"tier":45},{"id":472},{"sys":68394,"name":589,"slug":590,"tier":45},{"id":586},"PhHQYsz58S-CFuI0MPA3Ypt9HqK31oerSR9bZ31hOnY",1787040069681]