Your EDR is working exactly as intended. Attackers are getting around it anyway.
This article explains the gap between what EDR sees and what happens inside the browser, and what it takes to close it.
Stop account takeover
Stop ATO with stolen credential and compromised token detection.
Harden unmanaged identities
Harden access paths with visibility, detection, and guardrails.
Investigate browser-related incidents
Investigate and respond faster with unique browser telemetry.
Secure shadow SaaS
See and control shadow SaaS in the browser.
Secure AI
See and control AI apps in the browser.
Secure BYOD
Extend consistent browser-based protection to unmanaged devices.
Secure Chromebooks
Secure browser activity on Chromebooks without endpoint agents.
Investigate and stop data loss
Detect and prevent data loss across AI tools, apps, and sessions.
39 posts
Phishing-as-a-service (PhaaS) platforms sell ready-made phishing kits, hosted infrastructure, and management panels on subscription, letting low-skill criminals run MFA-bypassing campaigns at scale. Kits like Evilginx, Tycoon2FA, Sneaky2FA, FlowerStorm, and EvilTokens each add their own evasion and session-theft capabilities, and new entrants appear regularly. Push researchers continuously get hands-on with these tools — investigating attacks in the wild, reverse-engineering kit behavior, and turning that research into detections.
This article explains the gap between what EDR sees and what happens inside the browser, and what it takes to close it.
AI is accelerating the collapse of indicator-based threat detection. Here's why you need technique-level detection to stay ahead.
What we learned from sitting down with Matt Johansen to discuss the difference between security theater and security that actually works.
Here are 7 things we learned from our conversation with Troy Hunt on the "Yes, you've been pwned" webinar.
Here are 7 things we learned from our conversation with John Hammond on the "Why the browser is the new battleground" webinar.
Why "good enough" isn’t enough when it comes to browser security, and a best-of-breed approach is needed to tackle emerging threats.
Unpacking the latest research report from Omdia and what it means for the secure enterprise browser market.
Securing the browser vs. securing the organization via the browser — what's the difference?
How we built an end-to-end threat hunting and detection engineering capability at Push that uses AI agents as a force multiplier.
ShinyHunters' breach of Instructure is the latest in a long series of attacks. Here's our view of the big picture.
We're re-releasing the SaaS attack matrix as the Browser & Identity Attacks Matrix. Here's why we've decided to make the change and what it means.
We got an inside look at a phishing panel used in criminal campaigns linked to operators like ShinyHunters and BlackFile. Here’s what we found.
Investigating a new criminal toolkit for ConsentFix being promoted on criminal forums.
Device code phishing is seeing a huge spike in adoption in 2026, enabling attackers to steal access tokens while bypassing standard access controls.
Analyzing the latest Scattered Lapsus$ Hunters (SLH) phishing campaign targeting hundreds of organizations.
Here’s how real-world attacks and our own R&D informed what we built for Push customers over the last year.
Analyzing the key trends that defined phishing attacks in 2025, and what these changes mean for security teams heading into 2026.
Push recently detected and blocked a malvertising attack impersonating TradingView designed to hijack Google Workspace accounts.
Investigating a phishing campaign targeting Google Ads Manager MCC accounts to propagate malvertising lures.
Analyzing a BITB phishing page linked to the Sneaky2FA Phishing-as-a-Service operation.
How Push saved a company exec from a sophisticated Attacker-in-the-Middle phishing attack delivered via a LinkedIn direct message.
What security teams need to know about the browser-based attack techniques that are the leading cause of breaches.
How attacks have moved away from endpoints and internal networks to the browser — a blind spot for traditional security tools.
Introducing our latest resource for security teams breaking down the techniques that modern phishing attacks are using to evade detection.
MFA downgrade attacks are an increasingly common technique used by attackers to bypass phishing-resistant authentication methods registered to an account.
How the notorious Scattered Spider cyber criminal group are switching up their TTPs in 2025 to bypass MFA and breach cloud services via account takeover.
Why being in the browser gives defenders a key advantage over network and email phishing prevention, detection, and response tools.
Most phishing attacks involve a phishing page that has never been seen before. When detection relies on known-bad, this makes every attack feel like a zero-day.
I’m thrilled to share that Push Security has raised our Series B funding. This is a huge moment for us and our customers in the fight against identity attacks.
We recently investigated a malvertising campaign using Evilginx to target Onfido customers via Google ads.
Consent phishing is where attackers trick users into authorizing access for malicious OAuth apps. Here's how attackers are using this technique in the wild.
HIBP creator and well-known security person Troy Hunt recently blogged about a phish he fell for. Here’s what it tells us about how phishing is evolving.
Modern MFA-bypass phishing attacks are routinely defeating primarily email-based security controls. Why are controls failing and what can we do about it?
How in-the-wild attacks and our own R&D inspired what we built in 2024 to stop account takeover and reduce security risks across your workforce identities.
How attackers are breaking detection signatures designed to identify phishing sites impersonating real login pages.
We've added cloned login page detection, providing yet another layer of protection against phishing attacks.
Taking a closer look at the steps that AitM phishing kits take to hide from the prying eyes of security teams and threat intelligence vendors.
Push analyzes behavioral attributes of malware to identify phishing tools like Evilginx and NakedPages and immediately block end-users from visiting them.
Attackers are using Adversary in the Middle (AitM) phishing toolkits to bypass MFA. We look at what AitM is, how it works, and what you can do about it.
The latest news, articles, and resources, sent to your inbox.