What we learned from 'Security Theater vs. Security That Works' with Matt Johansen
What we learned from sitting down with Matt Johansen to discuss the difference between security theater and security that actually works.
Stop account takeover
Stop ATO with stolen credential and compromised token detection.
Harden unmanaged identities
Harden access paths with visibility, detection, and guardrails.
Investigate browser-related incidents
Investigate and respond faster with unique browser telemetry.
Secure shadow SaaS
See and control shadow SaaS in the browser.
Secure AI
See and control AI apps in the browser.
Secure BYOD
Extend consistent browser-based protection to unmanaged devices.
Secure Chromebooks
Secure browser activity on Chromebooks without endpoint agents.
Investigate and stop data loss
Detect and prevent data loss across AI tools, apps, and sessions.
58 posts
MFA bypass covers the techniques attackers use to defeat multi-factor authentication — AiTM phishing kits, consent phishing, device code phishing, and MFA downgrade attacks among them. None of these break the second factor; they route around it. Push researchers regularly get hands-on with phishing kits like Evilginx and Sneaky2FA, analyzing how these attacks work in the wild and how they evolve.
What we learned from sitting down with Matt Johansen to discuss the difference between security theater and security that actually works.
Here are 7 things we learned from our conversation with Troy Hunt on the "Yes, you've been pwned" webinar.
Here are 7 things we learned from our conversation with John Hammond on the "Why the browser is the new battleground" webinar.
We got an inside look at a phishing panel used in criminal campaigns linked to operators like ShinyHunters and BlackFile. Here’s what we found.
Investigating a new criminal toolkit for ConsentFix being promoted on criminal forums.
Browser sync attacks result in business credentials being compromised via personal account and device breaches. Here's what you need to know.
How to use in-browser controls to stop browser-based attacks before compromise can occur
Device code phishing is seeing a huge spike in adoption in 2026, enabling attackers to steal access tokens while bypassing standard access controls.
Analysing the Stryker breach in line with recent changes to the Iran-nexus cyber playbook.
Analyzing the latest Scattered Lapsus$ Hunters (SLH) phishing campaign targeting hundreds of organizations.
New insights on the ConsentFix campaign stopped by Push.
Here’s how real-world attacks and our own R&D informed what we built for Push customers over the last year.
Analyzing the key trends that defined phishing attacks in 2025, and what these changes mean for security teams heading into 2026.
Analyzing "ConsentFix", a new browser-native attack technique we've detected in the wild, combining OAuth consent phishing with a ClickFix-style user prompt.
Push recently detected and blocked a malvertising attack impersonating TradingView designed to hijack Google Workspace accounts.
Analysing a malvertising attack targeting Google business accounts that was intercepted by Push.
Investigating a phishing campaign targeting Google Ads Manager MCC accounts to propagate malvertising lures.
Analyzing a BITB phishing page linked to the Sneaky2FA Phishing-as-a-Service operation.
Diving into the latest sophisticated LinkedIn phishing campaign intercepted by Push.
Why phishing attacks are moving away from exclusively email-based delivery, and what this means for security teams.
How Push saved a company exec from a sophisticated Attacker-in-the-Middle phishing attack delivered via a LinkedIn direct message.
What security teams need to know about the browser-based attack techniques that are the leading cause of breaches.
How attacks have moved away from endpoints and internal networks to the browser — a blind spot for traditional security tools.
Push recently identified a novel phishing attack using Active Directory Federation Services to get Microsoft to send victims to a phishing site.
Introducing our latest resource for security teams breaking down the techniques that modern phishing attacks are using to evade detection.
We’re launching a new Detections capability, enabling security teams to more effectively investigate and triage alerts, and build more effective workflows.
MFA downgrade attacks are an increasingly common technique used by attackers to bypass phishing-resistant authentication methods registered to an account.
Scattered Spider continues to dominate the headlines, with attacks on aviation and insurance companies worldwide.
Scattered Spider has dominated the headlines in recent months with a consistent focus on help desk scams. Here's what you need to know to protect your business.
How App-Specific Password phishing is being used in the wild to bypass phishing-resistant authentication controls like passkeys.
How the notorious Scattered Spider cyber criminal group are switching up their TTPs in 2025 to bypass MFA and breach cloud services via account takeover.
Why being in the browser gives defenders a key advantage over network and email phishing prevention, detection, and response tools.
Most phishing attacks involve a phishing page that has never been seen before. When detection relies on known-bad, this makes every attack feel like a zero-day.
I’m thrilled to share that Push Security has raised our Series B funding. This is a huge moment for us and our customers in the fight against identity attacks.
We recently investigated a malvertising campaign using Evilginx to target Onfido customers via Google ads.
Consent phishing is where attackers trick users into authorizing access for malicious OAuth apps. Here's how attackers are using this technique in the wild.
HIBP creator and well-known security person Troy Hunt recently blogged about a phish he fell for. Here’s what it tells us about how phishing is evolving.
Modern MFA-bypass phishing attacks are routinely defeating primarily email-based security controls. Why are controls failing and what can we do about it?
How app developers can go beyond Minimum Viable Secure Product (MVSP) to implement better identity protections and prevent identity-based attacks.
Using Push to enforce MFA on third-party apps in the browser — even where MFA enforcement isn't supported by the app itself.
How in-the-wild attacks and our own R&D inspired what we built in 2024 to stop account takeover and reduce security risks across your workforce identities.
Reviewing public breaches that stemmed from identity attacks in 2024.
How phishing for email verification can be combined with cross-IdP impersonation to gain direct access to downstream SaaS and bypass hardened IdP accounts.
Cross-IdP impersonation is a method of hijacking SSO to access downstream apps — without needing to compromise accounts on your company’s main IdP.
Using Push data to calculate how many vulnerable identities the average organization has, and how they lead to different methods of account takeover.
It’s been almost exactly a year since we released our open source repository of SaaS-native attack techniques. Let's reflect on what’s changed.
How Push stops attackers from using identity attack tools and techniques to compromise your employee user accounts.
Taking a closer look at the steps that AitM phishing kits take to hide from the prying eyes of security teams and threat intelligence vendors.
Breaking down common misconceptions about identity threats and controls like MFA, SSO, passkeys, password managers, and more.
Push's browser agent identifies session token theft by adding telemetry to the user agent string to create a new high-fidelity signal for your security team.
Push analyzes behavioral attributes of malware to identify phishing tools like Evilginx and NakedPages and immediately block end-users from visiting them.
Attackers are using Adversary in the Middle (AitM) phishing toolkits to bypass MFA. We look at what AitM is, how it works, and what you can do about it.
Here’s what’s new on the Push platform for May 2024.
Use the Push browser agent’s unique vantage point to protect SSO credentials by blocking employees from entering their password into any other site.
To help organizations keep track of how browser-based identity attacks are evolving, we've put together this index of recent breaches.
In this article, we'll show you how to use Okta to do keylogging for you, without needing to have your own malicious domain hosting your malicious SAML server.
We'll walk through how to quickly detect and mitigate business email compromise (BEC) and then prevent future attacks.
Consent phishing is an emerging technique attackers are using to compromise user accounts, even if they have Multi-factor Authentication (MFA or 2FA) enabled.
The latest news, articles, and resources, sent to your inbox.