We coined the poisoned tenant attack in 2023; in 2026, someone used it on us
Someone created a fake OpenAI organization using our company's name and invited specific Push employees to join it. Here's what we learned.
Stop account takeover
Stop ATO with stolen credential and compromised token detection.
Harden unmanaged identities
Harden access paths with visibility, detection, and guardrails.
Investigate browser-related incidents
Investigate and respond faster with unique browser telemetry.
Secure shadow SaaS
See and control shadow SaaS in the browser.
Secure AI
See and control AI apps in the browser.
Secure BYOD
Extend consistent browser-based protection to unmanaged devices.
Secure Chromebooks
Secure browser activity on Chromebooks without endpoint agents.
Investigate and stop data loss
Detect and prevent data loss across AI tools, apps, and sessions.
56 posts
Identity attacks target user accounts rather than infrastructure — phishing credentials, stealing sessions, abusing OAuth grants — because logging in is easier than hacking in. Identity-based techniques are now the leading cause of breaches. Push’s offensive research maps these techniques continuously, coining attacks like SAMLjacking and the poisoned tenant before they appeared in the wild.
Someone created a fake OpenAI organization using our company's name and invited specific Push employees to join it. Here's what we learned.
We got an inside look at a phishing panel used in criminal campaigns linked to operators like ShinyHunters and BlackFile. Here’s what we found.
In April 2026, Vercel was compromised via an OAuth app integrated into their Google Workspace tenant stemming from a compromised third-party AI SaaS provider.
Device code phishing is seeing a huge spike in adoption in 2026, enabling attackers to steal access tokens while bypassing standard access controls.
Analysing the Stryker breach in line with recent changes to the Iran-nexus cyber playbook.
Why cloud security tools only give you part of the picture when it comes to modern attacks.
Analyzing the latest Scattered Lapsus$ Hunters (SLH) phishing campaign targeting hundreds of organizations.
Attackers are going out of their way to target Google Ad Manager accounts, powering malvertising scams. Here’s what you need to know.
Analyzing the key trends that defined phishing attacks in 2025, and what these changes mean for security teams heading into 2026.
How Scattered Lapsus$ Hunters breaches demonstrate the evolution of attacker TTPs, shaping the future of cyber attacks.
How attacks have moved away from endpoints and internal networks to the browser — a blind spot for traditional security tools.
Introducing our latest resource for security teams breaking down the techniques that modern phishing attacks are using to evade detection.
We’re launching a new Detections capability, enabling security teams to more effectively investigate and triage alerts, and build more effective workflows.
MFA downgrade attacks are an increasingly common technique used by attackers to bypass phishing-resistant authentication methods registered to an account.
Scattered Spider continues to dominate the headlines, with attacks on aviation and insurance companies worldwide.
Scattered Spider has dominated the headlines in recent months with a consistent focus on help desk scams. Here's what you need to know to protect your business.
How App-Specific Password phishing is being used in the wild to bypass phishing-resistant authentication controls like passkeys.
Attackers are routinely defeating conventional email, network, and endpoint-based security controls. Here's how browser controls can level the playing field.
Push's new Employee Identity Verification Codes feature is a simple way for your help desk to confirm they’re talking to someone from your organization.
We’re thrilled to announce our partnership with Cribl to make it much easier to snapshot, transform, and query Push telemetry.
Introducing a new era of partner-first phishing protection and identity security.
How the notorious Scattered Spider cyber criminal group are switching up their TTPs in 2025 to bypass MFA and breach cloud services via account takeover.
We're back with part 2 of our research into OpenAI Operator to share our findings on how it can be used to automate identity attacks.
Credential stuffing attacks had a huge impact in 2024. But things could be dialled up even further with Computer-Using Agents like OpenAI Operator.
How app developers can go beyond Minimum Viable Secure Product (MVSP) to implement better identity protections and prevent identity-based attacks.
CUAs are a new type of AI agent that drives your browser/OS for you, enabling effortless automation of web tasks — including those performed by attackers.
Using Push data to calculate how many vulnerable identities the average organization has, and how they lead to different methods of account takeover.
It’s been almost exactly a year since we released our open source repository of SaaS-native attack techniques. Let's reflect on what’s changed.
How Push stops attackers from using identity attack tools and techniques to compromise your employee user accounts.
We've added cloned login page detection, providing yet another layer of protection against phishing attacks.
This is the first blog in a short series we’re putting together about the ‘why’ behind the ‘what’ at Push. This entry is focused on threat detection.
What the rise in popularity of infostealers tells us about the cybercrime ecosystem and the shift toward identity attacks.
Taking a closer look at the steps that AitM phishing kits take to hide from the prying eyes of security teams and threat intelligence vendors.
Breaking down common misconceptions about identity threats and controls like MFA, SSO, passkeys, password managers, and more.
How ghost logins can be used by cyber attackers for account takeover and persistence.
Enable detections and interventions in the browser using Push’s new security controls.
Push is excited to partner with Panther, bringing our unique browser telemetry to your SIEM.
Push's browser agent identifies session token theft by adding telemetry to the user agent string to create a new high-fidelity signal for your security team.
How to use Push to investigate and respond to a third-party data breach, which results in credentials being stolen and sold on criminal marketplaces.
Right now the majority of detections for identity attacks rely on web proxy telemetry. Here’s why the browser can be a better alternative.
Push analyzes behavioral attributes of malware to identify phishing tools like Evilginx and NakedPages and immediately block end-users from visiting them.
To help organizations keep track of how browser-based identity attacks are evolving, we've put together this index of recent breaches.
Can admins access the secrets from your corporate password manager? If so, how does this affect incident response in a compromised admin account scenario?
In this blog post we will cover what identities are, how we secure perimeters in general, and and how this maps to the identity space.
In this article, we'll explain what SAML SSO is, how it works, and clarify some common misconceptions.
In this article, we'll show you how to use Okta to do keylogging for you, without needing to have your own malicious domain hosting your malicious SAML server.
We'll cover the implications of using Okta's SWA authentication method. Learn what security teams need to know in an account breach and IR scenario.
In this post, we're going to demonstrate how to phish via Slack to gain persistence and move laterally.
A new report on securing digital identities has some interesting takeaways to consider as we think about securing identities in the cloud. Here's our take.
Credential stuffing attacks are incredibly common, but they often go undetected. These attacks are often the entry point for attack. Learn how to prevent them.
In this article, we’re going to demonstrate how combining two of our favorite new SaaS attack techniques makes a simple, but very stealthy persistence approach.
While OAuth scopes provide seamless online user authentication, they also carry significant risk. Watch out for these common, dangerous scopes.
In this article, we’re going to demo combining two of our favorite new SaaS attack techniques to make a simple, but effective attack chain.
Offensive security drives defensive security. We're sharing a collection of SaaS attack techniques to help defenders understand the threats they face.
Attackers routinely use mail rules to hide their attacks, exfiltrate sensitive data, and to get persistent access to victim accounts.
Look at enabling SaaS from a broader understanding of the business and not just the impact to security
The latest news, articles, and resources, sent to your inbox.