The Pyramid of Pain in the AI era: Why technique-level detection matters more than ever
AI is accelerating the collapse of indicator-based threat detection. Here's why you need technique-level detection to stay ahead.
Stop account takeover
Stop ATO with stolen credential and compromised token detection.
Harden unmanaged identities
Harden access paths with visibility, detection, and guardrails.
Investigate browser-related incidents
Investigate and respond faster with unique browser telemetry.
Secure shadow SaaS
See and control shadow SaaS in the browser.
Secure AI
See and control AI apps in the browser.
Secure BYOD
Extend consistent browser-based protection to unmanaged devices.
Secure Chromebooks
Secure browser activity on Chromebooks without endpoint agents.
Investigate and stop data loss
Detect and prevent data loss across AI tools, apps, and sessions.
15 posts
Vishing — voice phishing — uses phone calls to impersonate IT support, help desks, or employees, talking targets into password resets, MFA approvals, or opening attacker-controlled pages. Threat actors now routinely pair calls with AiTM phishing to hijack SSO accounts, a chain Push has analyzed across campaigns targeting hundreds of organizations.
AI is accelerating the collapse of indicator-based threat detection. Here's why you need technique-level detection to stay ahead.
What we can learn from 2026's installment of the Verizon Data Breach Investigations Report.
ShinyHunters' breach of Instructure is the latest in a long series of attacks. Here's our view of the big picture.
We got an inside look at a phishing panel used in criminal campaigns linked to operators like ShinyHunters and BlackFile. Here’s what we found.
Device code phishing is seeing a huge spike in adoption in 2026, enabling attackers to steal access tokens while bypassing standard access controls.
Analysing the Stryker breach in line with recent changes to the Iran-nexus cyber playbook.
Analyzing the latest Scattered Lapsus$ Hunters (SLH) phishing campaign targeting hundreds of organizations.
Here’s how real-world attacks and our own R&D informed what we built for Push customers over the last year.
How Scattered Lapsus$ Hunters breaches demonstrate the evolution of attacker TTPs, shaping the future of cyber attacks.
Scattered Spider continues to dominate the headlines, with attacks on aviation and insurance companies worldwide.
Scattered Spider has dominated the headlines in recent months with a consistent focus on help desk scams. Here's what you need to know to protect your business.
Push's new Employee Identity Verification Codes feature is a simple way for your help desk to confirm they’re talking to someone from your organization.
Here’s what’s new on the Push platform for June 2025.
How the notorious Scattered Spider cyber criminal group are switching up their TTPs in 2025 to bypass MFA and breach cloud services via account takeover.
To help organizations keep track of how browser-based identity attacks are evolving, we've put together this index of recent breaches.
The latest news, articles, and resources, sent to your inbox.