[{"data":1,"prerenderedAt":51685},["ShallowReactive",2],{"application-flags":3,"navbar":7,"always-visible-banner":36,"navbar-about-highlight":108,"navbar-resource-highlight":182,"blog-topics":226,"trust-badges":656,"solution-nav":677,"fa-icon-solid-faUserSecret":800,"fa-icon-sharp-regular-faLaptopCode":804,"fa-icon-solid-faPlugCircleXmark":806,"fa-icon-sharp-regular-faPuzzlePiece":808,"fa-icon-solid-faFileCircleXmark":810,"fa-icon-solid-faGhost":813,"fa-icon-solid-faQrcode":816,"fa-icon-solid-faCookieBite":818,"fa-icon-sharp-regular-faFishingRod":820,"fa-icon-sharp-regular-faUserSecret":822,"fa-icon-sharp-regular-faRadar":824,"fa-icon-sharp-regular-faSatelliteDish":826,"fa-icon-sharp-regular-faShieldCheck":828,"fa-icon-sharp-regular-faBrainCircuit":830,"fa-icon-solid-faMobileScreenButton":832,"fa-icon-brands-faChrome":834,"fa-icon-solid-faDisplay":836,"fa-icon-solid-faFilter":838,"fa-icon-solid-faCloudArrowUp":840,"blog-topic-vishing":842},[4],{"name":5,"enabled":6},"maintenanceMode",false,[8],{"createdDate":9,"id":10,"name":11,"modelId":12,"published":13,"meta":14,"query":22,"data":23,"variations":28,"lastUpdated":29,"firstPublished":30,"testRatio":31,"createdBy":32,"lastUpdatedBy":33,"folders":34,"rev":35},1742208588866,"1c7a4e423bf54ac1a328bb4063459ef2","Banner","1c6207a5f24948ab82d4a0b17f251193","published",{"breakpoints":15,"hasAutosaves":19,"kind":20,"lastPreviewUrl":21},{"medium":16,"small":17,"xsmall":18},768,640,320,true,"data","",[],{"link":24,"text":25,"type":26,"url":27},{},"Get our latest report analyzing browser attack techniques in 2026","web-banner","https://pushsecurity.com/resources/browser-attacks-report",{},1774258294825,1742208637545,1,"CydmZnOWU1XuAaLhEDCoYNM4Z8W2","jKjF9r5jcvXU8tzZEfFQm31Iyvr2",[],"j7ew2tin4q",{"createdBy":37,"createdDate":38,"data":39,"folders":94,"id":95,"lastUpdated":96,"lastUpdatedBy":97,"meta":98,"modelId":102,"name":103,"published":13,"query":104,"testRatio":31,"variations":105,"firstPublished":106,"stageModifiedSincePublish":6,"rev":107},"ST0tXQM8slWpFrmioqKHmENB2qe2",1774965361051,{"ctaText":40,"text":41,"url":21,"blocks":42,"state":90},"ewrererw","testrfesssssssssss",[43,70,78],{"@type":44,"@version":45,"id":46,"component":47,"responsiveStyles":60},"@builder.io/sdk:Element",2,"builder-ca12c06a52de41d7b8743da53118cd38",{"name":48,"tag":48,"options":49,"isRSC":59},"TopBannerContent",{"text":50,"ctaText":51,"url":52,"mainText":53,"cta":56},"New Webinar Series: Join John Hammond, Troy Hunt, and Matt Johansen for the State of Browser Attacks","Save Your Spot","https://pushsecurity.com/webinar/state-of-browser-security",{"content":54,"fontSize":55},"\u003Cp class=\"\">Do you know how much AI is in your workforce? Find out August 20th.\u003C/p>","text-base",{"content":57,"fontSize":55,"url":58},"\u003Cp class=\"\">Save your seat →\u003C/p>","https://pushsecurity.com/webinar/shadow-ai",null,{"large":61},{"display":62,"flexDirection":63,"position":64,"flexShrink":65,"boxSizing":66,"marginTop":67,"marginBottom":67,"fontSize":68,"fontWeight":69},"flex","column","relative","0","border-box",".56rem","1.125rem","700",{"@type":44,"@version":45,"id":71,"component":72,"responsiveStyles":76},"builder-a2e1f4b9f30b464bb814d7f5de5b0aa7",{"name":73,"options":74,"isRSC":59},"Custom Code",{"code":75,"scriptsClientOnly":6},"\u003Cstyle>\n  .top-banner.bg-web-orange{background:rgb(114, 79, 255);}\n\u003C/style>\n",{"large":77},{"display":62,"flexDirection":63,"position":64,"flexShrink":65,"boxSizing":66},{"id":79,"@type":44,"tagName":80,"properties":81,"responsiveStyles":85},"builder-pixel-k74nkzlquog","img",{"src":82,"aria-hidden":83,"alt":21,"role":84,"width":65,"height":65},"https://cdn.builder.io/api/v1/pixel?apiKey=f3a1111ff5be48cdbb123cd9f5795a05","true","presentation",{"large":86},{"height":65,"width":65,"display":87,"opacity":65,"overflow":88,"pointerEvents":89},"block","hidden","none",{"deviceSize":91,"location":92},"large",{"path":21,"query":93},{},[],"fd266d0172cc47429be7ad10f48c99ad",1786155414606,"kYgMv6WsbvfmlOUYqR2SFwGzw6e2",{"breakpoints":99,"hasAutosaves":6,"hasErrors":6,"hasLinks":6,"kind":100,"lastPreviewUrl":101},{"medium":16,"small":17,"xsmall":18},"component","https://pushsecurity.com/?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CcreateProjects%2CsendPullRequests%2CfusionHostingPublish&builder.user.role.name=Designer&builder.user.role.id=creator&builder.cachebust=true&builder.preview=always-visible-banner&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.always-visible-banner=fd266d0172cc47429be7ad10f48c99ad&builder.overrides.fd266d0172cc47429be7ad10f48c99ad=fd266d0172cc47429be7ad10f48c99ad&builder.options.locale=Default","0678d178ec8b41efb8a23c09dba7874d","always visible banner",[],{},1774968080803,"1lcyl36j3gz",[109,145],{"createdBy":32,"createdDate":110,"data":111,"folders":134,"id":135,"lastUpdated":136,"lastUpdatedBy":32,"meta":137,"modelId":139,"name":140,"published":13,"query":141,"stageModifiedSincePublish":6,"testRatio":31,"variations":142,"firstPublished":143,"rev":144},1776247359804,{"link":112,"testimonial":113,"testimonialLink":133,"type":116},{},{"@type":114,"id":115,"model":116,"value":117},"@builder.io/core:Reference","f028f2b685bb47cd8bf9e82a26dd5a79","testimonial",{"query":118,"folders":119,"createdDate":120,"id":115,"name":121,"modelId":122,"published":13,"data":123,"variations":127,"lastUpdated":128,"firstPublished":129,"testRatio":31,"createdBy":37,"lastUpdatedBy":37,"meta":130,"rev":132},[],[],1735823466309,"We found Push to be more accurate when compared to competitors and the browser agent offered features that others couldn’t match.","42035571a56940ac98bff4544aa79aa5",{"author":124,"jobTitle":125,"quote":121,"image":126},"Jason Waits","\u003Cp>CISO at Inductive Automation\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Ff04c0c0689ce4a89ac0f0708d78c0a07",{},1735910703862,1735823501152,{"kind":20,"lastPreviewUrl":21,"breakpoints":131,"hasAutosaves":19},{"small":17,"medium":16},"xal7chkxmdh","/customer-stories/inductive-automation",[],"9136a8f18b3b4a6ba29b8653a99372b1",1776247404986,{"breakpoints":138,"hasAutosaves":6,"kind":20,"lastPreviewUrl":21},{"medium":16,"small":17,"xsmall":18},"20d9eaa352304613b3d1a794b400703d","testimonial-inductive-automation",[],{},1776247404973,"5mqgwlt47hs",{"createdBy":32,"createdDate":146,"data":147,"folders":174,"id":175,"lastUpdated":176,"lastUpdatedBy":32,"meta":177,"modelId":139,"name":172,"published":13,"query":179,"stageModifiedSincePublish":6,"testRatio":31,"variations":180,"firstPublished":181,"rev":144},1776255761419,{"description":148,"image":149,"link":150,"testimonial":153,"title":172,"type":173},"Learn about the latest techniques being used in the wild.","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F7b4a5ebf81d64e8c9d7fc35f6c96c4a9",{"text":151,"url":152},"Download now","/resources/browser-attacks-report",{"@type":114,"id":154,"model":116,"value":155},"192acbb1f9ca4cac918c0ec435a8bae3",{"query":156,"folders":157,"createdDate":158,"id":154,"name":159,"modelId":122,"published":13,"data":160,"variations":166,"lastUpdated":167,"firstPublished":168,"testRatio":31,"createdBy":37,"lastUpdatedBy":32,"meta":169,"rev":171},[],[],1728981467463,"Push does for identity what CrowdStrike did for the endpoint",{"video":161,"jobTitle":162,"author":163,"qoute":21,"quote":164,"image":165},"https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F8b30e8ca50064058bbaef0f3c6164575%2Fcompressed?apiKey=f3a1111ff5be48cdbb123cd9f5795a05&token=8b30e8ca50064058bbaef0f3c6164575&alt=media&optimized=true","\u003Cp>Deputy CISO at Microsoft\u003C/p>\u003Cp>Former LinkedIn, Slack, Palantir\u003C/p>","Geoff Belknap","Push does for identity what CrowdStrike did for the endpoint.","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F748f0ad0a5064a00a13f4721fcc8dea1",{},1742902158597,1728981782923,{"kind":20,"lastPreviewUrl":21,"breakpoints":170,"hasAutosaves":19},{"small":17,"medium":16},"kg131t0jkvo","Report: 2026 Browser Attack Techniques","resource",[],"05a9322735fc427db12e2740e4302300",1776255810913,{"breakpoints":178,"hasAutosaves":6,"kind":20,"lastPreviewUrl":21},{"medium":16,"small":17,"xsmall":18},[],{},1776255810900,[183,205],{"createdBy":32,"createdDate":184,"data":185,"folders":195,"id":196,"lastUpdated":197,"lastUpdatedBy":32,"meta":198,"modelId":200,"name":172,"published":13,"query":201,"stageModifiedSincePublish":6,"testRatio":31,"variations":202,"firstPublished":203,"rev":204},1776256900280,{"description":148,"image":149,"link":186,"testimonial":187,"title":172,"type":173},{"text":151,"url":152},{"@type":114,"id":154,"model":116,"value":188},{"query":189,"folders":190,"createdDate":158,"id":154,"name":159,"modelId":122,"published":13,"data":191,"variations":192,"lastUpdated":167,"firstPublished":168,"testRatio":31,"createdBy":37,"lastUpdatedBy":32,"meta":193,"rev":171},[],[],{"video":161,"jobTitle":162,"author":163,"qoute":21,"quote":164,"image":165},{},{"kind":20,"lastPreviewUrl":21,"breakpoints":194,"hasAutosaves":19},{"small":17,"medium":16},[],"1f429607996e4e5fae8fe3f9b9610e55",1776256937553,{"breakpoints":199,"hasAutosaves":6,"kind":20,"lastPreviewUrl":21},{"medium":16,"small":17,"xsmall":18},"4829faa81e7c4ee8bd2d000e160e8d3c",[],{},1776256937540,"470xio0yv7r",{"createdBy":32,"createdDate":206,"data":207,"folders":217,"id":218,"lastUpdated":219,"lastUpdatedBy":32,"meta":220,"modelId":200,"name":222,"published":13,"query":223,"stageModifiedSincePublish":6,"testRatio":31,"variations":224,"firstPublished":225,"rev":204},1776256949234,{"link":208,"testimonial":209,"testimonialLink":133,"type":116},{},{"@type":114,"id":115,"model":116,"value":210},{"query":211,"folders":212,"createdDate":120,"id":115,"name":121,"modelId":122,"published":13,"data":213,"variations":214,"lastUpdated":128,"firstPublished":129,"testRatio":31,"createdBy":37,"lastUpdatedBy":37,"meta":215,"rev":132},[],[],{"author":124,"jobTitle":125,"quote":121,"image":126},{},{"kind":20,"lastPreviewUrl":21,"breakpoints":216,"hasAutosaves":19},{"small":17,"medium":16},[],"ce043785b71b4ece98eac811ecf4ba10",1776256974140,{"breakpoints":221,"hasAutosaves":6,"kind":20,"lastPreviewUrl":21},{"medium":16,"small":17,"xsmall":18},"inductive-automation",[],{},1776256974130,{"id":227,"extension":228,"items":229,"meta":653,"stem":654,"__hash__":655},"blogTopics/blogtopics.json","json",[230,239,247,256,265,274,283,292,301,310,319,328,337,346,355,363,372,381,390,399,408,417,426,435,443,452,461,470,479,488,497,506,514,523,532,540,549,558,566,575,584,593,602,611,619,628,637,645],{"sys":231,"faqItemsCollection":233,"name":235,"slug":236,"tier":31,"intro":237,"faqTitle":59,"postCount":238,"hasPage":19},{"id":232},"topic-ai",{"items":234},[],"AI","ai","AI is reshaping both sides of the security equation: employees adopt AI tools faster than security teams can track them, while attackers use AI to scale and automate campaigns. Shadow AI adoption may now outpace wider shadow SaaS, and attackers are already turning AI chatbot platforms into malware delivery channels. Push has researched the offensive potential of computer-using agents and now applies AI agents to its own threat hunting. This hub covers AI as risk, target, and defensive tool.",22,{"sys":240,"faqItemsCollection":242,"name":244,"slug":245,"tier":45,"intro":246,"faqTitle":59,"postCount":238,"hasPage":19},{"id":241},"topic-ai-attacks",{"items":243},[],"AI attacks","ai-attacks","AI attacks run in both directions: attackers using AI to scale phishing, malware delivery, and identity attacks, and AI platforms themselves becoming the attack surface. Push has researched how computer-using agents can automate identity attacks, and has seen the poisoned tenant technique it coined used against its own employees in the wild.",{"sys":248,"faqItemsCollection":250,"name":252,"slug":253,"tier":45,"intro":254,"faqTitle":59,"postCount":255,"hasPage":19},{"id":249},"topic-ai-governance",{"items":251},[],"AI governance","ai-governance","AI governance is how organizations set and enforce rules for workplace AI use — which tools are allowed, what data can enter them, and how to evidence it to regulators. With US, EU, and UK AI regulations converging on obligations most organizations can’t yet meet, Push’s research makes the case that enforcement starts in the browser, where AI tools are actually used.",9,{"sys":257,"faqItemsCollection":259,"name":261,"slug":262,"tier":45,"intro":263,"faqTitle":59,"postCount":264,"hasPage":19},{"id":258},"topic-aitm",{"items":260},[],"AiTM phishing","aitm","Adversary-in-the-middle (AiTM) phishing proxies a real login page through an attacker-controlled site, capturing credentials, MFA codes, and session tokens in real time to bypass multi-factor authentication. Push’s research into kits like Evilginx and Sneaky2FA documents how they evade URL- and signature-based detection — and why analyzing toolkit behavior in the browser catches attacks that blocklists miss.",77,{"sys":266,"faqItemsCollection":268,"name":270,"slug":271,"tier":45,"intro":272,"faqTitle":59,"postCount":273,"hasPage":6},{"id":267},"topic-bec",{"items":269},[],"BEC","bec","Business email compromise (BEC) turns a hijacked mailbox into a fraud tool: attackers use mail rules, auto-forwarding, and payment redirection to steal money while staying invisible to the account owner. Alongside a first-hand case study of a BEC attack that nearly cost an engineering firm millions, Push breaks down these mailbox persistence tricks and how to detect them.",3,{"sys":275,"faqItemsCollection":277,"name":279,"slug":280,"tier":31,"intro":281,"faqTitle":59,"postCount":282,"hasPage":19},{"id":276},"topic-browser-attacks",{"items":278},[],"Browser attacks","browser-attacks","Browser attacks target users through the web pages, sessions, and extensions they rely on every day — bypassing endpoint and network defenses that never see inside the browser. Techniques like AiTM phishing kits, ClickFix-style copy-paste attacks, OAuth consent abuse, malvertising, and browser sync abuse have become a leading path to account takeover. Push researchers analyze these attacks in the wild, from infiltrating criminal phishing panels to dissecting toolkits like ConsentFix and Sneaky2FA. Use this hub to track how the techniques evolve and how to defend against them.",118,{"sys":284,"faqItemsCollection":286,"name":288,"slug":289,"tier":45,"intro":290,"faqTitle":59,"postCount":291,"hasPage":19},{"id":285},"topic-browser-extensions",{"items":287},[],"Browser extensions","browser-extensions","Browser extensions cut both ways for security teams: malicious or compromised extensions are a growing attack vector, while an extension is also the lightest-weight way to deploy security controls into the browsers employees already use. These posts cover both sides — extension-borne risks like browser sync attacks and the limits of risk scoring, and how Push uses its extension to detect threats and block risky extensions.",30,{"sys":293,"faqItemsCollection":295,"name":297,"slug":298,"tier":31,"intro":299,"faqTitle":59,"postCount":300,"hasPage":19},{"id":294},"topic-browser-security",{"items":296},[],"Browser security","browser-security","Work now happens in the browser, making browser security — visibility and control at the point where users meet the web — a core layer of enterprise defense. Endpoint, network, and email tools miss attacks that unfold inside the browser session, from AiTM phishing to risky extensions and shadow SaaS. Push has published extensively on choosing between enterprise browsers and browser extensions, using browser telemetry, and making the business case for browser security. Start here for both strategy and hands-on guidance.",127,{"sys":302,"faqItemsCollection":304,"name":306,"slug":307,"tier":45,"intro":308,"faqTitle":59,"postCount":309,"hasPage":19},{"id":303},"topic-casb",{"items":305},[],"CASB","casb","Cloud access security brokers (CASBs) govern cloud app usage through API integrations and network proxies — an approach that works for sanctioned apps but struggles with the long tail of shadow SaaS employees adopt on their own. Because every SaaS signup happens in a browser, Push captures that adoption in real time at the point of login, and these posts cover what proxy-based discovery misses.",12,{"sys":311,"faqItemsCollection":313,"name":315,"slug":316,"tier":45,"intro":317,"faqTitle":59,"postCount":318,"hasPage":19},{"id":312},"topic-clickfix",{"items":314},[],"ClickFix","clickfix","ClickFix attacks trick users into copying and running malicious commands themselves — typically through fake CAPTCHA, error, or fix-it prompts — so malware executes without a download for security tools to scan. Push researchers track the technique’s evolution in the wild and identified the ConsentFix and InstallFix variants, which extend it to OAuth consent grants and fake install guides.",39,{"sys":320,"faqItemsCollection":322,"name":324,"slug":325,"tier":45,"intro":326,"faqTitle":59,"postCount":327,"hasPage":19},{"id":321},"topic-credential-phishing",{"items":323},[],"Credential phishing","credential-phishing","Credential phishing steals usernames and passwords through fake login pages impersonating the services employees use, handing attackers direct access to corporate accounts. Attackers don’t hack in — they log in. Push’s browser extension analyzes login pages as users actually see them, blocking cloned pages and stopping employees from entering company passwords on lookalike sites.",89,{"sys":329,"faqItemsCollection":331,"name":333,"slug":334,"tier":45,"intro":335,"faqTitle":59,"postCount":336,"hasPage":19},{"id":330},"topic-credential-stuffing",{"items":332},[],"Credential stuffing","credential-stuffing","Credential stuffing is an attack where criminals replay username-password pairs stolen from one breach against other services, exploiting password reuse to take over accounts. Major breaches have shown how far a single set of stolen credentials can travel. Push detects verified stolen credentials by comparing employee passwords against breach datasets and dark-web threat intelligence, eliminating false positives.",64,{"sys":338,"faqItemsCollection":340,"name":342,"slug":343,"tier":31,"intro":344,"faqTitle":59,"postCount":345,"hasPage":19},{"id":339},"topic-detection-and-response",{"items":341},[],"Detection & response","detection-and-response","Detection and response is being reshaped as attacks move into the browser, where EDR, SIEM, and network tools have limited visibility. Modern phishing kits evade signature-based detection, and most malicious pages have never been seen before — so technique-level, in-browser detection matters more than known-bad indicators. Push’s work here spans high-fidelity browser telemetry, session token theft detection, and agentic threat hunting, plus practical IR guidance for compromised SaaS accounts and malicious OAuth apps. These posts cover both the philosophy and the workflows.",101,{"sys":347,"faqItemsCollection":349,"name":351,"slug":352,"tier":45,"intro":353,"faqTitle":59,"postCount":354,"hasPage":19},{"id":348},"topic-detection-engineering",{"items":350},[],"Detection engineering","detection-engineering","Detection engineering turns threat research into reliable, high-fidelity detections — and as AI accelerates the churn of attacker infrastructure, indicator-based detection is collapsing in favor of technique-level approaches. Here you’ll find teardowns of AiTM kits, ClickFix pages, and malvertising campaigns, alongside Push’s own account of building an agentic threat hunting pipeline that turns hunts into shipped detections.",42,{"sys":356,"faqItemsCollection":358,"name":360,"slug":361,"tier":45,"intro":362,"faqTitle":59,"postCount":238,"hasPage":19},{"id":357},"topic-device-code-phishing",{"items":359},[],"Device code phishing","device-code-phishing","Device code phishing abuses the OAuth device authorization flow: attackers generate a legitimate sign-in code, trick the victim into entering it on the vendor’s real login page, and walk away with access tokens — no fake site or password capture required. Push research tracked a sharp spike in adoption during 2026 as attackers use the technique to sidestep standard access controls.",{"sys":364,"faqItemsCollection":366,"name":368,"slug":369,"tier":45,"intro":370,"faqTitle":59,"postCount":371,"hasPage":19},{"id":365},"topic-dlp",{"items":367},[],"DLP","dlp","Data loss prevention (DLP) is the practice of stopping sensitive data from leaving your control — a problem that has shifted from email and endpoints to the browser, where employees move data into SaaS and AI tools. Push applies controls at that point of use, from keeping corporate credentials out of personal password managers to governing what flows into unsanctioned apps.",15,{"sys":373,"faqItemsCollection":375,"name":377,"slug":378,"tier":45,"intro":379,"faqTitle":59,"postCount":380,"hasPage":19},{"id":374},"topic-edr",{"items":376},[],"EDR","edr","Endpoint detection and response (EDR) watches processes, files, and memory on the device — a vantage point that never sees the phishing pages, stolen sessions, and identity attacks playing out inside the browser. That’s not an EDR failure; attackers have simply moved where it can’t follow. These posts map that gap and show how Push pairs browser-level detection and response with endpoint security to close it.",24,{"sys":382,"faqItemsCollection":384,"name":386,"slug":387,"tier":45,"intro":388,"faqTitle":59,"postCount":389,"hasPage":19},{"id":383},"topic-enterprise-browser",{"items":385},[],"Enterprise browser","enterprise-browser","An enterprise browser is a standalone, security-hardened browser that organizations deploy in place of Chrome, Edge, or other defaults. The real buying question is whether replacing the browser beats securing the browsers employees already use — a trade-off these posts examine directly, alongside analysis of Omdia’s secure enterprise browser market report and Push’s framework for weighing full browsers against extension-based deployment.",6,{"sys":391,"faqItemsCollection":393,"name":395,"slug":396,"tier":45,"intro":397,"faqTitle":59,"postCount":398,"hasPage":19},{"id":392},"topic-ghost-logins",{"items":394},[],"Ghost logins","ghost-logins","Ghost logins are overlooked authentication routes into an account — like a password login lingering behind SSO, or a forgotten secondary auth method — that attackers exploit for account takeover and persistence. Push coined the term after research showing how these forgotten login paths let attackers sidestep the MFA and SSO controls guarding an account’s primary sign-in method.",48,{"sys":400,"faqItemsCollection":402,"name":404,"slug":405,"tier":45,"intro":406,"faqTitle":59,"postCount":407,"hasPage":19},{"id":401},"topic-identity-attacks",{"items":403},[],"Identity attacks","identity-attacks","Identity attacks target user accounts rather than infrastructure — phishing credentials, stealing sessions, abusing OAuth grants — because logging in is easier than hacking in. Identity-based techniques are now the leading cause of breaches. Push’s offensive research maps these techniques continuously, coining attacks like SAMLjacking and the poisoned tenant before they appeared in the wild.",56,{"sys":409,"faqItemsCollection":411,"name":413,"slug":414,"tier":31,"intro":415,"faqTitle":59,"postCount":416,"hasPage":19},{"id":410},"topic-identity-security",{"items":412},[],"Identity security","identity-security","Identity security is the practice of protecting workforce accounts, credentials, and sessions — the primary route attackers now use to breach organizations. Instead of hacking in, attackers log in: through phished credentials, stolen session tokens, MFA bypass, and forgotten ghost logins. Push’s research team documents these techniques continuously, from cross-IdP impersonation and SAMLjacking to analyses of major identity-driven breaches. This hub collects that research alongside practical guidance on MFA, SSO, and stopping account takeover.",154,{"sys":418,"faqItemsCollection":420,"name":422,"slug":423,"tier":45,"intro":424,"faqTitle":59,"postCount":425,"hasPage":19},{"id":419},"topic-infostealer",{"items":421},[],"Infostealer","infostealer","Infostealers are malware built to harvest saved passwords, cookies, and session tokens from infected devices, supplying the stolen credentials behind some of the most consequential breaches of recent years. Push traces the ecosystem trading this data and checks employee passwords against threat intel feeds, flagging verified stolen credentials before attackers can log in with them.",52,{"sys":427,"faqItemsCollection":429,"name":431,"slug":432,"tier":45,"intro":433,"faqTitle":59,"postCount":434,"hasPage":19},{"id":428},"topic-legitimate-service-abuse",{"items":430},[],"Legitimate service abuse","legitimate-service-abuse","Legitimate service abuse means staging attacks on trusted platforms — Google Ads, AI chatbot share pages, office.com links, Slack, SaaS tenants — so malicious content inherits the reputation of the service hosting it. Push research has documented the pattern repeatedly, from malvertising run through hijacked Google Ad Manager accounts to phishing links generated by Active Directory Federation Services.",28,{"sys":436,"faqItemsCollection":438,"name":440,"slug":441,"tier":45,"intro":442,"faqTitle":59,"postCount":291,"hasPage":19},{"id":437},"topic-malvertising",{"items":439},[],"Malvertising","malvertising","Malvertising uses paid search and display ads to put phishing pages and malware in front of users, often by impersonating trusted brands at the top of Google results. Push tracks these campaigns continuously — intercepting live attacks spoofing well-known brands — and has documented how criminals hijack Google Ads accounts to fund and run them.",{"sys":444,"faqItemsCollection":446,"name":448,"slug":449,"tier":45,"intro":450,"faqTitle":59,"postCount":451,"hasPage":19},{"id":445},"topic-malware-delivery",{"items":447},[],"Malware delivery","malware-delivery","Malware delivery has moved into the browser: rather than email attachments, attackers now rely on malvertising, fake install guides, and ClickFix-style copy-paste lures to get code running on endpoints. Push research on techniques like InstallFix maps the playbook, and in-browser detection of malicious copy and paste blocks these attacks before commands reach the endpoint.",13,{"sys":453,"faqItemsCollection":455,"name":457,"slug":458,"tier":45,"intro":459,"faqTitle":59,"postCount":460,"hasPage":19},{"id":454},"topic-mfa",{"items":456},[],"MFA","mfa","Multi-factor authentication (MFA) requires a second proof of identity beyond a password, and it remains one of the most effective controls against account takeover. Regulators from Cyber Essentials to NYDFS now mandate it across cloud services. Push enforces MFA in the browser on third-party apps — even those with no native enforcement option — and shows security teams where coverage gaps remain.",83,{"sys":462,"faqItemsCollection":464,"name":466,"slug":467,"tier":45,"intro":468,"faqTitle":59,"postCount":469,"hasPage":19},{"id":463},"topic-mfa-bypass",{"items":465},[],"MFA bypass","mfa-bypass","MFA bypass covers the techniques attackers use to defeat multi-factor authentication — AiTM phishing kits, consent phishing, device code phishing, and MFA downgrade attacks among them. None of these break the second factor; they route around it. Push researchers regularly get hands-on with phishing kits like Evilginx and Sneaky2FA, analyzing how these attacks work in the wild and how they evolve.",58,{"sys":471,"faqItemsCollection":473,"name":475,"slug":476,"tier":45,"intro":477,"faqTitle":59,"postCount":478,"hasPage":19},{"id":472},"topic-non-email-phishing",{"items":474},[],"Non-email phishing","non-email-phishing","Non-email phishing delivers malicious links through channels your secure email gateway never sees — social media messages, IM apps like Slack and Teams, search ads, and SMS. Push has intercepted live campaigns arriving via LinkedIn DMs, malvertising, and messaging platforms, which is why it detects phishing pages in the browser at the point of click, regardless of delivery channel.",51,{"sys":480,"faqItemsCollection":482,"name":484,"slug":485,"tier":45,"intro":486,"faqTitle":59,"postCount":487,"hasPage":19},{"id":481},"topic-oauth-abuse",{"items":483},[],"OAuth abuse","oauth-abuse","OAuth abuse is attackers exploiting app-to-app authorization — consent phishing, malicious OAuth apps, stolen tokens, and device code flows — to gain persistent access to cloud tenants without touching a password or MFA prompt. Push tracks these techniques continuously and discovered ConsentFix, a browser-native attack in the wild that pairs OAuth consent phishing with a ClickFix-style prompt.",70,{"sys":489,"faqItemsCollection":491,"name":493,"slug":494,"tier":45,"intro":495,"faqTitle":59,"postCount":496,"hasPage":19},{"id":490},"topic-passkeys",{"items":492},[],"Passkeys","passkeys","Passkeys are phishing-resistant credentials that replace passwords with cryptographic key pairs bound to a user’s device. They defeat conventional credential phishing, but attackers adapt: Push research has documented MFA downgrade, app-specific password phishing, and device code phishing being used in the wild to route around passkey-protected accounts. Deploying passkeys is step one; closing those fallback paths is step two.",21,{"sys":498,"faqItemsCollection":500,"name":502,"slug":503,"tier":45,"intro":504,"faqTitle":59,"postCount":505,"hasPage":19},{"id":499},"topic-password-security",{"items":501},[],"Password security","password-security","Password security is the practice of keeping workforce credentials strong, unique, and out of attackers’ hands — still a frontline defense while most SaaS logins depend on passwords. Expiration policies don’t fix weak or reused passwords; visibility does. Push observes real logins in the browser to flag weak, reused, and breached passwords and guide employees to reset them on any app.",79,{"sys":507,"faqItemsCollection":509,"name":511,"slug":512,"tier":45,"intro":513,"faqTitle":59,"postCount":318,"hasPage":19},{"id":508},"topic-phaas",{"items":510},[],"PhaaS","phaas","Phishing-as-a-service (PhaaS) platforms sell ready-made phishing kits, hosted infrastructure, and management panels on subscription, letting low-skill criminals run MFA-bypassing campaigns at scale. Kits like Evilginx, Tycoon2FA, Sneaky2FA, FlowerStorm, and EvilTokens each add their own evasion and session-theft capabilities, and new entrants appear regularly. Push researchers continuously get hands-on with these tools — investigating attacks in the wild, reverse-engineering kit behavior, and turning that research into detections.",{"sys":515,"faqItemsCollection":517,"name":519,"slug":520,"tier":31,"intro":521,"faqTitle":59,"postCount":522,"hasPage":19},{"id":516},"topic-phishing",{"items":518},[],"Phishing","phishing","Phishing remains the most common way attackers compromise business accounts — and it has moved far beyond suspicious emails. Modern campaigns use AiTM toolkits that bypass MFA, consent phishing against OAuth, device code phishing, and lures delivered through malvertising, LinkedIn, and Slack. Push detects and blocks these attacks in the browser, and its researchers publish teardowns of live campaigns and kits like Evilginx and Sneaky2FA. Read on for how phishing actually works today and what stops it.",91,{"sys":524,"faqItemsCollection":526,"name":528,"slug":529,"tier":45,"intro":530,"faqTitle":59,"postCount":531,"hasPage":19},{"id":525},"topic-public-breach",{"items":527},[],"Public breach","public-breach","Public breaches are the disclosed incidents that show how attacks actually unfold once the headlines fade. Push’s breach analyses keep finding identity at the entry point: stolen credentials, OAuth abuse, and missing MFA recur across the incidents analyzed here.",29,{"sys":533,"faqItemsCollection":535,"name":537,"slug":538,"tier":45,"intro":539,"faqTitle":59,"postCount":451,"hasPage":19},{"id":534},"topic-ransomware",{"items":536},[],"Ransomware","ransomware","Ransomware attacks increasingly begin with an identity, not an exploit: stolen credentials, MFA bypass, and help desk scams give operators their initial foothold. The analysis here follows that front end of the kill chain — how identity compromise leads to ransomware deployment, and the breaches driving regulators toward tighter MFA requirements.",{"sys":541,"faqItemsCollection":543,"name":545,"slug":546,"tier":31,"intro":547,"faqTitle":59,"postCount":548,"hasPage":19},{"id":542},"topic-saas-security",{"items":544},[],"SaaS security","saas-security","SaaS security means protecting the sprawl of cloud apps, accounts, and integrations your employees adopt — often without IT ever knowing. Shadow SaaS, risky OAuth grants, ghost logins, and unmanaged third-party access create attack paths traditional controls can’t see, as recent high-profile breaches have demonstrated. Building on the original SaaS attack matrix, Push continues to map SaaS-native attack techniques alongside practical guides for discovering and securing unsanctioned apps, and this hub gathers all of it.",96,{"sys":550,"faqItemsCollection":552,"name":554,"slug":555,"tier":45,"intro":556,"faqTitle":59,"postCount":557,"hasPage":6},{"id":551},"topic-security-training",{"items":553},[],"Security training","security-training","Security training aims to teach employees to recognize and avoid attacks — yet modern phishing routinely fools even seasoned security professionals. Push argues that training budgets work harder as real-time, in-browser intervention: guardrails and warnings at the moment of risk, rather than lessons employees must recall under pressure.",4,{"sys":559,"faqItemsCollection":561,"name":563,"slug":564,"tier":45,"intro":565,"faqTitle":59,"postCount":389,"hasPage":19},{"id":560},"topic-seo-poisoning",{"items":562},[],"SEO poisoning","seo-poisoning","SEO poisoning manipulates search engine results so malicious pages rank prominently for the software, tools, or services users are actively searching for, turning a routine search into an infection vector. It often pairs with malvertising and ClickFix-style payloads — Push has documented attackers abusing shared pages on legitimate AI chatbot domains to deliver malware from trusted infrastructure.",{"sys":567,"faqItemsCollection":569,"name":571,"slug":572,"tier":45,"intro":573,"faqTitle":59,"postCount":574,"hasPage":19},{"id":568},"topic-session-hijacking",{"items":570},[],"Session hijacking","session-hijacking","Session hijacking is the theft of an authenticated session — usually via stolen session cookies or tokens — letting attackers walk past passwords and MFA into a live account. AiTM phishing kits and infostealers have made it a mainstream attack technique across both criminal and targeted intrusions. Push’s browser agent detects session token theft by adding telemetry to the user agent string, creating a high-fidelity signal for security teams.",74,{"sys":576,"faqItemsCollection":578,"name":580,"slug":581,"tier":45,"intro":582,"faqTitle":59,"postCount":583,"hasPage":19},{"id":577},"topic-shadow-ai",{"items":579},[],"Shadow AI","shadow-ai","Shadow AI is employees’ unsanctioned use of AI tools at work, putting corporate data into chatbots and assistants that security teams never approved and can’t see. Push’s own browser telemetry shows AI adoption acting as a force multiplier for shadow IT — potentially now outscaling shadow SaaS — and this hub tracks that research, real-world breach examples, and practical controls.",20,{"sys":585,"faqItemsCollection":587,"name":589,"slug":590,"tier":45,"intro":591,"faqTitle":59,"postCount":592,"hasPage":19},{"id":586},"topic-shadow-saas",{"items":588},[],"Shadow SaaS","shadow-saas","Shadow SaaS is the cloud applications employees adopt for work without IT approval, each one creating unmanaged accounts, identities, and data outside your security controls. Push covers the problem end to end — from browser-based SaaS discovery to in-browser app banners and MFA enforcement — alongside breach analyses that show where unmanaged accounts lead.",75,{"sys":594,"faqItemsCollection":596,"name":598,"slug":599,"tier":45,"intro":600,"faqTitle":59,"postCount":601,"hasPage":19},{"id":595},"topic-siem",{"items":597},[],"SIEM","siem","A SIEM is only as good as the telemetry feeding it, and most log sources never see what happens inside the browser — where phishing, session token theft, and account takeover actually play out. Push streams browser-level detections and identity telemetry into SIEMs, and these posts show how that data improves detection fidelity and cuts alert fatigue.",19,{"sys":603,"faqItemsCollection":605,"name":607,"slug":608,"tier":45,"intro":609,"faqTitle":59,"postCount":610,"hasPage":19},{"id":604},"topic-social-engineering",{"items":606},[],"Social engineering","social-engineering","Social engineering is the manipulation of people — through phishing pages, help desk impersonation, vishing calls, and poisoned tenant invites — into handing over access that no exploit could take. Coverage here tracks how threat actors run these plays — drawing on Push’s ongoing investigation of live phishing infrastructure and criminal tooling.",59,{"sys":612,"faqItemsCollection":614,"name":616,"slug":617,"tier":31,"intro":618,"faqTitle":59,"postCount":557,"hasPage":6},{"id":613},"topic-supply-chain-security",{"items":615},[],"Supply chain security","supply-chain-security","Supply chain security extends beyond your own perimeter to the vendors, platforms, and browser extensions your organization depends on. A compromised third party can hand attackers legitimate access — as recent campaigns against SaaS providers have shown. Push’s research examines the browser-extension supply chain in particular: why extension risk scores fail to predict compromise, and how developers can harden extensions against takeover. These posts frame supply chain risk through a browser and identity lens.",{"sys":620,"faqItemsCollection":622,"name":624,"slug":625,"tier":45,"intro":626,"faqTitle":59,"postCount":627,"hasPage":19},{"id":621},"topic-swg",{"items":623},[],"SWG","swg","A secure web gateway (SWG) filters and inspects web traffic in transit, sitting in the network path between users and the internet. That position shows you the packet but not the session: Push’s research on AitM phishing kits documents how attackers break the signatures proxies rely on, and these posts explain why phishing detection is moving from the network path into the browser itself.",17,{"sys":629,"faqItemsCollection":631,"name":633,"slug":634,"tier":45,"intro":635,"faqTitle":59,"postCount":636,"hasPage":19},{"id":630},"topic-third-party-risk",{"items":632},[],"Third-party risk","third-party-risk","Third-party risk is the exposure your organization inherits from vendors, SaaS providers, and integrations that hold your data or access your tenants — a chain now extended one employee sign-up at a time. This hub collects Push’s breach analyses and guides for assessing OAuth integrations, managing browser extensions, and responding when a supplier is compromised.",44,{"sys":638,"faqItemsCollection":640,"name":642,"slug":643,"tier":31,"intro":644,"faqTitle":59,"postCount":398,"hasPage":19},{"id":639},"topic-threat-landscape",{"items":641},[],"Threat landscape","threat-landscape","The enterprise threat landscape is now defined by identity attacks: criminals log in with phished, stolen, or stuffed credentials rather than breaking infrastructure. Threat actors keep proving how effective help desk scams, MFA bypass, and session theft are against well-defended organizations. Drawing on breach analyses, annual phishing trend reviews, and in-the-wild campaign tracking, Push documents how attacker TTPs are shifting. This hub is where to follow those changes.",{"sys":646,"faqItemsCollection":648,"name":650,"slug":651,"tier":45,"intro":652,"faqTitle":59,"postCount":371,"hasPage":19},{"id":647},"topic-vishing",{"items":649},[],"Vishing","vishing","Vishing — voice phishing — uses phone calls to impersonate IT support, help desks, or employees, talking targets into password resets, MFA approvals, or opening attacker-controlled pages. Threat actors now routinely pair calls with AiTM phishing to hijack SSO accounts, a chain Push has analyzed across campaigns targeting hundreds of organizations.",{},"blogtopics","w0ITersBlkytyrxHNkTEFmGsSW5X9NfdbmeXV1u8bAo",[657,661,665,669,673],{"title":658,"logo":659,"createdDate":660},"SOC2","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fb6727a5e00004d6e9e69fc3068b8b64c",1784291539953,{"title":662,"logo":663,"createdDate":664},"GDPR","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Ffe49f53211674deaa5a6640d929cdf42?format=webp",1784291672535,{"title":666,"logo":667,"createdDate":668},"Cyber essentials","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F53558c1045a342a7a28def960cd54ae7?format=webp",1784291702710,{"title":670,"logo":671,"createdDate":672},"ISO IEC 27001","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F578a404a61cf45db951a41fe3554d12d",1784291766222,{"title":674,"logo":675,"createdDate":676},"ISO IEC 27701","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fbe219844b13242fbba531959579a753c",1784291858848,[678,730,775],{"id":679,"label":680,"text":21,"navIcon":681,"items":682},"stop-browser-based-attacks","Stop browser-based attacks","solid:faShieldHalved",[683,688,693,698,703,708,712,717,721,725],{"title":684,"text":685,"url":686,"navIcon":687},"Adversary-in-the-Middle","Detect and block AiTM proxies stealing session tokens.","/solution/stop-browser-based-attacks/adversary-in-the-middle-attacks","solid:faUserSecret",{"title":689,"text":690,"url":691,"navIcon":692},"ClickFix (+Fix variants)","Block attacks that trick users into running malicious code.","/solution/stop-browser-based-attacks/clickfix-fix-variants","sharp-regular:faLaptopCode",{"title":694,"text":695,"url":696,"navIcon":697},"Malicious OAuth integrations","Detect suspicious OAuth consent flows and stop persistent access.","/solution/stop-browser-based-attacks/malicious-oauth-integrations","solid:faPlugCircleXmark",{"title":699,"text":700,"url":701,"navIcon":702},"Malicious browser extensions","Shine a light on risky browser extensions.","/solution/stop-browser-based-attacks/malicious-browser-extensions","sharp-regular:faPuzzlePiece",{"title":704,"text":705,"url":706,"navIcon":707},"Malicious file downloads","Gain visibility into browser downloads and block malicious files.","/solution/stop-browser-based-attacks/malicious-file-downloads","solid:faFileCircleXmark",{"title":395,"text":709,"url":710,"navIcon":711},"Surface hidden login paths that bypass SSO and expose accounts.","/solution/stop-browser-based-attacks/ghost-logins","solid:faGhost",{"title":713,"text":714,"url":715,"navIcon":716},"Mobile phishing (QR & SMS)","Detect phishing links delivered via SMS and QR codes.","/solution/stop-browser-based-attacks/mobile-phishing-qr-code-sms","solid:faQrcode",{"title":333,"text":718,"url":719,"navIcon":720},"Identify reused and compromised credentials across SaaS logins.","/solution/stop-browser-based-attacks/credential-stuffing","custom:credentialStuffing",{"title":571,"text":722,"url":723,"navIcon":724},"Detect and block stolen session tokens before attackers get access.","/solution/stop-browser-based-attacks/session-hijacking","solid:faCookieBite",{"title":726,"text":727,"url":728,"navIcon":729},"Zero-day phishing","Detect phishing TTPs directly in the browser and stop credential theft.","/solution/stop-browser-based-attacks/zero-day-phishing","sharp-regular:faFishingRod",{"id":731,"label":732,"text":21,"navIcon":733,"items":734},"achieve-security-outcomes","Achieve security outcomes","solid:faCheckToSlot",[735,740,745,750,755,760,765,770],{"title":736,"text":737,"url":738,"navIcon":739},"Stop account takeover","Stop ATO with stolen credential and compromised token detection.","/solution/achieve-security-outcomes/stop-account-takeover","sharp-regular:faUserSecret",{"title":741,"text":742,"url":743,"navIcon":744},"Harden unmanaged identities","Harden access paths with visibility, detection, and guardrails.","/solution/achieve-security-outcomes/harden-unmanaged-identities","sharp-regular:faRadar",{"title":746,"text":747,"url":748,"navIcon":749},"Investigate browser-related incidents","Investigate and respond faster with unique browser telemetry.","/solution/achieve-security-outcomes/investigate-browser-related-incidents","sharp-regular:faSatelliteDish",{"title":751,"text":752,"url":753,"navIcon":754},"Secure shadow SaaS","See and control shadow SaaS in the browser.","/solution/achieve-security-outcomes/secure-shadow-saas","sharp-regular:faShieldCheck",{"title":756,"text":757,"url":758,"navIcon":759},"Secure AI","See and control AI apps in the browser.","/solution/achieve-security-outcomes/secure-ai","sharp-regular:faBrainCircuit",{"title":761,"text":762,"url":763,"navIcon":764},"Secure BYOD","Extend consistent browser-based protection to unmanaged devices.","/solution/achieve-security-outcomes/secure-bring-your-own-device","solid:faMobileScreenButton",{"title":766,"text":767,"url":768,"navIcon":769},"Secure Chromebooks","Secure browser activity on Chromebooks without endpoint agents.","/solution/achieve-security-outcomes/secure-chromebooks","brands:faChrome",{"title":771,"text":772,"url":773,"navIcon":774},"Investigate and stop data loss","Detect and prevent data loss across AI tools, apps, and sessions.","/solution/achieve-security-outcomes/investigate-and-stop-data-loss","custom:investigateAndStopDataLoss",{"id":776,"label":777,"text":21,"navIcon":778,"items":779},"tool-replacements","Tool replacements","solid:faScrewdriverWrench",[780,785,790,795],{"title":781,"text":782,"url":783,"navIcon":784},"Remote browser isolation","Detect attacks that look like normal browsing.","/solution/tool-replacements/remote-browser-isolation","solid:faDisplay",{"title":786,"text":787,"url":788,"navIcon":789},"Secure web gateways","Detect attacks inside the browser after SWGs allowed the connection.","/solution/tool-replacements/secure-web-gateways","solid:faFilter",{"title":791,"text":792,"url":793,"navIcon":794},"Cloud access security broker","Catch browser-based identity threats in real time, not after the fact.","/solution/tool-replacements/cloud-access-security-broker","solid:faCloudArrowUp",{"title":796,"text":797,"url":798,"navIcon":799},"Security awareness training","Block real phishing instead of training users on simulations.","/solution/tool-replacements/security-awareness-training","custom:securityAwareness",{"w":801,"h":802,"d":803},448,512,"M171-16c-36.4 0-57.8 58.3-68.3 112L72 96c-13.3 0-24 10.7-24 24s10.7 24 24 24l24 0 0 32c0 17 3.3 33.2 9.3 48l-9.3 0 0 0-20.5 0c-15.2 0-27.5 12.3-27.5 27.5 0 3 .5 5.9 1.4 8.7l28.9 86.6C40.2 379.6 16 428.1 16 482.3 16 498.7 29.3 512 45.7 512l356.6 0c16.4 0 29.7-13.3 29.7-29.7 0-54.2-24.2-102.7-62.3-135.4l28.9-86.6c.9-2.8 1.4-5.7 1.4-8.7 0-15.2-12.3-27.5-27.5-27.5l-20.5 0 0 0-9.3 0c6-14.8 9.3-31 9.3-48l0-32 24 0c13.3 0 24-10.7 24-24s-10.7-24-24-24l-30.7 0c-10.4-53.7-31.9-112-68.3-112-9.6 0-19 3.9-27.5 8.2-8.2 4.1-18.4 7.8-25.5 7.8s-17.3-3.7-25.5-7.8C190-12.1 180.6-16 171-16zm93.7 484.4l-24.8-70.9 27.9-32.5c2.7-3.2 4.2-7.2 4.2-11.4 0-9.7-7.8-17.5-17.5-17.5l-61 0c-9.7 0-17.5 7.8-17.5 17.5 0 4.2 1.5 8.2 4.2 11.4l27.9 32.5-24.8 70.9-57-180.4 35.7 0c18.4 10.2 39.5 16 62 16s43.6-5.8 62-16l35.7 0-57 180.4zM224 256c-34.7 0-64.2-22.1-75.3-53 5.7 3.2 12.3 5 19.3 5l12.4 0c16.5 0 31.1-10.6 36.3-26.2 2.3-7 12.2-7 14.5 0 5.2 15.6 19.9 26.2 36.3 26.2l12.4 0c7 0 13.6-1.8 19.3-5-11.1 30.9-40.6 53-75.3 53z",{"w":17,"h":802,"d":805},"M112 80l416 0 0 224 48 0 0-272-512 0 0 272 48 0 0-224zM48 404.1l0-4.1 544 0 0 4.1-27.9 27.9-488.2 0-27.9-27.9zM592 352l-592 0 0 72 56 56 528 0 56-56 0-72-48 0zM281 169l17-17-33.9-33.9c-6.1 6.1-27.8 27.8-65 65l-17 17c6.1 6.1 27.8 27.8 65 65l17 17 33.9-33.9c-9-9-25-25-48-48l31-31zM393 135l-17-17-33.9 33.9c9 9 25 25 48 48-23 23-39 39-48 48L376 281.9c6.1-6.1 27.8-27.8 65-65l17-17c-6.1-6.1-27.8-27.8-65-65z",{"w":17,"h":802,"d":807},"M192-32c17.7 0 32 14.3 32 32l0 96 128 0 0-96c0-17.7 14.3-32 32-32s32 14.3 32 32l0 96 64 0c17.7 0 32 14.3 32 32s-14.3 32-32 32l0 48.7c-98.6 8.1-176 90.7-176 191.3 0 27.3 5.7 53.3 16 76.9l0 3.1c0 17.7-14.3 32-32 32s-32-14.3-32-32l0-66.7C165.2 398.1 96 319.1 96 224l0-64c-17.7 0-32-14.3-32-32S78.3 96 96 96l64 0 0-96c0-17.7 14.3-32 32-32zM496 256a144 144 0 1 1 0 288 144 144 0 1 1 0-288zm59.3 107.3c6.2-6.2 6.2-16.4 0-22.6s-16.4-6.2-22.6 0l-36.7 36.7-36.7-36.7c-6.2-6.2-16.4-6.2-22.6 0s-6.2 16.4 0 22.6l36.7 36.7-36.7 36.7c-6.2 6.2-6.2 16.4 0 22.6s16.4 6.2 22.6 0l36.7-36.7 36.7 36.7c6.2 6.2 16.4 6.2 22.6 0s6.2-16.4 0-22.6l-36.7-36.7 36.7-36.7z",{"w":802,"h":802,"d":809},"M201.1 57.3c-7 5.3-9.1 10.7-9.1 14.7 0 4.5 2.8 11.2 12.4 16.9l11.6 7 0 48.1-168 0 0 60.5c7.4-2.9 15.5-4.5 24-4.5 43.1 0 72 39.4 72 80s-28.9 80-72 80c-8.5 0-16.6-1.6-24-4.5l0 108.5 108.5 0c-2.9-7.4-4.5-15.5-4.5-24 0-43.1 39.4-72 80-72s80 28.9 80 72c0 8.5-1.6 16.6-4.5 24l60.5 0 0-168 48.1 0 7 11.6c5.8 9.6 12.4 12.4 16.9 12.4 4 0 9.5-2.1 14.7-9.1s9.3-17.9 9.3-30.9-4-23.8-9.3-30.9-10.7-9.1-14.7-9.1c-4.5 0-11.2 2.8-16.9 12.4l-7 11.6-48.1 0 0-120-120 0 0-48.1 11.6-7c9.6-5.8 12.4-12.4 12.4-16.9 0-4-2.1-9.5-9.1-14.7S245 48 232 48 208.2 52 201.1 57.3zM172.3 18.9C188.5 6.8 209.6 0 232 0S275.5 6.8 291.7 18.9 320 49.5 320 72c0 8.6-1.8 16.7-4.9 24l100.9 0 0 100.9c7.3-3.1 15.4-4.9 24-4.9 22.5 0 41 12.2 53.1 28.3s18.9 37.3 18.9 59.7-6.8 43.5-18.9 59.7-30.6 28.3-53.1 28.3c-8.6 0-16.7-1.8-24-4.9l0 148.9-168 0 0-49.3 8.2-7.2c5.4-4.7 7.8-10.3 7.8-15.5 0-9.9-10.7-24-32-24s-32 14.1-32 24c0 5.3 2.4 10.8 7.8 15.5l8.2 7.2 0 49.3-216 0 0-216 49.3 0 7.2 8.2c4.7 5.4 10.3 7.8 15.5 7.8 9.9 0 24-10.7 24-32s-14.1-32-24-32c-5.3 0-10.8 2.4-15.5 7.8L49.3 264 0 264 0 96 148.9 96c-3.1-7.3-4.9-15.4-4.9-24 0-22.5 12.2-41 28.3-53.1z",{"w":811,"h":802,"d":812},576,"M96 0C60.7 0 32 28.7 32 64l0 384c0 35.3 28.7 64 64 64l180 0c-22.7-31.5-36-70.2-36-112 0-100.6 77.4-183.2 176-191.3l0-38.1c0-17-6.7-33.3-18.7-45.3L290.7 18.7C278.7 6.7 262.5 0 245.5 0L96 0zM357.5 176L264 176c-13.3 0-24-10.7-24-24L240 58.5 357.5 176zM432 544a144 144 0 1 0 0-288 144 144 0 1 0 0 288zm59.3-180.7l-36.7 36.7 36.7 36.7c6.2 6.2 6.2 16.4 0 22.6s-16.4 6.2-22.6 0l-36.7-36.7-36.7 36.7c-6.2 6.2-16.4 6.2-22.6 0s-6.2-16.4 0-22.6l36.7-36.7-36.7-36.7c-6.2-6.2-6.2-16.4 0-22.6s16.4-6.2 22.6 0l36.7 36.7 36.7-36.7c6.2-6.2 16.4-6.2 22.6 0s6.2 16.4 0 22.6z",{"w":814,"h":802,"d":815},384,"M40.1 467.1l-11.2 9C25.7 478.6 21.8 480 17.8 480 8 480 0 472 0 462.2L0 192C0 86 86 0 192 0S384 86 384 192l0 270.2c0 9.8-8 17.8-17.8 17.8-4 0-7.9-1.4-11.1-3.9l-11.2-9c-13.4-10.7-32.8-9-44.1 3.9L269.3 506c-3.3 3.8-8.2 6-13.3 6s-9.9-2.2-13.3-6l-26.6-30.5c-12.7-14.6-35.4-14.6-48.2 0L141.3 506c-3.3 3.8-8.2 6-13.3 6s-9.9-2.2-13.3-6L84.2 471c-11.3-12.9-30.7-14.6-44.1-3.9zM160 192a32 32 0 1 0 -64 0 32 32 0 1 0 64 0zm96 32a32 32 0 1 0 0-64 32 32 0 1 0 0 64z",{"w":801,"h":802,"d":817},"M64 160l64 0 0-64-64 0 0 64zM0 80C0 53.5 21.5 32 48 32l96 0c26.5 0 48 21.5 48 48l0 96c0 26.5-21.5 48-48 48l-96 0c-26.5 0-48-21.5-48-48L0 80zM64 416l64 0 0-64-64 0 0 64zM0 336c0-26.5 21.5-48 48-48l96 0c26.5 0 48 21.5 48 48l0 96c0 26.5-21.5 48-48 48l-96 0c-26.5 0-48-21.5-48-48l0-96zM320 96l0 64 64 0 0-64-64 0zM304 32l96 0c26.5 0 48 21.5 48 48l0 96c0 26.5-21.5 48-48 48l-96 0c-26.5 0-48-21.5-48-48l0-96c0-26.5 21.5-48 48-48zM288 352a32 32 0 1 1 0-64 32 32 0 1 1 0 64zm0 64c17.7 0 32 14.3 32 32s-14.3 32-32 32-32-14.3-32-32 14.3-32 32-32zm96 32c0-17.7 14.3-32 32-32s32 14.3 32 32-14.3 32-32 32-32-14.3-32-32zm32-96a32 32 0 1 1 0-64 32 32 0 1 1 0 64zm-32 32a32 32 0 1 1 -64 0 32 32 0 1 1 64 0z",{"w":802,"h":802,"d":819},"M257.5 27.6c-.8-5.4-4.9-9.8-10.3-10.6-22.1-3.1-44.6 .9-64.4 11.4l-74 39.5C89.1 78.4 73.2 94.9 63.4 115L26.7 190.6c-9.8 20.1-13 42.9-9.1 64.9l14.5 82.8c3.9 22.1 14.6 42.3 30.7 57.9l60.3 58.4c16.1 15.6 36.6 25.6 58.7 28.7l83 11.7c22.1 3.1 44.6-.9 64.4-11.4l74-39.5c19.7-10.5 35.6-27 45.4-47.2l36.7-75.5c9.8-20.1 13-42.9 9.1-64.9-.9-5.3-5.3-9.3-10.6-10.1-51.5-8.2-92.8-47.1-104.5-97.4-1.8-7.6-8-13.4-15.7-14.6-54.6-8.7-97.7-52-106.2-106.8zM208 144a32 32 0 1 1 0 64 32 32 0 1 1 0-64zM144 336a32 32 0 1 1 64 0 32 32 0 1 1 -64 0zm224-64a32 32 0 1 1 0 64 32 32 0 1 1 0-64z",{"w":801,"h":802,"d":821},"M284.6 0l91.4 0 0 160-48 0 0-112-36.6 0-203.4 58.1 0 181.9 40 0 0 224-128 0 0-224 40 0 0-218.1 17.4-5 224-64 3.2-.9zM80 336l-32 0 0 128 32 0 0-128zm176 8c0-76.8 64-136 96-152 32 16 96 75.2 96 152 0 32-16 80-64 112l32 40 0 16-128 0 0-16 32-40c-48-32-64-80-64-112zm128-32a24 24 0 1 0 -48 0 24 24 0 1 0 48 0z",{"w":801,"h":802,"d":823},"M144-16l-48 112-48 0 0 48 48 0 0 32c0 17 3.3 33.2 9.3 48l-73.3 0 0 32 5.3 16 26.7 80-64 160 51.7 0 56.9-142.2 6.5-16.3c-1-3.1-10.1-30.3-27.2-81.5l51.4 0c22.6 19.9 52.2 32 84.7 32s62.1-12.1 84.7-32l51.4 0c-17.1 51.2-26.1 78.4-27.2 81.5l6.5 16.3 56.9 142.2 51.7 0-64-160 26.7-80 5.3-16 0-32-73.3 0c6-14.8 9.3-31 9.3-48l0-32 48 0 0-48-48 0-48-112-32 0-48 32-48-32-32 0zm80 272c-32.8 0-61-19.7-73.3-48l57.3 0 16-40 16 40 57.3 0c-12.3 28.3-40.5 48-73.3 48zm17.5 139.6l30.5-35.6 0-24-96 0 0 24 30.5 35.6-46.5 116.4 128 0-46.5-116.4z",{"w":802,"h":802,"d":825},"M497.4 49l17-17-33.9-33.9C473.6 4.9 453.3 25.2 419.7 58.8 375.4 22.1 318.5 0 256.4 0 115.1 0 .4 114.6 .4 256s114.6 256 256 256 256-114.6 256-256l-48 0c0 114.9-93.1 208-208 208s-208-93.1-208-208 93.1-208 208-208c48.8 0 93.7 16.8 129.1 44.9l-45.7 45.7c-23.5-16.8-52.3-26.6-83.4-26.6-79.5 0-144 64.5-144 144s64.5 144 144 144 144-64.5 144-144l-48 0c0 53-43 96-96 96s-96-43-96-96 43-96 96-96c17.8 0 34.5 4.8 48.8 13.3-52 52-79.5 79.5-82.7 82.7l33.9 33.9 17-17 224-224z",{"w":802,"h":802,"d":827},"M208 0l24 0C386.6 0 512 125.4 512 280l0 24-48 0 0-24C464 151.9 360.1 48 232 48l-24 0 0-48zm24 96c101.6 0 184 82.4 184 184l0 24-48 0 0-24c0-75.1-60.9-136-136-136l-24 0 0-48 24 0zM48 256c0 114.9 93.1 208 208 208 22.9 0 45-3.7 65.6-10.5l-263-263C51.7 211 48 233.1 48 256zM0 256c0-36.5 7.6-71.3 21.4-102.7 6.7-15.3 14.9-29.9 24.4-43.5 7.7 7.7 61.5 61.5 161.2 161.2 30.5-30.5 49.5-49.5 57-57L297.9 248c-7.5 7.5-26.5 26.5-57 57 99.7 99.7 153.5 153.5 161.2 161.2-13.6 9.5-28.2 17.7-43.5 24.4-31.4 13.8-66.2 21.4-102.7 21.4-141.4 0-256-114.6-256-256z",{"w":802,"h":802,"d":829},"M267.6 4.5l207.5 80.5 19.2 7.4 1.2 20.5c2.9 50-4.9 126.3-37.3 200.9-32.7 75.2-91.1 150-189.4 192.5l-12.7 5.5-12.7-5.5C144.9 463.9 86.6 389.2 53.9 313.9 21.5 239.3 13.7 162.9 16.6 113L17.8 92.5 37 85 244.5 4.5 256 0 267.6 4.5zM64.1 126C63.1 169.5 71 232.9 97.9 294.8 126.1 359.7 175 422.4 256 459.6 337.1 422.4 385.9 359.7 414.2 294.8 441 232.9 449 169.5 448 126L256 51.5 64.1 126zm302.3 44.7L352.3 190.1 249.8 330.9 233 354c-8.8-9.1-30.9-32-66.2-68.6l-16.7-17.3 34.5-33.3c9.5 9.8 23.9 24.7 43.2 44.7l85.6-117.7 14.1-19.4 38.8 28.2z",{"w":802,"h":802,"d":831},"M192 48l40 0 0 108-12.4 0c-7.6-16.5-24.3-28-43.6-28-26.5 0-48 21.5-48 48s21.5 48 48 48c19.4 0 36.1-11.5 43.6-28l12.4 0 0 56-92 0 0 56.4c-16.5 7.6-28 24.3-28 43.6 0 26.5 21.5 48 48 48s48-21.5 48-48c0-19.4-11.5-36.1-28-43.6l0-16.4 52 0 0 172-40 0c-16.8 0-31.2-10.3-37.1-25.1l-6.4-16-17.2 1c-1.1 .1-2.2 .1-3.2 .1-30.9 0-56-25.1-56-56 0-9.5 2.4-18.5 6.5-26.3l8.7-16.2-13.4-12.6c-11-10.2-17.8-24.8-17.8-40.9 0-21.6 12.2-40.4 30.3-49.8l22.6-11.7-13.1-21.9c-5-8.4-7.9-18.1-7.9-28.6 0-30.9 25.1-56 56-56l24 0 0-32c0-13.3 10.7-24 24-24zm88 148l12.4 0c7.6 16.5 24.3 28 43.6 28 26.5 0 48-21.5 48-48s-21.5-48-48-48c-19.4 0-36.1 11.5-43.6 28l-12.4 0 0-108 40 0c13.3 0 24 10.7 24 24l0 32 24 0c30.9 0 56 25.1 56 56 0 10.5-2.9 20.3-7.9 28.6l-13.1 21.9 22.6 11.7c18 9.3 30.3 28.1 30.3 49.8 0 16.1-6.8 30.7-17.8 40.9l-13.4 12.6 8.7 16.2c4.2 7.8 6.5 16.7 6.5 26.3 0 30.9-25.1 56-56 56-1.1 0-2.2 0-3.2-.1l-17.2-1-6.4 16C351.2 453.7 336.8 464 320 464l-40 0 0-76 92 0 0-56.4c16.5-7.6 28-24.3 28-43.6 0-26.5-21.5-48-48-48s-48 21.5-48 48c0 19.4 11.5 36.1 28 43.6l0 16.4-52 0 0-152zM192 512l128 0c31.1 0 58.4-16.2 74.1-40.5 52.7-5.1 93.9-49.5 93.9-103.5 0-11.5-1.9-22.5-5.3-32.9 13.4-17.5 21.3-39.4 21.3-63.1 0-32-14.5-60.6-37.1-79.7 3.3-10.2 5.1-21.1 5.1-32.3 0-49.6-34.8-91.1-81.3-101.5-6.3-33.3-35.6-58.5-70.7-58.5L192 0c-35.1 0-64.4 25.2-70.7 58.5-46.5 10.4-81.3 51.9-81.3 101.5 0 11.3 1.8 22.2 5.1 32.3-22.7 19.1-37.1 47.7-37.1 79.7 0 23.7 8 45.6 21.3 63.1-3.5 10.4-5.3 21.4-5.3 32.9 0 54 41.2 98.5 93.9 103.5 15.6 24.3 42.9 40.5 74.1 40.5zM336 192a16 16 0 1 1 0-32 16 16 0 1 1 0 32zm32 96a16 16 0 1 1 -32 0 16 16 0 1 1 32 0zM176 352a16 16 0 1 1 -32 0 16 16 0 1 1 32 0zm16-176a16 16 0 1 1 -32 0 16 16 0 1 1 32 0z",{"w":814,"h":802,"d":833},"M16 64C16 28.7 44.7 0 80 0L304 0c35.3 0 64 28.7 64 64l0 384c0 35.3-28.7 64-64 64L80 512c-35.3 0-64-28.7-64-64L16 64zm64 0l0 304 224 0 0-304-224 0zM192 472c17.7 0 32-14.3 32-32s-14.3-32-32-32-32 14.3-32 32 14.3 32 32 32z",{"w":802,"h":802,"d":835},"M0 256c0-46.6 12.5-90.4 34.3-128.9L144.1 318.3c21.9 39.2 63.8 65.7 111.9 65.7 14.3 0 27.1-2.3 40.8-6.6L220.5 509.6C95.9 492.3 0 385.3 0 256zm365.1 65.6c12.3-19.2 18.9-42.5 18.9-65.6 0-38.2-16.8-72.5-43.3-96l152.7 0c12 29.6 18.6 62.1 18.6 96 0 141.4-114.6 255.1-256 256L365.1 321.6zM477.8 128L256 128c-62.9 0-113.7 44.1-125.5 102.7L54.2 98.5C101 38.5 174 0 256 0 350.8 0 433.5 51.5 477.8 128zM344 256a88 88 0 1 1 -176 0 88 88 0 1 1 176 0z",{"w":802,"h":802,"d":837},"M448 96l0 256-384 0 0-256 384 0zM64 32C28.7 32 0 60.7 0 96L0 352c0 35.3 28.7 64 64 64l144 0-16 48-72 0c-13.3 0-24 10.7-24 24s10.7 24 24 24l272 0c13.3 0 24-10.7 24-24s-10.7-24-24-24l-72 0-16-48 144 0c35.3 0 64-28.7 64-64l0-256c0-35.3-28.7-64-64-64L64 32z",{"w":802,"h":802,"d":839},"M32 64C19.1 64 7.4 71.8 2.4 83.8S.2 109.5 9.4 118.6L192 301.3 192 416c0 8.5 3.4 16.6 9.4 22.6l64 64c9.2 9.2 22.9 11.9 34.9 6.9S320 492.9 320 480l0-178.7 182.6-182.6c9.2-9.2 11.9-22.9 6.9-34.9S492.9 64 480 64L32 64z",{"w":811,"h":802,"d":841},"M144 480c-79.5 0-144-64.5-144-144 0-63.4 41-117.2 97.9-136.5-1.3-7.7-1.9-15.5-1.9-23.5 0-79.5 64.5-144 144-144 55.4 0 103.5 31.3 127.6 77.1 14.2-8.3 30.8-13.1 48.4-13.1 53 0 96 43 96 96 0 15.7-3.8 30.6-10.5 43.7 44 20.3 74.5 64.7 74.5 116.3 0 70.7-57.3 128-128 128l-304 0zM305 191c-9.4-9.4-24.6-9.4-33.9 0l-72 72c-9.4 9.4-9.4 24.6 0 33.9s24.6 9.4 33.9 0l31-31 0 102.1c0 13.3 10.7 24 24 24s24-10.7 24-24l0-102.1 31 31c9.4 9.4 24.6 9.4 33.9 0s9.4-24.6 0-33.9l-72-72z",[843,4435,7236,11771,15931,21799,24929,28600,32213,35055,37481,40316,43560,44655,47823],{"id":844,"title":845,"authorsCollection":846,"content":856,"extension":228,"faqItemsCollection":1733,"faqTitle":59,"featured":6,"hashTags":59,"meta":1735,"metaTitle":1736,"ogImage":59,"postType":1737,"publishedDate":1738,"relatedBlogPostsCollection":1739,"slug":4377,"stem":4378,"subtitle":59,"summary":4379,"synopsis":4390,"sys":4391,"tagsCollection":4394,"topicsCollection":4400,"__hash__":4434},"blog/blog/the-pyramid-of-pain-in-the-ai-era.json","The Pyramid of Pain in the AI era: Why technique-level detection matters more than ever",{"items":847},[848],{"fullName":849,"firstName":850,"jobTitle":851,"socialLinks":852,"profilePicture":854},"Dan Green","Dan","Threat Research",[853],"https://www.linkedin.com/in/daniel-g-/",{"url":855},"https://images.ctfassets.net/y1cdw1ablpvd/7jik1VhFgA3kgzXBXTm2Vw/fcd8c171da644903d0827eafcfbcaad0/Dan_Headshot_2025.png",{"json":857,"links":1641},{"data":858,"content":859,"nodeType":1640},{},[860,882,891,898,905,909,919,938,957,964,970,977,983,990,999,1006,1025,1058,1064,1070,1078,1085,1104,1135,1167,1174,1180,1188,1195,1206,1213,1254,1260,1301,1341,1347,1350,1358,1365,1371,1378,1385,1391,1398,1405,1434,1437,1445,1452,1460,1467,1474,1493,1500,1506,1513,1521,1528,1546,1553,1572,1575,1583,1590,1597,1604,1607,1614,1621],{"data":861,"content":862,"nodeType":881},{},[863,868,877],{"data":864,"marks":865,"value":866,"nodeType":867},{},[],"Back in 2024, we wrote about ","text",{"data":869,"content":871,"nodeType":876},{"uri":870},"https://pushsecurity.com/blog/our-design-philosophy-detecting-what-matters/",[872],{"data":873,"marks":874,"value":875,"nodeType":867},{},[],"how the Pyramid of Pain shapes Push's detection philosophy","hyperlink",{"data":878,"marks":879,"value":880,"nodeType":867},{},[]," — detections targeting indicators that are easy for attackers to change deliver diminishing returns, while detections targeting attacker techniques impose a cost that's hard to absorb. Two years on, every force that made IoC-based detection fragile has intensified.","paragraph",{"data":883,"content":889,"nodeType":890},{"target":884},{"sys":885},{"id":886,"type":887,"linkType":888},"1iuLYxwI8T1wDUIFSom0G0","Link","Entry",[],"embedded-entry-block",{"data":892,"content":893,"nodeType":881},{},[894],{"data":895,"marks":896,"value":897,"nodeType":867},{},[],"AI hasn't introduced a new problem so much as it's compressed the timelines on an existing one — attackers can generate infrastructure, iterate on tooling, and industrialize newly discovered techniques faster than before. The bottom layers of the Pyramid are collapsing under the weight of machine-speed operations, and the middle layers are starting to buckle too.",{"data":899,"content":900,"nodeType":881},{},[901],{"data":902,"marks":903,"value":904,"nodeType":867},{},[],"These changes mean that technique-level detection is more important than ever. In this article, we’ll dig into how the Pyramid is changing, and what this means for our detection philosophy at Push (TL;DR — it reinforces the path we’re already on: building detections at the top of the Pyramid by harnessing browser visibility). ",{"data":906,"content":907,"nodeType":908},{},[],"hr",{"data":910,"content":911,"nodeType":918},{},[912],{"data":913,"marks":914,"value":917,"nodeType":867},{},[915],{"type":916},"bold","The bottom of the Pyramid was already crumbling","heading-1",{"data":920,"content":921,"nodeType":881},{},[922,926,934],{"data":923,"marks":924,"value":925,"nodeType":867},{},[],"The case against indicator-based detection didn't need AI to be compelling. ",{"data":927,"content":929,"nodeType":876},{"uri":928},"https://www.spamhaus.org/",[930],{"data":931,"marks":932,"value":933,"nodeType":867},{},[],"89% of phishing domains are active for fewer than two days",{"data":935,"marks":936,"value":937,"nodeType":867},{},[],", with just 6.5% surviving past 15 days — by the time a domain makes it onto a blocklist, the campaign has moved on.",{"data":939,"content":940,"nodeType":881},{},[941,945,953],{"data":942,"marks":943,"value":944,"nodeType":867},{},[],"We've ",{"data":946,"content":948,"nodeType":876},{"uri":947},"https://pushsecurity.com/blog/why-most-phishing-attacks-feel-like-a-zero-day/",[949],{"data":950,"marks":951,"value":952,"nodeType":867},{},[],"written before",{"data":954,"marks":955,"value":956,"nodeType":867},{},[]," about how this makes every phishing attack effectively a zero-day for organizations relying on known-bad detection. The phishing kit's behavior — its page structure, script signatures, malicious payload mechanics — is the only detection target that outlasts a single campaign.",{"data":958,"content":959,"nodeType":881},{},[960],{"data":961,"marks":962,"value":963,"nodeType":867},{},[],"When we blogged about the Pyramid of Pain for modern attacks that happen predominantly over the internet, with minimal (or zero) endpoint contact, it first looked like this: ",{"data":965,"content":969,"nodeType":890},{"target":966},{"sys":967},{"id":968,"type":887,"linkType":888},"2N04ycJ6RKGfHdX5X1TwU3",[],{"data":971,"content":972,"nodeType":881},{},[973],{"data":974,"marks":975,"value":976,"nodeType":867},{},[],"Now, it looks more like this:",{"data":978,"content":982,"nodeType":890},{"target":979},{"sys":980},{"id":981,"type":887,"linkType":888},"mfhP4WToOQkrHnVkXU0tX",[],{"data":984,"content":985,"nodeType":881},{},[986],{"data":987,"marks":988,"value":989,"nodeType":867},{},[],"Let’s explore why. ",{"data":991,"content":992,"nodeType":998},{},[993],{"data":994,"marks":995,"value":997,"nodeType":867},{},[996],{"type":916},"AI is accelerating phishing rotation and delivery","heading-2",{"data":1000,"content":1001,"nodeType":881},{},[1002],{"data":1003,"marks":1004,"value":1005,"nodeType":867},{},[],"Attackers are harnessing AI at every stage, speeding up the process of creating, rotating, and replacing phishing infrastructure at every level, as well as capitalizing on AI adoption itself to enhance their lures. The operational signature is more domains, shorter lifespans, more variation, and fewer of the reuse patterns that blocklists depend on.",{"data":1007,"content":1008,"nodeType":881},{},[1009,1013,1021],{"data":1010,"marks":1011,"value":1012,"nodeType":867},{},[],"Attackers can ",{"data":1014,"content":1016,"nodeType":876},{"uri":1015},"https://pushsecurity.com/blog/can-ai-replace-a-threat-researcher-what-we-learned-building-an-agentic-threat-hunting-pipeline/",[1017],{"data":1018,"marks":1019,"value":1020,"nodeType":867},{},[],"vibe-code entire phishing pages in minutes",{"data":1022,"marks":1023,"value":1024,"nodeType":867},{},[]," — not just cloning legitimate login pages but vibe-cloning them, feeding an AI a screenshot and having it rebuild a convincing frontend with a completely unique backend. ",{"data":1026,"content":1027,"nodeType":881},{},[1028,1032,1042,1046,1054],{"data":1029,"marks":1030,"value":1031,"nodeType":867},{},[],"We've seen attackers clone free SaaS tools like background removers and PDF converters, then inject phishing components or ClickFix payloads into what looks like a functional utility. We’ve even seen attackers distributing malware using AI-generated pages shared using ",{"data":1033,"content":1035,"nodeType":876},{"uri":1034},"https://pushsecurity.com/blog/llmshare-malvertising-campaign/",[1036],{"data":1037,"marks":1038,"value":1041,"nodeType":867},{},[1039],{"type":1040},"underline","LLM tool sharing functionality",{"data":1043,"marks":1044,"value":1045,"nodeType":867},{},[],", resulting in phishing delivery pages hosted on real claude.ai and chatgpt.com. And legitimate cloud platforms like ",{"data":1047,"content":1049,"nodeType":876},{"uri":1048},"https://www.huntress.com/blog/railway-paas-m365-token-replay-campaign",[1050],{"data":1051,"marks":1052,"value":1053,"nodeType":867},{},[],"Railway",{"data":1055,"marks":1056,"value":1057,"nodeType":867},{},[],", Cloudflare Workers, and Vercel host and dynamically rotate attack infrastructure, so the domains feeding into blocklists often belong to reputable services that can't simply be blocked. ",{"data":1059,"content":1063,"nodeType":890},{"target":1060},{"sys":1061},{"id":1062,"type":887,"linkType":888},"5yoLmqysyQazfzLITCUTfc",[],{"data":1065,"content":1069,"nodeType":890},{"target":1066},{"sys":1067},{"id":1068,"type":887,"linkType":888},"5XK5qZMQU19xlA8L2T5y0Z",[],{"data":1071,"content":1072,"nodeType":998},{},[1073],{"data":1074,"marks":1075,"value":1077,"nodeType":867},{},[1076],{"type":916},"The kit ecosystem is fragmenting faster than anyone can track",{"data":1079,"content":1080,"nodeType":881},{},[1081],{"data":1082,"marks":1083,"value":1084,"nodeType":867},{},[],"What we see across our install base is a huge and growing variation in phishing kits — new kits, derivative kits of known platforms, derivatives of those derivatives — appearing on a weekly basis.",{"data":1086,"content":1087,"nodeType":881},{},[1088,1092,1100],{"data":1089,"marks":1090,"value":1091,"nodeType":867},{},[],"As we reported in our ",{"data":1093,"content":1095,"nodeType":876},{"uri":1094},"https://pushsecurity.com/thank-you/browser-attacks-report",[1096],{"data":1097,"marks":1098,"value":1099,"nodeType":867},{},[],"Browser Attacks Report",{"data":1101,"marks":1102,"value":1103,"nodeType":867},{},[],", the most common AiTM kits we detected over the last year were Tycoon 2FA (59% of detections), followed by Sneaky 2FA, FlowerStorm, Evilginx (nominally a red team tool, but widely abused by attackers), NakedPages, Gabagool, and dozens more — but those established names are just the visible layer.",{"data":1105,"content":1106,"nodeType":881},{},[1107,1111,1119,1123,1131],{"data":1108,"marks":1109,"value":1110,"nodeType":867},{},[],"Code is forked, modified, and redeployed across kits in a pattern that ",{"data":1112,"content":1114,"nodeType":876},{"uri":1113},"https://blog.barracuda.com/2026/04/16/threat-spotlight-tycoon-2fa-scattered-everywhere",[1115],{"data":1116,"marks":1117,"value":1118,"nodeType":867},{},[],"resembles open-source development",{"data":1120,"marks":1121,"value":1122,"nodeType":867},{},[]," more than traditional criminal enterprise, and the rate at which new variants appear is accelerating. The ",{"data":1124,"content":1126,"nodeType":876},{"uri":1125},"https://pushsecurity.com/blog/device-code-phishing/",[1127],{"data":1128,"marks":1129,"value":1130,"nodeType":867},{},[],"Venom kit",{"data":1132,"marks":1133,"value":1134,"nodeType":867},{},[]," reuses Sneaky 2FA's AiTM infrastructure but carries different branding and adds device code phishing — whether it's the same developers, stolen code, or a deliberate fork is unclear.",{"data":1136,"content":1137,"nodeType":881},{},[1138,1142,1150,1154,1163],{"data":1139,"marks":1140,"value":1141,"nodeType":867},{},[],"Tycoon 2FA illustrates the scale of the evolution. The kit evolves continuously, addingnew capabilities, new evasion techniques, and hybridizing with other platforms. Even when Sekoia and Microsoft seized 330+ Tycoon domains in March 2026, the techniques it popularized were already embedded across competitors, and the slack was taken up by rival platforms within days. And in any case, Tycoon was back to ",{"data":1143,"content":1145,"nodeType":876},{"uri":1144},"https://www.crowdstrike.com/en-us/blog/tycoon2fa-phishing-as-a-service-platform-persists-following-takedown/",[1146],{"data":1147,"marks":1148,"value":1149,"nodeType":867},{},[],"normal levels of operation",{"data":1151,"marks":1152,"value":1153,"nodeType":867},{},[]," shortly after. It has also been observed ",{"data":1155,"content":1157,"nodeType":876},{"uri":1156},"https://www.okta.com/en-nl/blog/threat-intelligence/tycoon_2fa_phishing_actors_scatter/",[1158],{"data":1159,"marks":1160,"value":1162,"nodeType":867},{},[1161],{"type":1040},"pivoting to add new device code phishing capabilities",{"data":1164,"marks":1165,"value":1166,"nodeType":867},{},[]," (more on that below). ",{"data":1168,"content":1169,"nodeType":881},{},[1170],{"data":1171,"marks":1172,"value":1173,"nodeType":867},{},[],"Tear one down and there are many more to take its place — and meanwhile the original is already evolving into something new.",{"data":1175,"content":1179,"nodeType":890},{"target":1176},{"sys":1177},{"id":1178,"type":887,"linkType":888},"3UDzUCCizPJhXp3SsoZuSK",[],{"data":1181,"content":1182,"nodeType":998},{},[1183],{"data":1184,"marks":1185,"value":1187,"nodeType":867},{},[1186],{"type":916},"New techniques are being industrialized faster than ever",{"data":1189,"content":1190,"nodeType":881},{},[1191],{"data":1192,"marks":1193,"value":1194,"nodeType":867},{},[],"As well as the fragmentation of existing kits, we’re seeing new techniques added at an accelerating rate. ",{"data":1196,"content":1197,"nodeType":881},{},[1198,1202],{"data":1199,"marks":1200,"value":360,"nodeType":867},{},[1201],{"type":916},{"data":1203,"marks":1204,"value":1205,"nodeType":867},{},[]," is the clearest case study. From early nation state adoption in 2024, it took until 2026 for criminal adoption to really take off, but the take-up this year is unprecedented. The EvilTokens kit packaged device code phishing into a PhaaS offering with GPT-powered spear-phishing and adaptive landing pages, hitting 340+ organizations across five countries in March 2026. ",{"data":1207,"content":1208,"nodeType":881},{},[1209],{"data":1210,"marks":1211,"value":1212,"nodeType":867},{},[],"Now, device code functionality is now a core phish kit component. We’re tracking 18+ kits with device code phishing capabilities and a 37.5x increase in device code phishing detections this year alone, with the technique moving from state-sponsored exclusivity to something any PhaaS customer can rent.",{"data":1214,"content":1215,"nodeType":881},{},[1216,1220,1228,1232,1237,1241,1250],{"data":1217,"marks":1218,"value":1219,"nodeType":867},{},[],"Similarly, when we ",{"data":1221,"content":1223,"nodeType":876},{"uri":1222},"https://pushsecurity.com/blog/inside-criminal-phishing-panel",[1224],{"data":1225,"marks":1226,"value":1227,"nodeType":867},{},[],"infiltrated Doko's Panel",{"data":1229,"marks":1230,"value":1231,"nodeType":867},{},[]," — a ",{"data":1233,"marks":1234,"value":1236,"nodeType":867},{},[1235],{"type":916},"real-time vishing and AiTM platform",{"data":1238,"marks":1239,"value":1240,"nodeType":867},{},[]," used by ShinyHunters and affiliated groups — the codebase was full of LLM-generated artifacts. Multiple groups were using the templated vishing panel and spinning up their own variants, but the AI-generated indicators persisted throughout. This approach to real-time vishing + browser payload has been a ",{"data":1242,"content":1244,"nodeType":876},{"uri":1243},"https://pushsecurity.com/blog/analyzing-the-instructure-breach/",[1245],{"data":1246,"marks":1247,"value":1249,"nodeType":867},{},[1248],{"type":1040},"mainstay of the Com affiliates like ShinyHunters this year",{"data":1251,"marks":1252,"value":1253,"nodeType":867},{},[],". ",{"data":1255,"content":1259,"nodeType":890},{"target":1256},{"sys":1257},{"id":1258,"type":887,"linkType":888},"01mOiserRBXraawXwQyJNm",[],{"data":1261,"content":1262,"nodeType":881},{},[1263,1267,1271,1275,1284,1288,1297],{"data":1264,"marks":1265,"value":1266,"nodeType":867},{},[],"The broader ",{"data":1268,"marks":1269,"value":315,"nodeType":867},{},[1270],{"type":916},{"data":1272,"marks":1273,"value":1274,"nodeType":867},{},[]," family shows the same acceleration: First reported in early 2024 and adopted by four nation-state groups within a single quarter. Fast forward and ",{"data":1276,"content":1278,"nodeType":876},{"uri":1277},"https://www.crowdstrike.com/en-us/global-threat-report/",[1279],{"data":1280,"marks":1281,"value":1283,"nodeType":867},{},[1282],{"type":1040},"CrowdStrike's data",{"data":1285,"marks":1286,"value":1287,"nodeType":867},{},[]," shows a 563% increase in fake CAPTCHA incidents (one of the more common ClickFix lure types), while ",{"data":1289,"content":1291,"nodeType":876},{"uri":1290},"https://cdn-dynmedia-1.microsoft.com/is/content/microsoftcorp/microsoft/msc/documents/presentations/CSR/Microsoft-Digital-Defense-Report-2025.pdf",[1292],{"data":1293,"marks":1294,"value":1296,"nodeType":867},{},[1295],{"type":1040},"Microsoft reported",{"data":1298,"marks":1299,"value":1300,"nodeType":867},{},[]," it as making up 47% of observed attacks according to their Digital Defense Report.",{"data":1302,"content":1303,"nodeType":881},{},[1304,1308,1313,1317,1325,1329,1337],{"data":1305,"marks":1306,"value":1307,"nodeType":867},{},[],"And ",{"data":1309,"marks":1310,"value":1312,"nodeType":867},{},[1311],{"type":916},"ConsentFix",{"data":1314,"marks":1315,"value":1316,"nodeType":867},{},[]," — a combination of ClickFix and OAuth consent phishing techniques — suggests the next compression is already underway. Push researchers ",{"data":1318,"content":1320,"nodeType":876},{"uri":1319},"https://pushsecurity.com/blog/consentfix/",[1321],{"data":1322,"marks":1323,"value":1324,"nodeType":867},{},[],"discovered the technique",{"data":1326,"marks":1327,"value":1328,"nodeType":867},{},[]," in December 2025 — a browser-native ClickFix variant hijacking OAuth consent grants via Azure CLI's localhost redirect. It was later confirmed to be tied to APT29. By January 2026, a ",{"data":1330,"content":1332,"nodeType":876},{"uri":1331},"https://pushsecurity.com/blog/consentfix-v3-analyzing-a-new-toolkit/",[1333],{"data":1334,"marks":1335,"value":1336,"nodeType":867},{},[],"criminal ConsentFix v3 toolkit",{"data":1338,"marks":1339,"value":1340,"nodeType":867},{},[]," had appeared on the XSS forum with Cloudflare Workers, ZoomInfo targeting, and automated exfiltration via Pipedream.",{"data":1342,"content":1346,"nodeType":890},{"target":1343},{"sys":1344},{"id":1345,"type":887,"linkType":888},"41FMif4T0y1maflzonWgL8",[],{"data":1348,"content":1349,"nodeType":908},{},[],{"data":1351,"content":1352,"nodeType":918},{},[1353],{"data":1354,"marks":1355,"value":1357,"nodeType":867},{},[1356],{"type":916},"Why technique-level detection is the only layer that holds",{"data":1359,"content":1360,"nodeType":881},{},[1361],{"data":1362,"marks":1363,"value":1364,"nodeType":867},{},[],"The middle of the Pyramid — tool signatures and artifacts — used to offer much more durable detection than infrastructure indicators. Fingerprinting a specific phishing kit by its JavaScript structure or HTML patterns provided a detection target that survived across dozens or hundreds of campaigns, even as the underlying domains rotated. Tool level detections are still better, but not by quite the same margin.",{"data":1366,"content":1370,"nodeType":890},{"target":1367},{"sys":1368},{"id":1369,"type":887,"linkType":888},"5pxaYdCIFiFKLPhRaPoldX",[],{"data":1372,"content":1373,"nodeType":881},{},[1374],{"data":1375,"marks":1376,"value":1377,"nodeType":867},{},[],"When the kit landscape was dominated by a handful of platforms, you could write signatures for Tycoon, Sneaky2FA, EvilProxy, and so on, and cover the lion's share of attacks. With the ecosystem now producing new variants and entirely new kits on a weekly basis, detecting by kit fingerprint starts to look uncomfortably similar to detecting by domain.",{"data":1379,"content":1380,"nodeType":881},{},[1381],{"data":1382,"marks":1383,"value":1384,"nodeType":867},{},[],"But many of these proliferating kits do share behavioral patterns at a deeper level than their code signatures. For example, every device code phishing kit implements fundamentally the same flow: present a lure, generate a device code via the OAuth Device Authorization endpoint, get the user to enter it on the legitimate authorization page, and poll for the resulting tokens. The frontends vary, the infrastructure varies, but the behavioral pattern doesn't.",{"data":1386,"content":1390,"nodeType":890},{"target":1387},{"sys":1388},{"id":1389,"type":887,"linkType":888},"FyyHayQtsJTwoB1kluMOl",[],{"data":1392,"content":1393,"nodeType":881},{},[1394],{"data":1395,"marks":1396,"value":1397,"nodeType":867},{},[],"Genuinely new attack techniques still require human creativity — an attacker has to identify a gap in how a legitimate protocol or feature can be subverted. That kind of innovation hasn't been automated. But the window to discover a technique, build a detection, and then deploy it before it is adopted by criminals at scale is compressing with each generation.",{"data":1399,"content":1400,"nodeType":881},{},[1401],{"data":1402,"marks":1403,"value":1404,"nodeType":867},{},[],"Organizations that detect at the technique level and deploy before commoditization have a structural advantage that increases over time. Waiting for indicators — even tool-level indicators — means chasing a curve that's accelerating away from you. This is the challenge we grapple with every day as we strive for the most resilient detections possible. ",{"data":1406,"content":1407,"nodeType":1433},{},[1408],{"data":1409,"content":1410,"nodeType":881},{},[1411,1415,1423,1427],{"data":1412,"marks":1413,"value":1414,"nodeType":867},{},[],"As our CPO Jacques Louw put it on ",{"data":1416,"content":1418,"nodeType":876},{"uri":1417},"https://risky.biz/RBNEWSSI128/",[1419],{"data":1420,"marks":1421,"value":1422,"nodeType":867},{},[],"Risky Business",{"data":1424,"marks":1425,"value":1426,"nodeType":867},{},[],": ",{"data":1428,"marks":1429,"value":1432,"nodeType":867},{},[1430],{"type":1431},"italic","\"There's no list of bad domains anywhere in the product. It's a crutch — a false cheat code that stops you from doing the detection in the way that actually is resilient, because the next time you see it, it will be on a different domain.\"","blockquote",{"data":1435,"content":1436,"nodeType":908},{},[],{"data":1438,"content":1439,"nodeType":918},{},[1440],{"data":1441,"marks":1442,"value":1444,"nodeType":867},{},[1443],{"type":916},"What it takes to detect at the top of the Pyramid",{"data":1446,"content":1447,"nodeType":881},{},[1448],{"data":1449,"marks":1450,"value":1451,"nodeType":867},{},[],"If technique-level detection is the only layer that holds, two things have to be true about your detection capability: You need the right vantage point, and you need the research velocity to stay ahead.",{"data":1453,"content":1454,"nodeType":998},{},[1455],{"data":1456,"marks":1457,"value":1459,"nodeType":867},{},[1458],{"type":916},"You need the right vantage point",{"data":1461,"content":1462,"nodeType":881},{},[1463],{"data":1464,"marks":1465,"value":1466,"nodeType":867},{},[],"Technique-level behaviors in browser-based identity attacks — how a phishing page orchestrates credential entry, how a device code flow presents its authorization prompt, how a ClickFix variant manipulates the clipboard — are visible in the browser session and nowhere else.",{"data":1468,"content":1469,"nodeType":881},{},[1470],{"data":1471,"marks":1472,"value":1473,"nodeType":867},{},[],"Network proxies see encrypted traffic and can attempt to reconstruct page behavior from metadata, but DOM manipulation, user interaction sequences, and script execution aren't visible from that vantage point. Email gateways see the delivery mechanism (or nothing at all in the increasing number of social media and search engine based attacks) but not the payload.",{"data":1475,"content":1476,"nodeType":881},{},[1477,1481,1489],{"data":1478,"marks":1479,"value":1480,"nodeType":867},{},[],"As we disclosed in our ",{"data":1482,"content":1483,"nodeType":876},{"uri":1094},[1484],{"data":1485,"marks":1486,"value":1488,"nodeType":867},{},[1487],{"type":1040},"browser attacks report",{"data":1490,"marks":1491,"value":1492,"nodeType":867},{},[],", 95% of in-browser attacks we detect use some form of bot protection, often combined with conditional loading techniques like referrer and browser checks, reliably defeating automated analysis techniques. ",{"data":1494,"content":1495,"nodeType":881},{},[1496],{"data":1497,"marks":1498,"value":1499,"nodeType":867},{},[],"Behavioral detection at the technique level requires observing what happens on the page at the moment the user interacts with it — analyzing pages, not links. When you see the entire browsing flow — ad click, redirect chain, page render, credential prompt — an attack stands out immediately. Without that context, any detection system is forced to fill in gaps, and the gaps are where attacks hide.",{"data":1501,"content":1505,"nodeType":890},{"target":1502},{"sys":1503},{"id":1504,"type":887,"linkType":888},"4804g6u4POUDpL42bzP0EY",[],{"data":1507,"content":1508,"nodeType":881},{},[1509],{"data":1510,"marks":1511,"value":1512,"nodeType":867},{},[],"Push sits inside the browser session, observing this in real time. Its detections target the behavioral mechanics of techniques rather than the surface characteristics of individual kits or infrastructure.",{"data":1514,"content":1515,"nodeType":998},{},[1516],{"data":1517,"marks":1518,"value":1520,"nodeType":867},{},[1519],{"type":916},"You need the research expertise",{"data":1522,"content":1523,"nodeType":881},{},[1524],{"data":1525,"marks":1526,"value":1527,"nodeType":867},{},[],"When the window between technique discovery and industrialized exploitation is measured in weeks rather than years, the detection pipeline needs to operate on that same compressed timescale.",{"data":1529,"content":1530,"nodeType":881},{},[1531,1535,1542],{"data":1532,"marks":1533,"value":1534,"nodeType":867},{},[],"This is where our ",{"data":1536,"content":1537,"nodeType":876},{"uri":1015},[1538],{"data":1539,"marks":1540,"value":1541,"nodeType":867},{},[],"agentic threat hunting pipeline",{"data":1543,"marks":1544,"value":1545,"nodeType":867},{},[]," fits. It's tripled our monthly detection output — not by generating bigger blocklists, but by scaling the process of discovering behavioral patterns across the telemetry generated by 3+ million browser deployments.",{"data":1547,"content":1548,"nodeType":881},{},[1549],{"data":1550,"marks":1551,"value":1552,"nodeType":867},{},[],"The detections it produces are technique-class by design, targeting how attacks work rather than the infrastructure or specific tool that implements them. The goal is curation, not accumulation — hundreds of high-fidelity behavioral detections rather than the billions of signatures and domain entries that traditional approaches require.",{"data":1554,"content":1555,"nodeType":881},{},[1556,1560,1568],{"data":1557,"marks":1558,"value":1559,"nodeType":867},{},[],"When we detected the first in-the-wild ",{"data":1561,"content":1563,"nodeType":876},{"uri":1562},"https://pushsecurity.com/blog/installfix/",[1564],{"data":1565,"marks":1566,"value":1567,"nodeType":867},{},[],"InstallFix attack",{"data":1569,"marks":1570,"value":1571,"nodeType":867},{},[]," through the pipeline — a user had searched for NotebookLM, clicked a paid Google ad, and was redirected to a fake page with a WebAssembly C2 connector — the detection shipped to all customers within minutes. It didn't depend on knowing the domain, the ad creative, or the specific kit. It depended on recognizing the technique itself.",{"data":1573,"content":1574,"nodeType":908},{},[],{"data":1576,"content":1577,"nodeType":918},{},[1578],{"data":1579,"marks":1580,"value":1582,"nodeType":867},{},[1581],{"type":916},"Technique-level detection is now the only option",{"data":1584,"content":1585,"nodeType":881},{},[1586],{"data":1587,"marks":1588,"value":1589,"nodeType":867},{},[],"As a framework for detection durability, the Pyramid of Pain is more relevant than ever. ",{"data":1591,"content":1592,"nodeType":881},{},[1593],{"data":1594,"marks":1595,"value":1596,"nodeType":867},{},[],"AI has made infrastructure indicators essentially disposable. The tools tier is compressing as criminal vendors vibe-code, fork, and clone tooling at machine speed. Technique-level detection is the layer that holds long-term to be able to proactively detect and block net-new attacks and the kits that power them. ",{"data":1598,"content":1599,"nodeType":881},{},[1600],{"data":1601,"marks":1602,"value":1603,"nodeType":867},{},[],"Novel attack techniques still require human creativity to discover, and detections built around how those techniques work can survive infrastructure rotation, tool proliferation, and kit fragmentation. Defending that layer requires a vantage point inside the browser session and a research pipeline fast enough to stay ahead of the accelerating path from discovery to industrialization.",{"data":1605,"content":1606,"nodeType":908},{},[],{"data":1608,"content":1609,"nodeType":881},{},[1610],{"data":1611,"marks":1612,"value":1613,"nodeType":867},{},[],"Push Security is the most powerful AI-native security tool in the browser. Think EDR, but for the browser — high-fidelity telemetry and real-time control across every session, on every device, with no browser migration required.",{"data":1615,"content":1616,"nodeType":881},{},[1617],{"data":1618,"marks":1619,"value":1620,"nodeType":867},{},[],"Security teams use Push to detect and stop advanced browser-based attacks like AiTM phishing, ClickFix, and session hijacking; gain visibility and control over AI tool usage across their workforce; harden identities by surfacing credential reuse, SSO gaps, and shadow IT; and support data loss and insider investigations with browser-layer telemetry that other tools can't see.",{"data":1622,"content":1623,"nodeType":881},{},[1624,1627,1636],{"data":1625,"marks":1626,"value":21,"nodeType":867},{},[],{"data":1628,"content":1630,"nodeType":876},{"uri":1629},"https://pushsecurity.com/demo",[1631],{"data":1632,"marks":1633,"value":1635,"nodeType":867},{},[1634],{"type":1040},"Book a live demo",{"data":1637,"marks":1638,"value":1639,"nodeType":867},{},[]," to learn more.","document",{"entries":1642},{"hyperlink":1643,"inline":1644,"block":1645},[],[],[1646,1655,1663,1669,1675,1682,1687,1694,1709,1713,1727],{"sys":1647,"__typename":1648,"title":1649,"caption":1650,"layoutMode":59,"file":1651},{"id":886},"Image","The Pyramid of Pain illustrates how difficult it is for an attacker to get around different categories of detection, from Trivial to Tough","The Pyramid of Pain illustrates how difficult it is for an attacker to get around different categories of detection, from Trivial to Tough!",{"url":1652,"width":1653,"height":1654},"https://images.ctfassets.net/y1cdw1ablpvd/7dPJT7PYKX71FCCi0GeDzg/16fb3b07959612a45c1b7636da33e541/image3.png",720,405,{"sys":1656,"__typename":1648,"title":1657,"caption":1658,"layoutMode":59,"file":1659},{"id":968},"Pyramid of Pain for internet-based attacks","The Pyramid of Pain reworked for internet-based attacks.",{"url":1660,"width":1661,"height":1662},"https://images.ctfassets.net/y1cdw1ablpvd/2KJMvUn55yStIIB5jIcy0n/c64a1d128567ed1189821b8160f81fe7/image6.png",1999,1149,{"sys":1664,"__typename":1648,"title":1665,"caption":1666,"layoutMode":59,"file":1667},{"id":981},"The Pyramid of Pain in the AI era","The Pyramid of Pain in the AI era: The bar for effective detection has been raised even higher.",{"url":1668,"width":1661,"height":1662},"https://images.ctfassets.net/y1cdw1ablpvd/5cUP2dETihxQgWzIN9dsyH/fcb093c7b88b7a48190f528c87dd3935/image2.png",{"sys":1670,"__typename":1671,"title":1672,"arcadeDemoUrl":1673,"playText":1674},{"id":1062},"ArcadeDemo","ClickFix featuring cloned background remover PDF converter","https://demo.arcade.software/ueVViTh501mEYchV9aBe?embed","2 mins",{"sys":1676,"__typename":1648,"title":1677,"caption":1678,"layoutMode":59,"file":1679},{"id":1068},"LLMShare attack featuring a ChatGPT-designed page shared via malvertised sharing link.","LLMShare attack featuring a ChatGPT-designed page distributed via malvertised sharing link.",{"url":1680,"width":1661,"height":1681},"https://images.ctfassets.net/y1cdw1ablpvd/soQtEPyX9aQUfby2Ylm7m/0bb772950b7e3598a343f1609a955ed4/image3.png",1750,{"sys":1683,"__typename":1671,"title":1684,"arcadeDemoUrl":1685,"playText":1686},{"id":1178},"Tycoon2FA Device Code Phishing","https://demo.arcade.software/SPNMxNkoyY5vTMPPlqWS?embed","30 secs",{"sys":1688,"__typename":1648,"title":1689,"caption":1689,"layoutMode":59,"file":1690},{"id":1258},"Verbose phishing kit comments (a clear sign of AI involvement).",{"url":1691,"width":1692,"height":1693},"https://images.ctfassets.net/y1cdw1ablpvd/2XOX0xzOxsmBKUuQbup47x/a624c2141879f9238704167a35fdeb39/Screenshot_2026-05-07_at_12.53.27.png",1100,1332,{"sys":1695,"__typename":1696,"content":1697,"name":1708,"title":59},{"id":1345},"InsightTextBlockComponent",{"json":1698},{"nodeType":1640,"data":1699,"content":1700},{},[1701],{"nodeType":881,"data":1702,"content":1703},{},[1704],{"nodeType":867,"value":1705,"marks":1706,"data":1707},"Six weeks is all it took for ConsentFix to go from nation-state technique to commoditized criminal toolkit — a compression that took device code phishing and ClickFix roughly a year. ",[],{},"Pyramid of Pain IB1",{"sys":1710,"__typename":1648,"title":1711,"caption":1711,"layoutMode":59,"file":1712},{"id":1369},"Tool-level detections aren't as resilient as they were, even if they remain a useful component of the overall detection strategy.",{"url":1668,"width":1661,"height":1662},{"sys":1714,"__typename":1696,"content":1715,"name":1726,"title":59},{"id":1389},{"json":1716},{"nodeType":1640,"data":1717,"content":1718},{},[1719],{"nodeType":881,"data":1720,"content":1721},{},[1722],{"nodeType":867,"value":1723,"marks":1724,"data":1725},"If you build detections around a specific kit's JavaScript patterns, then you're in an arms race with the kit's developer. Build detections around the behavioral mechanics of the technique itself — how the page interacts with the authorization endpoint, the sequence of user actions it orchestrates, the redirect patterns — and you’re tracking something that changes at a much slower rate.",[],{},"Pyramid of Pain IB2",{"sys":1728,"__typename":1648,"title":1729,"caption":1729,"layoutMode":59,"file":1730},{"id":1504},"Solving the \"Missing Middle\" with browser visibility and control.",{"url":1731,"width":1661,"height":1732},"https://images.ctfassets.net/y1cdw1ablpvd/2OrpNtm3faEgGJpjUcmJ5q/275e5c84c72f43377131eb9071c9e2b4/image3.png",966,{"items":1734},[],{},"Using the Pyramid of Pain for threat detection in the AI era","thought-leadership","2026-06-01T00:00:00.000Z",{"items":1740},[1741,2559,3417],{"__typename":1742,"sys":1743,"content":1745,"title":2538,"synopsis":2539,"hashTags":59,"publishedDate":2540,"slug":2541,"tagsCollection":2542,"authorsCollection":2551},"BlogPosts",{"id":1744},"Gcg7PGuICrlRcqq1QFXxH",{"json":1746},{"data":1747,"content":1748,"nodeType":1640},{},[1749,1756,1763,1794,1801,1807,1813,1825,1828,1836,1852,1859,1865,1872,1879,1885,1888,1896,1903,1909,1915,1922,1929,1948,1954,1957,1965,1983,1989,1996,1999,2007,2014,2021,2027,2033,2077,2084,2087,2095,2102,2109,2152,2159,2190,2197,2240,2247,2250,2258,2277,2284,2292,2308,2315,2332,2339,2342,2348,2354,2372,2375,2383,2402,2409,2532],{"data":1750,"content":1751,"nodeType":881},{},[1752],{"data":1753,"marks":1754,"value":1755,"nodeType":867},{},[],"Shared conversations on AI chatbot platforms have become the latest delivery mechanism for malware campaigns targeting macOS and Windows users. Attackers create content on platforms like ChatGPT and Claude that appears to offer installation guidance or service updates, then drive traffic to it via search engine results in the form of malvertising and SEO poisoning.  ",{"data":1757,"content":1758,"nodeType":881},{},[1759],{"data":1760,"marks":1761,"value":1762,"nodeType":867},{},[],"The content lives on chatgpt.com or claude.ai — domains that users and security tools trust implicitly — so the attack bypasses URL reputation checks before the victim even reaches the malicious payload.",{"data":1764,"content":1765,"nodeType":881},{},[1766,1770,1778,1782,1790],{"data":1767,"marks":1768,"value":1769,"nodeType":867},{},[],"Several variants of this technique have been ",{"data":1771,"content":1773,"nodeType":876},{"uri":1772},"https://www.bleepingcomputer.com/news/security/hackers-abuse-google-ads-claudeai-chats-to-push-mac-malware/",[1774],{"data":1775,"marks":1776,"value":1777,"nodeType":867},{},[],"reported over the past few months",{"data":1779,"marks":1780,"value":1781,"nodeType":867},{},[],". The earliest examples used shared Claude.ai conversations disguised as installation guides — complete with fake \"Apple Support\" attribution — that walked users through opening a terminal and pasting a curl command that downloaded and executed an infostealer. ",{"data":1783,"content":1785,"nodeType":876},{"uri":1784},"https://www.kaspersky.com/blog/share-chatgpt-chat-clickfix-macos-amos-infostealer/54928/",[1786],{"data":1787,"marks":1788,"value":1789,"nodeType":867},{},[],"Kaspersky documented a parallel campaign",{"data":1791,"marks":1792,"value":1793,"nodeType":867},{},[]," using shared ChatGPT conversations to deliver the AMOS (Atomic macOS Stealer) via the same paste-this-command social engineering pattern. ",{"data":1795,"content":1796,"nodeType":881},{},[1797],{"data":1798,"marks":1799,"value":1800,"nodeType":867},{},[],"Push has detected a new variant that goes beyond the previously reported technique of embedding terminal commands in shared conversations: the attacker has used ChatGPT's code rendering feature to build a fully designed fake page that mimics a ChatGPT service disruption, redirecting victims to a convincing clone of ChatGPT's download page that delivers a malicious executable. ",{"data":1802,"content":1806,"nodeType":890},{"target":1803},{"sys":1804},{"id":1805,"type":887,"linkType":888},"5lz9zt223pecGvdaqdvSTQ",[],{"data":1808,"content":1812,"nodeType":890},{"target":1809},{"sys":1810},{"id":1811,"type":887,"linkType":888},"51GomAj3VOjnbmgd1DWYu0",[],{"data":1814,"content":1815,"nodeType":881},{},[1816,1821],{"data":1817,"marks":1818,"value":1820,"nodeType":867},{},[1819],{"type":916},"This is a live campaign which is still generating detections across our customer base at the time of writing. ",{"data":1822,"marks":1823,"value":1824,"nodeType":867},{},[],"Push customers are already protected and do not need to take further action. The malicious page URLs can be found at the end of this report but are not exhaustive and are liable to change. ",{"data":1826,"content":1827,"nodeType":908},{},[],{"data":1829,"content":1830,"nodeType":918},{},[1831],{"data":1832,"marks":1833,"value":1835,"nodeType":867},{},[1834],{"type":916},"A fake page, not a fake conversation",{"data":1837,"content":1838,"nodeType":881},{},[1839,1843,1848],{"data":1840,"marks":1841,"value":1842,"nodeType":867},{},[],"Previously reported variants relied on shared ",{"data":1844,"marks":1845,"value":1847,"nodeType":867},{},[1846],{"type":1431},"conversations",{"data":1849,"marks":1850,"value":1851,"nodeType":867},{},[]," — the attacker created a chat that contained step-by-step instructions for the victim to follow, typically involving pasting a command into their terminal. The social engineering was conversational: the \"AI assistant\" appeared to be helpfully guiding the user through an installation process.",{"data":1853,"content":1854,"nodeType":881},{},[1855],{"data":1856,"marks":1857,"value":1858,"nodeType":867},{},[],"But now, rather than a shared conversation, the attacker has used ChatGPT's code rendering feature to create a fully designed, self-contained web page hosted at a chatgpt.com/s/ URL. It renders as what appears to be a ChatGPT service disruption notice:",{"data":1860,"content":1864,"nodeType":890},{"target":1861},{"sys":1862},{"id":1863,"type":887,"linkType":888},"1O9gyQab81SnbxhQp2aa5Z",[],{"data":1866,"content":1867,"nodeType":881},{},[1868],{"data":1869,"marks":1870,"value":1871,"nodeType":867},{},[],"A professional-looking error message reads: \"We're experiencing high traffic right now. Our website is temporarily unavailable due to a large number of users. Download our desktop app to continue.\" A prominent download button sits below.",{"data":1873,"content":1874,"nodeType":881},{},[1875],{"data":1876,"marks":1877,"value":1878,"nodeType":867},{},[],"The \"Show code\" toggle at the top of the page reveals what's actually happening — the entire thing is custom HTML and CSS, authored to mimic a ChatGPT system notice, rendered using ChatGPT's code output feature. A web page inside a web page, hosted on a domain that every URL reputation system in the world considers safe.",{"data":1880,"content":1884,"nodeType":890},{"target":1881},{"sys":1882},{"id":1883,"type":887,"linkType":888},"4kQTfxB3aVH9W9BeYOuljP",[],{"data":1886,"content":1887,"nodeType":908},{},[],{"data":1889,"content":1890,"nodeType":918},{},[1891],{"data":1892,"marks":1893,"value":1895,"nodeType":867},{},[1894],{"type":916},"The download page",{"data":1897,"content":1898,"nodeType":881},{},[1899],{"data":1900,"marks":1901,"value":1902,"nodeType":867},{},[],"Clicking the download button redirects the user to openew[.]app, which presents a convincing clone of ChatGPT's official desktop application download page — complete with OpenAI branding, macOS and Windows download buttons, a Chrome extension link, and a mobile download section.",{"data":1904,"content":1908,"nodeType":890},{"target":1905},{"sys":1906},{"id":1907,"type":887,"linkType":888},"4MdFc4OB37ZihTGx506QJ6",[],{"data":1910,"content":1914,"nodeType":890},{"target":1911},{"sys":1912},{"id":1913,"type":887,"linkType":888},"LaPUy0zpIeY8s4PF2wkat",[],{"data":1916,"content":1917,"nodeType":881},{},[1918],{"data":1919,"marks":1920,"value":1921,"nodeType":867},{},[],"The site also displays differently depending on who visits it. When Push researchers examined the URL via URLScan, the scanner was redirected to a different page entirely — a generic AR/VR company website with no obvious connection to ChatGPT. ",{"data":1923,"content":1924,"nodeType":881},{},[1925],{"data":1926,"marks":1927,"value":1928,"nodeType":867},{},[],"Real users in a browser see the fake download page; automated scanners and bots see something benign. This kind of conditional rendering is a well-established evasion technique in the malvertising ecosystem, and it makes the malicious infrastructure harder for security teams and threat intelligence services to identify and analyze.",{"data":1930,"content":1931,"nodeType":881},{},[1932,1936,1944],{"data":1933,"marks":1934,"value":1935,"nodeType":867},{},[],"The downloaded executable poses as \"ChatGPT for Desktop\" and is ",{"data":1937,"content":1939,"nodeType":876},{"uri":1938},"https://www.virustotal.com/gui/file/de8c50e8ccd240ef9d10ec26c26eeb37a4d1cad7c1e0edf3bb6e5689ec2dde78",[1940],{"data":1941,"marks":1942,"value":1943,"nodeType":867},{},[],"flagged on VirusTotal",{"data":1945,"marks":1946,"value":1947,"nodeType":867},{},[],".",{"data":1949,"content":1953,"nodeType":890},{"target":1950},{"sys":1951},{"id":1952,"type":887,"linkType":888},"3FSbwoFJYQrcyo9uMsQIWI",[],{"data":1955,"content":1956,"nodeType":908},{},[],{"data":1958,"content":1959,"nodeType":918},{},[1960],{"data":1961,"marks":1962,"value":1964,"nodeType":867},{},[1963],{"type":916},"The Claude variant: same campaign, different platform",{"data":1966,"content":1967,"nodeType":881},{},[1968,1972,1979],{"data":1969,"marks":1970,"value":1971,"nodeType":867},{},[],"Alongside the ChatGPT rendered-page variant, Push has also detected the previously reported style of attack using shared Claude.ai conversations. These follow the pattern documented by ",{"data":1973,"content":1974,"nodeType":876},{"uri":1772},[1975],{"data":1976,"marks":1977,"value":1978,"nodeType":867},{},[],"BleepingComputer",{"data":1980,"marks":1981,"value":1982,"nodeType":867},{},[],": a shared chat disguised as a \"Claude Code on Mac\" installation guide, attributed to \"Apple Support,\" containing a curl command that downloads and executes malware.",{"data":1984,"content":1988,"nodeType":890},{"target":1985},{"sys":1986},{"id":1987,"type":887,"linkType":888},"5sWayuTsVdiLSLoS4sv2Vc",[],{"data":1990,"content":1991,"nodeType":881},{},[1992],{"data":1993,"marks":1994,"value":1995,"nodeType":867},{},[],"The fact that both the ChatGPT and Claude variants are appearing in Push customer environments suggests a campaign — or at least a shared playbook — that is actively experimenting with different platforms and different social engineering approaches to find what converts best.",{"data":1997,"content":1998,"nodeType":908},{},[],{"data":2000,"content":2001,"nodeType":918},{},[2002],{"data":2003,"marks":2004,"value":2006,"nodeType":867},{},[2005],{"type":916},"Malvertising remains one of the top phishing delivery channels",{"data":2008,"content":2009,"nodeType":881},{},[2010],{"data":2011,"marks":2012,"value":2013,"nodeType":867},{},[],"Push has detected this variant across multiple customer environments, with users arriving at these shared chat URLs after searching for terms including \"chatgpt,\" \"chatgpt free,\" \"chat gpt,\" and common typos like \"chatgo,\" \"chatgot,\" and \"cvhatgpt.\" ",{"data":2015,"content":2016,"nodeType":881},{},[2017],{"data":2018,"marks":2019,"value":2020,"nodeType":867},{},[],"You can see an example of this below: it's incredibly convincing, and uses the real ChatGPT domain — so even users that are paying attention are liable to fall for it. ",{"data":2022,"content":2026,"nodeType":890},{"target":2023},{"sys":2024},{"id":2025,"type":887,"linkType":888},"1GYWOyHpZT1rdTm6IGOKu8",[],{"data":2028,"content":2032,"nodeType":890},{"target":2029},{"sys":2030},{"id":2031,"type":887,"linkType":888},"4HpFJRAZH2lbygaEk2xOnN",[],{"data":2034,"content":2035,"nodeType":881},{},[2036,2040,2048,2052,2060,2064,2073],{"data":2037,"marks":2038,"value":2039,"nodeType":867},{},[],"This fits a pattern Push has tracked extensively. ",{"data":2041,"content":2043,"nodeType":876},{"uri":2042},"https://pushsecurity.com/blog/verizon-dbir-2026-review/",[2044],{"data":2045,"marks":2046,"value":2047,"nodeType":867},{},[],"Search-based delivery is now the dominant channel for malware distribution",{"data":2049,"marks":2050,"value":2051,"nodeType":867},{},[]," — our own data shows that ClickFix attacks are reached via search results rather than email in 4 of 5 cases, and Push's own research into ",{"data":2053,"content":2055,"nodeType":876},{"uri":2054},"https://pushsecurity.com/blog/analysing-a-sophisticated-google-malvertising-attack/",[2056],{"data":2057,"marks":2058,"value":2059,"nodeType":867},{},[],"malvertising campaigns impersonating brands like TradingView",{"data":2061,"marks":2062,"value":2063,"nodeType":867},{},[]," and ",{"data":2065,"content":2067,"nodeType":876},{"uri":2066},"https://pushsecurity.com/blog/google-search-malvertising-campaign-continues-now-impersonating-ahrefs/",[2068],{"data":2069,"marks":2070,"value":2072,"nodeType":867},{},[2071],{"type":1040},"Ahrefs",{"data":2074,"marks":2075,"value":2076,"nodeType":867},{},[]," has demonstrated how effectively search ads can funnel victims to malicious pages. ",{"data":2078,"content":2079,"nodeType":881},{},[2080],{"data":2081,"marks":2082,"value":2083,"nodeType":867},{},[],"The shared-chat technique adds a new dimension: the destination URL itself is genuine (chatgpt.com, claude.ai), which means even a cautious user who checks the URL before clicking will see nothing suspicious.",{"data":2085,"content":2086,"nodeType":908},{},[],{"data":2088,"content":2089,"nodeType":918},{},[2090],{"data":2091,"marks":2092,"value":2094,"nodeType":867},{},[2093],{"type":916},"Legitimate platform abuse is everywhere",{"data":2096,"content":2097,"nodeType":881},{},[2098],{"data":2099,"marks":2100,"value":2101,"nodeType":867},{},[],"This is one example of a much broader pattern that has become one of the defining characteristics of the 2026 threat landscape: attackers systematically abusing legitimate platforms as attack infrastructure. The scale and variety of this abuse in recent months alone is striking, and it spans every stage of the phishing chain.",{"data":2103,"content":2104,"nodeType":998},{},[2105],{"data":2106,"marks":2107,"value":2108,"nodeType":867},{},[],"Legit platform abuse for delivery",{"data":2110,"content":2111,"nodeType":881},{},[2112,2116,2124,2128,2136,2140,2148],{"data":2113,"marks":2114,"value":2115,"nodeType":867},{},[],"On the delivery side, attackers have been ",{"data":2117,"content":2119,"nodeType":876},{"uri":2118},"https://www.bleepingcomputer.com/news/security/amazon-ses-increasingly-abused-in-phishing-to-evade-detection/",[2120],{"data":2121,"marks":2122,"value":2123,"nodeType":867},{},[],"weaponizing stolen AWS credentials to send phishing through Amazon SES",{"data":2125,"marks":2126,"value":2127,"nodeType":867},{},[]," that passes SPF, DKIM, and DMARC validation because SES is a legitimate Amazon service. A Vietnamese operation dubbed ",{"data":2129,"content":2131,"nodeType":876},{"uri":2130},"https://thehackernews.com/2026/05/30000-facebook-accounts-hacked-via.html",[2132],{"data":2133,"marks":2134,"value":2135,"nodeType":867},{},[],"AccountDumpling used Google AppSheet's built-in email capability",{"data":2137,"marks":2138,"value":2139,"nodeType":867},{},[]," as a phishing relay to harvest 30,000 Facebook credentials. ",{"data":2141,"content":2143,"nodeType":876},{"uri":2142},"https://techcrunch.com/2026/05/21/scammers-are-abusing-an-internal-microsoft-account-to-send-spam/",[2144],{"data":2145,"marks":2146,"value":2147,"nodeType":867},{},[],"Scammers exploited Microsoft's own internal notification pipeline",{"data":2149,"marks":2150,"value":2151,"nodeType":867},{},[]," — sending phishing from the same msonlineservicesteam@microsoftonline.com address that delivers legitimate 2FA codes — with Spamhaus confirming months of ongoing abuse.",{"data":2153,"content":2154,"nodeType":998},{},[2155],{"data":2156,"marks":2157,"value":2158,"nodeType":867},{},[],"Legit platform abuse for hosting",{"data":2160,"content":2161,"nodeType":881},{},[2162,2166,2174,2178,2186],{"data":2163,"marks":2164,"value":2165,"nodeType":867},{},[],"For hosting, the platforms being abused read like a who's who of modern web infrastructure. ",{"data":2167,"content":2169,"nodeType":876},{"uri":2168},"https://www.securityweek.com/over-500-organizations-hit-in-years-long-phishing-campaign/",[2170],{"data":2171,"marks":2172,"value":2173,"nodeType":867},{},[],"Operation HookedWing ran for four years",{"data":2175,"marks":2176,"value":2177,"nodeType":867},{},[]," on GitHub Pages and Vercel, compromising 500+ organizations across more than 100 GitHub Pages domains before anyone documented it publicly. Cofense has separately ",{"data":2179,"content":2181,"nodeType":876},{"uri":2180},"https://cofense.com/blog/steal-smarter-not-harder-malicious-use-of-vercel-for-credential-phishing/",[2182],{"data":2183,"marks":2184,"value":2185,"nodeType":867},{},[],"documented the growing abuse of Vercel",{"data":2187,"marks":2188,"value":2189,"nodeType":867},{},[]," for credential phishing hosting. Pixm's Q1 2026 phishing report tracked over 100 unique Azure Blob Storage subdomain variants hosting phishing content that carried Microsoft's own domain reputation, alongside abuse of Cloudflare CDN, Cloudflare Workers, Cloudflare R2, Backblaze B2, and Supabase. ",{"data":2191,"content":2192,"nodeType":998},{},[2193],{"data":2194,"marks":2195,"value":2196,"nodeType":867},{},[],"Abuse of compromised websites that are otherwise legit",{"data":2198,"content":2199,"nodeType":881},{},[2200,2204,2212,2216,2224,2228,2236],{"data":2201,"marks":2202,"value":2203,"nodeType":867},{},[],"Compromised legitimate sites are also being repurposed at scale. A mass exploitation of a ",{"data":2205,"content":2207,"nodeType":876},{"uri":2206},"https://www.bleepingcomputer.com/news/security/ghost-cms-sql-injection-flaw-exploited-in-large-scale-clickfix-campaign/",[2208],{"data":2209,"marks":2210,"value":2211,"nodeType":867},{},[],"Ghost CMS vulnerability planted ClickFix pages across 700+ websites",{"data":2213,"marks":2214,"value":2215,"nodeType":867},{},[]," including Harvard, Oxford, and DuckDuckGo subdomains. Microsoft recently documented a campaign where ",{"data":2217,"content":2219,"nodeType":876},{"uri":2218},"https://www.microsoft.com/en-us/security/blog/2026/05/26/poisoned-search-results-gpu-mining-cryptojacking-campaign-abusing-screenconnect-microsoft-net-utilities/",[2220],{"data":2221,"marks":2222,"value":2223,"nodeType":867},{},[],"SEO poisoning was combined with AI chatbot recommendation manipulation",{"data":2225,"marks":2226,"value":2227,"nodeType":867},{},[]," to deliver GPU mining malware — extending the poisoning from traditional search results into AI-generated software recommendations. And ",{"data":2229,"content":2231,"nodeType":876},{"uri":2230},"https://www.helpnetsecurity.com/2026/05/27/deno-rat-malware-fake-chatgpt-claude-installers/",[2232],{"data":2233,"marks":2234,"value":2235,"nodeType":867},{},[],"fake ChatGPT and Claude installers on GitHub and SourceForge",{"data":2237,"marks":2238,"value":2239,"nodeType":867},{},[]," have been delivering the DinDoor backdoor and a Deno-based RAT via repositories that mimic legitimate developer tool distributions.",{"data":2241,"content":2242,"nodeType":881},{},[2243],{"data":2244,"marks":2245,"value":2246,"nodeType":867},{},[],"The structural problem is that every one of these platforms is genuinely legitimate, and the security controls that evaluate them — domain reputation, email authentication, URL categorization — confirm them as trusted because they are trusted. This attack extends this pattern into new territory by weaponizing the content-sharing features of AI chatbot platforms specifically, but the underlying principles are the same. ",{"data":2248,"content":2249,"nodeType":908},{},[],{"data":2251,"content":2252,"nodeType":918},{},[2253],{"data":2254,"marks":2255,"value":2257,"nodeType":867},{},[2256],{"type":916},"Impact analysis",{"data":2259,"content":2260,"nodeType":881},{},[2261,2265,2273],{"data":2262,"marks":2263,"value":2264,"nodeType":867},{},[],"Shared-chat malware delivery exploits a structural property of AI platforms that traditional security controls aren't designed to handle. Domain reputation, URL categorization, and safe browsing databases all treat chatgpt.com and claude.ai as trusted — because they are. Using these trusted pages to link off to further convincing-looking pages hosting malware allows the attacker to run campaigns that blend in, as well as rotate the phishing delivery pages later in the chain should they ever be flagged, allowing the campaign to continue without interruption (a well known ",{"data":2266,"content":2268,"nodeType":876},{"uri":2267},"https://phishing-techniques.pushsecurity.com/",[2269],{"data":2270,"marks":2271,"value":2272,"nodeType":867},{},[],"detection evasion technique",{"data":2274,"marks":2275,"value":2276,"nodeType":867},{},[],"). ",{"data":2278,"content":2279,"nodeType":881},{},[2280],{"data":2281,"marks":2282,"value":2283,"nodeType":867},{},[],"What makes the rendered-page variant particularly concerning is that it eliminates the most obvious red flag in the earlier attacks. The Claude.ai conversation variants required the victim to recognize that a shared chat instructing them to paste terminal commands might be suspicious — a tall order for many users, but at least the attack surface was visible. The rendered-page variant shows nothing that looks like an attack. It presents what appears to be a routine service disruption with a reasonable call to action: download the desktop app to continue using ChatGPT. ",{"data":2285,"content":2286,"nodeType":998},{},[2287],{"data":2288,"marks":2289,"value":2291,"nodeType":867},{},[2290],{"type":916},"How Push detected the attack",{"data":2293,"content":2294,"nodeType":881},{},[2295,2299,2304],{"data":2296,"marks":2297,"value":2298,"nodeType":867},{},[],"We've aligned our detection logic for this technique under the name ",{"data":2300,"marks":2301,"value":2303,"nodeType":867},{},[2302],{"type":916},"LLMShare",{"data":2305,"marks":2306,"value":2307,"nodeType":867},{},[]," — a technique-level detection that covers shared content abuse across LLM platforms, not tied to any single campaign or set of IOCs. ",{"data":2309,"content":2310,"nodeType":881},{},[2311],{"data":2312,"marks":2313,"value":2314,"nodeType":867},{},[],"Because Push sees the full context of how a user arrived at a page and what that page does once it renders, we can identify LLMShare attacks regardless of which AI platform is being abused or what social engineering wrapper the attacker has chosen. ",{"data":2316,"content":2317,"nodeType":881},{},[2318,2322,2328],{"data":2319,"marks":2320,"value":2321,"nodeType":867},{},[],"When we identified the initial instances of this campaign, we used our ",{"data":2323,"content":2324,"nodeType":876},{"uri":1015},[2325],{"data":2326,"marks":2327,"value":1541,"nodeType":867},{},[],{"data":2329,"marks":2330,"value":2331,"nodeType":867},{},[]," to hunt for additional examples across our customer telemetry, develop the LLMShare detection, and rapidly deploy it to customers. Push blocks users from interacting with the page before any malicious activity can occur. ",{"data":2333,"content":2334,"nodeType":881},{},[2335],{"data":2336,"marks":2337,"value":2338,"nodeType":867},{},[],"Push customers do not need to take any further action.",{"data":2340,"content":2341,"nodeType":908},{},[],{"data":2343,"content":2344,"nodeType":881},{},[2345],{"data":2346,"marks":2347,"value":1613,"nodeType":867},{},[],{"data":2349,"content":2350,"nodeType":881},{},[2351],{"data":2352,"marks":2353,"value":1620,"nodeType":867},{},[],{"data":2355,"content":2356,"nodeType":881},{},[2357,2360,2369],{"data":2358,"marks":2359,"value":21,"nodeType":867},{},[],{"data":2361,"content":2363,"nodeType":876},{"uri":2362},"https://pushsecurity.com/demo/",[2364],{"data":2365,"marks":2366,"value":2368,"nodeType":867},{},[2367],{"type":1040},"Book a live demo to learn more.",{"data":2370,"marks":2371,"value":21,"nodeType":867},{},[],{"data":2373,"content":2374,"nodeType":908},{},[],{"data":2376,"content":2377,"nodeType":918},{},[2378],{"data":2379,"marks":2380,"value":2382,"nodeType":867},{},[2381],{"type":916},"Indicators of compromise",{"data":2384,"content":2385,"nodeType":881},{},[2386,2390,2398],{"data":2387,"marks":2388,"value":2389,"nodeType":867},{},[],"As we always say, short-lived IoCs are of limited value when tackling modern phishing attacks due to the rate at which attackers are able to ",{"data":2391,"content":2393,"nodeType":876},{"uri":2392},"https://phishing-techniques.pushsecurity.com/techniques/domain-rotation-redirection/",[2394],{"data":2395,"marks":2396,"value":2397,"nodeType":867},{},[],"quickly spin up and rotate the sites used",{"data":2399,"marks":2400,"value":2401,"nodeType":867},{},[]," in the attack chain. IoC-based detections for campaigns like this are of limited value.",{"data":2403,"content":2404,"nodeType":881},{},[2405],{"data":2406,"marks":2407,"value":2408,"nodeType":867},{},[],"At the time of writing, the indicators observed were:",{"data":2410,"content":2411,"nodeType":2531},{},[2412,2439,2463,2485,2508],{"data":2413,"content":2414,"nodeType":2438},{},[2415,2427],{"data":2416,"content":2417,"nodeType":2426},{},[2418],{"data":2419,"content":2420,"nodeType":881},{},[2421],{"data":2422,"marks":2423,"value":2425,"nodeType":867},{},[2424],{"type":916},"Indicator","table-header-cell",{"data":2428,"content":2429,"nodeType":2426},{},[2430],{"data":2431,"content":2432,"nodeType":881},{},[2433],{"data":2434,"marks":2435,"value":2437,"nodeType":867},{},[2436],{"type":916},"Type","table-row",{"data":2440,"content":2441,"nodeType":2438},{},[2442,2453],{"data":2443,"content":2444,"nodeType":2452},{},[2445],{"data":2446,"content":2447,"nodeType":881},{},[2448],{"data":2449,"marks":2450,"value":2451,"nodeType":867},{},[],"hxxps://claude[.]ai/share/8e6401b5-4849-46c4-a3cb-29e1c3c49131","table-cell",{"data":2454,"content":2455,"nodeType":2452},{},[2456],{"data":2457,"content":2458,"nodeType":881},{},[2459],{"data":2460,"marks":2461,"value":2462,"nodeType":867},{},[],"URL",{"data":2464,"content":2465,"nodeType":2438},{},[2466,2476],{"data":2467,"content":2468,"nodeType":2452},{},[2469],{"data":2470,"content":2471,"nodeType":881},{},[2472],{"data":2473,"marks":2474,"value":2475,"nodeType":867},{},[],"hxxps://chatgpt[.]com/s/cb_6a0f1e6bbec88191aa7fede27163f08d",{"data":2477,"content":2478,"nodeType":2452},{},[2479],{"data":2480,"content":2481,"nodeType":881},{},[2482],{"data":2483,"marks":2484,"value":2462,"nodeType":867},{},[],{"data":2486,"content":2487,"nodeType":2438},{},[2488,2498],{"data":2489,"content":2490,"nodeType":2452},{},[2491],{"data":2492,"content":2493,"nodeType":881},{},[2494],{"data":2495,"marks":2496,"value":2497,"nodeType":867},{},[],"openew[.]app",{"data":2499,"content":2500,"nodeType":2452},{},[2501],{"data":2502,"content":2503,"nodeType":881},{},[2504],{"data":2505,"marks":2506,"value":2507,"nodeType":867},{},[],"Domain",{"data":2509,"content":2510,"nodeType":2438},{},[2511,2521],{"data":2512,"content":2513,"nodeType":2452},{},[2514],{"data":2515,"content":2516,"nodeType":881},{},[2517],{"data":2518,"marks":2519,"value":2520,"nodeType":867},{},[],"de8c50e8ccd240ef9d10ec26c26eeb37a4d1cad7c1e0edf3bb6e5689ec2dde78",{"data":2522,"content":2523,"nodeType":2452},{},[2524],{"data":2525,"content":2526,"nodeType":881},{},[2527],{"data":2528,"marks":2529,"value":2530,"nodeType":867},{},[],"SHA256","table",{"data":2533,"content":2534,"nodeType":881},{},[2535],{"data":2536,"marks":2537,"value":21,"nodeType":867},{},[],"LLMShare: how attackers are turning AI chatbot pages into malware delivery platforms","How attackers are using shared content features on AI chatbot platforms to deliver malware via pages hosted on legitimate domains, sent via malvertising.","2026-05-29T00:00:00.000Z","llmshare-malvertising-campaign",{"items":2543},[2544,2548],{"sys":2545,"name":2547},{"id":2546},"6A5RXS31ZQx3PwryGb1IMy","Browser-based attacks",{"sys":2549,"name":342},{"id":2550},"4ksQNCFeBf8H4QIORqpRLw",{"items":2552},[2553],{"fullName":2554,"firstName":2555,"jobTitle":2556,"profilePicture":2557},"Keanu Maharaj","Keanu","Senior Security Researcher",{"url":2558},"https://images.ctfassets.net/y1cdw1ablpvd/VCGOm62jiocjwngWTh32U/e9a30637b1c76bf988d2fec90f5b6c36/1689361049351_1.png",{"__typename":1742,"sys":2560,"content":2562,"title":3403,"synopsis":3404,"hashTags":59,"publishedDate":3405,"slug":3406,"tagsCollection":3407,"authorsCollection":3413},{"id":2561},"211Dd0EIrXPOFpvRgs0fEE",{"json":2563},{"data":2564,"content":2565,"nodeType":1640},{},[2566,2585,2604,2623,2629,2632,2640,2647,2654,2661,2668,2676,2679,2687,2694,2701,2708,2714,2722,2741,2748,2755,2771,2779,2809,2825,2832,2860,2868,2898,2905,2913,2931,2938,2945,2951,2958,2966,2985,2992,3011,3018,3021,3029,3036,3127,3134,3150,3153,3183,3202,3209,3216,3219,3227,3246,3253,3260,3277,3280,3288,3295,3328,3335,3352,3370,3376,3379,3386],{"data":2567,"content":2568,"nodeType":881},{},[2569,2573,2581],{"data":2570,"marks":2571,"value":2572,"nodeType":867},{},[],"When we released the ",{"data":2574,"content":2576,"nodeType":876},{"uri":2575},"https://pushsecurity.com/blog/saas-attack-techniques/",[2577],{"data":2578,"marks":2579,"value":2580,"nodeType":867},{},[],"SaaS attack matrix",{"data":2582,"marks":2583,"value":2584,"nodeType":867},{},[]," in 2023, we were anticipating a shift that was just beginning to take shape. The techniques that attackers were using to compromise cloud applications and identities weren't well represented in existing frameworks, and many of the ones we documented hadn't yet been widely observed in the wild.",{"data":2586,"content":2587,"nodeType":881},{},[2588,2592,2600],{"data":2589,"marks":2590,"value":2591,"nodeType":867},{},[],"A year later, we ",{"data":2593,"content":2595,"nodeType":876},{"uri":2594},"https://pushsecurity.com/blog/the-saas-attack-matrix-one-year-on/",[2596],{"data":2597,"marks":2598,"value":2599,"nodeType":867},{},[],"reviewed what had changed",{"data":2601,"marks":2602,"value":2603,"nodeType":867},{},[]," and found that the initial access phase — the techniques designed to compromise an identity in the first place — was where almost all of the attacker innovation was concentrated. And two years on, that trend has become the story of the modern threat landscape. ",{"data":2605,"content":2606,"nodeType":881},{},[2607,2611,2619],{"data":2608,"marks":2609,"value":2610,"nodeType":867},{},[],"Today, we're re-releasing the matrix as the ",{"data":2612,"content":2614,"nodeType":876},{"uri":2613},"https://pushsecurity.com/resources/browser-identity-attacks-matrix/",[2615],{"data":2616,"marks":2617,"value":2618,"nodeType":867},{},[],"Browser & Identity Attacks Matrix",{"data":2620,"marks":2621,"value":2622,"nodeType":867},{},[],". The name change isn't cosmetic. It reflects that the attacks driving the most consequential breaches are browser-based and identity-first.",{"data":2624,"content":2628,"nodeType":890},{"target":2625},{"sys":2626},{"id":2627,"type":887,"linkType":888},"MSnrBRJtiQxpv2qxFLCVE",[],{"data":2630,"content":2631,"nodeType":908},{},[],{"data":2633,"content":2634,"nodeType":918},{},[2635],{"data":2636,"marks":2637,"value":2639,"nodeType":867},{},[2638],{"type":916},"Why the scope needed to change",{"data":2641,"content":2642,"nodeType":881},{},[2643],{"data":2644,"marks":2645,"value":2646,"nodeType":867},{},[],"The original SaaS attack matrix was built around a specific insight: that attacks targeting modern business applications played out entirely over the internet, without touching endpoints or internal networks in any way that EDR or network detection tools would recognize.",{"data":2648,"content":2649,"nodeType":881},{},[2650],{"data":2651,"marks":2652,"value":2653,"nodeType":867},{},[],"That framing was useful, and it remains true. But it anchored the matrix to the post-access phase — what attackers do once they're inside a SaaS application — and didn't give enough weight to the initial access techniques that determine whether attackers get there in the first place.",{"data":2655,"content":2656,"nodeType":881},{},[2657],{"data":2658,"marks":2659,"value":2660,"nodeType":867},{},[],"The problem is that initial access is where the overwhelming majority of attacker innovation and investment is concentrated, and the techniques being used to achieve it are best understood as browser and identity attacks rather than SaaS-specific ones. AiTM phishing, ClickFix and its growing family of clipboard-injection variants, device code phishing, OAuth consent abuse, credential stuffing powered by infostealer supply chains, malicious browser extensions all happen in or via the browser.",{"data":2662,"content":2663,"nodeType":881},{},[2664],{"data":2665,"marks":2666,"value":2667,"nodeType":867},{},[],"Another issue is that \"SaaS\" has arguably ceased to be a meaningful category. When we consider that most organizations run the majority of their business on cloud applications, the difference between what constitutes \"SaaS\" versus cloud versus just \"business IT\" is pretty blurry (and feels like an academic rather than practical difference).",{"data":2669,"content":2670,"nodeType":881},{},[2671],{"data":2672,"marks":2673,"value":2675,"nodeType":867},{},[2674],{"type":916},"So it's less about whether an attack is a \"SaaS attack\" and more about how these attacks actually play out. ",{"data":2677,"content":2678,"nodeType":908},{},[],{"data":2680,"content":2681,"nodeType":918},{},[2682],{"data":2683,"marks":2684,"value":2686,"nodeType":867},{},[2685],{"type":916},"The technique landscape has transformed",{"data":2688,"content":2689,"nodeType":881},{},[2690],{"data":2691,"marks":2692,"value":2693,"nodeType":867},{},[],"The second part to the change is the fact that scale and speed of attacker innovation in the space justifies it.",{"data":2695,"content":2696,"nodeType":881},{},[2697],{"data":2698,"marks":2699,"value":2700,"nodeType":867},{},[],"When we launched the matrix in mid-2023, AiTM phishing was emerging as a serious concern but was far from ubiquitous. ClickFix didn't exist as a named technique. Device code phishing was a curiosity documented by a handful of researchers. ConsentFix was years away from being discovered. Browser extension supply chain attacks were rare enough to be individually notable.",{"data":2702,"content":2703,"nodeType":881},{},[2704],{"data":2705,"marks":2706,"value":2707,"nodeType":867},{},[],"In the two and a half years since, every one of these has become a mainstream, industrialized attack technique — and several have converged in ways that would have been hard to predict.",{"data":2709,"content":2713,"nodeType":890},{"target":2710},{"sys":2711},{"id":2712,"type":887,"linkType":888},"5Kw2kSrL8u4VyslxK8HCtR",[],{"data":2715,"content":2716,"nodeType":998},{},[2717],{"data":2718,"marks":2719,"value":2721,"nodeType":867},{},[2720],{"type":916},"AiTM phishing has become the default phishing method",{"data":2723,"content":2724,"nodeType":881},{},[2725,2729,2737],{"data":2726,"marks":2727,"value":2728,"nodeType":867},{},[],"AiTM phishing is now the standard, powered by Phishing-as-a-Service kits that operate with the release cycles and customer support of legitimate SaaS products. Tycoon 2FA alone accounted for ",{"data":2730,"content":2732,"nodeType":876},{"uri":2731},"https://pushsecurity.com/blog/2025-top-phishing-trends/",[2733],{"data":2734,"marks":2735,"value":2736,"nodeType":867},{},[],"62% of phishing detected by Microsoft",{"data":2738,"marks":2739,"value":2740,"nodeType":867},{},[]," and over 64,000 confirmed incidents, with Sneaky2FA, FlowerStorm, Evilginx, and a growing roster of competitors filling out the marketplace.",{"data":2742,"content":2743,"nodeType":881},{},[2744],{"data":2745,"marks":2746,"value":2747,"nodeType":867},{},[],"AiTM is constantly evolving, with vendors adding new features, capabilities, detection evasion techniques, and so on. Abuse of legitimate platforms, and increasingly AI-assisted development means that it’s trivial for attackers to spin up and tear down infrastructure, scale their campaigns, target specific organizations with crafted pages and lures, and generally means that attackers can operate highly sophisticated attacks with minimal effort and complexity. This makes AiTM and other PhaaS-powered techniques extremely accessible to all kinds of criminals.  ",{"data":2749,"content":2750,"nodeType":881},{},[2751],{"data":2752,"marks":2753,"value":2754,"nodeType":867},{},[],"These kits are delivered across several browser-based channels — not just email. Push data consistently shows that roughly 1 in 3 phishing payloads we intercept arrive via social media, search ads, messaging apps, or other non-email vectors.",{"data":2756,"content":2757,"nodeType":881},{},[2758,2762,2767],{"data":2759,"marks":2760,"value":2761,"nodeType":867},{},[],"Vishing has also surged as a delivery channel — CrowdStrike documented a ",{"data":2763,"marks":2764,"value":2766,"nodeType":867},{},[2765],{"type":916},"442% year-over-year increase",{"data":2768,"marks":2769,"value":2770,"nodeType":867},{},[],", and Mandiant found it was the single most common initial vector in cloud compromises at 23%. But the trend that matters isn't voice calls in isolation; it's voice calls combined with browser-based payloads, where a live operator guides the victim into an AiTM page or device code flow that the call alone could not execute.",{"data":2772,"content":2773,"nodeType":998},{},[2774],{"data":2775,"marks":2776,"value":2778,"nodeType":867},{},[2777],{"type":916},"ClickFix is the top reported initial access vector",{"data":2780,"content":2781,"nodeType":881},{},[2782,2786,2793,2797,2805],{"data":2783,"marks":2784,"value":2785,"nodeType":867},{},[],"ClickFix has gone from nonexistent to one of the most prevalent initial access techniques in under 18 months. Microsoft reported it as the ",{"data":2787,"content":2788,"nodeType":876},{"uri":1290},[2789],{"data":2790,"marks":2791,"value":2792,"nodeType":867},{},[],"most common initial access vector in 2025",{"data":2794,"marks":2795,"value":2796,"nodeType":867},{},[],", accounting for 47% of observed attacks, while CrowdStrike documented a ",{"data":2798,"content":2800,"nodeType":876},{"uri":2799},"https://www.crowdstrike.com/explore/2026-global-threat-report",[2801],{"data":2802,"marks":2803,"value":2804,"nodeType":867},{},[],"563% increase",{"data":2806,"marks":2807,"value":2808,"nodeType":867},{},[]," in fake CAPTCHA lures (a top ClickFix style).",{"data":2810,"content":2811,"nodeType":881},{},[2812,2816,2821],{"data":2813,"marks":2814,"value":2815,"nodeType":867},{},[],"ClickFix is admittedly an outlier in a browser attacks matrix — the payload ultimately executes on the endpoint, not in the browser — but the delivery is overwhelmingly browser-based: ",{"data":2817,"marks":2818,"value":2820,"nodeType":867},{},[2819],{"type":916},"4 in 5 ClickFix payloads",{"data":2822,"marks":2823,"value":2824,"nodeType":867},{},[]," intercepted by Push arrive via search engines as a result of malvertising or compromised web pages, not email, which means the browser is the only control point that actually sees the attack before the user pastes the malicious command.",{"data":2826,"content":2827,"nodeType":881},{},[2828],{"data":2829,"marks":2830,"value":2831,"nodeType":867},{},[],"ClickFix is now the primary delivery mechanism for infostealer malware, which is in turn the primary source of the stolen credentials and session tokens that power credential stuffing and session hijacking — which means the technique sits at the start of a cycle where one class of browser-delivered attack generates the raw material for the next.",{"data":2833,"content":2834,"nodeType":881},{},[2835,2839,2846,2850,2856],{"data":2836,"marks":2837,"value":2838,"nodeType":867},{},[],"The success of ClickFix has predictably spawned a growing family of derivatives — FileFix, CrashFix, ",{"data":2840,"content":2841,"nodeType":876},{"uri":1562},[2842],{"data":2843,"marks":2844,"value":2845,"nodeType":867},{},[],"InstallFix",{"data":2847,"marks":2848,"value":2849,"nodeType":867},{},[]," — and much of the naming is marketing hype around variations on the same clipboard-injection mechanic. But ",{"data":2851,"content":2852,"nodeType":876},{"uri":1319},[2853],{"data":2854,"marks":2855,"value":1312,"nodeType":867},{},[],{"data":2857,"marks":2858,"value":2859,"nodeType":867},{},[]," was a genuinely novel development.",{"data":2861,"content":2862,"nodeType":998},{},[2863],{"data":2864,"marks":2865,"value":2867,"nodeType":867},{},[2866],{"type":916},"Browser-native ClickFix: ConsentFix",{"data":2869,"content":2870,"nodeType":881},{},[2871,2875,2883,2887,2894],{"data":2872,"marks":2873,"value":2874,"nodeType":867},{},[],"ConsentFix is a fully browser-native attack that merged ClickFix-style social engineering with OAuth consent abuse, compromising accounts through a legitimate Microsoft authorization flow with no endpoint component at all. ConsentFix was ",{"data":2876,"content":2878,"nodeType":876},{"uri":2877},"https://pushsecurity.com/blog/consentfix-debrief/",[2879],{"data":2880,"marks":2881,"value":2882,"nodeType":867},{},[],"traced to APT29",{"data":2884,"marks":2885,"value":2886,"nodeType":867},{},[]," and has since been ",{"data":2888,"content":2889,"nodeType":876},{"uri":1331},[2890],{"data":2891,"marks":2892,"value":2893,"nodeType":867},{},[],"commercialized on criminal forums",{"data":2895,"marks":2896,"value":2897,"nodeType":867},{},[],", following the same path from state-sponsored technique to commodity criminal tooling that we've seen repeatedly in this space.",{"data":2899,"content":2900,"nodeType":881},{},[2901],{"data":2902,"marks":2903,"value":2904,"nodeType":867},{},[],"ConsentFix demonstrates that the clipboard-injection mechanic can evolve into something that operates entirely within the browser, eliminating the endpoint detection surface that traditional ClickFix still exposed.",{"data":2906,"content":2907,"nodeType":998},{},[2908],{"data":2909,"marks":2910,"value":2912,"nodeType":867},{},[2911],{"type":916},"Attackers have pivoted to authorization attacks to get around login controls",{"data":2914,"content":2915,"nodeType":881},{},[2916,2920,2927],{"data":2917,"marks":2918,"value":2919,"nodeType":867},{},[],"Authorization attacks like device code phishing have seen a ",{"data":2921,"content":2922,"nodeType":876},{"uri":1125},[2923],{"data":2924,"marks":2925,"value":2926,"nodeType":867},{},[],"37.5x increase",{"data":2928,"marks":2929,"value":2930,"nodeType":867},{},[]," since the start of 2026, with at least 12 distinct kits now offering the technique. It bypasses standard authentication controls — including passkeys — because the attack occurs through the OAuth device authorization flow rather than the standard login flow. ",{"data":2932,"content":2933,"nodeType":881},{},[2934],{"data":2935,"marks":2936,"value":2937,"nodeType":867},{},[],"The technique was first associated with nation-state actors like Storm-2372, but went from espionage-grade to commodity PhaaS tooling in roughly eighteen months, with kits like EvilTokens and Venom now offering turnkey device code phishing as a service.",{"data":2939,"content":2940,"nodeType":881},{},[2941],{"data":2942,"marks":2943,"value":2944,"nodeType":867},{},[],"The device code authorization is effectively performed post-authentication. If you already have an active session in your browser, entering the device code and selecting your account from a drop-down menu is all that's needed. No password or MFA required. You can see an example in the video below.",{"data":2946,"content":2950,"nodeType":890},{"target":2947},{"sys":2948},{"id":2949,"type":887,"linkType":888},"2WPb41lNRajdpt5pogQg8M",[],{"data":2952,"content":2953,"nodeType":881},{},[2954],{"data":2955,"marks":2956,"value":2957,"nodeType":867},{},[],"And the ecosystem is adapting to this opportunity: established AiTM vendors like Tycoon are adding authorization-focused options alongside their existing credential-harvesting capabilities, which points toward multi-technique platforms where operators pick the right tool for whatever defenses the target has in place.",{"data":2959,"content":2960,"nodeType":998},{},[2961],{"data":2962,"marks":2963,"value":2965,"nodeType":867},{},[2964],{"type":916},"Malicious and hacked browser extensions are one of the fastest growing threats",{"data":2967,"content":2968,"nodeType":881},{},[2969,2973,2981],{"data":2970,"marks":2971,"value":2972,"nodeType":867},{},[],"Malicious browser extensions have matured from an occasional nuisance into a scalable supply chain attack vector. The ",{"data":2974,"content":2976,"nodeType":876},{"uri":2975},"https://pushsecurity.com/blog/why-browser-extension-risk-scoring-wont-predict-your-next-breach/",[2977],{"data":2978,"marks":2979,"value":2980,"nodeType":867},{},[],"Cyberhaven compromise",{"data":2982,"marks":2983,"value":2984,"nodeType":867},{},[]," in December 2024 — where approximately 35 extensions were weaponized through a single OAuth phishing campaign targeting developers — impacted 2.6 million users and demonstrated that extension supply chain attacks can achieve the kind of reach that used to require a compromised software update server.",{"data":2986,"content":2987,"nodeType":881},{},[2988],{"data":2989,"marks":2990,"value":2991,"nodeType":867},{},[],"Since Cyberhaven, the pace has only accelerated. In 2026 alone, researchers have publicly disclosed at least 250 confirmed malicious browser extensions affecting roughly 1.75 million users, alongside a further 370+ extensions engaged in undisclosed or policy-disclosed data harvesting affecting an additional 44 million users. That doesn't count the extensions from late-2025 campaigns (DarkSpectre, AITOPIA, Trust Wallet) whose impacts carried into 2026.",{"data":2993,"content":2994,"nodeType":881},{},[2995,2999,3007],{"data":2996,"marks":2997,"value":2998,"nodeType":867},{},[],"The attack paths have also expanded. Beyond phishing developers for take over Web Store accounts (the Cyberhaven playbook), attackers are buying existing extensions from developers, waiting for ownership transfers or abandonments to take over, and increasingly vibe-coding their own functional extensions from scratch to build an audience that can later be weaponized. The common thread is that ",{"data":3000,"content":3001,"nodeType":876},{"uri":2975},[3002],{"data":3003,"marks":3004,"value":3006,"nodeType":867},{},[3005],{"type":1040},"most malicious extensions didn't start out malicious",{"data":3008,"marks":3009,"value":3010,"nodeType":867},{},[]," — they started as legitimate tools and were turned into weapons after the fact.",{"data":3012,"content":3013,"nodeType":881},{},[3014],{"data":3015,"marks":3016,"value":3017,"nodeType":867},{},[],"None of this is happening in isolation. The threat landscape has reoriented around browser-based initial access and identity compromise — and the matrix needed to catch up.",{"data":3019,"content":3020,"nodeType":908},{},[],{"data":3022,"content":3023,"nodeType":918},{},[3024],{"data":3025,"marks":3026,"value":3028,"nodeType":867},{},[3027],{"type":916},"The evolution is playing out in public breaches",{"data":3030,"content":3031,"nodeType":881},{},[3032],{"data":3033,"marks":3034,"value":3035,"nodeType":867},{},[],"It’s worth reinforcing that when the SaaS matrix was first released, many of these attacks hadn’t been seen in the wild. The change today is staggering:",{"data":3037,"content":3038,"nodeType":3126},{},[3039,3062,3084,3104],{"data":3040,"content":3041,"nodeType":3061},{},[3042],{"data":3043,"content":3044,"nodeType":881},{},[3045,3049,3057],{"data":3046,"marks":3047,"value":3048,"nodeType":867},{},[],"When ",{"data":3050,"content":3052,"nodeType":876},{"uri":3051},"https://pushsecurity.com/blog/scattered-lapsus-hunters/",[3053],{"data":3054,"marks":3055,"value":3056,"nodeType":867},{},[],"Scattered Lapsus$ Hunters",{"data":3058,"marks":3059,"value":3060,"nodeType":867},{},[]," compromised over a thousand organizations' Salesforce tenants through device code phishing, the attack started with a phone call, moved through a browser-based authorization flow for the attacker’s app, and ended with mass data exfiltration via API.","list-item",{"data":3063,"content":3064,"nodeType":3061},{},[3065],{"data":3066,"content":3067,"nodeType":881},{},[3068,3072,3080],{"data":3069,"marks":3070,"value":3071,"nodeType":867},{},[],"When the same collective launched ",{"data":3073,"content":3075,"nodeType":876},{"uri":3074},"https://pushsecurity.com/blog/unpacking-the-latest-slh-campaign/",[3076],{"data":3077,"marks":3078,"value":3079,"nodeType":867},{},[],"AiTM phishing campaigns",{"data":3081,"marks":3082,"value":3083,"nodeType":867},{},[]," targeting Okta and Entra SSO, the phishing page was operated by a human in real time and delivered over a voice call — not email.",{"data":3085,"content":3086,"nodeType":3061},{},[3087],{"data":3088,"content":3089,"nodeType":881},{},[3090,3093,3100],{"data":3091,"marks":3092,"value":3048,"nodeType":867},{},[],{"data":3094,"content":3095,"nodeType":876},{"uri":1319},[3096],{"data":3097,"marks":3098,"value":3099,"nodeType":867},{},[],"APT29 deployed ConsentFix",{"data":3101,"marks":3102,"value":3103,"nodeType":867},{},[]," across dozens of compromised websites, the entire attack chain was browser-native, abusing a legitimate Microsoft OAuth flow to bypass MFA without proxying a single credential.",{"data":3105,"content":3106,"nodeType":3061},{},[3107],{"data":3108,"content":3109,"nodeType":881},{},[3110,3114,3122],{"data":3111,"marks":3112,"value":3113,"nodeType":867},{},[],"The ",{"data":3115,"content":3117,"nodeType":876},{"uri":3116},"https://pushsecurity.com/blog/identity-attacks-in-the-wild/#id-snowflake-june-2024",[3118],{"data":3119,"marks":3120,"value":3121,"nodeType":867},{},[],"Snowflake breach",{"data":3123,"marks":3124,"value":3125,"nodeType":867},{},[]," — arguably the most consequential credential-based campaign of the past several years — saw 165 organizations breached using credentials that had been sitting in infostealer dumps for years, replayed against Snowflake tenants that lacked mandatory MFA. The attack surface wasn't Snowflake's application logic; it was the identity hygiene gap that every organization carries across hundreds of apps.","unordered-list",{"data":3128,"content":3129,"nodeType":881},{},[3130],{"data":3131,"marks":3132,"value":3133,"nodeType":867},{},[],"And that’s just the big picture. Every month we’re tracking new public breaches involving browser and identity TTPs — which again, are just the tip of the iceberg when you consider that many breaches are settled quietly without hitting the headlines. ",{"data":3135,"content":3136,"nodeType":881},{},[3137,3141,3146],{"data":3138,"marks":3139,"value":3140,"nodeType":867},{},[],"One of the key drivers here is the shrinking time-to-exploit. CrowdStrike's average e-crime breakout time is down to ",{"data":3142,"marks":3143,"value":3145,"nodeType":867},{},[3144],{"type":916},"29 minutes",{"data":3147,"marks":3148,"value":3149,"nodeType":867},{},[],", with the fastest recorded at 27 seconds. When attackers can move from initial access to data exfiltration within minutes, the window for post-compromise detection collapses to near zero. The best chance of stopping the attack is at the point of initial access before the identity is compromised.",{"data":3151,"content":3152,"nodeType":908},{},[],{"data":3154,"content":3155,"nodeType":918},{},[3156,3161,3167,3172,3178],{"data":3157,"marks":3158,"value":3160,"nodeType":867},{},[3159],{"type":916},"Sidenote: why we're looking at attacks ",{"data":3162,"marks":3163,"value":3166,"nodeType":867},{},[3164,3165],{"type":1431},{"type":916},"in",{"data":3168,"marks":3169,"value":3171,"nodeType":867},{},[3170],{"type":916}," the browser, not ",{"data":3173,"marks":3174,"value":3177,"nodeType":867},{},[3175,3176],{"type":1431},{"type":916},"on",{"data":3179,"marks":3180,"value":3182,"nodeType":867},{},[3181],{"type":916}," the browser",{"data":3184,"content":3185,"nodeType":881},{},[3186,3190,3198],{"data":3187,"marks":3188,"value":3189,"nodeType":867},{},[],"Calling this a \"browser attacks\" matrix needs clarification. We're not talking about browser exploits — RCE vulnerabilities, sandbox escapes, memory corruption bugs. Those attacks target the browser itself, they're extraordinarily expensive to develop, and they're increasingly rare. Browser zero-days hit a ",{"data":3191,"content":3193,"nodeType":876},{"uri":3192},"https://cloud.google.com/blog/topics/threat-intelligence/2025-zero-day-review",[3194],{"data":3195,"marks":3196,"value":3197,"nodeType":867},{},[],"historic low of 9%",{"data":3199,"marks":3200,"value":3201,"nodeType":867},{},[]," of all zero-days reported to Google, and a Chrome RCE commands a $250,000 bug bounty.",{"data":3203,"content":3204,"nodeType":881},{},[3205],{"data":3206,"marks":3207,"value":3208,"nodeType":867},{},[],"In comparison, a one-year phishing kit rental costs $1,000. A bulk stolen credential list costs $15. An initial-access-broker-provided IdP admin account costs $3,000. When it costs orders of magnitude less to exploit the person using the browser than to exploit the browser itself, attackers will take the cheaper option every time.",{"data":3210,"content":3211,"nodeType":881},{},[3212],{"data":3213,"marks":3214,"value":3215,"nodeType":867},{},[],"It's worth heading off the obvious counterargument: won't AI-assisted vulnerability discovery eventually make browser exploits cheaper? Perhaps — but it will simultaneously make them easier for browser vendors to find and patch, and vendors like Google and Microsoft have the engineering capacity and financial incentive to scale AI-driven remediation far faster than attackers can scale exploit development.",{"data":3217,"content":3218,"nodeType":908},{},[],{"data":3220,"content":3221,"nodeType":918},{},[3222],{"data":3223,"marks":3224,"value":3226,"nodeType":867},{},[3225],{"type":916},"What hasn't changed",{"data":3228,"content":3229,"nodeType":881},{},[3230,3234,3242],{"data":3231,"marks":3232,"value":3233,"nodeType":867},{},[],"The matrix remains open-source, community-maintained, and available on ",{"data":3235,"content":3237,"nodeType":876},{"uri":3236},"https://github.com/pushsecurity/saas-attacks",[3238],{"data":3239,"marks":3240,"value":3241,"nodeType":867},{},[],"GitHub",{"data":3243,"marks":3244,"value":3245,"nodeType":867},{},[],". The goal is the same as it was in 2023: to give offensive and defensive security teams a shared reference point for the techniques that matter most.",{"data":3247,"content":3248,"nodeType":881},{},[3249],{"data":3250,"marks":3251,"value":3252,"nodeType":867},{},[],"We built it because there was a gap in how the industry talked about these techniques, and that gap still exists — MITRE ATT&CK remains essential for endpoint and network TTPs, but the browser-based, identity-first techniques behind most modern breaches are still underrepresented in traditional frameworks.",{"data":3254,"content":3255,"nodeType":881},{},[3256],{"data":3257,"marks":3258,"value":3259,"nodeType":867},{},[],"We continue to maintain the matrix with input from red teams, detection engineers, and threat researchers across the community. Some of the most valuable additions over the past two years have come from practitioners who encountered a technique on an engagement or in an investigation and contributed it back to the repository.",{"data":3261,"content":3262,"nodeType":881},{},[3263,3267,3274],{"data":3264,"marks":3265,"value":3266,"nodeType":867},{},[],"If you're an offensive security professional using these techniques on engagements, or a defender building detections against them, we want to hear from you. Submit a PR, open a discussion, or flag a technique we've missed on ",{"data":3268,"content":3270,"nodeType":876},{"uri":3269},"https://github.com/pushsecurity/browser-identity-attacks-matrix",[3271],{"data":3272,"marks":3273,"value":3241,"nodeType":867},{},[],{"data":3275,"marks":3276,"value":1947,"nodeType":867},{},[],{"data":3278,"content":3279,"nodeType":908},{},[],{"data":3281,"content":3282,"nodeType":918},{},[3283],{"data":3284,"marks":3285,"value":3287,"nodeType":867},{},[3286],{"type":916},"Looking ahead",{"data":3289,"content":3290,"nodeType":881},{},[3291],{"data":3292,"marks":3293,"value":3294,"nodeType":867},{},[],"The pace of attacker innovation in browser-based initial access techniques over the past 18 months has been unlike anything we've tracked before — technique after technique moving from research curiosity to industrialized criminal tooling within months, not years.",{"data":3296,"content":3297,"nodeType":3126},{},[3298,3308,3318],{"data":3299,"content":3300,"nodeType":3061},{},[3301],{"data":3302,"content":3303,"nodeType":881},{},[3304],{"data":3305,"marks":3306,"value":3307,"nodeType":867},{},[],"AiTM platforms are adding authorization-based attack options alongside their credential-harvesting capabilities.",{"data":3309,"content":3310,"nodeType":3061},{},[3311],{"data":3312,"content":3313,"nodeType":881},{},[3314],{"data":3315,"marks":3316,"value":3317,"nodeType":867},{},[],"ClickFix has spawned fully browser-native variants.",{"data":3319,"content":3320,"nodeType":3061},{},[3321],{"data":3322,"content":3323,"nodeType":881},{},[3324],{"data":3325,"marks":3326,"value":3327,"nodeType":867},{},[],"AI is lowering the cost of producing convincing social engineering and phishing infrastructure at scale.",{"data":3329,"content":3330,"nodeType":881},{},[3331],{"data":3332,"marks":3333,"value":3334,"nodeType":867},{},[],"We don't see any of this slowing down, and that's exactly why thinking about these attacks as a browser problem instead of siloing them across email, endpoint, network, and cloud categories, each with a partial view of the picture (and still missing the whole when combined).",{"data":3336,"content":3337,"nodeType":881},{},[3338,3342,3349],{"data":3339,"marks":3340,"value":3341,"nodeType":867},{},[],"The Browser & Identity Attacks Matrix is our contribution to keeping that shared understanding current. You can ",{"data":3343,"content":3344,"nodeType":876},{"uri":2613},[3345],{"data":3346,"marks":3347,"value":3348,"nodeType":867},{},[],"explore the matrix here",{"data":3350,"marks":3351,"value":1947,"nodeType":867},{},[],{"data":3353,"content":3354,"nodeType":881},{},[3355,3359,3366],{"data":3356,"marks":3357,"value":3358,"nodeType":867},{},[],"You can also read our recent ",{"data":3360,"content":3361,"nodeType":876},{"uri":1094},[3362],{"data":3363,"marks":3364,"value":3365,"nodeType":867},{},[],"browser attack techniques report",{"data":3367,"marks":3368,"value":3369,"nodeType":867},{},[]," for more information.",{"data":3371,"content":3375,"nodeType":890},{"target":3372},{"sys":3373},{"id":3374,"type":887,"linkType":888},"1hx6sxpyEzxn4F4jc1RGQi",[],{"data":3377,"content":3378,"nodeType":908},{},[],{"data":3380,"content":3381,"nodeType":881},{},[3382],{"data":3383,"marks":3384,"value":3385,"nodeType":867},{},[],"Push Security is the most powerful AI-native security tool in the browser. Think EDR, but for the browser — high-fidelity telemetry and real-time control across every session, on every device, with no browser migration required. Security teams use Push to detect and stop advanced browser-based attacks like AiTM phishing, ClickFix, and session hijacking; gain visibility and control over AI tool usage across their workforce; harden identities by surfacing credential reuse, SSO gaps, and shadow IT; and support data loss and insider investigations with browser-layer telemetry that other tools can't see.",{"data":3387,"content":3388,"nodeType":881},{},[3389,3393,3400],{"data":3390,"marks":3391,"value":3392,"nodeType":867},{},[],"Book a ",{"data":3394,"content":3395,"nodeType":876},{"uri":1629},[3396],{"data":3397,"marks":3398,"value":3399,"nodeType":867},{},[],"live demo",{"data":3401,"marks":3402,"value":1639,"nodeType":867},{},[],"Introducing the Browser & Identity Attacks Matrix","We're re-releasing the SaaS attack matrix as the Browser & Identity Attacks Matrix. Here's why we've decided to make the change and what it means.","2026-05-08T00:00:00.000Z","introducing-the-browser-and-identity-attacks-matrix",{"items":3408},[3409,3411],{"sys":3410,"name":2547},{"id":2546},{"sys":3412,"name":342},{"id":2550},{"items":3414},[3415],{"fullName":849,"firstName":850,"jobTitle":851,"profilePicture":3416},{"url":855},{"__typename":1742,"sys":3418,"content":3420,"title":4359,"synopsis":4360,"hashTags":59,"publishedDate":4361,"slug":4362,"tagsCollection":4363,"authorsCollection":4369},{"id":3419},"1jfqiWQlL6qkn3i9yjNbFB",{"json":3421},{"data":3422,"content":3423,"nodeType":1640},{},[3424,3431,3452,3464,3471,3479,3486,3508,3515,3522,3529,3541,3547,3550,3558,3574,3593,3705,3711,3718,3724,3732,3739,3751,3758,3764,3771,3795,3802,3809,3815,3818,3826,3833,3841,3848,3864,3871,3878,3886,3893,3900,3908,3915,3922,3925,3933,3940,3948,3955,3962,3969,3976,3984,3991,4024,4031,4038,4044,4051,4059,4066,4144,4150,4158,4174,4181,4187,4194,4210,4213,4221,4228,4235,4241,4248,4293,4300,4307,4314,4320,4323,4331,4337,4343],{"data":3425,"content":3426,"nodeType":881},{},[3427],{"data":3428,"marks":3429,"value":3430,"nodeType":867},{},[],"In March, our threat hunting engine flagged something it hadn’t seen before.",{"data":3432,"content":3433,"nodeType":881},{},[3434,3438,3448],{"data":3435,"marks":3436,"value":3437,"nodeType":867},{},[],"Our research team had already been tracking the growing use of ",{"data":3439,"content":3443,"nodeType":3447},{"target":3440},{"sys":3441},{"id":3442,"type":887,"linkType":888},"2U6QpQ9rkY8x5ES48okHZB",[3444],{"data":3445,"marks":3446,"value":441,"nodeType":867},{},[],"entry-hyperlink",{"data":3449,"marks":3450,"value":3451,"nodeType":867},{},[]," tied to phishing campaigns. Malvertising frequently targets users via Google Search results, inserting malicious ads or redirects in place of legitimate ads, and using the familiar context of the search results page to trick users into clicking.",{"data":3453,"content":3454,"nodeType":881},{},[3455,3459],{"data":3456,"marks":3457,"value":3458,"nodeType":867},{},[],"To defend Push customers against this threat, we needed a way to spot malicious activity arising from clicking on Google ads. ",{"data":3460,"marks":3461,"value":3463,"nodeType":867},{},[3462],{"type":1431},"But how to separate signal from noise?",{"data":3465,"content":3466,"nodeType":881},{},[3467],{"data":3468,"marks":3469,"value":3470,"nodeType":867},{},[],"Our hunt combined the skills of human researchers and AI agents to find 12 meaningful results from trillions of browser events visible to the Push extension across our install base.",{"data":3472,"content":3473,"nodeType":881},{},[3474],{"data":3475,"marks":3476,"value":3478,"nodeType":867},{},[3477],{"type":916},"Of those, one was novel. ",{"data":3480,"content":3481,"nodeType":881},{},[3482],{"data":3483,"marks":3484,"value":3485,"nodeType":867},{},[],"A user had searched for NotebookLM, clicked a paid Google ad, and gotten redirected to a page impersonating NotebookLM. The page itself was just a facade fronting a Cloudflare Pages-hosted phishing kit with a WebAssembly C2 connector. To the user, it looked like a completely on-brand NotebookLM page, and if they had run the fake install prompt, they would have installed malware. (Note: NotebookLM doesn’t even require a local install, but the page was convincing enough — and AI platforms are changing so quickly — that the lure was extremely believable.)",{"data":3487,"content":3488,"nodeType":881},{},[3489,3494,3504],{"data":3490,"marks":3491,"value":3493,"nodeType":867},{},[3492],{"type":916},"We had found our first in-the-wild ",{"data":3495,"content":3499,"nodeType":3447},{"target":3496},{"sys":3497},{"id":3498,"type":887,"linkType":888},"7bG71Eo43crbIHKzczooVS",[3500],{"data":3501,"marks":3502,"value":1567,"nodeType":867},{},[3503],{"type":916},{"data":3505,"marks":3506,"value":1947,"nodeType":867},{},[3507],{"type":916},{"data":3509,"content":3510,"nodeType":881},{},[3511],{"data":3512,"marks":3513,"value":3514,"nodeType":867},{},[],"Within minutes, our analysis agents created detections, and researchers shipped a new detection to every Push customer. ",{"data":3516,"content":3517,"nodeType":881},{},[3518],{"data":3519,"marks":3520,"value":3521,"nodeType":867},{},[],"Eighteen months ago, it would have taken a human analyst days or even weeks to unpack the attack, comb through web requests, de-obfuscate web code, trace JavaScript execution, and extract signals of tactics, techniques, and procedures (TTPs) beyond short-lived single-use IOCs like domain name, then get their work coded up as a detection and deployed to customers. ",{"data":3523,"content":3524,"nodeType":881},{},[3525],{"data":3526,"marks":3527,"value":3528,"nodeType":867},{},[],"That was viable when new tools or techniques showed up once or twice a quarter. It doesn’t stand a chance when attack evolutions occur weekly or even daily. That’s the reality now with AI-generated adversary tools.",{"data":3530,"content":3531,"nodeType":881},{},[3532,3537],{"data":3533,"marks":3534,"value":3536,"nodeType":867},{},[3535],{"type":916},"So, can AI agents replace human threat researchers?",{"data":3538,"marks":3539,"value":3540,"nodeType":867},{},[]," That’s the wrong question. Can AI agents massively scale the expertise of a seasoned human threat hunter without getting bored of repetitive tasks, missing pertinent but easily overlooked details, or creating operational siloes dependent on one person’s knowledge — and do its work continuously across trillions of data points? Yes, absolutely.",{"data":3542,"content":3546,"nodeType":890},{"target":3543},{"sys":3544},{"id":3545,"type":887,"linkType":888},"3OiZ7BrViCTTMmHUAbloEt",[],{"data":3548,"content":3549,"nodeType":908},{},[],{"data":3551,"content":3552,"nodeType":918},{},[3553],{"data":3554,"marks":3555,"value":3557,"nodeType":867},{},[3556],{"type":916},"Why scaling browser threat detection requires more than more analysts",{"data":3559,"content":3560,"nodeType":881},{},[3561,3565,3570],{"data":3562,"marks":3563,"value":3564,"nodeType":867},{},[],"Already this year, we’ve ",{"data":3566,"marks":3567,"value":3569,"nodeType":867},{},[3568],{"type":916},"tripled",{"data":3571,"marks":3572,"value":3573,"nodeType":867},{},[]," the cumulative number of detections shipped to Push customers using this pipeline. That output points to the first problem we set out to solve by employing AI agents: Scaling our research team’s considerable expertise.",{"data":3575,"content":3576,"nodeType":881},{},[3577,3581,3589],{"data":3578,"marks":3579,"value":3580,"nodeType":867},{},[],"Push’s R&D team are experts at understanding and unpacking modern browser-based attacks. This is essential when you consider how quickly attacks themselves are evolving. When we created the ",{"data":3582,"content":3585,"nodeType":3447},{"target":3583},{"sys":3584},{"id":2561,"type":887,"linkType":888},[3586],{"data":3587,"marks":3588,"value":2618,"nodeType":867},{},[],{"data":3590,"marks":3591,"value":3592,"nodeType":867},{},[]," in 2023 (then called the SaaS Attacks Matrix), many of the ideas in it were theoretical. Not anymore. ",{"data":3594,"content":3595,"nodeType":3126},{},[3596,3606,3630],{"data":3597,"content":3598,"nodeType":3061},{},[3599],{"data":3600,"content":3601,"nodeType":881},{},[3602],{"data":3603,"marks":3604,"value":3605,"nodeType":867},{},[],"We’ve tracked the rise of AiTM phish kits from their status as MFA-bypassing novelties to the emergence of an entire criminal ecosystem built around increasingly sophisticated Phishing-as-a-Service tools. ",{"data":3607,"content":3608,"nodeType":3061},{},[3609],{"data":3610,"content":3611,"nodeType":881},{},[3612,3616,3626],{"data":3613,"marks":3614,"value":3615,"nodeType":867},{},[],"We imagined the simple but effective power of using device code authorization for phishing three years ago; in the last few months, we’ve detected a 37x increase in ",{"data":3617,"content":3621,"nodeType":3447},{"target":3618},{"sys":3619},{"id":3620,"type":887,"linkType":888},"5DmCqTU2Tg4adYScA5vT2x",[3622],{"data":3623,"marks":3624,"value":3625,"nodeType":867},{},[],"device code phishing attacks",{"data":3627,"marks":3628,"value":3629,"nodeType":867},{},[]," across our install base. ",{"data":3631,"content":3632,"nodeType":3061},{},[3633],{"data":3634,"content":3635,"nodeType":881},{},[3636,3640,3649,3653,3662,3666,3676,3680,3688,3691,3701],{"data":3637,"marks":3638,"value":3639,"nodeType":867},{},[],"We were also the first to detect a novel post-authorization attack we dubbed ",{"data":3641,"content":3645,"nodeType":3447},{"target":3642},{"sys":3643},{"id":3644,"type":887,"linkType":888},"71EaaK7lfl6bQBbkAU0qjv",[3646],{"data":3647,"marks":3648,"value":1312,"nodeType":867},{},[],{"data":3650,"marks":3651,"value":3652,"nodeType":867},{},[]," that combines OAuth consent phishing and ClickFix-style user prompts; reported on the rise of the ridiculously simple yet effective ",{"data":3654,"content":3657,"nodeType":3447},{"target":3655},{"sys":3656},{"id":3498,"type":887,"linkType":888},[3658],{"data":3659,"marks":3660,"value":3661,"nodeType":867},{},[],"InstallFix technique",{"data":3663,"marks":3664,"value":3665,"nodeType":867},{},[]," described earlier; and detected an array of other ",{"data":3667,"content":3671,"nodeType":3447},{"target":3668},{"sys":3669},{"id":3670,"type":887,"linkType":888},"2YmiesBvJHGw4wiKEKzLUq",[3672],{"data":3673,"marks":3674,"value":3675,"nodeType":867},{},[],"creative",{"data":3677,"marks":3678,"value":3679,"nodeType":867},{},[]," ",{"data":3681,"content":3684,"nodeType":3447},{"target":3682},{"sys":3683},{"id":3442,"type":887,"linkType":888},[3685],{"data":3686,"marks":3687,"value":520,"nodeType":867},{},[],{"data":3689,"marks":3690,"value":3679,"nodeType":867},{},[],{"data":3692,"content":3696,"nodeType":3447},{"target":3693},{"sys":3694},{"id":3695,"type":887,"linkType":888},"6Zosy4SU0LpjlaSWX75peb",[3697],{"data":3698,"marks":3699,"value":3700,"nodeType":867},{},[],"campaigns",{"data":3702,"marks":3703,"value":3704,"nodeType":867},{},[]," tied to malvertising scams.",{"data":3706,"content":3710,"nodeType":890},{"target":3707},{"sys":3708},{"id":3709,"type":887,"linkType":888},"53U3LHhhHFYnEpShdLmDqs",[],{"data":3712,"content":3713,"nodeType":881},{},[3714],{"data":3715,"marks":3716,"value":3717,"nodeType":867},{},[],"With an agentic approach, we could scale this expertise and reduce the time it takes to go from technique discovery to production-ready detection. This speed is critical now because adversaries are also using AI tools to do their work, exploding the number of trivial-to-rotate indicators of compromise and overwhelming existing detection workflows that lack an equivalent machine speed.",{"data":3719,"content":3723,"nodeType":890},{"target":3720},{"sys":3721},{"id":3722,"type":887,"linkType":888},"1u00uFbC4xsvP9lqahXbgD",[],{"data":3725,"content":3726,"nodeType":998},{},[3727],{"data":3728,"marks":3729,"value":3731,"nodeType":867},{},[3730],{"type":916},"Scaling behavioral detections, not just making bigger blocklists",{"data":3733,"content":3734,"nodeType":881},{},[3735],{"data":3736,"marks":3737,"value":3738,"nodeType":867},{},[],"But output numbers alone don’t tell the story of successful detections. That’s the other problem we set out to solve at scale: Most secure browser solutions rely on detection logic based on blocking known-bad indicators like domains, IPs, and URLs.",{"data":3740,"content":3741,"nodeType":881},{},[3742,3747],{"data":3743,"marks":3744,"value":3746,"nodeType":867},{},[3745],{"type":916},"If your solution offers 1,000 detections, and they’re all based on known-bad indicators that are easily rotated, then you’ve got 1,000 detections that worked once and will likely never fire again. ",{"data":3748,"marks":3749,"value":3750,"nodeType":867},{},[],"They certainly won’t catch subtle adaptations in adversary techniques that don’t rely on infrastructure changes, which are easy for attackers to swap anyway. ",{"data":3752,"content":3753,"nodeType":881},{},[3754],{"data":3755,"marks":3756,"value":3757,"nodeType":867},{},[],"Push does it differently. Our detection engine is focused on hunting for tactics, techniques, and procedures: the behavioral fingerprints of an attack, not just the infrastructure it runs on. ",{"data":3759,"content":3763,"nodeType":890},{"target":3760},{"sys":3761},{"id":3762,"type":887,"linkType":888},"5jR3YVUiusHGnXDOyrgYpr",[],{"data":3765,"content":3766,"nodeType":881},{},[3767],{"data":3768,"marks":3769,"value":3770,"nodeType":867},{},[],"Instead of blocking based on known-bad domains, URLs, and IPs, our detections are built around user-level and page-level behaviors like what scripts load, how redirects behave, what events fire, what actions a user takes and what happens next, etc. (In fact, Push detections don’t even use any infrastructure-based IOCs, though customers can write their own custom detections if they have a specific IOC they’re keeping an eye on.)",{"data":3772,"content":3773,"nodeType":881},{},[3774,3779,3790],{"data":3775,"marks":3776,"value":3778,"nodeType":867},{},[3777],{"type":916},"All the detections we write would survive infrastructure rotation by adversaries, and many of our existing detections have caught never-before-seen evolutions in TTPs. That’s because we focus on the top of the ",{"data":3780,"content":3784,"nodeType":3447},{"target":3781},{"sys":3782},{"id":3783,"type":887,"linkType":888},"1qegIy4rMdm5XZXnIEoKpE",[3785],{"data":3786,"marks":3787,"value":3789,"nodeType":867},{},[3788],{"type":916},"Pyramid of Pain",{"data":3791,"marks":3792,"value":3794,"nodeType":867},{},[3793],{"type":916},", the indicators that are hardest for attackers to change.",{"data":3796,"content":3797,"nodeType":881},{},[3798],{"data":3799,"marks":3800,"value":3801,"nodeType":867},{},[],"This focus on detecting TTPs has always been our approach. But with the acceleration in both attack types and the ease with which adversaries rotate infrastructure, we needed to build capabilities that scaled our knowledge. ",{"data":3803,"content":3804,"nodeType":881},{},[3805],{"data":3806,"marks":3807,"value":3808,"nodeType":867},{},[],"We did this not by replacing researchers, but by continuously activating their expertise. You can hear what our CEO and Co-founder Adam had to say about this below. ",{"data":3810,"content":3814,"nodeType":890},{"target":3811},{"sys":3812},{"id":3813,"type":887,"linkType":888},"C9gr4nF3f6CW45Aol9xij",[],{"data":3816,"content":3817,"nodeType":908},{},[],{"data":3819,"content":3820,"nodeType":918},{},[3821],{"data":3822,"marks":3823,"value":3825,"nodeType":867},{},[3824],{"type":916},"Core principles for agentic threat hunting",{"data":3827,"content":3828,"nodeType":881},{},[3829],{"data":3830,"marks":3831,"value":3832,"nodeType":867},{},[],"Three principles make Push's agentic threat hunting and detection engineering pipeline work:",{"data":3834,"content":3835,"nodeType":998},{},[3836],{"data":3837,"marks":3838,"value":3840,"nodeType":867},{},[3839],{"type":916},"Context matters more than custom models",{"data":3842,"content":3843,"nodeType":881},{},[3844],{"data":3845,"marks":3846,"value":3847,"nodeType":867},{},[],"We’re not AI researchers; we’re security researchers — we aren't trying to compete in building the most intelligent models. And in our view, AI models are quickly becoming commoditized like cloud infrastructure, anyway. Luckily, the commercial models today already excel at understanding web code. We just need to harness their power with our expertise.",{"data":3849,"content":3850,"nodeType":881},{},[3851,3855,3860],{"data":3852,"marks":3853,"value":3854,"nodeType":867},{},[],"So at Push, we use a variety of commercial AI models and tools in complementary ways. What matters most is the telemetry they analyze, and that’s where Push’s existing product infrastructure shines: We’re already deployed into over ",{"data":3856,"marks":3857,"value":3859,"nodeType":867},{},[3858],{"type":916},"3 million browsers worldwide",{"data":3861,"marks":3862,"value":3863,"nodeType":867},{},[],", and the Push browser extension includes a component that operates as a flight recorder to locally record everything that matters inside a browser session.",{"data":3865,"content":3866,"nodeType":881},{},[3867],{"data":3868,"marks":3869,"value":3870,"nodeType":867},{},[],"This universe of metadata — DOM elements, tab context, script execution, network traffic, user actions, credential entry, etc. — becomes the searchable corpus for hunts. Metadata is stored locally in users’ browsers and only queried during targeted threat hunts. ",{"data":3872,"content":3873,"nodeType":881},{},[3874],{"data":3875,"marks":3876,"value":3877,"nodeType":867},{},[],"This approach avoids dragnet collection of sensitive data. Instead, we focus on collecting metadata and distilling that into patterns and insights that provide context for agents to perform their analysis. This means that Push also does not train or fine-tune models on customer data.",{"data":3879,"content":3880,"nodeType":998},{},[3881],{"data":3882,"marks":3883,"value":3885,"nodeType":867},{},[3884],{"type":916},"Agents are only as good as the context you give them. Good context is researcher-led",{"data":3887,"content":3888,"nodeType":881},{},[3889],{"data":3890,"marks":3891,"value":3892,"nodeType":867},{},[],"AI agents don’t know how to identify the TTPs of browser-based attacks until you give them the right context, and Push researchers have spent years unpacking these techniques and tools. Agents at Push consume our internal knowledge base of identified TTPs, and both humans and agents perform meta-analyses to check their work. The agents have access to large libraries of traces of human interactions with real phishing kits. This is a powerful dataset to build on.",{"data":3894,"content":3895,"nodeType":881},{},[3896],{"data":3897,"marks":3898,"value":3899,"nodeType":867},{},[],"When we don’t get the results we want from AI models, the question is “What context is it missing? What does our human team know that the agents don’t, and how can we give them that context — do they need data, tools, better workflows?” That closes the gap in performance and keeps quality high.",{"data":3901,"content":3902,"nodeType":998},{},[3903],{"data":3904,"marks":3905,"value":3907,"nodeType":867},{},[3906],{"type":916},"Integrated architecture that makes agentic AI the throughput layer, not a bolt-on",{"data":3909,"content":3910,"nodeType":881},{},[3911],{"data":3912,"marks":3913,"value":3914,"nodeType":867},{},[],"The constraint we’re trying to break by using AI isn’t knowledge, it’s throughput. Our researchers deeply understand the techniques and tools. An agentic pipeline can apply that understanding continuously across millions of browsers and trillions of events, ingest new external signals, generate hunt hypotheses, triage results, and return only the findings that warrant escalation.",{"data":3916,"content":3917,"nodeType":881},{},[3918],{"data":3919,"marks":3920,"value":3921,"nodeType":867},{},[],"This approach relies on tight integration of our product and our agentic workflows. We’ll take a closer look at that in the next section.",{"data":3923,"content":3924,"nodeType":908},{},[],{"data":3926,"content":3927,"nodeType":918},{},[3928],{"data":3929,"marks":3930,"value":3932,"nodeType":867},{},[3931],{"type":916},"How the agentic detection pipeline runs",{"data":3934,"content":3935,"nodeType":881},{},[3936],{"data":3937,"marks":3938,"value":3939,"nodeType":867},{},[],"Now let’s look at how agentic threat detection actually works, and some of the emerging best practices we’ve identified. We'll cover two example hunts, one initiated autonomously by the agents themselves, and one by our research team. ",{"data":3941,"content":3942,"nodeType":998},{},[3943],{"data":3944,"marks":3945,"value":3947,"nodeType":867},{},[3946],{"type":916},"Example 1: Autonomous threat hunt",{"data":3949,"content":3950,"nodeType":881},{},[3951],{"data":3952,"marks":3953,"value":3954,"nodeType":867},{},[],"Push’s threat hunting pipeline ingested context from research articles describing a new attack technique, and an agent developed hypotheses on what to hunt for across Push’s install base to identify instances of this attack. ",{"data":3956,"content":3957,"nodeType":881},{},[3958],{"data":3959,"marks":3960,"value":3961,"nodeType":867},{},[],"The agent crafted detection queries and then refined them to reduce false positives. The successful query ran across stored metadata and returned results, validating that there were zero false positives. ",{"data":3963,"content":3964,"nodeType":881},{},[3965],{"data":3966,"marks":3967,"value":3968,"nodeType":867},{},[],"The validated query became a scheduled job that runs on a regular cadence to monitor for potentially malicious signals. A triage agent then received any matches, did an initial analysis, and passed anything that looked suspicious to another agent to perform deeper analysis. This deep analysis agent wields the full investigative toolkit that a human researcher would — using Push’s internal knowledge base, domain age and registration analysis, URLScan and whois lookups, DOM image analysis, and contextual analysis of page-level and user-level behaviors, etc.",{"data":3970,"content":3971,"nodeType":881},{},[3972],{"data":3973,"marks":3974,"value":3975,"nodeType":867},{},[],"Within a few minutes, it can filter a thousand or more signals in a hunt trace down to a handful with meaning and provide an actionable assessment. Then, once the TTP was well-understood, other agents wrote and refined detections that can raise alerts for customers when an event of this type is seen. The Push platform immediately applies the customer’s configured security controls, such as blocking users from interacting with malicious pages.",{"data":3977,"content":3978,"nodeType":998},{},[3979],{"data":3980,"marks":3981,"value":3983,"nodeType":867},{},[3982],{"type":916},"Example 2: Human-initiated threat hunt",{"data":3985,"content":3986,"nodeType":881},{},[3987],{"data":3988,"marks":3989,"value":3990,"nodeType":867},{},[],"Now, going back to the example from the beginning of the article: InstallFix. This hunt started with a thorny problem our research team needed to solve: How to detect bad things downstream of a user interacting with a Google ad? We needed a way to pinpoint the bad links from the good ones.",{"data":3992,"content":3993,"nodeType":881},{},[3994,3998,4003,4007,4012,4015,4020],{"data":3995,"marks":3996,"value":3997,"nodeType":867},{},[],"Our researchers collaborated with agents to formulate the right parameters for hunt queries, taking into account that good ads are normally bought by companies with marketing budgets, so therefore ads will be expected to redirect to pages hosted on custom domains, not shared domains like ",{"data":3999,"marks":4000,"value":4002,"nodeType":867},{},[4001],{"type":916},"*pages.dev",{"data":4004,"marks":4005,"value":4006,"nodeType":867},{},[],", ",{"data":4008,"marks":4009,"value":4011,"nodeType":867},{},[4010],{"type":916},"*workers.dev",{"data":4013,"marks":4014,"value":4006,"nodeType":867},{},[],{"data":4016,"marks":4017,"value":4019,"nodeType":867},{},[4018],{"type":916},"*squarespace.com",{"data":4021,"marks":4022,"value":4023,"nodeType":867},{},[],", etc.",{"data":4025,"content":4026,"nodeType":881},{},[4027],{"data":4028,"marks":4029,"value":4030,"nodeType":867},{},[],"Our AI agents already understood key TTPs that indicated potential maliciousness on a page: password prompts, file downloads, OAuth integrations, clipboard copies, and similar user prompts that are frequently abused.",{"data":4032,"content":4033,"nodeType":881},{},[4034],{"data":4035,"marks":4036,"value":4037,"nodeType":867},{},[],"The agent ran several queries that returned matching browsing traces — the term we use for sequences of events in a session or tab context — where the user clicked a Google ad, was redirected to a page on a shared hosting domain, and then clicked a button to copy content to their clipboard.",{"data":4039,"content":4043,"nodeType":890},{"target":4040},{"sys":4041},{"id":4042,"type":887,"linkType":888},"4IWOrWuvbwzWRJUkINiwKH",[],{"data":4045,"content":4046,"nodeType":881},{},[4047],{"data":4048,"marks":4049,"value":4050,"nodeType":867},{},[],"We got back high-fidelity findings and then tuned the query into a continuous detection that leveraged existing detection logic around related techniques. This process also effectively back-tests new detections, so we know we’re not going to generate a lot of false positives. Result: A new detection against a new technique, plus several improvements to existing detections.",{"data":4052,"content":4053,"nodeType":998},{},[4054],{"data":4055,"marks":4056,"value":4058,"nodeType":867},{},[4057],{"type":916},"What infrastructure is needed for agentic threat hunting?",{"data":4060,"content":4061,"nodeType":881},{},[4062],{"data":4063,"marks":4064,"value":4065,"nodeType":867},{},[],"Both of these examples illustrate the end-to-end workflows supported by this pipeline. From an infrastructure perspective, you can think about the pipeline as composed of:",{"data":4067,"content":4068,"nodeType":3126},{},[4069,4084,4099,4114,4129],{"data":4070,"content":4071,"nodeType":3061},{},[4072],{"data":4073,"content":4074,"nodeType":881},{},[4075,4080],{"data":4076,"marks":4077,"value":4079,"nodeType":867},{},[4078],{"type":916},"A flight recorder: ",{"data":4081,"marks":4082,"value":4083,"nodeType":867},{},[],"The Push extension-powered capability that collects and locally stores browser event metadata from users’ browsers.",{"data":4085,"content":4086,"nodeType":3061},{},[4087],{"data":4088,"content":4089,"nodeType":881},{},[4090,4095],{"data":4091,"marks":4092,"value":4094,"nodeType":867},{},[4093],{"type":916},"A knowledge base:",{"data":4096,"marks":4097,"value":4098,"nodeType":867},{},[]," Structured knowledge about what Push knows about TTPs and its existing body of detection logic, as well as externally sourced signals of new attack trends.",{"data":4100,"content":4101,"nodeType":3061},{},[4102],{"data":4103,"content":4104,"nodeType":881},{},[4105,4110],{"data":4106,"marks":4107,"value":4109,"nodeType":867},{},[4108],{"type":916},"Agents as tools: ",{"data":4111,"marks":4112,"value":4113,"nodeType":867},{},[],"Role-segmented agents that work as a team to triage, investigate, develop hunt queries, return analyses, write detections, and review each others’ work for completeness and accuracy.",{"data":4115,"content":4116,"nodeType":3061},{},[4117],{"data":4118,"content":4119,"nodeType":881},{},[4120,4125],{"data":4121,"marks":4122,"value":4124,"nodeType":867},{},[4123],{"type":916},"Humans in the loop: ",{"data":4126,"marks":4127,"value":4128,"nodeType":867},{},[],"Human researchers who collaborate with agents to initiate hunts and tune detections.",{"data":4130,"content":4131,"nodeType":3061},{},[4132],{"data":4133,"content":4134,"nodeType":881},{},[4135,4140],{"data":4136,"marks":4137,"value":4139,"nodeType":867},{},[4138],{"type":916},"Platform controls: ",{"data":4141,"marks":4142,"value":4143,"nodeType":867},{},[],"The Push administrator-configured controls that specify how to respond to detected events like AiTM phishing, tuneable by scope, user groups, browser profiles, apps, etc.",{"data":4145,"content":4149,"nodeType":890},{"target":4146},{"sys":4147},{"id":4148,"type":887,"linkType":888},"7FY0vCBUXOt4vnudFuKALC",[],{"data":4151,"content":4152,"nodeType":998},{},[4153],{"data":4154,"marks":4155,"value":4157,"nodeType":867},{},[4156],{"type":916},"What are the best practices for agentic threat detection?",{"data":4159,"content":4160,"nodeType":881},{},[4161,4165,4170],{"data":4162,"marks":4163,"value":4164,"nodeType":867},{},[],"To be effective, agents must specialize and focus. This is the ",{"data":4166,"marks":4167,"value":4169,"nodeType":867},{},[4168],{"type":916},"agents as tools",{"data":4171,"marks":4172,"value":4173,"nodeType":867},{},[]," concept. When we’re asking AI agents to take massive amounts of data and make a high-level decision about a signal in observed browser events, they must work as a team, finding intelligent ways to condense information without losing important context or hallucinating.",{"data":4175,"content":4176,"nodeType":881},{},[4177],{"data":4178,"marks":4179,"value":4180,"nodeType":867},{},[],"Creating a hierarchy of agent jobs — including agents to perform meta-analyses to catch mistakes and verify conclusions — makes the agents effective by giving them a manageable focus that controls the size of context windows.",{"data":4182,"content":4186,"nodeType":890},{"target":4183},{"sys":4184},{"id":4185,"type":887,"linkType":888},"3fzJCknMUmh4Z7YnhBSbsT",[],{"data":4188,"content":4189,"nodeType":881},{},[4190],{"data":4191,"marks":4192,"value":4193,"nodeType":867},{},[],"Creating an agentic workflow requires operationalizing your internal knowledge in a repeatable and trustworthy way. Sharing rich context from human discoveries is the key to getting the best results out of agents. ",{"data":4195,"content":4196,"nodeType":881},{},[4197,4201,4206],{"data":4198,"marks":4199,"value":4200,"nodeType":867},{},[],"It's vital too that the agent uses ",{"data":4202,"marks":4203,"value":4205,"nodeType":867},{},[4204],{"type":916},"privacy-preserving methods and infrastructure.",{"data":4207,"marks":4208,"value":4209,"nodeType":867},{},[]," The Push agent is designed to respect customer and user privacy while enabling high-fidelity detections. We do this by collecting broad browser metadata but storing it locally in users’ browsers and only querying that metadata during active threat hunting investigations.",{"data":4211,"content":4212,"nodeType":908},{},[],{"data":4214,"content":4215,"nodeType":918},{},[4216],{"data":4217,"marks":4218,"value":4220,"nodeType":867},{},[4219],{"type":916},"The compounding effect and how it benefits Push customers",{"data":4222,"content":4223,"nodeType":881},{},[4224],{"data":4225,"marks":4226,"value":4227,"nodeType":867},{},[],"At Push, we think about our detection capability as two learning loops with a compounding effect: An inner loop that serves as our real-time detection and response engine for known attacker techniques, and an outer loop that is the continuous learning our agents do as they hunt for new threats, analyze emerging behaviors, and create new detections. ",{"data":4229,"content":4230,"nodeType":881},{},[4231],{"data":4232,"marks":4233,"value":4234,"nodeType":867},{},[],"The outer loop feeds the inner loop, and vice versa.",{"data":4236,"content":4240,"nodeType":890},{"target":4237},{"sys":4238},{"id":4239,"type":887,"linkType":888},"1Jjqll7IIX2QRxN37gjFMH",[],{"data":4242,"content":4243,"nodeType":881},{},[4244],{"data":4245,"marks":4246,"value":4247,"nodeType":867},{},[],"Customers benefit from this approach because it means they:",{"data":4249,"content":4250,"nodeType":3126},{},[4251,4273,4283],{"data":4252,"content":4253,"nodeType":3061},{},[4254],{"data":4255,"content":4256,"nodeType":881},{},[4257,4261,4269],{"data":4258,"marks":4259,"value":4260,"nodeType":867},{},[],"Regularly receive ready-made detections against both known and emerging browser-based threats, without having to write their own detections. (Push also provides the ability to write your own ",{"data":4262,"content":4264,"nodeType":876},{"uri":4263},"/help/audience/engineering/resources/custom-detections",[4265],{"data":4266,"marks":4267,"value":4268,"nodeType":867},{},[],"custom detections",{"data":4270,"marks":4271,"value":4272,"nodeType":867},{},[],", too, for environment-specific use cases.)",{"data":4274,"content":4275,"nodeType":3061},{},[4276],{"data":4277,"content":4278,"nodeType":881},{},[4279],{"data":4280,"marks":4281,"value":4282,"nodeType":867},{},[],"Can configure Push’s response actions based on their security goals and environment. Agents act as the threat-hunting and detection engineering team; Push customers set the thresholds for how they want to respond. For example, customers can use Push controls to block all AiTM phishing attacks (or even carve out exceptions for their own incident responders to be able to visit malicious pages with just a warning), and agents continually feed new indicators into detection logic for that class of attack.",{"data":4284,"content":4285,"nodeType":3061},{},[4286],{"data":4287,"content":4288,"nodeType":881},{},[4289],{"data":4290,"marks":4291,"value":4292,"nodeType":867},{},[],"Get pre-digested and actionable intelligence from every detection, with extremely high fidelity.",{"data":4294,"content":4295,"nodeType":881},{},[4296],{"data":4297,"marks":4298,"value":4299,"nodeType":867},{},[],"This all equates to your own advanced browser threat protection, without requiring the specialized in-house expertise we’ve spent years building.",{"data":4301,"content":4302,"nodeType":881},{},[4303],{"data":4304,"marks":4305,"value":4306,"nodeType":867},{},[],"If you’re a Push customer, you already know that we regularly collaborate with security teams to identify and refine detection use cases, and assist with investigations. In the past few months alone, we’ve worked closely with teams targeted by device code phishing, and InstallFix and ClickFix campaigns, among others. ",{"data":4308,"content":4309,"nodeType":881},{},[4310],{"data":4311,"marks":4312,"value":4313,"nodeType":867},{},[],"If you’re not a customer and are curious about how Push’s agentic threat hunting and detection engineering capabilities can address your use cases, please get in touch.",{"data":4315,"content":4319,"nodeType":890},{"target":4316},{"sys":4317},{"id":4318,"type":887,"linkType":888},"607jrBjlD1vtcbkDfD04DE",[],{"data":4321,"content":4322,"nodeType":908},{},[],{"data":4324,"content":4325,"nodeType":918},{},[4326],{"data":4327,"marks":4328,"value":4330,"nodeType":867},{},[4329],{"type":916},"Learn more",{"data":4332,"content":4333,"nodeType":881},{},[4334],{"data":4335,"marks":4336,"value":1613,"nodeType":867},{},[],{"data":4338,"content":4339,"nodeType":881},{},[4340],{"data":4341,"marks":4342,"value":1620,"nodeType":867},{},[],{"data":4344,"content":4345,"nodeType":881},{},[4346,4349,4356],{"data":4347,"marks":4348,"value":3392,"nodeType":867},{},[],{"data":4350,"content":4352,"nodeType":876},{"uri":4351},"/demo",[4353],{"data":4354,"marks":4355,"value":3399,"nodeType":867},{},[],{"data":4357,"marks":4358,"value":1639,"nodeType":867},{},[],"Can AI replace a threat researcher? What we learned building an agentic threat hunting pipeline","How we built an end-to-end threat hunting and detection engineering capability at Push that uses AI agents as a force multiplier.","2026-05-12T00:00:00.000Z","can-ai-replace-a-threat-researcher-what-we-learned-building-an-agentic-threat-hunting-pipeline",{"items":4364},[4365,4367],{"sys":4366,"name":2547},{"id":2546},{"sys":4368,"name":342},{"id":2550},{"items":4370},[4371],{"fullName":4372,"firstName":4373,"jobTitle":4374,"profilePicture":4375},"Kelly Davenport","Kelly","Product Team",{"url":4376},"https://images.ctfassets.net/y1cdw1ablpvd/1hi8bEuVfn5sF57LivAq6d/9a3b82426c697d765e2e450e33a18424/kelly_profile_pic.jpeg","the-pyramid-of-pain-in-the-ai-era","blog/the-pyramid-of-pain-in-the-ai-era",{"json":4380},{"data":4381,"content":4382,"nodeType":1640},{},[4383],{"data":4384,"content":4385,"nodeType":881},{},[4386],{"data":4387,"marks":4388,"value":4389,"nodeType":867},{},[],"AI is accelerating the collapse of indicator-based threat detection. Technique-level detection is the only layer that holds, and requires both the right vantage point and the research capability to stay ahead.","AI is accelerating the collapse of indicator-based threat detection. Here's why you need technique-level detection to stay ahead.",{"id":4392,"publishedAt":4393},"5RDOpmzJolwT1hk0fNIxzf","2026-08-12T12:00:48.380Z",{"items":4395},[4396,4398],{"sys":4397,"name":342},{"id":2550},{"sys":4399,"name":2547},{"id":2546},{"items":4401},[4402,4404,4406,4408,4410,4412,4414,4416,4418,4420,4422,4424,4426,4428,4430,4432],{"sys":4403,"name":279,"slug":280,"tier":31},{"id":276},{"sys":4405,"name":297,"slug":298,"tier":31},{"id":294},{"sys":4407,"name":342,"slug":343,"tier":31},{"id":339},{"sys":4409,"name":235,"slug":236,"tier":31},{"id":232},{"sys":4411,"name":351,"slug":352,"tier":45},{"id":348},{"sys":4413,"name":244,"slug":245,"tier":45},{"id":241},{"sys":4415,"name":511,"slug":512,"tier":45},{"id":508},{"sys":4417,"name":261,"slug":262,"tier":45},{"id":258},{"sys":4419,"name":315,"slug":316,"tier":45},{"id":312},{"sys":4421,"name":360,"slug":361,"tier":45},{"id":357},{"sys":4423,"name":324,"slug":325,"tier":45},{"id":321},{"sys":4425,"name":440,"slug":441,"tier":45},{"id":437},{"sys":4427,"name":607,"slug":608,"tier":45},{"id":604},{"sys":4429,"name":484,"slug":485,"tier":45},{"id":481},{"sys":4431,"name":475,"slug":476,"tier":45},{"id":472},{"sys":4433,"name":650,"slug":651,"tier":45},{"id":647},"NcSsFyOCgz95lIcDmXKRjEU4Hg-WK6MPMgczrjIO-tI",{"id":4436,"title":4437,"authorsCollection":4438,"content":4446,"extension":228,"faqItemsCollection":5054,"faqTitle":59,"featured":6,"hashTags":59,"meta":5056,"metaTitle":5057,"ogImage":59,"postType":1737,"publishedDate":5058,"relatedBlogPostsCollection":5059,"slug":7162,"stem":7163,"subtitle":59,"summary":7164,"synopsis":7175,"sys":7176,"tagsCollection":7179,"topicsCollection":7185,"__hash__":7235},"blog/blog/verizon-dbir-2026-review.json","What the Verizon DBIR tells us about how breaches happen in 2026",{"items":4439},[4440],{"fullName":4441,"firstName":4442,"jobTitle":4443,"socialLinks":59,"profilePicture":4444},"Mark Orlando","Mark","Field CTO",{"url":4445},"https://images.ctfassets.net/y1cdw1ablpvd/592PMwIQQFaa24k5SKBEKF/a33090d0ad95d1e3081f5d16a46ba826/image__68_.png",{"json":4447,"links":4979},{"data":4448,"content":4449,"nodeType":1640},{},[4450,4457,4460,4468,4484,4491,4498,4504,4512,4519,4526,4532,4549,4554,4570,4578,4594,4601,4608,4611,4619,4635,4641,4660,4666,4674,4698,4705,4708,4716,4723,4729,4736,4755,4763,4779,4782,4790,4806,4813,4820,4839,4842,4850,4857,4864,4871,4877,4885,4901,4908,4926,4929,4937,4944,4951,4957,4963],{"data":4451,"content":4452,"nodeType":881},{},[4453],{"data":4454,"marks":4455,"value":4456,"nodeType":867},{},[],"The headline finding getting the most airtime in 2026 is that vulnerability exploitation has overtaken credential abuse as the top single initial access vector, jumping to 31% from 20% the year before. The vulnerability management crisis driving this statistic is one of the most important stories in this year's data. But reading it as evidence that identity threats are receding would be a mistake, because the DBIR's own data tells a more complicated and more useful story when you look at the full picture.",{"data":4458,"content":4459,"nodeType":908},{},[],{"data":4461,"content":4462,"nodeType":918},{},[4463],{"data":4464,"marks":4465,"value":4467,"nodeType":867},{},[4466],{"type":916},"Vulnerability exploitation has caught up with identity — not replaced it",{"data":4469,"content":4470,"nodeType":881},{},[4471,4475,4480],{"data":4472,"marks":4473,"value":4474,"nodeType":867},{},[],"The DBIR's headline comparison pits vulnerability exploitation (31%) against credential abuse (13%) as individual vectors. That comparison is accurate but incomplete, because the DBIR tracks identity-related initial access across ",{"data":4476,"marks":4477,"value":4479,"nodeType":867},{},[4478],{"type":916},"three",{"data":4481,"marks":4482,"value":4483,"nodeType":867},{},[]," separate categories: phishing (16%), credential abuse (13%), and pretexting (6%). Before interpreting those numbers, there's a methodological wrinkle worth understanding.",{"data":4485,"content":4486,"nodeType":881},{},[4487],{"data":4488,"marks":4489,"value":4490,"nodeType":867},{},[],"This year's report added pretexting as a newly tracked initial access vector, reclassifying some incidents previously counted as credential abuse. The DBIR is transparent about the effect: without that change, credential abuse would have been 16% rather than 13%. On an apples-to-apples basis, identity-related initial access (phishing 16% + credential abuse 16%) comes to 32% — versus 31% for vulnerability exploitation.",{"data":4492,"content":4493,"nodeType":881},{},[4494],{"data":4495,"marks":4496,"value":4497,"nodeType":867},{},[],"To be precise about what moved: phishing held roughly flat year over year, but credential abuse saw a modest decline even on the adjusted basis (from 22% to 16%). Overall, the identity picture is broadly stable. The reason the two categories have converged is that vulnerability exploitation surged 55%, not that identity attacks meaningfully receded.",{"data":4499,"content":4503,"nodeType":890},{"target":4500},{"sys":4501},{"id":4502,"type":887,"linkType":888},"5GvSsSY4R6X34ZBMidZ54X",[],{"data":4505,"content":4506,"nodeType":998},{},[4507],{"data":4508,"marks":4509,"value":4511,"nodeType":867},{},[4510],{"type":916},"The taxonomy gap",{"data":4513,"content":4514,"nodeType":881},{},[4515],{"data":4516,"marks":4517,"value":4518,"nodeType":867},{},[],"It's also worth asking how much the DBIR's initial access taxonomy can tell us. The figure that everyone is citing — Figure 10 — is labelled \"select enumerations,\" and the four tracked vectors (vulnerability exploitation, phishing, credential abuse, pretexting) add up to only 66% of initial access. A third of the picture isn't represented in the headline breakdown at all.",{"data":4520,"content":4521,"nodeType":881},{},[4522],{"data":4523,"marks":4524,"value":4525,"nodeType":867},{},[],"The cluster boundaries and where you draw them also changes the story. The DBIR classifies ClickFix under \"baiting\" — a category that covers malicious downloads and SEO poisoning — rather than phishing, even though the end goal is often the same: getting a user to execute something they shouldn't. Pretexting absorbed incidents that were previously credential abuse, shifting the numbers between categories. These are useful analytical clusters, but they aren't clean divisions of a neatly partitioned attack surface.",{"data":4527,"content":4531,"nodeType":890},{"target":4528},{"sys":4529},{"id":4530,"type":887,"linkType":888},"7t6ZcHDycaPOyLstX4r8zl",[],{"data":4533,"content":4534,"nodeType":881},{},[4535,4539,4546],{"data":4536,"marks":4537,"value":4538,"nodeType":867},{},[],"These are identity attacks at scale, and it isn't clear where — or whether — they show up in the DBIR's initial access vectors. This lack of depth in identity and in-browser attack vectors is common in many defensive models, which is why we've created our own ",{"data":4540,"content":4541,"nodeType":876},{"uri":2613},[4542],{"data":4543,"marks":4544,"value":4545,"nodeType":867},{},[],"Browser and Identity Attacks Matrix",{"data":4547,"marks":4548,"value":1947,"nodeType":867},{},[],{"data":4550,"content":4553,"nodeType":890},{"target":4551},{"sys":4552},{"id":3709,"type":887,"linkType":888},[],{"data":4555,"content":4556,"nodeType":881},{},[4557,4561,4566],{"data":4558,"marks":4559,"value":4560,"nodeType":867},{},[],"That convergence at initial access also understates the role credentials play across full breach chains. The DBIR states plainly that credential abuse at any point in the breach progression — not just as the first action — appears in ",{"data":4562,"marks":4563,"value":4565,"nodeType":867},{},[4564],{"type":916},"39% of all breaches",{"data":4567,"marks":4568,"value":4569,"nodeType":867},{},[],", making it the single most pervasive technique in the dataset. Credentials don't just open the front door; they unlock lateral movement, privilege escalation, and persistence throughout the attack chain.",{"data":4571,"content":4572,"nodeType":998},{},[4573],{"data":4574,"marks":4575,"value":4577,"nodeType":867},{},[4576],{"type":916},"The vulnerability treadmill",{"data":4579,"content":4580,"nodeType":881},{},[4581,4585,4590],{"data":4582,"marks":4583,"value":4584,"nodeType":867},{},[],"The vulnerability exploitation surge itself is driven by a structural capacity crisis rather than a shift in attacker preference. Edge devices and VPNs now account for 22% of vulnerability-exploitation breaches, up from 3% the prior year — a ",{"data":4586,"marks":4587,"value":4589,"nodeType":867},{},[4588],{"type":1431},"sevenfold",{"data":4591,"marks":4592,"value":4593,"nodeType":867},{},[]," increase. Organizations face 50% more CISA KEV vulnerabilities to remediate than a year ago, median remediation time has increased from 32 to 43 days, and the volume of vulnerability records in the dataset has grown roughly eightfold.",{"data":4595,"content":4596,"nodeType":881},{},[4597],{"data":4598,"marks":4599,"value":4600,"nodeType":867},{},[],"This trend was already visible in last year's DBIR, when vulnerability exploitation jumped from 15% to 20%. AI-assisted exploit development may be compounding the problem — the DBIR's own data shows 32% of AI-assisted initial access targeting vulnerability exploitation — but the structural capacity crisis was accelerating well before AI became a meaningful factor in the attacker toolkit.",{"data":4602,"content":4603,"nodeType":881},{},[4604],{"data":4605,"marks":4606,"value":4607,"nodeType":867},{},[],"The vulnerability treadmill is accelerating, and the DBIR's remediation data shows defenders losing ground. But this is an additive problem, not a substitution. Both attack surfaces are growing. ",{"data":4609,"content":4610,"nodeType":908},{},[],{"data":4612,"content":4613,"nodeType":918},{},[4614],{"data":4615,"marks":4616,"value":4618,"nodeType":867},{},[4617],{"type":916},"Phishing has left the inbox",{"data":4620,"content":4621,"nodeType":881},{},[4622,4626,4631],{"data":4623,"marks":4624,"value":4625,"nodeType":867},{},[],"41% percent of social engineering breaches now involve vectors other than email, with approximately a quarter coming from social media or phone-based channels. Voice phishing simulations show a ",{"data":4627,"marks":4628,"value":4630,"nodeType":867},{},[4629],{"type":916},"40% higher success rate",{"data":4632,"marks":4633,"value":4634,"nodeType":867},{},[]," than email phishing — a median click rate of 2% versus 1.4%.",{"data":4636,"content":4640,"nodeType":890},{"target":4637},{"sys":4638},{"id":4639,"type":887,"linkType":888},"7pK8qqIDDNmHmJmlcybNoe",[],{"data":4642,"content":4643,"nodeType":881},{},[4644,4648,4656],{"data":4645,"marks":4646,"value":4647,"nodeType":867},{},[],"Even within the email channel, the data confirms what ",{"data":4649,"content":4651,"nodeType":876},{"uri":4650},"https://pushsecurity.com/blog/the-top-10-security-problems-you-can-solve-in-the-browser-ranked-by-value/",[4652],{"data":4653,"marks":4654,"value":4655,"nodeType":867},{},[],"browser-level detection data has been showing",{"data":4657,"marks":4658,"value":4659,"nodeType":867},{},[],": credential harvesting dominates. The DBIR's email security gateway breakdown shows 80% of blocked attacks are credential or session phishing, with only 10% involving malware delivery, 5% callback phishing, and 3% BEC. If you're running an email security gateway, the vast majority of what it catches is credential phishing — and 41% of social engineering is arriving through channels it can't see at all.",{"data":4661,"content":4665,"nodeType":890},{"target":4662},{"sys":4663},{"id":4664,"type":887,"linkType":888},"6CvwzQA3gJ8B3RFzLrH7Kp",[],{"data":4667,"content":4668,"nodeType":998},{},[4669],{"data":4670,"marks":4671,"value":4673,"nodeType":867},{},[4672],{"type":916},"The ClickFix detection gap",{"data":4675,"content":4676,"nodeType":881},{},[4677,4681,4689,4693],{"data":4678,"marks":4679,"value":4680,"nodeType":867},{},[],"The DBIR reports ClickFix at only 2.7% of attacks detected at the browser level. For context, ",{"data":4682,"content":4684,"nodeType":876},{"uri":4683},"https://pushsecurity.com/blog/introducing-malicious-copy-paste-detection/",[4685],{"data":4686,"marks":4687,"value":4688,"nodeType":867},{},[],"CrowdStrike reported a 563% increase in ClickFix lures",{"data":4690,"marks":4691,"value":4692,"nodeType":867},{},[]," over the same period and Microsoft identified it as the most common initial access point at 47% of observed attacks. Push's own data shows ClickFix at a significantly higher proportion of browser-level detections, ",{"data":4694,"marks":4695,"value":4697,"nodeType":867},{},[4696],{"type":916},"with 4 in 5 delivered via search engines specifically.",{"data":4699,"content":4700,"nodeType":881},{},[4701],{"data":4702,"marks":4703,"value":4704,"nodeType":867},{},[],"The gap is striking, and the most likely explanation is a visibility one. ClickFix attacks result in a malware download or script execution on the endpoint — and without browser-layer context, that execution looks like any other malware delivery. If a contributing organization doesn't have visibility into the browser session that preceded the payload, they'd attribute the incident to \"malware download\" or \"user execution\" rather than ClickFix specifically. The DBIR's 2.7% probably reflects how often contributors could trace the chain back to a ClickFix page, not how often ClickFix was actually the delivery mechanism.",{"data":4706,"content":4707,"nodeType":908},{},[],{"data":4709,"content":4710,"nodeType":918},{},[4711],{"data":4712,"marks":4713,"value":4715,"nodeType":867},{},[4714],{"type":916},"Stolen credentials are the ransomware on-ramp",{"data":4717,"content":4718,"nodeType":881},{},[4719],{"data":4720,"marks":4721,"value":4722,"nodeType":867},{},[],"One of the most powerful findings in this year's DBIR is the quantification of the relationship between credential compromise and ransomware outcomes. Fifty percent of ransomware victims had a credential or infostealer event occur within 95 days prior to the ransomware attack, drawing a causal line from credential theft to ransomware deployment.",{"data":4724,"content":4728,"nodeType":890},{"target":4725},{"sys":4726},{"id":4727,"type":887,"linkType":888},"3ZwG5UiweFR4fYiDaxJJDm",[],{"data":4730,"content":4731,"nodeType":881},{},[4732],{"data":4733,"marks":4734,"value":4735,"nodeType":867},{},[],"The infostealer supply chain data reinforces the picture. Infostealers are surfacing an average of 2,362 breached corporate credentials per month from organizational email domains in stealer log datasets, and 54% of devices in Initial Access Broker logs had at least one infostealer installed. The 95-day median window is consistent with the known timeline from credential harvest to ransomware deployment.",{"data":4737,"content":4738,"nodeType":881},{},[4739,4743,4751],{"data":4740,"marks":4741,"value":4742,"nodeType":867},{},[],"That timeline reinforces an argument we've been making about ",{"data":4744,"content":4746,"nodeType":876},{"uri":4745},"https://pushsecurity.com/blog/the-cisos-data-problem-and-how-browser-telemetry-can-help/",[4747],{"data":4748,"marks":4749,"value":4750,"nodeType":867},{},[],"where the intervention point needs to be",{"data":4752,"marks":4753,"value":4754,"nodeType":867},{},[],": detecting credential compromise upstream — at the point of credential entry, session creation, or stolen credential reuse — rather than waiting for the ransomware deployment that follows weeks or months later.",{"data":4756,"content":4757,"nodeType":998},{},[4758],{"data":4759,"marks":4760,"value":4762,"nodeType":867},{},[4761],{"type":916},"Post-compromise tradecraft is shifting",{"data":4764,"content":4765,"nodeType":881},{},[4766,4770,4775],{"data":4767,"marks":4768,"value":4769,"nodeType":867},{},[],"The DBIR's post-compromise data adds another dimension. RMM tool abuse by threat actors showed a ",{"data":4771,"marks":4772,"value":4774,"nodeType":867},{},[4773],{"type":916},"240% increase",{"data":4776,"marks":4777,"value":4778,"nodeType":867},{},[]," over the prior year, while traditional backdoor and C2 malware usage fell 27%. Attackers are increasingly living off the land with the same remote access tools IT teams use. Post-compromise detection is getting harder, which makes catching the initial credential compromise upstream that much more valuable.",{"data":4780,"content":4781,"nodeType":908},{},[],{"data":4783,"content":4784,"nodeType":918},{},[4785],{"data":4786,"marks":4787,"value":4789,"nodeType":867},{},[4788],{"type":916},"Your vendors are half the problem",{"data":4791,"content":4792,"nodeType":881},{},[4793,4797,4802],{"data":4794,"marks":4795,"value":4796,"nodeType":867},{},[],"Third-party involvement in breaches reached ",{"data":4798,"marks":4799,"value":4801,"nodeType":867},{},[4800],{"type":916},"48%",{"data":4803,"marks":4804,"value":4805,"nodeType":867},{},[]," this year, up from 30% — a 60% increase that follows a prior year where the figure had already doubled.",{"data":4807,"content":4808,"nodeType":881},{},[4809],{"data":4810,"marks":4811,"value":4812,"nodeType":867},{},[],"The DBIR's root cause analysis maps directly to identity security: insecure authentication — absent MFA, improper credential rotation — and lack of least privilege enforcement account for a substantial share of cloud-based third-party incidents. Only 23% of third-party organizations fully remediated missing or improperly secured MFA on cloud accounts, and weak password and permission misconfigurations took a median of 8 months to resolve 50% of findings.",{"data":4814,"content":4815,"nodeType":881},{},[4816],{"data":4817,"marks":4818,"value":4819,"nodeType":867},{},[],"Eight months. That's the median timeline for third-party vendors to resolve the identity hygiene issues that create the attack surface in their environments — environments that your data lives in.",{"data":4821,"content":4822,"nodeType":881},{},[4823,4827,4835],{"data":4824,"marks":4825,"value":4826,"nodeType":867},{},[],"Extend that posture gap across every vendor and third-party integration, and you start to see why the third-party breach figure keeps climbing. Visibility into ",{"data":4828,"content":4830,"nodeType":876},{"uri":4829},"https://pushsecurity.com/blog/unpacking-the-vercel-breach/",[4831],{"data":4832,"marks":4833,"value":4834,"nodeType":867},{},[],"OAuth consent flows and third-party integration sprawl",{"data":4836,"marks":4837,"value":4838,"nodeType":867},{},[]," is the starting point for getting ahead of a supply chain problem that is structurally getting worse.",{"data":4840,"content":4841,"nodeType":908},{},[],{"data":4843,"content":4844,"nodeType":918},{},[4845],{"data":4846,"marks":4847,"value":4849,"nodeType":867},{},[4848],{"type":916},"AI is scaling known techniques — and creating new blind spots from the inside",{"data":4851,"content":4852,"nodeType":881},{},[4853],{"data":4854,"marks":4855,"value":4856,"nodeType":867},{},[],"The DBIR's AI analysis this year is grounded in a collaboration with Anthropic covering 793 threat actors who received enforcement action for violating acceptable use policy between March 2025 and February 2026. The findings are measured rather than alarmist: in the median case, actors sought AI assistance across about 15 distinct ATT&CK techniques, 44% of AI-assisted initial access was phishing-related, and less than 2.5% of techniques observed were classified as rare.",{"data":4858,"content":4859,"nodeType":881},{},[4860],{"data":4861,"marks":4862,"value":4863,"nodeType":867},{},[],"AI is currently an operational tool for attackers — automating and scaling known techniques rather than unlocking novel ones. Despite heavy AI-assisted focus on phishing, the DBIR's own incident dataset shows phishing as an initial access vector has barely changed year over year — suggesting AI may be uplifting less-experienced attackers to a higher baseline of lure quality without meaningfully increasing success rates against organizations that already have detection in place.",{"data":4865,"content":4866,"nodeType":881},{},[4867],{"data":4868,"marks":4869,"value":4870,"nodeType":867},{},[],"The more concerning number is the 32% of AI-assisted initial access targeting vulnerability exploitation — compounding the patching capacity crisis discussed earlier in a trend that was already accelerating before AI entered the picture.",{"data":4872,"content":4876,"nodeType":890},{"target":4873},{"sys":4874},{"id":4875,"type":887,"linkType":888},"4bFTnVx1SXMQzZSaICCJOn",[],{"data":4878,"content":4879,"nodeType":998},{},[4880],{"data":4881,"marks":4882,"value":4884,"nodeType":867},{},[4883],{"type":916},"Shadow AI is the bigger problem",{"data":4886,"content":4887,"nodeType":881},{},[4888,4892,4897],{"data":4889,"marks":4890,"value":4891,"nodeType":867},{},[],"The sharper AI risk for most organizations, though, is internal. Forty-five percent of employees are now regular AI users on corporate devices — up from 15%, a threefold increase — and ",{"data":4893,"marks":4894,"value":4896,"nodeType":867},{},[4895],{"type":916},"67% of them use non-corporate accounts",{"data":4898,"marks":4899,"value":4900,"nodeType":867},{},[],". Shadow AI has become the third most common non-malicious insider action in DLP data, a fourfold increase over the prior year, with source code as the leading data type submitted to unauthorized AI platforms by a wide margin.",{"data":4902,"content":4903,"nodeType":881},{},[4904],{"data":4905,"marks":4906,"value":4907,"nodeType":867},{},[],"The browser extension angle is particularly relevant. More than 15% of users had unauthorized AI browser extensions installed, and the DBIR specifically notes that these extensions collect and retain browsing context from internal sites — creating a data exfiltration pathway that operates independently of traditional DLP controls.",{"data":4909,"content":4910,"nodeType":881},{},[4911,4915,4923],{"data":4912,"marks":4913,"value":4914,"nodeType":867},{},[],"This is moving faster than any previous shadow IT wave, and the data loss vector is the browser — where users interact with AI tools, where extensions collect context, and where OAuth consent grants connect AI services to corporate data. Visibility and control at that layer isn't a nice-to-have for AI governance; ",{"data":4916,"content":4918,"nodeType":876},{"uri":4917},"https://pushsecurity.com/blog/browser-extension-management-guide/",[4919],{"data":4920,"marks":4921,"value":4922,"nodeType":867},{},[],"it's the minimum viable starting point",{"data":4924,"marks":4925,"value":1947,"nodeType":867},{},[],{"data":4927,"content":4928,"nodeType":908},{},[],{"data":4930,"content":4931,"nodeType":918},{},[4932],{"data":4933,"marks":4934,"value":4936,"nodeType":867},{},[4935],{"type":916},"What this means for defenders",{"data":4938,"content":4939,"nodeType":881},{},[4940],{"data":4941,"marks":4942,"value":4943,"nodeType":867},{},[],"The DBIR's 2026 data paints a picture of converging pressures rather than shifting priorities. Vulnerability exploitation surged, but identity-related initial access is broadly stable and credential abuse at 39% across full breach chains remains the single most pervasive technique in the dataset. Phishing is arriving through channels that email gateways can't see. The infostealer-to-ransomware pipeline now has longitudinal data behind it. Third-party involvement keeps climbing because vendor identity hygiene takes months to remediate. And shadow AI is creating data exposure pathways that most security stacks weren't designed to see.",{"data":4945,"content":4946,"nodeType":881},{},[4947],{"data":4948,"marks":4949,"value":4950,"nodeType":867},{},[],"The common thread across all of these findings is that the browser — where credentials are entered, sessions are created, OAuth consent is granted, AI tools are accessed, and extensions collect data — is the layer where these risks converge and where defenders need visibility and control if they're going to address them at the point of risk rather than after the fact.",{"data":4952,"content":4953,"nodeType":881},{},[4954],{"data":4955,"marks":4956,"value":1613,"nodeType":867},{},[],{"data":4958,"content":4959,"nodeType":881},{},[4960],{"data":4961,"marks":4962,"value":1620,"nodeType":867},{},[],{"data":4964,"content":4965,"nodeType":881},{},[4966,4969,4976],{"data":4967,"marks":4968,"value":21,"nodeType":867},{},[],{"data":4970,"content":4971,"nodeType":876},{"uri":1629},[4972],{"data":4973,"marks":4974,"value":2368,"nodeType":867},{},[4975],{"type":1040},{"data":4977,"marks":4978,"value":21,"nodeType":867},{},[],{"entries":4980},{"hyperlink":4981,"inline":4982,"block":4983},[],[],[4984,4990,5016,5023,5037,5042,5049],{"sys":4985,"__typename":1648,"title":4986,"caption":4986,"layoutMode":59,"file":4987},{"id":4502},"DBIR Figure 10 (p.15) — Initial access vectors, select enumerations",{"url":4988,"width":1661,"height":4989},"https://images.ctfassets.net/y1cdw1ablpvd/18rPvZ4Sw11UCHE7MxzXkd/17d059302242b4034686b13ee3044c8e/image4.png",1521,{"sys":4991,"__typename":1696,"content":4992,"name":5015,"title":59},{"id":4530},{"json":4993},{"nodeType":1640,"data":4994,"content":4995},{},[4996],{"nodeType":881,"data":4997,"content":4998},{},[4999,5003,5011],{"nodeType":867,"value":5000,"marks":5001,"data":5002},"Some of the ",[],{},{"nodeType":876,"data":5004,"content":5006},{"uri":5005},"https://pushsecurity.com/blog/analyzing-the-instructure-breach",[5007],{"nodeType":867,"value":5008,"marks":5009,"data":5010},"most consequential identity-based campaigns of the past 12 months",[],{},{"nodeType":867,"value":5012,"marks":5013,"data":5014}," don't map cleanly to any of these categories — the mass Salesforce campaign that compromised over 1,000 organizations via device code phishing, the Anodot breach chain that pivoted through stored OAuth tokens to reach Snowflake customers, ConsentFix abusing Azure CLI's OAuth flow to bypass MFA entirely.",[],{},"DBIR 2026 IB1",{"sys":5017,"__typename":1648,"title":2618,"caption":5018,"layoutMode":59,"file":5019},{"id":3709},"Browser and identity-based techniques have exploded since we first launched our attack matrix",{"url":5020,"width":5021,"height":5022},"https://images.ctfassets.net/y1cdw1ablpvd/L0Yc77y9vzrKVD72BQGX2/4ffe0bf61bd62f025262b8efd74394b7/Browser___Identity_Attacks_Matrix__1_.png",6160,4432,{"sys":5024,"__typename":1696,"content":5025,"name":5036,"title":59},{"id":4639},{"json":5026},{"data":5027,"content":5028,"nodeType":1640},{},[5029],{"data":5030,"content":5031,"nodeType":881},{},[5032],{"data":5033,"marks":5034,"value":5035,"nodeType":867},{},[],"The data is a little confusing. The DBIR draws a line between Phishing (asynchronous — send a message and hope for a click) and Pretexting (synchronous — someone interacting with you in real time). Voice phishing over a phone call is Pretexting in VERIS, not Phishing, even though most practitioners would call it phishing. Browser-based credential harvesting delivered via SEO poisoning or malicious downloads falls under \"Baiting.\" So the 16% phishing figure probably understates the full scope of credential-harvesting social engineering as most defenders would define it.","DBIR IB2",{"sys":5038,"__typename":1648,"title":5039,"caption":5039,"layoutMode":59,"file":5040},{"id":4664},"DBIR Figure 54 (p.49) — Median percentage of email attack types by month",{"url":5041,"width":1661,"height":4989},"https://images.ctfassets.net/y1cdw1ablpvd/4eWtJSz2QhM6QgXXjNuBNs/e6a33a088b7b0fb0dd1649c5d9164b53/image1.png",{"sys":5043,"__typename":1648,"title":5044,"caption":5044,"layoutMode":59,"file":5045},{"id":4727},"DBIR Figure 48 (p.45) — Credential leakage events prior to ransomware",{"url":5046,"width":5047,"height":5048},"https://images.ctfassets.net/y1cdw1ablpvd/26NpMQ31lpHgp5x8FrDumz/f022f1ede66b171dd756d28009a7d4a5/image2.png",1772,776,{"sys":5050,"__typename":1648,"title":5051,"caption":5051,"layoutMode":59,"file":5052},{"id":4875},"DBIR Figure 65 (p.60) — Select data types in DLP events targeting generative AI tools",{"url":5053,"width":1661,"height":4989},"https://images.ctfassets.net/y1cdw1ablpvd/584Txvap6FW9GlFlin9GwB/f5f5488251d9faee7fedc3030d2390b1/image5.png",{"items":5055},[],{},"What the Verizon DBIR tells us about breaches in 2026","2026-05-20T00:00:00.000Z",{"items":5060},[5061,5655,6638],{"__typename":1742,"sys":5062,"content":5064,"title":5638,"synopsis":5639,"hashTags":59,"publishedDate":5640,"slug":5641,"tagsCollection":5642,"authorsCollection":5651},{"id":5063},"217s8zu5idSdX25TUgbPQ1",{"json":5065},{"data":5066,"content":5067,"nodeType":1640},{},[5068,5086,5093,5100,5106,5109,5117,5133,5140,5146,5153,5236,5243,5248,5255,5261,5264,5272,5284,5291,5303,5306,5314,5330,5337,5344,5347,5355,5362,5378,5384,5400,5407,5414,5421,5437,5444,5447,5455,5462,5478,5485,5488,5496,5512,5519,5539,5551,5554,5562,5578,5585,5592,5599,5606,5609,5616,5622],{"data":5069,"content":5070,"nodeType":881},{},[5071,5074,5082],{"data":5072,"marks":5073,"value":3113,"nodeType":867},{},[],{"data":5075,"content":5077,"nodeType":876},{"uri":5076},"https://research.esg-global.com/reportaction/515202191/Marketing",[5078],{"data":5079,"marks":5080,"value":5081,"nodeType":867},{},[],"Omdia Browser Management and Security report",{"data":5083,"marks":5084,"value":5085,"nodeType":867},{},[],", based on a survey of 400 IT and security professionals across North America fielded in late 2025, is the most comprehensive industry data to date on how organizations are experiencing, prioritizing, and investing in the secure enterprise browser (SEB) market. ",{"data":5087,"content":5088,"nodeType":881},{},[5089],{"data":5090,"marks":5091,"value":5092,"nodeType":867},{},[],"For us at Push, it externally validates what we've known to be true for some time — the browser is where work happens, where attacks land, and where defenders need to be if they want to detect and stop threats before damage is done.",{"data":5094,"content":5095,"nodeType":881},{},[5096],{"data":5097,"marks":5098,"value":5099,"nodeType":867},{},[],"We pulled out seven findings that matter most for security teams evaluating their approach.",{"data":5101,"content":5105,"nodeType":890},{"target":5102},{"sys":5103},{"id":5104,"type":887,"linkType":888},"4aM879egIFYmDvOhzyNI9A",[],{"data":5107,"content":5108,"nodeType":908},{},[],{"data":5110,"content":5111,"nodeType":918},{},[5112],{"data":5113,"marks":5114,"value":5116,"nodeType":867},{},[5115],{"type":916},"1. The attacks driving concern are the ones happening inside the browser session",{"data":5118,"content":5119,"nodeType":881},{},[5120,5124,5129],{"data":5121,"marks":5122,"value":5123,"nodeType":867},{},[],"The threat picture is driving everything else in this report, so it's the right place to start. ",{"data":5125,"marks":5126,"value":5128,"nodeType":867},{},[5127],{"type":916},"49% of organizations suffered a successful browser-based attack in the last 12 months.",{"data":5130,"marks":5131,"value":5132,"nodeType":867},{},[]," Among those affected, browser-originated incidents account for roughly 37% of all security incidents — and 68% say that share has grown over the past two years. ",{"data":5134,"content":5135,"nodeType":881},{},[5136],{"data":5137,"marks":5138,"value":5139,"nodeType":867},{},[],"The browser is not an emerging threat vector. It’s worth noting here that these numbers are also likely lower than the reality, since many are only identified later in the kill chain. Without browser-level telemetry they can be difficult to trace back their source — which in the vast majority of cases, even for malware-driven attacks, is the browser. ",{"data":5141,"content":5145,"nodeType":890},{"target":5142},{"sys":5143},{"id":5144,"type":887,"linkType":888},"6Kcz8oILKVHmhQIo5Du6V",[],{"data":5147,"content":5148,"nodeType":881},{},[5149],{"data":5150,"marks":5151,"value":5152,"nodeType":867},{},[],"What stands out is that every one of the top attack categories plays out inside the browser session itself — not against the browser as a piece of software, but within the sessions where users interact with applications:",{"data":5154,"content":5155,"nodeType":3126},{},[5156,5166,5176,5186,5196,5206,5216,5226],{"data":5157,"content":5158,"nodeType":3061},{},[5159],{"data":5160,"content":5161,"nodeType":881},{},[5162],{"data":5163,"marks":5164,"value":5165,"nodeType":867},{},[],"Phishing (40%)",{"data":5167,"content":5168,"nodeType":3061},{},[5169],{"data":5170,"content":5171,"nodeType":881},{},[5172],{"data":5173,"marks":5174,"value":5175,"nodeType":867},{},[],"Data loss or leakage (38%)",{"data":5177,"content":5178,"nodeType":3061},{},[5179],{"data":5180,"content":5181,"nodeType":881},{},[5182],{"data":5183,"marks":5184,"value":5185,"nodeType":867},{},[],"Malicious browser extensions (34%)",{"data":5187,"content":5188,"nodeType":3061},{},[5189],{"data":5190,"content":5191,"nodeType":881},{},[5192],{"data":5193,"marks":5194,"value":5195,"nodeType":867},{},[],"Vulnerable browser extensions (33%)",{"data":5197,"content":5198,"nodeType":3061},{},[5199],{"data":5200,"content":5201,"nodeType":881},{},[5202],{"data":5203,"marks":5204,"value":5205,"nodeType":867},{},[],"Malicious scripts (31%)",{"data":5207,"content":5208,"nodeType":3061},{},[5209],{"data":5210,"content":5211,"nodeType":881},{},[5212],{"data":5213,"marks":5214,"value":5215,"nodeType":867},{},[],"Credential theft via browser (28%)",{"data":5217,"content":5218,"nodeType":3061},{},[5219],{"data":5220,"content":5221,"nodeType":881},{},[5222],{"data":5223,"marks":5224,"value":5225,"nodeType":867},{},[],"Cookie theft (22%)",{"data":5227,"content":5228,"nodeType":3061},{},[5229],{"data":5230,"content":5231,"nodeType":881},{},[5232],{"data":5233,"marks":5234,"value":5235,"nodeType":867},{},[],"AiTM attacks (17%)",{"data":5237,"content":5238,"nodeType":881},{},[5239],{"data":5240,"marks":5241,"value":5242,"nodeType":867},{},[],"Phishing, credential theft, cookie theft, and AiTM are attacks that target the user's interaction with a web page — the credential entry, the session creation, the token exchange. Malicious and vulnerable extensions are supply chain risks that operate inside the browser's own execution environment. Data loss happens through the browser when employees upload files, paste data into AI tools, or share information with unsanctioned applications. ",{"data":5244,"content":5247,"nodeType":890},{"target":5245},{"sys":5246},{"id":2712,"type":887,"linkType":888},[],{"data":5249,"content":5250,"nodeType":881},{},[5251],{"data":5252,"marks":5253,"value":5254,"nodeType":867},{},[],"None of these are attacks where network-layer traffic inspection, endpoint monitoring, or email scanning provides complete coverage, because the attack surface is the browser session itself.",{"data":5256,"content":5260,"nodeType":890},{"target":5257},{"sys":5258},{"id":5259,"type":887,"linkType":888},"5kI5h4Z31ByD73er7voayF",[],{"data":5262,"content":5263,"nodeType":908},{},[],{"data":5265,"content":5266,"nodeType":918},{},[5267],{"data":5268,"marks":5269,"value":5271,"nodeType":867},{},[5270],{"type":916},"2. Browser security is now a board-level priority",{"data":5273,"content":5274,"nodeType":881},{},[5275,5280],{"data":5276,"marks":5277,"value":5279,"nodeType":867},{},[5278],{"type":916},"88% of respondents rank browser security as at least a top-five security priority",{"data":5281,"marks":5282,"value":5283,"nodeType":867},{},[],", with more than a quarter (26%) calling it their single top priority. For context, this is a survey that covers the full spectrum of security concerns — cloud, supply chain, AI, insider risk — and browser security has risen above most of them.",{"data":5285,"content":5286,"nodeType":881},{},[5287],{"data":5288,"marks":5289,"value":5290,"nodeType":867},{},[],"This is not aspirational interest. The correlation between priority level and investment is sharp: among those who rank browser security as their top priority, 72% have significantly increased their investment due to emerging threats. Among those who rank it in their top five, that figure is 26%. The organizations that care most are spending the most.",{"data":5292,"content":5293,"nodeType":881},{},[5294,5299],{"data":5295,"marks":5296,"value":5298,"nodeType":867},{},[5297],{"type":916},"86% of respondents have increased their browser security investment in response to emerging threats",{"data":5300,"marks":5301,"value":5302,"nodeType":867},{},[],", with 36% saying the increase was significant. When you ask what's driving that spend, the answer is the threat landscape: the attacks cataloged in the previous section are the reason budgets are moving.",{"data":5304,"content":5305,"nodeType":908},{},[],{"data":5307,"content":5308,"nodeType":918},{},[5309],{"data":5310,"marks":5311,"value":5313,"nodeType":867},{},[5312],{"type":916},"3. Real budget is being allocated — and it's growing",{"data":5315,"content":5316,"nodeType":881},{},[5317,5321,5326],{"data":5318,"marks":5319,"value":5320,"nodeType":867},{},[],"Secure enterprise browser solutions already take up ",{"data":5322,"marks":5323,"value":5325,"nodeType":867},{},[5324],{"type":916},"12.6% of the average security budget",{"data":5327,"marks":5328,"value":5329,"nodeType":867},{},[]," — a substantial allocation for a category that didn't exist as a standalone line item a few years ago. And 85% of respondents expect to increase that spend over the next 12–24 months, with a quarter expecting significant increases.",{"data":5331,"content":5332,"nodeType":881},{},[5333],{"data":5334,"marks":5335,"value":5336,"nodeType":867},{},[],"Where the money comes from tells its own story. The most common funding model is a discrete line item within security program budgets (31%) or a dedicated secure browsing budget (30%). When organizations pull from an existing program budget, web security (26%) and endpoint security (21%) are the most common sources — while SASE/SSE accounts for just 9%, despite SASE vendors being the second most popular vendor category. That disconnect between vendor preference and budget origin suggests the SASE-bundled buying motion may be more aspirational than operational.",{"data":5338,"content":5339,"nodeType":881},{},[5340],{"data":5341,"marks":5342,"value":5343,"nodeType":867},{},[],"IT operations leadership is the top stakeholder in 82% of evaluations, with CISO and security leadership at 64% and CIOs at 42%. Day-to-day management sits primarily with IT Ops (77%) and SecOps (50%). This dual stakeholder picture — IT operations driving evaluation, security leadership providing strategic direction — shapes the competitive landscape in ways we'll come back to.",{"data":5345,"content":5346,"nodeType":908},{},[],{"data":5348,"content":5349,"nodeType":918},{},[5350],{"data":5351,"marks":5352,"value":5354,"nodeType":867},{},[5353],{"type":916},"4. AI is accelerating both the threat and the use case",{"data":5356,"content":5357,"nodeType":881},{},[5358],{"data":5359,"marks":5360,"value":5361,"nodeType":867},{},[],"AI shows up in this report from two directions, mirroring how it is reshaping the security landscape itself.",{"data":5363,"content":5364,"nodeType":881},{},[5365,5369,5374],{"data":5366,"marks":5367,"value":5368,"nodeType":867},{},[],"On the threat side, ",{"data":5370,"marks":5371,"value":5373,"nodeType":867},{},[5372],{"type":916},"AI-powered targeted phishing and social engineering is the top emerging concern",{"data":5375,"marks":5376,"value":5377,"nodeType":867},{},[],", cited by 75% of respondents as either very concerning or concerning. Data leakage via unsanctioned AI applications comes second at 71%, followed by deepfake/AI-generated malicious content at 69% and credential harvesting via fake AI or SaaS login pages at 66%. Every one of these threat categories involves the browser — AI-enhanced phishing lands in the browser, AI data leakage happens through browser-based AI tools, and fake AI login pages are browser-based credential harvesting.",{"data":5379,"content":5383,"nodeType":890},{"target":5380},{"sys":5381},{"id":5382,"type":887,"linkType":888},"2ajv2i5wn2GzKuyynQGlvq",[],{"data":5385,"content":5386,"nodeType":881},{},[5387,5391,5396],{"data":5388,"marks":5389,"value":5390,"nodeType":867},{},[],"On the adoption side, the picture is almost universal — and almost universally under-governed. ",{"data":5392,"marks":5393,"value":5395,"nodeType":867},{},[5394],{"type":916},"92% of organizations now allow employees to use public GenAI applications",{"data":5397,"marks":5398,"value":5399,"nodeType":867},{},[],", and virtually every organization has some kind of policy position: 37% have sanctioned one public app (with everything else unsanctioned), 39% have sanctioned multiple public apps (with others unsanctioned), and 23% restrict employees to a corporate instance while the public versions are unsanctioned. ",{"data":5401,"content":5402,"nodeType":881},{},[5403],{"data":5404,"marks":5405,"value":5406,"nodeType":867},{},[],"Even the 8% who don't allow GenAI at all have taken a policy position. Essentially 100% of organizations have a GenAI policy — but for the vast majority, that policy designates a large portion of public AI tool usage as unsanctioned, which raises the immediate question of whether they have the tooling to actually enforce it.",{"data":5408,"content":5409,"nodeType":881},{},[5410],{"data":5411,"marks":5412,"value":5413,"nodeType":867},{},[],"The answer, based on the current tooling landscape, appears to be: not quite. When Omdia asked how organizations currently secure GenAI usage, 58% rely on secure web gateways — tools that see traffic metadata but cannot observe what a user actually does inside a GenAI session — while 57% use secure browsing solutions and 57% use SaaS security solutions. ",{"data":5415,"content":5416,"nodeType":881},{},[5417],{"data":5418,"marks":5419,"value":5420,"nodeType":867},{},[],"An SWG can tell you that a user visited ChatGPT, but it cannot tell you whether they pasted your company's source code into the prompt. That distinction — between knowing where data went and knowing what the user actually did — is the fundamental gap that browser-layer visibility exists to close, and it is exactly the gap that makes GenAI policies unenforceable without browser-layer tooling.",{"data":5422,"content":5423,"nodeType":881},{},[5424,5428,5433],{"data":5425,"marks":5426,"value":5427,"nodeType":867},{},[],"The use case data reflects this. When Omdia asked about the most important use cases for a secure browsing solution, ",{"data":5429,"marks":5430,"value":5432,"nodeType":867},{},[5431],{"type":916},"generative AI application security came in first at 59%",{"data":5434,"marks":5435,"value":5436,"nodeType":867},{},[],", followed by data loss prevention at 51% and general web security enhancement at 42%. The feature priorities tell a consistent story: AI-powered threat detection and response (52%) and advanced GenAI usage controls and monitoring (41%) were the top two capabilities organizations said would be most important in a purchase decision. ",{"data":5438,"content":5439,"nodeType":881},{},[5440],{"data":5441,"marks":5442,"value":5443,"nodeType":867},{},[],"AI is both the top threat concern and the top use case for browser security — and it is a browser problem at both ends, because every LLM interaction, every prompt containing sensitive data, and every AI agent authorization happens inside a browser session.",{"data":5445,"content":5446,"nodeType":908},{},[],{"data":5448,"content":5449,"nodeType":918},{},[5450],{"data":5451,"marks":5452,"value":5454,"nodeType":867},{},[5453],{"type":916},"5. Organizations that have deployed secure enterprise browser solutions are seeing real results",{"data":5456,"content":5457,"nodeType":881},{},[5458],{"data":5459,"marks":5460,"value":5461,"nodeType":867},{},[],"One of the most useful sections in Omdia's report is the benefits data — what organizations that have deployed SEB solutions are actually getting out of them.",{"data":5463,"content":5464,"nodeType":881},{},[5465,5469,5474],{"data":5466,"marks":5467,"value":5468,"nodeType":867},{},[],"The top realized benefit is ",{"data":5470,"marks":5471,"value":5473,"nodeType":867},{},[5472],{"type":916},"improved data security, cited by 58% of respondents",{"data":5475,"marks":5476,"value":5477,"nodeType":867},{},[],", followed by fewer security incidents (49%), better visibility and auditing (47%), improved user experience (44%), and simplified configuration and policy management (41%). The picture that emerges is not just a security story but an operational one: organizations are seeing fewer incidents, better visibility, and simpler management alongside the security outcomes.",{"data":5479,"content":5480,"nodeType":881},{},[5481],{"data":5482,"marks":5483,"value":5484,"nodeType":867},{},[],"The 49% who cite fewer security incidents as a realized benefit is the number that matters most here, because it directly connects SEB deployment to measurable risk reduction. Organizations aren't just buying tools and hoping — they're deploying them and seeing fewer successful attacks as a result.",{"data":5486,"content":5487,"nodeType":908},{},[],{"data":5489,"content":5490,"nodeType":918},{},[5491],{"data":5492,"marks":5493,"value":5495,"nodeType":867},{},[5494],{"type":916},"6. The market wants protection in existing browsers, not migration",{"data":5497,"content":5498,"nodeType":881},{},[5499,5503,5508],{"data":5500,"marks":5501,"value":5502,"nodeType":867},{},[],"When Omdia asked what attributes matter most in a secure enterprise browser solution, ",{"data":5504,"marks":5505,"value":5507,"nodeType":867},{},[5506],{"type":916},"\"ability to use existing browsers\" ranked as the fourth most important attribute at 48%",{"data":5509,"marks":5510,"value":5511,"nodeType":867},{},[]," — behind only integration with other security tools (57%), controls over generative AI application usage (53%), and centralized policy enforcement (52%). ",{"data":5513,"content":5514,"nodeType":881},{},[5515],{"data":5516,"marks":5517,"value":5518,"nodeType":867},{},[],"That 48% figure, combined with 80% of respondents saying they expect to use an SEB solution as an integrated or alongside component rather than a replacement for existing tools, points to a clear market preference: organizations want browser security that works with their existing browser estate, not a migration to a new one.",{"data":5520,"content":5521,"nodeType":881},{},[5522,5526,5535],{"data":5523,"marks":5524,"value":5525,"nodeType":867},{},[],"This is consistent with what we hear from security leaders directly. As ",{"data":5527,"content":5529,"nodeType":876},{"uri":5528},"https://pushsecurity.com/customer-stories",[5530],{"data":5531,"marks":5532,"value":5534,"nodeType":867},{},[5533],{"type":1040},"Josh Lemos put it: ",{"data":5536,"marks":5537,"value":5538,"nodeType":867},{},[],"\"We looked at the full-stack enterprise browser approach, but converging on a single platform was tough. Push gave me the security instrumentation and context I needed without onerous headwinds.\" The deployment model matters because it determines adoption velocity — and a tool that requires browser migration introduces friction that delays time to value.",{"data":5540,"content":5541,"nodeType":881},{},[5542,5546],{"data":5543,"marks":5544,"value":5545,"nodeType":867},{},[],"Push was built around this insight from day one. As the secure enterprise browser extension for security teams, Push turns any browser — managed or unmanaged, including agentic browsers — into a telemetry source and control point the moment it's installed. It has been rolled out to 100,000 users in under an hour during normal office hours with zero downtime. ",{"data":5547,"marks":5548,"value":5550,"nodeType":867},{},[5549],{"type":916},"That is a deployment model that matches what Omdia's respondents are asking for.",{"data":5552,"content":5553,"nodeType":908},{},[],{"data":5555,"content":5556,"nodeType":918},{},[5557],{"data":5558,"marks":5559,"value":5561,"nodeType":867},{},[5560],{"type":916},"7. Dedicated vendors lead over platform plays",{"data":5563,"content":5564,"nodeType":881},{},[5565,5569,5574],{"data":5566,"marks":5567,"value":5568,"nodeType":867},{},[],"When Omdia asked which category of vendor organizations primarily use or expect to use for secure enterprise browsing, ",{"data":5570,"marks":5571,"value":5573,"nodeType":867},{},[5572],{"type":916},"36% chose a dedicated SEB vendor",{"data":5575,"marks":5576,"value":5577,"nodeType":867},{},[]," — the largest single category. SASE/network security vendors came second at 29%, followed by traditional VDI/desktop virtualization vendors at 19% and endpoint platform vendors at 15%.",{"data":5579,"content":5580,"nodeType":881},{},[5581],{"data":5582,"marks":5583,"value":5584,"nodeType":867},{},[],"The dedicated category leads, and the reason isn't just first-mover advantage — it's architectural. The alternative paths each come with structural constraints. SASE and SSE platforms are network-centric: they see traffic metadata and enforce URL categorization, but they can't observe the rendered page inside a browser tab — the DOM structure, the script behavior, the credential entry that distinguishes a legitimate login from an AiTM reverse-proxy kit. ",{"data":5586,"content":5587,"nodeType":881},{},[5588],{"data":5589,"marks":5590,"value":5591,"nodeType":867},{},[],"Endpoint platforms that bolt on browser visibility are still anchored to the OS layer, solving for browser exploit prevention rather than in-session behavioral detection of the attacks that actually dominate — phishing, credential theft, session hijacking, extension compromise. And when large platform vendors acquire browser security capabilities, the integration work takes years rather than months, during which detection depth sits in a transitional state. ",{"data":5593,"content":5594,"nodeType":881},{},[5595],{"data":5596,"marks":5597,"value":5598,"nodeType":867},{},[],"Dedicated browser-native vendors start from a different premise entirely: the browser isn't a supplementary signal feeding into someone else's SASE pipeline or XDR correlation engine — it is the telemetry source and the control point. The browser is the only place where you get simultaneous visibility into both the attacker's technique and the employee's action within the same session, because the phishing page, the credential submission, the token exchange, and the data exfiltration all happen inside the same tab. No network appliance, endpoint agent, or identity provider log can see all of that, because none of them are present where the interaction occurs.",{"data":5600,"content":5601,"nodeType":881},{},[5602],{"data":5603,"marks":5604,"value":5605,"nodeType":867},{},[],"For security teams evaluating SEB solutions, the architecture matters more than the vendor category label. The capabilities Omdia's respondents ranked highest — integration with existing tools, GenAI controls, centralized policy enforcement, and the ability to use existing browsers — all point toward solutions that deliver detection depth through a lightweight deployment model, without browser migration and without the integration debt of a platform acquisition.",{"data":5607,"content":5608,"nodeType":908},{},[],{"data":5610,"content":5611,"nodeType":881},{},[5612],{"data":5613,"marks":5614,"value":5615,"nodeType":867},{},[],"Push Security is the most powerful AI-native security tool in the browser. Think EDR, but for the browser — high-fidelity telemetry and real-time control across every session, on every device, with no browser migration required. ",{"data":5617,"content":5618,"nodeType":881},{},[5619],{"data":5620,"marks":5621,"value":1620,"nodeType":867},{},[],{"data":5623,"content":5624,"nodeType":881},{},[5625,5628,5635],{"data":5626,"marks":5627,"value":21,"nodeType":867},{},[],{"data":5629,"content":5630,"nodeType":876},{"uri":1629},[5631],{"data":5632,"marks":5633,"value":1635,"nodeType":867},{},[5634],{"type":1040},{"data":5636,"marks":5637,"value":1639,"nodeType":867},{},[],"7 things Omdia's latest report tells us about the secure enterprise browser market","Unpacking the latest research report from Omdia and what it means for the secure enterprise browser market.","2026-05-13T00:00:00.000Z","7-things-omdias-latest-report-tells-us-about-the-secure-enterprise-browser-market",{"items":5643},[5644,5647],{"sys":5645,"name":297},{"id":5646},"3pjES4THCIfSAwhGdNwBcy",{"sys":5648,"name":5650},{"id":5649},"1gZi8NrRy2v9OqPV7C4dwD","Risk management",{"items":5652},[5653],{"fullName":849,"firstName":850,"jobTitle":851,"profilePicture":5654},{"url":855},{"__typename":1742,"sys":5656,"content":5658,"title":6625,"synopsis":6626,"hashTags":59,"publishedDate":3405,"slug":6627,"tagsCollection":6628,"authorsCollection":6634},{"id":5657},"3jF1fypt08TNlSoWuoMWhj",{"json":5659},{"data":5660,"content":5661,"nodeType":1640},{},[5662,5688,5719,5762,5805,5811,5823,5826,5834,5887,5894,5917,5923,5926,5934,5962,5969,5977,5983,5986,5994,6001,6019,6026,6068,6075,6078,6086,6105,6160,6163,6171,6189,6207,6215,6222,6234,6246,6258,6270,6287,6295,6302,6305,6312,6318,6333,6336,6344,6362,6619],{"data":5663,"content":5664,"nodeType":881},{},[5665,5669,5675,5679,5684],{"data":5666,"marks":5667,"value":5668,"nodeType":867},{},[],"ShinyHunters and the broader SLH (",{"data":5670,"content":5671,"nodeType":876},{"uri":3051},[5672],{"data":5673,"marks":5674,"value":3056,"nodeType":867},{},[],{"data":5676,"marks":5677,"value":5678,"nodeType":867},{},[],") collective have claimed breaches at thousands of organizations over the past twelve months across retail, technology, aviation, financial services, media, gaming, and education, in what amounts to the most sustained data theft and extortion operation in recent cybercrime history. SLH's genealogy traces through a merger of Scattered Spider, Lapsus$, and ShinyHunters, all parts of ",{"data":5680,"marks":5681,"value":5683,"nodeType":867},{},[5682],{"type":916},"the Com",{"data":5685,"marks":5686,"value":5687,"nodeType":867},{},[],", a broader community of English-speaking cybercriminals with international links. ",{"data":5689,"content":5690,"nodeType":881},{},[5691,5695,5703,5707,5715],{"data":5692,"marks":5693,"value":5694,"nodeType":867},{},[],"The confirmed victim list reads like a Fortune 500 directory: Coca-Cola, Cisco, Qantas, Coinbase, ADT, Aflac, SoundCloud, Rockstar Games, Charter Communications, and recently ",{"data":5696,"content":5698,"nodeType":876},{"uri":5697},"https://www.bleepingcomputer.com/news/security/instructure-confirms-data-breach-shinyhunters-claims-attack/",[5699],{"data":5700,"marks":5701,"value":5702,"nodeType":867},{},[],"Instructure",{"data":5704,"marks":5705,"value":5706,"nodeType":867},{},[]," — whose breach ",{"data":5708,"content":5710,"nodeType":876},{"uri":5709},"https://krebsonsecurity.com/2026/05/canvas-breach-disrupts-schools-colleges-nationwide/",[5711],{"data":5712,"marks":5713,"value":5714,"nodeType":867},{},[],"disrupted schools and universities nationwide",{"data":5716,"marks":5717,"value":5718,"nodeType":867},{},[]," during final exams — among dozens more named publicly and likely many more that haven't been (breaches settled quickly behind closed doors don't always make it into the public eye). ShinyHunters alone claimed over 1.5 billion stolen Salesforce records from a single campaign targeting more than 1,000 organizations.",{"data":5720,"content":5721,"nodeType":881},{},[5722,5726,5734,5738,5746,5750,5758],{"data":5723,"marks":5724,"value":5725,"nodeType":867},{},[],"Additional operating clusters, including Cordial Spider and Snarky Spider (which CrowdStrike ",{"data":5727,"content":5729,"nodeType":876},{"uri":5728},"https://cyberscoop.com/crowdstrike-cordial-spider-snarky-spider-extortion-attacks/",[5730],{"data":5731,"marks":5732,"value":5733,"nodeType":867},{},[],"characterizes as the new generation of Scattered Spider",{"data":5735,"marks":5736,"value":5737,"nodeType":867},{},[],") run parallel campaigns against different target sectors, unified not by shared infrastructure but by a shared playbook of techniques that exploit the structural weakness in modern SaaS-first organizations. ",{"data":5739,"content":5741,"nodeType":876},{"uri":5740},"https://github.com/PaloAltoNetworks/Unit42-timely-threat-intel/blob/main/2026-03-12-Vishing-Campaigns-Lead-to-Data-Theft-and-Extortion.txt",[5742],{"data":5743,"marks":5744,"value":5745,"nodeType":867},{},[],"Unit 42 documented",{"data":5747,"marks":5748,"value":5749,"nodeType":867},{},[]," these groups moving from initial compromise to complete data exfiltration in under an hour — faster than most organizations can even begin to respond. Newer groups with links to the SLH ecosystem like CoinbaseCartel have also continued the tradition of weaponizing stolen credentials from the infostealer economy at scale, as ShinyHunters did in the ",{"data":5751,"content":5753,"nodeType":876},{"uri":5752},"https://www.bleepingcomputer.com/news/security/shinyhunters-claims-15-billion-salesforce-records-stolen-in-drift-hacks/",[5754],{"data":5755,"marks":5756,"value":5757,"nodeType":867},{},[],"2024 Snowflake breach",{"data":5759,"marks":5760,"value":5761,"nodeType":867},{},[]," that compromised over 165 customer environments (and claimed another billion-plus records).",{"data":5763,"content":5764,"nodeType":881},{},[5765,5769,5777,5781,5789,5793,5801],{"data":5766,"marks":5767,"value":5768,"nodeType":867},{},[],"Not every SLH breach is browser-based — the Instructure breach (275 million individuals, ~330 school login portals defaced) began with a Salesforce tenant compromise in September 2025, but resurfaced in May 2026 after attackers exploited a ",{"data":5770,"content":5772,"nodeType":876},{"uri":5771},"https://www.bitdefender.com/en-gb/blog/businessinsights/technical-advisory-shinyhunters-breach-instructure-canvas-lms",[5773],{"data":5774,"marks":5775,"value":5776,"nodeType":867},{},[],"vulnerability affecting Canvas's Free-For-Teacher program",{"data":5778,"marks":5779,"value":5780,"nodeType":867},{},[]," (it's now been confirmed that Instructure \"",{"data":5782,"content":5784,"nodeType":876},{"uri":5783},"https://www.instructure.com/incident_update",[5785],{"data":5786,"marks":5787,"value":5788,"nodeType":867},{},[],"reached a settlement",{"data":5790,"marks":5791,"value":5792,"nodeType":867},{},[],"\" for the deletion of the data, and shut down the free account tier), while the Coinbase breach cost ",{"data":5794,"content":5796,"nodeType":876},{"uri":5795},"https://www.bleepingcomputer.com/news/security/coinbase-discloses-breach-faces-up-to-400-million-in-losses/",[5797],{"data":5798,"marks":5799,"value":5800,"nodeType":867},{},[],"$180M–400M through insider bribery",{"data":5802,"marks":5803,"value":5804,"nodeType":867},{},[]," — but these are the exceptions that prove the rule. ",{"data":5806,"content":5810,"nodeType":890},{"target":5807},{"sys":5808},{"id":5809,"type":887,"linkType":888},"4qNrbDyMJIumQfdbh9YVkU",[],{"data":5812,"content":5813,"nodeType":881},{},[5814,5819],{"data":5815,"marks":5816,"value":5818,"nodeType":867},{},[5817],{"type":916},"The vast majority of SLH campaigns over the past year converge on three browser-based attack vectors: vishing combined with AiTM phishing, device code phishing exploiting account authorization flows, and OAuth supply chain attacks through compromised third-party integrators.",{"data":5820,"marks":5821,"value":5822,"nodeType":867},{},[]," Each is well-documented, each has produced confirmed victims at scale, and each is detectable or preventable through browser-layer security controls.",{"data":5824,"content":5825,"nodeType":908},{},[],{"data":5827,"content":5828,"nodeType":918},{},[5829],{"data":5830,"marks":5831,"value":5833,"nodeType":867},{},[5832],{"type":916},"Vector 1: Vishing combined with AiTM phishing",{"data":5835,"content":5836,"nodeType":881},{},[5837,5841,5849,5853,5861,5865,5872,5876,5884],{"data":5838,"marks":5839,"value":5840,"nodeType":867},{},[],"The most visible campaign right now pairs targeted voice calls with adversary-in-the-middle phishing pages — an approach that ",{"data":5842,"content":5844,"nodeType":876},{"uri":5843},"https://cloud.google.com/blog/topics/threat-intelligence/expansion-shinyhunters-saas-data-theft",[5845],{"data":5846,"marks":5847,"value":5848,"nodeType":867},{},[],"Mandiant",{"data":5850,"marks":5851,"value":5852,"nodeType":867},{},[],",",{"data":5854,"content":5856,"nodeType":876},{"uri":5855},"https://www.crowdstrike.com/en-us/blog/defending-against-cordial-spider-and-snarky-spider-with-falcon-shield/",[5857],{"data":5858,"marks":5859,"value":5860,"nodeType":867},{},[]," CrowdStrike",{"data":5862,"marks":5863,"value":5864,"nodeType":867},{},[],", and",{"data":5866,"content":5867,"nodeType":876},{"uri":5740},[5868],{"data":5869,"marks":5870,"value":5871,"nodeType":867},{},[]," Unit 42",{"data":5873,"marks":5874,"value":5875,"nodeType":867},{},[]," have all documented from the incident response side, and which Push has ",{"data":5877,"content":5879,"nodeType":876},{"uri":5878},"https://pushsecurity.com/blog/inside-criminal-phishing-panel/",[5880],{"data":5881,"marks":5882,"value":5883,"nodeType":867},{},[],"documented from inside the attacker's own operator panels",{"data":5885,"marks":5886,"value":1947,"nodeType":867},{},[],{"data":5888,"content":5889,"nodeType":881},{},[5890],{"data":5891,"marks":5892,"value":5893,"nodeType":867},{},[],"An attacker impersonating IT support calls the target employee, establishes urgency — often citing a \"mandatory passkey rollout\" or a \"security compliance update\" — and directs them to a victim-branded AiTM phishing page (typically at a domain like \u003Ccompany>sso.com or \u003Ccompany>internal.com). The attack is processed by a live human in real time, relaying credentials and MFA codes to the legitimate identity provider as they are entered, capturing the resulting session token, and granting the attacker an authenticated session. ",{"data":5895,"content":5896,"nodeType":881},{},[5897,5901,5908,5912],{"data":5898,"marks":5899,"value":5900,"nodeType":867},{},[],"One of the reasons that this method is becoming so widespread is the commoditization of effective tools. Push's ",{"data":5902,"content":5903,"nodeType":876},{"uri":5878},[5904],{"data":5905,"marks":5906,"value":5907,"nodeType":867},{},[],"infiltration of the criminal phishing panels",{"data":5909,"marks":5910,"value":5911,"nodeType":867},{},[]," identified over 400 linked domains across four distinct infrastructure clusters. ",{"data":5913,"marks":5914,"value":5916,"nodeType":867},{},[5915],{"type":916},"This mirrors the pattern that turned AiTM phishing from a specialist capability into an industrialized market with competing PhaaS platforms, but with the added complication that voice phishing as the delivery vector makes the attack invisible to traditional anti-phishing controls at the email layer.",{"data":5918,"content":5922,"nodeType":890},{"target":5919},{"sys":5920},{"id":5921,"type":887,"linkType":888},"1Yhthl0PILGW7EmCcZUrNv",[],{"data":5924,"content":5925,"nodeType":908},{},[],{"data":5927,"content":5928,"nodeType":918},{},[5929],{"data":5930,"marks":5931,"value":5933,"nodeType":867},{},[5932],{"type":916},"Vector 2: Vishing combined with device code phishing",{"data":5935,"content":5936,"nodeType":881},{},[5937,5940,5947,5951,5958],{"data":5938,"marks":5939,"value":3113,"nodeType":867},{},[],{"data":5941,"content":5942,"nodeType":876},{"uri":3074},[5943],{"data":5944,"marks":5945,"value":5946,"nodeType":867},{},[],"ShinyHunters Salesforce campaign",{"data":5948,"marks":5949,"value":5950,"nodeType":867},{},[]," that ran through 2025 and into 2026 used device code phishing as one of its core methods, ",{"data":5952,"content":5953,"nodeType":876},{"uri":5752},[5954],{"data":5955,"marks":5956,"value":5957,"nodeType":867},{},[],"compromising over 1,000 organizations and claiming 1.5 billion stolen records",{"data":5959,"marks":5960,"value":5961,"nodeType":867},{},[]," — including an attempted extortion of Salesforce itself. The attack involved registering an attacker-controlled \"DataLoader\" application mimicking a legitimate Salesforce tool, configuring it to request broad OAuth scopes including full API access and refresh token generation, and guiding victims through the device authorization flow via vishing calls.",{"data":5963,"content":5964,"nodeType":881},{},[5965],{"data":5966,"marks":5967,"value":5968,"nodeType":867},{},[],"Device code phishing exploits the OAuth 2.0 device authorization grant — a flow designed for devices without browsers, like smart TVs, but used in a wide range of scenarios including CLI logins — by tricking users into entering a code on Microsoft's (or another identity provider's) legitimate verification page. Since the victim is usually signed into the app in their browser, there’s no login at all. They simply navigate to the app’s device code login page and enter an attacker-provided code to grant the attacker an access token. ",{"data":5970,"content":5971,"nodeType":881},{},[5972],{"data":5973,"marks":5974,"value":5976,"nodeType":867},{},[5975],{"type":916},"This is what makes device code phishing structurally different from AiTM: it defeats all MFA (including passkeys) because the attack doesn’t target the login, but the authorization layer instead.",{"data":5978,"content":5982,"nodeType":890},{"target":5979},{"sys":5980},{"id":5981,"type":887,"linkType":888},"3ElQz8sLATnR8RY5nVlBGM",[],{"data":5984,"content":5985,"nodeType":908},{},[],{"data":5987,"content":5988,"nodeType":918},{},[5989],{"data":5990,"marks":5991,"value":5993,"nodeType":867},{},[5992],{"type":916},"Vector 3: OAuth supply chain attacks through compromised integrators",{"data":5995,"content":5996,"nodeType":881},{},[5997],{"data":5998,"marks":5999,"value":6000,"nodeType":867},{},[],"The third vector does not require the attacker to phish the victim organization's employees at all. Instead, it exploits the OAuth trust relationships that organizations create when they connect third-party SaaS vendors into their environments — and the consequence is that every organization that authorized one of these integrations effectively extended its security boundary to include the vendor's own security posture.",{"data":6002,"content":6003,"nodeType":881},{},[6004,6007,6015],{"data":6005,"marks":6006,"value":3113,"nodeType":867},{},[],{"data":6008,"content":6010,"nodeType":876},{"uri":6009},"https://cloud.google.com/blog/topics/threat-intelligence/data-theft-salesforce-instances-via-salesloft-drift",[6011],{"data":6012,"marks":6013,"value":6014,"nodeType":867},{},[],"Salesloft/Drift supply chain attack",{"data":6016,"marks":6017,"value":6018,"nodeType":867},{},[]," demonstrated this at scale in 2025: in an extension of the previously mentioned device code phishing campaign, the attacker compromised Salesloft's GitHub environment, used TruffleHog to find secrets, stole Drift OAuth tokens, and used them to access downstream Salesforce environments. The same pattern was later repeated at Gainsight. ",{"data":6020,"content":6021,"nodeType":881},{},[6022],{"data":6023,"marks":6024,"value":6025,"nodeType":867},{},[],"Along with the previously mentioned device code phishing attacks,  more than 1000 organizations were breached. The attackers then harvested AWS keys, Snowflake credentials, and stored passwords from breached Salesforce instances, compounding the access into progressively wider reach.",{"data":6027,"content":6028,"nodeType":881},{},[6029,6033,6041,6045,6053,6057,6064],{"data":6030,"marks":6031,"value":6032,"nodeType":867},{},[],"The same structural pattern has continued into 2026 with the Anodot supply chain compromise, which has produced confirmed breaches at ",{"data":6034,"content":6036,"nodeType":876},{"uri":6035},"https://www.bleepingcomputer.com/news/security/vimeo-data-breach-exposes-personal-information-of-119-000-people/",[6037],{"data":6038,"marks":6039,"value":6040,"nodeType":867},{},[],"Vimeo",{"data":6042,"marks":6043,"value":6044,"nodeType":867},{},[]," (119,000 users), Rockstar Games (78.6 million records), and ",{"data":6046,"content":6048,"nodeType":876},{"uri":6047},"https://www.bleepingcomputer.com/news/security/zara-data-breach-exposed-personal-information-of-197-000-people/",[6049],{"data":6050,"marks":6051,"value":6052,"nodeType":867},{},[],"Zara/Inditex",{"data":6054,"marks":6055,"value":6056,"nodeType":867},{},[]," (197,000 people), with further downstream victims likely still emerging. The ",{"data":6058,"content":6059,"nodeType":876},{"uri":4829},[6060],{"data":6061,"marks":6062,"value":6063,"nodeType":867},{},[],"Vercel breach",{"data":6065,"marks":6066,"value":6067,"nodeType":867},{},[],", which involved compromised OAuth tokens from Context.ai cascading into Google Workspace, also reinforces the same attack pattern (though it was likely not a ShinyHunters operation despite being claimed by someone pretending to be them).",{"data":6069,"content":6070,"nodeType":881},{},[6071],{"data":6072,"marks":6073,"value":6074,"nodeType":867},{},[],"A forgotten SaaS integration can easily become the pivot point for downstream compromise. The moment you authorize a third-party integration, your security boundary extends to include that vendor. If the third-party is compromised, every downstream customer organization with an active integration is exposed.",{"data":6076,"content":6077,"nodeType":908},{},[],{"data":6079,"content":6080,"nodeType":918},{},[6081],{"data":6082,"marks":6083,"value":6085,"nodeType":867},{},[6084],{"type":916},"The infostealer credential playbook sits alongside these attacks",{"data":6087,"content":6088,"nodeType":881},{},[6089,6093,6101],{"data":6090,"marks":6091,"value":6092,"nodeType":867},{},[],"Alongside the three vectors above, ShinyHunters has a track record of exploiting the infostealer credential economy at scale — and it predates any of them. The 2024 Snowflake campaign — 165+ customer environments compromised, over a billion records stolen from AT&T, Ticketmaster, Santander, and Advance Auto Parts among others — was built entirely on infostealer-harvested credentials replayed against MFA-less tenants, with ",{"data":6094,"content":6096,"nodeType":876},{"uri":6095},"https://cloud.google.com/blog/topics/threat-intelligence/unc5537-snowflake-data-theft-extortion",[6097],{"data":6098,"marks":6099,"value":6100,"nodeType":867},{},[],"Mandiant's investigation",{"data":6102,"marks":6103,"value":6104,"nodeType":867},{},[]," finding that 80% of compromised accounts had prior breach exposure in datasets dating back to 2020. The credentials were already circulating in criminal marketplaces; ShinyHunters simply purchased and operationalized them at industrial scale.",{"data":6106,"content":6107,"nodeType":881},{},[6108,6112,6120,6124,6132,6136,6144,6148,6156],{"data":6109,"marks":6110,"value":6111,"nodeType":867},{},[],"The same methodology powered the ",{"data":6113,"content":6115,"nodeType":876},{"uri":6114},"https://pushsecurity.com/blog/why-attackers-are-targeting-jira-with-stolen-credentials/",[6116],{"data":6117,"marks":6118,"value":6119,"nodeType":867},{},[],"HellCat Jira campaign",{"data":6121,"marks":6122,"value":6123,"nodeType":867},{},[]," through 2024–2025, and has now been industrialized as a standalone operation by ",{"data":6125,"content":6127,"nodeType":876},{"uri":6126},"https://www.halcyon.ai/jp/threat-group/coinbasecartel",[6128],{"data":6129,"marks":6130,"value":6131,"nodeType":867},{},[],"CoinbaseCartel",{"data":6133,"marks":6134,"value":6135,"nodeType":867},{},[],", another criminal group reported to be an offshoot of SLH. CoinbaseCartel's model is familiar: purchase old infostealer credentials, use them to access cloud and development environments, exfiltrate data, and demand ransom. ",{"data":6137,"content":6139,"nodeType":876},{"uri":6138},"https://www.infostealers.com/article/inside-the-coinbase-cartel-how-infostealer-credentials-fueled-a-100-company-ransomware-spree/",[6140],{"data":6141,"marks":6142,"value":6143,"nodeType":867},{},[],"Hudson Rock's analysis",{"data":6145,"marks":6146,"value":6147,"nodeType":867},{},[]," of the group's 170+ claimed victims confirms that roughly 80% had prior infostealer infections predating the attacks. The most recent named victim is ",{"data":6149,"content":6151,"nodeType":876},{"uri":6150},"https://www.bleepingcomputer.com/news/security/grafana-says-stolen-github-token-let-hackers-steal-codebase/",[6152],{"data":6153,"marks":6154,"value":6155,"nodeType":867},{},[],"Grafana",{"data":6157,"marks":6158,"value":6159,"nodeType":867},{},[],", where a GitHub token compromised via the TanStack npm supply chain attack and missed during credential rotation was used to download the codebase and attempt extortion. ",{"data":6161,"content":6162,"nodeType":908},{},[],{"data":6164,"content":6165,"nodeType":918},{},[6166],{"data":6167,"marks":6168,"value":6170,"nodeType":867},{},[6169],{"type":916},"These attacks all happen in the browser",{"data":6172,"content":6173,"nodeType":881},{},[6174,6178,6185],{"data":6175,"marks":6176,"value":6177,"nodeType":867},{},[],"Every one of these attack chains is a browser-based attack that either occurs in the browser (AiTM phishing, device code phishing) or could have been prevented at the browser layer (OAuth consent governance). The techniques are interchangeable — the",{"data":6179,"content":6180,"nodeType":876},{"uri":1125},[6181],{"data":6182,"marks":6183,"value":6184,"nodeType":867},{},[]," same criminal kits now offer AiTM and device code phishing side by side",{"data":6186,"marks":6187,"value":6188,"nodeType":867},{},[],", and the same threat actor (ShinyHunters) has used all three vectors across different campaigns within the same twelve-month period.",{"data":6190,"content":6191,"nodeType":881},{},[6192,6196,6203],{"data":6193,"marks":6194,"value":6195,"nodeType":867},{},[],"Additionally, infostealer infections themselves are increasingly delivered through browser-based methods like ",{"data":6197,"content":6199,"nodeType":876},{"uri":6198},"https://pushsecurity.com/blog/introducing-malicious-copy-paste-detection",[6200],{"data":6201,"marks":6202,"value":315,"nodeType":867},{},[],{"data":6204,"marks":6205,"value":6206,"nodeType":867},{},[],", closing the loop between the credential supply side and the browser-layer detection point.",{"data":6208,"content":6209,"nodeType":998},{},[6210],{"data":6211,"marks":6212,"value":6214,"nodeType":867},{},[6213],{"type":916},"How Push can help",{"data":6216,"content":6217,"nodeType":881},{},[6218],{"data":6219,"marks":6220,"value":6221,"nodeType":867},{},[],"Push operates at the exact point in each of these attack chains where automated intervention can still prevent the compromise. ",{"data":6223,"content":6224,"nodeType":881},{},[6225,6230],{"data":6226,"marks":6227,"value":6229,"nodeType":867},{},[6228],{"type":916},"For vishing + AiTM attacks, ",{"data":6231,"marks":6232,"value":6233,"nodeType":867},{},[],"Push's behavioral phishing detection analyzes and blocks the phishing page in real time by detecting it from the user's browser — regardless of the domains used, hosting infrastructure, or where the URL was delivered.  ",{"data":6235,"content":6236,"nodeType":881},{},[6237,6242],{"data":6238,"marks":6239,"value":6241,"nodeType":867},{},[6240],{"type":916},"For device code phishing,",{"data":6243,"marks":6244,"value":6245,"nodeType":867},{},[]," Push detects the phishing pages associated with device code phishing kits — including generic, technique-class detections that catch new kits without requiring kit-specific signatures. Second, Push provides an additional layer of protection on the legitimate device code authentication pages themselves, preventing users from entering attacker-supplied codes into them. Together, these detections cover both the kit-operated phishing infrastructure and the legitimate auth pages that the attack flow depends on.",{"data":6247,"content":6248,"nodeType":881},{},[6249,6254],{"data":6250,"marks":6251,"value":6253,"nodeType":867},{},[6252],{"type":916},"For OAuth supply chain attacks,",{"data":6255,"marks":6256,"value":6257,"nodeType":867},{},[]," Push's detects and controls OAuth consent flows at the browser layer — capturing which application is requesting access, what scopes it's requesting, and whether the grant should be permitted under organizational policy. Push customers can also block OAuth connection requests as they transit the browser, enabling security teams to stop unwanted integrations being added in the first place. ",{"data":6259,"content":6260,"nodeType":881},{},[6261,6266],{"data":6262,"marks":6263,"value":6265,"nodeType":867},{},[6264],{"type":916},"For the infostealer credential playbook,",{"data":6267,"marks":6268,"value":6269,"nodeType":867},{},[]," Push's stolen credential detection identifies when employees are using credentials that have appeared in breach datasets or dark web feeds — catching the moment a dormant infostealer credential surfaces at a browser-based login, as well as surfacing insecure login methods missing mitigating controls like MFA and enforcing them through in-browser guardrails. And on the supply side, Push's ClickFix detection addresses the browser-based delivery vector that is now the primary method for distributing infostealer malware in the first place.",{"data":6271,"content":6272,"nodeType":881},{},[6273,6276,6284],{"data":6274,"marks":6275,"value":21,"nodeType":867},{},[],{"data":6277,"content":6279,"nodeType":876},{"uri":6278},"https://pushsecurity.com/blog/guide-how-to-use-push-controls-to-protect-your-users-from-modern-attacks/",[6280],{"data":6281,"marks":6282,"value":6283,"nodeType":867},{},[],"Learn more about how you can use Push controls to protect your users from in-browser threats here. ",{"data":6285,"marks":6286,"value":21,"nodeType":867},{},[],{"data":6288,"content":6289,"nodeType":998},{},[6290],{"data":6291,"marks":6292,"value":6294,"nodeType":867},{},[6293],{"type":916},"Closing thoughts",{"data":6296,"content":6297,"nodeType":881},{},[6298],{"data":6299,"marks":6300,"value":6301,"nodeType":867},{},[],"The campaigns documented in this post are not historical — they are ongoing, with new victims surfacing weekly and the underlying criminal infrastructure still actively developing. But the defensive strategy does not require anticipating which specific group, vector, or target sector comes next, because all of them converge on the same control point: the browser, where the attack begins or the integration decision is made. Organizations with browser-layer detection and OAuth governance in place have defense-in-depth against the full range of techniques these groups employ, regardless of which specific vector any given campaign uses.",{"data":6303,"content":6304,"nodeType":908},{},[],{"data":6306,"content":6307,"nodeType":881},{},[6308],{"data":6309,"marks":6310,"value":6311,"nodeType":867},{},[],"Push Security is the most powerful AI-native security tool in the browser. Think EDR, but for the browser — high-fidelity telemetry and real-time control across every session, on every device, with no browser migration required. ",{"data":6313,"content":6314,"nodeType":881},{},[6315],{"data":6316,"marks":6317,"value":1620,"nodeType":867},{},[],{"data":6319,"content":6320,"nodeType":881},{},[6321,6324,6330],{"data":6322,"marks":6323,"value":21,"nodeType":867},{},[],{"data":6325,"content":6326,"nodeType":876},{"uri":2362},[6327],{"data":6328,"marks":6329,"value":2368,"nodeType":867},{},[],{"data":6331,"marks":6332,"value":21,"nodeType":867},{},[],{"data":6334,"content":6335,"nodeType":908},{},[],{"data":6337,"content":6338,"nodeType":918},{},[6339],{"data":6340,"marks":6341,"value":6343,"nodeType":867},{},[6342],{"type":916},"Appendix: named ShinyHunters victims since May 2025",{"data":6345,"content":6346,"nodeType":881},{},[6347,6351,6358],{"data":6348,"marks":6349,"value":6350,"nodeType":867},{},[],"To give an indication of the scale, the following table documents all publicly named victims attributed to ShinyHunters specifically since the Salesforce campaign began in May 2025. It is not exhaustive: ShinyHunters has claimed over 1,000 organizations in aggregate across its Salesforce campaigns alone, and many victims have not been publicly named. This list also doesn’t include the billion-plus records compromised in the 2024 Snowflake breaches. The major ransomware attacks executed against M&S, Co-op, and Jaguar Land Rover claimed by the ",{"data":6352,"content":6353,"nodeType":876},{"uri":3051},[6354],{"data":6355,"marks":6356,"value":6357,"nodeType":867},{},[],"Scattered Lapsus$ Hunters \"brand\"",{"data":6359,"marks":6360,"value":6361,"nodeType":867},{},[]," also aren't listed below. ",{"data":6363,"content":6364,"nodeType":2531},{},[6365,6412,6476,6524,6572],{"data":6366,"content":6367,"nodeType":2438},{},[6368,6379,6390,6401],{"data":6369,"content":6370,"nodeType":2452},{},[6371],{"data":6372,"content":6373,"nodeType":881},{},[6374],{"data":6375,"marks":6376,"value":6378,"nodeType":867},{},[6377],{"type":916},"Campaign",{"data":6380,"content":6381,"nodeType":2452},{},[6382],{"data":6383,"content":6384,"nodeType":881},{},[6385],{"data":6386,"marks":6387,"value":6389,"nodeType":867},{},[6388],{"type":916},"Began",{"data":6391,"content":6392,"nodeType":2452},{},[6393],{"data":6394,"content":6395,"nodeType":881},{},[6396],{"data":6397,"marks":6398,"value":6400,"nodeType":867},{},[6399],{"type":916},"Named victims",{"data":6402,"content":6403,"nodeType":2452},{},[6404],{"data":6405,"content":6406,"nodeType":881},{},[6407],{"data":6408,"marks":6409,"value":6411,"nodeType":867},{},[6410],{"type":916},"Confirmed impact",{"data":6413,"content":6414,"nodeType":2438},{},[6415,6439,6449,6459],{"data":6416,"content":6417,"nodeType":2452},{},[6418],{"data":6419,"content":6420,"nodeType":881},{},[6421,6426,6430,6435],{"data":6422,"marks":6423,"value":6425,"nodeType":867},{},[6424],{"type":916},"ShinyHunters Salesforce Vishing",{"data":6427,"marks":6428,"value":6429,"nodeType":867},{},[]," (vishing + device code phishing → Salesforce connected app authorization) \n\n& ",{"data":6431,"marks":6432,"value":6434,"nodeType":867},{},[6433],{"type":916},"Salesloft/Drift Supply Chain",{"data":6436,"marks":6437,"value":6438,"nodeType":867},{},[]," (stolen OAuth tokens → downstream Salesforce access)",{"data":6440,"content":6441,"nodeType":2452},{},[6442],{"data":6443,"content":6444,"nodeType":881},{},[6445],{"data":6446,"marks":6447,"value":6448,"nodeType":867},{},[],"May 2025",{"data":6450,"content":6451,"nodeType":2452},{},[6452],{"data":6453,"content":6454,"nodeType":881},{},[6455],{"data":6456,"marks":6457,"value":6458,"nodeType":867},{},[],"Coca-Cola Europacific Partners, Cisco, Qantas, LVMH, Adidas, Google, Chanel, Pandora, Allianz Life, Air France-KLM, Farmers Insurance, Workday, TransUnion, Stellantis, Kering, Odido, Hallmark, Salesloft (origin), Toast, Avalara, Fastly, Cato Networks, Cloudflare, Palo Alto Networks, Zscaler, Tenable, Elastic, JFrog, CyberArk, Rubrik, BeyondTrust, Proofpoint, Workiva, Mercer Advisors, Beacon Pointe, Ameriprise, Kemper, Udemy, 7-Eleven, Mytheresa, Marcus & Millichap, Carnival, Pitney Bowes, Alert 360, Amtrak, McGraw-Hill, Canada Life, Charter Communications",{"data":6460,"content":6461,"nodeType":2452},{},[6462,6469],{"data":6463,"content":6464,"nodeType":881},{},[6465],{"data":6466,"marks":6467,"value":6468,"nodeType":867},{},[],"49 named victims. Confirmed individual impact includes 23M+ records (Coca-Cola), 5.7M records (Qantas), 6.2M customers (Odido), 4.4M consumers (TransUnion), up to 18M records (Stellantis), 13.5M emails (McGraw-Hill), 8.2M emails (Pitney Bowes), 7.5M emails (Carnival), 7-Eleven: 185K confirmed by HIBP (SSNs, driver's licenses; franchisee data), Charter Communications: millions of records claimed (company disputes scope). ",{"data":6470,"content":6471,"nodeType":881},{},[6472],{"data":6473,"marks":6474,"value":6475,"nodeType":867},{},[],"ShinyHunters claims 1.5B+ Salesforce records across 1,000+ organizations total.",{"data":6477,"content":6478,"nodeType":2438},{},[6479,6494,6504,6514],{"data":6480,"content":6481,"nodeType":2452},{},[6482],{"data":6483,"content":6484,"nodeType":881},{},[6485,6490],{"data":6486,"marks":6487,"value":6489,"nodeType":867},{},[6488],{"type":916},"Vishing + AiTM SSO",{"data":6491,"marks":6492,"value":6493,"nodeType":867},{},[]," (vishing → AiTM phishing page → SSO session capture → SaaS data exfiltration)",{"data":6495,"content":6496,"nodeType":2452},{},[6497],{"data":6498,"content":6499,"nodeType":881},{},[6500],{"data":6501,"marks":6502,"value":6503,"nodeType":867},{},[],"Aug 2025",{"data":6505,"content":6506,"nodeType":2452},{},[6507],{"data":6508,"content":6509,"nodeType":881},{},[6510],{"data":6511,"marks":6512,"value":6513,"nodeType":867},{},[],"SoundCloud, GrubHub, Panera Bread, Match Group, Crunchbase, Betterment, CarMax, Edmunds, CarGurus, Hims & Hers, University of Pennsylvania, Harvard University, Optimizely, TELUS Digital, Crunchyroll, ADT",{"data":6515,"content":6516,"nodeType":2452},{},[6517],{"data":6518,"content":6519,"nodeType":881},{},[6520],{"data":6521,"marks":6522,"value":6523,"nodeType":867},{},[],"16 named victims. Confirmed individual impact includes ~30M records (SoundCloud), ~14M records (Panera), 10M+ records (Match Group), ~20M records (Betterment), 5.5M people (ADT), 1M+ records (UPenn), ~1PB stolen from TELUS Digital ($65M ransom refused).",{"data":6525,"content":6526,"nodeType":2438},{},[6527,6542,6552,6562],{"data":6528,"content":6529,"nodeType":2452},{},[6530],{"data":6531,"content":6532,"nodeType":881},{},[6533,6538],{"data":6534,"marks":6535,"value":6537,"nodeType":867},{},[6536],{"type":916},"Anodot Supply Chain",{"data":6539,"marks":6540,"value":6541,"nodeType":867},{},[]," (stolen OAuth tokens → downstream Snowflake/BigQuery access)",{"data":6543,"content":6544,"nodeType":2452},{},[6545],{"data":6546,"content":6547,"nodeType":881},{},[6548],{"data":6549,"marks":6550,"value":6551,"nodeType":867},{},[],"Apr 2026",{"data":6553,"content":6554,"nodeType":2452},{},[6555],{"data":6556,"content":6557,"nodeType":881},{},[6558],{"data":6559,"marks":6560,"value":6561,"nodeType":867},{},[],"Anodot/Glassbox (origin), Rockstar Games, Vimeo, Zara/Inditex",{"data":6563,"content":6564,"nodeType":2452},{},[6565],{"data":6566,"content":6567,"nodeType":881},{},[6568],{"data":6569,"marks":6570,"value":6571,"nodeType":867},{},[],"4 named victims (12+ total claimed). 78.6M records (Rockstar Games), 197K individuals (Zara), 119K individuals (Vimeo).",{"data":6573,"content":6574,"nodeType":2438},{},[6575,6590,6599,6609],{"data":6576,"content":6577,"nodeType":2452},{},[6578],{"data":6579,"content":6580,"nodeType":881},{},[6581,6586],{"data":6582,"marks":6583,"value":6585,"nodeType":867},{},[6584],{"type":916},"Other SLH-attributed",{"data":6587,"marks":6588,"value":6589,"nodeType":867},{},[]," (misc. vectors including infostealer chains, CI/CD supply chain, SaaS platform compromise)",{"data":6591,"content":6592,"nodeType":2452},{},[6593],{"data":6594,"content":6595,"nodeType":881},{},[6596],{"data":6597,"marks":6598,"value":6448,"nodeType":867},{},[],{"data":6600,"content":6601,"nodeType":2452},{},[6602],{"data":6603,"content":6604,"nodeType":881},{},[6605],{"data":6606,"marks":6607,"value":6608,"nodeType":867},{},[],"UK Legal Aid Agency, Mixpanel, Wynn Resorts, Woflow, Vercel, European Commission, Mercor, Medtronic, Instructure",{"data":6610,"content":6611,"nodeType":2452},{},[6612],{"data":6613,"content":6614,"nodeType":881},{},[6615],{"data":6616,"marks":6617,"value":6618,"nodeType":867},{},[],"10 named victims across varied vectors. Notable: Vercel (Lumma Stealer → Context.ai OAuth app → Google Workspace), European Commission (poisoned Trivy GitHub Action → 340GB across 71 EU entities)",{"data":6620,"content":6621,"nodeType":881},{},[6622],{"data":6623,"marks":6624,"value":21,"nodeType":867},{},[],"The three attack techniques behind ShinyHunters' 2026 campaigns ","ShinyHunters' breach of Instructure is the latest in a long series of attacks. Here's our view of the big picture. ","analyzing-the-instructure-breach",{"items":6629},[6630,6632],{"sys":6631,"name":2547},{"id":2546},{"sys":6633,"name":342},{"id":2550},{"items":6635},[6636],{"fullName":849,"firstName":850,"jobTitle":851,"profilePicture":6637},{"url":855},{"__typename":1742,"sys":6639,"content":6641,"title":7148,"synopsis":7149,"hashTags":59,"publishedDate":7150,"slug":7151,"tagsCollection":7152,"authorsCollection":7158},{"id":6640},"2MWicW07sNEBp59wxYtAiC",{"json":6642},{"data":6643,"content":6644,"nodeType":1640},{},[6645,6653,6684,6690,6697,6716,6731,6734,6742,6757,6777,6802,6808,6824,6854,6860,6866,6882,6885,6893,6900,6908,6926,6942,6949,6974,6981,6989,7018,7025,7033,7040,7046,7049,7057,7064,7072,7078,7081,7089,7096,7103,7110,7122,7125,7131],{"data":6646,"content":6647,"nodeType":918},{},[6648],{"data":6649,"marks":6650,"value":6652,"nodeType":867},{},[6651],{"type":916},"The quantification problem nobody talks about",{"data":6654,"content":6655,"nodeType":881},{},[6656,6660,6668,6672,6680],{"data":6657,"marks":6658,"value":6659,"nodeType":867},{},[],"I was recently teaching ",{"data":6661,"content":6663,"nodeType":876},{"uri":6662},"https://www.sans.org/cyber-security-courses/cybersecurity-leaders/",[6664],{"data":6665,"marks":6666,"value":6667,"nodeType":867},{},[],"SANS LDR551",{"data":6669,"marks":6670,"value":6671,"nodeType":867},{},[],", where we cover some of the flawed approaches used in risk measurement and prioritization — for example, presenting ordinal data in a risk matrix as ratio data, implying that the matrix represents quantitative analysis when it’s more of a best guess. We then look at modeling using ",{"data":6673,"content":6675,"nodeType":876},{"uri":6674},"https://en.wikipedia.org/wiki/Loss_exceedance_curve",[6676],{"data":6677,"marks":6678,"value":6679,"nodeType":867},{},[],"Loss Exceedance Curves",{"data":6681,"marks":6682,"value":6683,"nodeType":867},{},[]," as a more accurate, if much more difficult, approach to quantitative risk assessment.",{"data":6685,"content":6689,"nodeType":890},{"target":6686},{"sys":6687},{"id":6688,"type":887,"linkType":888},"4S1wJUm6E1qvyZzwrl2DL",[],{"data":6691,"content":6692,"nodeType":881},{},[6693],{"data":6694,"marks":6695,"value":6696,"nodeType":867},{},[],"The only problem is, we rarely have the time or the data to construct such models. Ask a CISO how they measure risk for credential compromise and other account takeover attacks, and the answer will probably include one or more of the following: a risk assessment, a whiteboard, and a room full of smart people making educated guesses about attack frequency and control strength. ",{"data":6698,"content":6699,"nodeType":881},{},[6700,6704,6712],{"data":6701,"marks":6702,"value":6703,"nodeType":867},{},[],"That isn't a criticism — for most risk scenarios, expert elicitation is the best (and most convenient) available method. Breach cost data is sparse, threat actor behavior is unpredictable, and internal incident history is (ideally!) a limited sample. Quantitative risk frameworks like ",{"data":6705,"content":6707,"nodeType":876},{"uri":6706},"https://www.fairinstitute.org/",[6708],{"data":6709,"marks":6710,"value":6711,"nodeType":867},{},[],"FAIR",{"data":6713,"marks":6714,"value":6715,"nodeType":867},{},[]," give structure to that uncertainty, but they can't conjure data that just doesn't exist.",{"data":6717,"content":6718,"nodeType":881},{},[6719,6723,6728],{"data":6720,"marks":6721,"value":6722,"nodeType":867},{},[],"The results are usually estimates with wide confidence intervals and loss distributions that appear precise, but are hard to defend to a CFO or a board. Finance leaders have seen Monte Carlo simulations before; the capable ones will challenge the quality of the outputs if they doubt the quality of the inputs. ",{"data":6724,"marks":6725,"value":6727,"nodeType":867},{},[6726],{"type":916},"But with the right telemetry, we can get both",{"data":6729,"marks":6730,"value":1947,"nodeType":867},{},[],{"data":6732,"content":6733,"nodeType":908},{},[],{"data":6735,"content":6736,"nodeType":918},{},[6737],{"data":6738,"marks":6739,"value":6741,"nodeType":867},{},[6740],{"type":916},"Why the identity attack surface is uniquely measurable",{"data":6743,"content":6744,"nodeType":881},{},[6745,6749,6754],{"data":6746,"marks":6747,"value":6748,"nodeType":867},{},[],"We've written extensively about the shift to identity as a primary attack vector — and the evidence continues to stack up. Credential phishing, device code phishing, ClickFix, adversary-in-the-middle attacks, session hijacking, and SaaS account compromise now account for the majority of breach entry points in most enterprise environments. But the silver lining here is that this shift has created something valuable for risk quantification: ",{"data":6750,"marks":6751,"value":6753,"nodeType":867},{},[6752],{"type":1431},"a highly observable threat surface",{"data":6755,"marks":6756,"value":1947,"nodeType":867},{},[],{"data":6758,"content":6759,"nodeType":881},{},[6760,6764,6773],{"data":6761,"marks":6762,"value":6763,"nodeType":867},{},[],"Identity attacks execute ",{"data":6765,"content":6767,"nodeType":876},{"uri":6766},"https://pushsecurity.com/blog/introducing-the-browser-and-identity-attacks-matrix/",[6768],{"data":6769,"marks":6770,"value":6772,"nodeType":867},{},[6771],{"type":1040},"in the browser",{"data":6774,"marks":6775,"value":6776,"nodeType":867},{},[],". They leave traces in authentication flows, login behaviors, OAuth integrations, extension activity, and SaaS access patterns — all of which are captured in real time by the Push extension. Unlike network or endpoint attacks, where the signal is often binary and retroactive, browser-based identity threats generate continuous, high-frequency telemetry that maps directly onto the inputs that drive quantitative risk models.",{"data":6778,"content":6779,"nodeType":881},{},[6780,6784,6789,6793,6798],{"data":6781,"marks":6782,"value":6783,"nodeType":867},{},[],"This telemetry directly informs the hardest inputs in any quantitative risk model. One is ",{"data":6785,"marks":6786,"value":6788,"nodeType":867},{},[6787],{"type":916},"Threat Event Frequency (TEF)",{"data":6790,"marks":6791,"value":6792,"nodeType":867},{},[],": how often a threat agent acts against an asset in a given period. For identity risks, this can be answered in how many credential phishing attempts reached your users across all delivery channels (social media, email, malvertising, etc.), or how frequently your users authorize malicious or compromised SaaS apps. Browser-level telemetry can answer these questions with ",{"data":6794,"marks":6795,"value":6797,"nodeType":867},{},[6796],{"type":1431},"observed",{"data":6799,"marks":6800,"value":6801,"nodeType":867},{},[]," data rather than industry lookups and general benchmarks. ",{"data":6803,"content":6807,"nodeType":890},{"target":6804},{"sys":6805},{"id":6806,"type":887,"linkType":888},"EvjT68MCWW7nz5q86xe8S",[],{"data":6809,"content":6810,"nodeType":881},{},[6811,6815,6820],{"data":6812,"marks":6813,"value":6814,"nodeType":867},{},[],"The other input to risk modeling that's difficult to express in concrete terms is ",{"data":6816,"marks":6817,"value":6819,"nodeType":867},{},[6818],{"type":916},"vulnerability",{"data":6821,"marks":6822,"value":6823,"nodeType":867},{},[],": the probability a threat becomes a loss event or, more specifically, how likely it is that your controls will fail. ",{"data":6825,"content":6826,"nodeType":881},{},[6827,6831,6839,6843,6851],{"data":6828,"marks":6829,"value":6830,"nodeType":867},{},[],"This is where browser telemetry gets especially concrete. ",{"data":6832,"content":6834,"nodeType":876},{"uri":6833},"https://pushsecurity.com/blog/how-many-vulnerable-identities-do-you-have/",[6835],{"data":6836,"marks":6837,"value":6838,"nodeType":867},{},[],"Analysis of login telemetry across Push-monitored environments",{"data":6840,"marks":6841,"value":6842,"nodeType":867},{},[]," shows that 1 in 4 logins are still password-only (not SSO), 2 in 5 are not protected by MFA, and 1 in 5 use a weak, breached, or reused password. Many of these logins occur outside the visibility of a central IdP platform like Microsoft, Google or Okta — the result of downstream ",{"data":6844,"content":6846,"nodeType":876},{"uri":6845},"https://pushsecurity.com/blog/ghost-logins-when-forgotten-identities-come-back-to-haunt-you/",[6847],{"data":6848,"marks":6849,"value":6850,"nodeType":867},{},[],"ghost logins",{"data":6852,"marks":6853,"value":1253,"nodeType":867},{},[],{"data":6855,"content":6859,"nodeType":890},{"target":6856},{"sys":6857},{"id":6858,"type":887,"linkType":888},"5GctExdVGjHRwKifiP00Fp",[],{"data":6861,"content":6865,"nodeType":890},{"target":6862},{"sys":6863},{"id":6864,"type":887,"linkType":888},"2mWToHCJcuB9FMwxxzd67F",[],{"data":6867,"content":6868,"nodeType":881},{},[6869,6873,6878],{"data":6870,"marks":6871,"value":6872,"nodeType":867},{},[],"In a FAIR-based model, TEF and vulnerability together determine ",{"data":6874,"marks":6875,"value":6877,"nodeType":867},{},[6876],{"type":916},"loss event frequency",{"data":6879,"marks":6880,"value":6881,"nodeType":867},{},[],": the foundational driver of the entire risk calculation. Using telemetry from your own environment as the basis for these calculations makes them far more accurate, and more likely to stand up to scrutiny.",{"data":6883,"content":6884,"nodeType":908},{},[],{"data":6886,"content":6887,"nodeType":918},{},[6888],{"data":6889,"marks":6890,"value":6892,"nodeType":867},{},[6891],{"type":916},"The attack surface is bigger than most models assume",{"data":6894,"content":6895,"nodeType":881},{},[6896],{"data":6897,"marks":6898,"value":6899,"nodeType":867},{},[],"One of the consistent failures in identity risk modeling is the tendency to model risks defenders can see, and leave the rest off the balance sheet. These omissions create a systematic understatement of exposure that browser-based telemetry can offset.",{"data":6901,"content":6902,"nodeType":998},{},[6903],{"data":6904,"marks":6905,"value":6907,"nodeType":867},{},[6906],{"type":916},"Shadow AI and OAuth sprawl",{"data":6909,"content":6910,"nodeType":881},{},[6911,6914,6922],{"data":6912,"marks":6913,"value":21,"nodeType":867},{},[],{"data":6915,"content":6916,"nodeType":876},{"uri":4829},[6917],{"data":6918,"marks":6919,"value":6921,"nodeType":867},{},[6920],{"type":1040},"The Vercel breach in April 2026",{"data":6923,"marks":6924,"value":6925,"nodeType":867},{},[]," was the result of an OAuth connection to a third-party AI SaaS tool a developer connected into the organization's Google Workspace tenant (without admin approval). When the AI vendor was compromised, the attacker leveraged stored OAuth tokens to access downstream accounts, ultimately reaching internal dashboards, API keys, and source code. ",{"data":6927,"content":6928,"nodeType":881},{},[6929,6933,6938],{"data":6930,"marks":6931,"value":6932,"nodeType":867},{},[],"Push telemetry across customer environments shows an average of ",{"data":6934,"marks":6935,"value":6937,"nodeType":867},{},[6936],{"type":916},"17 unique AI app integrations per organization in Microsoft and Google alone",{"data":6939,"marks":6940,"value":6941,"nodeType":867},{},[],", most of which security teams would describe as unapproved. These generally don't appear in a conventional risk model that isn't looking for them.",{"data":6943,"content":6944,"nodeType":998},{},[6945],{"data":6946,"marks":6947,"value":288,"nodeType":867},{},[6948],{"type":916},{"data":6950,"content":6951,"nodeType":881},{},[6952,6956,6965,6970],{"data":6953,"marks":6954,"value":21,"nodeType":867},{},[6955],{"type":916},{"data":6957,"content":6958,"nodeType":876},{"uri":2975},[6959],{"data":6960,"marks":6961,"value":6964,"nodeType":867},{},[6962,6963],{"type":1040},{"type":916},"Analysis of 20,000 unique extensions deployed across Push customer environments",{"data":6966,"marks":6967,"value":6969,"nodeType":867},{},[6968],{"type":916}," found that 46.76% have the permission combinations required for account takeover without user interaction. ",{"data":6971,"marks":6972,"value":6973,"nodeType":867},{},[],"The extensions carrying these permissions aren't flagged by risk scoring systems because the same permissions are used by ad blockers, password managers, and translation tools (the downside of relying on tools that rely on dubious scoring to assess extensions, but I digress). ",{"data":6975,"content":6976,"nodeType":881},{},[6977],{"data":6978,"marks":6979,"value":6980,"nodeType":867},{},[],"What matters for risk quantification isn't the permission set or an arbitrary score assigned by a vendor; it's whether the monitoring exists to detect when a previously-clean extension changes ownership, escalates permissions, or behaves anomalously. Without that monitoring, the exposure is real but unquantified.",{"data":6982,"content":6983,"nodeType":998},{},[6984],{"data":6985,"marks":6986,"value":6988,"nodeType":867},{},[6987],{"type":916},"ClickFix and non-email delivery channels",{"data":6990,"content":6991,"nodeType":881},{},[6992,6996,7003,7007,7014],{"data":6993,"marks":6994,"value":6995,"nodeType":867},{},[],"ClickFix — where a malicious page silently writes a PowerShell or mshta command into the victim's clipboard and instructs them to paste it — was ",{"data":6997,"content":6998,"nodeType":876},{"uri":1290},[6999],{"data":7000,"marks":7001,"value":7002,"nodeType":867},{},[],"the most common initial access vector observed by Microsoft in 2025",{"data":7004,"marks":7005,"value":7006,"nodeType":867},{},[],", and CrowdStrike reported a",{"data":7008,"content":7009,"nodeType":876},{"uri":2799},[7010],{"data":7011,"marks":7012,"value":7013,"nodeType":867},{},[]," 563% increase in fake CAPTCHA lures",{"data":7015,"marks":7016,"value":7017,"nodeType":867},{},[]," (one of the most common ClickFix styles in which the user has to \"verify they're human\" by running a command on their machine). ",{"data":7019,"content":7020,"nodeType":881},{},[7021],{"data":7022,"marks":7023,"value":7024,"nodeType":867},{},[],"What makes this particularly relevant for risk quantification is the delivery channel: 4 in 5 ClickFix payloads intercepted by Push arrive via search engines, not email. A risk model that estimates threat event frequency from email-based phishing telemetry alone is structurally blind to an entire category of attack that has become one of the most prevalent initial access methods in the landscape.",{"data":7026,"content":7027,"nodeType":998},{},[7028],{"data":7029,"marks":7030,"value":7032,"nodeType":867},{},[7031],{"type":916},"Authorization attacks",{"data":7034,"content":7035,"nodeType":881},{},[7036],{"data":7037,"marks":7038,"value":7039,"nodeType":867},{},[],"Device code phishing and OAuth consent abuse represent a slightly separate category of identity attack that most risk models don't account for because they operate after the authentication flow has already completed — meaning password strength, MFA coverage, and SSO adoption are irrelevant to whether the attack succeeds. ",{"data":7041,"content":7045,"nodeType":890},{"target":7042},{"sys":7043},{"id":7044,"type":887,"linkType":888},"7qtHmxCzBm5664jD6HsCwN",[],{"data":7047,"content":7048,"nodeType":908},{},[],{"data":7050,"content":7051,"nodeType":918},{},[7052],{"data":7053,"marks":7054,"value":7056,"nodeType":867},{},[7055],{"type":916},"The key lesson for CISOs",{"data":7058,"content":7059,"nodeType":881},{},[7060],{"data":7061,"marks":7062,"value":7063,"nodeType":867},{},[],"A risk model that measures identity vulnerability purely in terms of authentication hygiene at the IdP layer — how many accounts have MFA, how many use SSO — will correctly quantify one dimension of exposure while completely missing another that is growing faster and is structurally immune to the controls being measured.",{"data":7065,"content":7066,"nodeType":881},{},[7067],{"data":7068,"marks":7069,"value":7071,"nodeType":867},{},[7070],{"type":916},"For a CISO building a risk model, these aren't edge cases. They represent a real attack surface that doesn't show up in models built on conventional network, endpoint, and cloud telemetry. We aren't just talking about better inputs to risk modeling — we're talking about entirely new risk scenarios that aren't being modeled at all, supported by live data.",{"data":7073,"content":7077,"nodeType":890},{"target":7074},{"sys":7075},{"id":7076,"type":887,"linkType":888},"2ObEcO1gqz8lrOLCZzfpNw",[],{"data":7079,"content":7080,"nodeType":908},{},[],{"data":7082,"content":7083,"nodeType":998},{},[7084],{"data":7085,"marks":7086,"value":7088,"nodeType":867},{},[7087],{"type":916},"Browser telemetry makes a CISO's life easier",{"data":7090,"content":7091,"nodeType":881},{},[7092],{"data":7093,"marks":7094,"value":7095,"nodeType":867},{},[],"Browser-based telemetry changes the conversation a CISO can have with a CFO or board. Instead of \"industry benchmarks suggest our expected annual loss from account compromise is somewhere in this range,\" the answer is, \"We can see how often these attacks are attempted against our users, and we can measure what percentage of our accounts have the controls in place to stop them,\" or \"We know how many shadow AI apps our users self-provision and share data with each month.\" ",{"data":7097,"content":7098,"nodeType":881},{},[7099],{"data":7100,"marks":7101,"value":7102,"nodeType":867},{},[],"Identity risk is only a piece of the quantification problem. Loss magnitude, regulatory exposure, and reputational impact are still extremely hard to estimate regardless of how good your frequency inputs are. ",{"data":7104,"content":7105,"nodeType":881},{},[7106],{"data":7107,"marks":7108,"value":7109,"nodeType":867},{},[],"But the identity attack surface is one of the few areas in security where measurement is genuinely achievable right now, and the gap between what most organizations are modeling and what's actually observable is significant. Shadow SaaS integrations, unapproved AI connections, browser extensions with excessive privileges — these are enumerable risks that don't appear in models built on network, endpoint, and cloud access telemetry alone. ",{"data":7111,"content":7112,"nodeType":881},{},[7113,7118],{"data":7114,"marks":7115,"value":7117,"nodeType":867},{},[7116],{"type":916},"The lesson for CISOs serious about quantitative risk management is this: the frameworks exist, the talent is available, and the bottleneck is almost always data quality. ",{"data":7119,"marks":7120,"value":7121,"nodeType":867},{},[],"Browser telemetry is a good example of the kind of high-fidelity, environment-specific measurement that closes that gap.",{"data":7123,"content":7124,"nodeType":908},{},[],{"data":7126,"content":7127,"nodeType":881},{},[7128],{"data":7129,"marks":7130,"value":6311,"nodeType":867},{},[],{"data":7132,"content":7133,"nodeType":881},{},[7134,7138,7145],{"data":7135,"marks":7136,"value":7137,"nodeType":867},{},[],"Security teams use Push to detect and stop advanced browser-based attacks like AiTM phishing, ClickFix, and session hijacking; gain visibility and control over AI tool usage across their workforce; harden identities by surfacing credential reuse, SSO gaps, and shadow IT; and support data loss and insider investigations with browser-layer telemetry that other tools can't see. ",{"data":7139,"content":7141,"nodeType":876},{"uri":7140},"https://pushsecurity.com/book-demo/",[7142],{"data":7143,"marks":7144,"value":1635,"nodeType":867},{},[],{"data":7146,"marks":7147,"value":1639,"nodeType":867},{},[],"The CISO's data problem (and how browser telemetry can help)","How CISOs can use browser telemetry to support cyber risk quantification in areas where traditional data points fall short. ","2026-05-11T00:00:00.000Z","the-cisos-data-problem-and-how-browser-telemetry-can-help",{"items":7153},[7154,7156],{"sys":7155,"name":5650},{"id":5649},{"sys":7157,"name":342},{"id":2550},{"items":7159},[7160],{"fullName":4441,"firstName":4442,"jobTitle":4443,"profilePicture":7161},{"url":4445},"verizon-dbir-2026-review","blog/verizon-dbir-2026-review",{"json":7165},{"data":7166,"content":7167,"nodeType":1640},{},[7168],{"data":7169,"content":7170,"nodeType":881},{},[7171],{"data":7172,"marks":7173,"value":7174,"nodeType":867},{},[],"Verizon's 2026 Data Breach Investigations Report landed this week with the largest dataset in the report's 19-year history — more than 22,000 confirmed breaches across 145 countries, nearly double last year's count.","What we can learn from 2026's installment of the Verizon Data Breach Investigations Report.",{"id":7177,"publishedAt":7178},"7sZs2lHCTN8oYc2OIGCIQG","2026-08-12T12:00:55.865Z",{"items":7180},[7181,7183],{"sys":7182,"name":297},{"id":5646},{"sys":7184,"name":2547},{"id":2546},{"items":7186},[7187,7189,7191,7193,7195,7197,7199,7201,7203,7205,7207,7209,7211,7213,7215,7217,7219,7221,7223,7225,7227,7229,7231,7233],{"sys":7188,"name":279,"slug":280,"tier":31},{"id":276},{"sys":7190,"name":413,"slug":414,"tier":31},{"id":410},{"sys":7192,"name":642,"slug":643,"tier":31},{"id":639},{"sys":7194,"name":519,"slug":520,"tier":31},{"id":516},{"sys":7196,"name":297,"slug":298,"tier":31},{"id":294},{"sys":7198,"name":235,"slug":236,"tier":31},{"id":232},{"sys":7200,"name":422,"slug":423,"tier":45},{"id":419},{"sys":7202,"name":315,"slug":316,"tier":45},{"id":312},{"sys":7204,"name":324,"slug":325,"tier":45},{"id":321},{"sys":7206,"name":580,"slug":581,"tier":45},{"id":577},{"sys":7208,"name":537,"slug":538,"tier":45},{"id":534},{"sys":7210,"name":633,"slug":634,"tier":45},{"id":630},{"sys":7212,"name":261,"slug":262,"tier":45},{"id":258},{"sys":7214,"name":475,"slug":476,"tier":45},{"id":472},{"sys":7216,"name":333,"slug":334,"tier":45},{"id":330},{"sys":7218,"name":457,"slug":458,"tier":45},{"id":454},{"sys":7220,"name":288,"slug":289,"tier":45},{"id":285},{"sys":7222,"name":252,"slug":253,"tier":45},{"id":249},{"sys":7224,"name":607,"slug":608,"tier":45},{"id":604},{"sys":7226,"name":650,"slug":651,"tier":45},{"id":647},{"sys":7228,"name":244,"slug":245,"tier":45},{"id":241},{"sys":7230,"name":368,"slug":369,"tier":45},{"id":365},{"sys":7232,"name":571,"slug":572,"tier":45},{"id":568},{"sys":7234,"name":484,"slug":485,"tier":45},{"id":481},"hcNrtVGANdYvnes1Z8X1g9b6b_dm694k5qOhLd1GfaI",{"id":7237,"title":6625,"authorsCollection":7238,"content":7243,"extension":228,"faqItemsCollection":8152,"faqTitle":59,"featured":19,"hashTags":59,"meta":8154,"metaTitle":8155,"ogImage":59,"postType":8156,"publishedDate":3405,"relatedBlogPostsCollection":8157,"slug":6627,"stem":11714,"subtitle":59,"summary":11715,"synopsis":6626,"sys":11726,"tagsCollection":11728,"topicsCollection":11734,"__hash__":11770},"blog/blog/analyzing-the-instructure-breach.json",{"items":7239},[7240],{"fullName":849,"firstName":850,"jobTitle":851,"socialLinks":7241,"profilePicture":7242},[853],{"url":855},{"json":7244,"links":8064},{"data":7245,"content":7246,"nodeType":1640},{},[7247,7269,7293,7326,7359,7364,7374,7377,7384,7426,7432,7451,7456,7459,7466,7490,7496,7503,7508,7511,7518,7524,7539,7545,7578,7584,7587,7594,7609,7651,7654,7661,7676,7691,7698,7704,7714,7724,7734,7744,7759,7766,7772,7775,7781,7787,7802,7805,7812,7827,8058],{"data":7248,"content":7249,"nodeType":881},{},[7250,7253,7259,7262,7266],{"data":7251,"marks":7252,"value":5668,"nodeType":867},{},[],{"data":7254,"content":7255,"nodeType":876},{"uri":3051},[7256],{"data":7257,"marks":7258,"value":3056,"nodeType":867},{},[],{"data":7260,"marks":7261,"value":5678,"nodeType":867},{},[],{"data":7263,"marks":7264,"value":5683,"nodeType":867},{},[7265],{"type":916},{"data":7267,"marks":7268,"value":5687,"nodeType":867},{},[],{"data":7270,"content":7271,"nodeType":881},{},[7272,7275,7281,7284,7290],{"data":7273,"marks":7274,"value":5694,"nodeType":867},{},[],{"data":7276,"content":7277,"nodeType":876},{"uri":5697},[7278],{"data":7279,"marks":7280,"value":5702,"nodeType":867},{},[],{"data":7282,"marks":7283,"value":5706,"nodeType":867},{},[],{"data":7285,"content":7286,"nodeType":876},{"uri":5709},[7287],{"data":7288,"marks":7289,"value":5714,"nodeType":867},{},[],{"data":7291,"marks":7292,"value":5718,"nodeType":867},{},[],{"data":7294,"content":7295,"nodeType":881},{},[7296,7299,7305,7308,7314,7317,7323],{"data":7297,"marks":7298,"value":5725,"nodeType":867},{},[],{"data":7300,"content":7301,"nodeType":876},{"uri":5728},[7302],{"data":7303,"marks":7304,"value":5733,"nodeType":867},{},[],{"data":7306,"marks":7307,"value":5737,"nodeType":867},{},[],{"data":7309,"content":7310,"nodeType":876},{"uri":5740},[7311],{"data":7312,"marks":7313,"value":5745,"nodeType":867},{},[],{"data":7315,"marks":7316,"value":5749,"nodeType":867},{},[],{"data":7318,"content":7319,"nodeType":876},{"uri":5752},[7320],{"data":7321,"marks":7322,"value":5757,"nodeType":867},{},[],{"data":7324,"marks":7325,"value":5761,"nodeType":867},{},[],{"data":7327,"content":7328,"nodeType":881},{},[7329,7332,7338,7341,7347,7350,7356],{"data":7330,"marks":7331,"value":5768,"nodeType":867},{},[],{"data":7333,"content":7334,"nodeType":876},{"uri":5771},[7335],{"data":7336,"marks":7337,"value":5776,"nodeType":867},{},[],{"data":7339,"marks":7340,"value":5780,"nodeType":867},{},[],{"data":7342,"content":7343,"nodeType":876},{"uri":5783},[7344],{"data":7345,"marks":7346,"value":5788,"nodeType":867},{},[],{"data":7348,"marks":7349,"value":5792,"nodeType":867},{},[],{"data":7351,"content":7352,"nodeType":876},{"uri":5795},[7353],{"data":7354,"marks":7355,"value":5800,"nodeType":867},{},[],{"data":7357,"marks":7358,"value":5804,"nodeType":867},{},[],{"data":7360,"content":7363,"nodeType":890},{"target":7361},{"sys":7362},{"id":5809,"type":887,"linkType":888},[],{"data":7365,"content":7366,"nodeType":881},{},[7367,7371],{"data":7368,"marks":7369,"value":5818,"nodeType":867},{},[7370],{"type":916},{"data":7372,"marks":7373,"value":5822,"nodeType":867},{},[],{"data":7375,"content":7376,"nodeType":908},{},[],{"data":7378,"content":7379,"nodeType":918},{},[7380],{"data":7381,"marks":7382,"value":5833,"nodeType":867},{},[7383],{"type":916},{"data":7385,"content":7386,"nodeType":881},{},[7387,7390,7396,7399,7405,7408,7414,7417,7423],{"data":7388,"marks":7389,"value":5840,"nodeType":867},{},[],{"data":7391,"content":7392,"nodeType":876},{"uri":5843},[7393],{"data":7394,"marks":7395,"value":5848,"nodeType":867},{},[],{"data":7397,"marks":7398,"value":5852,"nodeType":867},{},[],{"data":7400,"content":7401,"nodeType":876},{"uri":5855},[7402],{"data":7403,"marks":7404,"value":5860,"nodeType":867},{},[],{"data":7406,"marks":7407,"value":5864,"nodeType":867},{},[],{"data":7409,"content":7410,"nodeType":876},{"uri":5740},[7411],{"data":7412,"marks":7413,"value":5871,"nodeType":867},{},[],{"data":7415,"marks":7416,"value":5875,"nodeType":867},{},[],{"data":7418,"content":7419,"nodeType":876},{"uri":5878},[7420],{"data":7421,"marks":7422,"value":5883,"nodeType":867},{},[],{"data":7424,"marks":7425,"value":1947,"nodeType":867},{},[],{"data":7427,"content":7428,"nodeType":881},{},[7429],{"data":7430,"marks":7431,"value":5893,"nodeType":867},{},[],{"data":7433,"content":7434,"nodeType":881},{},[7435,7438,7444,7447],{"data":7436,"marks":7437,"value":5900,"nodeType":867},{},[],{"data":7439,"content":7440,"nodeType":876},{"uri":5878},[7441],{"data":7442,"marks":7443,"value":5907,"nodeType":867},{},[],{"data":7445,"marks":7446,"value":5911,"nodeType":867},{},[],{"data":7448,"marks":7449,"value":5916,"nodeType":867},{},[7450],{"type":916},{"data":7452,"content":7455,"nodeType":890},{"target":7453},{"sys":7454},{"id":5921,"type":887,"linkType":888},[],{"data":7457,"content":7458,"nodeType":908},{},[],{"data":7460,"content":7461,"nodeType":918},{},[7462],{"data":7463,"marks":7464,"value":5933,"nodeType":867},{},[7465],{"type":916},{"data":7467,"content":7468,"nodeType":881},{},[7469,7472,7478,7481,7487],{"data":7470,"marks":7471,"value":3113,"nodeType":867},{},[],{"data":7473,"content":7474,"nodeType":876},{"uri":3074},[7475],{"data":7476,"marks":7477,"value":5946,"nodeType":867},{},[],{"data":7479,"marks":7480,"value":5950,"nodeType":867},{},[],{"data":7482,"content":7483,"nodeType":876},{"uri":5752},[7484],{"data":7485,"marks":7486,"value":5957,"nodeType":867},{},[],{"data":7488,"marks":7489,"value":5961,"nodeType":867},{},[],{"data":7491,"content":7492,"nodeType":881},{},[7493],{"data":7494,"marks":7495,"value":5968,"nodeType":867},{},[],{"data":7497,"content":7498,"nodeType":881},{},[7499],{"data":7500,"marks":7501,"value":5976,"nodeType":867},{},[7502],{"type":916},{"data":7504,"content":7507,"nodeType":890},{"target":7505},{"sys":7506},{"id":5981,"type":887,"linkType":888},[],{"data":7509,"content":7510,"nodeType":908},{},[],{"data":7512,"content":7513,"nodeType":918},{},[7514],{"data":7515,"marks":7516,"value":5993,"nodeType":867},{},[7517],{"type":916},{"data":7519,"content":7520,"nodeType":881},{},[7521],{"data":7522,"marks":7523,"value":6000,"nodeType":867},{},[],{"data":7525,"content":7526,"nodeType":881},{},[7527,7530,7536],{"data":7528,"marks":7529,"value":3113,"nodeType":867},{},[],{"data":7531,"content":7532,"nodeType":876},{"uri":6009},[7533],{"data":7534,"marks":7535,"value":6014,"nodeType":867},{},[],{"data":7537,"marks":7538,"value":6018,"nodeType":867},{},[],{"data":7540,"content":7541,"nodeType":881},{},[7542],{"data":7543,"marks":7544,"value":6025,"nodeType":867},{},[],{"data":7546,"content":7547,"nodeType":881},{},[7548,7551,7557,7560,7566,7569,7575],{"data":7549,"marks":7550,"value":6032,"nodeType":867},{},[],{"data":7552,"content":7553,"nodeType":876},{"uri":6035},[7554],{"data":7555,"marks":7556,"value":6040,"nodeType":867},{},[],{"data":7558,"marks":7559,"value":6044,"nodeType":867},{},[],{"data":7561,"content":7562,"nodeType":876},{"uri":6047},[7563],{"data":7564,"marks":7565,"value":6052,"nodeType":867},{},[],{"data":7567,"marks":7568,"value":6056,"nodeType":867},{},[],{"data":7570,"content":7571,"nodeType":876},{"uri":4829},[7572],{"data":7573,"marks":7574,"value":6063,"nodeType":867},{},[],{"data":7576,"marks":7577,"value":6067,"nodeType":867},{},[],{"data":7579,"content":7580,"nodeType":881},{},[7581],{"data":7582,"marks":7583,"value":6074,"nodeType":867},{},[],{"data":7585,"content":7586,"nodeType":908},{},[],{"data":7588,"content":7589,"nodeType":918},{},[7590],{"data":7591,"marks":7592,"value":6085,"nodeType":867},{},[7593],{"type":916},{"data":7595,"content":7596,"nodeType":881},{},[7597,7600,7606],{"data":7598,"marks":7599,"value":6092,"nodeType":867},{},[],{"data":7601,"content":7602,"nodeType":876},{"uri":6095},[7603],{"data":7604,"marks":7605,"value":6100,"nodeType":867},{},[],{"data":7607,"marks":7608,"value":6104,"nodeType":867},{},[],{"data":7610,"content":7611,"nodeType":881},{},[7612,7615,7621,7624,7630,7633,7639,7642,7648],{"data":7613,"marks":7614,"value":6111,"nodeType":867},{},[],{"data":7616,"content":7617,"nodeType":876},{"uri":6114},[7618],{"data":7619,"marks":7620,"value":6119,"nodeType":867},{},[],{"data":7622,"marks":7623,"value":6123,"nodeType":867},{},[],{"data":7625,"content":7626,"nodeType":876},{"uri":6126},[7627],{"data":7628,"marks":7629,"value":6131,"nodeType":867},{},[],{"data":7631,"marks":7632,"value":6135,"nodeType":867},{},[],{"data":7634,"content":7635,"nodeType":876},{"uri":6138},[7636],{"data":7637,"marks":7638,"value":6143,"nodeType":867},{},[],{"data":7640,"marks":7641,"value":6147,"nodeType":867},{},[],{"data":7643,"content":7644,"nodeType":876},{"uri":6150},[7645],{"data":7646,"marks":7647,"value":6155,"nodeType":867},{},[],{"data":7649,"marks":7650,"value":6159,"nodeType":867},{},[],{"data":7652,"content":7653,"nodeType":908},{},[],{"data":7655,"content":7656,"nodeType":918},{},[7657],{"data":7658,"marks":7659,"value":6170,"nodeType":867},{},[7660],{"type":916},{"data":7662,"content":7663,"nodeType":881},{},[7664,7667,7673],{"data":7665,"marks":7666,"value":6177,"nodeType":867},{},[],{"data":7668,"content":7669,"nodeType":876},{"uri":1125},[7670],{"data":7671,"marks":7672,"value":6184,"nodeType":867},{},[],{"data":7674,"marks":7675,"value":6188,"nodeType":867},{},[],{"data":7677,"content":7678,"nodeType":881},{},[7679,7682,7688],{"data":7680,"marks":7681,"value":6195,"nodeType":867},{},[],{"data":7683,"content":7684,"nodeType":876},{"uri":6198},[7685],{"data":7686,"marks":7687,"value":315,"nodeType":867},{},[],{"data":7689,"marks":7690,"value":6206,"nodeType":867},{},[],{"data":7692,"content":7693,"nodeType":998},{},[7694],{"data":7695,"marks":7696,"value":6214,"nodeType":867},{},[7697],{"type":916},{"data":7699,"content":7700,"nodeType":881},{},[7701],{"data":7702,"marks":7703,"value":6221,"nodeType":867},{},[],{"data":7705,"content":7706,"nodeType":881},{},[7707,7711],{"data":7708,"marks":7709,"value":6229,"nodeType":867},{},[7710],{"type":916},{"data":7712,"marks":7713,"value":6233,"nodeType":867},{},[],{"data":7715,"content":7716,"nodeType":881},{},[7717,7721],{"data":7718,"marks":7719,"value":6241,"nodeType":867},{},[7720],{"type":916},{"data":7722,"marks":7723,"value":6245,"nodeType":867},{},[],{"data":7725,"content":7726,"nodeType":881},{},[7727,7731],{"data":7728,"marks":7729,"value":6253,"nodeType":867},{},[7730],{"type":916},{"data":7732,"marks":7733,"value":6257,"nodeType":867},{},[],{"data":7735,"content":7736,"nodeType":881},{},[7737,7741],{"data":7738,"marks":7739,"value":6265,"nodeType":867},{},[7740],{"type":916},{"data":7742,"marks":7743,"value":6269,"nodeType":867},{},[],{"data":7745,"content":7746,"nodeType":881},{},[7747,7750,7756],{"data":7748,"marks":7749,"value":21,"nodeType":867},{},[],{"data":7751,"content":7752,"nodeType":876},{"uri":6278},[7753],{"data":7754,"marks":7755,"value":6283,"nodeType":867},{},[],{"data":7757,"marks":7758,"value":21,"nodeType":867},{},[],{"data":7760,"content":7761,"nodeType":998},{},[7762],{"data":7763,"marks":7764,"value":6294,"nodeType":867},{},[7765],{"type":916},{"data":7767,"content":7768,"nodeType":881},{},[7769],{"data":7770,"marks":7771,"value":6301,"nodeType":867},{},[],{"data":7773,"content":7774,"nodeType":908},{},[],{"data":7776,"content":7777,"nodeType":881},{},[7778],{"data":7779,"marks":7780,"value":6311,"nodeType":867},{},[],{"data":7782,"content":7783,"nodeType":881},{},[7784],{"data":7785,"marks":7786,"value":1620,"nodeType":867},{},[],{"data":7788,"content":7789,"nodeType":881},{},[7790,7793,7799],{"data":7791,"marks":7792,"value":21,"nodeType":867},{},[],{"data":7794,"content":7795,"nodeType":876},{"uri":2362},[7796],{"data":7797,"marks":7798,"value":2368,"nodeType":867},{},[],{"data":7800,"marks":7801,"value":21,"nodeType":867},{},[],{"data":7803,"content":7804,"nodeType":908},{},[],{"data":7806,"content":7807,"nodeType":918},{},[7808],{"data":7809,"marks":7810,"value":6343,"nodeType":867},{},[7811],{"type":916},{"data":7813,"content":7814,"nodeType":881},{},[7815,7818,7824],{"data":7816,"marks":7817,"value":6350,"nodeType":867},{},[],{"data":7819,"content":7820,"nodeType":876},{"uri":3051},[7821],{"data":7822,"marks":7823,"value":6357,"nodeType":867},{},[],{"data":7825,"marks":7826,"value":6361,"nodeType":867},{},[],{"data":7828,"content":7829,"nodeType":2531},{},[7830,7873,7929,7972,8015],{"data":7831,"content":7832,"nodeType":2438},{},[7833,7843,7853,7863],{"data":7834,"content":7835,"nodeType":2452},{},[7836],{"data":7837,"content":7838,"nodeType":881},{},[7839],{"data":7840,"marks":7841,"value":6378,"nodeType":867},{},[7842],{"type":916},{"data":7844,"content":7845,"nodeType":2452},{},[7846],{"data":7847,"content":7848,"nodeType":881},{},[7849],{"data":7850,"marks":7851,"value":6389,"nodeType":867},{},[7852],{"type":916},{"data":7854,"content":7855,"nodeType":2452},{},[7856],{"data":7857,"content":7858,"nodeType":881},{},[7859],{"data":7860,"marks":7861,"value":6400,"nodeType":867},{},[7862],{"type":916},{"data":7864,"content":7865,"nodeType":2452},{},[7866],{"data":7867,"content":7868,"nodeType":881},{},[7869],{"data":7870,"marks":7871,"value":6411,"nodeType":867},{},[7872],{"type":916},{"data":7874,"content":7875,"nodeType":2438},{},[7876,7896,7905,7914],{"data":7877,"content":7878,"nodeType":2452},{},[7879],{"data":7880,"content":7881,"nodeType":881},{},[7882,7886,7889,7893],{"data":7883,"marks":7884,"value":6425,"nodeType":867},{},[7885],{"type":916},{"data":7887,"marks":7888,"value":6429,"nodeType":867},{},[],{"data":7890,"marks":7891,"value":6434,"nodeType":867},{},[7892],{"type":916},{"data":7894,"marks":7895,"value":6438,"nodeType":867},{},[],{"data":7897,"content":7898,"nodeType":2452},{},[7899],{"data":7900,"content":7901,"nodeType":881},{},[7902],{"data":7903,"marks":7904,"value":6448,"nodeType":867},{},[],{"data":7906,"content":7907,"nodeType":2452},{},[7908],{"data":7909,"content":7910,"nodeType":881},{},[7911],{"data":7912,"marks":7913,"value":6458,"nodeType":867},{},[],{"data":7915,"content":7916,"nodeType":2452},{},[7917,7923],{"data":7918,"content":7919,"nodeType":881},{},[7920],{"data":7921,"marks":7922,"value":6468,"nodeType":867},{},[],{"data":7924,"content":7925,"nodeType":881},{},[7926],{"data":7927,"marks":7928,"value":6475,"nodeType":867},{},[],{"data":7930,"content":7931,"nodeType":2438},{},[7932,7945,7954,7963],{"data":7933,"content":7934,"nodeType":2452},{},[7935],{"data":7936,"content":7937,"nodeType":881},{},[7938,7942],{"data":7939,"marks":7940,"value":6489,"nodeType":867},{},[7941],{"type":916},{"data":7943,"marks":7944,"value":6493,"nodeType":867},{},[],{"data":7946,"content":7947,"nodeType":2452},{},[7948],{"data":7949,"content":7950,"nodeType":881},{},[7951],{"data":7952,"marks":7953,"value":6503,"nodeType":867},{},[],{"data":7955,"content":7956,"nodeType":2452},{},[7957],{"data":7958,"content":7959,"nodeType":881},{},[7960],{"data":7961,"marks":7962,"value":6513,"nodeType":867},{},[],{"data":7964,"content":7965,"nodeType":2452},{},[7966],{"data":7967,"content":7968,"nodeType":881},{},[7969],{"data":7970,"marks":7971,"value":6523,"nodeType":867},{},[],{"data":7973,"content":7974,"nodeType":2438},{},[7975,7988,7997,8006],{"data":7976,"content":7977,"nodeType":2452},{},[7978],{"data":7979,"content":7980,"nodeType":881},{},[7981,7985],{"data":7982,"marks":7983,"value":6537,"nodeType":867},{},[7984],{"type":916},{"data":7986,"marks":7987,"value":6541,"nodeType":867},{},[],{"data":7989,"content":7990,"nodeType":2452},{},[7991],{"data":7992,"content":7993,"nodeType":881},{},[7994],{"data":7995,"marks":7996,"value":6551,"nodeType":867},{},[],{"data":7998,"content":7999,"nodeType":2452},{},[8000],{"data":8001,"content":8002,"nodeType":881},{},[8003],{"data":8004,"marks":8005,"value":6561,"nodeType":867},{},[],{"data":8007,"content":8008,"nodeType":2452},{},[8009],{"data":8010,"content":8011,"nodeType":881},{},[8012],{"data":8013,"marks":8014,"value":6571,"nodeType":867},{},[],{"data":8016,"content":8017,"nodeType":2438},{},[8018,8031,8040,8049],{"data":8019,"content":8020,"nodeType":2452},{},[8021],{"data":8022,"content":8023,"nodeType":881},{},[8024,8028],{"data":8025,"marks":8026,"value":6585,"nodeType":867},{},[8027],{"type":916},{"data":8029,"marks":8030,"value":6589,"nodeType":867},{},[],{"data":8032,"content":8033,"nodeType":2452},{},[8034],{"data":8035,"content":8036,"nodeType":881},{},[8037],{"data":8038,"marks":8039,"value":6448,"nodeType":867},{},[],{"data":8041,"content":8042,"nodeType":2452},{},[8043],{"data":8044,"content":8045,"nodeType":881},{},[8046],{"data":8047,"marks":8048,"value":6608,"nodeType":867},{},[],{"data":8050,"content":8051,"nodeType":2452},{},[8052],{"data":8053,"content":8054,"nodeType":881},{},[8055],{"data":8056,"marks":8057,"value":6618,"nodeType":867},{},[],{"data":8059,"content":8060,"nodeType":881},{},[8061],{"data":8062,"marks":8063,"value":21,"nodeType":867},{},[],{"entries":8065},{"hyperlink":8066,"inline":8067,"block":8068},[],[],[8069,8083,8107],{"sys":8070,"__typename":1696,"content":8071,"name":8082,"title":59},{"id":5809},{"json":8072},{"nodeType":1640,"data":8073,"content":8074},{},[8075],{"nodeType":881,"data":8076,"content":8077},{},[8078],{"nodeType":867,"value":8079,"marks":8080,"data":8081},"It seems that ShinyHunters have opportunistically returned to the scene of the crime with Instructure because of the proven payoff of targeting EdTech organizations, combined with the existing leverage of data gathered during the previous breach (and previous refusal to pay). This shows that a major data breach is likely to result in further attempts to increase pressure and extort payment. We saw this in 2024's PowerSchool breach too, where individual victims were hit with blackmail and extortion attempts — even after PowerSchool paid the ransom to avoid such a scenario, but the attackers (unsurprisingly) didn't keep their end of the bargain. ",[],{},"Instructure IB5",{"sys":8084,"__typename":1696,"content":8085,"name":8106,"title":59},{"id":5921},{"json":8086},{"nodeType":1640,"data":8087,"content":8088},{},[8089],{"nodeType":881,"data":8090,"content":8091},{},[8092,8096,8102],{"nodeType":867,"value":8093,"marks":8094,"data":8095},"The speed at which these campaigns execute has compressed dramatically. ",[],{},{"nodeType":876,"data":8097,"content":8098},{"uri":5740},[8099],{"nodeType":867,"value":5745,"marks":8100,"data":8101},[],{},{"nodeType":867,"value":8103,"marks":8104,"data":8105}," Cordial Spider and Snarky Spider moving from initial compromise to complete data exfiltration in under an hour — fast enough that any detection strategy that relies on human SOC triage will arrive after the data has already left the building.",[],{},"Instructure IB3",{"sys":8108,"__typename":1696,"content":8109,"name":8151,"title":59},{"id":5981},{"json":8110},{"nodeType":1640,"data":8111,"content":8112},{},[8113],{"nodeType":881,"data":8114,"content":8115},{},[8116,8120,8128,8132,8139,8143,8148],{"nodeType":867,"value":8117,"marks":8118,"data":8119},"Device code phishing has been rapidly commoditized. What began with ",[],{},{"nodeType":876,"data":8121,"content":8123},{"uri":8122},"https://www.microsoft.com/en-us/security/blog/2025/02/13/storm-2372-conducts-device-code-phishing-campaign/",[8124],{"nodeType":867,"value":8125,"marks":8126,"data":8127},"Storm-2372's nation-state campaigns in August 2024",[],{},{"nodeType":867,"value":8129,"marks":8130,"data":8131}," has since proliferated through criminal kits like EvilTokens and Venom — which reuses Sneaky2FA's AiTM infrastructure while adding device code phishing options — and more recently through Tycoon2FA, which has ",[],{},{"nodeType":876,"data":8133,"content":8134},{"uri":1125},[8135],{"nodeType":867,"value":8136,"marks":8137,"data":8138},"adopted device code phishing capabilities",[],{},{"nodeType":867,"value":8140,"marks":8141,"data":8142}," alongside its established AiTM functionality. Push now tracks 12+ distinct device code phishing kits in the wild and has measured a ",[],{},{"nodeType":867,"value":8144,"marks":8145,"data":8147},"37.5x increase in device code phishing activity since the start of 2026",[8146],{"type":916},{},{"nodeType":867,"value":1253,"marks":8149,"data":8150},[],{},"Instructure IB2",{"items":8153},[],{},"How three techniques are behind ShinyHunters' 2026 campaigns","threat-research",{"items":8158},[8159,10076,10844],{"__typename":1742,"sys":8160,"content":8162,"title":10059,"synopsis":10060,"hashTags":59,"publishedDate":10061,"slug":10062,"tagsCollection":10063,"authorsCollection":10069},{"id":8161},"2tz0zEJCarJBkceOYk4zVg",{"json":8163},{"data":8164,"content":8165,"nodeType":1640},{},[8166,8173,8203,8214,8221,8227,8239,8245,8248,8256,8263,8326,8333,8339,8342,8350,8357,8363,8371,8378,8504,8510,8516,8522,8528,8536,8543,8550,8613,8620,8626,8632,8640,8647,8654,8662,8669,8702,8709,8715,8722,8770,8777,8785,8792,8798,8805,8812,8818,8825,8858,8865,8871,8874,8882,8889,8896,8903,8908,8915,8922,8928,8935,8941,8948,8954,8961,8968,8971,8979,8995,9002,9021,9264,9271,9302,9537,9544,9551,9752,9759,9944,9947,9955,9962,9969,9981,9984,9991,10008,10025,10032,10035,10043],{"data":8167,"content":8168,"nodeType":881},{},[8169],{"data":8170,"marks":8171,"value":8172,"nodeType":867},{},[],"When Push blocks an attack in the browser, we take the opportunity to do some more digging to see what else we can find. One recent detection led us down the rabbit hole — and right into a criminal phishing panel. ",{"data":8174,"content":8175,"nodeType":881},{},[8176,8180,8187,8191,8199],{"data":8177,"marks":8178,"value":8179,"nodeType":867},{},[],"Real-time operated phishing panels have been used extensively in recent months, in vishing + phishing attacks attributed to first ",{"data":8181,"content":8182,"nodeType":876},{"uri":3074},[8183],{"data":8184,"marks":8185,"value":8186,"nodeType":867},{},[],"ShinyHunters",{"data":8188,"marks":8189,"value":8190,"nodeType":867},{},[],", and more recently the ",{"data":8192,"content":8194,"nodeType":876},{"uri":8193},"https://www.bleepingcomputer.com/news/security/new-blackfile-extortion-gang-targets-retail-and-hospitality-orgs/",[8195],{"data":8196,"marks":8197,"value":8198,"nodeType":867},{},[],"BlackFile",{"data":8200,"marks":8201,"value":8202,"nodeType":867},{},[]," hacking group, with a significant overlap in techniques and tooling. ",{"data":8204,"content":8205,"nodeType":881},{},[8206,8211],{"data":8207,"marks":8208,"value":8210,"nodeType":867},{},[8209],{"type":916},"We’ve directly accessed active deployments of the operator panels driving these campaigns, observed what happens in real-time when a victim is targeted, and analyzed multiple variants and forks of the tooling. ",{"data":8212,"marks":8213,"value":3679,"nodeType":867},{},[],{"data":8215,"content":8216,"nodeType":881},{},[8217],{"data":8218,"marks":8219,"value":8220,"nodeType":867},{},[],"We identified four primary infrastructure clusters, with each deployment having its own panel implementation. While the panels share common heritage, the operators deploying them appear to be separate groups with different infrastructure preferences and operational patterns.",{"data":8222,"content":8226,"nodeType":890},{"target":8223},{"sys":8224},{"id":8225,"type":887,"linkType":888},"5BQOpzjSbobLx8OkvXl6os",[],{"data":8228,"content":8229,"nodeType":881},{},[8230,8234],{"data":8231,"marks":8232,"value":8233,"nodeType":867},{},[],"The existence of these independently branded forks indicates that the tooling has entered a phase of wider distribution — operators who obtained the original panel source are now customizing and reshipping it for their own purposes. As a result, the tooling is now most likely accessible to a broad population of financially motivated threat actors. ",{"data":8235,"marks":8236,"value":8238,"nodeType":867},{},[8237],{"type":916},"In total, we’ve identified over 400 domains linked to the attacks, giving an indication of the scale. ",{"data":8240,"content":8244,"nodeType":890},{"target":8241},{"sys":8242},{"id":8243,"type":887,"linkType":888},"2Z1LUdYXVONWO9nnJTkWsJ",[],{"data":8246,"content":8247,"nodeType":908},{},[],{"data":8249,"content":8250,"nodeType":918},{},[8251],{"data":8252,"marks":8253,"value":8255,"nodeType":867},{},[8254],{"type":916},"Background",{"data":8257,"content":8258,"nodeType":881},{},[8259],{"data":8260,"marks":8261,"value":8262,"nodeType":867},{},[],"Since at least August 2025, attackers have been running hybrid social engineering campaigns targeting hundreds of organizations across financial services, technology, cryptocurrency, healthcare, hospitality, and private aviation. ",{"data":8264,"content":8265,"nodeType":3126},{},[8266,8281,8296,8311],{"data":8267,"content":8268,"nodeType":3061},{},[8269],{"data":8270,"content":8271,"nodeType":881},{},[8272,8277],{"data":8273,"marks":8274,"value":8276,"nodeType":867},{},[8275],{"type":916},"August 2025: ",{"data":8278,"marks":8279,"value":8280,"nodeType":867},{},[],"Tooling made available, used in crypto-focused attacks",{"data":8282,"content":8283,"nodeType":3061},{},[8284],{"data":8285,"content":8286,"nodeType":881},{},[8287,8292],{"data":8288,"marks":8289,"value":8291,"nodeType":867},{},[8290],{"type":916},"November 2025:",{"data":8293,"marks":8294,"value":8295,"nodeType":867},{},[]," Major attacks on enterprise identity platforms begin",{"data":8297,"content":8298,"nodeType":3061},{},[8299],{"data":8300,"content":8301,"nodeType":881},{},[8302,8307],{"data":8303,"marks":8304,"value":8306,"nodeType":867},{},[8305],{"type":916},"January 2026: ",{"data":8308,"marks":8309,"value":8310,"nodeType":867},{},[],"Public breaches reported",{"data":8312,"content":8313,"nodeType":3061},{},[8314],{"data":8315,"content":8316,"nodeType":881},{},[8317,8322],{"data":8318,"marks":8319,"value":8321,"nodeType":867},{},[8320],{"type":916},"March 2026: ",{"data":8323,"marks":8324,"value":8325,"nodeType":867},{},[],"Activity spikes again",{"data":8327,"content":8328,"nodeType":881},{},[8329],{"data":8330,"marks":8331,"value":8332,"nodeType":867},{},[],"The attacks combine voice phishing with MFA-bypassing adversary-in-the-middle (AiTM) phishing mechanisms that allow the attacker to steal authenticated sessions for target applications — typically enterprise identity providers and cryptocurrency exchanges. Once an identity provider account is compromised, the attackers pivot across connected SaaS platforms — SharePoint, Salesforce, DocuSign, Slack — exfiltrates data, and attempts to extort the victim organization. ",{"data":8334,"content":8338,"nodeType":890},{"target":8335},{"sys":8336},{"id":8337,"type":887,"linkType":888},"2X2YXMpozrbRQhegk7yF1k",[],{"data":8340,"content":8341,"nodeType":908},{},[],{"data":8343,"content":8344,"nodeType":918},{},[8345],{"data":8346,"marks":8347,"value":8349,"nodeType":867},{},[8348],{"type":916},"Inside the panels: what Push found",{"data":8351,"content":8352,"nodeType":881},{},[8353],{"data":8354,"marks":8355,"value":8356,"nodeType":867},{},[],"Push detected an active Okta phishing site with TTPs aligned to the tooling used by SLH and affiliated groups. Through analysis of the phishing infrastructure, we gained direct access to Doko’s Panel and variants, and were able to observe how these attacks unfold from the operator's perspective — including real victim submission logs from the current week confirming ongoing active operations.",{"data":8358,"content":8362,"nodeType":890},{"target":8359},{"sys":8360},{"id":8361,"type":887,"linkType":888},"5ND0etPs5xN7ejz24l71jy",[],{"data":8364,"content":8365,"nodeType":998},{},[8366],{"data":8367,"marks":8368,"value":8370,"nodeType":867},{},[8369],{"type":916},"How the attack works",{"data":8372,"content":8373,"nodeType":881},{},[8374],{"data":8375,"marks":8376,"value":8377,"nodeType":867},{},[],"The general sequence of steps is the same across the panels:",{"data":8379,"content":8380,"nodeType":3126},{},[8381,8396,8411,8435,8450,8465,8489],{"data":8382,"content":8383,"nodeType":3061},{},[8384],{"data":8385,"content":8386,"nodeType":881},{},[8387,8392],{"data":8388,"marks":8389,"value":8391,"nodeType":867},{},[8390],{"type":916},"The operator calls the target",{"data":8393,"marks":8394,"value":8395,"nodeType":867},{},[]," spoofing the organization's IT helpdesk number, often referencing real employee names or internal ticket numbers to establish trust. The target is directed to a phishing domain — usually following a combosquatting pattern like my\u003Ctarget>internal[.]com or \u003Ctarget>sso[.]com — under the pretext of a mandatory security update, passkey enrollment, or support ticket resolution. ",{"data":8397,"content":8398,"nodeType":3061},{},[8399],{"data":8400,"content":8401,"nodeType":881},{},[8402,8407],{"data":8403,"marks":8404,"value":8406,"nodeType":867},{},[8405],{"type":916},"The victim lands on the phishing domain",{"data":8408,"marks":8409,"value":8410,"nodeType":867},{},[]," and is presented with a loading spinner — the anti-bot gate that prevents unauthorized access to the phishing pages.",{"data":8412,"content":8413,"nodeType":3061},{},[8414],{"data":8415,"content":8416,"nodeType":881},{},[8417,8422,8426,8431],{"data":8418,"marks":8419,"value":8421,"nodeType":867},{},[8420],{"type":916},"The operator accepts the visitor",{"data":8423,"marks":8424,"value":8425,"nodeType":867},{},[]," from the admin panel and ",{"data":8427,"marks":8428,"value":8430,"nodeType":867},{},[8429],{"type":916},"the victim is redirected",{"data":8432,"marks":8433,"value":8434,"nodeType":867},{},[]," to the cloned login page (e.g. Google, Microsoft, Okta).",{"data":8436,"content":8437,"nodeType":3061},{},[8438],{"data":8439,"content":8440,"nodeType":881},{},[8441,8446],{"data":8442,"marks":8443,"value":8445,"nodeType":867},{},[8444],{"type":916},"The victim enters their email address and password",{"data":8447,"marks":8448,"value":8449,"nodeType":867},{},[],", which is forwarded to the operator's Telegram channel. The victim sees a processing spinner on the branded login form.",{"data":8451,"content":8452,"nodeType":3061},{},[8453],{"data":8454,"content":8455,"nodeType":881},{},[8456,8461],{"data":8457,"marks":8458,"value":8460,"nodeType":867},{},[8459],{"type":916},"The operator relays the credentials",{"data":8462,"marks":8463,"value":8464,"nodeType":867},{},[]," to the real identity provider. If they're valid, the attack proceeds. If they're invalid, the operator can redirect the victim back to the credential entry pages. Assuming MFA is required, the operator issues a redirect to an appropriate MFA capture page — \"Submit SMS OTP,\" \"Submit Gauth OTP,\" or \"Approve [XX] Prompt,\" depending on what the legitimate IdP is presenting.",{"data":8466,"content":8467,"nodeType":3061},{},[8468],{"data":8469,"content":8470,"nodeType":881},{},[8471,8476,8480,8485],{"data":8472,"marks":8473,"value":8475,"nodeType":867},{},[8474],{"type":916},"The victim submits their OTP or approves the push notification ",{"data":8477,"marks":8478,"value":8479,"nodeType":867},{},[],"and",{"data":8481,"marks":8482,"value":8484,"nodeType":867},{},[8483],{"type":916}," the operator relays the OTP",{"data":8486,"marks":8487,"value":8488,"nodeType":867},{},[]," in their own login session, completes authentication, and captures the session. ",{"data":8490,"content":8491,"nodeType":3061},{},[8492],{"data":8493,"content":8494,"nodeType":881},{},[8495,8500],{"data":8496,"marks":8497,"value":8499,"nodeType":867},{},[8498],{"type":916},"The victim is redirected to a benign page",{"data":8501,"marks":8502,"value":8503,"nodeType":867},{},[]," (e.g., Google Drive) or to a support ticket closure screen displaying a fabricated ticket number.",{"data":8505,"content":8509,"nodeType":890},{"target":8506},{"sys":8507},{"id":8508,"type":887,"linkType":888},"1o0wm3EOd7zSl5MddsNxgL",[],{"data":8511,"content":8515,"nodeType":890},{"target":8512},{"sys":8513},{"id":8514,"type":887,"linkType":888},"7w7SQEn3aITpcgXLMThhbS",[],{"data":8517,"content":8518,"nodeType":881},{},[8519],{"data":8520,"marks":8521,"value":21,"nodeType":867},{},[],{"data":8523,"content":8527,"nodeType":890},{"target":8524},{"sys":8525},{"id":8526,"type":887,"linkType":888},"PJJabY1ZfoCfl8XQ6PMj2",[],{"data":8529,"content":8530,"nodeType":998},{},[8531],{"data":8532,"marks":8533,"value":8535,"nodeType":867},{},[8534],{"type":916},"Doko’s Panel",{"data":8537,"content":8538,"nodeType":881},{},[8539],{"data":8540,"marks":8541,"value":8542,"nodeType":867},{},[],"Let’s take a closer look at the panels themselves. We'll start with the default version of Doko's Panel since it’s the most established. It provides a multi-functional framework targeting users of Google, Microsoft Entra, Okta, and popular cryptocurrency exchanges including Abra, Coinbase, Gemini, and Kraken. Its core functionality resides in a client-side JavaScript file (client.js) that establishes the real-time feedback loop between the victim's browser and the operator's C2.",{"data":8544,"content":8545,"nodeType":881},{},[8546],{"data":8547,"marks":8548,"value":8549,"nodeType":867},{},[],"The technical indicators that characterize Doko's Panel in its standard form include:",{"data":8551,"content":8552,"nodeType":3126},{},[8553,8568,8583,8598],{"data":8554,"content":8555,"nodeType":3061},{},[8556],{"data":8557,"content":8558,"nodeType":881},{},[8559,8564],{"data":8560,"marks":8561,"value":8563,"nodeType":867},{},[8562],{"type":916},"client.js",{"data":8565,"marks":8566,"value":8567,"nodeType":867},{},[]," containing a pingServer() function that sends a JSON POST request to /backend.php every second with the structure { action: 'ping', token, window_id, page, os, browser }. If the response contains a redirect key, the victim's browser navigates to that path. ",{"data":8569,"content":8570,"nodeType":3061},{},[8571],{"data":8572,"content":8573,"nodeType":881},{},[8574,8579],{"data":8575,"marks":8576,"value":8578,"nodeType":867},{},[8577],{"type":916},"sendTelegramMessage()",{"data":8580,"marks":8581,"value":8582,"nodeType":867},{},[]," (aliased to sendtg()), a function for relaying real-time credential submissions and session updates to the operator's Telegram channel.",{"data":8584,"content":8585,"nodeType":3061},{},[8586],{"data":8587,"content":8588,"nodeType":881},{},[8589,8594],{"data":8590,"marks":8591,"value":8593,"nodeType":867},{},[8592],{"type":916},"backend.php",{"data":8595,"marks":8596,"value":8597,"nodeType":867},{},[]," as the primary server-side handler for both victim ping actions and admin panel operations (retrieving connected victim information, sending redirect instructions).",{"data":8599,"content":8600,"nodeType":3061},{},[8601],{"data":8602,"content":8603,"nodeType":881},{},[8604,8609],{"data":8605,"marks":8606,"value":8608,"nodeType":867},{},[8607],{"type":916},"j.php",{"data":8610,"marks":8611,"value":8612,"nodeType":867},{},[]," as the endpoint for sending Telegram messages, relaying captured credentials and session logs.",{"data":8614,"content":8615,"nodeType":881},{},[8616],{"data":8617,"marks":8618,"value":8619,"nodeType":867},{},[],"Push found that deployments of Doko's Panel had minimal security by default — anyone was able to view the admin panel and manage visitors' connections without authentication.",{"data":8621,"content":8625,"nodeType":890},{"target":8622},{"sys":8623},{"id":8624,"type":887,"linkType":888},"3glwGSGHdCpf3DLqNmQqN8",[],{"data":8627,"content":8631,"nodeType":890},{"target":8628},{"sys":8629},{"id":8630,"type":887,"linkType":888},"20ymWIXMkmJlw7XYb93c9o",[],{"data":8633,"content":8634,"nodeType":998},{},[8635],{"data":8636,"marks":8637,"value":8639,"nodeType":867},{},[8638],{"type":916},"Panel proliferation and remixes",{"data":8641,"content":8642,"nodeType":881},{},[8643],{"data":8644,"marks":8645,"value":8646,"nodeType":867},{},[],"Access to Doko's Panel has clearly proliferated beyond its original developers, resulting in remixes and variants being distributed across the ecosystem. Push identified a variant titled \"Lord Mensius's Panel\" targeting Koinly (a cryptocurrency tax platform), and another titled \"$$$\" using a template impersonating the Australian Tax Office, also targeting cryptocurrency tax filing. ",{"data":8648,"content":8649,"nodeType":881},{},[8650],{"data":8651,"marks":8652,"value":8653,"nodeType":867},{},[],"The existence of these independently branded forks indicates that the tooling has entered a phase of wider distribution — operators who obtained the original panel source are now customizing and reshipping it for their own purposes. As a result, the tooling is now accessible to a broad population of financially motivated threat actors. ",{"data":8655,"content":8656,"nodeType":998},{},[8657],{"data":8658,"marks":8659,"value":8661,"nodeType":867},{},[8660],{"type":916},"heartbeat/check_redirect variant",{"data":8663,"content":8664,"nodeType":881},{},[8665],{"data":8666,"marks":8667,"value":8668,"nodeType":867},{},[],"In addition to Doko’s Panel and its forks, the site initially detected by Push used a modified variant of Doko's Panel with a different C2 protocol. Rather than the standard ping action, this variant sent two types of regular requests from client.js to the backend:",{"data":8670,"content":8671,"nodeType":3126},{},[8672,8687],{"data":8673,"content":8674,"nodeType":3061},{},[8675],{"data":8676,"content":8677,"nodeType":881},{},[8678,8683],{"data":8679,"marks":8680,"value":8682,"nodeType":867},{},[8681],{"type":916},"Heartbeat",{"data":8684,"marks":8685,"value":8686,"nodeType":867},{},[]," — POST to backend.php with action=heartbeat along with page, token, and window_id.",{"data":8688,"content":8689,"nodeType":3061},{},[8690],{"data":8691,"content":8692,"nodeType":881},{},[8693,8698],{"data":8694,"marks":8695,"value":8697,"nodeType":867},{},[8696],{"type":916},"Check Redirect",{"data":8699,"marks":8700,"value":8701,"nodeType":867},{},[]," — GET to backend.php with parameters action=check_redirect along with token and window_id.",{"data":8703,"content":8704,"nodeType":881},{},[8705],{"data":8706,"marks":8707,"value":8708,"nodeType":867},{},[],"A redirect instruction in response to either request causes the victim's browser to navigate to the specified page. The variant compounds this with a separate inline script embedded in the landing gate HTML — in addition to client.js — that schedules its own sendHeartbeat() and checkRedirect() functions on regular intervals. ",{"data":8710,"content":8714,"nodeType":890},{"target":8711},{"sys":8712},{"id":8713,"type":887,"linkType":888},"6zRc9ublZvEQCxcWtMBSnF",[],{"data":8716,"content":8717,"nodeType":881},{},[8718],{"data":8719,"marks":8720,"value":8721,"nodeType":867},{},[],"Additional technical differentiators for this variant include:",{"data":8723,"content":8724,"nodeType":3126},{},[8725,8740,8755],{"data":8726,"content":8727,"nodeType":3061},{},[8728],{"data":8729,"content":8730,"nodeType":881},{},[8731,8736],{"data":8732,"marks":8733,"value":8735,"nodeType":867},{},[8734],{"type":916},"UUID generation",{"data":8737,"marks":8738,"value":8739,"nodeType":867},{},[]," using Math.random() to replace x in the template xxxxxxxx-xxxx-4xxx-yxxx-xxxxxxxxxxxx, rather than the original Doko's Panel method of constructing a template from [1e7]+-1e3+-4e3+-8e3+-1e11 and replacing [018].",{"data":8741,"content":8742,"nodeType":3061},{},[8743],{"data":8744,"content":8745,"nodeType":881},{},[8746,8751],{"data":8747,"marks":8748,"value":8750,"nodeType":867},{},[8749],{"type":916},"No central Telegram sending function",{"data":8752,"marks":8753,"value":8754,"nodeType":867},{},[],", though j.php still exists and is called from inline scripts on individual phishing pages.",{"data":8756,"content":8757,"nodeType":3061},{},[8758],{"data":8759,"content":8760,"nodeType":881},{},[8761,8766],{"data":8762,"marks":8763,"value":8765,"nodeType":867},{},[8764],{"type":916},"No use of FNV-1a",{"data":8767,"marks":8768,"value":8769,"nodeType":867},{},[]," to hash-generate the window ID.",{"data":8771,"content":8772,"nodeType":881},{},[8773],{"data":8774,"marks":8775,"value":8776,"nodeType":867},{},[],"Push also found sub-variants hosting Okta phishing pages with additional modifications: a minified client.js script, and a renamed backend endpoint (api_FyekIDWY.php replacing backend.php).",{"data":8778,"content":8779,"nodeType":998},{},[8780],{"data":8781,"marks":8782,"value":8784,"nodeType":867},{},[8783],{"type":916},"Revamped admin panel",{"data":8786,"content":8787,"nodeType":881},{},[8788],{"data":8789,"marks":8790,"value":8791,"nodeType":867},{},[],"Push also found examples of a significantly revamped admin panel, including a version from April 2026 specifically targeting Microsoft as an enterprise identity provider. ",{"data":8793,"content":8797,"nodeType":890},{"target":8794},{"sys":8795},{"id":8796,"type":887,"linkType":888},"3ufb4cotpg0f7yoIQJnND0",[],{"data":8799,"content":8800,"nodeType":881},{},[8801],{"data":8802,"marks":8803,"value":8804,"nodeType":867},{},[],"This panel featured a more sophisticated operator interface with an updated look, quick action buttons, and sound notifications.",{"data":8806,"content":8807,"nodeType":881},{},[8808],{"data":8809,"marks":8810,"value":8811,"nodeType":867},{},[],"In addition to the standard compromise flow for acquiring email, password, and OTP, this panel provided operator actions for sending Microsoft Teams call instructions to the victim — a Meeting ID and Passcode rendered on a branded page. This capability likely enables further interaction through a channel that supports screensharing, extending the attacker's reach beyond credential theft into live session manipulation. It also has the potential to make the scenario more believable for the victim.",{"data":8813,"content":8817,"nodeType":890},{"target":8814},{"sys":8815},{"id":8816,"type":887,"linkType":888},"4pg65d1SvTJA3xm6AsxZBp",[],{"data":8819,"content":8820,"nodeType":881},{},[8821],{"data":8822,"marks":8823,"value":8824,"nodeType":867},{},[],"Other capabilities were referenced in the panel's source code but did not appear active in the observed deployment:",{"data":8826,"content":8827,"nodeType":3126},{},[8828,8843],{"data":8829,"content":8830,"nodeType":3061},{},[8831],{"data":8832,"content":8833,"nodeType":881},{},[8834,8839],{"data":8835,"marks":8836,"value":8838,"nodeType":867},{},[8837],{"type":916},"Additional MFA approval pages",{"data":8840,"marks":8841,"value":8842,"nodeType":867},{},[]," for Duo and Okta, with the operator providing a code to display to the victim.",{"data":8844,"content":8845,"nodeType":3061},{},[8846],{"data":8847,"content":8848,"nodeType":881},{},[8849,8854],{"data":8850,"marks":8851,"value":8853,"nodeType":867},{},[8852],{"type":916},"A code execution prompt",{"data":8855,"marks":8856,"value":8857,"nodeType":867},{},[]," to instruct the victim to run a command — the placeholder example being mshta to execute a remote HTA file, suggesting a potential bridge from identity compromise into malware delivery.",{"data":8859,"content":8860,"nodeType":881},{},[8861],{"data":8862,"marks":8863,"value":8864,"nodeType":867},{},[],"The admin panel also included settings for restricting access to specific geographic locations and device types, allowing operators to refine their campaign targeting and also avoid detection from unusual devices (often an indicator that the visitor is not a real human and is actually a security tool or bot).",{"data":8866,"content":8870,"nodeType":890},{"target":8867},{"sys":8868},{"id":8869,"type":887,"linkType":888},"1hebGtxbkyuejWXczwx5n6",[],{"data":8872,"content":8873,"nodeType":908},{},[],{"data":8875,"content":8876,"nodeType":918},{},[8877],{"data":8878,"marks":8879,"value":8881,"nodeType":867},{},[8880],{"type":916},"LLM-generated tells: vibe-coded phishing infrastructure",{"data":8883,"content":8884,"nodeType":881},{},[8885],{"data":8886,"marks":8887,"value":8888,"nodeType":867},{},[],"Evidence of extensive LLM use is extremely prevalent in attacks detected by Push, from LLM-generated phishing kits and tools to vibe-coded cloned pages. Attackers have also been observed leveraging AI–assisted capabilities in SaaS platforms to automate and scale-up their campaigns from an infrastructure and operations perspective. ",{"data":8890,"content":8891,"nodeType":881},{},[8892],{"data":8893,"marks":8894,"value":8895,"nodeType":867},{},[],"The ‘heartbeat’ variant in particular has significant tells of heavy use of LLMs to modify the phishing panel for the operator’s needs. The fact that these are so blatant increases the belief that these tools are being vibe-coded by relatively inexperienced developers with limited regard for operational security.",{"data":8897,"content":8898,"nodeType":881},{},[8899],{"data":8900,"marks":8901,"value":8902,"nodeType":867},{},[],"Some versions of client.js begin with verbose header comments that no human developer would write:",{"data":8904,"content":8907,"nodeType":890},{"target":8905},{"sys":8906},{"id":1258,"type":887,"linkType":888},[],{"data":8909,"content":8910,"nodeType":881},{},[8911],{"data":8912,"marks":8913,"value":8914,"nodeType":867},{},[],"The \"NOTES FOR NEXT SESSION\" header is particularly telling — it's a pattern generated by LLMs that maintain context between chat sessions, not a convention any human developer would adopt in production code, let alone in a phishing kit where operational security should discourage self-documenting infrastructure.",{"data":8916,"content":8917,"nodeType":881},{},[8918],{"data":8919,"marks":8920,"value":8921,"nodeType":867},{},[],"The admin panel HTML contains similarly over-documented opening comments:",{"data":8923,"content":8927,"nodeType":890},{"target":8924},{"sys":8925},{"id":8926,"type":887,"linkType":888},"60snRhz0RIsvLI6OU9RDOk",[],{"data":8929,"content":8930,"nodeType":881},{},[8931],{"data":8932,"marks":8933,"value":8934,"nodeType":867},{},[],"One of the Okta cloned login pages observed by Push contained the following comments suggesting the use of an LLM to create the clone:",{"data":8936,"content":8940,"nodeType":890},{"target":8937},{"sys":8938},{"id":8939,"type":887,"linkType":888},"1WCd5LQ6cfPf1IsNAhPSIT",[],{"data":8942,"content":8943,"nodeType":881},{},[8944],{"data":8945,"marks":8946,"value":8947,"nodeType":867},{},[],"The cloned Microsoft login pages displayed previously contain terser comments, but still typical of useless comments that are included by an LLM rather than a human author, especially a malware/phishing author:",{"data":8949,"content":8953,"nodeType":890},{"target":8950},{"sys":8951},{"id":8952,"type":887,"linkType":888},"6WN59mkiscNmAt8dmOR81c",[],{"data":8955,"content":8956,"nodeType":881},{},[8957],{"data":8958,"marks":8959,"value":8960,"nodeType":867},{},[],"The broken duplication in the heartbeat variant — where an inline script and client.js independently schedule the same backend requests using slightly different data formats — is consistent with an operator pasting requirements into an LLM and accepting the output without understanding the existing codebase well enough to recognize the redundancy.",{"data":8962,"content":8963,"nodeType":881},{},[8964],{"data":8965,"marks":8966,"value":8967,"nodeType":867},{},[],"Clearly, the barrier to entry for building (or forking) and operating a real-time vishing phishing panel is lower than the effectiveness of the tooling might suggest.",{"data":8969,"content":8970,"nodeType":908},{},[],{"data":8972,"content":8973,"nodeType":918},{},[8974],{"data":8975,"marks":8976,"value":8978,"nodeType":867},{},[8977],{"type":916},"Infrastructure clustering and attribution",{"data":8980,"content":8981,"nodeType":881},{},[8982,8986,8991],{"data":8983,"marks":8984,"value":8985,"nodeType":867},{},[],"Through analysis of phishing domains, hosting infrastructure, and technical indicators in the panel source code, ",{"data":8987,"marks":8988,"value":8990,"nodeType":867},{},[8989],{"type":916},"we’re highlighting four distinct infrastructure clusters associated with this tooling. ",{"data":8992,"marks":8993,"value":8994,"nodeType":867},{},[],"While the panels share common heritage, the operators deploying them appear to be separate groups with different infrastructure preferences and operational patterns.",{"data":8996,"content":8997,"nodeType":998},{},[8998],{"data":8999,"marks":9000,"value":9001,"nodeType":867},{},[],"Cluster A",{"data":9003,"content":9004,"nodeType":881},{},[9005,9009,9017],{"data":9006,"marks":9007,"value":9008,"nodeType":867},{},[],"The indicators for Cluster A overlap with ",{"data":9010,"content":9011,"nodeType":876},{"uri":5843},[9012],{"data":9013,"marks":9014,"value":9016,"nodeType":867},{},[9015],{"type":1040},"Mandiant’s reporting on UNC6661",{"data":9018,"marks":9019,"value":9020,"nodeType":867},{},[],". Mandiant also attributes the extortion activity following UNC6661 intrusions to UNC6240, aka ShinyHunters.",{"data":9022,"content":9023,"nodeType":2531},{},[9024,9048,9077,9100,9151,9195,9218,9241],{"data":9025,"content":9026,"nodeType":2438},{},[9027,9038],{"data":9028,"content":9029,"nodeType":2452},{},[9030],{"data":9031,"content":9032,"nodeType":881},{},[9033],{"data":9034,"marks":9035,"value":9037,"nodeType":867},{},[9036],{"type":916},"Tool",{"data":9039,"content":9040,"nodeType":2452},{},[9041],{"data":9042,"content":9043,"nodeType":881},{},[9044],{"data":9045,"marks":9046,"value":8535,"nodeType":867},{},[9047],{"type":916},{"data":9049,"content":9050,"nodeType":2438},{},[9051,9060],{"data":9052,"content":9053,"nodeType":2452},{},[9054],{"data":9055,"content":9056,"nodeType":881},{},[9057],{"data":9058,"marks":9059,"value":8563,"nodeType":867},{},[],{"data":9061,"content":9062,"nodeType":2452},{},[9063,9070],{"data":9064,"content":9065,"nodeType":881},{},[9066],{"data":9067,"marks":9068,"value":9069,"nodeType":867},{},[],"8a01bcb70ec1c101a163c9cb8e074781c1322096f7ae01789f02252854def44c",{"data":9071,"content":9072,"nodeType":881},{},[9073],{"data":9074,"marks":9075,"value":9076,"nodeType":867},{},[],"f574b6e6b3a968cda5f51bec2c090d8eb095fbcfc383314f94bc15676a0d6692",{"data":9078,"content":9079,"nodeType":2438},{},[9080,9090],{"data":9081,"content":9082,"nodeType":2452},{},[9083],{"data":9084,"content":9085,"nodeType":881},{},[9086],{"data":9087,"marks":9088,"value":9089,"nodeType":867},{},[],"Timeframe",{"data":9091,"content":9092,"nodeType":2452},{},[9093],{"data":9094,"content":9095,"nodeType":881},{},[9096],{"data":9097,"marks":9098,"value":9099,"nodeType":867},{},[],"November 2025 - present (April 2026)",{"data":9101,"content":9102,"nodeType":2438},{},[9103,9113],{"data":9104,"content":9105,"nodeType":2452},{},[9106],{"data":9107,"content":9108,"nodeType":881},{},[9109],{"data":9110,"marks":9111,"value":9112,"nodeType":867},{},[],"Domain Patterns",{"data":9114,"content":9115,"nodeType":2452},{},[9116,9123,9130,9137,9144],{"data":9117,"content":9118,"nodeType":881},{},[9119],{"data":9120,"marks":9121,"value":9122,"nodeType":867},{},[],"\u003Ctarget>internal.com\n\u003Ctarget>sso.com",{"data":9124,"content":9125,"nodeType":881},{},[9126],{"data":9127,"marks":9128,"value":9129,"nodeType":867},{},[],"my\u003Ctarget>.com",{"data":9131,"content":9132,"nodeType":881},{},[9133],{"data":9134,"marks":9135,"value":9136,"nodeType":867},{},[],"my\u003Ctarget>internal.com",{"data":9138,"content":9139,"nodeType":881},{},[9140],{"data":9141,"marks":9142,"value":9143,"nodeType":867},{},[],"my\u003Ctarget>manager.com",{"data":9145,"content":9146,"nodeType":881},{},[9147],{"data":9148,"marks":9149,"value":9150,"nodeType":867},{},[],"my\u003Ctarget>sso.com",{"data":9152,"content":9153,"nodeType":2438},{},[9154,9164],{"data":9155,"content":9156,"nodeType":2452},{},[9157],{"data":9158,"content":9159,"nodeType":881},{},[9160],{"data":9161,"marks":9162,"value":9163,"nodeType":867},{},[],"Examples",{"data":9165,"content":9166,"nodeType":2452},{},[9167,9174,9181,9188],{"data":9168,"content":9169,"nodeType":881},{},[9170],{"data":9171,"marks":9172,"value":9173,"nodeType":867},{},[],"mydropboxinternal.com (November 2025)",{"data":9175,"content":9176,"nodeType":881},{},[9177],{"data":9178,"marks":9179,"value":9180,"nodeType":867},{},[],"myxerointernal.com (December 2025)",{"data":9182,"content":9183,"nodeType":881},{},[9184],{"data":9185,"marks":9186,"value":9187,"nodeType":867},{},[],"amazoninternal.com (March 2026)",{"data":9189,"content":9190,"nodeType":881},{},[9191],{"data":9192,"marks":9193,"value":9194,"nodeType":867},{},[],"mydisneysso.com (March 2026)",{"data":9196,"content":9197,"nodeType":2438},{},[9198,9208],{"data":9199,"content":9200,"nodeType":2452},{},[9201],{"data":9202,"content":9203,"nodeType":881},{},[9204],{"data":9205,"marks":9206,"value":9207,"nodeType":867},{},[],"Registrar",{"data":9209,"content":9210,"nodeType":2452},{},[9211],{"data":9212,"content":9213,"nodeType":881},{},[9214],{"data":9215,"marks":9216,"value":9217,"nodeType":867},{},[],"NiceNIC",{"data":9219,"content":9220,"nodeType":2438},{},[9221,9231],{"data":9222,"content":9223,"nodeType":2452},{},[9224],{"data":9225,"content":9226,"nodeType":881},{},[9227],{"data":9228,"marks":9229,"value":9230,"nodeType":867},{},[],"Name Servers",{"data":9232,"content":9233,"nodeType":2452},{},[9234],{"data":9235,"content":9236,"nodeType":881},{},[9237],{"data":9238,"marks":9239,"value":9240,"nodeType":867},{},[],"1984.is FreeDNS",{"data":9242,"content":9243,"nodeType":2438},{},[9244,9254],{"data":9245,"content":9246,"nodeType":2452},{},[9247],{"data":9248,"content":9249,"nodeType":881},{},[9250],{"data":9251,"marks":9252,"value":9253,"nodeType":867},{},[],"Hosting Provider",{"data":9255,"content":9256,"nodeType":2452},{},[9257],{"data":9258,"content":9259,"nodeType":881},{},[9260],{"data":9261,"marks":9262,"value":9263,"nodeType":867},{},[],"Mevspace (AS201814)",{"data":9265,"content":9266,"nodeType":998},{},[9267],{"data":9268,"marks":9269,"value":9270,"nodeType":867},{},[],"Cluster B",{"data":9272,"content":9273,"nodeType":881},{},[9274,9278,9286,9289,9298],{"data":9275,"marks":9276,"value":9277,"nodeType":867},{},[],"The indicators for Cluster B overlap with ",{"data":9279,"content":9280,"nodeType":876},{"uri":5843},[9281],{"data":9282,"marks":9283,"value":9285,"nodeType":867},{},[9284],{"type":1040},"Mandiant’s reporting on UNC6671",{"data":9287,"marks":9288,"value":1253,"nodeType":867},{},[],{"data":9290,"content":9292,"nodeType":876},{"uri":9291},"https://rhisac.org/threat-intelligence/extortion-in-the-enterprise-defending-against-blackfile-attacks/",[9293],{"data":9294,"marks":9295,"value":9297,"nodeType":867},{},[9296],{"type":1040},"Other external reporting",{"data":9299,"marks":9300,"value":9301,"nodeType":867},{},[]," has linked this group to BlackFile-branded extortion and leaks.",{"data":9303,"content":9304,"nodeType":2531},{},[9305,9328,9371,9393,9428,9471,9493,9515],{"data":9306,"content":9307,"nodeType":2438},{},[9308,9318],{"data":9309,"content":9310,"nodeType":2452},{},[9311],{"data":9312,"content":9313,"nodeType":881},{},[9314],{"data":9315,"marks":9316,"value":9037,"nodeType":867},{},[9317],{"type":916},{"data":9319,"content":9320,"nodeType":2452},{},[9321],{"data":9322,"content":9323,"nodeType":881},{},[9324],{"data":9325,"marks":9326,"value":8661,"nodeType":867},{},[9327],{"type":916},{"data":9329,"content":9330,"nodeType":2438},{},[9331,9340],{"data":9332,"content":9333,"nodeType":2452},{},[9334],{"data":9335,"content":9336,"nodeType":881},{},[9337],{"data":9338,"marks":9339,"value":8563,"nodeType":867},{},[],{"data":9341,"content":9342,"nodeType":2452},{},[9343,9350,9357,9364],{"data":9344,"content":9345,"nodeType":881},{},[9346],{"data":9347,"marks":9348,"value":9349,"nodeType":867},{},[],"c0df36ccf88d5c8434b13b58f7a55a9715643a126148b9d078a93075d09cad26",{"data":9351,"content":9352,"nodeType":881},{},[9353],{"data":9354,"marks":9355,"value":9356,"nodeType":867},{},[],"d178dc7108fa9344dae28e350e810352e9e874563496dc7876ee628b11b0eabb",{"data":9358,"content":9359,"nodeType":881},{},[9360],{"data":9361,"marks":9362,"value":9363,"nodeType":867},{},[],"9c0939960e49122196e44b6779fe55dd7a13ab437ce251c8cf35f8c6daf8be21",{"data":9365,"content":9366,"nodeType":881},{},[9367],{"data":9368,"marks":9369,"value":9370,"nodeType":867},{},[],"e8128b33259f7ea4313c942689ba0ba557f17b1474f2e621c62a5b77674fab86",{"data":9372,"content":9373,"nodeType":2438},{},[9374,9383],{"data":9375,"content":9376,"nodeType":2452},{},[9377],{"data":9378,"content":9379,"nodeType":881},{},[9380],{"data":9381,"marks":9382,"value":9089,"nodeType":867},{},[],{"data":9384,"content":9385,"nodeType":2452},{},[9386],{"data":9387,"content":9388,"nodeType":881},{},[9389],{"data":9390,"marks":9391,"value":9392,"nodeType":867},{},[],"January 2026",{"data":9394,"content":9395,"nodeType":2438},{},[9396,9405],{"data":9397,"content":9398,"nodeType":2452},{},[9399],{"data":9400,"content":9401,"nodeType":881},{},[9402],{"data":9403,"marks":9404,"value":9112,"nodeType":867},{},[],{"data":9406,"content":9407,"nodeType":2452},{},[9408,9415,9422],{"data":9409,"content":9410,"nodeType":881},{},[9411],{"data":9412,"marks":9413,"value":9414,"nodeType":867},{},[],"\u003Ctarget>internal.com",{"data":9416,"content":9417,"nodeType":881},{},[9418],{"data":9419,"marks":9420,"value":9421,"nodeType":867},{},[],"\u003Ctarget>sso.com",{"data":9423,"content":9424,"nodeType":881},{},[9425],{"data":9426,"marks":9427,"value":9150,"nodeType":867},{},[],{"data":9429,"content":9430,"nodeType":2438},{},[9431,9440],{"data":9432,"content":9433,"nodeType":2452},{},[9434],{"data":9435,"content":9436,"nodeType":881},{},[9437],{"data":9438,"marks":9439,"value":9163,"nodeType":867},{},[],{"data":9441,"content":9442,"nodeType":2452},{},[9443,9450,9457,9464],{"data":9444,"content":9445,"nodeType":881},{},[9446],{"data":9447,"marks":9448,"value":9449,"nodeType":867},{},[],"epicgamessso[.]com (December 2025)",{"data":9451,"content":9452,"nodeType":881},{},[9453],{"data":9454,"marks":9455,"value":9456,"nodeType":867},{},[],"myadyeninternal[.]com (January 2026)",{"data":9458,"content":9459,"nodeType":881},{},[9460],{"data":9461,"marks":9462,"value":9463,"nodeType":867},{},[],"mysonossso[.]com (January 2026)",{"data":9465,"content":9466,"nodeType":881},{},[9467],{"data":9468,"marks":9469,"value":9470,"nodeType":867},{},[],"sonosinternal[.]com (January 2026)",{"data":9472,"content":9473,"nodeType":2438},{},[9474,9483],{"data":9475,"content":9476,"nodeType":2452},{},[9477],{"data":9478,"content":9479,"nodeType":881},{},[9480],{"data":9481,"marks":9482,"value":9207,"nodeType":867},{},[],{"data":9484,"content":9485,"nodeType":2452},{},[9486],{"data":9487,"content":9488,"nodeType":881},{},[9489],{"data":9490,"marks":9491,"value":9492,"nodeType":867},{},[],"Tucows",{"data":9494,"content":9495,"nodeType":2438},{},[9496,9505],{"data":9497,"content":9498,"nodeType":2452},{},[9499],{"data":9500,"content":9501,"nodeType":881},{},[9502],{"data":9503,"marks":9504,"value":9230,"nodeType":867},{},[],{"data":9506,"content":9507,"nodeType":2452},{},[9508],{"data":9509,"content":9510,"nodeType":881},{},[9511],{"data":9512,"marks":9513,"value":9514,"nodeType":867},{},[],"Njalla",{"data":9516,"content":9517,"nodeType":2438},{},[9518,9527],{"data":9519,"content":9520,"nodeType":2452},{},[9521],{"data":9522,"content":9523,"nodeType":881},{},[9524],{"data":9525,"marks":9526,"value":9253,"nodeType":867},{},[],{"data":9528,"content":9529,"nodeType":2452},{},[9530],{"data":9531,"content":9532,"nodeType":881},{},[9533],{"data":9534,"marks":9535,"value":9536,"nodeType":867},{},[],"Njalla (AS39287)",{"data":9538,"content":9539,"nodeType":998},{},[9540],{"data":9541,"marks":9542,"value":9543,"nodeType":867},{},[],"Cluster C",{"data":9545,"content":9546,"nodeType":881},{},[9547],{"data":9548,"marks":9549,"value":9550,"nodeType":867},{},[],"Cluster C is likely an evolution of Cluster B. Some evidence has been observed tying the backend hosting to Njalla behind the Cloudflare CDN further solidifying the link. The shift to Cloudflare Turnstile protection and subdomain-based targeting represents an operational refinement — moving away from the distinctive [target]internal[.]com pattern that had become a well-known campaign indicator.",{"data":9552,"content":9553,"nodeType":2531},{},[9554,9578,9600,9622,9644,9687,9708,9730],{"data":9555,"content":9556,"nodeType":2438},{},[9557,9567],{"data":9558,"content":9559,"nodeType":2452},{},[9560],{"data":9561,"content":9562,"nodeType":881},{},[9563],{"data":9564,"marks":9565,"value":9037,"nodeType":867},{},[9566],{"type":916},{"data":9568,"content":9569,"nodeType":2452},{},[9570],{"data":9571,"content":9572,"nodeType":881},{},[9573],{"data":9574,"marks":9575,"value":9577,"nodeType":867},{},[9576],{"type":916},"heartbeat/check_redirect variant protected with Cloudflare turnstile",{"data":9579,"content":9580,"nodeType":2438},{},[9581,9590],{"data":9582,"content":9583,"nodeType":2452},{},[9584],{"data":9585,"content":9586,"nodeType":881},{},[9587],{"data":9588,"marks":9589,"value":8563,"nodeType":867},{},[],{"data":9591,"content":9592,"nodeType":2452},{},[9593],{"data":9594,"content":9595,"nodeType":881},{},[9596],{"data":9597,"marks":9598,"value":9599,"nodeType":867},{},[],"cb1d409278b2247af23e7b00ac779b232baaf4ce5f63fdf5ebc3920a38cc6102",{"data":9601,"content":9602,"nodeType":2438},{},[9603,9612],{"data":9604,"content":9605,"nodeType":2452},{},[9606],{"data":9607,"content":9608,"nodeType":881},{},[9609],{"data":9610,"marks":9611,"value":9089,"nodeType":867},{},[],{"data":9613,"content":9614,"nodeType":2452},{},[9615],{"data":9616,"content":9617,"nodeType":881},{},[9618],{"data":9619,"marks":9620,"value":9621,"nodeType":867},{},[],"March 2026 - present (April 2026)",{"data":9623,"content":9624,"nodeType":2438},{},[9625,9634],{"data":9626,"content":9627,"nodeType":2452},{},[9628],{"data":9629,"content":9630,"nodeType":881},{},[9631],{"data":9632,"marks":9633,"value":9112,"nodeType":867},{},[],{"data":9635,"content":9636,"nodeType":2452},{},[9637],{"data":9638,"content":9639,"nodeType":881},{},[9640],{"data":9641,"marks":9642,"value":9643,"nodeType":867},{},[],"\u003Ctarget> subdomain with generic “sso”, “passkey”, “enroll”, “okta” theme root domain",{"data":9645,"content":9646,"nodeType":2438},{},[9647,9656],{"data":9648,"content":9649,"nodeType":2452},{},[9650],{"data":9651,"content":9652,"nodeType":881},{},[9653],{"data":9654,"marks":9655,"value":9163,"nodeType":867},{},[],{"data":9657,"content":9658,"nodeType":2452},{},[9659,9666,9673,9680],{"data":9660,"content":9661,"nodeType":881},{},[9662],{"data":9663,"marks":9664,"value":9665,"nodeType":867},{},[],"\u003Ctarget>.passkeysetup.com (March 2026)",{"data":9667,"content":9668,"nodeType":881},{},[9669],{"data":9670,"marks":9671,"value":9672,"nodeType":867},{},[],"\u003Ctarget>.enrollms.com (March 2026)",{"data":9674,"content":9675,"nodeType":881},{},[9676],{"data":9677,"marks":9678,"value":9679,"nodeType":867},{},[],"\u003Ctarget>.keyokta.com (April 2026)",{"data":9681,"content":9682,"nodeType":881},{},[9683],{"data":9684,"marks":9685,"value":9686,"nodeType":867},{},[],"\u003Ctarget>.passkeywork.com (April 2026)",{"data":9688,"content":9689,"nodeType":2438},{},[9690,9699],{"data":9691,"content":9692,"nodeType":2452},{},[9693],{"data":9694,"content":9695,"nodeType":881},{},[9696],{"data":9697,"marks":9698,"value":9207,"nodeType":867},{},[],{"data":9700,"content":9701,"nodeType":2452},{},[9702],{"data":9703,"content":9704,"nodeType":881},{},[9705],{"data":9706,"marks":9707,"value":9492,"nodeType":867},{},[],{"data":9709,"content":9710,"nodeType":2438},{},[9711,9720],{"data":9712,"content":9713,"nodeType":2452},{},[9714],{"data":9715,"content":9716,"nodeType":881},{},[9717],{"data":9718,"marks":9719,"value":9230,"nodeType":867},{},[],{"data":9721,"content":9722,"nodeType":2452},{},[9723],{"data":9724,"content":9725,"nodeType":881},{},[9726],{"data":9727,"marks":9728,"value":9729,"nodeType":867},{},[],"Cloudflare",{"data":9731,"content":9732,"nodeType":2438},{},[9733,9742],{"data":9734,"content":9735,"nodeType":2452},{},[9736],{"data":9737,"content":9738,"nodeType":881},{},[9739],{"data":9740,"marks":9741,"value":9253,"nodeType":867},{},[],{"data":9743,"content":9744,"nodeType":2452},{},[9745],{"data":9746,"content":9747,"nodeType":881},{},[9748],{"data":9749,"marks":9750,"value":9751,"nodeType":867},{},[],"Cloudflare (AS13335)",{"data":9753,"content":9754,"nodeType":998},{},[9755],{"data":9756,"marks":9757,"value":9758,"nodeType":867},{},[],"Cluster D",{"data":9760,"content":9761,"nodeType":2531},{},[9762,9786,9808,9830,9852,9881,9902,9923],{"data":9763,"content":9764,"nodeType":2438},{},[9765,9775],{"data":9766,"content":9767,"nodeType":2452},{},[9768],{"data":9769,"content":9770,"nodeType":881},{},[9771],{"data":9772,"marks":9773,"value":9037,"nodeType":867},{},[9774],{"type":916},{"data":9776,"content":9777,"nodeType":2452},{},[9778],{"data":9779,"content":9780,"nodeType":881},{},[9781],{"data":9782,"marks":9783,"value":9785,"nodeType":867},{},[9784],{"type":916},"heartbeat/check_redirect variant (minified)",{"data":9787,"content":9788,"nodeType":2438},{},[9789,9798],{"data":9790,"content":9791,"nodeType":2452},{},[9792],{"data":9793,"content":9794,"nodeType":881},{},[9795],{"data":9796,"marks":9797,"value":8563,"nodeType":867},{},[],{"data":9799,"content":9800,"nodeType":2452},{},[9801],{"data":9802,"content":9803,"nodeType":881},{},[9804],{"data":9805,"marks":9806,"value":9807,"nodeType":867},{},[],"9d65dd34384b441505e6b67647153c02d5c367bb53da36ce36a392e70b37940a",{"data":9809,"content":9810,"nodeType":2438},{},[9811,9820],{"data":9812,"content":9813,"nodeType":2452},{},[9814],{"data":9815,"content":9816,"nodeType":881},{},[9817],{"data":9818,"marks":9819,"value":9089,"nodeType":867},{},[],{"data":9821,"content":9822,"nodeType":2452},{},[9823],{"data":9824,"content":9825,"nodeType":881},{},[9826],{"data":9827,"marks":9828,"value":9829,"nodeType":867},{},[],"April 2026 (low volume)",{"data":9831,"content":9832,"nodeType":2438},{},[9833,9842],{"data":9834,"content":9835,"nodeType":2452},{},[9836],{"data":9837,"content":9838,"nodeType":881},{},[9839],{"data":9840,"marks":9841,"value":9112,"nodeType":867},{},[],{"data":9843,"content":9844,"nodeType":2452},{},[9845],{"data":9846,"content":9847,"nodeType":881},{},[9848],{"data":9849,"marks":9850,"value":9851,"nodeType":867},{},[],"\u003Ctarget> subdomain with generic “passkey”, “portal”, “okta” theme root domain",{"data":9853,"content":9854,"nodeType":2438},{},[9855,9864],{"data":9856,"content":9857,"nodeType":2452},{},[9858],{"data":9859,"content":9860,"nodeType":881},{},[9861],{"data":9862,"marks":9863,"value":9163,"nodeType":867},{},[],{"data":9865,"content":9866,"nodeType":2452},{},[9867,9874],{"data":9868,"content":9869,"nodeType":881},{},[9870],{"data":9871,"marks":9872,"value":9873,"nodeType":867},{},[],"\u003Ctarget>.passkeyportalsetup.com",{"data":9875,"content":9876,"nodeType":881},{},[9877],{"data":9878,"marks":9879,"value":9880,"nodeType":867},{},[],"\u003Ctarget>.addoktapasskey.com",{"data":9882,"content":9883,"nodeType":2438},{},[9884,9893],{"data":9885,"content":9886,"nodeType":2452},{},[9887],{"data":9888,"content":9889,"nodeType":881},{},[9890],{"data":9891,"marks":9892,"value":9207,"nodeType":867},{},[],{"data":9894,"content":9895,"nodeType":2452},{},[9896],{"data":9897,"content":9898,"nodeType":881},{},[9899],{"data":9900,"marks":9901,"value":9217,"nodeType":867},{},[],{"data":9903,"content":9904,"nodeType":2438},{},[9905,9914],{"data":9906,"content":9907,"nodeType":2452},{},[9908],{"data":9909,"content":9910,"nodeType":881},{},[9911],{"data":9912,"marks":9913,"value":9230,"nodeType":867},{},[],{"data":9915,"content":9916,"nodeType":2452},{},[9917],{"data":9918,"content":9919,"nodeType":881},{},[9920],{"data":9921,"marks":9922,"value":9729,"nodeType":867},{},[],{"data":9924,"content":9925,"nodeType":2438},{},[9926,9935],{"data":9927,"content":9928,"nodeType":2452},{},[9929],{"data":9930,"content":9931,"nodeType":881},{},[9932],{"data":9933,"marks":9934,"value":9253,"nodeType":867},{},[],{"data":9936,"content":9937,"nodeType":2452},{},[9938],{"data":9939,"content":9940,"nodeType":881},{},[9941],{"data":9942,"marks":9943,"value":9751,"nodeType":867},{},[],{"data":9945,"content":9946,"nodeType":908},{},[],{"data":9948,"content":9949,"nodeType":918},{},[9950],{"data":9951,"marks":9952,"value":9954,"nodeType":867},{},[9953],{"type":916},"Detection considerations",{"data":9956,"content":9957,"nodeType":881},{},[9958],{"data":9959,"marks":9960,"value":9961,"nodeType":867},{},[],"For Push, the detection approach to these panels is fundamentally the same as for any other phishing kit — behavioral analysis of the rendered page in the browser, regardless of the C2 protocol running underneath. ",{"data":9963,"content":9964,"nodeType":881},{},[9965],{"data":9966,"marks":9967,"value":9968,"nodeType":867},{},[],"The main operational difference is on the operator end, where the human-in-the-loop interaction replaces fully automated credential harvesting. This has implications for defenders relying on proactive infrastructure scanning: the gated landing pages, anti-bot checks, and operator-approval requirements mean the malicious content is only served to active targets, making it significantly harder for automated scanners to discover and flag these domains before they're used against a victim.",{"data":9970,"content":9971,"nodeType":881},{},[9972,9977],{"data":9973,"marks":9974,"value":9976,"nodeType":867},{},[9975],{"type":916},"The phone call as delivery vector eliminates the email-based detection surface that most organizations rely on as their primary phishing defense. ",{"data":9978,"marks":9979,"value":9980,"nodeType":867},{},[],"Operator-gated payload delivery further reduces the likelihood that these sites will be flagged as malicious and added to known-bad detection lists (and in any case, it’s trivial for attackers to spin up new ones). This reinforces the need for browser-based detection at the point the user interacts with the page, analyzing it in real time for malicious content without relying on static IoCs. ",{"data":9982,"content":9983,"nodeType":908},{},[],{"data":9985,"content":9986,"nodeType":918},{},[9987],{"data":9988,"marks":9989,"value":2382,"nodeType":867},{},[9990],{"type":916},{"data":9992,"content":9993,"nodeType":881},{},[9994,9998,10004],{"data":9995,"marks":9996,"value":9997,"nodeType":867},{},[],"Short-lived IoCs are of limited value when tackling modern phishing attacks due to the rate at which attackers are able to ",{"data":9999,"content":10000,"nodeType":876},{"uri":2392},[10001],{"data":10002,"marks":10003,"value":2397,"nodeType":867},{},[],{"data":10005,"marks":10006,"value":10007,"nodeType":867},{},[]," in the attack chain, often dynamically serving different URLs to site visitors. ",{"data":10009,"content":10010,"nodeType":881},{},[10011,10014,10022],{"data":10012,"marks":10013,"value":21,"nodeType":867},{},[],{"data":10015,"content":10017,"nodeType":876},{"uri":10016},"https://www.virustotal.com/gui/collection/0f745e9da6ef7664444594a7ee930cfe5a9d8bd6c2f039dcde818599b8926610",[10018],{"data":10019,"marks":10020,"value":10021,"nodeType":867},{},[],"The full list of IoCs is on VirusTotal here. ",{"data":10023,"marks":10024,"value":21,"nodeType":867},{},[],{"data":10026,"content":10027,"nodeType":881},{},[10028],{"data":10029,"marks":10030,"value":2338,"nodeType":867},{},[10031],{"type":916},{"data":10033,"content":10034,"nodeType":908},{},[],{"data":10036,"content":10037,"nodeType":918},{},[10038],{"data":10039,"marks":10040,"value":10042,"nodeType":867},{},[10041],{"type":916},"Learn more about Push",{"data":10044,"content":10045,"nodeType":881},{},[10046,10050,10056],{"data":10047,"marks":10048,"value":10049,"nodeType":867},{},[],"Push Security is the most powerful AI-native security tool in the browser. Think EDR, but for the browser — high-fidelity telemetry and real-time control across every session, on every device, with no browser migration required.\n\nSecurity teams use Push to detect and stop advanced browser-based attacks like AiTM phishing, ClickFix, and session hijacking; gain visibility and control over AI tool usage across their workforce; harden identities by surfacing credential reuse, SSO gaps, and shadow IT; and support data loss and insider investigations with browser-layer telemetry that other tools can't see.\n\nBook a ",{"data":10051,"content":10052,"nodeType":876},{"uri":1629},[10053],{"data":10054,"marks":10055,"value":3399,"nodeType":867},{},[],{"data":10057,"marks":10058,"value":1639,"nodeType":867},{},[],"We infiltrated a criminal phishing panel: here’s what we found","We got an inside look at a phishing panel used in criminal campaigns linked to operators like ShinyHunters and BlackFile. Here’s what we found.","2026-05-07T00:00:00.000Z","inside-criminal-phishing-panel",{"items":10064},[10065,10067],{"sys":10066,"name":2547},{"id":2546},{"sys":10068,"name":342},{"id":2550},{"items":10070},[10071],{"fullName":10072,"firstName":10073,"jobTitle":851,"profilePicture":10074},"Push Security Research Team","Research",{"url":10075},"https://images.ctfassets.net/y1cdw1ablpvd/7LpkwyXbOZ8WCVTAXzULmC/bfa3634c78ee9dfbee6606ba5519918b/push-round.png",{"__typename":1742,"sys":10077,"content":10079,"title":10830,"synopsis":10831,"hashTags":59,"publishedDate":10832,"slug":10833,"tagsCollection":10834,"authorsCollection":10840},{"id":10078},"Lq2AFQ8VG2rMEe4h2CYuH",{"json":10080},{"data":10081,"content":10082,"nodeType":1640},{},[10083,10111,10144,10151,10157,10160,10168,10175,10181,10200,10207,10215,10235,10251,10258,10265,10268,10276,10283,10290,10353,10360,10368,10380,10387,10394,10400,10408,10415,10422,10429,10436,10442,10450,10457,10542,10548,10551,10559,10566,10582,10589,10596,10602,10621,10624,10632,10639,10645,10663,10670,10677,10683,10686,10693,10700,10707,10713,10720,10726,10732,10757,10763,10775,10782,10789],{"data":10084,"content":10085,"nodeType":881},{},[10086,10090,10098,10102,10107],{"data":10087,"marks":10088,"value":10089,"nodeType":867},{},[],"This week, a user going by the name of “ShinyHunters” (though allegedly not ",{"data":10091,"content":10092,"nodeType":876},{"uri":3051},[10093],{"data":10094,"marks":10095,"value":10097,"nodeType":867},{},[10096],{"type":1040},"actual ShinyHunters",{"data":10099,"marks":10100,"value":10101,"nodeType":867},{},[],", but someone imitating them in an attempt to trade off their credibility) posted on a breach forum claiming access keys, source code, and database data stolen from cloud development platform provider ",{"data":10103,"marks":10104,"value":10106,"nodeType":867},{},[10105],{"type":916},"Vercel",{"data":10108,"marks":10109,"value":10110,"nodeType":867},{},[],". ",{"data":10112,"content":10113,"nodeType":881},{},[10114,10118,10127,10131,10140],{"data":10115,"marks":10116,"value":10117,"nodeType":867},{},[],"This happened because a Vercel employee had connected an AI app, Context.ai, into their Google Workspace tenant. When Context.ai was compromised — ",{"data":10119,"content":10121,"nodeType":876},{"uri":10120},"https://www.infostealers.com/article/breaking-vercel-breach-linked-to-infostealer-infection-at-context-ai/",[10122],{"data":10123,"marks":10124,"value":10126,"nodeType":867},{},[10125],{"type":1040},"allegedly the result of an infostealer infection from an employee searching for Roblox cheats",{"data":10128,"marks":10129,"value":10130,"nodeType":867},{},[]," — the attacker was able to leverage OAuth tokens stored in Context.ai’s Supabase platform to access downstream customer accounts (pointing to a heavily permissioned victim, probably a developer, possibly even a ",{"data":10132,"content":10134,"nodeType":876},{"uri":10133},"https://pushsecurity.com/blog/browser-sync-attacks-where-personal-account-hacks-lead-to-corporate-breaches/",[10135],{"data":10136,"marks":10137,"value":10139,"nodeType":867},{},[10138],{"type":1040},"personal device with access to corp credentials",{"data":10141,"marks":10142,"value":10143,"nodeType":867},{},[],"). ",{"data":10145,"content":10146,"nodeType":881},{},[10147],{"data":10148,"marks":10149,"value":10150,"nodeType":867},{},[],"This access included a Vercel employee’s Google Workspace account. This particular user had significant access to data and secrets in Vercel’s systems, including internal dashboards, employee records, API keys, NPM tokens, and GitHub tokens, which the attacker was able to exfiltrate, holding Vercel to ransom for $2 million. ",{"data":10152,"content":10156,"nodeType":890},{"target":10153},{"sys":10154},{"id":10155,"type":887,"linkType":888},"6Ft8aSnzfYVZ7j57mYeXgQ",[],{"data":10158,"content":10159,"nodeType":908},{},[],{"data":10161,"content":10162,"nodeType":918},{},[10163],{"data":10164,"marks":10165,"value":10167,"nodeType":867},{},[10166],{"type":916},"How did this happen, and what could have stopped it?",{"data":10169,"content":10170,"nodeType":881},{},[10171],{"data":10172,"marks":10173,"value":10174,"nodeType":867},{},[],"From Vercel’s perspective, this attack could have been avoided had their employees been blocked from adding new OAuth integrations without admin approval (a toggle in their Google admin panel, and an essential control in a well-configured environment). Or, if the integration had been flagged in a routine audit and removed. ",{"data":10176,"content":10180,"nodeType":890},{"target":10177},{"sys":10178},{"id":10179,"type":887,"linkType":888},"b5HFvY1m6RnuXL3a95jVt",[],{"data":10182,"content":10183,"nodeType":881},{},[10184,10188,10196],{"data":10185,"marks":10186,"value":10187,"nodeType":867},{},[],"It probably should have been removed, too. The particular OAuth app that was connected into the environment was a deprecated “AI Office Suite” product intended for consumer use. ",{"data":10189,"content":10191,"nodeType":876},{"uri":10190},"https://context.ai/security-update",[10192],{"data":10193,"marks":10194,"value":10195,"nodeType":867},{},[],"According to Context.ai",{"data":10197,"marks":10198,"value":10199,"nodeType":867},{},[],", Vercel aren’t even a registered customer — adding more evidence that this was probably the result of a self-service trial that was subsequently forgotten about. That consumer product has also since been replaced by an enterprise product. But for whatever reason, the access hadn’t been revoked (from either side). ",{"data":10201,"content":10202,"nodeType":881},{},[10203],{"data":10204,"marks":10205,"value":10206,"nodeType":867},{},[],"The elephant in the room is that Context.ai is an AI app. Most organizations are rightly nervous about employees adding unapproved AI SaaS into their environment. Having employees use shadow AI in the form of LLMs is one thing — users uploading sensitive data to unapproved apps or external tenants being the key concern. But OAuth grants are even more dangerous. Because if that app or vendor is compromised, the apps and accounts you’ve integrated it with are also at risk — which is what was exploited here. ",{"data":10208,"content":10209,"nodeType":998},{},[10210],{"data":10211,"marks":10212,"value":10214,"nodeType":867},{},[10213],{"type":916},"Where’s the fault?",{"data":10216,"content":10217,"nodeType":881},{},[10218,10222,10231],{"data":10219,"marks":10220,"value":10221,"nodeType":867},{},[],"It’s easy to point fingers here. There are multiple control gaps and failures for both parties. Vercel should have disabled OAuth grants without admin approval, and regularly audited the connections in their environment. From a vendor's perspective, they could have also default applied a control that ",{"data":10223,"content":10225,"nodeType":876},{"uri":10224},"https://vercel.com/kb/bulletin/vercel-april-2026-security-incident",[10226],{"data":10227,"marks":10228,"value":10230,"nodeType":867},{},[10229],{"type":1040},"prevents secret environment variables from being read",{"data":10232,"marks":10233,"value":10234,"nodeType":867},{},[]," — which would have significantly reduced the impact to Vercel customers from the data breach. ",{"data":10236,"content":10237,"nodeType":881},{},[10238,10242,10247],{"data":10239,"marks":10240,"value":10241,"nodeType":867},{},[],"Context.ai comes off worse. They could and should have had better separation of accounts and privileges — and if true, their users really shouldn’t be downloading Roblox scripts on devices they use for work access. It’s important to say ",{"data":10243,"marks":10244,"value":10246,"nodeType":867},{},[10245],{"type":1431},"if true",{"data":10248,"marks":10249,"value":10250,"nodeType":867},{},[]," here, but the prospect of third parties accessing your environment from insecure devices that they use for gaming is the stuff of nightmares for enterprise security and compliance teams.",{"data":10252,"content":10253,"nodeType":881},{},[10254],{"data":10255,"marks":10256,"value":10257,"nodeType":867},{},[],"You definitely don’t want to be Context.ai in this scenario. The reputational harm could be pretty significant, and is a wake-up call for other SaaS vendors to check that their house is in order. But although Vercel have responded quickly and transparently to the incident, this could only really have happened as a result of technical and procedural control gaps on their end.",{"data":10259,"content":10260,"nodeType":881},{},[10261],{"data":10262,"marks":10263,"value":10264,"nodeType":867},{},[],"It’s worth taking a step back and looking at the bigger picture here — and how these issues might impact your organization too. ",{"data":10266,"content":10267,"nodeType":908},{},[],{"data":10269,"content":10270,"nodeType":918},{},[10271],{"data":10272,"marks":10273,"value":10275,"nodeType":867},{},[10274],{"type":916},"Shadow AI is still just shadow SaaS – but the AI scramble is a force multiplier",{"data":10277,"content":10278,"nodeType":881},{},[10279],{"data":10280,"marks":10281,"value":10282,"nodeType":867},{},[],"Shadow IT, and in particular shadow SaaS, is not a new problem. Most organizations run heavily (or exclusively) on SaaS, accessed in the browser, with hundreds of apps per enterprise. Unmanaged, self-adopted apps have been a thorn in the side of security teams for some time. ",{"data":10284,"content":10285,"nodeType":881},{},[10286],{"data":10287,"marks":10288,"value":10289,"nodeType":867},{},[],"There are essentially four kinds of shadow IT to be wary of in the context of AI apps:",{"data":10291,"content":10292,"nodeType":3126},{},[10293,10308,10323,10338],{"data":10294,"content":10295,"nodeType":3061},{},[10296],{"data":10297,"content":10298,"nodeType":881},{},[10299,10304],{"data":10300,"marks":10301,"value":10303,"nodeType":867},{},[10302],{"type":916},"Shadow apps:",{"data":10305,"marks":10306,"value":10307,"nodeType":867},{},[]," Apps that employees have signed up to and are using for business purposes without business approval. This includes apps signed up to with a corporate account or personal account. ",{"data":10309,"content":10310,"nodeType":3061},{},[10311],{"data":10312,"content":10313,"nodeType":881},{},[10314,10319],{"data":10315,"marks":10316,"value":10318,"nodeType":867},{},[10317],{"type":916},"Shadow tenants:",{"data":10320,"marks":10321,"value":10322,"nodeType":867},{},[]," Apps that employees are accessing with personal accounts, essentially creating shadow tenants outside of your organization’s control — even if you’ve approved the app itself.",{"data":10324,"content":10325,"nodeType":3061},{},[10326],{"data":10327,"content":10328,"nodeType":881},{},[10329,10334],{"data":10330,"marks":10331,"value":10333,"nodeType":867},{},[10332],{"type":916},"Shadow extensions:",{"data":10335,"marks":10336,"value":10337,"nodeType":867},{},[]," Many AI apps come with an extension counterpart, along with countless third-party extensions that are either untrustworthy or downright malicious. Browser extensions add another angle to the equation by presenting visibility beyond the application into browser activity. ",{"data":10339,"content":10340,"nodeType":3061},{},[10341],{"data":10342,"content":10343,"nodeType":881},{},[10344,10349],{"data":10345,"marks":10346,"value":10348,"nodeType":867},{},[10347],{"type":916},"Shadow integrations:",{"data":10350,"marks":10351,"value":10352,"nodeType":867},{},[]," OAuth connections across apps that aren’t known or approved. Even if an app itself is approved, plugging that app directly into your primary enterprise apps — with all the sensitive data and functionality therein — isn't necessarily also approved.  ",{"data":10354,"content":10355,"nodeType":881},{},[10356],{"data":10357,"marks":10358,"value":10359,"nodeType":867},{},[],"In the Vercel case, we’re talking specifically about shadow integrations. But all of these present a key risk to your organization. ",{"data":10361,"content":10362,"nodeType":998},{},[10363],{"data":10364,"marks":10365,"value":10367,"nodeType":867},{},[10366],{"type":916},"The web of OAuth sprawl spans way beyond Google and Microsoft ",{"data":10369,"content":10370,"nodeType":881},{},[10371,10376],{"data":10372,"marks":10373,"value":10375,"nodeType":867},{},[10374],{"type":916},"On average we see 17 unique AI app integrations per organization in Microsoft and Google alone",{"data":10377,"marks":10378,"value":10379,"nodeType":867},{},[],". If you consider that most organizations have probably approved 1 or 2 max for business use, and may have approved none at all for app-to-app OAuth connectivity, that’s quite a significant difference. ",{"data":10381,"content":10382,"nodeType":881},{},[10383],{"data":10384,"marks":10385,"value":10386,"nodeType":867},{},[],"The number of connections outside of these core platforms is significantly higher. Just think how the typical AI app operates. If you want it to be able to effectively automate workflows — pull data from one app, aggregate and analyze it in another, present that information in a report, dashboard, or presentation, and then distribute it — that’s a fair few integrations in just one workflow. MCP connections use OAuth to achieve this interconnectivity in the same way as any other SaaS app.",{"data":10388,"content":10389,"nodeType":881},{},[10390],{"data":10391,"marks":10392,"value":10393,"nodeType":867},{},[],"We used to talk about automation apps like Zapier as being a goldmine for attackers. Well, AI apps are on their way to being even more interconnected, more frequently used, and more flexible in terms of how attackers can abuse them. ",{"data":10395,"content":10399,"nodeType":890},{"target":10396},{"sys":10397},{"id":10398,"type":887,"linkType":888},"4FiWyVw7mpVBA5uBVJoOKL",[],{"data":10401,"content":10402,"nodeType":998},{},[10403],{"data":10404,"marks":10405,"value":10407,"nodeType":867},{},[10406],{"type":916},"A note on OAuth configuration complexity",{"data":10409,"content":10410,"nodeType":881},{},[10411],{"data":10412,"marks":10413,"value":10414,"nodeType":867},{},[],"A common misconception is that when a regular user consents to an OAuth app (let's use Google Workspace as the example) the app only gets access to the things they can directly access. Technically that's true — the access is scoped to that user's permissions. But in practice, the blast radius is almost always bigger than people think.",{"data":10416,"content":10417,"nodeType":881},{},[10418],{"data":10419,"marks":10420,"value":10421,"nodeType":867},{},[],"The scope includes shared drives, shared calendars, documents shared with them, and any other collaborative resources. A single well-permissioned user (think: developer with access to secrets, dashboards, and internal tooling) is more than enough to cause serious damage through a single OAuth grant. ",{"data":10423,"content":10424,"nodeType":881},{},[10425],{"data":10426,"marks":10427,"value":10428,"nodeType":867},{},[],"The scopes themselves are often deceptively broad. An app requesting https://www.googleapis.com/auth/drive gets full read/write access to everything the user can see in Drive — not just their personal files. And the blast radius is further contingent on the data and user permission hygiene in these broader environments. ",{"data":10430,"content":10431,"nodeType":881},{},[10432],{"data":10433,"marks":10434,"value":10435,"nodeType":867},{},[],"So if your environment hasn't got cleanly separated access and permissions for different users and groups, an attacker compromising a \"normal\" user account can end up with extensive access. You don't need tenant-wide admin access when a normal user's access already spans the crown jewels.",{"data":10437,"content":10441,"nodeType":890},{"target":10438},{"sys":10439},{"id":10440,"type":887,"linkType":888},"2t81AnAHx2On3fBynM4vVe",[],{"data":10443,"content":10444,"nodeType":998},{},[10445],{"data":10446,"marks":10447,"value":10449,"nodeType":867},{},[10448],{"type":916},"Unsurprisingly, OAuth breaches are stacking up",{"data":10451,"content":10452,"nodeType":881},{},[10453],{"data":10454,"marks":10455,"value":10456,"nodeType":867},{},[],"Widespread OAuth interconnectedness isn’t just an AI app problem. Attackers have been exploiting this for some time:",{"data":10458,"content":10459,"nodeType":3126},{},[10460,10506],{"data":10461,"content":10462,"nodeType":3061},{},[10463],{"data":10464,"content":10465,"nodeType":881},{},[10466,10470,10477,10481,10489,10493,10502],{"data":10467,"marks":10468,"value":10469,"nodeType":867},{},[],"In 2025, ",{"data":10471,"content":10472,"nodeType":876},{"uri":3051},[10473],{"data":10474,"marks":10475,"value":3056,"nodeType":867},{},[10476],{"type":1040},{"data":10478,"marks":10479,"value":10480,"nodeType":867},{},[]," launched OAuth-driven supply chain attacks against Salesforce and Google Workspace tenants after breaching Salesloft (specifically the ",{"data":10482,"content":10483,"nodeType":876},{"uri":5752},[10484],{"data":10485,"marks":10486,"value":10488,"nodeType":867},{},[10487],{"type":1040},"Salesloft Drift",{"data":10490,"marks":10491,"value":10492,"nodeType":867},{},[]," platform) and ",{"data":10494,"content":10496,"nodeType":876},{"uri":10495},"https://www.bleepingcomputer.com/news/security/salesforce-investigates-customer-data-theft-via-gainsight-breach/",[10497],{"data":10498,"marks":10499,"value":10501,"nodeType":867},{},[10500],{"type":1040},"Gainsight",{"data":10503,"marks":10504,"value":10505,"nodeType":867},{},[],". In total, over 1000 organizations were impacted, including Google, Cloudflare, Rubrik, Elastic, Proofpoint, JFrog, Zscaler, Tenable, Palo Alto Networks, CyberArk, BeyondTrust, Qualys, and many more, with over 1.5B records stolen. ",{"data":10507,"content":10508,"nodeType":3061},{},[10509],{"data":10510,"content":10511,"nodeType":881},{},[10512,10516,10525,10529,10538],{"data":10513,"marks":10514,"value":10515,"nodeType":867},{},[],"More recently, Snowflake customers were impacted after a ",{"data":10517,"content":10519,"nodeType":876},{"uri":10518},"https://www.bleepingcomputer.com/news/security/snowflake-customers-hit-in-data-theft-attacks-after-saas-integrator-breach/",[10520],{"data":10521,"marks":10522,"value":10524,"nodeType":867},{},[10523],{"type":1040},"breach at data anomaly detection company Anodot",{"data":10526,"marks":10527,"value":10528,"nodeType":867},{},[]," where the attacker attempted to leverage the stolen authentication tokens to access Salesforce data, with ",{"data":10530,"content":10532,"nodeType":876},{"uri":10531},"https://www.bleepingcomputer.com/news/security/stolen-rockstar-games-analytics-data-leaked-by-extortion-gang/",[10533],{"data":10534,"marks":10535,"value":10537,"nodeType":867},{},[10536],{"type":1040},"Rockstar",{"data":10539,"marks":10540,"value":10541,"nodeType":867},{},[]," a high-profile victim of the breach (again linked to Scattered Lapsus$ Hunters). ",{"data":10543,"content":10547,"nodeType":890},{"target":10544},{"sys":10545},{"id":10546,"type":887,"linkType":888},"3oqoL9L3fxetFcIhnfQhMQ",[],{"data":10549,"content":10550,"nodeType":908},{},[],{"data":10552,"content":10553,"nodeType":918},{},[10554],{"data":10555,"marks":10556,"value":10558,"nodeType":867},{},[10557],{"type":916},"Infostealers continue to drive corporate breaches",{"data":10560,"content":10561,"nodeType":881},{},[10562],{"data":10563,"marks":10564,"value":10565,"nodeType":867},{},[],"While unverified, Hudson Rock’s case for an infostealer breach being the root cause of the Context.ai breach seems believable. Infostealer infections have been one of the leading security threats for some time, fuelling breaches powered by stolen credentials and session tokens.",{"data":10567,"content":10568,"nodeType":881},{},[10569,10573,10578],{"data":10570,"marks":10571,"value":10572,"nodeType":867},{},[],"With the assumed rise in MFA coverage, it’s often surprising to security teams that stolen credentials are still a problem. ",{"data":10574,"marks":10575,"value":10577,"nodeType":867},{},[10576],{"type":916},"But of the last million logins we saw, 1 in 4 were password logins (not SSO), 2 in 5 were not protected by MFA, and 1 in 5 used a weak, breached, or reused password. ",{"data":10579,"marks":10580,"value":10581,"nodeType":867},{},[],"Plenty of scope for abuse. ",{"data":10583,"content":10584,"nodeType":881},{},[10585],{"data":10586,"marks":10587,"value":10588,"nodeType":867},{},[],"Stolen session tokens are even more valuable to attackers, enabling them to bypass authentication controls by replaying the token in their own browser. In theory, they should only be valid for a limited timeframe, but in practice this can be as many as 90 days, and sometimes indefinite. ",{"data":10590,"content":10591,"nodeType":881},{},[10592],{"data":10593,"marks":10594,"value":10595,"nodeType":867},{},[],"In this case, it seems likely that the compromised device was a developer machine (given the access to Supabase), or potentially even a personal device (given they were installing Roblox cheats…). This is relevant because these personal, developer, and BYOD machines are often less secure — developer machines are often exempt from EDR monitoring or significantly tuned-down (too noisy), while personal devices naturally lack enterprise security software.",{"data":10597,"content":10601,"nodeType":890},{"target":10598},{"sys":10599},{"id":10600,"type":887,"linkType":888},"139oaGgwRKZbwJzyex9LA5",[],{"data":10603,"content":10604,"nodeType":881},{},[10605,10609,10617],{"data":10606,"marks":10607,"value":10608,"nodeType":867},{},[],"We’ve also seen an uptick in developer-oriented phishing and malvertising campaigns. The ",{"data":10610,"content":10611,"nodeType":876},{"uri":1562},[10612],{"data":10613,"marks":10614,"value":10616,"nodeType":867},{},[10615],{"type":1040},"InstallFix campaign",{"data":10618,"marks":10619,"value":10620,"nodeType":867},{},[]," we identified, intercepting users as they attempt to install AI tools like Claude Code and NotebookLM, is an example of this — and also another way that attackers are capitalizing on AI hype. ",{"data":10622,"content":10623,"nodeType":908},{},[],{"data":10625,"content":10626,"nodeType":918},{},[10627],{"data":10628,"marks":10629,"value":10631,"nodeType":867},{},[10630],{"type":916},"Advice for security teams",{"data":10633,"content":10634,"nodeType":881},{},[10635],{"data":10636,"marks":10637,"value":10638,"nodeType":867},{},[],"There are some immediate next steps that we’ll quickly summarize here, as they've already been covered in wider reporting. If you’re a Vercel customer, you should urgently rotate every credential stored as a non-sensitive variable that could have been exposed, enable the sensitive variable feature toggle, and monitor your account for anomalous activity. And if you’re using the specific Context.ai integration, you need to revoke it ASAP and begin a full audit of the connected accounts, both inside Workspace and broader connected apps (this isn’t that easy, as we’ll highlight in a moment). ",{"data":10640,"content":10644,"nodeType":890},{"target":10641},{"sys":10642},{"id":10643,"type":887,"linkType":888},"76HViirkH2R4QAzWg605sv",[],{"data":10646,"content":10647,"nodeType":881},{},[10648,10652,10660],{"data":10649,"marks":10650,"value":10651,"nodeType":867},{},[],"Taking a step back, organizations really need to get their arms around OAuth integrations in their environment. A default-deny approach to allowing users to consent to new integrations, and routinely auditing the ones already in your environment to ensure they’re still definitely required, is essential. Each integration expands your attack surface and could potentially grant an attacker extensive access to your environment. This default-deny approach isn't exactly a new concept for security teams and is the same in principle as what we recently advised for ",{"data":10653,"content":10654,"nodeType":876},{"uri":4917},[10655],{"data":10656,"marks":10657,"value":10659,"nodeType":867},{},[10658],{"type":1040},"browser extension management",{"data":10661,"marks":10662,"value":10110,"nodeType":867},{},[],{"data":10664,"content":10665,"nodeType":881},{},[10666],{"data":10667,"marks":10668,"value":10669,"nodeType":867},{},[],"This is fairly straightforward in your main enterprise cloud environment (think M365 or Google Workspace). But doing it across every SaaS app that allows some level of OAuth integration with another (i.e. every SaaS app) is somewhat harder. Not only do you need to have a comprehensive and up-to-date inventory, you need to be an app admin for every app (not always the case for self-adopted apps) and the particular app needs to give you the control to restrict and remove OAuth grants on behalf of users in your tenant. ",{"data":10671,"content":10672,"nodeType":881},{},[10673],{"data":10674,"marks":10675,"value":10676,"nodeType":867},{},[],"Again, this is not exclusively a Shadow AI problem, even if AI adoption is contributing significantly to the sprawl. ",{"data":10678,"content":10682,"nodeType":890},{"target":10679},{"sys":10680},{"id":10681,"type":887,"linkType":888},"XKKHUiz56G82uwYhbv2Qv",[],{"data":10684,"content":10685,"nodeType":908},{},[],{"data":10687,"content":10688,"nodeType":918},{},[10689],{"data":10690,"marks":10691,"value":6214,"nodeType":867},{},[10692],{"type":916},{"data":10694,"content":10695,"nodeType":881},{},[10696],{"data":10697,"marks":10698,"value":10699,"nodeType":867},{},[],"As we’ve established, there are quite a few pieces to this puzzle. Push can help with all of them. ",{"data":10701,"content":10702,"nodeType":881},{},[10703],{"data":10704,"marks":10705,"value":10706,"nodeType":867},{},[],"Push observes every app login your employees make in their browser, building a comprehensive picture of SaaS and AI use across your organization. This includes how they’re logging in and how secure the login is: did it have MFA, what kind of MFA, was it using a weak or compromised password, did they use SSO, and so on. ",{"data":10708,"content":10712,"nodeType":890},{"target":10709},{"sys":10710},{"id":10711,"type":887,"linkType":888},"2B205bUaLm6vG8mIQ0rJvA",[],{"data":10714,"content":10715,"nodeType":881},{},[10716],{"data":10717,"marks":10718,"value":10719,"nodeType":867},{},[],"Push also tracks OAuth integrations in your environment and gives you the ability to manage and remove them in core environments like M365 and Google Workspace, providing a single platform for you to view, manage, and secure app use across your organization. ",{"data":10721,"content":10725,"nodeType":890},{"target":10722},{"sys":10723},{"id":10724,"type":887,"linkType":888},"eEbdBUfyzZsdIOjFOXHpM",[],{"data":10727,"content":10731,"nodeType":890},{"target":10728},{"sys":10729},{"id":10730,"type":887,"linkType":888},"1MTFxfROuGKxnkHQwWHe8K",[],{"data":10733,"content":10734,"nodeType":881},{},[10735,10739,10744,10748,10753],{"data":10736,"marks":10737,"value":10738,"nodeType":867},{},[],"This makes it easy to surface both vulnerabilities and possible control gaps, and do something about them. But where Push really excels is in the ability to observe and block OAuth connection requests ",{"data":10740,"marks":10741,"value":10743,"nodeType":867},{},[10742],{"type":916},"even outside of your primary enterprise apps.",{"data":10745,"marks":10746,"value":10747,"nodeType":867},{},[]," Using Push, you can detect and block OAuth integration requests as they traverse the browser. This ",{"data":10749,"marks":10750,"value":10752,"nodeType":867},{},[10751],{"type":916},"app-agnostic",{"data":10754,"marks":10755,"value":10756,"nodeType":867},{},[]," level of control is absolutely critical to halting OAuth integration sprawl. ",{"data":10758,"content":10762,"nodeType":890},{"target":10759},{"sys":10760},{"id":10761,"type":887,"linkType":888},"2VZ4uw6MXslXME2ueydGuT",[],{"data":10764,"content":10765,"nodeType":998},{},[10766,10770],{"data":10767,"marks":10768,"value":10769,"nodeType":867},{},[],"And t",{"data":10771,"marks":10772,"value":10774,"nodeType":867},{},[10773],{"type":916},"hat’s not all …",{"data":10776,"content":10777,"nodeType":881},{},[10778],{"data":10779,"marks":10780,"value":10781,"nodeType":867},{},[],"Push’s browser-based security platform also detects and blocks browser-based attacks like AiTM phishing, credential stuffing, malicious browser extensions, device code phishing, ClickFix, and session hijacking in real time. This includes the most prominent infostealer delivery vectors in terms of malvertising and *Fix-style attacks. Push analyzes every web page in every browser session and tab for threats, in real time, with no latency. ",{"data":10783,"content":10784,"nodeType":881},{},[10785],{"data":10786,"marks":10787,"value":10788,"nodeType":867},{},[],"But as we've established, you don't need to wait until it all goes wrong either — you can use Push to proactively find and fix vulnerabilities across the apps that your employees use, like ghost logins, SSO coverage gaps, MFA gaps, vulnerable passwords, risky OAuth integrations, and more to harden your attack surface.",{"data":10790,"content":10791,"nodeType":881},{},[10792,10796,10804,10807,10816,10820,10827],{"data":10793,"marks":10794,"value":10795,"nodeType":867},{},[],"To learn more about Push, ",{"data":10797,"content":10799,"nodeType":876},{"uri":10798},"https://pushsecurity.com/resources/product-brochure",[10800],{"data":10801,"marks":10802,"value":10803,"nodeType":867},{},[],"check out our latest product overview",{"data":10805,"marks":10806,"value":4006,"nodeType":867},{},[],{"data":10808,"content":10810,"nodeType":876},{"uri":10809},"https://pushsecurity.com/product-demo/",[10811],{"data":10812,"marks":10813,"value":10815,"nodeType":867},{},[10814],{"type":1040},"view our demo library",{"data":10817,"marks":10818,"value":10819,"nodeType":867},{},[],", or ",{"data":10821,"content":10822,"nodeType":876},{"uri":1629},[10823],{"data":10824,"marks":10825,"value":10826,"nodeType":867},{},[],"book some time with one of our team for a live demo",{"data":10828,"marks":10829,"value":1947,"nodeType":867},{},[],"Unpacking the Vercel breach: A cautionary tale for Shadow AI and OAuth sprawl","In April 2026, Vercel was compromised via an OAuth app integrated into their Google Workspace tenant stemming from a compromised third-party AI SaaS provider.","2026-04-23T00:00:00.000Z","unpacking-the-vercel-breach",{"items":10835},[10836,10838],{"sys":10837,"name":2547},{"id":2546},{"sys":10839,"name":342},{"id":2550},{"items":10841},[10842],{"fullName":849,"firstName":850,"jobTitle":851,"profilePicture":10843},{"url":855},{"__typename":1742,"sys":10845,"content":10847,"title":11700,"synopsis":11701,"hashTags":59,"publishedDate":11702,"slug":11703,"tagsCollection":11704,"authorsCollection":11710},{"id":10846},"6X3wP0WhtDk2l1jKH2fPIb",{"json":10848},{"data":10849,"content":10850,"nodeType":1640},{},[10851,10857,10900,10907,10914,10917,10925,10932,10940,10979,10996,10999,11007,11014,11021,11028,11044,11059,11066,11082,11089,11105,11126,11146,11202,11214,11234,11240,11247,11254,11261,11268,11291,11297,11304,11311,11318,11330,11355,11358,11366,11373,11380,11387,11406,11412,11435,11442,11449,11573,11579,11586,11593,11596,11604,11611,11630,11637,11645,11648,11667],{"data":10852,"content":10856,"nodeType":890},{"target":10853},{"sys":10854},{"id":10855,"type":887,"linkType":888},"4Lk4sATAlk2wPcevG0cJCu",[],{"data":10858,"content":10859,"nodeType":881},{},[10860,10864,10873,10876,10884,10887,10896],{"data":10861,"marks":10862,"value":10863,"nodeType":867},{},[],"Browser extensions have become one of the most talked-about attack surfaces in security over the past 18 months, and understandably so — a string of high-profile supply chain compromises have collectively impacted tens of millions of users since late 2024 (",{"data":10865,"content":10867,"nodeType":876},{"uri":10866},"https://www.cyberhaven.com/blog/cyberhavens-chrome-extension-security-incident-and-what-were-doing-about-it",[10868],{"data":10869,"marks":10870,"value":10872,"nodeType":867},{},[10871],{"type":1040},"Cyberhaven",{"data":10874,"marks":10875,"value":4006,"nodeType":867},{},[],{"data":10877,"content":10879,"nodeType":876},{"uri":10878},"https://thehackernews.com/2025/12/darkspectre-browser-extension-campaigns.html",[10880],{"data":10881,"marks":10882,"value":10883,"nodeType":867},{},[],"DarkSpectre",{"data":10885,"marks":10886,"value":4006,"nodeType":867},{},[],{"data":10888,"content":10890,"nodeType":876},{"uri":10889},"https://thehackernews.com/2025/12/trust-wallet-chrome-extension-hack.html",[10891],{"data":10892,"marks":10893,"value":10895,"nodeType":867},{},[10894],{"type":1040},"Trust Wallet",{"data":10897,"marks":10898,"value":10899,"nodeType":867},{},[],", among many others). ",{"data":10901,"content":10902,"nodeType":881},{},[10903],{"data":10904,"marks":10905,"value":10906,"nodeType":867},{},[],"But as the industry scrambles to respond, there's a tendency to treat browser extension management as an entirely new paradigm that requires a new approach, particularly risk scoring systems that attempt to rate each extension on a spectrum from safe to dangerous.",{"data":10908,"content":10909,"nodeType":881},{},[10910],{"data":10911,"marks":10912,"value":10913,"nodeType":867},{},[],"We think this framing misses the point, and that it's leading security teams toward a strategy that won't protect them from the attacks that actually cause damage.",{"data":10915,"content":10916,"nodeType":908},{},[],{"data":10918,"content":10919,"nodeType":918},{},[10920],{"data":10921,"marks":10922,"value":10924,"nodeType":867},{},[10923],{"type":916},"The practical problem: \"just remove the high-risk ones\" doesn't work",{"data":10926,"content":10927,"nodeType":881},{},[10928],{"data":10929,"marks":10930,"value":10931,"nodeType":867},{},[],"The strategy we see most often is some version of \"identify and remove the highest-risk extensions.\" On the surface this seems reasonable — you can't address everything, so you prioritize. The problem is that it doesn't materially reduce your exposure to the attacks that are actually happening.",{"data":10933,"content":10934,"nodeType":881},{},[10935],{"data":10936,"marks":10937,"value":10939,"nodeType":867},{},[10938],{"type":916},"Browser extension attacks almost always follow one of two patterns: ",{"data":10941,"content":10942,"nodeType":3126},{},[10943,10953],{"data":10944,"content":10945,"nodeType":3061},{},[10946],{"data":10947,"content":10948,"nodeType":881},{},[10949],{"data":10950,"marks":10951,"value":10952,"nodeType":867},{},[],"A legitimate developer is compromised through consent phishing, session theft, or AiTM phishing, and a malicious update is pushed to the existing user base. Cyberhaven is a good example of this — a developer got consent phished with a specific app that granted the attacker access to the extension store.",{"data":10954,"content":10955,"nodeType":3061},{},[10956],{"data":10957,"content":10958,"nodeType":881},{},[10959,10963,10975],{"data":10960,"marks":10961,"value":10962,"nodeType":867},{},[],"An attacker builds or acquires a clean extension, operates it legitimately until it accumulates a sufficient user base, then deploys a malicious update. GitLab's threat intelligence team documented a cluster of",{"data":10964,"content":10966,"nodeType":876},{"uri":10965},"https://gitlab-com.gitlab.io/gl-security/security-tech-notes/threat-intelligence-tech-notes/malicious-browser-extensions-feb-2025/",[10967,10970],{"data":10968,"marks":10969,"value":3679,"nodeType":867},{},[],{"data":10971,"marks":10972,"value":10974,"nodeType":867},{},[10973],{"type":1040},"16 extensions impacting 3.2 million users",{"data":10976,"marks":10977,"value":10978,"nodeType":867},{},[]," where access had been acquired from original developers rather than via compromise.",{"data":10980,"content":10981,"nodeType":881},{},[10982,10987,10991],{"data":10983,"marks":10984,"value":10986,"nodeType":867},{},[10985],{"type":916},"This means that real-world extension breaches aren't coming from extensions that looked risky beforehand.",{"data":10988,"marks":10989,"value":10990,"nodeType":867},{},[]," If your strategy is \"identify and remove the highest-risk extensions,\" you're optimizing for the wrong thing — because even extensions that score as moderate or low risk by every conventional measure still have the permissions and access needed for a full compromise. ",{"data":10992,"marks":10993,"value":10995,"nodeType":867},{},[10994],{"type":916},"If you skim off the top 10% “riskiest” extensions, 90% of the extensions in your environment could still become a breach vector. ",{"data":10997,"content":10998,"nodeType":908},{},[],{"data":11000,"content":11001,"nodeType":918},{},[11002],{"data":11003,"marks":11004,"value":11006,"nodeType":867},{},[11005],{"type":916},"What risk scoring is designed to measure — and why it can’t predict future compromise",{"data":11008,"content":11009,"nodeType":881},{},[11010],{"data":11011,"marks":11012,"value":11013,"nodeType":867},{},[],"Most extension risk scoring systems evaluate some combination of permissions, install count, user ratings, code analysis, developer reputation, and web store trust signals. Nice-to-have data points, but with a common limitation: they describe the extension as it is today, not what it will become after the next update. That makes them poor predictors of the thing that actually causes breaches — a previously-clean extension being weaponized through a supply chain compromise.",{"data":11015,"content":11016,"nodeType":881},{},[11017],{"data":11018,"marks":11019,"value":11020,"nodeType":867},{},[],"It's worth examining why each signal falls short as a predictor specifically of future compromise, because the failure modes are different and well-documented.",{"data":11022,"content":11023,"nodeType":998},{},[11024],{"data":11025,"marks":11026,"value":11027,"nodeType":867},{},[],"Permissions",{"data":11029,"content":11030,"nodeType":881},{},[11031,11035,11040],{"data":11032,"marks":11033,"value":11034,"nodeType":867},{},[],"Permissions are the most meaningful input to a risk score, because they determine what an extension is ",{"data":11036,"marks":11037,"value":11039,"nodeType":867},{},[11038],{"type":1431},"capable",{"data":11041,"marks":11042,"value":11043,"nodeType":867},{},[]," of doing if it turns malicious. An extension with access to cookies, scripting, and broad host permissions can steal session tokens, log keystrokes, and exfiltrate data from any site the user visits. This is the data that actually answers the question \"what could this extension do to us if it went bad?\"",{"data":11045,"content":11046,"nodeType":881},{},[11047,11051,11056],{"data":11048,"marks":11049,"value":11050,"nodeType":867},{},[],"The problem is that these permissions are extraordinarily common. We analyzed a sample of 20,000 unique extensions deployed across Push customers and found that ",{"data":11052,"marks":11053,"value":11055,"nodeType":867},{},[11054],{"type":916},"46.76% have the permission combinations needed to perform account takeover with no user interaction",{"data":11057,"marks":11058,"value":10110,"nodeType":867},{},[],{"data":11060,"content":11061,"nodeType":881},{},[11062],{"data":11063,"marks":11064,"value":11065,"nodeType":867},{},[],"These figures also understate the real exposure. One of the most straightforward attack techniques involves injecting content scripts into web pages to hook request functions and extract cookies. The user-facing warning Chrome shows for this capability — \"Read and change all your data on the websites you visit\" — is the same generic string shown for ad blockers, password managers, and translation tools. ",{"data":11067,"content":11068,"nodeType":881},{},[11069,11073,11078],{"data":11070,"marks":11071,"value":11072,"nodeType":867},{},[],"You can't practically remove everything that ",{"data":11074,"marks":11075,"value":11077,"nodeType":867},{},[11076],{"type":1431},"could",{"data":11079,"marks":11080,"value":11081,"nodeType":867},{},[]," be dangerous, because that includes most of the extensions people actually use for work. And if you set the threshold lower to keep the list manageable, you're excluding extensions that have the same permissions and pose the same theoretical risk.",{"data":11083,"content":11084,"nodeType":998},{},[11085],{"data":11086,"marks":11087,"value":11088,"nodeType":867},{},[],"Install counts, ratings, developer reputation, and web store badges",{"data":11090,"content":11091,"nodeType":881},{},[11092,11096,11101],{"data":11093,"marks":11094,"value":11095,"nodeType":867},{},[],"These signals share a common failure mode, so it's worth addressing them together: they all describe the extension's ",{"data":11097,"marks":11098,"value":11100,"nodeType":867},{},[11099],{"type":1431},"reputation",{"data":11102,"marks":11103,"value":11104,"nodeType":867},{},[]," at a point in time, and attackers have both the means and the incentive to ensure that reputation looks clean.",{"data":11106,"content":11107,"nodeType":881},{},[11108,11113,11117,11122],{"data":11109,"marks":11110,"value":11112,"nodeType":867},{},[11111],{"type":916},"Install count ",{"data":11114,"marks":11115,"value":11116,"nodeType":867},{},[],"is sometimes used as a proxy for trustworthiness, on the assumption that widely-adopted extensions are more likely to be legitimate. In practice, high install count is often a ",{"data":11118,"marks":11119,"value":11121,"nodeType":867},{},[11120],{"type":1431},"precondition",{"data":11123,"marks":11124,"value":11125,"nodeType":867},{},[]," for the attack rather than a signal against it. ",{"data":11127,"content":11128,"nodeType":881},{},[11129,11133,11142],{"data":11130,"marks":11131,"value":11132,"nodeType":867},{},[],"Attackers who acquire or build extensions are specifically waiting for the install base to grow before weaponizing — what researchers are calling the \"",{"data":11134,"content":11136,"nodeType":876},{"uri":11135},"https://www.malwarebytes.com/blog/news/2025/12/sleeper-browser-extensions-woke-up-as-spyware-on-4-million-devices",[11137],{"data":11138,"marks":11139,"value":11141,"nodeType":867},{},[11140],{"type":1040},"sleeper agent",{"data":11143,"marks":11144,"value":11145,"nodeType":867},{},[],"\" strategy. Install counts can also be easily inflated with bots, meaning that using them as a positive risk signal actively rewards the attackers who are best at gaming the system.",{"data":11147,"content":11148,"nodeType":3126},{},[11149,11170,11192],{"data":11150,"content":11151,"nodeType":3061},{},[11152],{"data":11153,"content":11154,"nodeType":881},{},[11155,11158,11166],{"data":11156,"marks":11157,"value":3113,"nodeType":867},{},[],{"data":11159,"content":11160,"nodeType":876},{"uri":10878},[11161],{"data":11162,"marks":11163,"value":11165,"nodeType":867},{},[11164],{"type":1040},"DarkSpectre campaign",{"data":11167,"marks":11168,"value":11169,"nodeType":867},{},[]," accumulated over 8.8 million compromised browsers across extensions that held \"verified\" status and healthy install counts throughout a seven-year operational period. ",{"data":11171,"content":11172,"nodeType":3061},{},[11173],{"data":11174,"content":11175,"nodeType":881},{},[11176,11179,11188],{"data":11177,"marks":11178,"value":3113,"nodeType":867},{},[],{"data":11180,"content":11182,"nodeType":876},{"uri":11181},"https://www.ox.security/blog/malicious-chrome-extensions-steal-chatgpt-deepseek-conversations/",[11183],{"data":11184,"marks":11185,"value":11187,"nodeType":867},{},[11186],{"type":1040},"AITOPIA",{"data":11189,"marks":11190,"value":11191,"nodeType":867},{},[]," impersonation extensions had over 900,000 combined installs and a Google \"Featured\" badge. ",{"data":11193,"content":11194,"nodeType":3061},{},[11195],{"data":11196,"content":11197,"nodeType":881},{},[11198],{"data":11199,"marks":11200,"value":11201,"nodeType":867},{},[],"Cyberhaven had approximately 400,000 users at the time of compromise. ",{"data":11203,"content":11204,"nodeType":881},{},[11205,11210],{"data":11206,"marks":11207,"value":11209,"nodeType":867},{},[11208],{"type":916},"User ratings",{"data":11211,"marks":11212,"value":11213,"nodeType":867},{},[]," suffer from the same problems. Attackers use bot networks to generate positive reviews, and even genuinely clean extensions will carry good ratings right up until they're compromised. By the time users start leaving negative reviews the attack has already run its course.",{"data":11215,"content":11216,"nodeType":881},{},[11217,11222,11225,11230],{"data":11218,"marks":11219,"value":11221,"nodeType":867},{},[11220],{"type":916},"Developer reputation and \"Featured\" and \"Verified\"",{"data":11223,"marks":11224,"value":3679,"nodeType":867},{},[],{"data":11226,"marks":11227,"value":11229,"nodeType":867},{},[11228],{"type":916},"badges",{"data":11231,"marks":11232,"value":11233,"nodeType":867},{},[]," fail for a related but slightly different reason: the attack typically doesn't come from a known-bad developer. It comes from a reputable developer whose account has been compromised, or from an extension that has changed hands. ",{"data":11235,"content":11239,"nodeType":890},{"target":11236},{"sys":11237},{"id":11238,"type":887,"linkType":888},"d1C5wKxUnKFwfhf4OBQAq",[],{"data":11241,"content":11242,"nodeType":881},{},[11243],{"data":11244,"marks":11245,"value":11246,"nodeType":867},{},[],"The net result across all of these signals is that the extensions most likely to appear in breach headlines — established tools with large user bases, good ratings, verified badges, and reputable developers — are precisely the ones that risk scoring would rate as low-risk.",{"data":11248,"content":11249,"nodeType":998},{},[11250],{"data":11251,"marks":11252,"value":11253,"nodeType":867},{},[],"Code analysis",{"data":11255,"content":11256,"nodeType":881},{},[11257],{"data":11258,"marks":11259,"value":11260,"nodeType":867},{},[],"Static analysis of extension code is the approach that sounds most rigorous, and it's the basis for Chrome Web Store's own review process. Google operates a hybrid system combining automated analysis and manual review, with manual review typically reserved for submissions that trigger specific signals such as sensitive permissions or large code volumes.",{"data":11262,"content":11263,"nodeType":881},{},[11264],{"data":11265,"marks":11266,"value":11267,"nodeType":867},{},[],"But attackers have developed reliable techniques to pass these checks, and the specific evasion methods used in major campaigns illustrate why static analysis consistently falls short. ",{"data":11269,"content":11270,"nodeType":3126},{},[11271,11281],{"data":11272,"content":11273,"nodeType":3061},{},[11274],{"data":11275,"content":11276,"nodeType":881},{},[11277],{"data":11278,"marks":11279,"value":11280,"nodeType":867},{},[],"The Cyberhaven compromise used dynamically loaded content fetched from a remote server via service workers, with the C2 infrastructure delivering different malicious configurations to different end-users — meaning that even if a scanner fetched the remote payload, it might receive a benign configuration depending on the target profile.",{"data":11282,"content":11283,"nodeType":3061},{},[11284],{"data":11285,"content":11286,"nodeType":881},{},[11287],{"data":11288,"marks":11289,"value":11290,"nodeType":867},{},[],"The GhostPoster campaign (part of the broader DarkSpectre operation) took evasion further still: the extension waited 48 hours between configuration check-ins and only loaded a malicious payload 10% of the time. No sandbox is running for 48 hours, and a 10% activation rate means that nine out of ten analysis runs would see nothing at all.",{"data":11292,"content":11296,"nodeType":890},{"target":11293},{"sys":11294},{"id":11295,"type":887,"linkType":888},"6jy6jvYcHTXO2uMd7kx647",[],{"data":11298,"content":11299,"nodeType":881},{},[11300],{"data":11301,"marks":11302,"value":11303,"nodeType":867},{},[],"It's also worth noting that Chrome Web Store policy explicitly disallows code obfuscation, precisely because it makes review impossible. The fact that attackers have found ways to hide malicious behavior without technically obfuscating their code speaks to the fundamental asymmetry at play: the attacker controls when and how malicious functionality appears, and static analysis can only evaluate what's present at the time of review.",{"data":11305,"content":11306,"nodeType":998},{},[11307],{"data":11308,"marks":11309,"value":11310,"nodeType":867},{},[],"But extension scores combine all of these things …",{"data":11312,"content":11313,"nodeType":881},{},[11314],{"data":11315,"marks":11316,"value":11317,"nodeType":867},{},[],"The obvious counterargument is that no serious risk scoring system relies on any single signal in isolation — the value is supposed to come from combining permissions, install count, ratings, code analysis, and developer reputation into a composite score that's more predictive than any individual input. In theory, this sounds like the right approach: weak signals aggregated together should produce a stronger signal.",{"data":11319,"content":11320,"nodeType":881},{},[11321,11326],{"data":11322,"marks":11323,"value":11325,"nodeType":867},{},[11324],{"type":916},"In practice, combining signals that are individually unable to predict supply chain compromise doesn't produce a signal that can. ",{"data":11327,"marks":11328,"value":11329,"nodeType":867},{},[],"Aggregating a set of backward-looking indicators doesn't make the aggregate forward-looking; it just gives you a more detailed description of the present state, which is the state before the attack has happened. No weighting or combination of install count, code behavior, and developer reputation would have flagged Cyberhaven, or DarkSpectre, or Trust Wallet before the malicious update shipped, because at that point every input to the composite score was returning a legitimate value.",{"data":11331,"content":11332,"nodeType":881},{},[11333,11337,11342,11346,11351],{"data":11334,"marks":11335,"value":11336,"nodeType":867},{},[],"Meanwhile, the indicators that ",{"data":11338,"marks":11339,"value":11341,"nodeType":867},{},[11340],{"type":1431},"do",{"data":11343,"marks":11344,"value":11345,"nodeType":867},{},[]," predict real-world compromise — an extension changing ownership, a developer account being phished, an update introducing behavior that wasn't present in prior versions, or an extension being explicitly confirmed as malicious through threat intelligence — aren't predictive risk score inputs. ",{"data":11347,"marks":11348,"value":11350,"nodeType":867},{},[11349],{"type":916},"They're discrete events that require monitoring and an immediate response, not a recalculated number on a dashboard. ",{"data":11352,"marks":11353,"value":11354,"nodeType":867},{},[],"This is an important distinction: the signals that matter are changes over time, not static attributes at a point in time, and they call for a detection-and-response workflow rather than a periodic risk review.",{"data":11356,"content":11357,"nodeType":908},{},[],{"data":11359,"content":11360,"nodeType":918},{},[11361],{"data":11362,"marks":11363,"value":11365,"nodeType":867},{},[11364],{"type":916},"What works instead",{"data":11367,"content":11368,"nodeType":881},{},[11369],{"data":11370,"marks":11371,"value":11372,"nodeType":867},{},[],"If the goal is to reduce your exposure to extension-based supply chain compromise rather than to generate a ranked list of risk, the approach is operationally straightforward — even if it requires more discipline than deploying a scoring dashboard.",{"data":11374,"content":11375,"nodeType":998},{},[11376],{"data":11377,"marks":11378,"value":11379,"nodeType":867},{},[],"Reduce your attack surface through allowlisting",{"data":11381,"content":11382,"nodeType":881},{},[11383],{"data":11384,"marks":11385,"value":11386,"nodeType":867},{},[],"Build a complete inventory of every extension running across your environment — what's installed, how it got there (managed deployment, manual install, sideloaded, developer mode), what permissions it has, who's using it, and whether it serves a legitimate work purpose. Then create a strict allowlist of vetted and approved extensions and block everything else.",{"data":11388,"content":11389,"nodeType":881},{},[11390,11394,11402],{"data":11391,"marks":11392,"value":11393,"nodeType":867},{},[],"This is the same default-deny approach that's been best practice for firewall policy and endpoint allowlisting for decades. ",{"data":11395,"content":11396,"nodeType":876},{"uri":4917},[11397],{"data":11398,"marks":11399,"value":11401,"nodeType":867},{},[11400],{"type":1040},"In Push, it works like building a firewall rule",{"data":11403,"marks":11404,"value":11405,"nodeType":867},{},[],": a global block rule at the bottom that disables all browser extensions, with explicit exceptions above it for approved tools. Users who attempt to install unapproved extensions see a block screen.",{"data":11407,"content":11411,"nodeType":890},{"target":11408},{"sys":11409},{"id":11410,"type":887,"linkType":888},"97dDukjKsRsAptpHV1kpn",[],{"data":11413,"content":11414,"nodeType":881},{},[11415,11420,11426,11431],{"data":11416,"marks":11417,"value":11419,"nodeType":867},{},[11418],{"type":916},"The key insight is that every extension you don't ",{"data":11421,"marks":11422,"value":11425,"nodeType":867},{},[11423,11424],{"type":916},{"type":1431},"really ",{"data":11427,"marks":11428,"value":11430,"nodeType":867},{},[11429],{"type":916},"need, but haven't blocked, is attack surface that exists for no business reason. ",{"data":11432,"marks":11433,"value":11434,"nodeType":867},{},[],"Most organizations are surprised by how many of the extensions in their environment are unused, forgotten, or have readily available alternatives. Reducing the population of installed extensions to only the ones that serve a genuine work purpose is the single most effective thing you can do — and it doesn't require a risk score to accomplish.",{"data":11436,"content":11437,"nodeType":998},{},[11438],{"data":11439,"marks":11440,"value":11441,"nodeType":867},{},[],"Monitor for changes that indicate weaponization",{"data":11443,"content":11444,"nodeType":881},{},[11445],{"data":11446,"marks":11447,"value":11448,"nodeType":867},{},[],"Once you have a controlled baseline, the risk shifts from unmanaged installations (those are blocked) to changes in the extensions you've already approved. These are the signals that map to real-world attack patterns and serve as leading indicators of weaponization:",{"data":11450,"content":11451,"nodeType":3126},{},[11452,11496,11511,11526,11541],{"data":11453,"content":11454,"nodeType":3061},{},[11455],{"data":11456,"content":11457,"nodeType":881},{},[11458,11463,11467,11476,11481,11485,11493],{"data":11459,"marks":11460,"value":11462,"nodeType":867},{},[11461],{"type":916},"Ownership changes",{"data":11464,"marks":11465,"value":11466,"nodeType":867},{},[]," — an extension changing hands is one of the most reliable precursors to supply chain compromise, as demonstrated by the ",{"data":11468,"content":11470,"nodeType":876},{"uri":11469},"https://thehackernews.com/2026/03/chrome-extension-turns-malicious-after.html",[11471],{"data":11472,"marks":11473,"value":11475,"nodeType":867},{},[11474],{"type":1040},"QuickLens and ShotBird attack",{"data":11477,"marks":11478,"value":11480,"nodeType":867},{},[11479],{"type":1040},"s",{"data":11482,"marks":11483,"value":11484,"nodeType":867},{},[]," and the acquired-extension clusters documented by ",{"data":11486,"content":11487,"nodeType":876},{"uri":10965},[11488],{"data":11489,"marks":11490,"value":11492,"nodeType":867},{},[11491],{"type":1040},"GitLab",{"data":11494,"marks":11495,"value":1947,"nodeType":867},{},[],{"data":11497,"content":11498,"nodeType":3061},{},[11499],{"data":11500,"content":11501,"nodeType":881},{},[11502,11507],{"data":11503,"marks":11504,"value":11506,"nodeType":867},{},[11505],{"type":916},"Developer contact information changes",{"data":11508,"marks":11509,"value":11510,"nodeType":867},{},[]," — often an early indicator that an extension has been sold or that a developer account has been taken over.",{"data":11512,"content":11513,"nodeType":3061},{},[11514],{"data":11515,"content":11516,"nodeType":881},{},[11517,11522],{"data":11518,"marks":11519,"value":11521,"nodeType":867},{},[11520],{"type":916},"Permission escalations in updates",{"data":11523,"marks":11524,"value":11525,"nodeType":867},{},[]," — a previously-scoped extension suddenly requesting broad host permissions or cookie access.",{"data":11527,"content":11528,"nodeType":3061},{},[11529],{"data":11530,"content":11531,"nodeType":881},{},[11532,11537],{"data":11533,"marks":11534,"value":11536,"nodeType":867},{},[11535],{"type":916},"Delisting from the web store",{"data":11538,"marks":11539,"value":11540,"nodeType":867},{},[]," — can indicate that the store's review process has caught something, or that the developer has abandoned the extension.",{"data":11542,"content":11543,"nodeType":3061},{},[11544],{"data":11545,"content":11546,"nodeType":881},{},[11547,11552,11556,11564,11569],{"data":11548,"marks":11549,"value":11551,"nodeType":867},{},[11550],{"type":916},"Known malicious classification",{"data":11553,"marks":11554,"value":11555,"nodeType":867},{},[]," — when an extension is confirmed as weaponized or linked to an active campaign through threat intelligence. (",{"data":11557,"content":11558,"nodeType":876},{"uri":4917},[11559],{"data":11560,"marks":11561,"value":11563,"nodeType":867},{},[11562],{"type":1040},"Push blocks known-bad extensions automaticall",{"data":11565,"marks":11566,"value":11568,"nodeType":867},{},[11567],{"type":1040},"y",{"data":11570,"marks":11571,"value":11572,"nodeType":867},{},[],").",{"data":11574,"content":11578,"nodeType":890},{"target":11575},{"sys":11576},{"id":11577,"type":887,"linkType":888},"4PWyOD92E549plkeNH1DxO",[],{"data":11580,"content":11581,"nodeType":881},{},[11582],{"data":11583,"marks":11584,"value":11585,"nodeType":867},{},[],"To make this concrete: Push emits structured events via webhook whenever extension metadata changes that captures all of the variables above. These these can be fed directly into your SIEM or SOAR workflows, making it easy for security teams to detect when a meaningful change occurs. An ownership change on its own warrants investigation; an ownership change paired with a new version and added permissions warrants an immediate block pending review.",{"data":11587,"content":11588,"nodeType":881},{},[11589],{"data":11590,"marks":11591,"value":11592,"nodeType":867},{},[],"Push detects these changes in real time and can automatically block an extension when a meaningful risk indicator fires, before the damage propagates. This is fundamentally different from a periodic risk score: rather than attempting to predict which extensions might go bad based on static attributes, Push monitors for the specific events that precede or accompany weaponization in the attacks we've actually observed.",{"data":11594,"content":11595,"nodeType":908},{},[],{"data":11597,"content":11598,"nodeType":918},{},[11599],{"data":11600,"marks":11601,"value":11603,"nodeType":867},{},[11602],{"type":916},"The bottom line",{"data":11605,"content":11606,"nodeType":881},{},[11607],{"data":11608,"marks":11609,"value":11610,"nodeType":867},{},[],"Traditional extension risk scores — based on permissions, store metadata, code analysis, and developer reputation — are poor predictors of which extensions will actually compromise you. The extensions involved in the major breaches of the past 18 months consistently scored as normal or low-risk right up until the moment they were weaponized. If your extension management strategy is built around \"identify the riskiest extensions and remove them,\" the extension that gets you is the one that wasn't on the list.",{"data":11612,"content":11613,"nodeType":881},{},[11614,11618,11626],{"data":11615,"marks":11616,"value":11617,"nodeType":867},{},[],"Browser extensions are software. They're third-party code running with significant privilege inside the browser, capable of reading and modifying page content, accessing cookies and session tokens, and interacting with virtually every web application your employees use. Like any other software dependency — ",{"data":11619,"content":11620,"nodeType":876},{"uri":4829},[11621],{"data":11622,"marks":11623,"value":11625,"nodeType":867},{},[11624],{"type":1040},"OAuth integrations",{"data":11627,"marks":11628,"value":11629,"nodeType":867},{},[]," being another relevant recent example in public breaches — each one expands your attack surface. ",{"data":11631,"content":11632,"nodeType":881},{},[11633],{"data":11634,"marks":11635,"value":11636,"nodeType":867},{},[],"The principles behind managing browser extensions need to be the same as any other software — default-deny, build an allowlist, monitor and maintain that allowlist. This might trigger some PTSD for security teams, but it shouldn’t. On the endpoint, application allowlisting has always been operationally painful — diverse workflows, unpredictable application needs, and the overhead of vetting every binary made it impractical for most organizations outside of high-security environments. In the browser, it’s not that serious. You’re not going to brick an endpoint by blocking a third-party browser extension. ",{"data":11638,"content":11639,"nodeType":881},{},[11640],{"data":11641,"marks":11642,"value":11644,"nodeType":867},{},[11643],{"type":916},"The browser is one of the few environments where an allowlisting approach is both technically feasible and operationally lightweight: use it to your advantage. ",{"data":11646,"content":11647,"nodeType":908},{},[],{"data":11649,"content":11650,"nodeType":881},{},[11651,11655,11663],{"data":11652,"marks":11653,"value":11654,"nodeType":867},{},[],"Push detects and blocks malicious browser extensions, and gives security teams the controls to ",{"data":11656,"content":11657,"nodeType":876},{"uri":4917},[11658],{"data":11659,"marks":11660,"value":11662,"nodeType":867},{},[11661],{"type":1040},"enforce an extension allowlist and monitor for risky changes",{"data":11664,"marks":11665,"value":11666,"nodeType":867},{},[]," across every browser in the environment. Combined with protection against AiTM phishing, ClickFix attacks, session hijacking, and stolen credentials — plus proactive hardening for ghost logins, SSO coverage gaps, MFA gaps, and vulnerable passwords — Push provides browser-native visibility and control where it matters most.",{"data":11668,"content":11669,"nodeType":881},{},[11670,11673,11679,11682,11688,11691,11697],{"data":11671,"marks":11672,"value":10795,"nodeType":867},{},[],{"data":11674,"content":11675,"nodeType":876},{"uri":10798},[11676],{"data":11677,"marks":11678,"value":10803,"nodeType":867},{},[],{"data":11680,"marks":11681,"value":4006,"nodeType":867},{},[],{"data":11683,"content":11684,"nodeType":876},{"uri":10809},[11685],{"data":11686,"marks":11687,"value":10815,"nodeType":867},{},[],{"data":11689,"marks":11690,"value":10819,"nodeType":867},{},[],{"data":11692,"content":11693,"nodeType":876},{"uri":1629},[11694],{"data":11695,"marks":11696,"value":10826,"nodeType":867},{},[],{"data":11698,"marks":11699,"value":1947,"nodeType":867},{},[],"Why relying on browser extension risk scoring is an antipattern that won’t predict your next breach","Why typical browser extension risk scores are poor predictors of which extensions will actually lead to a compromise.","2026-04-29T00:00:00.000Z","why-browser-extension-risk-scoring-wont-predict-your-next-breach",{"items":11705},[11706,11708],{"sys":11707,"name":342},{"id":2550},{"sys":11709,"name":2547},{"id":2546},{"items":11711},[11712],{"fullName":849,"firstName":850,"jobTitle":851,"profilePicture":11713},{"url":855},"blog/analyzing-the-instructure-breach",{"json":11716},{"data":11717,"content":11718,"nodeType":1640},{},[11719],{"data":11720,"content":11721,"nodeType":881},{},[11722],{"data":11723,"marks":11724,"value":11725,"nodeType":867},{},[],"ShinyHunters' 2025 hacking spree has continued at pace in 2026. In this blog post, we break down their main techniques and what security teams can do to counter the threat.",{"id":5657,"publishedAt":11727},"2026-08-12T12:01:00.410Z",{"items":11729},[11730,11732],{"sys":11731,"name":2547},{"id":2546},{"sys":11733,"name":342},{"id":2550},{"items":11735},[11736,11738,11740,11742,11744,11746,11748,11750,11752,11754,11756,11758,11760,11762,11764,11766,11768],{"sys":11737,"name":279,"slug":280,"tier":31},{"id":276},{"sys":11739,"name":413,"slug":414,"tier":31},{"id":410},{"sys":11741,"name":545,"slug":546,"tier":31},{"id":542},{"sys":11743,"name":519,"slug":520,"tier":31},{"id":516},{"sys":11745,"name":642,"slug":643,"tier":31},{"id":639},{"sys":11747,"name":616,"slug":617,"tier":31},{"id":613},{"sys":11749,"name":650,"slug":651,"tier":45},{"id":647},{"sys":11751,"name":261,"slug":262,"tier":45},{"id":258},{"sys":11753,"name":360,"slug":361,"tier":45},{"id":357},{"sys":11755,"name":484,"slug":485,"tier":45},{"id":481},{"sys":11757,"name":528,"slug":529,"tier":45},{"id":525},{"sys":11759,"name":422,"slug":423,"tier":45},{"id":419},{"sys":11761,"name":333,"slug":334,"tier":45},{"id":330},{"sys":11763,"name":511,"slug":512,"tier":45},{"id":508},{"sys":11765,"name":607,"slug":608,"tier":45},{"id":604},{"sys":11767,"name":571,"slug":572,"tier":45},{"id":568},{"sys":11769,"name":633,"slug":634,"tier":45},{"id":630},"q9ktZNEnjjJ4_6n87yiRtMpJvFaran6mMq5hhAKk8U0",{"id":11772,"title":10059,"authorsCollection":11773,"content":11777,"extension":228,"faqItemsCollection":13688,"faqTitle":59,"featured":6,"hashTags":59,"meta":13690,"metaTitle":13691,"ogImage":59,"postType":8156,"publishedDate":10061,"relatedBlogPostsCollection":13692,"slug":10062,"stem":15881,"subtitle":59,"summary":15882,"synopsis":10060,"sys":15892,"tagsCollection":15894,"topicsCollection":15900,"__hash__":15930},"blog/blog/inside-criminal-phishing-panel.json",{"items":11774},[11775],{"fullName":10072,"firstName":10073,"jobTitle":851,"socialLinks":59,"profilePicture":11776},{"url":10075},{"json":11778,"links":13484},{"data":11779,"content":11780,"nodeType":1640},{},[11781,11787,11811,11821,11827,11832,11842,11847,11850,11857,11863,11918,11924,11929,11932,11939,11945,11950,11957,11963,12071,12076,12081,12087,12092,12099,12105,12111,12166,12172,12177,12182,12189,12195,12201,12208,12214,12243,12249,12254,12260,12302,12308,12315,12321,12326,12332,12338,12343,12349,12378,12384,12389,12392,12399,12405,12411,12417,12422,12428,12434,12439,12445,12450,12456,12461,12467,12473,12476,12483,12496,12502,12518,12739,12745,12771,12992,12998,13004,13195,13201,13380,13383,13390,13396,13402,13412,13415,13422,13437,13452,13459,13462,13469],{"data":11782,"content":11783,"nodeType":881},{},[11784],{"data":11785,"marks":11786,"value":8172,"nodeType":867},{},[],{"data":11788,"content":11789,"nodeType":881},{},[11790,11793,11799,11802,11808],{"data":11791,"marks":11792,"value":8179,"nodeType":867},{},[],{"data":11794,"content":11795,"nodeType":876},{"uri":3074},[11796],{"data":11797,"marks":11798,"value":8186,"nodeType":867},{},[],{"data":11800,"marks":11801,"value":8190,"nodeType":867},{},[],{"data":11803,"content":11804,"nodeType":876},{"uri":8193},[11805],{"data":11806,"marks":11807,"value":8198,"nodeType":867},{},[],{"data":11809,"marks":11810,"value":8202,"nodeType":867},{},[],{"data":11812,"content":11813,"nodeType":881},{},[11814,11818],{"data":11815,"marks":11816,"value":8210,"nodeType":867},{},[11817],{"type":916},{"data":11819,"marks":11820,"value":3679,"nodeType":867},{},[],{"data":11822,"content":11823,"nodeType":881},{},[11824],{"data":11825,"marks":11826,"value":8220,"nodeType":867},{},[],{"data":11828,"content":11831,"nodeType":890},{"target":11829},{"sys":11830},{"id":8225,"type":887,"linkType":888},[],{"data":11833,"content":11834,"nodeType":881},{},[11835,11838],{"data":11836,"marks":11837,"value":8233,"nodeType":867},{},[],{"data":11839,"marks":11840,"value":8238,"nodeType":867},{},[11841],{"type":916},{"data":11843,"content":11846,"nodeType":890},{"target":11844},{"sys":11845},{"id":8243,"type":887,"linkType":888},[],{"data":11848,"content":11849,"nodeType":908},{},[],{"data":11851,"content":11852,"nodeType":918},{},[11853],{"data":11854,"marks":11855,"value":8255,"nodeType":867},{},[11856],{"type":916},{"data":11858,"content":11859,"nodeType":881},{},[11860],{"data":11861,"marks":11862,"value":8262,"nodeType":867},{},[],{"data":11864,"content":11865,"nodeType":3126},{},[11866,11879,11892,11905],{"data":11867,"content":11868,"nodeType":3061},{},[11869],{"data":11870,"content":11871,"nodeType":881},{},[11872,11876],{"data":11873,"marks":11874,"value":8276,"nodeType":867},{},[11875],{"type":916},{"data":11877,"marks":11878,"value":8280,"nodeType":867},{},[],{"data":11880,"content":11881,"nodeType":3061},{},[11882],{"data":11883,"content":11884,"nodeType":881},{},[11885,11889],{"data":11886,"marks":11887,"value":8291,"nodeType":867},{},[11888],{"type":916},{"data":11890,"marks":11891,"value":8295,"nodeType":867},{},[],{"data":11893,"content":11894,"nodeType":3061},{},[11895],{"data":11896,"content":11897,"nodeType":881},{},[11898,11902],{"data":11899,"marks":11900,"value":8306,"nodeType":867},{},[11901],{"type":916},{"data":11903,"marks":11904,"value":8310,"nodeType":867},{},[],{"data":11906,"content":11907,"nodeType":3061},{},[11908],{"data":11909,"content":11910,"nodeType":881},{},[11911,11915],{"data":11912,"marks":11913,"value":8321,"nodeType":867},{},[11914],{"type":916},{"data":11916,"marks":11917,"value":8325,"nodeType":867},{},[],{"data":11919,"content":11920,"nodeType":881},{},[11921],{"data":11922,"marks":11923,"value":8332,"nodeType":867},{},[],{"data":11925,"content":11928,"nodeType":890},{"target":11926},{"sys":11927},{"id":8337,"type":887,"linkType":888},[],{"data":11930,"content":11931,"nodeType":908},{},[],{"data":11933,"content":11934,"nodeType":918},{},[11935],{"data":11936,"marks":11937,"value":8349,"nodeType":867},{},[11938],{"type":916},{"data":11940,"content":11941,"nodeType":881},{},[11942],{"data":11943,"marks":11944,"value":8356,"nodeType":867},{},[],{"data":11946,"content":11949,"nodeType":890},{"target":11947},{"sys":11948},{"id":8361,"type":887,"linkType":888},[],{"data":11951,"content":11952,"nodeType":998},{},[11953],{"data":11954,"marks":11955,"value":8370,"nodeType":867},{},[11956],{"type":916},{"data":11958,"content":11959,"nodeType":881},{},[11960],{"data":11961,"marks":11962,"value":8377,"nodeType":867},{},[],{"data":11964,"content":11965,"nodeType":3126},{},[11966,11979,11992,12012,12025,12038,12058],{"data":11967,"content":11968,"nodeType":3061},{},[11969],{"data":11970,"content":11971,"nodeType":881},{},[11972,11976],{"data":11973,"marks":11974,"value":8391,"nodeType":867},{},[11975],{"type":916},{"data":11977,"marks":11978,"value":8395,"nodeType":867},{},[],{"data":11980,"content":11981,"nodeType":3061},{},[11982],{"data":11983,"content":11984,"nodeType":881},{},[11985,11989],{"data":11986,"marks":11987,"value":8406,"nodeType":867},{},[11988],{"type":916},{"data":11990,"marks":11991,"value":8410,"nodeType":867},{},[],{"data":11993,"content":11994,"nodeType":3061},{},[11995],{"data":11996,"content":11997,"nodeType":881},{},[11998,12002,12005,12009],{"data":11999,"marks":12000,"value":8421,"nodeType":867},{},[12001],{"type":916},{"data":12003,"marks":12004,"value":8425,"nodeType":867},{},[],{"data":12006,"marks":12007,"value":8430,"nodeType":867},{},[12008],{"type":916},{"data":12010,"marks":12011,"value":8434,"nodeType":867},{},[],{"data":12013,"content":12014,"nodeType":3061},{},[12015],{"data":12016,"content":12017,"nodeType":881},{},[12018,12022],{"data":12019,"marks":12020,"value":8445,"nodeType":867},{},[12021],{"type":916},{"data":12023,"marks":12024,"value":8449,"nodeType":867},{},[],{"data":12026,"content":12027,"nodeType":3061},{},[12028],{"data":12029,"content":12030,"nodeType":881},{},[12031,12035],{"data":12032,"marks":12033,"value":8460,"nodeType":867},{},[12034],{"type":916},{"data":12036,"marks":12037,"value":8464,"nodeType":867},{},[],{"data":12039,"content":12040,"nodeType":3061},{},[12041],{"data":12042,"content":12043,"nodeType":881},{},[12044,12048,12051,12055],{"data":12045,"marks":12046,"value":8475,"nodeType":867},{},[12047],{"type":916},{"data":12049,"marks":12050,"value":8479,"nodeType":867},{},[],{"data":12052,"marks":12053,"value":8484,"nodeType":867},{},[12054],{"type":916},{"data":12056,"marks":12057,"value":8488,"nodeType":867},{},[],{"data":12059,"content":12060,"nodeType":3061},{},[12061],{"data":12062,"content":12063,"nodeType":881},{},[12064,12068],{"data":12065,"marks":12066,"value":8499,"nodeType":867},{},[12067],{"type":916},{"data":12069,"marks":12070,"value":8503,"nodeType":867},{},[],{"data":12072,"content":12075,"nodeType":890},{"target":12073},{"sys":12074},{"id":8508,"type":887,"linkType":888},[],{"data":12077,"content":12080,"nodeType":890},{"target":12078},{"sys":12079},{"id":8514,"type":887,"linkType":888},[],{"data":12082,"content":12083,"nodeType":881},{},[12084],{"data":12085,"marks":12086,"value":21,"nodeType":867},{},[],{"data":12088,"content":12091,"nodeType":890},{"target":12089},{"sys":12090},{"id":8526,"type":887,"linkType":888},[],{"data":12093,"content":12094,"nodeType":998},{},[12095],{"data":12096,"marks":12097,"value":8535,"nodeType":867},{},[12098],{"type":916},{"data":12100,"content":12101,"nodeType":881},{},[12102],{"data":12103,"marks":12104,"value":8542,"nodeType":867},{},[],{"data":12106,"content":12107,"nodeType":881},{},[12108],{"data":12109,"marks":12110,"value":8549,"nodeType":867},{},[],{"data":12112,"content":12113,"nodeType":3126},{},[12114,12127,12140,12153],{"data":12115,"content":12116,"nodeType":3061},{},[12117],{"data":12118,"content":12119,"nodeType":881},{},[12120,12124],{"data":12121,"marks":12122,"value":8563,"nodeType":867},{},[12123],{"type":916},{"data":12125,"marks":12126,"value":8567,"nodeType":867},{},[],{"data":12128,"content":12129,"nodeType":3061},{},[12130],{"data":12131,"content":12132,"nodeType":881},{},[12133,12137],{"data":12134,"marks":12135,"value":8578,"nodeType":867},{},[12136],{"type":916},{"data":12138,"marks":12139,"value":8582,"nodeType":867},{},[],{"data":12141,"content":12142,"nodeType":3061},{},[12143],{"data":12144,"content":12145,"nodeType":881},{},[12146,12150],{"data":12147,"marks":12148,"value":8593,"nodeType":867},{},[12149],{"type":916},{"data":12151,"marks":12152,"value":8597,"nodeType":867},{},[],{"data":12154,"content":12155,"nodeType":3061},{},[12156],{"data":12157,"content":12158,"nodeType":881},{},[12159,12163],{"data":12160,"marks":12161,"value":8608,"nodeType":867},{},[12162],{"type":916},{"data":12164,"marks":12165,"value":8612,"nodeType":867},{},[],{"data":12167,"content":12168,"nodeType":881},{},[12169],{"data":12170,"marks":12171,"value":8619,"nodeType":867},{},[],{"data":12173,"content":12176,"nodeType":890},{"target":12174},{"sys":12175},{"id":8624,"type":887,"linkType":888},[],{"data":12178,"content":12181,"nodeType":890},{"target":12179},{"sys":12180},{"id":8630,"type":887,"linkType":888},[],{"data":12183,"content":12184,"nodeType":998},{},[12185],{"data":12186,"marks":12187,"value":8639,"nodeType":867},{},[12188],{"type":916},{"data":12190,"content":12191,"nodeType":881},{},[12192],{"data":12193,"marks":12194,"value":8646,"nodeType":867},{},[],{"data":12196,"content":12197,"nodeType":881},{},[12198],{"data":12199,"marks":12200,"value":8653,"nodeType":867},{},[],{"data":12202,"content":12203,"nodeType":998},{},[12204],{"data":12205,"marks":12206,"value":8661,"nodeType":867},{},[12207],{"type":916},{"data":12209,"content":12210,"nodeType":881},{},[12211],{"data":12212,"marks":12213,"value":8668,"nodeType":867},{},[],{"data":12215,"content":12216,"nodeType":3126},{},[12217,12230],{"data":12218,"content":12219,"nodeType":3061},{},[12220],{"data":12221,"content":12222,"nodeType":881},{},[12223,12227],{"data":12224,"marks":12225,"value":8682,"nodeType":867},{},[12226],{"type":916},{"data":12228,"marks":12229,"value":8686,"nodeType":867},{},[],{"data":12231,"content":12232,"nodeType":3061},{},[12233],{"data":12234,"content":12235,"nodeType":881},{},[12236,12240],{"data":12237,"marks":12238,"value":8697,"nodeType":867},{},[12239],{"type":916},{"data":12241,"marks":12242,"value":8701,"nodeType":867},{},[],{"data":12244,"content":12245,"nodeType":881},{},[12246],{"data":12247,"marks":12248,"value":8708,"nodeType":867},{},[],{"data":12250,"content":12253,"nodeType":890},{"target":12251},{"sys":12252},{"id":8713,"type":887,"linkType":888},[],{"data":12255,"content":12256,"nodeType":881},{},[12257],{"data":12258,"marks":12259,"value":8721,"nodeType":867},{},[],{"data":12261,"content":12262,"nodeType":3126},{},[12263,12276,12289],{"data":12264,"content":12265,"nodeType":3061},{},[12266],{"data":12267,"content":12268,"nodeType":881},{},[12269,12273],{"data":12270,"marks":12271,"value":8735,"nodeType":867},{},[12272],{"type":916},{"data":12274,"marks":12275,"value":8739,"nodeType":867},{},[],{"data":12277,"content":12278,"nodeType":3061},{},[12279],{"data":12280,"content":12281,"nodeType":881},{},[12282,12286],{"data":12283,"marks":12284,"value":8750,"nodeType":867},{},[12285],{"type":916},{"data":12287,"marks":12288,"value":8754,"nodeType":867},{},[],{"data":12290,"content":12291,"nodeType":3061},{},[12292],{"data":12293,"content":12294,"nodeType":881},{},[12295,12299],{"data":12296,"marks":12297,"value":8765,"nodeType":867},{},[12298],{"type":916},{"data":12300,"marks":12301,"value":8769,"nodeType":867},{},[],{"data":12303,"content":12304,"nodeType":881},{},[12305],{"data":12306,"marks":12307,"value":8776,"nodeType":867},{},[],{"data":12309,"content":12310,"nodeType":998},{},[12311],{"data":12312,"marks":12313,"value":8784,"nodeType":867},{},[12314],{"type":916},{"data":12316,"content":12317,"nodeType":881},{},[12318],{"data":12319,"marks":12320,"value":8791,"nodeType":867},{},[],{"data":12322,"content":12325,"nodeType":890},{"target":12323},{"sys":12324},{"id":8796,"type":887,"linkType":888},[],{"data":12327,"content":12328,"nodeType":881},{},[12329],{"data":12330,"marks":12331,"value":8804,"nodeType":867},{},[],{"data":12333,"content":12334,"nodeType":881},{},[12335],{"data":12336,"marks":12337,"value":8811,"nodeType":867},{},[],{"data":12339,"content":12342,"nodeType":890},{"target":12340},{"sys":12341},{"id":8816,"type":887,"linkType":888},[],{"data":12344,"content":12345,"nodeType":881},{},[12346],{"data":12347,"marks":12348,"value":8824,"nodeType":867},{},[],{"data":12350,"content":12351,"nodeType":3126},{},[12352,12365],{"data":12353,"content":12354,"nodeType":3061},{},[12355],{"data":12356,"content":12357,"nodeType":881},{},[12358,12362],{"data":12359,"marks":12360,"value":8838,"nodeType":867},{},[12361],{"type":916},{"data":12363,"marks":12364,"value":8842,"nodeType":867},{},[],{"data":12366,"content":12367,"nodeType":3061},{},[12368],{"data":12369,"content":12370,"nodeType":881},{},[12371,12375],{"data":12372,"marks":12373,"value":8853,"nodeType":867},{},[12374],{"type":916},{"data":12376,"marks":12377,"value":8857,"nodeType":867},{},[],{"data":12379,"content":12380,"nodeType":881},{},[12381],{"data":12382,"marks":12383,"value":8864,"nodeType":867},{},[],{"data":12385,"content":12388,"nodeType":890},{"target":12386},{"sys":12387},{"id":8869,"type":887,"linkType":888},[],{"data":12390,"content":12391,"nodeType":908},{},[],{"data":12393,"content":12394,"nodeType":918},{},[12395],{"data":12396,"marks":12397,"value":8881,"nodeType":867},{},[12398],{"type":916},{"data":12400,"content":12401,"nodeType":881},{},[12402],{"data":12403,"marks":12404,"value":8888,"nodeType":867},{},[],{"data":12406,"content":12407,"nodeType":881},{},[12408],{"data":12409,"marks":12410,"value":8895,"nodeType":867},{},[],{"data":12412,"content":12413,"nodeType":881},{},[12414],{"data":12415,"marks":12416,"value":8902,"nodeType":867},{},[],{"data":12418,"content":12421,"nodeType":890},{"target":12419},{"sys":12420},{"id":1258,"type":887,"linkType":888},[],{"data":12423,"content":12424,"nodeType":881},{},[12425],{"data":12426,"marks":12427,"value":8914,"nodeType":867},{},[],{"data":12429,"content":12430,"nodeType":881},{},[12431],{"data":12432,"marks":12433,"value":8921,"nodeType":867},{},[],{"data":12435,"content":12438,"nodeType":890},{"target":12436},{"sys":12437},{"id":8926,"type":887,"linkType":888},[],{"data":12440,"content":12441,"nodeType":881},{},[12442],{"data":12443,"marks":12444,"value":8934,"nodeType":867},{},[],{"data":12446,"content":12449,"nodeType":890},{"target":12447},{"sys":12448},{"id":8939,"type":887,"linkType":888},[],{"data":12451,"content":12452,"nodeType":881},{},[12453],{"data":12454,"marks":12455,"value":8947,"nodeType":867},{},[],{"data":12457,"content":12460,"nodeType":890},{"target":12458},{"sys":12459},{"id":8952,"type":887,"linkType":888},[],{"data":12462,"content":12463,"nodeType":881},{},[12464],{"data":12465,"marks":12466,"value":8960,"nodeType":867},{},[],{"data":12468,"content":12469,"nodeType":881},{},[12470],{"data":12471,"marks":12472,"value":8967,"nodeType":867},{},[],{"data":12474,"content":12475,"nodeType":908},{},[],{"data":12477,"content":12478,"nodeType":918},{},[12479],{"data":12480,"marks":12481,"value":8978,"nodeType":867},{},[12482],{"type":916},{"data":12484,"content":12485,"nodeType":881},{},[12486,12489,12493],{"data":12487,"marks":12488,"value":8985,"nodeType":867},{},[],{"data":12490,"marks":12491,"value":8990,"nodeType":867},{},[12492],{"type":916},{"data":12494,"marks":12495,"value":8994,"nodeType":867},{},[],{"data":12497,"content":12498,"nodeType":998},{},[12499],{"data":12500,"marks":12501,"value":9001,"nodeType":867},{},[],{"data":12503,"content":12504,"nodeType":881},{},[12505,12508,12515],{"data":12506,"marks":12507,"value":9008,"nodeType":867},{},[],{"data":12509,"content":12510,"nodeType":876},{"uri":5843},[12511],{"data":12512,"marks":12513,"value":9016,"nodeType":867},{},[12514],{"type":1040},{"data":12516,"marks":12517,"value":9020,"nodeType":867},{},[],{"data":12519,"content":12520,"nodeType":2531},{},[12521,12544,12571,12592,12637,12676,12697,12718],{"data":12522,"content":12523,"nodeType":2438},{},[12524,12534],{"data":12525,"content":12526,"nodeType":2452},{},[12527],{"data":12528,"content":12529,"nodeType":881},{},[12530],{"data":12531,"marks":12532,"value":9037,"nodeType":867},{},[12533],{"type":916},{"data":12535,"content":12536,"nodeType":2452},{},[12537],{"data":12538,"content":12539,"nodeType":881},{},[12540],{"data":12541,"marks":12542,"value":8535,"nodeType":867},{},[12543],{"type":916},{"data":12545,"content":12546,"nodeType":2438},{},[12547,12556],{"data":12548,"content":12549,"nodeType":2452},{},[12550],{"data":12551,"content":12552,"nodeType":881},{},[12553],{"data":12554,"marks":12555,"value":8563,"nodeType":867},{},[],{"data":12557,"content":12558,"nodeType":2452},{},[12559,12565],{"data":12560,"content":12561,"nodeType":881},{},[12562],{"data":12563,"marks":12564,"value":9069,"nodeType":867},{},[],{"data":12566,"content":12567,"nodeType":881},{},[12568],{"data":12569,"marks":12570,"value":9076,"nodeType":867},{},[],{"data":12572,"content":12573,"nodeType":2438},{},[12574,12583],{"data":12575,"content":12576,"nodeType":2452},{},[12577],{"data":12578,"content":12579,"nodeType":881},{},[12580],{"data":12581,"marks":12582,"value":9089,"nodeType":867},{},[],{"data":12584,"content":12585,"nodeType":2452},{},[12586],{"data":12587,"content":12588,"nodeType":881},{},[12589],{"data":12590,"marks":12591,"value":9099,"nodeType":867},{},[],{"data":12593,"content":12594,"nodeType":2438},{},[12595,12604],{"data":12596,"content":12597,"nodeType":2452},{},[12598],{"data":12599,"content":12600,"nodeType":881},{},[12601],{"data":12602,"marks":12603,"value":9112,"nodeType":867},{},[],{"data":12605,"content":12606,"nodeType":2452},{},[12607,12613,12619,12625,12631],{"data":12608,"content":12609,"nodeType":881},{},[12610],{"data":12611,"marks":12612,"value":9122,"nodeType":867},{},[],{"data":12614,"content":12615,"nodeType":881},{},[12616],{"data":12617,"marks":12618,"value":9129,"nodeType":867},{},[],{"data":12620,"content":12621,"nodeType":881},{},[12622],{"data":12623,"marks":12624,"value":9136,"nodeType":867},{},[],{"data":12626,"content":12627,"nodeType":881},{},[12628],{"data":12629,"marks":12630,"value":9143,"nodeType":867},{},[],{"data":12632,"content":12633,"nodeType":881},{},[12634],{"data":12635,"marks":12636,"value":9150,"nodeType":867},{},[],{"data":12638,"content":12639,"nodeType":2438},{},[12640,12649],{"data":12641,"content":12642,"nodeType":2452},{},[12643],{"data":12644,"content":12645,"nodeType":881},{},[12646],{"data":12647,"marks":12648,"value":9163,"nodeType":867},{},[],{"data":12650,"content":12651,"nodeType":2452},{},[12652,12658,12664,12670],{"data":12653,"content":12654,"nodeType":881},{},[12655],{"data":12656,"marks":12657,"value":9173,"nodeType":867},{},[],{"data":12659,"content":12660,"nodeType":881},{},[12661],{"data":12662,"marks":12663,"value":9180,"nodeType":867},{},[],{"data":12665,"content":12666,"nodeType":881},{},[12667],{"data":12668,"marks":12669,"value":9187,"nodeType":867},{},[],{"data":12671,"content":12672,"nodeType":881},{},[12673],{"data":12674,"marks":12675,"value":9194,"nodeType":867},{},[],{"data":12677,"content":12678,"nodeType":2438},{},[12679,12688],{"data":12680,"content":12681,"nodeType":2452},{},[12682],{"data":12683,"content":12684,"nodeType":881},{},[12685],{"data":12686,"marks":12687,"value":9207,"nodeType":867},{},[],{"data":12689,"content":12690,"nodeType":2452},{},[12691],{"data":12692,"content":12693,"nodeType":881},{},[12694],{"data":12695,"marks":12696,"value":9217,"nodeType":867},{},[],{"data":12698,"content":12699,"nodeType":2438},{},[12700,12709],{"data":12701,"content":12702,"nodeType":2452},{},[12703],{"data":12704,"content":12705,"nodeType":881},{},[12706],{"data":12707,"marks":12708,"value":9230,"nodeType":867},{},[],{"data":12710,"content":12711,"nodeType":2452},{},[12712],{"data":12713,"content":12714,"nodeType":881},{},[12715],{"data":12716,"marks":12717,"value":9240,"nodeType":867},{},[],{"data":12719,"content":12720,"nodeType":2438},{},[12721,12730],{"data":12722,"content":12723,"nodeType":2452},{},[12724],{"data":12725,"content":12726,"nodeType":881},{},[12727],{"data":12728,"marks":12729,"value":9253,"nodeType":867},{},[],{"data":12731,"content":12732,"nodeType":2452},{},[12733],{"data":12734,"content":12735,"nodeType":881},{},[12736],{"data":12737,"marks":12738,"value":9263,"nodeType":867},{},[],{"data":12740,"content":12741,"nodeType":998},{},[12742],{"data":12743,"marks":12744,"value":9270,"nodeType":867},{},[],{"data":12746,"content":12747,"nodeType":881},{},[12748,12751,12758,12761,12768],{"data":12749,"marks":12750,"value":9277,"nodeType":867},{},[],{"data":12752,"content":12753,"nodeType":876},{"uri":5843},[12754],{"data":12755,"marks":12756,"value":9285,"nodeType":867},{},[12757],{"type":1040},{"data":12759,"marks":12760,"value":1253,"nodeType":867},{},[],{"data":12762,"content":12763,"nodeType":876},{"uri":9291},[12764],{"data":12765,"marks":12766,"value":9297,"nodeType":867},{},[12767],{"type":1040},{"data":12769,"marks":12770,"value":9301,"nodeType":867},{},[],{"data":12772,"content":12773,"nodeType":2531},{},[12774,12797,12836,12857,12890,12929,12950,12971],{"data":12775,"content":12776,"nodeType":2438},{},[12777,12787],{"data":12778,"content":12779,"nodeType":2452},{},[12780],{"data":12781,"content":12782,"nodeType":881},{},[12783],{"data":12784,"marks":12785,"value":9037,"nodeType":867},{},[12786],{"type":916},{"data":12788,"content":12789,"nodeType":2452},{},[12790],{"data":12791,"content":12792,"nodeType":881},{},[12793],{"data":12794,"marks":12795,"value":8661,"nodeType":867},{},[12796],{"type":916},{"data":12798,"content":12799,"nodeType":2438},{},[12800,12809],{"data":12801,"content":12802,"nodeType":2452},{},[12803],{"data":12804,"content":12805,"nodeType":881},{},[12806],{"data":12807,"marks":12808,"value":8563,"nodeType":867},{},[],{"data":12810,"content":12811,"nodeType":2452},{},[12812,12818,12824,12830],{"data":12813,"content":12814,"nodeType":881},{},[12815],{"data":12816,"marks":12817,"value":9349,"nodeType":867},{},[],{"data":12819,"content":12820,"nodeType":881},{},[12821],{"data":12822,"marks":12823,"value":9356,"nodeType":867},{},[],{"data":12825,"content":12826,"nodeType":881},{},[12827],{"data":12828,"marks":12829,"value":9363,"nodeType":867},{},[],{"data":12831,"content":12832,"nodeType":881},{},[12833],{"data":12834,"marks":12835,"value":9370,"nodeType":867},{},[],{"data":12837,"content":12838,"nodeType":2438},{},[12839,12848],{"data":12840,"content":12841,"nodeType":2452},{},[12842],{"data":12843,"content":12844,"nodeType":881},{},[12845],{"data":12846,"marks":12847,"value":9089,"nodeType":867},{},[],{"data":12849,"content":12850,"nodeType":2452},{},[12851],{"data":12852,"content":12853,"nodeType":881},{},[12854],{"data":12855,"marks":12856,"value":9392,"nodeType":867},{},[],{"data":12858,"content":12859,"nodeType":2438},{},[12860,12869],{"data":12861,"content":12862,"nodeType":2452},{},[12863],{"data":12864,"content":12865,"nodeType":881},{},[12866],{"data":12867,"marks":12868,"value":9112,"nodeType":867},{},[],{"data":12870,"content":12871,"nodeType":2452},{},[12872,12878,12884],{"data":12873,"content":12874,"nodeType":881},{},[12875],{"data":12876,"marks":12877,"value":9414,"nodeType":867},{},[],{"data":12879,"content":12880,"nodeType":881},{},[12881],{"data":12882,"marks":12883,"value":9421,"nodeType":867},{},[],{"data":12885,"content":12886,"nodeType":881},{},[12887],{"data":12888,"marks":12889,"value":9150,"nodeType":867},{},[],{"data":12891,"content":12892,"nodeType":2438},{},[12893,12902],{"data":12894,"content":12895,"nodeType":2452},{},[12896],{"data":12897,"content":12898,"nodeType":881},{},[12899],{"data":12900,"marks":12901,"value":9163,"nodeType":867},{},[],{"data":12903,"content":12904,"nodeType":2452},{},[12905,12911,12917,12923],{"data":12906,"content":12907,"nodeType":881},{},[12908],{"data":12909,"marks":12910,"value":9449,"nodeType":867},{},[],{"data":12912,"content":12913,"nodeType":881},{},[12914],{"data":12915,"marks":12916,"value":9456,"nodeType":867},{},[],{"data":12918,"content":12919,"nodeType":881},{},[12920],{"data":12921,"marks":12922,"value":9463,"nodeType":867},{},[],{"data":12924,"content":12925,"nodeType":881},{},[12926],{"data":12927,"marks":12928,"value":9470,"nodeType":867},{},[],{"data":12930,"content":12931,"nodeType":2438},{},[12932,12941],{"data":12933,"content":12934,"nodeType":2452},{},[12935],{"data":12936,"content":12937,"nodeType":881},{},[12938],{"data":12939,"marks":12940,"value":9207,"nodeType":867},{},[],{"data":12942,"content":12943,"nodeType":2452},{},[12944],{"data":12945,"content":12946,"nodeType":881},{},[12947],{"data":12948,"marks":12949,"value":9492,"nodeType":867},{},[],{"data":12951,"content":12952,"nodeType":2438},{},[12953,12962],{"data":12954,"content":12955,"nodeType":2452},{},[12956],{"data":12957,"content":12958,"nodeType":881},{},[12959],{"data":12960,"marks":12961,"value":9230,"nodeType":867},{},[],{"data":12963,"content":12964,"nodeType":2452},{},[12965],{"data":12966,"content":12967,"nodeType":881},{},[12968],{"data":12969,"marks":12970,"value":9514,"nodeType":867},{},[],{"data":12972,"content":12973,"nodeType":2438},{},[12974,12983],{"data":12975,"content":12976,"nodeType":2452},{},[12977],{"data":12978,"content":12979,"nodeType":881},{},[12980],{"data":12981,"marks":12982,"value":9253,"nodeType":867},{},[],{"data":12984,"content":12985,"nodeType":2452},{},[12986],{"data":12987,"content":12988,"nodeType":881},{},[12989],{"data":12990,"marks":12991,"value":9536,"nodeType":867},{},[],{"data":12993,"content":12994,"nodeType":998},{},[12995],{"data":12996,"marks":12997,"value":9543,"nodeType":867},{},[],{"data":12999,"content":13000,"nodeType":881},{},[13001],{"data":13002,"marks":13003,"value":9550,"nodeType":867},{},[],{"data":13005,"content":13006,"nodeType":2531},{},[13007,13030,13051,13072,13093,13132,13153,13174],{"data":13008,"content":13009,"nodeType":2438},{},[13010,13020],{"data":13011,"content":13012,"nodeType":2452},{},[13013],{"data":13014,"content":13015,"nodeType":881},{},[13016],{"data":13017,"marks":13018,"value":9037,"nodeType":867},{},[13019],{"type":916},{"data":13021,"content":13022,"nodeType":2452},{},[13023],{"data":13024,"content":13025,"nodeType":881},{},[13026],{"data":13027,"marks":13028,"value":9577,"nodeType":867},{},[13029],{"type":916},{"data":13031,"content":13032,"nodeType":2438},{},[13033,13042],{"data":13034,"content":13035,"nodeType":2452},{},[13036],{"data":13037,"content":13038,"nodeType":881},{},[13039],{"data":13040,"marks":13041,"value":8563,"nodeType":867},{},[],{"data":13043,"content":13044,"nodeType":2452},{},[13045],{"data":13046,"content":13047,"nodeType":881},{},[13048],{"data":13049,"marks":13050,"value":9599,"nodeType":867},{},[],{"data":13052,"content":13053,"nodeType":2438},{},[13054,13063],{"data":13055,"content":13056,"nodeType":2452},{},[13057],{"data":13058,"content":13059,"nodeType":881},{},[13060],{"data":13061,"marks":13062,"value":9089,"nodeType":867},{},[],{"data":13064,"content":13065,"nodeType":2452},{},[13066],{"data":13067,"content":13068,"nodeType":881},{},[13069],{"data":13070,"marks":13071,"value":9621,"nodeType":867},{},[],{"data":13073,"content":13074,"nodeType":2438},{},[13075,13084],{"data":13076,"content":13077,"nodeType":2452},{},[13078],{"data":13079,"content":13080,"nodeType":881},{},[13081],{"data":13082,"marks":13083,"value":9112,"nodeType":867},{},[],{"data":13085,"content":13086,"nodeType":2452},{},[13087],{"data":13088,"content":13089,"nodeType":881},{},[13090],{"data":13091,"marks":13092,"value":9643,"nodeType":867},{},[],{"data":13094,"content":13095,"nodeType":2438},{},[13096,13105],{"data":13097,"content":13098,"nodeType":2452},{},[13099],{"data":13100,"content":13101,"nodeType":881},{},[13102],{"data":13103,"marks":13104,"value":9163,"nodeType":867},{},[],{"data":13106,"content":13107,"nodeType":2452},{},[13108,13114,13120,13126],{"data":13109,"content":13110,"nodeType":881},{},[13111],{"data":13112,"marks":13113,"value":9665,"nodeType":867},{},[],{"data":13115,"content":13116,"nodeType":881},{},[13117],{"data":13118,"marks":13119,"value":9672,"nodeType":867},{},[],{"data":13121,"content":13122,"nodeType":881},{},[13123],{"data":13124,"marks":13125,"value":9679,"nodeType":867},{},[],{"data":13127,"content":13128,"nodeType":881},{},[13129],{"data":13130,"marks":13131,"value":9686,"nodeType":867},{},[],{"data":13133,"content":13134,"nodeType":2438},{},[13135,13144],{"data":13136,"content":13137,"nodeType":2452},{},[13138],{"data":13139,"content":13140,"nodeType":881},{},[13141],{"data":13142,"marks":13143,"value":9207,"nodeType":867},{},[],{"data":13145,"content":13146,"nodeType":2452},{},[13147],{"data":13148,"content":13149,"nodeType":881},{},[13150],{"data":13151,"marks":13152,"value":9492,"nodeType":867},{},[],{"data":13154,"content":13155,"nodeType":2438},{},[13156,13165],{"data":13157,"content":13158,"nodeType":2452},{},[13159],{"data":13160,"content":13161,"nodeType":881},{},[13162],{"data":13163,"marks":13164,"value":9230,"nodeType":867},{},[],{"data":13166,"content":13167,"nodeType":2452},{},[13168],{"data":13169,"content":13170,"nodeType":881},{},[13171],{"data":13172,"marks":13173,"value":9729,"nodeType":867},{},[],{"data":13175,"content":13176,"nodeType":2438},{},[13177,13186],{"data":13178,"content":13179,"nodeType":2452},{},[13180],{"data":13181,"content":13182,"nodeType":881},{},[13183],{"data":13184,"marks":13185,"value":9253,"nodeType":867},{},[],{"data":13187,"content":13188,"nodeType":2452},{},[13189],{"data":13190,"content":13191,"nodeType":881},{},[13192],{"data":13193,"marks":13194,"value":9751,"nodeType":867},{},[],{"data":13196,"content":13197,"nodeType":998},{},[13198],{"data":13199,"marks":13200,"value":9758,"nodeType":867},{},[],{"data":13202,"content":13203,"nodeType":2531},{},[13204,13227,13248,13269,13290,13317,13338,13359],{"data":13205,"content":13206,"nodeType":2438},{},[13207,13217],{"data":13208,"content":13209,"nodeType":2452},{},[13210],{"data":13211,"content":13212,"nodeType":881},{},[13213],{"data":13214,"marks":13215,"value":9037,"nodeType":867},{},[13216],{"type":916},{"data":13218,"content":13219,"nodeType":2452},{},[13220],{"data":13221,"content":13222,"nodeType":881},{},[13223],{"data":13224,"marks":13225,"value":9785,"nodeType":867},{},[13226],{"type":916},{"data":13228,"content":13229,"nodeType":2438},{},[13230,13239],{"data":13231,"content":13232,"nodeType":2452},{},[13233],{"data":13234,"content":13235,"nodeType":881},{},[13236],{"data":13237,"marks":13238,"value":8563,"nodeType":867},{},[],{"data":13240,"content":13241,"nodeType":2452},{},[13242],{"data":13243,"content":13244,"nodeType":881},{},[13245],{"data":13246,"marks":13247,"value":9807,"nodeType":867},{},[],{"data":13249,"content":13250,"nodeType":2438},{},[13251,13260],{"data":13252,"content":13253,"nodeType":2452},{},[13254],{"data":13255,"content":13256,"nodeType":881},{},[13257],{"data":13258,"marks":13259,"value":9089,"nodeType":867},{},[],{"data":13261,"content":13262,"nodeType":2452},{},[13263],{"data":13264,"content":13265,"nodeType":881},{},[13266],{"data":13267,"marks":13268,"value":9829,"nodeType":867},{},[],{"data":13270,"content":13271,"nodeType":2438},{},[13272,13281],{"data":13273,"content":13274,"nodeType":2452},{},[13275],{"data":13276,"content":13277,"nodeType":881},{},[13278],{"data":13279,"marks":13280,"value":9112,"nodeType":867},{},[],{"data":13282,"content":13283,"nodeType":2452},{},[13284],{"data":13285,"content":13286,"nodeType":881},{},[13287],{"data":13288,"marks":13289,"value":9851,"nodeType":867},{},[],{"data":13291,"content":13292,"nodeType":2438},{},[13293,13302],{"data":13294,"content":13295,"nodeType":2452},{},[13296],{"data":13297,"content":13298,"nodeType":881},{},[13299],{"data":13300,"marks":13301,"value":9163,"nodeType":867},{},[],{"data":13303,"content":13304,"nodeType":2452},{},[13305,13311],{"data":13306,"content":13307,"nodeType":881},{},[13308],{"data":13309,"marks":13310,"value":9873,"nodeType":867},{},[],{"data":13312,"content":13313,"nodeType":881},{},[13314],{"data":13315,"marks":13316,"value":9880,"nodeType":867},{},[],{"data":13318,"content":13319,"nodeType":2438},{},[13320,13329],{"data":13321,"content":13322,"nodeType":2452},{},[13323],{"data":13324,"content":13325,"nodeType":881},{},[13326],{"data":13327,"marks":13328,"value":9207,"nodeType":867},{},[],{"data":13330,"content":13331,"nodeType":2452},{},[13332],{"data":13333,"content":13334,"nodeType":881},{},[13335],{"data":13336,"marks":13337,"value":9217,"nodeType":867},{},[],{"data":13339,"content":13340,"nodeType":2438},{},[13341,13350],{"data":13342,"content":13343,"nodeType":2452},{},[13344],{"data":13345,"content":13346,"nodeType":881},{},[13347],{"data":13348,"marks":13349,"value":9230,"nodeType":867},{},[],{"data":13351,"content":13352,"nodeType":2452},{},[13353],{"data":13354,"content":13355,"nodeType":881},{},[13356],{"data":13357,"marks":13358,"value":9729,"nodeType":867},{},[],{"data":13360,"content":13361,"nodeType":2438},{},[13362,13371],{"data":13363,"content":13364,"nodeType":2452},{},[13365],{"data":13366,"content":13367,"nodeType":881},{},[13368],{"data":13369,"marks":13370,"value":9253,"nodeType":867},{},[],{"data":13372,"content":13373,"nodeType":2452},{},[13374],{"data":13375,"content":13376,"nodeType":881},{},[13377],{"data":13378,"marks":13379,"value":9751,"nodeType":867},{},[],{"data":13381,"content":13382,"nodeType":908},{},[],{"data":13384,"content":13385,"nodeType":918},{},[13386],{"data":13387,"marks":13388,"value":9954,"nodeType":867},{},[13389],{"type":916},{"data":13391,"content":13392,"nodeType":881},{},[13393],{"data":13394,"marks":13395,"value":9961,"nodeType":867},{},[],{"data":13397,"content":13398,"nodeType":881},{},[13399],{"data":13400,"marks":13401,"value":9968,"nodeType":867},{},[],{"data":13403,"content":13404,"nodeType":881},{},[13405,13409],{"data":13406,"marks":13407,"value":9976,"nodeType":867},{},[13408],{"type":916},{"data":13410,"marks":13411,"value":9980,"nodeType":867},{},[],{"data":13413,"content":13414,"nodeType":908},{},[],{"data":13416,"content":13417,"nodeType":918},{},[13418],{"data":13419,"marks":13420,"value":2382,"nodeType":867},{},[13421],{"type":916},{"data":13423,"content":13424,"nodeType":881},{},[13425,13428,13434],{"data":13426,"marks":13427,"value":9997,"nodeType":867},{},[],{"data":13429,"content":13430,"nodeType":876},{"uri":2392},[13431],{"data":13432,"marks":13433,"value":2397,"nodeType":867},{},[],{"data":13435,"marks":13436,"value":10007,"nodeType":867},{},[],{"data":13438,"content":13439,"nodeType":881},{},[13440,13443,13449],{"data":13441,"marks":13442,"value":21,"nodeType":867},{},[],{"data":13444,"content":13445,"nodeType":876},{"uri":10016},[13446],{"data":13447,"marks":13448,"value":10021,"nodeType":867},{},[],{"data":13450,"marks":13451,"value":21,"nodeType":867},{},[],{"data":13453,"content":13454,"nodeType":881},{},[13455],{"data":13456,"marks":13457,"value":2338,"nodeType":867},{},[13458],{"type":916},{"data":13460,"content":13461,"nodeType":908},{},[],{"data":13463,"content":13464,"nodeType":918},{},[13465],{"data":13466,"marks":13467,"value":10042,"nodeType":867},{},[13468],{"type":916},{"data":13470,"content":13471,"nodeType":881},{},[13472,13475,13481],{"data":13473,"marks":13474,"value":10049,"nodeType":867},{},[],{"data":13476,"content":13477,"nodeType":876},{"uri":1629},[13478],{"data":13479,"marks":13480,"value":3399,"nodeType":867},{},[],{"data":13482,"marks":13483,"value":1639,"nodeType":867},{},[],{"entries":13485},{"hyperlink":13486,"inline":13487,"block":13488},[],[],[13489,13496,13521,13547,13561,13568,13573,13618,13624,13630,13644,13650,13657,13664,13667,13674,13681],{"sys":13490,"__typename":1648,"title":13491,"caption":13492,"layoutMode":59,"file":13493},{"id":8225},"One example of a deployment portal identified Push that is currently in active use (redacted).","One example of a deployment portal identified by Push that is currently in active use (redacted).",{"url":13494,"width":1661,"height":13495},"https://images.ctfassets.net/y1cdw1ablpvd/68nyea8Rava8TWxoodHhM7/ca0a81e683c541b969703c22a3f2b992/image4.png",1124,{"sys":13497,"__typename":1696,"content":13498,"name":13520,"title":59},{"id":8243},{"json":13499},{"nodeType":1640,"data":13500,"content":13501},{},[13502,13509],{"nodeType":881,"data":13503,"content":13504},{},[13505],{"nodeType":867,"value":13506,"marks":13507,"data":13508},"It’s easier than ever for attackers to spin up and tear down their phishing infrastructure by abusing a range of legitimate services. This is why we’re focused on detecting the actual malicious page at the end of the chain, regardless of the hosting, infrastructure, or delivery vector.",[],{},{"nodeType":881,"data":13510,"content":13511},{},[13512,13517],{"nodeType":867,"value":13513,"marks":13514,"data":13516},"This is extra useful in this case when we consider that a phone call is the delivery vector — not something that typically email-based phishing controls would be able to intercept",[13515],{"type":916},{},{"nodeType":867,"value":1947,"marks":13518,"data":13519},[],{},"Phishing Panel Blog IB1",{"sys":13522,"__typename":1696,"content":13523,"name":13546,"title":59},{"id":8337},{"json":13524},{"data":13525,"content":13526,"nodeType":1640},{},[13527],{"data":13528,"content":13529,"nodeType":881},{},[13530,13534,13542],{"data":13531,"marks":13532,"value":13533,"nodeType":867},{},[],"Resulting breaches have already been publicly confirmed at SoundCloud (30 million records), Match Group (Hinge, OkCupid, and Match.com — over 10 million records), Betterment (20 million records), and Crunchbase, among others — all linked to ",{"data":13535,"content":13536,"nodeType":876},{"uri":3051},[13537],{"data":13538,"marks":13539,"value":13541,"nodeType":867},{},[13540],{"type":1040},"ShinyHunters-branded",{"data":13543,"marks":13544,"value":13545,"nodeType":867},{},[]," extortion demands. The group also claimed breaches at Bumble, CarMax, Panera Bread, Harvard, the University of Pennsylvania and others in the same period, using data stolen in the Salesforce breaches in 2025 to identify victims and make the social engineering more convincing.","Phishing Panel Blog IB5",{"sys":13548,"__typename":1696,"content":13549,"name":13560,"title":59},{"id":8361},{"json":13550},{"nodeType":1640,"data":13551,"content":13552},{},[13553],{"nodeType":881,"data":13554,"content":13555},{},[13556],{"nodeType":867,"value":13557,"marks":13558,"data":13559},"Doko’s Panel, which takes its name from the Telegram alias of its developer, was linked to ShinyHunters attacks earlier this year. The same persona behind Doko's Panel has been observed actively recruiting \"experienced callers\" via Telegram, specifying requirements including fluent English with no accent, and advertising six-to-seven-figure weekly returns — evidence of the professionalized vishing-as-a-service model that complements the phishing kit ecosystem. ",[],{},"Phishing Panel Blog IB2",{"sys":13562,"__typename":1648,"title":13563,"caption":13563,"layoutMode":59,"file":13564},{"id":8508},"How the panel is operated during a phishing attack",{"url":13565,"width":13566,"height":13567},"https://images.ctfassets.net/y1cdw1ablpvd/37tinpxZjSb3LUOCdnVKge/b92c9911e992de27f6411f07b0c1e796/Screenshot_2026-05-07_at_12.33.21.png",3290,1902,{"sys":13569,"__typename":1671,"title":13570,"arcadeDemoUrl":13571,"playText":13572},{"id":8514},"Phishing Panel Annotated Demo","https://demo.arcade.software/dDjAyFfOHyGepDwLWJKw?embed","1 mins",{"sys":13574,"__typename":1696,"content":13575,"name":13617,"title":59},{"id":8526},{"json":13576},{"nodeType":1640,"data":13577,"content":13578},{},[13579,13586],{"nodeType":881,"data":13580,"content":13581},{},[13582],{"nodeType":867,"value":13583,"marks":13584,"data":13585},"Functionally, this is the same as a typical AITM attack — except that the stages are performed manually by the attacker instead of automatically proxying the victim’s inputs to the real site. ",[],{},{"nodeType":881,"data":13587,"content":13588},{},[13589,13593,13600,13604,13613],{"nodeType":867,"value":13590,"marks":13591,"data":13592},"This seems like an odd choice. On one hand, this is a very sophisticated version of a voice phishing attack. But on the other, it’s not taking advantage of some of the standard capabilities that common AITM kits have. This more manual approach is something that ",[],{},{"nodeType":876,"data":13594,"content":13595},{"uri":3051},[13596],{"nodeType":867,"value":13597,"marks":13598,"data":13599},"Scattered Spider",[],{},{"nodeType":867,"value":13601,"marks":13602,"data":13603}," were known for during the ",[],{},{"nodeType":876,"data":13605,"content":13607},{"uri":13606},"https://www.group-ib.com/blog/0ktapus/",[13608],{"nodeType":867,"value":13609,"marks":13610,"data":13612},"0ktapus",[13611],{"type":1040},{},{"nodeType":867,"value":13614,"marks":13615,"data":13616}," days. But it doesn’t make much difference to the outcome, or what we can observe to detect the attack in the browser.",[],{},"Phishing Panel Blog IB3",{"sys":13619,"__typename":1648,"title":13620,"caption":13620,"layoutMode":59,"file":13621},{"id":8624},"Anyone can access Doko’s Panel without authentication.",{"url":13622,"width":1661,"height":13623},"https://images.ctfassets.net/y1cdw1ablpvd/1E2c3tIITtYeiD5GtSecxt/91c95bb593188975b1a4a96effb5bea8/image5.png",307,{"sys":13625,"__typename":1648,"title":13626,"caption":13626,"layoutMode":59,"file":13627},{"id":8630},"Admin panel controls.",{"url":13628,"width":1661,"height":13629},"https://images.ctfassets.net/y1cdw1ablpvd/2A56uZUHEDmm8RbeW9IpjE/491e686b77dd60a676d0eebb3ca101c6/image2.png",1059,{"sys":13631,"__typename":1696,"content":13632,"name":13643,"title":59},{"id":8713},{"json":13633},{"data":13634,"content":13635,"nodeType":1640},{},[13636],{"data":13637,"content":13638,"nodeType":881},{},[13639],{"data":13640,"marks":13641,"value":13642,"nodeType":867},{},[],"The result is that the victim's browser sends two pairs of duplicate requests every few seconds (with the inline script transmitting heartbeats in JSON format rather than HTML form-encoded data). This level of broken duplication indicates an inexperienced developer making modifications to unfamiliar code — a pattern reinforced by the LLM-generated artifacts discussed later. ","Phishing Panel Blog IB4",{"sys":13645,"__typename":1648,"title":13646,"caption":13646,"layoutMode":59,"file":13647},{"id":8796},"Revamped admin panel specifically targeting M365.",{"url":13648,"width":1661,"height":13649},"https://images.ctfassets.net/y1cdw1ablpvd/6ltgUv6FOGaMkdYNW06uBC/6449e82609fda96af123dfbd09c2f8c0/image8.png",940,{"sys":13651,"__typename":1648,"title":13652,"caption":13652,"layoutMode":59,"file":13653},{"id":8816},"Instructions for joining the attacker’s Teams meeting.",{"url":13654,"width":13655,"height":13656},"https://images.ctfassets.net/y1cdw1ablpvd/7G6GLi6twkTrDOGFHU9RNt/a1aa2a7a324ba3eda2f38d21af0e4a85/image3.png",1390,1316,{"sys":13658,"__typename":1648,"title":13659,"caption":13659,"layoutMode":59,"file":13660},{"id":8869},"Device and country restriction options.",{"url":13661,"width":13662,"height":13663},"https://images.ctfassets.net/y1cdw1ablpvd/2nxMJQlSeyBwuFgZIsjeRF/78df4d0e8c75a8171937294c1684b3df/image6.png",1064,1192,{"sys":13665,"__typename":1648,"title":1689,"caption":1689,"layoutMode":59,"file":13666},{"id":1258},{"url":1691,"width":1692,"height":1693},{"sys":13668,"__typename":1648,"title":13669,"caption":13669,"layoutMode":59,"file":13670},{"id":8926},"More verbose phishing kit comments.",{"url":13671,"width":13672,"height":13673},"https://images.ctfassets.net/y1cdw1ablpvd/2VIaWB9ExM6nmURNtoP7f4/bc72afef6d151c7e9d5be71f0c74a651/Screenshot_2026-05-07_at_12.53.08.png",1184,1036,{"sys":13675,"__typename":1648,"title":13676,"caption":13676,"layoutMode":59,"file":13677},{"id":8939},"Evidence of LLM use in cloning the Okta login pages.",{"url":13678,"width":13679,"height":13680},"https://images.ctfassets.net/y1cdw1ablpvd/5UL0neYANY9ECegc0JsDzL/45a4576d016d9fa806598cabaf493a0f/Screenshot_2026-05-07_at_12.53.49.png",1164,586,{"sys":13682,"__typename":1648,"title":13683,"caption":13683,"layoutMode":59,"file":13684},{"id":8952},"LLM comments not typically included by a human author.",{"url":13685,"width":13686,"height":13687},"https://images.ctfassets.net/y1cdw1ablpvd/6yXfx49paHKklV1iLfGiBP/6eb461b66533a9ef25eb671370c8f316/Screenshot_2026-05-07_at_12.54.09.png",942,430,{"items":13689},[],{},"Inside a phishing panel used by ShinyHunters and BlackFile",{"items":13693},[13694,14275,15238],{"__typename":1742,"sys":13695,"content":13697,"title":14262,"synopsis":14263,"hashTags":59,"publishedDate":10832,"slug":14264,"tagsCollection":14265,"authorsCollection":14271},{"id":13696},"27Z1JlNtpGTPyarh393sHK",{"json":13698},{"data":13699,"content":13700,"nodeType":1640},{},[13701,13719,13726,13732,13739,13745,13764,13770,13776,13779,13787,13807,13813,13819,13825,13843,13850,13858,13865,13872,13879,13882,13890,13908,13931,13936,13941,13948,13955,13962,13965,13973,13991,14024,14031,14037,14040,14048,14055,14058,14066,14073,14081,14101,14121,14128,14134,14142,14149,14156,14159,14166,14173,14179,14199,14205,14212,14219,14226],{"data":13702,"content":13703,"nodeType":881},{},[13704,13708,13715],{"data":13705,"marks":13706,"value":13707,"nodeType":867},{},[],"In December 2025, we uncovered a state-sponsored campaign linked to Russian state-affiliated APT29 that used a new technique we called ",{"data":13709,"content":13710,"nodeType":876},{"uri":1319},[13711],{"data":13712,"marks":13713,"value":1312,"nodeType":867},{},[13714],{"type":1040},{"data":13716,"marks":13717,"value":13718,"nodeType":867},{},[],". This technique merged ClickFix-style social engineering with OAuth consent phishing to hijack Microsoft accounts. Effectively, ConsentFix is a browser-native attack that results in account takeover, without the downside of needing to touch the endpoint like typical ClickFix (really, the point that it's most likely to be detected and blocked). ",{"data":13720,"content":13721,"nodeType":881},{},[13722],{"data":13723,"marks":13724,"value":13725,"nodeType":867},{},[],"The quick 101 is that victims are tricked into copy-and-pasting a legitimate Microsoft URL into the phishing page. This URL contains an OAuth authorization code that the attacker uses to sign in to a first-party Microsoft application like Azure CLI — specifically targeting apps with known Conditional Access exclusions. ",{"data":13727,"content":13731,"nodeType":890},{"target":13728},{"sys":13729},{"id":13730,"type":887,"linkType":888},"7s4kF5CUFUmdkhpzuwNalX",[],{"data":13733,"content":13734,"nodeType":881},{},[13735],{"data":13736,"marks":13737,"value":13738,"nodeType":867},{},[],"At the end of the attack chain, the attacker is effectively granted API access to the victim's Entra account, while sidestepping MFA (even passkeys), device compliance checks, and in some cases conditional access controls (depending on the application ID targeted by the attacker). ",{"data":13740,"content":13744,"nodeType":890},{"target":13741},{"sys":13742},{"id":13743,"type":887,"linkType":888},"IMtJXMWeaIbRsWxuQ1CaS",[],{"data":13746,"content":13747,"nodeType":881},{},[13748,13752,13760],{"data":13749,"marks":13750,"value":13751,"nodeType":867},{},[],"It didn’t take long for security researchers to jump on this new technique. Lots of contributors rallied round the security recommendations (which we covered in a ",{"data":13753,"content":13754,"nodeType":876},{"uri":2877},[13755],{"data":13756,"marks":13757,"value":13759,"nodeType":867},{},[13758],{"type":1040},"follow-up blog post",{"data":13761,"marks":13762,"value":13763,"nodeType":867},{},[],") but the most notable contribution came from John Hammond, who took the attacker’s implementation and said “I can do better”. His v2 replaced a somewhat clunky implementation with a slick drag-and-drop function. But now, attackers have taken it one step further.",{"data":13765,"content":13769,"nodeType":890},{"target":13766},{"sys":13767},{"id":13768,"type":887,"linkType":888},"59tfJDRhGThKD48Wjg7uY2",[],{"data":13771,"content":13775,"nodeType":890},{"target":13772},{"sys":13773},{"id":13774,"type":887,"linkType":888},"6mEpyVD6f13ZttFmaBcxNm",[],{"data":13777,"content":13778,"nodeType":908},{},[],{"data":13780,"content":13781,"nodeType":918},{},[13782],{"data":13783,"marks":13784,"value":13786,"nodeType":867},{},[13785],{"type":916},"Introducing: ConsentFix v3",{"data":13788,"content":13789,"nodeType":881},{},[13790,13794,13803],{"data":13791,"marks":13792,"value":13793,"nodeType":867},{},[],"The latest development is that a member of the XSS criminal forum, a site strongly suspected to have ",{"data":13795,"content":13797,"nodeType":876},{"uri":13796},"https://flare.io/learn/resources/blog/state-of-the-dark-web-2026",[13798],{"data":13799,"marks":13800,"value":13802,"nodeType":867},{},[13801],{"type":1040},"Russian state involvement",{"data":13804,"marks":13805,"value":13806,"nodeType":867},{},[],", has released a new tool “ConsentFix v3”, building on the v1 we saw in the wild, and John’s v2. ",{"data":13808,"content":13812,"nodeType":890},{"target":13809},{"sys":13810},{"id":13811,"type":887,"linkType":888},"4AW0UnBlIaXbIFZjy8ObY1",[],{"data":13814,"content":13818,"nodeType":890},{"target":13815},{"sys":13816},{"id":13817,"type":887,"linkType":888},"1b36XjqBpPx7wteBu6OA6h",[],{"data":13820,"content":13824,"nodeType":890},{"target":13821},{"sys":13822},{"id":13823,"type":887,"linkType":888},"4kbiWA3b096BAFGQuozPaK",[],{"data":13826,"content":13827,"nodeType":881},{},[13828,13832,13839],{"data":13829,"marks":13830,"value":13831,"nodeType":867},{},[],"It looks like broader cybercriminals are starting to take note of ConsentFix, and with the release of public tools like this one, it could be about to go mainstream — like ",{"data":13833,"content":13834,"nodeType":876},{"uri":1125},[13835],{"data":13836,"marks":13837,"value":13838,"nodeType":867},{},[],"device code phishing",{"data":13840,"marks":13841,"value":13842,"nodeType":867},{},[]," has this year. ",{"data":13844,"content":13845,"nodeType":881},{},[13846],{"data":13847,"marks":13848,"value":13849,"nodeType":867},{},[],"Let’s take a closer look at some of the more interesting details of the ConsentFix v3 implementation before considering the bigger picture.  ",{"data":13851,"content":13852,"nodeType":998},{},[13853],{"data":13854,"marks":13855,"value":13857,"nodeType":867},{},[13856],{"type":916},"ConsentFix v3 under the hood",{"data":13859,"content":13860,"nodeType":881},{},[13861],{"data":13862,"marks":13863,"value":13864,"nodeType":867},{},[],"The first thing that jumps out is just how detailed this forum post is. It reads like a security vendor blog post. It walks through the key technical concepts that the reader needs to know, breaking down OAuth grants, consent phishing, refresh tokens, and FOCI (or 'Family of Client IDs' — basically, the feature that allows attackers to use a refresh token obtained for one Microsoft app to be exchanged for access tokens to other FOCI apps without re-authentication). It then walks through the history of ClickFix and ConsentFix before providing step-by-step guidance for users. ",{"data":13866,"content":13867,"nodeType":881},{},[13868],{"data":13869,"marks":13870,"value":13871,"nodeType":867},{},[],"ConsentFix v3 allows users to instrument the entire attack chain, enabling users to spin up ConsentFix infrastructure, create believable personas with which to interact with victims, craft and manage email campaigns, and automate the process of exchanging the captured OAuth token for session and refresh tokens to establish access to the compromised account. ",{"data":13873,"content":13874,"nodeType":881},{},[13875],{"data":13876,"marks":13877,"value":13878,"nodeType":867},{},[],"A combination of SaaS and open-source tools are used to perform the attack, including Cloudflare Workers for hosting, ZoomInfo for target identification, Dropbox for PDF hosting, and Pipedream as an exfiltration channel (effectively creating a webhook to automatically exchange the OAuth material in the URL for a refresh token). They also use hacker tools like SpecterPortal for post exploitation activity.",{"data":13880,"content":13881,"nodeType":908},{},[],{"data":13883,"content":13884,"nodeType":918},{},[13885],{"data":13886,"marks":13887,"value":13889,"nodeType":867},{},[13888],{"type":916},"Why attackers are turning to OAuth-based attacks",{"data":13891,"content":13892,"nodeType":881},{},[13893,13897,13904],{"data":13894,"marks":13895,"value":13896,"nodeType":867},{},[],"Attackers are increasingly turning to OAuth based techniques in 2026. Not only are “legit” OAuth connections being abused in supply chain attacks, but attacks targeting OAuth mechanisms have significantly increased with the rise of ",{"data":13898,"content":13899,"nodeType":876},{"uri":1125},[13900],{"data":13901,"marks":13902,"value":13838,"nodeType":867},{},[13903],{"type":1040},{"data":13905,"marks":13906,"value":13907,"nodeType":867},{},[],". This is because:",{"data":13909,"content":13910,"nodeType":3126},{},[13911,13921],{"data":13912,"content":13913,"nodeType":3061},{},[13914],{"data":13915,"content":13916,"nodeType":881},{},[13917],{"data":13918,"marks":13919,"value":13920,"nodeType":867},{},[],"OAuth attacks defeat standard access controls (including passkeys)",{"data":13922,"content":13923,"nodeType":3061},{},[13924],{"data":13925,"content":13926,"nodeType":881},{},[13927],{"data":13928,"marks":13929,"value":13930,"nodeType":867},{},[],"It’s very low friction, and less likely that users will identify it as phishing (see examples below)",{"data":13932,"content":13935,"nodeType":890},{"target":13933},{"sys":13934},{"id":13768,"type":887,"linkType":888},[],{"data":13937,"content":13940,"nodeType":890},{"target":13938},{"sys":13939},{"id":2949,"type":887,"linkType":888},[],{"data":13942,"content":13943,"nodeType":881},{},[13944],{"data":13945,"marks":13946,"value":13947,"nodeType":867},{},[],"From the user’s perspective, these aren’t situations that users are trained to treat as suspicious. In one case, the victim copies a URL (or simply drag-and-drops a box on the page). In another, they enter a short passcode that’s visible on the page. ",{"data":13949,"content":13950,"nodeType":881},{},[13951],{"data":13952,"marks":13953,"value":13954,"nodeType":867},{},[],"Both are using pop-up windows that look very convincing — and point to legitimate Microsoft pages/URLs. Even users scrutinizing the domain won’t see anything out of place. And as you can see, if the user is already signed into their Microsoft account in the browser, there’s no credential entry or MFA checks to pass through. Simply select your account from the drop down menu and … that’s it.",{"data":13956,"content":13957,"nodeType":881},{},[13958],{"data":13959,"marks":13960,"value":13961,"nodeType":867},{},[],"This unfamiliarity is the same reason that attacks like ClickFix have been so successful. In general, convincing social engineering — well crafted comms, legit-looking pages hosted on trusted sites — combined with unfamiliar payloads makes for a clever attack. And when these attacks play out entirely in the browser (circumventing endpoint controls) and sidestep identity controls, the impact is dialled up even further. ",{"data":13963,"content":13964,"nodeType":908},{},[],{"data":13966,"content":13967,"nodeType":918},{},[13968],{"data":13969,"marks":13970,"value":13972,"nodeType":867},{},[13971],{"type":916},"How ConsentFix and device code phishing overlap",{"data":13974,"content":13975,"nodeType":881},{},[13976,13980,13987],{"data":13977,"marks":13978,"value":13979,"nodeType":867},{},[],"It was only ever going to be a matter of time before ConsentFix was adopted by the mass market. But these things don’t always happen particularly fast. ",{"data":13981,"content":13982,"nodeType":876},{"uri":1125},[13983],{"data":13984,"marks":13985,"value":360,"nodeType":867},{},[13986],{"type":1040},{"data":13988,"marks":13989,"value":13990,"nodeType":867},{},[]," is probably the best example of this — it’s been a known technique since 2021, but it took until this year to enter mainstream adoption. A big part of that has been the availability of criminal toolkits, and also the rise in AI-assisted capabilities for tool creation (clearly at play here too). The similarity with device code phishing doesn’t end there. ",{"data":13992,"content":13993,"nodeType":881},{},[13994,13998,14007,14011,14020],{"data":13995,"marks":13996,"value":13997,"nodeType":867},{},[],"Both ConsentFix and device code phishing are OAuth attacks. They both find ways of bypassing the standard login procedure (and controls) by targeting different authorization flows, but with a similar outcome and the same advantages to an attacker. Device code phishing exploits the device authorization grant (",{"data":13999,"content":14001,"nodeType":876},{"uri":14000},"https://datatracker.ietf.org/doc/html/rfc8628",[14002],{"data":14003,"marks":14004,"value":14006,"nodeType":867},{},[14005],{"type":1040},"RFC 8628",{"data":14008,"marks":14009,"value":14010,"nodeType":867},{},[],"). ConsentFix exploits the authorization code grant (",{"data":14012,"content":14014,"nodeType":876},{"uri":14013},"https://datatracker.ietf.org/doc/html/rfc6749#section-4.1",[14015],{"data":14016,"marks":14017,"value":14019,"nodeType":867},{},[14018],{"type":1040},"RFC 6749",{"data":14021,"marks":14022,"value":14023,"nodeType":867},{},[],") as implemented for native/desktop apps with localhost redirects. ",{"data":14025,"content":14026,"nodeType":881},{},[14027],{"data":14028,"marks":14029,"value":14030,"nodeType":867},{},[],"The post-compromise paths are essentially identical because the tokens you get are determined by which app you target, what scopes it has, and the victim user’s permissions, not by which OAuth flow you used to obtain them. The authorization code flow and the device code flow are just different front doors into the same token issuance system.",{"data":14032,"content":14036,"nodeType":890},{"target":14033},{"sys":14034},{"id":14035,"type":887,"linkType":888},"7np3j139dWMP7sLlUQwEFC",[],{"data":14038,"content":14039,"nodeType":908},{},[],{"data":14041,"content":14042,"nodeType":918},{},[14043],{"data":14044,"marks":14045,"value":14047,"nodeType":867},{},[14046],{"type":916},"The verdict: An interesting sign of what’s coming, but maybe not the final form",{"data":14049,"content":14050,"nodeType":881},{},[14051],{"data":14052,"marks":14053,"value":14054,"nodeType":867},{},[],"It’s clear that ConsentFix v3 isn’t exactly an industrialized PhaaS-scale offering. It’s probably closer to a red team-esque proof of concept. But it is a good example of how attackers could operationalize ConsentFix campaigns using largely off-the-shelf tooling and legit SaaS tools. And an indicator of what might be coming soon. ",{"data":14056,"content":14057,"nodeType":908},{},[],{"data":14059,"content":14060,"nodeType":918},{},[14061],{"data":14062,"marks":14063,"value":14065,"nodeType":867},{},[14064],{"type":916},"Security recommendations",{"data":14067,"content":14068,"nodeType":881},{},[14069],{"data":14070,"marks":14071,"value":14072,"nodeType":867},{},[],"To be able to tackle modern attacks like ConsentFix that occur entirely within the browser context, it is vital that organizations look to monitor the browser as a detection surface, hunt for signs of malicious activity, and block attacks in real-time — in the same way that you would expect EDR to work for endpoint attacks. We’ll talk about how we do this below, but first here’s some general recommendations. ",{"data":14074,"content":14075,"nodeType":998},{},[14076],{"data":14077,"marks":14078,"value":14080,"nodeType":867},{},[14079],{"type":916},"Microsoft ecosystem",{"data":14082,"content":14083,"nodeType":881},{},[14084,14088,14097],{"data":14085,"marks":14086,"value":14087,"nodeType":867},{},[],"Despite the similarity with device code phishing, the ",{"data":14089,"content":14091,"nodeType":876},{"uri":14090},"https://techcommunity.microsoft.com/blog/microsoft-entra-blog/new-microsoft-managed-policies-to-raise-your-identity-security-posture/4286758",[14092],{"data":14093,"marks":14094,"value":14096,"nodeType":867},{},[14095],{"type":1040},"primary recommendation from Microsoft for device code attacks",{"data":14098,"marks":14099,"value":14100,"nodeType":867},{},[]," — disable the device code flow via conditional access — doesn’t apply to ConsentFix (because, as mentioned, it uses a different login flow).",{"data":14102,"content":14103,"nodeType":881},{},[14104,14108,14117],{"data":14105,"marks":14106,"value":14107,"nodeType":867},{},[],"For both ConsentFix and device code phishing, the ",{"data":14109,"content":14111,"nodeType":876},{"uri":14110},"https://msendpointmgr.com/2026/01/08/consentfix-quickfix/",[14112],{"data":14113,"marks":14114,"value":14116,"nodeType":867},{},[14115],{"type":1040},"strongest recommendation",{"data":14118,"marks":14119,"value":14120,"nodeType":867},{},[]," is to create Service Principals for each of the vulnerable apps and restrict the users that are authorized to access them to reduce the attack surface of users that can be phished with this method.",{"data":14122,"content":14123,"nodeType":881},{},[14124],{"data":14125,"marks":14126,"value":14127,"nodeType":867},{},[],"You should also hunt in logs for relevant application IDs and resource IDs, and look for mismatches in terms of the initial access IP and subsequent activity, because while the initial login is performed by the user, subsequent actions will be performed by the attacker.  ",{"data":14129,"content":14133,"nodeType":890},{"target":14130},{"sys":14131},{"id":14132,"type":887,"linkType":888},"49Y7NXpnAeAYe9fCp1oyKn",[],{"data":14135,"content":14136,"nodeType":998},{},[14137],{"data":14138,"marks":14139,"value":14141,"nodeType":867},{},[14140],{"type":916},"Beyond Microsoft — Google, GitHub, Salesforce, AWS",{"data":14143,"content":14144,"nodeType":881},{},[14145],{"data":14146,"marks":14147,"value":14148,"nodeType":867},{},[],"It’s worth calling out that these recommendations are Microsoft specific. While in-the-wild exploitation has focused on Microsoft, GitHub, Salesforce, AWS and others are also impacted by device code phishing, supporting device code flow either as a primary or fallback mechanism (Google less so due to inherent restrictions on scopes authorized in the context of device code logins). ",{"data":14150,"content":14151,"nodeType":881},{},[14152],{"data":14153,"marks":14154,"value":14155,"nodeType":867},{},[],"Similarly, ConsentFix principles can be applied beyond Microsoft too. The core requirement is that an OAuth code ends up in a location the victim can manually see and share, e.g. a localhost redirect where no listener is present to complete the handshake. Google Cloud CLI, GitHub CLI, and others support the auth code grant and allow localhost as a redirect URI. ",{"data":14157,"content":14158,"nodeType":908},{},[],{"data":14160,"content":14161,"nodeType":918},{},[14162],{"data":14163,"marks":14164,"value":6214,"nodeType":867},{},[14165],{"type":916},{"data":14167,"content":14168,"nodeType":881},{},[14169],{"data":14170,"marks":14171,"value":14172,"nodeType":867},{},[],"We’re already detecting and blocking both ConsentFix and device code phishing attacks as they target users in their web browser. When a page matches our detections for a device code or ConsentFix phishing kit (not limited to things like known-bad IPs and domains, but DOM-level analysis of the web page) Push detects and blocks it. Unlike an SWG or RBI type solution, Push analyzes every web page in every browser session and tab, in real time, with no latency. ",{"data":14174,"content":14178,"nodeType":890},{"target":14175},{"sys":14176},{"id":14177,"type":887,"linkType":888},"63EwHbmFZVAlhoXl17Xjfi",[],{"data":14180,"content":14181,"nodeType":881},{},[14182,14186,14195],{"data":14183,"marks":14184,"value":14185,"nodeType":867},{},[],"Using Push you can also ",{"data":14187,"content":14189,"nodeType":876},{"uri":14188},"https://pushsecurity.com/help/can-i-use-push-to-help-protect-against-device-code-phishing-scenarios/",[14190],{"data":14191,"marks":14192,"value":14194,"nodeType":867},{},[14193],{"type":1040},"configure in-browser warnings",{"data":14196,"marks":14197,"value":14198,"nodeType":867},{},[]," whenever a user accesses a URL used for device code logins, across any app that supports them. This provides universal, last-mile protection against even ‘zero-day’ device code phishing attacks using previously unidentified toolkits.  ",{"data":14200,"content":14204,"nodeType":890},{"target":14201},{"sys":14202},{"id":14203,"type":887,"linkType":888},"3baS2yqvJd2e4aczw73PTF",[],{"data":14206,"content":14207,"nodeType":881},{},[14208],{"data":14209,"marks":14210,"value":14211,"nodeType":867},{},[],"When a user visits those URLs, Push will also emit a webhook event that the banner was shown and acknowledged. If a user opts to proceed, you can treat this as a high-fidelity alert for your security team to investigate, providing app-agnostic telemetry that may not already be provided in your logs from that particular vendor. You can also simply use Push to block users from accessing these pages if you’re confident that disruption won’t be caused. ",{"data":14213,"content":14214,"nodeType":998},{},[14215],{"data":14216,"marks":14217,"value":10042,"nodeType":867},{},[14218],{"type":916},{"data":14220,"content":14221,"nodeType":881},{},[14222],{"data":14223,"marks":14224,"value":14225,"nodeType":867},{},[],"Push Security's browser-based security platform detects and blocks browser-based attacks like AiTM phishing, credential stuffing, malicious browser extensions, device code phishing, ClickFix, and session hijacking. You don't need to wait until it all goes wrong either — you can use Push to proactively find and fix vulnerabilities across the apps that your employees use, like ghost logins, SSO coverage gaps, MFA gaps, vulnerable passwords, risky OAuth integrations, and more to harden your attack surface.",{"data":14227,"content":14228,"nodeType":881},{},[14229,14232,14239,14242,14249,14252,14259],{"data":14230,"marks":14231,"value":10795,"nodeType":867},{},[],{"data":14233,"content":14234,"nodeType":876},{"uri":10798},[14235],{"data":14236,"marks":14237,"value":10803,"nodeType":867},{},[14238],{"type":1040},{"data":14240,"marks":14241,"value":4006,"nodeType":867},{},[],{"data":14243,"content":14244,"nodeType":876},{"uri":10809},[14245],{"data":14246,"marks":14247,"value":10815,"nodeType":867},{},[14248],{"type":1040},{"data":14250,"marks":14251,"value":10819,"nodeType":867},{},[],{"data":14253,"content":14254,"nodeType":876},{"uri":1629},[14255],{"data":14256,"marks":14257,"value":10826,"nodeType":867},{},[14258],{"type":1040},{"data":14260,"marks":14261,"value":1947,"nodeType":867},{},[],"ConsentFix v3: Analyzing a new criminal toolkit","Investigating a new criminal toolkit for ConsentFix being promoted on criminal forums. ","consentfix-v3-analyzing-a-new-toolkit",{"items":14266},[14267,14269],{"sys":14268,"name":2547},{"id":2546},{"sys":14270,"name":342},{"id":2550},{"items":14272},[14273],{"fullName":849,"firstName":850,"jobTitle":851,"profilePicture":14274},{"url":855},{"__typename":1742,"sys":14276,"content":14278,"title":15224,"synopsis":15225,"hashTags":59,"publishedDate":15226,"slug":15227,"tagsCollection":15228,"authorsCollection":15234},{"id":14277},"2sFCww9xnI8okIxhtOaiY1",{"json":14279},{"data":14280,"content":14281,"nodeType":1640},{},[14282,14289,14296,14303,14306,14314,14321,14328,14334,14341,14347,14366,14373,14385,14388,14396,14403,14419,14426,14438,14444,14447,14455,14463,14469,14478,14498,14507,14514,14523,14542,14551,14558,14567,14599,14608,14615,14624,14642,14648,14657,14664,14673,14714,14717,14725,14734,14754,14763,14770,14779,14812,14818,14827,14834,14840,14843,14850,14859,14866,14925,14931,14934,14941,14950,14957,14963,14966,14974,14981,14988,15058,15065,15128,15135,15138,15146,15153,15160,15166,15169,15176,15183,15190,15197],{"data":14283,"content":14284,"nodeType":881},{},[14285],{"data":14286,"marks":14287,"value":14288,"nodeType":867},{},[],"The biggest cybersecurity story this year (so far) has been the emergence of “Scattered Lapsus$ Hunters” and their record-breaking worldwide hacking spree. ",{"data":14290,"content":14291,"nodeType":881},{},[14292],{"data":14293,"marks":14294,"value":14295,"nodeType":867},{},[],"Scattered Lapsus$ Hunters is part of “The Com”, the name for the broad community of English-speaking cybercriminals with international criminal connections — including with nation-state sponsored groups. They are also known to collaborate with a range of cybercrime “as-a-Service” organizations for phishing, initial access, ransomware, and more. ",{"data":14297,"content":14298,"nodeType":881},{},[14299],{"data":14300,"marks":14301,"value":14302,"nodeType":867},{},[],"It’s difficult to pin down exactly who the individuals are that make up this criminal collective. But what is known is their MO — making money through extortion by means of account takeover, mass data theft, and ransomware deployment. ",{"data":14304,"content":14305,"nodeType":908},{},[],{"data":14307,"content":14308,"nodeType":918},{},[14309],{"data":14310,"marks":14311,"value":14313,"nodeType":867},{},[14312],{"type":916},"How did we get here? ",{"data":14315,"content":14316,"nodeType":881},{},[14317],{"data":14318,"marks":14319,"value":14320,"nodeType":867},{},[],"Earlier this year, the threat group known to most analysts as Scattered Spider (also tracked as 0ktapus, Octo Tempest, Scatter Swine, Muddled Libra, and UNC3944) re-emerged after a series of arrests in late 2024. ",{"data":14322,"content":14323,"nodeType":881},{},[14324],{"data":14325,"marks":14326,"value":14327,"nodeType":867},{},[],"This group has been active in peaks and troughs over the years, but are mainly known for high-profile ransomware attacks on Caesars and MGM Resorts in 2024. ",{"data":14329,"content":14333,"nodeType":890},{"target":14330},{"sys":14331},{"id":14332,"type":887,"linkType":888},"1Vt269d7n6IGMzOrJs1FDx",[],{"data":14335,"content":14336,"nodeType":881},{},[14337],{"data":14338,"marks":14339,"value":14340,"nodeType":867},{},[],"Scattered Spider hit the headlines again in April 2025 with attacks on UK retailers Marks & Spencer and Co-op, which resulted in significant, prolonged disruption, and a serious downstream impact on the retail supply chain. ",{"data":14342,"content":14346,"nodeType":890},{"target":14343},{"sys":14344},{"id":14345,"type":887,"linkType":888},"3kvcGV2zZZUPnM8IK04Y1O",[],{"data":14348,"content":14349,"nodeType":881},{},[14350,14354,14362],{"data":14351,"marks":14352,"value":14353,"nodeType":867},{},[],"It didn’t stop there, though. What followed was a wide-scale campaign targeting Salesforce customers, with the attackers claiming to have stolen ",{"data":14355,"content":14356,"nodeType":876},{"uri":5752},[14357],{"data":14358,"marks":14359,"value":14361,"nodeType":867},{},[14360],{"type":1040},"over 1.5 billion records from 1000+ companies",{"data":14363,"marks":14364,"value":14365,"nodeType":867},{},[]," across multiple verticals, including heavyweights like Google, Cloudflare, Workday, Adidas, FedEx, Disney, LVMH, and many more.",{"data":14367,"content":14368,"nodeType":881},{},[14369],{"data":14370,"marks":14371,"value":14372,"nodeType":867},{},[],"Around this time, the attackers began to refer to themselves as part of a wider collective, assuming the moniker “Scattered Lapsus$ Hunters” (a mash-up of names given by analysts and self-adopted by attackers — Scattered Spider, ShinyHunters, and Lapsus$).",{"data":14374,"content":14375,"nodeType":881},{},[14376,14380],{"data":14377,"marks":14378,"value":14379,"nodeType":867},{},[],"The most significant breach this year to-date impacted Jaguar Land Rover. A ransomware attack resulted in months of disruption that directly impacted the UK’s GDP, with the government underwriting a $1.5B loan to alleviate the supply chain impact. ",{"data":14381,"marks":14382,"value":14384,"nodeType":867},{},[14383],{"type":916},"In fact, this was the most economically consequential cyber attack yet recorded in a G7 economy. ",{"data":14386,"content":14387,"nodeType":908},{},[],{"data":14389,"content":14390,"nodeType":918},{},[14391],{"data":14392,"marks":14393,"value":14395,"nodeType":867},{},[14394],{"type":916},"2025 wasn’t a one-off",{"data":14397,"content":14398,"nodeType":881},{},[14399],{"data":14400,"marks":14401,"value":14402,"nodeType":867},{},[],"The developments through 2025 have presented a stronger picture than ever before that cybercriminal operations are heavily interlinked. Groups overlap considerably, and individuals freely move between different cells. ",{"data":14404,"content":14405,"nodeType":881},{},[14406,14410,14415],{"data":14407,"marks":14408,"value":14409,"nodeType":867},{},[],"When we scratch beneath the surface, this is evident in the tactics, techniques and procedures (TTPs) used by these attackers — even stretching as far back as 2021 with the initial rise of Lapsus$. This is not an accident. ",{"data":14411,"marks":14412,"value":14414,"nodeType":867},{},[14413],{"type":916},"The TTPs used show a conscious move by attackers to move away from environments that are well-protected by traditional security tools. ",{"data":14416,"marks":14417,"value":14418,"nodeType":867},{},[],"This means avoiding targeting endpoints with malware, and not relying on software-based exploits. Instead, these attackers look to take over apps and services directly over the internet. ",{"data":14420,"content":14421,"nodeType":881},{},[14422],{"data":14423,"marks":14424,"value":14425,"nodeType":867},{},[],"Most of the time, this is as simple as logging in to a SaaS app, or an enterprise SSO account (e.g. Microsoft, Okta, or Google) and dumping the data. For attackers that want to take it further, they can abuse the sprawl of interconnected apps that make up modern business IT, seeking out specific data or exploitable functionality. Or, they can leverage internet-accessible management portals to chart a path back to your on-premise assets, giving them everything they need to pivot toward more conventional methods such as ransomware deployment. ",{"data":14427,"content":14428,"nodeType":881},{},[14429,14433],{"data":14430,"marks":14431,"value":14432,"nodeType":867},{},[],"When we look at historical breaches, the pattern is clear. ",{"data":14434,"marks":14435,"value":14437,"nodeType":867},{},[14436],{"type":916},"Not one of the attacks attributed to Scattered Lapsus$ Hunters, or its predecessors, started with an endpoint or network attack — they all began with account takeover. ",{"data":14439,"content":14443,"nodeType":890},{"target":14440},{"sys":14441},{"id":14442,"type":887,"linkType":888},"6poP5VM2ARrEvwKEG42HgK",[],{"data":14445,"content":14446,"nodeType":908},{},[],{"data":14448,"content":14449,"nodeType":918},{},[14450],{"data":14451,"marks":14452,"value":14454,"nodeType":867},{},[14453],{"type":916},"TTP breakdown: Analyzing the top “Scattered Lapsus$ Hunters” breaches since 2021",{"data":14456,"content":14457,"nodeType":998},{},[14458],{"data":14459,"marks":14460,"value":14462,"nodeType":867},{},[14461],{"type":916},"Phishing and stolen credentials",{"data":14464,"content":14468,"nodeType":890},{"target":14465},{"sys":14466},{"id":14467,"type":887,"linkType":888},"4SNOanDIdGZsvRRnMYQVSo",[],{"data":14470,"content":14471,"nodeType":881},{},[14472],{"data":14473,"marks":14474,"value":14477,"nodeType":867},{},[14475,14476],{"type":916},{"type":1040},"EA Games (2021)",{"data":14479,"content":14480,"nodeType":881},{},[14481,14485,14494],{"data":14482,"marks":14483,"value":14484,"nodeType":867},{},[],"Attackers used stolen session cookies to log into EA’s Slack instance, purchased on a criminal forum. Combined with ",{"data":14486,"content":14488,"nodeType":876},{"uri":14487},"https://pushsecurity.com/blog/phishing-slack-persistence/",[14489],{"data":14490,"marks":14491,"value":14493,"nodeType":867},{},[14492],{"type":1040},"social engineering via Slack",{"data":14495,"marks":14496,"value":14497,"nodeType":867},{},[],", this was used to steal 750GB of data, including video game source code. ",{"data":14499,"content":14500,"nodeType":881},{},[14501],{"data":14502,"marks":14503,"value":14506,"nodeType":867},{},[14504,14505],{"type":916},{"type":1040},"Nvidia (2022)",{"data":14508,"content":14509,"nodeType":881},{},[14510],{"data":14511,"marks":14512,"value":14513,"nodeType":867},{},[],"Attackers used stolen credentials to steal 1TB of data from Nvidia’s internal shares, including a significant amount of sensitive information about the designs of Nvidia graphics cards, source code, and the usernames and passwords of more than 71,000 Nvidia employees.",{"data":14515,"content":14516,"nodeType":881},{},[14517],{"data":14518,"marks":14519,"value":14522,"nodeType":867},{},[14520,14521],{"type":916},{"type":1040},"Microsoft (2022)",{"data":14524,"content":14525,"nodeType":881},{},[14526,14530,14538],{"data":14527,"marks":14528,"value":14529,"nodeType":867},{},[],"Attackers used stolen credentials combined with SIM swapping and ",{"data":14531,"content":14533,"nodeType":876},{"uri":14532},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/mfa_fatigue/description.md",[14534],{"data":14535,"marks":14536,"value":14537,"nodeType":867},{},[],"MFA fatigue",{"data":14539,"marks":14540,"value":14541,"nodeType":867},{},[]," attacks to steal Azure DevOps source code — leaked a 9GB archive of Microsoft source code – including ~90% of Bing and 45% of Cortana code. ",{"data":14543,"content":14544,"nodeType":881},{},[14545],{"data":14546,"marks":14547,"value":14550,"nodeType":867},{},[14548,14549],{"type":916},{"type":1040},"T-Mobile (2022)",{"data":14552,"content":14553,"nodeType":881},{},[14554],{"data":14555,"marks":14556,"value":14557,"nodeType":867},{},[],"Attackers used stolen credentials to establish initial access, coupled with social engineering T-Mobile staff into approving the attacker’s device for VPN access. This resulted in source code being stolen from over 30,000 repositories. ",{"data":14559,"content":14560,"nodeType":881},{},[14561],{"data":14562,"marks":14563,"value":14566,"nodeType":867},{},[14564,14565],{"type":916},{"type":1040},"Snowflake (165 customers) (2024)",{"data":14568,"content":14569,"nodeType":881},{},[14570,14574,14583,14587,14595],{"data":14571,"marks":14572,"value":14573,"nodeType":867},{},[],"Attackers targeted ",{"data":14575,"content":14577,"nodeType":876},{"uri":14576},"https://pushsecurity.com/blog/snowflake-retro/",[14578],{"data":14579,"marks":14580,"value":14582,"nodeType":867},{},[14581],{"type":1040},"165 Snowflake customers",{"data":14584,"marks":14585,"value":14586,"nodeType":867},{},[]," using stolen credentials from credential breaches dating back as far as 2020. Due to widespread MFA gaps and the presence of ",{"data":14588,"content":14590,"nodeType":876},{"uri":14589},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/ghost_logins/description.md",[14591],{"data":14592,"marks":14593,"value":6850,"nodeType":867},{},[14594],{"type":1040},{"data":14596,"marks":14597,"value":14598,"nodeType":867},{},[],", attackers were able to simply log in to individual customer tenants, dump the data, and use it to extort the companies. In total, 9 public victims were named following the breach, with over 1B breached customer records. ",{"data":14600,"content":14601,"nodeType":881},{},[14602],{"data":14603,"marks":14604,"value":14607,"nodeType":867},{},[14605,14606],{"type":916},{"type":1040},"PowerSchool (2024)",{"data":14609,"content":14610,"nodeType":881},{},[14611],{"data":14612,"marks":14613,"value":14614,"nodeType":867},{},[],"Attackers gained access to a community-focused customer support portal, PowerSource, using compromised credentials and stole data using an \"export data manager\" customer support tool, stealing the data of 62.4 million students and 9.5 million teachers. PowerSchool paid an undisclosed ransom fee, but hackers returned later to extort schools and individuals separately anyway.",{"data":14616,"content":14617,"nodeType":881},{},[14618],{"data":14619,"marks":14620,"value":14623,"nodeType":867},{},[14621,14622],{"type":916},{"type":1040},"Red Hat (2025)",{"data":14625,"content":14626,"nodeType":881},{},[14627,14631,14638],{"data":14628,"marks":14629,"value":14630,"nodeType":867},{},[],"Attackers breached Red Hat’s GitLab instance via a compromised account — the result of ",{"data":14632,"content":14633,"nodeType":876},{"uri":14589},[14634],{"data":14635,"marks":14636,"value":6850,"nodeType":867},{},[14637],{"type":1040},{"data":14639,"marks":14640,"value":14641,"nodeType":867},{},[]," providing a backdoor to access an otherwise secure, SSO-connected account. Stolen data included approximately 800 Customer Engagement Reports (CERs), authentication tokens, full database URIs, and other private information in Red Hat code and CERs, which they claimed to use to gain access to downstream customer infrastructure. ",{"data":14643,"content":14647,"nodeType":890},{"target":14644},{"sys":14645},{"id":14646,"type":887,"linkType":888},"G1V7d5Dvevmr9p0YXElPX",[],{"data":14649,"content":14650,"nodeType":881},{},[14651],{"data":14652,"marks":14653,"value":14656,"nodeType":867},{},[14654,14655],{"type":916},{"type":1040},"Discord (2025)",{"data":14658,"content":14659,"nodeType":881},{},[14660],{"data":14661,"marks":14662,"value":14663,"nodeType":867},{},[],"Attackers compromised a Zendesk customer support account, stealing 1.6TB of data. The hackers say this consisted of roughly 8.4 million tickets affecting 5.5 million unique users, and that about 580,000 users contained payment information.",{"data":14665,"content":14666,"nodeType":881},{},[14667],{"data":14668,"marks":14669,"value":14672,"nodeType":867},{},[14670,14671],{"type":916},{"type":1040},"SoundCloud, MatchGroup, Crunchbase, Betterment... (2026)",{"data":14674,"content":14675,"nodeType":881},{},[14676,14680,14688,14691,14699,14703,14710],{"data":14677,"marks":14678,"value":14679,"nodeType":867},{},[],"Scattered Lapsus$ Hunters have already claimed several public victims in 2026, with over 60 million breached records. ",{"data":14681,"content":14683,"nodeType":876},{"uri":14682},"https://www.bleepingcomputer.com/news/security/shinyhunters-claim-to-be-behind-sso-account-data-theft-attacks/",[14684],{"data":14685,"marks":14686,"value":14687,"nodeType":867},{},[],"SoundCloud, Betterment, Crunchbase",{"data":14689,"marks":14690,"value":2063,"nodeType":867},{},[],{"data":14692,"content":14694,"nodeType":876},{"uri":14693},"https://www.bleepingcomputer.com/news/security/match-group-breach-exposes-data-from-hinge-tinder-okcupid-and-match/",[14695],{"data":14696,"marks":14697,"value":14698,"nodeType":867},{},[],"MatchGroup",{"data":14700,"marks":14701,"value":14702,"nodeType":867},{},[]," have all reported breaches this month, powered by a brand ",{"data":14704,"content":14705,"nodeType":876},{"uri":3074},[14706],{"data":14707,"marks":14708,"value":14709,"nodeType":867},{},[],"new real-time-operated AiTM phishing kit",{"data":14711,"marks":14712,"value":14713,"nodeType":867},{},[]," targeting Okta, Entra, and Google SSO accounts. This is a developing situation, with more victims expected to be announced publicly soon.",{"data":14715,"content":14716,"nodeType":908},{},[],{"data":14718,"content":14719,"nodeType":998},{},[14720],{"data":14721,"marks":14722,"value":14724,"nodeType":867},{},[14723],{"type":916},"Vishing and help desk scams",{"data":14726,"content":14727,"nodeType":881},{},[14728],{"data":14729,"marks":14730,"value":14733,"nodeType":867},{},[14731,14732],{"type":916},{"type":1040},"MGM Resorts & Caesars (2023)",{"data":14735,"content":14736,"nodeType":881},{},[14737,14741,14750],{"data":14738,"marks":14739,"value":14740,"nodeType":867},{},[],"MGM Resorts and Caesars were hit with twin breaches in 2023. Attackers socially engineered help desk personnel to take over accounts with Super Administrator privileges within MGM Resorts’ Okta tenant, which they then used to register a second, attacker-controlled IdP via ",{"data":14742,"content":14744,"nodeType":876},{"uri":14743},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/inbound_federation/description.md",[14745],{"data":14746,"marks":14747,"value":14749,"nodeType":867},{},[14748],{"type":1040},"inbound federation",{"data":14751,"marks":14752,"value":14753,"nodeType":867},{},[]," — granting comprehensive access that was used to deploy ransomware. ",{"data":14755,"content":14756,"nodeType":881},{},[14757],{"data":14758,"marks":14759,"value":14762,"nodeType":867},{},[14760,14761],{"type":916},{"type":1040},"Transport for London (2024)",{"data":14764,"content":14765,"nodeType":881},{},[14766],{"data":14767,"marks":14768,"value":14769,"nodeType":867},{},[],"Attackers socially engineered the Transport for London help desk to gain privileged access to the IT environment, resulting in prolonged disruption to key online services underpinning London’s public transport network, theft of 5,000 users bank details, and all 30,000 staff members having to reset their online credentials in person.",{"data":14771,"content":14772,"nodeType":881},{},[14773],{"data":14774,"marks":14775,"value":14778,"nodeType":867},{},[14776,14777],{"type":916},{"type":1040},"Marks & Spencer (2025)",{"data":14780,"content":14781,"nodeType":881},{},[14782,14786,14795,14799,14808],{"data":14783,"marks":14784,"value":14785,"nodeType":867},{},[],"Attackers compromised a Microsoft Entra account belonging to a privileged user via a ",{"data":14787,"content":14789,"nodeType":876},{"uri":14788},"https://pushsecurity.com/blog/scattered-spider-defending-against-help-desk-scams/",[14790],{"data":14791,"marks":14792,"value":14794,"nodeType":867},{},[14793],{"type":1040},"help desk scam",{"data":14796,"marks":14797,"value":14798,"nodeType":867},{},[],", which enabled them to steal sensitive data from cloud environments, as well as pivot to deploy ransomware via the ",{"data":14800,"content":14802,"nodeType":876},{"uri":14801},"https://cloud.google.com/blog/topics/threat-intelligence/vsphere-active-directory-integration-risks",[14803],{"data":14804,"marks":14805,"value":14807,"nodeType":867},{},[14806],{"type":1040},"VMware admin console",{"data":14809,"marks":14810,"value":14811,"nodeType":867},{},[],". This enabled ransomware to be deployed at the hypervisor layer, evading host-based protections like EDR. ",{"data":14813,"content":14817,"nodeType":890},{"target":14814},{"sys":14815},{"id":14816,"type":887,"linkType":888},"7hBdHG74NaA3bQfOMpYA9o",[],{"data":14819,"content":14820,"nodeType":881},{},[14821],{"data":14822,"marks":14823,"value":14826,"nodeType":867},{},[14824,14825],{"type":916},{"type":1040},"Jaguar Land Rover (2025)",{"data":14828,"content":14829,"nodeType":881},{},[14830],{"data":14831,"marks":14832,"value":14833,"nodeType":867},{},[],"Attackers compromised highly privileged admin accounts via a help desk scam, which they leveraged to access and deploy ransomware to all aspects of Jaguar’s business, from CAD and engineering software, to payments tracking, to customer car delivery, using similar techniques to the Marks & Spencer breach. ",{"data":14835,"content":14839,"nodeType":890},{"target":14836},{"sys":14837},{"id":14838,"type":887,"linkType":888},"6s1X2fo4K9EeVLBmHm4YXb",[],{"data":14841,"content":14842,"nodeType":908},{},[],{"data":14844,"content":14845,"nodeType":998},{},[14846],{"data":14847,"marks":14848,"value":694,"nodeType":867},{},[14849],{"type":916},{"data":14851,"content":14852,"nodeType":881},{},[14853],{"data":14854,"marks":14855,"value":14858,"nodeType":867},{},[14856,14857],{"type":916},{"type":1040},"Salesforce & Salesloft (1000+ customers) (2025)",{"data":14860,"content":14861,"nodeType":881},{},[14862],{"data":14863,"marks":14864,"value":14865,"nodeType":867},{},[],"A vast campaign against Salesforce customers resulted in the compromise of 1000+ Salesforce tenants (according to the attacker) with more than 1.5 billion records stolen. This campaign can consisted of three phases:",{"data":14867,"content":14868,"nodeType":3126},{},[14869,14884,14899],{"data":14870,"content":14871,"nodeType":3061},{},[14872],{"data":14873,"content":14874,"nodeType":881},{},[14875,14880],{"data":14876,"marks":14877,"value":14879,"nodeType":867},{},[14878],{"type":916},"Phase 1:",{"data":14881,"marks":14882,"value":14883,"nodeType":867},{},[]," The attacker conducted a large-scale vishing campaign against Salesforce customers, calling up users and socially engineering them into connecting a malicious version of the “Data Loader” app into their tenant. This was in fact an attacker-controlled app that enabled data to be mass-exfiltrated via API. ",{"data":14885,"content":14886,"nodeType":3061},{},[14887],{"data":14888,"content":14889,"nodeType":881},{},[14890,14895],{"data":14891,"marks":14892,"value":14894,"nodeType":867},{},[14893],{"type":916},"Phase 2: ",{"data":14896,"marks":14897,"value":14898,"nodeType":867},{},[],"The attacker conducted a supply-chain compromise against customers of Salesloft. Users of Salesloft’s “Drift” integration were impacted by attackers stealing access tokens from Salesloft’s AWS environment. This integration allowed the attacker to steal data from customers that had deployed Drift to connected environments — namely, Salesforce, and Google Workspace. ",{"data":14900,"content":14901,"nodeType":3061},{},[14902],{"data":14903,"content":14904,"nodeType":881},{},[14905,14910,14914,14921],{"data":14906,"marks":14907,"value":14909,"nodeType":867},{},[14908],{"type":916},"Phase 3:",{"data":14911,"marks":14912,"value":14913,"nodeType":867},{},[]," The attacker then conducted a separate supply-chain compromise involving Gainsight (allegedly using OAuth tokens stolen in the Salesloft attack) which enabled them to ",{"data":14915,"content":14916,"nodeType":876},{"uri":10495},[14917],{"data":14918,"marks":14919,"value":14920,"nodeType":867},{},[],"breach a further 285 Salesforce instances",{"data":14922,"marks":14923,"value":14924,"nodeType":867},{},[]," using stolen OAuth tokens from Gainsight's integrations. ",{"data":14926,"content":14930,"nodeType":890},{"target":14927},{"sys":14928},{"id":14929,"type":887,"linkType":888},"3TwjpVKQ42SwQRhvGFbZdn",[],{"data":14932,"content":14933,"nodeType":908},{},[],{"data":14935,"content":14936,"nodeType":998},{},[14937],{"data":14938,"marks":14939,"value":699,"nodeType":867},{},[14940],{"type":916},{"data":14942,"content":14943,"nodeType":881},{},[14944],{"data":14945,"marks":14946,"value":14949,"nodeType":867},{},[14947,14948],{"type":916},{"type":1040},"CyberHaven (2024)",{"data":14951,"content":14952,"nodeType":881},{},[14953],{"data":14954,"marks":14955,"value":14956,"nodeType":867},{},[],"Hackers phished a CyberHaven extension developer and uploaded a malicious version of the CyberHaven extension to the Chrome Web Store, leading to customer data breaches where installed in user browsers, impacting CyberHaven’s estimated ~400 business customers. This was part of a broader campaign that targeted 35 Chrome extensions, collectively impacting over 2.5 million users.",{"data":14958,"content":14962,"nodeType":890},{"target":14959},{"sys":14960},{"id":14961,"type":887,"linkType":888},"4ErDI0xi0Vj2Zrk8Qsb2NB",[],{"data":14964,"content":14965,"nodeType":908},{},[],{"data":14967,"content":14968,"nodeType":918},{},[14969],{"data":14970,"marks":14971,"value":14973,"nodeType":867},{},[14972],{"type":916},"The bigger picture",{"data":14975,"content":14976,"nodeType":881},{},[14977],{"data":14978,"marks":14979,"value":14980,"nodeType":867},{},[],"Scattered Lapsus$ Hunters are dominating the headlines right now, but they aren’t the only attackers using these modern techniques and consciously evading established security controls. ",{"data":14982,"content":14983,"nodeType":881},{},[14984],{"data":14985,"marks":14986,"value":14987,"nodeType":867},{},[],"Threat reports agree that attackers are steering away from traditional exploit and malware-driven breaches towards identities:",{"data":14989,"content":14990,"nodeType":3126},{},[14991,15014,15036],{"data":14992,"content":14993,"nodeType":3061},{},[14994],{"data":14995,"content":14996,"nodeType":881},{},[14997,15001,15010],{"data":14998,"marks":14999,"value":15000,"nodeType":867},{},[],"Identity-based attacks surged 32% in the last year, while 97% of identity attacks are password-based, driven by credential leaks and infostealer malware. (",{"data":15002,"content":15004,"nodeType":876},{"uri":15003},"https://cdn-dynmedia-1.microsoft.com/is/content/microsoftcorp/microsoft/msc/documents/presentations/CSR/Microsoft-Digital-Defense-Report-2025.pdf#page=1",[15005],{"data":15006,"marks":15007,"value":15009,"nodeType":867},{},[15008],{"type":1040},"Microsoft",{"data":15011,"marks":15012,"value":15013,"nodeType":867},{},[],")",{"data":15015,"content":15016,"nodeType":3061},{},[15017],{"data":15018,"content":15019,"nodeType":881},{},[15020,15024,15033],{"data":15021,"marks":15022,"value":15023,"nodeType":867},{},[],"79% of detections were malware-free in the last year, up from 40% in 2019. (",{"data":15025,"content":15027,"nodeType":876},{"uri":15026},"https://www.crowdstrike.com/en-gb/global-threat-report/",[15028],{"data":15029,"marks":15030,"value":15032,"nodeType":867},{},[15031],{"type":1040},"CrowdStrike",{"data":15034,"marks":15035,"value":15013,"nodeType":867},{},[],{"data":15037,"content":15038,"nodeType":3061},{},[15039],{"data":15040,"content":15041,"nodeType":881},{},[15042,15046,15055],{"data":15043,"marks":15044,"value":15045,"nodeType":867},{},[],"Credential abuse and phishing combined accounted for 38% of breaches, making identity the primary breach vector observed. (",{"data":15047,"content":15049,"nodeType":876},{"uri":15048},"https://www.verizon.com/business/resources/reports/dbir/",[15050],{"data":15051,"marks":15052,"value":15054,"nodeType":867},{},[15053],{"type":1040},"Verizon",{"data":15056,"marks":15057,"value":15013,"nodeType":867},{},[],{"data":15059,"content":15060,"nodeType":881},{},[15061],{"data":15062,"marks":15063,"value":15064,"nodeType":867},{},[],"And other public breaches from this year alone demonstrate similar TTPs from outside of the Scattered Lapsus$ Hunters orbit:",{"data":15066,"content":15067,"nodeType":3126},{},[15068,15083,15098,15113],{"data":15069,"content":15070,"nodeType":3061},{},[15071],{"data":15072,"content":15073,"nodeType":881},{},[15074,15079],{"data":15075,"marks":15076,"value":15078,"nodeType":867},{},[15077],{"type":916},"Nikkei",{"data":15080,"marks":15081,"value":15082,"nodeType":867},{},[],": Japanese publishing giant Nikkei’s Slack messaging platform was compromised using stolen credentials, leaking the names, email addresses, and chat histories for 17,368 individuals registered on Slack.",{"data":15084,"content":15085,"nodeType":3061},{},[15086],{"data":15087,"content":15088,"nodeType":881},{},[15089,15094],{"data":15090,"marks":15091,"value":15093,"nodeType":867},{},[15092],{"type":916},"Evertec",{"data":15095,"marks":15096,"value":15097,"nodeType":867},{},[],": Hackers tried to steal $130 million from Evertec’s Brazilian subsidiary Sinqia S.A.after gaining unauthorized access to its environment on the central bank’s real-time payment system (Pix) using stolen credentials.",{"data":15099,"content":15100,"nodeType":3061},{},[15101],{"data":15102,"content":15103,"nodeType":881},{},[15104,15109],{"data":15105,"marks":15106,"value":15108,"nodeType":867},{},[15107],{"type":916},"Hy-Vee:",{"data":15110,"marks":15111,"value":15112,"nodeType":867},{},[]," Was hit with a data breach after hackers logged in with stolen credentials, exposing 53GB of sensitive data.",{"data":15114,"content":15115,"nodeType":3061},{},[15116],{"data":15117,"content":15118,"nodeType":881},{},[15119,15124],{"data":15120,"marks":15121,"value":15123,"nodeType":867},{},[15122],{"type":916},"Scania: ",{"data":15125,"marks":15126,"value":15127,"nodeType":867},{},[],"Automotive giant Scania confirmed it suffered a cybersecurity incident where threat actors used compromised credentials to breach its Financial Services systems and steal insurance claim documents.",{"data":15129,"content":15130,"nodeType":881},{},[15131],{"data":15132,"marks":15133,"value":15134,"nodeType":867},{},[],"Scattered Lapsus$ Hunters may be grabbing the headlines — but this a huge movement in a vast and flexible community of attackers. And criminals around the world are learning from their success. ",{"data":15136,"content":15137,"nodeType":908},{},[],{"data":15139,"content":15140,"nodeType":918},{},[15141],{"data":15142,"marks":15143,"value":15145,"nodeType":867},{},[15144],{"type":916},"Lessons learned",{"data":15147,"content":15148,"nodeType":881},{},[15149],{"data":15150,"marks":15151,"value":15152,"nodeType":867},{},[],"The common thread with all of these attacks is that they are evading established security controls by targeting applications directly, over the internet, via account takeover.",{"data":15154,"content":15155,"nodeType":881},{},[15156],{"data":15157,"marks":15158,"value":15159,"nodeType":867},{},[],"Clearly, the success of these attacks shows the limitations of multiple control layers. Endpoint and network layer controls have no visibility of this attack surface. Identity-focused controls are being undermined by ghost logins and shadow IT. And the limitations of cloud security controls in their ability to encompass all apps, and detect and stop malicious actions in real-time (that often blend in seamlessly with normal user activity). ",{"data":15161,"content":15165,"nodeType":890},{"target":15162},{"sys":15163},{"id":15164,"type":887,"linkType":888},"4Dg3fZEGf7ShyQJ8jlNDME",[],{"data":15167,"content":15168,"nodeType":908},{},[],{"data":15170,"content":15171,"nodeType":918},{},[15172],{"data":15173,"marks":15174,"value":6214,"nodeType":867},{},[15175],{"type":916},{"data":15177,"content":15178,"nodeType":881},{},[15179],{"data":15180,"marks":15181,"value":15182,"nodeType":867},{},[],"Stopping attacks that are designed to evade established controls is in our DNA — it’s the reason Push was founded. ",{"data":15184,"content":15185,"nodeType":881},{},[15186],{"data":15187,"marks":15188,"value":15189,"nodeType":867},{},[],"The browser is the gateway to to the apps and identities that attackers are now targeting, with many attacks taking place inside the user’s browser — whether that’s entering credentials onto a phishing page, approving a malicious OAuth grant, installing a risky browser extension, or insecurely accessing an app with a weak password and no MFA. ",{"data":15191,"content":15192,"nodeType":881},{},[15193],{"data":15194,"marks":15195,"value":15196,"nodeType":867},{},[],"Push’s browser-based security platform provides comprehensive detection and response capabilities against attacks like AiTM phishing, credential stuffing, malicious browser extensions, malicious OAuth grants, ClickFix, and session hijacking. You don’t need to wait until it all goes wrong either — you can use Push to proactively find and fix vulnerabilities across the apps that your employees use, like ghost logins, SSO coverage gaps, MFA gaps, vulnerable passwords, and more to harden your attack surface.",{"data":15198,"content":15199,"nodeType":881},{},[15200,15203,15210,15214,15221],{"data":15201,"marks":15202,"value":10795,"nodeType":867},{},[],{"data":15204,"content":15205,"nodeType":876},{"uri":10798},[15206],{"data":15207,"marks":15208,"value":10803,"nodeType":867},{},[15209],{"type":1040},{"data":15211,"marks":15212,"value":15213,"nodeType":867},{},[]," or ",{"data":15215,"content":15216,"nodeType":876},{"uri":1629},[15217],{"data":15218,"marks":15219,"value":10826,"nodeType":867},{},[15220],{"type":1040},{"data":15222,"marks":15223,"value":1947,"nodeType":867},{},[],"\"Scattered Lapsus$ Hunters\" — how modern attackers exploit the gaps in your security stack ","How Scattered Lapsus$ Hunters breaches demonstrate the evolution of attacker TTPs, shaping the future of cyber attacks.","2025-11-13T00:00:00.000Z","scattered-lapsus-hunters",{"items":15229},[15230,15232],{"sys":15231,"name":2547},{"id":2546},{"sys":15233,"name":342},{"id":2550},{"items":15235},[15236],{"fullName":849,"firstName":850,"jobTitle":851,"profilePicture":15237},{"url":855},{"__typename":1742,"sys":15239,"content":15241,"title":15867,"synopsis":15868,"hashTags":59,"publishedDate":15869,"slug":15870,"tagsCollection":15871,"authorsCollection":15877},{"id":15240},"3ExexM6DB2QBOQrtbMrXnN",{"json":15242},{"data":15243,"content":15244,"nodeType":1640},{},[15245,15251,15283,15376,15453,15460,15463,15470,15477,15484,15500,15507,15514,15517,15524,15531,15538,15571,15578,15601,15608,15611,15618,15625,15644,15731,15738,15744,15747,15754,15761,15768,15774,15795,15801,15808,15811,15818,15838,15855,15861],{"data":15246,"content":15250,"nodeType":890},{"target":15247},{"sys":15248},{"id":15249,"type":887,"linkType":888},"6BjaSruVecmhn1NoHreRni",[],{"data":15252,"content":15253,"nodeType":881},{},[15254,15258,15267,15270,15279],{"data":15255,"marks":15256,"value":15257,"nodeType":867},{},[],"Scattered Spider have been busy. Major breaches of UK retailers ",{"data":15259,"content":15261,"nodeType":876},{"uri":15260},"https://www.bleepingcomputer.com/news/security/mands-says-customer-data-stolen-in-cyberattack-forces-password-resets/",[15262],{"data":15263,"marks":15264,"value":15266,"nodeType":867},{},[15265],{"type":1040},"Marks and Spencer",{"data":15268,"marks":15269,"value":2063,"nodeType":867},{},[],{"data":15271,"content":15273,"nodeType":876},{"uri":15272},"https://www.bleepingcomputer.com/news/security/co-op-confirms-data-theft-after-dragonforce-ransomware-claims-attack/",[15274],{"data":15275,"marks":15276,"value":15278,"nodeType":867},{},[15277],{"type":1040},"Co-op",{"data":15280,"marks":15281,"value":15282,"nodeType":867},{},[]," resulted in the loss of sensitive data and prolonged disruption to in-store and digital services, with M&S feeling the pain of £300m in lost profits and a share value hit approaching £1b, and a multimillion-pound class action lawsuit and possible ICO fines looming.",{"data":15284,"content":15285,"nodeType":881},{},[15286,15290,15299,15302,15311,15314,15323,15326,15335,15338,15347,15350,15359,15363,15372],{"data":15287,"marks":15288,"value":15289,"nodeType":867},{},[],"A series of attacks against retailers worldwide soon followed, at an unprecedented rate. ",{"data":15291,"content":15293,"nodeType":876},{"uri":15292},"https://www.bleepingcomputer.com/news/security/fashion-giant-dior-discloses-cyberattack-warns-of-data-breach/",[15294],{"data":15295,"marks":15296,"value":15298,"nodeType":867},{},[15297],{"type":1040},"Dior",{"data":15300,"marks":15301,"value":4006,"nodeType":867},{},[],{"data":15303,"content":15305,"nodeType":876},{"uri":15304},"https://www.bleepingcomputer.com/news/security/the-north-face-warns-customers-of-april-credential-stuffing-attack/",[15306],{"data":15307,"marks":15308,"value":15310,"nodeType":867},{},[15309],{"type":1040},"The North Face",{"data":15312,"marks":15313,"value":4006,"nodeType":867},{},[],{"data":15315,"content":15317,"nodeType":876},{"uri":15316},"https://www.bleepingcomputer.com/news/security/cartier-discloses-data-breach-amid-fashion-brand-cyberattacks/",[15318],{"data":15319,"marks":15320,"value":15322,"nodeType":867},{},[15321],{"type":1040},"Cartier",{"data":15324,"marks":15325,"value":4006,"nodeType":867},{},[],{"data":15327,"content":15329,"nodeType":876},{"uri":15328},"https://www.bleepingcomputer.com/news/security/victorias-secret-delays-earnings-release-after-security-incident/",[15330],{"data":15331,"marks":15332,"value":15334,"nodeType":867},{},[15333],{"type":1040},"Victoria’s Secret",{"data":15336,"marks":15337,"value":4006,"nodeType":867},{},[],{"data":15339,"content":15341,"nodeType":876},{"uri":15340},"https://www.bleepingcomputer.com/news/security/adidas-warns-of-data-breach-after-customer-service-provider-hack/",[15342],{"data":15343,"marks":15344,"value":15346,"nodeType":867},{},[15345],{"type":1040},"Adidas",{"data":15348,"marks":15349,"value":4006,"nodeType":867},{},[],{"data":15351,"content":15353,"nodeType":876},{"uri":15352},"https://www.scworld.com/brief/separate-ransomware-attacks-purportedly-hit-coca-cola-bottling-partner",[15354],{"data":15355,"marks":15356,"value":15358,"nodeType":867},{},[15357],{"type":1040},"Coca-Cola",{"data":15360,"marks":15361,"value":15362,"nodeType":867},{},[],", and ",{"data":15364,"content":15366,"nodeType":876},{"uri":15365},"https://www.bleepingcomputer.com/news/security/grocery-wholesale-giant-united-natural-foods-hit-by-cyberattack/",[15367],{"data":15368,"marks":15369,"value":15371,"nodeType":867},{},[15370],{"type":1040},"United Natural Foods",{"data":15373,"marks":15374,"value":15375,"nodeType":867},{},[]," were among the retailers to suffer a breach between May-June 2025. ",{"data":15377,"content":15378,"nodeType":881},{},[15379,15383,15392,15395,15404,15408,15417,15421,15429,15432,15440,15443,15450],{"data":15380,"marks":15381,"value":15382,"nodeType":867},{},[],"The latest news links the hackers to attacks on ",{"data":15384,"content":15386,"nodeType":876},{"uri":15385},"https://www.bleepingcomputer.com/news/security/aflac-discloses-breach-amidst-scattered-spider-insurance-attacks/",[15387],{"data":15388,"marks":15389,"value":15391,"nodeType":867},{},[15390],{"type":1040},"Aflac",{"data":15393,"marks":15394,"value":4006,"nodeType":867},{},[],{"data":15396,"content":15398,"nodeType":876},{"uri":15397},"https://www.bleepingcomputer.com/news/security/google-warns-scattered-spider-hackers-now-target-us-insurance-companies/",[15399],{"data":15400,"marks":15401,"value":15403,"nodeType":867},{},[15402],{"type":1040},"Philadelphia Insurance Companies",{"data":15405,"marks":15406,"value":15407,"nodeType":867},{},[],",  ",{"data":15409,"content":15411,"nodeType":876},{"uri":15410},"https://www.bleepingcomputer.com/news/security/erie-insurance-confirms-cyberattack-behind-business-disruptions/amp/",[15412],{"data":15413,"marks":15414,"value":15416,"nodeType":867},{},[15415],{"type":1040},"Erie Insurance",{"data":15418,"marks":15419,"value":15420,"nodeType":867},{},[],", and most recently ",{"data":15422,"content":15424,"nodeType":876},{"uri":15423},"https://www.bleepingcomputer.com/news/security/qantas-is-being-extorted-in-recent-data-theft-cyberattack/",[15425],{"data":15426,"marks":15427,"value":15428,"nodeType":867},{},[],"Qantas",{"data":15430,"marks":15431,"value":4006,"nodeType":867},{},[],{"data":15433,"content":15435,"nodeType":876},{"uri":15434},"https://www.bleepingcomputer.com/news/security/scattered-spider-hackers-shift-focus-to-aviation-transportation-firms/",[15436],{"data":15437,"marks":15438,"value":15439,"nodeType":867},{},[],"Hawaiian Airlines",{"data":15441,"marks":15442,"value":2063,"nodeType":867},{},[],{"data":15444,"content":15445,"nodeType":876},{"uri":15434},[15446],{"data":15447,"marks":15448,"value":15449,"nodeType":867},{},[],"WestJet",{"data":15451,"marks":15452,"value":1253,"nodeType":867},{},[],{"data":15454,"content":15455,"nodeType":881},{},[15456],{"data":15457,"marks":15458,"value":15459,"nodeType":867},{},[],"The top story from recent campaigns is the use of help desk scams. This typically involves the attacker calling up a company’s help desk with some level of information — at minimum, PII that allows them to impersonate their victim, and sometimes a password, leaning heavily on their native English-speaking abilities to trick the help desk operator into giving them access to a user account. ",{"data":15461,"content":15462,"nodeType":908},{},[],{"data":15464,"content":15465,"nodeType":918},{},[15466],{"data":15467,"marks":15468,"value":15469,"nodeType":867},{},[],"Help desk scams 101",{"data":15471,"content":15472,"nodeType":881},{},[15473],{"data":15474,"marks":15475,"value":15476,"nodeType":867},{},[],"The goal of a help desk scam is to get the help desk operator to reset the credentials and/or MFA used to access an account so the attacker can take control of it. They’ll use a variety of backstories and tactics to get that done, but most of the time it’s as simple as saying “I’ve got a new phone, can you remove my existing MFA and allow me to enroll a new one?”",{"data":15478,"content":15479,"nodeType":881},{},[15480],{"data":15481,"marks":15482,"value":15483,"nodeType":867},{},[],"From there, the attacker is then sent an MFA reset link via email or SMS. Usually, this would be sent to, for example, a number on file — but at this point, the attacker has already established trust and bypassed the help desk process to a degree. So asking “can you send it to this email address” or “I’ve actually got a new number too, can you send it to…” gets this sent directly to the attacker. ",{"data":15485,"content":15486,"nodeType":881},{},[15487,15491,15496],{"data":15488,"marks":15489,"value":15490,"nodeType":867},{},[],"At this point, it’s simply a case of using the self service password reset functionality for Okta or Entra (which you can get around because you now have the MFA factor to verify yourself) and ",{"data":15492,"marks":15493,"value":15495,"nodeType":867},{},[15494],{"type":1431},"voila",{"data":15497,"marks":15498,"value":15499,"nodeType":867},{},[],", the attacker has taken control of the account. ",{"data":15501,"content":15502,"nodeType":881},{},[15503],{"data":15504,"marks":15505,"value":15506,"nodeType":867},{},[],"And the best part? Most help desks have the same process for every account — it doesn’t matter who you’re impersonating or which account you’re trying to reset. So, attackers are specifically targeting accounts likely to have top tier admin privileges — meaning once they get in, progressing the attack is trivial and much of the typical privilege escalation and lateral movement is removed from the attack path. ",{"data":15508,"content":15509,"nodeType":881},{},[15510],{"data":15511,"marks":15512,"value":15513,"nodeType":867},{},[],"So, help desk scams have proved to be a reliable way of bypassing MFA and achieving account takeover — the foothold from which to launch the rest of an attack, such as stealing data, deploying ransomware, etc. ",{"data":15515,"content":15516,"nodeType":908},{},[],{"data":15518,"content":15519,"nodeType":918},{},[15520],{"data":15521,"marks":15522,"value":15523,"nodeType":867},{},[],"Avoiding help desk gotchas",{"data":15525,"content":15526,"nodeType":881},{},[15527],{"data":15528,"marks":15529,"value":15530,"nodeType":867},{},[],"There’s lots of advice for securing help desks being circulated, but much of the advice still results in a process that is either phishable or difficult to implement. ",{"data":15532,"content":15533,"nodeType":881},{},[15534],{"data":15535,"marks":15536,"value":15537,"nodeType":867},{},[],"Ultimately, organizations need to be prepared to introduce friction to their help desk process and either delay or deny requests in situations where there’s significant risk. So, for example, having a process for MFA reset that recognizes the risk associated with resetting a high-privileged account:",{"data":15539,"content":15540,"nodeType":3126},{},[15541,15551,15561],{"data":15542,"content":15543,"nodeType":3061},{},[15544],{"data":15545,"content":15546,"nodeType":881},{},[15547],{"data":15548,"marks":15549,"value":15550,"nodeType":867},{},[],"Require multi-party approval / escalation for admin-level account resets",{"data":15552,"content":15553,"nodeType":3061},{},[15554],{"data":15555,"content":15556,"nodeType":881},{},[15557],{"data":15558,"marks":15559,"value":15560,"nodeType":867},{},[],"Require in-person verification if the process can’t be followed remotely",{"data":15562,"content":15563,"nodeType":3061},{},[15564],{"data":15565,"content":15566,"nodeType":881},{},[15567],{"data":15568,"marks":15569,"value":15570,"nodeType":867},{},[],"Freeze self-service resets when suspicious behavior is encountered (this would require some kind of internal process and awareness training to raise the alarm if an attack is suspected)",{"data":15572,"content":15573,"nodeType":881},{},[15574],{"data":15575,"marks":15576,"value":15577,"nodeType":867},{},[],"And watch out for these gotchas: ",{"data":15579,"content":15580,"nodeType":3126},{},[15581,15591],{"data":15582,"content":15583,"nodeType":3061},{},[15584],{"data":15585,"content":15586,"nodeType":881},{},[15587],{"data":15588,"marks":15589,"value":15590,"nodeType":867},{},[],"If you receive a call, good practice is to terminate the call and dial the number on file for the employee. But, in a world of SIM swapping, this isn’t a foolproof solution — you could just be re-dialing the attacker. ",{"data":15592,"content":15593,"nodeType":3061},{},[15594],{"data":15595,"content":15596,"nodeType":881},{},[15597],{"data":15598,"marks":15599,"value":15600,"nodeType":867},{},[],"If your solution is to get the employee on camera, increasingly sophisticated deepfakes can thwart this approach.  ",{"data":15602,"content":15603,"nodeType":881},{},[15604],{"data":15605,"marks":15606,"value":15607,"nodeType":867},{},[],"But, help desks are a target for a reason. They’re “helpful” by nature. This is usually reflected in how they’re operated and performance measured — delays won’t help you to hit those SLAs! Ultimately, a process only works if employees are willing to adhere to it — and can’t be socially engineered to break it. Help desks that are removed from day-to-day operations (especially when outsourced or offshored) are also inherently susceptible to attacks where employees are impersonated. ",{"data":15609,"content":15610,"nodeType":908},{},[],{"data":15612,"content":15613,"nodeType":918},{},[15614],{"data":15615,"marks":15616,"value":15617,"nodeType":867},{},[],"Comparing help desk scams with other approaches",{"data":15619,"content":15620,"nodeType":881},{},[15621],{"data":15622,"marks":15623,"value":15624,"nodeType":867},{},[],"Taking a step back, it’s worth thinking about how help desk scams fit into the wider toolkit of tactics, techniques and procedures (TTPs) used by threat actors like Scattered Spider. ",{"data":15626,"content":15627,"nodeType":881},{},[15628,15631,15640],{"data":15629,"marks":15630,"value":21,"nodeType":867},{},[],{"data":15632,"content":15634,"nodeType":876},{"uri":15633},"https://pushsecurity.com/blog/scattered-spider-ttp-evolution-in-2025/",[15635],{"data":15636,"marks":15637,"value":15639,"nodeType":867},{},[15638],{"type":1040},"Scattered Spider has heavily relied on identity-based TTPs since they first emerged in 2022",{"data":15641,"marks":15642,"value":15643,"nodeType":867},{},[],", following a repeatable path of bypassing MFA, achieving account takeover on privileged accounts, stealing data from cloud services, and deploying ransomware (principally to VMware environments). ",{"data":15645,"content":15646,"nodeType":3126},{},[15647,15657,15667,15688,15698,15708],{"data":15648,"content":15649,"nodeType":3061},{},[15650],{"data":15651,"content":15652,"nodeType":881},{},[15653],{"data":15654,"marks":15655,"value":15656,"nodeType":867},{},[],"Credential phishing via email and SMS (smishing) to harvest passwords en masse",{"data":15658,"content":15659,"nodeType":3061},{},[15660],{"data":15661,"content":15662,"nodeType":881},{},[15663],{"data":15664,"marks":15665,"value":15666,"nodeType":867},{},[],"Using SIM swapping (where you get the carrier to transfer a number to your attacker-controlled SIM card) to bypass SMS-based MFA",{"data":15668,"content":15669,"nodeType":3061},{},[15670],{"data":15671,"content":15672,"nodeType":881},{},[15673,15677,15684],{"data":15674,"marks":15675,"value":15676,"nodeType":867},{},[],"Using ",{"data":15678,"content":15679,"nodeType":876},{"uri":14532},[15680],{"data":15681,"marks":15682,"value":14537,"nodeType":867},{},[15683],{"type":1040},{"data":15685,"marks":15686,"value":15687,"nodeType":867},{},[]," (aka. push bombing) to bypass app-based push authentication",{"data":15689,"content":15690,"nodeType":3061},{},[15691],{"data":15692,"content":15693,"nodeType":881},{},[15694],{"data":15695,"marks":15696,"value":15697,"nodeType":867},{},[],"Using vishing (i.e. directly calling a victim to social engineer their MFA code, as opposed to a help desk attack)",{"data":15699,"content":15700,"nodeType":3061},{},[15701],{"data":15702,"content":15703,"nodeType":881},{},[15704],{"data":15705,"marks":15706,"value":15707,"nodeType":867},{},[],"Social engineering domain registrars to take control of the target organization’s DNS, hijacking their MX records and inbound mail, and using this to take over the company’s business app environments ",{"data":15709,"content":15710,"nodeType":3061},{},[15711],{"data":15712,"content":15713,"nodeType":881},{},[15714,15718,15727],{"data":15715,"marks":15716,"value":15717,"nodeType":867},{},[],"And latterly, using ",{"data":15719,"content":15721,"nodeType":876},{"uri":15720},"https://pushsecurity.com/blog/phishing-2-0-how-phishing-toolkits-are-evolving-with-aitm/",[15722],{"data":15723,"marks":15724,"value":15726,"nodeType":867},{},[15725],{"type":1040},"MFA-bypass AiTM phishing kits like Evilginx",{"data":15728,"marks":15729,"value":15730,"nodeType":867},{},[]," to steal live user sessions, bypassing all common forms of MFA (with the exception of WebAuthn/FIDO2) ",{"data":15732,"content":15733,"nodeType":881},{},[15734],{"data":15735,"marks":15736,"value":15737,"nodeType":867},{},[],"So, help desk scams are an important part of their toolkit, but it’s not the whole picture. Methods like AiTM in particular have spiked in popularity this year as a reliable and scalable way of bypassing MFA and achieving account takeover, with attackers using these toolkits as the de facto standard, getting creative in their detection evasion methods and in some cases, evading standard delivery vectors like email altogether to ensure the success of their phishing campaigns. ",{"data":15739,"content":15743,"nodeType":890},{"target":15740},{"sys":15741},{"id":15742,"type":887,"linkType":888},"2F2dpOkyXWnrKgFC3dSl67",[],{"data":15745,"content":15746,"nodeType":908},{},[],{"data":15748,"content":15749,"nodeType":918},{},[15750],{"data":15751,"marks":15752,"value":15753,"nodeType":867},{},[],"Stop identity attacks with Push Security",{"data":15755,"content":15756,"nodeType":881},{},[15757],{"data":15758,"marks":15759,"value":15760,"nodeType":867},{},[],"Modern attacks no longer take place on the endpoint or network — they target identities created and used via the web browser. This means that attacks increasingly take place in the browser (or rather, on resources your employees access through the browser). ",{"data":15762,"content":15763,"nodeType":881},{},[15764],{"data":15765,"marks":15766,"value":15767,"nodeType":867},{},[],"Push Security’s browser-based security platform provides comprehensive identity attack detection and response capabilities against techniques like AiTM phishing, credential stuffing, password spraying and session hijacking using stolen session tokens. You can also use Push to find and fix identity vulnerabilities across every app that your employees use, like: ghost logins; SSO coverage gaps; MFA gaps; weak, breached and reused passwords; risky OAuth integrations; and more. ",{"data":15769,"content":15773,"nodeType":890},{"target":15770},{"sys":15771},{"id":15772,"type":887,"linkType":888},"4atESpAAPAC0zP8CO4m8oa",[],{"data":15775,"content":15776,"nodeType":881},{},[15777,15781,15791],{"data":15778,"marks":15779,"value":15780,"nodeType":867},{},[],"To help combat help desk scams, we recently released ",{"data":15782,"content":15784,"nodeType":876},{"uri":15783},"https://pushsecurity.com/blog/employee-identity-verification-codes-release/",[15785],{"data":15786,"marks":15787,"value":15790,"nodeType":867},{},[15788,15789],{"type":1040},{"type":916},"Employee Identity Verification Codes",{"data":15792,"marks":15793,"value":15794,"nodeType":867},{},[]," — a simple, browser-based identity check that gives your help desk a reliable way to confirm they’re talking to someone from your organization.",{"data":15796,"content":15800,"nodeType":890},{"target":15797},{"sys":15798},{"id":15799,"type":887,"linkType":888},"1TEpCjh8UGwmejgYSGC1by",[],{"data":15802,"content":15803,"nodeType":881},{},[15804],{"data":15805,"marks":15806,"value":15807,"nodeType":867},{},[],"It enables legitimate help desk callers to quickly verify that they’re in possession of their primary device (i.e. laptop) by relaying a rotating 6-digit verification code in their browser via the Push extension. This is a great way to securely confirm caller identity and sniff out fraudulent callers, and can be used as part of a phishing-resistant help desk process. ",{"data":15809,"content":15810,"nodeType":908},{},[],{"data":15812,"content":15813,"nodeType":918},{},[15814],{"data":15815,"marks":15816,"value":15817,"nodeType":867},{},[],"Get started today!",{"data":15819,"content":15820,"nodeType":881},{},[15821,15825,15834],{"data":15822,"marks":15823,"value":15824,"nodeType":867},{},[],"You can use Employee Verification Codes as a free tool by installing the Push browser extension. Simply ",{"data":15826,"content":15828,"nodeType":876},{"uri":15827},"https://pushsecurity.com/free-tool/employee-verification-codes",[15829],{"data":15830,"marks":15831,"value":15833,"nodeType":867},{},[15832],{"type":1040},"sign up for a trial account and you can deploy the extension organization-wide to make use of this feature",{"data":15835,"marks":15836,"value":15837,"nodeType":867},{},[],". While you’re at it, you can trial Push’s full features for up to 10 users for free. ",{"data":15839,"content":15840,"nodeType":881},{},[15841,15845,15852],{"data":15842,"marks":15843,"value":15844,"nodeType":867},{},[],"Or if you want to learn more about how Push helps you to detect and defeat common identity attack techniques, ",{"data":15846,"content":15847,"nodeType":876},{"uri":2362},[15848],{"data":15849,"marks":15850,"value":10826,"nodeType":867},{},[15851],{"type":1040},{"data":15853,"marks":15854,"value":1947,"nodeType":867},{},[],{"data":15856,"content":15860,"nodeType":890},{"target":15857},{"sys":15858},{"id":15859,"type":887,"linkType":888},"6Td0hDBYdeT8tlnnfwipmD",[],{"data":15862,"content":15863,"nodeType":881},{},[15864],{"data":15865,"marks":15866,"value":21,"nodeType":867},{},[],"Scattered Spider: Understanding help desk scams and how to defend your organization","Scattered Spider has dominated the headlines in recent months with a consistent focus on help desk scams. Here's what you need to know to protect your business.","2025-06-27T00:00:00.000Z","scattered-spider-defending-against-help-desk-scams",{"items":15872},[15873,15875],{"sys":15874,"name":2547},{"id":2546},{"sys":15876,"name":342},{"id":2550},{"items":15878},[15879],{"fullName":849,"firstName":850,"jobTitle":851,"profilePicture":15880},{"url":855},"blog/inside-criminal-phishing-panel",{"json":15883},{"data":15884,"content":15885,"nodeType":1640},{},[15886],{"data":15887,"content":15888,"nodeType":881},{},[15889],{"data":15890,"marks":15891,"value":10060,"nodeType":867},{},[],{"id":8161,"publishedAt":15893},"2026-08-12T12:01:02.042Z",{"items":15895},[15896,15898],{"sys":15897,"name":2547},{"id":2546},{"sys":15899,"name":342},{"id":2550},{"items":15901},[15902,15904,15906,15908,15910,15912,15914,15916,15918,15920,15922,15924,15926,15928],{"sys":15903,"name":279,"slug":280,"tier":31},{"id":276},{"sys":15905,"name":519,"slug":520,"tier":31},{"id":516},{"sys":15907,"name":413,"slug":414,"tier":31},{"id":410},{"sys":15909,"name":342,"slug":343,"tier":31},{"id":339},{"sys":15911,"name":511,"slug":512,"tier":45},{"id":508},{"sys":15913,"name":261,"slug":262,"tier":45},{"id":258},{"sys":15915,"name":650,"slug":651,"tier":45},{"id":647},{"sys":15917,"name":466,"slug":467,"tier":45},{"id":463},{"sys":15919,"name":571,"slug":572,"tier":45},{"id":568},{"sys":15921,"name":244,"slug":245,"tier":45},{"id":241},{"sys":15923,"name":324,"slug":325,"tier":45},{"id":321},{"sys":15925,"name":607,"slug":608,"tier":45},{"id":604},{"sys":15927,"name":475,"slug":476,"tier":45},{"id":472},{"sys":15929,"name":404,"slug":405,"tier":45},{"id":401},"N0vOV2VIW5hy8pMM0BbvNcTuREBRP3N1gHaQp2C33sk",{"id":15932,"title":15933,"authorsCollection":15934,"content":15944,"extension":228,"faqItemsCollection":19422,"faqTitle":59,"featured":6,"hashTags":59,"meta":19424,"metaTitle":19425,"ogImage":59,"postType":8156,"publishedDate":19426,"relatedBlogPostsCollection":19427,"slug":361,"stem":21741,"subtitle":59,"summary":21742,"synopsis":21753,"sys":21754,"tagsCollection":21756,"topicsCollection":21762,"__hash__":21798},"blog/blog/device-code-phishing.json","Device code phishing attacks have skyrocketed: here’s what you need to know",{"items":15935},[15936],{"fullName":15937,"firstName":15938,"jobTitle":15939,"socialLinks":15940,"profilePicture":15942},"Luke Jennings","Luke","Vice President, R&D",[15941],"https://www.linkedin.com/in/luke-jennings-042b5619b/",{"url":15943},"https://images.ctfassets.net/y1cdw1ablpvd/4Hosb4zKi1dA0PUyDLMe1h/27e09d894861f2196ba794037986fb08/T016S22KZ96-U02NVQM7ZD4-57761d542d83-512.jpeg",{"json":15945,"links":18925},{"data":15946,"content":15947,"nodeType":1640},{},[15948,15954,15974,15992,15999,16005,16012,16019,16022,16030,16036,16120,16140,16146,16153,16266,16272,16275,16283,16290,16296,16299,16307,16348,16354,16361,16368,16375,16382,16401,16407,16413,16419,16425,16431,16437,16443,16449,16712,16715,16723,16858,16864,16867,16875,16915,17049,17055,17058,17066,17213,17219,17222,17230,17236,17377,17383,17389,17392,17400,17547,17553,17556,17564,17710,17716,17719,17727,17822,17828,17831,17839,17933,17939,17942,17950,17956,18089,18095,18098,18106,18155,18161,18164,18172,18311,18316,18319,18327,18459,18465,18468,18476,18488,18495,18501,18507,18514,18535,18551,18557,18560,18568,18576,18597,18618,18623,18630,18637,18645,18652,18659,18666,18674,18681,18731,18737,18740,18747,18754,18761,18807,18813,18820,18823,18831,18838,18845,18862,18868,18875,18882,18889],{"data":15949,"content":15953,"nodeType":890},{"target":15950},{"sys":15951},{"id":15952,"type":887,"linkType":888},"XOFOeNqmRHeiRbkPOJrP1",[],{"data":15955,"content":15956,"nodeType":881},{},[15957,15961,15970],{"data":15958,"marks":15959,"value":15960,"nodeType":867},{},[],"The OAuth 2.0 ",{"data":15962,"content":15964,"nodeType":876},{"uri":15963},"https://www.rfc-editor.org/rfc/rfc8628",[15965],{"data":15966,"marks":15967,"value":15969,"nodeType":867},{},[15968],{"type":1040},"device authorization grant",{"data":15971,"marks":15972,"value":15973,"nodeType":867},{},[]," was designed to enable input-constrained devices to sign-in to apps by asking the user to complete the login on a separate device by entering a code. But today, it’s mainly used when accessing CLI tools, meaning that many users encounter the device code flow daily. ",{"data":15975,"content":15976,"nodeType":881},{},[15977,15980,15988],{"data":15978,"marks":15979,"value":21,"nodeType":867},{},[],{"data":15981,"content":15983,"nodeType":876},{"uri":15982},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/device_code_phishing/description.md",[15984],{"data":15985,"marks":15986,"value":360,"nodeType":867},{},[15987],{"type":1040},{"data":15989,"marks":15990,"value":15991,"nodeType":867},{},[]," attacks designed to exploit this authorization flow are not new — it was among the first techniques that we added to the SaaS attacks matrix back in 2023. But it’s taken until now for it to really enter mainstream adoption. ",{"data":15993,"content":15994,"nodeType":881},{},[15995],{"data":15996,"marks":15997,"value":15998,"nodeType":867},{},[],"The technique tricks a user into issuing access tokens for an attacker-controlled application (not a device, confusingly). Any app that supports device code logins can be a target. Popular examples include Microsoft, Google, Salesforce, GitHub, and AWS. That said, Microsoft is, as always, much more heavily targeted at scale now than any other app.",{"data":16000,"content":16004,"nodeType":890},{"target":16001},{"sys":16002},{"id":16003,"type":887,"linkType":888},"Al0pGH8vmOYiufDFiAbt0",[],{"data":16006,"content":16007,"nodeType":881},{},[16008],{"data":16009,"marks":16010,"value":16011,"nodeType":867},{},[],"We’ve always been surprised that attackers haven’t commonly used device code phishing in their standard toolkit, preferring session-stealing AITM phishing and other social engineering attacks like ClickFix. But it’s pretty clear from the recent data that the shift to mainstream adoption has now happened. ",{"data":16013,"content":16014,"nodeType":881},{},[16015],{"data":16016,"marks":16017,"value":16018,"nodeType":867},{},[],"In this blog post, we’ll explore the history of device code phishing, what’s changed for it to enter mainstream adoption, how it works under the hood (with recent examples), and what security teams can do about it. ",{"data":16020,"content":16021,"nodeType":908},{},[],{"data":16023,"content":16024,"nodeType":918},{},[16025],{"data":16026,"marks":16027,"value":16029,"nodeType":867},{},[16028],{"type":916},"A brief history of device code phishing",{"data":16031,"content":16035,"nodeType":890},{"target":16032},{"sys":16033},{"id":16034,"type":887,"linkType":888},"6u3DgvSGChtTJu7l9I7PG1",[],{"data":16037,"content":16038,"nodeType":881},{},[16039,16043,16052,16056,16065,16069,16078,16082,16091,16095,16104,16107,16116],{"data":16040,"marks":16041,"value":16042,"nodeType":867},{},[],"The technique was first documented in 2020, before Secureworks released the first tooling framework ",{"data":16044,"content":16046,"nodeType":876},{"uri":16045},"https://github.com/secureworks/PhishInSuits",[16047],{"data":16048,"marks":16049,"value":16051,"nodeType":867},{},[16050],{"type":1040},"PhishInSuits",{"data":16053,"marks":16054,"value":16055,"nodeType":867},{},[]," a year later. A host of research followed, including ",{"data":16057,"content":16059,"nodeType":876},{"uri":16058},"https://github.com/secureworks/squarephish",[16060],{"data":16061,"marks":16062,"value":16064,"nodeType":867},{},[16063],{"type":1040},"SquarePhish",{"data":16066,"marks":16067,"value":16068,"nodeType":867},{},[]," v1 (using QR codes to trigger the 15 minute code expiration window), Dirk-Jan Mollema’s ",{"data":16070,"content":16072,"nodeType":876},{"uri":16071},"https://dirkjanm.io/phishing-for-microsoft-entra-primary-refresh-tokens/",[16073],{"data":16074,"marks":16075,"value":16077,"nodeType":867},{},[16076],{"type":1040},"key research",{"data":16079,"marks":16080,"value":16081,"nodeType":867},{},[]," (chaining device code phishing via Microsoft apps into Primary Refresh Token (PRT) acquisition to gain full browser-level access) and Dennis Kniep’s ",{"data":16083,"content":16085,"nodeType":876},{"uri":16084},"https://github.com/denniskniep/DeviceCodePhishing",[16086],{"data":16087,"marks":16088,"value":16090,"nodeType":867},{},[16089],{"type":1040},"DeviceCodePhishing tool",{"data":16092,"marks":16093,"value":16094,"nodeType":867},{},[]," which automates the entire flow with a headless browser. (Other recent noteworthy tools include ",{"data":16096,"content":16098,"nodeType":876},{"uri":16097},"https://github.com/nromsdahl/squarephish2",[16099],{"data":16100,"marks":16101,"value":16103,"nodeType":867},{},[16102],{"type":1040},"SquarePhish2",{"data":16105,"marks":16106,"value":2063,"nodeType":867},{},[],{"data":16108,"content":16110,"nodeType":876},{"uri":16109},"https://github.com/praetorian-inc/GitPhish",[16111],{"data":16112,"marks":16113,"value":16115,"nodeType":867},{},[16114],{"type":1040},"GitPhish",{"data":16117,"marks":16118,"value":16119,"nodeType":867},{},[],", so shout out to those too). ",{"data":16121,"content":16122,"nodeType":881},{},[16123,16127,16136],{"data":16124,"marks":16125,"value":16126,"nodeType":867},{},[],"It wasn’t until August 2024 that in-the-wild exploitation was first identified, with Russia-linked campaigns then continuing into 2025 before entering mainstream criminal adoption. This trend has continued to gather momentum in 2026 with ",{"data":16128,"content":16130,"nodeType":876},{"uri":16129},"https://thehackernews.com/2026/03/device-code-phishing-hits-340-microsoft.html",[16131],{"data":16132,"marks":16133,"value":16135,"nodeType":867},{},[16134],{"type":1040},"EvilTokens",{"data":16137,"marks":16138,"value":16139,"nodeType":867},{},[],", the first reported criminal PhaaS kit for device code phishing, already powering massive campaigns after launching in February. ",{"data":16141,"content":16145,"nodeType":890},{"target":16142},{"sys":16143},{"id":16144,"type":887,"linkType":888},"6xsfmbYEzpW7CdDiNzO6cu",[],{"data":16147,"content":16148,"nodeType":881},{},[16149],{"data":16150,"marks":16151,"value":16152,"nodeType":867},{},[],"Some of the noteworthy in-the-wild campaigns include:",{"data":16154,"content":16155,"nodeType":3126},{},[16156,16187,16207],{"data":16157,"content":16158,"nodeType":3061},{},[16159],{"data":16160,"content":16161,"nodeType":881},{},[16162,16166,16172,16175,16183],{"data":16163,"marks":16164,"value":16165,"nodeType":867},{},[],"Storm-2372, tracked by ",{"data":16167,"content":16168,"nodeType":876},{"uri":8122},[16169],{"data":16170,"marks":16171,"value":15009,"nodeType":867},{},[],{"data":16173,"marks":16174,"value":2063,"nodeType":867},{},[],{"data":16176,"content":16178,"nodeType":876},{"uri":16177},"https://www.volexity.com/blog/2025/02/13/multiple-russian-threat-actors-targeting-microsoft-device-code-authentication/",[16179],{"data":16180,"marks":16181,"value":16182,"nodeType":867},{},[],"Volexity",{"data":16184,"marks":16185,"value":16186,"nodeType":867},{},[],", linked to multiple Russia-aligned clusters, combining spear-phishing and social engineering with device code phishing payloads against strategic intelligence targets.",{"data":16188,"content":16189,"nodeType":3061},{},[16190],{"data":16191,"content":16192,"nodeType":881},{},[16193,16197,16203],{"data":16194,"marks":16195,"value":16196,"nodeType":867},{},[],"The massive Salesforce campaign operated by ",{"data":16198,"content":16199,"nodeType":876},{"uri":3051},[16200],{"data":16201,"marks":16202,"value":3056,"nodeType":867},{},[],{"data":16204,"marks":16205,"value":16206,"nodeType":867},{},[]," (SLH) combined vishing with a device code phishing payload targeting Salesforce. The attacks morphed into a broader supply chain campaign using stolen credentials, ultimately resulting in 1000+ organizations being compromised and over 1.5 billion stolen records claimed. ",{"data":16208,"content":16209,"nodeType":3061},{},[16210],{"data":16211,"content":16212,"nodeType":881},{},[16213,16217,16225,16229,16238,16241,16250,16254,16262],{"data":16214,"marks":16215,"value":16216,"nodeType":867},{},[],"A massive spike in activity in late 2025 and 2026. This includes ",{"data":16218,"content":16220,"nodeType":876},{"uri":16219},"https://www.proofpoint.com/us/blog/threat-insight/access-granted-phishing-device-code-authorization-account-takeover",[16221],{"data":16222,"marks":16223,"value":16224,"nodeType":867},{},[],"multiple threat clusters",{"data":16226,"marks":16227,"value":16228,"nodeType":867},{},[]," tracked using device code phishing techniques, more ",{"data":16230,"content":16232,"nodeType":876},{"uri":16231},"https://www.bleepingcomputer.com/news/security/hackers-target-microsoft-entra-accounts-in-device-code-vishing-attacks/",[16233],{"data":16234,"marks":16235,"value":16237,"nodeType":867},{},[16236],{"type":1040},"criminal operations linked to SLH",{"data":16239,"marks":16240,"value":15362,"nodeType":867},{},[],{"data":16242,"content":16244,"nodeType":876},{"uri":16243},"https://newtonpaul.com/blog/device-code-phish-update/",[16245],{"data":16246,"marks":16247,"value":16249,"nodeType":867},{},[16248],{"type":1040},"hundreds of organizations being targeted via PhaaS architecture,",{"data":16251,"marks":16252,"value":16253,"nodeType":867},{},[]," which looks to be the same campaign as the recently uncovered EvilTokens PhaaS reported by ",{"data":16255,"content":16256,"nodeType":876},{"uri":1048},[16257],{"data":16258,"marks":16259,"value":16261,"nodeType":867},{},[16260],{"type":1040},"Huntress",{"data":16263,"marks":16264,"value":16265,"nodeType":867},{},[]," (featuring abuse of the Railway PaaS platform). ",{"data":16267,"content":16271,"nodeType":890},{"target":16268},{"sys":16269},{"id":16270,"type":887,"linkType":888},"3WLt6qLCK8CSwr0QZxZiMv",[],{"data":16273,"content":16274,"nodeType":908},{},[],{"data":16276,"content":16277,"nodeType":918},{},[16278],{"data":16279,"marks":16280,"value":16282,"nodeType":867},{},[16281],{"type":916},"What we’re seeing in the wild",{"data":16284,"content":16285,"nodeType":881},{},[16286],{"data":16287,"marks":16288,"value":16289,"nodeType":867},{},[],"As mentioned, we’ve also seen a huge spike in device code phishing activity this year, with multiple kits, page designs, and lure types. We’ve now identified 14+ distinct kits in circulation in the wild, with EvilTokens being the most prevalent. It’s clear that attackers are both spinning up their own kits and creative derivatives of others — we’ve seen kits that are visually similar to EvilTokens (close enough to be clones or forks) but with very different backends, for example AWS, Digital Ocean, 2cloud, and more. ",{"data":16291,"content":16295,"nodeType":890},{"target":16292},{"sys":16293},{"id":16294,"type":887,"linkType":888},"nJCbTw85GKXdqrlIkzZwi",[],{"data":16297,"content":16298,"nodeType":908},{},[],{"data":16300,"content":16301,"nodeType":998},{},[16302],{"data":16303,"marks":16304,"value":16306,"nodeType":867},{},[16305],{"type":916},"“ANTIBOT” (EvilTokens)",{"data":16308,"content":16309,"nodeType":881},{},[16310,16313,16320,16323,16332,16336,16344],{"data":16311,"marks":16312,"value":21,"nodeType":867},{},[],{"data":16314,"content":16315,"nodeType":876},{"uri":1048},[16316],{"data":16317,"marks":16318,"value":16261,"nodeType":867},{},[16319],{"type":1040},{"data":16321,"marks":16322,"value":4006,"nodeType":867},{},[],{"data":16324,"content":16326,"nodeType":876},{"uri":16325},"https://blog.sekoia.io/new-widespread-eviltokens-kit-device-code-phishing-as-a-service-part-1/",[16327],{"data":16328,"marks":16329,"value":16331,"nodeType":867},{},[16330],{"type":1040},"Sekoia",{"data":16333,"marks":16334,"value":16335,"nodeType":867},{},[],", and researcher ",{"data":16337,"content":16338,"nodeType":876},{"uri":16243},[16339],{"data":16340,"marks":16341,"value":16343,"nodeType":867},{},[16342],{"type":1040},"Paul Newton",{"data":16345,"marks":16346,"value":16347,"nodeType":867},{},[]," have already done a great job of providing IOCs for the recent EvilTokens activity spike, including multiple backend Railway IPs in authentication events. ",{"data":16349,"content":16353,"nodeType":890},{"target":16350},{"sys":16351},{"id":16352,"type":887,"linkType":888},"1XNviq5OvMf5TEAc59F6g5",[],{"data":16355,"content":16356,"nodeType":881},{},[16357],{"data":16358,"marks":16359,"value":16360,"nodeType":867},{},[],"Beyond the most widely observed implementation featuring a Cloudflare Workers frontend and Railway backend for authentication, we’ve also tracked additional versions of EvilTokens in circulation since January 2026 (many of which remain live along with the current “production” version of the kit). ",{"data":16362,"content":16363,"nodeType":881},{},[16364],{"data":16365,"marks":16366,"value":16367,"nodeType":867},{},[],"You can see an evolution of the kit in the videos and screenshots below, from early precursors seen in mid-January, the first mentions of ANTIBOT in the page code in late-January, the parallel development of a “Courts Access” fork that lacks the ANTIBOT references, and finally production EvilTokens in February. One of the key threads between the versions is the presence of a generateFallbackCode() JS function and use of a /generate-codes API call. ",{"data":16369,"content":16370,"nodeType":881},{},[16371],{"data":16372,"marks":16373,"value":16374,"nodeType":867},{},[],"Early implementations were quite different, for example using ScrapingBee to generate the displayed code, and varied hosting on vercel, fastly, edgeone, and others. ",{"data":16376,"content":16377,"nodeType":881},{},[16378],{"data":16379,"marks":16380,"value":16381,"nodeType":867},{},[],"After initially appearing on custom domains, the production version is now predominantly hosted on Cloudflare Workers, as per the broader tracking of the campaign. The descriptive HTML comments around ANTIBOT functions have also been removed in later versions. ",{"data":16383,"content":16384,"nodeType":881},{},[16385,16389,16397],{"data":16386,"marks":16387,"value":16388,"nodeType":867},{},[],"The production version of EvilTokens showcases common ",{"data":16390,"content":16391,"nodeType":876},{"uri":2267},[16392],{"data":16393,"marks":16394,"value":16396,"nodeType":867},{},[16395],{"type":1040},"detection evasion techniques",{"data":16398,"marks":16399,"value":16400,"nodeType":867},{},[]," we've come to associate with PhaaS kits in the AiTM space — using multiple redirects through trusted sites before serving the malicious page, using bot protection to block security tools from analyzing the page, and so on. It also uses a pop-up window for the device code entry rather than a redirect, reducing the friction for the victim (it looks pretty convincing, too).",{"data":16402,"content":16406,"nodeType":890},{"target":16403},{"sys":16404},{"id":16405,"type":887,"linkType":888},"73rNOIEDPfP5IJwpFaxVc2",[],{"data":16408,"content":16412,"nodeType":890},{"target":16409},{"sys":16410},{"id":16411,"type":887,"linkType":888},"5BJSvOQUW9UpsQtoDNtgTC",[],{"data":16414,"content":16418,"nodeType":890},{"target":16415},{"sys":16416},{"id":16417,"type":887,"linkType":888},"3dbePPxVb4h4SauGg3glIL",[],{"data":16420,"content":16424,"nodeType":890},{"target":16421},{"sys":16422},{"id":16423,"type":887,"linkType":888},"1UOLcmNQvOsL5tdLSVuviq",[],{"data":16426,"content":16430,"nodeType":890},{"target":16427},{"sys":16428},{"id":16429,"type":887,"linkType":888},"55XRqLSwUUi2D4ZVpJboml",[],{"data":16432,"content":16436,"nodeType":890},{"target":16433},{"sys":16434},{"id":16435,"type":887,"linkType":888},"5wg5yr2Lo8t3f72ZV815c",[],{"data":16438,"content":16442,"nodeType":890},{"target":16439},{"sys":16440},{"id":16441,"type":887,"linkType":888},"35cowlL6i3rkGXOGmSxlI1",[],{"data":16444,"content":16445,"nodeType":881},{},[16446],{"data":16447,"marks":16448,"value":21,"nodeType":867},{},[],{"data":16450,"content":16451,"nodeType":2531},{},[16452,16476,16559,16611,16635],{"data":16453,"content":16454,"nodeType":2438},{},[16455,16466],{"data":16456,"content":16457,"nodeType":2452},{},[16458],{"data":16459,"content":16460,"nodeType":881},{},[16461],{"data":16462,"marks":16463,"value":16465,"nodeType":867},{},[16464],{"type":916},"Frontend infrastructure",{"data":16467,"content":16468,"nodeType":2452},{},[16469],{"data":16470,"content":16471,"nodeType":881},{},[16472],{"data":16473,"marks":16474,"value":16475,"nodeType":867},{},[],"Workers.dev, vercel.app, github.io, fastly.net, edgeone.dev",{"data":16477,"content":16478,"nodeType":2438},{},[16479,16490],{"data":16480,"content":16481,"nodeType":2452},{},[16482],{"data":16483,"content":16484,"nodeType":881},{},[16485],{"data":16486,"marks":16487,"value":16489,"nodeType":867},{},[16488],{"type":916},"Backend infrastructure",{"data":16491,"content":16492,"nodeType":2452},{},[16493,16523],{"data":16494,"content":16495,"nodeType":881},{},[16496,16501,16505,16510,16514,16519],{"data":16497,"marks":16498,"value":16500,"nodeType":867},{},[16499],{"type":916},"Example IP: (V3) ",{"data":16502,"marks":16503,"value":16504,"nodeType":867},{},[],"162.220.232.71 (Railway AS400940) ",{"data":16506,"marks":16507,"value":16509,"nodeType":867},{},[16508],{"type":916},"(V2)",{"data":16511,"marks":16512,"value":16513,"nodeType":867},{},[]," 71.11.42.193 ",{"data":16515,"marks":16516,"value":16518,"nodeType":867},{},[16517],{"type":916},"(V1) ",{"data":16520,"marks":16521,"value":16522,"nodeType":867},{},[],"72.218.25.107",{"data":16524,"content":16525,"nodeType":881},{},[16526,16531,16534,16539,16543,16547,16551,16555],{"data":16527,"marks":16528,"value":16530,"nodeType":867},{},[16529],{"type":916},"Backend User Agent:",{"data":16532,"marks":16533,"value":3679,"nodeType":867},{},[],{"data":16535,"marks":16536,"value":16538,"nodeType":867},{},[16537],{"type":916},"(V3) ",{"data":16540,"marks":16541,"value":16542,"nodeType":867},{},[],"node, ",{"data":16544,"marks":16545,"value":16509,"nodeType":867},{},[16546],{"type":916},{"data":16548,"marks":16549,"value":16550,"nodeType":867},{},[],", Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_4) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/73.0.3683 Safari/537.36 OPR/57.0.3098.91 ",{"data":16552,"marks":16553,"value":16518,"nodeType":867},{},[16554],{"type":916},{"data":16556,"marks":16557,"value":16558,"nodeType":867},{},[],"Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/71.0.3578.98 Safari/537.36 OPR/56.0.3051.52 ",{"data":16560,"content":16561,"nodeType":2438},{},[16562,16573],{"data":16563,"content":16564,"nodeType":2452},{},[16565],{"data":16566,"content":16567,"nodeType":881},{},[16568],{"data":16569,"marks":16570,"value":16572,"nodeType":867},{},[16571],{"type":916},"Network paths",{"data":16574,"content":16575,"nodeType":2452},{},[16576,16583,16590,16597,16604],{"data":16577,"content":16578,"nodeType":881},{},[16579],{"data":16580,"marks":16581,"value":16582,"nodeType":867},{},[],"/api/rate-limit ",{"data":16584,"content":16585,"nodeType":881},{},[16586],{"data":16587,"marks":16588,"value":16589,"nodeType":867},{},[],"/api/fingerprint ",{"data":16591,"content":16592,"nodeType":881},{},[16593],{"data":16594,"marks":16595,"value":16596,"nodeType":867},{},[],"/api/captcha-verify ",{"data":16598,"content":16599,"nodeType":881},{},[16600],{"data":16601,"marks":16602,"value":16603,"nodeType":867},{},[],"/api/init /api/generate-code ",{"data":16605,"content":16606,"nodeType":881},{},[16607],{"data":16608,"marks":16609,"value":16610,"nodeType":867},{},[],"/api/check-auth",{"data":16612,"content":16613,"nodeType":2438},{},[16614,16625],{"data":16615,"content":16616,"nodeType":2452},{},[16617],{"data":16618,"content":16619,"nodeType":881},{},[16620],{"data":16621,"marks":16622,"value":16624,"nodeType":867},{},[16623],{"type":916},"Lure themes",{"data":16626,"content":16627,"nodeType":2452},{},[16628],{"data":16629,"content":16630,"nodeType":881},{},[16631],{"data":16632,"marks":16633,"value":16634,"nodeType":867},{},[],"Various MS lures (e.g. Outlook, SharePoint, Teams) DocuSign, Adobe",{"data":16636,"content":16637,"nodeType":2438},{},[16638,16649],{"data":16639,"content":16640,"nodeType":2452},{},[16641],{"data":16642,"content":16643,"nodeType":881},{},[16644],{"data":16645,"marks":16646,"value":16648,"nodeType":867},{},[16647],{"type":916},"Example Domain",{"data":16650,"content":16651,"nodeType":2452},{},[16652,16664,16676,16688,16700],{"data":16653,"content":16654,"nodeType":881},{},[16655,16660],{"data":16656,"marks":16657,"value":16659,"nodeType":867},{},[16658],{"type":916},"Precursor A:",{"data":16661,"marks":16662,"value":16663,"nodeType":867},{},[]," teams-zpfvwnpxuc[.]edgeone.dev",{"data":16665,"content":16666,"nodeType":881},{},[16667,16672],{"data":16668,"marks":16669,"value":16671,"nodeType":867},{},[16670],{"type":916},"Precursor B: ",{"data":16673,"marks":16674,"value":16675,"nodeType":867},{},[],"authenticate-m365-accountsecurity-m-pi[.]vercel.app",{"data":16677,"content":16678,"nodeType":881},{},[16679,16684],{"data":16680,"marks":16681,"value":16683,"nodeType":867},{},[16682],{"type":916},"Courts Access: ",{"data":16685,"marks":16686,"value":16687,"nodeType":867},{},[],"secure-systems-validations-courts[.]vercel.app",{"data":16689,"content":16690,"nodeType":881},{},[16691,16696],{"data":16692,"marks":16693,"value":16695,"nodeType":867},{},[16694],{"type":916},"Early ANTIBOT:",{"data":16697,"marks":16698,"value":16699,"nodeType":867},{},[]," interface-auth-en-useast[.]global.ssl.fastly.net",{"data":16701,"content":16702,"nodeType":881},{},[16703,16708],{"data":16704,"marks":16705,"value":16707,"nodeType":867},{},[16706],{"type":916},"Production ANTIBOT: ",{"data":16709,"marks":16710,"value":16711,"nodeType":867},{},[],"index-z059-document-pending-reviewsign-xlss7994824[.]awalizer[.]workers.dev",{"data":16713,"content":16714,"nodeType":908},{},[],{"data":16716,"content":16717,"nodeType":998},{},[16718],{"data":16719,"marks":16720,"value":16722,"nodeType":867},{},[16721],{"type":916},"“SHAREFILE”",{"data":16724,"content":16725,"nodeType":2531},{},[16726,16749,16788,16811,16834],{"data":16727,"content":16728,"nodeType":2438},{},[16729,16739],{"data":16730,"content":16731,"nodeType":2452},{},[16732],{"data":16733,"content":16734,"nodeType":881},{},[16735],{"data":16736,"marks":16737,"value":16465,"nodeType":867},{},[16738],{"type":916},{"data":16740,"content":16741,"nodeType":2452},{},[16742],{"data":16743,"content":16744,"nodeType":881},{},[16745],{"data":16746,"marks":16747,"value":16748,"nodeType":867},{},[],"No hosting markers visible.",{"data":16750,"content":16751,"nodeType":2438},{},[16752,16762],{"data":16753,"content":16754,"nodeType":2452},{},[16755],{"data":16756,"content":16757,"nodeType":881},{},[16758],{"data":16759,"marks":16760,"value":16489,"nodeType":867},{},[16761],{"type":916},{"data":16763,"content":16764,"nodeType":2452},{},[16765,16777],{"data":16766,"content":16767,"nodeType":881},{},[16768,16773],{"data":16769,"marks":16770,"value":16772,"nodeType":867},{},[16771],{"type":916},"Example IP:",{"data":16774,"marks":16775,"value":16776,"nodeType":867},{},[]," 147.45.60.47 (Global Connectivity Solutions LLP AS215540)",{"data":16778,"content":16779,"nodeType":881},{},[16780,16784],{"data":16781,"marks":16782,"value":16530,"nodeType":867},{},[16783],{"type":916},{"data":16785,"marks":16786,"value":16787,"nodeType":867},{},[]," node",{"data":16789,"content":16790,"nodeType":2438},{},[16791,16801],{"data":16792,"content":16793,"nodeType":2452},{},[16794],{"data":16795,"content":16796,"nodeType":881},{},[16797],{"data":16798,"marks":16799,"value":16572,"nodeType":867},{},[16800],{"type":916},{"data":16802,"content":16803,"nodeType":2452},{},[16804],{"data":16805,"content":16806,"nodeType":881},{},[16807],{"data":16808,"marks":16809,"value":16810,"nodeType":867},{},[],"POST /api/device/start  POST /api/device/poll",{"data":16812,"content":16813,"nodeType":2438},{},[16814,16824],{"data":16815,"content":16816,"nodeType":2452},{},[16817],{"data":16818,"content":16819,"nodeType":881},{},[16820],{"data":16821,"marks":16822,"value":16624,"nodeType":867},{},[16823],{"type":916},{"data":16825,"content":16826,"nodeType":2452},{},[16827],{"data":16828,"content":16829,"nodeType":881},{},[16830],{"data":16831,"marks":16832,"value":16833,"nodeType":867},{},[],"Citrix ShareFile document transfer — file card with sender info, expiry warning, download/preview buttons",{"data":16835,"content":16836,"nodeType":2438},{},[16837,16848],{"data":16838,"content":16839,"nodeType":2452},{},[16840],{"data":16841,"content":16842,"nodeType":881},{},[16843],{"data":16844,"marks":16845,"value":16847,"nodeType":867},{},[16846],{"type":916},"Example domain",{"data":16849,"content":16850,"nodeType":2452},{},[16851],{"data":16852,"content":16853,"nodeType":881},{},[16854],{"data":16855,"marks":16856,"value":16857,"nodeType":867},{},[],"cghdfg[.]vbchkioi[.]su",{"data":16859,"content":16863,"nodeType":890},{"target":16860},{"sys":16861},{"id":16862,"type":887,"linkType":888},"1TtZ6VsMSTlPvy7W996w9E",[],{"data":16865,"content":16866,"nodeType":908},{},[],{"data":16868,"content":16869,"nodeType":998},{},[16870],{"data":16871,"marks":16872,"value":16874,"nodeType":867},{},[16873],{"type":916},"Kali365 (internal name “CLURE”)",{"data":16876,"content":16877,"nodeType":881},{},[16878,16882,16887,16891,16899,16903,16911],{"data":16879,"marks":16880,"value":16881,"nodeType":867},{},[],"Clure was recently linked to the ",{"data":16883,"marks":16884,"value":16886,"nodeType":867},{},[16885],{"type":916},"Kali365",{"data":16888,"marks":16889,"value":16890,"nodeType":867},{},[]," PhaaS platform based on an ",{"data":16892,"content":16894,"nodeType":876},{"uri":16893},"https://www.ic3.gov/PSA/2026/PSA260521",[16895],{"data":16896,"marks":16897,"value":16898,"nodeType":867},{},[],"FBI advisory",{"data":16900,"marks":16901,"value":16902,"nodeType":867},{},[]," and additional research from ",{"data":16904,"content":16906,"nodeType":876},{"uri":16905},"https://arcticwolf.com/resources/blog/token-bingo-dont-let-your-code-be-the-winner/",[16907],{"data":16908,"marks":16909,"value":16910,"nodeType":867},{},[],"Arctic Wolf",{"data":16912,"marks":16913,"value":16914,"nodeType":867},{},[],". This is yet another example of Device Code Phishing and AiTM phishing capabilities being integrated into unified phishing platforms. ",{"data":16916,"content":16917,"nodeType":2531},{},[16918,16941,16980,17003,17026],{"data":16919,"content":16920,"nodeType":2438},{},[16921,16931],{"data":16922,"content":16923,"nodeType":2452},{},[16924],{"data":16925,"content":16926,"nodeType":881},{},[16927],{"data":16928,"marks":16929,"value":16465,"nodeType":867},{},[16930],{"type":916},{"data":16932,"content":16933,"nodeType":2452},{},[16934],{"data":16935,"content":16936,"nodeType":881},{},[16937],{"data":16938,"marks":16939,"value":16940,"nodeType":867},{},[],"API on api.duemineral.uk:8443 and api.loadingdocuments.uk:8443 (rotates). ",{"data":16942,"content":16943,"nodeType":2438},{},[16944,16954],{"data":16945,"content":16946,"nodeType":2452},{},[16947],{"data":16948,"content":16949,"nodeType":881},{},[16950],{"data":16951,"marks":16952,"value":16489,"nodeType":867},{},[16953],{"type":916},{"data":16955,"content":16956,"nodeType":2452},{},[16957,16969],{"data":16958,"content":16959,"nodeType":881},{},[16960,16965],{"data":16961,"marks":16962,"value":16964,"nodeType":867},{},[16963],{"type":916},"Example IP: ",{"data":16966,"marks":16967,"value":16968,"nodeType":867},{},[],"162.243.166.119 (DigitalOcean AS14061)",{"data":16970,"content":16971,"nodeType":881},{},[16972,16976],{"data":16973,"marks":16974,"value":16530,"nodeType":867},{},[16975],{"type":916},{"data":16977,"marks":16978,"value":16979,"nodeType":867},{},[]," python-requests/2.32.5",{"data":16981,"content":16982,"nodeType":2438},{},[16983,16993],{"data":16984,"content":16985,"nodeType":2452},{},[16986],{"data":16987,"content":16988,"nodeType":881},{},[16989],{"data":16990,"marks":16991,"value":16572,"nodeType":867},{},[16992],{"type":916},{"data":16994,"content":16995,"nodeType":2452},{},[16996],{"data":16997,"content":16998,"nodeType":881},{},[16999],{"data":17000,"marks":17001,"value":17002,"nodeType":867},{},[],"GET /api/status/{numeric_SID} (port :8443)",{"data":17004,"content":17005,"nodeType":2438},{},[17006,17016],{"data":17007,"content":17008,"nodeType":2452},{},[17009],{"data":17010,"content":17011,"nodeType":881},{},[17012],{"data":17013,"marks":17014,"value":16624,"nodeType":867},{},[17015],{"type":916},{"data":17017,"content":17018,"nodeType":2452},{},[17019],{"data":17020,"content":17021,"nodeType":881},{},[17022],{"data":17023,"marks":17024,"value":17025,"nodeType":867},{},[],"SharePoint \"Team Site\" doc library, SharePoint \"Shared Document\" individual share",{"data":17027,"content":17028,"nodeType":2438},{},[17029,17039],{"data":17030,"content":17031,"nodeType":2452},{},[17032],{"data":17033,"content":17034,"nodeType":881},{},[17035],{"data":17036,"marks":17037,"value":16847,"nodeType":867},{},[17038],{"type":916},{"data":17040,"content":17041,"nodeType":2452},{},[17042],{"data":17043,"content":17044,"nodeType":881},{},[17045],{"data":17046,"marks":17047,"value":17048,"nodeType":867},{},[],"auth[.]duemineral[.]uk",{"data":17050,"content":17054,"nodeType":890},{"target":17051},{"sys":17052},{"id":17053,"type":887,"linkType":888},"Y1AiT3dJRTXz64pb68kca",[],{"data":17056,"content":17057,"nodeType":908},{},[],{"data":17059,"content":17060,"nodeType":998},{},[17061],{"data":17062,"marks":17063,"value":17065,"nodeType":867},{},[17064],{"type":916},"“LINKID”",{"data":17067,"content":17068,"nodeType":2531},{},[17069,17092,17137,17167,17190],{"data":17070,"content":17071,"nodeType":2438},{},[17072,17082],{"data":17073,"content":17074,"nodeType":2452},{},[17075],{"data":17076,"content":17077,"nodeType":881},{},[17078],{"data":17079,"marks":17080,"value":16465,"nodeType":867},{},[17081],{"type":916},{"data":17083,"content":17084,"nodeType":2452},{},[17085],{"data":17086,"content":17087,"nodeType":881},{},[17088],{"data":17089,"marks":17090,"value":17091,"nodeType":867},{},[],"Adobe variant has Cloudflare challenge-platform iframe (CF-protected origin). Relative API paths — self-hosted.",{"data":17093,"content":17094,"nodeType":2438},{},[17095,17105],{"data":17096,"content":17097,"nodeType":2452},{},[17098],{"data":17099,"content":17100,"nodeType":881},{},[17101],{"data":17102,"marks":17103,"value":16489,"nodeType":867},{},[17104],{"type":916},{"data":17106,"content":17107,"nodeType":2452},{},[17108,17119,17126],{"data":17109,"content":17110,"nodeType":881},{},[17111,17115],{"data":17112,"marks":17113,"value":16964,"nodeType":867},{},[17114],{"type":916},{"data":17116,"marks":17117,"value":17118,"nodeType":867},{},[],"185.176.220.22 (2cloud.eu AS39845)",{"data":17120,"content":17121,"nodeType":881},{},[17122],{"data":17123,"marks":17124,"value":17125,"nodeType":867},{},[],"2600:1f10:470d:9a00:1437:ec30:be61:3494 (AWS AS16509)",{"data":17127,"content":17128,"nodeType":881},{},[17129,17133],{"data":17130,"marks":17131,"value":16530,"nodeType":867},{},[17132],{"type":916},{"data":17134,"marks":17135,"value":17136,"nodeType":867},{},[]," axios/1.10.0 , axios/1.13.6",{"data":17138,"content":17139,"nodeType":2438},{},[17140,17150],{"data":17141,"content":17142,"nodeType":2452},{},[17143],{"data":17144,"content":17145,"nodeType":881},{},[17146],{"data":17147,"marks":17148,"value":16572,"nodeType":867},{},[17149],{"type":916},{"data":17151,"content":17152,"nodeType":2452},{},[17153,17160],{"data":17154,"content":17155,"nodeType":881},{},[17156],{"data":17157,"marks":17158,"value":17159,"nodeType":867},{},[],"POST /api/device/start",{"data":17161,"content":17162,"nodeType":881},{},[17163],{"data":17164,"marks":17165,"value":17166,"nodeType":867},{},[],"GET /api/device/status/{sessionId}",{"data":17168,"content":17169,"nodeType":2438},{},[17170,17180],{"data":17171,"content":17172,"nodeType":2452},{},[17173],{"data":17174,"content":17175,"nodeType":881},{},[17176],{"data":17177,"marks":17178,"value":16624,"nodeType":867},{},[17179],{"type":916},{"data":17181,"content":17182,"nodeType":2452},{},[17183],{"data":17184,"content":17185,"nodeType":881},{},[17186],{"data":17187,"marks":17188,"value":17189,"nodeType":867},{},[],"MS Teams meeting invitation (with interactive date/time picker), Adobe Acrobat Sign document review",{"data":17191,"content":17192,"nodeType":2438},{},[17193,17203],{"data":17194,"content":17195,"nodeType":2452},{},[17196],{"data":17197,"content":17198,"nodeType":881},{},[17199],{"data":17200,"marks":17201,"value":16847,"nodeType":867},{},[17202],{"type":916},{"data":17204,"content":17205,"nodeType":2452},{},[17206],{"data":17207,"content":17208,"nodeType":881},{},[17209],{"data":17210,"marks":17211,"value":17212,"nodeType":867},{},[],"sdtr-site[.]cfd",{"data":17214,"content":17218,"nodeType":890},{"target":17215},{"sys":17216},{"id":17217,"type":887,"linkType":888},"22hsIzlkptC2JTIUtbOuUn",[],{"data":17220,"content":17221,"nodeType":908},{},[],{"data":17223,"content":17224,"nodeType":998},{},[17225],{"data":17226,"marks":17227,"value":17229,"nodeType":867},{},[17228],{"type":916},"Device Code Lab (formerly codename \"AUTHOV”)",{"data":17231,"content":17235,"nodeType":890},{"target":17232},{"sys":17233},{"id":17234,"type":887,"linkType":888},"5vllVaa0Ry0wKs46ssrZLC",[],{"data":17237,"content":17238,"nodeType":2531},{},[17239,17262,17308,17331,17354],{"data":17240,"content":17241,"nodeType":2438},{},[17242,17252],{"data":17243,"content":17244,"nodeType":2452},{},[17245],{"data":17246,"content":17247,"nodeType":881},{},[17248],{"data":17249,"marks":17250,"value":16465,"nodeType":867},{},[17251],{"type":916},{"data":17253,"content":17254,"nodeType":2452},{},[17255],{"data":17256,"content":17257,"nodeType":881},{},[17258],{"data":17259,"marks":17260,"value":17261,"nodeType":867},{},[],"workers.dev",{"data":17263,"content":17264,"nodeType":2438},{},[17265,17275],{"data":17266,"content":17267,"nodeType":2452},{},[17268],{"data":17269,"content":17270,"nodeType":881},{},[17271],{"data":17272,"marks":17273,"value":16489,"nodeType":867},{},[17274],{"type":916},{"data":17276,"content":17277,"nodeType":2452},{},[17278,17289],{"data":17279,"content":17280,"nodeType":881},{},[17281,17285],{"data":17282,"marks":17283,"value":16964,"nodeType":867},{},[17284],{"type":916},{"data":17286,"marks":17287,"value":17288,"nodeType":867},{},[],"192.3.225.100 (HostPapa / ColoCrossing AS36352)",{"data":17290,"content":17291,"nodeType":881},{},[17292,17296,17299,17304],{"data":17293,"marks":17294,"value":16530,"nodeType":867},{},[17295],{"type":916},{"data":17297,"marks":17298,"value":3679,"nodeType":867},{},[],{"data":17300,"marks":17301,"value":17303,"nodeType":867},{},[17302],{"type":916}," ",{"data":17305,"marks":17306,"value":17307,"nodeType":867},{},[],"python-httpx/0.28.1",{"data":17309,"content":17310,"nodeType":2438},{},[17311,17321],{"data":17312,"content":17313,"nodeType":2452},{},[17314],{"data":17315,"content":17316,"nodeType":881},{},[17317],{"data":17318,"marks":17319,"value":16572,"nodeType":867},{},[17320],{"type":916},{"data":17322,"content":17323,"nodeType":2452},{},[17324],{"data":17325,"content":17326,"nodeType":881},{},[17327],{"data":17328,"marks":17329,"value":17330,"nodeType":867},{},[],"GET /landing/api/session-status?session_id=&token=",{"data":17332,"content":17333,"nodeType":2438},{},[17334,17344],{"data":17335,"content":17336,"nodeType":2452},{},[17337],{"data":17338,"content":17339,"nodeType":881},{},[17340],{"data":17341,"marks":17342,"value":16624,"nodeType":867},{},[17343],{"type":916},{"data":17345,"content":17346,"nodeType":2452},{},[17347],{"data":17348,"content":17349,"nodeType":881},{},[17350],{"data":17351,"marks":17352,"value":17353,"nodeType":867},{},[],"Adobe Acrobat document sharing (PDF preview, sender avatar)",{"data":17355,"content":17356,"nodeType":2438},{},[17357,17367],{"data":17358,"content":17359,"nodeType":2452},{},[17360],{"data":17361,"content":17362,"nodeType":881},{},[17363],{"data":17364,"marks":17365,"value":16847,"nodeType":867},{},[17366],{"type":916},{"data":17368,"content":17369,"nodeType":2452},{},[17370],{"data":17371,"content":17372,"nodeType":881},{},[17373],{"data":17374,"marks":17375,"value":17376,"nodeType":867},{},[],"milosh-solibella-0dcio[.]sgttommy.workers.dev",{"data":17378,"content":17382,"nodeType":890},{"target":17379},{"sys":17380},{"id":17381,"type":887,"linkType":888},"6szO6IKJ32usyxIKX1efZy",[],{"data":17384,"content":17388,"nodeType":890},{"target":17385},{"sys":17386},{"id":17387,"type":887,"linkType":888},"lEqV3RTMIY8y011lnhX7P",[],{"data":17390,"content":17391,"nodeType":908},{},[],{"data":17393,"content":17394,"nodeType":998},{},[17395],{"data":17396,"marks":17397,"value":17399,"nodeType":867},{},[17398],{"type":916},"“DOCUPOLL”",{"data":17401,"content":17402,"nodeType":2531},{},[17403,17426,17464,17501,17524],{"data":17404,"content":17405,"nodeType":2438},{},[17406,17416],{"data":17407,"content":17408,"nodeType":2452},{},[17409],{"data":17410,"content":17411,"nodeType":881},{},[17412],{"data":17413,"marks":17414,"value":16465,"nodeType":867},{},[17415],{"type":916},{"data":17417,"content":17418,"nodeType":2452},{},[17419],{"data":17420,"content":17421,"nodeType":881},{},[17422],{"data":17423,"marks":17424,"value":17425,"nodeType":867},{},[],"Github.io and workers.dev hosting",{"data":17427,"content":17428,"nodeType":2438},{},[17429,17439],{"data":17430,"content":17431,"nodeType":2452},{},[17432],{"data":17433,"content":17434,"nodeType":881},{},[17435],{"data":17436,"marks":17437,"value":16489,"nodeType":867},{},[17438],{"type":916},{"data":17440,"content":17441,"nodeType":2452},{},[17442,17453],{"data":17443,"content":17444,"nodeType":881},{},[17445,17449],{"data":17446,"marks":17447,"value":16964,"nodeType":867},{},[17448],{"type":916},{"data":17450,"marks":17451,"value":17452,"nodeType":867},{},[],"144.172.103.240 (FranTech Solutions / RouterHosting / Cloudzy AS14956)",{"data":17454,"content":17455,"nodeType":881},{},[17456,17460],{"data":17457,"marks":17458,"value":16530,"nodeType":867},{},[17459],{"type":916},{"data":17461,"marks":17462,"value":17463,"nodeType":867},{},[]," Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.102 Safari/537.36 Edge/18.19042",{"data":17465,"content":17466,"nodeType":2438},{},[17467,17477],{"data":17468,"content":17469,"nodeType":2452},{},[17470],{"data":17471,"content":17472,"nodeType":881},{},[17473],{"data":17474,"marks":17475,"value":16572,"nodeType":867},{},[17476],{"type":916},{"data":17478,"content":17479,"nodeType":2452},{},[17480,17487,17494],{"data":17481,"content":17482,"nodeType":881},{},[17483],{"data":17484,"marks":17485,"value":17486,"nodeType":867},{},[],"POST /api/v1/landing-pages/public/{slug}/init",{"data":17488,"content":17489,"nodeType":881},{},[17490],{"data":17491,"marks":17492,"value":17493,"nodeType":867},{},[],"POST .../poll",{"data":17495,"content":17496,"nodeType":881},{},[17497],{"data":17498,"marks":17499,"value":17500,"nodeType":867},{},[],"POST .../track",{"data":17502,"content":17503,"nodeType":2438},{},[17504,17514],{"data":17505,"content":17506,"nodeType":2452},{},[17507],{"data":17508,"content":17509,"nodeType":881},{},[17510],{"data":17511,"marks":17512,"value":16624,"nodeType":867},{},[17513],{"type":916},{"data":17515,"content":17516,"nodeType":2452},{},[17517],{"data":17518,"content":17519,"nodeType":881},{},[17520],{"data":17521,"marks":17522,"value":17523,"nodeType":867},{},[],"DocuSign document signing. One sample is a full scrape of real docusign.com (free-account page) with kit injected.",{"data":17525,"content":17526,"nodeType":2438},{},[17527,17537],{"data":17528,"content":17529,"nodeType":2452},{},[17530],{"data":17531,"content":17532,"nodeType":881},{},[17533],{"data":17534,"marks":17535,"value":16847,"nodeType":867},{},[17536],{"type":916},{"data":17538,"content":17539,"nodeType":2452},{},[17540],{"data":17541,"content":17542,"nodeType":881},{},[17543],{"data":17544,"marks":17545,"value":17546,"nodeType":867},{},[],"docufirmar[.]github.io",{"data":17548,"content":17552,"nodeType":890},{"target":17549},{"sys":17550},{"id":17551,"type":887,"linkType":888},"6Y1XABHnQD82R3MW80HnQZ",[],{"data":17554,"content":17555,"nodeType":908},{},[],{"data":17557,"content":17558,"nodeType":998},{},[17559],{"data":17560,"marks":17561,"value":17563,"nodeType":867},{},[17562],{"type":916},"“FLOW_TOKEN”",{"data":17565,"content":17566,"nodeType":2531},{},[17567,17589,17634,17664,17687],{"data":17568,"content":17569,"nodeType":2438},{},[17570,17580],{"data":17571,"content":17572,"nodeType":2452},{},[17573],{"data":17574,"content":17575,"nodeType":881},{},[17576],{"data":17577,"marks":17578,"value":16465,"nodeType":867},{},[17579],{"type":916},{"data":17581,"content":17582,"nodeType":2452},{},[17583],{"data":17584,"content":17585,"nodeType":881},{},[17586],{"data":17587,"marks":17588,"value":17261,"nodeType":867},{},[],{"data":17590,"content":17591,"nodeType":2438},{},[17592,17602],{"data":17593,"content":17594,"nodeType":2452},{},[17595],{"data":17596,"content":17597,"nodeType":881},{},[17598],{"data":17599,"marks":17600,"value":16489,"nodeType":867},{},[17601],{"type":916},{"data":17603,"content":17604,"nodeType":2452},{},[17605,17616],{"data":17606,"content":17607,"nodeType":881},{},[17608,17612],{"data":17609,"marks":17610,"value":16964,"nodeType":867},{},[17611],{"type":916},{"data":17613,"marks":17614,"value":17615,"nodeType":867},{},[],"43.166.163.163 (Tencent Cloud AS132203)",{"data":17617,"content":17618,"nodeType":881},{},[17619,17623,17626,17630],{"data":17620,"marks":17621,"value":16530,"nodeType":867},{},[17622],{"type":916},{"data":17624,"marks":17625,"value":3679,"nodeType":867},{},[],{"data":17627,"marks":17628,"value":17303,"nodeType":867},{},[17629],{"type":916},{"data":17631,"marks":17632,"value":17633,"nodeType":867},{},[],"(null)",{"data":17635,"content":17636,"nodeType":2438},{},[17637,17647],{"data":17638,"content":17639,"nodeType":2452},{},[17640],{"data":17641,"content":17642,"nodeType":881},{},[17643],{"data":17644,"marks":17645,"value":16572,"nodeType":867},{},[17646],{"type":916},{"data":17648,"content":17649,"nodeType":2452},{},[17650,17657],{"data":17651,"content":17652,"nodeType":881},{},[17653],{"data":17654,"marks":17655,"value":17656,"nodeType":867},{},[],"POST /api/handler.php ",{"data":17658,"content":17659,"nodeType":881},{},[17660],{"data":17661,"marks":17662,"value":17663,"nodeType":867},{},[],"(actions: device_code_generate, device_code_poll_public)",{"data":17665,"content":17666,"nodeType":2438},{},[17667,17677],{"data":17668,"content":17669,"nodeType":2452},{},[17670],{"data":17671,"content":17672,"nodeType":881},{},[17673],{"data":17674,"marks":17675,"value":16624,"nodeType":867},{},[17676],{"type":916},{"data":17678,"content":17679,"nodeType":2452},{},[17680],{"data":17681,"content":17682,"nodeType":881},{},[17683],{"data":17684,"marks":17685,"value":17686,"nodeType":867},{},[],"DocuSign \"Salary Adjustment Document — 2026\", Microsoft banner · HR Department sender",{"data":17688,"content":17689,"nodeType":2438},{},[17690,17700],{"data":17691,"content":17692,"nodeType":2452},{},[17693],{"data":17694,"content":17695,"nodeType":881},{},[17696],{"data":17697,"marks":17698,"value":16847,"nodeType":867},{},[17699],{"type":916},{"data":17701,"content":17702,"nodeType":2452},{},[17703],{"data":17704,"content":17705,"nodeType":881},{},[17706],{"data":17707,"marks":17708,"value":17709,"nodeType":867},{},[],"salaryadjustment-2afb52.pmb6fefc52b3f9aa5c2dbf[.]workers.dev",{"data":17711,"content":17715,"nodeType":890},{"target":17712},{"sys":17713},{"id":17714,"type":887,"linkType":888},"6xiTDHStbiJh7LMhjAZcPd",[],{"data":17717,"content":17718,"nodeType":908},{},[],{"data":17720,"content":17721,"nodeType":998},{},[17722],{"data":17723,"marks":17724,"value":17726,"nodeType":867},{},[17725],{"type":916},"“PAPRIKA”",{"data":17728,"content":17729,"nodeType":2531},{},[17730,17753,17776,17799],{"data":17731,"content":17732,"nodeType":2438},{},[17733,17743],{"data":17734,"content":17735,"nodeType":2452},{},[17736],{"data":17737,"content":17738,"nodeType":881},{},[17739],{"data":17740,"marks":17741,"value":16465,"nodeType":867},{},[17742],{"type":916},{"data":17744,"content":17745,"nodeType":2452},{},[17746],{"data":17747,"content":17748,"nodeType":881},{},[17749],{"data":17750,"marks":17751,"value":17752,"nodeType":867},{},[],"AWS S3 hosting",{"data":17754,"content":17755,"nodeType":2438},{},[17756,17766],{"data":17757,"content":17758,"nodeType":2452},{},[17759],{"data":17760,"content":17761,"nodeType":881},{},[17762],{"data":17763,"marks":17764,"value":16572,"nodeType":867},{},[17765],{"type":916},{"data":17767,"content":17768,"nodeType":2452},{},[17769],{"data":17770,"content":17771,"nodeType":881},{},[17772],{"data":17773,"marks":17774,"value":17775,"nodeType":867},{},[],"POST /api/v1/loader",{"data":17777,"content":17778,"nodeType":2438},{},[17779,17789],{"data":17780,"content":17781,"nodeType":2452},{},[17782],{"data":17783,"content":17784,"nodeType":881},{},[17785],{"data":17786,"marks":17787,"value":16624,"nodeType":867},{},[17788],{"type":916},{"data":17790,"content":17791,"nodeType":2452},{},[17792],{"data":17793,"content":17794,"nodeType":881},{},[17795],{"data":17796,"marks":17797,"value":17798,"nodeType":867},{},[],"MS login clone (\"Sign in to your account\"), \"Office 365\" branding, fake \"Powered by Okta\" footer",{"data":17800,"content":17801,"nodeType":2438},{},[17802,17812],{"data":17803,"content":17804,"nodeType":2452},{},[17805],{"data":17806,"content":17807,"nodeType":881},{},[17808],{"data":17809,"marks":17810,"value":16847,"nodeType":867},{},[17811],{"type":916},{"data":17813,"content":17814,"nodeType":2452},{},[17815],{"data":17816,"content":17817,"nodeType":881},{},[17818],{"data":17819,"marks":17820,"value":17821,"nodeType":867},{},[],"redirect-523346-d95027ec[.]s3.amazonaws.com",{"data":17823,"content":17827,"nodeType":890},{"target":17824},{"sys":17825},{"id":17826,"type":887,"linkType":888},"6WFXqUDzcJHKWSwVIcDZAf",[],{"data":17829,"content":17830,"nodeType":908},{},[],{"data":17832,"content":17833,"nodeType":998},{},[17834],{"data":17835,"marks":17836,"value":17838,"nodeType":867},{},[17837],{"type":916},"“DCSTATUS”",{"data":17840,"content":17841,"nodeType":2531},{},[17842,17864,17887,17910],{"data":17843,"content":17844,"nodeType":2438},{},[17845,17855],{"data":17846,"content":17847,"nodeType":2452},{},[17848],{"data":17849,"content":17850,"nodeType":881},{},[17851],{"data":17852,"marks":17853,"value":16465,"nodeType":867},{},[17854],{"type":916},{"data":17856,"content":17857,"nodeType":2452},{},[17858],{"data":17859,"content":17860,"nodeType":881},{},[17861],{"data":17862,"marks":17863,"value":16748,"nodeType":867},{},[],{"data":17865,"content":17866,"nodeType":2438},{},[17867,17877],{"data":17868,"content":17869,"nodeType":2452},{},[17870],{"data":17871,"content":17872,"nodeType":881},{},[17873],{"data":17874,"marks":17875,"value":16572,"nodeType":867},{},[17876],{"type":916},{"data":17878,"content":17879,"nodeType":2452},{},[17880],{"data":17881,"content":17882,"nodeType":881},{},[17883],{"data":17884,"marks":17885,"value":17886,"nodeType":867},{},[],"GET /dc/status/{base64url_sid}",{"data":17888,"content":17889,"nodeType":2438},{},[17890,17900],{"data":17891,"content":17892,"nodeType":2452},{},[17893],{"data":17894,"content":17895,"nodeType":881},{},[17896],{"data":17897,"marks":17898,"value":16624,"nodeType":867},{},[17899],{"type":916},{"data":17901,"content":17902,"nodeType":2452},{},[17903],{"data":17904,"content":17905,"nodeType":881},{},[17906],{"data":17907,"marks":17908,"value":17909,"nodeType":867},{},[],"Generic \"Microsoft 365 - Secure Access\" verification page",{"data":17911,"content":17912,"nodeType":2438},{},[17913,17923],{"data":17914,"content":17915,"nodeType":2452},{},[17916],{"data":17917,"content":17918,"nodeType":881},{},[17919],{"data":17920,"marks":17921,"value":16847,"nodeType":867},{},[17922],{"type":916},{"data":17924,"content":17925,"nodeType":2452},{},[17926],{"data":17927,"content":17928,"nodeType":881},{},[17929],{"data":17930,"marks":17931,"value":17932,"nodeType":867},{},[],"owa[.]apmmacleans[.]ca",{"data":17934,"content":17938,"nodeType":890},{"target":17935},{"sys":17936},{"id":17937,"type":887,"linkType":888},"ugYhHeXY1lQdKooALmrIs",[],{"data":17940,"content":17941,"nodeType":908},{},[],{"data":17943,"content":17944,"nodeType":998},{},[17945],{"data":17946,"marks":17947,"value":17949,"nodeType":867},{},[17948],{"type":916},"“DOLCE”",{"data":17951,"content":17955,"nodeType":890},{"target":17952},{"sys":17953},{"id":17954,"type":887,"linkType":888},"7TzU6kk01Un45NB0buEz2",[],{"data":17957,"content":17958,"nodeType":2531},{},[17959,17982,18020,18043,18066],{"data":17960,"content":17961,"nodeType":2438},{},[17962,17972],{"data":17963,"content":17964,"nodeType":2452},{},[17965],{"data":17966,"content":17967,"nodeType":881},{},[17968],{"data":17969,"marks":17970,"value":16465,"nodeType":867},{},[17971],{"type":916},{"data":17973,"content":17974,"nodeType":2452},{},[17975],{"data":17976,"content":17977,"nodeType":881},{},[17978],{"data":17979,"marks":17980,"value":17981,"nodeType":867},{},[],"Microsoft PowerApps hosting",{"data":17983,"content":17984,"nodeType":2438},{},[17985,17995],{"data":17986,"content":17987,"nodeType":2452},{},[17988],{"data":17989,"content":17990,"nodeType":881},{},[17991],{"data":17992,"marks":17993,"value":16489,"nodeType":867},{},[17994],{"type":916},{"data":17996,"content":17997,"nodeType":2452},{},[17998,18009],{"data":17999,"content":18000,"nodeType":881},{},[18001,18005],{"data":18002,"marks":18003,"value":16964,"nodeType":867},{},[18004],{"type":916},{"data":18006,"marks":18007,"value":18008,"nodeType":867},{},[],"34.53.159.84 (Google Cloud AS396982)",{"data":18010,"content":18011,"nodeType":881},{},[18012,18016],{"data":18013,"marks":18014,"value":16530,"nodeType":867},{},[18015],{"type":916},{"data":18017,"marks":18018,"value":18019,"nodeType":867},{},[]," Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/123.0.0.0 Safari/537.36",{"data":18021,"content":18022,"nodeType":2438},{},[18023,18033],{"data":18024,"content":18025,"nodeType":2452},{},[18026],{"data":18027,"content":18028,"nodeType":881},{},[18029],{"data":18030,"marks":18031,"value":16572,"nodeType":867},{},[18032],{"type":916},{"data":18034,"content":18035,"nodeType":2452},{},[18036],{"data":18037,"content":18038,"nodeType":881},{},[18039],{"data":18040,"marks":18041,"value":18042,"nodeType":867},{},[],"GET /api/generatecode (CloudFront)",{"data":18044,"content":18045,"nodeType":2438},{},[18046,18056],{"data":18047,"content":18048,"nodeType":2452},{},[18049],{"data":18050,"content":18051,"nodeType":881},{},[18052],{"data":18053,"marks":18054,"value":16624,"nodeType":867},{},[18055],{"type":916},{"data":18057,"content":18058,"nodeType":2452},{},[18059],{"data":18060,"content":18061,"nodeType":881},{},[18062],{"data":18063,"marks":18064,"value":18065,"nodeType":867},{},[],"Dolce & Gabbana branded, Italian language, MS account verification",{"data":18067,"content":18068,"nodeType":2438},{},[18069,18079],{"data":18070,"content":18071,"nodeType":2452},{},[18072],{"data":18073,"content":18074,"nodeType":881},{},[18075],{"data":18076,"marks":18077,"value":16847,"nodeType":867},{},[18078],{"type":916},{"data":18080,"content":18081,"nodeType":2452},{},[18082],{"data":18083,"content":18084,"nodeType":881},{},[18085],{"data":18086,"marks":18087,"value":18088,"nodeType":867},{},[],"data-migration-dolcegabbana[.]powerappsportals.com",{"data":18090,"content":18094,"nodeType":890},{"target":18091},{"sys":18092},{"id":18093,"type":887,"linkType":888},"4ayQDvpf5NNOBrj9wZZRiO",[],{"data":18096,"content":18097,"nodeType":908},{},[],{"data":18099,"content":18100,"nodeType":998},{},[18101],{"data":18102,"marks":18103,"value":18105,"nodeType":867},{},[18104],{"type":916},"Venom",{"data":18107,"content":18108,"nodeType":2531},{},[18109,18132],{"data":18110,"content":18111,"nodeType":2438},{},[18112,18122],{"data":18113,"content":18114,"nodeType":2452},{},[18115],{"data":18116,"content":18117,"nodeType":881},{},[18118],{"data":18119,"marks":18120,"value":16572,"nodeType":867},{},[18121],{"type":916},{"data":18123,"content":18124,"nodeType":2452},{},[18125],{"data":18126,"content":18127,"nodeType":881},{},[18128],{"data":18129,"marks":18130,"value":18131,"nodeType":867},{},[],"POST /token/api/device/start\nGET /token/api/device/status/{sessionId}",{"data":18133,"content":18134,"nodeType":2438},{},[18135,18145],{"data":18136,"content":18137,"nodeType":2452},{},[18138],{"data":18139,"content":18140,"nodeType":881},{},[18141],{"data":18142,"marks":18143,"value":16624,"nodeType":867},{},[18144],{"type":916},{"data":18146,"content":18147,"nodeType":2452},{},[18148],{"data":18149,"content":18150,"nodeType":881},{},[18151],{"data":18152,"marks":18153,"value":18154,"nodeType":867},{},[],"Various: examples include DocuSign \"Verification\" (Microsoft sign-in pretext); DHL \"Delivery Checkpoint\" package shipment pretext",{"data":18156,"content":18160,"nodeType":890},{"target":18157},{"sys":18158},{"id":18159,"type":887,"linkType":888},"79C3fces0hgTdf3G68cIrf",[],{"data":18162,"content":18163,"nodeType":908},{},[],{"data":18165,"content":18166,"nodeType":998},{},[18167],{"data":18168,"marks":18169,"value":18171,"nodeType":867},{},[18170],{"type":916},"Tycoon2FA",{"data":18173,"content":18174,"nodeType":2531},{},[18175,18205,18242,18265,18288],{"data":18176,"content":18177,"nodeType":2438},{},[18178,18188],{"data":18179,"content":18180,"nodeType":2452},{},[18181],{"data":18182,"content":18183,"nodeType":881},{},[18184],{"data":18185,"marks":18186,"value":16465,"nodeType":867},{},[18187],{"type":916},{"data":18189,"content":18190,"nodeType":2452},{},[18191,18198],{"data":18192,"content":18193,"nodeType":881},{},[18194],{"data":18195,"marks":18196,"value":18197,"nodeType":867},{},[],"Github.io and Cloudflare Workers (workers.dev) hosting",{"data":18199,"content":18200,"nodeType":881},{},[18201],{"data":18202,"marks":18203,"value":18204,"nodeType":867},{},[],"Compromised-site landing pages and CF Workers (*.workers.dev) used as frontends; victim email passed in URL as last path segment ($base64) or ?acct/?encoded query",{"data":18206,"content":18207,"nodeType":2438},{},[18208,18218],{"data":18209,"content":18210,"nodeType":2452},{},[18211],{"data":18212,"content":18213,"nodeType":881},{},[18214],{"data":18215,"marks":18216,"value":16489,"nodeType":867},{},[18217],{"type":916},{"data":18219,"content":18220,"nodeType":2452},{},[18221,18232],{"data":18222,"content":18223,"nodeType":881},{},[18224,18228],{"data":18225,"marks":18226,"value":16964,"nodeType":867},{},[18227],{"type":916},{"data":18229,"marks":18230,"value":18231,"nodeType":867},{},[],"47.253.5.88 (Alibaba Cloud)",{"data":18233,"content":18234,"nodeType":881},{},[18235,18239],{"data":18236,"marks":18237,"value":16530,"nodeType":867},{},[18238],{"type":916},{"data":18240,"marks":18241,"value":16787,"nodeType":867},{},[],{"data":18243,"content":18244,"nodeType":2438},{},[18245,18255],{"data":18246,"content":18247,"nodeType":2452},{},[18248],{"data":18249,"content":18250,"nodeType":881},{},[18251],{"data":18252,"marks":18253,"value":16572,"nodeType":867},{},[18254],{"type":916},{"data":18256,"content":18257,"nodeType":2452},{},[18258],{"data":18259,"content":18260,"nodeType":881},{},[18261],{"data":18262,"marks":18263,"value":18264,"nodeType":867},{},[],"GET /api/session/{UUIDv4} polled with header X-API-Key: \u003Cprefix>_\u003C64-hex> (key materialised at runtime via atob(window.__cyb3r.k)) \nPOST /api/device-code with body {\"prt_foci_session_id\": \"\u003CUUID>\"} (second-stage code retrieval after initial session error)",{"data":18266,"content":18267,"nodeType":2438},{},[18268,18278],{"data":18269,"content":18270,"nodeType":2452},{},[18271],{"data":18272,"content":18273,"nodeType":881},{},[18274],{"data":18275,"marks":18276,"value":16624,"nodeType":867},{},[18277],{"type":916},{"data":18279,"content":18280,"nodeType":2452},{},[18281],{"data":18282,"content":18283,"nodeType":881},{},[18284],{"data":18285,"marks":18286,"value":18287,"nodeType":867},{},[],"Various: SharePoint \"Remittance Advice\"; Microsoft 365 generic sign-in; Microsoft 365 Voicemail (.mp3 attachment); OneDrive \"Shared file\"; German \"Sicheres Dokumentenportal\" PDF lure",{"data":18289,"content":18290,"nodeType":2438},{},[18291,18301],{"data":18292,"content":18293,"nodeType":2452},{},[18294],{"data":18295,"content":18296,"nodeType":881},{},[18297],{"data":18298,"marks":18299,"value":16847,"nodeType":867},{},[18300],{"type":916},{"data":18302,"content":18303,"nodeType":2452},{},[18304],{"data":18305,"content":18306,"nodeType":881},{},[18307],{"data":18308,"marks":18309,"value":18310,"nodeType":867},{},[],"afriqbeauglobal[.]com/homepage/index[.]html",{"data":18312,"content":18315,"nodeType":890},{"target":18313},{"sys":18314},{"id":1178,"type":887,"linkType":888},[],{"data":18317,"content":18318,"nodeType":908},{},[],{"data":18320,"content":18321,"nodeType":998},{},[18322],{"data":18323,"marks":18324,"value":18326,"nodeType":867},{},[18325],{"type":916},"\"CYB3R\"",{"data":18328,"content":18329,"nodeType":2531},{},[18330,18353,18391,18413,18436],{"data":18331,"content":18332,"nodeType":2438},{},[18333,18343],{"data":18334,"content":18335,"nodeType":2452},{},[18336],{"data":18337,"content":18338,"nodeType":881},{},[18339],{"data":18340,"marks":18341,"value":16465,"nodeType":867},{},[18342],{"type":916},{"data":18344,"content":18345,"nodeType":2452},{},[18346],{"data":18347,"content":18348,"nodeType":881},{},[18349],{"data":18350,"marks":18351,"value":18352,"nodeType":867},{},[],"Cloudflare Workers (workers.dev) hosting",{"data":18354,"content":18355,"nodeType":2438},{},[18356,18366],{"data":18357,"content":18358,"nodeType":2452},{},[18359],{"data":18360,"content":18361,"nodeType":881},{},[18362],{"data":18363,"marks":18364,"value":16489,"nodeType":867},{},[18365],{"type":916},{"data":18367,"content":18368,"nodeType":2452},{},[18369,18380],{"data":18370,"content":18371,"nodeType":881},{},[18372,18376],{"data":18373,"marks":18374,"value":16964,"nodeType":867},{},[18375],{"type":916},{"data":18377,"marks":18378,"value":18379,"nodeType":867},{},[],"2400:8d60:2::1:c116:843e (Evoxt VPS)",{"data":18381,"content":18382,"nodeType":881},{},[18383,18387],{"data":18384,"marks":18385,"value":16530,"nodeType":867},{},[18386],{"type":916},{"data":18388,"marks":18389,"value":18390,"nodeType":867},{},[]," axios/1.13.6",{"data":18392,"content":18393,"nodeType":2438},{},[18394,18404],{"data":18395,"content":18396,"nodeType":2452},{},[18397],{"data":18398,"content":18399,"nodeType":881},{},[18400],{"data":18401,"marks":18402,"value":16572,"nodeType":867},{},[18403],{"type":916},{"data":18405,"content":18406,"nodeType":2452},{},[18407],{"data":18408,"content":18409,"nodeType":881},{},[18410],{"data":18411,"marks":18412,"value":18264,"nodeType":867},{},[],{"data":18414,"content":18415,"nodeType":2438},{},[18416,18426],{"data":18417,"content":18418,"nodeType":2452},{},[18419],{"data":18420,"content":18421,"nodeType":881},{},[18422],{"data":18423,"marks":18424,"value":16624,"nodeType":867},{},[18425],{"type":916},{"data":18427,"content":18428,"nodeType":2452},{},[18429],{"data":18430,"content":18431,"nodeType":881},{},[18432],{"data":18433,"marks":18434,"value":18435,"nodeType":867},{},[],"DocuSign in Spanish (\"Documento Firmar — COTIZACIÓN/ESTIMACIÓN.pdf\", \"Complete su firma\", \"Verifique su identidad\", \"Continuar a Microsoft\").",{"data":18437,"content":18438,"nodeType":2438},{},[18439,18449],{"data":18440,"content":18441,"nodeType":2452},{},[18442],{"data":18443,"content":18444,"nodeType":881},{},[18445],{"data":18446,"marks":18447,"value":16847,"nodeType":867},{},[18448],{"type":916},{"data":18450,"content":18451,"nodeType":2452},{},[18452],{"data":18453,"content":18454,"nodeType":881},{},[18455],{"data":18456,"marks":18457,"value":18458,"nodeType":867},{},[],"muzagestion[.]secure-share[.]workers.dev",{"data":18460,"content":18464,"nodeType":890},{"target":18461},{"sys":18462},{"id":18463,"type":887,"linkType":888},"5EU0QNteiQcYybKG1W1cS3",[],{"data":18466,"content":18467,"nodeType":908},{},[],{"data":18469,"content":18470,"nodeType":918},{},[18471],{"data":18472,"marks":18473,"value":18475,"nodeType":867},{},[18474],{"type":916},"Device code phishing under the hood",{"data":18477,"content":18478,"nodeType":881},{},[18479,18483],{"data":18480,"marks":18481,"value":18482,"nodeType":867},{},[],"The attacker POSTs to the authorization server's device authorization endpoint with its client_id (i.e. an application ID) and requested scopes or resources. The server responds with a device_code (used for polling), a user_code, a verification_uri, an expires_in value, and a polling interval. The user visits the URL, enters the code and approves the request. Meanwhile, the device polls the token endpoint. Once approved, the server returns an access token, a refresh token (if offline_access was requested), and an ID token (if openid was included). ",{"data":18484,"marks":18485,"value":18487,"nodeType":867},{},[18486],{"type":916},"The attacker now has API access to the victim's account. ",{"data":18489,"content":18490,"nodeType":881},{},[18491],{"data":18492,"marks":18493,"value":18494,"nodeType":867},{},[],"Broadly, this gives the attacker a comparable level of control to a “normal” phishing attack (with conditions based on the scopes granted and specific app being targeted) while API access grants additional capabilities beyond standard browser sessions. When combined with other techniques, this access can be exchanged to open normal browser app sessions and access SSO connected apps.",{"data":18496,"content":18500,"nodeType":890},{"target":18497},{"sys":18498},{"id":18499,"type":887,"linkType":888},"4WtQR2xsE236yoyhSXj58Z",[],{"data":18502,"content":18506,"nodeType":890},{"target":18503},{"sys":18504},{"id":18505,"type":887,"linkType":888},"1x7Lip7JdY2xlHKKurT7qJ",[],{"data":18508,"content":18509,"nodeType":881},{},[18510],{"data":18511,"marks":18512,"value":18513,"nodeType":867},{},[],"At this point, you can achieve a number of objectives both inside the app ecosystem and across SSO connected apps — e.g. data theft, disruption, and ultimately extortion.",{"data":18515,"content":18516,"nodeType":881},{},[18517,18521,18526,18530],{"data":18518,"marks":18519,"value":18520,"nodeType":867},{},[],"Critically, the initial request to generate a device code is typically ",{"data":18522,"marks":18523,"value":18525,"nodeType":867},{},[18524],{"type":916},"unauthenticated",{"data":18527,"marks":18528,"value":18529,"nodeType":867},{},[]," across all providers — ",{"data":18531,"marks":18532,"value":18534,"nodeType":867},{},[18533],{"type":916},"anyone can generate one, from any machine, without proving any relationship to the target organization.",{"data":18536,"content":18537,"nodeType":881},{},[18538,18542,18547],{"data":18539,"marks":18540,"value":18541,"nodeType":867},{},[],"So, the attacker has to deliver a set of instructions via a phishing channel (e.g. email, social media DM, corp IM platform, and so on) with a device code that they have generated. The victim then enters this code on the ",{"data":18543,"marks":18544,"value":18546,"nodeType":867},{},[18545],{"type":916},"legitimate device code login page",{"data":18548,"marks":18549,"value":18550,"nodeType":867},{},[]," for that app and issues the tokens to the attacker.",{"data":18552,"content":18556,"nodeType":890},{"target":18553},{"sys":18554},{"id":18555,"type":887,"linkType":888},"1txUYuQjH9FlbDGTo8AbZB",[],{"data":18558,"content":18559,"nodeType":908},{},[],{"data":18561,"content":18562,"nodeType":918},{},[18563],{"data":18564,"marks":18565,"value":18567,"nodeType":867},{},[18566],{"type":916},"Why device code phishing is so dangerous",{"data":18569,"content":18570,"nodeType":998},{},[18571],{"data":18572,"marks":18573,"value":18575,"nodeType":867},{},[18574],{"type":916},"Device code phishing bypasses authentication controls (including passkeys)",{"data":18577,"content":18578,"nodeType":881},{},[18579,18583,18588,18592],{"data":18580,"marks":18581,"value":18582,"nodeType":867},{},[],"A device code phishing attack ",{"data":18584,"marks":18585,"value":18587,"nodeType":867},{},[18586],{"type":916},"cannot be prevented with authentication controls",{"data":18589,"marks":18590,"value":18591,"nodeType":867},{},[],". This includes all forms of MFA and ",{"data":18593,"marks":18594,"value":18596,"nodeType":867},{},[18595],{"type":916},"even “phishing-resistant” authentication methods such as passkeys. ",{"data":18598,"content":18599,"nodeType":881},{},[18600,18605,18609,18614],{"data":18601,"marks":18602,"value":18604,"nodeType":867},{},[18603],{"type":916},"The device code authorization is effectively performed post-authentication. ",{"data":18606,"marks":18607,"value":18608,"nodeType":867},{},[],"If you already have an active session in your browser, entering the device code and selecting your account from a drop-down menu is all that's needed. ",{"data":18610,"marks":18611,"value":18613,"nodeType":867},{},[18612],{"type":916},"No password or MFA required. ",{"data":18615,"marks":18616,"value":18617,"nodeType":867},{},[],"You can see an example in the video below.",{"data":18619,"content":18622,"nodeType":890},{"target":18620},{"sys":18621},{"id":17551,"type":887,"linkType":888},[],{"data":18624,"content":18625,"nodeType":881},{},[18626],{"data":18627,"marks":18628,"value":18629,"nodeType":867},{},[],"Even if you do have to sign in again (because you're not already signed in for some reason), the attack still works because it isn't targeting the login — it's targeting the authorization layer instead.",{"data":18631,"content":18632,"nodeType":881},{},[18633],{"data":18634,"marks":18635,"value":18636,"nodeType":867},{},[],"This is what makes device code phishing different to other standard phishing methods like AiTM phishing (and arguably even more effective in environments with strict identity control enforcement). ",{"data":18638,"content":18639,"nodeType":998},{},[18640],{"data":18641,"marks":18642,"value":18644,"nodeType":867},{},[18643],{"type":916},"Device code logins are a feature, not a vulnerability, making attacks difficult to block",{"data":18646,"content":18647,"nodeType":881},{},[18648],{"data":18649,"marks":18650,"value":18651,"nodeType":867},{},[],"Device code authorization is a legitimate mechanism regularly used in enterprise environments, particularly for CLI logins. Tools like Azure CLI, GitHub CLI, and AWS CLI all use (or have used) the device code flow as a primary or fallback authentication method. This creates a dual problem for defenders. ",{"data":18653,"content":18654,"nodeType":881},{},[18655],{"data":18656,"marks":18657,"value":18658,"nodeType":867},{},[],"First, the phishing attack happens entirely on a legitimate site — there's no fake login page, no malicious payload to scan for, and the URL in the browser is genuine. Since there's no traditional phishing content being delivered, these attacks are more resistant to detection by email and network security tools.",{"data":18660,"content":18661,"nodeType":881},{},[18662],{"data":18663,"marks":18664,"value":18665,"nodeType":867},{},[],"Second, the widespread legitimate use of device code flow — particularly among developers and technical users — normalizes the experience of entering device codes. A phishing lure asking them to do the same thing is indistinguishable from a legitimate IT request. And for non-technical users, this experience isn't much different to, for example, entering a code sent via email or authenticator app. ",{"data":18667,"content":18668,"nodeType":998},{},[18669],{"data":18670,"marks":18671,"value":18673,"nodeType":867},{},[18672],{"type":916},"Multiple apps are vulnerable, with different risk profiles",{"data":18675,"content":18676,"nodeType":881},{},[18677],{"data":18678,"marks":18679,"value":18680,"nodeType":867},{},[],"Various apps implement the device code flow, each with different levels of control and default security, but the risk is not uniform across platforms. ",{"data":18682,"content":18683,"nodeType":3126},{},[18684,18699,18713],{"data":18685,"content":18686,"nodeType":3061},{},[18687],{"data":18688,"content":18689,"nodeType":881},{},[18690,18695],{"data":18691,"marks":18692,"value":18694,"nodeType":867},{},[18693],{"type":916},"Google Workspace ",{"data":18696,"marks":18697,"value":18698,"nodeType":867},{},[],"is a significantly lower-risk target because Google explicitly limits which scopes are available to the device code flow — Gmail, Calendar, and most Workspace APIs are simply unavailable through this mechanism. ",{"data":18700,"content":18701,"nodeType":3061},{},[18702],{"data":18703,"content":18704,"nodeType":881},{},[18705,18709],{"data":18706,"marks":18707,"value":15009,"nodeType":867},{},[18708],{"type":916},{"data":18710,"marks":18711,"value":18712,"nodeType":867},{},[]," offers the broadest attack surface due to unrestricted scopes, reusable first-party client IDs, and the FOCI/PRT escalation paths. ",{"data":18714,"content":18715,"nodeType":3061},{},[18716],{"data":18717,"content":18718,"nodeType":881},{},[18719,18723,18727],{"data":18720,"marks":18721,"value":18722,"nodeType":867},{},[],"Apps like ",{"data":18724,"marks":18725,"value":3241,"nodeType":867},{},[18726],{"type":916},{"data":18728,"marks":18729,"value":18730,"nodeType":867},{},[]," sit in between — broad scopes are available (including full repository access), but the attacker must control their own OAuth app and the victim sees an explicit consent screen. ",{"data":18732,"content":18736,"nodeType":890},{"target":18733},{"sys":18734},{"id":18735,"type":887,"linkType":888},"ejNSC76jge1p1zzz9wwiG",[],{"data":18738,"content":18739,"nodeType":908},{},[],{"data":18741,"content":18742,"nodeType":918},{},[18743],{"data":18744,"marks":18745,"value":14065,"nodeType":867},{},[18746],{"type":916},{"data":18748,"content":18749,"nodeType":881},{},[18750],{"data":18751,"marks":18752,"value":18753,"nodeType":867},{},[],"Security teams need to consider the risk posed by device code phishing across multiple apps where device code authorization grants are common, particularly for developers and technical users. ",{"data":18755,"content":18756,"nodeType":881},{},[18757],{"data":18758,"marks":18759,"value":18760,"nodeType":867},{},[],"In an ideal world, you would simply block device code logins. But this can’t be done without causing serious disruption in some environments, while some apps simply don’t provide the tools required to do so. For example, device code is the default CLI sign-in method for GitHub. Developer-heavy organizations are likely to encounter higher levels of legitimate use.",{"data":18762,"content":18763,"nodeType":881},{},[18764,18768,18776,18780,18785,18789,18794,18798,18803],{"data":18765,"marks":18766,"value":18767,"nodeType":867},{},[],"Microsoft arguably offers the strongest control options (other than Google, who negate it right out of the gate), though they do require a fair amount of work. ",{"data":18769,"content":18770,"nodeType":876},{"uri":14090},[18771],{"data":18772,"marks":18773,"value":18775,"nodeType":867},{},[18774],{"type":1040},"Microsoft now explicitly recommends",{"data":18777,"marks":18778,"value":18779,"nodeType":867},{},[]," blocking device code flow for tenants that haven't used it in the past 25 days. Their guidance is to create a custom CA policy: target relevant users, set the ",{"data":18781,"marks":18782,"value":18784,"nodeType":867},{},[18783],{"type":916},"Authentication Flows",{"data":18786,"marks":18787,"value":18788,"nodeType":867},{},[]," condition to block ",{"data":18790,"marks":18791,"value":18793,"nodeType":867},{},[18792],{"type":916},"Device Code Flow",{"data":18795,"marks":18796,"value":18797,"nodeType":867},{},[],", and set the grant control to ",{"data":18799,"marks":18800,"value":18802,"nodeType":867},{},[18801],{"type":916},"Block Access",{"data":18804,"marks":18805,"value":18806,"nodeType":867},{},[],". Deploy in report-only mode first to identify any legitimate device code usage, then enforce with narrow exceptions.",{"data":18808,"content":18812,"nodeType":890},{"target":18809},{"sys":18810},{"id":18811,"type":887,"linkType":888},"mQIj2o9xRzkZYKNmanB25",[],{"data":18814,"content":18815,"nodeType":881},{},[18816],{"data":18817,"marks":18818,"value":18819,"nodeType":867},{},[],"For other apps, you’re mainly limited to monitoring and response. Ensuring you’re getting authentication logs for these apps is vital, and searching for unusual access patterns (e.g. unusual login protocols, having different IPs for the authorization grant and subsequent account activity). ",{"data":18821,"content":18822,"nodeType":908},{},[],{"data":18824,"content":18825,"nodeType":918},{},[18826],{"data":18827,"marks":18828,"value":18830,"nodeType":867},{},[18829],{"type":916},"How Push Security can help",{"data":18832,"content":18833,"nodeType":881},{},[18834],{"data":18835,"marks":18836,"value":18837,"nodeType":867},{},[],"Push customers can use our browser-based capabilities to overcome the limitations of app-level controls and detect, intercept, and shut down attacks in real time. ",{"data":18839,"content":18840,"nodeType":881},{},[18841],{"data":18842,"marks":18843,"value":18844,"nodeType":867},{},[],"Our research team is already tracking multiple device code phishing campaigns and toolkits, including the EvilTokens kit. Blocking controls are already in place to prevent customers from interacting with malicious pages that match our detections for these new toolkits, ensuring that these pages can be identified and blocked in real time regardless of the infrastructure. ",{"data":18846,"content":18847,"nodeType":881},{},[18848,18851,18858],{"data":18849,"marks":18850,"value":14185,"nodeType":867},{},[],{"data":18852,"content":18853,"nodeType":876},{"uri":14188},[18854],{"data":18855,"marks":18856,"value":14194,"nodeType":867},{},[18857],{"type":1040},{"data":18859,"marks":18860,"value":18861,"nodeType":867},{},[]," whenever a user accesses a URL used for device code logins. This provides universal, last-mile protection against even ‘zero-day’ device code phishing attacks using previously unidentified toolkits.  ",{"data":18863,"content":18867,"nodeType":890},{"target":18864},{"sys":18865},{"id":18866,"type":887,"linkType":888},"3JsbGaOKSS3INzBUJpoh1W",[],{"data":18869,"content":18870,"nodeType":881},{},[18871],{"data":18872,"marks":18873,"value":18874,"nodeType":867},{},[],"When a user visits those URLs, Push will also emit a webhook event that the banner was shown and acknowledged. If a user opts to proceed, you can treat this as a high-fidelity alert for your security team to investigate, providing app-agnostic telemetry that may not already be provided in your logs from that particular vendor. You can also simply use Push to block users from accessing device login pages if you’re confident that disruption won’t be caused. ",{"data":18876,"content":18877,"nodeType":998},{},[18878],{"data":18879,"marks":18880,"value":10042,"nodeType":867},{},[18881],{"type":916},{"data":18883,"content":18884,"nodeType":881},{},[18885],{"data":18886,"marks":18887,"value":18888,"nodeType":867},{},[],"Push Security's browser-based security platform detects and blocks browser-based attacks like AiTM phishing, credential stuffing, malicious browser extensions, ClickFix, and session hijacking. You don't need to wait until it all goes wrong either — you can use Push to proactively find and fix vulnerabilities across the apps that your employees use, like ghost logins, SSO coverage gaps, MFA gaps, vulnerable passwords, and more to harden your attack surface.",{"data":18890,"content":18891,"nodeType":881},{},[18892,18895,18902,18905,18912,18915,18922],{"data":18893,"marks":18894,"value":10795,"nodeType":867},{},[],{"data":18896,"content":18897,"nodeType":876},{"uri":10798},[18898],{"data":18899,"marks":18900,"value":10803,"nodeType":867},{},[18901],{"type":1040},{"data":18903,"marks":18904,"value":4006,"nodeType":867},{},[],{"data":18906,"content":18907,"nodeType":876},{"uri":10809},[18908],{"data":18909,"marks":18910,"value":10815,"nodeType":867},{},[18911],{"type":1040},{"data":18913,"marks":18914,"value":10819,"nodeType":867},{},[],{"data":18916,"content":18917,"nodeType":876},{"uri":1629},[18918],{"data":18919,"marks":18920,"value":10826,"nodeType":867},{},[18921],{"type":1040},{"data":18923,"marks":18924,"value":1947,"nodeType":867},{},[],{"entries":18926},{"hyperlink":18927,"inline":18928,"block":18929},[],[],[18930,18949,18981,18988,19002,19043,19057,19085,19091,19098,19103,19110,19114,19120,19123,19129,19133,19139,19173,19179,19187,19191,19196,19202,19207,19221,19227,19235,19237,19251,19310,19316,19330,19390,19414],{"sys":18931,"__typename":1696,"content":18932,"name":18948,"title":59},{"id":15952},{"json":18933},{"data":18934,"content":18935,"nodeType":1640},{},[18936],{"data":18937,"content":18938,"nodeType":881},{},[18939,18944],{"data":18940,"marks":18941,"value":18943,"nodeType":867},{},[18942],{"type":916},"Update May 15:",{"data":18945,"marks":18946,"value":18947,"nodeType":867},{},[]," We've added details of three new kits, including proper samples of Venom, Tycoon2FA, and CYB3R, a new self-identifying kit — all from Push's customer detections. ","DCP IB 11",{"sys":18950,"__typename":1696,"content":18951,"name":18980,"title":59},{"id":16003},{"json":18952},{"nodeType":1640,"data":18953,"content":18954},{},[18955],{"nodeType":881,"data":18956,"content":18957},{},[18958,18962,18967,18971,18976],{"nodeType":867,"value":18959,"marks":18960,"data":18961},"At the start of March, we’d observed a ",[],{},{"nodeType":867,"value":18963,"marks":18964,"data":18966},"15x",[18965],{"type":916},{},{"nodeType":867,"value":18968,"marks":18969,"data":18970}," increase in device code phishing pages detected by our research team this year, with multiple kits and campaigns being tracked — with the kit now identified as EvilTokens the most prominent. ",[],{},{"nodeType":867,"value":18972,"marks":18973,"data":18975},"That figure has now risen to 37.5x",[18974],{"type":916},{},{"nodeType":867,"value":18977,"marks":18978,"data":18979},". More on that later. ",[],{},"DCP IB 1",{"sys":18982,"__typename":1648,"title":18983,"caption":18983,"layoutMode":59,"file":18984},{"id":16034},"Device code phishing evolution 2019-2026.",{"url":18985,"width":18986,"height":18987},"https://images.ctfassets.net/y1cdw1ablpvd/7dPjgH1qTrpBIdqE0D4D0g/8d0bcaea877a9fcd325b272890d8dc63/device_code_phishing_4col_timeline_1.png",1360,1160,{"sys":18989,"__typename":1696,"content":18990,"name":19001,"title":59},{"id":16144},{"json":18991},{"nodeType":1640,"data":18992,"content":18993},{},[18994],{"nodeType":881,"data":18995,"content":18996},{},[18997],{"nodeType":867,"value":18998,"marks":18999,"data":19000},"PhaaS is key to the adoption of new phishing tools and techniques, providing broad access to criminal operators at scale while driving up execution standards. It has been central to the continued evolution of AITM and ClickFix, and is a strong indicator of what comes next for device code phishing.",[],{},"DCP IB 2",{"sys":19003,"__typename":1696,"content":19004,"name":19042,"title":59},{"id":16270},{"json":19005},{"data":19006,"content":19007,"nodeType":1640},{},[19008],{"data":19009,"content":19010,"nodeType":881},{},[19011,19015,19022,19026,19030,19038],{"data":19012,"marks":19013,"value":19014,"nodeType":867},{},[],"We're seeing a clear trend of existing PhaaS kits adding device code phishing functionality. Tycoon2FA, the category leader for criminal AITM phishing capabilities, has recently",{"data":19016,"content":19017,"nodeType":876},{"uri":1125},[19018],{"data":19019,"marks":19020,"value":19021,"nodeType":867},{},[]," adopted device code phishing ",{"data":19023,"marks":19024,"value":19025,"nodeType":867},{},[],"alongside its established AiTM functionality (we've provided some examples below), while t",{"data":19027,"marks":19028,"value":19029,"nodeType":867},{},[],"he ",{"data":19031,"content":19033,"nodeType":876},{"uri":19032},"https://abnormal.ai/blog/venom-phishing-campaign-mfa-credential-theft",[19034],{"data":19035,"marks":19036,"value":18105,"nodeType":867},{},[19037],{"type":1040},{"data":19039,"marks":19040,"value":19041,"nodeType":867},{},[]," kit that offers device code phishing capabilities that appear visually and functionally similar to EvilTokens has an AITM component that matches our detections for Sneaky2FA, indicating a possible overlap in tooling.","DCP IB12",{"sys":19044,"__typename":1696,"content":19045,"name":19056,"title":59},{"id":16294},{"json":19046},{"nodeType":1640,"data":19047,"content":19048},{},[19049],{"nodeType":881,"data":19050,"content":19051},{},[19052],{"nodeType":867,"value":19053,"marks":19054,"data":19055},"Many of the names provided are internal codenames. The information per kit is by no means exhaustive and is likely to evolve over time. ",[],{},"DCP IP 7",{"sys":19058,"__typename":1696,"content":19059,"name":19084,"title":59},{"id":16352},{"json":19060},{"nodeType":1640,"data":19061,"content":19062},{},[19063,19070,19077],{"nodeType":881,"data":19064,"content":19065},{},[19066],{"nodeType":867,"value":19067,"marks":19068,"data":19069},"Our codename for EvilTokens internally was derived from the overly descriptive page code describing its bot protection capabilities (a clear sign of vibe coding — thanks Claude!):",[],{},{"nodeType":881,"data":19071,"content":19072},{},[19073],{"nodeType":867,"value":19074,"marks":19075,"data":19076},"\u003C!-- FIXED ANTI-BOT SYSTEM - WON'T REDIRECT REAL USERS -->",[],{},{"nodeType":881,"data":19078,"content":19079},{},[19080],{"nodeType":867,"value":19081,"marks":19082,"data":19083},"\u003C!-- ENHANCED ANTI-BOT SYSTEM WITH SERVER-SIDE VALIDATION -->",[],{},"DCP IB3",{"sys":19086,"__typename":1648,"title":19087,"caption":19087,"layoutMode":59,"file":19088},{"id":16405},"Precursor A (Left) & B (Right): Different visual lures from January 2026. ",{"url":19089,"width":1661,"height":19090},"https://images.ctfassets.net/y1cdw1ablpvd/3pfFR7ICQQqOyhGAFAj67C/6f8873d82cc7f5233a0ca9baa74f7585/image15.png",773,{"sys":19092,"__typename":1648,"title":19093,"caption":19094,"layoutMode":59,"file":19095},{"id":16411},"Early ANTIBOT: First appearance of the ANTIBOT comments, mid-Jan.","Early ANTIBOT: First appearance of the ANTIBOT comments, late-Jan.",{"url":19096,"width":1661,"height":19097},"https://images.ctfassets.net/y1cdw1ablpvd/VAdFlnCF4YftsOV02wnwu/8813ea3957b65ddfb84bb8ba5fb25a55/image6.png",564,{"sys":19099,"__typename":1671,"title":19100,"arcadeDemoUrl":19101,"playText":19102},{"id":16417},"Early ANTIBOT page load","https://demo.arcade.software/wRcvXg62Lok57ZjOKgJI?embed","20 secs",{"sys":19104,"__typename":1648,"title":19105,"caption":19105,"layoutMode":59,"file":19106},{"id":16423},"\"Courts Access\" lure with a similar security verification to Early ANTIBOT.",{"url":19107,"width":19108,"height":19109},"https://images.ctfassets.net/y1cdw1ablpvd/7LEJpoif8dnub4qJw2z6kL/3b15161c9d3f2e4f7d4f323ec04f1f33/Group_687.png",3103,1200,{"sys":19111,"__typename":1671,"title":19112,"arcadeDemoUrl":19113,"playText":1674},{"id":16429},"ANTIBOT \"Courts Access\" lure","https://demo.arcade.software/8b4YuKm1EXPmgx2q7q2D?embed",{"sys":19115,"__typename":1648,"title":19116,"caption":19116,"layoutMode":59,"file":19117},{"id":16435},"Production ANTIBOT: Current EvilTokens implementation.",{"url":19118,"width":1661,"height":19119},"https://images.ctfassets.net/y1cdw1ablpvd/1J3fOSmUPF8f3FlcwYFoGe/5eff8c1a892f870d1488d6a0f38da03c/image12.png",591,{"sys":19121,"__typename":1671,"title":16135,"arcadeDemoUrl":19122,"playText":19102},{"id":16441},"https://demo.arcade.software/zB6dqehj1lbnB2dur9lB?embed",{"sys":19124,"__typename":1648,"title":19125,"caption":19125,"layoutMode":59,"file":19126},{"id":16862},"SHAREFILE kit.",{"url":19127,"width":1661,"height":19128},"https://images.ctfassets.net/y1cdw1ablpvd/1iKelffs399PIIBedgnqmu/64a40d1ad7f69f966665f44c52e0817b/image1.png",1500,{"sys":19130,"__typename":1671,"title":19131,"arcadeDemoUrl":19132,"playText":1686},{"id":17053},"Kali365 / Clure Demo","https://demo.arcade.software/dwwFeSKGldZvTrYZDtZV?embed",{"sys":19134,"__typename":1648,"title":19135,"caption":59,"layoutMode":59,"file":19136},{"id":17217},"LINKID landing page requires an email before serving the payload.",{"url":19137,"width":1661,"height":19138},"https://images.ctfassets.net/y1cdw1ablpvd/5XAibmWt8HDGbpOC9n1DEk/d4bcb1006d82116dff5865f5b911bc88/image9.png",1049,{"sys":19140,"__typename":1696,"content":19141,"name":19172,"title":59},{"id":17234},{"json":19142},{"nodeType":1640,"data":19143,"content":19144},{},[19145],{"nodeType":881,"data":19146,"content":19147},{},[19148,19152,19157,19161,19169],{"nodeType":867,"value":19149,"marks":19150,"data":19151},"AUTHOV was recently attributed to ",[],{},{"nodeType":867,"value":19153,"marks":19154,"data":19156},"Device Code Lab",[19155],{"type":916},{},{"nodeType":867,"value":19158,"marks":19159,"data":19160},", a professional grade, device code phishing platform, with numerous defense evasion and post-exploitation features, designed to interoperate with other phishing platforms. You can ",[],{},{"nodeType":876,"data":19162,"content":19164},{"uri":19163},"https://newtonpaul.com/blog/device-code-lab-post-exploit/",[19165],{"nodeType":867,"value":19166,"marks":19167,"data":19168},"read Paul Newton's write-up here",[],{},{"nodeType":867,"value":1253,"marks":19170,"data":19171},[],{},"dcp ib14",{"sys":19174,"__typename":1648,"title":19175,"caption":19175,"layoutMode":59,"file":19176},{"id":17381},"AUTHOV kit. Notably uses a popup like prod EvilTokens.",{"url":19177,"width":1661,"height":19178},"https://images.ctfassets.net/y1cdw1ablpvd/4wKaHuSRfMXvi056r88u0b/e77feca260fe5ceb07ea7a080a09148f/image8.png",1128,{"sys":19180,"__typename":1648,"title":19181,"caption":19182,"layoutMode":59,"file":19183},{"id":17387},"Device code lab portal","Device Code Lab portal login page. Credit: Paul Newton",{"url":19184,"width":19185,"height":19186},"https://images.ctfassets.net/y1cdw1ablpvd/3qgmWJFz6hDUSEu2TcUWWU/9df13412c9ddb216020ae7a5fe476b5d/portal.png",912,787,{"sys":19188,"__typename":1671,"title":19189,"arcadeDemoUrl":19190,"playText":19102},{"id":17551},"DOCUPOLL DCP Kit","https://demo.arcade.software/Wv84a7Vziha9RwTdctvg?embed",{"sys":19192,"__typename":1648,"title":19193,"caption":19193,"layoutMode":59,"file":19194},{"id":17714},"FLOW_TOKEN kit. Notably uses a popup like prod EvilTokens.",{"url":19195,"width":1661,"height":19178},"https://images.ctfassets.net/y1cdw1ablpvd/4Bvbx5dwwBTOvAzULbnhIF/2d676145af0648b1e6f43b624af3ffbc/image7.png",{"sys":19197,"__typename":1648,"title":19198,"caption":19198,"layoutMode":59,"file":19199},{"id":17826},"PAPRIKA kit.",{"url":19200,"width":1661,"height":19201},"https://images.ctfassets.net/y1cdw1ablpvd/2XqwbTyGXRBaH6OM0t9moI/107cd701784fe8eed96eea2b9c09731a/image5.png",727,{"sys":19203,"__typename":1648,"title":19204,"caption":19204,"layoutMode":59,"file":19205},{"id":17937},"DCSTATUS kit. ",{"url":19206,"width":1661,"height":19128},"https://images.ctfassets.net/y1cdw1ablpvd/1zKQp6Wi0ckDZMLHBriU2Y/7d1c7c348407dcbde2eb94551baca7f5/image14.png",{"sys":19208,"__typename":1696,"content":19209,"name":19220,"title":59},{"id":17954},{"json":19210},{"data":19211,"content":19212,"nodeType":1640},{},[19213],{"data":19214,"content":19215,"nodeType":881},{},[19216],{"data":19217,"marks":19218,"value":19219,"nodeType":867},{},[],"Our suspicion is that this was a one-off — potentially for a red team exercise — rather than representative of a more widely used kit.","DCP IB 4",{"sys":19222,"__typename":1648,"title":19223,"caption":19223,"layoutMode":59,"file":19224},{"id":18093},"DOLCE kit.",{"url":19225,"width":1661,"height":19226},"https://images.ctfassets.net/y1cdw1ablpvd/6iUfj8vMymi2c7lZxj006n/88b8066e6bea9fa7a81bd6b546264796/image16.png",728,{"sys":19228,"__typename":1648,"title":19229,"caption":19230,"layoutMode":59,"file":19231},{"id":18159},"Venom Device Code Phishing Screenshots","Examples of the Venom platform impersonating brands like YPO, FedEx and DHL.",{"url":19232,"width":19233,"height":19234},"https://images.ctfassets.net/y1cdw1ablpvd/2NThjmQSR5XFdnKEQKXfnd/237318895da6f558cc03b2915217afea/Venom_Device_Code_Phishing__1_.png",13114,3310,{"sys":19236,"__typename":1671,"title":1684,"arcadeDemoUrl":1685,"playText":1686},{"id":1178},{"sys":19238,"__typename":1696,"content":19239,"name":19250,"title":59},{"id":18463},{"json":19240},{"nodeType":1640,"data":19241,"content":19242},{},[19243],{"nodeType":881,"data":19244,"content":19245},{},[19246],{"nodeType":867,"value":19247,"marks":19248,"data":19249},"Clearly, device code phishing has entered mainstream adoption and we should be prepared for a lot more of it in future. So how does it work, and why is it so effective?",[],{},"DCP IB13",{"sys":19252,"__typename":1696,"content":19253,"name":19309,"title":59},{"id":18499},{"json":19254},{"nodeType":1640,"data":19255,"content":19256},{},[19257,19293],{"nodeType":881,"data":19258,"content":19259},{},[19260,19264,19271,19275,19280,19284,19289],{"nodeType":867,"value":19261,"marks":19262,"data":19263},"When targeting Microsoft environments, attackers can use the ",[],{},{"nodeType":876,"data":19265,"content":19266},{"uri":16071},[19267],{"nodeType":867,"value":19268,"marks":19269,"data":19270},"PRT escalation technique",[],{},{"nodeType":867,"value":19272,"marks":19273,"data":19274}," I mentioned in earlier research to get seamless SSO across ",[],{},{"nodeType":867,"value":19276,"marks":19277,"data":19279},"all",[19278],{"type":1431},{},{"nodeType":867,"value":19281,"marks":19282,"data":19283}," Entra ID-connected applications and web services. This requires that you specifically target the ",[],{},{"nodeType":867,"value":19285,"marks":19286,"data":19288},"Microsoft Authentication Broker",[19287],{"type":916},{},{"nodeType":867,"value":19290,"marks":19291,"data":19292}," application, chained into a new device registration in the victim's environment. This is the method that Storm-2372 was leveraging in 2025. ",[],{},{"nodeType":881,"data":19294,"content":19295},{},[19296,19300,19305],{"nodeType":867,"value":19297,"marks":19298,"data":19299},"But even without this step, many Microsoft first-party apps also belong to the ",[],{},{"nodeType":867,"value":19301,"marks":19302,"data":19304},"Family of Client IDs (FOCI)",[19303],{"type":916},{},{"nodeType":867,"value":19306,"marks":19307,"data":19308},", meaning a refresh token obtained for one family member can be exchanged for access tokens to other family members without re-authentication. In practice, this means an attacker who phishes a token via e.g. the Microsoft Office client ID, can silently pivot to access Outlook, Teams, OneDrive, SharePoint, and Azure Management APIs — all from a single phished session. ",[],{},"DCP IB 8",{"sys":19311,"__typename":1648,"title":19312,"caption":19312,"layoutMode":59,"file":19313},{"id":18505},"Device code phishing attack chain.",{"url":19314,"width":1661,"height":19315},"https://images.ctfassets.net/y1cdw1ablpvd/60e9ErrL8tp3xtoer4gNUl/83899c207f61fdd9ff8aad0e1001030d/image2.png",1275,{"sys":19317,"__typename":1696,"content":19318,"name":19329,"title":59},{"id":18555},{"json":19319},{"nodeType":1640,"data":19320,"content":19321},{},[19322],{"nodeType":881,"data":19323,"content":19324},{},[19325],{"nodeType":867,"value":19326,"marks":19327,"data":19328},"One of the key limitations of early device code phishing was that the code was being sent directly over email (as in the Russia-linked campaigns in 2024-5). This meant that the code would expire unless used immediately, requiring highly engaged social engineering to pull off. To get around this, modern device code phishing pages are continuously polling for fresh codes via API. This arguably makes them more discoverable than simply providing the code and instructions in a direct message, but is way more scalable for the attacker. ",[],{},"DCP IB 5",{"sys":19331,"__typename":1696,"content":19332,"name":19389,"title":59},{"id":18735},{"json":19333},{"nodeType":1640,"data":19334,"content":19335},{},[19336,19373],{"nodeType":881,"data":19337,"content":19338},{},[19339,19344,19348,19358,19362,19369],{"nodeType":867,"value":19340,"marks":19341,"data":19343},"First-party applications",[19342],{"type":916},{},{"nodeType":867,"value":19345,"marks":19346,"data":19347}," are commonly abused in Microsoft-targeted attacks. These are ",[],{},{"nodeType":876,"data":19349,"content":19351},{"uri":19350},"https://gist.github.com/dafthack/2c0bbcac72b10c1ee205d1dd2fed3fe7",[19352],{"nodeType":867,"value":19353,"marks":19354,"data":19357},"real Microsoft applications",[19355,19356],{"type":1040},{"type":916},{},{"nodeType":867,"value":19359,"marks":19360,"data":19361}," registered in every Entra ID tenant. Not only are they allowed by default (unlike third-party apps that are often subject to additional restrictions and require additional tenant-level consent before they can be accessed by a user), they come with pre-consented permissions, and can even access undocumented “legacy” scopes that aren't logged by default (exploited in the Russia-linked ",[],{},{"nodeType":876,"data":19363,"content":19364},{"uri":1319},[19365],{"nodeType":867,"value":1312,"marks":19366,"data":19368},[19367],{"type":1040},{},{"nodeType":867,"value":19370,"marks":19371,"data":19372}," campaign reported by Push researchers). ",[],{},{"nodeType":881,"data":19374,"content":19375},{},[19376,19380,19385],{"nodeType":867,"value":19377,"marks":19378,"data":19379},"In other cases, such as when targeting GitHub or Salesforce, ",[],{},{"nodeType":867,"value":19381,"marks":19382,"data":19384},"third-party applications",[19383],{"type":916},{},{"nodeType":867,"value":19386,"marks":19387,"data":19388}," are often leveraged. These aren't necessarily fresh, attacker-created apps — they can be attacker-controlled instances of otherwise legitimate applications. That said, it is easier than ever for attackers to spin up their own OAuth apps, particularly using AI tools. The trade-off is that the victim has to consent to the app from the tenant level before also granting access to their account, introducing more friction to the process, and potentially running into additional security controls and restrictions depending on tenant configuration. ",[],{},"DCP IB 6",{"sys":19391,"__typename":1696,"content":19392,"name":19413,"title":59},{"id":18811},{"json":19393},{"nodeType":1640,"data":19394,"content":19395},{},[19396],{"nodeType":881,"data":19397,"content":19398},{},[19399,19403,19409],{"nodeType":867,"value":19400,"marks":19401,"data":19402},"However, it's important to recognize that blocking device code flow is not a complete solution. Related techniques like ",[],{},{"nodeType":876,"data":19404,"content":19405},{"uri":1319},[19406],{"nodeType":867,"value":1312,"marks":19407,"data":19408},[],{},{"nodeType":867,"value":19410,"marks":19411,"data":19412}," — which exploits the authorization code flow with localhost redirects rather than the device code flow — produce the same access tokens with the same capabilities but are not blocked by device code flow specific CA policies. ",[],{},"DCP IB 7",{"sys":19415,"__typename":1648,"title":19416,"caption":19417,"layoutMode":59,"file":19418},{"id":18866},"DCP warning banner","Users visiting a device code login page will be required to click through a warning banner, emitting a webhook event.",{"url":19419,"width":19420,"height":19421},"https://images.ctfassets.net/y1cdw1ablpvd/2Gtct2qofWtLLVi31Pk8NY/616e56fc4fa7dcb905a0a3a1ca28709b/image17.png",1367,859,{"items":19423},[],{},"Analyzing the rise in device code phishing attacks in 2026","2026-04-04T00:00:00.000Z",{"items":19428},[19429,20257,21118],{"__typename":1742,"sys":19430,"content":19431,"title":15224,"synopsis":15225,"hashTags":59,"publishedDate":15226,"slug":15227,"tagsCollection":20247,"authorsCollection":20253},{"id":14277},{"json":19432},{"data":19433,"content":19434,"nodeType":1640},{},[19435,19441,19447,19453,19456,19463,19469,19475,19480,19486,19491,19507,19513,19523,19526,19533,19539,19552,19558,19568,19573,19576,19583,19590,19595,19603,19619,19627,19633,19641,19656,19664,19670,19678,19704,19712,19718,19726,19742,19747,19755,19761,19769,19802,19805,19812,19820,19836,19844,19850,19858,19884,19889,19897,19903,19908,19911,19918,19926,19932,19983,19988,19991,19998,20006,20012,20017,20020,20027,20033,20039,20099,20105,20160,20166,20169,20176,20182,20188,20193,20196,20203,20209,20215,20221],{"data":19436,"content":19437,"nodeType":881},{},[19438],{"data":19439,"marks":19440,"value":14288,"nodeType":867},{},[],{"data":19442,"content":19443,"nodeType":881},{},[19444],{"data":19445,"marks":19446,"value":14295,"nodeType":867},{},[],{"data":19448,"content":19449,"nodeType":881},{},[19450],{"data":19451,"marks":19452,"value":14302,"nodeType":867},{},[],{"data":19454,"content":19455,"nodeType":908},{},[],{"data":19457,"content":19458,"nodeType":918},{},[19459],{"data":19460,"marks":19461,"value":14313,"nodeType":867},{},[19462],{"type":916},{"data":19464,"content":19465,"nodeType":881},{},[19466],{"data":19467,"marks":19468,"value":14320,"nodeType":867},{},[],{"data":19470,"content":19471,"nodeType":881},{},[19472],{"data":19473,"marks":19474,"value":14327,"nodeType":867},{},[],{"data":19476,"content":19479,"nodeType":890},{"target":19477},{"sys":19478},{"id":14332,"type":887,"linkType":888},[],{"data":19481,"content":19482,"nodeType":881},{},[19483],{"data":19484,"marks":19485,"value":14340,"nodeType":867},{},[],{"data":19487,"content":19490,"nodeType":890},{"target":19488},{"sys":19489},{"id":14345,"type":887,"linkType":888},[],{"data":19492,"content":19493,"nodeType":881},{},[19494,19497,19504],{"data":19495,"marks":19496,"value":14353,"nodeType":867},{},[],{"data":19498,"content":19499,"nodeType":876},{"uri":5752},[19500],{"data":19501,"marks":19502,"value":14361,"nodeType":867},{},[19503],{"type":1040},{"data":19505,"marks":19506,"value":14365,"nodeType":867},{},[],{"data":19508,"content":19509,"nodeType":881},{},[19510],{"data":19511,"marks":19512,"value":14372,"nodeType":867},{},[],{"data":19514,"content":19515,"nodeType":881},{},[19516,19519],{"data":19517,"marks":19518,"value":14379,"nodeType":867},{},[],{"data":19520,"marks":19521,"value":14384,"nodeType":867},{},[19522],{"type":916},{"data":19524,"content":19525,"nodeType":908},{},[],{"data":19527,"content":19528,"nodeType":918},{},[19529],{"data":19530,"marks":19531,"value":14395,"nodeType":867},{},[19532],{"type":916},{"data":19534,"content":19535,"nodeType":881},{},[19536],{"data":19537,"marks":19538,"value":14402,"nodeType":867},{},[],{"data":19540,"content":19541,"nodeType":881},{},[19542,19545,19549],{"data":19543,"marks":19544,"value":14409,"nodeType":867},{},[],{"data":19546,"marks":19547,"value":14414,"nodeType":867},{},[19548],{"type":916},{"data":19550,"marks":19551,"value":14418,"nodeType":867},{},[],{"data":19553,"content":19554,"nodeType":881},{},[19555],{"data":19556,"marks":19557,"value":14425,"nodeType":867},{},[],{"data":19559,"content":19560,"nodeType":881},{},[19561,19564],{"data":19562,"marks":19563,"value":14432,"nodeType":867},{},[],{"data":19565,"marks":19566,"value":14437,"nodeType":867},{},[19567],{"type":916},{"data":19569,"content":19572,"nodeType":890},{"target":19570},{"sys":19571},{"id":14442,"type":887,"linkType":888},[],{"data":19574,"content":19575,"nodeType":908},{},[],{"data":19577,"content":19578,"nodeType":918},{},[19579],{"data":19580,"marks":19581,"value":14454,"nodeType":867},{},[19582],{"type":916},{"data":19584,"content":19585,"nodeType":998},{},[19586],{"data":19587,"marks":19588,"value":14462,"nodeType":867},{},[19589],{"type":916},{"data":19591,"content":19594,"nodeType":890},{"target":19592},{"sys":19593},{"id":14467,"type":887,"linkType":888},[],{"data":19596,"content":19597,"nodeType":881},{},[19598],{"data":19599,"marks":19600,"value":14477,"nodeType":867},{},[19601,19602],{"type":916},{"type":1040},{"data":19604,"content":19605,"nodeType":881},{},[19606,19609,19616],{"data":19607,"marks":19608,"value":14484,"nodeType":867},{},[],{"data":19610,"content":19611,"nodeType":876},{"uri":14487},[19612],{"data":19613,"marks":19614,"value":14493,"nodeType":867},{},[19615],{"type":1040},{"data":19617,"marks":19618,"value":14497,"nodeType":867},{},[],{"data":19620,"content":19621,"nodeType":881},{},[19622],{"data":19623,"marks":19624,"value":14506,"nodeType":867},{},[19625,19626],{"type":916},{"type":1040},{"data":19628,"content":19629,"nodeType":881},{},[19630],{"data":19631,"marks":19632,"value":14513,"nodeType":867},{},[],{"data":19634,"content":19635,"nodeType":881},{},[19636],{"data":19637,"marks":19638,"value":14522,"nodeType":867},{},[19639,19640],{"type":916},{"type":1040},{"data":19642,"content":19643,"nodeType":881},{},[19644,19647,19653],{"data":19645,"marks":19646,"value":14529,"nodeType":867},{},[],{"data":19648,"content":19649,"nodeType":876},{"uri":14532},[19650],{"data":19651,"marks":19652,"value":14537,"nodeType":867},{},[],{"data":19654,"marks":19655,"value":14541,"nodeType":867},{},[],{"data":19657,"content":19658,"nodeType":881},{},[19659],{"data":19660,"marks":19661,"value":14550,"nodeType":867},{},[19662,19663],{"type":916},{"type":1040},{"data":19665,"content":19666,"nodeType":881},{},[19667],{"data":19668,"marks":19669,"value":14557,"nodeType":867},{},[],{"data":19671,"content":19672,"nodeType":881},{},[19673],{"data":19674,"marks":19675,"value":14566,"nodeType":867},{},[19676,19677],{"type":916},{"type":1040},{"data":19679,"content":19680,"nodeType":881},{},[19681,19684,19691,19694,19701],{"data":19682,"marks":19683,"value":14573,"nodeType":867},{},[],{"data":19685,"content":19686,"nodeType":876},{"uri":14576},[19687],{"data":19688,"marks":19689,"value":14582,"nodeType":867},{},[19690],{"type":1040},{"data":19692,"marks":19693,"value":14586,"nodeType":867},{},[],{"data":19695,"content":19696,"nodeType":876},{"uri":14589},[19697],{"data":19698,"marks":19699,"value":6850,"nodeType":867},{},[19700],{"type":1040},{"data":19702,"marks":19703,"value":14598,"nodeType":867},{},[],{"data":19705,"content":19706,"nodeType":881},{},[19707],{"data":19708,"marks":19709,"value":14607,"nodeType":867},{},[19710,19711],{"type":916},{"type":1040},{"data":19713,"content":19714,"nodeType":881},{},[19715],{"data":19716,"marks":19717,"value":14614,"nodeType":867},{},[],{"data":19719,"content":19720,"nodeType":881},{},[19721],{"data":19722,"marks":19723,"value":14623,"nodeType":867},{},[19724,19725],{"type":916},{"type":1040},{"data":19727,"content":19728,"nodeType":881},{},[19729,19732,19739],{"data":19730,"marks":19731,"value":14630,"nodeType":867},{},[],{"data":19733,"content":19734,"nodeType":876},{"uri":14589},[19735],{"data":19736,"marks":19737,"value":6850,"nodeType":867},{},[19738],{"type":1040},{"data":19740,"marks":19741,"value":14641,"nodeType":867},{},[],{"data":19743,"content":19746,"nodeType":890},{"target":19744},{"sys":19745},{"id":14646,"type":887,"linkType":888},[],{"data":19748,"content":19749,"nodeType":881},{},[19750],{"data":19751,"marks":19752,"value":14656,"nodeType":867},{},[19753,19754],{"type":916},{"type":1040},{"data":19756,"content":19757,"nodeType":881},{},[19758],{"data":19759,"marks":19760,"value":14663,"nodeType":867},{},[],{"data":19762,"content":19763,"nodeType":881},{},[19764],{"data":19765,"marks":19766,"value":14672,"nodeType":867},{},[19767,19768],{"type":916},{"type":1040},{"data":19770,"content":19771,"nodeType":881},{},[19772,19775,19781,19784,19790,19793,19799],{"data":19773,"marks":19774,"value":14679,"nodeType":867},{},[],{"data":19776,"content":19777,"nodeType":876},{"uri":14682},[19778],{"data":19779,"marks":19780,"value":14687,"nodeType":867},{},[],{"data":19782,"marks":19783,"value":2063,"nodeType":867},{},[],{"data":19785,"content":19786,"nodeType":876},{"uri":14693},[19787],{"data":19788,"marks":19789,"value":14698,"nodeType":867},{},[],{"data":19791,"marks":19792,"value":14702,"nodeType":867},{},[],{"data":19794,"content":19795,"nodeType":876},{"uri":3074},[19796],{"data":19797,"marks":19798,"value":14709,"nodeType":867},{},[],{"data":19800,"marks":19801,"value":14713,"nodeType":867},{},[],{"data":19803,"content":19804,"nodeType":908},{},[],{"data":19806,"content":19807,"nodeType":998},{},[19808],{"data":19809,"marks":19810,"value":14724,"nodeType":867},{},[19811],{"type":916},{"data":19813,"content":19814,"nodeType":881},{},[19815],{"data":19816,"marks":19817,"value":14733,"nodeType":867},{},[19818,19819],{"type":916},{"type":1040},{"data":19821,"content":19822,"nodeType":881},{},[19823,19826,19833],{"data":19824,"marks":19825,"value":14740,"nodeType":867},{},[],{"data":19827,"content":19828,"nodeType":876},{"uri":14743},[19829],{"data":19830,"marks":19831,"value":14749,"nodeType":867},{},[19832],{"type":1040},{"data":19834,"marks":19835,"value":14753,"nodeType":867},{},[],{"data":19837,"content":19838,"nodeType":881},{},[19839],{"data":19840,"marks":19841,"value":14762,"nodeType":867},{},[19842,19843],{"type":916},{"type":1040},{"data":19845,"content":19846,"nodeType":881},{},[19847],{"data":19848,"marks":19849,"value":14769,"nodeType":867},{},[],{"data":19851,"content":19852,"nodeType":881},{},[19853],{"data":19854,"marks":19855,"value":14778,"nodeType":867},{},[19856,19857],{"type":916},{"type":1040},{"data":19859,"content":19860,"nodeType":881},{},[19861,19864,19871,19874,19881],{"data":19862,"marks":19863,"value":14785,"nodeType":867},{},[],{"data":19865,"content":19866,"nodeType":876},{"uri":14788},[19867],{"data":19868,"marks":19869,"value":14794,"nodeType":867},{},[19870],{"type":1040},{"data":19872,"marks":19873,"value":14798,"nodeType":867},{},[],{"data":19875,"content":19876,"nodeType":876},{"uri":14801},[19877],{"data":19878,"marks":19879,"value":14807,"nodeType":867},{},[19880],{"type":1040},{"data":19882,"marks":19883,"value":14811,"nodeType":867},{},[],{"data":19885,"content":19888,"nodeType":890},{"target":19886},{"sys":19887},{"id":14816,"type":887,"linkType":888},[],{"data":19890,"content":19891,"nodeType":881},{},[19892],{"data":19893,"marks":19894,"value":14826,"nodeType":867},{},[19895,19896],{"type":916},{"type":1040},{"data":19898,"content":19899,"nodeType":881},{},[19900],{"data":19901,"marks":19902,"value":14833,"nodeType":867},{},[],{"data":19904,"content":19907,"nodeType":890},{"target":19905},{"sys":19906},{"id":14838,"type":887,"linkType":888},[],{"data":19909,"content":19910,"nodeType":908},{},[],{"data":19912,"content":19913,"nodeType":998},{},[19914],{"data":19915,"marks":19916,"value":694,"nodeType":867},{},[19917],{"type":916},{"data":19919,"content":19920,"nodeType":881},{},[19921],{"data":19922,"marks":19923,"value":14858,"nodeType":867},{},[19924,19925],{"type":916},{"type":1040},{"data":19927,"content":19928,"nodeType":881},{},[19929],{"data":19930,"marks":19931,"value":14865,"nodeType":867},{},[],{"data":19933,"content":19934,"nodeType":3126},{},[19935,19948,19961],{"data":19936,"content":19937,"nodeType":3061},{},[19938],{"data":19939,"content":19940,"nodeType":881},{},[19941,19945],{"data":19942,"marks":19943,"value":14879,"nodeType":867},{},[19944],{"type":916},{"data":19946,"marks":19947,"value":14883,"nodeType":867},{},[],{"data":19949,"content":19950,"nodeType":3061},{},[19951],{"data":19952,"content":19953,"nodeType":881},{},[19954,19958],{"data":19955,"marks":19956,"value":14894,"nodeType":867},{},[19957],{"type":916},{"data":19959,"marks":19960,"value":14898,"nodeType":867},{},[],{"data":19962,"content":19963,"nodeType":3061},{},[19964],{"data":19965,"content":19966,"nodeType":881},{},[19967,19971,19974,19980],{"data":19968,"marks":19969,"value":14909,"nodeType":867},{},[19970],{"type":916},{"data":19972,"marks":19973,"value":14913,"nodeType":867},{},[],{"data":19975,"content":19976,"nodeType":876},{"uri":10495},[19977],{"data":19978,"marks":19979,"value":14920,"nodeType":867},{},[],{"data":19981,"marks":19982,"value":14924,"nodeType":867},{},[],{"data":19984,"content":19987,"nodeType":890},{"target":19985},{"sys":19986},{"id":14929,"type":887,"linkType":888},[],{"data":19989,"content":19990,"nodeType":908},{},[],{"data":19992,"content":19993,"nodeType":998},{},[19994],{"data":19995,"marks":19996,"value":699,"nodeType":867},{},[19997],{"type":916},{"data":19999,"content":20000,"nodeType":881},{},[20001],{"data":20002,"marks":20003,"value":14949,"nodeType":867},{},[20004,20005],{"type":916},{"type":1040},{"data":20007,"content":20008,"nodeType":881},{},[20009],{"data":20010,"marks":20011,"value":14956,"nodeType":867},{},[],{"data":20013,"content":20016,"nodeType":890},{"target":20014},{"sys":20015},{"id":14961,"type":887,"linkType":888},[],{"data":20018,"content":20019,"nodeType":908},{},[],{"data":20021,"content":20022,"nodeType":918},{},[20023],{"data":20024,"marks":20025,"value":14973,"nodeType":867},{},[20026],{"type":916},{"data":20028,"content":20029,"nodeType":881},{},[20030],{"data":20031,"marks":20032,"value":14980,"nodeType":867},{},[],{"data":20034,"content":20035,"nodeType":881},{},[20036],{"data":20037,"marks":20038,"value":14987,"nodeType":867},{},[],{"data":20040,"content":20041,"nodeType":3126},{},[20042,20061,20080],{"data":20043,"content":20044,"nodeType":3061},{},[20045],{"data":20046,"content":20047,"nodeType":881},{},[20048,20051,20058],{"data":20049,"marks":20050,"value":15000,"nodeType":867},{},[],{"data":20052,"content":20053,"nodeType":876},{"uri":15003},[20054],{"data":20055,"marks":20056,"value":15009,"nodeType":867},{},[20057],{"type":1040},{"data":20059,"marks":20060,"value":15013,"nodeType":867},{},[],{"data":20062,"content":20063,"nodeType":3061},{},[20064],{"data":20065,"content":20066,"nodeType":881},{},[20067,20070,20077],{"data":20068,"marks":20069,"value":15023,"nodeType":867},{},[],{"data":20071,"content":20072,"nodeType":876},{"uri":15026},[20073],{"data":20074,"marks":20075,"value":15032,"nodeType":867},{},[20076],{"type":1040},{"data":20078,"marks":20079,"value":15013,"nodeType":867},{},[],{"data":20081,"content":20082,"nodeType":3061},{},[20083],{"data":20084,"content":20085,"nodeType":881},{},[20086,20089,20096],{"data":20087,"marks":20088,"value":15045,"nodeType":867},{},[],{"data":20090,"content":20091,"nodeType":876},{"uri":15048},[20092],{"data":20093,"marks":20094,"value":15054,"nodeType":867},{},[20095],{"type":1040},{"data":20097,"marks":20098,"value":15013,"nodeType":867},{},[],{"data":20100,"content":20101,"nodeType":881},{},[20102],{"data":20103,"marks":20104,"value":15064,"nodeType":867},{},[],{"data":20106,"content":20107,"nodeType":3126},{},[20108,20121,20134,20147],{"data":20109,"content":20110,"nodeType":3061},{},[20111],{"data":20112,"content":20113,"nodeType":881},{},[20114,20118],{"data":20115,"marks":20116,"value":15078,"nodeType":867},{},[20117],{"type":916},{"data":20119,"marks":20120,"value":15082,"nodeType":867},{},[],{"data":20122,"content":20123,"nodeType":3061},{},[20124],{"data":20125,"content":20126,"nodeType":881},{},[20127,20131],{"data":20128,"marks":20129,"value":15093,"nodeType":867},{},[20130],{"type":916},{"data":20132,"marks":20133,"value":15097,"nodeType":867},{},[],{"data":20135,"content":20136,"nodeType":3061},{},[20137],{"data":20138,"content":20139,"nodeType":881},{},[20140,20144],{"data":20141,"marks":20142,"value":15108,"nodeType":867},{},[20143],{"type":916},{"data":20145,"marks":20146,"value":15112,"nodeType":867},{},[],{"data":20148,"content":20149,"nodeType":3061},{},[20150],{"data":20151,"content":20152,"nodeType":881},{},[20153,20157],{"data":20154,"marks":20155,"value":15123,"nodeType":867},{},[20156],{"type":916},{"data":20158,"marks":20159,"value":15127,"nodeType":867},{},[],{"data":20161,"content":20162,"nodeType":881},{},[20163],{"data":20164,"marks":20165,"value":15134,"nodeType":867},{},[],{"data":20167,"content":20168,"nodeType":908},{},[],{"data":20170,"content":20171,"nodeType":918},{},[20172],{"data":20173,"marks":20174,"value":15145,"nodeType":867},{},[20175],{"type":916},{"data":20177,"content":20178,"nodeType":881},{},[20179],{"data":20180,"marks":20181,"value":15152,"nodeType":867},{},[],{"data":20183,"content":20184,"nodeType":881},{},[20185],{"data":20186,"marks":20187,"value":15159,"nodeType":867},{},[],{"data":20189,"content":20192,"nodeType":890},{"target":20190},{"sys":20191},{"id":15164,"type":887,"linkType":888},[],{"data":20194,"content":20195,"nodeType":908},{},[],{"data":20197,"content":20198,"nodeType":918},{},[20199],{"data":20200,"marks":20201,"value":6214,"nodeType":867},{},[20202],{"type":916},{"data":20204,"content":20205,"nodeType":881},{},[20206],{"data":20207,"marks":20208,"value":15182,"nodeType":867},{},[],{"data":20210,"content":20211,"nodeType":881},{},[20212],{"data":20213,"marks":20214,"value":15189,"nodeType":867},{},[],{"data":20216,"content":20217,"nodeType":881},{},[20218],{"data":20219,"marks":20220,"value":15196,"nodeType":867},{},[],{"data":20222,"content":20223,"nodeType":881},{},[20224,20227,20234,20237,20244],{"data":20225,"marks":20226,"value":10795,"nodeType":867},{},[],{"data":20228,"content":20229,"nodeType":876},{"uri":10798},[20230],{"data":20231,"marks":20232,"value":10803,"nodeType":867},{},[20233],{"type":1040},{"data":20235,"marks":20236,"value":15213,"nodeType":867},{},[],{"data":20238,"content":20239,"nodeType":876},{"uri":1629},[20240],{"data":20241,"marks":20242,"value":10826,"nodeType":867},{},[20243],{"type":1040},{"data":20245,"marks":20246,"value":1947,"nodeType":867},{},[],{"items":20248},[20249,20251],{"sys":20250,"name":2547},{"id":2546},{"sys":20252,"name":342},{"id":2550},{"items":20254},[20255],{"fullName":849,"firstName":850,"jobTitle":851,"profilePicture":20256},{"url":855},{"__typename":1742,"sys":20258,"content":20259,"title":21104,"synopsis":21105,"hashTags":59,"publishedDate":21106,"slug":21107,"tagsCollection":21108,"authorsCollection":21114},{"id":3644},{"json":20260},{"data":20261,"content":20262,"nodeType":1640},{},[20263,20271,20278,20285,20292,20304,20311,20317,20323,20326,20334,20341,20348,20354,20374,20381,20387,20394,20400,20407,20450,20456,20462,20469,20476,20479,20487,20507,20514,20520,20539,20545,20564,20571,20574,20582,20589,20633,20645,20648,20656,20673,20680,20696,20703,20710,20716,20723,20726,20734,20741,20794,20801,20804,20812,20818,20825,20832,20838,20845,20878,20885,20892,20898,20905,20911,20919,20936,20943,20976,20983,21016,21019,21027,21034,21040,21059,21066,21092,21098],{"data":20264,"content":20265,"nodeType":918},{},[20266],{"data":20267,"marks":20268,"value":20270,"nodeType":867},{},[20269],{"type":916},"Introducing “ConsentFix” — a new kind of phishing attack",{"data":20272,"content":20273,"nodeType":881},{},[20274],{"data":20275,"marks":20276,"value":20277,"nodeType":867},{},[],"The Push browser agent recently detected and blocked a new attack technique seen targeting several Push customers. ",{"data":20279,"content":20280,"nodeType":881},{},[20281],{"data":20282,"marks":20283,"value":20284,"nodeType":867},{},[],"This is a new kind of browser-based attack technique that takes over user accounts with a simple copy and paste. If you’re already logged into the app in your browser, you don’t even need to supply creds, or pass an MFA check — meaning it effectively circumvents phishing-resistant auth like passkeys too.",{"data":20286,"content":20287,"nodeType":881},{},[20288],{"data":20289,"marks":20290,"value":20291,"nodeType":867},{},[],"This is so different from the AiTM phish kits we usually come up against that we felt it deserved a new name. ",{"data":20293,"content":20294,"nodeType":881},{},[20295,20300],{"data":20296,"marks":20297,"value":20299,"nodeType":867},{},[20298],{"type":916},"Enter: ConsentFix. ",{"data":20301,"marks":20302,"value":20303,"nodeType":867},{},[],"This attack shares a lot of similarities with ClickFix/FileFix, AiTM phishing, and OAuth Consent Phishing. You can think of this as a browser-native ClickFix attack that phishes an OAuth token on a target app by getting the victim to copy and paste a URL containing OAuth key material into a phishing page. ",{"data":20305,"content":20306,"nodeType":881},{},[20307],{"data":20308,"marks":20309,"value":20310,"nodeType":867},{},[],"The campaign we detected looks to be specifically targeting Microsoft accounts by abusing the Azure CLI OAuth app. Essentially, the attacker tricks the victim into logging into Azure CLI, by generating an OAuth authorization code — visible in a localhost URL — and then pasting that URL (including the code) into an attacker-controlled page. This then creates an OAuth connection between the victim’s Microsoft account and the attacker’s Azure CLI instance. ",{"data":20312,"content":20316,"nodeType":890},{"target":20313},{"sys":20314},{"id":20315,"type":887,"linkType":888},"5GTnqWIbmraz8HZeHMybrP",[],{"data":20318,"content":20322,"nodeType":890},{"target":20319},{"sys":20320},{"id":20321,"type":887,"linkType":888},"1lcjX5q3b1bsuhyOXKvJpW",[],{"data":20324,"content":20325,"nodeType":908},{},[],{"data":20327,"content":20328,"nodeType":918},{},[20329],{"data":20330,"marks":20331,"value":20333,"nodeType":867},{},[20332],{"type":916},"How ConsentFix works",{"data":20335,"content":20336,"nodeType":881},{},[20337],{"data":20338,"marks":20339,"value":20340,"nodeType":867},{},[],"In all of the examples we saw, the victim accessed a malicious or compromised webpage via Google Search. The vast majority of the sites we’ve seen associated with the campaign are legitimate, compromised websites with high domain reputation that are easily findable via search engines.",{"data":20342,"content":20343,"nodeType":881},{},[20344],{"data":20345,"marks":20346,"value":20347,"nodeType":867},{},[],"The attacker had injected a fake Cloudflare Turnstile into the compromised websites, requiring an email address to be supplied in order to proceed. ",{"data":20349,"content":20353,"nodeType":890},{"target":20350},{"sys":20351},{"id":20352,"type":887,"linkType":888},"39jEjeLqOYIkGc4o9w3MuX",[],{"data":20355,"content":20356,"nodeType":881},{},[20357,20361,20370],{"data":20358,"marks":20359,"value":20360,"nodeType":867},{},[],"This acted as a form of ",{"data":20362,"content":20364,"nodeType":876},{"uri":20363},"https://phishing-techniques.pushsecurity.com/techniques/conditional-loading/",[20365],{"data":20366,"marks":20367,"value":20369,"nodeType":867},{},[20368],{"type":1040},"conditional loading",{"data":20371,"marks":20372,"value":20373,"nodeType":867},{},[]," that would only continue if a valid email address and domain was supplied, designed to prevent the page from being analyzed by security bots, analysts, and low-value accounts that run the risk of exposing the campaign before the intended recipient(s) can be phished. ",{"data":20375,"content":20376,"nodeType":881},{},[20377],{"data":20378,"marks":20379,"value":20380,"nodeType":867},{},[],"If a domain not on the target list was provided, the victim was passed back to the original website and the attack did not progress to the next stage. Further, once the check has concluded per IP, the phishing page will no longer activate, even a different email is provided.  ",{"data":20382,"content":20386,"nodeType":890},{"target":20383},{"sys":20384},{"id":20385,"type":887,"linkType":888},"7ttmGnTzi9j87tBXfyFcOA",[],{"data":20388,"content":20389,"nodeType":881},{},[20390],{"data":20391,"marks":20392,"value":20393,"nodeType":867},{},[],"After entering an approved email address, the next stage was loaded, prompting the victim to complete a set of instructions on the page to continue.",{"data":20395,"content":20399,"nodeType":890},{"target":20396},{"sys":20397},{"id":20398,"type":887,"linkType":888},"2oHYNoMgAz6MdgLlcWjbaB",[],{"data":20401,"content":20402,"nodeType":881},{},[20403],{"data":20404,"marks":20405,"value":20406,"nodeType":867},{},[],"To complete the attack, the victim must:",{"data":20408,"content":20409,"nodeType":3126},{},[20410,20420,20430,20440],{"data":20411,"content":20412,"nodeType":3061},{},[20413],{"data":20414,"content":20415,"nodeType":881},{},[20416],{"data":20417,"marks":20418,"value":20419,"nodeType":867},{},[],"Click the “Sign In” button. This opens a new tab that loads a legitimate Microsoft URL associated with the user account/email used to access the page.",{"data":20421,"content":20422,"nodeType":3061},{},[20423],{"data":20424,"content":20425,"nodeType":881},{},[20426],{"data":20427,"marks":20428,"value":20429,"nodeType":867},{},[],"If the user is already logged into Microsoft in their browser, they simply need to select their MS account from the dropdown. Otherwise, they will be required to login via the legitimate Microsoft login URL (no phishing takes place at this stage). ",{"data":20431,"content":20432,"nodeType":3061},{},[20433],{"data":20434,"content":20435,"nodeType":881},{},[20436],{"data":20437,"marks":20438,"value":20439,"nodeType":867},{},[],"Once logged into legit Microsoft or the account is selected from the dropdown, the user is redirected to localhost, which generates a URL containing a code associated with the user’s Microsoft account. ",{"data":20441,"content":20442,"nodeType":3061},{},[20443],{"data":20444,"content":20445,"nodeType":881},{},[20446],{"data":20447,"marks":20448,"value":20449,"nodeType":867},{},[],"To complete the phish, the victim copies the URL and pastes it onto the original page. ",{"data":20451,"content":20455,"nodeType":890},{"target":20452},{"sys":20453},{"id":20454,"type":887,"linkType":888},"7zendMbmCViGwtEpUQvq6y",[],{"data":20457,"content":20461,"nodeType":890},{"target":20458},{"sys":20459},{"id":20460,"type":887,"linkType":888},"1eZOs7hXi9FzCE92QEP6xh",[],{"data":20463,"content":20464,"nodeType":881},{},[20465],{"data":20466,"marks":20467,"value":20468,"nodeType":867},{},[],"Once the steps are completed, the victim has granted the attacker access to their Microsoft account via Azure CLI. ",{"data":20470,"content":20471,"nodeType":881},{},[20472],{"data":20473,"marks":20474,"value":20475,"nodeType":867},{},[],"At this point, the attacker has effective control of the victim’s Microsoft account, but without ever needing to phish a password, or pass an MFA check. In fact, if the user was already logged in to their Microsoft account (i.e. they had an active session) no login is required at all. ",{"data":20477,"content":20478,"nodeType":908},{},[],{"data":20480,"content":20481,"nodeType":918},{},[20482],{"data":20483,"marks":20484,"value":20486,"nodeType":867},{},[20485],{"type":916},"The next evolution of ClickFix?",{"data":20488,"content":20489,"nodeType":881},{},[20490,20494,20503],{"data":20491,"marks":20492,"value":20493,"nodeType":867},{},[],"When we presented ",{"data":20495,"content":20497,"nodeType":876},{"uri":20496},"https://pushsecurity.com/webinar/clickfix",[20498],{"data":20499,"marks":20500,"value":20502,"nodeType":867},{},[20501],{"type":1040},"our last webinar on ClickFix",{"data":20504,"marks":20505,"value":20506,"nodeType":867},{},[],", we predicted that the next evolution of the attack would happen entirely within the browser context. This is because any attack that touches the endpoint (a traditionally much better protected surface) is way more likely to be detected. And with many ClickFix attacks being used to deliver infostealer malware, these attacks are really trying to get back into the browser anyway — to steal credentials and sessions stored there. ",{"data":20508,"content":20509,"nodeType":881},{},[20510],{"data":20511,"marks":20512,"value":20513,"nodeType":867},{},[],"Let’s take a closer look at the page — if you follow Push research, you might be getting déjà vu. ",{"data":20515,"content":20519,"nodeType":890},{"target":20516},{"sys":20517},{"id":20518,"type":887,"linkType":888},"1vMZCJ92IxFdR1EzzCOOvb",[],{"data":20521,"content":20522,"nodeType":881},{},[20523,20527,20536],{"data":20524,"marks":20525,"value":20526,"nodeType":867},{},[],"We’ve seen this kind of embedded video player before (albeit a slicker looking one) that we blogged about as ",{"data":20528,"content":20530,"nodeType":876},{"uri":20529},"https://pushsecurity.com/blog/the-most-advanced-clickfix-yet/",[20531],{"data":20532,"marks":20533,"value":20535,"nodeType":867},{},[20534],{"type":1040},"the most advanced ClickFix we’d seen",{"data":20537,"marks":20538,"value":1947,"nodeType":867},{},[],{"data":20540,"content":20544,"nodeType":890},{"target":20541},{"sys":20542},{"id":20543,"type":887,"linkType":888},"ID7VKJNOZk729P5zBOBjZ",[],{"data":20546,"content":20547,"nodeType":881},{},[20548,20552,20560],{"data":20549,"marks":20550,"value":20551,"nodeType":867},{},[],"Another similarity with ClickFix campaigns we’ve investigated is the use of Google Search as a delivery vector. 4 in 5 ClickFix attacks intercepted by Push came via Google Search, with attackers using ",{"data":20553,"content":20555,"nodeType":876},{"uri":20554},"https://phishing-techniques.pushsecurity.com/techniques/malvertising/",[20556],{"data":20557,"marks":20558,"value":441,"nodeType":867},{},[20559],{"type":1040},{"data":20561,"marks":20562,"value":20563,"nodeType":867},{},[]," and either compromised or custom vibe-coded websites to intercept users as they browse the internet. ",{"data":20565,"content":20566,"nodeType":881},{},[20567],{"data":20568,"marks":20569,"value":20570,"nodeType":867},{},[],"So it seems highly likely that this is a kind of browser-native evolution of ClickFix that shares many elements with typical ClickFix attacks, and is probably used by the same groups of attackers.",{"data":20572,"content":20573,"nodeType":908},{},[],{"data":20575,"content":20576,"nodeType":918},{},[20577],{"data":20578,"marks":20579,"value":20581,"nodeType":867},{},[20580],{"type":916},"OAuth shenanigans via Azure CLI",{"data":20583,"content":20584,"nodeType":881},{},[20585],{"data":20586,"marks":20587,"value":20588,"nodeType":867},{},[],"The clever use of Azure CLI and OAuth consent abuse is another clever iteration on previous techniques. ",{"data":20590,"content":20591,"nodeType":881},{},[20592,20596,20605,20608,20616,20620,20629],{"data":20593,"marks":20594,"value":20595,"nodeType":867},{},[],"We’ve previously seen ",{"data":20597,"content":20599,"nodeType":876},{"uri":20598},"https://phishing-techniques.pushsecurity.com/techniques/consent-phishing/",[20600],{"data":20601,"marks":20602,"value":20604,"nodeType":867},{},[20603],{"type":1040},"consent phishing",{"data":20606,"marks":20607,"value":2063,"nodeType":867},{},[],{"data":20609,"content":20611,"nodeType":876},{"uri":20610},"https://phishing-techniques.pushsecurity.com/techniques/device-code-phishing/",[20612],{"data":20613,"marks":20614,"value":13838,"nodeType":867},{},[20615],{"type":1040},{"data":20617,"marks":20618,"value":20619,"nodeType":867},{},[]," attacks where attackers have tricked victims into connecting malicious external apps into their tenant via OAuth, but this is becoming increasingly difficult in core enterprise cloud environments like Azure due to ",{"data":20621,"content":20623,"nodeType":876},{"uri":20622},"https://learn.microsoft.com/en-us/microsoft-365/admin/misc/user-consent?view=o365-worldwide",[20624],{"data":20625,"marks":20626,"value":20628,"nodeType":867},{},[20627],{"type":1040},"stricter default configs",{"data":20630,"marks":20631,"value":20632,"nodeType":867},{},[],". However, since Azure CLI is a first-party Microsoft app, it is implicitly trusted in Entra ID, and is excluded from these restrictions. ",{"data":20634,"content":20635,"nodeType":881},{},[20636,20640],{"data":20637,"marks":20638,"value":20639,"nodeType":867},{},[],"First-party apps like Azure CLI are trusted by default in all tenants, allowed to request permissions without admin approval, and cannot be deleted or blocked. They can also be granted special permissions, such as tenant-wide service permissions (without needing admin approval), use of legacy or undocumented graph scopes, internal scopes for Microsoft client operations, and permissions for Office/Entra admin functions. ",{"data":20641,"marks":20642,"value":20644,"nodeType":867},{},[20643],{"type":916},"This makes Azure CLI a prime target for attackers, and significantly more exploitable than when connecting a third-party app. ",{"data":20646,"content":20647,"nodeType":908},{},[],{"data":20649,"content":20650,"nodeType":918},{},[20651],{"data":20652,"marks":20653,"value":20655,"nodeType":867},{},[20654],{"type":916},"Advanced detection evasion techniques",{"data":20657,"content":20658,"nodeType":881},{},[20659,20663,20669],{"data":20660,"marks":20661,"value":20662,"nodeType":867},{},[],"This campaign features some of the most advanced ",{"data":20664,"content":20665,"nodeType":876},{"uri":2267},[20666],{"data":20667,"marks":20668,"value":16396,"nodeType":867},{},[],{"data":20670,"marks":20671,"value":20672,"nodeType":867},{},[]," we've seen in the wild. ",{"data":20674,"content":20675,"nodeType":881},{},[20676],{"data":20677,"marks":20678,"value":20679,"nodeType":867},{},[],"As well as the use of Google Search to deliver the lure, and bot protection to prevent security tools from analyzing the page, there were multiple layers of anti-analysis techniques to navigate.",{"data":20681,"content":20682,"nodeType":881},{},[20683,20687,20692],{"data":20684,"marks":20685,"value":20686,"nodeType":867},{},[],"We already mentioned the use of selective targeting based on email addresses and domain names. But all sites involved in the campaign also have synchronized IP blocking — meaning if you visit one site and are served one of the associated phishing pages, the phish will never be served again, ",{"data":20688,"marks":20689,"value":20691,"nodeType":867},{},[20690],{"type":916},"across any of the sites linked to the campaign",{"data":20693,"marks":20694,"value":20695,"nodeType":867},{},[],". When you visit any of the sites again, the phish won't trigger, and it can be browsed as normal. ",{"data":20697,"content":20698,"nodeType":881},{},[20699],{"data":20700,"marks":20701,"value":20702,"nodeType":867},{},[],"On the backend, there are multiple checks based on your IP and identifiers unique to your session. Unless all of the conditions are met, certain JavaScript packages won't be served — preventing full inspection of the page to detect malicious elements. ",{"data":20704,"content":20705,"nodeType":881},{},[20706],{"data":20707,"marks":20708,"value":20709,"nodeType":867},{},[],"If the conditions aren't met, the page may not load the Cloudflare Turnstile check at all, or will redirect you back to the site to continue browsing as normal.",{"data":20711,"content":20715,"nodeType":890},{"target":20712},{"sys":20713},{"id":20714,"type":887,"linkType":888},"5v0zDoscA6pYLBfkXrNtIH",[],{"data":20717,"content":20718,"nodeType":881},{},[20719],{"data":20720,"marks":20721,"value":20722,"nodeType":867},{},[],"All of these make it incredibly hard to detect and block these attacks ahead of time when relying on URL-based checks and traffic analysis.",{"data":20724,"content":20725,"nodeType":908},{},[],{"data":20727,"content":20728,"nodeType":918},{},[20729],{"data":20730,"marks":20731,"value":20733,"nodeType":867},{},[20732],{"type":916},"Key takeaways",{"data":20735,"content":20736,"nodeType":881},{},[20737],{"data":20738,"marks":20739,"value":20740,"nodeType":867},{},[],"ConsentFix is a dangerous evolution of ClickFix and consent phishing that is incredibly hard for traditional security tools to detect and block, as:",{"data":20742,"content":20743,"nodeType":3126},{},[20744,20754,20764,20774,20784],{"data":20745,"content":20746,"nodeType":3061},{},[20747],{"data":20748,"content":20749,"nodeType":881},{},[20750],{"data":20751,"marks":20752,"value":20753,"nodeType":867},{},[],"The attack happens entirely inside the browser context, removing one of the key detection opportunities for ClickFix (because it doesn’t touch the endpoint).",{"data":20755,"content":20756,"nodeType":3061},{},[20757],{"data":20758,"content":20759,"nodeType":881},{},[20760],{"data":20761,"marks":20762,"value":20763,"nodeType":867},{},[],"Delivering the lure via a Google Search watering hole attack completely circumvents email-based anti-phishing controls.",{"data":20765,"content":20766,"nodeType":3061},{},[20767],{"data":20768,"content":20769,"nodeType":881},{},[20770],{"data":20771,"marks":20772,"value":20773,"nodeType":867},{},[],"Targeting a first-party app like Azure CLI means that many of the mitigating controls available for third-party app integrations do not apply — making this attack way harder to prevent.",{"data":20775,"content":20776,"nodeType":3061},{},[20777],{"data":20778,"content":20779,"nodeType":881},{},[20780],{"data":20781,"marks":20782,"value":20783,"nodeType":867},{},[],"Because there’s no login required, phishing-resistant authentication controls like passkeys have no impact on this attack. ",{"data":20785,"content":20786,"nodeType":3061},{},[20787],{"data":20788,"content":20789,"nodeType":881},{},[20790],{"data":20791,"marks":20792,"value":20793,"nodeType":867},{},[],"The use of advanced detection evasion techniques makes this attack difficult to investigate, meaning these attacks are going undetected. ",{"data":20795,"content":20796,"nodeType":881},{},[20797],{"data":20798,"marks":20799,"value":20800,"nodeType":867},{},[],"We’re sure to see more examples of ConsentFix in future. We’ll be monitoring to see how attackers adapt in terms of integrating these capabilities with common as-a-Service offerings to make them more widespread, and whether the scope extends further beyond Microsoft / Azure CLI targets in the future to target other enterprise cloud ecosystems. ",{"data":20802,"content":20803,"nodeType":908},{},[],{"data":20805,"content":20806,"nodeType":918},{},[20807],{"data":20808,"marks":20809,"value":20811,"nodeType":867},{},[20810],{"type":916},"Recommendations",{"data":20813,"content":20817,"nodeType":890},{"target":20814},{"sys":20815},{"id":20816,"type":887,"linkType":888},"3aBCwdB2aNnLRxRN5RrshC",[],{"data":20819,"content":20820,"nodeType":881},{},[20821],{"data":20822,"marks":20823,"value":20824,"nodeType":867},{},[],"On the backend, exploitation of this attack will lead to login events being observed to the Microsoft Azure CLI app. It’s likely that any legitimate use of this will most likely be limited to system administrators and possibly developers. Therefore, logins outside of these groups will be inherently more suspicious.",{"data":20826,"content":20827,"nodeType":881},{},[20828],{"data":20829,"marks":20830,"value":20831,"nodeType":867},{},[],"Additionally, it’s possible that aspects of the logins themselves will be different between legitimate Azure CLI use and exploitation of this attack. For example, see the following logs from a lab environment. The login events with an application of  “Microsoft Azure CLI” and a resource of “Azure Resource Manager” was legitimate use of the Azure CLI using the powershell CLI framework. Conversely, the login event with the Resource of “Windows Azure Active Directory” was produced by logging in using the method used by the phishing kit.",{"data":20833,"content":20837,"nodeType":890},{"target":20834},{"sys":20835},{"id":20836,"type":887,"linkType":888},"6ie0nkk6XbgwidfwmiGwL4",[],{"data":20839,"content":20840,"nodeType":881},{},[20841],{"data":20842,"marks":20843,"value":20844,"nodeType":867},{},[],"There is no guarantee this can be used to differentiate between legitimate and malicious examples, but it’s another data point to consider. If searching logs you may wish to use the respective GUIDs for these:",{"data":20846,"content":20847,"nodeType":3126},{},[20848,20863],{"data":20849,"content":20850,"nodeType":3061},{},[20851],{"data":20852,"content":20853,"nodeType":881},{},[20854,20859],{"data":20855,"marks":20856,"value":20858,"nodeType":867},{},[20857],{"type":916},"Application ID",{"data":20860,"marks":20861,"value":20862,"nodeType":867},{},[]," = 04b07795-8ddb-461a-bbee-02f9e1bf7b46",{"data":20864,"content":20865,"nodeType":3061},{},[20866],{"data":20867,"content":20868,"nodeType":881},{},[20869,20874],{"data":20870,"marks":20871,"value":20873,"nodeType":867},{},[20872],{"type":916},"Resource ID",{"data":20875,"marks":20876,"value":20877,"nodeType":867},{},[]," = 00000002-0000-0000-c000-000000000000",{"data":20879,"content":20880,"nodeType":881},{},[20881],{"data":20882,"marks":20883,"value":20884,"nodeType":867},{},[],"For interactive logins, like above, you cannot rely on looking for logins from suspicious IP addresses or locations. The login itself occurs from the victims browser directly to Microsoft, and so the IP addresses associated with these events will be the legitimate IP used by the target user, not by the threat actor. ",{"data":20886,"content":20887,"nodeType":881},{},[20888],{"data":20889,"marks":20890,"value":20891,"nodeType":867},{},[],"However, for non-interactive logins and other audit logs for actions taken, you may be able to uncover unusual IP addresses that differ from the original interactive login. For example, here are some non-interactive logins that were observed immediately after compromise that came from different IP addresses in both the US and Indonesia.",{"data":20893,"content":20897,"nodeType":890},{"target":20894},{"sys":20895},{"id":20896,"type":887,"linkType":888},"TD3YeWqgGIWIWM8FRHU4o",[],{"data":20899,"content":20900,"nodeType":881},{},[20901],{"data":20902,"marks":20903,"value":20904,"nodeType":867},{},[],"Interestingly, they differ in which resources they accessed, with one accessing the Windows Azure Active Directory resource ID like the interactive login, but two others accessing the Microsoft Intune Checkin resource ID. ",{"data":20906,"content":20910,"nodeType":890},{"target":20907},{"sys":20908},{"id":20909,"type":887,"linkType":888},"57PqDQiAiwzqkspVpROQXb",[],{"data":20912,"content":20913,"nodeType":998},{},[20914],{"data":20915,"marks":20916,"value":20918,"nodeType":867},{},[20917],{"type":916},"IoCs",{"data":20920,"content":20921,"nodeType":881},{},[20922,20925,20932],{"data":20923,"marks":20924,"value":9997,"nodeType":867},{},[],{"data":20926,"content":20927,"nodeType":876},{"uri":2392},[20928],{"data":20929,"marks":20930,"value":2397,"nodeType":867},{},[20931],{"type":1040},{"data":20933,"marks":20934,"value":20935,"nodeType":867},{},[]," in the attack chain, often dynamically serving different URLs to site visitors. ",{"data":20937,"content":20938,"nodeType":881},{},[20939],{"data":20940,"marks":20941,"value":20942,"nodeType":867},{},[],"That said, the domains used to deliver the final phishing payload were:",{"data":20944,"content":20945,"nodeType":3126},{},[20946,20956,20966],{"data":20947,"content":20948,"nodeType":3061},{},[20949],{"data":20950,"content":20951,"nodeType":881},{},[20952],{"data":20953,"marks":20954,"value":20955,"nodeType":867},{},[],"hxxps://trustpointassurance.com/",{"data":20957,"content":20958,"nodeType":3061},{},[20959],{"data":20960,"content":20961,"nodeType":881},{},[20962],{"data":20963,"marks":20964,"value":20965,"nodeType":867},{},[],"hxxps://fastwaycheck.com/",{"data":20967,"content":20968,"nodeType":3061},{},[20969],{"data":20970,"content":20971,"nodeType":881},{},[20972],{"data":20973,"marks":20974,"value":20975,"nodeType":867},{},[],"hxxps://previewcentral.com",{"data":20977,"content":20978,"nodeType":881},{},[20979],{"data":20980,"marks":20981,"value":20982,"nodeType":867},{},[],"In addition, we recommend hunting for connections from the following IPs in Azure logs:",{"data":20984,"content":20985,"nodeType":3126},{},[20986,20996,21006],{"data":20987,"content":20988,"nodeType":3061},{},[20989],{"data":20990,"content":20991,"nodeType":881},{},[20992],{"data":20993,"marks":20994,"value":20995,"nodeType":867},{},[],"12.75.216.90",{"data":20997,"content":20998,"nodeType":3061},{},[20999],{"data":21000,"content":21001,"nodeType":881},{},[21002],{"data":21003,"marks":21004,"value":21005,"nodeType":867},{},[],"182.3.36.223",{"data":21007,"content":21008,"nodeType":3061},{},[21009],{"data":21010,"content":21011,"nodeType":881},{},[21012],{"data":21013,"marks":21014,"value":21015,"nodeType":867},{},[],"12.75.116.137",{"data":21017,"content":21018,"nodeType":908},{},[],{"data":21020,"content":21021,"nodeType":918},{},[21022],{"data":21023,"marks":21024,"value":21026,"nodeType":867},{},[21025],{"type":916},"How Push stopped the attack",{"data":21028,"content":21029,"nodeType":881},{},[21030],{"data":21031,"marks":21032,"value":21033,"nodeType":867},{},[],"Even though this was a brand new technique, Push intercepted this attack and shut it down before customers could interact with it. ",{"data":21035,"content":21039,"nodeType":890},{"target":21036},{"sys":21037},{"id":21038,"type":887,"linkType":888},"5YzpiQH974EYA5iPPZMXkV",[],{"data":21041,"content":21042,"nodeType":881},{},[21043,21047,21055],{"data":21044,"marks":21045,"value":21046,"nodeType":867},{},[],"Push doesn’t detect the redirect tricks or rely on outdated domain TI feeds. The reason we detect these attacks (which make it through all the other layers of phishing protection) is that Push sees what your users see. It doesn’t matter what ",{"data":21048,"content":21049,"nodeType":876},{"uri":2267},[21050],{"data":21051,"marks":21052,"value":21054,"nodeType":867},{},[21053],{"type":1040},"delivery channel or camouflage methods are used",{"data":21056,"marks":21057,"value":21058,"nodeType":867},{},[],", Push shuts the attack down in real time, as the user loads the malicious page in their web browser.",{"data":21060,"content":21061,"nodeType":881},{},[21062],{"data":21063,"marks":21064,"value":21065,"nodeType":867},{},[],"This isn’t all we do: Push’s browser-based security platform provides comprehensive detection and response capabilities against the leading cause of breaches. Push blocks browser-based attacks like AiTM phishing, credential stuffing, malicious browser extensions, ClickFix, and session hijacking. You don’t need to wait until it all goes wrong — you can also use Push to proactively find and fix vulnerabilities across the apps that your employees use, like ghost logins, SSO coverage gaps, MFA gaps, vulnerable passwords, and more to harden your identity attack surface.",{"data":21067,"content":21068,"nodeType":881},{},[21069,21072,21079,21082,21089],{"data":21070,"marks":21071,"value":10795,"nodeType":867},{},[],{"data":21073,"content":21074,"nodeType":876},{"uri":10798},[21075],{"data":21076,"marks":21077,"value":10803,"nodeType":867},{},[21078],{"type":1040},{"data":21080,"marks":21081,"value":15213,"nodeType":867},{},[],{"data":21083,"content":21084,"nodeType":876},{"uri":1629},[21085],{"data":21086,"marks":21087,"value":10826,"nodeType":867},{},[21088],{"type":1040},{"data":21090,"marks":21091,"value":1947,"nodeType":867},{},[],{"data":21093,"content":21097,"nodeType":890},{"target":21094},{"sys":21095},{"id":21096,"type":887,"linkType":888},"6QzB0BlVC5mstXwXHvy2c3",[],{"data":21099,"content":21100,"nodeType":881},{},[21101],{"data":21102,"marks":21103,"value":21,"nodeType":867},{},[],"ConsentFix: Analyzing a browser-native ClickFix-style attack that hijacks OAuth consent grants","Analyzing \"ConsentFix\", a new browser-native attack technique we've detected in the wild, combining OAuth consent phishing with a ClickFix-style user prompt. ","2025-12-11T00:00:00.000Z","consentfix",{"items":21109},[21110,21112],{"sys":21111,"name":2547},{"id":2546},{"sys":21113,"name":342},{"id":2550},{"items":21115},[21116],{"fullName":15937,"firstName":15938,"jobTitle":15939,"profilePicture":21117},{"url":15943},{"__typename":1742,"sys":21119,"content":21121,"title":21727,"synopsis":21728,"hashTags":59,"publishedDate":21729,"slug":21730,"tagsCollection":21731,"authorsCollection":21737},{"id":21120},"44DXq5ZkL9XQV5Fngto0XZ",{"json":21122},{"data":21123,"content":21124,"nodeType":1640},{},[21125,21142,21149,21156,21159,21167,21187,21206,21240,21246,21249,21257,21265,21272,21290,21297,21302,21308,21315,21322,21330,21337,21344,21350,21357,21377,21385,21392,21399,21419,21425,21444,21450,21457,21463,21466,21473,21480,21499,21506,21533,21540,21548,21551,21559,21566,21573,21579,21586,21631,21637,21644,21675,21680,21721],{"data":21126,"content":21127,"nodeType":881},{},[21128,21131,21138],{"data":21129,"marks":21130,"value":21,"nodeType":867},{},[],{"data":21132,"content":21133,"nodeType":876},{"uri":3051},[21134],{"data":21135,"marks":21136,"value":3056,"nodeType":867},{},[21137],{"type":1040},{"data":21139,"marks":21140,"value":21141,"nodeType":867},{},[]," are running a large-scale hybrid vishing plus AiTM phishing campaign across several industry verticals, targeting Okta, Entra, and Google SSO platforms. ",{"data":21143,"content":21144,"nodeType":881},{},[21145],{"data":21146,"marks":21147,"value":21148,"nodeType":867},{},[],"The attacks begin with the attacker calling their victim, impersonating IT staff from their company. They offer to help the employee set up passkeys for logging into the enterprise SSO service, tricking the victim into visiting a specially crafted adversary-in-the-middle phishing site that captures their SSO credentials, MFA codes, and ultimately live session access. ",{"data":21150,"content":21151,"nodeType":881},{},[21152],{"data":21153,"marks":21154,"value":21155,"nodeType":867},{},[],"Once an account is stolen, the attacker logs in to the SSO dashboard to see which platforms they have access to and then proceeds to steal data from them — with the ultimate goal of extorting victims. ",{"data":21157,"content":21158,"nodeType":908},{},[],{"data":21160,"content":21161,"nodeType":918},{},[21162],{"data":21163,"marks":21164,"value":21166,"nodeType":867},{},[21165],{"type":916},"What we know",{"data":21168,"content":21169,"nodeType":881},{},[21170,21174,21183],{"data":21171,"marks":21172,"value":21173,"nodeType":867},{},[],"To date, ",{"data":21175,"content":21177,"nodeType":876},{"uri":21176},"https://www.silentpush.com/blog/slsh-alert/",[21178],{"data":21179,"marks":21180,"value":21182,"nodeType":867},{},[21181],{"type":1040},"100+ companies have been targeted",{"data":21184,"marks":21185,"value":21186,"nodeType":867},{},[],", with infrastructure and domains impersonating their brand to be used in legit-looking campaigns against them. The reality is that the list of targets could be more extensive, and will continue to increase over time. ",{"data":21188,"content":21189,"nodeType":881},{},[21190,21194,21202],{"data":21191,"marks":21192,"value":21193,"nodeType":867},{},[],"SLH ",{"data":21195,"content":21196,"nodeType":876},{"uri":14682},[21197],{"data":21198,"marks":21199,"value":21201,"nodeType":867},{},[21200],{"type":1040},"claims to be using data stolen in previous breaches",{"data":21203,"marks":21204,"value":21205,"nodeType":867},{},[],", such as the widespread Salesforce data theft attacks reported in 2025, to identify and contact employees. This data includes phone numbers, job titles, names, and other details used to make the social engineering calls more convincing.",{"data":21207,"content":21208,"nodeType":881},{},[21209,21213,21218,21222,21227,21231,21236],{"data":21210,"marks":21211,"value":21212,"nodeType":867},{},[],"The group recently relaunched its Tor data leak site, which currently lists breaches at ",{"data":21214,"marks":21215,"value":21217,"nodeType":867},{},[21216],{"type":916},"Betterment",{"data":21219,"marks":21220,"value":21221,"nodeType":867},{},[]," (20 million records containing PII), ",{"data":21223,"marks":21224,"value":21226,"nodeType":867},{},[21225],{"type":916},"Crunchbase",{"data":21228,"marks":21229,"value":21230,"nodeType":867},{},[]," (2 million records containing PII), and ",{"data":21232,"marks":21233,"value":21235,"nodeType":867},{},[21234],{"type":916},"SoundCloud",{"data":21237,"marks":21238,"value":21239,"nodeType":867},{},[]," (30 million records containing PII). ",{"data":21241,"content":21245,"nodeType":890},{"target":21242},{"sys":21243},{"id":21244,"type":887,"linkType":888},"5scKHYJJleNklGAXNKVc7b",[],{"data":21247,"content":21248,"nodeType":908},{},[],{"data":21250,"content":21251,"nodeType":918},{},[21252],{"data":21253,"marks":21254,"value":21256,"nodeType":867},{},[21255],{"type":916},"What’s new?",{"data":21258,"content":21259,"nodeType":998},{},[21260],{"data":21261,"marks":21262,"value":21264,"nodeType":867},{},[21263],{"type":916},"The best of both worlds? Vishing + AiTM phishing",{"data":21266,"content":21267,"nodeType":881},{},[21268],{"data":21269,"marks":21270,"value":21271,"nodeType":867},{},[],"SLH and threat actors affiliated with “The Com” are no stranger to voice phishing (vishing) or the use of MFA-bypassing Attacker-in-the-Middle (AitM) phishing kits. ",{"data":21273,"content":21274,"nodeType":881},{},[21275,21278,21286],{"data":21276,"marks":21277,"value":21,"nodeType":867},{},[],{"data":21279,"content":21280,"nodeType":876},{"uri":3051},[21281],{"data":21282,"marks":21283,"value":21285,"nodeType":867},{},[21284],{"type":1040},"SLH and it’s precursor groups",{"data":21287,"marks":21288,"value":21289,"nodeType":867},{},[]," leveraged vishing to great success in the form of help desk impersonation and password/MFA reset attacks as seen in the high profile Marks & Spencer, Co-Op, and Jaguar Land Rover attacks in 2025, as well as the Caesars and MGM attacks in 2023. MFA-bypassing phishing techniques have also long been a part of their arsenal, from the 2022 0ktapus phishing campaign to more recent use of modern AiTM phishing kits. ",{"data":21291,"content":21292,"nodeType":881},{},[21293],{"data":21294,"marks":21295,"value":21296,"nodeType":867},{},[],"But until now, we haven’t seen them used together. ",{"data":21298,"content":21301,"nodeType":890},{"target":21299},{"sys":21300},{"id":14442,"type":887,"linkType":888},[],{"data":21303,"content":21307,"nodeType":890},{"target":21304},{"sys":21305},{"id":21306,"type":887,"linkType":888},"1IDsaYD3H5MjvPS4ekcUhU",[],{"data":21309,"content":21310,"nodeType":881},{},[21311],{"data":21312,"marks":21313,"value":21314,"nodeType":867},{},[],"It makes sense to combine these methods. AiTM phishing kits are flexible, highly customizable, and can be used to target a broad range of apps — including all of the major IdP platforms used for SSO. Vishing on the other hand is proven to increase the effectiveness of social engineering attacks when performed by an effective operator — which SLH are proven to be (helped by predominantly native English speakers making up their membership, along with the use of effective voice phishing tools). ",{"data":21316,"content":21317,"nodeType":881},{},[21318],{"data":21319,"marks":21320,"value":21321,"nodeType":867},{},[],"Both vishing and AiTM phishing are identity-first methods that consciously evade traditional security tools and detection controls at the endpoint and network layer. This makes them highly effective in today’s IT environment. ",{"data":21323,"content":21324,"nodeType":998},{},[21325],{"data":21326,"marks":21327,"value":21329,"nodeType":867},{},[21328],{"type":916},"A new kind of operator-driven AiTM kit",{"data":21331,"content":21332,"nodeType":881},{},[21333],{"data":21334,"marks":21335,"value":21336,"nodeType":867},{},[],"Another unique part about this campaign is that it uses a “live phishing panel” — i.e. a customizable phishing page controlled by the attacker in real time. This enables attackers to dynamically change what a victim sees on a phishing site while speaking to them on the phone. This allows them to guide victims through each step of the login and MFA authentication process.",{"data":21338,"content":21339,"nodeType":881},{},[21340],{"data":21341,"marks":21342,"value":21343,"nodeType":867},{},[],"This is principally to increase the victim’s likelihood of engaging with the phishing page. As you can see in the image below, there are several options that can be presented to the victim — including not just the normal phishing stages of entering credentials and passing MFA checks, but also post-compromise actions (e.g. creating a passkey that would then be controlled by the attacker for persistent access even if an account password is reset). ",{"data":21345,"content":21349,"nodeType":890},{"target":21346},{"sys":21347},{"id":21348,"type":887,"linkType":888},"73Y2n3tRkGFtfhrA2AVJyv",[],{"data":21351,"content":21352,"nodeType":881},{},[21353],{"data":21354,"marks":21355,"value":21356,"nodeType":867},{},[],"At the end of the authentication flow, the threat actor can choose to redirect their target to a “support ticket\" closure screen. This allows the threat actor to manually terminate the session once the compromise is complete while providing the targeted user with context that matches the \"IT support\" ruse. This further reduces the likelihood of post-hoc reporting by a suspicious victim.",{"data":21358,"content":21359,"nodeType":881},{},[21360,21364,21373],{"data":21361,"marks":21362,"value":21363,"nodeType":867},{},[],"Given that this modular, operator-controlled phishing kit is reportedly available “",{"data":21365,"content":21367,"nodeType":876},{"uri":21366},"https://www.okta.com/blog/threat-intelligence/phishing-kits-adapt-to-the-script-of-callers/",[21368],{"data":21369,"marks":21370,"value":21372,"nodeType":867},{},[21371],{"type":1040},"as a service",{"data":21374,"marks":21375,"value":21376,"nodeType":867},{},[],"” for criminals, we should expect to see much more of this in future. ",{"data":21378,"content":21379,"nodeType":998},{},[21380],{"data":21381,"marks":21382,"value":21384,"nodeType":867},{},[21383],{"type":916},"0ktapus 2.0?",{"data":21386,"content":21387,"nodeType":881},{},[21388],{"data":21389,"marks":21390,"value":21391,"nodeType":867},{},[],"As we mentioned earlier, Scattered Spider made their reputation launching phishing attacks against Okta accounts in the 2022 0ktapus campaign. ",{"data":21393,"content":21394,"nodeType":881},{},[21395],{"data":21396,"marks":21397,"value":21398,"nodeType":867},{},[],"The vast majority of phishing attacks target IdP accounts because of the widespread access to downstream apps they grant via SSO. ",{"data":21400,"content":21401,"nodeType":881},{},[21402,21406,21415],{"data":21403,"marks":21404,"value":21405,"nodeType":867},{},[],"This comes at the same time as ",{"data":21407,"content":21409,"nodeType":876},{"uri":21408},"https://www.bleepingcomputer.com/news/security/fake-lastpass-emails-pose-as-password-vault-backup-alerts/",[21410],{"data":21411,"marks":21412,"value":21414,"nodeType":867},{},[21413],{"type":1040},"attackers running campaigns to target LastPass master passwords",{"data":21416,"marks":21417,"value":21418,"nodeType":867},{},[],". This provides a similar level of access to apps in the form of credentials (and sometimes saved passkeys). ",{"data":21420,"content":21424,"nodeType":890},{"target":21421},{"sys":21422},{"id":21423,"type":887,"linkType":888},"1vyu5WvdktTnC24TkVFqfs",[],{"data":21426,"content":21427,"nodeType":881},{},[21428,21432,21440],{"data":21429,"marks":21430,"value":21431,"nodeType":867},{},[],"Not only is this a goldmine for attackers looking to steal data or pivot to other systems to be able to launch further attacks (e.g. pivoting to cloud and on-prem services for ransomware deployment) but it’s a nightmare for incident responders. If an attacker can access an app and create a backdoor login method (AKA. a ",{"data":21433,"content":21434,"nodeType":876},{"uri":6845},[21435],{"data":21436,"marks":21437,"value":21439,"nodeType":867},{},[21438],{"type":1040},"ghost login",{"data":21441,"marks":21442,"value":21443,"nodeType":867},{},[],") it can be very difficult for a security team to identify and clean them up. ",{"data":21445,"content":21449,"nodeType":890},{"target":21446},{"sys":21447},{"id":21448,"type":887,"linkType":888},"7tILkroPw9w0WLIo1bVV24",[],{"data":21451,"content":21452,"nodeType":881},{},[21453],{"data":21454,"marks":21455,"value":21456,"nodeType":867},{},[],"Check out the excerpt from one of our recent webinars below for more information. ",{"data":21458,"content":21462,"nodeType":890},{"target":21459},{"sys":21460},{"id":21461,"type":887,"linkType":888},"5IVkapjwLp1Ys14vXagQRD",[],{"data":21464,"content":21465,"nodeType":908},{},[],{"data":21467,"content":21468,"nodeType":918},{},[21469],{"data":21470,"marks":21471,"value":2257,"nodeType":867},{},[21472],{"type":916},{"data":21474,"content":21475,"nodeType":881},{},[21476],{"data":21477,"marks":21478,"value":21479,"nodeType":867},{},[],"This combination of methods is likely to increase the success of these malicious campaigns as well as reducing the likelihood of detection. ",{"data":21481,"content":21482,"nodeType":881},{},[21483,21487,21495],{"data":21484,"marks":21485,"value":21486,"nodeType":867},{},[],"It’s well documented that modern phishing attacks use a wide and ever-expanding range of ",{"data":21488,"content":21490,"nodeType":876},{"uri":21489},"https://pushsecurity.com/blog/phishing-detection-evasion-launch/",[21491],{"data":21492,"marks":21493,"value":16396,"nodeType":867},{},[21494],{"type":1040},{"data":21496,"marks":21497,"value":21498,"nodeType":867},{},[]," — from implementing legitimate bot protection technologies to prevent analysis, to only loading pages if the correct parameters are met — such as coming through a specific URL redirect path, and adhering to “normal” browser configs (excluding unusual browser window sizes and the presence of security analysis tools).",{"data":21500,"content":21501,"nodeType":881},{},[21502],{"data":21503,"marks":21504,"value":21505,"nodeType":867},{},[],"In this case, the malicious payload will only trigger in the event that the delivery is approved by an operator in real time. This means that anyone attempting to find and proactively block a phishing page based on indicators of known-bad is going to have a tough time finding and flagging them. If you haven’t got a community of security analysts sharing and tagging samples of malicious pages, it makes it really hard to find and block them at scale before they hit a victim. And if these convincing attacks aren’t being reported, they’re even less likely to be investigated. This is what we mean when we say that most phishing attacks today are effectively zero-day. ",{"data":21507,"content":21508,"nodeType":881},{},[21509,21513,21518,21521,21529],{"data":21510,"marks":21511,"value":21512,"nodeType":867},{},[],"In this case, it’s worth pointing out that the phone call is essentially the delivery vector for the phishing page. This means there’s no email to intercept and analyse. This isn’t new — ",{"data":21514,"marks":21515,"value":21517,"nodeType":867},{},[21516],{"type":916},"non-email vectors now account for more than 1 in 3 phishing attacks intercepted by Push",{"data":21519,"marks":21520,"value":4006,"nodeType":867},{},[],{"data":21522,"content":21523,"nodeType":876},{"uri":2731},[21524],{"data":21525,"marks":21526,"value":21528,"nodeType":867},{},[21527],{"type":1040},"LinkedIn and Google Search being the top culprits",{"data":21530,"marks":21531,"value":21532,"nodeType":867},{},[],". This effectively cuts out the primary phishing detection surface for most organizations.",{"data":21534,"content":21535,"nodeType":881},{},[21536],{"data":21537,"marks":21538,"value":21539,"nodeType":867},{},[],"All this means that unless you’re able to detect and block these attacks in real time, organizations will find themselves unable to counter this evolving threat. ",{"data":21541,"content":21542,"nodeType":881},{},[21543],{"data":21544,"marks":21545,"value":21547,"nodeType":867},{},[21546],{"type":916},"The best/only way to do that is to be in the browser. ",{"data":21549,"content":21550,"nodeType":908},{},[],{"data":21552,"content":21553,"nodeType":918},{},[21554],{"data":21555,"marks":21556,"value":21558,"nodeType":867},{},[21557],{"type":916},"How Push stops the attack",{"data":21560,"content":21561,"nodeType":881},{},[21562],{"data":21563,"marks":21564,"value":21565,"nodeType":867},{},[],"As a browser-based detection and response tool, Push is perfectly positioned to detect and block attacks like this in real-time. ",{"data":21567,"content":21568,"nodeType":881},{},[21569],{"data":21570,"marks":21571,"value":21572,"nodeType":867},{},[],"Push harnesses deep browser telemetry to detect and block phishing based on behaviors, not static indicators. By analyzing how phishing pages behave and how users interact with them, Push uncovers fake pages, attempted credential theft, and phishing kits the moment they load in the browser — regardless of the delivery mechanism, and even when the attack has never been seen before. ",{"data":21574,"content":21578,"nodeType":890},{"target":21575},{"sys":21576},{"id":21577,"type":887,"linkType":888},"2TAKFM1rpETq4KtTY3FPIs",[],{"data":21580,"content":21581,"nodeType":881},{},[21582],{"data":21583,"marks":21584,"value":21585,"nodeType":867},{},[],"Push's browser-based controls include:",{"data":21587,"content":21588,"nodeType":3126},{},[21589,21610],{"data":21590,"content":21591,"nodeType":3061},{},[21592],{"data":21593,"content":21594,"nodeType":881},{},[21595,21598,21606],{"data":21596,"marks":21597,"value":21,"nodeType":867},{},[],{"data":21599,"content":21601,"nodeType":876},{"uri":21600},"https://pushsecurity.com/blog/introducing-sso-password-protection/",[21602],{"data":21603,"marks":21604,"value":21605,"nodeType":867},{},[],"Fingerprinting high-risk app passwords",{"data":21607,"marks":21608,"value":21609,"nodeType":867},{},[]," so they can only be used on a specific domain. Any attempt to reuse this password elsewhere (such as on a phishing site) results in the attempt being blocked. ",{"data":21611,"content":21612,"nodeType":3061},{},[21613],{"data":21614,"content":21615,"nodeType":881},{},[21616,21619,21627],{"data":21617,"marks":21618,"value":21,"nodeType":867},{},[],{"data":21620,"content":21622,"nodeType":876},{"uri":21621},"https://pushsecurity.com/blog/detecting-and-blocking-phishing-attacks-in-the-browser/",[21623],{"data":21624,"marks":21625,"value":21626,"nodeType":867},{},[],"Multiple browser-based checks",{"data":21628,"marks":21629,"value":21630,"nodeType":867},{},[]," looking for indicators of bad, such as cloned elements from legitimate websites, and an ever-growing number of detections relating to phishing kit behaviors and attributes as they are rendered on a page. ",{"data":21632,"content":21636,"nodeType":890},{"target":21633},{"sys":21634},{"id":21635,"type":887,"linkType":888},"4ESxxjTjNwNXGEW4DBcMVV",[],{"data":21638,"content":21639,"nodeType":881},{},[21640],{"data":21641,"marks":21642,"value":21643,"nodeType":867},{},[],"Because Push observes every login made in the browser, you can also use Push to find identities susceptible to phishing attacks, such as those not using phishing-resistant authentication methods (e.g. passkeys), to proactively improve your account hygiene and reduce your attack surface. ",{"data":21645,"content":21646,"nodeType":881},{},[21647,21651,21659,21663,21671],{"data":21648,"marks":21649,"value":21650,"nodeType":867},{},[],"Finally, you can also use our ",{"data":21652,"content":21653,"nodeType":876},{"uri":15783},[21654],{"data":21655,"marks":21656,"value":21658,"nodeType":867},{},[21657],{"type":1040},"employee verification codes",{"data":21660,"marks":21661,"value":21662,"nodeType":867},{},[]," feature as part of a layered defense — a simple, browser-based identity check that gives your employees a reliable way to confirm they’re talking to another employee from your organization. It enables employees to quickly verify that a caller is who they say they are by relaying a rotating 6-digit verification code displayed in every employee's browser via the Push extension. This is an effective way of combating ",{"data":21664,"content":21665,"nodeType":876},{"uri":14788},[21666],{"data":21667,"marks":21668,"value":21670,"nodeType":867},{},[21669],{"type":1040},"help desk scams",{"data":21672,"marks":21673,"value":21674,"nodeType":867},{},[]," too — another favorite of SLH. ",{"data":21676,"content":21679,"nodeType":890},{"target":21677},{"sys":21678},{"id":15799,"type":887,"linkType":888},[],{"data":21681,"content":21682,"nodeType":1433},{},[21683],{"data":21684,"content":21685,"nodeType":881},{},[21686,21690,21698,21701,21708,21711,21718],{"data":21687,"marks":21688,"value":21689,"nodeType":867},{},[],"Want to learn more about Push? ",{"data":21691,"content":21692,"nodeType":876},{"uri":10798},[21693],{"data":21694,"marks":21695,"value":21697,"nodeType":867},{},[21696],{"type":1040},"Check out our latest product overview",{"data":21699,"marks":21700,"value":4006,"nodeType":867},{},[],{"data":21702,"content":21703,"nodeType":876},{"uri":10809},[21704],{"data":21705,"marks":21706,"value":21707,"nodeType":867},{},[],"visit our demo library",{"data":21709,"marks":21710,"value":10819,"nodeType":867},{},[],{"data":21712,"content":21713,"nodeType":876},{"uri":1629},[21714],{"data":21715,"marks":21716,"value":10826,"nodeType":867},{},[21717],{"type":1040},{"data":21719,"marks":21720,"value":1947,"nodeType":867},{},[],{"data":21722,"content":21723,"nodeType":881},{},[21724],{"data":21725,"marks":21726,"value":21,"nodeType":867},{},[],"Unpacking the latest SLH campaign — combining vishing with AiTM phishing to hijack SSO accounts","Analyzing the latest Scattered Lapsus$ Hunters (SLH) phishing campaign targeting hundreds of organizations.\n","2026-01-28T00:00:00.000Z","unpacking-the-latest-slh-campaign",{"items":21732},[21733,21735],{"sys":21734,"name":2547},{"id":2546},{"sys":21736,"name":342},{"id":2550},{"items":21738},[21739],{"fullName":849,"firstName":850,"jobTitle":851,"profilePicture":21740},{"url":855},"blog/device-code-phishing",{"json":21743},{"data":21744,"content":21745,"nodeType":1640},{},[21746],{"data":21747,"content":21748,"nodeType":881},{},[21749],{"data":21750,"marks":21751,"value":21752,"nodeType":867},{},[],"Device code phishing is an account takeover technique that abuses the OAuth 2.0 Device Authorization Grant to steal access tokens while bypassing standard access controls (like passwords, MFA, and even passkeys).","Device code phishing is seeing a huge spike in adoption in 2026, enabling attackers to steal access tokens while bypassing standard access controls.",{"id":3620,"publishedAt":21755},"2026-08-12T11:53:02.556Z",{"items":21757},[21758,21760],{"sys":21759,"name":2547},{"id":2546},{"sys":21761,"name":342},{"id":2550},{"items":21763},[21764,21766,21768,21770,21772,21774,21776,21778,21780,21782,21784,21786,21788,21790,21792,21794,21796],{"sys":21765,"name":279,"slug":280,"tier":31},{"id":276},{"sys":21767,"name":519,"slug":520,"tier":31},{"id":516},{"sys":21769,"name":413,"slug":414,"tier":31},{"id":410},{"sys":21771,"name":642,"slug":643,"tier":31},{"id":639},{"sys":21773,"name":342,"slug":343,"tier":31},{"id":339},{"sys":21775,"name":360,"slug":361,"tier":45},{"id":357},{"sys":21777,"name":466,"slug":467,"tier":45},{"id":463},{"sys":21779,"name":484,"slug":485,"tier":45},{"id":481},{"sys":21781,"name":571,"slug":572,"tier":45},{"id":568},{"sys":21783,"name":511,"slug":512,"tier":45},{"id":508},{"sys":21785,"name":607,"slug":608,"tier":45},{"id":604},{"sys":21787,"name":650,"slug":651,"tier":45},{"id":647},{"sys":21789,"name":261,"slug":262,"tier":45},{"id":258},{"sys":21791,"name":493,"slug":494,"tier":45},{"id":490},{"sys":21793,"name":475,"slug":476,"tier":45},{"id":472},{"sys":21795,"name":404,"slug":405,"tier":45},{"id":401},{"sys":21797,"name":315,"slug":316,"tier":45},{"id":312},"8tjCe4rlgxCHc3XVdlvd0ZnFwPabXi2E9C7FD0L6OHs",{"id":21800,"title":21801,"authorsCollection":21802,"content":21807,"extension":228,"faqItemsCollection":22754,"faqTitle":59,"featured":6,"hashTags":59,"meta":22756,"metaTitle":22757,"ogImage":59,"postType":22758,"publishedDate":22759,"relatedBlogPostsCollection":22760,"slug":24873,"stem":24874,"subtitle":59,"summary":24875,"synopsis":24886,"sys":24887,"tagsCollection":24890,"topicsCollection":24896,"__hash__":24928},"blog/blog/stryker-handala-report.json","The Stryker breach didn't match the playbook. That shouldn't be a surprise.",{"items":21803},[21804],{"fullName":849,"firstName":850,"jobTitle":851,"socialLinks":21805,"profilePicture":21806},[853],{"url":855},{"json":21808,"links":22710},{"data":21809,"content":21810,"nodeType":1640},{},[21811,21818,21824,21843,21846,21854,21861,21868,21871,21879,21886,22057,22064,22071,22074,22082,22089,22096,22103,22110,22113,22121,22140,22147,22155,22162,22307,22326,22334,22341,22476,22495,22501,22504,22512,22519,22526,22533,22536,22544,22584,22615,22622,22628,22631,22638,22645,22652,22659,22662,22670,22677],{"data":21812,"content":21813,"nodeType":881},{},[21814],{"data":21815,"marks":21816,"value":21817,"nodeType":867},{},[],"On the morning of March 11, employees at Stryker Corporation offices across 79 countries turned on their laptops and found them wiped and unusable. Personal phones enrolled in the company's BYOD program had been factory reset overnight, taking photos, banking apps, and authenticator tokens with them. Login pages had also been defaced with the logo of Handala, a persona operated by Iran's Ministry of Intelligence and Security (MOIS).",{"data":21819,"content":21823,"nodeType":890},{"target":21820},{"sys":21821},{"id":21822,"type":887,"linkType":888},"6JtlGFq0RDoW9g6zyAcPvn",[],{"data":21825,"content":21826,"nodeType":881},{},[21827,21831,21839],{"data":21828,"marks":21829,"value":21830,"nodeType":867},{},[],"In a break from the standard Handala playbook, there was no ransomware, no malware, and no exploit chain. The attacker ",{"data":21832,"content":21834,"nodeType":876},{"uri":21833},"https://www.bleepingcomputer.com/news/security/stryker-attack-wiped-tens-of-thousands-of-devices-no-malware-needed/",[21835],{"data":21836,"marks":21837,"value":21838,"nodeType":867},{},[],"simply logged into Microsoft Intune",{"data":21840,"marks":21841,"value":21842,"nodeType":867},{},[]," with compromised Global Administrator credentials, abused a legitimate feature, and wiped over 80,000 systems, servers, and mobile devices.",{"data":21844,"content":21845,"nodeType":908},{},[],{"data":21847,"content":21848,"nodeType":918},{},[21849],{"data":21850,"marks":21851,"value":21853,"nodeType":867},{},[21852],{"type":916},"What a Handala attack was supposed to look like",{"data":21855,"content":21856,"nodeType":881},{},[21857],{"data":21858,"marks":21859,"value":21860,"nodeType":867},{},[],"Handala has a reputation for being a manual, hands-on intrusion team whose TTPs have typically included VPN credential brute-force for initial access (hundreds of logon attempts from commercial VPN nodes), supply chain compromise via managed service providers, RDP as the primary lateral movement method, ADRecon for Active Directory enumeration, LSASS credential dumping via comsvcs.dll, and GPO logon scripts for wiper distribution.",{"data":21862,"content":21863,"nodeType":881},{},[21864],{"data":21865,"marks":21866,"value":21867,"nodeType":867},{},[],"If you had invested in detection logic around Handala's documented toolkit (BiBi Wiper file extensions, Cl Wiper's EldoS RawDisk driver calls, No-Justice partition table manipulation, Karma Shell's Base64-with-XOR web shell patterns) none of it would have fired. Wiper malware signatures, web shell indicators, RawDisk driver loading, MBR/GPT manipulation, SharePoint exploitation patterns, anomalous RDP/SMB lateral movement: all reasonable detection priorities given the group's threat intelligence profile, but all irrelevant when it mattered most.",{"data":21869,"content":21870,"nodeType":908},{},[],{"data":21872,"content":21873,"nodeType":918},{},[21874],{"data":21875,"marks":21876,"value":21878,"nodeType":867},{},[21877],{"type":916},"What Handala actually did",{"data":21880,"content":21881,"nodeType":881},{},[21882],{"data":21883,"marks":21884,"value":21885,"nodeType":867},{},[],"The Stryker attack departs from the documented baseline across the kill chain.",{"data":21887,"content":21888,"nodeType":2531},{},[21889,21925,21958,21991,22024],{"data":21890,"content":21891,"nodeType":2438},{},[21892,21903,21914],{"data":21893,"content":21894,"nodeType":2426},{},[21895],{"data":21896,"content":21897,"nodeType":881},{},[21898],{"data":21899,"marks":21900,"value":21902,"nodeType":867},{},[21901],{"type":916},"Kill chain phase",{"data":21904,"content":21905,"nodeType":2426},{},[21906],{"data":21907,"content":21908,"nodeType":881},{},[21909],{"data":21910,"marks":21911,"value":21913,"nodeType":867},{},[21912],{"type":916},"Historical TTP",{"data":21915,"content":21916,"nodeType":2426},{},[21917],{"data":21918,"content":21919,"nodeType":881},{},[21920],{"data":21921,"marks":21922,"value":21924,"nodeType":867},{},[21923],{"type":916},"Stryker TTP",{"data":21926,"content":21927,"nodeType":2438},{},[21928,21938,21948],{"data":21929,"content":21930,"nodeType":2452},{},[21931],{"data":21932,"content":21933,"nodeType":881},{},[21934],{"data":21935,"marks":21936,"value":21937,"nodeType":867},{},[],"Initial access",{"data":21939,"content":21940,"nodeType":2452},{},[21941],{"data":21942,"content":21943,"nodeType":881},{},[21944],{"data":21945,"marks":21946,"value":21947,"nodeType":867},{},[],"VPN credential brute-force, supply chain compromise of managed service providers and IT vendors, spearphishing with wiper delivery, exploitation of SharePoint and Windows server vulnerabilities",{"data":21949,"content":21950,"nodeType":2452},{},[21951],{"data":21952,"content":21953,"nodeType":881},{},[21954],{"data":21955,"marks":21956,"value":21957,"nodeType":867},{},[],"Identity compromise targeting Microsoft Entra ID",{"data":21959,"content":21960,"nodeType":2438},{},[21961,21971,21981],{"data":21962,"content":21963,"nodeType":2452},{},[21964],{"data":21965,"content":21966,"nodeType":881},{},[21967],{"data":21968,"marks":21969,"value":21970,"nodeType":867},{},[],"Persistence",{"data":21972,"content":21973,"nodeType":2452},{},[21974],{"data":21975,"content":21976,"nodeType":881},{},[21977],{"data":21978,"marks":21979,"value":21980,"nodeType":867},{},[],"Web shells (Karma Shell, reGeorg)",{"data":21982,"content":21983,"nodeType":2452},{},[21984],{"data":21985,"content":21986,"nodeType":881},{},[21987],{"data":21988,"marks":21989,"value":21990,"nodeType":867},{},[],"Global Administrator access to cloud tenant, no persistence mechanism needed",{"data":21992,"content":21993,"nodeType":2438},{},[21994,22004,22014],{"data":21995,"content":21996,"nodeType":2452},{},[21997],{"data":21998,"content":21999,"nodeType":881},{},[22000],{"data":22001,"marks":22002,"value":22003,"nodeType":867},{},[],"Lateral movement",{"data":22005,"content":22006,"nodeType":2452},{},[22007],{"data":22008,"content":22009,"nodeType":881},{},[22010],{"data":22011,"marks":22012,"value":22013,"nodeType":867},{},[],"RDP, SMB, FTP, Mimikatz",{"data":22015,"content":22016,"nodeType":2452},{},[22017],{"data":22018,"content":22019,"nodeType":881},{},[22020],{"data":22021,"marks":22022,"value":22023,"nodeType":867},{},[],"None required, Intune console provides global reach from a single session",{"data":22025,"content":22026,"nodeType":2438},{},[22027,22037,22047],{"data":22028,"content":22029,"nodeType":2452},{},[22030],{"data":22031,"content":22032,"nodeType":881},{},[22033],{"data":22034,"marks":22035,"value":22036,"nodeType":867},{},[],"Impact",{"data":22038,"content":22039,"nodeType":2452},{},[22040],{"data":22041,"content":22042,"nodeType":881},{},[22043],{"data":22044,"marks":22045,"value":22046,"nodeType":867},{},[],"Custom wiper malware (BiBi, Cl Wiper, No-Justice, Hatef)",{"data":22048,"content":22049,"nodeType":2452},{},[22050],{"data":22051,"content":22052,"nodeType":881},{},[22053],{"data":22054,"marks":22055,"value":22056,"nodeType":867},{},[],"Microsoft Intune Remote Wipe, a legitimate built-in administrative feature",{"data":22058,"content":22059,"nodeType":881},{},[22060],{"data":22061,"marks":22062,"value":22063,"nodeType":867},{},[],"An organization with detections built around malware signatures, file system manipulation, and anomalous process execution would be unprepared for an attack with zero malware artifacts, where every action was a legitimate administrative command.",{"data":22065,"content":22066,"nodeType":881},{},[22067],{"data":22068,"marks":22069,"value":22070,"nodeType":867},{},[],"But while the methods were different, the core objective — mass destruction of data — is entirely consistent with previous campaigns, just through a legitimate management plane rather than custom malware.",{"data":22072,"content":22073,"nodeType":908},{},[],{"data":22075,"content":22076,"nodeType":918},{},[22077],{"data":22078,"marks":22079,"value":22081,"nodeType":867},{},[22080],{"type":916},"The kill chain looks different now",{"data":22083,"content":22084,"nodeType":881},{},[22085],{"data":22086,"marks":22087,"value":22088,"nodeType":867},{},[],"The attack path was devastatingly simple. It didn't require lateral movement because there was nothing to move laterally through. It didn't require privilege escalation because they directly compromised a global administrator account. Every device managed by Intune was already within reach.",{"data":22090,"content":22091,"nodeType":881},{},[22092],{"data":22093,"marks":22094,"value":22095,"nodeType":867},{},[],"The traditional network-centric kill chain collapses into: compromise identity, access management plane, execute objective.",{"data":22097,"content":22098,"nodeType":881},{},[22099],{"data":22100,"marks":22101,"value":22102,"nodeType":867},{},[],"This is not specific to Iran-aligned actors. Russian groups are leveraging AITM phishing kits and abusing Microsoft 365 OAuth tokens via consent attacks. Scattered Spider built an operational model around social engineering and SSO account takeover. And now Handala has demonstrated that a nation-state destructive operation can be executed entirely by abusing legitimate enterprise tooling.",{"data":22104,"content":22105,"nodeType":881},{},[22106],{"data":22107,"marks":22108,"value":22109,"nodeType":867},{},[],"This kind of attack is more direct, faster to execute, and carries a significantly lower barrier to entry. You don't need custom malware and exploit development when you can log in using as-a-Service kits or partner with an access brokering specialist.",{"data":22111,"content":22112,"nodeType":908},{},[],{"data":22114,"content":22115,"nodeType":918},{},[22116],{"data":22117,"marks":22118,"value":22120,"nodeType":867},{},[22119],{"type":916},"The big picture of Iranian cyber TTPs",{"data":22122,"content":22123,"nodeType":881},{},[22124,22128,22136],{"data":22125,"marks":22126,"value":22127,"nodeType":867},{},[],"Iran's offensive cyber capability is split between two rival intelligence bureaucracies. The Ministry of Intelligence and Security (MOIS) runs groups like APT34, MuddyWater, Scarred Manticore, and Void Manticore (Handala), which tend toward long-dwell espionage and coordinated destructive operations, often using a ",{"data":22129,"content":22131,"nodeType":876},{"uri":22130},"https://research.checkpoint.com/2024/bad-karma-no-justice-void-manticore-destructive-activities-in-israel/",[22132],{"data":22133,"marks":22134,"value":22135,"nodeType":867},{},[],"documented dual-actor handoff model",{"data":22137,"marks":22138,"value":22139,"nodeType":867},{},[]," where Scarred Manticore conducts stealthy espionage before handing targets to Void Manticore (Handala) for destruction.",{"data":22141,"content":22142,"nodeType":881},{},[22143],{"data":22144,"marks":22145,"value":22146,"nodeType":867},{},[],"The Islamic Revolutionary Guard Corps (IRGC) runs a wider set of groups, including APT33/Peach Sandstorm, APT35/Charming Kitten, APT42, Tortoiseshell/Imperial Kitten, Cotton Sandstorm, and CyberAv3ngers. IRGC groups cover espionage, destructive attacks, influence operations, election interference, ICS targeting across U.S. water and wastewater facilities), and individual surveillance.",{"data":22148,"content":22149,"nodeType":998},{},[22150],{"data":22151,"marks":22152,"value":22154,"nodeType":867},{},[22153],{"type":916},"IRGC groups have already shifted to identity-first TTPs",{"data":22156,"content":22157,"nodeType":881},{},[22158],{"data":22159,"marks":22160,"value":22161,"nodeType":867},{},[],"On the IRGC side, the shift toward identity-centric operations is well-documented:",{"data":22163,"content":22164,"nodeType":3126},{},[22165,22216,22254,22281],{"data":22166,"content":22167,"nodeType":3061},{},[22168],{"data":22169,"content":22170,"nodeType":881},{},[22171,22176,22180,22188,22192,22200,22204,22212],{"data":22172,"marks":22173,"value":22175,"nodeType":867},{},[22174],{"type":916},"APT33/Peach Sandstorm",{"data":22177,"marks":22178,"value":22179,"nodeType":867},{},[]," shifted decisively toward credential-based initial access starting in early 2023, with Microsoft ",{"data":22181,"content":22183,"nodeType":876},{"uri":22182},"https://www.microsoft.com/en-us/security/blog/2023/09/14/peach-sandstorm-password-spray-campaigns-enable-intelligence-collection-at-high-value-targets/",[22184],{"data":22185,"marks":22186,"value":22187,"nodeType":867},{},[],"documenting",{"data":22189,"marks":22190,"value":22191,"nodeType":867},{},[]," large-scale password spray campaigns targeting thousands of organizations, ",{"data":22193,"content":22195,"nodeType":876},{"uri":22194},"https://www.bleepingcomputer.com/news/security/iranian-hackers-breach-defense-orgs-in-password-spray-attacks/",[22196],{"data":22197,"marks":22198,"value":22199,"nodeType":867},{},[],"Golden SAML",{"data":22201,"marks":22202,"value":22203,"nodeType":867},{},[]," attacks for persistent cloud access, and the use of ",{"data":22205,"content":22207,"nodeType":876},{"uri":22206},"https://www.microsoft.com/en-us/security/blog/2024/08/28/peach-sandstorm-deploys-new-custom-tickler-malware-in-long-running-intelligence-gathering-operations/",[22208],{"data":22209,"marks":22210,"value":22211,"nodeType":867},{},[],"fraudulent Azure subscriptions",{"data":22213,"marks":22214,"value":22215,"nodeType":867},{},[]," for C2 infrastructure.",{"data":22217,"content":22218,"nodeType":3061},{},[22219],{"data":22220,"content":22221,"nodeType":881},{},[22222,22227,22230,22238,22242,22250],{"data":22223,"marks":22224,"value":22226,"nodeType":867},{},[22225],{"type":916},"APT42",{"data":22228,"marks":22229,"value":4006,"nodeType":867},{},[],{"data":22231,"content":22233,"nodeType":876},{"uri":22232},"https://cloud.google.com/blog/topics/threat-intelligence/untangling-iran-apt42-operations",[22234],{"data":22235,"marks":22236,"value":22237,"nodeType":867},{},[],"assessed by Mandiant to operate on behalf of the IRGC-IO, ",{"data":22239,"marks":22240,"value":22241,"nodeType":867},{},[],"has made credential harvesting and MFA bypass its core competency, operating almost entirely within cloud environments post-compromise and ",{"data":22243,"content":22245,"nodeType":876},{"uri":22244},"https://cloud.google.com/blog/topics/threat-intelligence/apt42-charms-cons-compromises",[22246],{"data":22247,"marks":22248,"value":22249,"nodeType":867},{},[],"registering its own Microsoft Authenticator",{"data":22251,"marks":22252,"value":22253,"nodeType":867},{},[]," on compromised accounts for persistent access.",{"data":22255,"content":22256,"nodeType":3061},{},[22257],{"data":22258,"content":22259,"nodeType":881},{},[22260,22265,22269,22277],{"data":22261,"marks":22262,"value":22264,"nodeType":867},{},[22263],{"type":916},"APT35",{"data":22266,"marks":22267,"value":22268,"nodeType":867},{},[]," (aka Imperial Kitten/Tortoiseshell) was observed ",{"data":22270,"content":22272,"nodeType":876},{"uri":22271},"https://www.crowdstrike.com/explore/2026-global-threat-report?utm_medium=org",[22273],{"data":22274,"marks":22275,"value":22276,"nodeType":867},{},[],"targeting cloud identities in November 2025",{"data":22278,"marks":22279,"value":22280,"nodeType":867},{},[],", deploying the Evilginx2 AitM toolkit against Microsoft 365 users in Israel.",{"data":22282,"content":22283,"nodeType":3061},{},[22284],{"data":22285,"content":22286,"nodeType":881},{},[22287,22292,22296,22303],{"data":22288,"marks":22289,"value":22291,"nodeType":867},{},[22290],{"type":916},"CrustyKrill",{"data":22293,"marks":22294,"value":22295,"nodeType":867},{},[]," (TA455/Smoke Sandstorm) ",{"data":22297,"content":22298,"nodeType":876},{"uri":22271},[22299],{"data":22300,"marks":22301,"value":22302,"nodeType":867},{},[],"uses fake Google Meet and Microsoft Teams pages",{"data":22304,"marks":22305,"value":22306,"nodeType":867},{},[]," with a live operator intercepting 2FA codes in real time, alongside Azure Web Apps for C2.",{"data":22308,"content":22309,"nodeType":881},{},[22310,22314,22322],{"data":22311,"marks":22312,"value":22313,"nodeType":867},{},[],"A ",{"data":22315,"content":22317,"nodeType":876},{"uri":22316},"https://media.defense.gov/2024/Oct/16/2003565317/-1/-1/0/CSA-IRAN-CYBER-BRUTE-FORCE-CRITICAL-INFRASTRUCTURE-ORGS.PDF",[22318],{"data":22319,"marks":22320,"value":22321,"nodeType":867},{},[],"joint advisory from six nations",{"data":22323,"marks":22324,"value":22325,"nodeType":867},{},[]," (FBI, CISA, NSA, CSE, AFP, ASD, advisory AA24-290A, October 2024) confirmed the pattern at the government level, documenting Iranian actors using brute force, password spraying, and MFA push bombing to compromise critical infrastructure accounts since October 2023, and assessing that the actors sell this access on cybercriminal forums.",{"data":22327,"content":22328,"nodeType":998},{},[22329],{"data":22330,"marks":22331,"value":22333,"nodeType":867},{},[22332],{"type":916},"MOIS groups are changing their approach too",{"data":22335,"content":22336,"nodeType":881},{},[22337],{"data":22338,"marks":22339,"value":22340,"nodeType":867},{},[],"On the MOIS side, the documented TTP baseline has historically centred on custom malware, network-level persistence, and exploitation of on-premises infrastructure. But identity compromise, particularly credential theft, has been a consistent thread across broader MOIS groups too:",{"data":22342,"content":22343,"nodeType":3126},{},[22344,22383,22410,22461],{"data":22345,"content":22346,"nodeType":3061},{},[22347],{"data":22348,"content":22349,"nodeType":881},{},[22350,22355,22359,22367,22371,22379],{"data":22351,"marks":22352,"value":22354,"nodeType":867},{},[22353],{"type":916},"APT34 (OilRig) ",{"data":22356,"marks":22357,"value":22358,"nodeType":867},{},[],"built its reputation on DNS tunnelling and custom backdoors, but its initial access methods include spearphishing and fake VPN portals for credential harvesting. Its 2024 campaigns introduced ",{"data":22360,"content":22362,"nodeType":876},{"uri":22361},"https://www.trendmicro.com/en_us/research/24/j/earth-simnavaz-cyberattacks.html",[22363],{"data":22364,"marks":22365,"value":22366,"nodeType":867},{},[],"password filter DLLs",{"data":22368,"marks":22369,"value":22370,"nodeType":867},{},[]," registered at the domain controller level to intercept plaintext credentials during password change events, with the ",{"data":22372,"content":22374,"nodeType":876},{"uri":22373},"https://www.bleepingcomputer.com/news/security/oilrig-hackers-now-exploit-windows-flaw-to-elevate-privileges/",[22375],{"data":22376,"marks":22377,"value":22378,"nodeType":867},{},[],"STEALHOOK backdoor",{"data":22380,"marks":22381,"value":22382,"nodeType":867},{},[]," exfiltrating stolen domain credentials via compromised Exchange servers. Cloud-based downloaders leveraging OneDrive and Microsoft Graph API were active against Israeli targets from 2022 to 2024.",{"data":22384,"content":22385,"nodeType":3061},{},[22386],{"data":22387,"content":22388,"nodeType":881},{},[22389,22394,22398,22406],{"data":22390,"marks":22391,"value":22393,"nodeType":867},{},[22392],{"type":916},"APT39 (Chafer) ",{"data":22395,"marks":22396,"value":22397,"nodeType":867},{},[],"operated through the ",{"data":22399,"content":22401,"nodeType":876},{"uri":22400},"https://home.treasury.gov/news/press-releases/sm1127",[22402],{"data":22403,"marks":22404,"value":22405,"nodeType":867},{},[],"sanctioned front company Rana Intelligence Computing",{"data":22407,"marks":22408,"value":22409,"nodeType":867},{},[],", focuses on surveillance and tracking of individuals, using credential harvesting through spoofed airline and telecom domains across 30+ countries.",{"data":22411,"content":22412,"nodeType":3061},{},[22413],{"data":22414,"content":22415,"nodeType":881},{},[22416,22421,22425,22433,22437,22445,22449,22457],{"data":22417,"marks":22418,"value":22420,"nodeType":867},{},[22419],{"type":916},"MuddyWater",{"data":22422,"marks":22423,"value":22424,"nodeType":867},{},[],", confirmed by a ",{"data":22426,"content":22428,"nodeType":876},{"uri":22427},"https://www.cisa.gov/news-events/cybersecurity-advisories/aa22-055a",[22429],{"data":22430,"marks":22431,"value":22432,"nodeType":867},{},[],"joint CISA/FBI/NSA/NCSC advisory",{"data":22434,"marks":22435,"value":22436,"nodeType":867},{},[]," as a subordinate element of MOIS, functions as an initial access broker within the ecosystem. Its operations rely on spearphishing and abuse of legitimate RMM tools, but the group has developed ",{"data":22438,"content":22440,"nodeType":876},{"uri":22439},"https://thehackernews.com/2025/12/iran-linked-hackers-hits-israeli_2.html",[22441],{"data":22442,"marks":22443,"value":22444,"nodeType":867},{},[],"dedicated credential stealers",{"data":22446,"marks":22447,"value":22448,"nodeType":867},{},[]," including CE-Notes (which bypasses Chrome's app-bound encryption), Blub (a multi-browser credential extractor), and LP-Notes (fake Windows Security dialogs to capture system credentials). A parallel campaign documented by ",{"data":22450,"content":22452,"nodeType":876},{"uri":22451},"https://www.group-ib.com/blog/muddywater-espionage/",[22453],{"data":22454,"marks":22455,"value":22456,"nodeType":867},{},[],"Group-IB",{"data":22458,"marks":22459,"value":22460,"nodeType":867},{},[]," found the group deploying a custom Chromium credential stealer alongside its Phoenix backdoor.",{"data":22462,"content":22463,"nodeType":3061},{},[22464],{"data":22465,"content":22466,"nodeType":881},{},[22467,22472],{"data":22468,"marks":22469,"value":22471,"nodeType":867},{},[22470],{"type":916},"Lyceum (Hexane)",{"data":22473,"marks":22474,"value":22475,"nodeType":867},{},[]," overlaps operationally with APT34 and uses password spraying and brute-force attacks for initial access, and notably probed Albanian government infrastructure ahead of Handala destructive attacks in 2022, illustrating the collaborative model across MOIS groups.",{"data":22477,"content":22478,"nodeType":881},{},[22479,22483,22491],{"data":22480,"marks":22481,"value":22482,"nodeType":867},{},[],"Check Point has also ",{"data":22484,"content":22486,"nodeType":876},{"uri":22485},"https://research.checkpoint.com/2026/iranian-mois-actors-the-cyber-crime-connection/",[22487],{"data":22488,"marks":22489,"value":22490,"nodeType":867},{},[],"documented",{"data":22492,"marks":22493,"value":22494,"nodeType":867},{},[]," a broader pattern of MOIS actors engaging directly with the criminal ecosystem, including Handala's adoption of the Rhadamanthys commercial infostealer and Iranian-affiliated operators working through the Qilin ransomware-as-a-service infrastructure.",{"data":22496,"content":22500,"nodeType":890},{"target":22497},{"sys":22498},{"id":22499,"type":887,"linkType":888},"2SFtROFuPZ4SPTL87Vpjr9",[],{"data":22502,"content":22503,"nodeType":908},{},[],{"data":22505,"content":22506,"nodeType":918},{},[22507],{"data":22508,"marks":22509,"value":22511,"nodeType":867},{},[22510],{"type":916},"The problem with over-indexing on TTPs",{"data":22513,"content":22514,"nodeType":881},{},[22515],{"data":22516,"marks":22517,"value":22518,"nodeType":867},{},[],"Threat intelligence has real value. Attributing campaigns to named groups, mapping their techniques to MITRE ATT&CK, and generating detection rules gives defenders a meaningful starting point. The problem is treating a specific actor's historical TTP catalogue as the primary basis for detection logic, rather than combining it with the broader trends in attacker behaviour visible across the entire landscape.",{"data":22520,"content":22521,"nodeType":881},{},[22522],{"data":22523,"marks":22524,"value":22525,"nodeType":867},{},[],"Operators are creative and pragmatic. If the path of least resistance is a compromised admin credential and a legitimate MDM feature, no serious attacker is going to deploy custom wiper malware instead because that's what they used last time.",{"data":22527,"content":22528,"nodeType":881},{},[22529],{"data":22530,"marks":22531,"value":22532,"nodeType":867},{},[],"If your threat model says you're a plausible target for an Iranian threat group, and the trend data tells you that identity compromise is the most common initial access method across all actors, the rational response is to evaluate your controls aligned to identity-based initial access, not just deploy signatures for BiBi Wiper. When the specific actor profile crowds out the general trend data, you end up building defences against the last attack and leaving yourself exposed to the shift that every actor is going through.",{"data":22534,"content":22535,"nodeType":908},{},[],{"data":22537,"content":22538,"nodeType":918},{},[22539],{"data":22540,"marks":22541,"value":22543,"nodeType":867},{},[22542],{"type":916},"Evaluating the security guidance",{"data":22545,"content":22546,"nodeType":881},{},[22547,22551,22559,22563,22571,22575,22580],{"data":22548,"marks":22549,"value":22550,"nodeType":867},{},[],"In the wake of the breach, industry guidance has settled around enforcing phishing-resistant MFA on privileged accounts, implementing just-in-time privilege activation via ",{"data":22552,"content":22554,"nodeType":876},{"uri":22553},"https://learn.microsoft.com/en-us/entra/id-governance/privileged-identity-management/pim-configure",[22555],{"data":22556,"marks":22557,"value":22558,"nodeType":867},{},[],"PIM",{"data":22560,"marks":22561,"value":22562,"nodeType":867},{},[],", enabling ",{"data":22564,"content":22566,"nodeType":876},{"uri":22565},"https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/multi-admin-approval",[22567],{"data":22568,"marks":22569,"value":22570,"nodeType":867},{},[],"Multi Admin Approval ",{"data":22572,"marks":22573,"value":22574,"nodeType":867},{},[],"for high-risk Intune operations, configuring anomaly alerting on bulk device actions, and segregating administrative identities from everyday user accounts. This is all sound advice, but these recommendations are designed to limit what an attacker can do ",{"data":22576,"marks":22577,"value":22579,"nodeType":867},{},[22578],{"type":1431},"after",{"data":22581,"marks":22582,"value":22583,"nodeType":867},{},[]," an account has already been compromised — introducing friction, but not blocking them entirely.",{"data":22585,"content":22586,"nodeType":881},{},[22587,22591,22599,22603,22611],{"data":22588,"marks":22589,"value":22590,"nodeType":867},{},[],"The detection challenges compound this. Entra ID sign-in logs and ",{"data":22592,"content":22594,"nodeType":876},{"uri":22593},"https://www.a6n.co.uk/2025/11/tracking-device-wipes-in-microsoft.html",[22595],{"data":22596,"marks":22597,"value":22598,"nodeType":867},{},[],"Intune audit logs exist in separate systems",{"data":22600,"marks":22601,"value":22602,"nodeType":867},{},[]," with separate correlation IDs. Tracing a sign-in to a subsequent device action requires deliberate log integration that many organizations haven't implemented. The ",{"data":22604,"content":22606,"nodeType":876},{"uri":22605},"https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/monitor-audit-logs",[22607],{"data":22608,"marks":22609,"value":22610,"nodeType":867},{},[],"logs do record",{"data":22612,"marks":22613,"value":22614,"nodeType":867},{},[]," \"wipe ManagedDevice\" events, but may not be linked to real-time alerting. And the underlying action, Intune's Remote Wipe, is a legitimate feature used routinely in enterprise IT. Again, the attack could have succeeded even with these in place.",{"data":22616,"content":22617,"nodeType":881},{},[22618],{"data":22619,"marks":22620,"value":22621,"nodeType":867},{},[],"In a world where a compromised account can be rapidly exploited, it's vital to focus on improving detection and prevention as early as possible in the kill chain — combating initial access techniques themselves.",{"data":22623,"content":22627,"nodeType":890},{"target":22624},{"sys":22625},{"id":22626,"type":887,"linkType":888},"4H3AzW7q4QBv7pJawSqQBJ",[],{"data":22629,"content":22630,"nodeType":908},{},[],{"data":22632,"content":22633,"nodeType":918},{},[22634],{"data":22635,"marks":22636,"value":6294,"nodeType":867},{},[22637],{"type":916},{"data":22639,"content":22640,"nodeType":881},{},[22641],{"data":22642,"marks":22643,"value":22644,"nodeType":867},{},[],"The Stryker attack reflects what attackers everywhere — from financially motivated criminal groups to more destructive nation-state operators — are already doing. Identity-based initial access, abuse of legitimate tools and services, and living-off-the-land execution are the current standard operating procedure.",{"data":22646,"content":22647,"nodeType":881},{},[22648],{"data":22649,"marks":22650,"value":22651,"nodeType":867},{},[],"Even with a perfectly hardened environment, most public breaches today involve attackers hijacking SSO mechanisms to move into connected applications, exfiltrating data for resale or extortion, and in some cases leveraging cloud services and admin platforms to deploy ransomware (the Scattered Spider playbook of dropping ransomware via VMware management portal being a well-documented example).",{"data":22653,"content":22654,"nodeType":881},{},[22655],{"data":22656,"marks":22657,"value":22658,"nodeType":867},{},[],"The majority of attackers will have no interest in destructively wiping an Intune environment — that's difficult to monetize. But the techniques that enabled the Stryker wipe are the same as those that enable financially motivated breaches at scale, pointing to a challenge that extends well beyond Iran-nexus threat actors and MDM hardening.",{"data":22660,"content":22661,"nodeType":908},{},[],{"data":22663,"content":22664,"nodeType":918},{},[22665],{"data":22666,"marks":22667,"value":22669,"nodeType":867},{},[22668],{"type":916},"About Push Security",{"data":22671,"content":22672,"nodeType":881},{},[22673],{"data":22674,"marks":22675,"value":22676,"nodeType":867},{},[],"Push Security's browser-based security platform provides comprehensive detection and response capabilities against the leading cause of breaches. Push blocks browser-based attacks like AiTM phishing, credential stuffing, malicious browser extensions, ClickFix, and session hijacking. You don't need to wait until it all goes wrong — you can also use Push to proactively find and fix vulnerabilities across the apps that your employees use, like ghost logins, SSO coverage gaps, MFA gaps, vulnerable passwords, and more to harden your identity attack surface.",{"data":22678,"content":22679,"nodeType":881},{},[22680,22683,22689,22692,22698,22701,22707],{"data":22681,"marks":22682,"value":10795,"nodeType":867},{},[],{"data":22684,"content":22685,"nodeType":876},{"uri":10798},[22686],{"data":22687,"marks":22688,"value":10803,"nodeType":867},{},[],{"data":22690,"marks":22691,"value":4006,"nodeType":867},{},[],{"data":22693,"content":22694,"nodeType":876},{"uri":10809},[22695],{"data":22696,"marks":22697,"value":10815,"nodeType":867},{},[],{"data":22699,"marks":22700,"value":10819,"nodeType":867},{},[],{"data":22702,"content":22703,"nodeType":876},{"uri":1629},[22704],{"data":22705,"marks":22706,"value":10826,"nodeType":867},{},[],{"data":22708,"marks":22709,"value":1947,"nodeType":867},{},[],{"entries":22711},{"hyperlink":22712,"inline":22713,"block":22714},[],[],[22715,22729,22747],{"sys":22716,"__typename":1696,"content":22717,"name":22728,"title":59},{"id":21822},{"json":22718},{"nodeType":1640,"data":22719,"content":22720},{},[22721],{"nodeType":881,"data":22722,"content":22723},{},[22724],{"nodeType":867,"value":22725,"marks":22726,"data":22727},"Handala is a public-facing \"faketivist\" persona, also known as Handala Hack Team, Void Manticore, Storm-0842, Dune, Red Sandstorm, and Banished Kitten. The group also operates under regional personas like Karma and Homeland Justice. We'll refer to them as Handala in this piece.",[],{},"Handala blog insight box 1",{"sys":22730,"__typename":1696,"content":22731,"name":22746,"title":59},{"id":22499},{"json":22732},{"nodeType":1640,"data":22733,"content":22734},{},[22735],{"nodeType":881,"data":22736,"content":22737},{},[22738,22742],{"nodeType":867,"value":22739,"marks":22740,"data":22741},"So, t",[],{},{"nodeType":867,"value":22743,"marks":22744,"data":22745},"he Stryker attack path is operationally consistent with the direction the Iranian threat ecosystem has been moving, even though it departs from Handala's own documented TTPs. Many of Handala's previous methods — targeting managed service providers and IT vendors, malware spearphishing, VPN credential stuffing — can also be repurposed in identity-focused social engineering attacks, particularly when boosted with widely available tools already powering criminal campaigns.",[],{},"Handala blog insight box 3",{"sys":22748,"__typename":22749,"type":22750,"ctaText":22751,"buttonLabel":22752,"buttonColour":22753,"buttonUrl":27},{"id":22626},"CtaWidget","Custom","Learn about the browser attack techniques security teams must contend with in 2026","Get the Report","sunny orange",{"items":22755},[],{},"Analyzing Iran-nexus TTP evolution in 2026","breach-analysis","2026-03-19T00:00:00.000Z",{"items":22761},[22762,23590,24338],{"__typename":1742,"sys":22763,"content":22764,"title":15224,"synopsis":15225,"hashTags":59,"publishedDate":15226,"slug":15227,"tagsCollection":23580,"authorsCollection":23586},{"id":14277},{"json":22765},{"data":22766,"content":22767,"nodeType":1640},{},[22768,22774,22780,22786,22789,22796,22802,22808,22813,22819,22824,22840,22846,22856,22859,22866,22872,22885,22891,22901,22906,22909,22916,22923,22928,22936,22952,22960,22966,22974,22989,22997,23003,23011,23037,23045,23051,23059,23075,23080,23088,23094,23102,23135,23138,23145,23153,23169,23177,23183,23191,23217,23222,23230,23236,23241,23244,23251,23259,23265,23316,23321,23324,23331,23339,23345,23350,23353,23360,23366,23372,23432,23438,23493,23499,23502,23509,23515,23521,23526,23529,23536,23542,23548,23554],{"data":22769,"content":22770,"nodeType":881},{},[22771],{"data":22772,"marks":22773,"value":14288,"nodeType":867},{},[],{"data":22775,"content":22776,"nodeType":881},{},[22777],{"data":22778,"marks":22779,"value":14295,"nodeType":867},{},[],{"data":22781,"content":22782,"nodeType":881},{},[22783],{"data":22784,"marks":22785,"value":14302,"nodeType":867},{},[],{"data":22787,"content":22788,"nodeType":908},{},[],{"data":22790,"content":22791,"nodeType":918},{},[22792],{"data":22793,"marks":22794,"value":14313,"nodeType":867},{},[22795],{"type":916},{"data":22797,"content":22798,"nodeType":881},{},[22799],{"data":22800,"marks":22801,"value":14320,"nodeType":867},{},[],{"data":22803,"content":22804,"nodeType":881},{},[22805],{"data":22806,"marks":22807,"value":14327,"nodeType":867},{},[],{"data":22809,"content":22812,"nodeType":890},{"target":22810},{"sys":22811},{"id":14332,"type":887,"linkType":888},[],{"data":22814,"content":22815,"nodeType":881},{},[22816],{"data":22817,"marks":22818,"value":14340,"nodeType":867},{},[],{"data":22820,"content":22823,"nodeType":890},{"target":22821},{"sys":22822},{"id":14345,"type":887,"linkType":888},[],{"data":22825,"content":22826,"nodeType":881},{},[22827,22830,22837],{"data":22828,"marks":22829,"value":14353,"nodeType":867},{},[],{"data":22831,"content":22832,"nodeType":876},{"uri":5752},[22833],{"data":22834,"marks":22835,"value":14361,"nodeType":867},{},[22836],{"type":1040},{"data":22838,"marks":22839,"value":14365,"nodeType":867},{},[],{"data":22841,"content":22842,"nodeType":881},{},[22843],{"data":22844,"marks":22845,"value":14372,"nodeType":867},{},[],{"data":22847,"content":22848,"nodeType":881},{},[22849,22852],{"data":22850,"marks":22851,"value":14379,"nodeType":867},{},[],{"data":22853,"marks":22854,"value":14384,"nodeType":867},{},[22855],{"type":916},{"data":22857,"content":22858,"nodeType":908},{},[],{"data":22860,"content":22861,"nodeType":918},{},[22862],{"data":22863,"marks":22864,"value":14395,"nodeType":867},{},[22865],{"type":916},{"data":22867,"content":22868,"nodeType":881},{},[22869],{"data":22870,"marks":22871,"value":14402,"nodeType":867},{},[],{"data":22873,"content":22874,"nodeType":881},{},[22875,22878,22882],{"data":22876,"marks":22877,"value":14409,"nodeType":867},{},[],{"data":22879,"marks":22880,"value":14414,"nodeType":867},{},[22881],{"type":916},{"data":22883,"marks":22884,"value":14418,"nodeType":867},{},[],{"data":22886,"content":22887,"nodeType":881},{},[22888],{"data":22889,"marks":22890,"value":14425,"nodeType":867},{},[],{"data":22892,"content":22893,"nodeType":881},{},[22894,22897],{"data":22895,"marks":22896,"value":14432,"nodeType":867},{},[],{"data":22898,"marks":22899,"value":14437,"nodeType":867},{},[22900],{"type":916},{"data":22902,"content":22905,"nodeType":890},{"target":22903},{"sys":22904},{"id":14442,"type":887,"linkType":888},[],{"data":22907,"content":22908,"nodeType":908},{},[],{"data":22910,"content":22911,"nodeType":918},{},[22912],{"data":22913,"marks":22914,"value":14454,"nodeType":867},{},[22915],{"type":916},{"data":22917,"content":22918,"nodeType":998},{},[22919],{"data":22920,"marks":22921,"value":14462,"nodeType":867},{},[22922],{"type":916},{"data":22924,"content":22927,"nodeType":890},{"target":22925},{"sys":22926},{"id":14467,"type":887,"linkType":888},[],{"data":22929,"content":22930,"nodeType":881},{},[22931],{"data":22932,"marks":22933,"value":14477,"nodeType":867},{},[22934,22935],{"type":916},{"type":1040},{"data":22937,"content":22938,"nodeType":881},{},[22939,22942,22949],{"data":22940,"marks":22941,"value":14484,"nodeType":867},{},[],{"data":22943,"content":22944,"nodeType":876},{"uri":14487},[22945],{"data":22946,"marks":22947,"value":14493,"nodeType":867},{},[22948],{"type":1040},{"data":22950,"marks":22951,"value":14497,"nodeType":867},{},[],{"data":22953,"content":22954,"nodeType":881},{},[22955],{"data":22956,"marks":22957,"value":14506,"nodeType":867},{},[22958,22959],{"type":916},{"type":1040},{"data":22961,"content":22962,"nodeType":881},{},[22963],{"data":22964,"marks":22965,"value":14513,"nodeType":867},{},[],{"data":22967,"content":22968,"nodeType":881},{},[22969],{"data":22970,"marks":22971,"value":14522,"nodeType":867},{},[22972,22973],{"type":916},{"type":1040},{"data":22975,"content":22976,"nodeType":881},{},[22977,22980,22986],{"data":22978,"marks":22979,"value":14529,"nodeType":867},{},[],{"data":22981,"content":22982,"nodeType":876},{"uri":14532},[22983],{"data":22984,"marks":22985,"value":14537,"nodeType":867},{},[],{"data":22987,"marks":22988,"value":14541,"nodeType":867},{},[],{"data":22990,"content":22991,"nodeType":881},{},[22992],{"data":22993,"marks":22994,"value":14550,"nodeType":867},{},[22995,22996],{"type":916},{"type":1040},{"data":22998,"content":22999,"nodeType":881},{},[23000],{"data":23001,"marks":23002,"value":14557,"nodeType":867},{},[],{"data":23004,"content":23005,"nodeType":881},{},[23006],{"data":23007,"marks":23008,"value":14566,"nodeType":867},{},[23009,23010],{"type":916},{"type":1040},{"data":23012,"content":23013,"nodeType":881},{},[23014,23017,23024,23027,23034],{"data":23015,"marks":23016,"value":14573,"nodeType":867},{},[],{"data":23018,"content":23019,"nodeType":876},{"uri":14576},[23020],{"data":23021,"marks":23022,"value":14582,"nodeType":867},{},[23023],{"type":1040},{"data":23025,"marks":23026,"value":14586,"nodeType":867},{},[],{"data":23028,"content":23029,"nodeType":876},{"uri":14589},[23030],{"data":23031,"marks":23032,"value":6850,"nodeType":867},{},[23033],{"type":1040},{"data":23035,"marks":23036,"value":14598,"nodeType":867},{},[],{"data":23038,"content":23039,"nodeType":881},{},[23040],{"data":23041,"marks":23042,"value":14607,"nodeType":867},{},[23043,23044],{"type":916},{"type":1040},{"data":23046,"content":23047,"nodeType":881},{},[23048],{"data":23049,"marks":23050,"value":14614,"nodeType":867},{},[],{"data":23052,"content":23053,"nodeType":881},{},[23054],{"data":23055,"marks":23056,"value":14623,"nodeType":867},{},[23057,23058],{"type":916},{"type":1040},{"data":23060,"content":23061,"nodeType":881},{},[23062,23065,23072],{"data":23063,"marks":23064,"value":14630,"nodeType":867},{},[],{"data":23066,"content":23067,"nodeType":876},{"uri":14589},[23068],{"data":23069,"marks":23070,"value":6850,"nodeType":867},{},[23071],{"type":1040},{"data":23073,"marks":23074,"value":14641,"nodeType":867},{},[],{"data":23076,"content":23079,"nodeType":890},{"target":23077},{"sys":23078},{"id":14646,"type":887,"linkType":888},[],{"data":23081,"content":23082,"nodeType":881},{},[23083],{"data":23084,"marks":23085,"value":14656,"nodeType":867},{},[23086,23087],{"type":916},{"type":1040},{"data":23089,"content":23090,"nodeType":881},{},[23091],{"data":23092,"marks":23093,"value":14663,"nodeType":867},{},[],{"data":23095,"content":23096,"nodeType":881},{},[23097],{"data":23098,"marks":23099,"value":14672,"nodeType":867},{},[23100,23101],{"type":916},{"type":1040},{"data":23103,"content":23104,"nodeType":881},{},[23105,23108,23114,23117,23123,23126,23132],{"data":23106,"marks":23107,"value":14679,"nodeType":867},{},[],{"data":23109,"content":23110,"nodeType":876},{"uri":14682},[23111],{"data":23112,"marks":23113,"value":14687,"nodeType":867},{},[],{"data":23115,"marks":23116,"value":2063,"nodeType":867},{},[],{"data":23118,"content":23119,"nodeType":876},{"uri":14693},[23120],{"data":23121,"marks":23122,"value":14698,"nodeType":867},{},[],{"data":23124,"marks":23125,"value":14702,"nodeType":867},{},[],{"data":23127,"content":23128,"nodeType":876},{"uri":3074},[23129],{"data":23130,"marks":23131,"value":14709,"nodeType":867},{},[],{"data":23133,"marks":23134,"value":14713,"nodeType":867},{},[],{"data":23136,"content":23137,"nodeType":908},{},[],{"data":23139,"content":23140,"nodeType":998},{},[23141],{"data":23142,"marks":23143,"value":14724,"nodeType":867},{},[23144],{"type":916},{"data":23146,"content":23147,"nodeType":881},{},[23148],{"data":23149,"marks":23150,"value":14733,"nodeType":867},{},[23151,23152],{"type":916},{"type":1040},{"data":23154,"content":23155,"nodeType":881},{},[23156,23159,23166],{"data":23157,"marks":23158,"value":14740,"nodeType":867},{},[],{"data":23160,"content":23161,"nodeType":876},{"uri":14743},[23162],{"data":23163,"marks":23164,"value":14749,"nodeType":867},{},[23165],{"type":1040},{"data":23167,"marks":23168,"value":14753,"nodeType":867},{},[],{"data":23170,"content":23171,"nodeType":881},{},[23172],{"data":23173,"marks":23174,"value":14762,"nodeType":867},{},[23175,23176],{"type":916},{"type":1040},{"data":23178,"content":23179,"nodeType":881},{},[23180],{"data":23181,"marks":23182,"value":14769,"nodeType":867},{},[],{"data":23184,"content":23185,"nodeType":881},{},[23186],{"data":23187,"marks":23188,"value":14778,"nodeType":867},{},[23189,23190],{"type":916},{"type":1040},{"data":23192,"content":23193,"nodeType":881},{},[23194,23197,23204,23207,23214],{"data":23195,"marks":23196,"value":14785,"nodeType":867},{},[],{"data":23198,"content":23199,"nodeType":876},{"uri":14788},[23200],{"data":23201,"marks":23202,"value":14794,"nodeType":867},{},[23203],{"type":1040},{"data":23205,"marks":23206,"value":14798,"nodeType":867},{},[],{"data":23208,"content":23209,"nodeType":876},{"uri":14801},[23210],{"data":23211,"marks":23212,"value":14807,"nodeType":867},{},[23213],{"type":1040},{"data":23215,"marks":23216,"value":14811,"nodeType":867},{},[],{"data":23218,"content":23221,"nodeType":890},{"target":23219},{"sys":23220},{"id":14816,"type":887,"linkType":888},[],{"data":23223,"content":23224,"nodeType":881},{},[23225],{"data":23226,"marks":23227,"value":14826,"nodeType":867},{},[23228,23229],{"type":916},{"type":1040},{"data":23231,"content":23232,"nodeType":881},{},[23233],{"data":23234,"marks":23235,"value":14833,"nodeType":867},{},[],{"data":23237,"content":23240,"nodeType":890},{"target":23238},{"sys":23239},{"id":14838,"type":887,"linkType":888},[],{"data":23242,"content":23243,"nodeType":908},{},[],{"data":23245,"content":23246,"nodeType":998},{},[23247],{"data":23248,"marks":23249,"value":694,"nodeType":867},{},[23250],{"type":916},{"data":23252,"content":23253,"nodeType":881},{},[23254],{"data":23255,"marks":23256,"value":14858,"nodeType":867},{},[23257,23258],{"type":916},{"type":1040},{"data":23260,"content":23261,"nodeType":881},{},[23262],{"data":23263,"marks":23264,"value":14865,"nodeType":867},{},[],{"data":23266,"content":23267,"nodeType":3126},{},[23268,23281,23294],{"data":23269,"content":23270,"nodeType":3061},{},[23271],{"data":23272,"content":23273,"nodeType":881},{},[23274,23278],{"data":23275,"marks":23276,"value":14879,"nodeType":867},{},[23277],{"type":916},{"data":23279,"marks":23280,"value":14883,"nodeType":867},{},[],{"data":23282,"content":23283,"nodeType":3061},{},[23284],{"data":23285,"content":23286,"nodeType":881},{},[23287,23291],{"data":23288,"marks":23289,"value":14894,"nodeType":867},{},[23290],{"type":916},{"data":23292,"marks":23293,"value":14898,"nodeType":867},{},[],{"data":23295,"content":23296,"nodeType":3061},{},[23297],{"data":23298,"content":23299,"nodeType":881},{},[23300,23304,23307,23313],{"data":23301,"marks":23302,"value":14909,"nodeType":867},{},[23303],{"type":916},{"data":23305,"marks":23306,"value":14913,"nodeType":867},{},[],{"data":23308,"content":23309,"nodeType":876},{"uri":10495},[23310],{"data":23311,"marks":23312,"value":14920,"nodeType":867},{},[],{"data":23314,"marks":23315,"value":14924,"nodeType":867},{},[],{"data":23317,"content":23320,"nodeType":890},{"target":23318},{"sys":23319},{"id":14929,"type":887,"linkType":888},[],{"data":23322,"content":23323,"nodeType":908},{},[],{"data":23325,"content":23326,"nodeType":998},{},[23327],{"data":23328,"marks":23329,"value":699,"nodeType":867},{},[23330],{"type":916},{"data":23332,"content":23333,"nodeType":881},{},[23334],{"data":23335,"marks":23336,"value":14949,"nodeType":867},{},[23337,23338],{"type":916},{"type":1040},{"data":23340,"content":23341,"nodeType":881},{},[23342],{"data":23343,"marks":23344,"value":14956,"nodeType":867},{},[],{"data":23346,"content":23349,"nodeType":890},{"target":23347},{"sys":23348},{"id":14961,"type":887,"linkType":888},[],{"data":23351,"content":23352,"nodeType":908},{},[],{"data":23354,"content":23355,"nodeType":918},{},[23356],{"data":23357,"marks":23358,"value":14973,"nodeType":867},{},[23359],{"type":916},{"data":23361,"content":23362,"nodeType":881},{},[23363],{"data":23364,"marks":23365,"value":14980,"nodeType":867},{},[],{"data":23367,"content":23368,"nodeType":881},{},[23369],{"data":23370,"marks":23371,"value":14987,"nodeType":867},{},[],{"data":23373,"content":23374,"nodeType":3126},{},[23375,23394,23413],{"data":23376,"content":23377,"nodeType":3061},{},[23378],{"data":23379,"content":23380,"nodeType":881},{},[23381,23384,23391],{"data":23382,"marks":23383,"value":15000,"nodeType":867},{},[],{"data":23385,"content":23386,"nodeType":876},{"uri":15003},[23387],{"data":23388,"marks":23389,"value":15009,"nodeType":867},{},[23390],{"type":1040},{"data":23392,"marks":23393,"value":15013,"nodeType":867},{},[],{"data":23395,"content":23396,"nodeType":3061},{},[23397],{"data":23398,"content":23399,"nodeType":881},{},[23400,23403,23410],{"data":23401,"marks":23402,"value":15023,"nodeType":867},{},[],{"data":23404,"content":23405,"nodeType":876},{"uri":15026},[23406],{"data":23407,"marks":23408,"value":15032,"nodeType":867},{},[23409],{"type":1040},{"data":23411,"marks":23412,"value":15013,"nodeType":867},{},[],{"data":23414,"content":23415,"nodeType":3061},{},[23416],{"data":23417,"content":23418,"nodeType":881},{},[23419,23422,23429],{"data":23420,"marks":23421,"value":15045,"nodeType":867},{},[],{"data":23423,"content":23424,"nodeType":876},{"uri":15048},[23425],{"data":23426,"marks":23427,"value":15054,"nodeType":867},{},[23428],{"type":1040},{"data":23430,"marks":23431,"value":15013,"nodeType":867},{},[],{"data":23433,"content":23434,"nodeType":881},{},[23435],{"data":23436,"marks":23437,"value":15064,"nodeType":867},{},[],{"data":23439,"content":23440,"nodeType":3126},{},[23441,23454,23467,23480],{"data":23442,"content":23443,"nodeType":3061},{},[23444],{"data":23445,"content":23446,"nodeType":881},{},[23447,23451],{"data":23448,"marks":23449,"value":15078,"nodeType":867},{},[23450],{"type":916},{"data":23452,"marks":23453,"value":15082,"nodeType":867},{},[],{"data":23455,"content":23456,"nodeType":3061},{},[23457],{"data":23458,"content":23459,"nodeType":881},{},[23460,23464],{"data":23461,"marks":23462,"value":15093,"nodeType":867},{},[23463],{"type":916},{"data":23465,"marks":23466,"value":15097,"nodeType":867},{},[],{"data":23468,"content":23469,"nodeType":3061},{},[23470],{"data":23471,"content":23472,"nodeType":881},{},[23473,23477],{"data":23474,"marks":23475,"value":15108,"nodeType":867},{},[23476],{"type":916},{"data":23478,"marks":23479,"value":15112,"nodeType":867},{},[],{"data":23481,"content":23482,"nodeType":3061},{},[23483],{"data":23484,"content":23485,"nodeType":881},{},[23486,23490],{"data":23487,"marks":23488,"value":15123,"nodeType":867},{},[23489],{"type":916},{"data":23491,"marks":23492,"value":15127,"nodeType":867},{},[],{"data":23494,"content":23495,"nodeType":881},{},[23496],{"data":23497,"marks":23498,"value":15134,"nodeType":867},{},[],{"data":23500,"content":23501,"nodeType":908},{},[],{"data":23503,"content":23504,"nodeType":918},{},[23505],{"data":23506,"marks":23507,"value":15145,"nodeType":867},{},[23508],{"type":916},{"data":23510,"content":23511,"nodeType":881},{},[23512],{"data":23513,"marks":23514,"value":15152,"nodeType":867},{},[],{"data":23516,"content":23517,"nodeType":881},{},[23518],{"data":23519,"marks":23520,"value":15159,"nodeType":867},{},[],{"data":23522,"content":23525,"nodeType":890},{"target":23523},{"sys":23524},{"id":15164,"type":887,"linkType":888},[],{"data":23527,"content":23528,"nodeType":908},{},[],{"data":23530,"content":23531,"nodeType":918},{},[23532],{"data":23533,"marks":23534,"value":6214,"nodeType":867},{},[23535],{"type":916},{"data":23537,"content":23538,"nodeType":881},{},[23539],{"data":23540,"marks":23541,"value":15182,"nodeType":867},{},[],{"data":23543,"content":23544,"nodeType":881},{},[23545],{"data":23546,"marks":23547,"value":15189,"nodeType":867},{},[],{"data":23549,"content":23550,"nodeType":881},{},[23551],{"data":23552,"marks":23553,"value":15196,"nodeType":867},{},[],{"data":23555,"content":23556,"nodeType":881},{},[23557,23560,23567,23570,23577],{"data":23558,"marks":23559,"value":10795,"nodeType":867},{},[],{"data":23561,"content":23562,"nodeType":876},{"uri":10798},[23563],{"data":23564,"marks":23565,"value":10803,"nodeType":867},{},[23566],{"type":1040},{"data":23568,"marks":23569,"value":15213,"nodeType":867},{},[],{"data":23571,"content":23572,"nodeType":876},{"uri":1629},[23573],{"data":23574,"marks":23575,"value":10826,"nodeType":867},{},[23576],{"type":1040},{"data":23578,"marks":23579,"value":1947,"nodeType":867},{},[],{"items":23581},[23582,23584],{"sys":23583,"name":2547},{"id":2546},{"sys":23585,"name":342},{"id":2550},{"items":23587},[23588],{"fullName":849,"firstName":850,"jobTitle":851,"profilePicture":23589},{"url":855},{"__typename":1742,"sys":23591,"content":23592,"title":21104,"synopsis":21105,"hashTags":59,"publishedDate":21106,"slug":21107,"tagsCollection":24328,"authorsCollection":24334},{"id":3644},{"json":23593},{"data":23594,"content":23595,"nodeType":1640},{},[23596,23603,23609,23615,23621,23631,23637,23642,23647,23650,23657,23663,23669,23674,23690,23696,23701,23707,23712,23718,23757,23762,23767,23773,23779,23782,23789,23805,23811,23816,23832,23837,23853,23859,23862,23869,23875,23911,23921,23924,23931,23946,23952,23965,23971,23977,23982,23988,23991,23998,24004,24052,24058,24061,24068,24073,24079,24085,24090,24096,24125,24131,24137,24142,24148,24153,24160,24176,24182,24212,24218,24248,24251,24258,24264,24269,24285,24291,24317,24322],{"data":23597,"content":23598,"nodeType":918},{},[23599],{"data":23600,"marks":23601,"value":20270,"nodeType":867},{},[23602],{"type":916},{"data":23604,"content":23605,"nodeType":881},{},[23606],{"data":23607,"marks":23608,"value":20277,"nodeType":867},{},[],{"data":23610,"content":23611,"nodeType":881},{},[23612],{"data":23613,"marks":23614,"value":20284,"nodeType":867},{},[],{"data":23616,"content":23617,"nodeType":881},{},[23618],{"data":23619,"marks":23620,"value":20291,"nodeType":867},{},[],{"data":23622,"content":23623,"nodeType":881},{},[23624,23628],{"data":23625,"marks":23626,"value":20299,"nodeType":867},{},[23627],{"type":916},{"data":23629,"marks":23630,"value":20303,"nodeType":867},{},[],{"data":23632,"content":23633,"nodeType":881},{},[23634],{"data":23635,"marks":23636,"value":20310,"nodeType":867},{},[],{"data":23638,"content":23641,"nodeType":890},{"target":23639},{"sys":23640},{"id":20315,"type":887,"linkType":888},[],{"data":23643,"content":23646,"nodeType":890},{"target":23644},{"sys":23645},{"id":20321,"type":887,"linkType":888},[],{"data":23648,"content":23649,"nodeType":908},{},[],{"data":23651,"content":23652,"nodeType":918},{},[23653],{"data":23654,"marks":23655,"value":20333,"nodeType":867},{},[23656],{"type":916},{"data":23658,"content":23659,"nodeType":881},{},[23660],{"data":23661,"marks":23662,"value":20340,"nodeType":867},{},[],{"data":23664,"content":23665,"nodeType":881},{},[23666],{"data":23667,"marks":23668,"value":20347,"nodeType":867},{},[],{"data":23670,"content":23673,"nodeType":890},{"target":23671},{"sys":23672},{"id":20352,"type":887,"linkType":888},[],{"data":23675,"content":23676,"nodeType":881},{},[23677,23680,23687],{"data":23678,"marks":23679,"value":20360,"nodeType":867},{},[],{"data":23681,"content":23682,"nodeType":876},{"uri":20363},[23683],{"data":23684,"marks":23685,"value":20369,"nodeType":867},{},[23686],{"type":1040},{"data":23688,"marks":23689,"value":20373,"nodeType":867},{},[],{"data":23691,"content":23692,"nodeType":881},{},[23693],{"data":23694,"marks":23695,"value":20380,"nodeType":867},{},[],{"data":23697,"content":23700,"nodeType":890},{"target":23698},{"sys":23699},{"id":20385,"type":887,"linkType":888},[],{"data":23702,"content":23703,"nodeType":881},{},[23704],{"data":23705,"marks":23706,"value":20393,"nodeType":867},{},[],{"data":23708,"content":23711,"nodeType":890},{"target":23709},{"sys":23710},{"id":20398,"type":887,"linkType":888},[],{"data":23713,"content":23714,"nodeType":881},{},[23715],{"data":23716,"marks":23717,"value":20406,"nodeType":867},{},[],{"data":23719,"content":23720,"nodeType":3126},{},[23721,23730,23739,23748],{"data":23722,"content":23723,"nodeType":3061},{},[23724],{"data":23725,"content":23726,"nodeType":881},{},[23727],{"data":23728,"marks":23729,"value":20419,"nodeType":867},{},[],{"data":23731,"content":23732,"nodeType":3061},{},[23733],{"data":23734,"content":23735,"nodeType":881},{},[23736],{"data":23737,"marks":23738,"value":20429,"nodeType":867},{},[],{"data":23740,"content":23741,"nodeType":3061},{},[23742],{"data":23743,"content":23744,"nodeType":881},{},[23745],{"data":23746,"marks":23747,"value":20439,"nodeType":867},{},[],{"data":23749,"content":23750,"nodeType":3061},{},[23751],{"data":23752,"content":23753,"nodeType":881},{},[23754],{"data":23755,"marks":23756,"value":20449,"nodeType":867},{},[],{"data":23758,"content":23761,"nodeType":890},{"target":23759},{"sys":23760},{"id":20454,"type":887,"linkType":888},[],{"data":23763,"content":23766,"nodeType":890},{"target":23764},{"sys":23765},{"id":20460,"type":887,"linkType":888},[],{"data":23768,"content":23769,"nodeType":881},{},[23770],{"data":23771,"marks":23772,"value":20468,"nodeType":867},{},[],{"data":23774,"content":23775,"nodeType":881},{},[23776],{"data":23777,"marks":23778,"value":20475,"nodeType":867},{},[],{"data":23780,"content":23781,"nodeType":908},{},[],{"data":23783,"content":23784,"nodeType":918},{},[23785],{"data":23786,"marks":23787,"value":20486,"nodeType":867},{},[23788],{"type":916},{"data":23790,"content":23791,"nodeType":881},{},[23792,23795,23802],{"data":23793,"marks":23794,"value":20493,"nodeType":867},{},[],{"data":23796,"content":23797,"nodeType":876},{"uri":20496},[23798],{"data":23799,"marks":23800,"value":20502,"nodeType":867},{},[23801],{"type":1040},{"data":23803,"marks":23804,"value":20506,"nodeType":867},{},[],{"data":23806,"content":23807,"nodeType":881},{},[23808],{"data":23809,"marks":23810,"value":20513,"nodeType":867},{},[],{"data":23812,"content":23815,"nodeType":890},{"target":23813},{"sys":23814},{"id":20518,"type":887,"linkType":888},[],{"data":23817,"content":23818,"nodeType":881},{},[23819,23822,23829],{"data":23820,"marks":23821,"value":20526,"nodeType":867},{},[],{"data":23823,"content":23824,"nodeType":876},{"uri":20529},[23825],{"data":23826,"marks":23827,"value":20535,"nodeType":867},{},[23828],{"type":1040},{"data":23830,"marks":23831,"value":1947,"nodeType":867},{},[],{"data":23833,"content":23836,"nodeType":890},{"target":23834},{"sys":23835},{"id":20543,"type":887,"linkType":888},[],{"data":23838,"content":23839,"nodeType":881},{},[23840,23843,23850],{"data":23841,"marks":23842,"value":20551,"nodeType":867},{},[],{"data":23844,"content":23845,"nodeType":876},{"uri":20554},[23846],{"data":23847,"marks":23848,"value":441,"nodeType":867},{},[23849],{"type":1040},{"data":23851,"marks":23852,"value":20563,"nodeType":867},{},[],{"data":23854,"content":23855,"nodeType":881},{},[23856],{"data":23857,"marks":23858,"value":20570,"nodeType":867},{},[],{"data":23860,"content":23861,"nodeType":908},{},[],{"data":23863,"content":23864,"nodeType":918},{},[23865],{"data":23866,"marks":23867,"value":20581,"nodeType":867},{},[23868],{"type":916},{"data":23870,"content":23871,"nodeType":881},{},[23872],{"data":23873,"marks":23874,"value":20588,"nodeType":867},{},[],{"data":23876,"content":23877,"nodeType":881},{},[23878,23881,23888,23891,23898,23901,23908],{"data":23879,"marks":23880,"value":20595,"nodeType":867},{},[],{"data":23882,"content":23883,"nodeType":876},{"uri":20598},[23884],{"data":23885,"marks":23886,"value":20604,"nodeType":867},{},[23887],{"type":1040},{"data":23889,"marks":23890,"value":2063,"nodeType":867},{},[],{"data":23892,"content":23893,"nodeType":876},{"uri":20610},[23894],{"data":23895,"marks":23896,"value":13838,"nodeType":867},{},[23897],{"type":1040},{"data":23899,"marks":23900,"value":20619,"nodeType":867},{},[],{"data":23902,"content":23903,"nodeType":876},{"uri":20622},[23904],{"data":23905,"marks":23906,"value":20628,"nodeType":867},{},[23907],{"type":1040},{"data":23909,"marks":23910,"value":20632,"nodeType":867},{},[],{"data":23912,"content":23913,"nodeType":881},{},[23914,23917],{"data":23915,"marks":23916,"value":20639,"nodeType":867},{},[],{"data":23918,"marks":23919,"value":20644,"nodeType":867},{},[23920],{"type":916},{"data":23922,"content":23923,"nodeType":908},{},[],{"data":23925,"content":23926,"nodeType":918},{},[23927],{"data":23928,"marks":23929,"value":20655,"nodeType":867},{},[23930],{"type":916},{"data":23932,"content":23933,"nodeType":881},{},[23934,23937,23943],{"data":23935,"marks":23936,"value":20662,"nodeType":867},{},[],{"data":23938,"content":23939,"nodeType":876},{"uri":2267},[23940],{"data":23941,"marks":23942,"value":16396,"nodeType":867},{},[],{"data":23944,"marks":23945,"value":20672,"nodeType":867},{},[],{"data":23947,"content":23948,"nodeType":881},{},[23949],{"data":23950,"marks":23951,"value":20679,"nodeType":867},{},[],{"data":23953,"content":23954,"nodeType":881},{},[23955,23958,23962],{"data":23956,"marks":23957,"value":20686,"nodeType":867},{},[],{"data":23959,"marks":23960,"value":20691,"nodeType":867},{},[23961],{"type":916},{"data":23963,"marks":23964,"value":20695,"nodeType":867},{},[],{"data":23966,"content":23967,"nodeType":881},{},[23968],{"data":23969,"marks":23970,"value":20702,"nodeType":867},{},[],{"data":23972,"content":23973,"nodeType":881},{},[23974],{"data":23975,"marks":23976,"value":20709,"nodeType":867},{},[],{"data":23978,"content":23981,"nodeType":890},{"target":23979},{"sys":23980},{"id":20714,"type":887,"linkType":888},[],{"data":23983,"content":23984,"nodeType":881},{},[23985],{"data":23986,"marks":23987,"value":20722,"nodeType":867},{},[],{"data":23989,"content":23990,"nodeType":908},{},[],{"data":23992,"content":23993,"nodeType":918},{},[23994],{"data":23995,"marks":23996,"value":20733,"nodeType":867},{},[23997],{"type":916},{"data":23999,"content":24000,"nodeType":881},{},[24001],{"data":24002,"marks":24003,"value":20740,"nodeType":867},{},[],{"data":24005,"content":24006,"nodeType":3126},{},[24007,24016,24025,24034,24043],{"data":24008,"content":24009,"nodeType":3061},{},[24010],{"data":24011,"content":24012,"nodeType":881},{},[24013],{"data":24014,"marks":24015,"value":20753,"nodeType":867},{},[],{"data":24017,"content":24018,"nodeType":3061},{},[24019],{"data":24020,"content":24021,"nodeType":881},{},[24022],{"data":24023,"marks":24024,"value":20763,"nodeType":867},{},[],{"data":24026,"content":24027,"nodeType":3061},{},[24028],{"data":24029,"content":24030,"nodeType":881},{},[24031],{"data":24032,"marks":24033,"value":20773,"nodeType":867},{},[],{"data":24035,"content":24036,"nodeType":3061},{},[24037],{"data":24038,"content":24039,"nodeType":881},{},[24040],{"data":24041,"marks":24042,"value":20783,"nodeType":867},{},[],{"data":24044,"content":24045,"nodeType":3061},{},[24046],{"data":24047,"content":24048,"nodeType":881},{},[24049],{"data":24050,"marks":24051,"value":20793,"nodeType":867},{},[],{"data":24053,"content":24054,"nodeType":881},{},[24055],{"data":24056,"marks":24057,"value":20800,"nodeType":867},{},[],{"data":24059,"content":24060,"nodeType":908},{},[],{"data":24062,"content":24063,"nodeType":918},{},[24064],{"data":24065,"marks":24066,"value":20811,"nodeType":867},{},[24067],{"type":916},{"data":24069,"content":24072,"nodeType":890},{"target":24070},{"sys":24071},{"id":20816,"type":887,"linkType":888},[],{"data":24074,"content":24075,"nodeType":881},{},[24076],{"data":24077,"marks":24078,"value":20824,"nodeType":867},{},[],{"data":24080,"content":24081,"nodeType":881},{},[24082],{"data":24083,"marks":24084,"value":20831,"nodeType":867},{},[],{"data":24086,"content":24089,"nodeType":890},{"target":24087},{"sys":24088},{"id":20836,"type":887,"linkType":888},[],{"data":24091,"content":24092,"nodeType":881},{},[24093],{"data":24094,"marks":24095,"value":20844,"nodeType":867},{},[],{"data":24097,"content":24098,"nodeType":3126},{},[24099,24112],{"data":24100,"content":24101,"nodeType":3061},{},[24102],{"data":24103,"content":24104,"nodeType":881},{},[24105,24109],{"data":24106,"marks":24107,"value":20858,"nodeType":867},{},[24108],{"type":916},{"data":24110,"marks":24111,"value":20862,"nodeType":867},{},[],{"data":24113,"content":24114,"nodeType":3061},{},[24115],{"data":24116,"content":24117,"nodeType":881},{},[24118,24122],{"data":24119,"marks":24120,"value":20873,"nodeType":867},{},[24121],{"type":916},{"data":24123,"marks":24124,"value":20877,"nodeType":867},{},[],{"data":24126,"content":24127,"nodeType":881},{},[24128],{"data":24129,"marks":24130,"value":20884,"nodeType":867},{},[],{"data":24132,"content":24133,"nodeType":881},{},[24134],{"data":24135,"marks":24136,"value":20891,"nodeType":867},{},[],{"data":24138,"content":24141,"nodeType":890},{"target":24139},{"sys":24140},{"id":20896,"type":887,"linkType":888},[],{"data":24143,"content":24144,"nodeType":881},{},[24145],{"data":24146,"marks":24147,"value":20904,"nodeType":867},{},[],{"data":24149,"content":24152,"nodeType":890},{"target":24150},{"sys":24151},{"id":20909,"type":887,"linkType":888},[],{"data":24154,"content":24155,"nodeType":998},{},[24156],{"data":24157,"marks":24158,"value":20918,"nodeType":867},{},[24159],{"type":916},{"data":24161,"content":24162,"nodeType":881},{},[24163,24166,24173],{"data":24164,"marks":24165,"value":9997,"nodeType":867},{},[],{"data":24167,"content":24168,"nodeType":876},{"uri":2392},[24169],{"data":24170,"marks":24171,"value":2397,"nodeType":867},{},[24172],{"type":1040},{"data":24174,"marks":24175,"value":20935,"nodeType":867},{},[],{"data":24177,"content":24178,"nodeType":881},{},[24179],{"data":24180,"marks":24181,"value":20942,"nodeType":867},{},[],{"data":24183,"content":24184,"nodeType":3126},{},[24185,24194,24203],{"data":24186,"content":24187,"nodeType":3061},{},[24188],{"data":24189,"content":24190,"nodeType":881},{},[24191],{"data":24192,"marks":24193,"value":20955,"nodeType":867},{},[],{"data":24195,"content":24196,"nodeType":3061},{},[24197],{"data":24198,"content":24199,"nodeType":881},{},[24200],{"data":24201,"marks":24202,"value":20965,"nodeType":867},{},[],{"data":24204,"content":24205,"nodeType":3061},{},[24206],{"data":24207,"content":24208,"nodeType":881},{},[24209],{"data":24210,"marks":24211,"value":20975,"nodeType":867},{},[],{"data":24213,"content":24214,"nodeType":881},{},[24215],{"data":24216,"marks":24217,"value":20982,"nodeType":867},{},[],{"data":24219,"content":24220,"nodeType":3126},{},[24221,24230,24239],{"data":24222,"content":24223,"nodeType":3061},{},[24224],{"data":24225,"content":24226,"nodeType":881},{},[24227],{"data":24228,"marks":24229,"value":20995,"nodeType":867},{},[],{"data":24231,"content":24232,"nodeType":3061},{},[24233],{"data":24234,"content":24235,"nodeType":881},{},[24236],{"data":24237,"marks":24238,"value":21005,"nodeType":867},{},[],{"data":24240,"content":24241,"nodeType":3061},{},[24242],{"data":24243,"content":24244,"nodeType":881},{},[24245],{"data":24246,"marks":24247,"value":21015,"nodeType":867},{},[],{"data":24249,"content":24250,"nodeType":908},{},[],{"data":24252,"content":24253,"nodeType":918},{},[24254],{"data":24255,"marks":24256,"value":21026,"nodeType":867},{},[24257],{"type":916},{"data":24259,"content":24260,"nodeType":881},{},[24261],{"data":24262,"marks":24263,"value":21033,"nodeType":867},{},[],{"data":24265,"content":24268,"nodeType":890},{"target":24266},{"sys":24267},{"id":21038,"type":887,"linkType":888},[],{"data":24270,"content":24271,"nodeType":881},{},[24272,24275,24282],{"data":24273,"marks":24274,"value":21046,"nodeType":867},{},[],{"data":24276,"content":24277,"nodeType":876},{"uri":2267},[24278],{"data":24279,"marks":24280,"value":21054,"nodeType":867},{},[24281],{"type":1040},{"data":24283,"marks":24284,"value":21058,"nodeType":867},{},[],{"data":24286,"content":24287,"nodeType":881},{},[24288],{"data":24289,"marks":24290,"value":21065,"nodeType":867},{},[],{"data":24292,"content":24293,"nodeType":881},{},[24294,24297,24304,24307,24314],{"data":24295,"marks":24296,"value":10795,"nodeType":867},{},[],{"data":24298,"content":24299,"nodeType":876},{"uri":10798},[24300],{"data":24301,"marks":24302,"value":10803,"nodeType":867},{},[24303],{"type":1040},{"data":24305,"marks":24306,"value":15213,"nodeType":867},{},[],{"data":24308,"content":24309,"nodeType":876},{"uri":1629},[24310],{"data":24311,"marks":24312,"value":10826,"nodeType":867},{},[24313],{"type":1040},{"data":24315,"marks":24316,"value":1947,"nodeType":867},{},[],{"data":24318,"content":24321,"nodeType":890},{"target":24319},{"sys":24320},{"id":21096,"type":887,"linkType":888},[],{"data":24323,"content":24324,"nodeType":881},{},[24325],{"data":24326,"marks":24327,"value":21,"nodeType":867},{},[],{"items":24329},[24330,24332],{"sys":24331,"name":2547},{"id":2546},{"sys":24333,"name":342},{"id":2550},{"items":24335},[24336],{"fullName":15937,"firstName":15938,"jobTitle":15939,"profilePicture":24337},{"url":15943},{"__typename":1742,"sys":24339,"content":24340,"title":21727,"synopsis":21728,"hashTags":59,"publishedDate":21729,"slug":21730,"tagsCollection":24863,"authorsCollection":24869},{"id":21120},{"json":24341},{"data":24342,"content":24343,"nodeType":1640},{},[24344,24360,24366,24372,24375,24382,24398,24414,24441,24446,24449,24456,24463,24469,24485,24491,24496,24501,24507,24513,24520,24526,24532,24537,24543,24559,24566,24572,24578,24594,24599,24615,24620,24626,24631,24634,24641,24647,24663,24669,24692,24698,24705,24708,24715,24721,24727,24732,24738,24777,24782,24788,24814,24819,24857],{"data":24345,"content":24346,"nodeType":881},{},[24347,24350,24357],{"data":24348,"marks":24349,"value":21,"nodeType":867},{},[],{"data":24351,"content":24352,"nodeType":876},{"uri":3051},[24353],{"data":24354,"marks":24355,"value":3056,"nodeType":867},{},[24356],{"type":1040},{"data":24358,"marks":24359,"value":21141,"nodeType":867},{},[],{"data":24361,"content":24362,"nodeType":881},{},[24363],{"data":24364,"marks":24365,"value":21148,"nodeType":867},{},[],{"data":24367,"content":24368,"nodeType":881},{},[24369],{"data":24370,"marks":24371,"value":21155,"nodeType":867},{},[],{"data":24373,"content":24374,"nodeType":908},{},[],{"data":24376,"content":24377,"nodeType":918},{},[24378],{"data":24379,"marks":24380,"value":21166,"nodeType":867},{},[24381],{"type":916},{"data":24383,"content":24384,"nodeType":881},{},[24385,24388,24395],{"data":24386,"marks":24387,"value":21173,"nodeType":867},{},[],{"data":24389,"content":24390,"nodeType":876},{"uri":21176},[24391],{"data":24392,"marks":24393,"value":21182,"nodeType":867},{},[24394],{"type":1040},{"data":24396,"marks":24397,"value":21186,"nodeType":867},{},[],{"data":24399,"content":24400,"nodeType":881},{},[24401,24404,24411],{"data":24402,"marks":24403,"value":21193,"nodeType":867},{},[],{"data":24405,"content":24406,"nodeType":876},{"uri":14682},[24407],{"data":24408,"marks":24409,"value":21201,"nodeType":867},{},[24410],{"type":1040},{"data":24412,"marks":24413,"value":21205,"nodeType":867},{},[],{"data":24415,"content":24416,"nodeType":881},{},[24417,24420,24424,24427,24431,24434,24438],{"data":24418,"marks":24419,"value":21212,"nodeType":867},{},[],{"data":24421,"marks":24422,"value":21217,"nodeType":867},{},[24423],{"type":916},{"data":24425,"marks":24426,"value":21221,"nodeType":867},{},[],{"data":24428,"marks":24429,"value":21226,"nodeType":867},{},[24430],{"type":916},{"data":24432,"marks":24433,"value":21230,"nodeType":867},{},[],{"data":24435,"marks":24436,"value":21235,"nodeType":867},{},[24437],{"type":916},{"data":24439,"marks":24440,"value":21239,"nodeType":867},{},[],{"data":24442,"content":24445,"nodeType":890},{"target":24443},{"sys":24444},{"id":21244,"type":887,"linkType":888},[],{"data":24447,"content":24448,"nodeType":908},{},[],{"data":24450,"content":24451,"nodeType":918},{},[24452],{"data":24453,"marks":24454,"value":21256,"nodeType":867},{},[24455],{"type":916},{"data":24457,"content":24458,"nodeType":998},{},[24459],{"data":24460,"marks":24461,"value":21264,"nodeType":867},{},[24462],{"type":916},{"data":24464,"content":24465,"nodeType":881},{},[24466],{"data":24467,"marks":24468,"value":21271,"nodeType":867},{},[],{"data":24470,"content":24471,"nodeType":881},{},[24472,24475,24482],{"data":24473,"marks":24474,"value":21,"nodeType":867},{},[],{"data":24476,"content":24477,"nodeType":876},{"uri":3051},[24478],{"data":24479,"marks":24480,"value":21285,"nodeType":867},{},[24481],{"type":1040},{"data":24483,"marks":24484,"value":21289,"nodeType":867},{},[],{"data":24486,"content":24487,"nodeType":881},{},[24488],{"data":24489,"marks":24490,"value":21296,"nodeType":867},{},[],{"data":24492,"content":24495,"nodeType":890},{"target":24493},{"sys":24494},{"id":14442,"type":887,"linkType":888},[],{"data":24497,"content":24500,"nodeType":890},{"target":24498},{"sys":24499},{"id":21306,"type":887,"linkType":888},[],{"data":24502,"content":24503,"nodeType":881},{},[24504],{"data":24505,"marks":24506,"value":21314,"nodeType":867},{},[],{"data":24508,"content":24509,"nodeType":881},{},[24510],{"data":24511,"marks":24512,"value":21321,"nodeType":867},{},[],{"data":24514,"content":24515,"nodeType":998},{},[24516],{"data":24517,"marks":24518,"value":21329,"nodeType":867},{},[24519],{"type":916},{"data":24521,"content":24522,"nodeType":881},{},[24523],{"data":24524,"marks":24525,"value":21336,"nodeType":867},{},[],{"data":24527,"content":24528,"nodeType":881},{},[24529],{"data":24530,"marks":24531,"value":21343,"nodeType":867},{},[],{"data":24533,"content":24536,"nodeType":890},{"target":24534},{"sys":24535},{"id":21348,"type":887,"linkType":888},[],{"data":24538,"content":24539,"nodeType":881},{},[24540],{"data":24541,"marks":24542,"value":21356,"nodeType":867},{},[],{"data":24544,"content":24545,"nodeType":881},{},[24546,24549,24556],{"data":24547,"marks":24548,"value":21363,"nodeType":867},{},[],{"data":24550,"content":24551,"nodeType":876},{"uri":21366},[24552],{"data":24553,"marks":24554,"value":21372,"nodeType":867},{},[24555],{"type":1040},{"data":24557,"marks":24558,"value":21376,"nodeType":867},{},[],{"data":24560,"content":24561,"nodeType":998},{},[24562],{"data":24563,"marks":24564,"value":21384,"nodeType":867},{},[24565],{"type":916},{"data":24567,"content":24568,"nodeType":881},{},[24569],{"data":24570,"marks":24571,"value":21391,"nodeType":867},{},[],{"data":24573,"content":24574,"nodeType":881},{},[24575],{"data":24576,"marks":24577,"value":21398,"nodeType":867},{},[],{"data":24579,"content":24580,"nodeType":881},{},[24581,24584,24591],{"data":24582,"marks":24583,"value":21405,"nodeType":867},{},[],{"data":24585,"content":24586,"nodeType":876},{"uri":21408},[24587],{"data":24588,"marks":24589,"value":21414,"nodeType":867},{},[24590],{"type":1040},{"data":24592,"marks":24593,"value":21418,"nodeType":867},{},[],{"data":24595,"content":24598,"nodeType":890},{"target":24596},{"sys":24597},{"id":21423,"type":887,"linkType":888},[],{"data":24600,"content":24601,"nodeType":881},{},[24602,24605,24612],{"data":24603,"marks":24604,"value":21431,"nodeType":867},{},[],{"data":24606,"content":24607,"nodeType":876},{"uri":6845},[24608],{"data":24609,"marks":24610,"value":21439,"nodeType":867},{},[24611],{"type":1040},{"data":24613,"marks":24614,"value":21443,"nodeType":867},{},[],{"data":24616,"content":24619,"nodeType":890},{"target":24617},{"sys":24618},{"id":21448,"type":887,"linkType":888},[],{"data":24621,"content":24622,"nodeType":881},{},[24623],{"data":24624,"marks":24625,"value":21456,"nodeType":867},{},[],{"data":24627,"content":24630,"nodeType":890},{"target":24628},{"sys":24629},{"id":21461,"type":887,"linkType":888},[],{"data":24632,"content":24633,"nodeType":908},{},[],{"data":24635,"content":24636,"nodeType":918},{},[24637],{"data":24638,"marks":24639,"value":2257,"nodeType":867},{},[24640],{"type":916},{"data":24642,"content":24643,"nodeType":881},{},[24644],{"data":24645,"marks":24646,"value":21479,"nodeType":867},{},[],{"data":24648,"content":24649,"nodeType":881},{},[24650,24653,24660],{"data":24651,"marks":24652,"value":21486,"nodeType":867},{},[],{"data":24654,"content":24655,"nodeType":876},{"uri":21489},[24656],{"data":24657,"marks":24658,"value":16396,"nodeType":867},{},[24659],{"type":1040},{"data":24661,"marks":24662,"value":21498,"nodeType":867},{},[],{"data":24664,"content":24665,"nodeType":881},{},[24666],{"data":24667,"marks":24668,"value":21505,"nodeType":867},{},[],{"data":24670,"content":24671,"nodeType":881},{},[24672,24675,24679,24682,24689],{"data":24673,"marks":24674,"value":21512,"nodeType":867},{},[],{"data":24676,"marks":24677,"value":21517,"nodeType":867},{},[24678],{"type":916},{"data":24680,"marks":24681,"value":4006,"nodeType":867},{},[],{"data":24683,"content":24684,"nodeType":876},{"uri":2731},[24685],{"data":24686,"marks":24687,"value":21528,"nodeType":867},{},[24688],{"type":1040},{"data":24690,"marks":24691,"value":21532,"nodeType":867},{},[],{"data":24693,"content":24694,"nodeType":881},{},[24695],{"data":24696,"marks":24697,"value":21539,"nodeType":867},{},[],{"data":24699,"content":24700,"nodeType":881},{},[24701],{"data":24702,"marks":24703,"value":21547,"nodeType":867},{},[24704],{"type":916},{"data":24706,"content":24707,"nodeType":908},{},[],{"data":24709,"content":24710,"nodeType":918},{},[24711],{"data":24712,"marks":24713,"value":21558,"nodeType":867},{},[24714],{"type":916},{"data":24716,"content":24717,"nodeType":881},{},[24718],{"data":24719,"marks":24720,"value":21565,"nodeType":867},{},[],{"data":24722,"content":24723,"nodeType":881},{},[24724],{"data":24725,"marks":24726,"value":21572,"nodeType":867},{},[],{"data":24728,"content":24731,"nodeType":890},{"target":24729},{"sys":24730},{"id":21577,"type":887,"linkType":888},[],{"data":24733,"content":24734,"nodeType":881},{},[24735],{"data":24736,"marks":24737,"value":21585,"nodeType":867},{},[],{"data":24739,"content":24740,"nodeType":3126},{},[24741,24759],{"data":24742,"content":24743,"nodeType":3061},{},[24744],{"data":24745,"content":24746,"nodeType":881},{},[24747,24750,24756],{"data":24748,"marks":24749,"value":21,"nodeType":867},{},[],{"data":24751,"content":24752,"nodeType":876},{"uri":21600},[24753],{"data":24754,"marks":24755,"value":21605,"nodeType":867},{},[],{"data":24757,"marks":24758,"value":21609,"nodeType":867},{},[],{"data":24760,"content":24761,"nodeType":3061},{},[24762],{"data":24763,"content":24764,"nodeType":881},{},[24765,24768,24774],{"data":24766,"marks":24767,"value":21,"nodeType":867},{},[],{"data":24769,"content":24770,"nodeType":876},{"uri":21621},[24771],{"data":24772,"marks":24773,"value":21626,"nodeType":867},{},[],{"data":24775,"marks":24776,"value":21630,"nodeType":867},{},[],{"data":24778,"content":24781,"nodeType":890},{"target":24779},{"sys":24780},{"id":21635,"type":887,"linkType":888},[],{"data":24783,"content":24784,"nodeType":881},{},[24785],{"data":24786,"marks":24787,"value":21643,"nodeType":867},{},[],{"data":24789,"content":24790,"nodeType":881},{},[24791,24794,24801,24804,24811],{"data":24792,"marks":24793,"value":21650,"nodeType":867},{},[],{"data":24795,"content":24796,"nodeType":876},{"uri":15783},[24797],{"data":24798,"marks":24799,"value":21658,"nodeType":867},{},[24800],{"type":1040},{"data":24802,"marks":24803,"value":21662,"nodeType":867},{},[],{"data":24805,"content":24806,"nodeType":876},{"uri":14788},[24807],{"data":24808,"marks":24809,"value":21670,"nodeType":867},{},[24810],{"type":1040},{"data":24812,"marks":24813,"value":21674,"nodeType":867},{},[],{"data":24815,"content":24818,"nodeType":890},{"target":24816},{"sys":24817},{"id":15799,"type":887,"linkType":888},[],{"data":24820,"content":24821,"nodeType":1433},{},[24822],{"data":24823,"content":24824,"nodeType":881},{},[24825,24828,24835,24838,24844,24847,24854],{"data":24826,"marks":24827,"value":21689,"nodeType":867},{},[],{"data":24829,"content":24830,"nodeType":876},{"uri":10798},[24831],{"data":24832,"marks":24833,"value":21697,"nodeType":867},{},[24834],{"type":1040},{"data":24836,"marks":24837,"value":4006,"nodeType":867},{},[],{"data":24839,"content":24840,"nodeType":876},{"uri":10809},[24841],{"data":24842,"marks":24843,"value":21707,"nodeType":867},{},[],{"data":24845,"marks":24846,"value":10819,"nodeType":867},{},[],{"data":24848,"content":24849,"nodeType":876},{"uri":1629},[24850],{"data":24851,"marks":24852,"value":10826,"nodeType":867},{},[24853],{"type":1040},{"data":24855,"marks":24856,"value":1947,"nodeType":867},{},[],{"data":24858,"content":24859,"nodeType":881},{},[24860],{"data":24861,"marks":24862,"value":21,"nodeType":867},{},[],{"items":24864},[24865,24867],{"sys":24866,"name":2547},{"id":2546},{"sys":24868,"name":342},{"id":2550},{"items":24870},[24871],{"fullName":849,"firstName":850,"jobTitle":851,"profilePicture":24872},{"url":855},"stryker-handala-report","blog/stryker-handala-report",{"json":24876},{"data":24877,"content":24878,"nodeType":1640},{},[24879],{"data":24880,"content":24881,"nodeType":881},{},[24882],{"data":24883,"marks":24884,"value":24885,"nodeType":867},{},[],"The Stryker breach doesn't track with Handala's historical TTPs. This shows just how quickly the default attacker toolkit is evolving, and is a wake-up call for defenders.","Analysing the Stryker breach in line with recent changes to the Iran-nexus cyber playbook.",{"id":24888,"publishedAt":24889},"10hUzI9iiY8fFtmlA0M9Ne","2026-08-12T11:53:05.473Z",{"items":24891},[24892,24894],{"sys":24893,"name":2547},{"id":2546},{"sys":24895,"name":342},{"id":2550},{"items":24897},[24898,24900,24902,24904,24906,24908,24910,24912,24914,24916,24918,24920,24922,24924,24926],{"sys":24899,"name":279,"slug":280,"tier":31},{"id":276},{"sys":24901,"name":413,"slug":414,"tier":31},{"id":410},{"sys":24903,"name":642,"slug":643,"tier":31},{"id":639},{"sys":24905,"name":342,"slug":343,"tier":31},{"id":339},{"sys":24907,"name":528,"slug":529,"tier":45},{"id":525},{"sys":24909,"name":404,"slug":405,"tier":45},{"id":401},{"sys":24911,"name":333,"slug":334,"tier":45},{"id":330},{"sys":24913,"name":466,"slug":467,"tier":45},{"id":463},{"sys":24915,"name":261,"slug":262,"tier":45},{"id":258},{"sys":24917,"name":422,"slug":423,"tier":45},{"id":419},{"sys":24919,"name":607,"slug":608,"tier":45},{"id":604},{"sys":24921,"name":650,"slug":651,"tier":45},{"id":647},{"sys":24923,"name":324,"slug":325,"tier":45},{"id":321},{"sys":24925,"name":484,"slug":485,"tier":45},{"id":481},{"sys":24927,"name":571,"slug":572,"tier":45},{"id":568},"HW8q7GTrDntSuJ9ZluqxI3jsbkqipTZ55wT8PFnf3RM",{"id":24930,"title":21727,"authorsCollection":24931,"content":24936,"extension":228,"faqItemsCollection":25585,"faqTitle":59,"featured":6,"hashTags":59,"meta":25587,"metaTitle":25588,"ogImage":59,"postType":8156,"publishedDate":21729,"relatedBlogPostsCollection":25589,"slug":21730,"stem":28543,"subtitle":59,"summary":28544,"synopsis":21728,"sys":28555,"tagsCollection":28557,"topicsCollection":28563,"__hash__":28599},"blog/blog/unpacking-the-latest-slh-campaign.json",{"items":24932},[24933],{"fullName":849,"firstName":850,"jobTitle":851,"socialLinks":24934,"profilePicture":24935},[853],{"url":855},{"json":24937,"links":25459},{"data":24938,"content":24939,"nodeType":1640},{},[24940,24956,24962,24968,24971,24978,24994,25010,25037,25042,25045,25052,25059,25065,25081,25087,25092,25097,25103,25109,25116,25122,25128,25133,25139,25155,25162,25168,25174,25190,25195,25211,25216,25222,25227,25230,25237,25243,25259,25265,25288,25294,25301,25304,25311,25317,25323,25328,25334,25373,25378,25384,25410,25415,25453],{"data":24941,"content":24942,"nodeType":881},{},[24943,24946,24953],{"data":24944,"marks":24945,"value":21,"nodeType":867},{},[],{"data":24947,"content":24948,"nodeType":876},{"uri":3051},[24949],{"data":24950,"marks":24951,"value":3056,"nodeType":867},{},[24952],{"type":1040},{"data":24954,"marks":24955,"value":21141,"nodeType":867},{},[],{"data":24957,"content":24958,"nodeType":881},{},[24959],{"data":24960,"marks":24961,"value":21148,"nodeType":867},{},[],{"data":24963,"content":24964,"nodeType":881},{},[24965],{"data":24966,"marks":24967,"value":21155,"nodeType":867},{},[],{"data":24969,"content":24970,"nodeType":908},{},[],{"data":24972,"content":24973,"nodeType":918},{},[24974],{"data":24975,"marks":24976,"value":21166,"nodeType":867},{},[24977],{"type":916},{"data":24979,"content":24980,"nodeType":881},{},[24981,24984,24991],{"data":24982,"marks":24983,"value":21173,"nodeType":867},{},[],{"data":24985,"content":24986,"nodeType":876},{"uri":21176},[24987],{"data":24988,"marks":24989,"value":21182,"nodeType":867},{},[24990],{"type":1040},{"data":24992,"marks":24993,"value":21186,"nodeType":867},{},[],{"data":24995,"content":24996,"nodeType":881},{},[24997,25000,25007],{"data":24998,"marks":24999,"value":21193,"nodeType":867},{},[],{"data":25001,"content":25002,"nodeType":876},{"uri":14682},[25003],{"data":25004,"marks":25005,"value":21201,"nodeType":867},{},[25006],{"type":1040},{"data":25008,"marks":25009,"value":21205,"nodeType":867},{},[],{"data":25011,"content":25012,"nodeType":881},{},[25013,25016,25020,25023,25027,25030,25034],{"data":25014,"marks":25015,"value":21212,"nodeType":867},{},[],{"data":25017,"marks":25018,"value":21217,"nodeType":867},{},[25019],{"type":916},{"data":25021,"marks":25022,"value":21221,"nodeType":867},{},[],{"data":25024,"marks":25025,"value":21226,"nodeType":867},{},[25026],{"type":916},{"data":25028,"marks":25029,"value":21230,"nodeType":867},{},[],{"data":25031,"marks":25032,"value":21235,"nodeType":867},{},[25033],{"type":916},{"data":25035,"marks":25036,"value":21239,"nodeType":867},{},[],{"data":25038,"content":25041,"nodeType":890},{"target":25039},{"sys":25040},{"id":21244,"type":887,"linkType":888},[],{"data":25043,"content":25044,"nodeType":908},{},[],{"data":25046,"content":25047,"nodeType":918},{},[25048],{"data":25049,"marks":25050,"value":21256,"nodeType":867},{},[25051],{"type":916},{"data":25053,"content":25054,"nodeType":998},{},[25055],{"data":25056,"marks":25057,"value":21264,"nodeType":867},{},[25058],{"type":916},{"data":25060,"content":25061,"nodeType":881},{},[25062],{"data":25063,"marks":25064,"value":21271,"nodeType":867},{},[],{"data":25066,"content":25067,"nodeType":881},{},[25068,25071,25078],{"data":25069,"marks":25070,"value":21,"nodeType":867},{},[],{"data":25072,"content":25073,"nodeType":876},{"uri":3051},[25074],{"data":25075,"marks":25076,"value":21285,"nodeType":867},{},[25077],{"type":1040},{"data":25079,"marks":25080,"value":21289,"nodeType":867},{},[],{"data":25082,"content":25083,"nodeType":881},{},[25084],{"data":25085,"marks":25086,"value":21296,"nodeType":867},{},[],{"data":25088,"content":25091,"nodeType":890},{"target":25089},{"sys":25090},{"id":14442,"type":887,"linkType":888},[],{"data":25093,"content":25096,"nodeType":890},{"target":25094},{"sys":25095},{"id":21306,"type":887,"linkType":888},[],{"data":25098,"content":25099,"nodeType":881},{},[25100],{"data":25101,"marks":25102,"value":21314,"nodeType":867},{},[],{"data":25104,"content":25105,"nodeType":881},{},[25106],{"data":25107,"marks":25108,"value":21321,"nodeType":867},{},[],{"data":25110,"content":25111,"nodeType":998},{},[25112],{"data":25113,"marks":25114,"value":21329,"nodeType":867},{},[25115],{"type":916},{"data":25117,"content":25118,"nodeType":881},{},[25119],{"data":25120,"marks":25121,"value":21336,"nodeType":867},{},[],{"data":25123,"content":25124,"nodeType":881},{},[25125],{"data":25126,"marks":25127,"value":21343,"nodeType":867},{},[],{"data":25129,"content":25132,"nodeType":890},{"target":25130},{"sys":25131},{"id":21348,"type":887,"linkType":888},[],{"data":25134,"content":25135,"nodeType":881},{},[25136],{"data":25137,"marks":25138,"value":21356,"nodeType":867},{},[],{"data":25140,"content":25141,"nodeType":881},{},[25142,25145,25152],{"data":25143,"marks":25144,"value":21363,"nodeType":867},{},[],{"data":25146,"content":25147,"nodeType":876},{"uri":21366},[25148],{"data":25149,"marks":25150,"value":21372,"nodeType":867},{},[25151],{"type":1040},{"data":25153,"marks":25154,"value":21376,"nodeType":867},{},[],{"data":25156,"content":25157,"nodeType":998},{},[25158],{"data":25159,"marks":25160,"value":21384,"nodeType":867},{},[25161],{"type":916},{"data":25163,"content":25164,"nodeType":881},{},[25165],{"data":25166,"marks":25167,"value":21391,"nodeType":867},{},[],{"data":25169,"content":25170,"nodeType":881},{},[25171],{"data":25172,"marks":25173,"value":21398,"nodeType":867},{},[],{"data":25175,"content":25176,"nodeType":881},{},[25177,25180,25187],{"data":25178,"marks":25179,"value":21405,"nodeType":867},{},[],{"data":25181,"content":25182,"nodeType":876},{"uri":21408},[25183],{"data":25184,"marks":25185,"value":21414,"nodeType":867},{},[25186],{"type":1040},{"data":25188,"marks":25189,"value":21418,"nodeType":867},{},[],{"data":25191,"content":25194,"nodeType":890},{"target":25192},{"sys":25193},{"id":21423,"type":887,"linkType":888},[],{"data":25196,"content":25197,"nodeType":881},{},[25198,25201,25208],{"data":25199,"marks":25200,"value":21431,"nodeType":867},{},[],{"data":25202,"content":25203,"nodeType":876},{"uri":6845},[25204],{"data":25205,"marks":25206,"value":21439,"nodeType":867},{},[25207],{"type":1040},{"data":25209,"marks":25210,"value":21443,"nodeType":867},{},[],{"data":25212,"content":25215,"nodeType":890},{"target":25213},{"sys":25214},{"id":21448,"type":887,"linkType":888},[],{"data":25217,"content":25218,"nodeType":881},{},[25219],{"data":25220,"marks":25221,"value":21456,"nodeType":867},{},[],{"data":25223,"content":25226,"nodeType":890},{"target":25224},{"sys":25225},{"id":21461,"type":887,"linkType":888},[],{"data":25228,"content":25229,"nodeType":908},{},[],{"data":25231,"content":25232,"nodeType":918},{},[25233],{"data":25234,"marks":25235,"value":2257,"nodeType":867},{},[25236],{"type":916},{"data":25238,"content":25239,"nodeType":881},{},[25240],{"data":25241,"marks":25242,"value":21479,"nodeType":867},{},[],{"data":25244,"content":25245,"nodeType":881},{},[25246,25249,25256],{"data":25247,"marks":25248,"value":21486,"nodeType":867},{},[],{"data":25250,"content":25251,"nodeType":876},{"uri":21489},[25252],{"data":25253,"marks":25254,"value":16396,"nodeType":867},{},[25255],{"type":1040},{"data":25257,"marks":25258,"value":21498,"nodeType":867},{},[],{"data":25260,"content":25261,"nodeType":881},{},[25262],{"data":25263,"marks":25264,"value":21505,"nodeType":867},{},[],{"data":25266,"content":25267,"nodeType":881},{},[25268,25271,25275,25278,25285],{"data":25269,"marks":25270,"value":21512,"nodeType":867},{},[],{"data":25272,"marks":25273,"value":21517,"nodeType":867},{},[25274],{"type":916},{"data":25276,"marks":25277,"value":4006,"nodeType":867},{},[],{"data":25279,"content":25280,"nodeType":876},{"uri":2731},[25281],{"data":25282,"marks":25283,"value":21528,"nodeType":867},{},[25284],{"type":1040},{"data":25286,"marks":25287,"value":21532,"nodeType":867},{},[],{"data":25289,"content":25290,"nodeType":881},{},[25291],{"data":25292,"marks":25293,"value":21539,"nodeType":867},{},[],{"data":25295,"content":25296,"nodeType":881},{},[25297],{"data":25298,"marks":25299,"value":21547,"nodeType":867},{},[25300],{"type":916},{"data":25302,"content":25303,"nodeType":908},{},[],{"data":25305,"content":25306,"nodeType":918},{},[25307],{"data":25308,"marks":25309,"value":21558,"nodeType":867},{},[25310],{"type":916},{"data":25312,"content":25313,"nodeType":881},{},[25314],{"data":25315,"marks":25316,"value":21565,"nodeType":867},{},[],{"data":25318,"content":25319,"nodeType":881},{},[25320],{"data":25321,"marks":25322,"value":21572,"nodeType":867},{},[],{"data":25324,"content":25327,"nodeType":890},{"target":25325},{"sys":25326},{"id":21577,"type":887,"linkType":888},[],{"data":25329,"content":25330,"nodeType":881},{},[25331],{"data":25332,"marks":25333,"value":21585,"nodeType":867},{},[],{"data":25335,"content":25336,"nodeType":3126},{},[25337,25355],{"data":25338,"content":25339,"nodeType":3061},{},[25340],{"data":25341,"content":25342,"nodeType":881},{},[25343,25346,25352],{"data":25344,"marks":25345,"value":21,"nodeType":867},{},[],{"data":25347,"content":25348,"nodeType":876},{"uri":21600},[25349],{"data":25350,"marks":25351,"value":21605,"nodeType":867},{},[],{"data":25353,"marks":25354,"value":21609,"nodeType":867},{},[],{"data":25356,"content":25357,"nodeType":3061},{},[25358],{"data":25359,"content":25360,"nodeType":881},{},[25361,25364,25370],{"data":25362,"marks":25363,"value":21,"nodeType":867},{},[],{"data":25365,"content":25366,"nodeType":876},{"uri":21621},[25367],{"data":25368,"marks":25369,"value":21626,"nodeType":867},{},[],{"data":25371,"marks":25372,"value":21630,"nodeType":867},{},[],{"data":25374,"content":25377,"nodeType":890},{"target":25375},{"sys":25376},{"id":21635,"type":887,"linkType":888},[],{"data":25379,"content":25380,"nodeType":881},{},[25381],{"data":25382,"marks":25383,"value":21643,"nodeType":867},{},[],{"data":25385,"content":25386,"nodeType":881},{},[25387,25390,25397,25400,25407],{"data":25388,"marks":25389,"value":21650,"nodeType":867},{},[],{"data":25391,"content":25392,"nodeType":876},{"uri":15783},[25393],{"data":25394,"marks":25395,"value":21658,"nodeType":867},{},[25396],{"type":1040},{"data":25398,"marks":25399,"value":21662,"nodeType":867},{},[],{"data":25401,"content":25402,"nodeType":876},{"uri":14788},[25403],{"data":25404,"marks":25405,"value":21670,"nodeType":867},{},[25406],{"type":1040},{"data":25408,"marks":25409,"value":21674,"nodeType":867},{},[],{"data":25411,"content":25414,"nodeType":890},{"target":25412},{"sys":25413},{"id":15799,"type":887,"linkType":888},[],{"data":25416,"content":25417,"nodeType":1433},{},[25418],{"data":25419,"content":25420,"nodeType":881},{},[25421,25424,25431,25434,25440,25443,25450],{"data":25422,"marks":25423,"value":21689,"nodeType":867},{},[],{"data":25425,"content":25426,"nodeType":876},{"uri":10798},[25427],{"data":25428,"marks":25429,"value":21697,"nodeType":867},{},[25430],{"type":1040},{"data":25432,"marks":25433,"value":4006,"nodeType":867},{},[],{"data":25435,"content":25436,"nodeType":876},{"uri":10809},[25437],{"data":25438,"marks":25439,"value":21707,"nodeType":867},{},[],{"data":25441,"marks":25442,"value":10819,"nodeType":867},{},[],{"data":25444,"content":25445,"nodeType":876},{"uri":1629},[25446],{"data":25447,"marks":25448,"value":10826,"nodeType":867},{},[25449],{"type":1040},{"data":25451,"marks":25452,"value":1947,"nodeType":867},{},[],{"data":25454,"content":25455,"nodeType":881},{},[25456],{"data":25457,"marks":25458,"value":21,"nodeType":867},{},[],{"entries":25460},{"hyperlink":25461,"inline":25462,"block":25463},[],[],[25464,25472,25479,25504,25512,25518,25542,25546,25571,25577],{"sys":25465,"__typename":1648,"title":25466,"caption":25467,"layoutMode":59,"file":25468},{"id":21244},"SLH TOR leak site with claimed victims.","SLH Tor leak site with claimed victims.",{"url":25469,"width":25470,"height":25471},"https://images.ctfassets.net/y1cdw1ablpvd/PoWJBZ3uyl94usKVv3zgr/ed5aefc88cf39fe354755c7b145564bf/image4.png",1284,588,{"sys":25473,"__typename":1648,"title":25474,"caption":25474,"layoutMode":59,"file":25475},{"id":14442},"Big picture view of Scattered Lapsus$ Hunters breaches since 2021.",{"url":25476,"width":25477,"height":25478},"https://images.ctfassets.net/y1cdw1ablpvd/415gvGUy6Ywr2zofY8Phpk/dc9a8461ef07c041fef4a7fb39d0a25b/Screenshot_2026-02-25_at_09.50.56.png",3414,1852,{"sys":25480,"__typename":1696,"content":25481,"name":25503,"title":59},{"id":21306},{"json":25482},{"data":25483,"content":25484,"nodeType":1640},{},[25485],{"data":25486,"content":25487,"nodeType":881},{},[25488,25492,25500],{"data":25489,"marks":25490,"value":25491,"nodeType":867},{},[],"Get the background on Scattered Lapsus$ Hunters, and how they relate to Scattered Spider, Lapsus$, ShinyHunters, and other Com-affiliated groups in our recent deep dive, unpacking related breaches dating back to 2021 ",{"data":25493,"content":25494,"nodeType":876},{"uri":3051},[25495],{"data":25496,"marks":25497,"value":25499,"nodeType":867},{},[25498],{"type":1040},"in our recent blog post",{"data":25501,"marks":25502,"value":1947,"nodeType":867},{},[],"SLH campaign insight box 1",{"sys":25505,"__typename":1648,"title":25506,"caption":25507,"layoutMode":59,"file":25508},{"id":21348},"What the operator sees in their phishing dashboard.","Phishing dashboard view provided by Okta Threat Intelligence.",{"url":25509,"width":25510,"height":25511},"https://images.ctfassets.net/y1cdw1ablpvd/3IvcYr8sCMsCbhnzG9OzJA/35e3bdcf6dcddb3c431600afe490fe7e/image5.png",1600,558,{"sys":25513,"__typename":1648,"title":25514,"caption":25514,"layoutMode":59,"file":25515},{"id":21423},"SSO panel examples in Entra and Okta.",{"url":25516,"width":1661,"height":25517},"https://images.ctfassets.net/y1cdw1ablpvd/31RIcvGgLz2fmHBYsZyEV5/4326e200aa8ba9879257c2f9b643cf08/image1.png",680,{"sys":25519,"__typename":1696,"content":25520,"name":25541,"title":59},{"id":21448},{"json":25521},{"data":25522,"content":25523,"nodeType":1640},{},[25524],{"data":25525,"content":25526,"nodeType":881},{},[25527,25530,25537],{"data":25528,"marks":25529,"value":21,"nodeType":867},{},[],{"data":25531,"content":25532,"nodeType":876},{"uri":5843},[25533],{"data":25534,"marks":25535,"value":25536,"nodeType":867},{},[],"Mandiant has reported",{"data":25538,"marks":25539,"value":25540,"nodeType":867},{},[]," how the attacker opportunistically pivots across accessible SaaS platforms (SharePoint, Salesforce, DocuSign, Slack), hunting for specific strings like “poc,” “confidential,” “salesforce,” and “vpn.” Notable tradecraft includes using ToogleBox Recall to delete MFA enrollment notifications from victims’ inboxes and leveraging PowerShell to bulk-download SharePoint content routed through commercial VPN services like Mullvad, Oxylabs, and NetNut. Check out their blog post for some example SaaS activity logs that can be used to investigate a potential compromise. ","SLH V2 insight box 1",{"sys":25543,"__typename":1671,"title":25544,"arcadeDemoUrl":25545,"playText":1674},{"id":21461},"SSO Exploitation Demo","https://demo.arcade.software/pwGUZuoRdTLzfbWGZUDJ?embed",{"sys":25547,"__typename":1696,"content":25548,"name":25570,"title":59},{"id":21577},{"json":25549},{"data":25550,"content":25551,"nodeType":1640},{},[25552],{"data":25553,"content":25554,"nodeType":881},{},[25555,25559,25566],{"data":25556,"marks":25557,"value":25558,"nodeType":867},{},[],"This even includes brand new techniques that have never been seen in the wild — such as ",{"data":25560,"content":25561,"nodeType":876},{"uri":2877},[25562],{"data":25563,"marks":25564,"value":1312,"nodeType":867},{},[25565],{"type":1040},{"data":25567,"marks":25568,"value":25569,"nodeType":867},{},[],", which we blocked the first time it was seen targeting our customers, before even realizing it was a new kind of attack.","SLH campaign insight box 2",{"sys":25572,"__typename":1648,"title":25573,"caption":25573,"layoutMode":59,"file":25574},{"id":21635},"Push blocks phishing pages using real-time, in-browser analysis — shutting the attack down before a compromise happens. ",{"url":25575,"width":1661,"height":25576},"https://images.ctfassets.net/y1cdw1ablpvd/6InFhVkJJOPhsojQoub04K/b43e32cfa0bdc423dc993e930ebe1ae2/image1.png",1125,{"sys":25578,"__typename":1648,"title":25579,"caption":25580,"layoutMode":59,"file":25581},{"id":15799},"Employee Verification Codes","Push provides a lightweight verification feature in every user’s browser — no additional apps or devices required.",{"url":25582,"width":25583,"height":25584},"https://images.ctfassets.net/y1cdw1ablpvd/41X6fkPJgqf14vO3O14TF3/e0cecdbdfaee1353f15ff77ecb6a55a8/Employee_verification_codes.png",2088,1240,{"items":25586},[],{},"Unpacking the latest SLH phishing campaign",{"items":25590},[25591,26407,27715],{"__typename":1742,"sys":25592,"content":25594,"title":26393,"synopsis":26394,"hashTags":59,"publishedDate":26395,"slug":26396,"tagsCollection":26397,"authorsCollection":26403},{"id":25593},"4jcVFrvGBtVXpKU3gDMaa2",{"json":25595},{"data":25596,"content":25597,"nodeType":1640},{},[25598,25616,25623,25629,25684,25691,25698,25701,25709,25716,25723,25774,25782,25789,25812,25819,25822,25830,25837,25844,25851,25858,25865,25872,25877,25885,25892,25911,25931,25934,25942,25949,25956,25963,25971,25990,25997,26002,26010,26030,26050,26163,26166,26174,26181,26188,26191,26199,26206,26213,26220,26287,26317,26320,26328,26334,26341,26348,26355,26381,26387],{"data":25599,"content":25600,"nodeType":881},{},[25601,25605,25612],{"data":25602,"marks":25603,"value":25604,"nodeType":867},{},[],"In December, the Push Security research team discovered and blocked a brand new attack technique that we coined ",{"data":25606,"content":25607,"nodeType":876},{"uri":1319},[25608],{"data":25609,"marks":25610,"value":1312,"nodeType":867},{},[25611],{"type":1040},{"data":25613,"marks":25614,"value":25615,"nodeType":867},{},[],". This technique merged ClickFix-style social engineering with OAuth consent phishing to hijack Microsoft accounts. ",{"data":25617,"content":25618,"nodeType":881},{},[25619],{"data":25620,"marks":25621,"value":25622,"nodeType":867},{},[],"We saw this attack running across a large network of compromised websites that attackers were injecting the malicious payload into, forming a large-scale campaign that was detected across multiple customer estates. ",{"data":25624,"content":25628,"nodeType":890},{"target":25625},{"sys":25626},{"id":25627,"type":887,"linkType":888},"603MWDqc9NsqkklIkfGNZN",[],{"data":25630,"content":25631,"nodeType":881},{},[25632,25636,25645,25649,25657,25660,25669,25672,25680],{"data":25633,"marks":25634,"value":25635,"nodeType":867},{},[],"ConsentFix got a pretty awesome response from the community in a very short space of time. Within days, ",{"data":25637,"content":25639,"nodeType":876},{"uri":25638},"https://www.youtube.com/watch?v=AAiiIY-Soak",[25640],{"data":25641,"marks":25642,"value":25644,"nodeType":867},{},[25643],{"type":1040},"John Hammond shared a new and improved version of the technique",{"data":25646,"marks":25647,"value":25648,"nodeType":867},{},[]," that he’d spun up in his own lab, while security researchers from ",{"data":25650,"content":25652,"nodeType":876},{"uri":25651},"https://medium.com/@nitashathakur/consentfix-poc-how-the-attack-works-end-to-end-4f8b656f977d",[25653],{"data":25654,"marks":25655,"value":15009,"nodeType":867},{},[25656],{"type":1040},{"data":25658,"marks":25659,"value":4006,"nodeType":867},{},[],{"data":25661,"content":25663,"nodeType":876},{"uri":25662},"https://www.glueckkanja.com/en/posts/2025-12-31-vulnerability-consentfix",[25664],{"data":25665,"marks":25666,"value":25668,"nodeType":867},{},[25667],{"type":1040},"Glueck Kanja",{"data":25670,"marks":25671,"value":15362,"nodeType":867},{},[],{"data":25673,"content":25674,"nodeType":876},{"uri":14110},[25675],{"data":25676,"marks":25677,"value":25679,"nodeType":867},{},[25678],{"type":1040},"other individual contributors",{"data":25681,"marks":25682,"value":25683,"nodeType":867},{},[]," all shared analysis and recommendations. ",{"data":25685,"content":25686,"nodeType":881},{},[25687],{"data":25688,"marks":25689,"value":25690,"nodeType":867},{},[],"In this blog, we’re sharing some new insights on the campaign, pulling together some of the top recommendations and resources shared across the community, and predicting what the future holds for this novel technique as it quickly enters the mainstream. ",{"data":25692,"content":25693,"nodeType":881},{},[25694],{"data":25695,"marks":25696,"value":25697,"nodeType":867},{},[],"First though, let’s quickly recap what ConsentFix is and how it works. ",{"data":25699,"content":25700,"nodeType":908},{},[],{"data":25702,"content":25703,"nodeType":918},{},[25704],{"data":25705,"marks":25706,"value":25708,"nodeType":867},{},[25707],{"type":916},"ConsentFix 101",{"data":25710,"content":25711,"nodeType":881},{},[25712],{"data":25713,"marks":25714,"value":25715,"nodeType":867},{},[],"ConsentFix is an attack technique that prompts the victim to share an OAuth authorization code with an attacker via a phishing page. The attacker then enters this code into a target application on their own device in order to complete the authorization handshake and take over the account. ",{"data":25717,"content":25718,"nodeType":881},{},[25719],{"data":25720,"marks":25721,"value":25722,"nodeType":867},{},[],"By hijacking OAuth, attackers can effectively bypass identity-layer controls like passwords and MFA — even phishing resistant authentication methods like passkeys have no impact on this attack, because it sidesteps the authentication process altogether. ",{"data":25724,"content":25725,"nodeType":881},{},[25726,25730,25738,25741,25748,25752,25759,25763,25771],{"data":25727,"marks":25728,"value":25729,"nodeType":867},{},[],"OAuth abuse attacks are not new. Techniques like ",{"data":25731,"content":25733,"nodeType":876},{"uri":25732},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/consent_phishing/description.md",[25734],{"data":25735,"marks":25736,"value":20604,"nodeType":867},{},[25737],{"type":1040},{"data":25739,"marks":25740,"value":2063,"nodeType":867},{},[],{"data":25742,"content":25743,"nodeType":876},{"uri":15982},[25744],{"data":25745,"marks":25746,"value":13838,"nodeType":867},{},[25747],{"type":1040},{"data":25749,"marks":25750,"value":25751,"nodeType":867},{},[]," have been around for some time. However, these mainly focus on connecting your primary workspace account (e.g. Microsoft, Google, etc.) to a fraudulent, attacker-controlled application. But this is becoming increasingly difficult in core enterprise cloud environments like Azure due to ",{"data":25753,"content":25754,"nodeType":876},{"uri":20622},[25755],{"data":25756,"marks":25757,"value":20628,"nodeType":867},{},[25758],{"type":1040},{"data":25760,"marks":25761,"value":25762,"nodeType":867},{},[],". That said, device code phishing still featured prominently in the recent ",{"data":25764,"content":25765,"nodeType":876},{"uri":3051},[25766],{"data":25767,"marks":25768,"value":25770,"nodeType":867},{},[25769],{"type":1040},"high-profile Salesforce attacks in 2025",{"data":25772,"marks":25773,"value":1947,"nodeType":867},{},[],{"data":25775,"content":25776,"nodeType":998},{},[25777],{"data":25778,"marks":25779,"value":25781,"nodeType":867},{},[25780],{"type":916},"What makes ConsentFix so dangerous?",{"data":25783,"content":25784,"nodeType":881},{},[25785],{"data":25786,"marks":25787,"value":25788,"nodeType":867},{},[],"Unlike typical OAuth attacks, the novel ConsentFix approach enabled the attacker to target different types of application to what they usually go after — with big implications for detection and response. In this case, the attacker:",{"data":25790,"content":25791,"nodeType":3126},{},[25792,25802],{"data":25793,"content":25794,"nodeType":3061},{},[25795],{"data":25796,"content":25797,"nodeType":881},{},[25798],{"data":25799,"marks":25800,"value":25801,"nodeType":867},{},[],"Specifically targeted first-party Microsoft apps that cannot be restricted in the same way as third-party applications, and are pre-consented in every tenant (meaning users can authenticate to them without admin approval). ",{"data":25803,"content":25804,"nodeType":3061},{},[25805],{"data":25806,"content":25807,"nodeType":881},{},[25808],{"data":25809,"marks":25810,"value":25811,"nodeType":867},{},[],"Leveraged legacy scopes that are outside the scope of default logging to evade detection, and targeted scopes with known Conditional Access policy exclusions.",{"data":25813,"content":25814,"nodeType":881},{},[25815],{"data":25816,"marks":25817,"value":25818,"nodeType":867},{},[],"This means that default controls you’d expect to block malicious OAuth grants don’t apply, you may not have logging enabled to detect it if it did happen to you, and to top it off, conditional access policy exclusions mean that many organizations’ expected controls don’t work as intended in this case. ",{"data":25820,"content":25821,"nodeType":908},{},[],{"data":25823,"content":25824,"nodeType":918},{},[25825],{"data":25826,"marks":25827,"value":25829,"nodeType":867},{},[25828],{"type":916},"ConsentFix campaign recap",{"data":25831,"content":25832,"nodeType":881},{},[25833],{"data":25834,"marks":25835,"value":25836,"nodeType":867},{},[],"Let’s quickly recap how the ConsentFix campaign was implemented. ",{"data":25838,"content":25839,"nodeType":881},{},[25840],{"data":25841,"marks":25842,"value":25843,"nodeType":867},{},[],"The victim is served a page which requires that they verify that they are human by pasting a URL into the phishing page.",{"data":25845,"content":25846,"nodeType":881},{},[25847],{"data":25848,"marks":25849,"value":25850,"nodeType":867},{},[],"Clicking the “Sign In” button opens a legitimate Microsoft login page. If the user is already logged in (which they likely are if working in their normal browser) their account information is already pre-populated and they won’t need to authenticate again. ",{"data":25852,"content":25853,"nodeType":881},{},[25854],{"data":25855,"marks":25856,"value":25857,"nodeType":867},{},[],"Selecting their account redirects them to a localhost URL containing an OAuth authorization code — this is what they then post into the original phishing page to complete the attack. ",{"data":25859,"content":25860,"nodeType":881},{},[25861],{"data":25862,"marks":25863,"value":25864,"nodeType":867},{},[],"Once the attacker gets the URL, they can exchange it for an access token or refresh token for the particular application being targeted — in this case, Azure CLI.",{"data":25866,"content":25867,"nodeType":881},{},[25868],{"data":25869,"marks":25870,"value":25871,"nodeType":867},{},[],"The TL;DR is that the attacker is manually completing an authorization flow that happens when a user logs into Azure CLI — a a command line client that provides you with the ability to easily manage your Azure AD / Entra ID environment. Except in this case, they’re taking the victim’s information to log in on the attacker’s device instead. ",{"data":25873,"content":25876,"nodeType":890},{"target":25874},{"sys":25875},{"id":20460,"type":887,"linkType":888},[],{"data":25878,"content":25879,"nodeType":998},{},[25880],{"data":25881,"marks":25882,"value":25884,"nodeType":867},{},[25883],{"type":916},"Latest campaign details",{"data":25886,"content":25887,"nodeType":881},{},[25888],{"data":25889,"marks":25890,"value":25891,"nodeType":867},{},[],"Since we shared our blog post, we’ve had a number of additional details come to light about the campaign, which we’ve continued to track. ",{"data":25893,"content":25894,"nodeType":881},{},[25895,25899,25907],{"data":25896,"marks":25897,"value":25898,"nodeType":867},{},[],"It appears to be linked to Russian state-affiliated APT29, as corroborated by threat researchers we’ve been collaborating with. This is consistent with the ",{"data":25900,"content":25901,"nodeType":876},{"uri":1319},[25902],{"data":25903,"marks":25904,"value":25906,"nodeType":867},{},[25905],{"type":1040},"stealthy tactics we observed",{"data":25908,"marks":25909,"value":25910,"nodeType":867},{},[],", which go far beyond the run-of-the-mill detection evasion techniques we see used in criminal phishing campaigns. ",{"data":25912,"content":25913,"nodeType":881},{},[25914,25918,25927],{"data":25915,"marks":25916,"value":25917,"nodeType":867},{},[],"It shares many similarities with, and appears to be an evolution of, ",{"data":25919,"content":25921,"nodeType":876},{"uri":25920},"https://www.volexity.com/blog/2025/12/04/dangerous-invitations-russian-threat-actor-spoofs-european-security-events-in-targeted-phishing-attacks/",[25922],{"data":25923,"marks":25924,"value":25926,"nodeType":867},{},[25925],{"type":1040},"this Russia-affiliated campaign identified by Volexity",{"data":25928,"marks":25929,"value":25930,"nodeType":867},{},[]," that featured a manual version of the attack — where they victim was social engineered via email into opening the Microsoft URL, copying the localhost response, and sending it back to the attacker via email. ",{"data":25932,"content":25933,"nodeType":908},{},[],{"data":25935,"content":25936,"nodeType":918},{},[25937],{"data":25938,"marks":25939,"value":25941,"nodeType":867},{},[25940],{"type":916},"Top contributions from the community",{"data":25943,"content":25944,"nodeType":881},{},[25945],{"data":25946,"marks":25947,"value":25948,"nodeType":867},{},[],"As we mentioned earlier, the community response to ConsentFix has been incredible. ",{"data":25950,"content":25951,"nodeType":881},{},[25952],{"data":25953,"marks":25954,"value":25955,"nodeType":867},{},[],"As ever, you get a lot of vendors covering the attack technique with “install our product” as the recommendation. This is to be expected, but it’s misleading when some of these vendors are pushing EDR products that would have absolutely no way of detecting or blocking the attack. ",{"data":25957,"content":25958,"nodeType":881},{},[25959],{"data":25960,"marks":25961,"value":25962,"nodeType":867},{},[],"But cutting through the marketing, a lot of really great resources and recommendations were shared. ",{"data":25964,"content":25965,"nodeType":998},{},[25966],{"data":25967,"marks":25968,"value":25970,"nodeType":867},{},[25969],{"type":916},"V2.0 released by John Hammond",{"data":25972,"content":25973,"nodeType":881},{},[25974,25978,25986],{"data":25975,"marks":25976,"value":25977,"nodeType":867},{},[],"Within days, John Hammond ",{"data":25979,"content":25980,"nodeType":876},{"uri":25638},[25981],{"data":25982,"marks":25983,"value":25985,"nodeType":867},{},[25984],{"type":1040},"posted about ConsentFix on his Youtube channel",{"data":25987,"marks":25988,"value":25989,"nodeType":867},{},[],", where he showed off a slick improvement on the ConsentFix implementation used by attackers. In his version, the URL containing the Microsoft authorization code was generated in a pop-up browser window that could simply be drag-and-dropped into the phishing page. ",{"data":25991,"content":25992,"nodeType":881},{},[25993],{"data":25994,"marks":25995,"value":25996,"nodeType":867},{},[],"This implementation is way smoother, making it much more likely that a victim would fall for it. And this took a matter of days… ",{"data":25998,"content":26001,"nodeType":890},{"target":25999},{"sys":26000},{"id":13768,"type":887,"linkType":888},[],{"data":26003,"content":26004,"nodeType":998},{},[26005],{"data":26006,"marks":26007,"value":26009,"nodeType":867},{},[26008],{"type":916},"Additional vulnerable first-party apps identified",{"data":26011,"content":26012,"nodeType":881},{},[26013,26017,26026],{"data":26014,"marks":26015,"value":26016,"nodeType":867},{},[],"Fabian Bader and Dirk-jan Mollema from Glueck Kanja have ",{"data":26018,"content":26020,"nodeType":876},{"uri":26019},"https://entrascopes.com/?bypass=true&authcodeFix=true",[26021],{"data":26022,"marks":26023,"value":26025,"nodeType":867},{},[26024],{"type":1040},"shared a great resource",{"data":26027,"marks":26028,"value":26029,"nodeType":867},{},[]," on wider first-party apps that are vulnerable to ConsentFix. ",{"data":26031,"content":26032,"nodeType":881},{},[26033,26037,26046],{"data":26034,"marks":26035,"value":26036,"nodeType":867},{},[],"In total, there are 11 apps vulnerable to ConsentFix that also have known ",{"data":26038,"content":26040,"nodeType":876},{"uri":26039},"https://cloudbrothers.info/conditional-access-bypasses/#documented-bypasses",[26041],{"data":26042,"marks":26043,"value":26045,"nodeType":867},{},[26044],{"type":1040},"Conditional Access exclusions",{"data":26047,"marks":26048,"value":26049,"nodeType":867},{},[]," (either for the app generally, or when specific scopes are requested for the app):",{"data":26051,"content":26052,"nodeType":3126},{},[26053,26063,26073,26083,26093,26103,26113,26123,26133,26143,26153],{"data":26054,"content":26055,"nodeType":3061},{},[26056],{"data":26057,"content":26058,"nodeType":881},{},[26059],{"data":26060,"marks":26061,"value":26062,"nodeType":867},{},[],"Microsoft Azure CLI: 04b07795-8ddb-461a-bbee-02f9e1bf7b46",{"data":26064,"content":26065,"nodeType":3061},{},[26066],{"data":26067,"content":26068,"nodeType":881},{},[26069],{"data":26070,"marks":26071,"value":26072,"nodeType":867},{},[],"Microsoft Azure PowerShell: 1950a258-227b-4e31-a9cf-717495945fc2",{"data":26074,"content":26075,"nodeType":3061},{},[26076],{"data":26077,"content":26078,"nodeType":881},{},[26079],{"data":26080,"marks":26081,"value":26082,"nodeType":867},{},[],"Microsoft Teams: 1fec8e78-bce4-4aaf-ab1b-5451cc387264",{"data":26084,"content":26085,"nodeType":3061},{},[26086],{"data":26087,"content":26088,"nodeType":881},{},[26089],{"data":26090,"marks":26091,"value":26092,"nodeType":867},{},[],"Microsoft Whiteboard Client: 57336123-6e14-4acc-8dcf-287b6088aa28",{"data":26094,"content":26095,"nodeType":3061},{},[26096],{"data":26097,"content":26098,"nodeType":881},{},[26099],{"data":26100,"marks":26101,"value":26102,"nodeType":867},{},[],"Microsoft Flow Mobile PROD-GCCH-CN: 57fcbcfa-7cee-4eb1-8b25-12d2030b4ee0",{"data":26104,"content":26105,"nodeType":3061},{},[26106],{"data":26107,"content":26108,"nodeType":881},{},[26109],{"data":26110,"marks":26111,"value":26112,"nodeType":867},{},[],"Enterprise Roaming and Backup: 60c8bde5-3167-4f92-8fdb-059f6176dc0",{"data":26114,"content":26115,"nodeType":3061},{},[26116],{"data":26117,"content":26118,"nodeType":881},{},[26119],{"data":26120,"marks":26121,"value":26122,"nodeType":867},{},[],"Visual Studio: 872cd9fa-d31f-45e0-9eab-6e460a02d1f1",{"data":26124,"content":26125,"nodeType":3061},{},[26126],{"data":26127,"content":26128,"nodeType":881},{},[26129],{"data":26130,"marks":26131,"value":26132,"nodeType":867},{},[],"Aadrm Admin Powershell: 90f610bf-206d-4950-b61d-37fa6fd1b224",{"data":26134,"content":26135,"nodeType":3061},{},[26136],{"data":26137,"content":26138,"nodeType":881},{},[26139],{"data":26140,"marks":26141,"value":26142,"nodeType":867},{},[],"Microsoft SharePoint Online Management Shell: 9bc3ab49-b65d-410a-85ad-de819febfddc",{"data":26144,"content":26145,"nodeType":3061},{},[26146],{"data":26147,"content":26148,"nodeType":881},{},[26149],{"data":26150,"marks":26151,"value":26152,"nodeType":867},{},[],"Microsoft Power Query for Excel: a672d62c-fc7b-4e81-a576-e60dc46e951d",{"data":26154,"content":26155,"nodeType":3061},{},[26156],{"data":26157,"content":26158,"nodeType":881},{},[26159],{"data":26160,"marks":26161,"value":26162,"nodeType":867},{},[],"Visual Studio Code: aebc6443-996d-45c2-90f0-388ff96faa56",{"data":26164,"content":26165,"nodeType":908},{},[],{"data":26167,"content":26168,"nodeType":918},{},[26169],{"data":26170,"marks":26171,"value":26173,"nodeType":867},{},[26172],{"type":916},"Predictions for ConsentFix",{"data":26175,"content":26176,"nodeType":881},{},[26177],{"data":26178,"marks":26179,"value":26180,"nodeType":867},{},[],"Based on the speed at which new iterations on the ConsentFix technique were shared by security researchers, and the breadth of apps and possible scopes that can be leveraged, both red teams and criminals will inevitably adopt ConsentFix into their arsenal of TTPs in the near future. It is likely that new ConsentFix variants will emerge imminently (if not already in circulation). ",{"data":26182,"content":26183,"nodeType":881},{},[26184],{"data":26185,"marks":26186,"value":26187,"nodeType":867},{},[],"All security teams responsible for protecting Microsoft environments should ensure that monitoring controls and mitigations are put in place as a matter of high priority. ",{"data":26189,"content":26190,"nodeType":908},{},[],{"data":26192,"content":26193,"nodeType":918},{},[26194],{"data":26195,"marks":26196,"value":26198,"nodeType":867},{},[26197],{"type":916},"Updated recommendations for security teams",{"data":26200,"content":26201,"nodeType":881},{},[26202],{"data":26203,"marks":26204,"value":26205,"nodeType":867},{},[],"As an entirely browser-native attack technique, many traditional security tools and data sources are of limited use when it comes to detecting or pre-emptively blocking this attack. At the same time, the attack exploits default Microsoft security configs to evade both prevention and detection controls.",{"data":26207,"content":26208,"nodeType":881},{},[26209],{"data":26210,"marks":26211,"value":26212,"nodeType":867},{},[],"To be able to tackle modern attacks like ConsentFix that occur entirely within the browser context, it is vital that organizations look to monitor the browser as a detection surface, hunt for signs of malicious activity, and block attacks in real-time — in the same way that you would expect EDR to work for endpoint attacks. ",{"data":26214,"content":26215,"nodeType":881},{},[26216],{"data":26217,"marks":26218,"value":26219,"nodeType":867},{},[],"For organizations relying on Microsoft logging as the sole line of defense against this attack, there are some new recommendations to add to the list thanks to the community response: ",{"data":26221,"content":26222,"nodeType":3126},{},[26223,26246,26256,26277],{"data":26224,"content":26225,"nodeType":3061},{},[26226],{"data":26227,"content":26228,"nodeType":881},{},[26229,26233,26242],{"data":26230,"marks":26231,"value":26232,"nodeType":867},{},[],"Ensure that logging for the deprecated ",{"data":26234,"content":26236,"nodeType":876},{"uri":26235},"https://learn.microsoft.com/en-us/azure/azure-monitor/reference/tables/aadgraphactivitylogs",[26237],{"data":26238,"marks":26239,"value":26241,"nodeType":867},{},[26240],{"type":1040},"AADGraphActivityLogs",{"data":26243,"marks":26244,"value":26245,"nodeType":867},{},[]," is enabled.",{"data":26247,"content":26248,"nodeType":3061},{},[26249],{"data":26250,"content":26251,"nodeType":881},{},[26252],{"data":26253,"marks":26254,"value":26255,"nodeType":867},{},[],"Hunt in logs for the Application IDs highlighted above, along with the Resource IDs for Windows Azure Active Directory (00000002-0000-0000-c000-000000000000) and Microsoft Intune Checkin (26a4ae64-5862-427f-a9b0-044e62572a4f)",{"data":26257,"content":26258,"nodeType":3061},{},[26259],{"data":26260,"content":26261,"nodeType":881},{},[26262,26265,26273],{"data":26263,"marks":26264,"value":21,"nodeType":867},{},[],{"data":26266,"content":26267,"nodeType":876},{"uri":14110},[26268],{"data":26269,"marks":26270,"value":26272,"nodeType":867},{},[26271],{"type":1040},"Create Service Principals for each of the vulnerable apps and restrict the users that are authorized to access them",{"data":26274,"marks":26275,"value":26276,"nodeType":867},{},[]," to reduce the attack surface of users that can be phished with this method.",{"data":26278,"content":26279,"nodeType":3061},{},[26280],{"data":26281,"content":26282,"nodeType":881},{},[26283],{"data":26284,"marks":26285,"value":26286,"nodeType":867},{},[],"Block access to CLI tools via Conditional Access policy and issue exclusions for authorized users/groups. ",{"data":26288,"content":26289,"nodeType":881},{},[26290,26294,26303,26307,26314],{"data":26291,"marks":26292,"value":26293,"nodeType":867},{},[],"Additional resources that may be of use include community-created ",{"data":26295,"content":26297,"nodeType":876},{"uri":26296},"https://github.com/elastic/detection-rules/pull/5485",[26298],{"data":26299,"marks":26300,"value":26302,"nodeType":867},{},[26301],{"type":1040},"Elastic detection rules",{"data":26304,"marks":26305,"value":26306,"nodeType":867},{},[]," for ConsentFix and further mitigation and hunting guidance from ",{"data":26308,"content":26309,"nodeType":876},{"uri":25662},[26310],{"data":26311,"marks":26312,"value":25668,"nodeType":867},{},[26313],{"type":1040},{"data":26315,"marks":26316,"value":10110,"nodeType":867},{},[],{"data":26318,"content":26319,"nodeType":908},{},[],{"data":26321,"content":26322,"nodeType":918},{},[26323],{"data":26324,"marks":26325,"value":26327,"nodeType":867},{},[26326],{"type":916},"Learn more about Push Security",{"data":26329,"content":26330,"nodeType":881},{},[26331],{"data":26332,"marks":26333,"value":21033,"nodeType":867},{},[],{"data":26335,"content":26336,"nodeType":881},{},[26337],{"data":26338,"marks":26339,"value":26340,"nodeType":867},{},[],"Push tackles browser-based attacks using behavioral threat detection controls, powered by deep browser telemetry, to provide broad detection and blocking capabilities against attacks happening in the browser. This means analyzing the end-to-end process of a webpage loading/running in the browser, and how the user interacts with the page, to spot universal indicators of bad activity. ",{"data":26342,"content":26343,"nodeType":881},{},[26344],{"data":26345,"marks":26346,"value":26347,"nodeType":867},{},[],"This is the only reliable way to detect malicious websites in a world where IoC-based detections are trivial for attackers to get around. Rather than playing known-bad whac-a-mole, Push detects and blocks even zero-day browser threats in real time.",{"data":26349,"content":26350,"nodeType":881},{},[26351],{"data":26352,"marks":26353,"value":26354,"nodeType":867},{},[],"Push stops browser-based attacks like AiTM phishing, credential stuffing, malicious browser extensions, ClickFix, ConsentFix, and session hijacking. You don’t need to wait until it all goes wrong either — you can also use Push to proactively find and fix vulnerabilities across the apps that your employees use, like ghost logins, SSO coverage gaps, MFA gaps, vulnerable passwords, and more to harden your identity attack surface.",{"data":26356,"content":26357,"nodeType":881},{},[26358,26361,26368,26371,26378],{"data":26359,"marks":26360,"value":10795,"nodeType":867},{},[],{"data":26362,"content":26363,"nodeType":876},{"uri":10798},[26364],{"data":26365,"marks":26366,"value":10803,"nodeType":867},{},[26367],{"type":1040},{"data":26369,"marks":26370,"value":15213,"nodeType":867},{},[],{"data":26372,"content":26373,"nodeType":876},{"uri":1629},[26374],{"data":26375,"marks":26376,"value":10826,"nodeType":867},{},[26377],{"type":1040},{"data":26379,"marks":26380,"value":1947,"nodeType":867},{},[],{"data":26382,"content":26386,"nodeType":890},{"target":26383},{"sys":26384},{"id":26385,"type":887,"linkType":888},"4D7zpYAc1tTEAmn2hpkWPe",[],{"data":26388,"content":26389,"nodeType":881},{},[26390],{"data":26391,"marks":26392,"value":21,"nodeType":867},{},[],"ConsentFix debrief: latest community insights, recommendations, and predictions","New insights on the ConsentFix campaign stopped by Push.","2026-01-14T00:00:00.000Z","consentfix-debrief",{"items":26398},[26399,26401],{"sys":26400,"name":342},{"id":2550},{"sys":26402,"name":2547},{"id":2546},{"items":26404},[26405],{"fullName":849,"firstName":850,"jobTitle":851,"profilePicture":26406},{"url":855},{"__typename":1742,"sys":26408,"content":26410,"title":27701,"synopsis":27702,"hashTags":59,"publishedDate":27703,"slug":27704,"tagsCollection":27705,"authorsCollection":27711},{"id":26409},"37KWV8V5L3aNZBSx6JMd0Z",{"json":26411},{"data":26412,"content":26413,"nodeType":1640},{},[26414,26421,26428,26489,26496,26565,26571,26578,26585,26588,26595,26602,26609,26711,26730,26737,26779,26786,26793,26800,26833,26839,26871,26877,26884,26891,26924,26944,26947,26954,26960,26991,26998,27005,27012,27018,27025,27031,27046,27089,27095,27115,27118,27125,27131,27151,27158,27187,27207,27213,27234,27241,27248,27308,27315,27321,27336,27350,27371,27377,27398,27405,27408,27415,27421,27428,27435,27456,27462,27483,27489,27496,27529,27547,27550,27557,27563,27570,27590,27596,27611,27617,27624,27631,27650,27653,27659,27666,27673],{"data":26415,"content":26416,"nodeType":881},{},[26417],{"data":26418,"marks":26419,"value":26420,"nodeType":867},{},[],"Looking back over the year’s headlines and trending TTPs, it’s clear that 2025 was the year that browser-based account takeover techniques made the leap into the mainstream.",{"data":26422,"content":26423,"nodeType":881},{},[26424],{"data":26425,"marks":26426,"value":26427,"nodeType":867},{},[],"A few stats tell the story …",{"data":26429,"content":26430,"nodeType":3126},{},[26431,26450,26469],{"data":26432,"content":26433,"nodeType":3061},{},[26434],{"data":26435,"content":26436,"nodeType":881},{},[26437,26441,26447],{"data":26438,"marks":26439,"value":26440,"nodeType":867},{},[],"Identity-based attacks surged by 32% over the last year, and 97% of identity attacks were password-based, driven by a combination of credential leaks and infostealer malware. (",{"data":26442,"content":26443,"nodeType":876},{"uri":15003},[26444],{"data":26445,"marks":26446,"value":15009,"nodeType":867},{},[],{"data":26448,"marks":26449,"value":15013,"nodeType":867},{},[],{"data":26451,"content":26452,"nodeType":3061},{},[26453],{"data":26454,"content":26455,"nodeType":881},{},[26456,26460,26466],{"data":26457,"marks":26458,"value":26459,"nodeType":867},{},[],"ClickFix was the most common initial point of access for adversaries in the past year, accounting for a whopping 47% of observed attacks. (",{"data":26461,"content":26462,"nodeType":876},{"uri":15003},[26463],{"data":26464,"marks":26465,"value":15009,"nodeType":867},{},[],{"data":26467,"marks":26468,"value":15013,"nodeType":867},{},[],{"data":26470,"content":26471,"nodeType":3061},{},[26472],{"data":26473,"content":26474,"nodeType":881},{},[26475,26479,26486],{"data":26476,"marks":26477,"value":26478,"nodeType":867},{},[],"Pure malware-based attacks declined, as adversaries continued to shift from targeting endpoints to corporate identities. In the last year-plus, 79% of detections were malware-free, up from 40% in 2019. And abuse of valid accounts was responsible for more than one-third of all cloud-related incidents. (",{"data":26480,"content":26481,"nodeType":876},{"uri":15026},[26482],{"data":26483,"marks":26484,"value":26485,"nodeType":867},{},[],"Crowdstrike",{"data":26487,"marks":26488,"value":15013,"nodeType":867},{},[],{"data":26490,"content":26491,"nodeType":881},{},[26492],{"data":26493,"marks":26494,"value":26495,"nodeType":867},{},[],"… and so do the headlines from 2025:",{"data":26497,"content":26498,"nodeType":3126},{},[26499,26518,26546],{"data":26500,"content":26501,"nodeType":3061},{},[26502],{"data":26503,"content":26504,"nodeType":881},{},[26505,26509,26514],{"data":26506,"marks":26507,"value":26508,"nodeType":867},{},[],"Attackers stole over ",{"data":26510,"marks":26511,"value":26513,"nodeType":867},{},[26512],{"type":916},"1.5 billion records",{"data":26515,"marks":26516,"value":26517,"nodeType":867},{},[]," from an estimated 1,000+ Salesforce tenants by exploiting integrations (Salesloft, Gainsight), phishing credentials, and by tricking users into installing a malicious OAuth app.",{"data":26519,"content":26520,"nodeType":3061},{},[26521],{"data":26522,"content":26523,"nodeType":881},{},[26524,26528,26533,26537,26542],{"data":26525,"marks":26526,"value":26527,"nodeType":867},{},[],"Marks & Spencer was hit with a help desk scam that led to a compromised Microsoft Entra account, followed by a ransomware deployment resulting in months of disruption, ",{"data":26529,"marks":26530,"value":26532,"nodeType":867},{},[26531],{"type":916},"$400M",{"data":26534,"marks":26535,"value":26536,"nodeType":867},{},[]," in lost profits, and around ",{"data":26538,"marks":26539,"value":26541,"nodeType":867},{},[26540],{"type":916},"$1.3B",{"data":26543,"marks":26544,"value":26545,"nodeType":867},{},[]," wiped off their stock market valuation at one stage.",{"data":26547,"content":26548,"nodeType":3061},{},[26549],{"data":26550,"content":26551,"nodeType":881},{},[26552,26556,26561],{"data":26553,"marks":26554,"value":26555,"nodeType":867},{},[],"Jaguar Land Rover was compromised via highly privileged admin accounts — another help desk scam targeting workforce credentials for initial access — resulting in months of disruption that led the UK government to underwrite a ",{"data":26557,"marks":26558,"value":26560,"nodeType":867},{},[26559],{"type":916},"$1.5B",{"data":26562,"marks":26563,"value":26564,"nodeType":867},{},[]," loan to alleviate the supply chain impact. This was the most economically consequential cyber attack yet recorded in a G7 economy.",{"data":26566,"content":26570,"nodeType":890},{"target":26567},{"sys":26568},{"id":26569,"type":887,"linkType":888},"v5YYnjP2NViOh6Ucxp2Fe",[],{"data":26572,"content":26573,"nodeType":881},{},[26574],{"data":26575,"marks":26576,"value":26577,"nodeType":867},{},[],"At Push, we’ve been closely tracking the evolution of browser-based attacks. Looking back at 2025, we’ve seen a notable increase in the sophistication and frequency of modern attack techniques methods like ClickFix, commodified phish kits that bypass MFA, malicious browser extensions, and many more. (Writing phish kit teardowns for the Push blog is practically a full-time job now.)",{"data":26579,"content":26580,"nodeType":881},{},[26581],{"data":26582,"marks":26583,"value":26584,"nodeType":867},{},[],"In this article, we’ll take a look at how real-world attacks and our own research drove the features we delivered for Push customers this year to take the fight to adversaries.",{"data":26586,"content":26587,"nodeType":908},{},[],{"data":26589,"content":26590,"nodeType":918},{},[26591],{"data":26592,"marks":26593,"value":26594,"nodeType":867},{},[],"Detecting and blocking increasingly sophisticated phishing-as-a-service tools",{"data":26596,"content":26597,"nodeType":998},{},[26598],{"data":26599,"marks":26600,"value":26601,"nodeType":867},{},[],"What happened",{"data":26603,"content":26604,"nodeType":881},{},[26605],{"data":26606,"marks":26607,"value":26608,"nodeType":867},{},[],"The current state of the art for phishing centers on three core developments:",{"data":26610,"content":26611,"nodeType":3126},{},[26612,26641,26682],{"data":26613,"content":26614,"nodeType":3061},{},[26615],{"data":26616,"content":26617,"nodeType":881},{},[26618,26623,26627,26637],{"data":26619,"marks":26620,"value":26622,"nodeType":867},{},[26621],{"type":916},"Detection evasion: ",{"data":26624,"marks":26625,"value":26626,"nodeType":867},{},[],"Adversaries demonstrated a ",{"data":26628,"content":26632,"nodeType":3447},{"target":26629},{"sys":26630},{"id":26631,"type":887,"linkType":888},"4XZ6qCr8pjJvcD7hi09x2Y",[26633],{"data":26634,"marks":26635,"value":26636,"nodeType":867},{},[],"creative array of approaches",{"data":26638,"marks":26639,"value":26640,"nodeType":867},{},[]," this year to hide their intentions from end-users and defenders, using methods such as sending phishing emails from legitimate services; serving phishing pages via malvertising and SEO poisoning; and obfuscating URLs. More sophisticated techniques used page-level obfuscation, cross-domain iframes, single-use links, and legitimate OIDC logins to evade detection and analysis from traditional tools.",{"data":26642,"content":26643,"nodeType":3061},{},[26644],{"data":26645,"content":26646,"nodeType":881},{},[26647,26652,26656,26665,26669,26679],{"data":26648,"marks":26649,"value":26651,"nodeType":867},{},[26650],{"type":916},"Multi-channel delivery of lures:",{"data":26653,"marks":26654,"value":26655,"nodeType":867},{},[]," Adversaries proved the truism of “phishing doesn’t just happen in the mailbox” this year by increasing their observed use of ",{"data":26657,"content":26661,"nodeType":3447},{"target":26658},{"sys":26659},{"id":26660,"type":887,"linkType":888},"72lLmy0CXnOp3LWOdcUguX",[26662],{"data":26663,"marks":26664,"value":441,"nodeType":867},{},[],{"data":26666,"marks":26667,"value":26668,"nodeType":867},{},[]," and SEO poisoning — techniques that place malicious pages within trusted contexts like the Google search engine results page — as well as the use of social media services like LinkedIn to ",{"data":26670,"content":26674,"nodeType":3447},{"target":26671},{"sys":26672},{"id":26673,"type":887,"linkType":888},"2yEhB2gFC2TJDLquVP3cg2",[26675],{"data":26676,"marks":26677,"value":26678,"nodeType":867},{},[],"deliver phishing lures",{"data":26680,"marks":26681,"value":1253,"nodeType":867},{},[],{"data":26683,"content":26684,"nodeType":3061},{},[26685],{"data":26686,"content":26687,"nodeType":881},{},[26688,26693,26697,26707],{"data":26689,"marks":26690,"value":26692,"nodeType":867},{},[26691],{"type":916},"Commodification of phishing toolkits:",{"data":26694,"marks":26695,"value":26696,"nodeType":867},{},[]," Phishing-as-a-service (PhaaS) kits have become another SaaS with their own supply chain, including developers of malicious tooling, operators who run the campaigns, and brokers who sell stolen credentials and tokens. The incentives for attackers are clear: quick ROI from targeting workforce identities, and out-of-the-box tools that make it easier to efficiently spin up new campaigns or try new techniques. As with any SaaS offering, the customer (attackers, in this case) benefits from rapid innovations they didn’t have to build. We saw this recently with the ",{"data":26698,"content":26702,"nodeType":3447},{"target":26699},{"sys":26700},{"id":26701,"type":887,"linkType":888},"6QLonRmBzbj9h88Y7jD0LU",[26703],{"data":26704,"marks":26705,"value":26706,"nodeType":867},{},[],"addition of a browser-in-the-browser (BitB) technique",{"data":26708,"marks":26709,"value":26710,"nodeType":867},{},[]," to the phish kit Sneaky2FA — a change that makes it even more effective.",{"data":26712,"content":26713,"nodeType":881},{},[26714,26718,26726],{"data":26715,"marks":26716,"value":26717,"nodeType":867},{},[],"In 2025, Push researchers tracked how each of these developments expanded in scope and sophistication. Check out our ",{"data":26719,"content":26721,"nodeType":876},{"uri":26720},"https://pushsecurity.github.io/phishing-techniques/",[26722],{"data":26723,"marks":26724,"value":26725,"nodeType":867},{},[],"phishing detection evasion techniques matrix",{"data":26727,"marks":26728,"value":26729,"nodeType":867},{},[]," on Github for more detail. ",{"data":26731,"content":26732,"nodeType":881},{},[26733],{"data":26734,"marks":26735,"value":26736,"nodeType":867},{},[],"The takeaways for security teams?",{"data":26738,"content":26739,"nodeType":3126},{},[26740,26750,26769],{"data":26741,"content":26742,"nodeType":3061},{},[26743],{"data":26744,"content":26745,"nodeType":881},{},[26746],{"data":26747,"marks":26748,"value":26749,"nodeType":867},{},[],"You can’t block your way to safety when adversaries are using the same legitimate apps that your employees use.",{"data":26751,"content":26752,"nodeType":3061},{},[26753],{"data":26754,"content":26755,"nodeType":881},{},[26756,26760,26765],{"data":26757,"marks":26758,"value":26759,"nodeType":867},{},[],"Similarly, while end-user training is important, it’s not reasonable to expect employees to know when a SharePoint document link is malicious when it looks identical to the ones they trust every day — because adversaries ",{"data":26761,"marks":26762,"value":26764,"nodeType":867},{},[26763],{"type":1431},"are using the legitimate service",{"data":26766,"marks":26767,"value":26768,"nodeType":867},{},[],". Push researchers have observed the abuse of hundreds of legitimate services in phishing attacks this year.",{"data":26770,"content":26771,"nodeType":3061},{},[26772],{"data":26773,"content":26774,"nodeType":881},{},[26775],{"data":26776,"marks":26777,"value":26778,"nodeType":867},{},[],"Security solutions need to be able to analyze real-time context and behavior, not rely solely on inferences from secondary characteristics like domain reputation.",{"data":26780,"content":26781,"nodeType":881},{},[26782],{"data":26783,"marks":26784,"value":26785,"nodeType":867},{},[],"Here's what we built to help defend organizations.",{"data":26787,"content":26788,"nodeType":998},{},[26789],{"data":26790,"marks":26791,"value":26792,"nodeType":867},{},[],"What we built",{"data":26794,"content":26795,"nodeType":881},{},[26796],{"data":26797,"marks":26798,"value":26799,"nodeType":867},{},[],"The feature we built in 2025 that gave us unique insight into these TTPs is Push’s Detections capability. With Detections, you can:",{"data":26801,"content":26802,"nodeType":3126},{},[26803,26813,26823],{"data":26804,"content":26805,"nodeType":3061},{},[26806],{"data":26807,"content":26808,"nodeType":881},{},[26809],{"data":26810,"marks":26811,"value":26812,"nodeType":867},{},[],"Get alerted when Push detects a browser-based attack, and see how the Push agent responded to block the attack. The platform provides a front-end view for quick triage, and you can also pipe the detection events to your SIEM or other platform of choice.",{"data":26814,"content":26815,"nodeType":3061},{},[26816],{"data":26817,"content":26818,"nodeType":881},{},[26819],{"data":26820,"marks":26821,"value":26822,"nodeType":867},{},[],"Review a timeline of the incident: Where a phishing link originated; whether a user entered their credentials; what kind of phishkit was detected; and how Push responded (configurable based on your environment).",{"data":26824,"content":26825,"nodeType":3061},{},[26826],{"data":26827,"content":26828,"nodeType":881},{},[26829],{"data":26830,"marks":26831,"value":26832,"nodeType":867},{},[],"Get actionable telemetry and metadata about an incident, including a screenshot of the malicious page to see exactly what the user saw; intel about the involved domains, including when they were registered and if they’ve been scanned by urlscan before; and the blast radius of an attack, including other apps that shared a password with the potentially compromised account",{"data":26834,"content":26838,"nodeType":890},{"target":26835},{"sys":26836},{"id":26837,"type":887,"linkType":888},"5dygPaG3Gfw4Yeicffv6tV",[],{"data":26840,"content":26841,"nodeType":881},{},[26842,26846,26851,26854,26859,26862,26867],{"data":26843,"marks":26844,"value":26845,"nodeType":867},{},[],"This telemetry — combined with Push’s out-of-the-box controls like ",{"data":26847,"marks":26848,"value":26850,"nodeType":867},{},[26849],{"type":916},"Phishing tool detection",{"data":26852,"marks":26853,"value":4006,"nodeType":867},{},[],{"data":26855,"marks":26856,"value":26858,"nodeType":867},{},[26857],{"type":916},"Cloned login page detection",{"data":26860,"marks":26861,"value":15362,"nodeType":867},{},[],{"data":26863,"marks":26864,"value":26866,"nodeType":867},{},[26865],{"type":916},"Malicious copy and paste detection",{"data":26868,"marks":26869,"value":26870,"nodeType":867},{},[]," (aka ClickFix detection) — give you a seat on the user’s side of the equation, capturing real-time information about what users did and the TTPs of an attack so you can investigate and respond efficiently and confidently.",{"data":26872,"content":26876,"nodeType":890},{"target":26873},{"sys":26874},{"id":26875,"type":887,"linkType":888},"563fJFSgoLDOwSXSQ9Y0MM",[],{"data":26878,"content":26879,"nodeType":881},{},[26880],{"data":26881,"marks":26882,"value":26883,"nodeType":867},{},[],"With the visibility provided by this telemetry across Push’s install base, our R&D and Product teams have rapidly iterated all year on our detections to increase coverage and respond quickly to newly identified attack types.",{"data":26885,"content":26886,"nodeType":881},{},[26887],{"data":26888,"marks":26889,"value":26890,"nodeType":867},{},[],"This year, we also released:",{"data":26892,"content":26893,"nodeType":3126},{},[26894,26904,26914],{"data":26895,"content":26896,"nodeType":3061},{},[26897],{"data":26898,"content":26899,"nodeType":881},{},[26900],{"data":26901,"marks":26902,"value":26903,"nodeType":867},{},[],"Detections for new variants of cloned login pages and AiTM phish kits.",{"data":26905,"content":26906,"nodeType":3061},{},[26907],{"data":26908,"content":26909,"nodeType":881},{},[26910],{"data":26911,"marks":26912,"value":26913,"nodeType":867},{},[],"12+ pre-release detections focused on flagging emerging attacker techniques.",{"data":26915,"content":26916,"nodeType":3061},{},[26917],{"data":26918,"content":26919,"nodeType":881},{},[26920],{"data":26921,"marks":26922,"value":26923,"nodeType":867},{},[],"7+ first-class SIEM and SOAR integrations, to make it simpler to ingest Push telemetry and operationalize it.",{"data":26925,"content":26926,"nodeType":881},{},[26927,26931,26941],{"data":26928,"marks":26929,"value":26930,"nodeType":867},{},[],"Learn more about Push’s detections features in our ",{"data":26932,"content":26936,"nodeType":3447},{"target":26933},{"sys":26934},{"id":26935,"type":887,"linkType":888},"6OFdfAsoPUECeRAetWvedp",[26937],{"data":26938,"marks":26939,"value":26940,"nodeType":867},{},[],"blog article",{"data":26942,"marks":26943,"value":1947,"nodeType":867},{},[],{"data":26945,"content":26946,"nodeType":908},{},[],{"data":26948,"content":26949,"nodeType":918},{},[26950],{"data":26951,"marks":26952,"value":26953,"nodeType":867},{},[],"Detecting and blocking ClickFix-style malicious copy and paste attacks",{"data":26955,"content":26956,"nodeType":998},{},[26957],{"data":26958,"marks":26959,"value":26601,"nodeType":867},{},[],{"data":26961,"content":26962,"nodeType":881},{},[26963,26967,26975,26979,26987],{"data":26964,"marks":26965,"value":26966,"nodeType":867},{},[],"ClickFix-style attacks left their mark in 2025, quickly becoming one of the most prevalent attack techniques — with ",{"data":26968,"content":26970,"nodeType":876},{"uri":26969},"https://www.scworld.com/news/clickfix-phishing-links-increased-nearly-400-in-12-months-report-says",[26971],{"data":26972,"marks":26973,"value":26974,"nodeType":867},{},[],"estimates",{"data":26976,"marks":26977,"value":26978,"nodeType":867},{},[]," of a 400 percent year-over-year increase, and another ",{"data":26980,"content":26982,"nodeType":876},{"uri":26981},"https://web-assets.esetstatic.com/wls/en/papers/threat-reports/eset-threat-report-h12025.pdf",[26983],{"data":26984,"marks":26985,"value":26986,"nodeType":867},{},[],"report",{"data":26988,"marks":26989,"value":26990,"nodeType":867},{},[]," documenting a 517 percent growth in just the last 6 months of the year.",{"data":26992,"content":26993,"nodeType":881},{},[26994],{"data":26995,"marks":26996,"value":26997,"nodeType":867},{},[],"What is ClickFix? This attack technique prompts the user to solve some kind of problem or troubleshooting step in the browser — often presented as a CAPTCHA challenge. The key aspect of the attack is that it tricks users into running malicious commands on their device by copying malicious code from the page clipboard and running it locally. (The copy typically occurs  automatically via the page itself, but can also be performed manually by the user.)",{"data":26999,"content":27000,"nodeType":881},{},[27001],{"data":27002,"marks":27003,"value":27004,"nodeType":867},{},[],"These malicious copy and paste attacks are often used to deliver infostealer malware or remote access software, with the attacker’s end goal being stealing session cookies and credentials to facilitate attacks on business apps.",{"data":27006,"content":27007,"nodeType":881},{},[27008],{"data":27009,"marks":27010,"value":27011,"nodeType":867},{},[],"What’s especially challenging about this attack type is that it usually can only be detected after the fact — when a machine is already compromised, or malicious code attempts to execute (if EDR catches it). Even if it is detected, security teams are left flying blind when they try to determine the initial vector for the attack, and which other users might have been targeted.",{"data":27013,"content":27014,"nodeType":998},{},[27015],{"data":27016,"marks":27017,"value":26792,"nodeType":867},{},[],{"data":27019,"content":27020,"nodeType":881},{},[27021],{"data":27022,"marks":27023,"value":27024,"nodeType":867},{},[],"Because of our position in the browser, Push is uniquely positioned to detect and block browser-native attacks like ClickFix and other forms of malicious copy and paste techniques. So that’s what we built.",{"data":27026,"content":27030,"nodeType":890},{"target":27027},{"sys":27028},{"id":27029,"type":887,"linkType":888},"56jVT7dbNqUGiSRTfTCQw2",[],{"data":27032,"content":27033,"nodeType":881},{},[27034,27038,27042],{"data":27035,"marks":27036,"value":27037,"nodeType":867},{},[],"With our ",{"data":27039,"marks":27040,"value":26866,"nodeType":867},{},[27041],{"type":916},{"data":27043,"marks":27044,"value":27045,"nodeType":867},{},[],", you can:",{"data":27047,"content":27048,"nodeType":3126},{},[27049,27059,27069,27079],{"data":27050,"content":27051,"nodeType":3061},{},[27052],{"data":27053,"content":27054,"nodeType":881},{},[27055],{"data":27056,"marks":27057,"value":27058,"nodeType":867},{},[],"Detect ClickFix-style attacks as soon as they target end-users, regardless of the delivery channel for the lure, or the specifics of the malware type and execution.",{"data":27060,"content":27061,"nodeType":3061},{},[27062],{"data":27063,"content":27064,"nodeType":881},{},[27065],{"data":27066,"marks":27067,"value":27068,"nodeType":867},{},[],"Block these attacks before the malicious code is copied to the clipboard.",{"data":27070,"content":27071,"nodeType":3061},{},[27072],{"data":27073,"content":27074,"nodeType":881},{},[27075],{"data":27076,"marks":27077,"value":27078,"nodeType":867},{},[],"Safely collect the payload for further investigation by your security team, and replace the clipboard contents with safe text as part of the blocking action.",{"data":27080,"content":27081,"nodeType":3061},{},[27082],{"data":27083,"content":27084,"nodeType":881},{},[27085],{"data":27086,"marks":27087,"value":27088,"nodeType":867},{},[],"Capture a detailed timeline of events to see how users were targeted and how the attack unfolded.",{"data":27090,"content":27094,"nodeType":890},{"target":27091},{"sys":27092},{"id":27093,"type":887,"linkType":888},"sALkMt8UbTZ2f34hKvGLj",[],{"data":27096,"content":27097,"nodeType":881},{},[27098,27102,27112],{"data":27099,"marks":27100,"value":27101,"nodeType":867},{},[],"Learn more about ClickFix detection in our ",{"data":27103,"content":27107,"nodeType":3447},{"target":27104},{"sys":27105},{"id":27106,"type":887,"linkType":888},"7jygmadjoz0asAHv7e5PuK",[27108],{"data":27109,"marks":27110,"value":27111,"nodeType":867},{},[],"documentation",{"data":27113,"marks":27114,"value":1947,"nodeType":867},{},[],{"data":27116,"content":27117,"nodeType":908},{},[],{"data":27119,"content":27120,"nodeType":918},{},[27121],{"data":27122,"marks":27123,"value":27124,"nodeType":867},{},[],"Getting ahead of breaches tied to stolen credentials and ghost logins",{"data":27126,"content":27127,"nodeType":998},{},[27128],{"data":27129,"marks":27130,"value":26601,"nodeType":867},{},[],{"data":27132,"content":27133,"nodeType":881},{},[27134,27138,27148],{"data":27135,"marks":27136,"value":27137,"nodeType":867},{},[],"Starting in November 2024 and continuing through July 2025, adversaries linked to the HELLCAT threat group compromised Jira tenants belonging to 10 organizations using ",{"data":27139,"content":27143,"nodeType":3447},{"target":27140},{"sys":27141},{"id":27142,"type":887,"linkType":888},"gANCbeL9AnxmbGAE5HhyG",[27144],{"data":27145,"marks":27146,"value":27147,"nodeType":867},{},[],"stolen credentials",{"data":27149,"marks":27150,"value":1253,"nodeType":867},{},[],{"data":27152,"content":27153,"nodeType":881},{},[27154],{"data":27155,"marks":27156,"value":27157,"nodeType":867},{},[],"Business-critical applications like Jira are prime targets for attackers, who in this case dumped valuable data and then held it for ransom (or sold it on criminal marketplaces). Of course, this isn’t just a problem for Jira — data from Push’s initial deployment into customer environments shows that lots of critical apps lack basic controls like strong passwords and MFA.",{"data":27159,"content":27160,"nodeType":881},{},[27161,27165,27173,27177,27183],{"data":27162,"marks":27163,"value":27164,"nodeType":867},{},[],"The evolving threat group known as ",{"data":27166,"content":27169,"nodeType":3447},{"target":27167},{"sys":27168},{"id":14277,"type":887,"linkType":888},[27170],{"data":27171,"marks":27172,"value":3056,"nodeType":867},{},[],{"data":27174,"marks":27175,"value":27176,"nodeType":867},{},[]," has also embraced the use of stolen creds, session cookies, and unprotected local account logins — aka ",{"data":27178,"content":27179,"nodeType":876},{"uri":14589},[27180],{"data":27181,"marks":27182,"value":6850,"nodeType":867},{},[],{"data":27184,"marks":27185,"value":27186,"nodeType":867},{},[]," — to compromise large organizations.",{"data":27188,"content":27189,"nodeType":881},{},[27190,27194,27203],{"data":27191,"marks":27192,"value":27193,"nodeType":867},{},[],"In 2025, Red Hat’s GitLab instance was compromised due to a local account that essentially provided a backdoor to an otherwise secure and SSO-connected account — an attack reminiscent of the ",{"data":27195,"content":27199,"nodeType":3447},{"target":27196},{"sys":27197},{"id":27198,"type":887,"linkType":888},"PAPJPr3CIB6J20udYyy1r",[27200],{"data":27201,"marks":27202,"value":5757,"nodeType":867},{},[],{"data":27204,"marks":27205,"value":27206,"nodeType":867},{},[],", which targeted local logins that lacked MFA.",{"data":27208,"content":27209,"nodeType":998},{},[27210],{"data":27211,"marks":27212,"value":26792,"nodeType":867},{},[],{"data":27214,"content":27215,"nodeType":881},{},[27216,27220,27230],{"data":27217,"marks":27218,"value":27219,"nodeType":867},{},[],"Push already provided the ability to detect stolen credentials being actively used by employees in your organization with our ",{"data":27221,"content":27225,"nodeType":3447},{"target":27222},{"sys":27223},{"id":27224,"type":887,"linkType":888},"6vCr4d3R1XA1E8dU883l7N",[27226],{"data":27227,"marks":27228,"value":27229,"nodeType":867},{},[],"Stolen credential detection control",{"data":27231,"marks":27232,"value":27233,"nodeType":867},{},[],". This provides an early-warning signal when Push finds a match between credentials for sale on criminal forums with those still being used by your employees, reducing some 99.5% of false positives we usually see with TI feed data.",{"data":27235,"content":27236,"nodeType":881},{},[27237],{"data":27238,"marks":27239,"value":27240,"nodeType":867},{},[],"With Push, you can also identify where employees are logging in with passwords on apps that otherwise should be using SAML, OIDC, or some other federated mechanism — aka the ghost login vulnerability.",{"data":27242,"content":27243,"nodeType":881},{},[27244],{"data":27245,"marks":27246,"value":27247,"nodeType":867},{},[],"This year, we made it easier for security teams to enforce two security fundamentals that help harden accounts and reduce the risk of ATO, even on unmanaged apps:",{"data":27249,"content":27250,"nodeType":3126},{},[27251,27280],{"data":27252,"content":27253,"nodeType":3061},{},[27254],{"data":27255,"content":27256,"nodeType":881},{},[27257,27262,27266,27276],{"data":27258,"marks":27259,"value":27261,"nodeType":867},{},[27260],{"type":916},"Strong password enforcement:",{"data":27263,"marks":27264,"value":27265,"nodeType":867},{},[]," With this control, you can prompt end-users to ",{"data":27267,"content":27271,"nodeType":3447},{"target":27268},{"sys":27269},{"id":27270,"type":887,"linkType":888},"5aB5x5VXrMv7PDmH0iiK0c",[27272],{"data":27273,"marks":27274,"value":27275,"nodeType":867},{},[],"fix an insecure password",{"data":27277,"marks":27278,"value":27279,"nodeType":867},{},[]," on all your workforce apps, even the ones you don’t centrally manage. ",{"data":27281,"content":27282,"nodeType":3061},{},[27283],{"data":27284,"content":27285,"nodeType":881},{},[27286,27291,27294,27304],{"data":27287,"marks":27288,"value":27290,"nodeType":867},{},[27289],{"type":916},"MFA enforcement:",{"data":27292,"marks":27293,"value":27265,"nodeType":867},{},[],{"data":27295,"content":27299,"nodeType":3447},{"target":27296},{"sys":27297},{"id":27298,"type":887,"linkType":888},"wikyVxlHwKUOKM9xo19eP",[27300],{"data":27301,"marks":27302,"value":27303,"nodeType":867},{},[],"register for MFA",{"data":27305,"marks":27306,"value":27307,"nodeType":867},{},[]," where Push detects it’s missing — again, even on unmanaged apps.",{"data":27309,"content":27310,"nodeType":881},{},[27311],{"data":27312,"marks":27313,"value":27314,"nodeType":867},{},[],"Both of these controls use in-browser banners to provide point-in-time guidance to users when they’re most likely to see it and act on it.",{"data":27316,"content":27320,"nodeType":890},{"target":27317},{"sys":27318},{"id":27319,"type":887,"linkType":888},"3XH0hnnhcZNI47PhdiD4q0",[],{"data":27322,"content":27323,"nodeType":881},{},[27324,27328,27333],{"data":27325,"marks":27326,"value":27327,"nodeType":867},{},[],"To address the pattern of adversaries moving from targeting hardened core apps such as identity providers to the likes of GitLab, Postman, Jira, and others containing valuable corporate data, we also expanded one of the Push platform’s core security controls called ",{"data":27329,"marks":27330,"value":27332,"nodeType":867},{},[27331],{"type":916},"Password protection",{"data":27334,"marks":27335,"value":1947,"nodeType":867},{},[],{"data":27337,"content":27338,"nodeType":881},{},[27339,27342,27346],{"data":27340,"marks":27341,"value":3113,"nodeType":867},{},[],{"data":27343,"marks":27344,"value":27332,"nodeType":867},{},[27345],{"type":916},{"data":27347,"marks":27348,"value":27349,"nodeType":867},{},[]," control previously could be applied only to IdP passwords, allowing you to essentially “pin” the credential for those systems so that it could never be entered on a phishing page or reused on any other app. ",{"data":27351,"content":27352,"nodeType":881},{},[27353,27357,27367],{"data":27354,"marks":27355,"value":27356,"nodeType":867},{},[],"We expanded that control to allow you to ",{"data":27358,"content":27362,"nodeType":3447},{"target":27359},{"sys":27360},{"id":27361,"type":887,"linkType":888},"6FYHbkcRUrtznPo7RarRsz",[27363],{"data":27364,"marks":27365,"value":27366,"nodeType":867},{},[],"protect passwords on any valuable app",{"data":27368,"marks":27369,"value":27370,"nodeType":867},{},[],", preventing account takeover through phished creds and reducing the blast radius of attacks when a compromised account has been reusing passwords on multiple applications.",{"data":27372,"content":27376,"nodeType":890},{"target":27373},{"sys":27374},{"id":27375,"type":887,"linkType":888},"74l82HIeaumFX4u9AMjj79",[],{"data":27378,"content":27379,"nodeType":881},{},[27380,27384,27394],{"data":27381,"marks":27382,"value":27383,"nodeType":867},{},[],"Push also now gives you visibility into where employees are ",{"data":27385,"content":27389,"nodeType":3447},{"target":27386},{"sys":27387},{"id":27388,"type":887,"linkType":888},"7uLeQ9twNl5RyNaWkkJNjd",[27390],{"data":27391,"marks":27392,"value":27393,"nodeType":867},{},[],"syncing their corporate browser profile",{"data":27395,"marks":27396,"value":27397,"nodeType":867},{},[]," to a personal profile, raising the risk of syncing corporate passwords to unmanaged devices — another vector for credential harvesting if those endpoints become compromised.",{"data":27399,"content":27400,"nodeType":881},{},[27401],{"data":27402,"marks":27403,"value":27404,"nodeType":867},{},[],"And of course, underlying all these features is the foundational visibility of all your apps, accounts, account vulnerabilities, and login methods that Push provides.",{"data":27406,"content":27407,"nodeType":908},{},[],{"data":27409,"content":27410,"nodeType":918},{},[27411],{"data":27412,"marks":27413,"value":27414,"nodeType":867},{},[],"Blocking malicious browser extensions",{"data":27416,"content":27417,"nodeType":998},{},[27418],{"data":27419,"marks":27420,"value":26601,"nodeType":867},{},[],{"data":27422,"content":27423,"nodeType":881},{},[27424],{"data":27425,"marks":27426,"value":27427,"nodeType":867},{},[],"Getting visibility and control over all the browser extensions used across your workforce has long been a thorny problem for security teams. ",{"data":27429,"content":27430,"nodeType":881},{},[27431],{"data":27432,"marks":27433,"value":27434,"nodeType":867},{},[],"The possible solutions haven’t been great, either. Teams could either apply a blunt-force block for most or all extensions, or spend painstaking time trying to understand what was installed, why, and by whom, across all the browsers in the environment.",{"data":27436,"content":27437,"nodeType":881},{},[27438,27442,27452],{"data":27439,"marks":27440,"value":27441,"nodeType":867},{},[],"The urgency of solving this problem increased for many organizations this year after the December 2024 compromise of at least 35 Google Chrome extensions in a ",{"data":27443,"content":27447,"nodeType":3447},{"target":27444},{"sys":27445},{"id":27446,"type":887,"linkType":888},"6sprbTRpfnTJsP3mGR2gKa",[27448],{"data":27449,"marks":27450,"value":27451,"nodeType":867},{},[],"campaign targeting browser extension developers",{"data":27453,"marks":27454,"value":27455,"nodeType":867},{},[],". Cyberhaven’s extension was one of these, and the campaign inherited their name.",{"data":27457,"content":27458,"nodeType":998},{},[27459],{"data":27460,"marks":27461,"value":26792,"nodeType":867},{},[],{"data":27463,"content":27464,"nodeType":881},{},[27465,27469,27479],{"data":27466,"marks":27467,"value":27468,"nodeType":867},{},[],"With Push, you can now get visibility across ",{"data":27470,"content":27474,"nodeType":3447},{"target":27471},{"sys":27472},{"id":27473,"type":887,"linkType":888},"3ibVBa6u0XfcXXDVtON5th",[27475],{"data":27476,"marks":27477,"value":27478,"nodeType":867},{},[],"all the browser extensions",{"data":27480,"marks":27481,"value":27482,"nodeType":867},{},[]," installed on employee browsers in your environment, and block the ones you don’t want.",{"data":27484,"content":27488,"nodeType":890},{"target":27485},{"sys":27486},{"id":27487,"type":887,"linkType":888},"5J5jdmwugy7yU8GGwxe7iH",[],{"data":27490,"content":27491,"nodeType":881},{},[27492],{"data":27493,"marks":27494,"value":27495,"nodeType":867},{},[],"You can also:",{"data":27497,"content":27498,"nodeType":3126},{},[27499,27509,27519],{"data":27500,"content":27501,"nodeType":3061},{},[27502],{"data":27503,"content":27504,"nodeType":881},{},[27505],{"data":27506,"marks":27507,"value":27508,"nodeType":867},{},[],"Review extensions with risky permissions.",{"data":27510,"content":27511,"nodeType":3061},{},[27512],{"data":27513,"content":27514,"nodeType":881},{},[27515],{"data":27516,"marks":27517,"value":27518,"nodeType":867},{},[],"Identify extensions with potentially suspicious installation methods, such as sideloaded or manually installed.",{"data":27520,"content":27521,"nodeType":3061},{},[27522],{"data":27523,"content":27524,"nodeType":881},{},[27525],{"data":27526,"marks":27527,"value":27528,"nodeType":867},{},[],"Block extensions based on user groups and browser profiles (e.g. profiles logged in with a company domain).",{"data":27530,"content":27531,"nodeType":881},{},[27532,27536,27544],{"data":27533,"marks":27534,"value":27535,"nodeType":867},{},[],"Learn more about extension visibility and management in our ",{"data":27537,"content":27540,"nodeType":3447},{"target":27538},{"sys":27539},{"id":27473,"type":887,"linkType":888},[27541],{"data":27542,"marks":27543,"value":27111,"nodeType":867},{},[],{"data":27545,"marks":27546,"value":1947,"nodeType":867},{},[],{"data":27548,"content":27549,"nodeType":908},{},[],{"data":27551,"content":27552,"nodeType":918},{},[27553],{"data":27554,"marks":27555,"value":27556,"nodeType":867},{},[],"Adding a layer of protection against help desk scams",{"data":27558,"content":27559,"nodeType":998},{},[27560],{"data":27561,"marks":27562,"value":26601,"nodeType":867},{},[],{"data":27564,"content":27565,"nodeType":881},{},[27566],{"data":27567,"marks":27568,"value":27569,"nodeType":867},{},[],"Finally, another big theme in this year’s TTPs was the use of help desk social engineering to compromise organizations. ",{"data":27571,"content":27572,"nodeType":881},{},[27573,27577,27586],{"data":27574,"marks":27575,"value":27576,"nodeType":867},{},[],"Attackers like ",{"data":27578,"content":27582,"nodeType":3447},{"target":27579},{"sys":27580},{"id":27581,"type":887,"linkType":888},"wgpdyHDn9NcpIJNr7jnFp",[27583],{"data":27584,"marks":27585,"value":13597,"nodeType":867},{},[],{"data":27587,"marks":27588,"value":27589,"nodeType":867},{},[]," — now known as part of the evolving cybercriminal group Scattered Lapsus$ Hunters — have targeted organizations including MGM Resorts and Marks & Spencer by convincing help desk staff to help them bypass MFA or reset credentials for accounts they then use to access corporate systems. ",{"data":27591,"content":27592,"nodeType":998},{},[27593],{"data":27594,"marks":27595,"value":26792,"nodeType":867},{},[],{"data":27597,"content":27598,"nodeType":881},{},[27599,27603,27608],{"data":27600,"marks":27601,"value":27602,"nodeType":867},{},[],"To provide an additional layer of security when verifying employee identities during help desk interactions, Push introduced ",{"data":27604,"marks":27605,"value":27607,"nodeType":867},{},[27606],{"type":916},"Employee verification codes",{"data":27609,"marks":27610,"value":1947,"nodeType":867},{},[],{"data":27612,"content":27616,"nodeType":890},{"target":27613},{"sys":27614},{"id":27615,"type":887,"linkType":888},"19Baqh5QwbonzsR0EcaDS8",[],{"data":27618,"content":27619,"nodeType":881},{},[27620],{"data":27621,"marks":27622,"value":27623,"nodeType":867},{},[],"These are a rotating 6-digit verification code accessible via the Push Security extension dropdown. When an employee contacts your help desk, staff can use this code to help verify their identity before performing any sensitive account changes.",{"data":27625,"content":27626,"nodeType":881},{},[27627],{"data":27628,"marks":27629,"value":27630,"nodeType":867},{},[],"Employee verification codes are lightweight, rotate every 24 hours, and don’t require any additional apps or devices.",{"data":27632,"content":27633,"nodeType":881},{},[27634,27638,27647],{"data":27635,"marks":27636,"value":27637,"nodeType":867},{},[],"Learn more about verification codes in our ",{"data":27639,"content":27643,"nodeType":3447},{"target":27640},{"sys":27641},{"id":27642,"type":887,"linkType":888},"4rLP8wr6HnvBG2OzqYYKpF",[27644],{"data":27645,"marks":27646,"value":26940,"nodeType":867},{},[],{"data":27648,"marks":27649,"value":1947,"nodeType":867},{},[],{"data":27651,"content":27652,"nodeType":908},{},[],{"data":27654,"content":27655,"nodeType":918},{},[27656],{"data":27657,"marks":27658,"value":10042,"nodeType":867},{},[],{"data":27660,"content":27661,"nodeType":881},{},[27662],{"data":27663,"marks":27664,"value":27665,"nodeType":867},{},[],"Push Security’s browser-based security platform provides comprehensive detection and response capabilities against the leading cause of breaches. Push blocks browser-based attacks like AiTM phishing, credential stuffing, malicious browser extensions, ClickFix, and session hijacking. ",{"data":27667,"content":27668,"nodeType":881},{},[27669],{"data":27670,"marks":27671,"value":27672,"nodeType":867},{},[],"You don’t need to wait until it all goes wrong — you can also use Push to proactively find and fix vulnerabilities across the apps that your employees use, like ghost logins, SSO coverage gaps, MFA gaps, vulnerable passwords, and more to harden your identity attack surface.",{"data":27674,"content":27675,"nodeType":881},{},[27676,27680,27688,27692,27698],{"data":27677,"marks":27678,"value":27679,"nodeType":867},{},[],"To learn more about Push, check out our latest ",{"data":27681,"content":27683,"nodeType":876},{"uri":27682},"/resources/product-brochure",[27684],{"data":27685,"marks":27686,"value":27687,"nodeType":867},{},[],"product overview",{"data":27689,"marks":27690,"value":27691,"nodeType":867},{},[]," or book some time with one of our team for a ",{"data":27693,"content":27694,"nodeType":876},{"uri":4351},[27695],{"data":27696,"marks":27697,"value":3399,"nodeType":867},{},[],{"data":27699,"marks":27700,"value":1947,"nodeType":867},{},[],"Taking the fight to attackers: Push’s top features of 2025","Here’s how real-world attacks and our own R&D informed what we built for Push customers over the last year.","2025-12-17T00:00:00.000Z","taking-the-fight-to-attackers-top-features-of-2025",{"items":27706},[27707,27709],{"sys":27708,"name":342},{"id":2550},{"sys":27710,"name":2547},{"id":2546},{"items":27712},[27713],{"fullName":4372,"firstName":4373,"jobTitle":4374,"profilePicture":27714},{"url":4376},{"__typename":1742,"sys":27716,"content":27717,"title":15224,"synopsis":15225,"hashTags":59,"publishedDate":15226,"slug":15227,"tagsCollection":28533,"authorsCollection":28539},{"id":14277},{"json":27718},{"data":27719,"content":27720,"nodeType":1640},{},[27721,27727,27733,27739,27742,27749,27755,27761,27766,27772,27777,27793,27799,27809,27812,27819,27825,27838,27844,27854,27859,27862,27869,27876,27881,27889,27905,27913,27919,27927,27942,27950,27956,27964,27990,27998,28004,28012,28028,28033,28041,28047,28055,28088,28091,28098,28106,28122,28130,28136,28144,28170,28175,28183,28189,28194,28197,28204,28212,28218,28269,28274,28277,28284,28292,28298,28303,28306,28313,28319,28325,28385,28391,28446,28452,28455,28462,28468,28474,28479,28482,28489,28495,28501,28507],{"data":27722,"content":27723,"nodeType":881},{},[27724],{"data":27725,"marks":27726,"value":14288,"nodeType":867},{},[],{"data":27728,"content":27729,"nodeType":881},{},[27730],{"data":27731,"marks":27732,"value":14295,"nodeType":867},{},[],{"data":27734,"content":27735,"nodeType":881},{},[27736],{"data":27737,"marks":27738,"value":14302,"nodeType":867},{},[],{"data":27740,"content":27741,"nodeType":908},{},[],{"data":27743,"content":27744,"nodeType":918},{},[27745],{"data":27746,"marks":27747,"value":14313,"nodeType":867},{},[27748],{"type":916},{"data":27750,"content":27751,"nodeType":881},{},[27752],{"data":27753,"marks":27754,"value":14320,"nodeType":867},{},[],{"data":27756,"content":27757,"nodeType":881},{},[27758],{"data":27759,"marks":27760,"value":14327,"nodeType":867},{},[],{"data":27762,"content":27765,"nodeType":890},{"target":27763},{"sys":27764},{"id":14332,"type":887,"linkType":888},[],{"data":27767,"content":27768,"nodeType":881},{},[27769],{"data":27770,"marks":27771,"value":14340,"nodeType":867},{},[],{"data":27773,"content":27776,"nodeType":890},{"target":27774},{"sys":27775},{"id":14345,"type":887,"linkType":888},[],{"data":27778,"content":27779,"nodeType":881},{},[27780,27783,27790],{"data":27781,"marks":27782,"value":14353,"nodeType":867},{},[],{"data":27784,"content":27785,"nodeType":876},{"uri":5752},[27786],{"data":27787,"marks":27788,"value":14361,"nodeType":867},{},[27789],{"type":1040},{"data":27791,"marks":27792,"value":14365,"nodeType":867},{},[],{"data":27794,"content":27795,"nodeType":881},{},[27796],{"data":27797,"marks":27798,"value":14372,"nodeType":867},{},[],{"data":27800,"content":27801,"nodeType":881},{},[27802,27805],{"data":27803,"marks":27804,"value":14379,"nodeType":867},{},[],{"data":27806,"marks":27807,"value":14384,"nodeType":867},{},[27808],{"type":916},{"data":27810,"content":27811,"nodeType":908},{},[],{"data":27813,"content":27814,"nodeType":918},{},[27815],{"data":27816,"marks":27817,"value":14395,"nodeType":867},{},[27818],{"type":916},{"data":27820,"content":27821,"nodeType":881},{},[27822],{"data":27823,"marks":27824,"value":14402,"nodeType":867},{},[],{"data":27826,"content":27827,"nodeType":881},{},[27828,27831,27835],{"data":27829,"marks":27830,"value":14409,"nodeType":867},{},[],{"data":27832,"marks":27833,"value":14414,"nodeType":867},{},[27834],{"type":916},{"data":27836,"marks":27837,"value":14418,"nodeType":867},{},[],{"data":27839,"content":27840,"nodeType":881},{},[27841],{"data":27842,"marks":27843,"value":14425,"nodeType":867},{},[],{"data":27845,"content":27846,"nodeType":881},{},[27847,27850],{"data":27848,"marks":27849,"value":14432,"nodeType":867},{},[],{"data":27851,"marks":27852,"value":14437,"nodeType":867},{},[27853],{"type":916},{"data":27855,"content":27858,"nodeType":890},{"target":27856},{"sys":27857},{"id":14442,"type":887,"linkType":888},[],{"data":27860,"content":27861,"nodeType":908},{},[],{"data":27863,"content":27864,"nodeType":918},{},[27865],{"data":27866,"marks":27867,"value":14454,"nodeType":867},{},[27868],{"type":916},{"data":27870,"content":27871,"nodeType":998},{},[27872],{"data":27873,"marks":27874,"value":14462,"nodeType":867},{},[27875],{"type":916},{"data":27877,"content":27880,"nodeType":890},{"target":27878},{"sys":27879},{"id":14467,"type":887,"linkType":888},[],{"data":27882,"content":27883,"nodeType":881},{},[27884],{"data":27885,"marks":27886,"value":14477,"nodeType":867},{},[27887,27888],{"type":916},{"type":1040},{"data":27890,"content":27891,"nodeType":881},{},[27892,27895,27902],{"data":27893,"marks":27894,"value":14484,"nodeType":867},{},[],{"data":27896,"content":27897,"nodeType":876},{"uri":14487},[27898],{"data":27899,"marks":27900,"value":14493,"nodeType":867},{},[27901],{"type":1040},{"data":27903,"marks":27904,"value":14497,"nodeType":867},{},[],{"data":27906,"content":27907,"nodeType":881},{},[27908],{"data":27909,"marks":27910,"value":14506,"nodeType":867},{},[27911,27912],{"type":916},{"type":1040},{"data":27914,"content":27915,"nodeType":881},{},[27916],{"data":27917,"marks":27918,"value":14513,"nodeType":867},{},[],{"data":27920,"content":27921,"nodeType":881},{},[27922],{"data":27923,"marks":27924,"value":14522,"nodeType":867},{},[27925,27926],{"type":916},{"type":1040},{"data":27928,"content":27929,"nodeType":881},{},[27930,27933,27939],{"data":27931,"marks":27932,"value":14529,"nodeType":867},{},[],{"data":27934,"content":27935,"nodeType":876},{"uri":14532},[27936],{"data":27937,"marks":27938,"value":14537,"nodeType":867},{},[],{"data":27940,"marks":27941,"value":14541,"nodeType":867},{},[],{"data":27943,"content":27944,"nodeType":881},{},[27945],{"data":27946,"marks":27947,"value":14550,"nodeType":867},{},[27948,27949],{"type":916},{"type":1040},{"data":27951,"content":27952,"nodeType":881},{},[27953],{"data":27954,"marks":27955,"value":14557,"nodeType":867},{},[],{"data":27957,"content":27958,"nodeType":881},{},[27959],{"data":27960,"marks":27961,"value":14566,"nodeType":867},{},[27962,27963],{"type":916},{"type":1040},{"data":27965,"content":27966,"nodeType":881},{},[27967,27970,27977,27980,27987],{"data":27968,"marks":27969,"value":14573,"nodeType":867},{},[],{"data":27971,"content":27972,"nodeType":876},{"uri":14576},[27973],{"data":27974,"marks":27975,"value":14582,"nodeType":867},{},[27976],{"type":1040},{"data":27978,"marks":27979,"value":14586,"nodeType":867},{},[],{"data":27981,"content":27982,"nodeType":876},{"uri":14589},[27983],{"data":27984,"marks":27985,"value":6850,"nodeType":867},{},[27986],{"type":1040},{"data":27988,"marks":27989,"value":14598,"nodeType":867},{},[],{"data":27991,"content":27992,"nodeType":881},{},[27993],{"data":27994,"marks":27995,"value":14607,"nodeType":867},{},[27996,27997],{"type":916},{"type":1040},{"data":27999,"content":28000,"nodeType":881},{},[28001],{"data":28002,"marks":28003,"value":14614,"nodeType":867},{},[],{"data":28005,"content":28006,"nodeType":881},{},[28007],{"data":28008,"marks":28009,"value":14623,"nodeType":867},{},[28010,28011],{"type":916},{"type":1040},{"data":28013,"content":28014,"nodeType":881},{},[28015,28018,28025],{"data":28016,"marks":28017,"value":14630,"nodeType":867},{},[],{"data":28019,"content":28020,"nodeType":876},{"uri":14589},[28021],{"data":28022,"marks":28023,"value":6850,"nodeType":867},{},[28024],{"type":1040},{"data":28026,"marks":28027,"value":14641,"nodeType":867},{},[],{"data":28029,"content":28032,"nodeType":890},{"target":28030},{"sys":28031},{"id":14646,"type":887,"linkType":888},[],{"data":28034,"content":28035,"nodeType":881},{},[28036],{"data":28037,"marks":28038,"value":14656,"nodeType":867},{},[28039,28040],{"type":916},{"type":1040},{"data":28042,"content":28043,"nodeType":881},{},[28044],{"data":28045,"marks":28046,"value":14663,"nodeType":867},{},[],{"data":28048,"content":28049,"nodeType":881},{},[28050],{"data":28051,"marks":28052,"value":14672,"nodeType":867},{},[28053,28054],{"type":916},{"type":1040},{"data":28056,"content":28057,"nodeType":881},{},[28058,28061,28067,28070,28076,28079,28085],{"data":28059,"marks":28060,"value":14679,"nodeType":867},{},[],{"data":28062,"content":28063,"nodeType":876},{"uri":14682},[28064],{"data":28065,"marks":28066,"value":14687,"nodeType":867},{},[],{"data":28068,"marks":28069,"value":2063,"nodeType":867},{},[],{"data":28071,"content":28072,"nodeType":876},{"uri":14693},[28073],{"data":28074,"marks":28075,"value":14698,"nodeType":867},{},[],{"data":28077,"marks":28078,"value":14702,"nodeType":867},{},[],{"data":28080,"content":28081,"nodeType":876},{"uri":3074},[28082],{"data":28083,"marks":28084,"value":14709,"nodeType":867},{},[],{"data":28086,"marks":28087,"value":14713,"nodeType":867},{},[],{"data":28089,"content":28090,"nodeType":908},{},[],{"data":28092,"content":28093,"nodeType":998},{},[28094],{"data":28095,"marks":28096,"value":14724,"nodeType":867},{},[28097],{"type":916},{"data":28099,"content":28100,"nodeType":881},{},[28101],{"data":28102,"marks":28103,"value":14733,"nodeType":867},{},[28104,28105],{"type":916},{"type":1040},{"data":28107,"content":28108,"nodeType":881},{},[28109,28112,28119],{"data":28110,"marks":28111,"value":14740,"nodeType":867},{},[],{"data":28113,"content":28114,"nodeType":876},{"uri":14743},[28115],{"data":28116,"marks":28117,"value":14749,"nodeType":867},{},[28118],{"type":1040},{"data":28120,"marks":28121,"value":14753,"nodeType":867},{},[],{"data":28123,"content":28124,"nodeType":881},{},[28125],{"data":28126,"marks":28127,"value":14762,"nodeType":867},{},[28128,28129],{"type":916},{"type":1040},{"data":28131,"content":28132,"nodeType":881},{},[28133],{"data":28134,"marks":28135,"value":14769,"nodeType":867},{},[],{"data":28137,"content":28138,"nodeType":881},{},[28139],{"data":28140,"marks":28141,"value":14778,"nodeType":867},{},[28142,28143],{"type":916},{"type":1040},{"data":28145,"content":28146,"nodeType":881},{},[28147,28150,28157,28160,28167],{"data":28148,"marks":28149,"value":14785,"nodeType":867},{},[],{"data":28151,"content":28152,"nodeType":876},{"uri":14788},[28153],{"data":28154,"marks":28155,"value":14794,"nodeType":867},{},[28156],{"type":1040},{"data":28158,"marks":28159,"value":14798,"nodeType":867},{},[],{"data":28161,"content":28162,"nodeType":876},{"uri":14801},[28163],{"data":28164,"marks":28165,"value":14807,"nodeType":867},{},[28166],{"type":1040},{"data":28168,"marks":28169,"value":14811,"nodeType":867},{},[],{"data":28171,"content":28174,"nodeType":890},{"target":28172},{"sys":28173},{"id":14816,"type":887,"linkType":888},[],{"data":28176,"content":28177,"nodeType":881},{},[28178],{"data":28179,"marks":28180,"value":14826,"nodeType":867},{},[28181,28182],{"type":916},{"type":1040},{"data":28184,"content":28185,"nodeType":881},{},[28186],{"data":28187,"marks":28188,"value":14833,"nodeType":867},{},[],{"data":28190,"content":28193,"nodeType":890},{"target":28191},{"sys":28192},{"id":14838,"type":887,"linkType":888},[],{"data":28195,"content":28196,"nodeType":908},{},[],{"data":28198,"content":28199,"nodeType":998},{},[28200],{"data":28201,"marks":28202,"value":694,"nodeType":867},{},[28203],{"type":916},{"data":28205,"content":28206,"nodeType":881},{},[28207],{"data":28208,"marks":28209,"value":14858,"nodeType":867},{},[28210,28211],{"type":916},{"type":1040},{"data":28213,"content":28214,"nodeType":881},{},[28215],{"data":28216,"marks":28217,"value":14865,"nodeType":867},{},[],{"data":28219,"content":28220,"nodeType":3126},{},[28221,28234,28247],{"data":28222,"content":28223,"nodeType":3061},{},[28224],{"data":28225,"content":28226,"nodeType":881},{},[28227,28231],{"data":28228,"marks":28229,"value":14879,"nodeType":867},{},[28230],{"type":916},{"data":28232,"marks":28233,"value":14883,"nodeType":867},{},[],{"data":28235,"content":28236,"nodeType":3061},{},[28237],{"data":28238,"content":28239,"nodeType":881},{},[28240,28244],{"data":28241,"marks":28242,"value":14894,"nodeType":867},{},[28243],{"type":916},{"data":28245,"marks":28246,"value":14898,"nodeType":867},{},[],{"data":28248,"content":28249,"nodeType":3061},{},[28250],{"data":28251,"content":28252,"nodeType":881},{},[28253,28257,28260,28266],{"data":28254,"marks":28255,"value":14909,"nodeType":867},{},[28256],{"type":916},{"data":28258,"marks":28259,"value":14913,"nodeType":867},{},[],{"data":28261,"content":28262,"nodeType":876},{"uri":10495},[28263],{"data":28264,"marks":28265,"value":14920,"nodeType":867},{},[],{"data":28267,"marks":28268,"value":14924,"nodeType":867},{},[],{"data":28270,"content":28273,"nodeType":890},{"target":28271},{"sys":28272},{"id":14929,"type":887,"linkType":888},[],{"data":28275,"content":28276,"nodeType":908},{},[],{"data":28278,"content":28279,"nodeType":998},{},[28280],{"data":28281,"marks":28282,"value":699,"nodeType":867},{},[28283],{"type":916},{"data":28285,"content":28286,"nodeType":881},{},[28287],{"data":28288,"marks":28289,"value":14949,"nodeType":867},{},[28290,28291],{"type":916},{"type":1040},{"data":28293,"content":28294,"nodeType":881},{},[28295],{"data":28296,"marks":28297,"value":14956,"nodeType":867},{},[],{"data":28299,"content":28302,"nodeType":890},{"target":28300},{"sys":28301},{"id":14961,"type":887,"linkType":888},[],{"data":28304,"content":28305,"nodeType":908},{},[],{"data":28307,"content":28308,"nodeType":918},{},[28309],{"data":28310,"marks":28311,"value":14973,"nodeType":867},{},[28312],{"type":916},{"data":28314,"content":28315,"nodeType":881},{},[28316],{"data":28317,"marks":28318,"value":14980,"nodeType":867},{},[],{"data":28320,"content":28321,"nodeType":881},{},[28322],{"data":28323,"marks":28324,"value":14987,"nodeType":867},{},[],{"data":28326,"content":28327,"nodeType":3126},{},[28328,28347,28366],{"data":28329,"content":28330,"nodeType":3061},{},[28331],{"data":28332,"content":28333,"nodeType":881},{},[28334,28337,28344],{"data":28335,"marks":28336,"value":15000,"nodeType":867},{},[],{"data":28338,"content":28339,"nodeType":876},{"uri":15003},[28340],{"data":28341,"marks":28342,"value":15009,"nodeType":867},{},[28343],{"type":1040},{"data":28345,"marks":28346,"value":15013,"nodeType":867},{},[],{"data":28348,"content":28349,"nodeType":3061},{},[28350],{"data":28351,"content":28352,"nodeType":881},{},[28353,28356,28363],{"data":28354,"marks":28355,"value":15023,"nodeType":867},{},[],{"data":28357,"content":28358,"nodeType":876},{"uri":15026},[28359],{"data":28360,"marks":28361,"value":15032,"nodeType":867},{},[28362],{"type":1040},{"data":28364,"marks":28365,"value":15013,"nodeType":867},{},[],{"data":28367,"content":28368,"nodeType":3061},{},[28369],{"data":28370,"content":28371,"nodeType":881},{},[28372,28375,28382],{"data":28373,"marks":28374,"value":15045,"nodeType":867},{},[],{"data":28376,"content":28377,"nodeType":876},{"uri":15048},[28378],{"data":28379,"marks":28380,"value":15054,"nodeType":867},{},[28381],{"type":1040},{"data":28383,"marks":28384,"value":15013,"nodeType":867},{},[],{"data":28386,"content":28387,"nodeType":881},{},[28388],{"data":28389,"marks":28390,"value":15064,"nodeType":867},{},[],{"data":28392,"content":28393,"nodeType":3126},{},[28394,28407,28420,28433],{"data":28395,"content":28396,"nodeType":3061},{},[28397],{"data":28398,"content":28399,"nodeType":881},{},[28400,28404],{"data":28401,"marks":28402,"value":15078,"nodeType":867},{},[28403],{"type":916},{"data":28405,"marks":28406,"value":15082,"nodeType":867},{},[],{"data":28408,"content":28409,"nodeType":3061},{},[28410],{"data":28411,"content":28412,"nodeType":881},{},[28413,28417],{"data":28414,"marks":28415,"value":15093,"nodeType":867},{},[28416],{"type":916},{"data":28418,"marks":28419,"value":15097,"nodeType":867},{},[],{"data":28421,"content":28422,"nodeType":3061},{},[28423],{"data":28424,"content":28425,"nodeType":881},{},[28426,28430],{"data":28427,"marks":28428,"value":15108,"nodeType":867},{},[28429],{"type":916},{"data":28431,"marks":28432,"value":15112,"nodeType":867},{},[],{"data":28434,"content":28435,"nodeType":3061},{},[28436],{"data":28437,"content":28438,"nodeType":881},{},[28439,28443],{"data":28440,"marks":28441,"value":15123,"nodeType":867},{},[28442],{"type":916},{"data":28444,"marks":28445,"value":15127,"nodeType":867},{},[],{"data":28447,"content":28448,"nodeType":881},{},[28449],{"data":28450,"marks":28451,"value":15134,"nodeType":867},{},[],{"data":28453,"content":28454,"nodeType":908},{},[],{"data":28456,"content":28457,"nodeType":918},{},[28458],{"data":28459,"marks":28460,"value":15145,"nodeType":867},{},[28461],{"type":916},{"data":28463,"content":28464,"nodeType":881},{},[28465],{"data":28466,"marks":28467,"value":15152,"nodeType":867},{},[],{"data":28469,"content":28470,"nodeType":881},{},[28471],{"data":28472,"marks":28473,"value":15159,"nodeType":867},{},[],{"data":28475,"content":28478,"nodeType":890},{"target":28476},{"sys":28477},{"id":15164,"type":887,"linkType":888},[],{"data":28480,"content":28481,"nodeType":908},{},[],{"data":28483,"content":28484,"nodeType":918},{},[28485],{"data":28486,"marks":28487,"value":6214,"nodeType":867},{},[28488],{"type":916},{"data":28490,"content":28491,"nodeType":881},{},[28492],{"data":28493,"marks":28494,"value":15182,"nodeType":867},{},[],{"data":28496,"content":28497,"nodeType":881},{},[28498],{"data":28499,"marks":28500,"value":15189,"nodeType":867},{},[],{"data":28502,"content":28503,"nodeType":881},{},[28504],{"data":28505,"marks":28506,"value":15196,"nodeType":867},{},[],{"data":28508,"content":28509,"nodeType":881},{},[28510,28513,28520,28523,28530],{"data":28511,"marks":28512,"value":10795,"nodeType":867},{},[],{"data":28514,"content":28515,"nodeType":876},{"uri":10798},[28516],{"data":28517,"marks":28518,"value":10803,"nodeType":867},{},[28519],{"type":1040},{"data":28521,"marks":28522,"value":15213,"nodeType":867},{},[],{"data":28524,"content":28525,"nodeType":876},{"uri":1629},[28526],{"data":28527,"marks":28528,"value":10826,"nodeType":867},{},[28529],{"type":1040},{"data":28531,"marks":28532,"value":1947,"nodeType":867},{},[],{"items":28534},[28535,28537],{"sys":28536,"name":2547},{"id":2546},{"sys":28538,"name":342},{"id":2550},{"items":28540},[28541],{"fullName":849,"firstName":850,"jobTitle":851,"profilePicture":28542},{"url":855},"blog/unpacking-the-latest-slh-campaign",{"json":28545},{"data":28546,"content":28547,"nodeType":1640},{},[28548],{"data":28549,"content":28550,"nodeType":881},{},[28551],{"data":28552,"marks":28553,"value":28554,"nodeType":867},{},[],"Analyzing the latest Scattered Lapsus$ Hunters (SLH) phishing campaign targeting hundreds of organizations. ",{"id":21120,"publishedAt":28556},"2026-08-12T11:53:16.417Z",{"items":28558},[28559,28561],{"sys":28560,"name":2547},{"id":2546},{"sys":28562,"name":342},{"id":2550},{"items":28564},[28565,28567,28569,28571,28573,28575,28577,28579,28581,28583,28585,28587,28589,28591,28593,28595,28597],{"sys":28566,"name":279,"slug":280,"tier":31},{"id":276},{"sys":28568,"name":413,"slug":414,"tier":31},{"id":410},{"sys":28570,"name":519,"slug":520,"tier":31},{"id":516},{"sys":28572,"name":342,"slug":343,"tier":31},{"id":339},{"sys":28574,"name":642,"slug":643,"tier":31},{"id":639},{"sys":28576,"name":650,"slug":651,"tier":45},{"id":647},{"sys":28578,"name":261,"slug":262,"tier":45},{"id":258},{"sys":28580,"name":571,"slug":572,"tier":45},{"id":568},{"sys":28582,"name":466,"slug":467,"tier":45},{"id":463},{"sys":28584,"name":607,"slug":608,"tier":45},{"id":604},{"sys":28586,"name":511,"slug":512,"tier":45},{"id":508},{"sys":28588,"name":324,"slug":325,"tier":45},{"id":321},{"sys":28590,"name":475,"slug":476,"tier":45},{"id":472},{"sys":28592,"name":395,"slug":396,"tier":45},{"id":392},{"sys":28594,"name":493,"slug":494,"tier":45},{"id":490},{"sys":28596,"name":537,"slug":538,"tier":45},{"id":534},{"sys":28598,"name":404,"slug":405,"tier":45},{"id":401},"nlrbqqJFVIlz8E8KpfsQufXY-yj--6GLH62nM04r1CY",{"id":28601,"title":27701,"authorsCollection":28602,"content":28606,"extension":228,"faqItemsCollection":29881,"faqTitle":59,"featured":6,"hashTags":59,"meta":29883,"metaTitle":29884,"ogImage":59,"postType":29885,"publishedDate":27703,"relatedBlogPostsCollection":29886,"slug":27704,"stem":32148,"subtitle":59,"summary":32149,"synopsis":27702,"sys":32160,"tagsCollection":32162,"topicsCollection":32168,"__hash__":32212},"blog/blog/taking-the-fight-to-attackers-top-features-of-2025.json",{"items":28603},[28604],{"fullName":4372,"firstName":4373,"jobTitle":4374,"socialLinks":59,"profilePicture":28605},{"url":4376},{"json":28607,"links":29727},{"data":28608,"content":28609,"nodeType":1640},{},[28610,28616,28622,28679,28685,28743,28748,28754,28760,28763,28769,28775,28781,28867,28882,28888,28925,28931,28937,28943,28973,28978,29005,29010,29016,29022,29052,29069,29072,29078,29084,29108,29114,29120,29126,29132,29138,29143,29156,29195,29200,29217,29220,29226,29232,29249,29255,29281,29298,29304,29321,29327,29333,29384,29390,29395,29408,29421,29438,29443,29460,29466,29469,29475,29481,29487,29493,29510,29516,29533,29538,29544,29574,29591,29594,29600,29606,29612,29629,29635,29648,29653,29659,29665,29682,29685,29691,29697,29703],{"data":28611,"content":28612,"nodeType":881},{},[28613],{"data":28614,"marks":28615,"value":26420,"nodeType":867},{},[],{"data":28617,"content":28618,"nodeType":881},{},[28619],{"data":28620,"marks":28621,"value":26427,"nodeType":867},{},[],{"data":28623,"content":28624,"nodeType":3126},{},[28625,28643,28661],{"data":28626,"content":28627,"nodeType":3061},{},[28628],{"data":28629,"content":28630,"nodeType":881},{},[28631,28634,28640],{"data":28632,"marks":28633,"value":26440,"nodeType":867},{},[],{"data":28635,"content":28636,"nodeType":876},{"uri":15003},[28637],{"data":28638,"marks":28639,"value":15009,"nodeType":867},{},[],{"data":28641,"marks":28642,"value":15013,"nodeType":867},{},[],{"data":28644,"content":28645,"nodeType":3061},{},[28646],{"data":28647,"content":28648,"nodeType":881},{},[28649,28652,28658],{"data":28650,"marks":28651,"value":26459,"nodeType":867},{},[],{"data":28653,"content":28654,"nodeType":876},{"uri":15003},[28655],{"data":28656,"marks":28657,"value":15009,"nodeType":867},{},[],{"data":28659,"marks":28660,"value":15013,"nodeType":867},{},[],{"data":28662,"content":28663,"nodeType":3061},{},[28664],{"data":28665,"content":28666,"nodeType":881},{},[28667,28670,28676],{"data":28668,"marks":28669,"value":26478,"nodeType":867},{},[],{"data":28671,"content":28672,"nodeType":876},{"uri":15026},[28673],{"data":28674,"marks":28675,"value":26485,"nodeType":867},{},[],{"data":28677,"marks":28678,"value":15013,"nodeType":867},{},[],{"data":28680,"content":28681,"nodeType":881},{},[28682],{"data":28683,"marks":28684,"value":26495,"nodeType":867},{},[],{"data":28686,"content":28687,"nodeType":3126},{},[28688,28704,28727],{"data":28689,"content":28690,"nodeType":3061},{},[28691],{"data":28692,"content":28693,"nodeType":881},{},[28694,28697,28701],{"data":28695,"marks":28696,"value":26508,"nodeType":867},{},[],{"data":28698,"marks":28699,"value":26513,"nodeType":867},{},[28700],{"type":916},{"data":28702,"marks":28703,"value":26517,"nodeType":867},{},[],{"data":28705,"content":28706,"nodeType":3061},{},[28707],{"data":28708,"content":28709,"nodeType":881},{},[28710,28713,28717,28720,28724],{"data":28711,"marks":28712,"value":26527,"nodeType":867},{},[],{"data":28714,"marks":28715,"value":26532,"nodeType":867},{},[28716],{"type":916},{"data":28718,"marks":28719,"value":26536,"nodeType":867},{},[],{"data":28721,"marks":28722,"value":26541,"nodeType":867},{},[28723],{"type":916},{"data":28725,"marks":28726,"value":26545,"nodeType":867},{},[],{"data":28728,"content":28729,"nodeType":3061},{},[28730],{"data":28731,"content":28732,"nodeType":881},{},[28733,28736,28740],{"data":28734,"marks":28735,"value":26555,"nodeType":867},{},[],{"data":28737,"marks":28738,"value":26560,"nodeType":867},{},[28739],{"type":916},{"data":28741,"marks":28742,"value":26564,"nodeType":867},{},[],{"data":28744,"content":28747,"nodeType":890},{"target":28745},{"sys":28746},{"id":26569,"type":887,"linkType":888},[],{"data":28749,"content":28750,"nodeType":881},{},[28751],{"data":28752,"marks":28753,"value":26577,"nodeType":867},{},[],{"data":28755,"content":28756,"nodeType":881},{},[28757],{"data":28758,"marks":28759,"value":26584,"nodeType":867},{},[],{"data":28761,"content":28762,"nodeType":908},{},[],{"data":28764,"content":28765,"nodeType":918},{},[28766],{"data":28767,"marks":28768,"value":26594,"nodeType":867},{},[],{"data":28770,"content":28771,"nodeType":998},{},[28772],{"data":28773,"marks":28774,"value":26601,"nodeType":867},{},[],{"data":28776,"content":28777,"nodeType":881},{},[28778],{"data":28779,"marks":28780,"value":26608,"nodeType":867},{},[],{"data":28782,"content":28783,"nodeType":3126},{},[28784,28808,28843],{"data":28785,"content":28786,"nodeType":3061},{},[28787],{"data":28788,"content":28789,"nodeType":881},{},[28790,28794,28797,28805],{"data":28791,"marks":28792,"value":26622,"nodeType":867},{},[28793],{"type":916},{"data":28795,"marks":28796,"value":26626,"nodeType":867},{},[],{"data":28798,"content":28801,"nodeType":3447},{"target":28799},{"sys":28800},{"id":26631,"type":887,"linkType":888},[28802],{"data":28803,"marks":28804,"value":26636,"nodeType":867},{},[],{"data":28806,"marks":28807,"value":26640,"nodeType":867},{},[],{"data":28809,"content":28810,"nodeType":3061},{},[28811],{"data":28812,"content":28813,"nodeType":881},{},[28814,28818,28821,28829,28832,28840],{"data":28815,"marks":28816,"value":26651,"nodeType":867},{},[28817],{"type":916},{"data":28819,"marks":28820,"value":26655,"nodeType":867},{},[],{"data":28822,"content":28825,"nodeType":3447},{"target":28823},{"sys":28824},{"id":26660,"type":887,"linkType":888},[28826],{"data":28827,"marks":28828,"value":441,"nodeType":867},{},[],{"data":28830,"marks":28831,"value":26668,"nodeType":867},{},[],{"data":28833,"content":28836,"nodeType":3447},{"target":28834},{"sys":28835},{"id":26673,"type":887,"linkType":888},[28837],{"data":28838,"marks":28839,"value":26678,"nodeType":867},{},[],{"data":28841,"marks":28842,"value":1253,"nodeType":867},{},[],{"data":28844,"content":28845,"nodeType":3061},{},[28846],{"data":28847,"content":28848,"nodeType":881},{},[28849,28853,28856,28864],{"data":28850,"marks":28851,"value":26692,"nodeType":867},{},[28852],{"type":916},{"data":28854,"marks":28855,"value":26696,"nodeType":867},{},[],{"data":28857,"content":28860,"nodeType":3447},{"target":28858},{"sys":28859},{"id":26701,"type":887,"linkType":888},[28861],{"data":28862,"marks":28863,"value":26706,"nodeType":867},{},[],{"data":28865,"marks":28866,"value":26710,"nodeType":867},{},[],{"data":28868,"content":28869,"nodeType":881},{},[28870,28873,28879],{"data":28871,"marks":28872,"value":26717,"nodeType":867},{},[],{"data":28874,"content":28875,"nodeType":876},{"uri":26720},[28876],{"data":28877,"marks":28878,"value":26725,"nodeType":867},{},[],{"data":28880,"marks":28881,"value":26729,"nodeType":867},{},[],{"data":28883,"content":28884,"nodeType":881},{},[28885],{"data":28886,"marks":28887,"value":26736,"nodeType":867},{},[],{"data":28889,"content":28890,"nodeType":3126},{},[28891,28900,28916],{"data":28892,"content":28893,"nodeType":3061},{},[28894],{"data":28895,"content":28896,"nodeType":881},{},[28897],{"data":28898,"marks":28899,"value":26749,"nodeType":867},{},[],{"data":28901,"content":28902,"nodeType":3061},{},[28903],{"data":28904,"content":28905,"nodeType":881},{},[28906,28909,28913],{"data":28907,"marks":28908,"value":26759,"nodeType":867},{},[],{"data":28910,"marks":28911,"value":26764,"nodeType":867},{},[28912],{"type":1431},{"data":28914,"marks":28915,"value":26768,"nodeType":867},{},[],{"data":28917,"content":28918,"nodeType":3061},{},[28919],{"data":28920,"content":28921,"nodeType":881},{},[28922],{"data":28923,"marks":28924,"value":26778,"nodeType":867},{},[],{"data":28926,"content":28927,"nodeType":881},{},[28928],{"data":28929,"marks":28930,"value":26785,"nodeType":867},{},[],{"data":28932,"content":28933,"nodeType":998},{},[28934],{"data":28935,"marks":28936,"value":26792,"nodeType":867},{},[],{"data":28938,"content":28939,"nodeType":881},{},[28940],{"data":28941,"marks":28942,"value":26799,"nodeType":867},{},[],{"data":28944,"content":28945,"nodeType":3126},{},[28946,28955,28964],{"data":28947,"content":28948,"nodeType":3061},{},[28949],{"data":28950,"content":28951,"nodeType":881},{},[28952],{"data":28953,"marks":28954,"value":26812,"nodeType":867},{},[],{"data":28956,"content":28957,"nodeType":3061},{},[28958],{"data":28959,"content":28960,"nodeType":881},{},[28961],{"data":28962,"marks":28963,"value":26822,"nodeType":867},{},[],{"data":28965,"content":28966,"nodeType":3061},{},[28967],{"data":28968,"content":28969,"nodeType":881},{},[28970],{"data":28971,"marks":28972,"value":26832,"nodeType":867},{},[],{"data":28974,"content":28977,"nodeType":890},{"target":28975},{"sys":28976},{"id":26837,"type":887,"linkType":888},[],{"data":28979,"content":28980,"nodeType":881},{},[28981,28984,28988,28991,28995,28998,29002],{"data":28982,"marks":28983,"value":26845,"nodeType":867},{},[],{"data":28985,"marks":28986,"value":26850,"nodeType":867},{},[28987],{"type":916},{"data":28989,"marks":28990,"value":4006,"nodeType":867},{},[],{"data":28992,"marks":28993,"value":26858,"nodeType":867},{},[28994],{"type":916},{"data":28996,"marks":28997,"value":15362,"nodeType":867},{},[],{"data":28999,"marks":29000,"value":26866,"nodeType":867},{},[29001],{"type":916},{"data":29003,"marks":29004,"value":26870,"nodeType":867},{},[],{"data":29006,"content":29009,"nodeType":890},{"target":29007},{"sys":29008},{"id":26875,"type":887,"linkType":888},[],{"data":29011,"content":29012,"nodeType":881},{},[29013],{"data":29014,"marks":29015,"value":26883,"nodeType":867},{},[],{"data":29017,"content":29018,"nodeType":881},{},[29019],{"data":29020,"marks":29021,"value":26890,"nodeType":867},{},[],{"data":29023,"content":29024,"nodeType":3126},{},[29025,29034,29043],{"data":29026,"content":29027,"nodeType":3061},{},[29028],{"data":29029,"content":29030,"nodeType":881},{},[29031],{"data":29032,"marks":29033,"value":26903,"nodeType":867},{},[],{"data":29035,"content":29036,"nodeType":3061},{},[29037],{"data":29038,"content":29039,"nodeType":881},{},[29040],{"data":29041,"marks":29042,"value":26913,"nodeType":867},{},[],{"data":29044,"content":29045,"nodeType":3061},{},[29046],{"data":29047,"content":29048,"nodeType":881},{},[29049],{"data":29050,"marks":29051,"value":26923,"nodeType":867},{},[],{"data":29053,"content":29054,"nodeType":881},{},[29055,29058,29066],{"data":29056,"marks":29057,"value":26930,"nodeType":867},{},[],{"data":29059,"content":29062,"nodeType":3447},{"target":29060},{"sys":29061},{"id":26935,"type":887,"linkType":888},[29063],{"data":29064,"marks":29065,"value":26940,"nodeType":867},{},[],{"data":29067,"marks":29068,"value":1947,"nodeType":867},{},[],{"data":29070,"content":29071,"nodeType":908},{},[],{"data":29073,"content":29074,"nodeType":918},{},[29075],{"data":29076,"marks":29077,"value":26953,"nodeType":867},{},[],{"data":29079,"content":29080,"nodeType":998},{},[29081],{"data":29082,"marks":29083,"value":26601,"nodeType":867},{},[],{"data":29085,"content":29086,"nodeType":881},{},[29087,29090,29096,29099,29105],{"data":29088,"marks":29089,"value":26966,"nodeType":867},{},[],{"data":29091,"content":29092,"nodeType":876},{"uri":26969},[29093],{"data":29094,"marks":29095,"value":26974,"nodeType":867},{},[],{"data":29097,"marks":29098,"value":26978,"nodeType":867},{},[],{"data":29100,"content":29101,"nodeType":876},{"uri":26981},[29102],{"data":29103,"marks":29104,"value":26986,"nodeType":867},{},[],{"data":29106,"marks":29107,"value":26990,"nodeType":867},{},[],{"data":29109,"content":29110,"nodeType":881},{},[29111],{"data":29112,"marks":29113,"value":26997,"nodeType":867},{},[],{"data":29115,"content":29116,"nodeType":881},{},[29117],{"data":29118,"marks":29119,"value":27004,"nodeType":867},{},[],{"data":29121,"content":29122,"nodeType":881},{},[29123],{"data":29124,"marks":29125,"value":27011,"nodeType":867},{},[],{"data":29127,"content":29128,"nodeType":998},{},[29129],{"data":29130,"marks":29131,"value":26792,"nodeType":867},{},[],{"data":29133,"content":29134,"nodeType":881},{},[29135],{"data":29136,"marks":29137,"value":27024,"nodeType":867},{},[],{"data":29139,"content":29142,"nodeType":890},{"target":29140},{"sys":29141},{"id":27029,"type":887,"linkType":888},[],{"data":29144,"content":29145,"nodeType":881},{},[29146,29149,29153],{"data":29147,"marks":29148,"value":27037,"nodeType":867},{},[],{"data":29150,"marks":29151,"value":26866,"nodeType":867},{},[29152],{"type":916},{"data":29154,"marks":29155,"value":27045,"nodeType":867},{},[],{"data":29157,"content":29158,"nodeType":3126},{},[29159,29168,29177,29186],{"data":29160,"content":29161,"nodeType":3061},{},[29162],{"data":29163,"content":29164,"nodeType":881},{},[29165],{"data":29166,"marks":29167,"value":27058,"nodeType":867},{},[],{"data":29169,"content":29170,"nodeType":3061},{},[29171],{"data":29172,"content":29173,"nodeType":881},{},[29174],{"data":29175,"marks":29176,"value":27068,"nodeType":867},{},[],{"data":29178,"content":29179,"nodeType":3061},{},[29180],{"data":29181,"content":29182,"nodeType":881},{},[29183],{"data":29184,"marks":29185,"value":27078,"nodeType":867},{},[],{"data":29187,"content":29188,"nodeType":3061},{},[29189],{"data":29190,"content":29191,"nodeType":881},{},[29192],{"data":29193,"marks":29194,"value":27088,"nodeType":867},{},[],{"data":29196,"content":29199,"nodeType":890},{"target":29197},{"sys":29198},{"id":27093,"type":887,"linkType":888},[],{"data":29201,"content":29202,"nodeType":881},{},[29203,29206,29214],{"data":29204,"marks":29205,"value":27101,"nodeType":867},{},[],{"data":29207,"content":29210,"nodeType":3447},{"target":29208},{"sys":29209},{"id":27106,"type":887,"linkType":888},[29211],{"data":29212,"marks":29213,"value":27111,"nodeType":867},{},[],{"data":29215,"marks":29216,"value":1947,"nodeType":867},{},[],{"data":29218,"content":29219,"nodeType":908},{},[],{"data":29221,"content":29222,"nodeType":918},{},[29223],{"data":29224,"marks":29225,"value":27124,"nodeType":867},{},[],{"data":29227,"content":29228,"nodeType":998},{},[29229],{"data":29230,"marks":29231,"value":26601,"nodeType":867},{},[],{"data":29233,"content":29234,"nodeType":881},{},[29235,29238,29246],{"data":29236,"marks":29237,"value":27137,"nodeType":867},{},[],{"data":29239,"content":29242,"nodeType":3447},{"target":29240},{"sys":29241},{"id":27142,"type":887,"linkType":888},[29243],{"data":29244,"marks":29245,"value":27147,"nodeType":867},{},[],{"data":29247,"marks":29248,"value":1253,"nodeType":867},{},[],{"data":29250,"content":29251,"nodeType":881},{},[29252],{"data":29253,"marks":29254,"value":27157,"nodeType":867},{},[],{"data":29256,"content":29257,"nodeType":881},{},[29258,29261,29269,29272,29278],{"data":29259,"marks":29260,"value":27164,"nodeType":867},{},[],{"data":29262,"content":29265,"nodeType":3447},{"target":29263},{"sys":29264},{"id":14277,"type":887,"linkType":888},[29266],{"data":29267,"marks":29268,"value":3056,"nodeType":867},{},[],{"data":29270,"marks":29271,"value":27176,"nodeType":867},{},[],{"data":29273,"content":29274,"nodeType":876},{"uri":14589},[29275],{"data":29276,"marks":29277,"value":6850,"nodeType":867},{},[],{"data":29279,"marks":29280,"value":27186,"nodeType":867},{},[],{"data":29282,"content":29283,"nodeType":881},{},[29284,29287,29295],{"data":29285,"marks":29286,"value":27193,"nodeType":867},{},[],{"data":29288,"content":29291,"nodeType":3447},{"target":29289},{"sys":29290},{"id":27198,"type":887,"linkType":888},[29292],{"data":29293,"marks":29294,"value":5757,"nodeType":867},{},[],{"data":29296,"marks":29297,"value":27206,"nodeType":867},{},[],{"data":29299,"content":29300,"nodeType":998},{},[29301],{"data":29302,"marks":29303,"value":26792,"nodeType":867},{},[],{"data":29305,"content":29306,"nodeType":881},{},[29307,29310,29318],{"data":29308,"marks":29309,"value":27219,"nodeType":867},{},[],{"data":29311,"content":29314,"nodeType":3447},{"target":29312},{"sys":29313},{"id":27224,"type":887,"linkType":888},[29315],{"data":29316,"marks":29317,"value":27229,"nodeType":867},{},[],{"data":29319,"marks":29320,"value":27233,"nodeType":867},{},[],{"data":29322,"content":29323,"nodeType":881},{},[29324],{"data":29325,"marks":29326,"value":27240,"nodeType":867},{},[],{"data":29328,"content":29329,"nodeType":881},{},[29330],{"data":29331,"marks":29332,"value":27247,"nodeType":867},{},[],{"data":29334,"content":29335,"nodeType":3126},{},[29336,29360],{"data":29337,"content":29338,"nodeType":3061},{},[29339],{"data":29340,"content":29341,"nodeType":881},{},[29342,29346,29349,29357],{"data":29343,"marks":29344,"value":27261,"nodeType":867},{},[29345],{"type":916},{"data":29347,"marks":29348,"value":27265,"nodeType":867},{},[],{"data":29350,"content":29353,"nodeType":3447},{"target":29351},{"sys":29352},{"id":27270,"type":887,"linkType":888},[29354],{"data":29355,"marks":29356,"value":27275,"nodeType":867},{},[],{"data":29358,"marks":29359,"value":27279,"nodeType":867},{},[],{"data":29361,"content":29362,"nodeType":3061},{},[29363],{"data":29364,"content":29365,"nodeType":881},{},[29366,29370,29373,29381],{"data":29367,"marks":29368,"value":27290,"nodeType":867},{},[29369],{"type":916},{"data":29371,"marks":29372,"value":27265,"nodeType":867},{},[],{"data":29374,"content":29377,"nodeType":3447},{"target":29375},{"sys":29376},{"id":27298,"type":887,"linkType":888},[29378],{"data":29379,"marks":29380,"value":27303,"nodeType":867},{},[],{"data":29382,"marks":29383,"value":27307,"nodeType":867},{},[],{"data":29385,"content":29386,"nodeType":881},{},[29387],{"data":29388,"marks":29389,"value":27314,"nodeType":867},{},[],{"data":29391,"content":29394,"nodeType":890},{"target":29392},{"sys":29393},{"id":27319,"type":887,"linkType":888},[],{"data":29396,"content":29397,"nodeType":881},{},[29398,29401,29405],{"data":29399,"marks":29400,"value":27327,"nodeType":867},{},[],{"data":29402,"marks":29403,"value":27332,"nodeType":867},{},[29404],{"type":916},{"data":29406,"marks":29407,"value":1947,"nodeType":867},{},[],{"data":29409,"content":29410,"nodeType":881},{},[29411,29414,29418],{"data":29412,"marks":29413,"value":3113,"nodeType":867},{},[],{"data":29415,"marks":29416,"value":27332,"nodeType":867},{},[29417],{"type":916},{"data":29419,"marks":29420,"value":27349,"nodeType":867},{},[],{"data":29422,"content":29423,"nodeType":881},{},[29424,29427,29435],{"data":29425,"marks":29426,"value":27356,"nodeType":867},{},[],{"data":29428,"content":29431,"nodeType":3447},{"target":29429},{"sys":29430},{"id":27361,"type":887,"linkType":888},[29432],{"data":29433,"marks":29434,"value":27366,"nodeType":867},{},[],{"data":29436,"marks":29437,"value":27370,"nodeType":867},{},[],{"data":29439,"content":29442,"nodeType":890},{"target":29440},{"sys":29441},{"id":27375,"type":887,"linkType":888},[],{"data":29444,"content":29445,"nodeType":881},{},[29446,29449,29457],{"data":29447,"marks":29448,"value":27383,"nodeType":867},{},[],{"data":29450,"content":29453,"nodeType":3447},{"target":29451},{"sys":29452},{"id":27388,"type":887,"linkType":888},[29454],{"data":29455,"marks":29456,"value":27393,"nodeType":867},{},[],{"data":29458,"marks":29459,"value":27397,"nodeType":867},{},[],{"data":29461,"content":29462,"nodeType":881},{},[29463],{"data":29464,"marks":29465,"value":27404,"nodeType":867},{},[],{"data":29467,"content":29468,"nodeType":908},{},[],{"data":29470,"content":29471,"nodeType":918},{},[29472],{"data":29473,"marks":29474,"value":27414,"nodeType":867},{},[],{"data":29476,"content":29477,"nodeType":998},{},[29478],{"data":29479,"marks":29480,"value":26601,"nodeType":867},{},[],{"data":29482,"content":29483,"nodeType":881},{},[29484],{"data":29485,"marks":29486,"value":27427,"nodeType":867},{},[],{"data":29488,"content":29489,"nodeType":881},{},[29490],{"data":29491,"marks":29492,"value":27434,"nodeType":867},{},[],{"data":29494,"content":29495,"nodeType":881},{},[29496,29499,29507],{"data":29497,"marks":29498,"value":27441,"nodeType":867},{},[],{"data":29500,"content":29503,"nodeType":3447},{"target":29501},{"sys":29502},{"id":27446,"type":887,"linkType":888},[29504],{"data":29505,"marks":29506,"value":27451,"nodeType":867},{},[],{"data":29508,"marks":29509,"value":27455,"nodeType":867},{},[],{"data":29511,"content":29512,"nodeType":998},{},[29513],{"data":29514,"marks":29515,"value":26792,"nodeType":867},{},[],{"data":29517,"content":29518,"nodeType":881},{},[29519,29522,29530],{"data":29520,"marks":29521,"value":27468,"nodeType":867},{},[],{"data":29523,"content":29526,"nodeType":3447},{"target":29524},{"sys":29525},{"id":27473,"type":887,"linkType":888},[29527],{"data":29528,"marks":29529,"value":27478,"nodeType":867},{},[],{"data":29531,"marks":29532,"value":27482,"nodeType":867},{},[],{"data":29534,"content":29537,"nodeType":890},{"target":29535},{"sys":29536},{"id":27487,"type":887,"linkType":888},[],{"data":29539,"content":29540,"nodeType":881},{},[29541],{"data":29542,"marks":29543,"value":27495,"nodeType":867},{},[],{"data":29545,"content":29546,"nodeType":3126},{},[29547,29556,29565],{"data":29548,"content":29549,"nodeType":3061},{},[29550],{"data":29551,"content":29552,"nodeType":881},{},[29553],{"data":29554,"marks":29555,"value":27508,"nodeType":867},{},[],{"data":29557,"content":29558,"nodeType":3061},{},[29559],{"data":29560,"content":29561,"nodeType":881},{},[29562],{"data":29563,"marks":29564,"value":27518,"nodeType":867},{},[],{"data":29566,"content":29567,"nodeType":3061},{},[29568],{"data":29569,"content":29570,"nodeType":881},{},[29571],{"data":29572,"marks":29573,"value":27528,"nodeType":867},{},[],{"data":29575,"content":29576,"nodeType":881},{},[29577,29580,29588],{"data":29578,"marks":29579,"value":27535,"nodeType":867},{},[],{"data":29581,"content":29584,"nodeType":3447},{"target":29582},{"sys":29583},{"id":27473,"type":887,"linkType":888},[29585],{"data":29586,"marks":29587,"value":27111,"nodeType":867},{},[],{"data":29589,"marks":29590,"value":1947,"nodeType":867},{},[],{"data":29592,"content":29593,"nodeType":908},{},[],{"data":29595,"content":29596,"nodeType":918},{},[29597],{"data":29598,"marks":29599,"value":27556,"nodeType":867},{},[],{"data":29601,"content":29602,"nodeType":998},{},[29603],{"data":29604,"marks":29605,"value":26601,"nodeType":867},{},[],{"data":29607,"content":29608,"nodeType":881},{},[29609],{"data":29610,"marks":29611,"value":27569,"nodeType":867},{},[],{"data":29613,"content":29614,"nodeType":881},{},[29615,29618,29626],{"data":29616,"marks":29617,"value":27576,"nodeType":867},{},[],{"data":29619,"content":29622,"nodeType":3447},{"target":29620},{"sys":29621},{"id":27581,"type":887,"linkType":888},[29623],{"data":29624,"marks":29625,"value":13597,"nodeType":867},{},[],{"data":29627,"marks":29628,"value":27589,"nodeType":867},{},[],{"data":29630,"content":29631,"nodeType":998},{},[29632],{"data":29633,"marks":29634,"value":26792,"nodeType":867},{},[],{"data":29636,"content":29637,"nodeType":881},{},[29638,29641,29645],{"data":29639,"marks":29640,"value":27602,"nodeType":867},{},[],{"data":29642,"marks":29643,"value":27607,"nodeType":867},{},[29644],{"type":916},{"data":29646,"marks":29647,"value":1947,"nodeType":867},{},[],{"data":29649,"content":29652,"nodeType":890},{"target":29650},{"sys":29651},{"id":27615,"type":887,"linkType":888},[],{"data":29654,"content":29655,"nodeType":881},{},[29656],{"data":29657,"marks":29658,"value":27623,"nodeType":867},{},[],{"data":29660,"content":29661,"nodeType":881},{},[29662],{"data":29663,"marks":29664,"value":27630,"nodeType":867},{},[],{"data":29666,"content":29667,"nodeType":881},{},[29668,29671,29679],{"data":29669,"marks":29670,"value":27637,"nodeType":867},{},[],{"data":29672,"content":29675,"nodeType":3447},{"target":29673},{"sys":29674},{"id":27642,"type":887,"linkType":888},[29676],{"data":29677,"marks":29678,"value":26940,"nodeType":867},{},[],{"data":29680,"marks":29681,"value":1947,"nodeType":867},{},[],{"data":29683,"content":29684,"nodeType":908},{},[],{"data":29686,"content":29687,"nodeType":918},{},[29688],{"data":29689,"marks":29690,"value":10042,"nodeType":867},{},[],{"data":29692,"content":29693,"nodeType":881},{},[29694],{"data":29695,"marks":29696,"value":27665,"nodeType":867},{},[],{"data":29698,"content":29699,"nodeType":881},{},[29700],{"data":29701,"marks":29702,"value":27672,"nodeType":867},{},[],{"data":29704,"content":29705,"nodeType":881},{},[29706,29709,29715,29718,29724],{"data":29707,"marks":29708,"value":27679,"nodeType":867},{},[],{"data":29710,"content":29711,"nodeType":876},{"uri":27682},[29712],{"data":29713,"marks":29714,"value":27687,"nodeType":867},{},[],{"data":29716,"marks":29717,"value":27691,"nodeType":867},{},[],{"data":29719,"content":29720,"nodeType":876},{"uri":4351},[29721],{"data":29722,"marks":29723,"value":3399,"nodeType":867},{},[],{"data":29725,"marks":29726,"value":1947,"nodeType":867},{},[],{"entries":29728},{"inline":29729,"hyperlink":29730,"block":29805},[],[29731,29735,29739,29743,29747,29751,29757,29761,29763,29767,29771,29775,29779,29784,29788,29792,29797,29801],{"sys":29732,"__typename":1742,"title":29733,"slug":29734},{"id":26631},"Introducing our guide to phishing detection evasion techniques","phishing-detection-evasion-launch",{"sys":29736,"__typename":1742,"title":29737,"slug":29738},{"id":26660},"Analysing a malvertising attack targeting business Google accounts intercepted by Push","analysing-a-malvertising-attack-targeting-business-google-accounts",{"sys":29740,"__typename":1742,"title":29741,"slug":29742},{"id":26673},"How Push stopped a high risk LinkedIn spear-phishing attack against a company exec","how-push-stopped-a-high-risk-linkedin-spear-phishing-attack",{"sys":29744,"__typename":1742,"title":29745,"slug":29746},{"id":26701},"Analyzing the latest Sneaky2FA Browser-in-the-Browser phishing page","analyzing-the-latest-sneaky2fa-phishing-page",{"sys":29748,"__typename":1742,"title":29749,"slug":29750},{"id":26935},"Introducing Push Detections: Equipping SecOps and IR teams to stop browser-based attacks","introducing-push-detections",{"sys":29752,"__typename":29753,"title":29754,"slug":29755,"articleId":29756},{"id":27106},"HelpArticle","How does Push detect attacks like ClickFix and FileFix?","how-does-push-detect-attacks-like-clickfix-and-filefix",10141,{"sys":29758,"__typename":1742,"title":29759,"slug":29760},{"id":27142},"6 breaches in 5 months: Why attackers are targeting Jira with stolen credentials","why-attackers-are-targeting-jira-with-stolen-credentials",{"sys":29762,"__typename":1742,"title":15224,"slug":15227},{"id":14277},{"sys":29764,"__typename":1742,"title":29765,"slug":29766},{"id":27198},"Snowflake: Looking back on 2024’s landmark security event","snowflake-retro",{"sys":29768,"__typename":1742,"title":29769,"slug":29770},{"id":27224},"Eliminate false positives with verified stolen credential detections using Push","verified-stolen-credential-detection",{"sys":29772,"__typename":1742,"title":29773,"slug":29774},{"id":27270},"Introducing Push password enforcement — for when weak passwords are still plaguing you","introducing-strong-password-enforcement",{"sys":29776,"__typename":1742,"title":29777,"slug":29778},{"id":27298},"No more hard simple problems: Enforce MFA on third-party apps with Push","enforce-mfa-on-third-party-apps",{"sys":29780,"__typename":29753,"title":29781,"slug":29782,"articleId":29783},{"id":27361},"How does Push protect passwords from being reused or phished?","how-does-push-detect-and-prevent-phishing-attacks",10109,{"sys":29785,"__typename":1742,"title":29786,"slug":29787},{"id":27388},"Don’t let attackers find the keys to your kingdom in a personal password manager","stop-users-saving-corp-creds-into-personal-password-managers",{"sys":29789,"__typename":1742,"title":29790,"slug":29791},{"id":27446},"Guide to secure browser extension deployment","guide-to-secure-browser-extension-deployment",{"sys":29793,"__typename":29753,"title":29794,"slug":29795,"articleId":29796},{"id":27473},"Can Push detect and disable other installed browser extensions?","can-push-detect-other-installed-browser-extensions",10138,{"sys":29798,"__typename":1742,"title":29799,"slug":29800},{"id":27581},"Scattered Spider: TTP evolution in 2025","scattered-spider-ttp-evolution-in-2025",{"sys":29802,"__typename":1742,"title":29803,"slug":29804},{"id":27642},"A simple, browser-based way to protect your help desk against social engineering","employee-identity-verification-codes-release",[29806,29831,29835,29842,29849,29853,29860,29867,29874],{"sys":29807,"__typename":1696,"content":29808,"name":29830,"title":59},{"id":26569},{"json":29809},{"nodeType":1640,"data":29810,"content":29811},{},[29812],{"nodeType":881,"data":29813,"content":29814},{},[29815,29819,29827],{"nodeType":867,"value":29816,"marks":29817,"data":29818},"Learn more about these attacks and the rise of the Scattered Lapsus$ Hunters supergroup in our ",[],{},{"nodeType":876,"data":29820,"content":29822},{"uri":29821},"/blog/scattered-lapsus-hunters/",[29823],{"nodeType":867,"value":29824,"marks":29825,"data":29826},"recent blog post",[],{},{"nodeType":867,"value":1947,"marks":29828,"data":29829},[],{},"Scattered Lapsus$ Hunters blog promo",{"sys":29832,"__typename":1671,"title":29833,"arcadeDemoUrl":29834,"playText":1674},{"id":26837},"Detect and respond to browser-based attacks","https://demo.arcade.software/FDPVuWkgezE91MicpCx7?embed",{"sys":29836,"__typename":1648,"title":29837,"caption":59,"layoutMode":59,"file":29838},{"id":26875},"Detection details slideout w/ timeline etc. - KB 10136",{"url":29839,"width":29840,"height":29841},"https://images.ctfassets.net/y1cdw1ablpvd/6qMAmnkXcJpsp19n7YANTV/b89b76929cc68387121c60ee3c48b0f2/detection_enrichment_example.png",977,758,{"sys":29843,"__typename":1648,"title":29844,"caption":59,"layoutMode":59,"file":29845},{"id":27029},"Clickfix detection block page",{"url":29846,"width":29847,"height":29848},"https://images.ctfassets.net/y1cdw1ablpvd/5QM8JNSvpRk1y7eoYw7CLw/ae9e6aa8b27c067f88cfb600c57c0a34/malicious_copypaste_block_example.png",2568,1604,{"sys":29850,"__typename":1671,"title":29851,"arcadeDemoUrl":29852,"playText":1674},{"id":27093},"ClickFix Feature Release","https://demo.arcade.software/qhzGMAx2q3b6IRlHqBsB?embed",{"sys":29854,"__typename":1648,"title":29855,"caption":59,"layoutMode":59,"file":29856},{"id":27319},"MFA enforcement banner - KB 10121",{"url":29857,"width":29858,"height":29859},"https://images.ctfassets.net/y1cdw1ablpvd/1H45Qj9vCfyQTCMxs8ypU5/6eeb494d24a904058d5635f290569889/Screenshot_2024-12-09_at_1.58.57_PM.png",1438,785,{"sys":29861,"__typename":1648,"title":29862,"caption":59,"layoutMode":59,"file":29863},{"id":27375},"Password protection block screen for end-users - KB 10109",{"url":29864,"width":29865,"height":29866},"https://images.ctfassets.net/y1cdw1ablpvd/5y1AiJEoLP6BveEJwDKhAL/ba22c55dced3ec2842093000ea050fa7/protected_pwd_block_screen_branded_20260420.png",2670,1622,{"sys":29868,"__typename":1648,"title":29869,"caption":59,"layoutMode":59,"file":29870},{"id":27487},"Extension enumeration - KB 10138",{"url":29871,"width":29872,"height":29873},"https://images.ctfassets.net/y1cdw1ablpvd/1dByBmqYgpC9KhPkZoUbGN/0d65ee5ce5abceed6e8538319d83d761/extension_data_table_20251216.png",1480,826,{"sys":29875,"__typename":1648,"title":29876,"caption":59,"layoutMode":59,"file":29877},{"id":27615},"Employee verification codes - Labs - for June 2025 release notes",{"url":29878,"width":29879,"height":29880},"https://images.ctfassets.net/y1cdw1ablpvd/4es73ojyk572RJHuSrAahL/91be55af18fbcfb5f2fc3067497c9746/employee_verification_code_annotated.png",472,241,{"items":29882},[],{},"Push features we built in 2025 to stop browser-based attacks","product-feature",{"items":29887},[29888,30716,31464],{"__typename":1742,"sys":29889,"content":29890,"title":15224,"synopsis":15225,"hashTags":59,"publishedDate":15226,"slug":15227,"tagsCollection":30706,"authorsCollection":30712},{"id":14277},{"json":29891},{"data":29892,"content":29893,"nodeType":1640},{},[29894,29900,29906,29912,29915,29922,29928,29934,29939,29945,29950,29966,29972,29982,29985,29992,29998,30011,30017,30027,30032,30035,30042,30049,30054,30062,30078,30086,30092,30100,30115,30123,30129,30137,30163,30171,30177,30185,30201,30206,30214,30220,30228,30261,30264,30271,30279,30295,30303,30309,30317,30343,30348,30356,30362,30367,30370,30377,30385,30391,30442,30447,30450,30457,30465,30471,30476,30479,30486,30492,30498,30558,30564,30619,30625,30628,30635,30641,30647,30652,30655,30662,30668,30674,30680],{"data":29895,"content":29896,"nodeType":881},{},[29897],{"data":29898,"marks":29899,"value":14288,"nodeType":867},{},[],{"data":29901,"content":29902,"nodeType":881},{},[29903],{"data":29904,"marks":29905,"value":14295,"nodeType":867},{},[],{"data":29907,"content":29908,"nodeType":881},{},[29909],{"data":29910,"marks":29911,"value":14302,"nodeType":867},{},[],{"data":29913,"content":29914,"nodeType":908},{},[],{"data":29916,"content":29917,"nodeType":918},{},[29918],{"data":29919,"marks":29920,"value":14313,"nodeType":867},{},[29921],{"type":916},{"data":29923,"content":29924,"nodeType":881},{},[29925],{"data":29926,"marks":29927,"value":14320,"nodeType":867},{},[],{"data":29929,"content":29930,"nodeType":881},{},[29931],{"data":29932,"marks":29933,"value":14327,"nodeType":867},{},[],{"data":29935,"content":29938,"nodeType":890},{"target":29936},{"sys":29937},{"id":14332,"type":887,"linkType":888},[],{"data":29940,"content":29941,"nodeType":881},{},[29942],{"data":29943,"marks":29944,"value":14340,"nodeType":867},{},[],{"data":29946,"content":29949,"nodeType":890},{"target":29947},{"sys":29948},{"id":14345,"type":887,"linkType":888},[],{"data":29951,"content":29952,"nodeType":881},{},[29953,29956,29963],{"data":29954,"marks":29955,"value":14353,"nodeType":867},{},[],{"data":29957,"content":29958,"nodeType":876},{"uri":5752},[29959],{"data":29960,"marks":29961,"value":14361,"nodeType":867},{},[29962],{"type":1040},{"data":29964,"marks":29965,"value":14365,"nodeType":867},{},[],{"data":29967,"content":29968,"nodeType":881},{},[29969],{"data":29970,"marks":29971,"value":14372,"nodeType":867},{},[],{"data":29973,"content":29974,"nodeType":881},{},[29975,29978],{"data":29976,"marks":29977,"value":14379,"nodeType":867},{},[],{"data":29979,"marks":29980,"value":14384,"nodeType":867},{},[29981],{"type":916},{"data":29983,"content":29984,"nodeType":908},{},[],{"data":29986,"content":29987,"nodeType":918},{},[29988],{"data":29989,"marks":29990,"value":14395,"nodeType":867},{},[29991],{"type":916},{"data":29993,"content":29994,"nodeType":881},{},[29995],{"data":29996,"marks":29997,"value":14402,"nodeType":867},{},[],{"data":29999,"content":30000,"nodeType":881},{},[30001,30004,30008],{"data":30002,"marks":30003,"value":14409,"nodeType":867},{},[],{"data":30005,"marks":30006,"value":14414,"nodeType":867},{},[30007],{"type":916},{"data":30009,"marks":30010,"value":14418,"nodeType":867},{},[],{"data":30012,"content":30013,"nodeType":881},{},[30014],{"data":30015,"marks":30016,"value":14425,"nodeType":867},{},[],{"data":30018,"content":30019,"nodeType":881},{},[30020,30023],{"data":30021,"marks":30022,"value":14432,"nodeType":867},{},[],{"data":30024,"marks":30025,"value":14437,"nodeType":867},{},[30026],{"type":916},{"data":30028,"content":30031,"nodeType":890},{"target":30029},{"sys":30030},{"id":14442,"type":887,"linkType":888},[],{"data":30033,"content":30034,"nodeType":908},{},[],{"data":30036,"content":30037,"nodeType":918},{},[30038],{"data":30039,"marks":30040,"value":14454,"nodeType":867},{},[30041],{"type":916},{"data":30043,"content":30044,"nodeType":998},{},[30045],{"data":30046,"marks":30047,"value":14462,"nodeType":867},{},[30048],{"type":916},{"data":30050,"content":30053,"nodeType":890},{"target":30051},{"sys":30052},{"id":14467,"type":887,"linkType":888},[],{"data":30055,"content":30056,"nodeType":881},{},[30057],{"data":30058,"marks":30059,"value":14477,"nodeType":867},{},[30060,30061],{"type":916},{"type":1040},{"data":30063,"content":30064,"nodeType":881},{},[30065,30068,30075],{"data":30066,"marks":30067,"value":14484,"nodeType":867},{},[],{"data":30069,"content":30070,"nodeType":876},{"uri":14487},[30071],{"data":30072,"marks":30073,"value":14493,"nodeType":867},{},[30074],{"type":1040},{"data":30076,"marks":30077,"value":14497,"nodeType":867},{},[],{"data":30079,"content":30080,"nodeType":881},{},[30081],{"data":30082,"marks":30083,"value":14506,"nodeType":867},{},[30084,30085],{"type":916},{"type":1040},{"data":30087,"content":30088,"nodeType":881},{},[30089],{"data":30090,"marks":30091,"value":14513,"nodeType":867},{},[],{"data":30093,"content":30094,"nodeType":881},{},[30095],{"data":30096,"marks":30097,"value":14522,"nodeType":867},{},[30098,30099],{"type":916},{"type":1040},{"data":30101,"content":30102,"nodeType":881},{},[30103,30106,30112],{"data":30104,"marks":30105,"value":14529,"nodeType":867},{},[],{"data":30107,"content":30108,"nodeType":876},{"uri":14532},[30109],{"data":30110,"marks":30111,"value":14537,"nodeType":867},{},[],{"data":30113,"marks":30114,"value":14541,"nodeType":867},{},[],{"data":30116,"content":30117,"nodeType":881},{},[30118],{"data":30119,"marks":30120,"value":14550,"nodeType":867},{},[30121,30122],{"type":916},{"type":1040},{"data":30124,"content":30125,"nodeType":881},{},[30126],{"data":30127,"marks":30128,"value":14557,"nodeType":867},{},[],{"data":30130,"content":30131,"nodeType":881},{},[30132],{"data":30133,"marks":30134,"value":14566,"nodeType":867},{},[30135,30136],{"type":916},{"type":1040},{"data":30138,"content":30139,"nodeType":881},{},[30140,30143,30150,30153,30160],{"data":30141,"marks":30142,"value":14573,"nodeType":867},{},[],{"data":30144,"content":30145,"nodeType":876},{"uri":14576},[30146],{"data":30147,"marks":30148,"value":14582,"nodeType":867},{},[30149],{"type":1040},{"data":30151,"marks":30152,"value":14586,"nodeType":867},{},[],{"data":30154,"content":30155,"nodeType":876},{"uri":14589},[30156],{"data":30157,"marks":30158,"value":6850,"nodeType":867},{},[30159],{"type":1040},{"data":30161,"marks":30162,"value":14598,"nodeType":867},{},[],{"data":30164,"content":30165,"nodeType":881},{},[30166],{"data":30167,"marks":30168,"value":14607,"nodeType":867},{},[30169,30170],{"type":916},{"type":1040},{"data":30172,"content":30173,"nodeType":881},{},[30174],{"data":30175,"marks":30176,"value":14614,"nodeType":867},{},[],{"data":30178,"content":30179,"nodeType":881},{},[30180],{"data":30181,"marks":30182,"value":14623,"nodeType":867},{},[30183,30184],{"type":916},{"type":1040},{"data":30186,"content":30187,"nodeType":881},{},[30188,30191,30198],{"data":30189,"marks":30190,"value":14630,"nodeType":867},{},[],{"data":30192,"content":30193,"nodeType":876},{"uri":14589},[30194],{"data":30195,"marks":30196,"value":6850,"nodeType":867},{},[30197],{"type":1040},{"data":30199,"marks":30200,"value":14641,"nodeType":867},{},[],{"data":30202,"content":30205,"nodeType":890},{"target":30203},{"sys":30204},{"id":14646,"type":887,"linkType":888},[],{"data":30207,"content":30208,"nodeType":881},{},[30209],{"data":30210,"marks":30211,"value":14656,"nodeType":867},{},[30212,30213],{"type":916},{"type":1040},{"data":30215,"content":30216,"nodeType":881},{},[30217],{"data":30218,"marks":30219,"value":14663,"nodeType":867},{},[],{"data":30221,"content":30222,"nodeType":881},{},[30223],{"data":30224,"marks":30225,"value":14672,"nodeType":867},{},[30226,30227],{"type":916},{"type":1040},{"data":30229,"content":30230,"nodeType":881},{},[30231,30234,30240,30243,30249,30252,30258],{"data":30232,"marks":30233,"value":14679,"nodeType":867},{},[],{"data":30235,"content":30236,"nodeType":876},{"uri":14682},[30237],{"data":30238,"marks":30239,"value":14687,"nodeType":867},{},[],{"data":30241,"marks":30242,"value":2063,"nodeType":867},{},[],{"data":30244,"content":30245,"nodeType":876},{"uri":14693},[30246],{"data":30247,"marks":30248,"value":14698,"nodeType":867},{},[],{"data":30250,"marks":30251,"value":14702,"nodeType":867},{},[],{"data":30253,"content":30254,"nodeType":876},{"uri":3074},[30255],{"data":30256,"marks":30257,"value":14709,"nodeType":867},{},[],{"data":30259,"marks":30260,"value":14713,"nodeType":867},{},[],{"data":30262,"content":30263,"nodeType":908},{},[],{"data":30265,"content":30266,"nodeType":998},{},[30267],{"data":30268,"marks":30269,"value":14724,"nodeType":867},{},[30270],{"type":916},{"data":30272,"content":30273,"nodeType":881},{},[30274],{"data":30275,"marks":30276,"value":14733,"nodeType":867},{},[30277,30278],{"type":916},{"type":1040},{"data":30280,"content":30281,"nodeType":881},{},[30282,30285,30292],{"data":30283,"marks":30284,"value":14740,"nodeType":867},{},[],{"data":30286,"content":30287,"nodeType":876},{"uri":14743},[30288],{"data":30289,"marks":30290,"value":14749,"nodeType":867},{},[30291],{"type":1040},{"data":30293,"marks":30294,"value":14753,"nodeType":867},{},[],{"data":30296,"content":30297,"nodeType":881},{},[30298],{"data":30299,"marks":30300,"value":14762,"nodeType":867},{},[30301,30302],{"type":916},{"type":1040},{"data":30304,"content":30305,"nodeType":881},{},[30306],{"data":30307,"marks":30308,"value":14769,"nodeType":867},{},[],{"data":30310,"content":30311,"nodeType":881},{},[30312],{"data":30313,"marks":30314,"value":14778,"nodeType":867},{},[30315,30316],{"type":916},{"type":1040},{"data":30318,"content":30319,"nodeType":881},{},[30320,30323,30330,30333,30340],{"data":30321,"marks":30322,"value":14785,"nodeType":867},{},[],{"data":30324,"content":30325,"nodeType":876},{"uri":14788},[30326],{"data":30327,"marks":30328,"value":14794,"nodeType":867},{},[30329],{"type":1040},{"data":30331,"marks":30332,"value":14798,"nodeType":867},{},[],{"data":30334,"content":30335,"nodeType":876},{"uri":14801},[30336],{"data":30337,"marks":30338,"value":14807,"nodeType":867},{},[30339],{"type":1040},{"data":30341,"marks":30342,"value":14811,"nodeType":867},{},[],{"data":30344,"content":30347,"nodeType":890},{"target":30345},{"sys":30346},{"id":14816,"type":887,"linkType":888},[],{"data":30349,"content":30350,"nodeType":881},{},[30351],{"data":30352,"marks":30353,"value":14826,"nodeType":867},{},[30354,30355],{"type":916},{"type":1040},{"data":30357,"content":30358,"nodeType":881},{},[30359],{"data":30360,"marks":30361,"value":14833,"nodeType":867},{},[],{"data":30363,"content":30366,"nodeType":890},{"target":30364},{"sys":30365},{"id":14838,"type":887,"linkType":888},[],{"data":30368,"content":30369,"nodeType":908},{},[],{"data":30371,"content":30372,"nodeType":998},{},[30373],{"data":30374,"marks":30375,"value":694,"nodeType":867},{},[30376],{"type":916},{"data":30378,"content":30379,"nodeType":881},{},[30380],{"data":30381,"marks":30382,"value":14858,"nodeType":867},{},[30383,30384],{"type":916},{"type":1040},{"data":30386,"content":30387,"nodeType":881},{},[30388],{"data":30389,"marks":30390,"value":14865,"nodeType":867},{},[],{"data":30392,"content":30393,"nodeType":3126},{},[30394,30407,30420],{"data":30395,"content":30396,"nodeType":3061},{},[30397],{"data":30398,"content":30399,"nodeType":881},{},[30400,30404],{"data":30401,"marks":30402,"value":14879,"nodeType":867},{},[30403],{"type":916},{"data":30405,"marks":30406,"value":14883,"nodeType":867},{},[],{"data":30408,"content":30409,"nodeType":3061},{},[30410],{"data":30411,"content":30412,"nodeType":881},{},[30413,30417],{"data":30414,"marks":30415,"value":14894,"nodeType":867},{},[30416],{"type":916},{"data":30418,"marks":30419,"value":14898,"nodeType":867},{},[],{"data":30421,"content":30422,"nodeType":3061},{},[30423],{"data":30424,"content":30425,"nodeType":881},{},[30426,30430,30433,30439],{"data":30427,"marks":30428,"value":14909,"nodeType":867},{},[30429],{"type":916},{"data":30431,"marks":30432,"value":14913,"nodeType":867},{},[],{"data":30434,"content":30435,"nodeType":876},{"uri":10495},[30436],{"data":30437,"marks":30438,"value":14920,"nodeType":867},{},[],{"data":30440,"marks":30441,"value":14924,"nodeType":867},{},[],{"data":30443,"content":30446,"nodeType":890},{"target":30444},{"sys":30445},{"id":14929,"type":887,"linkType":888},[],{"data":30448,"content":30449,"nodeType":908},{},[],{"data":30451,"content":30452,"nodeType":998},{},[30453],{"data":30454,"marks":30455,"value":699,"nodeType":867},{},[30456],{"type":916},{"data":30458,"content":30459,"nodeType":881},{},[30460],{"data":30461,"marks":30462,"value":14949,"nodeType":867},{},[30463,30464],{"type":916},{"type":1040},{"data":30466,"content":30467,"nodeType":881},{},[30468],{"data":30469,"marks":30470,"value":14956,"nodeType":867},{},[],{"data":30472,"content":30475,"nodeType":890},{"target":30473},{"sys":30474},{"id":14961,"type":887,"linkType":888},[],{"data":30477,"content":30478,"nodeType":908},{},[],{"data":30480,"content":30481,"nodeType":918},{},[30482],{"data":30483,"marks":30484,"value":14973,"nodeType":867},{},[30485],{"type":916},{"data":30487,"content":30488,"nodeType":881},{},[30489],{"data":30490,"marks":30491,"value":14980,"nodeType":867},{},[],{"data":30493,"content":30494,"nodeType":881},{},[30495],{"data":30496,"marks":30497,"value":14987,"nodeType":867},{},[],{"data":30499,"content":30500,"nodeType":3126},{},[30501,30520,30539],{"data":30502,"content":30503,"nodeType":3061},{},[30504],{"data":30505,"content":30506,"nodeType":881},{},[30507,30510,30517],{"data":30508,"marks":30509,"value":15000,"nodeType":867},{},[],{"data":30511,"content":30512,"nodeType":876},{"uri":15003},[30513],{"data":30514,"marks":30515,"value":15009,"nodeType":867},{},[30516],{"type":1040},{"data":30518,"marks":30519,"value":15013,"nodeType":867},{},[],{"data":30521,"content":30522,"nodeType":3061},{},[30523],{"data":30524,"content":30525,"nodeType":881},{},[30526,30529,30536],{"data":30527,"marks":30528,"value":15023,"nodeType":867},{},[],{"data":30530,"content":30531,"nodeType":876},{"uri":15026},[30532],{"data":30533,"marks":30534,"value":15032,"nodeType":867},{},[30535],{"type":1040},{"data":30537,"marks":30538,"value":15013,"nodeType":867},{},[],{"data":30540,"content":30541,"nodeType":3061},{},[30542],{"data":30543,"content":30544,"nodeType":881},{},[30545,30548,30555],{"data":30546,"marks":30547,"value":15045,"nodeType":867},{},[],{"data":30549,"content":30550,"nodeType":876},{"uri":15048},[30551],{"data":30552,"marks":30553,"value":15054,"nodeType":867},{},[30554],{"type":1040},{"data":30556,"marks":30557,"value":15013,"nodeType":867},{},[],{"data":30559,"content":30560,"nodeType":881},{},[30561],{"data":30562,"marks":30563,"value":15064,"nodeType":867},{},[],{"data":30565,"content":30566,"nodeType":3126},{},[30567,30580,30593,30606],{"data":30568,"content":30569,"nodeType":3061},{},[30570],{"data":30571,"content":30572,"nodeType":881},{},[30573,30577],{"data":30574,"marks":30575,"value":15078,"nodeType":867},{},[30576],{"type":916},{"data":30578,"marks":30579,"value":15082,"nodeType":867},{},[],{"data":30581,"content":30582,"nodeType":3061},{},[30583],{"data":30584,"content":30585,"nodeType":881},{},[30586,30590],{"data":30587,"marks":30588,"value":15093,"nodeType":867},{},[30589],{"type":916},{"data":30591,"marks":30592,"value":15097,"nodeType":867},{},[],{"data":30594,"content":30595,"nodeType":3061},{},[30596],{"data":30597,"content":30598,"nodeType":881},{},[30599,30603],{"data":30600,"marks":30601,"value":15108,"nodeType":867},{},[30602],{"type":916},{"data":30604,"marks":30605,"value":15112,"nodeType":867},{},[],{"data":30607,"content":30608,"nodeType":3061},{},[30609],{"data":30610,"content":30611,"nodeType":881},{},[30612,30616],{"data":30613,"marks":30614,"value":15123,"nodeType":867},{},[30615],{"type":916},{"data":30617,"marks":30618,"value":15127,"nodeType":867},{},[],{"data":30620,"content":30621,"nodeType":881},{},[30622],{"data":30623,"marks":30624,"value":15134,"nodeType":867},{},[],{"data":30626,"content":30627,"nodeType":908},{},[],{"data":30629,"content":30630,"nodeType":918},{},[30631],{"data":30632,"marks":30633,"value":15145,"nodeType":867},{},[30634],{"type":916},{"data":30636,"content":30637,"nodeType":881},{},[30638],{"data":30639,"marks":30640,"value":15152,"nodeType":867},{},[],{"data":30642,"content":30643,"nodeType":881},{},[30644],{"data":30645,"marks":30646,"value":15159,"nodeType":867},{},[],{"data":30648,"content":30651,"nodeType":890},{"target":30649},{"sys":30650},{"id":15164,"type":887,"linkType":888},[],{"data":30653,"content":30654,"nodeType":908},{},[],{"data":30656,"content":30657,"nodeType":918},{},[30658],{"data":30659,"marks":30660,"value":6214,"nodeType":867},{},[30661],{"type":916},{"data":30663,"content":30664,"nodeType":881},{},[30665],{"data":30666,"marks":30667,"value":15182,"nodeType":867},{},[],{"data":30669,"content":30670,"nodeType":881},{},[30671],{"data":30672,"marks":30673,"value":15189,"nodeType":867},{},[],{"data":30675,"content":30676,"nodeType":881},{},[30677],{"data":30678,"marks":30679,"value":15196,"nodeType":867},{},[],{"data":30681,"content":30682,"nodeType":881},{},[30683,30686,30693,30696,30703],{"data":30684,"marks":30685,"value":10795,"nodeType":867},{},[],{"data":30687,"content":30688,"nodeType":876},{"uri":10798},[30689],{"data":30690,"marks":30691,"value":10803,"nodeType":867},{},[30692],{"type":1040},{"data":30694,"marks":30695,"value":15213,"nodeType":867},{},[],{"data":30697,"content":30698,"nodeType":876},{"uri":1629},[30699],{"data":30700,"marks":30701,"value":10826,"nodeType":867},{},[30702],{"type":1040},{"data":30704,"marks":30705,"value":1947,"nodeType":867},{},[],{"items":30707},[30708,30710],{"sys":30709,"name":2547},{"id":2546},{"sys":30711,"name":342},{"id":2550},{"items":30713},[30714],{"fullName":849,"firstName":850,"jobTitle":851,"profilePicture":30715},{"url":855},{"__typename":1742,"sys":30717,"content":30718,"title":21104,"synopsis":21105,"hashTags":59,"publishedDate":21106,"slug":21107,"tagsCollection":31454,"authorsCollection":31460},{"id":3644},{"json":30719},{"data":30720,"content":30721,"nodeType":1640},{},[30722,30729,30735,30741,30747,30757,30763,30768,30773,30776,30783,30789,30795,30800,30816,30822,30827,30833,30838,30844,30883,30888,30893,30899,30905,30908,30915,30931,30937,30942,30958,30963,30979,30985,30988,30995,31001,31037,31047,31050,31057,31072,31078,31091,31097,31103,31108,31114,31117,31124,31130,31178,31184,31187,31194,31199,31205,31211,31216,31222,31251,31257,31263,31268,31274,31279,31286,31302,31308,31338,31344,31374,31377,31384,31390,31395,31411,31417,31443,31448],{"data":30723,"content":30724,"nodeType":918},{},[30725],{"data":30726,"marks":30727,"value":20270,"nodeType":867},{},[30728],{"type":916},{"data":30730,"content":30731,"nodeType":881},{},[30732],{"data":30733,"marks":30734,"value":20277,"nodeType":867},{},[],{"data":30736,"content":30737,"nodeType":881},{},[30738],{"data":30739,"marks":30740,"value":20284,"nodeType":867},{},[],{"data":30742,"content":30743,"nodeType":881},{},[30744],{"data":30745,"marks":30746,"value":20291,"nodeType":867},{},[],{"data":30748,"content":30749,"nodeType":881},{},[30750,30754],{"data":30751,"marks":30752,"value":20299,"nodeType":867},{},[30753],{"type":916},{"data":30755,"marks":30756,"value":20303,"nodeType":867},{},[],{"data":30758,"content":30759,"nodeType":881},{},[30760],{"data":30761,"marks":30762,"value":20310,"nodeType":867},{},[],{"data":30764,"content":30767,"nodeType":890},{"target":30765},{"sys":30766},{"id":20315,"type":887,"linkType":888},[],{"data":30769,"content":30772,"nodeType":890},{"target":30770},{"sys":30771},{"id":20321,"type":887,"linkType":888},[],{"data":30774,"content":30775,"nodeType":908},{},[],{"data":30777,"content":30778,"nodeType":918},{},[30779],{"data":30780,"marks":30781,"value":20333,"nodeType":867},{},[30782],{"type":916},{"data":30784,"content":30785,"nodeType":881},{},[30786],{"data":30787,"marks":30788,"value":20340,"nodeType":867},{},[],{"data":30790,"content":30791,"nodeType":881},{},[30792],{"data":30793,"marks":30794,"value":20347,"nodeType":867},{},[],{"data":30796,"content":30799,"nodeType":890},{"target":30797},{"sys":30798},{"id":20352,"type":887,"linkType":888},[],{"data":30801,"content":30802,"nodeType":881},{},[30803,30806,30813],{"data":30804,"marks":30805,"value":20360,"nodeType":867},{},[],{"data":30807,"content":30808,"nodeType":876},{"uri":20363},[30809],{"data":30810,"marks":30811,"value":20369,"nodeType":867},{},[30812],{"type":1040},{"data":30814,"marks":30815,"value":20373,"nodeType":867},{},[],{"data":30817,"content":30818,"nodeType":881},{},[30819],{"data":30820,"marks":30821,"value":20380,"nodeType":867},{},[],{"data":30823,"content":30826,"nodeType":890},{"target":30824},{"sys":30825},{"id":20385,"type":887,"linkType":888},[],{"data":30828,"content":30829,"nodeType":881},{},[30830],{"data":30831,"marks":30832,"value":20393,"nodeType":867},{},[],{"data":30834,"content":30837,"nodeType":890},{"target":30835},{"sys":30836},{"id":20398,"type":887,"linkType":888},[],{"data":30839,"content":30840,"nodeType":881},{},[30841],{"data":30842,"marks":30843,"value":20406,"nodeType":867},{},[],{"data":30845,"content":30846,"nodeType":3126},{},[30847,30856,30865,30874],{"data":30848,"content":30849,"nodeType":3061},{},[30850],{"data":30851,"content":30852,"nodeType":881},{},[30853],{"data":30854,"marks":30855,"value":20419,"nodeType":867},{},[],{"data":30857,"content":30858,"nodeType":3061},{},[30859],{"data":30860,"content":30861,"nodeType":881},{},[30862],{"data":30863,"marks":30864,"value":20429,"nodeType":867},{},[],{"data":30866,"content":30867,"nodeType":3061},{},[30868],{"data":30869,"content":30870,"nodeType":881},{},[30871],{"data":30872,"marks":30873,"value":20439,"nodeType":867},{},[],{"data":30875,"content":30876,"nodeType":3061},{},[30877],{"data":30878,"content":30879,"nodeType":881},{},[30880],{"data":30881,"marks":30882,"value":20449,"nodeType":867},{},[],{"data":30884,"content":30887,"nodeType":890},{"target":30885},{"sys":30886},{"id":20454,"type":887,"linkType":888},[],{"data":30889,"content":30892,"nodeType":890},{"target":30890},{"sys":30891},{"id":20460,"type":887,"linkType":888},[],{"data":30894,"content":30895,"nodeType":881},{},[30896],{"data":30897,"marks":30898,"value":20468,"nodeType":867},{},[],{"data":30900,"content":30901,"nodeType":881},{},[30902],{"data":30903,"marks":30904,"value":20475,"nodeType":867},{},[],{"data":30906,"content":30907,"nodeType":908},{},[],{"data":30909,"content":30910,"nodeType":918},{},[30911],{"data":30912,"marks":30913,"value":20486,"nodeType":867},{},[30914],{"type":916},{"data":30916,"content":30917,"nodeType":881},{},[30918,30921,30928],{"data":30919,"marks":30920,"value":20493,"nodeType":867},{},[],{"data":30922,"content":30923,"nodeType":876},{"uri":20496},[30924],{"data":30925,"marks":30926,"value":20502,"nodeType":867},{},[30927],{"type":1040},{"data":30929,"marks":30930,"value":20506,"nodeType":867},{},[],{"data":30932,"content":30933,"nodeType":881},{},[30934],{"data":30935,"marks":30936,"value":20513,"nodeType":867},{},[],{"data":30938,"content":30941,"nodeType":890},{"target":30939},{"sys":30940},{"id":20518,"type":887,"linkType":888},[],{"data":30943,"content":30944,"nodeType":881},{},[30945,30948,30955],{"data":30946,"marks":30947,"value":20526,"nodeType":867},{},[],{"data":30949,"content":30950,"nodeType":876},{"uri":20529},[30951],{"data":30952,"marks":30953,"value":20535,"nodeType":867},{},[30954],{"type":1040},{"data":30956,"marks":30957,"value":1947,"nodeType":867},{},[],{"data":30959,"content":30962,"nodeType":890},{"target":30960},{"sys":30961},{"id":20543,"type":887,"linkType":888},[],{"data":30964,"content":30965,"nodeType":881},{},[30966,30969,30976],{"data":30967,"marks":30968,"value":20551,"nodeType":867},{},[],{"data":30970,"content":30971,"nodeType":876},{"uri":20554},[30972],{"data":30973,"marks":30974,"value":441,"nodeType":867},{},[30975],{"type":1040},{"data":30977,"marks":30978,"value":20563,"nodeType":867},{},[],{"data":30980,"content":30981,"nodeType":881},{},[30982],{"data":30983,"marks":30984,"value":20570,"nodeType":867},{},[],{"data":30986,"content":30987,"nodeType":908},{},[],{"data":30989,"content":30990,"nodeType":918},{},[30991],{"data":30992,"marks":30993,"value":20581,"nodeType":867},{},[30994],{"type":916},{"data":30996,"content":30997,"nodeType":881},{},[30998],{"data":30999,"marks":31000,"value":20588,"nodeType":867},{},[],{"data":31002,"content":31003,"nodeType":881},{},[31004,31007,31014,31017,31024,31027,31034],{"data":31005,"marks":31006,"value":20595,"nodeType":867},{},[],{"data":31008,"content":31009,"nodeType":876},{"uri":20598},[31010],{"data":31011,"marks":31012,"value":20604,"nodeType":867},{},[31013],{"type":1040},{"data":31015,"marks":31016,"value":2063,"nodeType":867},{},[],{"data":31018,"content":31019,"nodeType":876},{"uri":20610},[31020],{"data":31021,"marks":31022,"value":13838,"nodeType":867},{},[31023],{"type":1040},{"data":31025,"marks":31026,"value":20619,"nodeType":867},{},[],{"data":31028,"content":31029,"nodeType":876},{"uri":20622},[31030],{"data":31031,"marks":31032,"value":20628,"nodeType":867},{},[31033],{"type":1040},{"data":31035,"marks":31036,"value":20632,"nodeType":867},{},[],{"data":31038,"content":31039,"nodeType":881},{},[31040,31043],{"data":31041,"marks":31042,"value":20639,"nodeType":867},{},[],{"data":31044,"marks":31045,"value":20644,"nodeType":867},{},[31046],{"type":916},{"data":31048,"content":31049,"nodeType":908},{},[],{"data":31051,"content":31052,"nodeType":918},{},[31053],{"data":31054,"marks":31055,"value":20655,"nodeType":867},{},[31056],{"type":916},{"data":31058,"content":31059,"nodeType":881},{},[31060,31063,31069],{"data":31061,"marks":31062,"value":20662,"nodeType":867},{},[],{"data":31064,"content":31065,"nodeType":876},{"uri":2267},[31066],{"data":31067,"marks":31068,"value":16396,"nodeType":867},{},[],{"data":31070,"marks":31071,"value":20672,"nodeType":867},{},[],{"data":31073,"content":31074,"nodeType":881},{},[31075],{"data":31076,"marks":31077,"value":20679,"nodeType":867},{},[],{"data":31079,"content":31080,"nodeType":881},{},[31081,31084,31088],{"data":31082,"marks":31083,"value":20686,"nodeType":867},{},[],{"data":31085,"marks":31086,"value":20691,"nodeType":867},{},[31087],{"type":916},{"data":31089,"marks":31090,"value":20695,"nodeType":867},{},[],{"data":31092,"content":31093,"nodeType":881},{},[31094],{"data":31095,"marks":31096,"value":20702,"nodeType":867},{},[],{"data":31098,"content":31099,"nodeType":881},{},[31100],{"data":31101,"marks":31102,"value":20709,"nodeType":867},{},[],{"data":31104,"content":31107,"nodeType":890},{"target":31105},{"sys":31106},{"id":20714,"type":887,"linkType":888},[],{"data":31109,"content":31110,"nodeType":881},{},[31111],{"data":31112,"marks":31113,"value":20722,"nodeType":867},{},[],{"data":31115,"content":31116,"nodeType":908},{},[],{"data":31118,"content":31119,"nodeType":918},{},[31120],{"data":31121,"marks":31122,"value":20733,"nodeType":867},{},[31123],{"type":916},{"data":31125,"content":31126,"nodeType":881},{},[31127],{"data":31128,"marks":31129,"value":20740,"nodeType":867},{},[],{"data":31131,"content":31132,"nodeType":3126},{},[31133,31142,31151,31160,31169],{"data":31134,"content":31135,"nodeType":3061},{},[31136],{"data":31137,"content":31138,"nodeType":881},{},[31139],{"data":31140,"marks":31141,"value":20753,"nodeType":867},{},[],{"data":31143,"content":31144,"nodeType":3061},{},[31145],{"data":31146,"content":31147,"nodeType":881},{},[31148],{"data":31149,"marks":31150,"value":20763,"nodeType":867},{},[],{"data":31152,"content":31153,"nodeType":3061},{},[31154],{"data":31155,"content":31156,"nodeType":881},{},[31157],{"data":31158,"marks":31159,"value":20773,"nodeType":867},{},[],{"data":31161,"content":31162,"nodeType":3061},{},[31163],{"data":31164,"content":31165,"nodeType":881},{},[31166],{"data":31167,"marks":31168,"value":20783,"nodeType":867},{},[],{"data":31170,"content":31171,"nodeType":3061},{},[31172],{"data":31173,"content":31174,"nodeType":881},{},[31175],{"data":31176,"marks":31177,"value":20793,"nodeType":867},{},[],{"data":31179,"content":31180,"nodeType":881},{},[31181],{"data":31182,"marks":31183,"value":20800,"nodeType":867},{},[],{"data":31185,"content":31186,"nodeType":908},{},[],{"data":31188,"content":31189,"nodeType":918},{},[31190],{"data":31191,"marks":31192,"value":20811,"nodeType":867},{},[31193],{"type":916},{"data":31195,"content":31198,"nodeType":890},{"target":31196},{"sys":31197},{"id":20816,"type":887,"linkType":888},[],{"data":31200,"content":31201,"nodeType":881},{},[31202],{"data":31203,"marks":31204,"value":20824,"nodeType":867},{},[],{"data":31206,"content":31207,"nodeType":881},{},[31208],{"data":31209,"marks":31210,"value":20831,"nodeType":867},{},[],{"data":31212,"content":31215,"nodeType":890},{"target":31213},{"sys":31214},{"id":20836,"type":887,"linkType":888},[],{"data":31217,"content":31218,"nodeType":881},{},[31219],{"data":31220,"marks":31221,"value":20844,"nodeType":867},{},[],{"data":31223,"content":31224,"nodeType":3126},{},[31225,31238],{"data":31226,"content":31227,"nodeType":3061},{},[31228],{"data":31229,"content":31230,"nodeType":881},{},[31231,31235],{"data":31232,"marks":31233,"value":20858,"nodeType":867},{},[31234],{"type":916},{"data":31236,"marks":31237,"value":20862,"nodeType":867},{},[],{"data":31239,"content":31240,"nodeType":3061},{},[31241],{"data":31242,"content":31243,"nodeType":881},{},[31244,31248],{"data":31245,"marks":31246,"value":20873,"nodeType":867},{},[31247],{"type":916},{"data":31249,"marks":31250,"value":20877,"nodeType":867},{},[],{"data":31252,"content":31253,"nodeType":881},{},[31254],{"data":31255,"marks":31256,"value":20884,"nodeType":867},{},[],{"data":31258,"content":31259,"nodeType":881},{},[31260],{"data":31261,"marks":31262,"value":20891,"nodeType":867},{},[],{"data":31264,"content":31267,"nodeType":890},{"target":31265},{"sys":31266},{"id":20896,"type":887,"linkType":888},[],{"data":31269,"content":31270,"nodeType":881},{},[31271],{"data":31272,"marks":31273,"value":20904,"nodeType":867},{},[],{"data":31275,"content":31278,"nodeType":890},{"target":31276},{"sys":31277},{"id":20909,"type":887,"linkType":888},[],{"data":31280,"content":31281,"nodeType":998},{},[31282],{"data":31283,"marks":31284,"value":20918,"nodeType":867},{},[31285],{"type":916},{"data":31287,"content":31288,"nodeType":881},{},[31289,31292,31299],{"data":31290,"marks":31291,"value":9997,"nodeType":867},{},[],{"data":31293,"content":31294,"nodeType":876},{"uri":2392},[31295],{"data":31296,"marks":31297,"value":2397,"nodeType":867},{},[31298],{"type":1040},{"data":31300,"marks":31301,"value":20935,"nodeType":867},{},[],{"data":31303,"content":31304,"nodeType":881},{},[31305],{"data":31306,"marks":31307,"value":20942,"nodeType":867},{},[],{"data":31309,"content":31310,"nodeType":3126},{},[31311,31320,31329],{"data":31312,"content":31313,"nodeType":3061},{},[31314],{"data":31315,"content":31316,"nodeType":881},{},[31317],{"data":31318,"marks":31319,"value":20955,"nodeType":867},{},[],{"data":31321,"content":31322,"nodeType":3061},{},[31323],{"data":31324,"content":31325,"nodeType":881},{},[31326],{"data":31327,"marks":31328,"value":20965,"nodeType":867},{},[],{"data":31330,"content":31331,"nodeType":3061},{},[31332],{"data":31333,"content":31334,"nodeType":881},{},[31335],{"data":31336,"marks":31337,"value":20975,"nodeType":867},{},[],{"data":31339,"content":31340,"nodeType":881},{},[31341],{"data":31342,"marks":31343,"value":20982,"nodeType":867},{},[],{"data":31345,"content":31346,"nodeType":3126},{},[31347,31356,31365],{"data":31348,"content":31349,"nodeType":3061},{},[31350],{"data":31351,"content":31352,"nodeType":881},{},[31353],{"data":31354,"marks":31355,"value":20995,"nodeType":867},{},[],{"data":31357,"content":31358,"nodeType":3061},{},[31359],{"data":31360,"content":31361,"nodeType":881},{},[31362],{"data":31363,"marks":31364,"value":21005,"nodeType":867},{},[],{"data":31366,"content":31367,"nodeType":3061},{},[31368],{"data":31369,"content":31370,"nodeType":881},{},[31371],{"data":31372,"marks":31373,"value":21015,"nodeType":867},{},[],{"data":31375,"content":31376,"nodeType":908},{},[],{"data":31378,"content":31379,"nodeType":918},{},[31380],{"data":31381,"marks":31382,"value":21026,"nodeType":867},{},[31383],{"type":916},{"data":31385,"content":31386,"nodeType":881},{},[31387],{"data":31388,"marks":31389,"value":21033,"nodeType":867},{},[],{"data":31391,"content":31394,"nodeType":890},{"target":31392},{"sys":31393},{"id":21038,"type":887,"linkType":888},[],{"data":31396,"content":31397,"nodeType":881},{},[31398,31401,31408],{"data":31399,"marks":31400,"value":21046,"nodeType":867},{},[],{"data":31402,"content":31403,"nodeType":876},{"uri":2267},[31404],{"data":31405,"marks":31406,"value":21054,"nodeType":867},{},[31407],{"type":1040},{"data":31409,"marks":31410,"value":21058,"nodeType":867},{},[],{"data":31412,"content":31413,"nodeType":881},{},[31414],{"data":31415,"marks":31416,"value":21065,"nodeType":867},{},[],{"data":31418,"content":31419,"nodeType":881},{},[31420,31423,31430,31433,31440],{"data":31421,"marks":31422,"value":10795,"nodeType":867},{},[],{"data":31424,"content":31425,"nodeType":876},{"uri":10798},[31426],{"data":31427,"marks":31428,"value":10803,"nodeType":867},{},[31429],{"type":1040},{"data":31431,"marks":31432,"value":15213,"nodeType":867},{},[],{"data":31434,"content":31435,"nodeType":876},{"uri":1629},[31436],{"data":31437,"marks":31438,"value":10826,"nodeType":867},{},[31439],{"type":1040},{"data":31441,"marks":31442,"value":1947,"nodeType":867},{},[],{"data":31444,"content":31447,"nodeType":890},{"target":31445},{"sys":31446},{"id":21096,"type":887,"linkType":888},[],{"data":31449,"content":31450,"nodeType":881},{},[31451],{"data":31452,"marks":31453,"value":21,"nodeType":867},{},[],{"items":31455},[31456,31458],{"sys":31457,"name":2547},{"id":2546},{"sys":31459,"name":342},{"id":2550},{"items":31461},[31462],{"fullName":15937,"firstName":15938,"jobTitle":15939,"profilePicture":31463},{"url":15943},{"__typename":1742,"sys":31465,"content":31467,"title":32134,"synopsis":32135,"hashTags":59,"publishedDate":32136,"slug":32137,"tagsCollection":32138,"authorsCollection":32144},{"id":31466},"5CqV6e5wfHsfEVczkWSerZ",{"json":31468},{"data":31469,"content":31470,"nodeType":1640},{},[31471,31477,31484,31491,31494,31502,31509,31516,31523,31619,31625,31631,31637,31644,31651,31670,31673,31681,31688,31695,31702,31745,31752,31797,31803,31810,31817,31820,31828,31835,31842,31849,31919,31925,31931,31963,31969,31988,31994,32001,32008,32014,32017,32025,32032,32065,32072,32075,32083,32090,32097,32123,32128],{"data":31472,"content":31476,"nodeType":890},{"target":31473},{"sys":31474},{"id":31475,"type":887,"linkType":888},"1axcGwWxeKxDMk8jOWhYT6",[],{"data":31478,"content":31479,"nodeType":881},{},[31480],{"data":31481,"marks":31482,"value":31483,"nodeType":867},{},[],"2025 saw a huge amount of attacker innovation when it comes to phishing attacks, as attackers continue to double down on identity-based techniques. The continual evolution of phishing means it remains one of the most effective methods available to attackers today — in fact, it’s arguably more effective than ever. ",{"data":31485,"content":31486,"nodeType":881},{},[31487],{"data":31488,"marks":31489,"value":31490,"nodeType":867},{},[],"Let’s take a closer look at the key trends that defined phishing attacks in 2025, and what these changes mean for security teams heading into 2026. ",{"data":31492,"content":31493,"nodeType":908},{},[],{"data":31495,"content":31496,"nodeType":918},{},[31497],{"data":31498,"marks":31499,"value":31501,"nodeType":867},{},[31500],{"type":916},"#1: Phishing goes omni-channel",{"data":31503,"content":31504,"nodeType":881},{},[31505],{"data":31506,"marks":31507,"value":31508,"nodeType":867},{},[],"We’ve been talking about the rise of non-email phishing for some time now, but 2025 was the year phishing truly went omni-channel. ",{"data":31510,"content":31511,"nodeType":881},{},[31512],{"data":31513,"marks":31514,"value":31515,"nodeType":867},{},[],"Although most of the industry’s data on phishing still comes from email security vendors and tools, the picture is starting to change. Roughly 1 in 3 phishing attacks detected by Push Security were delivered outside of email. ",{"data":31517,"content":31518,"nodeType":881},{},[31519],{"data":31520,"marks":31521,"value":31522,"nodeType":867},{},[],"There are many examples of phishing campaigns operated outside of email, with LinkedIn DMs and Google Search being the top channels we identified. Notable campaigns include:",{"data":31524,"content":31525,"nodeType":3126},{},[31526,31548,31570],{"data":31527,"content":31528,"nodeType":3061},{},[31529],{"data":31530,"content":31531,"nodeType":881},{},[31532,31535,31544],{"data":31533,"marks":31534,"value":21,"nodeType":867},{},[],{"data":31536,"content":31538,"nodeType":876},{"uri":31537},"https://pushsecurity.com/blog/how-push-stopped-a-high-risk-linkedin-spear-phishing-attack",[31539],{"data":31540,"marks":31541,"value":31543,"nodeType":867},{},[31542],{"type":1040},"A targeted campaign against tech company Exec’s",{"data":31545,"marks":31546,"value":31547,"nodeType":867},{},[]," delivered via compromised accounts on LinkedIn from other employees of the same organization, framed as an investment opportunity.",{"data":31549,"content":31550,"nodeType":3061},{},[31551],{"data":31552,"content":31553,"nodeType":881},{},[31554,31557,31566],{"data":31555,"marks":31556,"value":21,"nodeType":867},{},[],{"data":31558,"content":31560,"nodeType":876},{"uri":31559},"https://pushsecurity.com/blog/new-phishing-campaign-identified-targeting-linkedin-users",[31561],{"data":31562,"marks":31563,"value":31565,"nodeType":867},{},[31564],{"type":1040},"A campaign posing as a South American investment fund",{"data":31567,"marks":31568,"value":31569,"nodeType":867},{},[]," offering the opportunity to join the fund. ",{"data":31571,"content":31572,"nodeType":3061},{},[31573],{"data":31574,"content":31575,"nodeType":881},{},[31576,31580,31589,31593,31602,31606,31615],{"data":31577,"marks":31578,"value":31579,"nodeType":867},{},[],"Several malvertising campaigns capturing users searching for key search terms such as “",{"data":31581,"content":31583,"nodeType":876},{"uri":31582},"https://pushsecurity.com/blog/analysing-a-malvertising-attack-targeting-business-google-accounts",[31584],{"data":31585,"marks":31586,"value":31588,"nodeType":867},{},[31587],{"type":1040},"Google Ads",{"data":31590,"marks":31591,"value":31592,"nodeType":867},{},[],"”, “",{"data":31594,"content":31596,"nodeType":876},{"uri":31595},"https://pushsecurity.com/blog/analysing-a-sophisticated-google-malvertising-attack",[31597],{"data":31598,"marks":31599,"value":31601,"nodeType":867},{},[31600],{"type":1040},"TradingView",{"data":31603,"marks":31604,"value":31605,"nodeType":867},{},[],"” and “",{"data":31607,"content":31609,"nodeType":876},{"uri":31608},"https://pushsecurity.com/blog/investigating-a-recent-malvertising-campaign-targeting-onfido-customers",[31610],{"data":31611,"marks":31612,"value":31614,"nodeType":867},{},[31613],{"type":1040},"Onfido",{"data":31616,"marks":31617,"value":31618,"nodeType":867},{},[],"”. ",{"data":31620,"content":31624,"nodeType":890},{"target":31621},{"sys":31622},{"id":31623,"type":887,"linkType":888},"3LjyZooaJQ83eJt8DRX9bP",[],{"data":31626,"content":31630,"nodeType":890},{"target":31627},{"sys":31628},{"id":31629,"type":887,"linkType":888},"644LdQYjRHerpKU5pCGv1n",[],{"data":31632,"content":31636,"nodeType":890},{"target":31633},{"sys":31634},{"id":31635,"type":887,"linkType":888},"3anCGk5A4AOVH1t9dr1xKp",[],{"data":31638,"content":31639,"nodeType":881},{},[31640],{"data":31641,"marks":31642,"value":31643,"nodeType":867},{},[],"Phishing via non-email channels has a number of advantages. With email being the best protected phishing vector, it sidesteps these controls entirely. There’s no need to build up your sender reputation, find ways to trick content analysis engines, or hope your message doesn’t end up in the spam folder.",{"data":31645,"content":31646,"nodeType":881},{},[31647],{"data":31648,"marks":31649,"value":31650,"nodeType":867},{},[],"In comparison, non-email vectors have practically no screening, your security team has no visibility, and users are less likely to anticipate possible phishing. It’s arguable that a company Exec is more likely to engage with a LinkedIn DM from a reputable account than a cold email. And social media apps do nothing to analyse messages for phishing links. (And because of the limitations of URL-based checks when it comes to today’s multi-stage phishing attacks, this would be extremely difficult even if they tried). ",{"data":31652,"content":31653,"nodeType":881},{},[31654,31658,31666],{"data":31655,"marks":31656,"value":31657,"nodeType":867},{},[],"Search engines also present a huge opportunity for attackers, whether they’re compromising existing, high reputation sites, spinning up malicious ads, or simply vibe coding their own SEO-optimized websites. This is an effective way to launch “watering hole” style attacks, casting a wide net to harvest credentials and account access that can be re-sold to other criminals for a fee, or leveraged by partners in the cybercriminal ecosystem as part of major cyber breaches (such as the recent attacks by the “",{"data":31659,"content":31661,"nodeType":876},{"uri":31660},"https://pushsecurity.com/blog/scattered-lapsus-hunters",[31662],{"data":31663,"marks":31664,"value":3056,"nodeType":867},{},[31665],{"type":1040},{"data":31667,"marks":31668,"value":31669,"nodeType":867},{},[],"” criminal collective, all of which began with identity-based initial access). ",{"data":31671,"content":31672,"nodeType":908},{},[],{"data":31674,"content":31675,"nodeType":918},{},[31676],{"data":31677,"marks":31678,"value":31680,"nodeType":867},{},[31679],{"type":916},"#2: Criminal PhaaS kits dominate",{"data":31682,"content":31683,"nodeType":881},{},[31684],{"data":31685,"marks":31686,"value":31687,"nodeType":867},{},[],"The vast majority of phishing attacks today use a reverse proxy. This means they are capable of bypassing most forms of MFA because a session is created and stolen in real time as part of the attack. There is no downside to this approach compared to the basic credential phishing that was the norm more than a decade ago.",{"data":31689,"content":31690,"nodeType":881},{},[31691],{"data":31692,"marks":31693,"value":31694,"nodeType":867},{},[],"These Attacker-in-the-Middle attacks are powered by criminal Phishing-as-a-Service (PhaaS) kits such as Tycoon, NakedPages, Sneaky2FA, Flowerstorm, Salty2FA, along with various Evilginx variations (nominally a tool for red teamers, but widely used by attackers). ",{"data":31696,"content":31697,"nodeType":881},{},[31698],{"data":31699,"marks":31700,"value":31701,"nodeType":867},{},[],"PhaaS kits are incredibly important to cybercrime because they make sophisticated and continuously evolving capabilities available to the criminal marketplace, lowering the barrier to entry for criminals running advanced phishing campaigns. This is not unique to phishing: Ransomware-as-a-Service, Credential Stuffing-as-a-Service, and many more for-hire tools and services exist for criminals to use for a fee. ",{"data":31703,"content":31704,"nodeType":881},{},[31705,31709,31718,31721,31728,31732,31741],{"data":31706,"marks":31707,"value":31708,"nodeType":867},{},[],"This competitive environment has fueled attacker innovation, resulting in an environment in which MFA-bypass is table stakes, phishing-resistant authentication is being circumvented through ",{"data":31710,"content":31712,"nodeType":876},{"uri":31711},"https://pushsecurity.com/blog/mfa-downgrade-attacks",[31713],{"data":31714,"marks":31715,"value":31717,"nodeType":867},{},[31716],{"type":1040},"downgrade attacks",{"data":31719,"marks":31720,"value":15362,"nodeType":867},{},[],{"data":31722,"content":31723,"nodeType":876},{"uri":2267},[31724],{"data":31725,"marks":31726,"value":16396,"nodeType":867},{},[31727],{"type":1040},{"data":31729,"marks":31730,"value":31731,"nodeType":867},{},[]," are being used to circumvent security tools — from email scanners, to web-crawling security tools, to web proxies analyzing network traffic. It also means that when new capabilities emerge — such as ",{"data":31733,"content":31735,"nodeType":876},{"uri":31734},"https://pushsecurity.com/blog/analyzing-the-latest-sneaky2fa-phishing-page",[31736],{"data":31737,"marks":31738,"value":31740,"nodeType":867},{},[31739],{"type":1040},"Browser-in-the-Browser",{"data":31742,"marks":31743,"value":31744,"nodeType":867},{},[]," — these are quickly integrated into a range of phishing kits. ",{"data":31746,"content":31747,"nodeType":881},{},[31748],{"data":31749,"marks":31750,"value":31751,"nodeType":867},{},[],"Some of the most prevalent detection evasion methods we’ve seen this year are:",{"data":31753,"content":31754,"nodeType":3126},{},[31755,31765,31775],{"data":31756,"content":31757,"nodeType":3061},{},[31758],{"data":31759,"content":31760,"nodeType":881},{},[31761],{"data":31762,"marks":31763,"value":31764,"nodeType":867},{},[],"Widespread use of bot protection. Every phishing page today comes with either a custom CAPTCHA or Cloudflare Turnstile (legitimate and fake versions) designed to block web-crawling security bots from being able to analyse phishing pages. ",{"data":31766,"content":31767,"nodeType":3061},{},[31768],{"data":31769,"content":31770,"nodeType":881},{},[31771],{"data":31772,"marks":31773,"value":31774,"nodeType":867},{},[],"Extensive redirect chains between the initial link seeded out to the victim, and the actual malicious page hosting phishing content, designed to bury phishing sites among several legitimate pages. ",{"data":31776,"content":31777,"nodeType":3061},{},[31778],{"data":31779,"content":31780,"nodeType":881},{},[31781,31785,31793],{"data":31782,"marks":31783,"value":31784,"nodeType":867},{},[],"Multi-stage page loading performed client-side via JavaScript. This means that pages are ",{"data":31786,"content":31787,"nodeType":876},{"uri":20363},[31788],{"data":31789,"marks":31790,"value":31792,"nodeType":867},{},[31791],{"type":1040},"conditionally loaded",{"data":31794,"marks":31795,"value":31796,"nodeType":867},{},[],", and if conditions aren’t met, malicious content isn’t served — so the page looks clean. This also means that most of the malicious activity is happening locally, without creating web requests that can be analysed by network traffic analysis tools (e.g. web proxies). ",{"data":31798,"content":31802,"nodeType":890},{"target":31799},{"sys":31800},{"id":31801,"type":887,"linkType":888},"5LLgjhCexTYd5OlHuptv3n",[],{"data":31804,"content":31805,"nodeType":881},{},[31806],{"data":31807,"marks":31808,"value":31809,"nodeType":867},{},[],"This contributes to an environment where phishing is going undetected for extended periods of time. Even when a page is flagged, it’s trivial for attackers to dynamically serve up different phishing pages from the same benign chain of URLs used in the attack. ",{"data":31811,"content":31812,"nodeType":881},{},[31813],{"data":31814,"marks":31815,"value":31816,"nodeType":867},{},[],"This is all to say that the old-school approach to URL blocking bad sites is becoming much harder and leaves you two steps behind attackers at all times.",{"data":31818,"content":31819,"nodeType":908},{},[],{"data":31821,"content":31822,"nodeType":918},{},[31823],{"data":31824,"marks":31825,"value":31827,"nodeType":867},{},[31826],{"type":916},"#3: Attackers find ways around phishing-resistant authentication (and other security controls)",{"data":31829,"content":31830,"nodeType":881},{},[31831],{"data":31832,"marks":31833,"value":31834,"nodeType":867},{},[],"We already mentioned that MFA downgrade has been an area of focus for security researchers and attackers. But phishing-resistant authentication methods (i.e. passkeys) remain effective so long as the phishing-resistant factor is the only possible login factor, and there are no backup methods enabled for the account. (Though because of the logistical issues of having just one factor, this is fairly uncommon.) ",{"data":31836,"content":31837,"nodeType":881},{},[31838],{"data":31839,"marks":31840,"value":31841,"nodeType":867},{},[],"Equally, access control policies can be applied on larger enterprise apps and cloud platforms to reduce the risk of unauthorized access (although these can be tricky to implement and maintain without error).",{"data":31843,"content":31844,"nodeType":881},{},[31845],{"data":31846,"marks":31847,"value":31848,"nodeType":867},{},[],"In any case, attackers are considering all eventualities and looking for alternative ways into accounts that are less well protected. This mainly involves attackers circumventing the standard authentication process, through techniques such as:",{"data":31850,"content":31851,"nodeType":3126},{},[31852,31879,31904],{"data":31853,"content":31854,"nodeType":3061},{},[31855],{"data":31856,"content":31857,"nodeType":881},{},[31858,31861,31870,31875],{"data":31859,"marks":31860,"value":21,"nodeType":867},{},[],{"data":31862,"content":31863,"nodeType":876},{"uri":25732},[31864],{"data":31865,"marks":31866,"value":31869,"nodeType":867},{},[31867,31868],{"type":1040},{"type":916},"Consent phishing",{"data":31871,"marks":31872,"value":31874,"nodeType":867},{},[31873],{"type":916},":",{"data":31876,"marks":31877,"value":31878,"nodeType":867},{},[]," Tricking victims into connecting malicious OAuth apps into their app tenant.",{"data":31880,"content":31881,"nodeType":3061},{},[31882],{"data":31883,"content":31884,"nodeType":881},{},[31885,31888,31896,31900],{"data":31886,"marks":31887,"value":21,"nodeType":867},{},[],{"data":31889,"content":31890,"nodeType":876},{"uri":15982},[31891],{"data":31892,"marks":31893,"value":360,"nodeType":867},{},[31894,31895],{"type":1040},{"type":916},{"data":31897,"marks":31898,"value":1426,"nodeType":867},{},[31899],{"type":916},{"data":31901,"marks":31902,"value":31903,"nodeType":867},{},[],"The same as consent phishing, but authorizing through the device code flow designed for device logins that cannot support OAuth, by providing a substitute passcode. ",{"data":31905,"content":31906,"nodeType":3061},{},[31907],{"data":31908,"content":31909,"nodeType":881},{},[31910,31915],{"data":31911,"marks":31912,"value":31914,"nodeType":867},{},[31913],{"type":916},"Malicious browser extensions: ",{"data":31916,"marks":31917,"value":31918,"nodeType":867},{},[],"Tricking victims into installing a malicious extension (or hijacking an existing one) to steal credentials and cookies from the browser. ",{"data":31920,"content":31924,"nodeType":890},{"target":31921},{"sys":31922},{"id":31923,"type":887,"linkType":888},"75lMjdJtq9APebTaF2hQ1b",[],{"data":31926,"content":31930,"nodeType":890},{"target":31927},{"sys":31928},{"id":31929,"type":887,"linkType":888},"4KWwlg8PsuyAud8i5tpWfH",[],{"data":31932,"content":31933,"nodeType":881},{},[31934,31938,31946,31950,31959],{"data":31935,"marks":31936,"value":31937,"nodeType":867},{},[],"Another technique that attackers are using to steal credentials and sessions is ",{"data":31939,"content":31941,"nodeType":876},{"uri":31940},"https://pushsecurity.com/blog/the-most-advanced-clickfix-yet",[31942],{"data":31943,"marks":31944,"value":315,"nodeType":867},{},[31945],{"type":1040},{"data":31947,"marks":31948,"value":31949,"nodeType":867},{},[],". ClickFix was the ",{"data":31951,"content":31953,"nodeType":876},{"uri":31952},"https://cdn-dynmedia-1.microsoft.com/is/content/microsoftcorp/microsoft/msc/documents/presentations/CSR/Microsoft-Digital-Defense-Report-2025.pdf#page=36",[31954],{"data":31955,"marks":31956,"value":31958,"nodeType":867},{},[31957],{"type":1040},"top initial access vector detected by Microsoft last year",{"data":31960,"marks":31961,"value":31962,"nodeType":867},{},[],", involved in 47% of attacks. While not a traditional phishing attack, this sees attackers socially engineer users into running malicious code on their machine, typically deploying remote access tools and infostealer malware. Infostealers are then used to harvest credentials and cookies for initial access to various apps and services. ",{"data":31964,"content":31968,"nodeType":890},{"target":31965},{"sys":31966},{"id":31967,"type":887,"linkType":888},"4cC9GbPoKFmYUJgbkbeOLs",[],{"data":31970,"content":31971,"nodeType":881},{},[31972,31976,31984],{"data":31973,"marks":31974,"value":31975,"nodeType":867},{},[],"Push Security researchers have also discovered a brand new technique dubbed ",{"data":31977,"content":31979,"nodeType":876},{"uri":31978},"https://pushsecurity.com/blog/consentfix",[31980],{"data":31981,"marks":31982,"value":1312,"nodeType":867},{},[31983],{"type":1040},{"data":31985,"marks":31986,"value":31987,"nodeType":867},{},[]," — a browser-native version of ClickFix that results in an OAuth connection being established to the target app, simply by copying and pasting a legitimate URL containing OAuth key material. ",{"data":31989,"content":31993,"nodeType":890},{"target":31990},{"sys":31991},{"id":31992,"type":887,"linkType":888},"4bdqleePd53oK5v5uEUFbr",[],{"data":31995,"content":31996,"nodeType":881},{},[31997],{"data":31998,"marks":31999,"value":32000,"nodeType":867},{},[],"This is even more dangerous than ClickFix as it is entirely browser-native — removing the endpoint detection surface (and strong security controls like EDR) from the equation entirely. And in the particular case spotted by Push, the attackers targeted Azure CLI — a first-party Microsoft app that has special permissions and can’t be restricted like third-party apps. ",{"data":32002,"content":32003,"nodeType":881},{},[32004],{"data":32005,"marks":32006,"value":32007,"nodeType":867},{},[],"Really, there are lots of different techniques attackers can use to take over accounts on key business applications — it’s outdated to think of phishing as being locked in to passwords, MFA, and the standard authentication flow. ",{"data":32009,"content":32013,"nodeType":890},{"target":32010},{"sys":32011},{"id":32012,"type":887,"linkType":888},"74S97KkuFzI48UwXw3msTq",[],{"data":32015,"content":32016,"nodeType":908},{},[],{"data":32018,"content":32019,"nodeType":918},{},[32020],{"data":32021,"marks":32022,"value":32024,"nodeType":867},{},[32023],{"type":916},"Guidance for security teams in 2026",{"data":32026,"content":32027,"nodeType":881},{},[32028],{"data":32029,"marks":32030,"value":32031,"nodeType":867},{},[],"To tackle phishing in 2026, security teams need to change their threat model for phishing, and acknowledge that:",{"data":32033,"content":32034,"nodeType":3126},{},[32035,32045,32055],{"data":32036,"content":32037,"nodeType":3061},{},[32038],{"data":32039,"content":32040,"nodeType":881},{},[32041],{"data":32042,"marks":32043,"value":32044,"nodeType":867},{},[],"It’s not enough to protect email as your main anti-phishing surface",{"data":32046,"content":32047,"nodeType":3061},{},[32048],{"data":32049,"content":32050,"nodeType":881},{},[32051],{"data":32052,"marks":32053,"value":32054,"nodeType":867},{},[],"Network and traffic monitoring tools aren’t keeping up with modern phishing pages",{"data":32056,"content":32057,"nodeType":3061},{},[32058],{"data":32059,"content":32060,"nodeType":881},{},[32061],{"data":32062,"marks":32063,"value":32064,"nodeType":867},{},[],"Phishing-resistant authentication, even if perfectly implemented, doesn’t make you immune",{"data":32066,"content":32067,"nodeType":881},{},[32068],{"data":32069,"marks":32070,"value":32071,"nodeType":867},{},[],"Detection and response is key. But most organizations have significant visibility gaps.",{"data":32073,"content":32074,"nodeType":908},{},[],{"data":32076,"content":32077,"nodeType":918},{},[32078],{"data":32079,"marks":32080,"value":32082,"nodeType":867},{},[32081],{"type":916},"Solving the detection gap in the browser",{"data":32084,"content":32085,"nodeType":881},{},[32086],{"data":32087,"marks":32088,"value":32089,"nodeType":867},{},[],"One thing that these attacks have in common is that they all take place in the web browser, targeting users as they go about their work on the internet. That makes it the perfect place to detect and respond to these attacks. But right now, the browser is a blind-spot for most security teams.",{"data":32091,"content":32092,"nodeType":881},{},[32093],{"data":32094,"marks":32095,"value":32096,"nodeType":867},{},[],"Push Security’s browser-based security platform provides comprehensive detection and response capabilities against the leading cause of breaches. Push blocks browser-based attacks like AiTM phishing, credential stuffing, malicious browser extensions, ClickFix, and session hijacking. You don’t need to wait until it all goes wrong — you can also use Push to proactively find and fix vulnerabilities across the apps that your employees use, like ghost logins, SSO coverage gaps, MFA gaps, vulnerable passwords, and more to harden your identity attack surface.",{"data":32098,"content":32099,"nodeType":881},{},[32100,32103,32110,32113,32120],{"data":32101,"marks":32102,"value":10795,"nodeType":867},{},[],{"data":32104,"content":32105,"nodeType":876},{"uri":10798},[32106],{"data":32107,"marks":32108,"value":10803,"nodeType":867},{},[32109],{"type":1040},{"data":32111,"marks":32112,"value":15213,"nodeType":867},{},[],{"data":32114,"content":32115,"nodeType":876},{"uri":1629},[32116],{"data":32117,"marks":32118,"value":10826,"nodeType":867},{},[32119],{"type":1040},{"data":32121,"marks":32122,"value":1947,"nodeType":867},{},[],{"data":32124,"content":32127,"nodeType":890},{"target":32125},{"sys":32126},{"id":21096,"type":887,"linkType":888},[],{"data":32129,"content":32130,"nodeType":881},{},[32131],{"data":32132,"marks":32133,"value":21,"nodeType":867},{},[],"2025’s top phishing trends — and what they mean for your 2026 security strategy","Analyzing the key trends that defined phishing attacks in 2025, and what these changes mean for security teams heading into 2026. ","2025-12-15T00:00:00.000Z","2025-top-phishing-trends",{"items":32139},[32140,32142],{"sys":32141,"name":342},{"id":2550},{"sys":32143,"name":2547},{"id":2546},{"items":32145},[32146],{"fullName":849,"firstName":850,"jobTitle":851,"profilePicture":32147},{"url":855},"blog/taking-the-fight-to-attackers-top-features-of-2025",{"json":32150},{"data":32151,"content":32152,"nodeType":1640},{},[32153],{"data":32154,"content":32155,"nodeType":881},{},[32156],{"data":32157,"marks":32158,"value":32159,"nodeType":867},{},[],"Here’s how real-world attacks and our own R&D informed what we built this year.",{"id":26409,"publishedAt":32161},"2026-08-13T09:35:11.859Z",{"items":32163},[32164,32166],{"sys":32165,"name":342},{"id":2550},{"sys":32167,"name":2547},{"id":2546},{"items":32169},[32170,32172,32174,32176,32178,32180,32182,32184,32186,32188,32190,32192,32194,32196,32198,32200,32202,32204,32206,32208,32210],{"sys":32171,"name":279,"slug":280,"tier":31},{"id":276},{"sys":32173,"name":413,"slug":414,"tier":31},{"id":410},{"sys":32175,"name":297,"slug":298,"tier":31},{"id":294},{"sys":32177,"name":519,"slug":520,"tier":31},{"id":516},{"sys":32179,"name":342,"slug":343,"tier":31},{"id":339},{"sys":32181,"name":642,"slug":643,"tier":31},{"id":639},{"sys":32183,"name":261,"slug":262,"tier":45},{"id":258},{"sys":32185,"name":315,"slug":316,"tier":45},{"id":312},{"sys":32187,"name":333,"slug":334,"tier":45},{"id":330},{"sys":32189,"name":571,"slug":572,"tier":45},{"id":568},{"sys":32191,"name":466,"slug":467,"tier":45},{"id":463},{"sys":32193,"name":511,"slug":512,"tier":45},{"id":508},{"sys":32195,"name":288,"slug":289,"tier":45},{"id":285},{"sys":32197,"name":395,"slug":396,"tier":45},{"id":392},{"sys":32199,"name":502,"slug":503,"tier":45},{"id":499},{"sys":32201,"name":457,"slug":458,"tier":45},{"id":454},{"sys":32203,"name":607,"slug":608,"tier":45},{"id":604},{"sys":32205,"name":422,"slug":423,"tier":45},{"id":419},{"sys":32207,"name":324,"slug":325,"tier":45},{"id":321},{"sys":32209,"name":440,"slug":441,"tier":45},{"id":437},{"sys":32211,"name":650,"slug":651,"tier":45},{"id":647},"PWDqfteh31QCBsZyOGrfwwzxqUSG34OMPlcKf1pr6SQ",{"id":32214,"title":15224,"authorsCollection":32215,"content":32220,"extension":228,"faqItemsCollection":33205,"faqTitle":59,"featured":6,"hashTags":59,"meta":33207,"metaTitle":33208,"ogImage":59,"postType":8156,"publishedDate":15226,"relatedBlogPostsCollection":33209,"slug":15227,"stem":35002,"subtitle":59,"summary":35003,"synopsis":15225,"sys":35014,"tagsCollection":35016,"topicsCollection":35022,"__hash__":35054},"blog/blog/scattered-lapsus-hunters.json",{"items":32216},[32217],{"fullName":849,"firstName":850,"jobTitle":851,"socialLinks":32218,"profilePicture":32219},[853],{"url":855},{"json":32221,"links":33036},{"data":32222,"content":32223,"nodeType":1640},{},[32224,32230,32236,32242,32245,32252,32258,32264,32269,32275,32280,32296,32302,32312,32315,32322,32328,32341,32347,32357,32362,32365,32372,32379,32384,32392,32408,32416,32422,32430,32445,32453,32459,32467,32493,32501,32507,32515,32531,32536,32544,32550,32558,32591,32594,32601,32609,32625,32633,32639,32647,32673,32678,32686,32692,32697,32700,32707,32715,32721,32772,32777,32780,32787,32795,32801,32806,32809,32816,32822,32828,32888,32894,32949,32955,32958,32965,32971,32977,32982,32985,32992,32998,33004,33010],{"data":32225,"content":32226,"nodeType":881},{},[32227],{"data":32228,"marks":32229,"value":14288,"nodeType":867},{},[],{"data":32231,"content":32232,"nodeType":881},{},[32233],{"data":32234,"marks":32235,"value":14295,"nodeType":867},{},[],{"data":32237,"content":32238,"nodeType":881},{},[32239],{"data":32240,"marks":32241,"value":14302,"nodeType":867},{},[],{"data":32243,"content":32244,"nodeType":908},{},[],{"data":32246,"content":32247,"nodeType":918},{},[32248],{"data":32249,"marks":32250,"value":14313,"nodeType":867},{},[32251],{"type":916},{"data":32253,"content":32254,"nodeType":881},{},[32255],{"data":32256,"marks":32257,"value":14320,"nodeType":867},{},[],{"data":32259,"content":32260,"nodeType":881},{},[32261],{"data":32262,"marks":32263,"value":14327,"nodeType":867},{},[],{"data":32265,"content":32268,"nodeType":890},{"target":32266},{"sys":32267},{"id":14332,"type":887,"linkType":888},[],{"data":32270,"content":32271,"nodeType":881},{},[32272],{"data":32273,"marks":32274,"value":14340,"nodeType":867},{},[],{"data":32276,"content":32279,"nodeType":890},{"target":32277},{"sys":32278},{"id":14345,"type":887,"linkType":888},[],{"data":32281,"content":32282,"nodeType":881},{},[32283,32286,32293],{"data":32284,"marks":32285,"value":14353,"nodeType":867},{},[],{"data":32287,"content":32288,"nodeType":876},{"uri":5752},[32289],{"data":32290,"marks":32291,"value":14361,"nodeType":867},{},[32292],{"type":1040},{"data":32294,"marks":32295,"value":14365,"nodeType":867},{},[],{"data":32297,"content":32298,"nodeType":881},{},[32299],{"data":32300,"marks":32301,"value":14372,"nodeType":867},{},[],{"data":32303,"content":32304,"nodeType":881},{},[32305,32308],{"data":32306,"marks":32307,"value":14379,"nodeType":867},{},[],{"data":32309,"marks":32310,"value":14384,"nodeType":867},{},[32311],{"type":916},{"data":32313,"content":32314,"nodeType":908},{},[],{"data":32316,"content":32317,"nodeType":918},{},[32318],{"data":32319,"marks":32320,"value":14395,"nodeType":867},{},[32321],{"type":916},{"data":32323,"content":32324,"nodeType":881},{},[32325],{"data":32326,"marks":32327,"value":14402,"nodeType":867},{},[],{"data":32329,"content":32330,"nodeType":881},{},[32331,32334,32338],{"data":32332,"marks":32333,"value":14409,"nodeType":867},{},[],{"data":32335,"marks":32336,"value":14414,"nodeType":867},{},[32337],{"type":916},{"data":32339,"marks":32340,"value":14418,"nodeType":867},{},[],{"data":32342,"content":32343,"nodeType":881},{},[32344],{"data":32345,"marks":32346,"value":14425,"nodeType":867},{},[],{"data":32348,"content":32349,"nodeType":881},{},[32350,32353],{"data":32351,"marks":32352,"value":14432,"nodeType":867},{},[],{"data":32354,"marks":32355,"value":14437,"nodeType":867},{},[32356],{"type":916},{"data":32358,"content":32361,"nodeType":890},{"target":32359},{"sys":32360},{"id":14442,"type":887,"linkType":888},[],{"data":32363,"content":32364,"nodeType":908},{},[],{"data":32366,"content":32367,"nodeType":918},{},[32368],{"data":32369,"marks":32370,"value":14454,"nodeType":867},{},[32371],{"type":916},{"data":32373,"content":32374,"nodeType":998},{},[32375],{"data":32376,"marks":32377,"value":14462,"nodeType":867},{},[32378],{"type":916},{"data":32380,"content":32383,"nodeType":890},{"target":32381},{"sys":32382},{"id":14467,"type":887,"linkType":888},[],{"data":32385,"content":32386,"nodeType":881},{},[32387],{"data":32388,"marks":32389,"value":14477,"nodeType":867},{},[32390,32391],{"type":916},{"type":1040},{"data":32393,"content":32394,"nodeType":881},{},[32395,32398,32405],{"data":32396,"marks":32397,"value":14484,"nodeType":867},{},[],{"data":32399,"content":32400,"nodeType":876},{"uri":14487},[32401],{"data":32402,"marks":32403,"value":14493,"nodeType":867},{},[32404],{"type":1040},{"data":32406,"marks":32407,"value":14497,"nodeType":867},{},[],{"data":32409,"content":32410,"nodeType":881},{},[32411],{"data":32412,"marks":32413,"value":14506,"nodeType":867},{},[32414,32415],{"type":916},{"type":1040},{"data":32417,"content":32418,"nodeType":881},{},[32419],{"data":32420,"marks":32421,"value":14513,"nodeType":867},{},[],{"data":32423,"content":32424,"nodeType":881},{},[32425],{"data":32426,"marks":32427,"value":14522,"nodeType":867},{},[32428,32429],{"type":916},{"type":1040},{"data":32431,"content":32432,"nodeType":881},{},[32433,32436,32442],{"data":32434,"marks":32435,"value":14529,"nodeType":867},{},[],{"data":32437,"content":32438,"nodeType":876},{"uri":14532},[32439],{"data":32440,"marks":32441,"value":14537,"nodeType":867},{},[],{"data":32443,"marks":32444,"value":14541,"nodeType":867},{},[],{"data":32446,"content":32447,"nodeType":881},{},[32448],{"data":32449,"marks":32450,"value":14550,"nodeType":867},{},[32451,32452],{"type":916},{"type":1040},{"data":32454,"content":32455,"nodeType":881},{},[32456],{"data":32457,"marks":32458,"value":14557,"nodeType":867},{},[],{"data":32460,"content":32461,"nodeType":881},{},[32462],{"data":32463,"marks":32464,"value":14566,"nodeType":867},{},[32465,32466],{"type":916},{"type":1040},{"data":32468,"content":32469,"nodeType":881},{},[32470,32473,32480,32483,32490],{"data":32471,"marks":32472,"value":14573,"nodeType":867},{},[],{"data":32474,"content":32475,"nodeType":876},{"uri":14576},[32476],{"data":32477,"marks":32478,"value":14582,"nodeType":867},{},[32479],{"type":1040},{"data":32481,"marks":32482,"value":14586,"nodeType":867},{},[],{"data":32484,"content":32485,"nodeType":876},{"uri":14589},[32486],{"data":32487,"marks":32488,"value":6850,"nodeType":867},{},[32489],{"type":1040},{"data":32491,"marks":32492,"value":14598,"nodeType":867},{},[],{"data":32494,"content":32495,"nodeType":881},{},[32496],{"data":32497,"marks":32498,"value":14607,"nodeType":867},{},[32499,32500],{"type":916},{"type":1040},{"data":32502,"content":32503,"nodeType":881},{},[32504],{"data":32505,"marks":32506,"value":14614,"nodeType":867},{},[],{"data":32508,"content":32509,"nodeType":881},{},[32510],{"data":32511,"marks":32512,"value":14623,"nodeType":867},{},[32513,32514],{"type":916},{"type":1040},{"data":32516,"content":32517,"nodeType":881},{},[32518,32521,32528],{"data":32519,"marks":32520,"value":14630,"nodeType":867},{},[],{"data":32522,"content":32523,"nodeType":876},{"uri":14589},[32524],{"data":32525,"marks":32526,"value":6850,"nodeType":867},{},[32527],{"type":1040},{"data":32529,"marks":32530,"value":14641,"nodeType":867},{},[],{"data":32532,"content":32535,"nodeType":890},{"target":32533},{"sys":32534},{"id":14646,"type":887,"linkType":888},[],{"data":32537,"content":32538,"nodeType":881},{},[32539],{"data":32540,"marks":32541,"value":14656,"nodeType":867},{},[32542,32543],{"type":916},{"type":1040},{"data":32545,"content":32546,"nodeType":881},{},[32547],{"data":32548,"marks":32549,"value":14663,"nodeType":867},{},[],{"data":32551,"content":32552,"nodeType":881},{},[32553],{"data":32554,"marks":32555,"value":14672,"nodeType":867},{},[32556,32557],{"type":916},{"type":1040},{"data":32559,"content":32560,"nodeType":881},{},[32561,32564,32570,32573,32579,32582,32588],{"data":32562,"marks":32563,"value":14679,"nodeType":867},{},[],{"data":32565,"content":32566,"nodeType":876},{"uri":14682},[32567],{"data":32568,"marks":32569,"value":14687,"nodeType":867},{},[],{"data":32571,"marks":32572,"value":2063,"nodeType":867},{},[],{"data":32574,"content":32575,"nodeType":876},{"uri":14693},[32576],{"data":32577,"marks":32578,"value":14698,"nodeType":867},{},[],{"data":32580,"marks":32581,"value":14702,"nodeType":867},{},[],{"data":32583,"content":32584,"nodeType":876},{"uri":3074},[32585],{"data":32586,"marks":32587,"value":14709,"nodeType":867},{},[],{"data":32589,"marks":32590,"value":14713,"nodeType":867},{},[],{"data":32592,"content":32593,"nodeType":908},{},[],{"data":32595,"content":32596,"nodeType":998},{},[32597],{"data":32598,"marks":32599,"value":14724,"nodeType":867},{},[32600],{"type":916},{"data":32602,"content":32603,"nodeType":881},{},[32604],{"data":32605,"marks":32606,"value":14733,"nodeType":867},{},[32607,32608],{"type":916},{"type":1040},{"data":32610,"content":32611,"nodeType":881},{},[32612,32615,32622],{"data":32613,"marks":32614,"value":14740,"nodeType":867},{},[],{"data":32616,"content":32617,"nodeType":876},{"uri":14743},[32618],{"data":32619,"marks":32620,"value":14749,"nodeType":867},{},[32621],{"type":1040},{"data":32623,"marks":32624,"value":14753,"nodeType":867},{},[],{"data":32626,"content":32627,"nodeType":881},{},[32628],{"data":32629,"marks":32630,"value":14762,"nodeType":867},{},[32631,32632],{"type":916},{"type":1040},{"data":32634,"content":32635,"nodeType":881},{},[32636],{"data":32637,"marks":32638,"value":14769,"nodeType":867},{},[],{"data":32640,"content":32641,"nodeType":881},{},[32642],{"data":32643,"marks":32644,"value":14778,"nodeType":867},{},[32645,32646],{"type":916},{"type":1040},{"data":32648,"content":32649,"nodeType":881},{},[32650,32653,32660,32663,32670],{"data":32651,"marks":32652,"value":14785,"nodeType":867},{},[],{"data":32654,"content":32655,"nodeType":876},{"uri":14788},[32656],{"data":32657,"marks":32658,"value":14794,"nodeType":867},{},[32659],{"type":1040},{"data":32661,"marks":32662,"value":14798,"nodeType":867},{},[],{"data":32664,"content":32665,"nodeType":876},{"uri":14801},[32666],{"data":32667,"marks":32668,"value":14807,"nodeType":867},{},[32669],{"type":1040},{"data":32671,"marks":32672,"value":14811,"nodeType":867},{},[],{"data":32674,"content":32677,"nodeType":890},{"target":32675},{"sys":32676},{"id":14816,"type":887,"linkType":888},[],{"data":32679,"content":32680,"nodeType":881},{},[32681],{"data":32682,"marks":32683,"value":14826,"nodeType":867},{},[32684,32685],{"type":916},{"type":1040},{"data":32687,"content":32688,"nodeType":881},{},[32689],{"data":32690,"marks":32691,"value":14833,"nodeType":867},{},[],{"data":32693,"content":32696,"nodeType":890},{"target":32694},{"sys":32695},{"id":14838,"type":887,"linkType":888},[],{"data":32698,"content":32699,"nodeType":908},{},[],{"data":32701,"content":32702,"nodeType":998},{},[32703],{"data":32704,"marks":32705,"value":694,"nodeType":867},{},[32706],{"type":916},{"data":32708,"content":32709,"nodeType":881},{},[32710],{"data":32711,"marks":32712,"value":14858,"nodeType":867},{},[32713,32714],{"type":916},{"type":1040},{"data":32716,"content":32717,"nodeType":881},{},[32718],{"data":32719,"marks":32720,"value":14865,"nodeType":867},{},[],{"data":32722,"content":32723,"nodeType":3126},{},[32724,32737,32750],{"data":32725,"content":32726,"nodeType":3061},{},[32727],{"data":32728,"content":32729,"nodeType":881},{},[32730,32734],{"data":32731,"marks":32732,"value":14879,"nodeType":867},{},[32733],{"type":916},{"data":32735,"marks":32736,"value":14883,"nodeType":867},{},[],{"data":32738,"content":32739,"nodeType":3061},{},[32740],{"data":32741,"content":32742,"nodeType":881},{},[32743,32747],{"data":32744,"marks":32745,"value":14894,"nodeType":867},{},[32746],{"type":916},{"data":32748,"marks":32749,"value":14898,"nodeType":867},{},[],{"data":32751,"content":32752,"nodeType":3061},{},[32753],{"data":32754,"content":32755,"nodeType":881},{},[32756,32760,32763,32769],{"data":32757,"marks":32758,"value":14909,"nodeType":867},{},[32759],{"type":916},{"data":32761,"marks":32762,"value":14913,"nodeType":867},{},[],{"data":32764,"content":32765,"nodeType":876},{"uri":10495},[32766],{"data":32767,"marks":32768,"value":14920,"nodeType":867},{},[],{"data":32770,"marks":32771,"value":14924,"nodeType":867},{},[],{"data":32773,"content":32776,"nodeType":890},{"target":32774},{"sys":32775},{"id":14929,"type":887,"linkType":888},[],{"data":32778,"content":32779,"nodeType":908},{},[],{"data":32781,"content":32782,"nodeType":998},{},[32783],{"data":32784,"marks":32785,"value":699,"nodeType":867},{},[32786],{"type":916},{"data":32788,"content":32789,"nodeType":881},{},[32790],{"data":32791,"marks":32792,"value":14949,"nodeType":867},{},[32793,32794],{"type":916},{"type":1040},{"data":32796,"content":32797,"nodeType":881},{},[32798],{"data":32799,"marks":32800,"value":14956,"nodeType":867},{},[],{"data":32802,"content":32805,"nodeType":890},{"target":32803},{"sys":32804},{"id":14961,"type":887,"linkType":888},[],{"data":32807,"content":32808,"nodeType":908},{},[],{"data":32810,"content":32811,"nodeType":918},{},[32812],{"data":32813,"marks":32814,"value":14973,"nodeType":867},{},[32815],{"type":916},{"data":32817,"content":32818,"nodeType":881},{},[32819],{"data":32820,"marks":32821,"value":14980,"nodeType":867},{},[],{"data":32823,"content":32824,"nodeType":881},{},[32825],{"data":32826,"marks":32827,"value":14987,"nodeType":867},{},[],{"data":32829,"content":32830,"nodeType":3126},{},[32831,32850,32869],{"data":32832,"content":32833,"nodeType":3061},{},[32834],{"data":32835,"content":32836,"nodeType":881},{},[32837,32840,32847],{"data":32838,"marks":32839,"value":15000,"nodeType":867},{},[],{"data":32841,"content":32842,"nodeType":876},{"uri":15003},[32843],{"data":32844,"marks":32845,"value":15009,"nodeType":867},{},[32846],{"type":1040},{"data":32848,"marks":32849,"value":15013,"nodeType":867},{},[],{"data":32851,"content":32852,"nodeType":3061},{},[32853],{"data":32854,"content":32855,"nodeType":881},{},[32856,32859,32866],{"data":32857,"marks":32858,"value":15023,"nodeType":867},{},[],{"data":32860,"content":32861,"nodeType":876},{"uri":15026},[32862],{"data":32863,"marks":32864,"value":15032,"nodeType":867},{},[32865],{"type":1040},{"data":32867,"marks":32868,"value":15013,"nodeType":867},{},[],{"data":32870,"content":32871,"nodeType":3061},{},[32872],{"data":32873,"content":32874,"nodeType":881},{},[32875,32878,32885],{"data":32876,"marks":32877,"value":15045,"nodeType":867},{},[],{"data":32879,"content":32880,"nodeType":876},{"uri":15048},[32881],{"data":32882,"marks":32883,"value":15054,"nodeType":867},{},[32884],{"type":1040},{"data":32886,"marks":32887,"value":15013,"nodeType":867},{},[],{"data":32889,"content":32890,"nodeType":881},{},[32891],{"data":32892,"marks":32893,"value":15064,"nodeType":867},{},[],{"data":32895,"content":32896,"nodeType":3126},{},[32897,32910,32923,32936],{"data":32898,"content":32899,"nodeType":3061},{},[32900],{"data":32901,"content":32902,"nodeType":881},{},[32903,32907],{"data":32904,"marks":32905,"value":15078,"nodeType":867},{},[32906],{"type":916},{"data":32908,"marks":32909,"value":15082,"nodeType":867},{},[],{"data":32911,"content":32912,"nodeType":3061},{},[32913],{"data":32914,"content":32915,"nodeType":881},{},[32916,32920],{"data":32917,"marks":32918,"value":15093,"nodeType":867},{},[32919],{"type":916},{"data":32921,"marks":32922,"value":15097,"nodeType":867},{},[],{"data":32924,"content":32925,"nodeType":3061},{},[32926],{"data":32927,"content":32928,"nodeType":881},{},[32929,32933],{"data":32930,"marks":32931,"value":15108,"nodeType":867},{},[32932],{"type":916},{"data":32934,"marks":32935,"value":15112,"nodeType":867},{},[],{"data":32937,"content":32938,"nodeType":3061},{},[32939],{"data":32940,"content":32941,"nodeType":881},{},[32942,32946],{"data":32943,"marks":32944,"value":15123,"nodeType":867},{},[32945],{"type":916},{"data":32947,"marks":32948,"value":15127,"nodeType":867},{},[],{"data":32950,"content":32951,"nodeType":881},{},[32952],{"data":32953,"marks":32954,"value":15134,"nodeType":867},{},[],{"data":32956,"content":32957,"nodeType":908},{},[],{"data":32959,"content":32960,"nodeType":918},{},[32961],{"data":32962,"marks":32963,"value":15145,"nodeType":867},{},[32964],{"type":916},{"data":32966,"content":32967,"nodeType":881},{},[32968],{"data":32969,"marks":32970,"value":15152,"nodeType":867},{},[],{"data":32972,"content":32973,"nodeType":881},{},[32974],{"data":32975,"marks":32976,"value":15159,"nodeType":867},{},[],{"data":32978,"content":32981,"nodeType":890},{"target":32979},{"sys":32980},{"id":15164,"type":887,"linkType":888},[],{"data":32983,"content":32984,"nodeType":908},{},[],{"data":32986,"content":32987,"nodeType":918},{},[32988],{"data":32989,"marks":32990,"value":6214,"nodeType":867},{},[32991],{"type":916},{"data":32993,"content":32994,"nodeType":881},{},[32995],{"data":32996,"marks":32997,"value":15182,"nodeType":867},{},[],{"data":32999,"content":33000,"nodeType":881},{},[33001],{"data":33002,"marks":33003,"value":15189,"nodeType":867},{},[],{"data":33005,"content":33006,"nodeType":881},{},[33007],{"data":33008,"marks":33009,"value":15196,"nodeType":867},{},[],{"data":33011,"content":33012,"nodeType":881},{},[33013,33016,33023,33026,33033],{"data":33014,"marks":33015,"value":10795,"nodeType":867},{},[],{"data":33017,"content":33018,"nodeType":876},{"uri":10798},[33019],{"data":33020,"marks":33021,"value":10803,"nodeType":867},{},[33022],{"type":1040},{"data":33024,"marks":33025,"value":15213,"nodeType":867},{},[],{"data":33027,"content":33028,"nodeType":876},{"uri":1629},[33029],{"data":33030,"marks":33031,"value":10826,"nodeType":867},{},[33032],{"type":1040},{"data":33034,"marks":33035,"value":1947,"nodeType":867},{},[],{"entries":33037},{"hyperlink":33038,"inline":33039,"block":33040},[],[],[33041,33055,33069,33072,33099,33113,33127,33152,33166,33180],{"sys":33042,"__typename":1696,"content":33043,"name":33054,"title":59},{"id":14332},{"json":33044},{"nodeType":1640,"data":33045,"content":33046},{},[33047],{"nodeType":881,"data":33048,"content":33049},{},[33050],{"nodeType":867,"value":33051,"marks":33052,"data":33053},"The MGM hack resulted in a 36-hour outage, a $100M hit to its Q3 results, one-time cyber consulting fees in the region of $10M, and a class-action lawsuit later settled for $45M. Less is known about Caesars, except that a ransom of $15M was paid in an attempt to prevent stolen data being leaked online.",[],{},"SLH insight box 1",{"sys":33056,"__typename":1696,"content":33057,"name":33068,"title":59},{"id":14345},{"json":33058},{"nodeType":1640,"data":33059,"content":33060},{},[33061],{"nodeType":881,"data":33062,"content":33063},{},[33064],{"nodeType":867,"value":33065,"marks":33066,"data":33067},"The Marks & Spencer ransomware breach resulted in online shopping services being taken offline, stores running low on products, £300M in lost profits, and almost £1B wiped off the company’s stock market valuation at one stage. Co-op proactively pulled the plug on their network to prevent further damage, lessening the impact to a still-sizeable £107m in lost profits.",[],{},"SLH insight box 2",{"sys":33070,"__typename":1648,"title":25474,"caption":25474,"layoutMode":59,"file":33071},{"id":14442},{"url":25476,"width":25477,"height":25478},{"sys":33073,"__typename":1696,"content":33074,"name":33098,"title":59},{"id":14467},{"json":33075},{"nodeType":1640,"data":33076,"content":33077},{},[33078],{"nodeType":881,"data":33079,"content":33080},{},[33081,33085,33094],{"nodeType":867,"value":33082,"marks":33083,"data":33084},"Stolen credentials were, and still are, one of the easiest ways in for an attacker. They're one of the most abundant resources available to attackers online, with billions leaked as a by-product of phishing, malware infections (infostealers), and data breaches, which are packaged up and resold to other criminals. Sure, ",[],{},{"nodeType":876,"data":33086,"content":33088},{"uri":33087},"https://pushsecurity.com/blog/verified-stolen-credential-detection/",[33089],{"nodeType":867,"value":33090,"marks":33091,"data":33093},"there’s a lot of noise in credential feeds",[33092],{"type":1040},{},{"nodeType":867,"value":33095,"marks":33096,"data":33097}," — but it only takes the attacker to get lucky once. And the steady stream of breaches are living proof of the MFA gaps waiting to be exploited.",[],{},"SLH insight box 3",{"sys":33100,"__typename":1696,"content":33101,"name":33112,"title":59},{"id":14646},{"json":33102},{"nodeType":1640,"data":33103,"content":33104},{},[33105],{"nodeType":881,"data":33106,"content":33107},{},[33108],{"nodeType":867,"value":33109,"marks":33110,"data":33111},"A group calling themselves “The Crimson Collective” originally claimed the breach, with Scattered Lapsus$ Hunters becoming the main voice behind the breach at the extortion phase — showing just how interconnected the ecosystem of cybercriminals is.",[],{},"SLH insight box 10",{"sys":33114,"__typename":1696,"content":33115,"name":33126,"title":59},{"id":14816},{"json":33116},{"nodeType":1640,"data":33117,"content":33118},{},[33119],{"nodeType":881,"data":33120,"content":33121},{},[33122],{"nodeType":867,"value":33123,"marks":33124,"data":33125},"An identical attack path was attempted against Co-op, but was detected early enough for the security team to pull the plug on their own network. This significantly reduced the disruption, although customer data was still taken by the attacker.",[],{},"SLH insight box 4",{"sys":33128,"__typename":1696,"content":33129,"name":33151,"title":59},{"id":14838},{"json":33130},{"nodeType":1640,"data":33131,"content":33132},{},[33133],{"nodeType":881,"data":33134,"content":33135},{},[33136,33139,33147],{"nodeType":867,"value":21,"marks":33137,"data":33138},[],{},{"nodeType":876,"data":33140,"content":33141},{"uri":6114},[33142],{"nodeType":867,"value":33143,"marks":33144,"data":33146},"Jaguar’s Jira tenant was breached",[33145],{"type":1040},{},{"nodeType":867,"value":33148,"marks":33149,"data":33150}," by the “Scattered Lapsus$ Hunters” affiliated “HellCat” group earlier in 2025, which led to an alleged ~350GB of data being stolen. It is highly likely that this inside information from Jira (a platform storing huge amounts of business process information, architectural diagrams, and even improperly stored credentials and secrets) was leveraged in the later ransomware breach.",[],{},"SLH insight box 5",{"sys":33153,"__typename":1696,"content":33154,"name":33165,"title":59},{"id":14929},{"json":33155},{"nodeType":1640,"data":33156,"content":33157},{},[33158],{"nodeType":881,"data":33159,"content":33160},{},[33161],{"nodeType":867,"value":33162,"marks":33163,"data":33164},"The Salesloft breach in fact originated from a developer’s GitHub account being phished, which enabled the attacker to pivot into AWS, steal access tokens, and pivot to downstream customer environments.",[],{},"SLH insight box 6",{"sys":33167,"__typename":1696,"content":33168,"name":33179,"title":59},{"id":14961},{"json":33169},{"nodeType":1640,"data":33170,"content":33171},{},[33172],{"nodeType":881,"data":33173,"content":33174},{},[33175],{"nodeType":867,"value":33176,"marks":33177,"data":33178},"While the CyberHaven attacks were conducted by an unknown threat group, the MO of the attacker — pursuing financial gain, bypassing traditional defenses — is very much in-line with the Scattered Lapsus$ Hunters TTPs observed. ",[],{},"SLH insight box 7",{"sys":33181,"__typename":1696,"content":33182,"name":33204,"title":59},{"id":15164},{"json":33183},{"nodeType":1640,"data":33184,"content":33185},{},[33186],{"nodeType":881,"data":33187,"content":33188},{},[33189,33193,33200],{"nodeType":867,"value":33190,"marks":33191,"data":33192},"One of the common threads from all of these breaches is the risk posed by ",[],{},{"nodeType":876,"data":33194,"content":33195},{"uri":14788},[33196],{"nodeType":867,"value":33197,"marks":33198,"data":33199},"help desk attacks",[],{},{"nodeType":867,"value":33201,"marks":33202,"data":33203},", but it’s easy to over-index here. Naturally, making it possible for help desk operators to reset MFA for all users (including accounts with dangerous privileges) is always going to be targeted — but is fairly easy to address in principle by requiring escalations for high-risk changes. What is more interesting is that the vast majority of the help desk attacks featured in this article involved a single provider that is now no longer contracted by a number of the victims.",[],{},"SLH insight box 8",{"items":33206},[],{},"Analyzing \"Scattered Lapsus$ Hunters\" breaches since 2021",{"items":33210},[33211,33874,34328],{"__typename":1742,"sys":33212,"content":33214,"title":33860,"synopsis":33861,"hashTags":59,"publishedDate":33862,"slug":33863,"tagsCollection":33864,"authorsCollection":33870},{"id":33213},"62Zyr35VUmijkpupWk3hoD",{"json":33215},{"data":33216,"content":33217,"nodeType":1640},{},[33218,33234,33241,33244,33252,33259,33266,33286,33292,33299,33306,33313,33320,33323,33331,33338,33344,33351,33359,33366,33373,33379,33397,33403,33410,33417,33424,33430,33433,33441,33459,33466,33498,33505,33512,33518,33525,33532,33539,33542,33550,33566,33572,33579,33586,33592,33599,33606,33609,33617,33624,33644,33688,33695,33702,33709,33712,33720,33727,33734,33741,33744,33752,33759,33790,33810,33817,33820,33828,33835,33842],{"data":33219,"content":33220,"nodeType":881},{},[33221,33225,33230],{"data":33222,"marks":33223,"value":33224,"nodeType":867},{},[],"The view that \"the browser is the new endpoint\" and \"the new battleground for cyber attacks\" is becoming increasingly advocated by security leaders. But what does this ",{"data":33226,"marks":33227,"value":33229,"nodeType":867},{},[33228],{"type":1431},"actually",{"data":33231,"marks":33232,"value":33233,"nodeType":867},{},[]," mean for security teams? ",{"data":33235,"content":33236,"nodeType":881},{},[33237],{"data":33238,"marks":33239,"value":33240,"nodeType":867},{},[],"In this article, we’re cutting out the jargon to explore what a browser-based attack is, and what’s required for effective detection and response. ",{"data":33242,"content":33243,"nodeType":908},{},[],{"data":33245,"content":33246,"nodeType":918},{},[33247],{"data":33248,"marks":33249,"value":33251,"nodeType":867},{},[33250],{"type":916},"What is the goal of a browser-based attack?   ",{"data":33253,"content":33254,"nodeType":881},{},[33255],{"data":33256,"marks":33257,"value":33258,"nodeType":867},{},[],"First, it’s important to establish what the point of a browser-based attack is.",{"data":33260,"content":33261,"nodeType":881},{},[33262],{"data":33263,"marks":33264,"value":33265,"nodeType":867},{},[],"In most scenarios, attackers don’t think of themselves as attacking your web browser. Their end-goal is to compromise your business apps and data. That means going after the third-party apps and services that are now the backbone of business IT — and therefore the top target for attackers. ",{"data":33267,"content":33268,"nodeType":881},{},[33269,33273,33282],{"data":33270,"marks":33271,"value":33272,"nodeType":867},{},[],"The most common attack path today sees attackers log into third-party services, dump the data, and monetize it through extortion. You need only look at last year’s ",{"data":33274,"content":33276,"nodeType":876},{"uri":33275},"https://pushsecurity.com/blog/snowflake-retro?utm_source=bleeping-computer&utm_medium=sponsored-content&utm_term=article",[33277],{"data":33278,"marks":33279,"value":33281,"nodeType":867},{},[33280],{"type":1040},"Snowflake",{"data":33283,"marks":33284,"value":33285,"nodeType":867},{},[]," customer breaches or the still-ongoing Salesforce attacks to see the impact.",{"data":33287,"content":33291,"nodeType":890},{"target":33288},{"sys":33289},{"id":33290,"type":887,"linkType":888},"5agrVXzEdwALmew2F5SPDp",[],{"data":33293,"content":33294,"nodeType":881},{},[33295],{"data":33296,"marks":33297,"value":33298,"nodeType":867},{},[],"The most logical way to do this is by targeting users of those apps. And because of the changes to working practices, your users are more accessible than ever to external attackers.",{"data":33300,"content":33301,"nodeType":881},{},[33302],{"data":33303,"marks":33304,"value":33305,"nodeType":867},{},[],"Once upon a time, email was the primary communication channel with the wider world, and work happened locally — on your device, and inside your locked-down network environment. This made email and the endpoint the highest priority from a security perspective. But now, with modern work happening across a network of decentralized internet apps, and more varied communication channels outside of email, it’s harder to stop users from interacting with malicious content (at least, without significantly impeding their ability to do their jobs).",{"data":33307,"content":33308,"nodeType":881},{},[33309],{"data":33310,"marks":33311,"value":33312,"nodeType":867},{},[],"Given that the browser is the place where business apps are accessed and used, it makes sense that attacks are increasingly playing out there too. ",{"data":33314,"content":33315,"nodeType":881},{},[33316],{"data":33317,"marks":33318,"value":33319,"nodeType":867},{},[],"With that covered off, let’s take a closer look at the most prevalent browser-based attack techniques being used by attackers in the wild today.",{"data":33321,"content":33322,"nodeType":908},{},[],{"data":33324,"content":33325,"nodeType":918},{},[33326],{"data":33327,"marks":33328,"value":33330,"nodeType":867},{},[33329],{"type":916},"The 6 key browser-based attacks that security teams need to know about",{"data":33332,"content":33333,"nodeType":881},{},[33334],{"data":33335,"marks":33336,"value":33337,"nodeType":867},{},[],"Attacks that target users in their web browsers have seen an unprecedented rise in recent years. ",{"data":33339,"content":33343,"nodeType":890},{"target":33340},{"sys":33341},{"id":33342,"type":887,"linkType":888},"4ogNqZdObSIJXavHP44lom",[],{"data":33345,"content":33346,"nodeType":881},{},[33347],{"data":33348,"marks":33349,"value":33350,"nodeType":867},{},[],"Here's our breakdown of the top 6 browser-based attacks that should be on every security team's radar right now. ",{"data":33352,"content":33353,"nodeType":998},{},[33354],{"data":33355,"marks":33356,"value":33358,"nodeType":867},{},[33357],{"type":916},"1. Phishing for credentials and sessions",{"data":33360,"content":33361,"nodeType":881},{},[33362],{"data":33363,"marks":33364,"value":33365,"nodeType":867},{},[],"The most direct way for an attacker to compromise a business application is to phish a user of that app. You might not necessarily think of phishing as a browser-based attack, but that’s exactly what it is today. ",{"data":33367,"content":33368,"nodeType":881},{},[33369],{"data":33370,"marks":33371,"value":33372,"nodeType":867},{},[],"Phishing tooling and infrastructure has evolved a lot in the past decade, while the changes to business IT means there are both many more vectors for phishing attack delivery, and apps and identities to target. Attackers can deliver links over instant messenger apps, social media, SMS, malicious ads, and using in-app messenger functionality, as well as sending emails directly from SaaS services to bypass email-based checks. Likewise, there are now hundreds of apps per enterprise to target, with varying levels of account security configuration. ",{"data":33374,"content":33378,"nodeType":890},{"target":33375},{"sys":33376},{"id":33377,"type":887,"linkType":888},"3SrKOgpedLMQRpKIZqUQur",[],{"data":33380,"content":33381,"nodeType":881},{},[33382,33386,33394],{"data":33383,"marks":33384,"value":33385,"nodeType":867},{},[],"Whereas phishing was once entirely focused on credential theft, modern phishing attacks see the attacker intercept the victim’s session on the target app, using reverse-proxy Attacker-in-the-Middle kits that are the standard choice for attackers today. This means most forms of MFA can be bypassed, with the exception of passkeys (though attackers are finding ways to work around passkeys using ",{"data":33387,"content":33389,"nodeType":876},{"uri":33388},"https://pushsecurity.com/blog/mfa-downgrade-attacks/?utm_source=bleeping-computer&utm_medium=sponsored-content&utm_term=article",[33390],{"data":33391,"marks":33392,"value":31717,"nodeType":867},{},[33393],{"type":1040},{"data":33395,"marks":33396,"value":10143,"nodeType":867},{},[],{"data":33398,"content":33402,"nodeType":890},{"target":33399},{"sys":33400},{"id":33401,"type":887,"linkType":888},"2sOFEdAwQZjWOGzNAlGavb",[],{"data":33404,"content":33405,"nodeType":881},{},[33406],{"data":33407,"marks":33408,"value":33409,"nodeType":867},{},[],"There are other key differences to be aware of too. Today, phishing operates on an industrial scale, using an array of obfuscation and detection evasion techniques. The latest generation of fully customized AitM phishing kits are dynamically obfuscating the code that loads the web page, implementing custom bot protection (e.g. CAPTCHA or Cloudflare Turnstile), using runtime anti-analysis features, and using legitimate SaaS and cloud services to host and deliver phishing links to cover their tracks.",{"data":33411,"content":33412,"nodeType":881},{},[33413],{"data":33414,"marks":33415,"value":33416,"nodeType":867},{},[],"This means that traditional anti-phishing tools at the email and network layer are struggling to keep up, with many attacks evading email-based detections (or bypassing email altogether). At the same time, proxy-based solutions now see a garbled mess of JavaScript code without the necessary context of what is actually happening in the browser to be able to piece it together effectively. Even if they don’t realize it, this means many organizations are now relying solely on blocking known-bad sites and hosts — a wildly ineffective solution in 2025 with the rate that attackers refresh and rotate their phishing infrastructure. ",{"data":33418,"content":33419,"nodeType":881},{},[33420],{"data":33421,"marks":33422,"value":33423,"nodeType":867},{},[],"These changes make phishing more effective than ever, and increasingly difficult to detect and block without being able to observe and analyze web pages that a user interacts with in real time — something only possible with browser-level visibility. ",{"data":33425,"content":33429,"nodeType":890},{"target":33426},{"sys":33427},{"id":33428,"type":887,"linkType":888},"1II2kHyOZcShLsexx1TAgy",[],{"data":33431,"content":33432,"nodeType":908},{},[],{"data":33434,"content":33435,"nodeType":998},{},[33436],{"data":33437,"marks":33438,"value":33440,"nodeType":867},{},[33439],{"type":916},"2. Malicious copy and paste (aka. ClickFix, FileFix, etc.)",{"data":33442,"content":33443,"nodeType":881},{},[33444,33448,33456],{"data":33445,"marks":33446,"value":33447,"nodeType":867},{},[],"One of the biggest security trends in the past year has been the emergence of the attack technique known as ",{"data":33449,"content":33451,"nodeType":876},{"uri":33450},"https://www.microsoft.com/en-us/security/blog/2025/08/21/think-before-you-clickfix-analyzing-the-clickfix-social-engineering-technique/",[33452],{"data":33453,"marks":33454,"value":315,"nodeType":867},{},[33455],{"type":1040},{"data":33457,"marks":33458,"value":10110,"nodeType":867},{},[],{"data":33460,"content":33461,"nodeType":881},{},[33462],{"data":33463,"marks":33464,"value":33465,"nodeType":867},{},[],"Originally known as “Fake CAPTCHA”, these attacks attempt to trick users into running malicious commands on their device — typically by solving some form of verification challenge in the browser. ",{"data":33467,"content":33468,"nodeType":881},{},[33469,33473,33482,33486,33495],{"data":33470,"marks":33471,"value":33472,"nodeType":867},{},[],"In reality, by solving the challenge, the victim is actually copying malicious code from the page clipboard and running it on their device. It typically gives the victim instructions that involve clicking prompts and copying, pasting, and running commands directly in the Windows Run dialog box, Terminal, or PowerShell. Variants such as ",{"data":33474,"content":33476,"nodeType":876},{"uri":33475},"https://mrd0x.com/filefix-clickfix-alternative/",[33477],{"data":33478,"marks":33479,"value":33481,"nodeType":867},{},[33480],{"type":1040},"FileFix",{"data":33483,"marks":33484,"value":33485,"nodeType":867},{},[]," have also emerged which instead uses the File Explorer Address Bar to execute OS commands, while recent examples have seen this attack branch out to ",{"data":33487,"content":33489,"nodeType":876},{"uri":33488},"https://www.bleepingcomputer.com/news/security/fake-mac-fixes-trick-users-into-installing-new-shamos-infostealer/",[33490],{"data":33491,"marks":33492,"value":33494,"nodeType":867},{},[33493],{"type":1040},"Mac via the macOS terminal",{"data":33496,"marks":33497,"value":1947,"nodeType":867},{},[],{"data":33499,"content":33500,"nodeType":881},{},[33501],{"data":33502,"marks":33503,"value":33504,"nodeType":867},{},[],"Most commonly, these attacks are used to deliver infostealer malware, using stolen session cookies and credentials to access business apps and services. ",{"data":33506,"content":33507,"nodeType":881},{},[33508],{"data":33509,"marks":33510,"value":33511,"nodeType":867},{},[],"Like modern credential and session phishing, links to malicious pages are distributed over various delivery channels and using a variety of lures, including impersonating CAPTCHA, Cloudflare Turnstile, simulating an error loading a webpage, and many more. ",{"data":33513,"content":33517,"nodeType":890},{"target":33514},{"sys":33515},{"id":33516,"type":887,"linkType":888},"6O9YiOfhpGFCDsTil9F3On",[],{"data":33519,"content":33520,"nodeType":881},{},[33521],{"data":33522,"marks":33523,"value":33524,"nodeType":867},{},[],"The variance in lure, and differences between different versions of the same lure, can make it difficult to fingerprint and detect based on visual elements alone. Also, many of the same protections being used to obfuscate and prevent analysis of phishing pages also apply to ClickFix pages, making it equally challenging to detect and block them. ",{"data":33526,"content":33527,"nodeType":881},{},[33528],{"data":33529,"marks":33530,"value":33531,"nodeType":867},{},[],"This leaves most of the detection and blocking down to endpoint-layer controls around user-level code execution and malware running on a device. The quantity of ClickFix-related headlines in the news would indicate that endpoint controls are being routinely bypassed, or perhaps evaded altogether by targeting personal or BYOD devices. ",{"data":33533,"content":33534,"nodeType":881},{},[33535],{"data":33536,"marks":33537,"value":33538,"nodeType":867},{},[],"There is a significant opportunity to detect these attacks in the browser and stop them at the earliest opportunity, before they reach the endpoint. Every ClickFix attack and variant has a key action in common — malicious code is copied from the page’s clipboard. In some cases, this happens without any user interaction (where the only requirement on the user is to run code that has been silently copied behind the scenes), presenting a strong indicator of malicious behavior that can be observed in the browser. ",{"data":33540,"content":33541,"nodeType":908},{},[],{"data":33543,"content":33544,"nodeType":998},{},[33545],{"data":33546,"marks":33547,"value":33549,"nodeType":867},{},[33548],{"type":916},"3. Malicious OAuth integrations",{"data":33551,"content":33552,"nodeType":881},{},[33553,33557,33563],{"data":33554,"marks":33555,"value":33556,"nodeType":867},{},[],"Malicious OAuth integrations are another way for attackers to compromise an app by tricking a user into authorizing an integration with a malicious, attacker-controlled app, with the level of data access and functionality dictated by the scopes authorized in the request. This is also known as ",{"data":33558,"content":33559,"nodeType":876},{"uri":25732},[33560],{"data":33561,"marks":33562,"value":20604,"nodeType":867},{},[],{"data":33564,"marks":33565,"value":1253,"nodeType":867},{},[],{"data":33567,"content":33571,"nodeType":890},{"target":33568},{"sys":33569},{"id":33570,"type":887,"linkType":888},"5JaP4WSfFsFSbvaa9BQBOq",[],{"data":33573,"content":33574,"nodeType":881},{},[33575],{"data":33576,"marks":33577,"value":33578,"nodeType":867},{},[],"This is an effective way for attackers to bypass hardened authentication and access controls by sidestepping the typical login process to take over an account and compromise business apps. This includes phishing-resistant MFA methods like passkeys — since the standard login process does not apply. ",{"data":33580,"content":33581,"nodeType":881},{},[33582],{"data":33583,"marks":33584,"value":33585,"nodeType":867},{},[],"A variant of this attack has dominated the headlines recently with the ongoing Salesforce breaches. In this scenario, the attacker tricked the victim into authorizing an attacker-controlled OAuth app via the device code authorization flow in Salesforce, which requires the user to enter an 8-digit code in place of a password or MFA factor.",{"data":33587,"content":33591,"nodeType":890},{"target":33588},{"sys":33589},{"id":33590,"type":887,"linkType":888},"3odEFcUcpKN553gHh2P5yr",[],{"data":33593,"content":33594,"nodeType":881},{},[33595],{"data":33596,"marks":33597,"value":33598,"nodeType":867},{},[],"Preventing malicious OAuth grants being authorized requires tight in-app management of user permissions and tenant security settings. This is no mean feat when considering the 100s of apps in use across the modern enterprise, many of which are not centrally managed by IT and security teams (or in some cases, are completely unknown to them). Even then, you’re limited by the controls made available by the app vendor. In this case, Salesforce has announced planned changes to OAuth app authorization in order to improve security prompted by these attacks — but many more apps with insecure configs exist for attackers to take advantage of in future. ",{"data":33600,"content":33601,"nodeType":881},{},[33602],{"data":33603,"marks":33604,"value":33605,"nodeType":867},{},[],"However, unlike app-specific integrations, browser-based security tools are well positioned to observe OAuth grants across all apps accessed in the browser — even the ones the security team doesn’t manage or know about, or without needing to pay for the app’s special security add-on to get visibility.",{"data":33607,"content":33608,"nodeType":908},{},[],{"data":33610,"content":33611,"nodeType":998},{},[33612],{"data":33613,"marks":33614,"value":33616,"nodeType":867},{},[33615],{"type":916},"4. Malicious browser extensions",{"data":33618,"content":33619,"nodeType":881},{},[33620],{"data":33621,"marks":33622,"value":33623,"nodeType":867},{},[],"Malicious browser extensions are another way for attackers to compromise your business apps by observing and capturing logins as they happen, and/or extracting session cookies and credentials saved in the browser cache and password manager. ",{"data":33625,"content":33626,"nodeType":881},{},[33627,33631,33640],{"data":33628,"marks":33629,"value":33630,"nodeType":867},{},[],"Attackers do this by creating their own malicious extension and tricking your users into installing it, or taking over an existing extension to gain access to browsers where it is already installed (",{"data":33632,"content":33634,"nodeType":876},{"uri":33633},"https://secureannex.com/blog/buying-browser-extensions/",[33635],{"data":33636,"marks":33637,"value":33639,"nodeType":867},{},[33638],{"type":1040},"it’s very easy for attackers to buy and add malicious updates to existing extensions",{"data":33641,"marks":33642,"value":33643,"nodeType":867},{},[],", easily passing extension web store security checks). ",{"data":33645,"content":33646,"nodeType":881},{},[33647,33651,33660,33664,33673,33676,33685],{"data":33648,"marks":33649,"value":33650,"nodeType":867},{},[],"The news around extension-based compromises has been on the rise since the ",{"data":33652,"content":33654,"nodeType":876},{"uri":33653},"https://www.bleepingcomputer.com/news/security/new-details-reveal-how-hackers-hijacked-35-google-chrome-extensions/",[33655],{"data":33656,"marks":33657,"value":33659,"nodeType":867},{},[33658],{"type":1040},"Cyberhaven extension",{"data":33661,"marks":33662,"value":33663,"nodeType":867},{},[]," was hacked in December 2024, along with at least 35 other extensions. Since then, there has been regular reporting on data-stealing extensions ",{"data":33665,"content":33667,"nodeType":876},{"uri":33666},"https://www.bleepingcomputer.com/news/security/data-stealing-chrome-extensions-impersonate-fortinet-youtube-vpns/",[33668],{"data":33669,"marks":33670,"value":33672,"nodeType":867},{},[33671],{"type":1040},"impersonating legitimate brands",{"data":33674,"marks":33675,"value":15362,"nodeType":867},{},[],{"data":33677,"content":33679,"nodeType":876},{"uri":33678},"https://www.bleepingcomputer.com/news/security/chrome-extensions-with-6-million-installs-have-hidden-tracking-code/",[33680],{"data":33681,"marks":33682,"value":33684,"nodeType":867},{},[33683],{"type":1040},"impacting millions of users",{"data":33686,"marks":33687,"value":1947,"nodeType":867},{},[],{"data":33689,"content":33690,"nodeType":881},{},[33691],{"data":33692,"marks":33693,"value":33694,"nodeType":867},{},[],"Risky browser extension permissions include broad data access, the ability to modify website content, track user activity, capture screenshots, and manage tabs or network requests. Permissions like \"read and change all data on all websites\" or access to cookies and browsing history are particularly dangerous as they can be exploited for session hijacking, data theft, malware injection, or phishing.",{"data":33696,"content":33697,"nodeType":881},{},[33698],{"data":33699,"marks":33700,"value":33701,"nodeType":867},{},[],"Generally, your employees should not be randomly installing browser extensions unless pre-approved by your security team. The reality, however, is that many organizations have very little visibility of the extensions their employees are using, and the potential risk they’re exposed to as a result. ",{"data":33703,"content":33704,"nodeType":881},{},[33705],{"data":33706,"marks":33707,"value":33708,"nodeType":867},{},[],"To tackle malicious extensions, security tools operating in the browser can track the browser extensions deployed, highlight risky permissions, compare with known-malicious extensions, identify fraudulent/unofficial versions of a legitimate extension, and highlight other risky properties commonly associated with malicious extensions (e.g. “Developer” extensions). ",{"data":33710,"content":33711,"nodeType":908},{},[],{"data":33713,"content":33714,"nodeType":998},{},[33715],{"data":33716,"marks":33717,"value":33719,"nodeType":867},{},[33718],{"type":916},"5. Malicious file delivery",{"data":33721,"content":33722,"nodeType":881},{},[33723],{"data":33724,"marks":33725,"value":33726,"nodeType":867},{},[],"Malicious files have been a core part of malware delivery and credential theft for many years. Just as non-email channels like malvertising and drive-by attacks are used to deliver phishing and ClickFix lures, malicious files are also distributed through similar means — leaving malicious file detection to basic known-bad checks, sandbox analysis using a proxy (not that useful in the context of sandbox-aware malware) or runtime analysis on the endpoint. ",{"data":33728,"content":33729,"nodeType":881},{},[33730],{"data":33731,"marks":33732,"value":33733,"nodeType":867},{},[],"This doesn’t just have to be malicious executables directly dropping malware onto the device. File downloads can also contain additional links taking the user to malicious content. In fact, one of the most common types of downloadable content are HTML Applications (HTAs), commonly used to spawn local phishing pages to stealthily capture credentials. More recently, attackers have been weaponizing SVG files for a similar purpose, running as self-contained phishing pages that render fake login portals entirely client-side. ",{"data":33735,"content":33736,"nodeType":881},{},[33737],{"data":33738,"marks":33739,"value":33740,"nodeType":867},{},[],"Even if malicious content cannot always be flagged from surface-level inspection of a file, recording file downloads in the browser is a useful addition to endpoint-based malware protection, and provides another layer of defense against file downloads that perform client-side attacks, or redirect the user to malicious web-based content. ",{"data":33742,"content":33743,"nodeType":908},{},[],{"data":33745,"content":33746,"nodeType":998},{},[33747],{"data":33748,"marks":33749,"value":33751,"nodeType":867},{},[33750],{"type":916},"6. Stolen credentials and MFA gaps",{"data":33753,"content":33754,"nodeType":881},{},[33755],{"data":33756,"marks":33757,"value":33758,"nodeType":867},{},[],"This last one isn’t so much a browser-based attack, but it is a product of them. When credentials are stolen through phishing or infostealer malware they can be used to take over accounts missing MFA. ",{"data":33760,"content":33761,"nodeType":881},{},[33762,33766,33773,33777,33786],{"data":33763,"marks":33764,"value":33765,"nodeType":867},{},[],"This isn’t the most sophisticated attack, but it’s very effective. You need only look at last year’s ",{"data":33767,"content":33768,"nodeType":876},{"uri":33275},[33769],{"data":33770,"marks":33771,"value":33281,"nodeType":867},{},[33772],{"type":1040},{"data":33774,"marks":33775,"value":33776,"nodeType":867},{},[]," account compromises or the ",{"data":33778,"content":33780,"nodeType":876},{"uri":33779},"https://pushsecurity.com/blog/why-attackers-are-targeting-jira-with-stolen-credentials?utm_source=bleeping-computer&utm_medium=sponsored-content&utm_term=article",[33781],{"data":33782,"marks":33783,"value":33785,"nodeType":867},{},[33784],{"type":1040},"Jira",{"data":33787,"marks":33788,"value":33789,"nodeType":867},{},[]," attacks earlier this year to see how attackers harness stolen credentials at scale. ",{"data":33791,"content":33792,"nodeType":881},{},[33793,33797,33806],{"data":33794,"marks":33795,"value":33796,"nodeType":867},{},[],"With the modern enterprise using hundreds of apps, the likelihood that an app hasn’t been configured for mandatory MFA (if possible) is high. And even when an app has been configured for SSO and connected to your primary corporate identity, ",{"data":33798,"content":33800,"nodeType":876},{"uri":33799},"https://pushsecurity.com/blog/how-many-vulnerable-identities-do-you-have/?utm_source=bleeping-computer&utm_medium=sponsored-content&utm_term=sidebar",[33801],{"data":33802,"marks":33803,"value":33805,"nodeType":867},{},[33804],{"type":1040},"local “ghost logins” can continue to exist",{"data":33807,"marks":33808,"value":33809,"nodeType":867},{},[],", accepting passwords with no MFA required. Just having visibility of your primary Identity Provider accounts (e.g. Google, Microsoft, Okta) and SSO-connected apps doesn't give you a full picture of your identity surface.",{"data":33811,"content":33812,"nodeType":881},{},[33813],{"data":33814,"marks":33815,"value":33816,"nodeType":867},{},[],"Logins can also be observed in the browser — in fact, it’s as close to a universal source of truth as you’re going to get about how your employees are actually logging in, which apps they’re using, and whether MFA is present, enabling security teams to find and fix vulnerable logins before they can be exploited by attackers. ",{"data":33818,"content":33819,"nodeType":908},{},[],{"data":33821,"content":33822,"nodeType":918},{},[33823],{"data":33824,"marks":33825,"value":33827,"nodeType":867},{},[33826],{"type":916},"Conclusion",{"data":33829,"content":33830,"nodeType":881},{},[33831],{"data":33832,"marks":33833,"value":33834,"nodeType":867},{},[],"Attacks are increasingly happening in the browser. That makes it the perfect place to detect and respond to these attacks. But right now, the browser is a blind-spot for most security teams. ",{"data":33836,"content":33837,"nodeType":881},{},[33838],{"data":33839,"marks":33840,"value":33841,"nodeType":867},{},[],"Push Security’s browser-based security platform provides comprehensive detection and response capabilities against the leading cause of breaches. Push blocks browser-based attacks like AiTM phishing, credential stuffing, password spraying and session hijacking using stolen session tokens. You can also use Push to find and fix vulnerabilities across the apps that your employees use, like ghost logins, SSO coverage gaps, MFA gaps, vulnerable passwords, risky OAuth integrations, and more to harden your identity attack surface.",{"data":33843,"content":33844,"nodeType":881},{},[33845,33849,33857],{"data":33846,"marks":33847,"value":33848,"nodeType":867},{},[],"If you want to learn more about how Push helps you to detect and stop attacks in the browser, ",{"data":33850,"content":33852,"nodeType":876},{"uri":33851},"https://pushsecurity.com/demo?utm_source=bleeping-computer&utm_medium=sponsored-content&utm_term=article",[33853],{"data":33854,"marks":33855,"value":10826,"nodeType":867},{},[33856],{"type":1040},{"data":33858,"marks":33859,"value":1947,"nodeType":867},{},[],"6 browser-based attacks every security team should be prepared for","What security teams need to know about the browser-based attack techniques that are the leading cause of breaches.","2025-09-05T00:00:00.000Z","6-browser-based-attacks-every-security-team-should-be-prepared-for",{"items":33865},[33866,33868],{"sys":33867,"name":2547},{"id":2546},{"sys":33869,"name":342},{"id":2550},{"items":33871},[33872],{"fullName":849,"firstName":850,"jobTitle":851,"profilePicture":33873},{"url":855},{"__typename":1742,"sys":33875,"content":33877,"title":34314,"synopsis":34315,"hashTags":59,"publishedDate":34316,"slug":34317,"tagsCollection":34318,"authorsCollection":34324},{"id":33876},"4vPEPmjd8MOlARD7oXfOrj",{"json":33878},{"data":33879,"content":33880,"nodeType":1640},{},[33881,33898,33914,33920,33927,33934,33937,33945,33963,33970,33976,33983,33989,33996,34002,34009,34015,34022,34028,34031,34039,34057,34063,34071,34091,34099,34131,34138,34146,34166,34174,34194,34200,34203,34210,34230,34237,34242,34245,34252,34268,34275,34282,34288],{"data":33882,"content":33883,"nodeType":881},{},[33884,33888,33895],{"data":33885,"marks":33886,"value":33887,"nodeType":867},{},[],"Push recently detected and blocked a high-risk LinkedIn phishing attack that demonstrated a number of crafty (and increasingly common) ",{"data":33889,"content":33890,"nodeType":876},{"uri":2267},[33891],{"data":33892,"marks":33893,"value":16396,"nodeType":867},{},[33894],{"type":1040},{"data":33896,"marks":33897,"value":10110,"nodeType":867},{},[],{"data":33899,"content":33900,"nodeType":881},{},[33901,33905,33910],{"data":33902,"marks":33903,"value":33904,"nodeType":867},{},[],"Phishing via LinkedIn is increasingly common, although it often goes undetected and unreported. This is to be expected when most of the industry’s data on phishing attacks comes from email security vendors and tools. In contrast to email-centric reporting, ",{"data":33906,"marks":33907,"value":33909,"nodeType":867},{},[33908],{"type":916},"34% of the phishing attacks intercepted by Push last month came through non-email channels",{"data":33911,"marks":33912,"value":33913,"nodeType":867},{},[]," like social media, IM platforms, malicious search engine ads, and in-app communications. ",{"data":33915,"content":33919,"nodeType":890},{"target":33916},{"sys":33917},{"id":33918,"type":887,"linkType":888},"7i8panfdFUqW9wqYkd9uDc",[],{"data":33921,"content":33922,"nodeType":881},{},[33923],{"data":33924,"marks":33925,"value":33926,"nodeType":867},{},[],"Phishing via LinkedIn is a great way to catch victims unawares and evade traditionally email-based anti-phishing controls. While often used for work and commonly accessed from corporate devices, it sits outside the purview of enterprise security tools, exploiting a visibility and control blind spot. ",{"data":33928,"content":33929,"nodeType":881},{},[33930],{"data":33931,"marks":33932,"value":33933,"nodeType":867},{},[],"Let’s break it down. ",{"data":33935,"content":33936,"nodeType":908},{},[],{"data":33938,"content":33939,"nodeType":918},{},[33940],{"data":33941,"marks":33942,"value":33944,"nodeType":867},{},[33943],{"type":916},"Phishing attack breakdown",{"data":33946,"content":33947,"nodeType":881},{},[33948,33952,33960],{"data":33949,"marks":33950,"value":33951,"nodeType":867},{},[],"The victim was sent a malicious link via LinkedIn DM relating to a fake investment opportunity for executives ",{"data":33953,"content":33955,"nodeType":876},{"uri":33954},"https://www.bleepingcomputer.com/news/security/linkedin-phishing-targets-finance-execs-with-fake-board-invites/",[33956],{"data":33957,"marks":33958,"value":33959,"nodeType":867},{},[],"to join the executive board of a newly created \"Common Wealth\" investment fund.",{"data":33961,"marks":33962,"value":3679,"nodeType":867},{},[],{"data":33964,"content":33965,"nodeType":881},{},[33966],{"data":33967,"marks":33968,"value":33969,"nodeType":867},{},[],"After clicking the link, they were redirected three times — via Google Search, and then payrails-canaccord[.]icu/(redacted) — before being sent to a custom landing page hosted on firebasestorage.googleapis[.]com/(redacted). ",{"data":33971,"content":33975,"nodeType":890},{"target":33972},{"sys":33973},{"id":33974,"type":887,"linkType":888},"65PeJOKzn6Ba7FDUQRae3Q",[],{"data":33977,"content":33978,"nodeType":881},{},[33979],{"data":33980,"marks":33981,"value":33982,"nodeType":867},{},[],"Upon clicking on one of the document links on the page, the victim is prompted to “view with Microsoft”. ",{"data":33984,"content":33988,"nodeType":890},{"target":33985},{"sys":33986},{"id":33987,"type":887,"linkType":888},"4f27KuwTRx1Do59rs3JoVl",[],{"data":33990,"content":33991,"nodeType":881},{},[33992],{"data":33993,"marks":33994,"value":33995,"nodeType":867},{},[],"The user is then met with a Cloudflare Turnstile gate challenge at login.kggpho[.]icu before the page will fully render, and malicious content is loaded. ",{"data":33997,"content":34001,"nodeType":890},{"target":33998},{"sys":33999},{"id":34000,"type":887,"linkType":888},"3lpVmLBZSocOSGdlCKhKnD",[],{"data":34003,"content":34004,"nodeType":881},{},[34005],{"data":34006,"marks":34007,"value":34008,"nodeType":867},{},[],"The Microsoft-impersonating AITM phishing page is then served to the victim. Entering credentials and completing the MFA check will result in their Microsoft session being stolen by the attacker. ",{"data":34010,"content":34014,"nodeType":890},{"target":34011},{"sys":34012},{"id":34013,"type":887,"linkType":888},"5FCa4EJwyux13K9KBT3nd4",[],{"data":34016,"content":34017,"nodeType":881},{},[34018],{"data":34019,"marks":34020,"value":34021,"nodeType":867},{},[],"You can see the full timeline of events in the Detection Timeline below. ",{"data":34023,"content":34027,"nodeType":890},{"target":34024},{"sys":34025},{"id":34026,"type":887,"linkType":888},"8lizkPJcGdZhtWFV2QEwQ",[],{"data":34029,"content":34030,"nodeType":908},{},[],{"data":34032,"content":34033,"nodeType":918},{},[34034],{"data":34035,"marks":34036,"value":34038,"nodeType":867},{},[34037],{"type":916},"Detection evasion techniques observed",{"data":34040,"content":34041,"nodeType":881},{},[34042,34046,34053],{"data":34043,"marks":34044,"value":34045,"nodeType":867},{},[],"The attacker used a number of ",{"data":34047,"content":34048,"nodeType":876},{"uri":2267},[34049],{"data":34050,"marks":34051,"value":16396,"nodeType":867},{},[34052],{"type":1040},{"data":34054,"marks":34055,"value":34056,"nodeType":867},{},[]," to prevent the phishing site being analysed and detected by security tools. ",{"data":34058,"content":34062,"nodeType":890},{"target":34059},{"sys":34060},{"id":34061,"type":887,"linkType":888},"7q9D1MREwTCCpnjvZZ5wk1",[],{"data":34064,"content":34065,"nodeType":998},{},[34066],{"data":34067,"marks":34068,"value":34070,"nodeType":867},{},[34069],{"type":916},"LinkedIn delivery",{"data":34072,"content":34073,"nodeType":881},{},[34074,34078,34087],{"data":34075,"marks":34076,"value":34077,"nodeType":867},{},[],"As we mentioned above, sending phishing lures via ",{"data":34079,"content":34081,"nodeType":876},{"uri":34080},"https://phishing-techniques.pushsecurity.com/techniques/social-media/",[34082],{"data":34083,"marks":34084,"value":34086,"nodeType":867},{},[34085],{"type":1040},"social media apps",{"data":34088,"marks":34089,"value":34090,"nodeType":867},{},[]," like LinkedIn is a great way to reach employees in a place that they expect to be contacted by people outside of their organization. By evading the traditional phishing control point altogether (email) attackers significantly reduce the risk of interception. ",{"data":34092,"content":34093,"nodeType":998},{},[34094],{"data":34095,"marks":34096,"value":34098,"nodeType":867},{},[34097],{"type":916},"Lengthy redirect chain through trusted sites",{"data":34100,"content":34101,"nodeType":881},{},[34102,34106,34114,34118,34127],{"data":34103,"marks":34104,"value":34105,"nodeType":867},{},[],"Attackers use ",{"data":34107,"content":34108,"nodeType":876},{"uri":2392},[34109],{"data":34110,"marks":34111,"value":34113,"nodeType":867},{},[34112],{"type":1040},"lengthy redirect chains",{"data":34115,"marks":34116,"value":34117,"nodeType":867},{},[]," in combination with hosting pages on ",{"data":34119,"content":34121,"nodeType":876},{"uri":34120},"https://phishing-techniques.pushsecurity.com/techniques/trusted-website-hosting/",[34122],{"data":34123,"marks":34124,"value":34126,"nodeType":867},{},[34125],{"type":1040},"legitimate, trusted sites",{"data":34128,"marks":34129,"value":34130,"nodeType":867},{},[]," (in this case Firebase, Google’s app development platform). This is a technique we see a lot, with various Google and Microsoft sites cropping up time and again, including Google Forms, Google Sites, Google Script, Google AMP, Microsoft Dynamics, SharePoint, Azure Front Door, and many more, all used by attackers as part of their phishing attacks. ",{"data":34132,"content":34133,"nodeType":881},{},[34134],{"data":34135,"marks":34136,"value":34137,"nodeType":867},{},[],"Legitimate services are less likely to be flagged by link analysis tools and effectively cloak the initial URL delivered to the victim to increase the chance of successful delivery of and access to the link, while many services are excluded from page scanning tools owing to their association with trusted domains. ",{"data":34139,"content":34140,"nodeType":998},{},[34141],{"data":34142,"marks":34143,"value":34145,"nodeType":867},{},[34144],{"type":916},"Bot protection",{"data":34147,"content":34148,"nodeType":881},{},[34149,34153,34162],{"data":34150,"marks":34151,"value":34152,"nodeType":867},{},[],"Attackers are using common ",{"data":34154,"content":34156,"nodeType":876},{"uri":34155},"https://phishing-techniques.pushsecurity.com/techniques/bot-protection/",[34157],{"data":34158,"marks":34159,"value":34161,"nodeType":867},{},[34160],{"type":1040},"bot protection",{"data":34163,"marks":34164,"value":34165,"nodeType":867},{},[]," technologies like CAPTCHA and Cloudflare Turnstile to prevent security bots from accessing their web pages to be able to analyse them (and therefore block pages from being automatically flagged). This requires anyone visiting the page to pass a bot check/challenge before the page can be loaded, meaning the full page cannot be analysed by automated tools. ",{"data":34167,"content":34168,"nodeType":998},{},[34169],{"data":34170,"marks":34171,"value":34173,"nodeType":867},{},[34172],{"type":916},"Page obfuscation",{"data":34175,"content":34176,"nodeType":881},{},[34177,34181,34190],{"data":34178,"marks":34179,"value":34180,"nodeType":867},{},[],"Phishing pages ",{"data":34182,"content":34184,"nodeType":876},{"uri":34183},"https://phishing-techniques.pushsecurity.com/techniques/page-obfuscation/",[34185],{"data":34186,"marks":34187,"value":34189,"nodeType":867},{},[34188],{"type":1040},"change and even randomize elements of the page",{"data":34191,"marks":34192,"value":34193,"nodeType":867},{},[]," to avoid static fingerprints and defeat comparison-based checks against real pages. This includes the page title, text, images, backgrounds, logos, favicons, etc. — all of which may be signatured components using web page analysis tools. These elements can even be embedded in an encoded form so it isn’t present in the initial HTML, and is instead dynamically set at runtime when loaded. As an example, you can see that the page randomly generated the tab header text.",{"data":34195,"content":34199,"nodeType":890},{"target":34196},{"sys":34197},{"id":34198,"type":887,"linkType":888},"2bbOZC9M4y69ACDy7bn209",[],{"data":34201,"content":34202,"nodeType":908},{},[],{"data":34204,"content":34205,"nodeType":918},{},[34206],{"data":34207,"marks":34208,"value":2257,"nodeType":867},{},[34209],{"type":916},{"data":34211,"content":34212,"nodeType":881},{},[34213,34217,34226],{"data":34214,"marks":34215,"value":34216,"nodeType":867},{},[],"We’re seeing ",{"data":34218,"content":34220,"nodeType":876},{"uri":34219},"https://pushsecurity.com/blog/how-push-stopped-a-high-risk-linkedin-spear-phishing-attack/",[34221],{"data":34222,"marks":34223,"value":34225,"nodeType":867},{},[34224],{"type":1040},"many phishing campaigns pivoting to social media apps like LinkedIn",{"data":34227,"marks":34228,"value":34229,"nodeType":867},{},[]," and organizations should be on guard against this attack vector, which is highly effective at evading common anti-phishing controls.  ",{"data":34231,"content":34232,"nodeType":881},{},[34233],{"data":34234,"marks":34235,"value":34236,"nodeType":867},{},[],"Just because the attack happens over LinkedIn doesn’t lessen the impact — these are corporate credentials and accounts being targeted, even if it is nominally a “personal” application. Taking over a core identity like a Microsoft or Google account can have wide-ranging consequences, putting data at risk in both core apps and any downstream apps that can be accessed via SSO from the compromised account. ",{"data":34238,"content":34241,"nodeType":890},{"target":34239},{"sys":34240},{"id":21096,"type":887,"linkType":888},[],{"data":34243,"content":34244,"nodeType":908},{},[],{"data":34246,"content":34247,"nodeType":918},{},[34248],{"data":34249,"marks":34250,"value":21026,"nodeType":867},{},[34251],{"type":916},{"data":34253,"content":34254,"nodeType":881},{},[34255,34258,34265],{"data":34256,"marks":34257,"value":21046,"nodeType":867},{},[],{"data":34259,"content":34260,"nodeType":876},{"uri":2267},[34261],{"data":34262,"marks":34263,"value":21054,"nodeType":867},{},[34264],{"type":1040},{"data":34266,"marks":34267,"value":21058,"nodeType":867},{},[],{"data":34269,"content":34270,"nodeType":881},{},[34271],{"data":34272,"marks":34273,"value":34274,"nodeType":867},{},[],"This isn’t all we do: Push’s browser-based security platform provides comprehensive detection and response capabilities against the leading cause of breaches. Push blocks browser-based attacks like AiTM phishing, credential stuffing, malicious browser extensions, malicious OAuth grants, ClickFix, and session hijacking. You don’t need to wait until it all goes wrong — you can also use Push to proactively find and fix vulnerabilities across the apps that your employees use, like ghost logins, SSO coverage gaps, MFA gaps, vulnerable passwords, and more to harden your identity attack surface.",{"data":34276,"content":34277,"nodeType":881},{},[34278],{"data":34279,"marks":34280,"value":34281,"nodeType":867},{},[],"Check out the demo below to see Push detect and block this attack in real-time. ",{"data":34283,"content":34287,"nodeType":890},{"target":34284},{"sys":34285},{"id":34286,"type":887,"linkType":888},"5VsFECWlJ1HNGtC0jUcPjH",[],{"data":34289,"content":34290,"nodeType":881},{},[34291,34294,34301,34304,34311],{"data":34292,"marks":34293,"value":10795,"nodeType":867},{},[],{"data":34295,"content":34296,"nodeType":876},{"uri":10798},[34297],{"data":34298,"marks":34299,"value":10803,"nodeType":867},{},[34300],{"type":1040},{"data":34302,"marks":34303,"value":15213,"nodeType":867},{},[],{"data":34305,"content":34306,"nodeType":876},{"uri":1629},[34307],{"data":34308,"marks":34309,"value":10826,"nodeType":867},{},[34310],{"type":1040},{"data":34312,"marks":34313,"value":1947,"nodeType":867},{},[],"New phishing campaign identified targeting LinkedIn users","Diving into the latest sophisticated LinkedIn phishing campaign intercepted by Push. ","2025-10-30T00:00:00.000Z","new-phishing-campaign-identified-targeting-linkedin-users",{"items":34319},[34320,34322],{"sys":34321,"name":342},{"id":2550},{"sys":34323,"name":2547},{"id":2546},{"items":34325},[34326],{"fullName":849,"firstName":850,"jobTitle":851,"profilePicture":34327},{"url":855},{"__typename":1742,"sys":34329,"content":34331,"title":34988,"synopsis":34989,"hashTags":59,"publishedDate":34990,"slug":34991,"tagsCollection":34992,"authorsCollection":34998},{"id":34330},"7dqGkFzSMA00bIJ94rW4na",{"json":34332},{"data":34333,"content":34334,"nodeType":1640},{},[34335,34342,34349,34355,34380,34400,34403,34411,34418,34425,34433,34453,34456,34464,34471,34477,34484,34490,34493,34501,34508,34515,34538,34545,34578,34585,34593,34612,34619,34625,34652,34683,34691,34698,34705,34738,34741,34749,34768,34775,34798,34805,34811,34814,34822,34829,34954,34957,34964,34971],{"data":34336,"content":34337,"nodeType":881},{},[34338],{"data":34339,"marks":34340,"value":34341,"nodeType":867},{},[],"As awareness grows around many MFA methods being “phishable” (i.e. not phishing resistant), passwordless authentication methods are being increasingly advocated. ",{"data":34343,"content":34344,"nodeType":881},{},[34345],{"data":34346,"marks":34347,"value":34348,"nodeType":867},{},[],"This is a good thing. The most commonly used MFA factors (like SMS codes, push notifications, and app-based OTP) are routinely bypassed, with modern reverse-proxy phishing kits the most common method. ",{"data":34350,"content":34354,"nodeType":890},{"target":34351},{"sys":34352},{"id":34353,"type":887,"linkType":888},"ImwzE2R9qaHaqlWn0GqIa",[],{"data":34356,"content":34357,"nodeType":881},{},[34358,34362,34367,34371,34376],{"data":34359,"marks":34360,"value":34361,"nodeType":867},{},[],"Often referred to as a “passkey”, passwordless authentication typically consists of a hardware security device that is built-into your laptop (e.g. the fingerprint sensor on a laptop) or something you plug into your device (e.g. a Yubikey). Because passkey-based logins are domain-bound, trying to use a passkey for ",{"data":34363,"marks":34364,"value":34366,"nodeType":867},{},[34365],{"type":1040},"microsoft.com",{"data":34368,"marks":34369,"value":34370,"nodeType":867},{},[]," on ",{"data":34372,"marks":34373,"value":34375,"nodeType":867},{},[34374],{"type":1040},"phishing.com",{"data":34377,"marks":34378,"value":34379,"nodeType":867},{},[]," simply won’t generate the correct value to pass the authentication check, even when proxied using an AitM kit. ",{"data":34381,"content":34382,"nodeType":881},{},[34383,34387,34397],{"data":34384,"marks":34385,"value":34386,"nodeType":867},{},[],"However, attackers have realized that even as these new phishing-resistant methods are starting to become used, most users still have alternative MFA methods active. The attacker can then do what’s called a ",{"data":34388,"content":34390,"nodeType":876},{"uri":34389},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/mfa_downgrade/description.md",[34391],{"data":34392,"marks":34393,"value":34396,"nodeType":867},{},[34394,34395],{"type":1040},{"type":916},"downgrade attack",{"data":34398,"marks":34399,"value":1947,"nodeType":867},{},[],{"data":34401,"content":34402,"nodeType":908},{},[],{"data":34404,"content":34405,"nodeType":918},{},[34406],{"data":34407,"marks":34408,"value":34410,"nodeType":867},{},[34409],{"type":916},"Downgrade attacks 101",{"data":34412,"content":34413,"nodeType":881},{},[34414],{"data":34415,"marks":34416,"value":34417,"nodeType":867},{},[],"When conducting an Attacker-in-the-Middle phishing attack, the attacker doesn’t need to relay 100% of the messages accurately. Instead, they can alter some of them. The app might ask the user “You need to MFA — do you want to use your passkey, or your backup authenticator code?”, but the phishing website might modify this page to say “You need to MFA — use your backup authenticator code” not giving you the option to use your secure passkey. This is called a downgrade attack.",{"data":34419,"content":34420,"nodeType":881},{},[34421],{"data":34422,"marks":34423,"value":34424,"nodeType":867},{},[],"This can also be applied to accounts that use SSO as the default login method. In this scenario, the phish kit can select a backup username and password option to allow the phishing attack to proceed.  ",{"data":34426,"content":34427,"nodeType":881},{},[34428],{"data":34429,"marks":34430,"value":34432,"nodeType":867},{},[34431],{"type":916},"So, you have a situation where even if a phishing-resistant login method exists, the presence of a less secure backup method means the account is still vulnerable to phishing attacks. ",{"data":34434,"content":34435,"nodeType":881},{},[34436,34440,34449],{"data":34437,"marks":34438,"value":34439,"nodeType":867},{},[],"These attacks are effective across a number of sites and login methods that support passkey-based logins, for example, Windows Hello, Okta FastPass, and Google Workspace. As an example, here’s a link to a ",{"data":34441,"content":34443,"nodeType":876},{"uri":34442},"https://github.com/yudasm/WHfB-o365-Phishlet",[34444],{"data":34445,"marks":34446,"value":34448,"nodeType":867},{},[34447],{"type":1040},"custom phishlet for Evilginx",{"data":34450,"marks":34451,"value":34452,"nodeType":867},{},[]," targeting Windows Hello for Business. A small caveat is that changes made by Microsoft have since broken this plugin, but we were able to write our own custom phishlet to achieve the same outcome. ",{"data":34454,"content":34455,"nodeType":908},{},[],{"data":34457,"content":34458,"nodeType":918},{},[34459],{"data":34460,"marks":34461,"value":34463,"nodeType":867},{},[34462],{"type":916},"MFA downgrade in action",{"data":34465,"content":34466,"nodeType":881},{},[34467],{"data":34468,"marks":34469,"value":34470,"nodeType":867},{},[],"Check out the video below to see an example of using Evilginx with a custom phishlet to downgrade authentication for a Microsoft account using Windows Hello. ",{"data":34472,"content":34476,"nodeType":890},{"target":34473},{"sys":34474},{"id":34475,"type":887,"linkType":888},"54I3YQ2gK26a8FIocQ3WYT",[],{"data":34478,"content":34479,"nodeType":881},{},[34480],{"data":34481,"marks":34482,"value":34483,"nodeType":867},{},[],"We’ve encountered similar functionality in criminal phishing platforms we’ve investigated such as Tycoon — in this case, targeting Google accounts. This snippet is notable in that it includes JavaScript to abuse UI features to bypass passkeys.",{"data":34485,"content":34489,"nodeType":890},{"target":34486},{"sys":34487},{"id":34488,"type":887,"linkType":888},"5Vya1VApSisr0000HuTLY2",[],{"data":34491,"content":34492,"nodeType":908},{},[],{"data":34494,"content":34495,"nodeType":918},{},[34496],{"data":34497,"marks":34498,"value":34500,"nodeType":867},{},[34499],{"type":916},"Mitigations (and challenges)",{"data":34502,"content":34503,"nodeType":881},{},[34504],{"data":34505,"marks":34506,"value":34507,"nodeType":867},{},[],"MFA downgrade is made possible by the existence of backup authentication methods. So the obvious solution is to remove backup/unused login and MFA methods from your accounts, ensuring you’re accessing apps using SSO from a hardened Identity Provider (IdP) account (e.g. Okta, Entra, Google Workspace). ",{"data":34509,"content":34510,"nodeType":881},{},[34511],{"data":34512,"marks":34513,"value":34514,"nodeType":867},{},[],"In the ideal world, you’d be:",{"data":34516,"content":34517,"nodeType":3126},{},[34518,34528],{"data":34519,"content":34520,"nodeType":3061},{},[34521],{"data":34522,"content":34523,"nodeType":881},{},[34524],{"data":34525,"marks":34526,"value":34527,"nodeType":867},{},[],"Using only one IdP account, which you access via passkey, with no backup methods.",{"data":34529,"content":34530,"nodeType":3061},{},[34531],{"data":34532,"content":34533,"nodeType":881},{},[34534],{"data":34535,"marks":34536,"value":34537,"nodeType":867},{},[],"Accessing all business apps using SSO from your locked-down IdP account. ",{"data":34539,"content":34540,"nodeType":881},{},[34541],{"data":34542,"marks":34543,"value":34544,"nodeType":867},{},[],"The reality is way different, though. Because going totally passwordless is hard. It requires a large investment of time, money, and training for end-users. You’ll find many cautionary tales of companies starting on their passkey adoption journey and ultimately failing to make it a reality. This is largely because:",{"data":34546,"content":34547,"nodeType":3126},{},[34548,34558,34568],{"data":34549,"content":34550,"nodeType":3061},{},[34551],{"data":34552,"content":34553,"nodeType":881},{},[34554],{"data":34555,"marks":34556,"value":34557,"nodeType":867},{},[],"In environments with a mix of older and newer infrastructure, it can be challenging to get complete coverage. ",{"data":34559,"content":34560,"nodeType":3061},{},[34561],{"data":34562,"content":34563,"nodeType":881},{},[34564],{"data":34565,"marks":34566,"value":34567,"nodeType":867},{},[],"Not every device comes with an in-built biometric identification method, so you need to use a second device — which employees may struggle with (especially when they lose it and aren’t familiar with how to regain account access).",{"data":34569,"content":34570,"nodeType":3061},{},[34571],{"data":34572,"content":34573,"nodeType":881},{},[34574],{"data":34575,"marks":34576,"value":34577,"nodeType":867},{},[],"Most apps don’t allow you to log in directly with a passkey, meaning you need to SSO from your IdP account. But many apps don’t support every preferred SSO provider, and fail to provide SAML support, so there can be gaps.  ",{"data":34579,"content":34580,"nodeType":881},{},[34581],{"data":34582,"marks":34583,"value":34584,"nodeType":867},{},[],"And ultimately, because of the self-service, product-led growth fuelled nature of most online services today, it’s easy for users to slip back into using passwords — and hard for security teams to find and remove them (particularly if an app isn’t centrally managed). And the level of support that different apps provide users and administrators to secure how they access their services varies significantly. ",{"data":34586,"content":34587,"nodeType":998},{},[34588],{"data":34589,"marks":34590,"value":34592,"nodeType":867},{},[34591],{"type":916},"Most apps make removing phishable authentication hard",{"data":34594,"content":34595,"nodeType":881},{},[34596,34600,34608],{"data":34597,"marks":34598,"value":34599,"nodeType":867},{},[],"While some providers are taking steps to go passwordless by default, which makes it easier to remove passwords (e.g. ",{"data":34601,"content":34603,"nodeType":876},{"uri":34602},"https://techcommunity.microsoft.com/blog/microsoft-entra-blog/introducing-password-removal-for-microsoft-accounts/2747280",[34604],{"data":34605,"marks":34606,"value":15009,"nodeType":867},{},[34607],{"type":1040},{"data":34609,"marks":34610,"value":34611,"nodeType":867},{},[]," recently made a big deal of its desire to get rid of passwords), the quality of identity security management functionality varies significantly from app to app. ",{"data":34613,"content":34614,"nodeType":881},{},[34615],{"data":34616,"marks":34617,"value":34618,"nodeType":867},{},[],"Many apps default to the most recently used or strongest login method, but very few automatically lock you in to using the strongest method available. Most of the time, these kinds of controls also need to be configured in the app — which can be challenging if your security team doesn’t manage it (or simply isn’t aware of it). ",{"data":34620,"content":34624,"nodeType":890},{"target":34621},{"sys":34622},{"id":34623,"type":887,"linkType":888},"4X9MR0CbSMltOmw767XNOm",[],{"data":34626,"content":34627,"nodeType":881},{},[34628,34632,34637,34641,34648],{"data":34629,"marks":34630,"value":34631,"nodeType":867},{},[],"Finally, configuring MFA is often an additive process — you start by adding a phone number, then you add an authenticator app or a passkey. Just like we find that most accounts with SSO ",{"data":34633,"marks":34634,"value":34636,"nodeType":867},{},[34635],{"type":916},"also",{"data":34638,"marks":34639,"value":34640,"nodeType":867},{},[]," have a password login configured (also known as ",{"data":34642,"content":34643,"nodeType":876},{"uri":14589},[34644],{"data":34645,"marks":34646,"value":6850,"nodeType":867},{},[34647],{"type":1040},{"data":34649,"marks":34650,"value":34651,"nodeType":867},{},[],"), most accounts with MFA typically have multiple methods attached to their account. ",{"data":34653,"content":34654,"nodeType":881},{},[34655,34659,34667,34670,34679],{"data":34656,"marks":34657,"value":34658,"nodeType":867},{},[],"The result is that even if you can successfully lock down a handful of apps, many more will continue to be susceptible to phishing attacks using commonly available downgrade functionality. And as attackers diversify the apps they target (such as these recent examples targeting ",{"data":34660,"content":34662,"nodeType":876},{"uri":34661},"https://pushsecurity.com/blog/investigating-a-recent-malvertising-campaign-targeting-onfido-customers/",[34663],{"data":34664,"marks":34665,"value":31614,"nodeType":867},{},[34666],{"type":1040},{"data":34668,"marks":34669,"value":2063,"nodeType":867},{},[],{"data":34671,"content":34673,"nodeType":876},{"uri":34672},"https://pushsecurity.com/blog/dissecting-a-recent-mailchimp-phishing-attack/",[34674],{"data":34675,"marks":34676,"value":34678,"nodeType":867},{},[34677],{"type":1040},"MailChimp",{"data":34680,"marks":34681,"value":34682,"nodeType":867},{},[],"), this becomes increasingly likely. ",{"data":34684,"content":34685,"nodeType":998},{},[34686],{"data":34687,"marks":34688,"value":34690,"nodeType":867},{},[34689],{"type":916},"Conditional access is a useful mitigation if configured properly, but only on apps which support it",{"data":34692,"content":34693,"nodeType":881},{},[34694],{"data":34695,"marks":34696,"value":34697,"nodeType":867},{},[],"Conditional access policies are a useful last line of defense against account takeover attacks by denying logins that don't meet certain criteria, even if they user is able to authenticate. In larger IdP platforms that typically support more granular conditional access policies, this is a useful addition when configured correctly. However, many apps simply don't support conditional access, so will be vulnerable to attackers targeting them directly (as opposed to first logging into e.g. Microsoft or Google, and then accessing downstream apps via SSO). ",{"data":34699,"content":34700,"nodeType":881},{},[34701],{"data":34702,"marks":34703,"value":34704,"nodeType":867},{},[],"That said, locking down your core IdP platforms with robust conditional access should be a top priority for security teams. Useful policies that should be configured include:",{"data":34706,"content":34707,"nodeType":3126},{},[34708,34718,34728],{"data":34709,"content":34710,"nodeType":3061},{},[34711],{"data":34712,"content":34713,"nodeType":881},{},[34714],{"data":34715,"marks":34716,"value":34717,"nodeType":867},{},[],"Limiting logins to domain-joined devices.",{"data":34719,"content":34720,"nodeType":3061},{},[34721],{"data":34722,"content":34723,"nodeType":881},{},[34724],{"data":34725,"marks":34726,"value":34727,"nodeType":867},{},[],"Set phishing-resistant MFA as required. ",{"data":34729,"content":34730,"nodeType":3061},{},[34731],{"data":34732,"content":34733,"nodeType":881},{},[34734],{"data":34735,"marks":34736,"value":34737,"nodeType":867},{},[],"(Where possible) limit logins to trusted IP ranges. ",{"data":34739,"content":34740,"nodeType":908},{},[],{"data":34742,"content":34743,"nodeType":918},{},[34744],{"data":34745,"marks":34746,"value":34748,"nodeType":867},{},[34747],{"type":916},"Tackling MFA downgrade with Push Security",{"data":34750,"content":34751,"nodeType":881},{},[34752,34756,34764],{"data":34753,"marks":34754,"value":34755,"nodeType":867},{},[],"Phishing-resistant authentication methods like passkeys are key to the future of enterprise identity security, but organizations need to recognize that adopting passkeys isn’t a silver bullet. Ensuring that passkeys are the only authentication method supported by your business apps is no mean feat, considering ",{"data":34757,"content":34758,"nodeType":876},{"uri":6833},[34759],{"data":34760,"marks":34761,"value":34763,"nodeType":867},{},[34762],{"type":1040},"most organizations are using hundreds of them",{"data":34765,"marks":34766,"value":34767,"nodeType":867},{},[]," — all with their own specific ways of handling and administering identities. ",{"data":34769,"content":34770,"nodeType":881},{},[34771],{"data":34772,"marks":34773,"value":34774,"nodeType":867},{},[],"That’s why we support a layered defense, providing last-mile protection by:",{"data":34776,"content":34777,"nodeType":3126},{},[34778,34788],{"data":34779,"content":34780,"nodeType":3061},{},[34781],{"data":34782,"content":34783,"nodeType":881},{},[34784],{"data":34785,"marks":34786,"value":34787,"nodeType":867},{},[],"Intercepting and blocking phishing attacks in the browser to prevent AiTM attacks using downgrade techniques.",{"data":34789,"content":34790,"nodeType":3061},{},[34791],{"data":34792,"content":34793,"nodeType":881},{},[34794],{"data":34795,"marks":34796,"value":34797,"nodeType":867},{},[],"Identifying backup MFA and login methods across the business apps your employees use, so they can be removed (individually or through app-level configuration changes).",{"data":34799,"content":34800,"nodeType":881},{},[34801],{"data":34802,"marks":34803,"value":34804,"nodeType":867},{},[],"Here’s how it works.",{"data":34806,"content":34810,"nodeType":890},{"target":34807},{"sys":34808},{"id":34809,"type":887,"linkType":888},"2uvItnfaOQZHa4a9BIIhRn",[],{"data":34812,"content":34813,"nodeType":908},{},[],{"data":34815,"content":34816,"nodeType":918},{},[34817],{"data":34818,"marks":34819,"value":34821,"nodeType":867},{},[34820],{"type":916},"Further reading",{"data":34823,"content":34824,"nodeType":881},{},[34825],{"data":34826,"marks":34827,"value":34828,"nodeType":867},{},[],"MFA downgrade is just one method of getting into an otherwise locked-down account. Attackers are also finding ways to bypass the standard authentication process entirely, through: ",{"data":34830,"content":34831,"nodeType":3126},{},[34832,34866,34899,34919],{"data":34833,"content":34834,"nodeType":3061},{},[34835],{"data":34836,"content":34837,"nodeType":881},{},[34838,34841,34850,34854,34863],{"data":34839,"marks":34840,"value":21,"nodeType":867},{},[],{"data":34842,"content":34844,"nodeType":876},{"uri":34843},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/app_specific_password_phishing/description.md",[34845],{"data":34846,"marks":34847,"value":34849,"nodeType":867},{},[34848],{"type":1040},"App-specific password phishing",{"data":34851,"marks":34852,"value":34853,"nodeType":867},{},[],", where attackers can abuse functionality designed to enable users to log into apps that don’t support modern authentication. (",{"data":34855,"content":34857,"nodeType":876},{"uri":34856},"https://pushsecurity.com/blog/app-specific-password-phishing/",[34858],{"data":34859,"marks":34860,"value":34862,"nodeType":867},{},[34861],{"type":1040},"Read the article for more information here",{"data":34864,"marks":34865,"value":11572,"nodeType":867},{},[],{"data":34867,"content":34868,"nodeType":3061},{},[34869],{"data":34870,"content":34871,"nodeType":881},{},[34872,34875,34882,34886,34895],{"data":34873,"marks":34874,"value":21,"nodeType":867},{},[],{"data":34876,"content":34877,"nodeType":876},{"uri":25732},[34878],{"data":34879,"marks":34880,"value":31869,"nodeType":867},{},[34881],{"type":1040},{"data":34883,"marks":34884,"value":34885,"nodeType":867},{},[],", which sees the victim accept OAuth scopes for an attacker-controlled app integration granting access to the account without needing to directly compromise it. (",{"data":34887,"content":34889,"nodeType":876},{"uri":34888},"https://pushsecurity.com/blog/how-consent-phishing-is-evolving/",[34890],{"data":34891,"marks":34892,"value":34894,"nodeType":867},{},[34893],{"type":1040},"You can read more about recent examples here",{"data":34896,"marks":34897,"value":34898,"nodeType":867},{},[],".) ",{"data":34900,"content":34901,"nodeType":3061},{},[34902],{"data":34903,"content":34904,"nodeType":881},{},[34905,34908,34915],{"data":34906,"marks":34907,"value":21,"nodeType":867},{},[],{"data":34909,"content":34910,"nodeType":876},{"uri":15982},[34911],{"data":34912,"marks":34913,"value":360,"nodeType":867},{},[34914],{"type":1040},{"data":34916,"marks":34917,"value":34918,"nodeType":867},{},[],", functionally very similar to consent phishing but involving the victim entering a code for authorization. ",{"data":34920,"content":34921,"nodeType":3061},{},[34922],{"data":34923,"content":34924,"nodeType":881},{},[34925,34928,34937,34941,34950],{"data":34926,"marks":34927,"value":21,"nodeType":867},{},[],{"data":34929,"content":34931,"nodeType":876},{"uri":34930},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/cross-idp_impersonation/description.md",[34932],{"data":34933,"marks":34934,"value":34936,"nodeType":867},{},[34935],{"type":1040},"Cross-IdP impersonation",{"data":34938,"marks":34939,"value":34940,"nodeType":867},{},[],", which sees the attacker register a new IdP connected to the victim’s email account that can be used to access connected apps via SSO without directly compromising the primary IdP. (",{"data":34942,"content":34944,"nodeType":876},{"uri":34943},"https://pushsecurity.com/blog/a-new-class-of-phishing-verification-phishing-and-cross-idp-impersonation/",[34945],{"data":34946,"marks":34947,"value":34949,"nodeType":867},{},[34948],{"type":1040},"You can read more about this here",{"data":34951,"marks":34952,"value":34953,"nodeType":867},{},[],".)",{"data":34955,"content":34956,"nodeType":908},{},[],{"data":34958,"content":34959,"nodeType":918},{},[34960],{"data":34961,"marks":34962,"value":4330,"nodeType":867},{},[34963],{"type":916},{"data":34965,"content":34966,"nodeType":881},{},[34967],{"data":34968,"marks":34969,"value":34970,"nodeType":867},{},[],"Push Security’s browser-based security platform provides comprehensive identity attack detection and response capabilities against techniques like AiTM phishing, credential stuffing, password spraying and session hijacking using stolen session tokens. You can also use Push to find and fix identity vulnerabilities across every app that your employees use, like: ghost logins; SSO coverage gaps; MFA gaps; weak, breached and reused passwords; risky OAuth integrations; and more.",{"data":34972,"content":34973,"nodeType":881},{},[34974,34978,34985],{"data":34975,"marks":34976,"value":34977,"nodeType":867},{},[],"If you want to learn more about how Push helps you to detect and defeat common identity attack techniques, ",{"data":34979,"content":34980,"nodeType":876},{"uri":2362},[34981],{"data":34982,"marks":34983,"value":10826,"nodeType":867},{},[34984],{"type":1040},{"data":34986,"marks":34987,"value":1947,"nodeType":867},{},[],"MFA downgrade: How attackers are getting around phishing-resistant authentication","MFA downgrade attacks are an increasingly common technique used by attackers to bypass phishing-resistant authentication methods registered to an account.","2025-07-21T00:00:00.000Z","mfa-downgrade-attacks",{"items":34993},[34994,34996],{"sys":34995,"name":342},{"id":2550},{"sys":34997,"name":2547},{"id":2546},{"items":34999},[35000],{"fullName":15937,"firstName":15938,"jobTitle":15939,"profilePicture":35001},{"url":15943},"blog/scattered-lapsus-hunters",{"json":35004},{"data":35005,"content":35006,"nodeType":1640},{},[35007],{"data":35008,"content":35009,"nodeType":881},{},[35010],{"data":35011,"marks":35012,"value":35013,"nodeType":867},{},[],"In this blog post, we’ll be taking a closer look at the breaches linked to Scattered Lapsus$ Hunters, the evolution of TTPs that makes them so successful, and how they’re shaping the current and next generation of cyber criminals.",{"id":14277,"publishedAt":35015},"2026-08-12T11:53:35.368Z",{"items":35017},[35018,35020],{"sys":35019,"name":2547},{"id":2546},{"sys":35021,"name":342},{"id":2550},{"items":35023},[35024,35026,35028,35030,35032,35034,35036,35038,35040,35042,35044,35046,35048,35050,35052],{"sys":35025,"name":279,"slug":280,"tier":31},{"id":276},{"sys":35027,"name":413,"slug":414,"tier":31},{"id":410},{"sys":35029,"name":642,"slug":643,"tier":31},{"id":639},{"sys":35031,"name":650,"slug":651,"tier":45},{"id":647},{"sys":35033,"name":261,"slug":262,"tier":45},{"id":258},{"sys":35035,"name":404,"slug":405,"tier":45},{"id":401},{"sys":35037,"name":537,"slug":538,"tier":45},{"id":534},{"sys":35039,"name":333,"slug":334,"tier":45},{"id":330},{"sys":35041,"name":607,"slug":608,"tier":45},{"id":604},{"sys":35043,"name":484,"slug":485,"tier":45},{"id":481},{"sys":35045,"name":288,"slug":289,"tier":45},{"id":285},{"sys":35047,"name":422,"slug":423,"tier":45},{"id":419},{"sys":35049,"name":571,"slug":572,"tier":45},{"id":568},{"sys":35051,"name":528,"slug":529,"tier":45},{"id":525},{"sys":35053,"name":395,"slug":396,"tier":45},{"id":392},"cPGKjifHC8Xc0ke0Qls0IvBKrqcQS7B54QT7CK7Q1JI",{"id":35056,"title":35057,"authorsCollection":35058,"content":35063,"extension":228,"faqItemsCollection":35869,"faqTitle":59,"featured":6,"hashTags":59,"meta":35871,"metaTitle":35872,"ogImage":35873,"postType":22758,"publishedDate":35875,"relatedBlogPostsCollection":35876,"slug":37419,"stem":37420,"subtitle":59,"summary":37421,"synopsis":37432,"sys":37433,"tagsCollection":37436,"topicsCollection":37442,"__hash__":37480},"blog/blog/key-takeaways-from-the-scattered-spider-attacks-on-insurance-firms.json","3 key takeaways from the Scattered Spider attacks on aviation & insurance firms",{"items":35059},[35060],{"fullName":849,"firstName":850,"jobTitle":851,"socialLinks":35061,"profilePicture":35062},[853],{"url":855},{"json":35064,"links":35774},{"data":35065,"content":35066,"nodeType":1640},{},[35067,35072,35136,35143,35150,35153,35159,35166,35214,35221,35224,35231,35259,35348,35364,35369,35372,35379,35386,35392,35398,35405,35483,35490,35532,35540,35543,35550,35557,35564,35571,35578,35584,35587,35594,35614,35621,35644,35651,35654,35660,35666,35672,35677,35694,35699,35705,35712,35718,35721,35727,35746,35763,35768],{"data":35068,"content":35071,"nodeType":890},{"target":35069},{"sys":35070},{"id":15249,"type":887,"linkType":888},[],{"data":35073,"content":35074,"nodeType":881},{},[35075,35079,35086,35089,35096,35099,35106,35109,35115,35118,35124,35127,35133],{"data":35076,"marks":35077,"value":35078,"nodeType":867},{},[],"Scattered Spider continues to dominate the headlines, with the latest news linking the hackers to attacks on U.S. insurance giant ",{"data":35080,"content":35081,"nodeType":876},{"uri":15385},[35082],{"data":35083,"marks":35084,"value":15391,"nodeType":867},{},[35085],{"type":1040},{"data":35087,"marks":35088,"value":4006,"nodeType":867},{},[],{"data":35090,"content":35091,"nodeType":876},{"uri":15397},[35092],{"data":35093,"marks":35094,"value":15403,"nodeType":867},{},[35095],{"type":1040},{"data":35097,"marks":35098,"value":4006,"nodeType":867},{},[],{"data":35100,"content":35101,"nodeType":876},{"uri":15410},[35102],{"data":35103,"marks":35104,"value":15416,"nodeType":867},{},[35105],{"type":1040},{"data":35107,"marks":35108,"value":15420,"nodeType":867},{},[],{"data":35110,"content":35111,"nodeType":876},{"uri":15423},[35112],{"data":35113,"marks":35114,"value":15428,"nodeType":867},{},[],{"data":35116,"marks":35117,"value":4006,"nodeType":867},{},[],{"data":35119,"content":35120,"nodeType":876},{"uri":15434},[35121],{"data":35122,"marks":35123,"value":15439,"nodeType":867},{},[],{"data":35125,"marks":35126,"value":2063,"nodeType":867},{},[],{"data":35128,"content":35129,"nodeType":876},{"uri":15434},[35130],{"data":35131,"marks":35132,"value":15449,"nodeType":867},{},[],{"data":35134,"marks":35135,"value":1253,"nodeType":867},{},[],{"data":35137,"content":35138,"nodeType":881},{},[35139],{"data":35140,"marks":35141,"value":35142,"nodeType":867},{},[],"This comes at the same time that Google Threat Intelligence Group shared that it “is now aware of multiple intrusions in the U.S. which bear the hallmarks of Scattered Spider activity”, specifically impacting the insurance industry. ",{"data":35144,"content":35145,"nodeType":881},{},[35146],{"data":35147,"marks":35148,"value":35149,"nodeType":867},{},[],"But what exactly does this mean? To answer this, let’s quickly recap how we got here and what a Scattered Spider attack looks like.  ",{"data":35151,"content":35152,"nodeType":908},{},[],{"data":35154,"content":35155,"nodeType":918},{},[35156],{"data":35157,"marks":35158,"value":14313,"nodeType":867},{},[],{"data":35160,"content":35161,"nodeType":881},{},[35162],{"data":35163,"marks":35164,"value":35165,"nodeType":867},{},[],"The criminal collective tracked by analysts as Scattered Spider has been active since 2022 and have been linked to a range of high-profile breaches, for example the attacks on Caesars and MGM Resorts in 2023, and Transport for London in 2024. ",{"data":35167,"content":35168,"nodeType":3126},{},[35169,35184,35199],{"data":35170,"content":35171,"nodeType":3061},{},[35172],{"data":35173,"content":35174,"nodeType":881},{},[35175,35180],{"data":35176,"marks":35177,"value":35179,"nodeType":867},{},[35178],{"type":916},"Caesars: ",{"data":35181,"marks":35182,"value":35183,"nodeType":867},{},[],"hackers impersonated an IT user and convinced an outsourced help desk to reset credentials, after which the attacker stole the customer loyalty program database and secured a $15m ransom payment. ",{"data":35185,"content":35186,"nodeType":3061},{},[35187],{"data":35188,"content":35189,"nodeType":881},{},[35190,35195],{"data":35191,"marks":35192,"value":35194,"nodeType":867},{},[35193],{"type":916},"MGM Resorts: ",{"data":35196,"marks":35197,"value":35198,"nodeType":867},{},[],"hackers used LinkedIn information to impersonate an employee and reset the employee’s credentials, resulting in a 6TB data theft. After MGM refused to pay, the attack eventually resulted in a 36-hour outage, a $100m hit, and a class-action lawsuit settled for $45m. ",{"data":35200,"content":35201,"nodeType":3061},{},[35202],{"data":35203,"content":35204,"nodeType":881},{},[35205,35210],{"data":35206,"marks":35207,"value":35209,"nodeType":867},{},[35208],{"type":916},"Transport for London:",{"data":35211,"marks":35212,"value":35213,"nodeType":867},{},[]," resulted in 5,000 users’ bank details exposed, 30,000 staff required to attend in-person appointments to verify their identities and reset passwords, and significant disruption to online services lasting for months.",{"data":35215,"content":35216,"nodeType":881},{},[35217],{"data":35218,"marks":35219,"value":35220,"nodeType":867},{},[],"The calling card in these attacks was the abuse of help desk processes to reset passwords and/or MFA factors used to access an account. The attacker simply calls up the help desk with enough information to impersonate an employee, asks them to send an MFA enrollment link for their new mobile device, and can then utilize self-service password reset functionality to take control of the account. Scarily simple. ",{"data":35222,"content":35223,"nodeType":908},{},[],{"data":35225,"content":35226,"nodeType":918},{},[35227],{"data":35228,"marks":35229,"value":35230,"nodeType":867},{},[],"Scattered Spider’s resurgence in 2025",{"data":35232,"content":35233,"nodeType":881},{},[35234,35238,35245,35248,35255],{"data":35235,"marks":35236,"value":35237,"nodeType":867},{},[],"This technique was reprised in a series of high-profile attacks in 2025, with major breaches of UK retailers ",{"data":35239,"content":35240,"nodeType":876},{"uri":15260},[35241],{"data":35242,"marks":35243,"value":15266,"nodeType":867},{},[35244],{"type":1040},{"data":35246,"marks":35247,"value":2063,"nodeType":867},{},[],{"data":35249,"content":35250,"nodeType":876},{"uri":15272},[35251],{"data":35252,"marks":35253,"value":15278,"nodeType":867},{},[35254],{"type":1040},{"data":35256,"marks":35257,"value":35258,"nodeType":867},{},[]," dominating the headlines. Both resulted in the loss of sensitive data and prolonged disruption to in-store and digital services, with M&S feeling the pain of £300m in lost profits and a share value hit approaching £1b, and a multimillion-pound class action lawsuit and possible ICO fines looming.",{"data":35260,"content":35261,"nodeType":881},{},[35262,35265,35272,35275,35282,35285,35292,35295,35302,35305,35312,35315,35322,35325,35332,35336,35344],{"data":35263,"marks":35264,"value":15289,"nodeType":867},{},[],{"data":35266,"content":35267,"nodeType":876},{"uri":15292},[35268],{"data":35269,"marks":35270,"value":15298,"nodeType":867},{},[35271],{"type":1040},{"data":35273,"marks":35274,"value":4006,"nodeType":867},{},[],{"data":35276,"content":35277,"nodeType":876},{"uri":15304},[35278],{"data":35279,"marks":35280,"value":15310,"nodeType":867},{},[35281],{"type":1040},{"data":35283,"marks":35284,"value":4006,"nodeType":867},{},[],{"data":35286,"content":35287,"nodeType":876},{"uri":15316},[35288],{"data":35289,"marks":35290,"value":15322,"nodeType":867},{},[35291],{"type":1040},{"data":35293,"marks":35294,"value":4006,"nodeType":867},{},[],{"data":35296,"content":35297,"nodeType":876},{"uri":15328},[35298],{"data":35299,"marks":35300,"value":15334,"nodeType":867},{},[35301],{"type":1040},{"data":35303,"marks":35304,"value":4006,"nodeType":867},{},[],{"data":35306,"content":35307,"nodeType":876},{"uri":15340},[35308],{"data":35309,"marks":35310,"value":15346,"nodeType":867},{},[35311],{"type":1040},{"data":35313,"marks":35314,"value":4006,"nodeType":867},{},[],{"data":35316,"content":35317,"nodeType":876},{"uri":15352},[35318],{"data":35319,"marks":35320,"value":15358,"nodeType":867},{},[35321],{"type":1040},{"data":35323,"marks":35324,"value":15362,"nodeType":867},{},[],{"data":35326,"content":35327,"nodeType":876},{"uri":15365},[35328],{"data":35329,"marks":35330,"value":15371,"nodeType":867},{},[35331],{"type":1040},{"data":35333,"marks":35334,"value":35335,"nodeType":867},{},[]," were among the retailers to suffer a breach between May-June 2025. Unlike the ",{"data":35337,"content":35338,"nodeType":876},{"uri":14576},[35339],{"data":35340,"marks":35341,"value":35343,"nodeType":867},{},[35342],{"type":1040},"mass Snowflake breaches in 2024",{"data":35345,"marks":35346,"value":35347,"nodeType":867},{},[]," (which targeted a single platform used by many organizations), these attacks are notable in that they are seemingly unrelated — they simply represent a concerted effort by attackers to target the retail sector. ",{"data":35349,"content":35350,"nodeType":881},{},[35351,35355,35360],{"data":35352,"marks":35353,"value":35354,"nodeType":867},{},[],"Less details have been provided about these attacks compared to the M&S and Co-op breaches, but a number of them specifically point to the use of ",{"data":35356,"marks":35357,"value":35359,"nodeType":867},{},[35358],{"type":916},"identity-based techniques",{"data":35361,"marks":35362,"value":35363,"nodeType":867},{},[]," as opposed to more traditional software exploits — another hallmark of Scattered Spider. This leads us to our first key takeaway…",{"data":35365,"content":35368,"nodeType":890},{"target":35366},{"sys":35367},{"id":15742,"type":887,"linkType":888},[],{"data":35370,"content":35371,"nodeType":908},{},[],{"data":35373,"content":35374,"nodeType":918},{},[35375],{"data":35376,"marks":35377,"value":35378,"nodeType":867},{},[],"Takeaway #1: Identity-based TTPs are the new normal",{"data":35380,"content":35381,"nodeType":881},{},[35382],{"data":35383,"marks":35384,"value":35385,"nodeType":867},{},[],"Scattered Spider’s attacks are the latest in a growing number of identity-based breaches. When we look back at Scattered Spider’s TTP evolution, we can see that they have consistently exploited identity-based weaknesses in order to gain access to victim environments. ",{"data":35387,"content":35391,"nodeType":890},{"target":35388},{"sys":35389},{"id":35390,"type":887,"linkType":888},"2vs8WgO4gfGLxscjGMBSY6",[],{"data":35393,"content":35394,"nodeType":881},{},[35395],{"data":35396,"marks":35397,"value":15624,"nodeType":867},{},[],{"data":35399,"content":35400,"nodeType":881},{},[35401],{"data":35402,"marks":35403,"value":35404,"nodeType":867},{},[],"Scattered Spider has heavily relied on identity-based TTPs since they first emerged in 2022, following a repeatable path of bypassing MFA, achieving account takeover on privileged accounts, stealing data from cloud services, and deploying ransomware (principally in VMware environments). TTPs used by Scattered Spider include:",{"data":35406,"content":35407,"nodeType":3126},{},[35408,35417,35426,35445,35454,35463],{"data":35409,"content":35410,"nodeType":3061},{},[35411],{"data":35412,"content":35413,"nodeType":881},{},[35414],{"data":35415,"marks":35416,"value":15656,"nodeType":867},{},[],{"data":35418,"content":35419,"nodeType":3061},{},[35420],{"data":35421,"content":35422,"nodeType":881},{},[35423],{"data":35424,"marks":35425,"value":15666,"nodeType":867},{},[],{"data":35427,"content":35428,"nodeType":3061},{},[35429],{"data":35430,"content":35431,"nodeType":881},{},[35432,35435,35442],{"data":35433,"marks":35434,"value":15676,"nodeType":867},{},[],{"data":35436,"content":35437,"nodeType":876},{"uri":14532},[35438],{"data":35439,"marks":35440,"value":14537,"nodeType":867},{},[35441],{"type":1040},{"data":35443,"marks":35444,"value":15687,"nodeType":867},{},[],{"data":35446,"content":35447,"nodeType":3061},{},[35448],{"data":35449,"content":35450,"nodeType":881},{},[35451],{"data":35452,"marks":35453,"value":15697,"nodeType":867},{},[],{"data":35455,"content":35456,"nodeType":3061},{},[35457],{"data":35458,"content":35459,"nodeType":881},{},[35460],{"data":35461,"marks":35462,"value":15707,"nodeType":867},{},[],{"data":35464,"content":35465,"nodeType":3061},{},[35466],{"data":35467,"content":35468,"nodeType":881},{},[35469,35472,35479],{"data":35470,"marks":35471,"value":15717,"nodeType":867},{},[],{"data":35473,"content":35474,"nodeType":876},{"uri":15720},[35475],{"data":35476,"marks":35477,"value":15726,"nodeType":867},{},[35478],{"type":1040},{"data":35480,"marks":35481,"value":35482,"nodeType":867},{},[]," to steal live user sessions",{"data":35484,"content":35485,"nodeType":881},{},[35486],{"data":35487,"marks":35488,"value":35489,"nodeType":867},{},[],"So, help desk scams are an important part of their toolkit, but it’s not the whole picture. Methods like AiTM phishing in particular have spiked in popularity this year as a reliable and scalable way of bypassing MFA and achieving account takeover.",{"data":35491,"content":35492,"nodeType":881},{},[35493,35497,35506,35509,35516,35520,35529],{"data":35494,"marks":35495,"value":35496,"nodeType":867},{},[],"It’s important not to think about these techniques as just a Scattered Spider trait either. After all, Scattered Spider is not a self-identified group — it’s a name given by analysts to patterns of activity. Given the series of arrests in 2024, it’s unlikely that the current incarnation of Scattered Spider is the same individuals behind the attacks in 2022-2024. And these identity-based attack patterns are shared across various self-named criminal groups like, ",{"data":35498,"content":35500,"nodeType":876},{"uri":35499},"https://www.cisa.gov/sites/default/files/2023-08/CSRB_Lapsus%24_508c.pdf",[35501],{"data":35502,"marks":35503,"value":35505,"nodeType":867},{},[35504],{"type":1040},"Lapsus$, Yanluowang, Karakurt",{"data":35507,"marks":35508,"value":15362,"nodeType":867},{},[],{"data":35510,"content":35511,"nodeType":876},{"uri":14576},[35512],{"data":35513,"marks":35514,"value":8186,"nodeType":867},{},[35515],{"type":1040},{"data":35517,"marks":35518,"value":35519,"nodeType":867},{},[],". Even Russian state-sponsored actors are ",{"data":35521,"content":35523,"nodeType":876},{"uri":35522},"https://www.microsoft.com/en-us/security/blog/2025/05/27/new-russia-affiliated-actor-void-blizzard-targets-critical-sectors-for-espionage/",[35524],{"data":35525,"marks":35526,"value":35528,"nodeType":867},{},[35527],{"type":1040},"increasingly using the kinds of techniques popularised by criminal groups",{"data":35530,"marks":35531,"value":1947,"nodeType":867},{},[],{"data":35533,"content":35534,"nodeType":881},{},[35535],{"data":35536,"marks":35537,"value":35539,"nodeType":867},{},[35538],{"type":916},"Simply, identity-based techniques are the new normal for attackers in 2025. ",{"data":35541,"content":35542,"nodeType":908},{},[],{"data":35544,"content":35545,"nodeType":918},{},[35546],{"data":35547,"marks":35548,"value":35549,"nodeType":867},{},[],"Takeaway #2: Help desk scams aren't new, but they're here to stay",{"data":35551,"content":35552,"nodeType":881},{},[35553],{"data":35554,"marks":35555,"value":35556,"nodeType":867},{},[],"As we established earlier, help desk scams are nothing new (we saw them in the Caesars, MGM Resorts, and Transport for London breaches to name a few). But they’re likely to become increasingly prevalent as Scattered Spider continues to demonstrate just how effective help desk scams are. ",{"data":35558,"content":35559,"nodeType":881},{},[35560],{"data":35561,"marks":35562,"value":35563,"nodeType":867},{},[],"One of the reasons they’re so effective is that most help desks have the same process for every account — it doesn’t matter who you’re impersonating or which account you’re trying to reset. So, attackers are specifically targeting accounts likely to have top tier admin privileges — meaning once they get in, progressing the attack is trivial and much of the typical privilege escalation and lateral movement is removed from the attack path. ",{"data":35565,"content":35566,"nodeType":881},{},[35567],{"data":35568,"marks":35569,"value":35570,"nodeType":867},{},[],"Help desks are a target for a reason. They’re “helpful” by nature. This is usually reflected in how they’re operated and performance measured — delays won’t help you to hit those SLAs! Ultimately, a process only works if employees are willing to adhere to it — and can’t be socially engineered to break it. Help desks that are removed from day-to-day operations (especially when outsourced or offshored) are also inherently susceptible to attacks where employees are impersonated. ",{"data":35572,"content":35573,"nodeType":881},{},[35574],{"data":35575,"marks":35576,"value":35577,"nodeType":867},{},[],"But, the attacks that organizations are experiencing at the moment should give security stakeholders plenty of ammunition as to why help desk reforms are vital to securing the business (and what can happen if you don’t make changes). ",{"data":35579,"content":35583,"nodeType":890},{"target":35580},{"sys":35581},{"id":35582,"type":887,"linkType":888},"5Z3J9QuPKesWShV4OGMrYt",[],{"data":35585,"content":35586,"nodeType":908},{},[],{"data":35588,"content":35589,"nodeType":918},{},[35590],{"data":35591,"marks":35592,"value":35593,"nodeType":867},{},[],"Takeaway #3: Scattered Spider are consciously evading established security controls",{"data":35595,"content":35596,"nodeType":881},{},[35597,35601,35606,35609],{"data":35598,"marks":35599,"value":35600,"nodeType":867},{},[],"So, there’s more to Scattered Spider’s toolkit than just help desk scams. In fact, their approach can be broadly classified as",{"data":35602,"marks":35603,"value":35605,"nodeType":867},{},[35604],{"type":916}," consciously evading established controls",{"data":35607,"marks":35608,"value":3679,"nodeType":867},{},[],{"data":35610,"marks":35611,"value":35613,"nodeType":867},{},[35612],{"type":916},"at the endpoint and network layer by targeting identities. ",{"data":35615,"content":35616,"nodeType":881},{},[35617],{"data":35618,"marks":35619,"value":35620,"nodeType":867},{},[],"From the point of account takeover, they also follow repeatable patterns:",{"data":35622,"content":35623,"nodeType":3126},{},[35624,35634],{"data":35625,"content":35626,"nodeType":3061},{},[35627],{"data":35628,"content":35629,"nodeType":881},{},[35630],{"data":35631,"marks":35632,"value":35633,"nodeType":867},{},[],"Harvesting and exfiltrating data from cloud and SaaS services, where monitoring is typically less consistent than traditional on-premise environments, and exfiltration often blends in with normal activity. Many organizations simply don’t have the logs or visibility to detect malicious activity in the cloud anyway, and Scattered Spider have also been seen tampering with cloud logs (e.g. filtering risky AWS CloudTrail logs, but not disabling it entirely so as not to raise suspicion).",{"data":35635,"content":35636,"nodeType":3061},{},[35637],{"data":35638,"content":35639,"nodeType":881},{},[35640],{"data":35641,"marks":35642,"value":35643,"nodeType":867},{},[],"Targeting VMware environments for ransomware deployment. They do this by adding their compromised user account to the VMware admins group in VCentre (if needed — they are going after accounts with top tier privileges by default). From here, they can access the VMware environment via the ESXi hypervisor layer, where security software is nonexistent — thereby bypassing EDR and other typical endpoint and host based controls you rely on to prevent ransomware execution. ",{"data":35645,"content":35646,"nodeType":881},{},[35647],{"data":35648,"marks":35649,"value":35650,"nodeType":867},{},[],"The key theme? Getting around your established security controls. ",{"data":35652,"content":35653,"nodeType":908},{},[],{"data":35655,"content":35656,"nodeType":918},{},[35657],{"data":35658,"marks":35659,"value":15753,"nodeType":867},{},[],{"data":35661,"content":35662,"nodeType":881},{},[35663],{"data":35664,"marks":35665,"value":15760,"nodeType":867},{},[],{"data":35667,"content":35668,"nodeType":881},{},[35669],{"data":35670,"marks":35671,"value":15767,"nodeType":867},{},[],{"data":35673,"content":35676,"nodeType":890},{"target":35674},{"sys":35675},{"id":15772,"type":887,"linkType":888},[],{"data":35678,"content":35679,"nodeType":881},{},[35680,35684,35691],{"data":35681,"marks":35682,"value":35683,"nodeType":867},{},[],"To help combat help desk scams, Push recently released ",{"data":35685,"content":35686,"nodeType":876},{"uri":15783},[35687],{"data":35688,"marks":35689,"value":15790,"nodeType":867},{},[35690],{"type":916},{"data":35692,"marks":35693,"value":15794,"nodeType":867},{},[],{"data":35695,"content":35698,"nodeType":890},{"target":35696},{"sys":35697},{"id":15799,"type":887,"linkType":888},[],{"data":35700,"content":35701,"nodeType":881},{},[35702],{"data":35703,"marks":35704,"value":15807,"nodeType":867},{},[],{"data":35706,"content":35707,"nodeType":881},{},[35708],{"data":35709,"marks":35710,"value":35711,"nodeType":867},{},[],"Eric Rubin — a Senior Manager in GitLab’s Corporate Security team — has already rolled out Employee Identity Verification Codes across his workforce. Here’s what he had to say:",{"data":35713,"content":35717,"nodeType":890},{"target":35714},{"sys":35715},{"id":35716,"type":887,"linkType":888},"jHH13doHHHaqUUxHoBeKW",[],{"data":35719,"content":35720,"nodeType":908},{},[],{"data":35722,"content":35723,"nodeType":918},{},[35724],{"data":35725,"marks":35726,"value":15817,"nodeType":867},{},[],{"data":35728,"content":35729,"nodeType":881},{},[35730,35733,35742],{"data":35731,"marks":35732,"value":15824,"nodeType":867},{},[],{"data":35734,"content":35736,"nodeType":876},{"uri":35735},"https://pushsecurity.com/free-tool/employee-verification-codes?utm_campaign=15408561-FY25Q2-Employee-verification-codes&utm_source=Sponsored-content&utm_content=bleepingcomputer",[35737],{"data":35738,"marks":35739,"value":35741,"nodeType":867},{},[35740],{"type":1040},"sign up for a trial account and you can deploy the extension organization-wide to make use of this feature.",{"data":35743,"marks":35744,"value":35745,"nodeType":867},{},[]," While you’re at it, you can trial Push’s full features for up to 10 users for free. ",{"data":35747,"content":35748,"nodeType":881},{},[35749,35752,35760],{"data":35750,"marks":35751,"value":15844,"nodeType":867},{},[],{"data":35753,"content":35755,"nodeType":876},{"uri":35754},"https://pushsecurity.com/demo/?utm_campaign=12883224-FY25Q2_Scattered-Spider&utm_source=bleepingcomputer&utm_content=sponsored-article",[35756],{"data":35757,"marks":35758,"value":10826,"nodeType":867},{},[35759],{"type":1040},{"data":35761,"marks":35762,"value":1947,"nodeType":867},{},[],{"data":35764,"content":35767,"nodeType":890},{"target":35765},{"sys":35766},{"id":15859,"type":887,"linkType":888},[],{"data":35769,"content":35770,"nodeType":881},{},[35771],{"data":35772,"marks":35773,"value":21,"nodeType":867},{},[],{"entries":35775},{"hyperlink":35776,"inline":35777,"block":35778},[],[],[35779,35815,35820,35826,35850,35855,35858,35865],{"sys":35780,"__typename":1696,"content":35781,"name":35814,"title":59},{"id":15249},{"json":35782},{"nodeType":1640,"data":35783,"content":35784},{},[35785],{"nodeType":881,"data":35786,"content":35787},{},[35788,35792,35799,35803,35810],{"nodeType":867,"value":35789,"marks":35790,"data":35791},"It's been a busy year for cyber criminals! This article has now been superseded with the rise to infamy of ",[],{},{"nodeType":876,"data":35793,"content":35794},{"uri":31660},[35795],{"nodeType":867,"value":35796,"marks":35797,"data":35798},"\"Scattered Lapsus$ Hunters\"",[],{},{"nodeType":867,"value":35800,"marks":35801,"data":35802},". The guidance and TTPs in this blog post still apply, but ",[],{},{"nodeType":876,"data":35804,"content":35805},{"uri":31660},[35806],{"nodeType":867,"value":35807,"marks":35808,"data":35809},"check out our new post",[],{},{"nodeType":867,"value":35811,"marks":35812,"data":35813}," for the full picture of Scattered Spider-linked breaches dating back to 2021. ",[],{},"SS insight box 1",{"sys":35816,"__typename":22749,"type":22750,"ctaText":35817,"buttonLabel":35818,"buttonColour":22753,"buttonUrl":35819},{"id":15742},"Learn about Scattered Spider's latest TTPs in our on-demand webinar","Watch on-demand","https://pushsecurity.com/webinar/scatteredspider",{"sys":35821,"__typename":1648,"title":35822,"caption":35822,"layoutMode":59,"file":35823},{"id":35390},"Scattered Spider initial access vectors in public breaches where the attack vector was disclosed.",{"url":35824,"width":1661,"height":35825},"https://images.ctfassets.net/y1cdw1ablpvd/7hJowGlrqAWDpGIag1xWX5/0ce85d41e117129c3db25ea4a09a5604/image3.png",1136,{"sys":35827,"__typename":1696,"content":35828,"name":35849,"title":59},{"id":35582},{"json":35829},{"nodeType":1640,"data":35830,"content":35831},{},[35832],{"nodeType":881,"data":35833,"content":35834},{},[35835,35838,35845],{"nodeType":867,"value":21,"marks":35836,"data":35837},[],{},{"nodeType":876,"data":35839,"content":35840},{"uri":14788},[35841],{"nodeType":867,"value":35842,"marks":35843,"data":35844},"Check out our recent blog post",[],{},{"nodeType":867,"value":35846,"marks":35847,"data":35848}," to learn more about help desk scams and how to protect your organization. ",[],{},"Scattered Spider Insurance Blog Insight Box 1",{"sys":35851,"__typename":1648,"title":35852,"caption":35852,"layoutMode":59,"file":35853},{"id":15772},"Push Security contributes to a layered defense against known Scattered Spider TTPs.",{"url":35854,"width":1661,"height":35825},"https://images.ctfassets.net/y1cdw1ablpvd/1l3phtTjFoQDleiOKYfrXn/ead73aef01e72f08885656d79521a27a/image3.png",{"sys":35856,"__typename":1648,"title":25579,"caption":25580,"layoutMode":59,"file":35857},{"id":15799},{"url":25582,"width":25583,"height":25584},{"sys":35859,"__typename":1648,"title":35860,"caption":59,"layoutMode":59,"file":35861},{"id":35716},"GitLab Quote",{"url":35862,"width":35863,"height":35864},"https://images.ctfassets.net/y1cdw1ablpvd/72pQc6jrPIdG2IMgv45Rf8/4ca5d7c9586d16fdfc0596813156c9b8/GitLab_Quote.png",2000,861,{"sys":35866,"__typename":22749,"type":22750,"ctaText":35867,"buttonLabel":35868,"buttonColour":22753,"buttonUrl":15827},{"id":15859},"Deploy Employee Verification Codes for free today and protect your help desk from Scattered Spider","Try it free",{"items":35870},[],{},"Scattered Spider target aviation & insurance firms",{"url":35874},"https://images.ctfassets.net/y1cdw1ablpvd/mMbgUER8qJH3p4YF8CsAE/cfc45da4f29fb417a627be97335ab23e/Help_desk_verification_codes.png","2025-06-30T00:00:00.000Z",{"items":35877},[35878,36425,36784],{"__typename":1742,"sys":35879,"content":35880,"title":15867,"synopsis":15868,"hashTags":59,"publishedDate":15869,"slug":15870,"tagsCollection":36415,"authorsCollection":36421},{"id":15240},{"json":35881},{"data":35882,"content":35883,"nodeType":1640},{},[35884,35889,35915,35991,36054,36060,36063,36069,36075,36081,36094,36100,36106,36109,36115,36121,36127,36157,36163,36184,36190,36193,36199,36205,36221,36298,36304,36309,36312,36318,36324,36330,36335,36352,36357,36363,36366,36372,36388,36404,36409],{"data":35885,"content":35888,"nodeType":890},{"target":35886},{"sys":35887},{"id":15249,"type":887,"linkType":888},[],{"data":35890,"content":35891,"nodeType":881},{},[35892,35895,35902,35905,35912],{"data":35893,"marks":35894,"value":15257,"nodeType":867},{},[],{"data":35896,"content":35897,"nodeType":876},{"uri":15260},[35898],{"data":35899,"marks":35900,"value":15266,"nodeType":867},{},[35901],{"type":1040},{"data":35903,"marks":35904,"value":2063,"nodeType":867},{},[],{"data":35906,"content":35907,"nodeType":876},{"uri":15272},[35908],{"data":35909,"marks":35910,"value":15278,"nodeType":867},{},[35911],{"type":1040},{"data":35913,"marks":35914,"value":15282,"nodeType":867},{},[],{"data":35916,"content":35917,"nodeType":881},{},[35918,35921,35928,35931,35938,35941,35948,35951,35958,35961,35968,35971,35978,35981,35988],{"data":35919,"marks":35920,"value":15289,"nodeType":867},{},[],{"data":35922,"content":35923,"nodeType":876},{"uri":15292},[35924],{"data":35925,"marks":35926,"value":15298,"nodeType":867},{},[35927],{"type":1040},{"data":35929,"marks":35930,"value":4006,"nodeType":867},{},[],{"data":35932,"content":35933,"nodeType":876},{"uri":15304},[35934],{"data":35935,"marks":35936,"value":15310,"nodeType":867},{},[35937],{"type":1040},{"data":35939,"marks":35940,"value":4006,"nodeType":867},{},[],{"data":35942,"content":35943,"nodeType":876},{"uri":15316},[35944],{"data":35945,"marks":35946,"value":15322,"nodeType":867},{},[35947],{"type":1040},{"data":35949,"marks":35950,"value":4006,"nodeType":867},{},[],{"data":35952,"content":35953,"nodeType":876},{"uri":15328},[35954],{"data":35955,"marks":35956,"value":15334,"nodeType":867},{},[35957],{"type":1040},{"data":35959,"marks":35960,"value":4006,"nodeType":867},{},[],{"data":35962,"content":35963,"nodeType":876},{"uri":15340},[35964],{"data":35965,"marks":35966,"value":15346,"nodeType":867},{},[35967],{"type":1040},{"data":35969,"marks":35970,"value":4006,"nodeType":867},{},[],{"data":35972,"content":35973,"nodeType":876},{"uri":15352},[35974],{"data":35975,"marks":35976,"value":15358,"nodeType":867},{},[35977],{"type":1040},{"data":35979,"marks":35980,"value":15362,"nodeType":867},{},[],{"data":35982,"content":35983,"nodeType":876},{"uri":15365},[35984],{"data":35985,"marks":35986,"value":15371,"nodeType":867},{},[35987],{"type":1040},{"data":35989,"marks":35990,"value":15375,"nodeType":867},{},[],{"data":35992,"content":35993,"nodeType":881},{},[35994,35997,36004,36007,36014,36017,36024,36027,36033,36036,36042,36045,36051],{"data":35995,"marks":35996,"value":15382,"nodeType":867},{},[],{"data":35998,"content":35999,"nodeType":876},{"uri":15385},[36000],{"data":36001,"marks":36002,"value":15391,"nodeType":867},{},[36003],{"type":1040},{"data":36005,"marks":36006,"value":4006,"nodeType":867},{},[],{"data":36008,"content":36009,"nodeType":876},{"uri":15397},[36010],{"data":36011,"marks":36012,"value":15403,"nodeType":867},{},[36013],{"type":1040},{"data":36015,"marks":36016,"value":15407,"nodeType":867},{},[],{"data":36018,"content":36019,"nodeType":876},{"uri":15410},[36020],{"data":36021,"marks":36022,"value":15416,"nodeType":867},{},[36023],{"type":1040},{"data":36025,"marks":36026,"value":15420,"nodeType":867},{},[],{"data":36028,"content":36029,"nodeType":876},{"uri":15423},[36030],{"data":36031,"marks":36032,"value":15428,"nodeType":867},{},[],{"data":36034,"marks":36035,"value":4006,"nodeType":867},{},[],{"data":36037,"content":36038,"nodeType":876},{"uri":15434},[36039],{"data":36040,"marks":36041,"value":15439,"nodeType":867},{},[],{"data":36043,"marks":36044,"value":2063,"nodeType":867},{},[],{"data":36046,"content":36047,"nodeType":876},{"uri":15434},[36048],{"data":36049,"marks":36050,"value":15449,"nodeType":867},{},[],{"data":36052,"marks":36053,"value":1253,"nodeType":867},{},[],{"data":36055,"content":36056,"nodeType":881},{},[36057],{"data":36058,"marks":36059,"value":15459,"nodeType":867},{},[],{"data":36061,"content":36062,"nodeType":908},{},[],{"data":36064,"content":36065,"nodeType":918},{},[36066],{"data":36067,"marks":36068,"value":15469,"nodeType":867},{},[],{"data":36070,"content":36071,"nodeType":881},{},[36072],{"data":36073,"marks":36074,"value":15476,"nodeType":867},{},[],{"data":36076,"content":36077,"nodeType":881},{},[36078],{"data":36079,"marks":36080,"value":15483,"nodeType":867},{},[],{"data":36082,"content":36083,"nodeType":881},{},[36084,36087,36091],{"data":36085,"marks":36086,"value":15490,"nodeType":867},{},[],{"data":36088,"marks":36089,"value":15495,"nodeType":867},{},[36090],{"type":1431},{"data":36092,"marks":36093,"value":15499,"nodeType":867},{},[],{"data":36095,"content":36096,"nodeType":881},{},[36097],{"data":36098,"marks":36099,"value":15506,"nodeType":867},{},[],{"data":36101,"content":36102,"nodeType":881},{},[36103],{"data":36104,"marks":36105,"value":15513,"nodeType":867},{},[],{"data":36107,"content":36108,"nodeType":908},{},[],{"data":36110,"content":36111,"nodeType":918},{},[36112],{"data":36113,"marks":36114,"value":15523,"nodeType":867},{},[],{"data":36116,"content":36117,"nodeType":881},{},[36118],{"data":36119,"marks":36120,"value":15530,"nodeType":867},{},[],{"data":36122,"content":36123,"nodeType":881},{},[36124],{"data":36125,"marks":36126,"value":15537,"nodeType":867},{},[],{"data":36128,"content":36129,"nodeType":3126},{},[36130,36139,36148],{"data":36131,"content":36132,"nodeType":3061},{},[36133],{"data":36134,"content":36135,"nodeType":881},{},[36136],{"data":36137,"marks":36138,"value":15550,"nodeType":867},{},[],{"data":36140,"content":36141,"nodeType":3061},{},[36142],{"data":36143,"content":36144,"nodeType":881},{},[36145],{"data":36146,"marks":36147,"value":15560,"nodeType":867},{},[],{"data":36149,"content":36150,"nodeType":3061},{},[36151],{"data":36152,"content":36153,"nodeType":881},{},[36154],{"data":36155,"marks":36156,"value":15570,"nodeType":867},{},[],{"data":36158,"content":36159,"nodeType":881},{},[36160],{"data":36161,"marks":36162,"value":15577,"nodeType":867},{},[],{"data":36164,"content":36165,"nodeType":3126},{},[36166,36175],{"data":36167,"content":36168,"nodeType":3061},{},[36169],{"data":36170,"content":36171,"nodeType":881},{},[36172],{"data":36173,"marks":36174,"value":15590,"nodeType":867},{},[],{"data":36176,"content":36177,"nodeType":3061},{},[36178],{"data":36179,"content":36180,"nodeType":881},{},[36181],{"data":36182,"marks":36183,"value":15600,"nodeType":867},{},[],{"data":36185,"content":36186,"nodeType":881},{},[36187],{"data":36188,"marks":36189,"value":15607,"nodeType":867},{},[],{"data":36191,"content":36192,"nodeType":908},{},[],{"data":36194,"content":36195,"nodeType":918},{},[36196],{"data":36197,"marks":36198,"value":15617,"nodeType":867},{},[],{"data":36200,"content":36201,"nodeType":881},{},[36202],{"data":36203,"marks":36204,"value":15624,"nodeType":867},{},[],{"data":36206,"content":36207,"nodeType":881},{},[36208,36211,36218],{"data":36209,"marks":36210,"value":21,"nodeType":867},{},[],{"data":36212,"content":36213,"nodeType":876},{"uri":15633},[36214],{"data":36215,"marks":36216,"value":15639,"nodeType":867},{},[36217],{"type":1040},{"data":36219,"marks":36220,"value":15643,"nodeType":867},{},[],{"data":36222,"content":36223,"nodeType":3126},{},[36224,36233,36242,36261,36270,36279],{"data":36225,"content":36226,"nodeType":3061},{},[36227],{"data":36228,"content":36229,"nodeType":881},{},[36230],{"data":36231,"marks":36232,"value":15656,"nodeType":867},{},[],{"data":36234,"content":36235,"nodeType":3061},{},[36236],{"data":36237,"content":36238,"nodeType":881},{},[36239],{"data":36240,"marks":36241,"value":15666,"nodeType":867},{},[],{"data":36243,"content":36244,"nodeType":3061},{},[36245],{"data":36246,"content":36247,"nodeType":881},{},[36248,36251,36258],{"data":36249,"marks":36250,"value":15676,"nodeType":867},{},[],{"data":36252,"content":36253,"nodeType":876},{"uri":14532},[36254],{"data":36255,"marks":36256,"value":14537,"nodeType":867},{},[36257],{"type":1040},{"data":36259,"marks":36260,"value":15687,"nodeType":867},{},[],{"data":36262,"content":36263,"nodeType":3061},{},[36264],{"data":36265,"content":36266,"nodeType":881},{},[36267],{"data":36268,"marks":36269,"value":15697,"nodeType":867},{},[],{"data":36271,"content":36272,"nodeType":3061},{},[36273],{"data":36274,"content":36275,"nodeType":881},{},[36276],{"data":36277,"marks":36278,"value":15707,"nodeType":867},{},[],{"data":36280,"content":36281,"nodeType":3061},{},[36282],{"data":36283,"content":36284,"nodeType":881},{},[36285,36288,36295],{"data":36286,"marks":36287,"value":15717,"nodeType":867},{},[],{"data":36289,"content":36290,"nodeType":876},{"uri":15720},[36291],{"data":36292,"marks":36293,"value":15726,"nodeType":867},{},[36294],{"type":1040},{"data":36296,"marks":36297,"value":15730,"nodeType":867},{},[],{"data":36299,"content":36300,"nodeType":881},{},[36301],{"data":36302,"marks":36303,"value":15737,"nodeType":867},{},[],{"data":36305,"content":36308,"nodeType":890},{"target":36306},{"sys":36307},{"id":15742,"type":887,"linkType":888},[],{"data":36310,"content":36311,"nodeType":908},{},[],{"data":36313,"content":36314,"nodeType":918},{},[36315],{"data":36316,"marks":36317,"value":15753,"nodeType":867},{},[],{"data":36319,"content":36320,"nodeType":881},{},[36321],{"data":36322,"marks":36323,"value":15760,"nodeType":867},{},[],{"data":36325,"content":36326,"nodeType":881},{},[36327],{"data":36328,"marks":36329,"value":15767,"nodeType":867},{},[],{"data":36331,"content":36334,"nodeType":890},{"target":36332},{"sys":36333},{"id":15772,"type":887,"linkType":888},[],{"data":36336,"content":36337,"nodeType":881},{},[36338,36341,36349],{"data":36339,"marks":36340,"value":15780,"nodeType":867},{},[],{"data":36342,"content":36343,"nodeType":876},{"uri":15783},[36344],{"data":36345,"marks":36346,"value":15790,"nodeType":867},{},[36347,36348],{"type":1040},{"type":916},{"data":36350,"marks":36351,"value":15794,"nodeType":867},{},[],{"data":36353,"content":36356,"nodeType":890},{"target":36354},{"sys":36355},{"id":15799,"type":887,"linkType":888},[],{"data":36358,"content":36359,"nodeType":881},{},[36360],{"data":36361,"marks":36362,"value":15807,"nodeType":867},{},[],{"data":36364,"content":36365,"nodeType":908},{},[],{"data":36367,"content":36368,"nodeType":918},{},[36369],{"data":36370,"marks":36371,"value":15817,"nodeType":867},{},[],{"data":36373,"content":36374,"nodeType":881},{},[36375,36378,36385],{"data":36376,"marks":36377,"value":15824,"nodeType":867},{},[],{"data":36379,"content":36380,"nodeType":876},{"uri":15827},[36381],{"data":36382,"marks":36383,"value":15833,"nodeType":867},{},[36384],{"type":1040},{"data":36386,"marks":36387,"value":15837,"nodeType":867},{},[],{"data":36389,"content":36390,"nodeType":881},{},[36391,36394,36401],{"data":36392,"marks":36393,"value":15844,"nodeType":867},{},[],{"data":36395,"content":36396,"nodeType":876},{"uri":2362},[36397],{"data":36398,"marks":36399,"value":10826,"nodeType":867},{},[36400],{"type":1040},{"data":36402,"marks":36403,"value":1947,"nodeType":867},{},[],{"data":36405,"content":36408,"nodeType":890},{"target":36406},{"sys":36407},{"id":15859,"type":887,"linkType":888},[],{"data":36410,"content":36411,"nodeType":881},{},[36412],{"data":36413,"marks":36414,"value":21,"nodeType":867},{},[],{"items":36416},[36417,36419],{"sys":36418,"name":2547},{"id":2546},{"sys":36420,"name":342},{"id":2550},{"items":36422},[36423],{"fullName":849,"firstName":850,"jobTitle":851,"profilePicture":36424},{"url":855},{"__typename":1742,"sys":36426,"content":36427,"title":29803,"synopsis":36771,"hashTags":59,"publishedDate":36772,"slug":29804,"tagsCollection":36773,"authorsCollection":36777},{"id":27642},{"json":36428},{"data":36429,"content":36430,"nodeType":1640},{},[36431,36438,36445,36452,36458,36465,36498,36505,36512,36519,36525,36532,36539,36557,36562,36569,36589,36607,36614,36621,36628,36635,36642,36649,36656,36676,36683,36690,36696,36702,36709,36734,36740,36759,36765],{"data":36432,"content":36433,"nodeType":881},{},[36434],{"data":36435,"marks":36436,"value":36437,"nodeType":867},{},[],"Scattered Spider has shown the world the devastating effects attackers can achieve by socially engineering IT help desks into performing MFA resets so they can take over accounts on sensitive corporate apps. ",{"data":36439,"content":36440,"nodeType":881},{},[36441],{"data":36442,"marks":36443,"value":36444,"nodeType":867},{},[],"That’s why we’re introducing Employee Identity Verification Codes — a simple, browser-based identity check that gives your help desk a reliable way to confirm they’re talking to someone from your organization.",{"data":36446,"content":36447,"nodeType":881},{},[36448],{"data":36449,"marks":36450,"value":36451,"nodeType":867},{},[],"Push now provides your employees with a rotating 6-digit verification code in their browser via the Push Security extension. When an employee contacts your IT help desk to request an MFA reset or access recovery, the help desk can ask for this code to verify their identity — ensuring it’s really them, and not an attacker.",{"data":36453,"content":36457,"nodeType":890},{"target":36454},{"sys":36455},{"id":36456,"type":887,"linkType":888},"3PkiGgzwSt9Nb5rsGRiQVZ",[],{"data":36459,"content":36460,"nodeType":881},{},[36461],{"data":36462,"marks":36463,"value":36464,"nodeType":867},{},[],"The employee identity verification codes are:",{"data":36466,"content":36467,"nodeType":3126},{},[36468,36478,36488],{"data":36469,"content":36470,"nodeType":3061},{},[36471],{"data":36472,"content":36473,"nodeType":881},{},[36474],{"data":36475,"marks":36476,"value":36477,"nodeType":867},{},[],"Session-aware - generated in users’ browsers and only visible to them when they click on the Push Security extension icon in their browser toolbar.",{"data":36479,"content":36480,"nodeType":3061},{},[36481],{"data":36482,"content":36483,"nodeType":881},{},[36484],{"data":36485,"marks":36486,"value":36487,"nodeType":867},{},[],"Rotating: they change every 24 hours",{"data":36489,"content":36490,"nodeType":3061},{},[36491],{"data":36492,"content":36493,"nodeType":881},{},[36494],{"data":36495,"marks":36496,"value":36497,"nodeType":867},{},[],"Lightweight: no additional apps or devices required",{"data":36499,"content":36500,"nodeType":881},{},[36501],{"data":36502,"marks":36503,"value":36504,"nodeType":867},{},[],"It’s a fast, simple verification method — directly in the employee’s browser — that addresses a real-world threat.",{"data":36506,"content":36507,"nodeType":918},{},[36508],{"data":36509,"marks":36510,"value":36511,"nodeType":867},{},[],"We think it’s swell, but don’t just take our word for it …",{"data":36513,"content":36514,"nodeType":881},{},[36515],{"data":36516,"marks":36517,"value":36518,"nodeType":867},{},[],"Eric Rubin — a Senior Manager in GitLab’s Corporate Security team — has already rolled out Employee Identity Verification Codes across his workforce. Here’s what he had to say about it:",{"data":36520,"content":36524,"nodeType":890},{"target":36521},{"sys":36522},{"id":36523,"type":887,"linkType":888},"5ZLaA869NXpMjVwkswEyOB",[],{"data":36526,"content":36527,"nodeType":881},{},[36528],{"data":36529,"marks":36530,"value":36531,"nodeType":867},{},[],"Thank you, Eric!",{"data":36533,"content":36534,"nodeType":918},{},[36535],{"data":36536,"marks":36537,"value":36538,"nodeType":867},{},[],"Why are help desk identity verification methods so hot right now?",{"data":36540,"content":36541,"nodeType":881},{},[36542,36546,36553],{"data":36543,"marks":36544,"value":36545,"nodeType":867},{},[],"A number of the high-profile incidents attributed to the ",{"data":36547,"content":36548,"nodeType":876},{"uri":15633},[36549],{"data":36550,"marks":36551,"value":36552,"nodeType":867},{},[],"Scattered Spider cybercriminal group",{"data":36554,"marks":36555,"value":36556,"nodeType":867},{},[]," saw them socially engineer IT help desks into resetting MFA on employee accounts that they had already acquired valid credentials for. These compromised accounts were typically on IdP systems like Okta providing SSO access to large numbers of downstream applications.",{"data":36558,"content":36561,"nodeType":890},{"target":36559},{"sys":36560},{"id":15742,"type":887,"linkType":888},[],{"data":36563,"content":36564,"nodeType":998},{},[36565],{"data":36566,"marks":36567,"value":36568,"nodeType":867},{},[],"Case study: The MGM Resorts breach",{"data":36570,"content":36571,"nodeType":881},{},[36572,36576,36585],{"data":36573,"marks":36574,"value":36575,"nodeType":867},{},[],"One of Scattered Spider’s most notorious and well-documented attacks was against ",{"data":36577,"content":36579,"nodeType":876},{"uri":36578},"https://pushsecurity.com/blog/identity-attacks-in-the-wild/#id-mgm-resorts-september-2023",[36580],{"data":36581,"marks":36582,"value":36584,"nodeType":867},{},[36583],{"type":1040},"MGM Resorts",{"data":36586,"marks":36587,"value":36588,"nodeType":867},{},[],". Scattered Spider socially engineered MGM Resorts’ help desk personnel to bypass MFA and log in to accounts for which they had acquired valid login credentials via credential phishing and historical infostealer compromises. ",{"data":36590,"content":36591,"nodeType":881},{},[36592,36596,36603],{"data":36593,"marks":36594,"value":36595,"nodeType":867},{},[],"They specifically targeted accounts with Super Administrator privileges within MGM Resorts’ Okta tenant, which they then used to register a second, attacker-controlled IdP via ",{"data":36597,"content":36598,"nodeType":876},{"uri":14743},[36599],{"data":36600,"marks":36601,"value":14749,"nodeType":867},{},[36602],{"type":1040},{"data":36604,"marks":36605,"value":36606,"nodeType":867},{},[],". This then enabled them to impersonate any user within the Okta tenant. ",{"data":36608,"content":36609,"nodeType":881},{},[36610],{"data":36611,"marks":36612,"value":36613,"nodeType":867},{},[],"The attackers were then able to abuse SSO access to downstream apps and platforms from various accounts, culminating in deployment of ransomware to around 100 ESXi servers and data exfiltration. ",{"data":36615,"content":36616,"nodeType":881},{},[36617],{"data":36618,"marks":36619,"value":36620,"nodeType":867},{},[],"The breach resulted in a 36-hour outage, a $100M hit to its Q3 results, one-time cyber consulting fees in the region of $10M, and a class-action lawsuit later settled for $45M. ",{"data":36622,"content":36623,"nodeType":998},{},[36624],{"data":36625,"marks":36626,"value":36627,"nodeType":867},{},[],"Reassessing help desk verification processes",{"data":36629,"content":36630,"nodeType":881},{},[36631],{"data":36632,"marks":36633,"value":36634,"nodeType":867},{},[],"Scattered Spider’s high-profile attacks — including its most recent against UK retailers Marks & Spencer’s and the Co-op — has prompted many security teams to reassess the verification processes used by their IT help desks when an employee requests an MFA reset or access to sensitive applications. ",{"data":36636,"content":36637,"nodeType":881},{},[36638],{"data":36639,"marks":36640,"value":36641,"nodeType":867},{},[],"Initial guidance from across the industry included the use of call-back verification for any MFA or credential changes requested by an employee. However, Scattered Spider are also known to use SIM-swapping to trick mobile carriers into transferring a victim’s phone number to a SIM card controlled by the attacker - thereby allowing them to intercept verification calls. ",{"data":36643,"content":36644,"nodeType":918},{},[36645],{"data":36646,"marks":36647,"value":36648,"nodeType":867},{},[],"Simple verification using your employees’ browsers",{"data":36650,"content":36651,"nodeType":881},{},[36652],{"data":36653,"marks":36654,"value":36655,"nodeType":867},{},[],"Push already provides several controls that directly align to the other TTPs used by Scattered Spider. They include detecting stolen credentials, cloned login pages, AitM toolkits and compromised IdP sessions. ",{"data":36657,"content":36658,"nodeType":881},{},[36659,36663,36672],{"data":36660,"marks":36661,"value":36662,"nodeType":867},{},[],"(BTW, if this piques your interest, you can ",{"data":36664,"content":36666,"nodeType":876},{"uri":36665},"https://pushsecurity.com/resources?type=webinar#content",[36667],{"data":36668,"marks":36669,"value":36671,"nodeType":867},{},[36670],{"type":1040},"stream our latest webinar",{"data":36673,"marks":36674,"value":36675,"nodeType":867},{},[]," where we deep-dive into Scattered Spider, how their TTPs are evolving in 2025, and what Push is doing to protect organizations against them.) ",{"data":36677,"content":36678,"nodeType":881},{},[36679],{"data":36680,"marks":36681,"value":36682,"nodeType":867},{},[],"But to provide our customers with an additional layer of defense against the Scattered Spider attack chain, we wanted to see how we could make it harder for attackers to socially engineer IT help desks into gaining access to IdP systems and sensitive apps.",{"data":36684,"content":36685,"nodeType":881},{},[36686],{"data":36687,"marks":36688,"value":36689,"nodeType":867},{},[],"As so often is the case, the answer was staring us right in the face - we can use our browser extension. By placing a verification code in the details tray of every employees’ Push extension, they can use that to verify their identity with their help desk team.",{"data":36691,"content":36695,"nodeType":890},{"target":36692},{"sys":36693},{"id":36694,"type":887,"linkType":888},"4hRJVGqKGyOHJ8NSsQYWGP",[],{"data":36697,"content":36698,"nodeType":918},{},[36699],{"data":36700,"marks":36701,"value":15817,"nodeType":867},{},[],{"data":36703,"content":36704,"nodeType":881},{},[36705],{"data":36706,"marks":36707,"value":36708,"nodeType":867},{},[],"Employee verification codes is a Labs feature, which means it’s available on an early-access basis. We're particularly interested in hearing your feedback on how to develop this feature further.",{"data":36710,"content":36711,"nodeType":881},{},[36712,36716,36721,36725,36730],{"data":36713,"marks":36714,"value":36715,"nodeType":867},{},[],"You can enable Labs features by going to the ",{"data":36717,"marks":36718,"value":36720,"nodeType":867},{},[36719],{"type":916},"Settings",{"data":36722,"marks":36723,"value":36724,"nodeType":867},{},[]," page of the Push admin console and choosing the ",{"data":36726,"marks":36727,"value":36729,"nodeType":867},{},[36728],{"type":916},"Labs",{"data":36731,"marks":36732,"value":36733,"nodeType":867},{},[]," tab.",{"data":36735,"content":36739,"nodeType":890},{"target":36736},{"sys":36737},{"id":36738,"type":887,"linkType":888},"6TyqP2eOmalIF6RRoe476Y",[],{"data":36741,"content":36742,"nodeType":881},{},[36743,36747,36755],{"data":36744,"marks":36745,"value":36746,"nodeType":867},{},[],"If you’d like to find out more about this feature, and the other ways Push is stopping identity attacks in the browser, ",{"data":36748,"content":36749,"nodeType":876},{"uri":2362},[36750],{"data":36751,"marks":36752,"value":36754,"nodeType":867},{},[36753],{"type":1040},"book a demo",{"data":36756,"marks":36757,"value":36758,"nodeType":867},{},[]," with one of our team. ",{"data":36760,"content":36764,"nodeType":890},{"target":36761},{"sys":36762},{"id":36763,"type":887,"linkType":888},"7xBE9MrnMy3hfwIkhLhNhQ",[],{"data":36766,"content":36767,"nodeType":881},{},[36768],{"data":36769,"marks":36770,"value":21,"nodeType":867},{},[],"Push's new Employee Identity Verification Codes feature is a simple way for your help desk to confirm they’re talking to someone from your organization.\n","2025-06-19T00:00:00.000Z",{"items":36774},[36775],{"sys":36776,"name":297},{"id":5646},{"items":36778},[36779],{"fullName":36780,"firstName":36781,"jobTitle":4374,"profilePicture":36782},"Alex Henshall","Alex",{"url":36783},"https://images.ctfassets.net/y1cdw1ablpvd/2rz3Pre3b1MexPIQ4hzPUe/0ef8a092b7e7df00fbce3f7d1ccb96d1/Alex_Henshall.jpeg",{"__typename":1742,"sys":36785,"content":36787,"title":37402,"synopsis":37403,"hashTags":59,"publishedDate":37404,"slug":37405,"tagsCollection":37406,"authorsCollection":37412},{"id":36786},"XQHcBu5kiSBd6MMwICYI4",{"json":36788},{"data":36789,"content":36790,"nodeType":1640},{},[36791,36798,36805,36813,36842,36849,36855,36858,36866,36873,36880,36923,36930,36937,36940,36948,36955,36962,36969,36987,36994,37000,37008,37015,37022,37029,37035,37038,37046,37054,37061,37069,37076,37141,37148,37156,37163,37196,37204,37211,37219,37226,37234,37241,37294,37301,37304,37312,37319,37336,37369,37390,37396],{"data":36792,"content":36793,"nodeType":881},{},[36794],{"data":36795,"marks":36796,"value":36797,"nodeType":867},{},[],"Phishing has undergone a radical transformation. The laughably bad emails and fake PayPal logins of the past have given way to sophisticated campaigns engineered to slip through even the most hardened security stacks. ",{"data":36799,"content":36800,"nodeType":881},{},[36801],{"data":36802,"marks":36803,"value":36804,"nodeType":867},{},[],"Today’s phishing attacks are faster, more adaptable, and harder to catch with traditional tools. Email filters and threat intel still play an important role, but they’re often reacting to threats that are already in motion, and by the time a phishing link is flagged and blocklisted, someone has probably already clicked — and the attacker has moved onto their next set of links.",{"data":36806,"content":36807,"nodeType":881},{},[36808],{"data":36809,"marks":36810,"value":36812,"nodeType":867},{},[36811],{"type":916},"The problem isn’t that phishing has evolved. It’s that our defenses haven’t.",{"data":36814,"content":36815,"nodeType":881},{},[36816,36820,36829,36833,36838],{"data":36817,"marks":36818,"value":36819,"nodeType":867},{},[],"That’s where ",{"data":36821,"content":36823,"nodeType":876},{"uri":36822},"https://pushsecurity.com/uc/zero-day-phishing-protection",[36824],{"data":36825,"marks":36826,"value":36828,"nodeType":867},{},[36827],{"type":1040},"Push Security",{"data":36830,"marks":36831,"value":36832,"nodeType":867},{},[]," comes in. By embedding real-time detection directly into the browser, the very place where phishing attacks unfold, Push offers a fundamentally new way to stop phishing: ",{"data":36834,"marks":36835,"value":36837,"nodeType":867},{},[36836],{"type":1431},"as it happens",{"data":36839,"marks":36840,"value":36841,"nodeType":867},{},[],", regardless of whether or not the exact attack has ever been seen before. ",{"data":36843,"content":36844,"nodeType":881},{},[36845],{"data":36846,"marks":36847,"value":36848,"nodeType":867},{},[],"Check out the video to see how it works. ",{"data":36850,"content":36854,"nodeType":890},{"target":36851},{"sys":36852},{"id":36853,"type":887,"linkType":888},"4LaKobadjp19jjocLXcW4E",[],{"data":36856,"content":36857,"nodeType":908},{},[],{"data":36859,"content":36860,"nodeType":918},{},[36861],{"data":36862,"marks":36863,"value":36865,"nodeType":867},{},[36864],{"type":916},"The modern phishing playground",{"data":36867,"content":36868,"nodeType":881},{},[36869],{"data":36870,"marks":36871,"value":36872,"nodeType":867},{},[],"Phishing attacks today look nothing like the blunt instruments of a few years ago. These are fast, customized, and often completely ephemeral. A phishing domain might go live at 9 a.m., compromise scores of credentials, and be gone before lunch, long before it ever hits a threat intel feed.",{"data":36874,"content":36875,"nodeType":881},{},[36876],{"data":36877,"marks":36878,"value":36879,"nodeType":867},{},[],"Modern attackers use:",{"data":36881,"content":36882,"nodeType":3126},{},[36883,36893,36903,36913],{"data":36884,"content":36885,"nodeType":3061},{},[36886],{"data":36887,"content":36888,"nodeType":881},{},[36889],{"data":36890,"marks":36891,"value":36892,"nodeType":867},{},[],"Dynamic content and user-adaptive emails that can be easily changed based on the target’s identity and environment.",{"data":36894,"content":36895,"nodeType":3061},{},[36896],{"data":36897,"content":36898,"nodeType":881},{},[36899],{"data":36900,"marks":36901,"value":36902,"nodeType":867},{},[],"Obfuscated URLs hidden behind trusted services (like Google Sites), making reputation analysis less than reliable.",{"data":36904,"content":36905,"nodeType":3061},{},[36906],{"data":36907,"content":36908,"nodeType":881},{},[36909],{"data":36910,"marks":36911,"value":36912,"nodeType":867},{},[],"Real-time proxying tools to clone login flows and harvest credentials.",{"data":36914,"content":36915,"nodeType":3061},{},[36916],{"data":36917,"content":36918,"nodeType":881},{},[36919],{"data":36920,"marks":36921,"value":36922,"nodeType":867},{},[],"Rapid-fire infrastructure rotation, making the attack’s infrastructure almost impossible to track in time.",{"data":36924,"content":36925,"nodeType":881},{},[36926],{"data":36927,"marks":36928,"value":36929,"nodeType":867},{},[],"These attacks often bypass traditional defenses entirely, not because the tools are broken, but because they were designed for a different era, one where phishing pages lived for days or weeks, not minutes.",{"data":36931,"content":36932,"nodeType":881},{},[36933],{"data":36934,"marks":36935,"value":36936,"nodeType":867},{},[],"It’s not enough to know what was bad yesterday. You need to know what’s happening now.",{"data":36938,"content":36939,"nodeType":908},{},[],{"data":36941,"content":36942,"nodeType":918},{},[36943],{"data":36944,"marks":36945,"value":36947,"nodeType":867},{},[36946],{"type":916},"Why blocklists and perimeter defenses are falling behind",{"data":36949,"content":36950,"nodeType":881},{},[36951],{"data":36952,"marks":36953,"value":36954,"nodeType":867},{},[],"The security ecosystem has long depended on reputation-based systems: block the known bad, allow the rest. That worked when attackers reused infrastructure and relied on mass campaigns. Today’s adversaries have adapted.",{"data":36956,"content":36957,"nodeType":881},{},[36958],{"data":36959,"marks":36960,"value":36961,"nodeType":867},{},[],"Consider a scenario similar to the one from our video:",{"data":36963,"content":36964,"nodeType":881},{},[36965],{"data":36966,"marks":36967,"value":36968,"nodeType":867},{},[],"A staff member receives an email appearing to be from Microsoft Teams. It includes dynamic content that mirrors their actual environment, including their username, company logo, and real collaboration data. The embedded link takes them to a cloned Microsoft login page hosted on a benign-looking subdomain. The site is brand new. It’s not on any blocklist. Your email filter passes it. The employee logs in. Credentials and session tokens? Gone.",{"data":36970,"content":36971,"nodeType":881},{},[36972,36976,36983],{"data":36973,"marks":36974,"value":36975,"nodeType":867},{},[],"And that’s just step one. The attacker now pivots to connected apps like ",{"data":36977,"content":36978,"nodeType":876},{"uri":6114},[36979],{"data":36980,"marks":36981,"value":33785,"nodeType":867},{},[36982],{"type":1040},{"data":36984,"marks":36985,"value":36986,"nodeType":867},{},[],", Confluence, or AWS, moving laterally through your cloud environment using the compromised credentials.",{"data":36988,"content":36989,"nodeType":881},{},[36990],{"data":36991,"marks":36992,"value":36993,"nodeType":867},{},[],"Traditional tools often miss these threats not due to a lack of sophistication, but because they’re looking from the outside in. The browser is where the attack actually unfolds. Without visibility there, key indicators of compromise go undetected.",{"data":36995,"content":36999,"nodeType":890},{"target":36996},{"sys":36997},{"id":36998,"type":887,"linkType":888},"1UGu43QxCiYofkeGtOMp5J",[],{"data":37001,"content":37002,"nodeType":918},{},[37003],{"data":37004,"marks":37005,"value":37007,"nodeType":867},{},[37006],{"type":916},"Rethinking where phishing defense happens",{"data":37009,"content":37010,"nodeType":881},{},[37011],{"data":37012,"marks":37013,"value":37014,"nodeType":867},{},[],"Push changes where phishing protection happens, from upstream detection to point-of-interaction control. Instead of chasing malicious links through email gateways or external threat feeds, Push embeds lightweight, always-on protection directly, as users go about their work in the browser.",{"data":37016,"content":37017,"nodeType":881},{},[37018],{"data":37019,"marks":37020,"value":37021,"nodeType":867},{},[],"Push monitors what’s happening in each session: how pages are built, how they behave, and how users interact with them. That means it can recognize when a login prompt doesn’t match your identity provider or when a script behaves like part of a phishing toolkit.",{"data":37023,"content":37024,"nodeType":881},{},[37025],{"data":37026,"marks":37027,"value":37028,"nodeType":867},{},[],"When Push identifies something suspicious, it takes action right away. Logins are interrupted before any data is exposed. Users get clear guidance in-browser. And security teams receive detailed telemetry that shows exactly what happened, who was targeted, and how the threat was stopped.",{"data":37030,"content":37034,"nodeType":890},{"target":37031},{"sys":37032},{"id":37033,"type":887,"linkType":888},"7Hu3kypFWwJAGOuQp0kYmU",[],{"data":37036,"content":37037,"nodeType":908},{},[],{"data":37039,"content":37040,"nodeType":918},{},[37041],{"data":37042,"marks":37043,"value":37045,"nodeType":867},{},[37044],{"type":916},"The benefits of browser-native phishing defense",{"data":37047,"content":37048,"nodeType":998},{},[37049],{"data":37050,"marks":37051,"value":37053,"nodeType":867},{},[37052],{"type":916},"True zero-day protection",{"data":37055,"content":37056,"nodeType":881},{},[37057],{"data":37058,"marks":37059,"value":37060,"nodeType":867},{},[],"Push doesn’t rely on known indicators of compromise. It evaluates the actual behavior and context of every session in real-time. Whether the phishing site was created 5 months ago or 5 minutes ago is irrelevant — Push detects it and shuts it down.",{"data":37062,"content":37063,"nodeType":998},{},[37064],{"data":37065,"marks":37066,"value":37068,"nodeType":867},{},[37067],{"type":916},"Contextual threat detection",{"data":37070,"content":37071,"nodeType":881},{},[37072],{"data":37073,"marks":37074,"value":37075,"nodeType":867},{},[],"Because Push operates in the browser, it sees everything:",{"data":37077,"content":37078,"nodeType":3126},{},[37079,37089,37099,37121,37131],{"data":37080,"content":37081,"nodeType":3061},{},[37082],{"data":37083,"content":37084,"nodeType":881},{},[37085],{"data":37086,"marks":37087,"value":37088,"nodeType":867},{},[],"The page layout",{"data":37090,"content":37091,"nodeType":3061},{},[37092],{"data":37093,"content":37094,"nodeType":881},{},[37095],{"data":37096,"marks":37097,"value":37098,"nodeType":867},{},[],"Where the user came from",{"data":37100,"content":37101,"nodeType":3061},{},[37102],{"data":37103,"content":37104,"nodeType":881},{},[37105,37109,37118],{"data":37106,"marks":37107,"value":37108,"nodeType":867},{},[],"The password they enter ",{"data":37110,"content":37112,"nodeType":876},{"uri":37111},"https://pushsecurity.com/help/10043/#how-push-securely-analyzes-passwords",[37113],{"data":37114,"marks":37115,"value":37117,"nodeType":867},{},[37116],{"type":1040},"(as a salted, abbreviated hash)",{"data":37119,"marks":37120,"value":21,"nodeType":867},{},[],{"data":37122,"content":37123,"nodeType":3061},{},[37124],{"data":37125,"content":37126,"nodeType":881},{},[37127],{"data":37128,"marks":37129,"value":37130,"nodeType":867},{},[],"What scripts are running",{"data":37132,"content":37133,"nodeType":3061},{},[37134],{"data":37135,"content":37136,"nodeType":881},{},[37137],{"data":37138,"marks":37139,"value":37140,"nodeType":867},{},[],"And where credentials are being sent",{"data":37142,"content":37143,"nodeType":881},{},[37144],{"data":37145,"marks":37146,"value":37147,"nodeType":867},{},[],"This context enables Push to stop even well-camouflaged phishing attempts, including AitM attacks that bypass MFA.",{"data":37149,"content":37150,"nodeType":998},{},[37151],{"data":37152,"marks":37153,"value":37155,"nodeType":867},{},[37154],{"type":916},"Real-time interception of malicious activity",{"data":37157,"content":37158,"nodeType":881},{},[37159],{"data":37160,"marks":37161,"value":37162,"nodeType":867},{},[],"As soon as a phishing attempt is confirmed, the response is immediate:",{"data":37164,"content":37165,"nodeType":3126},{},[37166,37176,37186],{"data":37167,"content":37168,"nodeType":3061},{},[37169],{"data":37170,"content":37171,"nodeType":881},{},[37172],{"data":37173,"marks":37174,"value":37175,"nodeType":867},{},[],"Credential entry is halted.",{"data":37177,"content":37178,"nodeType":3061},{},[37179],{"data":37180,"content":37181,"nodeType":881},{},[37182],{"data":37183,"marks":37184,"value":37185,"nodeType":867},{},[],"Sessions are revoked.",{"data":37187,"content":37188,"nodeType":3061},{},[37189],{"data":37190,"content":37191,"nodeType":881},{},[37192],{"data":37193,"marks":37194,"value":37195,"nodeType":867},{},[],"The user is protected without delay.",{"data":37197,"content":37198,"nodeType":998},{},[37199],{"data":37200,"marks":37201,"value":37203,"nodeType":867},{},[37202],{"type":916},"Reduced incident response overhead",{"data":37205,"content":37206,"nodeType":881},{},[37207],{"data":37208,"marks":37209,"value":37210,"nodeType":867},{},[],"Most phishing attacks end in hours of IR and expensive cleanup. With Push, attacks don’t escalate beyond the initial click. That means fewer compromised accounts, fewer escalations, and less fatigue on your security team.",{"data":37212,"content":37213,"nodeType":998},{},[37214],{"data":37215,"marks":37216,"value":37218,"nodeType":867},{},[37217],{"type":916},"Empowered, educated users",{"data":37220,"content":37221,"nodeType":881},{},[37222],{"data":37223,"marks":37224,"value":37225,"nodeType":867},{},[],"Push doesn’t just block phishing; it helps users learn from it. When someone interacts with a suspicious page, they get clear, actionable feedback right in the browser. Over time, these in-the-moment cues help build stronger phishing awareness across your workforce. Employee-facing messages are fully customizable to match the tone and style of your organization.",{"data":37227,"content":37228,"nodeType":998},{},[37229],{"data":37230,"marks":37231,"value":37233,"nodeType":867},{},[37232],{"type":916},"A new paradigm for identity security",{"data":37235,"content":37236,"nodeType":881},{},[37237],{"data":37238,"marks":37239,"value":37240,"nodeType":867},{},[],"While phishing detection is core, Push also helps you defend your entire browser-based identity attack surface. That means protecting against other common forms of account compromise, like:",{"data":37242,"content":37243,"nodeType":3126},{},[37244,37254,37264,37274,37284],{"data":37245,"content":37246,"nodeType":3061},{},[37247],{"data":37248,"content":37249,"nodeType":881},{},[37250],{"data":37251,"marks":37252,"value":37253,"nodeType":867},{},[],"Employees using breached or reused passwords",{"data":37255,"content":37256,"nodeType":3061},{},[37257],{"data":37258,"content":37259,"nodeType":881},{},[37260],{"data":37261,"marks":37262,"value":37263,"nodeType":867},{},[],"Missing or misconfigured MFA",{"data":37265,"content":37266,"nodeType":3061},{},[37267],{"data":37268,"content":37269,"nodeType":881},{},[37270],{"data":37271,"marks":37272,"value":37273,"nodeType":867},{},[],"Ghost logins that bypass your identity provider",{"data":37275,"content":37276,"nodeType":3061},{},[37277],{"data":37278,"content":37279,"nodeType":881},{},[37280],{"data":37281,"marks":37282,"value":37283,"nodeType":867},{},[],"Token-based session hijacking",{"data":37285,"content":37286,"nodeType":3061},{},[37287],{"data":37288,"content":37289,"nodeType":881},{},[37290],{"data":37291,"marks":37292,"value":37293,"nodeType":867},{},[],"Shadow SaaS usage",{"data":37295,"content":37296,"nodeType":881},{},[37297],{"data":37298,"marks":37299,"value":37300,"nodeType":867},{},[],"Because Push runs directly in the browser, it gives you visibility across every app your employees access, whether it’s officially managed or not. And it doesn’t just alert, it actively helps you fix the issues, guiding users to take action when risks are found.",{"data":37302,"content":37303,"nodeType":908},{},[],{"data":37305,"content":37306,"nodeType":918},{},[37307],{"data":37308,"marks":37309,"value":37311,"nodeType":867},{},[37310],{"type":916},"Modern phishing requires a modern defense",{"data":37313,"content":37314,"nodeType":881},{},[37315],{"data":37316,"marks":37317,"value":37318,"nodeType":867},{},[],"Phishing is no longer an email problem. It’s not even just a domain reputation problem. It’s an identity attack problem, and the only place you can see those attacks in action is inside the browser.",{"data":37320,"content":37321,"nodeType":881},{},[37322,37326,37333],{"data":37323,"marks":37324,"value":37325,"nodeType":867},{},[],"Push Security gives you a new advantage: proactive, in-browser protection against modern phishing campaigns — ",{"data":37327,"content":37328,"nodeType":876},{"uri":36822},[37329],{"data":37330,"marks":37331,"value":37332,"nodeType":867},{},[],"even those with never-before-seen phishing sites",{"data":37334,"marks":37335,"value":1947,"nodeType":867},{},[],{"data":37337,"content":37338,"nodeType":3126},{},[37339,37349,37359],{"data":37340,"content":37341,"nodeType":3061},{},[37342],{"data":37343,"content":37344,"nodeType":881},{},[37345],{"data":37346,"marks":37347,"value":37348,"nodeType":867},{},[],"See the phish happen.",{"data":37350,"content":37351,"nodeType":3061},{},[37352],{"data":37353,"content":37354,"nodeType":881},{},[37355],{"data":37356,"marks":37357,"value":37358,"nodeType":867},{},[],"Stop it in real time.",{"data":37360,"content":37361,"nodeType":3061},{},[37362],{"data":37363,"content":37364,"nodeType":881},{},[37365],{"data":37366,"marks":37367,"value":37368,"nodeType":867},{},[],"Keep your workforce identities safe.",{"data":37370,"content":37371,"nodeType":881},{},[37372,37377,37385],{"data":37373,"marks":37374,"value":37376,"nodeType":867},{},[37375],{"type":916},"Want to see Push in action? ",{"data":37378,"content":37379,"nodeType":876},{"uri":2362},[37380],{"data":37381,"marks":37382,"value":37384,"nodeType":867},{},[37383],{"type":916},"Book a demo",{"data":37386,"marks":37387,"value":37389,"nodeType":867},{},[37388],{"type":916}," and watch a real-time phishing attack get stopped mid-flow.",{"data":37391,"content":37395,"nodeType":890},{"target":37392},{"sys":37393},{"id":37394,"type":887,"linkType":888},"7eSsPjEj178j3ViloaChbQ",[],{"data":37397,"content":37398,"nodeType":881},{},[37399],{"data":37400,"marks":37401,"value":21,"nodeType":867},{},[],"How browser-level controls change the fight against phishing","Attackers are routinely defeating conventional email, network, and endpoint-based security controls. Here's how browser controls can level the playing field.","2025-06-26T00:00:00.000Z","how-browser-level-controls-change-the-fight-against-phishing",{"items":37407},[37408,37410],{"sys":37409,"name":2547},{"id":2546},{"sys":37411,"name":342},{"id":2550},{"items":37413},[37414],{"fullName":37415,"firstName":37416,"jobTitle":4374,"profilePicture":37417},"Peyton Padfield","Peyton",{"url":37418},"https://images.ctfassets.net/y1cdw1ablpvd/1GU01HXElmc07nwi89qP3b/3188050420106c62e9df2ed4e4893b7f/1677005177901__1_.jpeg","key-takeaways-from-the-scattered-spider-attacks-on-insurance-firms","blog/key-takeaways-from-the-scattered-spider-attacks-on-insurance-firms",{"json":37422},{"data":37423,"content":37424,"nodeType":1640},{},[37425],{"data":37426,"content":37427,"nodeType":881},{},[37428],{"data":37429,"marks":37430,"value":37431,"nodeType":867},{},[],"Scattered Spider continues to dominate the headlines, with the latest news linking the hackers to attacks on U.S. insurance giant Aflac, Philadelphia Insurance Companies, Erie Insurance, Hawaiian Airlines, WestJet, and Qantas. Here's what you need to know to defend your organization. ","Scattered Spider continues to dominate the headlines, with attacks on aviation and insurance companies worldwide.",{"id":37434,"publishedAt":37435},"3JS30QKx42bLnGYZh5K9ZP","2026-08-12T11:54:01.317Z",{"items":37437},[37438,37440],{"sys":37439,"name":2547},{"id":2546},{"sys":37441,"name":342},{"id":2550},{"items":37443},[37444,37446,37448,37450,37452,37454,37456,37458,37460,37462,37464,37466,37468,37470,37472,37474,37476,37478],{"sys":37445,"name":279,"slug":280,"tier":31},{"id":276},{"sys":37447,"name":413,"slug":414,"tier":31},{"id":410},{"sys":37449,"name":519,"slug":520,"tier":31},{"id":516},{"sys":37451,"name":642,"slug":643,"tier":31},{"id":639},{"sys":37453,"name":342,"slug":343,"tier":31},{"id":339},{"sys":37455,"name":650,"slug":651,"tier":45},{"id":647},{"sys":37457,"name":261,"slug":262,"tier":45},{"id":258},{"sys":37459,"name":404,"slug":405,"tier":45},{"id":401},{"sys":37461,"name":528,"slug":529,"tier":45},{"id":525},{"sys":37463,"name":607,"slug":608,"tier":45},{"id":604},{"sys":37465,"name":466,"slug":467,"tier":45},{"id":463},{"sys":37467,"name":324,"slug":325,"tier":45},{"id":321},{"sys":37469,"name":333,"slug":334,"tier":45},{"id":330},{"sys":37471,"name":422,"slug":423,"tier":45},{"id":419},{"sys":37473,"name":571,"slug":572,"tier":45},{"id":568},{"sys":37475,"name":537,"slug":538,"tier":45},{"id":534},{"sys":37477,"name":457,"slug":458,"tier":45},{"id":454},{"sys":37479,"name":502,"slug":503,"tier":45},{"id":499},"EUQaIzN2danmdv-FjrFO_UhoqY0mW4m10bij_jFoR_I",{"id":37482,"title":15867,"authorsCollection":37483,"content":37488,"extension":228,"faqItemsCollection":38068,"faqTitle":59,"featured":6,"hashTags":59,"meta":38070,"metaTitle":38071,"ogImage":38072,"postType":8156,"publishedDate":15869,"relatedBlogPostsCollection":38073,"slug":15870,"stem":40263,"subtitle":59,"summary":40264,"synopsis":15868,"sys":40275,"tagsCollection":40277,"topicsCollection":40283,"__hash__":40315},"blog/blog/scattered-spider-defending-against-help-desk-scams.json",{"items":37484},[37485],{"fullName":849,"firstName":850,"jobTitle":851,"socialLinks":37486,"profilePicture":37487},[853],{"url":855},{"json":37489,"links":38023},{"data":37490,"content":37491,"nodeType":1640},{},[37492,37497,37523,37599,37662,37668,37671,37677,37683,37689,37702,37708,37714,37717,37723,37729,37735,37765,37771,37792,37798,37801,37807,37813,37829,37906,37912,37917,37920,37926,37932,37938,37943,37960,37965,37971,37974,37980,37996,38012,38017],{"data":37493,"content":37496,"nodeType":890},{"target":37494},{"sys":37495},{"id":15249,"type":887,"linkType":888},[],{"data":37498,"content":37499,"nodeType":881},{},[37500,37503,37510,37513,37520],{"data":37501,"marks":37502,"value":15257,"nodeType":867},{},[],{"data":37504,"content":37505,"nodeType":876},{"uri":15260},[37506],{"data":37507,"marks":37508,"value":15266,"nodeType":867},{},[37509],{"type":1040},{"data":37511,"marks":37512,"value":2063,"nodeType":867},{},[],{"data":37514,"content":37515,"nodeType":876},{"uri":15272},[37516],{"data":37517,"marks":37518,"value":15278,"nodeType":867},{},[37519],{"type":1040},{"data":37521,"marks":37522,"value":15282,"nodeType":867},{},[],{"data":37524,"content":37525,"nodeType":881},{},[37526,37529,37536,37539,37546,37549,37556,37559,37566,37569,37576,37579,37586,37589,37596],{"data":37527,"marks":37528,"value":15289,"nodeType":867},{},[],{"data":37530,"content":37531,"nodeType":876},{"uri":15292},[37532],{"data":37533,"marks":37534,"value":15298,"nodeType":867},{},[37535],{"type":1040},{"data":37537,"marks":37538,"value":4006,"nodeType":867},{},[],{"data":37540,"content":37541,"nodeType":876},{"uri":15304},[37542],{"data":37543,"marks":37544,"value":15310,"nodeType":867},{},[37545],{"type":1040},{"data":37547,"marks":37548,"value":4006,"nodeType":867},{},[],{"data":37550,"content":37551,"nodeType":876},{"uri":15316},[37552],{"data":37553,"marks":37554,"value":15322,"nodeType":867},{},[37555],{"type":1040},{"data":37557,"marks":37558,"value":4006,"nodeType":867},{},[],{"data":37560,"content":37561,"nodeType":876},{"uri":15328},[37562],{"data":37563,"marks":37564,"value":15334,"nodeType":867},{},[37565],{"type":1040},{"data":37567,"marks":37568,"value":4006,"nodeType":867},{},[],{"data":37570,"content":37571,"nodeType":876},{"uri":15340},[37572],{"data":37573,"marks":37574,"value":15346,"nodeType":867},{},[37575],{"type":1040},{"data":37577,"marks":37578,"value":4006,"nodeType":867},{},[],{"data":37580,"content":37581,"nodeType":876},{"uri":15352},[37582],{"data":37583,"marks":37584,"value":15358,"nodeType":867},{},[37585],{"type":1040},{"data":37587,"marks":37588,"value":15362,"nodeType":867},{},[],{"data":37590,"content":37591,"nodeType":876},{"uri":15365},[37592],{"data":37593,"marks":37594,"value":15371,"nodeType":867},{},[37595],{"type":1040},{"data":37597,"marks":37598,"value":15375,"nodeType":867},{},[],{"data":37600,"content":37601,"nodeType":881},{},[37602,37605,37612,37615,37622,37625,37632,37635,37641,37644,37650,37653,37659],{"data":37603,"marks":37604,"value":15382,"nodeType":867},{},[],{"data":37606,"content":37607,"nodeType":876},{"uri":15385},[37608],{"data":37609,"marks":37610,"value":15391,"nodeType":867},{},[37611],{"type":1040},{"data":37613,"marks":37614,"value":4006,"nodeType":867},{},[],{"data":37616,"content":37617,"nodeType":876},{"uri":15397},[37618],{"data":37619,"marks":37620,"value":15403,"nodeType":867},{},[37621],{"type":1040},{"data":37623,"marks":37624,"value":15407,"nodeType":867},{},[],{"data":37626,"content":37627,"nodeType":876},{"uri":15410},[37628],{"data":37629,"marks":37630,"value":15416,"nodeType":867},{},[37631],{"type":1040},{"data":37633,"marks":37634,"value":15420,"nodeType":867},{},[],{"data":37636,"content":37637,"nodeType":876},{"uri":15423},[37638],{"data":37639,"marks":37640,"value":15428,"nodeType":867},{},[],{"data":37642,"marks":37643,"value":4006,"nodeType":867},{},[],{"data":37645,"content":37646,"nodeType":876},{"uri":15434},[37647],{"data":37648,"marks":37649,"value":15439,"nodeType":867},{},[],{"data":37651,"marks":37652,"value":2063,"nodeType":867},{},[],{"data":37654,"content":37655,"nodeType":876},{"uri":15434},[37656],{"data":37657,"marks":37658,"value":15449,"nodeType":867},{},[],{"data":37660,"marks":37661,"value":1253,"nodeType":867},{},[],{"data":37663,"content":37664,"nodeType":881},{},[37665],{"data":37666,"marks":37667,"value":15459,"nodeType":867},{},[],{"data":37669,"content":37670,"nodeType":908},{},[],{"data":37672,"content":37673,"nodeType":918},{},[37674],{"data":37675,"marks":37676,"value":15469,"nodeType":867},{},[],{"data":37678,"content":37679,"nodeType":881},{},[37680],{"data":37681,"marks":37682,"value":15476,"nodeType":867},{},[],{"data":37684,"content":37685,"nodeType":881},{},[37686],{"data":37687,"marks":37688,"value":15483,"nodeType":867},{},[],{"data":37690,"content":37691,"nodeType":881},{},[37692,37695,37699],{"data":37693,"marks":37694,"value":15490,"nodeType":867},{},[],{"data":37696,"marks":37697,"value":15495,"nodeType":867},{},[37698],{"type":1431},{"data":37700,"marks":37701,"value":15499,"nodeType":867},{},[],{"data":37703,"content":37704,"nodeType":881},{},[37705],{"data":37706,"marks":37707,"value":15506,"nodeType":867},{},[],{"data":37709,"content":37710,"nodeType":881},{},[37711],{"data":37712,"marks":37713,"value":15513,"nodeType":867},{},[],{"data":37715,"content":37716,"nodeType":908},{},[],{"data":37718,"content":37719,"nodeType":918},{},[37720],{"data":37721,"marks":37722,"value":15523,"nodeType":867},{},[],{"data":37724,"content":37725,"nodeType":881},{},[37726],{"data":37727,"marks":37728,"value":15530,"nodeType":867},{},[],{"data":37730,"content":37731,"nodeType":881},{},[37732],{"data":37733,"marks":37734,"value":15537,"nodeType":867},{},[],{"data":37736,"content":37737,"nodeType":3126},{},[37738,37747,37756],{"data":37739,"content":37740,"nodeType":3061},{},[37741],{"data":37742,"content":37743,"nodeType":881},{},[37744],{"data":37745,"marks":37746,"value":15550,"nodeType":867},{},[],{"data":37748,"content":37749,"nodeType":3061},{},[37750],{"data":37751,"content":37752,"nodeType":881},{},[37753],{"data":37754,"marks":37755,"value":15560,"nodeType":867},{},[],{"data":37757,"content":37758,"nodeType":3061},{},[37759],{"data":37760,"content":37761,"nodeType":881},{},[37762],{"data":37763,"marks":37764,"value":15570,"nodeType":867},{},[],{"data":37766,"content":37767,"nodeType":881},{},[37768],{"data":37769,"marks":37770,"value":15577,"nodeType":867},{},[],{"data":37772,"content":37773,"nodeType":3126},{},[37774,37783],{"data":37775,"content":37776,"nodeType":3061},{},[37777],{"data":37778,"content":37779,"nodeType":881},{},[37780],{"data":37781,"marks":37782,"value":15590,"nodeType":867},{},[],{"data":37784,"content":37785,"nodeType":3061},{},[37786],{"data":37787,"content":37788,"nodeType":881},{},[37789],{"data":37790,"marks":37791,"value":15600,"nodeType":867},{},[],{"data":37793,"content":37794,"nodeType":881},{},[37795],{"data":37796,"marks":37797,"value":15607,"nodeType":867},{},[],{"data":37799,"content":37800,"nodeType":908},{},[],{"data":37802,"content":37803,"nodeType":918},{},[37804],{"data":37805,"marks":37806,"value":15617,"nodeType":867},{},[],{"data":37808,"content":37809,"nodeType":881},{},[37810],{"data":37811,"marks":37812,"value":15624,"nodeType":867},{},[],{"data":37814,"content":37815,"nodeType":881},{},[37816,37819,37826],{"data":37817,"marks":37818,"value":21,"nodeType":867},{},[],{"data":37820,"content":37821,"nodeType":876},{"uri":15633},[37822],{"data":37823,"marks":37824,"value":15639,"nodeType":867},{},[37825],{"type":1040},{"data":37827,"marks":37828,"value":15643,"nodeType":867},{},[],{"data":37830,"content":37831,"nodeType":3126},{},[37832,37841,37850,37869,37878,37887],{"data":37833,"content":37834,"nodeType":3061},{},[37835],{"data":37836,"content":37837,"nodeType":881},{},[37838],{"data":37839,"marks":37840,"value":15656,"nodeType":867},{},[],{"data":37842,"content":37843,"nodeType":3061},{},[37844],{"data":37845,"content":37846,"nodeType":881},{},[37847],{"data":37848,"marks":37849,"value":15666,"nodeType":867},{},[],{"data":37851,"content":37852,"nodeType":3061},{},[37853],{"data":37854,"content":37855,"nodeType":881},{},[37856,37859,37866],{"data":37857,"marks":37858,"value":15676,"nodeType":867},{},[],{"data":37860,"content":37861,"nodeType":876},{"uri":14532},[37862],{"data":37863,"marks":37864,"value":14537,"nodeType":867},{},[37865],{"type":1040},{"data":37867,"marks":37868,"value":15687,"nodeType":867},{},[],{"data":37870,"content":37871,"nodeType":3061},{},[37872],{"data":37873,"content":37874,"nodeType":881},{},[37875],{"data":37876,"marks":37877,"value":15697,"nodeType":867},{},[],{"data":37879,"content":37880,"nodeType":3061},{},[37881],{"data":37882,"content":37883,"nodeType":881},{},[37884],{"data":37885,"marks":37886,"value":15707,"nodeType":867},{},[],{"data":37888,"content":37889,"nodeType":3061},{},[37890],{"data":37891,"content":37892,"nodeType":881},{},[37893,37896,37903],{"data":37894,"marks":37895,"value":15717,"nodeType":867},{},[],{"data":37897,"content":37898,"nodeType":876},{"uri":15720},[37899],{"data":37900,"marks":37901,"value":15726,"nodeType":867},{},[37902],{"type":1040},{"data":37904,"marks":37905,"value":15730,"nodeType":867},{},[],{"data":37907,"content":37908,"nodeType":881},{},[37909],{"data":37910,"marks":37911,"value":15737,"nodeType":867},{},[],{"data":37913,"content":37916,"nodeType":890},{"target":37914},{"sys":37915},{"id":15742,"type":887,"linkType":888},[],{"data":37918,"content":37919,"nodeType":908},{},[],{"data":37921,"content":37922,"nodeType":918},{},[37923],{"data":37924,"marks":37925,"value":15753,"nodeType":867},{},[],{"data":37927,"content":37928,"nodeType":881},{},[37929],{"data":37930,"marks":37931,"value":15760,"nodeType":867},{},[],{"data":37933,"content":37934,"nodeType":881},{},[37935],{"data":37936,"marks":37937,"value":15767,"nodeType":867},{},[],{"data":37939,"content":37942,"nodeType":890},{"target":37940},{"sys":37941},{"id":15772,"type":887,"linkType":888},[],{"data":37944,"content":37945,"nodeType":881},{},[37946,37949,37957],{"data":37947,"marks":37948,"value":15780,"nodeType":867},{},[],{"data":37950,"content":37951,"nodeType":876},{"uri":15783},[37952],{"data":37953,"marks":37954,"value":15790,"nodeType":867},{},[37955,37956],{"type":1040},{"type":916},{"data":37958,"marks":37959,"value":15794,"nodeType":867},{},[],{"data":37961,"content":37964,"nodeType":890},{"target":37962},{"sys":37963},{"id":15799,"type":887,"linkType":888},[],{"data":37966,"content":37967,"nodeType":881},{},[37968],{"data":37969,"marks":37970,"value":15807,"nodeType":867},{},[],{"data":37972,"content":37973,"nodeType":908},{},[],{"data":37975,"content":37976,"nodeType":918},{},[37977],{"data":37978,"marks":37979,"value":15817,"nodeType":867},{},[],{"data":37981,"content":37982,"nodeType":881},{},[37983,37986,37993],{"data":37984,"marks":37985,"value":15824,"nodeType":867},{},[],{"data":37987,"content":37988,"nodeType":876},{"uri":15827},[37989],{"data":37990,"marks":37991,"value":15833,"nodeType":867},{},[37992],{"type":1040},{"data":37994,"marks":37995,"value":15837,"nodeType":867},{},[],{"data":37997,"content":37998,"nodeType":881},{},[37999,38002,38009],{"data":38000,"marks":38001,"value":15844,"nodeType":867},{},[],{"data":38003,"content":38004,"nodeType":876},{"uri":2362},[38005],{"data":38006,"marks":38007,"value":10826,"nodeType":867},{},[38008],{"type":1040},{"data":38010,"marks":38011,"value":1947,"nodeType":867},{},[],{"data":38013,"content":38016,"nodeType":890},{"target":38014},{"sys":38015},{"id":15859,"type":887,"linkType":888},[],{"data":38018,"content":38019,"nodeType":881},{},[38020],{"data":38021,"marks":38022,"value":21,"nodeType":867},{},[],{"entries":38024},{"hyperlink":38025,"inline":38026,"block":38027},[],[],[38028,38058,38060,38063,38066],{"sys":38029,"__typename":1696,"content":38030,"name":35814,"title":59},{"id":15249},{"json":38031},{"nodeType":1640,"data":38032,"content":38033},{},[38034],{"nodeType":881,"data":38035,"content":38036},{},[38037,38040,38046,38049,38055],{"nodeType":867,"value":35789,"marks":38038,"data":38039},[],{},{"nodeType":876,"data":38041,"content":38042},{"uri":31660},[38043],{"nodeType":867,"value":35796,"marks":38044,"data":38045},[],{},{"nodeType":867,"value":35800,"marks":38047,"data":38048},[],{},{"nodeType":876,"data":38050,"content":38051},{"uri":31660},[38052],{"nodeType":867,"value":35807,"marks":38053,"data":38054},[],{},{"nodeType":867,"value":35811,"marks":38056,"data":38057},[],{},{"sys":38059,"__typename":22749,"type":22750,"ctaText":35817,"buttonLabel":35818,"buttonColour":22753,"buttonUrl":35819},{"id":15742},{"sys":38061,"__typename":1648,"title":35852,"caption":35852,"layoutMode":59,"file":38062},{"id":15772},{"url":35854,"width":1661,"height":35825},{"sys":38064,"__typename":1648,"title":25579,"caption":25580,"layoutMode":59,"file":38065},{"id":15799},{"url":25582,"width":25583,"height":25584},{"sys":38067,"__typename":22749,"type":22750,"ctaText":35867,"buttonLabel":35868,"buttonColour":22753,"buttonUrl":15827},{"id":15859},{"items":38069},[],{},"How to protect your organization from help desk scams",{"url":35874},{"items":38074},[38075,38628,38933],{"__typename":1742,"sys":38076,"content":38077,"title":37402,"synopsis":37403,"hashTags":59,"publishedDate":37404,"slug":37405,"tagsCollection":38618,"authorsCollection":38624},{"id":36786},{"json":38078},{"data":38079,"content":38080,"nodeType":1640},{},[38081,38087,38093,38100,38123,38129,38134,38137,38144,38150,38156,38195,38201,38207,38210,38217,38223,38229,38235,38251,38257,38262,38269,38275,38281,38287,38292,38295,38302,38309,38315,38322,38328,38386,38392,38399,38405,38435,38442,38448,38455,38461,38468,38474,38522,38528,38531,38538,38544,38559,38589,38607,38612],{"data":38082,"content":38083,"nodeType":881},{},[38084],{"data":38085,"marks":38086,"value":36797,"nodeType":867},{},[],{"data":38088,"content":38089,"nodeType":881},{},[38090],{"data":38091,"marks":38092,"value":36804,"nodeType":867},{},[],{"data":38094,"content":38095,"nodeType":881},{},[38096],{"data":38097,"marks":38098,"value":36812,"nodeType":867},{},[38099],{"type":916},{"data":38101,"content":38102,"nodeType":881},{},[38103,38106,38113,38116,38120],{"data":38104,"marks":38105,"value":36819,"nodeType":867},{},[],{"data":38107,"content":38108,"nodeType":876},{"uri":36822},[38109],{"data":38110,"marks":38111,"value":36828,"nodeType":867},{},[38112],{"type":1040},{"data":38114,"marks":38115,"value":36832,"nodeType":867},{},[],{"data":38117,"marks":38118,"value":36837,"nodeType":867},{},[38119],{"type":1431},{"data":38121,"marks":38122,"value":36841,"nodeType":867},{},[],{"data":38124,"content":38125,"nodeType":881},{},[38126],{"data":38127,"marks":38128,"value":36848,"nodeType":867},{},[],{"data":38130,"content":38133,"nodeType":890},{"target":38131},{"sys":38132},{"id":36853,"type":887,"linkType":888},[],{"data":38135,"content":38136,"nodeType":908},{},[],{"data":38138,"content":38139,"nodeType":918},{},[38140],{"data":38141,"marks":38142,"value":36865,"nodeType":867},{},[38143],{"type":916},{"data":38145,"content":38146,"nodeType":881},{},[38147],{"data":38148,"marks":38149,"value":36872,"nodeType":867},{},[],{"data":38151,"content":38152,"nodeType":881},{},[38153],{"data":38154,"marks":38155,"value":36879,"nodeType":867},{},[],{"data":38157,"content":38158,"nodeType":3126},{},[38159,38168,38177,38186],{"data":38160,"content":38161,"nodeType":3061},{},[38162],{"data":38163,"content":38164,"nodeType":881},{},[38165],{"data":38166,"marks":38167,"value":36892,"nodeType":867},{},[],{"data":38169,"content":38170,"nodeType":3061},{},[38171],{"data":38172,"content":38173,"nodeType":881},{},[38174],{"data":38175,"marks":38176,"value":36902,"nodeType":867},{},[],{"data":38178,"content":38179,"nodeType":3061},{},[38180],{"data":38181,"content":38182,"nodeType":881},{},[38183],{"data":38184,"marks":38185,"value":36912,"nodeType":867},{},[],{"data":38187,"content":38188,"nodeType":3061},{},[38189],{"data":38190,"content":38191,"nodeType":881},{},[38192],{"data":38193,"marks":38194,"value":36922,"nodeType":867},{},[],{"data":38196,"content":38197,"nodeType":881},{},[38198],{"data":38199,"marks":38200,"value":36929,"nodeType":867},{},[],{"data":38202,"content":38203,"nodeType":881},{},[38204],{"data":38205,"marks":38206,"value":36936,"nodeType":867},{},[],{"data":38208,"content":38209,"nodeType":908},{},[],{"data":38211,"content":38212,"nodeType":918},{},[38213],{"data":38214,"marks":38215,"value":36947,"nodeType":867},{},[38216],{"type":916},{"data":38218,"content":38219,"nodeType":881},{},[38220],{"data":38221,"marks":38222,"value":36954,"nodeType":867},{},[],{"data":38224,"content":38225,"nodeType":881},{},[38226],{"data":38227,"marks":38228,"value":36961,"nodeType":867},{},[],{"data":38230,"content":38231,"nodeType":881},{},[38232],{"data":38233,"marks":38234,"value":36968,"nodeType":867},{},[],{"data":38236,"content":38237,"nodeType":881},{},[38238,38241,38248],{"data":38239,"marks":38240,"value":36975,"nodeType":867},{},[],{"data":38242,"content":38243,"nodeType":876},{"uri":6114},[38244],{"data":38245,"marks":38246,"value":33785,"nodeType":867},{},[38247],{"type":1040},{"data":38249,"marks":38250,"value":36986,"nodeType":867},{},[],{"data":38252,"content":38253,"nodeType":881},{},[38254],{"data":38255,"marks":38256,"value":36993,"nodeType":867},{},[],{"data":38258,"content":38261,"nodeType":890},{"target":38259},{"sys":38260},{"id":36998,"type":887,"linkType":888},[],{"data":38263,"content":38264,"nodeType":918},{},[38265],{"data":38266,"marks":38267,"value":37007,"nodeType":867},{},[38268],{"type":916},{"data":38270,"content":38271,"nodeType":881},{},[38272],{"data":38273,"marks":38274,"value":37014,"nodeType":867},{},[],{"data":38276,"content":38277,"nodeType":881},{},[38278],{"data":38279,"marks":38280,"value":37021,"nodeType":867},{},[],{"data":38282,"content":38283,"nodeType":881},{},[38284],{"data":38285,"marks":38286,"value":37028,"nodeType":867},{},[],{"data":38288,"content":38291,"nodeType":890},{"target":38289},{"sys":38290},{"id":37033,"type":887,"linkType":888},[],{"data":38293,"content":38294,"nodeType":908},{},[],{"data":38296,"content":38297,"nodeType":918},{},[38298],{"data":38299,"marks":38300,"value":37045,"nodeType":867},{},[38301],{"type":916},{"data":38303,"content":38304,"nodeType":998},{},[38305],{"data":38306,"marks":38307,"value":37053,"nodeType":867},{},[38308],{"type":916},{"data":38310,"content":38311,"nodeType":881},{},[38312],{"data":38313,"marks":38314,"value":37060,"nodeType":867},{},[],{"data":38316,"content":38317,"nodeType":998},{},[38318],{"data":38319,"marks":38320,"value":37068,"nodeType":867},{},[38321],{"type":916},{"data":38323,"content":38324,"nodeType":881},{},[38325],{"data":38326,"marks":38327,"value":37075,"nodeType":867},{},[],{"data":38329,"content":38330,"nodeType":3126},{},[38331,38340,38349,38368,38377],{"data":38332,"content":38333,"nodeType":3061},{},[38334],{"data":38335,"content":38336,"nodeType":881},{},[38337],{"data":38338,"marks":38339,"value":37088,"nodeType":867},{},[],{"data":38341,"content":38342,"nodeType":3061},{},[38343],{"data":38344,"content":38345,"nodeType":881},{},[38346],{"data":38347,"marks":38348,"value":37098,"nodeType":867},{},[],{"data":38350,"content":38351,"nodeType":3061},{},[38352],{"data":38353,"content":38354,"nodeType":881},{},[38355,38358,38365],{"data":38356,"marks":38357,"value":37108,"nodeType":867},{},[],{"data":38359,"content":38360,"nodeType":876},{"uri":37111},[38361],{"data":38362,"marks":38363,"value":37117,"nodeType":867},{},[38364],{"type":1040},{"data":38366,"marks":38367,"value":21,"nodeType":867},{},[],{"data":38369,"content":38370,"nodeType":3061},{},[38371],{"data":38372,"content":38373,"nodeType":881},{},[38374],{"data":38375,"marks":38376,"value":37130,"nodeType":867},{},[],{"data":38378,"content":38379,"nodeType":3061},{},[38380],{"data":38381,"content":38382,"nodeType":881},{},[38383],{"data":38384,"marks":38385,"value":37140,"nodeType":867},{},[],{"data":38387,"content":38388,"nodeType":881},{},[38389],{"data":38390,"marks":38391,"value":37147,"nodeType":867},{},[],{"data":38393,"content":38394,"nodeType":998},{},[38395],{"data":38396,"marks":38397,"value":37155,"nodeType":867},{},[38398],{"type":916},{"data":38400,"content":38401,"nodeType":881},{},[38402],{"data":38403,"marks":38404,"value":37162,"nodeType":867},{},[],{"data":38406,"content":38407,"nodeType":3126},{},[38408,38417,38426],{"data":38409,"content":38410,"nodeType":3061},{},[38411],{"data":38412,"content":38413,"nodeType":881},{},[38414],{"data":38415,"marks":38416,"value":37175,"nodeType":867},{},[],{"data":38418,"content":38419,"nodeType":3061},{},[38420],{"data":38421,"content":38422,"nodeType":881},{},[38423],{"data":38424,"marks":38425,"value":37185,"nodeType":867},{},[],{"data":38427,"content":38428,"nodeType":3061},{},[38429],{"data":38430,"content":38431,"nodeType":881},{},[38432],{"data":38433,"marks":38434,"value":37195,"nodeType":867},{},[],{"data":38436,"content":38437,"nodeType":998},{},[38438],{"data":38439,"marks":38440,"value":37203,"nodeType":867},{},[38441],{"type":916},{"data":38443,"content":38444,"nodeType":881},{},[38445],{"data":38446,"marks":38447,"value":37210,"nodeType":867},{},[],{"data":38449,"content":38450,"nodeType":998},{},[38451],{"data":38452,"marks":38453,"value":37218,"nodeType":867},{},[38454],{"type":916},{"data":38456,"content":38457,"nodeType":881},{},[38458],{"data":38459,"marks":38460,"value":37225,"nodeType":867},{},[],{"data":38462,"content":38463,"nodeType":998},{},[38464],{"data":38465,"marks":38466,"value":37233,"nodeType":867},{},[38467],{"type":916},{"data":38469,"content":38470,"nodeType":881},{},[38471],{"data":38472,"marks":38473,"value":37240,"nodeType":867},{},[],{"data":38475,"content":38476,"nodeType":3126},{},[38477,38486,38495,38504,38513],{"data":38478,"content":38479,"nodeType":3061},{},[38480],{"data":38481,"content":38482,"nodeType":881},{},[38483],{"data":38484,"marks":38485,"value":37253,"nodeType":867},{},[],{"data":38487,"content":38488,"nodeType":3061},{},[38489],{"data":38490,"content":38491,"nodeType":881},{},[38492],{"data":38493,"marks":38494,"value":37263,"nodeType":867},{},[],{"data":38496,"content":38497,"nodeType":3061},{},[38498],{"data":38499,"content":38500,"nodeType":881},{},[38501],{"data":38502,"marks":38503,"value":37273,"nodeType":867},{},[],{"data":38505,"content":38506,"nodeType":3061},{},[38507],{"data":38508,"content":38509,"nodeType":881},{},[38510],{"data":38511,"marks":38512,"value":37283,"nodeType":867},{},[],{"data":38514,"content":38515,"nodeType":3061},{},[38516],{"data":38517,"content":38518,"nodeType":881},{},[38519],{"data":38520,"marks":38521,"value":37293,"nodeType":867},{},[],{"data":38523,"content":38524,"nodeType":881},{},[38525],{"data":38526,"marks":38527,"value":37300,"nodeType":867},{},[],{"data":38529,"content":38530,"nodeType":908},{},[],{"data":38532,"content":38533,"nodeType":918},{},[38534],{"data":38535,"marks":38536,"value":37311,"nodeType":867},{},[38537],{"type":916},{"data":38539,"content":38540,"nodeType":881},{},[38541],{"data":38542,"marks":38543,"value":37318,"nodeType":867},{},[],{"data":38545,"content":38546,"nodeType":881},{},[38547,38550,38556],{"data":38548,"marks":38549,"value":37325,"nodeType":867},{},[],{"data":38551,"content":38552,"nodeType":876},{"uri":36822},[38553],{"data":38554,"marks":38555,"value":37332,"nodeType":867},{},[],{"data":38557,"marks":38558,"value":1947,"nodeType":867},{},[],{"data":38560,"content":38561,"nodeType":3126},{},[38562,38571,38580],{"data":38563,"content":38564,"nodeType":3061},{},[38565],{"data":38566,"content":38567,"nodeType":881},{},[38568],{"data":38569,"marks":38570,"value":37348,"nodeType":867},{},[],{"data":38572,"content":38573,"nodeType":3061},{},[38574],{"data":38575,"content":38576,"nodeType":881},{},[38577],{"data":38578,"marks":38579,"value":37358,"nodeType":867},{},[],{"data":38581,"content":38582,"nodeType":3061},{},[38583],{"data":38584,"content":38585,"nodeType":881},{},[38586],{"data":38587,"marks":38588,"value":37368,"nodeType":867},{},[],{"data":38590,"content":38591,"nodeType":881},{},[38592,38596,38603],{"data":38593,"marks":38594,"value":37376,"nodeType":867},{},[38595],{"type":916},{"data":38597,"content":38598,"nodeType":876},{"uri":2362},[38599],{"data":38600,"marks":38601,"value":37384,"nodeType":867},{},[38602],{"type":916},{"data":38604,"marks":38605,"value":37389,"nodeType":867},{},[38606],{"type":916},{"data":38608,"content":38611,"nodeType":890},{"target":38609},{"sys":38610},{"id":37394,"type":887,"linkType":888},[],{"data":38613,"content":38614,"nodeType":881},{},[38615],{"data":38616,"marks":38617,"value":21,"nodeType":867},{},[],{"items":38619},[38620,38622],{"sys":38621,"name":2547},{"id":2546},{"sys":38623,"name":342},{"id":2550},{"items":38625},[38626],{"fullName":37415,"firstName":37416,"jobTitle":4374,"profilePicture":38627},{"url":37418},{"__typename":1742,"sys":38629,"content":38630,"title":29803,"synopsis":36771,"hashTags":59,"publishedDate":36772,"slug":29804,"tagsCollection":38925,"authorsCollection":38929},{"id":27642},{"json":38631},{"data":38632,"content":38633,"nodeType":1640},{},[38634,38640,38646,38652,38657,38663,38693,38699,38705,38711,38716,38722,38728,38743,38748,38754,38770,38786,38792,38798,38804,38810,38816,38822,38828,38844,38850,38856,38861,38867,38873,38893,38898,38914,38919],{"data":38635,"content":38636,"nodeType":881},{},[38637],{"data":38638,"marks":38639,"value":36437,"nodeType":867},{},[],{"data":38641,"content":38642,"nodeType":881},{},[38643],{"data":38644,"marks":38645,"value":36444,"nodeType":867},{},[],{"data":38647,"content":38648,"nodeType":881},{},[38649],{"data":38650,"marks":38651,"value":36451,"nodeType":867},{},[],{"data":38653,"content":38656,"nodeType":890},{"target":38654},{"sys":38655},{"id":36456,"type":887,"linkType":888},[],{"data":38658,"content":38659,"nodeType":881},{},[38660],{"data":38661,"marks":38662,"value":36464,"nodeType":867},{},[],{"data":38664,"content":38665,"nodeType":3126},{},[38666,38675,38684],{"data":38667,"content":38668,"nodeType":3061},{},[38669],{"data":38670,"content":38671,"nodeType":881},{},[38672],{"data":38673,"marks":38674,"value":36477,"nodeType":867},{},[],{"data":38676,"content":38677,"nodeType":3061},{},[38678],{"data":38679,"content":38680,"nodeType":881},{},[38681],{"data":38682,"marks":38683,"value":36487,"nodeType":867},{},[],{"data":38685,"content":38686,"nodeType":3061},{},[38687],{"data":38688,"content":38689,"nodeType":881},{},[38690],{"data":38691,"marks":38692,"value":36497,"nodeType":867},{},[],{"data":38694,"content":38695,"nodeType":881},{},[38696],{"data":38697,"marks":38698,"value":36504,"nodeType":867},{},[],{"data":38700,"content":38701,"nodeType":918},{},[38702],{"data":38703,"marks":38704,"value":36511,"nodeType":867},{},[],{"data":38706,"content":38707,"nodeType":881},{},[38708],{"data":38709,"marks":38710,"value":36518,"nodeType":867},{},[],{"data":38712,"content":38715,"nodeType":890},{"target":38713},{"sys":38714},{"id":36523,"type":887,"linkType":888},[],{"data":38717,"content":38718,"nodeType":881},{},[38719],{"data":38720,"marks":38721,"value":36531,"nodeType":867},{},[],{"data":38723,"content":38724,"nodeType":918},{},[38725],{"data":38726,"marks":38727,"value":36538,"nodeType":867},{},[],{"data":38729,"content":38730,"nodeType":881},{},[38731,38734,38740],{"data":38732,"marks":38733,"value":36545,"nodeType":867},{},[],{"data":38735,"content":38736,"nodeType":876},{"uri":15633},[38737],{"data":38738,"marks":38739,"value":36552,"nodeType":867},{},[],{"data":38741,"marks":38742,"value":36556,"nodeType":867},{},[],{"data":38744,"content":38747,"nodeType":890},{"target":38745},{"sys":38746},{"id":15742,"type":887,"linkType":888},[],{"data":38749,"content":38750,"nodeType":998},{},[38751],{"data":38752,"marks":38753,"value":36568,"nodeType":867},{},[],{"data":38755,"content":38756,"nodeType":881},{},[38757,38760,38767],{"data":38758,"marks":38759,"value":36575,"nodeType":867},{},[],{"data":38761,"content":38762,"nodeType":876},{"uri":36578},[38763],{"data":38764,"marks":38765,"value":36584,"nodeType":867},{},[38766],{"type":1040},{"data":38768,"marks":38769,"value":36588,"nodeType":867},{},[],{"data":38771,"content":38772,"nodeType":881},{},[38773,38776,38783],{"data":38774,"marks":38775,"value":36595,"nodeType":867},{},[],{"data":38777,"content":38778,"nodeType":876},{"uri":14743},[38779],{"data":38780,"marks":38781,"value":14749,"nodeType":867},{},[38782],{"type":1040},{"data":38784,"marks":38785,"value":36606,"nodeType":867},{},[],{"data":38787,"content":38788,"nodeType":881},{},[38789],{"data":38790,"marks":38791,"value":36613,"nodeType":867},{},[],{"data":38793,"content":38794,"nodeType":881},{},[38795],{"data":38796,"marks":38797,"value":36620,"nodeType":867},{},[],{"data":38799,"content":38800,"nodeType":998},{},[38801],{"data":38802,"marks":38803,"value":36627,"nodeType":867},{},[],{"data":38805,"content":38806,"nodeType":881},{},[38807],{"data":38808,"marks":38809,"value":36634,"nodeType":867},{},[],{"data":38811,"content":38812,"nodeType":881},{},[38813],{"data":38814,"marks":38815,"value":36641,"nodeType":867},{},[],{"data":38817,"content":38818,"nodeType":918},{},[38819],{"data":38820,"marks":38821,"value":36648,"nodeType":867},{},[],{"data":38823,"content":38824,"nodeType":881},{},[38825],{"data":38826,"marks":38827,"value":36655,"nodeType":867},{},[],{"data":38829,"content":38830,"nodeType":881},{},[38831,38834,38841],{"data":38832,"marks":38833,"value":36662,"nodeType":867},{},[],{"data":38835,"content":38836,"nodeType":876},{"uri":36665},[38837],{"data":38838,"marks":38839,"value":36671,"nodeType":867},{},[38840],{"type":1040},{"data":38842,"marks":38843,"value":36675,"nodeType":867},{},[],{"data":38845,"content":38846,"nodeType":881},{},[38847],{"data":38848,"marks":38849,"value":36682,"nodeType":867},{},[],{"data":38851,"content":38852,"nodeType":881},{},[38853],{"data":38854,"marks":38855,"value":36689,"nodeType":867},{},[],{"data":38857,"content":38860,"nodeType":890},{"target":38858},{"sys":38859},{"id":36694,"type":887,"linkType":888},[],{"data":38862,"content":38863,"nodeType":918},{},[38864],{"data":38865,"marks":38866,"value":15817,"nodeType":867},{},[],{"data":38868,"content":38869,"nodeType":881},{},[38870],{"data":38871,"marks":38872,"value":36708,"nodeType":867},{},[],{"data":38874,"content":38875,"nodeType":881},{},[38876,38879,38883,38886,38890],{"data":38877,"marks":38878,"value":36715,"nodeType":867},{},[],{"data":38880,"marks":38881,"value":36720,"nodeType":867},{},[38882],{"type":916},{"data":38884,"marks":38885,"value":36724,"nodeType":867},{},[],{"data":38887,"marks":38888,"value":36729,"nodeType":867},{},[38889],{"type":916},{"data":38891,"marks":38892,"value":36733,"nodeType":867},{},[],{"data":38894,"content":38897,"nodeType":890},{"target":38895},{"sys":38896},{"id":36738,"type":887,"linkType":888},[],{"data":38899,"content":38900,"nodeType":881},{},[38901,38904,38911],{"data":38902,"marks":38903,"value":36746,"nodeType":867},{},[],{"data":38905,"content":38906,"nodeType":876},{"uri":2362},[38907],{"data":38908,"marks":38909,"value":36754,"nodeType":867},{},[38910],{"type":1040},{"data":38912,"marks":38913,"value":36758,"nodeType":867},{},[],{"data":38915,"content":38918,"nodeType":890},{"target":38916},{"sys":38917},{"id":36763,"type":887,"linkType":888},[],{"data":38920,"content":38921,"nodeType":881},{},[38922],{"data":38923,"marks":38924,"value":21,"nodeType":867},{},[],{"items":38926},[38927],{"sys":38928,"name":297},{"id":5646},{"items":38930},[38931],{"fullName":36780,"firstName":36781,"jobTitle":4374,"profilePicture":38932},{"url":36783},{"__typename":1742,"sys":38934,"content":38935,"title":29799,"synopsis":40251,"hashTags":59,"publishedDate":40252,"slug":29800,"tagsCollection":40253,"authorsCollection":40259},{"id":27581},{"json":38936},{"data":38937,"content":38938,"nodeType":1640},{},[38939,38944,38952,38959,38987,38993,39001,39030,39072,39078,39086,39104,39110,39113,39121,39128,39134,39175,39306,39309,39317,39324,39332,39363,39369,39377,39397,39404,39410,39417,39423,39442,39450,39468,39476,39483,39490,39493,39501,39508,39514,39521,39529,39547,39554,39560,39568,39575,39582,39613,39619,39626,39634,39641,39647,39678,39686,39706,39713,39719,39727,39747,39754,39817,39823,39826,39834,39841,39848,39879,39882,39890,39898,39904,39911,39919,39925,39932,39939,39945,39952,39960,39967,39974,39981,40000,40019,40026,40033,40039,40046,40054,40061,40068,40074,40081,40089,40096,40103,40110,40116,40123,40131,40138,40156,40162,40169,40186,40191,40197,40213,40218,40221,40228,40235],{"data":38940,"content":38943,"nodeType":890},{"target":38941},{"sys":38942},{"id":15249,"type":887,"linkType":888},[],{"data":38945,"content":38946,"nodeType":918},{},[38947],{"data":38948,"marks":38949,"value":38951,"nodeType":867},{},[38950],{"type":916},"Background: Who are Scattered Spider?",{"data":38953,"content":38954,"nodeType":881},{},[38955],{"data":38956,"marks":38957,"value":38958,"nodeType":867},{},[],"Scattered Spider (also tracked as 0ktapus, Octo Tempest, Scatter Swine, Muddled Libra, and UNC3944) is a native English speaking, financially motivated criminal collective known for high-profile cyber breaches in recent years, including MoneyGram, Transport for London, Caesars, MGM Resorts, Clorox, DoorDash, Twilio, Reddit, Coinbase, MailChimp, Okta, HubSpot, Cloudflare, Activision, Pure Storage, and the ongoing Marks & Spencer, Co-op, and Harrods incidents.",{"data":38960,"content":38961,"nodeType":881},{},[38962,38966,38973,38976,38983],{"data":38963,"marks":38964,"value":38965,"nodeType":867},{},[],"Scattered Spider shares similar characteristics and TTPs with a number of named threat groups such as ",{"data":38967,"content":38968,"nodeType":876},{"uri":35499},[38969],{"data":38970,"marks":38971,"value":35505,"nodeType":867},{},[38972],{"type":1040},{"data":38974,"marks":38975,"value":15362,"nodeType":867},{},[],{"data":38977,"content":38978,"nodeType":876},{"uri":14576},[38979],{"data":38980,"marks":38981,"value":8186,"nodeType":867},{},[38982],{"type":1040},{"data":38984,"marks":38985,"value":38986,"nodeType":867},{},[]," (behind the Snowflake attacks in 2024).",{"data":38988,"content":38992,"nodeType":890},{"target":38989},{"sys":38990},{"id":38991,"type":887,"linkType":888},"4sgT2Jw3iODUTdG2oPOrFC",[],{"data":38994,"content":38995,"nodeType":998},{},[38996],{"data":38997,"marks":38998,"value":39000,"nodeType":867},{},[38999],{"type":916},"Case study: MGM Resorts",{"data":39002,"content":39003,"nodeType":881},{},[39004,39008,39015,39019,39026],{"data":39005,"marks":39006,"value":39007,"nodeType":867},{},[],"One of Scattered Spider’s most notorious and well-documented attacks was that affecting ",{"data":39009,"content":39010,"nodeType":876},{"uri":36578},[39011],{"data":39012,"marks":39013,"value":36584,"nodeType":867},{},[39014],{"type":1040},{"data":39016,"marks":39017,"value":39018,"nodeType":867},{},[],". Scattered Spider socially engineered MGM Resorts helpdesk personnel bypass MFA and log into accounts for which they had acquired valid login credentials for via credential phishing and historical infostealer compromises. They specifically targeted accounts with Super Administrator privileges within MGM Resorts’ Okta tenant, which they then used to register a second, attacker-controlled IdP via ",{"data":39020,"content":39021,"nodeType":876},{"uri":14743},[39022],{"data":39023,"marks":39024,"value":14749,"nodeType":867},{},[39025],{"type":1040},{"data":39027,"marks":39028,"value":39029,"nodeType":867},{},[],", which enabled them to impersonate any user within the Okta tenant. This then enabled them to abuse SSO access to downstream apps and platforms from various accounts, culminating in deployment of ransomware to around 100 ESXi servers and data exfiltration. ",{"data":39031,"content":39032,"nodeType":881},{},[39033,39037,39042,39046,39051,39055,39060,39064,39069],{"data":39034,"marks":39035,"value":39036,"nodeType":867},{},[],"The breach resulted in a ",{"data":39038,"marks":39039,"value":39041,"nodeType":867},{},[39040],{"type":916},"36-hour outage",{"data":39043,"marks":39044,"value":39045,"nodeType":867},{},[],", a ",{"data":39047,"marks":39048,"value":39050,"nodeType":867},{},[39049],{"type":916},"$100M ",{"data":39052,"marks":39053,"value":39054,"nodeType":867},{},[],"hit to its Q3 results, one-time cyber consulting fees in the region of ",{"data":39056,"marks":39057,"value":39059,"nodeType":867},{},[39058],{"type":916},"$10M",{"data":39061,"marks":39062,"value":39063,"nodeType":867},{},[],", and a class-action lawsuit later settled for ",{"data":39065,"marks":39066,"value":39068,"nodeType":867},{},[39067],{"type":916},"$45M",{"data":39070,"marks":39071,"value":10110,"nodeType":867},{},[],{"data":39073,"content":39077,"nodeType":890},{"target":39074},{"sys":39075},{"id":39076,"type":887,"linkType":888},"2vYvBXqFeKt7Ix0Ynh8cZu",[],{"data":39079,"content":39080,"nodeType":998},{},[39081],{"data":39082,"marks":39083,"value":39085,"nodeType":867},{},[39084],{"type":916},"Case Study: Snowflake",{"data":39087,"content":39088,"nodeType":881},{},[39089,39093,39100],{"data":39090,"marks":39091,"value":39092,"nodeType":867},{},[],"Members of Scattered Spider have been affiliated with ShinyHunters, the group behind the ",{"data":39094,"content":39095,"nodeType":876},{"uri":14576},[39096],{"data":39097,"marks":39098,"value":39099,"nodeType":867},{},[],"Snowflake breaches in mid-2024",{"data":39101,"marks":39102,"value":39103,"nodeType":867},{},[],". ShinyHunters associates targeted ~165 organizations that were subjected to account takeover attacks using stolen credentials harvested from historical infostealer infections dating back as far as 2020, according to Mandiant’s investigation. In total, 9 public victims were named following the breach, collectively impacting hundreds of millions of people. Snowflake was a watershed moment that signalled the significant opportunity presented by identity attacks on cloud services. It demonstrated how comparatively unsophisticated methods (logging in to user accounts with stolen credentials and dumping the data) can have the same or greater impact as a traditional network or endpoint based cyber attack involving vulnerability exploitation, malware deployment, ransomware, etc.",{"data":39105,"content":39109,"nodeType":890},{"target":39106},{"sys":39107},{"id":39108,"type":887,"linkType":888},"49nJMPQjQ37Mfr2yWA56P3",[],{"data":39111,"content":39112,"nodeType":908},{},[],{"data":39114,"content":39115,"nodeType":918},{},[39116],{"data":39117,"marks":39118,"value":39120,"nodeType":867},{},[39119],{"type":916},"Arrests haven’t slowed Scattered Spider",{"data":39122,"content":39123,"nodeType":881},{},[39124],{"data":39125,"marks":39126,"value":39127,"nodeType":867},{},[],"In late 2024 following the Transport for London attacks (which resulted in prolonged disruption to key online services underpinning London’s public transport network, theft of 5,000 users bank details, and all 30,000 staff members having to reset their online credentials in person) a series of arrests were made in the UK and USA. ",{"data":39129,"content":39133,"nodeType":890},{"target":39130},{"sys":39131},{"id":39132,"type":887,"linkType":888},"2X2nyhO2hOqm9f0Le4lDC5",[],{"data":39135,"content":39136,"nodeType":881},{},[39137,39141,39149,39152,39159,39162,39171],{"data":39138,"marks":39139,"value":39140,"nodeType":867},{},[],"However, this doesn’t seem to have impacted Scattered Spider’s ability to operate, with the ongoing campaign against UK retail companies including ",{"data":39142,"content":39144,"nodeType":876},{"uri":39143},"https://www.bleepingcomputer.com/news/security/marks-and-spencer-breach-linked-to-scattered-spider-ransomware-attack/",[39145],{"data":39146,"marks":39147,"value":15266,"nodeType":867},{},[39148],{"type":1040},{"data":39150,"marks":39151,"value":4006,"nodeType":867},{},[],{"data":39153,"content":39154,"nodeType":876},{"uri":15272},[39155],{"data":39156,"marks":39157,"value":15278,"nodeType":867},{},[39158],{"type":1040},{"data":39160,"marks":39161,"value":15362,"nodeType":867},{},[],{"data":39163,"content":39165,"nodeType":876},{"uri":39164},"https://www.bleepingcomputer.com/news/security/harrods-the-next-uk-retailer-targeted-in-a-cyberattack/",[39166],{"data":39167,"marks":39168,"value":39170,"nodeType":867},{},[39169],{"type":1040},"Harrods",{"data":39172,"marks":39173,"value":39174,"nodeType":867},{},[]," being strongly linked to Scattered Spider. Beginning on Easter weekend, the Marks and Spencer attack has had the biggest impact so far, resulting in severe disruption to the retailer with agency staff told not to come into work, online shopping services being taken offline, stores running low on products, £300M in lost profits, and almost £1B wiped off the company’s stock market valuation at one stage. ",{"data":39176,"content":39177,"nodeType":881},{},[39178,39181,39188,39191,39198,39201,39208,39211,39218,39221,39228,39231,39238,39241,39248,39252,39258,39261,39267,39270,39276,39279,39285,39288,39294,39297,39303],{"data":39179,"marks":39180,"value":15289,"nodeType":867},{},[],{"data":39182,"content":39183,"nodeType":876},{"uri":15292},[39184],{"data":39185,"marks":39186,"value":15298,"nodeType":867},{},[39187],{"type":1040},{"data":39189,"marks":39190,"value":4006,"nodeType":867},{},[],{"data":39192,"content":39193,"nodeType":876},{"uri":15304},[39194],{"data":39195,"marks":39196,"value":15310,"nodeType":867},{},[39197],{"type":1040},{"data":39199,"marks":39200,"value":4006,"nodeType":867},{},[],{"data":39202,"content":39203,"nodeType":876},{"uri":15316},[39204],{"data":39205,"marks":39206,"value":15322,"nodeType":867},{},[39207],{"type":1040},{"data":39209,"marks":39210,"value":4006,"nodeType":867},{},[],{"data":39212,"content":39213,"nodeType":876},{"uri":15328},[39214],{"data":39215,"marks":39216,"value":15334,"nodeType":867},{},[39217],{"type":1040},{"data":39219,"marks":39220,"value":4006,"nodeType":867},{},[],{"data":39222,"content":39223,"nodeType":876},{"uri":15340},[39224],{"data":39225,"marks":39226,"value":15346,"nodeType":867},{},[39227],{"type":1040},{"data":39229,"marks":39230,"value":4006,"nodeType":867},{},[],{"data":39232,"content":39233,"nodeType":876},{"uri":15352},[39234],{"data":39235,"marks":39236,"value":15358,"nodeType":867},{},[39237],{"type":1040},{"data":39239,"marks":39240,"value":15362,"nodeType":867},{},[],{"data":39242,"content":39243,"nodeType":876},{"uri":15365},[39244],{"data":39245,"marks":39246,"value":15371,"nodeType":867},{},[39247],{"type":1040},{"data":39249,"marks":39250,"value":39251,"nodeType":867},{},[]," were among the retailers to suffer a breach between May-June 2025. More recently, Scattered Spider has targeted U.S. insurance giant ",{"data":39253,"content":39254,"nodeType":876},{"uri":15385},[39255],{"data":39256,"marks":39257,"value":15391,"nodeType":867},{},[],{"data":39259,"marks":39260,"value":4006,"nodeType":867},{},[],{"data":39262,"content":39263,"nodeType":876},{"uri":15397},[39264],{"data":39265,"marks":39266,"value":15403,"nodeType":867},{},[],{"data":39268,"marks":39269,"value":4006,"nodeType":867},{},[],{"data":39271,"content":39272,"nodeType":876},{"uri":15410},[39273],{"data":39274,"marks":39275,"value":15416,"nodeType":867},{},[],{"data":39277,"marks":39278,"value":4006,"nodeType":867},{},[],{"data":39280,"content":39281,"nodeType":876},{"uri":15434},[39282],{"data":39283,"marks":39284,"value":15439,"nodeType":867},{},[],{"data":39286,"marks":39287,"value":4006,"nodeType":867},{},[],{"data":39289,"content":39290,"nodeType":876},{"uri":15434},[39291],{"data":39292,"marks":39293,"value":15449,"nodeType":867},{},[],{"data":39295,"marks":39296,"value":15362,"nodeType":867},{},[],{"data":39298,"content":39299,"nodeType":876},{"uri":15423},[39300],{"data":39301,"marks":39302,"value":15428,"nodeType":867},{},[],{"data":39304,"marks":39305,"value":1947,"nodeType":867},{},[],{"data":39307,"content":39308,"nodeType":908},{},[],{"data":39310,"content":39311,"nodeType":918},{},[39312],{"data":39313,"marks":39314,"value":39316,"nodeType":867},{},[39315],{"type":916},"Scattered Spider TTP analysis",{"data":39318,"content":39319,"nodeType":881},{},[39320],{"data":39321,"marks":39322,"value":39323,"nodeType":867},{},[],"Along with a clear MO (financial gain via data exfiltration and extortion) Scattered Spider has demonstrated a pattern of go-to TTPs over recent years. ",{"data":39325,"content":39326,"nodeType":998},{},[39327],{"data":39328,"marks":39329,"value":39331,"nodeType":867},{},[39330],{"type":916},"Social engineering, help desk scams, and SIM swapping",{"data":39333,"content":39334,"nodeType":881},{},[39335,39339,39348,39351,39359],{"data":39336,"marks":39337,"value":39338,"nodeType":867},{},[],"The public breaches associated with Scattered Spider have predominantly featured social engineering heavy initial access, mainly through help desk scams where the attacker contacts support personnel specifically to bypass MFA for accounts where they have acquired valid credentials via credential phishing or infostealers, but cannot access the account due the additional layer of protection. They have similarly used ",{"data":39340,"content":39342,"nodeType":876},{"uri":39341},"https://cloud.google.com/blog/topics/threat-intelligence/unc3944-sms-phishing-sim-swapping-ransomware/",[39343],{"data":39344,"marks":39345,"value":39347,"nodeType":867},{},[39346],{"type":1040},"SIM swapping, smishing",{"data":39349,"marks":39350,"value":2063,"nodeType":867},{},[],{"data":39352,"content":39353,"nodeType":876},{"uri":14532},[39354],{"data":39355,"marks":39356,"value":39358,"nodeType":867},{},[39357],{"type":1040},"MFA fatigue/push bombing",{"data":39360,"marks":39361,"value":39362,"nodeType":867},{},[]," to achieve account takeover.",{"data":39364,"content":39368,"nodeType":890},{"target":39365},{"sys":39366},{"id":39367,"type":887,"linkType":888},"2Z7qnaK4LXRhnQDvPT2ZXe",[],{"data":39370,"content":39371,"nodeType":998},{},[39372],{"data":39373,"marks":39374,"value":39376,"nodeType":867},{},[39375],{"type":916},"Impersonating and targeting SaaS services",{"data":39378,"content":39379,"nodeType":881},{},[39380,39384,39393],{"data":39381,"marks":39382,"value":39383,"nodeType":867},{},[],"Scattered Spider have also been known to ",{"data":39385,"content":39387,"nodeType":876},{"uri":39386},"https://cloud.google.com/blog/topics/threat-intelligence/unc3944-targets-saas-applications",[39388],{"data":39389,"marks":39390,"value":39392,"nodeType":867},{},[39391],{"type":1040},"target SaaS applications and cloud services",{"data":39394,"marks":39395,"value":39396,"nodeType":867},{},[]," — both as part of their phishing strategies by impersonating app providers, as well as in their lateral movement and exploitation when an identity has been compromised. This has included applications such as vCenter, CyberArk, SalesForce, Azure, CrowdStrike, AWS, and GCP. ",{"data":39398,"content":39399,"nodeType":881},{},[39400],{"data":39401,"marks":39402,"value":39403,"nodeType":867},{},[],"When conducting phishing campaigns, they’ve created custom domains for their phishing sites based on the organizations they are targeting: ",{"data":39405,"content":39409,"nodeType":890},{"target":39406},{"sys":39407},{"id":39408,"type":887,"linkType":888},"3ufdtfyJpZ4FUWbKR2yNNm",[],{"data":39411,"content":39412,"nodeType":881},{},[39413],{"data":39414,"marks":39415,"value":39416,"nodeType":867},{},[],"And they have impersonated many software brands — either as targets themselves, or as convincing third-parties to lure their targets to interact with. ",{"data":39418,"content":39422,"nodeType":890},{"target":39419},{"sys":39420},{"id":39421,"type":887,"linkType":888},"XgrG1qKwXrpd399BwkHiR",[],{"data":39424,"content":39425,"nodeType":881},{},[39426,39430,39439],{"data":39427,"marks":39428,"value":39429,"nodeType":867},{},[],"(Shout out to the excellent analysis by the folks at ",{"data":39431,"content":39433,"nodeType":876},{"uri":39432},"https://www.silentpush.com/blog/scattered-spider-2025/#h-new-scattered-spider-ttps-for-2025",[39434],{"data":39435,"marks":39436,"value":39438,"nodeType":867},{},[39437],{"type":1040},"Silent Push",{"data":39440,"marks":39441,"value":10143,"nodeType":867},{},[],{"data":39443,"content":39444,"nodeType":998},{},[39445],{"data":39446,"marks":39447,"value":39449,"nodeType":867},{},[39448],{"type":916},"Targeting identity providers to abuse OAuth and SSO",{"data":39451,"content":39452,"nodeType":881},{},[39453,39457,39464],{"data":39454,"marks":39455,"value":39456,"nodeType":867},{},[],"A key part of this approach is abusing OAuth by targeting identity providers (IdPs) such as Okta and Microsoft Entra. By compromising IdP accounts with administrator privileges, Scattered Spider has leveraged techniques such as ",{"data":39458,"content":39459,"nodeType":876},{"uri":14743},[39460],{"data":39461,"marks":39462,"value":14749,"nodeType":867},{},[39463],{"type":1040},{"data":39465,"marks":39466,"value":39467,"nodeType":867},{},[]," to gain unrestricted access to the identities within the target IdP tenant (the equivalent of a full Active Directory compromise on-premise).",{"data":39469,"content":39470,"nodeType":998},{},[39471],{"data":39472,"marks":39473,"value":39475,"nodeType":867},{},[39474],{"type":916},"Encryption of cloud servers and data theft for extortion",{"data":39477,"content":39478,"nodeType":881},{},[39479],{"data":39480,"marks":39481,"value":39482,"nodeType":867},{},[],"When executing the final stages of an attack, Scattered Spider first exfiltrates data through a variety of methods, even using SaaS services such as DropBox and FiveTran to extract copies of high-value service databases, such as SalesForce and ZenDesk, using API connectors. ",{"data":39484,"content":39485,"nodeType":881},{},[39486],{"data":39487,"marks":39488,"value":39489,"nodeType":867},{},[],"In a typical \"double-extortion\" style, they then deploy ransomware by targeting cloud server environments such as VMWare ESXi (specifically to avoid security tools by targeting the hypervisor layer). Scattered Spider have been known to act as affiliates for various ransomware operations, including RansomHub, Qilin, and DragonForce.",{"data":39491,"content":39492,"nodeType":908},{},[],{"data":39494,"content":39495,"nodeType":918},{},[39496],{"data":39497,"marks":39498,"value":39500,"nodeType":867},{},[39499],{"type":916},"Scattered Spider TTP evolution in 2025",{"data":39502,"content":39503,"nodeType":881},{},[39504],{"data":39505,"marks":39506,"value":39507,"nodeType":867},{},[],"In 2025, security researchers have observed a significant increase in Scattered Spider phishing activity, particularly in the form of MFA-bypassing Attacker-in-the-Middle (AiTM) phishing pages. ",{"data":39509,"content":39513,"nodeType":890},{"target":39510},{"sys":39511},{"id":39512,"type":887,"linkType":888},"2jH5TrpHueIE8qpU3lunJi",[],{"data":39515,"content":39516,"nodeType":881},{},[39517],{"data":39518,"marks":39519,"value":39520,"nodeType":867},{},[],"Along with this shift, a number of TTPs have been observed relating to detection evasion measures implemented on these phishing pages.",{"data":39522,"content":39523,"nodeType":998},{},[39524],{"data":39525,"marks":39526,"value":39528,"nodeType":867},{},[39527],{"type":916},"Rapid phishing domain rotation",{"data":39530,"content":39531,"nodeType":881},{},[39532,39535,39543],{"data":39533,"marks":39534,"value":21,"nodeType":867},{},[],{"data":39536,"content":39537,"nodeType":876},{"uri":39432},[39538],{"data":39539,"marks":39540,"value":39542,"nodeType":867},{},[39541],{"type":1040},"According to researchers",{"data":39544,"marks":39545,"value":39546,"nodeType":867},{},[]," Scattered Spider have been observed using phishing pages hosted on short-lived domains that included specific keywords such as “okta,” “sso,” “help,” “hr,” “corp,” “my,” “internal,” “sso,” or “vpn,”, which were quickly operationalized within minutes of registering a domain. After a couple of hours, the domain would often be taken down by the registrar. However, as we’ve discussed in various blog posts, this is to be expected. Domains are highly disposable by nature and attackers plan to get through them in large numbers. They don’t need their phishing pages to live indefinitely — just as long as it takes for someone to be successfully phished.",{"data":39548,"content":39549,"nodeType":881},{},[39550],{"data":39551,"marks":39552,"value":39553,"nodeType":867},{},[],"You would expect these kinds of untrusted links to be flagged by enterprise security tools, but through clever use of obfuscation methods such as using legitimate apps to host the phishing link, using an initially benign link to a document or other source with the malicious link, or avoiding email as the delivery vector altogether, network and email-based controls are being routinely bypassed.  ",{"data":39555,"content":39559,"nodeType":890},{"target":39556},{"sys":39557},{"id":39558,"type":887,"linkType":888},"2DviJNOMbKgbcqwkNl0LDP",[],{"data":39561,"content":39562,"nodeType":998},{},[39563],{"data":39564,"marks":39565,"value":39567,"nodeType":867},{},[39566],{"type":916},"Using custom subdomains that allow public registrations",{"data":39569,"content":39570,"nodeType":881},{},[39571],{"data":39572,"marks":39573,"value":39574,"nodeType":867},{},[],"Scattered Spider have been observed registering their malicious domains on publicly rentable subdomains such as it[.]com. This limits the information that can be gathered about the domain (for example, preventing WHOIS information from being accessed) ",{"data":39576,"content":39577,"nodeType":881},{},[39578],{"data":39579,"marks":39580,"value":39581,"nodeType":867},{},[],"This is incredibly deceptive to the user and will fool many people glancing at the link. It doesn’t look as obviously suspicious as the typical .xyz or .biz, and has the feel of a legitimate domain. As these convincing rentable subdomains start to appear online more frequently, it becomes easier for attackers to pick up convincing domain names with fewer obvious deviations from the real one, without needing to resort to special characters or other tactics that might be spotted. ",{"data":39583,"content":39584,"nodeType":881},{},[39585,39589,39597,39601,39609],{"data":39586,"marks":39587,"value":39588,"nodeType":867},{},[],"This is strikingly similar ",{"data":39590,"content":39591,"nodeType":876},{"uri":34661},[39592],{"data":39593,"marks":39594,"value":39596,"nodeType":867},{},[39595],{"type":1040},"to an attack we investigated recently",{"data":39598,"marks":39599,"value":39600,"nodeType":867},{},[],", where an attacker was using the us[.]com domain to impersonate Onfido, the digital identity platform. These malicious links were actually distributed via malicious advertising on Google, which is an increasingly popular tactic ",{"data":39602,"content":39603,"nodeType":876},{"uri":947},[39604],{"data":39605,"marks":39606,"value":39608,"nodeType":867},{},[39607],{"type":1040},"to evade email and network detection controls",{"data":39610,"marks":39611,"value":39612,"nodeType":867},{},[]," for phishing links and pages. ",{"data":39614,"content":39618,"nodeType":890},{"target":39615},{"sys":39616},{"id":39617,"type":887,"linkType":888},"34ZpjuFhaSMC6MtjThQsnK",[],{"data":39620,"content":39621,"nodeType":881},{},[39622],{"data":39623,"marks":39624,"value":39625,"nodeType":867},{},[],"This comparison is also interesting when you consider…",{"data":39627,"content":39628,"nodeType":998},{},[39629],{"data":39630,"marks":39631,"value":39633,"nodeType":867},{},[39632],{"type":916},"Using commercial AiTM toolkits like Evilginx to bypass MFA and evade detection",{"data":39635,"content":39636,"nodeType":881},{},[39637],{"data":39638,"marks":39639,"value":39640,"nodeType":867},{},[],"Scattered Spider have been observed frequently using Evilginx as their phishing kit of choice. Evilginx is a great choice for attackers looking to target non-standard web apps because it is capable of emulating a range of domains — it’s designed to be flexible and work for any page without generating a load of custom JavaScript that might stand out to security tools/analysts. See an example of Evilginx being used to phish a user below.",{"data":39642,"content":39646,"nodeType":890},{"target":39643},{"sys":39644},{"id":39645,"type":887,"linkType":888},"7IuP0mcRZJkL8YGNoZo5Dj",[],{"data":39648,"content":39649,"nodeType":881},{},[39650,39654,39663,39667,39674],{"data":39651,"marks":39652,"value":39653,"nodeType":867},{},[],"By default, Evilginx redirects any site visitor not following the correct url path or supplying the correct parameters to the YouTube video for Rick Astley’s “Never Gonna Give You Up” (aka “Rickrolling”). This behavior has been observed on Scattered Spider phishing sites. Interestingly, we also observed this in the Onfido malvertising example above, ",{"data":39655,"content":39657,"nodeType":876},{"uri":39656},"https://www.linkedin.com/feed/update/urn:li:activity:7323102794813505536?commentUrn=urn%3Ali%3Acomment%3A%28activity%3A7323102794813505536%2C7323308731813814272%29&dashCommentUrn=urn%3Ali%3Afsd_comment%3A%287323308731813814272%2Curn%3Ali%3Aactivity%3A7323102794813505536%29",[39658],{"data":39659,"marks":39660,"value":39662,"nodeType":867},{},[39661],{"type":1040},"while members of the infosec community",{"data":39664,"marks":39665,"value":39666,"nodeType":867},{},[]," are increasingly seeing phishing attacks with this behavior. (This example also features use of ",{"data":39668,"content":39669,"nodeType":876},{"uri":34888},[39670],{"data":39671,"marks":39672,"value":20604,"nodeType":867},{},[39673],{"type":1040},{"data":39675,"marks":39676,"value":39677,"nodeType":867},{},[]," to prevent analysis of the malicious link by hiding it behind a legit Microsoft app consent page, another detection evasion tactic). ",{"data":39679,"content":39680,"nodeType":998},{},[39681],{"data":39682,"marks":39683,"value":39685,"nodeType":867},{},[39684],{"type":916},"Pre-populating victim information using targeted phishing links",{"data":39687,"content":39688,"nodeType":881},{},[39689,39693,39702],{"data":39690,"marks":39691,"value":39692,"nodeType":867},{},[],"A general trend that we’re seeing in the wild, also utilized by Scattered Spider, is phishing attacks becoming increasingly targeted. This includes using redirects to legitimate apps unless specific parameters are supplied, ",{"data":39694,"content":39696,"nodeType":876},{"uri":39695},"https://www.bleepingcomputer.com/news/security/phishing-kits-now-vet-victims-in-real-time-before-stealing-credentials/",[39697],{"data":39698,"marks":39699,"value":39701,"nodeType":867},{},[39700],{"type":1040},"only loading malicious content for specific usernames",{"data":39703,"marks":39704,"value":39705,"nodeType":867},{},[]," (and redirecting to benign sites otherwise) implementing the use of one-time phishing links (essentially magic links that work once for the victim, preventing security teams or tools from accessing the page to analyse it later), and pre-populating the victim information on the page to make it feel more genuine (you would expect a website you have visited and logged into before to pre-populate some of your details, like your username/email). ",{"data":39707,"content":39708,"nodeType":881},{},[39709],{"data":39710,"marks":39711,"value":39712,"nodeType":867},{},[],"See an example of this (along with a few of the detection evasion techniques we've mentioned) below. ",{"data":39714,"content":39718,"nodeType":890},{"target":39715},{"sys":39716},{"id":39717,"type":887,"linkType":888},"1zn1G6CutY0HBkXHUIo159",[],{"data":39720,"content":39721,"nodeType":998},{},[39722],{"data":39723,"marks":39724,"value":39726,"nodeType":867},{},[39725],{"type":916},"Varying login pages to evade cloned page detections",{"data":39728,"content":39729,"nodeType":881},{},[39730,39734,39743],{"data":39731,"marks":39732,"value":39733,"nodeType":867},{},[],"Attackers are routinely using a ",{"data":39735,"content":39737,"nodeType":876},{"uri":39736},"https://pushsecurity.com/blog/how-aitm-phishing-kits-evade-detection-p2/",[39738],{"data":39739,"marks":39740,"value":39742,"nodeType":867},{},[39741],{"type":1040},"combination of visual and DOM-based obfuscation techniques",{"data":39744,"marks":39745,"value":39746,"nodeType":867},{},[]," to create convincing phishing pages that are different enough from the real page being impersonated so that detections based on cloned pages do not fire. ",{"data":39748,"content":39749,"nodeType":881},{},[39750],{"data":39751,"marks":39752,"value":39753,"nodeType":867},{},[],"While Okta accounts remain a key target for Scattered Spider, they are using a range of customized landing pages to target Okta accounts for various organizations at URLs like:",{"data":39755,"content":39756,"nodeType":3126},{},[39757,39767,39777,39787,39797,39807],{"data":39758,"content":39759,"nodeType":3061},{},[39760],{"data":39761,"content":39762,"nodeType":881},{},[39763],{"data":39764,"marks":39765,"value":39766,"nodeType":867},{},[],"corp-hubspot[.]com – HubSpot",{"data":39768,"content":39769,"nodeType":3061},{},[39770],{"data":39771,"content":39772,"nodeType":881},{},[39773],{"data":39774,"marks":39775,"value":39776,"nodeType":867},{},[],"morningstar-okta[.]com – Morningstar",{"data":39778,"content":39779,"nodeType":3061},{},[39780],{"data":39781,"content":39782,"nodeType":881},{},[39783],{"data":39784,"marks":39785,"value":39786,"nodeType":867},{},[],"pure-okta[.]com – Pure Storage",{"data":39788,"content":39789,"nodeType":3061},{},[39790],{"data":39791,"content":39792,"nodeType":881},{},[39793],{"data":39794,"marks":39795,"value":39796,"nodeType":867},{},[],"signin-nydig[.]com – New York Digital Investment Group",{"data":39798,"content":39799,"nodeType":3061},{},[39800],{"data":39801,"content":39802,"nodeType":881},{},[39803],{"data":39804,"marks":39805,"value":39806,"nodeType":867},{},[],"sso-instacart[.]com – Instacart",{"data":39808,"content":39809,"nodeType":3061},{},[39810],{"data":39811,"content":39812,"nodeType":881},{},[39813],{"data":39814,"marks":39815,"value":39816,"nodeType":867},{},[],"sts-vodafone[.]com – Vodafone",{"data":39818,"content":39822,"nodeType":890},{"target":39819},{"sys":39820},{"id":39821,"type":887,"linkType":888},"38EyQfvJWcqHukYq8rm8ap",[],{"data":39824,"content":39825,"nodeType":908},{},[],{"data":39827,"content":39828,"nodeType":918},{},[39829],{"data":39830,"marks":39831,"value":39833,"nodeType":867},{},[39832],{"type":916},"Defend your organization from Scattered Spider",{"data":39835,"content":39836,"nodeType":881},{},[39837],{"data":39838,"marks":39839,"value":39840,"nodeType":867},{},[],"Scattered Spider have proven to be a highly creative and adaptable threat group, using a range of identity-centric TTPs and evolving (or rather, adding to) their repertoire over time. ",{"data":39842,"content":39843,"nodeType":881},{},[39844],{"data":39845,"marks":39846,"value":39847,"nodeType":867},{},[],"Although Scattered Spider have a number of telltale actions and behaviors, like targeting and leveraging SaaS services, utilizing AiTM phishing kits like Evilginx to target IdP accounts like Okta, and deploying ransomware to cloud servers, they are able to flex their approach to take down their targets. ",{"data":39849,"content":39850,"nodeType":881},{},[39851,39855,39864,39868,39876],{"data":39852,"marks":39853,"value":39854,"nodeType":867},{},[],"Scattered Spider’s behavior demonstrates that they are extremely ",{"data":39856,"content":39858,"nodeType":876},{"uri":39857},"https://www.crowdstrike.com/en-us/resources/crowdcasts/cloud-threat-summit/",[39859],{"data":39860,"marks":39861,"value":39863,"nodeType":867},{},[39862],{"type":1040},"cloud-conscious",{"data":39865,"marks":39866,"value":39867,"nodeType":867},{},[]," (as many modern threat actors are) and are leveraging modern TTPs designed to evade traditional security controls and exploit blind-spots in enterprise security visibility. For example, by constantly rotating their phishing domains and pages, Scattered Spider (and many threat actors like them) are routinely evading common phishing detection controls, taking advantage of the limitations of ",{"data":39869,"content":39870,"nodeType":876},{"uri":947},[39871],{"data":39872,"marks":39873,"value":39875,"nodeType":867},{},[39874],{"type":1040},"blocklist-driven approaches to phishing detection",{"data":39877,"marks":39878,"value":10110,"nodeType":867},{},[],{"data":39880,"content":39881,"nodeType":908},{},[],{"data":39883,"content":39884,"nodeType":918},{},[39885],{"data":39886,"marks":39887,"value":39889,"nodeType":867},{},[39888],{"type":916},"Aligning Push Security’s capabilities against Scattered Spider’s TTPs",{"data":39891,"content":39892,"nodeType":881},{},[39893],{"data":39894,"marks":39895,"value":39897,"nodeType":867},{},[39896],{"type":916},"Push provides a multi-layered set of detections and controls for defending against the TTPs known to be used by Scattered Spider. ",{"data":39899,"content":39903,"nodeType":890},{"target":39900},{"sys":39901},{"id":39902,"type":887,"linkType":888},"6aB3mLLXZIhrlyuCx2hOzY",[],{"data":39905,"content":39906,"nodeType":998},{},[39907],{"data":39908,"marks":39909,"value":39910,"nodeType":867},{},[],"Detect and block AiTM phishing toolkits",{"data":39912,"content":39913,"nodeType":881},{},[39914],{"data":39915,"marks":39916,"value":39918,"nodeType":867},{},[39917],{"type":916},"The Push browser agent will detect when employees visit websites running MFA-bypassing phishing toolkits such as Evilginx. ",{"data":39920,"content":39924,"nodeType":890},{"target":39921},{"sys":39922},{"id":39923,"type":887,"linkType":888},"I19TQYItDFlaOgisrST6P",[],{"data":39926,"content":39927,"nodeType":881},{},[39928],{"data":39929,"marks":39930,"value":39931,"nodeType":867},{},[],"The Push browser agent analyzes the behavioral attributes of phishing tools, e.g. “something the toolkit does” vs. just a static signature like a URL path or domain.",{"data":39933,"content":39934,"nodeType":881},{},[39935],{"data":39936,"marks":39937,"value":39938,"nodeType":867},{},[],"Based on your configuration, Push can then warn or block employees from accessing those phishing sites using a customisable blocking page or banner.",{"data":39940,"content":39944,"nodeType":890},{"target":39941},{"sys":39942},{"id":39943,"type":887,"linkType":888},"4ixcEsEW4EyqckOTmP5Pbb",[],{"data":39946,"content":39947,"nodeType":998},{},[39948],{"data":39949,"marks":39950,"value":39951,"nodeType":867},{},[],"Detect cloned login pages",{"data":39953,"content":39954,"nodeType":881},{},[39955],{"data":39956,"marks":39957,"value":39959,"nodeType":867},{},[39958],{"type":916},"The Push browser agent will detect when employees visit websites using cloned login screens to steal credentials - i.e. a cloned Okta login page.",{"data":39961,"content":39962,"nodeType":881},{},[39963],{"data":39964,"marks":39965,"value":39966,"nodeType":867},{},[],"Push does this by fingerprinting the page structure and resources of your legitimate login pages and monitoring for pages that are very similar.",{"data":39968,"content":39969,"nodeType":881},{},[39970],{"data":39971,"marks":39972,"value":39973,"nodeType":867},{},[],"Push will then emit a webhook event when it detects that an employee has visited a page that appears to be a clone of a legitimate login page.",{"data":39975,"content":39976,"nodeType":998},{},[39977],{"data":39978,"marks":39979,"value":39980,"nodeType":867},{},[],"Pin your sensitive passwords to specific sites",{"data":39982,"content":39983,"nodeType":881},{},[39984,39989,39995],{"data":39985,"marks":39986,"value":39988,"nodeType":867},{},[39987],{"type":916},"The Push browser agent will detect when employees attempt to enter their IdP password (such as Okta) into webpages that ",{"data":39990,"marks":39991,"value":39994,"nodeType":867},{},[39992,39993],{"type":1040},{"type":916},"do not",{"data":39996,"marks":39997,"value":39999,"nodeType":867},{},[39998],{"type":916}," belong to that IdP.",{"data":40001,"content":40002,"nodeType":881},{},[40003,40007,40016],{"data":40004,"marks":40005,"value":40006,"nodeType":867},{},[],"When observing logins, the Push browser agent generates a salted partial hash of the user’s password, known as a fingerprint. This fingerprint is then stored locally in the browser to allow Push to perform password comparisons. You can read more about how the extension securely observes passwords in this ",{"data":40008,"content":40010,"nodeType":876},{"uri":40009},"https://pushsecurity.com/help/10065/#start",[40011],{"data":40012,"marks":40013,"value":40015,"nodeType":867},{},[40014],{"type":1040},"help article",{"data":40017,"marks":40018,"value":1947,"nodeType":867},{},[],{"data":40020,"content":40021,"nodeType":881},{},[40022],{"data":40023,"marks":40024,"value":40025,"nodeType":867},{},[],"To detect phishing attempts against Okta (and other identity providers), the Push browser agent compares the observed Okta password fingerprint to the known Okta fingerprint that already exists in local storage.",{"data":40027,"content":40028,"nodeType":881},{},[40029],{"data":40030,"marks":40031,"value":40032,"nodeType":867},{},[],"If an employee has entered their valid Okta password on a webpage that does not belong to Okta — i.e. a phishing page — Push will enforce the SSO password protection settings set by an administrator (block or warn). This serves as a second layer of defense when used in conjunction with AiTM and cloned login page detections. ",{"data":40034,"content":40038,"nodeType":890},{"target":40035},{"sys":40036},{"id":40037,"type":887,"linkType":888},"20FIoIyuQYxep3V4SFWdoK",[],{"data":40040,"content":40041,"nodeType":998},{},[40042],{"data":40043,"marks":40044,"value":40045,"nodeType":867},{},[],"Detect compromised sessions",{"data":40047,"content":40048,"nodeType":881},{},[40049],{"data":40050,"marks":40051,"value":40053,"nodeType":867},{},[40052],{"type":916},"By correlating Push telemetry with Okta logs, Push can detect compromised Okta sessions originating from outside employees’ supported browsers. ",{"data":40055,"content":40056,"nodeType":881},{},[40057],{"data":40058,"marks":40059,"value":40060,"nodeType":867},{},[],"Using the Push browser agent, you can inject a unique marker into the User Agent string of Okta sessions that occur in browsers enrolled in Push.",{"data":40062,"content":40063,"nodeType":881},{},[40064],{"data":40065,"marks":40066,"value":40067,"nodeType":867},{},[],"By then comparing against Okta logs, you can identify sessions that both have the Push marker and those that lack the marker, the latter indicating the session is being used from a machine without the Push extension and therefore the session token may have been stolen.",{"data":40069,"content":40073,"nodeType":890},{"target":40070},{"sys":40071},{"id":40072,"type":887,"linkType":888},"1XNNkaoW64t3PPvC54KGXF",[],{"data":40075,"content":40076,"nodeType":998},{},[40077],{"data":40078,"marks":40079,"value":40080,"nodeType":867},{},[],"Detect when employee credentials are stolen",{"data":40082,"content":40083,"nodeType":881},{},[40084],{"data":40085,"marks":40086,"value":40088,"nodeType":867},{},[40087],{"type":916},"Push will detect when valid credentials appear for sale on criminal forums. ",{"data":40090,"content":40091,"nodeType":881},{},[40092],{"data":40093,"marks":40094,"value":40095,"nodeType":867},{},[],"The Push platform detects valid, stolen credentials on criminal forums by ingesting threat intelligence data and then verifying which credentials flagged by TI sources are still being used by employees.",{"data":40097,"content":40098,"nodeType":881},{},[40099],{"data":40100,"marks":40101,"value":40102,"nodeType":867},{},[],"When suspected stolen credentials for the corporate domain are present, Push hashes and salts the passwords and then sends those fingerprints to the relevant browser agents for comparison. If the stolen credential fingerprint matches a known credential fingerprint observed to be in use by the Push browser agent, the platform returns a validated true positive alert.",{"data":40104,"content":40105,"nodeType":881},{},[40106],{"data":40107,"marks":40108,"value":40109,"nodeType":867},{},[],"You can choose to receive alerts for this detection via webhook, ChatOps notification, or in the Push admin console.",{"data":40111,"content":40115,"nodeType":890},{"target":40112},{"sys":40113},{"id":40114,"type":887,"linkType":888},"6wfLCTzvHeMzagyuEWGyJg",[],{"data":40117,"content":40118,"nodeType":998},{},[40119],{"data":40120,"marks":40121,"value":40122,"nodeType":867},{},[],"Map login methods and remove ghost logins",{"data":40124,"content":40125,"nodeType":881},{},[40126],{"data":40127,"marks":40128,"value":40130,"nodeType":867},{},[40129],{"type":916},"Push maps all the identities used by employees to access workforce apps, including local, non-Okta identities. This data can be used to migrate more apps and accounts to Okta SSO and reduce the overall identity attack surface. ",{"data":40132,"content":40133,"nodeType":881},{},[40134],{"data":40135,"marks":40136,"value":40137,"nodeType":867},{},[],"The Push browser agent observes employees using their corporate identities to access work applications. Push customers gain accurate visibility across all Okta and non-Okta identities, the employees that are using them, the apps they are accessing and the authentication methods being used. ",{"data":40139,"content":40140,"nodeType":881},{},[40141,40145,40152],{"data":40142,"marks":40143,"value":40144,"nodeType":867},{},[],"Armed with this data, security teams can get more workforce apps and accounts behind SSO to reduce the overall identity attack surface, while removing any ",{"data":40146,"content":40147,"nodeType":876},{"uri":6845},[40148],{"data":40149,"marks":40150,"value":6850,"nodeType":867},{},[40151],{"type":1040},{"data":40153,"marks":40154,"value":40155,"nodeType":867},{},[]," that enable attackers to circumvent MFA by logging in directly to the app/page. ",{"data":40157,"content":40161,"nodeType":890},{"target":40158},{"sys":40159},{"id":40160,"type":887,"linkType":888},"dbDM075qSd4P3wnXuXX2Z",[],{"data":40163,"content":40164,"nodeType":998},{},[40165],{"data":40166,"marks":40167,"value":40168,"nodeType":867},{},[],"Verify help desk caller identities with in-browser verification codes",{"data":40170,"content":40171,"nodeType":881},{},[40172,40175,40183],{"data":40173,"marks":40174,"value":15780,"nodeType":867},{},[],{"data":40176,"content":40177,"nodeType":876},{"uri":15783},[40178],{"data":40179,"marks":40180,"value":15790,"nodeType":867},{},[40181,40182],{"type":1040},{"type":916},{"data":40184,"marks":40185,"value":15794,"nodeType":867},{},[],{"data":40187,"content":40190,"nodeType":890},{"target":40188},{"sys":40189},{"id":15799,"type":887,"linkType":888},[],{"data":40192,"content":40193,"nodeType":881},{},[40194],{"data":40195,"marks":40196,"value":15807,"nodeType":867},{},[],{"data":40198,"content":40199,"nodeType":881},{},[40200,40203,40210],{"data":40201,"marks":40202,"value":15824,"nodeType":867},{},[],{"data":40204,"content":40205,"nodeType":876},{"uri":15827},[40206],{"data":40207,"marks":40208,"value":15833,"nodeType":867},{},[40209],{"type":1040},{"data":40211,"marks":40212,"value":15837,"nodeType":867},{},[],{"data":40214,"content":40217,"nodeType":890},{"target":40215},{"sys":40216},{"id":15859,"type":887,"linkType":888},[],{"data":40219,"content":40220,"nodeType":908},{},[],{"data":40222,"content":40223,"nodeType":918},{},[40224],{"data":40225,"marks":40226,"value":4330,"nodeType":867},{},[40227],{"type":916},{"data":40229,"content":40230,"nodeType":881},{},[40231],{"data":40232,"marks":40233,"value":40234,"nodeType":867},{},[],"It doesn’t stop there — Push provides comprehensive identity attack detection and response capabilities against techniques like credential stuffing, password spraying and session hijacking using stolen session tokens. You can also use Push to find and fix identity vulnerabilities across every app that your employees use like: ghost logins; SSO coverage gaps; MFA gaps; weak, breached and reused passwords; risky OAuth integrations; and more. ",{"data":40236,"content":40237,"nodeType":881},{},[40238,40241,40248],{"data":40239,"marks":40240,"value":34977,"nodeType":867},{},[],{"data":40242,"content":40244,"nodeType":876},{"uri":40243},"https://pushsecurity.com/demo?utm_campaign=12081956-FY25Q2_Hacker-News-Article&utm_source=thehackernews&utm_medium=sponsored&utm_content=external-article",[40245],{"data":40246,"marks":40247,"value":10826,"nodeType":867},{},[],{"data":40249,"marks":40250,"value":1947,"nodeType":867},{},[],"How the notorious Scattered Spider cyber criminal group are switching up their TTPs in 2025 to bypass MFA and breach cloud services via account takeover.","2025-05-06T00:00:00.000Z",{"items":40254},[40255,40257],{"sys":40256,"name":2547},{"id":2546},{"sys":40258,"name":342},{"id":2550},{"items":40260},[40261],{"fullName":849,"firstName":850,"jobTitle":851,"profilePicture":40262},{"url":855},"blog/scattered-spider-defending-against-help-desk-scams",{"json":40265},{"data":40266,"content":40267,"nodeType":1640},{},[40268],{"data":40269,"content":40270,"nodeType":881},{},[40271],{"data":40272,"marks":40273,"value":40274,"nodeType":867},{},[],"Scattered Spider has dominated the headlines in recent months and has gained significant attention for its use of help desk scams. Here's how they work and what you can do to protect your organization. ",{"id":15240,"publishedAt":40276},"2026-08-12T11:54:03.755Z",{"items":40278},[40279,40281],{"sys":40280,"name":2547},{"id":2546},{"sys":40282,"name":342},{"id":2550},{"items":40284},[40285,40287,40289,40291,40293,40295,40297,40299,40301,40303,40305,40307,40309,40311,40313],{"sys":40286,"name":279,"slug":280,"tier":31},{"id":276},{"sys":40288,"name":413,"slug":414,"tier":31},{"id":410},{"sys":40290,"name":519,"slug":520,"tier":31},{"id":516},{"sys":40292,"name":642,"slug":643,"tier":31},{"id":639},{"sys":40294,"name":342,"slug":343,"tier":31},{"id":339},{"sys":40296,"name":650,"slug":651,"tier":45},{"id":647},{"sys":40298,"name":607,"slug":608,"tier":45},{"id":604},{"sys":40300,"name":466,"slug":467,"tier":45},{"id":463},{"sys":40302,"name":261,"slug":262,"tier":45},{"id":258},{"sys":40304,"name":324,"slug":325,"tier":45},{"id":321},{"sys":40306,"name":404,"slug":405,"tier":45},{"id":401},{"sys":40308,"name":571,"slug":572,"tier":45},{"id":568},{"sys":40310,"name":457,"slug":458,"tier":45},{"id":454},{"sys":40312,"name":537,"slug":538,"tier":45},{"id":534},{"sys":40314,"name":502,"slug":503,"tier":45},{"id":499},"yjH55ZXCaQvQjWDumXOTsjiEZ1Fw112-VkrcDK6-4V0",{"id":40317,"title":29803,"authorsCollection":40318,"content":40324,"extension":228,"faqItemsCollection":40681,"faqTitle":59,"featured":6,"hashTags":59,"meta":40683,"metaTitle":40684,"ogImage":59,"postType":29885,"publishedDate":36772,"relatedBlogPostsCollection":40685,"slug":29804,"stem":43525,"subtitle":59,"summary":43526,"synopsis":36771,"sys":43537,"tagsCollection":43539,"topicsCollection":43543,"__hash__":43559},"blog/blog/employee-identity-verification-codes-release.json",{"items":40319},[40320],{"fullName":36780,"firstName":36781,"jobTitle":4374,"socialLinks":40321,"profilePicture":40323},[40322],"https://www.linkedin.com/in/alexhenshall/",{"url":36783},{"json":40325,"links":40619},{"data":40326,"content":40327,"nodeType":1640},{},[40328,40334,40340,40346,40351,40357,40387,40393,40399,40405,40410,40416,40422,40437,40442,40448,40464,40480,40486,40492,40498,40504,40510,40516,40522,40538,40544,40550,40555,40561,40567,40587,40592,40608,40613],{"data":40329,"content":40330,"nodeType":881},{},[40331],{"data":40332,"marks":40333,"value":36437,"nodeType":867},{},[],{"data":40335,"content":40336,"nodeType":881},{},[40337],{"data":40338,"marks":40339,"value":36444,"nodeType":867},{},[],{"data":40341,"content":40342,"nodeType":881},{},[40343],{"data":40344,"marks":40345,"value":36451,"nodeType":867},{},[],{"data":40347,"content":40350,"nodeType":890},{"target":40348},{"sys":40349},{"id":36456,"type":887,"linkType":888},[],{"data":40352,"content":40353,"nodeType":881},{},[40354],{"data":40355,"marks":40356,"value":36464,"nodeType":867},{},[],{"data":40358,"content":40359,"nodeType":3126},{},[40360,40369,40378],{"data":40361,"content":40362,"nodeType":3061},{},[40363],{"data":40364,"content":40365,"nodeType":881},{},[40366],{"data":40367,"marks":40368,"value":36477,"nodeType":867},{},[],{"data":40370,"content":40371,"nodeType":3061},{},[40372],{"data":40373,"content":40374,"nodeType":881},{},[40375],{"data":40376,"marks":40377,"value":36487,"nodeType":867},{},[],{"data":40379,"content":40380,"nodeType":3061},{},[40381],{"data":40382,"content":40383,"nodeType":881},{},[40384],{"data":40385,"marks":40386,"value":36497,"nodeType":867},{},[],{"data":40388,"content":40389,"nodeType":881},{},[40390],{"data":40391,"marks":40392,"value":36504,"nodeType":867},{},[],{"data":40394,"content":40395,"nodeType":918},{},[40396],{"data":40397,"marks":40398,"value":36511,"nodeType":867},{},[],{"data":40400,"content":40401,"nodeType":881},{},[40402],{"data":40403,"marks":40404,"value":36518,"nodeType":867},{},[],{"data":40406,"content":40409,"nodeType":890},{"target":40407},{"sys":40408},{"id":36523,"type":887,"linkType":888},[],{"data":40411,"content":40412,"nodeType":881},{},[40413],{"data":40414,"marks":40415,"value":36531,"nodeType":867},{},[],{"data":40417,"content":40418,"nodeType":918},{},[40419],{"data":40420,"marks":40421,"value":36538,"nodeType":867},{},[],{"data":40423,"content":40424,"nodeType":881},{},[40425,40428,40434],{"data":40426,"marks":40427,"value":36545,"nodeType":867},{},[],{"data":40429,"content":40430,"nodeType":876},{"uri":15633},[40431],{"data":40432,"marks":40433,"value":36552,"nodeType":867},{},[],{"data":40435,"marks":40436,"value":36556,"nodeType":867},{},[],{"data":40438,"content":40441,"nodeType":890},{"target":40439},{"sys":40440},{"id":15742,"type":887,"linkType":888},[],{"data":40443,"content":40444,"nodeType":998},{},[40445],{"data":40446,"marks":40447,"value":36568,"nodeType":867},{},[],{"data":40449,"content":40450,"nodeType":881},{},[40451,40454,40461],{"data":40452,"marks":40453,"value":36575,"nodeType":867},{},[],{"data":40455,"content":40456,"nodeType":876},{"uri":36578},[40457],{"data":40458,"marks":40459,"value":36584,"nodeType":867},{},[40460],{"type":1040},{"data":40462,"marks":40463,"value":36588,"nodeType":867},{},[],{"data":40465,"content":40466,"nodeType":881},{},[40467,40470,40477],{"data":40468,"marks":40469,"value":36595,"nodeType":867},{},[],{"data":40471,"content":40472,"nodeType":876},{"uri":14743},[40473],{"data":40474,"marks":40475,"value":14749,"nodeType":867},{},[40476],{"type":1040},{"data":40478,"marks":40479,"value":36606,"nodeType":867},{},[],{"data":40481,"content":40482,"nodeType":881},{},[40483],{"data":40484,"marks":40485,"value":36613,"nodeType":867},{},[],{"data":40487,"content":40488,"nodeType":881},{},[40489],{"data":40490,"marks":40491,"value":36620,"nodeType":867},{},[],{"data":40493,"content":40494,"nodeType":998},{},[40495],{"data":40496,"marks":40497,"value":36627,"nodeType":867},{},[],{"data":40499,"content":40500,"nodeType":881},{},[40501],{"data":40502,"marks":40503,"value":36634,"nodeType":867},{},[],{"data":40505,"content":40506,"nodeType":881},{},[40507],{"data":40508,"marks":40509,"value":36641,"nodeType":867},{},[],{"data":40511,"content":40512,"nodeType":918},{},[40513],{"data":40514,"marks":40515,"value":36648,"nodeType":867},{},[],{"data":40517,"content":40518,"nodeType":881},{},[40519],{"data":40520,"marks":40521,"value":36655,"nodeType":867},{},[],{"data":40523,"content":40524,"nodeType":881},{},[40525,40528,40535],{"data":40526,"marks":40527,"value":36662,"nodeType":867},{},[],{"data":40529,"content":40530,"nodeType":876},{"uri":36665},[40531],{"data":40532,"marks":40533,"value":36671,"nodeType":867},{},[40534],{"type":1040},{"data":40536,"marks":40537,"value":36675,"nodeType":867},{},[],{"data":40539,"content":40540,"nodeType":881},{},[40541],{"data":40542,"marks":40543,"value":36682,"nodeType":867},{},[],{"data":40545,"content":40546,"nodeType":881},{},[40547],{"data":40548,"marks":40549,"value":36689,"nodeType":867},{},[],{"data":40551,"content":40554,"nodeType":890},{"target":40552},{"sys":40553},{"id":36694,"type":887,"linkType":888},[],{"data":40556,"content":40557,"nodeType":918},{},[40558],{"data":40559,"marks":40560,"value":15817,"nodeType":867},{},[],{"data":40562,"content":40563,"nodeType":881},{},[40564],{"data":40565,"marks":40566,"value":36708,"nodeType":867},{},[],{"data":40568,"content":40569,"nodeType":881},{},[40570,40573,40577,40580,40584],{"data":40571,"marks":40572,"value":36715,"nodeType":867},{},[],{"data":40574,"marks":40575,"value":36720,"nodeType":867},{},[40576],{"type":916},{"data":40578,"marks":40579,"value":36724,"nodeType":867},{},[],{"data":40581,"marks":40582,"value":36729,"nodeType":867},{},[40583],{"type":916},{"data":40585,"marks":40586,"value":36733,"nodeType":867},{},[],{"data":40588,"content":40591,"nodeType":890},{"target":40589},{"sys":40590},{"id":36738,"type":887,"linkType":888},[],{"data":40593,"content":40594,"nodeType":881},{},[40595,40598,40605],{"data":40596,"marks":40597,"value":36746,"nodeType":867},{},[],{"data":40599,"content":40600,"nodeType":876},{"uri":2362},[40601],{"data":40602,"marks":40603,"value":36754,"nodeType":867},{},[40604],{"type":1040},{"data":40606,"marks":40607,"value":36758,"nodeType":867},{},[],{"data":40609,"content":40612,"nodeType":890},{"target":40610},{"sys":40611},{"id":36763,"type":887,"linkType":888},[],{"data":40614,"content":40615,"nodeType":881},{},[40616],{"data":40617,"marks":40618,"value":21,"nodeType":867},{},[],{"entries":40620},{"hyperlink":40621,"inline":40622,"block":40623},[],[],[40624,40630,40637,40639,40647,40677],{"sys":40625,"__typename":1648,"title":40626,"caption":59,"layoutMode":40627,"file":40628},{"id":36456},"Screenshot of an employee verification code seen in the browser ","Centre aligned",{"url":40629,"width":29879,"height":29880},"https://images.ctfassets.net/y1cdw1ablpvd/6NN7y6uMvJZimdyX7iXI0Z/23ce9794d9508f5b7706ef8e5e928189/employee_verification_code_annotated.png",{"sys":40631,"__typename":1648,"title":40632,"caption":59,"layoutMode":59,"file":40633},{"id":36523},"Eric from GitLab's quote about Push Security's Employee Identity Verification Code feature",{"url":40634,"width":40635,"height":40636},"https://images.ctfassets.net/y1cdw1ablpvd/5n0gGVgLPdwYutOsrVhPCm/504144852029af2b59e0c2abc336b2bf/Group_544__1_.png",7204,3100,{"sys":40638,"__typename":22749,"type":22750,"ctaText":35817,"buttonLabel":35818,"buttonColour":22753,"buttonUrl":35819},{"id":15742},{"sys":40640,"__typename":1648,"title":40641,"caption":40642,"layoutMode":40627,"file":40643},{"id":36694},"Push's control coverage across a typical Scattered Spider attack chain","Coverage of Push’s controls across a typical Scattered Spider attack chain",{"url":40644,"width":40645,"height":40646},"https://images.ctfassets.net/y1cdw1ablpvd/1nmpSqVCUUa3FY6Vc74zh9/07e800d974017def0c35d54caa02f1a3/Screenshot_2025-06-19_at_10.29.48.png",1264,710,{"sys":40648,"__typename":1696,"content":40649,"name":40676,"title":59},{"id":36738},{"json":40650},{"nodeType":1640,"data":40651,"content":40652},{},[40653,40660],{"nodeType":881,"data":40654,"content":40655},{},[40656],{"nodeType":867,"value":40657,"marks":40658,"data":40659},"We're also offering this feature as a free tool for security teams that aren't currently Push customers, but want to start using this browser-based verification code as part of their help desk caller identification process. ",[],{},{"nodeType":881,"data":40661,"content":40662},{},[40663,40666,40673],{"nodeType":867,"value":21,"marks":40664,"data":40665},[],{},{"nodeType":876,"data":40667,"content":40668},{"uri":15827},[40669],{"nodeType":867,"value":40670,"marks":40671,"data":40672},"Find out more here. ",[],{},{"nodeType":867,"value":21,"marks":40674,"data":40675},[],{},"Verification codes insight box 1",{"sys":40678,"__typename":22749,"type":40679,"ctaText":40680,"buttonLabel":37384,"buttonColour":22753,"buttonUrl":2362},{"id":36763},"Demo","Want to find out how else Push can stop identity attacks in the browser?",{"items":40682},[],{},"Introducing the Employee Identity Verification Code feature",{"items":40686},[40687,41858,42519],{"__typename":1742,"sys":40688,"content":40689,"title":29799,"synopsis":40251,"hashTags":59,"publishedDate":40252,"slug":29800,"tagsCollection":41848,"authorsCollection":41854},{"id":27581},{"json":40690},{"data":40691,"content":40692,"nodeType":1640},{},[40693,40698,40705,40711,40737,40742,40749,40775,40809,40814,40821,40836,40841,40844,40851,40857,40862,40898,41028,41031,41038,41044,41051,41077,41082,41089,41105,41111,41116,41122,41127,41143,41150,41166,41173,41179,41185,41188,41195,41201,41206,41212,41219,41235,41241,41246,41253,41259,41265,41291,41296,41302,41309,41315,41320,41346,41353,41369,41375,41380,41387,41403,41409,41466,41471,41474,41481,41487,41493,41519,41522,41529,41536,41541,41547,41554,41559,41565,41571,41576,41582,41589,41595,41601,41607,41623,41639,41645,41651,41656,41662,41669,41675,41681,41686,41692,41699,41705,41711,41717,41722,41728,41735,41741,41757,41762,41768,41785,41790,41796,41812,41817,41820,41827,41833],{"data":40694,"content":40697,"nodeType":890},{"target":40695},{"sys":40696},{"id":15249,"type":887,"linkType":888},[],{"data":40699,"content":40700,"nodeType":918},{},[40701],{"data":40702,"marks":40703,"value":38951,"nodeType":867},{},[40704],{"type":916},{"data":40706,"content":40707,"nodeType":881},{},[40708],{"data":40709,"marks":40710,"value":38958,"nodeType":867},{},[],{"data":40712,"content":40713,"nodeType":881},{},[40714,40717,40724,40727,40734],{"data":40715,"marks":40716,"value":38965,"nodeType":867},{},[],{"data":40718,"content":40719,"nodeType":876},{"uri":35499},[40720],{"data":40721,"marks":40722,"value":35505,"nodeType":867},{},[40723],{"type":1040},{"data":40725,"marks":40726,"value":15362,"nodeType":867},{},[],{"data":40728,"content":40729,"nodeType":876},{"uri":14576},[40730],{"data":40731,"marks":40732,"value":8186,"nodeType":867},{},[40733],{"type":1040},{"data":40735,"marks":40736,"value":38986,"nodeType":867},{},[],{"data":40738,"content":40741,"nodeType":890},{"target":40739},{"sys":40740},{"id":38991,"type":887,"linkType":888},[],{"data":40743,"content":40744,"nodeType":998},{},[40745],{"data":40746,"marks":40747,"value":39000,"nodeType":867},{},[40748],{"type":916},{"data":40750,"content":40751,"nodeType":881},{},[40752,40755,40762,40765,40772],{"data":40753,"marks":40754,"value":39007,"nodeType":867},{},[],{"data":40756,"content":40757,"nodeType":876},{"uri":36578},[40758],{"data":40759,"marks":40760,"value":36584,"nodeType":867},{},[40761],{"type":1040},{"data":40763,"marks":40764,"value":39018,"nodeType":867},{},[],{"data":40766,"content":40767,"nodeType":876},{"uri":14743},[40768],{"data":40769,"marks":40770,"value":14749,"nodeType":867},{},[40771],{"type":1040},{"data":40773,"marks":40774,"value":39029,"nodeType":867},{},[],{"data":40776,"content":40777,"nodeType":881},{},[40778,40781,40785,40788,40792,40795,40799,40802,40806],{"data":40779,"marks":40780,"value":39036,"nodeType":867},{},[],{"data":40782,"marks":40783,"value":39041,"nodeType":867},{},[40784],{"type":916},{"data":40786,"marks":40787,"value":39045,"nodeType":867},{},[],{"data":40789,"marks":40790,"value":39050,"nodeType":867},{},[40791],{"type":916},{"data":40793,"marks":40794,"value":39054,"nodeType":867},{},[],{"data":40796,"marks":40797,"value":39059,"nodeType":867},{},[40798],{"type":916},{"data":40800,"marks":40801,"value":39063,"nodeType":867},{},[],{"data":40803,"marks":40804,"value":39068,"nodeType":867},{},[40805],{"type":916},{"data":40807,"marks":40808,"value":10110,"nodeType":867},{},[],{"data":40810,"content":40813,"nodeType":890},{"target":40811},{"sys":40812},{"id":39076,"type":887,"linkType":888},[],{"data":40815,"content":40816,"nodeType":998},{},[40817],{"data":40818,"marks":40819,"value":39085,"nodeType":867},{},[40820],{"type":916},{"data":40822,"content":40823,"nodeType":881},{},[40824,40827,40833],{"data":40825,"marks":40826,"value":39092,"nodeType":867},{},[],{"data":40828,"content":40829,"nodeType":876},{"uri":14576},[40830],{"data":40831,"marks":40832,"value":39099,"nodeType":867},{},[],{"data":40834,"marks":40835,"value":39103,"nodeType":867},{},[],{"data":40837,"content":40840,"nodeType":890},{"target":40838},{"sys":40839},{"id":39108,"type":887,"linkType":888},[],{"data":40842,"content":40843,"nodeType":908},{},[],{"data":40845,"content":40846,"nodeType":918},{},[40847],{"data":40848,"marks":40849,"value":39120,"nodeType":867},{},[40850],{"type":916},{"data":40852,"content":40853,"nodeType":881},{},[40854],{"data":40855,"marks":40856,"value":39127,"nodeType":867},{},[],{"data":40858,"content":40861,"nodeType":890},{"target":40859},{"sys":40860},{"id":39132,"type":887,"linkType":888},[],{"data":40863,"content":40864,"nodeType":881},{},[40865,40868,40875,40878,40885,40888,40895],{"data":40866,"marks":40867,"value":39140,"nodeType":867},{},[],{"data":40869,"content":40870,"nodeType":876},{"uri":39143},[40871],{"data":40872,"marks":40873,"value":15266,"nodeType":867},{},[40874],{"type":1040},{"data":40876,"marks":40877,"value":4006,"nodeType":867},{},[],{"data":40879,"content":40880,"nodeType":876},{"uri":15272},[40881],{"data":40882,"marks":40883,"value":15278,"nodeType":867},{},[40884],{"type":1040},{"data":40886,"marks":40887,"value":15362,"nodeType":867},{},[],{"data":40889,"content":40890,"nodeType":876},{"uri":39164},[40891],{"data":40892,"marks":40893,"value":39170,"nodeType":867},{},[40894],{"type":1040},{"data":40896,"marks":40897,"value":39174,"nodeType":867},{},[],{"data":40899,"content":40900,"nodeType":881},{},[40901,40904,40911,40914,40921,40924,40931,40934,40941,40944,40951,40954,40961,40964,40971,40974,40980,40983,40989,40992,40998,41001,41007,41010,41016,41019,41025],{"data":40902,"marks":40903,"value":15289,"nodeType":867},{},[],{"data":40905,"content":40906,"nodeType":876},{"uri":15292},[40907],{"data":40908,"marks":40909,"value":15298,"nodeType":867},{},[40910],{"type":1040},{"data":40912,"marks":40913,"value":4006,"nodeType":867},{},[],{"data":40915,"content":40916,"nodeType":876},{"uri":15304},[40917],{"data":40918,"marks":40919,"value":15310,"nodeType":867},{},[40920],{"type":1040},{"data":40922,"marks":40923,"value":4006,"nodeType":867},{},[],{"data":40925,"content":40926,"nodeType":876},{"uri":15316},[40927],{"data":40928,"marks":40929,"value":15322,"nodeType":867},{},[40930],{"type":1040},{"data":40932,"marks":40933,"value":4006,"nodeType":867},{},[],{"data":40935,"content":40936,"nodeType":876},{"uri":15328},[40937],{"data":40938,"marks":40939,"value":15334,"nodeType":867},{},[40940],{"type":1040},{"data":40942,"marks":40943,"value":4006,"nodeType":867},{},[],{"data":40945,"content":40946,"nodeType":876},{"uri":15340},[40947],{"data":40948,"marks":40949,"value":15346,"nodeType":867},{},[40950],{"type":1040},{"data":40952,"marks":40953,"value":4006,"nodeType":867},{},[],{"data":40955,"content":40956,"nodeType":876},{"uri":15352},[40957],{"data":40958,"marks":40959,"value":15358,"nodeType":867},{},[40960],{"type":1040},{"data":40962,"marks":40963,"value":15362,"nodeType":867},{},[],{"data":40965,"content":40966,"nodeType":876},{"uri":15365},[40967],{"data":40968,"marks":40969,"value":15371,"nodeType":867},{},[40970],{"type":1040},{"data":40972,"marks":40973,"value":39251,"nodeType":867},{},[],{"data":40975,"content":40976,"nodeType":876},{"uri":15385},[40977],{"data":40978,"marks":40979,"value":15391,"nodeType":867},{},[],{"data":40981,"marks":40982,"value":4006,"nodeType":867},{},[],{"data":40984,"content":40985,"nodeType":876},{"uri":15397},[40986],{"data":40987,"marks":40988,"value":15403,"nodeType":867},{},[],{"data":40990,"marks":40991,"value":4006,"nodeType":867},{},[],{"data":40993,"content":40994,"nodeType":876},{"uri":15410},[40995],{"data":40996,"marks":40997,"value":15416,"nodeType":867},{},[],{"data":40999,"marks":41000,"value":4006,"nodeType":867},{},[],{"data":41002,"content":41003,"nodeType":876},{"uri":15434},[41004],{"data":41005,"marks":41006,"value":15439,"nodeType":867},{},[],{"data":41008,"marks":41009,"value":4006,"nodeType":867},{},[],{"data":41011,"content":41012,"nodeType":876},{"uri":15434},[41013],{"data":41014,"marks":41015,"value":15449,"nodeType":867},{},[],{"data":41017,"marks":41018,"value":15362,"nodeType":867},{},[],{"data":41020,"content":41021,"nodeType":876},{"uri":15423},[41022],{"data":41023,"marks":41024,"value":15428,"nodeType":867},{},[],{"data":41026,"marks":41027,"value":1947,"nodeType":867},{},[],{"data":41029,"content":41030,"nodeType":908},{},[],{"data":41032,"content":41033,"nodeType":918},{},[41034],{"data":41035,"marks":41036,"value":39316,"nodeType":867},{},[41037],{"type":916},{"data":41039,"content":41040,"nodeType":881},{},[41041],{"data":41042,"marks":41043,"value":39323,"nodeType":867},{},[],{"data":41045,"content":41046,"nodeType":998},{},[41047],{"data":41048,"marks":41049,"value":39331,"nodeType":867},{},[41050],{"type":916},{"data":41052,"content":41053,"nodeType":881},{},[41054,41057,41064,41067,41074],{"data":41055,"marks":41056,"value":39338,"nodeType":867},{},[],{"data":41058,"content":41059,"nodeType":876},{"uri":39341},[41060],{"data":41061,"marks":41062,"value":39347,"nodeType":867},{},[41063],{"type":1040},{"data":41065,"marks":41066,"value":2063,"nodeType":867},{},[],{"data":41068,"content":41069,"nodeType":876},{"uri":14532},[41070],{"data":41071,"marks":41072,"value":39358,"nodeType":867},{},[41073],{"type":1040},{"data":41075,"marks":41076,"value":39362,"nodeType":867},{},[],{"data":41078,"content":41081,"nodeType":890},{"target":41079},{"sys":41080},{"id":39367,"type":887,"linkType":888},[],{"data":41083,"content":41084,"nodeType":998},{},[41085],{"data":41086,"marks":41087,"value":39376,"nodeType":867},{},[41088],{"type":916},{"data":41090,"content":41091,"nodeType":881},{},[41092,41095,41102],{"data":41093,"marks":41094,"value":39383,"nodeType":867},{},[],{"data":41096,"content":41097,"nodeType":876},{"uri":39386},[41098],{"data":41099,"marks":41100,"value":39392,"nodeType":867},{},[41101],{"type":1040},{"data":41103,"marks":41104,"value":39396,"nodeType":867},{},[],{"data":41106,"content":41107,"nodeType":881},{},[41108],{"data":41109,"marks":41110,"value":39403,"nodeType":867},{},[],{"data":41112,"content":41115,"nodeType":890},{"target":41113},{"sys":41114},{"id":39408,"type":887,"linkType":888},[],{"data":41117,"content":41118,"nodeType":881},{},[41119],{"data":41120,"marks":41121,"value":39416,"nodeType":867},{},[],{"data":41123,"content":41126,"nodeType":890},{"target":41124},{"sys":41125},{"id":39421,"type":887,"linkType":888},[],{"data":41128,"content":41129,"nodeType":881},{},[41130,41133,41140],{"data":41131,"marks":41132,"value":39429,"nodeType":867},{},[],{"data":41134,"content":41135,"nodeType":876},{"uri":39432},[41136],{"data":41137,"marks":41138,"value":39438,"nodeType":867},{},[41139],{"type":1040},{"data":41141,"marks":41142,"value":10143,"nodeType":867},{},[],{"data":41144,"content":41145,"nodeType":998},{},[41146],{"data":41147,"marks":41148,"value":39449,"nodeType":867},{},[41149],{"type":916},{"data":41151,"content":41152,"nodeType":881},{},[41153,41156,41163],{"data":41154,"marks":41155,"value":39456,"nodeType":867},{},[],{"data":41157,"content":41158,"nodeType":876},{"uri":14743},[41159],{"data":41160,"marks":41161,"value":14749,"nodeType":867},{},[41162],{"type":1040},{"data":41164,"marks":41165,"value":39467,"nodeType":867},{},[],{"data":41167,"content":41168,"nodeType":998},{},[41169],{"data":41170,"marks":41171,"value":39475,"nodeType":867},{},[41172],{"type":916},{"data":41174,"content":41175,"nodeType":881},{},[41176],{"data":41177,"marks":41178,"value":39482,"nodeType":867},{},[],{"data":41180,"content":41181,"nodeType":881},{},[41182],{"data":41183,"marks":41184,"value":39489,"nodeType":867},{},[],{"data":41186,"content":41187,"nodeType":908},{},[],{"data":41189,"content":41190,"nodeType":918},{},[41191],{"data":41192,"marks":41193,"value":39500,"nodeType":867},{},[41194],{"type":916},{"data":41196,"content":41197,"nodeType":881},{},[41198],{"data":41199,"marks":41200,"value":39507,"nodeType":867},{},[],{"data":41202,"content":41205,"nodeType":890},{"target":41203},{"sys":41204},{"id":39512,"type":887,"linkType":888},[],{"data":41207,"content":41208,"nodeType":881},{},[41209],{"data":41210,"marks":41211,"value":39520,"nodeType":867},{},[],{"data":41213,"content":41214,"nodeType":998},{},[41215],{"data":41216,"marks":41217,"value":39528,"nodeType":867},{},[41218],{"type":916},{"data":41220,"content":41221,"nodeType":881},{},[41222,41225,41232],{"data":41223,"marks":41224,"value":21,"nodeType":867},{},[],{"data":41226,"content":41227,"nodeType":876},{"uri":39432},[41228],{"data":41229,"marks":41230,"value":39542,"nodeType":867},{},[41231],{"type":1040},{"data":41233,"marks":41234,"value":39546,"nodeType":867},{},[],{"data":41236,"content":41237,"nodeType":881},{},[41238],{"data":41239,"marks":41240,"value":39553,"nodeType":867},{},[],{"data":41242,"content":41245,"nodeType":890},{"target":41243},{"sys":41244},{"id":39558,"type":887,"linkType":888},[],{"data":41247,"content":41248,"nodeType":998},{},[41249],{"data":41250,"marks":41251,"value":39567,"nodeType":867},{},[41252],{"type":916},{"data":41254,"content":41255,"nodeType":881},{},[41256],{"data":41257,"marks":41258,"value":39574,"nodeType":867},{},[],{"data":41260,"content":41261,"nodeType":881},{},[41262],{"data":41263,"marks":41264,"value":39581,"nodeType":867},{},[],{"data":41266,"content":41267,"nodeType":881},{},[41268,41271,41278,41281,41288],{"data":41269,"marks":41270,"value":39588,"nodeType":867},{},[],{"data":41272,"content":41273,"nodeType":876},{"uri":34661},[41274],{"data":41275,"marks":41276,"value":39596,"nodeType":867},{},[41277],{"type":1040},{"data":41279,"marks":41280,"value":39600,"nodeType":867},{},[],{"data":41282,"content":41283,"nodeType":876},{"uri":947},[41284],{"data":41285,"marks":41286,"value":39608,"nodeType":867},{},[41287],{"type":1040},{"data":41289,"marks":41290,"value":39612,"nodeType":867},{},[],{"data":41292,"content":41295,"nodeType":890},{"target":41293},{"sys":41294},{"id":39617,"type":887,"linkType":888},[],{"data":41297,"content":41298,"nodeType":881},{},[41299],{"data":41300,"marks":41301,"value":39625,"nodeType":867},{},[],{"data":41303,"content":41304,"nodeType":998},{},[41305],{"data":41306,"marks":41307,"value":39633,"nodeType":867},{},[41308],{"type":916},{"data":41310,"content":41311,"nodeType":881},{},[41312],{"data":41313,"marks":41314,"value":39640,"nodeType":867},{},[],{"data":41316,"content":41319,"nodeType":890},{"target":41317},{"sys":41318},{"id":39645,"type":887,"linkType":888},[],{"data":41321,"content":41322,"nodeType":881},{},[41323,41326,41333,41336,41343],{"data":41324,"marks":41325,"value":39653,"nodeType":867},{},[],{"data":41327,"content":41328,"nodeType":876},{"uri":39656},[41329],{"data":41330,"marks":41331,"value":39662,"nodeType":867},{},[41332],{"type":1040},{"data":41334,"marks":41335,"value":39666,"nodeType":867},{},[],{"data":41337,"content":41338,"nodeType":876},{"uri":34888},[41339],{"data":41340,"marks":41341,"value":20604,"nodeType":867},{},[41342],{"type":1040},{"data":41344,"marks":41345,"value":39677,"nodeType":867},{},[],{"data":41347,"content":41348,"nodeType":998},{},[41349],{"data":41350,"marks":41351,"value":39685,"nodeType":867},{},[41352],{"type":916},{"data":41354,"content":41355,"nodeType":881},{},[41356,41359,41366],{"data":41357,"marks":41358,"value":39692,"nodeType":867},{},[],{"data":41360,"content":41361,"nodeType":876},{"uri":39695},[41362],{"data":41363,"marks":41364,"value":39701,"nodeType":867},{},[41365],{"type":1040},{"data":41367,"marks":41368,"value":39705,"nodeType":867},{},[],{"data":41370,"content":41371,"nodeType":881},{},[41372],{"data":41373,"marks":41374,"value":39712,"nodeType":867},{},[],{"data":41376,"content":41379,"nodeType":890},{"target":41377},{"sys":41378},{"id":39717,"type":887,"linkType":888},[],{"data":41381,"content":41382,"nodeType":998},{},[41383],{"data":41384,"marks":41385,"value":39726,"nodeType":867},{},[41386],{"type":916},{"data":41388,"content":41389,"nodeType":881},{},[41390,41393,41400],{"data":41391,"marks":41392,"value":39733,"nodeType":867},{},[],{"data":41394,"content":41395,"nodeType":876},{"uri":39736},[41396],{"data":41397,"marks":41398,"value":39742,"nodeType":867},{},[41399],{"type":1040},{"data":41401,"marks":41402,"value":39746,"nodeType":867},{},[],{"data":41404,"content":41405,"nodeType":881},{},[41406],{"data":41407,"marks":41408,"value":39753,"nodeType":867},{},[],{"data":41410,"content":41411,"nodeType":3126},{},[41412,41421,41430,41439,41448,41457],{"data":41413,"content":41414,"nodeType":3061},{},[41415],{"data":41416,"content":41417,"nodeType":881},{},[41418],{"data":41419,"marks":41420,"value":39766,"nodeType":867},{},[],{"data":41422,"content":41423,"nodeType":3061},{},[41424],{"data":41425,"content":41426,"nodeType":881},{},[41427],{"data":41428,"marks":41429,"value":39776,"nodeType":867},{},[],{"data":41431,"content":41432,"nodeType":3061},{},[41433],{"data":41434,"content":41435,"nodeType":881},{},[41436],{"data":41437,"marks":41438,"value":39786,"nodeType":867},{},[],{"data":41440,"content":41441,"nodeType":3061},{},[41442],{"data":41443,"content":41444,"nodeType":881},{},[41445],{"data":41446,"marks":41447,"value":39796,"nodeType":867},{},[],{"data":41449,"content":41450,"nodeType":3061},{},[41451],{"data":41452,"content":41453,"nodeType":881},{},[41454],{"data":41455,"marks":41456,"value":39806,"nodeType":867},{},[],{"data":41458,"content":41459,"nodeType":3061},{},[41460],{"data":41461,"content":41462,"nodeType":881},{},[41463],{"data":41464,"marks":41465,"value":39816,"nodeType":867},{},[],{"data":41467,"content":41470,"nodeType":890},{"target":41468},{"sys":41469},{"id":39821,"type":887,"linkType":888},[],{"data":41472,"content":41473,"nodeType":908},{},[],{"data":41475,"content":41476,"nodeType":918},{},[41477],{"data":41478,"marks":41479,"value":39833,"nodeType":867},{},[41480],{"type":916},{"data":41482,"content":41483,"nodeType":881},{},[41484],{"data":41485,"marks":41486,"value":39840,"nodeType":867},{},[],{"data":41488,"content":41489,"nodeType":881},{},[41490],{"data":41491,"marks":41492,"value":39847,"nodeType":867},{},[],{"data":41494,"content":41495,"nodeType":881},{},[41496,41499,41506,41509,41516],{"data":41497,"marks":41498,"value":39854,"nodeType":867},{},[],{"data":41500,"content":41501,"nodeType":876},{"uri":39857},[41502],{"data":41503,"marks":41504,"value":39863,"nodeType":867},{},[41505],{"type":1040},{"data":41507,"marks":41508,"value":39867,"nodeType":867},{},[],{"data":41510,"content":41511,"nodeType":876},{"uri":947},[41512],{"data":41513,"marks":41514,"value":39875,"nodeType":867},{},[41515],{"type":1040},{"data":41517,"marks":41518,"value":10110,"nodeType":867},{},[],{"data":41520,"content":41521,"nodeType":908},{},[],{"data":41523,"content":41524,"nodeType":918},{},[41525],{"data":41526,"marks":41527,"value":39889,"nodeType":867},{},[41528],{"type":916},{"data":41530,"content":41531,"nodeType":881},{},[41532],{"data":41533,"marks":41534,"value":39897,"nodeType":867},{},[41535],{"type":916},{"data":41537,"content":41540,"nodeType":890},{"target":41538},{"sys":41539},{"id":39902,"type":887,"linkType":888},[],{"data":41542,"content":41543,"nodeType":998},{},[41544],{"data":41545,"marks":41546,"value":39910,"nodeType":867},{},[],{"data":41548,"content":41549,"nodeType":881},{},[41550],{"data":41551,"marks":41552,"value":39918,"nodeType":867},{},[41553],{"type":916},{"data":41555,"content":41558,"nodeType":890},{"target":41556},{"sys":41557},{"id":39923,"type":887,"linkType":888},[],{"data":41560,"content":41561,"nodeType":881},{},[41562],{"data":41563,"marks":41564,"value":39931,"nodeType":867},{},[],{"data":41566,"content":41567,"nodeType":881},{},[41568],{"data":41569,"marks":41570,"value":39938,"nodeType":867},{},[],{"data":41572,"content":41575,"nodeType":890},{"target":41573},{"sys":41574},{"id":39943,"type":887,"linkType":888},[],{"data":41577,"content":41578,"nodeType":998},{},[41579],{"data":41580,"marks":41581,"value":39951,"nodeType":867},{},[],{"data":41583,"content":41584,"nodeType":881},{},[41585],{"data":41586,"marks":41587,"value":39959,"nodeType":867},{},[41588],{"type":916},{"data":41590,"content":41591,"nodeType":881},{},[41592],{"data":41593,"marks":41594,"value":39966,"nodeType":867},{},[],{"data":41596,"content":41597,"nodeType":881},{},[41598],{"data":41599,"marks":41600,"value":39973,"nodeType":867},{},[],{"data":41602,"content":41603,"nodeType":998},{},[41604],{"data":41605,"marks":41606,"value":39980,"nodeType":867},{},[],{"data":41608,"content":41609,"nodeType":881},{},[41610,41614,41619],{"data":41611,"marks":41612,"value":39988,"nodeType":867},{},[41613],{"type":916},{"data":41615,"marks":41616,"value":39994,"nodeType":867},{},[41617,41618],{"type":1040},{"type":916},{"data":41620,"marks":41621,"value":39999,"nodeType":867},{},[41622],{"type":916},{"data":41624,"content":41625,"nodeType":881},{},[41626,41629,41636],{"data":41627,"marks":41628,"value":40006,"nodeType":867},{},[],{"data":41630,"content":41631,"nodeType":876},{"uri":40009},[41632],{"data":41633,"marks":41634,"value":40015,"nodeType":867},{},[41635],{"type":1040},{"data":41637,"marks":41638,"value":1947,"nodeType":867},{},[],{"data":41640,"content":41641,"nodeType":881},{},[41642],{"data":41643,"marks":41644,"value":40025,"nodeType":867},{},[],{"data":41646,"content":41647,"nodeType":881},{},[41648],{"data":41649,"marks":41650,"value":40032,"nodeType":867},{},[],{"data":41652,"content":41655,"nodeType":890},{"target":41653},{"sys":41654},{"id":40037,"type":887,"linkType":888},[],{"data":41657,"content":41658,"nodeType":998},{},[41659],{"data":41660,"marks":41661,"value":40045,"nodeType":867},{},[],{"data":41663,"content":41664,"nodeType":881},{},[41665],{"data":41666,"marks":41667,"value":40053,"nodeType":867},{},[41668],{"type":916},{"data":41670,"content":41671,"nodeType":881},{},[41672],{"data":41673,"marks":41674,"value":40060,"nodeType":867},{},[],{"data":41676,"content":41677,"nodeType":881},{},[41678],{"data":41679,"marks":41680,"value":40067,"nodeType":867},{},[],{"data":41682,"content":41685,"nodeType":890},{"target":41683},{"sys":41684},{"id":40072,"type":887,"linkType":888},[],{"data":41687,"content":41688,"nodeType":998},{},[41689],{"data":41690,"marks":41691,"value":40080,"nodeType":867},{},[],{"data":41693,"content":41694,"nodeType":881},{},[41695],{"data":41696,"marks":41697,"value":40088,"nodeType":867},{},[41698],{"type":916},{"data":41700,"content":41701,"nodeType":881},{},[41702],{"data":41703,"marks":41704,"value":40095,"nodeType":867},{},[],{"data":41706,"content":41707,"nodeType":881},{},[41708],{"data":41709,"marks":41710,"value":40102,"nodeType":867},{},[],{"data":41712,"content":41713,"nodeType":881},{},[41714],{"data":41715,"marks":41716,"value":40109,"nodeType":867},{},[],{"data":41718,"content":41721,"nodeType":890},{"target":41719},{"sys":41720},{"id":40114,"type":887,"linkType":888},[],{"data":41723,"content":41724,"nodeType":998},{},[41725],{"data":41726,"marks":41727,"value":40122,"nodeType":867},{},[],{"data":41729,"content":41730,"nodeType":881},{},[41731],{"data":41732,"marks":41733,"value":40130,"nodeType":867},{},[41734],{"type":916},{"data":41736,"content":41737,"nodeType":881},{},[41738],{"data":41739,"marks":41740,"value":40137,"nodeType":867},{},[],{"data":41742,"content":41743,"nodeType":881},{},[41744,41747,41754],{"data":41745,"marks":41746,"value":40144,"nodeType":867},{},[],{"data":41748,"content":41749,"nodeType":876},{"uri":6845},[41750],{"data":41751,"marks":41752,"value":6850,"nodeType":867},{},[41753],{"type":1040},{"data":41755,"marks":41756,"value":40155,"nodeType":867},{},[],{"data":41758,"content":41761,"nodeType":890},{"target":41759},{"sys":41760},{"id":40160,"type":887,"linkType":888},[],{"data":41763,"content":41764,"nodeType":998},{},[41765],{"data":41766,"marks":41767,"value":40168,"nodeType":867},{},[],{"data":41769,"content":41770,"nodeType":881},{},[41771,41774,41782],{"data":41772,"marks":41773,"value":15780,"nodeType":867},{},[],{"data":41775,"content":41776,"nodeType":876},{"uri":15783},[41777],{"data":41778,"marks":41779,"value":15790,"nodeType":867},{},[41780,41781],{"type":1040},{"type":916},{"data":41783,"marks":41784,"value":15794,"nodeType":867},{},[],{"data":41786,"content":41789,"nodeType":890},{"target":41787},{"sys":41788},{"id":15799,"type":887,"linkType":888},[],{"data":41791,"content":41792,"nodeType":881},{},[41793],{"data":41794,"marks":41795,"value":15807,"nodeType":867},{},[],{"data":41797,"content":41798,"nodeType":881},{},[41799,41802,41809],{"data":41800,"marks":41801,"value":15824,"nodeType":867},{},[],{"data":41803,"content":41804,"nodeType":876},{"uri":15827},[41805],{"data":41806,"marks":41807,"value":15833,"nodeType":867},{},[41808],{"type":1040},{"data":41810,"marks":41811,"value":15837,"nodeType":867},{},[],{"data":41813,"content":41816,"nodeType":890},{"target":41814},{"sys":41815},{"id":15859,"type":887,"linkType":888},[],{"data":41818,"content":41819,"nodeType":908},{},[],{"data":41821,"content":41822,"nodeType":918},{},[41823],{"data":41824,"marks":41825,"value":4330,"nodeType":867},{},[41826],{"type":916},{"data":41828,"content":41829,"nodeType":881},{},[41830],{"data":41831,"marks":41832,"value":40234,"nodeType":867},{},[],{"data":41834,"content":41835,"nodeType":881},{},[41836,41839,41845],{"data":41837,"marks":41838,"value":34977,"nodeType":867},{},[],{"data":41840,"content":41841,"nodeType":876},{"uri":40243},[41842],{"data":41843,"marks":41844,"value":10826,"nodeType":867},{},[],{"data":41846,"marks":41847,"value":1947,"nodeType":867},{},[],{"items":41849},[41850,41852],{"sys":41851,"name":2547},{"id":2546},{"sys":41853,"name":342},{"id":2550},{"items":41855},[41856],{"fullName":849,"firstName":850,"jobTitle":851,"profilePicture":41857},{"url":855},{"__typename":1742,"sys":41859,"content":41861,"title":42505,"synopsis":42506,"hashTags":59,"publishedDate":42507,"slug":42508,"tagsCollection":42509,"authorsCollection":42515},{"id":41860},"3dtvtDQdcQ6fAW7CB8VOFP",{"json":41862},{"data":41863,"content":41864,"nodeType":1640},{},[41865,41872,41879,41886,41889,41897,41904,41923,41956,41962,41982,41988,42013,42016,42024,42031,42047,42062,42068,42075,42082,42088,42104,42107,42115,42122,42129,42136,42143,42146,42154,42161,42168,42188,42195,42203,42246,42253,42259,42266,42272,42279,42282,42290,42305,42312,42354,42366,42369,42377,42384,42391,42424,42431,42451,42456,42462,42465,42472,42478,42494,42499],{"data":41866,"content":41867,"nodeType":881},{},[41868],{"data":41869,"marks":41870,"value":41871,"nodeType":867},{},[],"Phishing attacks remain a huge challenge for organizations in 2025. In fact, with attackers increasingly leveraging identity-based techniques over software exploits, phishing arguably poses a bigger threat than ever before. ",{"data":41873,"content":41874,"nodeType":881},{},[41875],{"data":41876,"marks":41877,"value":41878,"nodeType":867},{},[],"Attackers are turning to identity attacks like phishing because they can achieve all of the same objectives as they would in a traditional endpoint or network attack, simply by logging into a victim’s account. And with organizations now using hundreds of internet apps across their workforce, the scope of accounts that can be phished or targeted with stolen credentials has grown exponentially. ",{"data":41880,"content":41881,"nodeType":881},{},[41882],{"data":41883,"marks":41884,"value":41885,"nodeType":867},{},[],"With MFA-bypassing phishing kits the new normal, capable of phishing accounts protected by SMS, OTP, and push-based methods, detection controls are being put under constant pressure as prevention controls fall short. ",{"data":41887,"content":41888,"nodeType":908},{},[],{"data":41890,"content":41891,"nodeType":918},{},[41892],{"data":41893,"marks":41894,"value":41896,"nodeType":867},{},[41895],{"type":916},"Attackers are bypassing detection controls",{"data":41898,"content":41899,"nodeType":881},{},[41900],{"data":41901,"marks":41902,"value":41903,"nodeType":867},{},[],"The majority of phishing detection and control enforcement is focused at the email and network layer — typically at the Secure Email Gateway (SEG), Secure Web Gateway (SWG)/proxy, or both. ",{"data":41905,"content":41906,"nodeType":881},{},[41907,41911,41919],{"data":41908,"marks":41909,"value":41910,"nodeType":867},{},[],"But attackers know this, ",{"data":41912,"content":41913,"nodeType":876},{"uri":39736},[41914],{"data":41915,"marks":41916,"value":41918,"nodeType":867},{},[41917],{"type":1040},"and are taking steps to avoid these controls",{"data":41920,"marks":41921,"value":41922,"nodeType":867},{},[],", by:",{"data":41924,"content":41925,"nodeType":3126},{},[41926,41936,41946],{"data":41927,"content":41928,"nodeType":3061},{},[41929],{"data":41930,"content":41931,"nodeType":881},{},[41932],{"data":41933,"marks":41934,"value":41935,"nodeType":867},{},[],"Routinely evading IoC driven blocklists by dynamically rotating and updating commonly signatured elements like IPs, domains, and URLs.",{"data":41937,"content":41938,"nodeType":3061},{},[41939],{"data":41940,"content":41941,"nodeType":881},{},[41942],{"data":41943,"marks":41944,"value":41945,"nodeType":867},{},[],"Preventing analysis of their phishing pages by implementing bot protection like CAPTCHA or Cloudflare Turnstile alongside other detection evasion methods. ",{"data":41947,"content":41948,"nodeType":3061},{},[41949],{"data":41950,"content":41951,"nodeType":881},{},[41952],{"data":41953,"marks":41954,"value":41955,"nodeType":867},{},[],"Changing visual and DOM elements on the page so that even when the page is loaded, detection signatures may fail to trigger.  ",{"data":41957,"content":41961,"nodeType":890},{"target":41958},{"sys":41959},{"id":41960,"type":887,"linkType":888},"5w44LsamEfcwSACx3MA997",[],{"data":41963,"content":41964,"nodeType":881},{},[41965,41969,41978],{"data":41966,"marks":41967,"value":41968,"nodeType":867},{},[],"And in fact, by launching multi- and cross-channel attacks, attackers are evading email-based controls entirely. Just see ",{"data":41970,"content":41972,"nodeType":876},{"uri":41971},"https://pushsecurity.com/blog/investigating-a-recent-malvertising-campaign-targeting-onfido-customers/?utm_campaign=12081956-FY25Q2_Hacker-News-Article&utm_source=thehackernews&utm_medium=sponsored&utm_content=external-article",[41973],{"data":41974,"marks":41975,"value":41977,"nodeType":867},{},[41976],{"type":1040},"this recent example",{"data":41979,"marks":41980,"value":41981,"nodeType":867},{},[],", where attackers impersonating Onfido delivered their phishing attack via malicious Google ads (aka malvertising) — bypassing email altogether. ",{"data":41983,"content":41987,"nodeType":890},{"target":41984},{"sys":41985},{"id":41986,"type":887,"linkType":888},"3sGmVHl1Rwjyw3TMZSYuy4",[],{"data":41989,"content":41990,"nodeType":881},{},[41991,41995,42000,42004,42009],{"data":41992,"marks":41993,"value":41994,"nodeType":867},{},[],"It’s worth pointing out the limitations of email-based solutions here too. Email has some additional checks around the sender’s reputation and things like DMARC/DKIM, but these don’t actually identify malicious ",{"data":41996,"marks":41997,"value":41999,"nodeType":867},{},[41998],{"type":916},"pages",{"data":42001,"marks":42002,"value":42003,"nodeType":867},{},[],". Similarly, some modern email solutions are doing much deeper analysis of the ",{"data":42005,"marks":42006,"value":42008,"nodeType":867},{},[42007],{"type":916},"content",{"data":42010,"marks":42011,"value":42012,"nodeType":867},{},[]," of an email. But… that doesn’t really help with identifying the phishing sites themselves (just indicates that one might be linked in the email). This is much more appropriate for BEC-style attacks where the goal is to social engineer the victim, as opposed to linking them to a malicious page. And this still doesn’t help with attacks launched over different mediums as we’ve highlighted above.",{"data":42014,"content":42015,"nodeType":908},{},[],{"data":42017,"content":42018,"nodeType":918},{},[42019],{"data":42020,"marks":42021,"value":42023,"nodeType":867},{},[42022],{"type":916},"How browser-based detection and response can level the playing field",{"data":42025,"content":42026,"nodeType":881},{},[42027],{"data":42028,"marks":42029,"value":42030,"nodeType":867},{},[],"Most phishing attacks involve the delivery of a malicious link to a user. The user clicks the link and loads a malicious page. In the vast majority of cases, the malicious page is a login portal for a specific website, where the goal for the attacker is to steal the victim’s account.",{"data":42032,"content":42033,"nodeType":881},{},[42034,42038,42043],{"data":42035,"marks":42036,"value":42037,"nodeType":867},{},[],"These attacks are happening pretty much exclusively in the victim’s browser. So rather than building more email or network based controls looking from the outside-in at phishing pages accessed in the browser, there’s a huge opportunity presented by building phishing detection and response capabilities ",{"data":42039,"marks":42040,"value":42042,"nodeType":867},{},[42041],{"type":1431},"inside",{"data":42044,"marks":42045,"value":42046,"nodeType":867},{},[]," the browser. ",{"data":42048,"content":42049,"nodeType":881},{},[42050,42054,42059],{"data":42051,"marks":42052,"value":42053,"nodeType":867},{},[],"When we look at the history of detection and response, this makes a lot of sense. When endpoint attacks skyrocketed in the late 2000s / early 2010s, they took advantage of the fact that defenders were trying to detect malware with primarily network-based detections, signature-based analysis of files, and running files in sandboxes (which was reliably defeated with sandbox-aware malware and using things as simple as putting an execution delay in the code). But this gave way to EDR, which presented a better way of observing and intercepting malicious software in ",{"data":42055,"marks":42056,"value":42058,"nodeType":867},{},[42057],{"type":916},"real-time",{"data":42060,"marks":42061,"value":10110,"nodeType":867},{},[],{"data":42063,"content":42067,"nodeType":890},{"target":42064},{"sys":42065},{"id":42066,"type":887,"linkType":888},"1KFwJvbIMiWHb1erWlljZf",[],{"data":42069,"content":42070,"nodeType":881},{},[42071],{"data":42072,"marks":42073,"value":42074,"nodeType":867},{},[],"The key here was getting inside the data stream to be able to observe activity in real-time on the endpoint. ",{"data":42076,"content":42077,"nodeType":881},{},[42078],{"data":42079,"marks":42080,"value":42081,"nodeType":867},{},[],"We’re in a similar position today. Modern phishing attacks are happening on web pages accessed via the browser, and the tools we’re relying on — email, network, even endpoint — don’t have the required visibility. They’re looking from the outside-in. ",{"data":42083,"content":42087,"nodeType":890},{"target":42084},{"sys":42085},{"id":42086,"type":887,"linkType":888},"59t6AcjpRjs3VQQXQO3PWu",[],{"data":42089,"content":42090,"nodeType":881},{},[42091,42095,42100],{"data":42092,"marks":42093,"value":42094,"nodeType":867},{},[],"But what if we could do detection and response from ",{"data":42096,"marks":42097,"value":42099,"nodeType":867},{},[42098],{"type":916},"inside the browser?",{"data":42101,"marks":42102,"value":42103,"nodeType":867},{},[]," Here’s three reasons why the browser is best for stopping phishing attacks:",{"data":42105,"content":42106,"nodeType":908},{},[],{"data":42108,"content":42109,"nodeType":918},{},[42110],{"data":42111,"marks":42112,"value":42114,"nodeType":867},{},[42113],{"type":916},"#1: Analyze pages, not links",{"data":42116,"content":42117,"nodeType":881},{},[42118],{"data":42119,"marks":42120,"value":42121,"nodeType":867},{},[],"Common phishing detections rely on the analysis of links or static HTML as opposed to malicious pages. Modern phishing pages are no longer static HTML — like most other modern web pages, these are dynamic web apps rendered in the browser, with JavaScript dynamically rewriting the page and launching the malicious content. This means that most basic, static checks fail to identify the malicious content running on the page. ",{"data":42123,"content":42124,"nodeType":881},{},[42125],{"data":42126,"marks":42127,"value":42128,"nodeType":867},{},[],"Without deeper analysis, you’re reliant on analyzing things like domains, URLs and IP addresses against known-bad blocklists. But these are all highly disposable. Attackers are buying them in bulk, constantly taking over legitimate domains, and generally planning for the fact that they’ll get through a lot of them. Modern phishing architecture is also able to dynamically rotate and update the links served to visitors from a continually refreshed pool (so every person that clicks the link gets served a different URL) and even going as far as using things like one-time magic links (which also means that any security team members trying to investigate the page later won’t be able to do so). ",{"data":42130,"content":42131,"nodeType":881},{},[42132],{"data":42133,"marks":42134,"value":42135,"nodeType":867},{},[],"Ultimately, this means that blocklists just aren’t that effective — because it’s trivial for attackers to change the indicators being used to create detections. If you think about the Pyramid of Pain, these indicators sit right at the bottom — the kind of thing we’ve been moving away from for years in the endpoint security world.  ",{"data":42137,"content":42138,"nodeType":881},{},[42139],{"data":42140,"marks":42141,"value":42142,"nodeType":867},{},[],"But in the browser, you can observe the rendered web page in all its glory. With much deeper visibility of the page (and its malicious elements) you can…",{"data":42144,"content":42145,"nodeType":908},{},[],{"data":42147,"content":42148,"nodeType":918},{},[42149],{"data":42150,"marks":42151,"value":42153,"nodeType":867},{},[42152],{"type":916},"#2: Detect TTPs, not IoCs",{"data":42155,"content":42156,"nodeType":881},{},[42157],{"data":42158,"marks":42159,"value":42160,"nodeType":867},{},[],"Even where TTP-based detections are in play, they’re typically reliant on either piecing together network requests, or loading the page in a sandbox. ",{"data":42162,"content":42163,"nodeType":881},{},[42164],{"data":42165,"marks":42166,"value":42167,"nodeType":867},{},[],"However, attackers are getting pretty good at evading sandbox analysis — simply by implementing bot protection by requiring user interaction with a CAPTCHA or Cloudflare Turnstile. Even if you can get past Turnstile, then you’ll need to supply the correct URL parameters and headers, and execute JavaScript, to be served the malicious page. This means that a defender who knows the domain name can’t discover the malicious behavior just by making a simple HTTP(S) request to the domain.",{"data":42169,"content":42170,"nodeType":881},{},[42171,42175,42184],{"data":42172,"marks":42173,"value":42174,"nodeType":867},{},[],"And if all this wasn’t enough, ",{"data":42176,"content":42178,"nodeType":876},{"uri":42177},"https://pushsecurity.com/blog/how-aitm-phishing-kits-evade-detection-p2/?utm_campaign=12081956-FY25Q2_Hacker-News-Article&utm_source=thehackernews&utm_medium=sponsored&utm_content=external-article",[42179],{"data":42180,"marks":42181,"value":42183,"nodeType":867},{},[42182],{"type":1040},"they’re also obfuscating both visual and DOM elements to prevent signature-based detections from picking them up",{"data":42185,"marks":42186,"value":42187,"nodeType":867},{},[]," — so even if you can land on the page, there’s a high chance that your detections won’t trigger.",{"data":42189,"content":42190,"nodeType":881},{},[42191],{"data":42192,"marks":42193,"value":42194,"nodeType":867},{},[],"When using a proxy, you’ll have some visibility of the network traffic generated by a user accessing and interacting with a page. However, you’ll struggle to correlate key actions like whether the user entered their password with the specific tab when dealing with the sheer volume of disorganized network traffic data. ",{"data":42196,"content":42197,"nodeType":881},{},[42198],{"data":42199,"marks":42200,"value":42202,"nodeType":867},{},[42201],{"type":916},"But you get much better visibility of all this in the browser, with access to:",{"data":42204,"content":42205,"nodeType":3126},{},[42206,42216,42226,42236],{"data":42207,"content":42208,"nodeType":3061},{},[42209],{"data":42210,"content":42211,"nodeType":881},{},[42212],{"data":42213,"marks":42214,"value":42215,"nodeType":867},{},[],"Full decrypted HTTP traffic — not just DNS and TCP/IP metadata",{"data":42217,"content":42218,"nodeType":3061},{},[42219],{"data":42220,"content":42221,"nodeType":881},{},[42222],{"data":42223,"marks":42224,"value":42225,"nodeType":867},{},[],"Full user interaction tracing — every click, keystroke, or DOM change can be traced",{"data":42227,"content":42228,"nodeType":3061},{},[42229],{"data":42230,"content":42231,"nodeType":881},{},[42232],{"data":42233,"marks":42234,"value":42235,"nodeType":867},{},[],"Full inspection at every layer of execution, not just initial HTML served",{"data":42237,"content":42238,"nodeType":3061},{},[42239],{"data":42240,"content":42241,"nodeType":881},{},[42242],{"data":42243,"marks":42244,"value":42245,"nodeType":867},{},[],"Full access to browser APIs, to correlate with browser history, local storage, attached cookies, etc.",{"data":42247,"content":42248,"nodeType":881},{},[42249],{"data":42250,"marks":42251,"value":42252,"nodeType":867},{},[],"This gives you everything you need to build high-fidelity detections focused on page behavior and user interaction – that are much harder for attackers to get around when compared to IoC-based detections. ",{"data":42254,"content":42258,"nodeType":890},{"target":42255},{"sys":42256},{"id":42257,"type":887,"linkType":888},"1YggWcADAWgt3sUkXMsVIw",[],{"data":42260,"content":42261,"nodeType":881},{},[42262],{"data":42263,"marks":42264,"value":42265,"nodeType":867},{},[],"In the browser, you get much better visibility of the user and page behavior to enable phishing page detection.",{"data":42267,"content":42271,"nodeType":890},{"target":42268},{"sys":42269},{"id":42270,"type":887,"linkType":888},"1BKgjnYkLJIRW0LJZYpfga",[],{"data":42273,"content":42274,"nodeType":881},{},[42275],{"data":42276,"marks":42277,"value":42278,"nodeType":867},{},[],"And with this new visibility, because you’re in the browser and seeing the page at the same time as the user is interacting with it, you can…",{"data":42280,"content":42281,"nodeType":908},{},[],{"data":42283,"content":42284,"nodeType":918},{},[42285],{"data":42286,"marks":42287,"value":42289,"nodeType":867},{},[42288],{"type":916},"#3: Intercept in real time, not post mortem",{"data":42291,"content":42292,"nodeType":881},{},[42293,42297,42302],{"data":42294,"marks":42295,"value":42296,"nodeType":867},{},[],"For non-browser solutions, ",{"data":42298,"marks":42299,"value":42301,"nodeType":867},{},[42300],{"type":916},"real-time phishing detection is basically nonexistent",{"data":42303,"marks":42304,"value":10110,"nodeType":867},{},[],{"data":42306,"content":42307,"nodeType":881},{},[42308],{"data":42309,"marks":42310,"value":42311,"nodeType":867},{},[],"At best, your proxy-based solution might be able to detect malicious behavior via the network traffic generated by your user interacting with the page. But because of the complexity of reconstructing network requests post-TLS-encryption, this typically happens on a time delay and is not entirely reliable. ",{"data":42313,"content":42314,"nodeType":881},{},[42315,42319,42324,42328,42333,42337,42341,42345,42350],{"data":42316,"marks":42317,"value":42318,"nodeType":867},{},[],"If a page is flagged, it usually requires further investigation by a security team to rule out any false positives and kick off an investigation. This can take ",{"data":42320,"marks":42321,"value":42323,"nodeType":867},{},[42322],{"type":916},"hours",{"data":42325,"marks":42326,"value":42327,"nodeType":867},{},[]," at best, probably ",{"data":42329,"marks":42330,"value":42332,"nodeType":867},{},[42331],{"type":916},"days",{"data":42334,"marks":42335,"value":42336,"nodeType":867},{},[],". Then, once a page is identified as malicious and IoCs are created, it can take ",{"data":42338,"marks":42339,"value":42332,"nodeType":867},{},[42340],{"type":916},{"data":42342,"marks":42343,"value":42344,"nodeType":867},{},[]," or even ",{"data":42346,"marks":42347,"value":42349,"nodeType":867},{},[42348],{"type":916},"weeks",{"data":42351,"marks":42352,"value":42353,"nodeType":867},{},[]," before the information is distributed, TI feeds are updated, and ingested into blocklists. ",{"data":42355,"content":42356,"nodeType":881},{},[42357,42361],{"data":42358,"marks":42359,"value":42360,"nodeType":867},{},[],"But in the browser, you’re observing the page in real-time, as the user sees it, from inside the browser. This is a game changer when it comes to not just detecting, but intercepting and shutting down attacks before a user is phished and the damage is done. ",{"data":42362,"marks":42363,"value":42365,"nodeType":867},{},[42364],{"type":916},"This changes the focus from post mortem containment and cleanup, to pre-compromise interception in real time. ",{"data":42367,"content":42368,"nodeType":908},{},[],{"data":42370,"content":42371,"nodeType":918},{},[42372],{"data":42373,"marks":42374,"value":42376,"nodeType":867},{},[42375],{"type":916},"The future of phishing detection and response is browser based",{"data":42378,"content":42379,"nodeType":881},{},[42380],{"data":42381,"marks":42382,"value":42383,"nodeType":867},{},[],"Push provides a browser-based identity security solution that intercepts phishing attacks as they happen — in employee browsers. Being in the browser delivers a lot of advantages when it comes to detecting and intercepting phishing attacks. You see the live webpage that the user sees, as they see it, meaning you have much better visibility of malicious elements running on the page. It also means that you can implement real-time controls that kick in when a malicious element is detected. ",{"data":42385,"content":42386,"nodeType":881},{},[42387],{"data":42388,"marks":42389,"value":42390,"nodeType":867},{},[],"When a phishing attack hits a user with Push, regardless of the delivery channel, our browser extension inspects the webpage running in the user's browser. Push observes that the webpage is a login page and the user is entering their password into the page, detecting that:",{"data":42392,"content":42393,"nodeType":3126},{},[42394,42404,42414],{"data":42395,"content":42396,"nodeType":3061},{},[42397],{"data":42398,"content":42399,"nodeType":881},{},[42400],{"data":42401,"marks":42402,"value":42403,"nodeType":867},{},[],"The password the user is entering into the phishing site has been used to log into another site previously. This means that the password is being reused (bad) or the user is being phished (even worse).  ",{"data":42405,"content":42406,"nodeType":3061},{},[42407],{"data":42408,"content":42409,"nodeType":881},{},[42410],{"data":42411,"marks":42412,"value":42413,"nodeType":867},{},[],"The web page is cloned from a legitimate login page that has been fingerprinted by Push. ",{"data":42415,"content":42416,"nodeType":3061},{},[42417],{"data":42418,"content":42419,"nodeType":881},{},[42420],{"data":42421,"marks":42422,"value":42423,"nodeType":867},{},[],"A phishing toolkit is running on the web page. ",{"data":42425,"content":42426,"nodeType":881},{},[42427],{"data":42428,"marks":42429,"value":42430,"nodeType":867},{},[],"As a result, the user is blocked from interacting with the phishing site and prevented from continuing. ",{"data":42432,"content":42433,"nodeType":881},{},[42434,42439,42448],{"data":42435,"marks":42436,"value":42438,"nodeType":867},{},[42437],{"type":916},"These are good examples of detections that are difficult (or impossible) for an attacker to evade — you can’t phish a victim if they can’t enter their credentials into your phishing site! ",{"data":42440,"content":42442,"nodeType":876},{"uri":42441},"https://pushsecurity.com/blog/detecting-and-blocking-phishing-attacks-in-the-browser/?utm_campaign=12081956-FY25Q2_Hacker-News-Article&utm_source=thehackernews&utm_medium=sponsored&utm_content=external-article",[42443],{"data":42444,"marks":42445,"value":42447,"nodeType":867},{},[42446],{"type":1040},"Find out more about how Push detects and blocks phishing attacks here.",{"data":42449,"marks":42450,"value":21,"nodeType":867},{},[],{"data":42452,"content":42455,"nodeType":890},{"target":42453},{"sys":42454},{"id":39943,"type":887,"linkType":888},[],{"data":42457,"content":42461,"nodeType":890},{"target":42458},{"sys":42459},{"id":42460,"type":887,"linkType":888},"4PJKxWTroEPohYm4mklfl6",[],{"data":42463,"content":42464,"nodeType":908},{},[],{"data":42466,"content":42467,"nodeType":918},{},[42468],{"data":42469,"marks":42470,"value":4330,"nodeType":867},{},[42471],{"type":916},{"data":42473,"content":42474,"nodeType":881},{},[42475],{"data":42476,"marks":42477,"value":40234,"nodeType":867},{},[],{"data":42479,"content":42480,"nodeType":881},{},[42481,42484,42491],{"data":42482,"marks":42483,"value":34977,"nodeType":867},{},[],{"data":42485,"content":42486,"nodeType":876},{"uri":40243},[42487],{"data":42488,"marks":42489,"value":10826,"nodeType":867},{},[42490],{"type":1040},{"data":42492,"marks":42493,"value":1947,"nodeType":867},{},[],{"data":42495,"content":42498,"nodeType":890},{"target":42496},{"sys":42497},{"id":39558,"type":887,"linkType":888},[],{"data":42500,"content":42501,"nodeType":881},{},[42502],{"data":42503,"marks":42504,"value":21,"nodeType":867},{},[],"Three reasons why browser is best for stopping phishing attacks","Why being in the browser gives defenders a key advantage over network and email phishing prevention, detection, and response tools. ","2025-04-28T00:00:00.000Z","three-reasons-why-browser-is-best-for-stopping-phishing-attacks",{"items":42510},[42511,42513],{"sys":42512,"name":342},{"id":2550},{"sys":42514,"name":2547},{"id":2546},{"items":42516},[42517],{"fullName":849,"firstName":850,"jobTitle":851,"profilePicture":42518},{"url":855},{"__typename":1742,"sys":42520,"content":42521,"title":29773,"synopsis":43513,"hashTags":59,"publishedDate":43514,"slug":29774,"tagsCollection":43515,"authorsCollection":43521},{"id":27270},{"json":42522},{"data":42523,"content":42524,"nodeType":1640},{},[42525,42544,42551,42558,42565,42572,42578,42585,42601,42604,42611,42618,42625,42632,42642,42649,42656,42663,42671,42678,42749,42761,42768,42776,42783,42841,42853,42860,42866,42874,42881,42914,42938,42945,42955,42958,42965,42985,42992,43025,43032,43039,43046,43052,43055,43062,43069,43077,43084,43091,43107,43113,43121,43128,43134,43142,43162,43169,43202,43222,43227,43247,43267,43275,43282,43289,43295,43315,43318,43326,43341,43348,43355,43405,43411,43418,43425,43468,43471,43479,43486,43489,43496],{"data":42526,"content":42527,"nodeType":881},{},[42528,42532,42541],{"data":42529,"marks":42530,"value":42531,"nodeType":867},{},[],"It wasn’t supposed to be like this. Passwords were supposed to be dead (just ask ",{"data":42533,"content":42535,"nodeType":876},{"uri":42534},"https://www.cnet.com/news/privacy/gates-predicts-death-of-the-password/",[42536],{"data":42537,"marks":42538,"value":42540,"nodeType":867},{},[42539],{"type":1040},"Bill Gates",{"data":42542,"marks":42543,"value":11572,"nodeType":867},{},[],{"data":42545,"content":42546,"nodeType":881},{},[42547],{"data":42548,"marks":42549,"value":42550,"nodeType":867},{},[],"Instead, hardworking security pros are left to sit around in community center basements drinking mediocre coffee and commiserating.",{"data":42552,"content":42553,"nodeType":881},{},[42554],{"data":42555,"marks":42556,"value":42557,"nodeType":867},{},[],"“I admit it. My users still use passwords.”",{"data":42559,"content":42560,"nodeType":881},{},[42561],{"data":42562,"marks":42563,"value":42564,"nodeType":867},{},[],"“Yeah, mine too. I’ve been telling people we’re rolling out passkeys for three years now. I’m not sure how much longer I can keep this up …”",{"data":42566,"content":42567,"nodeType":881},{},[42568],{"data":42569,"marks":42570,"value":42571,"nodeType":867},{},[],"Somber nodding all around. Hugs. A few chocolate-chip cookies on paper napkins.",{"data":42573,"content":42577,"nodeType":890},{"target":42574},{"sys":42575},{"id":42576,"type":887,"linkType":888},"4Wt29DxSSczFt5THWkuIiS",[],{"data":42579,"content":42580,"nodeType":881},{},[42581],{"data":42582,"marks":42583,"value":42584,"nodeType":867},{},[],"This is a no-judgment zone here at Push Security. So let’s take a look at why we’re still stuck with passwords, how attackers are increasingly exploiting weak credentials to infiltrate organizations, and how Push can help you get visibility and control of all your workforce identities.",{"data":42586,"content":42587,"nodeType":881},{},[42588,42592,42597],{"data":42589,"marks":42590,"value":42591,"nodeType":867},{},[],"We’ll also cover how you can use Push’s latest feature, ",{"data":42593,"marks":42594,"value":42596,"nodeType":867},{},[42595],{"type":916},"Strong password enforcement",{"data":42598,"marks":42599,"value":42600,"nodeType":867},{},[],", to require that employees use strong, unique passwords. Push automatically detects when employees have weak, reused, or stolen passwords and then guides them to update their password using in-browser messaging — even on apps that don’t natively support administrative control of password posture.",{"data":42602,"content":42603,"nodeType":908},{},[],{"data":42605,"content":42606,"nodeType":918},{},[42607],{"data":42608,"marks":42609,"value":42610,"nodeType":867},{},[],"3 reasons why we’re still stuck with passwords",{"data":42612,"content":42613,"nodeType":881},{},[42614],{"data":42615,"marks":42616,"value":42617,"nodeType":867},{},[],"At the risk of preaching to the choir, let’s review why we’re still stuck with passwords. ",{"data":42619,"content":42620,"nodeType":881},{},[42621],{"data":42622,"marks":42623,"value":42624,"nodeType":867},{},[],"It’s worth stating the Push perspective up front: We’re not here to push the narrative that you must completely get rid of passwords. To begin with, it’s not easy to get rid of them. Like the imaginary scene from the passwordless support group, we’ve lived the reality of this.",{"data":42626,"content":42627,"nodeType":881},{},[42628],{"data":42629,"marks":42630,"value":42631,"nodeType":867},{},[],"What we observe across our install base for the Push browser agent reinforces this reality. For the last 1 million or so logins that Push recorded, more than a quarter (26%) were password logins.",{"data":42633,"content":42634,"nodeType":1433},{},[42635],{"data":42636,"content":42637,"nodeType":881},{},[42638],{"data":42639,"marks":42640,"value":42641,"nodeType":867},{},[],"For the last 1M+ logins that the Push browser agent observed, more than a quarter were password logins.",{"data":42643,"content":42644,"nodeType":881},{},[42645],{"data":42646,"marks":42647,"value":42648,"nodeType":867},{},[],"Of those password logins, 18% had a security issue with the password — reused, easily guessable, already leaked in a public breach list, or actively for sale in criminal forums.",{"data":42650,"content":42651,"nodeType":881},{},[42652],{"data":42653,"marks":42654,"value":42655,"nodeType":867},{},[],"Yet when strong, unique passwords are used in conjunction with MFA, they can provide a powerful line of defense. Indeed, in cases where onboarding an app to SSO isn’t possible (for reasons we’ll cover below), a strong, unique password plus MFA is the most pragmatic solution you can achieve.",{"data":42657,"content":42658,"nodeType":881},{},[42659],{"data":42660,"marks":42661,"value":42662,"nodeType":867},{},[],"Here’s why bad passwords persist, and why it matters.",{"data":42664,"content":42665,"nodeType":998},{},[42666],{"data":42667,"marks":42668,"value":42670,"nodeType":867},{},[42669],{"type":916},"Systemic reasons",{"data":42672,"content":42673,"nodeType":881},{},[42674],{"data":42675,"marks":42676,"value":42677,"nodeType":867},{},[],"If we zoom out, there are several systemic reasons that contribute to the persistence of password security issues:",{"data":42679,"content":42680,"nodeType":3126},{},[42681,42708,42734],{"data":42682,"content":42683,"nodeType":3061},{},[42684],{"data":42685,"content":42686,"nodeType":881},{},[42687,42692,42696,42704],{"data":42688,"marks":42689,"value":42691,"nodeType":867},{},[42690],{"type":916},"Self-adoption of work apps",{"data":42693,"marks":42694,"value":42695,"nodeType":867},{},[]," makes it extremely difficult to know all the workforce identities that exist across your environment, let alone whether they’re using a secure authentication method, or the strength or uniqueness of their password. Push’s ",{"data":42697,"content":42698,"nodeType":876},{"uri":6833},[42699],{"data":42700,"marks":42701,"value":42703,"nodeType":867},{},[42702],{"type":1040},"own research",{"data":42705,"marks":42706,"value":42707,"nodeType":867},{},[]," shows that for an average organization, each employee has 15 identities.",{"data":42709,"content":42710,"nodeType":3061},{},[42711],{"data":42712,"content":42713,"nodeType":881},{},[42714,42719,42723,42730],{"data":42715,"marks":42716,"value":42718,"nodeType":867},{},[42717],{"type":916},"Apps optimize signups for low friction, not security.",{"data":42720,"marks":42721,"value":42722,"nodeType":867},{},[]," That often results in multiple authentication methods tied to any given account because local password accounts can still persist even after SSO onboarding — a phenomenon that we call ",{"data":42724,"content":42725,"nodeType":876},{"uri":14589},[42726],{"data":42727,"marks":42728,"value":6850,"nodeType":867},{},[42729],{"type":1040},{"data":42731,"marks":42732,"value":42733,"nodeType":867},{},[]," because they provide attackers with a way around a company’s enterprise SSO solution. These local accounts represent a significant risk, and most are invisible. Which brings us to …",{"data":42735,"content":42736,"nodeType":3061},{},[42737],{"data":42738,"content":42739,"nodeType":881},{},[42740,42745],{"data":42741,"marks":42742,"value":42744,"nodeType":867},{},[42743],{"type":916},"Many apps provide very little information to admins about the posture of accounts",{"data":42746,"marks":42747,"value":42748,"nodeType":867},{},[]," on that service, and even fewer offer management options to address security issues on those accounts. Some services provide no information at all about which accounts can even access a given tenant.",{"data":42750,"content":42751,"nodeType":881},{},[42752,42757],{"data":42753,"marks":42754,"value":42756,"nodeType":867},{},[42755],{"type":916},"The impact: ",{"data":42758,"marks":42759,"value":42760,"nodeType":867},{},[],"These systemic factors contribute to what we see many organizations grappling with: Known visibility gaps in their workforce identities, which are scattered across many more third-party apps than they imagine, and unknown account security risks for both managed and unmanaged apps.",{"data":42762,"content":42763,"nodeType":881},{},[42764],{"data":42765,"marks":42766,"value":42767,"nodeType":867},{},[],"These gaps open up a large attack surface for organizations. The 2024 Verizon DBIR found that 79% of web application compromises were the result of breached creds, and researchers at IBM reported last year that they observed a 71% year-over-year increase in cyberattacks using stolen or compromised credentials.",{"data":42769,"content":42770,"nodeType":998},{},[42771],{"data":42772,"marks":42773,"value":42775,"nodeType":867},{},[42774],{"type":916},"Technical reasons",{"data":42777,"content":42778,"nodeType":881},{},[42779],{"data":42780,"marks":42781,"value":42782,"nodeType":867},{},[],"There are also several technical reasons why bad passwords persist:",{"data":42784,"content":42785,"nodeType":3126},{},[42786,42813],{"data":42787,"content":42788,"nodeType":3061},{},[42789],{"data":42790,"content":42791,"nodeType":881},{},[42792,42795,42805,42809],{"data":42793,"marks":42794,"value":21,"nodeType":867},{},[],{"data":42796,"content":42798,"nodeType":876},{"uri":42797},"https://www.ncsc.gov.uk/blog-post/passkeys-not-perfect-getting-better",[42799],{"data":42800,"marks":42801,"value":42804,"nodeType":867},{},[42802,42803],{"type":1040},{"type":916},"Going passwordless is hard",{"data":42806,"marks":42807,"value":3679,"nodeType":867},{},[42808],{"type":916},{"data":42810,"marks":42811,"value":42812,"nodeType":867},{},[],"because it requires a large investment of time, money, and training for end-users. In environments with a mix of older and newer infrastructure, it can be challenging to get complete coverage, and employees may struggle with the transition to device-based authentication (especially when they lose their device and aren’t familiar with how to regain account access).",{"data":42814,"content":42815,"nodeType":3061},{},[42816],{"data":42817,"content":42818,"nodeType":881},{},[42819,42824,42828,42837],{"data":42820,"marks":42821,"value":42823,"nodeType":867},{},[42822],{"type":916},"Many apps do not even provide a SAML option",{"data":42825,"marks":42826,"value":42827,"nodeType":867},{},[],", making it difficult to onboard every business app to SSO even once you know about them all. Last we checked, only about 30% of commonly used work apps supported SAML. Even when apps do provide the option, many charge the infamous “",{"data":42829,"content":42831,"nodeType":876},{"uri":42830},"https://sso.tax/",[42832],{"data":42833,"marks":42834,"value":42836,"nodeType":867},{},[42835],{"type":1040},"SSO tax",{"data":42838,"marks":42839,"value":42840,"nodeType":867},{},[],",” putting the feature behind enterprise plans.",{"data":42842,"content":42843,"nodeType":881},{},[42844,42849],{"data":42845,"marks":42846,"value":42848,"nodeType":867},{},[42847],{"type":916},"The impact:",{"data":42850,"marks":42851,"value":42852,"nodeType":867},{},[]," What ends up happening in many organizations is a patchwork of login methods, including passwords, passkeys, OIDC, and SAML. Looking at data from Push’s install base, we see on average around 15,000 accounts per 1,000 users, with 5,900+ outside of SSO — about 40%. ",{"data":42854,"content":42855,"nodeType":881},{},[42856],{"data":42857,"marks":42858,"value":42859,"nodeType":867},{},[],"That means more — not less — for a security and IT team to manage, often without the visibility or control they need to do so effectively.",{"data":42861,"content":42865,"nodeType":890},{"target":42862},{"sys":42863},{"id":42864,"type":887,"linkType":888},"2QnWVpPYRyJQaQ5TuKSSLp",[],{"data":42867,"content":42868,"nodeType":998},{},[42869],{"data":42870,"marks":42871,"value":42873,"nodeType":867},{},[42872],{"type":916},"Human reasons",{"data":42875,"content":42876,"nodeType":881},{},[42877],{"data":42878,"marks":42879,"value":42880,"nodeType":867},{},[],"Finally, there are a lot of human reasons why poor passwords persist, all of them familiar and intractable:",{"data":42882,"content":42883,"nodeType":3126},{},[42884,42899],{"data":42885,"content":42886,"nodeType":3061},{},[42887],{"data":42888,"content":42889,"nodeType":881},{},[42890,42895],{"data":42891,"marks":42892,"value":42894,"nodeType":867},{},[42893],{"type":916},"Password change fatigue",{"data":42896,"marks":42897,"value":42898,"nodeType":867},{},[],", resulting in weak and reused passwords — often driven by incomplete adoption of enterprise password managers or outdated password security policies that require users to rotate passwords frequently. ",{"data":42900,"content":42901,"nodeType":3061},{},[42902],{"data":42903,"content":42904,"nodeType":881},{},[42905,42910],{"data":42906,"marks":42907,"value":42909,"nodeType":867},{},[42908],{"type":916},"Shortcuts that busy humans take",{"data":42911,"marks":42912,"value":42913,"nodeType":867},{},[]," to get work done on a daily basis, including reusing passwords across personal and corporate accounts, storing passwords insecurely, and using easier-to-remember passwords over secure, complex ones.  ",{"data":42915,"content":42916,"nodeType":881},{},[42917,42921,42925,42934],{"data":42918,"marks":42919,"value":42848,"nodeType":867},{},[42920],{"type":916},{"data":42922,"marks":42923,"value":42924,"nodeType":867},{},[]," When there’s a large, complex, and largely invisible attack surface made up of these online corporate identities, adversaries profit. Just look at any of the ",{"data":42926,"content":42928,"nodeType":876},{"uri":42927},"https://pushsecurity.com/resources/2024-identity-attacks",[42929],{"data":42930,"marks":42931,"value":42933,"nodeType":867},{},[42932],{"type":1040},"major identity attacks",{"data":42935,"marks":42936,"value":42937,"nodeType":867},{},[]," of the past year, some of which used password-spraying and credential-stuffing techniques to compromise accounts and pivot to high-value systems and data.",{"data":42939,"content":42940,"nodeType":881},{},[42941],{"data":42942,"marks":42943,"value":42944,"nodeType":867},{},[],"Password reuse also extends the blast radius for any account takeover incident when MFA is missing — a gap that occurs more often than you may think. Typically, 37% of logins observed by Push upon initial deployment into a new customer environment do not use any form of MFA.",{"data":42946,"content":42947,"nodeType":1433},{},[42948],{"data":42949,"content":42950,"nodeType":881},{},[42951],{"data":42952,"marks":42953,"value":42954,"nodeType":867},{},[],"2 in 5 logins observed by Push upon initial deployment into a new customer environment do not use any form of MFA.",{"data":42956,"content":42957,"nodeType":908},{},[],{"data":42959,"content":42960,"nodeType":918},{},[42961],{"data":42962,"marks":42963,"value":42964,"nodeType":867},{},[],"Why identity posture matters more in a SaaS-first world",{"data":42966,"content":42967,"nodeType":881},{},[42968,42972,42981],{"data":42969,"marks":42970,"value":42971,"nodeType":867},{},[],"When most work now happens via the browser on web-based applications, the stakes are even higher for preventing account takeover. That’s because the way that attacks occur in a SaaS environment is ",{"data":42973,"content":42975,"nodeType":876},{"uri":42974},"https://pushsecurity.com/blog/shifting-detection-left-for-more-effective-itdr/",[42976],{"data":42977,"marks":42978,"value":42980,"nodeType":867},{},[42979],{"type":1040},"very different",{"data":42982,"marks":42983,"value":42984,"nodeType":867},{},[]," from traditional network attacks, and there are few effective ways to detect and respond post-account compromise.",{"data":42986,"content":42987,"nodeType":881},{},[42988],{"data":42989,"marks":42990,"value":42991,"nodeType":867},{},[],"The average SaaS attack path looks like this:",{"data":42993,"content":42994,"nodeType":3126},{},[42995,43005,43015],{"data":42996,"content":42997,"nodeType":3061},{},[42998],{"data":42999,"content":43000,"nodeType":881},{},[43001],{"data":43002,"marks":43003,"value":43004,"nodeType":867},{},[],"Attackers gain control of legitimate employee accounts using stolen credentials or via password-spraying or credential-stuffing techniques.",{"data":43006,"content":43007,"nodeType":3061},{},[43008],{"data":43009,"content":43010,"nodeType":881},{},[43011],{"data":43012,"marks":43013,"value":43014,"nodeType":867},{},[],"Attackers exfiltrate data.",{"data":43016,"content":43017,"nodeType":3061},{},[43018],{"data":43019,"content":43020,"nodeType":881},{},[43021],{"data":43022,"marks":43023,"value":43024,"nodeType":867},{},[],"The end.",{"data":43026,"content":43027,"nodeType":881},{},[43028],{"data":43029,"marks":43030,"value":43031,"nodeType":867},{},[],"Compare that to traditional network or enterprise cloud attacks, which usually involve more complex lateral movement, privilege escalation, and defense evasion.",{"data":43033,"content":43034,"nodeType":881},{},[43035],{"data":43036,"marks":43037,"value":43038,"nodeType":867},{},[],"With limited log data and few response capabilities provided by most SaaS apps, security teams also have few good options to stop the damage of an account takeover once one has occurred. ",{"data":43040,"content":43041,"nodeType":881},{},[43042],{"data":43043,"marks":43044,"value":43045,"nodeType":867},{},[],"That’s why at Push, we advocate for “shifting left,” and preventing account takeover before it happens.",{"data":43047,"content":43051,"nodeType":890},{"target":43048},{"sys":43049},{"id":43050,"type":887,"linkType":888},"6wIzMu3jBhaas9jtpV48bz",[],{"data":43053,"content":43054,"nodeType":908},{},[],{"data":43056,"content":43057,"nodeType":918},{},[43058],{"data":43059,"marks":43060,"value":43061,"nodeType":867},{},[],"How Push helps you ensure strong passwords",{"data":43063,"content":43064,"nodeType":881},{},[43065],{"data":43066,"marks":43067,"value":43068,"nodeType":867},{},[],"There are four capabilities that security teams need in order to regain control over password security issues across their corporate accounts. Here’s how Push accomplishes each one.",{"data":43070,"content":43071,"nodeType":998},{},[43072],{"data":43073,"marks":43074,"value":43076,"nodeType":867},{},[43075],{"type":916},"1. A reliable inventory of all the apps that employees are using, including work apps and internal apps.",{"data":43078,"content":43079,"nodeType":881},{},[43080],{"data":43081,"marks":43082,"value":43083,"nodeType":867},{},[],"Push achieves this by deploying a browser agent to employee browsers that can directly observe their login activity, which feeds the data back into an admin console (or your SIEM/SOAR or other third-party system). You can enforce the installation of the agent using any MDM solution, on all major browsers.",{"data":43085,"content":43086,"nodeType":881},{},[43087],{"data":43088,"marks":43089,"value":43090,"nodeType":867},{},[],"Once the agent is activated, it begins immediately capturing employee logins and produces a real-time inventory of all your work and internal apps. Because Push observes the login directly in the browser, it can identify all the apps and accounts being used by your employees — both managed and unmanaged (shadow IT).",{"data":43092,"content":43093,"nodeType":881},{},[43094,43098,43103],{"data":43095,"marks":43096,"value":43097,"nodeType":867},{},[],"You can also configure Push to monitor ",{"data":43099,"marks":43100,"value":43102,"nodeType":867},{},[43101],{"type":1431},"any",{"data":43104,"marks":43105,"value":43106,"nodeType":867},{},[]," login to a work app, regardless of the associated email domain of the employee. This means you can monitor personal account logins to apps that are commonly used for work.",{"data":43108,"content":43112,"nodeType":890},{"target":43109},{"sys":43110},{"id":43111,"type":887,"linkType":888},"4ctCB7kBscj12BnfHhk3ro",[],{"data":43114,"content":43115,"nodeType":998},{},[43116],{"data":43117,"marks":43118,"value":43120,"nodeType":867},{},[43119],{"type":916},"2. A way to identify the login methods an account is using, whether that’s SAML, OIDC, or password.",{"data":43122,"content":43123,"nodeType":881},{},[43124],{"data":43125,"marks":43126,"value":43127,"nodeType":867},{},[],"Again, because Push observes the login event, it can analyze the authentication method or methods in use by a given account. Push tells you which SSO accounts still have passwords associated with them, and which authentication methods are being actively used.",{"data":43129,"content":43133,"nodeType":890},{"target":43130},{"sys":43131},{"id":43132,"type":887,"linkType":888},"pVD238hZ331gjWalDTM1q",[],{"data":43135,"content":43136,"nodeType":998},{},[43137],{"data":43138,"marks":43139,"value":43141,"nodeType":867},{},[43140],{"type":916},"3. A method for analyzing whether an employee is using secure passwords on all their accounts.",{"data":43143,"content":43144,"nodeType":881},{},[43145,43149,43158],{"data":43146,"marks":43147,"value":43148,"nodeType":867},{},[],"Using Push, you can also check the posture of all your employee accounts. The browser agent accomplishes this by ",{"data":43150,"content":43152,"nodeType":876},{"uri":43151},"https://pushsecurity.com/help/10065#start",[43153],{"data":43154,"marks":43155,"value":43157,"nodeType":867},{},[43156],{"type":1040},"creating a salted hash",{"data":43159,"marks":43160,"value":43161,"nodeType":867},{},[]," of a user’s observed password and then taking the first 8 characters of that hash to store locally in the browser.",{"data":43163,"content":43164,"nodeType":881},{},[43165],{"data":43166,"marks":43167,"value":43168,"nodeType":867},{},[],"This allows Push to analyze whether the password is weak (comparing the hash to a list of 10,000 common basewords and common permutations); or reused across accounts.",{"data":43170,"content":43171,"nodeType":881},{},[43172,43176,43185,43189,43198],{"data":43173,"marks":43174,"value":43175,"nodeType":867},{},[],"Push can also identify when employee passwords have ",{"data":43177,"content":43179,"nodeType":876},{"uri":43178},"https://pushsecurity.com/help/10066#start",[43180],{"data":43181,"marks":43182,"value":43184,"nodeType":867},{},[43183],{"type":1040},"appeared in a public breach list",{"data":43186,"marks":43187,"value":43188,"nodeType":867},{},[]," using the Have I Been Pwned service, using a k-anonymized hash. Using similar secure methods, Push can detect when employees are sharing account credentials, whether they’re using a ",{"data":43190,"content":43192,"nodeType":876},{"uri":43191},"https://pushsecurity.com/help/10085/#start",[43193],{"data":43194,"marks":43195,"value":43197,"nodeType":867},{},[43196],{"type":1040},"password manager",{"data":43199,"marks":43200,"value":43201,"nodeType":867},{},[],", and which one.",{"data":43203,"content":43204,"nodeType":881},{},[43205,43209,43218],{"data":43206,"marks":43207,"value":43208,"nodeType":867},{},[],"Using Push’s ",{"data":43210,"content":43211,"nodeType":876},{"uri":33087},[43212],{"data":43213,"marks":43214,"value":43217,"nodeType":867},{},[43215,43216],{"type":1040},{"type":916},"Stolen credentials detection",{"data":43219,"marks":43220,"value":43221,"nodeType":867},{},[]," feature, you can also get alerted when an employee is using credentials that match those for sale in criminal forums. Push integrates with commercial threat intelligence sources to perform these matches, and you can also bring your own TI using the Push REST API to perform additional checks for in-use stolen creds. This check still happens locally in the browser, so no hashes are sent to third-party systems.",{"data":43223,"content":43226,"nodeType":890},{"target":43224},{"sys":43225},{"id":40114,"type":887,"linkType":888},[],{"data":43228,"content":43229,"nodeType":881},{},[43230,43234,43243],{"data":43231,"marks":43232,"value":43233,"nodeType":867},{},[],"If you configure Push to also monitor for employees who are logging in to work apps using ",{"data":43235,"content":43237,"nodeType":876},{"uri":43236},"https://pushsecurity.com/help/10105#start",[43238],{"data":43239,"marks":43240,"value":43242,"nodeType":867},{},[43241],{"type":1040},"personal email addresses",{"data":43244,"marks":43245,"value":43246,"nodeType":867},{},[]," or any non-corporate email, Push can identify when personal accounts and work accounts are reusing passwords for the same work application.",{"data":43248,"content":43249,"nodeType":881},{},[43250,43254,43263],{"data":43251,"marks":43252,"value":43253,"nodeType":867},{},[],"Using the Push ",{"data":43255,"content":43257,"nodeType":876},{"uri":43256},"https://pushsecurity.com/help/audience/administrators/docs/getting-started/#api-and-webhooks",[43258],{"data":43259,"marks":43260,"value":43262,"nodeType":867},{},[43261],{"type":1040},"REST API and webhooks",{"data":43264,"marks":43265,"value":43266,"nodeType":867},{},[],", you can get alerted when Push raises a security finding for an account, and when a finding is resolved.",{"data":43268,"content":43269,"nodeType":998},{},[43270],{"data":43271,"marks":43272,"value":43274,"nodeType":867},{},[43273],{"type":916},"4. The ability to solve any issues at scale, including remediating bad passwords and enforcing MFA, even on apps where the security team doesn’t have administrative control.",{"data":43276,"content":43277,"nodeType":881},{},[43278],{"data":43279,"marks":43280,"value":43281,"nodeType":867},{},[],"Finally, you can enforce self-remediation workflows using Push’s position in the browser, right where employees are working. ",{"data":43283,"content":43284,"nodeType":881},{},[43285],{"data":43286,"marks":43287,"value":43288,"nodeType":867},{},[],"Push recently released a new in-browser control to enforce strong passwords. It works by detecting when an employee has a password security issue, and then prompting them to update their password by displaying a customizable banner message when they log in to the affected account.",{"data":43290,"content":43294,"nodeType":890},{"target":43291},{"sys":43292},{"id":43293,"type":887,"linkType":888},"4IfBLaE66CJSsb5h44vSNp",[],{"data":43296,"content":43297,"nodeType":881},{},[43298,43302,43311],{"data":43299,"marks":43300,"value":43301,"nodeType":867},{},[],"This control complements an existing ",{"data":43303,"content":43305,"nodeType":876},{"uri":43304},"https://pushsecurity.com/blog/enforce-mfa-on-third-party-apps/",[43306],{"data":43307,"marks":43308,"value":43310,"nodeType":867},{},[43309],{"type":1040},"MFA enforcement",{"data":43312,"marks":43313,"value":43314,"nodeType":867},{},[]," guardrail, which uses a similar workflow to prompt employees to register for MFA on apps where it’s missing.",{"data":43316,"content":43317,"nodeType":908},{},[],{"data":43319,"content":43320,"nodeType":918},{},[43321],{"data":43322,"marks":43323,"value":43325,"nodeType":867},{},[43324],{"type":916},"A closer look at password enforcement",{"data":43327,"content":43328,"nodeType":881},{},[43329,43333,43337],{"data":43330,"marks":43331,"value":43332,"nodeType":867},{},[],"In the spirit of helping users do the right thing, we designed the",{"data":43334,"marks":43335,"value":3679,"nodeType":867},{},[43336],{"type":916},{"data":43338,"marks":43339,"value":43340,"nodeType":867},{},[],"password enforcement control to meet users where they are, in the most relevant context where they can fix the problem. ",{"data":43342,"content":43343,"nodeType":881},{},[43344],{"data":43345,"marks":43346,"value":43347,"nodeType":867},{},[],"Because this control is powered by the Push browser agent, security teams don’t need administrative control over every app where password accounts exist — which often isn’t practical for all the reasons we reviewed earlier. Instead, they can use Push to prompt employees to fix the issue themselves.",{"data":43349,"content":43350,"nodeType":881},{},[43351],{"data":43352,"marks":43353,"value":43354,"nodeType":867},{},[],"Here’s a closer look at how it works:",{"data":43356,"content":43357,"nodeType":3126},{},[43358,43385,43395],{"data":43359,"content":43360,"nodeType":3061},{},[43361],{"data":43362,"content":43363,"nodeType":881},{},[43364,43368,43372,43376,43381],{"data":43365,"marks":43366,"value":43367,"nodeType":867},{},[],"You can enable ",{"data":43369,"marks":43370,"value":42596,"nodeType":867},{},[43371],{"type":916},{"data":43373,"marks":43374,"value":43375,"nodeType":867},{},[]," from the tile on the ",{"data":43377,"marks":43378,"value":43380,"nodeType":867},{},[43379],{"type":916},"Controls",{"data":43382,"marks":43383,"value":43384,"nodeType":867},{},[]," page of the Push admin console. ",{"data":43386,"content":43387,"nodeType":3061},{},[43388],{"data":43389,"content":43390,"nodeType":881},{},[43391],{"data":43392,"marks":43393,"value":43394,"nodeType":867},{},[],"Using the rule editor, select whether you want to apply the control for all employees, or just specific groups or individuals, and which apps it should apply to. You can also select which types of password security issues you want to prompt users about.",{"data":43396,"content":43397,"nodeType":3061},{},[43398],{"data":43399,"content":43400,"nodeType":881},{},[43401],{"data":43402,"marks":43403,"value":43404,"nodeType":867},{},[],"Then customize the message that employees will see. Push will then automatically display the banner based on your criteria. Where possible, Push will include a link in the banner that takes employees directly to the page in the app where they can change their password — or you can add a link yourself.",{"data":43406,"content":43410,"nodeType":890},{"target":43407},{"sys":43408},{"id":43409,"type":887,"linkType":888},"shpVOAMlk7OE1mWrE9h8S",[],{"data":43412,"content":43413,"nodeType":881},{},[43414],{"data":43415,"marks":43416,"value":43417,"nodeType":867},{},[],"Once the password has been changed and Push verifies that the new password is strong, you’ll see the security finding cleared from the account record in the admin console and the banner will no longer display to the end-user.",{"data":43419,"content":43420,"nodeType":881},{},[43421],{"data":43422,"marks":43423,"value":43424,"nodeType":867},{},[],"Push also sends webhook events when:",{"data":43426,"content":43427,"nodeType":3126},{},[43428,43438,43448,43458],{"data":43429,"content":43430,"nodeType":3061},{},[43431],{"data":43432,"content":43433,"nodeType":881},{},[43434],{"data":43435,"marks":43436,"value":43437,"nodeType":867},{},[],"A banner is displayed",{"data":43439,"content":43440,"nodeType":3061},{},[43441],{"data":43442,"content":43443,"nodeType":881},{},[43444],{"data":43445,"marks":43446,"value":43447,"nodeType":867},{},[],"A user clicks the link in the banner to take action",{"data":43449,"content":43450,"nodeType":3061},{},[43451],{"data":43452,"content":43453,"nodeType":881},{},[43454],{"data":43455,"marks":43456,"value":43457,"nodeType":867},{},[],"A password is updated",{"data":43459,"content":43460,"nodeType":3061},{},[43461],{"data":43462,"content":43463,"nodeType":881},{},[43464],{"data":43465,"marks":43466,"value":43467,"nodeType":867},{},[],"A password security finding is resolved",{"data":43469,"content":43470,"nodeType":908},{},[],{"data":43472,"content":43473,"nodeType":918},{},[43474],{"data":43475,"marks":43476,"value":43478,"nodeType":867},{},[43477],{"type":916},"Where to begin",{"data":43480,"content":43481,"nodeType":881},{},[43482],{"data":43483,"marks":43484,"value":43485,"nodeType":867},{},[],"Most organizations we work with deploy the Push agent first to get an initial understanding of their attack surface and account posture issues. Then we recommend enabling the one-two punch of MFA and strong password enforcement guardrails. You can use both controls in tandem, and Push will first seek to resolve the password issues on a given account, and then prompt the user to register for MFA.",{"data":43487,"content":43488,"nodeType":908},{},[],{"data":43490,"content":43491,"nodeType":918},{},[43492],{"data":43493,"marks":43494,"value":43495,"nodeType":867},{},[],"Find out more",{"data":43497,"content":43498,"nodeType":881},{},[43499,43503,43510],{"data":43500,"marks":43501,"value":43502,"nodeType":867},{},[],"If you want to learn more about how Push helps you to detect and defeat common identity attack techniques like AiTM phishing, credential stuffing, and session hijacking while improving your workforce identity posture, book some time with one of our team for a ",{"data":43504,"content":43505,"nodeType":876},{"uri":2362},[43506],{"data":43507,"marks":43508,"value":3399,"nodeType":867},{},[43509],{"type":1040},{"data":43511,"marks":43512,"value":1947,"nodeType":867},{},[],"Detects when employees have weak, reused, or stolen passwords and guide them to update their password using in-browser messaging on any app. ","2025-03-25T00:00:00.000Z",{"items":43516},[43517,43519],{"sys":43518,"name":297},{"id":5646},{"sys":43520,"name":2547},{"id":2546},{"items":43522},[43523],{"fullName":4372,"firstName":4373,"jobTitle":4374,"profilePicture":43524},{"url":4376},"blog/employee-identity-verification-codes-release",{"json":43527},{"data":43528,"content":43529,"nodeType":1640},{},[43530],{"data":43531,"content":43532,"nodeType":881},{},[43533],{"data":43534,"marks":43535,"value":43536,"nodeType":867},{},[],"Attackers like Scattered Spider are tricking help desks into reseting MFA on sensitive apps. Find out how Push can stop them in the browser.\n",{"id":27642,"publishedAt":43538},"2026-08-12T11:57:08.613Z",{"items":43540},[43541],{"sys":43542,"name":297},{"id":5646},{"items":43544},[43545,43547,43549,43551,43553,43555,43557],{"sys":43546,"name":413,"slug":414,"tier":31},{"id":410},{"sys":43548,"name":297,"slug":298,"tier":31},{"id":294},{"sys":43550,"name":342,"slug":343,"tier":31},{"id":339},{"sys":43552,"name":650,"slug":651,"tier":45},{"id":647},{"sys":43554,"name":607,"slug":608,"tier":45},{"id":604},{"sys":43556,"name":457,"slug":458,"tier":45},{"id":454},{"sys":43558,"name":404,"slug":405,"tier":45},{"id":401},"OkYaBgB1YDarn9Eczj5pPuCsLsMZ4fen4GPASrYm0AQ",{"id":43561,"title":43562,"authorsCollection":43563,"content":43571,"extension":228,"faqItemsCollection":44106,"faqTitle":59,"featured":6,"hashTags":59,"meta":44108,"metaTitle":44109,"ogImage":59,"postType":44110,"publishedDate":44111,"relatedBlogPostsCollection":44112,"slug":44617,"stem":44618,"subtitle":59,"summary":44619,"synopsis":44630,"sys":44631,"tagsCollection":44634,"topicsCollection":44638,"__hash__":44654},"blog/blog/product-release-june-2025.json","Product release: June 2025",{"items":43564},[43565],{"fullName":43566,"firstName":43567,"jobTitle":43568,"socialLinks":59,"profilePicture":43569},"Andy Waugh","Andy","VP Product",{"url":43570},"https://images.ctfassets.net/y1cdw1ablpvd/3Rf76rJn6S9inMb4dUnAIJ/0a787f8141d05b95300e2fe77c4493fa/DSC_6868.jpg",{"json":43572,"links":44040},{"data":43573,"content":43574,"nodeType":1640},{},[43575,43582,43655,43661,43677,43684,43690,43708,43714,43730,43737,43744,43764,43769,43775,43789,43796,43802,43820,43826,43842,43849,43856,43862,43880,43886,43902,43909,43915,43931,43937,43968,43984,43990,44006,44012,44028,44034],{"data":43576,"content":43577,"nodeType":918},{},[43578],{"data":43579,"marks":43580,"value":43581,"nodeType":867},{},[],"What's new this month:",{"data":43583,"content":43584,"nodeType":3126},{},[43585,43595,43605,43615,43625,43635,43645],{"data":43586,"content":43587,"nodeType":3061},{},[43588],{"data":43589,"content":43590,"nodeType":881},{},[43591],{"data":43592,"marks":43593,"value":43594,"nodeType":867},{},[],"Streamline investigations with Detections page",{"data":43596,"content":43597,"nodeType":3061},{},[43598],{"data":43599,"content":43600,"nodeType":881},{},[43601],{"data":43602,"marks":43603,"value":43604,"nodeType":867},{},[],"New Labs feature: Employee verification codes",{"data":43606,"content":43607,"nodeType":3061},{},[43608],{"data":43609,"content":43610,"nodeType":881},{},[43611],{"data":43612,"marks":43613,"value":43614,"nodeType":867},{},[],"Enforce strong passwords with in-browser guardrails",{"data":43616,"content":43617,"nodeType":3061},{},[43618],{"data":43619,"content":43620,"nodeType":881},{},[43621],{"data":43622,"marks":43623,"value":43624,"nodeType":867},{},[],"Merge related employee records",{"data":43626,"content":43627,"nodeType":3061},{},[43628],{"data":43629,"content":43630,"nodeType":881},{},[43631],{"data":43632,"marks":43633,"value":43634,"nodeType":867},{},[],"Customize your webhook events",{"data":43636,"content":43637,"nodeType":3061},{},[43638],{"data":43639,"content":43640,"nodeType":881},{},[43641],{"data":43642,"marks":43643,"value":43644,"nodeType":867},{},[],"Create rules for phishing tool detection and MFA enforcement",{"data":43646,"content":43647,"nodeType":3061},{},[43648],{"data":43649,"content":43650,"nodeType":881},{},[43651],{"data":43652,"marks":43653,"value":43654,"nodeType":867},{},[],"New integration for Microsoft Sentinel",{"data":43656,"content":43657,"nodeType":918},{},[43658],{"data":43659,"marks":43660,"value":43594,"nodeType":867},{},[],{"data":43662,"content":43663,"nodeType":881},{},[43664,43668,43673],{"data":43665,"marks":43666,"value":43667,"nodeType":867},{},[],"You can now receive and triage detections in the Push admin console (or get them via the Push REST API, webhooks or ChatOps), giving you a ",{"data":43669,"marks":43670,"value":43672,"nodeType":867},{},[43671],{"type":916},"single view of all the security events that Push has detected",{"data":43674,"marks":43675,"value":43676,"nodeType":867},{},[],", such as AiTM phishing, stolen creds, or blocked URLs being visited by employees.",{"data":43678,"content":43679,"nodeType":881},{},[43680],{"data":43681,"marks":43682,"value":43683,"nodeType":867},{},[]," Use the additional telemetry about each detection, such as timestamp, detection URL, type of phishkit detected, Push response action, etc., to understand how to triage the incident. ",{"data":43685,"content":43689,"nodeType":890},{"target":43686},{"sys":43687},{"id":43688,"type":887,"linkType":888},"53BOccCQ72Yo3oCSUWVFXn",[],{"data":43691,"content":43692,"nodeType":881},{},[43693,43696,43705],{"data":43694,"marks":43695,"value":21,"nodeType":867},{},[],{"data":43697,"content":43701,"nodeType":3447},{"target":43698},{"sys":43699},{"id":43700,"type":887,"linkType":888},"6jbLw9Wi2JuddCXL6ncrCV",[43702],{"data":43703,"marks":43704,"value":4330,"nodeType":867},{},[],{"data":43706,"marks":43707,"value":21,"nodeType":867},{},[],{"data":43709,"content":43710,"nodeType":918},{},[43711],{"data":43712,"marks":43713,"value":43604,"nodeType":867},{},[],{"data":43715,"content":43716,"nodeType":881},{},[43717,43721,43726],{"data":43718,"marks":43719,"value":43720,"nodeType":867},{},[],"Employees can now get a 6-digit verification code via the Push browser extension that you can use to ",{"data":43722,"marks":43723,"value":43725,"nodeType":867},{},[43724],{"type":916},"validate that your help desk is speaking to someone from your organization",{"data":43727,"marks":43728,"value":43729,"nodeType":867},{},[],".  ",{"data":43731,"content":43732,"nodeType":881},{},[43733],{"data":43734,"marks":43735,"value":43736,"nodeType":867},{},[],"The verification code is the same for all employees at a given organization, and resets every 24 hours. If your help desk needs to verify that they’re speaking to an employee, they can ask them to open the details tray for their Push extension and verify the code.",{"data":43738,"content":43739,"nodeType":881},{},[43740],{"data":43741,"marks":43742,"value":43743,"nodeType":867},{},[],"Employee verification codes is a Labs feature, which means it’s available on an early-access basis and we're particularly interested in hearing from you if this is a problem you're interested in solving using Push. ",{"data":43745,"content":43746,"nodeType":881},{},[43747,43750,43754,43757,43761],{"data":43748,"marks":43749,"value":36715,"nodeType":867},{},[],{"data":43751,"marks":43752,"value":36720,"nodeType":867},{},[43753],{"type":916},{"data":43755,"marks":43756,"value":36724,"nodeType":867},{},[],{"data":43758,"marks":43759,"value":36729,"nodeType":867},{},[43760],{"type":916},{"data":43762,"marks":43763,"value":36733,"nodeType":867},{},[],{"data":43765,"content":43768,"nodeType":890},{"target":43766},{"sys":43767},{"id":27615,"type":887,"linkType":888},[],{"data":43770,"content":43771,"nodeType":918},{},[43772],{"data":43773,"marks":43774,"value":43614,"nodeType":867},{},[],{"data":43776,"content":43777,"nodeType":881},{},[43778,43782,43786],{"data":43779,"marks":43780,"value":43781,"nodeType":867},{},[],"Prompt your employees to change an insecure password using Push’s new in-browser guardrail, ",{"data":43783,"marks":43784,"value":42596,"nodeType":867},{},[43785],{"type":916},{"data":43787,"marks":43788,"value":1253,"nodeType":867},{},[],{"data":43790,"content":43791,"nodeType":881},{},[43792],{"data":43793,"marks":43794,"value":43795,"nodeType":867},{},[],"You can select which password security issues you want to remediate, and which apps you want to target using the configuration rules for this control. Then, when Push observes a password issue, it will automatically display a banner to end-users prompting them to change their password.",{"data":43797,"content":43801,"nodeType":890},{"target":43798},{"sys":43799},{"id":43800,"type":887,"linkType":888},"6ZcsdzYPxLAE1K170mQPHE",[],{"data":43803,"content":43804,"nodeType":881},{},[43805,43808,43817],{"data":43806,"marks":43807,"value":21,"nodeType":867},{},[],{"data":43809,"content":43813,"nodeType":3447},{"target":43810},{"sys":43811},{"id":43812,"type":887,"linkType":888},"2dAP36chda6ZDGKzw0Itfs",[43814],{"data":43815,"marks":43816,"value":4330,"nodeType":867},{},[],{"data":43818,"marks":43819,"value":21,"nodeType":867},{},[],{"data":43821,"content":43822,"nodeType":918},{},[43823],{"data":43824,"marks":43825,"value":43624,"nodeType":867},{},[],{"data":43827,"content":43828,"nodeType":881},{},[43829,43833,43838],{"data":43830,"marks":43831,"value":43832,"nodeType":867},{},[],"If you have employees using multiple email addresses, you can ",{"data":43834,"marks":43835,"value":43837,"nodeType":867},{},[43836],{"type":916},"now merge those records in the Push platform",{"data":43839,"marks":43840,"value":43841,"nodeType":867},{},[]," so they can be treated as a single employee. ",{"data":43843,"content":43844,"nodeType":881},{},[43845],{"data":43846,"marks":43847,"value":43848,"nodeType":867},{},[],"A common use case for merging employee records is when you have employees with a user account and an administrator account. By merging records in cases like this, you can resolve incorrect shared account findings and correct your license usage so only the primary employee record consumes a license. ",{"data":43850,"content":43851,"nodeType":881},{},[43852],{"data":43853,"marks":43854,"value":43855,"nodeType":867},{},[],"You can also merge records programmatically via the Push REST API. This is helpful if you have a predictable pattern for usernames you're mapping.",{"data":43857,"content":43861,"nodeType":890},{"target":43858},{"sys":43859},{"id":43860,"type":887,"linkType":888},"3xcEqhSUZ1VmZTsgSOS4xH",[],{"data":43863,"content":43864,"nodeType":881},{},[43865,43868,43877],{"data":43866,"marks":43867,"value":21,"nodeType":867},{},[],{"data":43869,"content":43873,"nodeType":3447},{"target":43870},{"sys":43871},{"id":43872,"type":887,"linkType":888},"3RIMjhmhJcHC2V7Lkrhvj2",[43874],{"data":43875,"marks":43876,"value":4330,"nodeType":867},{},[],{"data":43878,"marks":43879,"value":21,"nodeType":867},{},[],{"data":43881,"content":43882,"nodeType":918},{},[43883],{"data":43884,"marks":43885,"value":43634,"nodeType":867},{},[],{"data":43887,"content":43888,"nodeType":881},{},[43889,43893,43898],{"data":43890,"marks":43891,"value":43892,"nodeType":867},{},[],"You can now ",{"data":43894,"marks":43895,"value":43897,"nodeType":867},{},[43896],{"type":916},"select which events you want when creating a webhook",{"data":43899,"marks":43900,"value":43901,"nodeType":867},{},[]," in the Push platform. For example, if you want to build an automation around specific Push events or send only Push detection alerts to your SIEM, you can elect to send just those events to your configured destinations. ",{"data":43903,"content":43904,"nodeType":881},{},[43905],{"data":43906,"marks":43907,"value":43908,"nodeType":867},{},[],"You can select which events you want to consume when configuring a new webhook via the Push admin console.",{"data":43910,"content":43914,"nodeType":890},{"target":43911},{"sys":43912},{"id":43913,"type":887,"linkType":888},"755nABuK9KGdHHwWNqDtmS",[],{"data":43916,"content":43917,"nodeType":881},{},[43918,43921,43928],{"data":43919,"marks":43920,"value":21,"nodeType":867},{},[],{"data":43922,"content":43924,"nodeType":876},{"uri":43923},"https://pushsecurity.redoc.ly/webhooks-v1",[43925],{"data":43926,"marks":43927,"value":4330,"nodeType":867},{},[],{"data":43929,"marks":43930,"value":21,"nodeType":867},{},[],{"data":43932,"content":43933,"nodeType":918},{},[43934],{"data":43935,"marks":43936,"value":43644,"nodeType":867},{},[],{"data":43938,"content":43939,"nodeType":881},{},[43940,43944,43949,43953,43958,43961,43965],{"data":43941,"marks":43942,"value":43943,"nodeType":867},{},[],"We’re continuing to ",{"data":43945,"marks":43946,"value":43948,"nodeType":867},{},[43947],{"type":916},"add configuration rule capabilities to security controls",{"data":43950,"marks":43951,"value":43952,"nodeType":867},{},[]," in the Push platform, including for ",{"data":43954,"marks":43955,"value":43957,"nodeType":867},{},[43956],{"type":916},"phishing tool detection",{"data":43959,"marks":43960,"value":2063,"nodeType":867},{},[],{"data":43962,"marks":43963,"value":43310,"nodeType":867},{},[43964],{"type":916},{"data":43966,"marks":43967,"value":1253,"nodeType":867},{},[],{"data":43969,"content":43970,"nodeType":881},{},[43971,43975,43980],{"data":43972,"marks":43973,"value":43974,"nodeType":867},{},[],"With these config rules, you can scope a control to specific employees or employee groups, and carve out exemptions if you like. You can also set the control to apply to specific apps, or set the ",{"data":43976,"marks":43977,"value":43979,"nodeType":867},{},[43978],{"type":916},"Mode",{"data":43981,"marks":43982,"value":43983,"nodeType":867},{},[]," (e.g. Monitor, Warn, or Block), where applicable.",{"data":43985,"content":43989,"nodeType":890},{"target":43986},{"sys":43987},{"id":43988,"type":887,"linkType":888},"2eKYcSet4tkd6UEffzdaaa",[],{"data":43991,"content":43992,"nodeType":881},{},[43993,43996,44003],{"data":43994,"marks":43995,"value":21,"nodeType":867},{},[],{"data":43997,"content":43999,"nodeType":876},{"uri":43998},"/help/10121/#how-to-create-a-configuration-rule",[44000],{"data":44001,"marks":44002,"value":4330,"nodeType":867},{},[],{"data":44004,"marks":44005,"value":21,"nodeType":867},{},[],{"data":44007,"content":44008,"nodeType":918},{},[44009],{"data":44010,"marks":44011,"value":43654,"nodeType":867},{},[],{"data":44013,"content":44014,"nodeType":881},{},[44015,44019,44024],{"data":44016,"marks":44017,"value":44018,"nodeType":867},{},[],"Push now offers a Microsoft Sentinel integration to make it easier to send Push data to your Sentinel SIEM. You can start setting up your integration by going to ",{"data":44020,"marks":44021,"value":44023,"nodeType":867},{},[44022],{"type":916},"Settings > Integrations",{"data":44025,"marks":44026,"value":44027,"nodeType":867},{},[]," in the Push admin console and selecting the Sentinel tile.",{"data":44029,"content":44033,"nodeType":890},{"target":44030},{"sys":44031},{"id":44032,"type":887,"linkType":888},"5l5TIPvbOoNgauV7gUj7fy",[],{"data":44035,"content":44036,"nodeType":881},{},[44037],{"data":44038,"marks":44039,"value":21,"nodeType":867},{},[],{"entries":44041},{"inline":44042,"hyperlink":44043,"block":44060},[],[44044,44050,44055],{"sys":44045,"__typename":44046,"linkedFromParent":59,"title":44047,"slug":44048,"audience":44049},{"id":43700},"DocumentationPage","Administering Push","administering-push","administrators",{"sys":44051,"__typename":29753,"title":44052,"slug":44053,"articleId":44054},{"id":43812},"How does strong password enforcement work?","how-does-strong-password-enforcement-work",10129,{"sys":44056,"__typename":29753,"title":44057,"slug":44058,"articleId":44059},{"id":43872},"What happens when I merge employee records?","what-happens-when-i-merge-employee-records",10127,[44061,44068,44071,44078,44085,44092,44099],{"sys":44062,"__typename":1648,"title":44063,"caption":59,"layoutMode":59,"file":44064},{"id":43688},"Detections page overview - docs - Administering Push",{"url":44065,"width":44066,"height":44067},"https://images.ctfassets.net/y1cdw1ablpvd/2FcQEiNpkohhhv631S3QK/bf8a9d96cf6c4db9193c7e1c07cb31dd/detections_page_20250505.png",3014,1714,{"sys":44069,"__typename":1648,"title":29876,"caption":59,"layoutMode":59,"file":44070},{"id":27615},{"url":29878,"width":29879,"height":29880},{"sys":44072,"__typename":1648,"title":44073,"caption":59,"layoutMode":59,"file":44074},{"id":43800},"Password enforcement banner - KB 10129",{"url":44075,"width":44076,"height":44077},"https://images.ctfassets.net/y1cdw1ablpvd/3UDPMdxBrIOj6Uw3iDJxEF/bf3233e24a93e7bca9138bdb21a7ecc5/password_enforcement_banner.png",1440,809,{"sys":44079,"__typename":1648,"title":44080,"caption":59,"layoutMode":59,"file":44081},{"id":43860},"Merge employees - select primary - KB 10127",{"url":44082,"width":44083,"height":44084},"https://images.ctfassets.net/y1cdw1ablpvd/6UnGOsbhaHaORo0ltzEWiv/6e37edf71db832d6c61671cfbdb8afeb/merge_employees_primary_20250402.png",539,346,{"sys":44086,"__typename":1648,"title":44087,"caption":59,"layoutMode":59,"file":44088},{"id":43913},"Webhook event selection config screen - for June 2025 release notes",{"url":44089,"width":44090,"height":44091},"https://images.ctfassets.net/y1cdw1ablpvd/3IfutfvORDc67NnRcPE6Jk/4544e0c12224fddde9ae734564c5faac/webhook_select_events_20250528.png",1396,1708,{"sys":44093,"__typename":1648,"title":44094,"caption":59,"layoutMode":59,"file":44095},{"id":43988},"Phishing tool detection config rule slideout - for June 2025 release notes",{"url":44096,"width":44097,"height":44098},"https://images.ctfassets.net/y1cdw1ablpvd/1lSBIFFHjN7wJmoZIsTPwS/83e30221f36160b52c1f29720d03f012/config_rule_example_20250528.png",1468,1704,{"sys":44100,"__typename":1648,"title":44101,"caption":59,"layoutMode":59,"file":44102},{"id":44032},"Microsoft Sentinel tile on Settings - for release notes",{"url":44103,"width":44104,"height":44105},"https://images.ctfassets.net/y1cdw1ablpvd/2r29uCFauPYNnz2Jbs75Kc/4e180eea6c79ecc253919a651a63851a/sentinel_integration_tile_20250528.png",2498,1364,{"items":44107},[],{},"Push Security new product features for June 2025","release-notes","2025-06-09T00:00:00.000Z",{"items":44113},[44114],{"__typename":1742,"sys":44115,"content":44117,"title":44603,"synopsis":44604,"hashTags":59,"publishedDate":44605,"slug":44606,"tagsCollection":44607,"authorsCollection":44613},{"id":44116},"4Aln4tyCmoffCEg6yiUO4J",{"json":44118},{"data":44119,"content":44120,"nodeType":1640},{},[44121,44127,44180,44186,44201,44208,44277,44283,44301,44308,44324,44339,44345,44352,44370,44377,44392,44407,44414,44432,44439,44463,44470,44486,44492,44508,44548,44591,44597],{"data":44122,"content":44123,"nodeType":918},{},[44124],{"data":44125,"marks":44126,"value":43581,"nodeType":867},{},[],{"data":44128,"content":44129,"nodeType":3126},{},[44130,44140,44150,44160,44170],{"data":44131,"content":44132,"nodeType":3061},{},[44133],{"data":44134,"content":44135,"nodeType":881},{},[44136],{"data":44137,"marks":44138,"value":44139,"nodeType":867},{},[],"Add app banners to custom URLs",{"data":44141,"content":44142,"nodeType":3061},{},[44143],{"data":44144,"content":44145,"nodeType":881},{},[44146],{"data":44147,"marks":44148,"value":44149,"nodeType":867},{},[],"Self-service SAML for the Push platform",{"data":44151,"content":44152,"nodeType":3061},{},[44153],{"data":44154,"content":44155,"nodeType":881},{},[44156],{"data":44157,"marks":44158,"value":44159,"nodeType":867},{},[],"Support for Island enterprise browser",{"data":44161,"content":44162,"nodeType":3061},{},[44163],{"data":44164,"content":44165,"nodeType":881},{},[44166],{"data":44167,"marks":44168,"value":44169,"nodeType":867},{},[],"Landing page browser enrollment option",{"data":44171,"content":44172,"nodeType":3061},{},[44173],{"data":44174,"content":44175,"nodeType":881},{},[44176],{"data":44177,"marks":44178,"value":44179,"nodeType":867},{},[],"Improved filters for apps, accounts, and more",{"data":44181,"content":44182,"nodeType":918},{},[44183],{"data":44184,"marks":44185,"value":44139,"nodeType":867},{},[],{"data":44187,"content":44188,"nodeType":881},{},[44189,44192,44197],{"data":44190,"marks":44191,"value":43892,"nodeType":867},{},[],{"data":44193,"marks":44194,"value":44196,"nodeType":867},{},[44195],{"type":916},"add app banners to a custom-defined URL or URL pattern",{"data":44198,"marks":44199,"value":44200,"nodeType":867},{},[],". Previously, app banners displayed only on login and signup pages for configured apps. With this update, you can put them on any page you like. ",{"data":44202,"content":44203,"nodeType":881},{},[44204],{"data":44205,"marks":44206,"value":44207,"nodeType":867},{},[],"That means you can:",{"data":44209,"content":44210,"nodeType":3126},{},[44211,44230,44248,44267],{"data":44212,"content":44213,"nodeType":3061},{},[44214],{"data":44215,"content":44216,"nodeType":881},{},[44217,44221,44226],{"data":44218,"marks":44219,"value":44220,"nodeType":867},{},[],"Remind employees ",{"data":44222,"marks":44223,"value":44225,"nodeType":867},{},[44224],{"type":916},"not to store credentials",{"data":44227,"marks":44228,"value":44229,"nodeType":867},{},[]," or sensitive information on internal wikis.",{"data":44231,"content":44232,"nodeType":3061},{},[44233],{"data":44234,"content":44235,"nodeType":881},{},[44236,44240,44245],{"data":44237,"marks":44238,"value":44239,"nodeType":867},{},[],"Require acknowledgement of your security policies when using ",{"data":44241,"marks":44242,"value":44244,"nodeType":867},{},[44243],{"type":916},"high-value GitHub repos",{"data":44246,"marks":44247,"value":1947,"nodeType":867},{},[],{"data":44249,"content":44250,"nodeType":3061},{},[44251],{"data":44252,"content":44253,"nodeType":881},{},[44254,44258,44263],{"data":44255,"marks":44256,"value":44257,"nodeType":867},{},[],"Ask employees not to share sensitive information when using ",{"data":44259,"marks":44260,"value":44262,"nodeType":867},{},[44261],{"type":916},"GenAI tools",{"data":44264,"marks":44265,"value":44266,"nodeType":867},{},[]," during an unauthenticated session.",{"data":44268,"content":44269,"nodeType":3061},{},[44270],{"data":44271,"content":44272,"nodeType":881},{},[44273],{"data":44274,"marks":44275,"value":44276,"nodeType":867},{},[],"Or anything else you can think of!",{"data":44278,"content":44282,"nodeType":890},{"target":44279},{"sys":44280},{"id":44281,"type":887,"linkType":888},"6Jq3wMNCf1ns8zH6Z8tvGX",[],{"data":44284,"content":44285,"nodeType":881},{},[44286,44289,44298],{"data":44287,"marks":44288,"value":21,"nodeType":867},{},[],{"data":44290,"content":44294,"nodeType":3447},{"target":44291},{"sys":44292},{"id":44293,"type":887,"linkType":888},"2ti5f4Eh4teqnVkKDgztcm",[44295],{"data":44296,"marks":44297,"value":4330,"nodeType":867},{},[],{"data":44299,"marks":44300,"value":21,"nodeType":867},{},[],{"data":44302,"content":44303,"nodeType":918},{},[44304],{"data":44305,"marks":44306,"value":44307,"nodeType":867},{},[],"Self-service SAML for the Push admin console",{"data":44309,"content":44310,"nodeType":881},{},[44311,44315,44320],{"data":44312,"marks":44313,"value":44314,"nodeType":867},{},[],"It’s now ",{"data":44316,"marks":44317,"value":44319,"nodeType":867},{},[44318],{"type":916},"easier to set up SAML for the Push admin console",{"data":44321,"marks":44322,"value":44323,"nodeType":867},{},[]," so your Push admins can log in using your SSO provider, such as Okta or Microsoft Entra ID. Once you’ve created the Push app in your identity provider, you can manage admin access via your IdP.",{"data":44325,"content":44326,"nodeType":881},{},[44327,44331,44335],{"data":44328,"marks":44329,"value":44330,"nodeType":867},{},[],"You can set up SAML yourself from the admin console by going to the ",{"data":44332,"marks":44333,"value":36720,"nodeType":867},{},[44334],{"type":916},{"data":44336,"marks":44337,"value":44338,"nodeType":867},{},[]," page and following the steps in the setup wizard.",{"data":44340,"content":44344,"nodeType":890},{"target":44341},{"sys":44342},{"id":44343,"type":887,"linkType":888},"23nEc3hEVCjENod1xpLW97",[],{"data":44346,"content":44347,"nodeType":881},{},[44348],{"data":44349,"marks":44350,"value":44351,"nodeType":867},{},[],"SAML for the Push platform is available at no additional cost.",{"data":44353,"content":44354,"nodeType":881},{},[44355,44358,44367],{"data":44356,"marks":44357,"value":21,"nodeType":867},{},[],{"data":44359,"content":44363,"nodeType":3447},{"target":44360},{"sys":44361},{"id":44362,"type":887,"linkType":888},"2SRHVwdI7xMYdyrMifgqog",[44364],{"data":44365,"marks":44366,"value":4330,"nodeType":867},{},[],{"data":44368,"marks":44369,"value":21,"nodeType":867},{},[],{"data":44371,"content":44372,"nodeType":918},{},[44373],{"data":44374,"marks":44375,"value":44376,"nodeType":867},{},[],"Push now supports Island enterprise browser",{"data":44378,"content":44379,"nodeType":881},{},[44380,44383,44388],{"data":44381,"marks":44382,"value":43892,"nodeType":867},{},[],{"data":44384,"marks":44385,"value":44387,"nodeType":867},{},[44386],{"type":916},"install the Push browser agent on Island",{"data":44389,"marks":44390,"value":44391,"nodeType":867},{},[],", adding a powerful, complementary set of identity security controls to the enterprise browser.",{"data":44393,"content":44394,"nodeType":881},{},[44395,44399,44404],{"data":44396,"marks":44397,"value":44398,"nodeType":867},{},[],"With Island, you can deploy and activate the Push agent seamlessly ",{"data":44400,"marks":44401,"value":44403,"nodeType":867},{},[44402],{"type":916},"without any end-user interaction",{"data":44405,"marks":44406,"value":1947,"nodeType":867},{},[],{"data":44408,"content":44409,"nodeType":881},{},[44410],{"data":44411,"marks":44412,"value":44413,"nodeType":867},{},[],"Push already provides managed deployment support for other major browsers, including Chrome, Edge, Firefox, Brave, Safari, and Arc. ",{"data":44415,"content":44416,"nodeType":881},{},[44417,44420,44429],{"data":44418,"marks":44419,"value":21,"nodeType":867},{},[],{"data":44421,"content":44425,"nodeType":3447},{"target":44422},{"sys":44423},{"id":44424,"type":887,"linkType":888},"3mUYngymmVLnXaRZSmii5Q",[44426],{"data":44427,"marks":44428,"value":4330,"nodeType":867},{},[],{"data":44430,"marks":44431,"value":21,"nodeType":867},{},[],{"data":44433,"content":44434,"nodeType":918},{},[44435],{"data":44436,"marks":44437,"value":44438,"nodeType":867},{},[],"New landing page browser enrollment option",{"data":44440,"content":44441,"nodeType":881},{},[44442,44446,44451,44455,44460],{"data":44443,"marks":44444,"value":44445,"nodeType":867},{},[],"As an alternative to Push’s email self-enrollment option for end-users, you can now invite employees to ",{"data":44447,"marks":44448,"value":44450,"nodeType":867},{},[44449],{"type":916},"self-enroll and install the Push browser extension",{"data":44452,"marks":44453,"value":44454,"nodeType":867},{},[]," themselves by directing them to a ",{"data":44456,"marks":44457,"value":44459,"nodeType":867},{},[44458],{"type":916},"landing page",{"data":44461,"marks":44462,"value":1253,"nodeType":867},{},[],{"data":44464,"content":44465,"nodeType":881},{},[44466],{"data":44467,"marks":44468,"value":44469,"nodeType":867},{},[],"Once employees visit the page, they’ll be prompted to verify their identity via OIDC login using your identity provider. Once confirmed, they’ll be prompted to install the Push extension and enrolled in Push.",{"data":44471,"content":44472,"nodeType":881},{},[44473,44476,44483],{"data":44474,"marks":44475,"value":21,"nodeType":867},{},[],{"data":44477,"content":44479,"nodeType":876},{"uri":44478},"/help/audience/administrators/docs/install-the-browser-extension/#self-enrollment-via-landing-page",[44480],{"data":44481,"marks":44482,"value":4330,"nodeType":867},{},[],{"data":44484,"marks":44485,"value":21,"nodeType":867},{},[],{"data":44487,"content":44488,"nodeType":918},{},[44489],{"data":44490,"marks":44491,"value":44179,"nodeType":867},{},[],{"data":44493,"content":44494,"nodeType":881},{},[44495,44499,44504],{"data":44496,"marks":44497,"value":44498,"nodeType":867},{},[],"We’ve improved the ",{"data":44500,"marks":44501,"value":44503,"nodeType":867},{},[44502],{"type":916},"visibility and function of filters",{"data":44505,"marks":44506,"value":44507,"nodeType":867},{},[]," on pages in the Push admin console that help you explore and manage employees, apps, and accounts. You can also pin the filters you use the most and Push will remember your selection.",{"data":44509,"content":44510,"nodeType":881},{},[44511,44515,44520,44523,44528,44531,44536,44539,44544],{"data":44512,"marks":44513,"value":44514,"nodeType":867},{},[],"You’ll find the new filters under the keyword search on all the data tables in Push, including the ",{"data":44516,"marks":44517,"value":44519,"nodeType":867},{},[44518],{"type":916},"Employees",{"data":44521,"marks":44522,"value":4006,"nodeType":867},{},[],{"data":44524,"marks":44525,"value":44527,"nodeType":867},{},[44526],{"type":916},"Apps",{"data":44529,"marks":44530,"value":4006,"nodeType":867},{},[],{"data":44532,"marks":44533,"value":44535,"nodeType":867},{},[44534],{"type":916},"Accounts",{"data":44537,"marks":44538,"value":15362,"nodeType":867},{},[],{"data":44540,"marks":44541,"value":44543,"nodeType":867},{},[44542],{"type":916},"OAuth apps",{"data":44545,"marks":44546,"value":44547,"nodeType":867},{},[]," pages. Combine multiple filters to pinpoint useful data trends, such as:",{"data":44549,"content":44550,"nodeType":3126},{},[44551,44561,44571,44581],{"data":44552,"content":44553,"nodeType":3061},{},[44554],{"data":44555,"content":44556,"nodeType":881},{},[44557],{"data":44558,"marks":44559,"value":44560,"nodeType":867},{},[],"Which accounts are accessing SAML apps using passwords.",{"data":44562,"content":44563,"nodeType":3061},{},[44564],{"data":44565,"content":44566,"nodeType":881},{},[44567],{"data":44568,"marks":44569,"value":44570,"nodeType":867},{},[],"Which accounts are using verified stolen credentials.",{"data":44572,"content":44573,"nodeType":3061},{},[44574],{"data":44575,"content":44576,"nodeType":881},{},[44577],{"data":44578,"marks":44579,"value":44580,"nodeType":867},{},[],"Which employees do not have the Push browser extension.",{"data":44582,"content":44583,"nodeType":3061},{},[44584],{"data":44585,"content":44586,"nodeType":881},{},[44587],{"data":44588,"marks":44589,"value":44590,"nodeType":867},{},[],"And many more.",{"data":44592,"content":44596,"nodeType":890},{"target":44593},{"sys":44594},{"id":44595,"type":887,"linkType":888},"OAXAnXKt4TcLOlUpdQP3X",[],{"data":44598,"content":44599,"nodeType":881},{},[44600],{"data":44601,"marks":44602,"value":21,"nodeType":867},{},[],"Product release: March 2025","Here’s what’s new on the Push platform for March 2025.","2025-03-11T00:00:00.000Z","product-release-march-2025",{"items":44608},[44609],{"sys":44610,"name":44612},{"id":44611},"5jk0kqjSdSK2L0YiistQjY","Release notes",{"items":44614},[44615],{"fullName":43566,"firstName":43567,"jobTitle":43568,"profilePicture":44616},{"url":43570},"product-release-june-2025","blog/product-release-june-2025",{"json":44620},{"data":44621,"content":44622,"nodeType":1640},{},[44623],{"data":44624,"content":44625,"nodeType":881},{},[44626],{"data":44627,"marks":44628,"value":44629,"nodeType":867},{},[],"Streamline investigations with our new Detections page, enforce strong passwords in the browser, and more","Here’s what’s new on the Push platform for June 2025.",{"id":44632,"publishedAt":44633},"20xOvhmIKW7E0e1g5q7D2h","2026-08-13T09:34:55.198Z",{"items":44635},[44636],{"sys":44637,"name":44612},{"id":44611},{"items":44639},[44640,44642,44644,44646,44648,44650,44652],{"sys":44641,"name":297,"slug":298,"tier":31},{"id":294},{"sys":44643,"name":502,"slug":503,"tier":45},{"id":499},{"sys":44645,"name":650,"slug":651,"tier":45},{"id":647},{"sys":44647,"name":607,"slug":608,"tier":45},{"id":604},{"sys":44649,"name":457,"slug":458,"tier":45},{"id":454},{"sys":44651,"name":598,"slug":599,"tier":45},{"id":595},{"sys":44653,"name":261,"slug":262,"tier":45},{"id":258},"W-f08Qh1XP8pZC3uSHuDuastmdH4_uFvRNEb3aoOxAg",{"id":44656,"title":29799,"authorsCollection":44657,"content":44662,"extension":228,"faqItemsCollection":46086,"faqTitle":59,"featured":6,"hashTags":59,"meta":46088,"metaTitle":46089,"ogImage":46090,"postType":8156,"publishedDate":40252,"relatedBlogPostsCollection":46091,"slug":29800,"stem":47752,"subtitle":59,"summary":47753,"synopsis":40251,"sys":47764,"tagsCollection":47766,"topicsCollection":47772,"__hash__":47822},"blog/blog/scattered-spider-ttp-evolution-in-2025.json",{"items":44658},[44659],{"fullName":849,"firstName":850,"jobTitle":851,"socialLinks":44660,"profilePicture":44661},[853],{"url":855},{"json":44663,"links":45821},{"data":44664,"content":44665,"nodeType":1640},{},[44666,44671,44678,44684,44710,44715,44722,44748,44782,44787,44794,44809,44814,44817,44824,44830,44835,44871,45001,45004,45011,45017,45024,45050,45055,45062,45078,45084,45089,45095,45100,45116,45123,45139,45146,45152,45158,45161,45168,45174,45179,45185,45192,45208,45214,45219,45226,45232,45238,45264,45269,45275,45282,45288,45293,45319,45326,45342,45348,45353,45360,45376,45382,45439,45444,45447,45454,45460,45466,45492,45495,45502,45509,45514,45520,45527,45532,45538,45544,45549,45555,45562,45568,45574,45580,45596,45612,45618,45624,45629,45635,45642,45648,45654,45659,45665,45672,45678,45684,45690,45695,45701,45708,45714,45730,45735,45741,45758,45763,45769,45785,45790,45793,45800,45806],{"data":44667,"content":44670,"nodeType":890},{"target":44668},{"sys":44669},{"id":15249,"type":887,"linkType":888},[],{"data":44672,"content":44673,"nodeType":918},{},[44674],{"data":44675,"marks":44676,"value":38951,"nodeType":867},{},[44677],{"type":916},{"data":44679,"content":44680,"nodeType":881},{},[44681],{"data":44682,"marks":44683,"value":38958,"nodeType":867},{},[],{"data":44685,"content":44686,"nodeType":881},{},[44687,44690,44697,44700,44707],{"data":44688,"marks":44689,"value":38965,"nodeType":867},{},[],{"data":44691,"content":44692,"nodeType":876},{"uri":35499},[44693],{"data":44694,"marks":44695,"value":35505,"nodeType":867},{},[44696],{"type":1040},{"data":44698,"marks":44699,"value":15362,"nodeType":867},{},[],{"data":44701,"content":44702,"nodeType":876},{"uri":14576},[44703],{"data":44704,"marks":44705,"value":8186,"nodeType":867},{},[44706],{"type":1040},{"data":44708,"marks":44709,"value":38986,"nodeType":867},{},[],{"data":44711,"content":44714,"nodeType":890},{"target":44712},{"sys":44713},{"id":38991,"type":887,"linkType":888},[],{"data":44716,"content":44717,"nodeType":998},{},[44718],{"data":44719,"marks":44720,"value":39000,"nodeType":867},{},[44721],{"type":916},{"data":44723,"content":44724,"nodeType":881},{},[44725,44728,44735,44738,44745],{"data":44726,"marks":44727,"value":39007,"nodeType":867},{},[],{"data":44729,"content":44730,"nodeType":876},{"uri":36578},[44731],{"data":44732,"marks":44733,"value":36584,"nodeType":867},{},[44734],{"type":1040},{"data":44736,"marks":44737,"value":39018,"nodeType":867},{},[],{"data":44739,"content":44740,"nodeType":876},{"uri":14743},[44741],{"data":44742,"marks":44743,"value":14749,"nodeType":867},{},[44744],{"type":1040},{"data":44746,"marks":44747,"value":39029,"nodeType":867},{},[],{"data":44749,"content":44750,"nodeType":881},{},[44751,44754,44758,44761,44765,44768,44772,44775,44779],{"data":44752,"marks":44753,"value":39036,"nodeType":867},{},[],{"data":44755,"marks":44756,"value":39041,"nodeType":867},{},[44757],{"type":916},{"data":44759,"marks":44760,"value":39045,"nodeType":867},{},[],{"data":44762,"marks":44763,"value":39050,"nodeType":867},{},[44764],{"type":916},{"data":44766,"marks":44767,"value":39054,"nodeType":867},{},[],{"data":44769,"marks":44770,"value":39059,"nodeType":867},{},[44771],{"type":916},{"data":44773,"marks":44774,"value":39063,"nodeType":867},{},[],{"data":44776,"marks":44777,"value":39068,"nodeType":867},{},[44778],{"type":916},{"data":44780,"marks":44781,"value":10110,"nodeType":867},{},[],{"data":44783,"content":44786,"nodeType":890},{"target":44784},{"sys":44785},{"id":39076,"type":887,"linkType":888},[],{"data":44788,"content":44789,"nodeType":998},{},[44790],{"data":44791,"marks":44792,"value":39085,"nodeType":867},{},[44793],{"type":916},{"data":44795,"content":44796,"nodeType":881},{},[44797,44800,44806],{"data":44798,"marks":44799,"value":39092,"nodeType":867},{},[],{"data":44801,"content":44802,"nodeType":876},{"uri":14576},[44803],{"data":44804,"marks":44805,"value":39099,"nodeType":867},{},[],{"data":44807,"marks":44808,"value":39103,"nodeType":867},{},[],{"data":44810,"content":44813,"nodeType":890},{"target":44811},{"sys":44812},{"id":39108,"type":887,"linkType":888},[],{"data":44815,"content":44816,"nodeType":908},{},[],{"data":44818,"content":44819,"nodeType":918},{},[44820],{"data":44821,"marks":44822,"value":39120,"nodeType":867},{},[44823],{"type":916},{"data":44825,"content":44826,"nodeType":881},{},[44827],{"data":44828,"marks":44829,"value":39127,"nodeType":867},{},[],{"data":44831,"content":44834,"nodeType":890},{"target":44832},{"sys":44833},{"id":39132,"type":887,"linkType":888},[],{"data":44836,"content":44837,"nodeType":881},{},[44838,44841,44848,44851,44858,44861,44868],{"data":44839,"marks":44840,"value":39140,"nodeType":867},{},[],{"data":44842,"content":44843,"nodeType":876},{"uri":39143},[44844],{"data":44845,"marks":44846,"value":15266,"nodeType":867},{},[44847],{"type":1040},{"data":44849,"marks":44850,"value":4006,"nodeType":867},{},[],{"data":44852,"content":44853,"nodeType":876},{"uri":15272},[44854],{"data":44855,"marks":44856,"value":15278,"nodeType":867},{},[44857],{"type":1040},{"data":44859,"marks":44860,"value":15362,"nodeType":867},{},[],{"data":44862,"content":44863,"nodeType":876},{"uri":39164},[44864],{"data":44865,"marks":44866,"value":39170,"nodeType":867},{},[44867],{"type":1040},{"data":44869,"marks":44870,"value":39174,"nodeType":867},{},[],{"data":44872,"content":44873,"nodeType":881},{},[44874,44877,44884,44887,44894,44897,44904,44907,44914,44917,44924,44927,44934,44937,44944,44947,44953,44956,44962,44965,44971,44974,44980,44983,44989,44992,44998],{"data":44875,"marks":44876,"value":15289,"nodeType":867},{},[],{"data":44878,"content":44879,"nodeType":876},{"uri":15292},[44880],{"data":44881,"marks":44882,"value":15298,"nodeType":867},{},[44883],{"type":1040},{"data":44885,"marks":44886,"value":4006,"nodeType":867},{},[],{"data":44888,"content":44889,"nodeType":876},{"uri":15304},[44890],{"data":44891,"marks":44892,"value":15310,"nodeType":867},{},[44893],{"type":1040},{"data":44895,"marks":44896,"value":4006,"nodeType":867},{},[],{"data":44898,"content":44899,"nodeType":876},{"uri":15316},[44900],{"data":44901,"marks":44902,"value":15322,"nodeType":867},{},[44903],{"type":1040},{"data":44905,"marks":44906,"value":4006,"nodeType":867},{},[],{"data":44908,"content":44909,"nodeType":876},{"uri":15328},[44910],{"data":44911,"marks":44912,"value":15334,"nodeType":867},{},[44913],{"type":1040},{"data":44915,"marks":44916,"value":4006,"nodeType":867},{},[],{"data":44918,"content":44919,"nodeType":876},{"uri":15340},[44920],{"data":44921,"marks":44922,"value":15346,"nodeType":867},{},[44923],{"type":1040},{"data":44925,"marks":44926,"value":4006,"nodeType":867},{},[],{"data":44928,"content":44929,"nodeType":876},{"uri":15352},[44930],{"data":44931,"marks":44932,"value":15358,"nodeType":867},{},[44933],{"type":1040},{"data":44935,"marks":44936,"value":15362,"nodeType":867},{},[],{"data":44938,"content":44939,"nodeType":876},{"uri":15365},[44940],{"data":44941,"marks":44942,"value":15371,"nodeType":867},{},[44943],{"type":1040},{"data":44945,"marks":44946,"value":39251,"nodeType":867},{},[],{"data":44948,"content":44949,"nodeType":876},{"uri":15385},[44950],{"data":44951,"marks":44952,"value":15391,"nodeType":867},{},[],{"data":44954,"marks":44955,"value":4006,"nodeType":867},{},[],{"data":44957,"content":44958,"nodeType":876},{"uri":15397},[44959],{"data":44960,"marks":44961,"value":15403,"nodeType":867},{},[],{"data":44963,"marks":44964,"value":4006,"nodeType":867},{},[],{"data":44966,"content":44967,"nodeType":876},{"uri":15410},[44968],{"data":44969,"marks":44970,"value":15416,"nodeType":867},{},[],{"data":44972,"marks":44973,"value":4006,"nodeType":867},{},[],{"data":44975,"content":44976,"nodeType":876},{"uri":15434},[44977],{"data":44978,"marks":44979,"value":15439,"nodeType":867},{},[],{"data":44981,"marks":44982,"value":4006,"nodeType":867},{},[],{"data":44984,"content":44985,"nodeType":876},{"uri":15434},[44986],{"data":44987,"marks":44988,"value":15449,"nodeType":867},{},[],{"data":44990,"marks":44991,"value":15362,"nodeType":867},{},[],{"data":44993,"content":44994,"nodeType":876},{"uri":15423},[44995],{"data":44996,"marks":44997,"value":15428,"nodeType":867},{},[],{"data":44999,"marks":45000,"value":1947,"nodeType":867},{},[],{"data":45002,"content":45003,"nodeType":908},{},[],{"data":45005,"content":45006,"nodeType":918},{},[45007],{"data":45008,"marks":45009,"value":39316,"nodeType":867},{},[45010],{"type":916},{"data":45012,"content":45013,"nodeType":881},{},[45014],{"data":45015,"marks":45016,"value":39323,"nodeType":867},{},[],{"data":45018,"content":45019,"nodeType":998},{},[45020],{"data":45021,"marks":45022,"value":39331,"nodeType":867},{},[45023],{"type":916},{"data":45025,"content":45026,"nodeType":881},{},[45027,45030,45037,45040,45047],{"data":45028,"marks":45029,"value":39338,"nodeType":867},{},[],{"data":45031,"content":45032,"nodeType":876},{"uri":39341},[45033],{"data":45034,"marks":45035,"value":39347,"nodeType":867},{},[45036],{"type":1040},{"data":45038,"marks":45039,"value":2063,"nodeType":867},{},[],{"data":45041,"content":45042,"nodeType":876},{"uri":14532},[45043],{"data":45044,"marks":45045,"value":39358,"nodeType":867},{},[45046],{"type":1040},{"data":45048,"marks":45049,"value":39362,"nodeType":867},{},[],{"data":45051,"content":45054,"nodeType":890},{"target":45052},{"sys":45053},{"id":39367,"type":887,"linkType":888},[],{"data":45056,"content":45057,"nodeType":998},{},[45058],{"data":45059,"marks":45060,"value":39376,"nodeType":867},{},[45061],{"type":916},{"data":45063,"content":45064,"nodeType":881},{},[45065,45068,45075],{"data":45066,"marks":45067,"value":39383,"nodeType":867},{},[],{"data":45069,"content":45070,"nodeType":876},{"uri":39386},[45071],{"data":45072,"marks":45073,"value":39392,"nodeType":867},{},[45074],{"type":1040},{"data":45076,"marks":45077,"value":39396,"nodeType":867},{},[],{"data":45079,"content":45080,"nodeType":881},{},[45081],{"data":45082,"marks":45083,"value":39403,"nodeType":867},{},[],{"data":45085,"content":45088,"nodeType":890},{"target":45086},{"sys":45087},{"id":39408,"type":887,"linkType":888},[],{"data":45090,"content":45091,"nodeType":881},{},[45092],{"data":45093,"marks":45094,"value":39416,"nodeType":867},{},[],{"data":45096,"content":45099,"nodeType":890},{"target":45097},{"sys":45098},{"id":39421,"type":887,"linkType":888},[],{"data":45101,"content":45102,"nodeType":881},{},[45103,45106,45113],{"data":45104,"marks":45105,"value":39429,"nodeType":867},{},[],{"data":45107,"content":45108,"nodeType":876},{"uri":39432},[45109],{"data":45110,"marks":45111,"value":39438,"nodeType":867},{},[45112],{"type":1040},{"data":45114,"marks":45115,"value":10143,"nodeType":867},{},[],{"data":45117,"content":45118,"nodeType":998},{},[45119],{"data":45120,"marks":45121,"value":39449,"nodeType":867},{},[45122],{"type":916},{"data":45124,"content":45125,"nodeType":881},{},[45126,45129,45136],{"data":45127,"marks":45128,"value":39456,"nodeType":867},{},[],{"data":45130,"content":45131,"nodeType":876},{"uri":14743},[45132],{"data":45133,"marks":45134,"value":14749,"nodeType":867},{},[45135],{"type":1040},{"data":45137,"marks":45138,"value":39467,"nodeType":867},{},[],{"data":45140,"content":45141,"nodeType":998},{},[45142],{"data":45143,"marks":45144,"value":39475,"nodeType":867},{},[45145],{"type":916},{"data":45147,"content":45148,"nodeType":881},{},[45149],{"data":45150,"marks":45151,"value":39482,"nodeType":867},{},[],{"data":45153,"content":45154,"nodeType":881},{},[45155],{"data":45156,"marks":45157,"value":39489,"nodeType":867},{},[],{"data":45159,"content":45160,"nodeType":908},{},[],{"data":45162,"content":45163,"nodeType":918},{},[45164],{"data":45165,"marks":45166,"value":39500,"nodeType":867},{},[45167],{"type":916},{"data":45169,"content":45170,"nodeType":881},{},[45171],{"data":45172,"marks":45173,"value":39507,"nodeType":867},{},[],{"data":45175,"content":45178,"nodeType":890},{"target":45176},{"sys":45177},{"id":39512,"type":887,"linkType":888},[],{"data":45180,"content":45181,"nodeType":881},{},[45182],{"data":45183,"marks":45184,"value":39520,"nodeType":867},{},[],{"data":45186,"content":45187,"nodeType":998},{},[45188],{"data":45189,"marks":45190,"value":39528,"nodeType":867},{},[45191],{"type":916},{"data":45193,"content":45194,"nodeType":881},{},[45195,45198,45205],{"data":45196,"marks":45197,"value":21,"nodeType":867},{},[],{"data":45199,"content":45200,"nodeType":876},{"uri":39432},[45201],{"data":45202,"marks":45203,"value":39542,"nodeType":867},{},[45204],{"type":1040},{"data":45206,"marks":45207,"value":39546,"nodeType":867},{},[],{"data":45209,"content":45210,"nodeType":881},{},[45211],{"data":45212,"marks":45213,"value":39553,"nodeType":867},{},[],{"data":45215,"content":45218,"nodeType":890},{"target":45216},{"sys":45217},{"id":39558,"type":887,"linkType":888},[],{"data":45220,"content":45221,"nodeType":998},{},[45222],{"data":45223,"marks":45224,"value":39567,"nodeType":867},{},[45225],{"type":916},{"data":45227,"content":45228,"nodeType":881},{},[45229],{"data":45230,"marks":45231,"value":39574,"nodeType":867},{},[],{"data":45233,"content":45234,"nodeType":881},{},[45235],{"data":45236,"marks":45237,"value":39581,"nodeType":867},{},[],{"data":45239,"content":45240,"nodeType":881},{},[45241,45244,45251,45254,45261],{"data":45242,"marks":45243,"value":39588,"nodeType":867},{},[],{"data":45245,"content":45246,"nodeType":876},{"uri":34661},[45247],{"data":45248,"marks":45249,"value":39596,"nodeType":867},{},[45250],{"type":1040},{"data":45252,"marks":45253,"value":39600,"nodeType":867},{},[],{"data":45255,"content":45256,"nodeType":876},{"uri":947},[45257],{"data":45258,"marks":45259,"value":39608,"nodeType":867},{},[45260],{"type":1040},{"data":45262,"marks":45263,"value":39612,"nodeType":867},{},[],{"data":45265,"content":45268,"nodeType":890},{"target":45266},{"sys":45267},{"id":39617,"type":887,"linkType":888},[],{"data":45270,"content":45271,"nodeType":881},{},[45272],{"data":45273,"marks":45274,"value":39625,"nodeType":867},{},[],{"data":45276,"content":45277,"nodeType":998},{},[45278],{"data":45279,"marks":45280,"value":39633,"nodeType":867},{},[45281],{"type":916},{"data":45283,"content":45284,"nodeType":881},{},[45285],{"data":45286,"marks":45287,"value":39640,"nodeType":867},{},[],{"data":45289,"content":45292,"nodeType":890},{"target":45290},{"sys":45291},{"id":39645,"type":887,"linkType":888},[],{"data":45294,"content":45295,"nodeType":881},{},[45296,45299,45306,45309,45316],{"data":45297,"marks":45298,"value":39653,"nodeType":867},{},[],{"data":45300,"content":45301,"nodeType":876},{"uri":39656},[45302],{"data":45303,"marks":45304,"value":39662,"nodeType":867},{},[45305],{"type":1040},{"data":45307,"marks":45308,"value":39666,"nodeType":867},{},[],{"data":45310,"content":45311,"nodeType":876},{"uri":34888},[45312],{"data":45313,"marks":45314,"value":20604,"nodeType":867},{},[45315],{"type":1040},{"data":45317,"marks":45318,"value":39677,"nodeType":867},{},[],{"data":45320,"content":45321,"nodeType":998},{},[45322],{"data":45323,"marks":45324,"value":39685,"nodeType":867},{},[45325],{"type":916},{"data":45327,"content":45328,"nodeType":881},{},[45329,45332,45339],{"data":45330,"marks":45331,"value":39692,"nodeType":867},{},[],{"data":45333,"content":45334,"nodeType":876},{"uri":39695},[45335],{"data":45336,"marks":45337,"value":39701,"nodeType":867},{},[45338],{"type":1040},{"data":45340,"marks":45341,"value":39705,"nodeType":867},{},[],{"data":45343,"content":45344,"nodeType":881},{},[45345],{"data":45346,"marks":45347,"value":39712,"nodeType":867},{},[],{"data":45349,"content":45352,"nodeType":890},{"target":45350},{"sys":45351},{"id":39717,"type":887,"linkType":888},[],{"data":45354,"content":45355,"nodeType":998},{},[45356],{"data":45357,"marks":45358,"value":39726,"nodeType":867},{},[45359],{"type":916},{"data":45361,"content":45362,"nodeType":881},{},[45363,45366,45373],{"data":45364,"marks":45365,"value":39733,"nodeType":867},{},[],{"data":45367,"content":45368,"nodeType":876},{"uri":39736},[45369],{"data":45370,"marks":45371,"value":39742,"nodeType":867},{},[45372],{"type":1040},{"data":45374,"marks":45375,"value":39746,"nodeType":867},{},[],{"data":45377,"content":45378,"nodeType":881},{},[45379],{"data":45380,"marks":45381,"value":39753,"nodeType":867},{},[],{"data":45383,"content":45384,"nodeType":3126},{},[45385,45394,45403,45412,45421,45430],{"data":45386,"content":45387,"nodeType":3061},{},[45388],{"data":45389,"content":45390,"nodeType":881},{},[45391],{"data":45392,"marks":45393,"value":39766,"nodeType":867},{},[],{"data":45395,"content":45396,"nodeType":3061},{},[45397],{"data":45398,"content":45399,"nodeType":881},{},[45400],{"data":45401,"marks":45402,"value":39776,"nodeType":867},{},[],{"data":45404,"content":45405,"nodeType":3061},{},[45406],{"data":45407,"content":45408,"nodeType":881},{},[45409],{"data":45410,"marks":45411,"value":39786,"nodeType":867},{},[],{"data":45413,"content":45414,"nodeType":3061},{},[45415],{"data":45416,"content":45417,"nodeType":881},{},[45418],{"data":45419,"marks":45420,"value":39796,"nodeType":867},{},[],{"data":45422,"content":45423,"nodeType":3061},{},[45424],{"data":45425,"content":45426,"nodeType":881},{},[45427],{"data":45428,"marks":45429,"value":39806,"nodeType":867},{},[],{"data":45431,"content":45432,"nodeType":3061},{},[45433],{"data":45434,"content":45435,"nodeType":881},{},[45436],{"data":45437,"marks":45438,"value":39816,"nodeType":867},{},[],{"data":45440,"content":45443,"nodeType":890},{"target":45441},{"sys":45442},{"id":39821,"type":887,"linkType":888},[],{"data":45445,"content":45446,"nodeType":908},{},[],{"data":45448,"content":45449,"nodeType":918},{},[45450],{"data":45451,"marks":45452,"value":39833,"nodeType":867},{},[45453],{"type":916},{"data":45455,"content":45456,"nodeType":881},{},[45457],{"data":45458,"marks":45459,"value":39840,"nodeType":867},{},[],{"data":45461,"content":45462,"nodeType":881},{},[45463],{"data":45464,"marks":45465,"value":39847,"nodeType":867},{},[],{"data":45467,"content":45468,"nodeType":881},{},[45469,45472,45479,45482,45489],{"data":45470,"marks":45471,"value":39854,"nodeType":867},{},[],{"data":45473,"content":45474,"nodeType":876},{"uri":39857},[45475],{"data":45476,"marks":45477,"value":39863,"nodeType":867},{},[45478],{"type":1040},{"data":45480,"marks":45481,"value":39867,"nodeType":867},{},[],{"data":45483,"content":45484,"nodeType":876},{"uri":947},[45485],{"data":45486,"marks":45487,"value":39875,"nodeType":867},{},[45488],{"type":1040},{"data":45490,"marks":45491,"value":10110,"nodeType":867},{},[],{"data":45493,"content":45494,"nodeType":908},{},[],{"data":45496,"content":45497,"nodeType":918},{},[45498],{"data":45499,"marks":45500,"value":39889,"nodeType":867},{},[45501],{"type":916},{"data":45503,"content":45504,"nodeType":881},{},[45505],{"data":45506,"marks":45507,"value":39897,"nodeType":867},{},[45508],{"type":916},{"data":45510,"content":45513,"nodeType":890},{"target":45511},{"sys":45512},{"id":39902,"type":887,"linkType":888},[],{"data":45515,"content":45516,"nodeType":998},{},[45517],{"data":45518,"marks":45519,"value":39910,"nodeType":867},{},[],{"data":45521,"content":45522,"nodeType":881},{},[45523],{"data":45524,"marks":45525,"value":39918,"nodeType":867},{},[45526],{"type":916},{"data":45528,"content":45531,"nodeType":890},{"target":45529},{"sys":45530},{"id":39923,"type":887,"linkType":888},[],{"data":45533,"content":45534,"nodeType":881},{},[45535],{"data":45536,"marks":45537,"value":39931,"nodeType":867},{},[],{"data":45539,"content":45540,"nodeType":881},{},[45541],{"data":45542,"marks":45543,"value":39938,"nodeType":867},{},[],{"data":45545,"content":45548,"nodeType":890},{"target":45546},{"sys":45547},{"id":39943,"type":887,"linkType":888},[],{"data":45550,"content":45551,"nodeType":998},{},[45552],{"data":45553,"marks":45554,"value":39951,"nodeType":867},{},[],{"data":45556,"content":45557,"nodeType":881},{},[45558],{"data":45559,"marks":45560,"value":39959,"nodeType":867},{},[45561],{"type":916},{"data":45563,"content":45564,"nodeType":881},{},[45565],{"data":45566,"marks":45567,"value":39966,"nodeType":867},{},[],{"data":45569,"content":45570,"nodeType":881},{},[45571],{"data":45572,"marks":45573,"value":39973,"nodeType":867},{},[],{"data":45575,"content":45576,"nodeType":998},{},[45577],{"data":45578,"marks":45579,"value":39980,"nodeType":867},{},[],{"data":45581,"content":45582,"nodeType":881},{},[45583,45587,45592],{"data":45584,"marks":45585,"value":39988,"nodeType":867},{},[45586],{"type":916},{"data":45588,"marks":45589,"value":39994,"nodeType":867},{},[45590,45591],{"type":1040},{"type":916},{"data":45593,"marks":45594,"value":39999,"nodeType":867},{},[45595],{"type":916},{"data":45597,"content":45598,"nodeType":881},{},[45599,45602,45609],{"data":45600,"marks":45601,"value":40006,"nodeType":867},{},[],{"data":45603,"content":45604,"nodeType":876},{"uri":40009},[45605],{"data":45606,"marks":45607,"value":40015,"nodeType":867},{},[45608],{"type":1040},{"data":45610,"marks":45611,"value":1947,"nodeType":867},{},[],{"data":45613,"content":45614,"nodeType":881},{},[45615],{"data":45616,"marks":45617,"value":40025,"nodeType":867},{},[],{"data":45619,"content":45620,"nodeType":881},{},[45621],{"data":45622,"marks":45623,"value":40032,"nodeType":867},{},[],{"data":45625,"content":45628,"nodeType":890},{"target":45626},{"sys":45627},{"id":40037,"type":887,"linkType":888},[],{"data":45630,"content":45631,"nodeType":998},{},[45632],{"data":45633,"marks":45634,"value":40045,"nodeType":867},{},[],{"data":45636,"content":45637,"nodeType":881},{},[45638],{"data":45639,"marks":45640,"value":40053,"nodeType":867},{},[45641],{"type":916},{"data":45643,"content":45644,"nodeType":881},{},[45645],{"data":45646,"marks":45647,"value":40060,"nodeType":867},{},[],{"data":45649,"content":45650,"nodeType":881},{},[45651],{"data":45652,"marks":45653,"value":40067,"nodeType":867},{},[],{"data":45655,"content":45658,"nodeType":890},{"target":45656},{"sys":45657},{"id":40072,"type":887,"linkType":888},[],{"data":45660,"content":45661,"nodeType":998},{},[45662],{"data":45663,"marks":45664,"value":40080,"nodeType":867},{},[],{"data":45666,"content":45667,"nodeType":881},{},[45668],{"data":45669,"marks":45670,"value":40088,"nodeType":867},{},[45671],{"type":916},{"data":45673,"content":45674,"nodeType":881},{},[45675],{"data":45676,"marks":45677,"value":40095,"nodeType":867},{},[],{"data":45679,"content":45680,"nodeType":881},{},[45681],{"data":45682,"marks":45683,"value":40102,"nodeType":867},{},[],{"data":45685,"content":45686,"nodeType":881},{},[45687],{"data":45688,"marks":45689,"value":40109,"nodeType":867},{},[],{"data":45691,"content":45694,"nodeType":890},{"target":45692},{"sys":45693},{"id":40114,"type":887,"linkType":888},[],{"data":45696,"content":45697,"nodeType":998},{},[45698],{"data":45699,"marks":45700,"value":40122,"nodeType":867},{},[],{"data":45702,"content":45703,"nodeType":881},{},[45704],{"data":45705,"marks":45706,"value":40130,"nodeType":867},{},[45707],{"type":916},{"data":45709,"content":45710,"nodeType":881},{},[45711],{"data":45712,"marks":45713,"value":40137,"nodeType":867},{},[],{"data":45715,"content":45716,"nodeType":881},{},[45717,45720,45727],{"data":45718,"marks":45719,"value":40144,"nodeType":867},{},[],{"data":45721,"content":45722,"nodeType":876},{"uri":6845},[45723],{"data":45724,"marks":45725,"value":6850,"nodeType":867},{},[45726],{"type":1040},{"data":45728,"marks":45729,"value":40155,"nodeType":867},{},[],{"data":45731,"content":45734,"nodeType":890},{"target":45732},{"sys":45733},{"id":40160,"type":887,"linkType":888},[],{"data":45736,"content":45737,"nodeType":998},{},[45738],{"data":45739,"marks":45740,"value":40168,"nodeType":867},{},[],{"data":45742,"content":45743,"nodeType":881},{},[45744,45747,45755],{"data":45745,"marks":45746,"value":15780,"nodeType":867},{},[],{"data":45748,"content":45749,"nodeType":876},{"uri":15783},[45750],{"data":45751,"marks":45752,"value":15790,"nodeType":867},{},[45753,45754],{"type":1040},{"type":916},{"data":45756,"marks":45757,"value":15794,"nodeType":867},{},[],{"data":45759,"content":45762,"nodeType":890},{"target":45760},{"sys":45761},{"id":15799,"type":887,"linkType":888},[],{"data":45764,"content":45765,"nodeType":881},{},[45766],{"data":45767,"marks":45768,"value":15807,"nodeType":867},{},[],{"data":45770,"content":45771,"nodeType":881},{},[45772,45775,45782],{"data":45773,"marks":45774,"value":15824,"nodeType":867},{},[],{"data":45776,"content":45777,"nodeType":876},{"uri":15827},[45778],{"data":45779,"marks":45780,"value":15833,"nodeType":867},{},[45781],{"type":1040},{"data":45783,"marks":45784,"value":15837,"nodeType":867},{},[],{"data":45786,"content":45789,"nodeType":890},{"target":45787},{"sys":45788},{"id":15859,"type":887,"linkType":888},[],{"data":45791,"content":45792,"nodeType":908},{},[],{"data":45794,"content":45795,"nodeType":918},{},[45796],{"data":45797,"marks":45798,"value":4330,"nodeType":867},{},[45799],{"type":916},{"data":45801,"content":45802,"nodeType":881},{},[45803],{"data":45804,"marks":45805,"value":40234,"nodeType":867},{},[],{"data":45807,"content":45808,"nodeType":881},{},[45809,45812,45818],{"data":45810,"marks":45811,"value":34977,"nodeType":867},{},[],{"data":45813,"content":45814,"nodeType":876},{"uri":40243},[45815],{"data":45816,"marks":45817,"value":10826,"nodeType":867},{},[],{"data":45819,"marks":45820,"value":1947,"nodeType":867},{},[],{"entries":45822},{"hyperlink":45823,"inline":45824,"block":45825},[],[],[45826,45856,45882,45910,45914,45928,45963,45977,45991,45999,46004,46011,46015,46019,46026,46031,46045,46052,46060,46066,46074,46081,46084],{"sys":45827,"__typename":1696,"content":45828,"name":35814,"title":59},{"id":15249},{"json":45829},{"nodeType":1640,"data":45830,"content":45831},{},[45832],{"nodeType":881,"data":45833,"content":45834},{},[45835,45838,45844,45847,45853],{"nodeType":867,"value":35789,"marks":45836,"data":45837},[],{},{"nodeType":876,"data":45839,"content":45840},{"uri":31660},[45841],{"nodeType":867,"value":35796,"marks":45842,"data":45843},[],{},{"nodeType":867,"value":35800,"marks":45845,"data":45846},[],{},{"nodeType":876,"data":45848,"content":45849},{"uri":31660},[45850],{"nodeType":867,"value":35807,"marks":45851,"data":45852},[],{},{"nodeType":867,"value":35811,"marks":45854,"data":45855},[],{},{"sys":45857,"__typename":1696,"content":45858,"name":45881,"title":59},{"id":38991},{"json":45859},{"nodeType":1640,"data":45860,"content":45861},{},[45862],{"nodeType":881,"data":45863,"content":45864},{},[45865,45869,45877],{"nodeType":867,"value":45866,"marks":45867,"data":45868},"With criminal hacker collectives being fluid in nature, Scattered Spider has also been associated with ",[],{},{"nodeType":876,"data":45870,"content":45871},{"uri":14576},[45872],{"nodeType":867,"value":45873,"marks":45874,"data":45876},"the Snowflake attacks",[45875],{"type":1040},{},{"nodeType":867,"value":45878,"marks":45879,"data":45880}," attributed to the ShinyHunters group, which resulted in hundreds of millions of breached records from 9 public victims including AT&T, Ticketmaster, and Santander (with the full impact suggested to be around 165 organizations), monetized through ransom payments, extortion of individual victims, and resale of the data on criminal forums.",[],{},"Scattered Spider insight box 0",{"sys":45883,"__typename":1696,"content":45884,"name":45909,"title":59},{"id":39076},{"json":45885},{"nodeType":1640,"data":45886,"content":45887},{},[45888],{"nodeType":881,"data":45889,"content":45890},{},[45891,45896,45900,45905],{"nodeType":867,"value":45892,"marks":45893,"data":45895},"Caesars",[45894],{"type":916},{},{"nodeType":867,"value":45897,"marks":45898,"data":45899}," was also hit at the same time as MGM Resorts. Less is known about the Caesars attack, except that a ransom of ",[],{},{"nodeType":867,"value":45901,"marks":45902,"data":45904},"$15M",[45903],{"type":916},{},{"nodeType":867,"value":45906,"marks":45907,"data":45908}," was paid to Scattered Spider in an attempt to prevent stolen data being leaked online.",[],{},"Scattered Spider insight box 1",{"sys":45911,"__typename":22749,"type":22750,"ctaText":45912,"buttonLabel":45913,"buttonColour":22753,"buttonUrl":35819},{"id":39108},"Want to learn more from our security researchers? Watch our webinar on Scattered Spider's 2025 TTPs here. ","Stream On-Demand",{"sys":45915,"__typename":1696,"content":45916,"name":45927,"title":59},{"id":39132},{"json":45917},{"nodeType":1640,"data":45918,"content":45919},{},[45920],{"nodeType":881,"data":45921,"content":45922},{},[45923],{"nodeType":867,"value":45924,"marks":45925,"data":45926},"It's worth thinking about Scattered Spider less as a neatly identified group of individuals, but more as a pattern of activity and behaviors. For this reason, it's unlikely that arrests will have a definitive impact — the TTPs exhibited will continue to be used and refined by newcomers.  ",[],{},"Scattered Spider TTPs Insight Box 5",{"sys":45929,"__typename":1696,"content":45930,"name":45962,"title":59},{"id":39367},{"json":45931},{"nodeType":1640,"data":45932,"content":45933},{},[45934],{"nodeType":881,"data":45935,"content":45936},{},[45937,45941,45948,45952,45959],{"nodeType":867,"value":45938,"marks":45939,"data":45940},"Learn more about how Scattered Spider conducts help desk attacks ",[],{},{"nodeType":876,"data":45942,"content":45943},{"uri":14788},[45944],{"nodeType":867,"value":45945,"marks":45946,"data":45947},"in our recent blog pos",[],{},{"nodeType":867,"value":45949,"marks":45950,"data":45951},"t or by checking out ",[],{},{"nodeType":876,"data":45953,"content":45954},{"uri":35819},[45955],{"nodeType":867,"value":45956,"marks":45957,"data":45958},"our on-demand webinar — available to stream now",[],{},{"nodeType":867,"value":1253,"marks":45960,"data":45961},[],{},"Scattered Spider TTPs insight box 6",{"sys":45964,"__typename":1696,"content":45965,"name":45976,"title":59},{"id":39408},{"json":45966},{"nodeType":1640,"data":45967,"content":45968},{},[45969],{"nodeType":881,"data":45970,"content":45971},{},[45972],{"nodeType":867,"value":45973,"marks":45974,"data":45975},"Accenture, Aflac, Allstate, Ally Bank, Amica, Apple, AT&T, Athene, Audemars Piguet, Ballet Crypto, BCB Group, Bell, Bitcoin Suisse, Blockdaemon, Blockstream, Charter Communications, Chik-fil-A, Cincinnati Financial, Comcast Corporation, Core Scientific, Costco, Credit Karma, DoorDash, Fireblocks, Forbes, Gemini, Grayscale, H&R Block, Hanover Insurance, Harrow Health, Iliad, Instacart, Jackson Hewitt, Kemper, Louis Vuitton, Luno, Marsh, Mercury, Morningstar, Mutual of Omaha, Nansen, NGRAVE, New York Digital Investment Group, New York Life Insurance, News Corporation, Nike, Orange, P.F. Chang’s, Paxos, PNC Bank, Revolut, RiteAid, 7-Eleven, Singtel, Stargate Industries, Synchrony Bank, Synovus, T-Mobile, Telstra, TIAA, Transamerica, Twitter/X, UScellular, Verizon, Vodafone, WINDTRE, and Xapo Bank.",[],{},"Scattered Spider insight box 3",{"sys":45978,"__typename":1696,"content":45979,"name":45990,"title":59},{"id":39421},{"json":45980},{"nodeType":1640,"data":45981,"content":45982},{},[45983],{"nodeType":881,"data":45984,"content":45985},{},[45986],{"nodeType":867,"value":45987,"marks":45988,"data":45989},"ActiveCampaign, Ada CX, Alchemy, Asurion, Bandwith, Bird CRM, Campaign Monitor, Concentrix, Constant Contact, Corporate Tools, CTS, eClerx, Expedia Group, FalconX, FICO, Five9, Foundever, Freshworks, Genesis Trading, Givebutter, GoDaddy, HubSpot, Incode, Intercom, iQor, Iterable, Jumio, Klaviyo, LinkedIn, Mixpanel, Nuance Communications, Onfido, OnSolve, Podium, Pure Storage, Ripple, Roblox, Salesforce, Shipbob, Sinch, Socure, SPOC, Squarespace, TaskUs, TriVista, Twilio, Ulta Beauty, Upland Software, Wix, Workday, Ziff Davis, and 247[.]ai.",[],{},"Scattered Spider insight box 4",{"sys":45992,"__typename":1648,"title":45993,"caption":45994,"layoutMode":59,"file":45995},{"id":39512},"Scattered Spider image 1","Summary of Scattered Spider TTP evolution in the context of an end-to-end attack chain.",{"url":45996,"width":45997,"height":45998},"https://images.ctfassets.net/y1cdw1ablpvd/16ngVb8CXbn6jnv7CNeCs5/1d708ddda20413c228d1239f6739acae/Screenshot_2025-06-27_at_15.30.27.png",3376,1876,{"sys":46000,"__typename":22749,"type":22750,"ctaText":46001,"buttonLabel":46002,"buttonColour":22753,"buttonUrl":46003},{"id":39558},"Frustrated that phishing attacks are still so successful in 2025? Check out on-demand latest webinar where we analyze exactly why and where controls are failing.","Watch On-demand","https://pushsecurity.com/resources/phishing-2025",{"sys":46005,"__typename":1648,"title":46006,"caption":46007,"layoutMode":59,"file":46008},{"id":39617},"Scattered spider image 2","Comparing the it.com domain observed by security researchers with the us.com observed in our recent Onfido malvertising investigation.",{"url":46009,"width":1661,"height":46010},"https://images.ctfassets.net/y1cdw1ablpvd/36YNp6VD5QfqcFcB4actyT/e31cc1dad9f55d49e1d793711199a666/image1.png",791,{"sys":46012,"__typename":1671,"title":46013,"arcadeDemoUrl":46014,"playText":13572},{"id":39645},"Evilginx demo","https://demo.arcade.software/2OpOz9hyjfIu5o8KtAmI?embed",{"sys":46016,"__typename":1671,"title":46017,"arcadeDemoUrl":46018,"playText":13572},{"id":39717},"Phishing Toolkit Detection Evasion Arcade","https://demo.arcade.software/tDUPQV1Nlaralf6VQHT2?embed",{"sys":46020,"__typename":1648,"title":46021,"caption":46022,"layoutMode":59,"file":46023},{"id":39821},"Scattered spider image 3","Scattered Spider Okta phishing pages impersonating various brands",{"url":46024,"width":46025,"height":1661},"https://images.ctfassets.net/y1cdw1ablpvd/7HWejTJs8g5dtoZLK2oqg7/72e3461a28811d0b80d6322f2f93a431/image3.png",1645,{"sys":46027,"__typename":1648,"title":46028,"caption":46029,"layoutMode":59,"file":46030},{"id":39902},"Push vs Scattered Spider","Push controls mapped against Scattered Spider TTPs.",{"url":35854,"width":1661,"height":35825},{"sys":46032,"__typename":1696,"content":46033,"name":46044,"title":59},{"id":39923},{"json":46034},{"nodeType":1640,"data":46035,"content":46036},{},[46037],{"nodeType":881,"data":46038,"content":46039},{},[46040],{"nodeType":867,"value":46041,"marks":46042,"data":46043},"To detect modern, sophisticated phishing kits like those used by Scattered Spider, organizations need to be able to detect and block phishing pages in real-time. Push’s browser-based approach intercepts phishing attacks as they happen — in employee browsers. Being in the browser delivers a lot of advantages when it comes to detecting and intercepting phishing attacks. You see the live webpage that the user sees, as they see it, meaning you have much better visibility of malicious elements running on the page. It also means that you can implement real-time controls that kick in when a malicious element is detected.",[],{},"Scattered Spider insight box 2",{"sys":46046,"__typename":1648,"title":46047,"caption":46048,"layoutMode":59,"file":46049},{"id":39943},"Phishing toolkit detection","Accessing pages running malicious phishing toolkits is automatically blocked. ",{"url":46050,"width":44076,"height":46051},"https://images.ctfassets.net/y1cdw1ablpvd/3ylgW0MDCCesBjQsoqjD4P/a8bc4df9a430aca6c725f913d2bc6444/image11.png",767,{"sys":46053,"__typename":1648,"title":46054,"caption":46055,"layoutMode":59,"file":46056},{"id":40037},"Scattered spider image 4","Push detects and blocks when a password is used on a site it doesn't belong to.",{"url":46057,"width":46058,"height":46059},"https://images.ctfassets.net/y1cdw1ablpvd/3DsbAAM2GCMbyfBdENebFJ/89978c80fe97b46d2e80089b19d8cb73/image8.png",1920,1080,{"sys":46061,"__typename":1648,"title":46062,"caption":46062,"layoutMode":59,"file":46063},{"id":40072},"Detecting stolen sessions running on attacker machines. ",{"url":46064,"width":44076,"height":46065},"https://images.ctfassets.net/y1cdw1ablpvd/3Pp4bDB2FkGlHbOEt35j0j/49a92cf3c2f805850eff23bacd43818c/image8.png",398,{"sys":46067,"__typename":1648,"title":46068,"caption":46069,"layoutMode":59,"file":46070},{"id":40114},"Detecting stolen credentials in lastpass","Push shows where stolen credentials have been used to log into an account and the source of the leak",{"url":46071,"width":46072,"height":46073},"https://images.ctfassets.net/y1cdw1ablpvd/HYlWtjgQJdjOYgjmRVMf3/2444a1804ff5c75e88884d75c8735aa8/image8.png",697,668,{"sys":46075,"__typename":1648,"title":46076,"caption":46077,"layoutMode":59,"file":46078},{"id":40160},"Scattered spider image 5","Push identifies where multiple login methods are configured for a single account, as well as when the method was last observed, to surface ghost logins.",{"url":46079,"width":1661,"height":46080},"https://images.ctfassets.net/y1cdw1ablpvd/4LigZHBdaNgpK4vXjr80Ct/5c904257035d6507eff924bff131ced9/image5.png",887,{"sys":46082,"__typename":1648,"title":25579,"caption":25580,"layoutMode":59,"file":46083},{"id":15799},{"url":25582,"width":25583,"height":25584},{"sys":46085,"__typename":22749,"type":22750,"ctaText":35867,"buttonLabel":35868,"buttonColour":22753,"buttonUrl":15827},{"id":15859},{"items":46087},[],{},"How Scattered Spider TTPs are evolving in 2025",{"url":35874},{"items":46092},[46093,46398,47199],{"__typename":1742,"sys":46094,"content":46095,"title":29803,"synopsis":36771,"hashTags":59,"publishedDate":36772,"slug":29804,"tagsCollection":46390,"authorsCollection":46394},{"id":27642},{"json":46096},{"data":46097,"content":46098,"nodeType":1640},{},[46099,46105,46111,46117,46122,46128,46158,46164,46170,46176,46181,46187,46193,46208,46213,46219,46235,46251,46257,46263,46269,46275,46281,46287,46293,46309,46315,46321,46326,46332,46338,46358,46363,46379,46384],{"data":46100,"content":46101,"nodeType":881},{},[46102],{"data":46103,"marks":46104,"value":36437,"nodeType":867},{},[],{"data":46106,"content":46107,"nodeType":881},{},[46108],{"data":46109,"marks":46110,"value":36444,"nodeType":867},{},[],{"data":46112,"content":46113,"nodeType":881},{},[46114],{"data":46115,"marks":46116,"value":36451,"nodeType":867},{},[],{"data":46118,"content":46121,"nodeType":890},{"target":46119},{"sys":46120},{"id":36456,"type":887,"linkType":888},[],{"data":46123,"content":46124,"nodeType":881},{},[46125],{"data":46126,"marks":46127,"value":36464,"nodeType":867},{},[],{"data":46129,"content":46130,"nodeType":3126},{},[46131,46140,46149],{"data":46132,"content":46133,"nodeType":3061},{},[46134],{"data":46135,"content":46136,"nodeType":881},{},[46137],{"data":46138,"marks":46139,"value":36477,"nodeType":867},{},[],{"data":46141,"content":46142,"nodeType":3061},{},[46143],{"data":46144,"content":46145,"nodeType":881},{},[46146],{"data":46147,"marks":46148,"value":36487,"nodeType":867},{},[],{"data":46150,"content":46151,"nodeType":3061},{},[46152],{"data":46153,"content":46154,"nodeType":881},{},[46155],{"data":46156,"marks":46157,"value":36497,"nodeType":867},{},[],{"data":46159,"content":46160,"nodeType":881},{},[46161],{"data":46162,"marks":46163,"value":36504,"nodeType":867},{},[],{"data":46165,"content":46166,"nodeType":918},{},[46167],{"data":46168,"marks":46169,"value":36511,"nodeType":867},{},[],{"data":46171,"content":46172,"nodeType":881},{},[46173],{"data":46174,"marks":46175,"value":36518,"nodeType":867},{},[],{"data":46177,"content":46180,"nodeType":890},{"target":46178},{"sys":46179},{"id":36523,"type":887,"linkType":888},[],{"data":46182,"content":46183,"nodeType":881},{},[46184],{"data":46185,"marks":46186,"value":36531,"nodeType":867},{},[],{"data":46188,"content":46189,"nodeType":918},{},[46190],{"data":46191,"marks":46192,"value":36538,"nodeType":867},{},[],{"data":46194,"content":46195,"nodeType":881},{},[46196,46199,46205],{"data":46197,"marks":46198,"value":36545,"nodeType":867},{},[],{"data":46200,"content":46201,"nodeType":876},{"uri":15633},[46202],{"data":46203,"marks":46204,"value":36552,"nodeType":867},{},[],{"data":46206,"marks":46207,"value":36556,"nodeType":867},{},[],{"data":46209,"content":46212,"nodeType":890},{"target":46210},{"sys":46211},{"id":15742,"type":887,"linkType":888},[],{"data":46214,"content":46215,"nodeType":998},{},[46216],{"data":46217,"marks":46218,"value":36568,"nodeType":867},{},[],{"data":46220,"content":46221,"nodeType":881},{},[46222,46225,46232],{"data":46223,"marks":46224,"value":36575,"nodeType":867},{},[],{"data":46226,"content":46227,"nodeType":876},{"uri":36578},[46228],{"data":46229,"marks":46230,"value":36584,"nodeType":867},{},[46231],{"type":1040},{"data":46233,"marks":46234,"value":36588,"nodeType":867},{},[],{"data":46236,"content":46237,"nodeType":881},{},[46238,46241,46248],{"data":46239,"marks":46240,"value":36595,"nodeType":867},{},[],{"data":46242,"content":46243,"nodeType":876},{"uri":14743},[46244],{"data":46245,"marks":46246,"value":14749,"nodeType":867},{},[46247],{"type":1040},{"data":46249,"marks":46250,"value":36606,"nodeType":867},{},[],{"data":46252,"content":46253,"nodeType":881},{},[46254],{"data":46255,"marks":46256,"value":36613,"nodeType":867},{},[],{"data":46258,"content":46259,"nodeType":881},{},[46260],{"data":46261,"marks":46262,"value":36620,"nodeType":867},{},[],{"data":46264,"content":46265,"nodeType":998},{},[46266],{"data":46267,"marks":46268,"value":36627,"nodeType":867},{},[],{"data":46270,"content":46271,"nodeType":881},{},[46272],{"data":46273,"marks":46274,"value":36634,"nodeType":867},{},[],{"data":46276,"content":46277,"nodeType":881},{},[46278],{"data":46279,"marks":46280,"value":36641,"nodeType":867},{},[],{"data":46282,"content":46283,"nodeType":918},{},[46284],{"data":46285,"marks":46286,"value":36648,"nodeType":867},{},[],{"data":46288,"content":46289,"nodeType":881},{},[46290],{"data":46291,"marks":46292,"value":36655,"nodeType":867},{},[],{"data":46294,"content":46295,"nodeType":881},{},[46296,46299,46306],{"data":46297,"marks":46298,"value":36662,"nodeType":867},{},[],{"data":46300,"content":46301,"nodeType":876},{"uri":36665},[46302],{"data":46303,"marks":46304,"value":36671,"nodeType":867},{},[46305],{"type":1040},{"data":46307,"marks":46308,"value":36675,"nodeType":867},{},[],{"data":46310,"content":46311,"nodeType":881},{},[46312],{"data":46313,"marks":46314,"value":36682,"nodeType":867},{},[],{"data":46316,"content":46317,"nodeType":881},{},[46318],{"data":46319,"marks":46320,"value":36689,"nodeType":867},{},[],{"data":46322,"content":46325,"nodeType":890},{"target":46323},{"sys":46324},{"id":36694,"type":887,"linkType":888},[],{"data":46327,"content":46328,"nodeType":918},{},[46329],{"data":46330,"marks":46331,"value":15817,"nodeType":867},{},[],{"data":46333,"content":46334,"nodeType":881},{},[46335],{"data":46336,"marks":46337,"value":36708,"nodeType":867},{},[],{"data":46339,"content":46340,"nodeType":881},{},[46341,46344,46348,46351,46355],{"data":46342,"marks":46343,"value":36715,"nodeType":867},{},[],{"data":46345,"marks":46346,"value":36720,"nodeType":867},{},[46347],{"type":916},{"data":46349,"marks":46350,"value":36724,"nodeType":867},{},[],{"data":46352,"marks":46353,"value":36729,"nodeType":867},{},[46354],{"type":916},{"data":46356,"marks":46357,"value":36733,"nodeType":867},{},[],{"data":46359,"content":46362,"nodeType":890},{"target":46360},{"sys":46361},{"id":36738,"type":887,"linkType":888},[],{"data":46364,"content":46365,"nodeType":881},{},[46366,46369,46376],{"data":46367,"marks":46368,"value":36746,"nodeType":867},{},[],{"data":46370,"content":46371,"nodeType":876},{"uri":2362},[46372],{"data":46373,"marks":46374,"value":36754,"nodeType":867},{},[46375],{"type":1040},{"data":46377,"marks":46378,"value":36758,"nodeType":867},{},[],{"data":46380,"content":46383,"nodeType":890},{"target":46381},{"sys":46382},{"id":36763,"type":887,"linkType":888},[],{"data":46385,"content":46386,"nodeType":881},{},[46387],{"data":46388,"marks":46389,"value":21,"nodeType":867},{},[],{"items":46391},[46392],{"sys":46393,"name":297},{"id":5646},{"items":46395},[46396],{"fullName":36780,"firstName":36781,"jobTitle":4374,"profilePicture":46397},{"url":36783},{"__typename":1742,"sys":46399,"content":46400,"title":29765,"synopsis":47189,"hashTags":59,"publishedDate":47190,"slug":29766,"tagsCollection":47191,"authorsCollection":47195},{"id":27198},{"json":46401},{"data":46402,"content":46403,"nodeType":1640},{},[46404,46410,46430,46437,46444,46450,46453,46461,46468,46486,46497,46504,46511,46518,46611,46614,46622,46705,46711,46714,46722,46730,46737,46744,46752,46769,46776,46784,46791,46798,46806,46813,46820,46840,46846,46849,46857,46865,46872,46974,46981,46989,46996,47003,47009,47017,47024,47031,47038,47046,47053,47060,47067,47074,47080,47083,47091,47098,47131,47138,47157,47177,47183],{"data":46405,"content":46409,"nodeType":890},{"target":46406},{"sys":46407},{"id":46408,"type":887,"linkType":888},"1eBClNW4NOR66F0tl9h6lD",[],{"data":46411,"content":46412,"nodeType":881},{},[46413,46417,46426],{"data":46414,"marks":46415,"value":46416,"nodeType":867},{},[],"The attacks on Snowflake customers in 2024 collectively constituted the biggest cyber security event of the year in terms of the number of organizations and individuals affected (at least, if you exclude CrowdStrike causing a worldwide outage in July) — certainly, it was the largest perpetrated by a criminal group against commercial enterprises. It has been touted by some news outlets as ‘",{"data":46418,"content":46420,"nodeType":876},{"uri":46419},"https://www.wired.com/story/snowflake-breach-advanced-auto-parts-lendingtree/",[46421],{"data":46422,"marks":46423,"value":46425,"nodeType":867},{},[46424],{"type":1040},"one of the biggest breaches ever",{"data":46427,"marks":46428,"value":46429,"nodeType":867},{},[],"’.  ",{"data":46431,"content":46432,"nodeType":881},{},[46433],{"data":46434,"marks":46435,"value":46436,"nodeType":867},{},[],"Snowflake was a watershed moment that signalled the significant opportunity presented by identity attacks on cloud services. It demonstrated how comparatively unsophisticated methods (logging in to user accounts with stolen credentials and dumping the data) can have the same or greater impact as a traditional network or endpoint based cyber attack involving vulnerability exploitation, malware deployment, ransomware, etc. ",{"data":46438,"content":46439,"nodeType":881},{},[46440],{"data":46441,"marks":46442,"value":46443,"nodeType":867},{},[],"Here’s everything you need to know about the Snowflake attacks — and what you can do to protect yourself against the next Snowflake in the future.",{"data":46445,"content":46449,"nodeType":890},{"target":46446},{"sys":46447},{"id":46448,"type":887,"linkType":888},"4QoPUiP5q6Mwj1eWUZT15Q",[],{"data":46451,"content":46452,"nodeType":908},{},[],{"data":46454,"content":46455,"nodeType":918},{},[46456],{"data":46457,"marks":46458,"value":46460,"nodeType":867},{},[46459],{"type":916},"Snowflake: The facts",{"data":46462,"content":46463,"nodeType":881},{},[46464],{"data":46465,"marks":46466,"value":46467,"nodeType":867},{},[],"Cyber criminals associated with the threat group known as ShinyHunters claimed responsibility for breaching multiple organizations using Snowflake, a cloud-based data warehousing and analytics platform. ",{"data":46469,"content":46470,"nodeType":881},{},[46471,46475,46483],{"data":46472,"marks":46473,"value":46474,"nodeType":867},{},[],"ShinyHunters associates targeted ~165 organizations that were subjected to account takeover attacks using stolen credentials harvested from historical infostealer infections dating back as far as 2020, ",{"data":46476,"content":46477,"nodeType":876},{"uri":6095},[46478],{"data":46479,"marks":46480,"value":46482,"nodeType":867},{},[46481],{"type":1040},"according to Mandiant’s investigation",{"data":46484,"marks":46485,"value":10110,"nodeType":867},{},[],{"data":46487,"content":46488,"nodeType":1433},{},[46489],{"data":46490,"content":46491,"nodeType":881},{},[46492],{"data":46493,"marks":46494,"value":46496,"nodeType":867},{},[46495],{"type":916},">80% of the compromised accounts belonging to Snowflake customers had prior credential exposure. ",{"data":46498,"content":46499,"nodeType":881},{},[46500],{"data":46501,"marks":46502,"value":46503,"nodeType":867},{},[],"The impacted accounts lacked MFA, meaning successful authentication only required a valid username and password. As the Snowflake credentials found in infostealer malware credential dumps had not been rotated or updated, they remained valid and could be used to authenticate to user accounts on Snowflake tenants belonging to various customers.",{"data":46505,"content":46506,"nodeType":881},{},[46507],{"data":46508,"marks":46509,"value":46510,"nodeType":867},{},[],"As a data warehousing platform integrated with a range of connected cloud services, access to a customer’s Snowflake tenant provided attackers with large quantities of sensitive commercial and personal data that could be stolen and monetized by attackers in a variety of ways — such as by ransoming the victim organization, extorting individual end-customers, and selling the data on to other criminal organizations. ",{"data":46512,"content":46513,"nodeType":881},{},[46514],{"data":46515,"marks":46516,"value":46517,"nodeType":867},{},[],"In total, 9 public victims were named following the breach, collectively impacting hundreds of millions of people. ",{"data":46519,"content":46520,"nodeType":3126},{},[46521,46531,46541,46551,46561,46571,46581,46591,46601],{"data":46522,"content":46523,"nodeType":3061},{},[46524],{"data":46525,"content":46526,"nodeType":881},{},[46527],{"data":46528,"marks":46529,"value":46530,"nodeType":867},{},[],"Lending Tree: Sensitive data for over 190 million people available online including customer details, partial credit card numbers, insurance quotes and other information, being sold for $2m.",{"data":46532,"content":46533,"nodeType":3061},{},[46534],{"data":46535,"content":46536,"nodeType":881},{},[46537],{"data":46538,"marks":46539,"value":46540,"nodeType":867},{},[],"Truist Bank: Information belonging to 65,000 employees being sold online for $1m",{"data":46542,"content":46543,"nodeType":3061},{},[46544],{"data":46545,"content":46546,"nodeType":881},{},[46547],{"data":46548,"marks":46549,"value":46550,"nodeType":867},{},[],"Advance Auto Parts: 3TB of data for sale for $1.5 million. Affected 2.3 million people, as well as current and former employees and job applicants.",{"data":46552,"content":46553,"nodeType":3061},{},[46554],{"data":46555,"content":46556,"nodeType":881},{},[46557],{"data":46558,"marks":46559,"value":46560,"nodeType":867},{},[],"Pure Storage: Workspace with 11k customer records including company, email, LDAP username and software version numbers.",{"data":46562,"content":46563,"nodeType":3061},{},[46564],{"data":46565,"content":46566,"nodeType":881},{},[46567],{"data":46568,"marks":46569,"value":46570,"nodeType":867},{},[],"Los Angeles Unified: Student data, disability information, discipline details, and parent information, being sold online for $150k.",{"data":46572,"content":46573,"nodeType":3061},{},[46574],{"data":46575,"content":46576,"nodeType":881},{},[46577],{"data":46578,"marks":46579,"value":46580,"nodeType":867},{},[],"Neiman Marcus: 31m email addresses exposed alongside various personal information.",{"data":46582,"content":46583,"nodeType":3061},{},[46584],{"data":46585,"content":46586,"nodeType":881},{},[46587],{"data":46588,"marks":46589,"value":46590,"nodeType":867},{},[],"Santander: 30 million customer details for sale relating to customers of Santander Chile, Spain, and Uruguay.",{"data":46592,"content":46593,"nodeType":3061},{},[46594],{"data":46595,"content":46596,"nodeType":881},{},[46597],{"data":46598,"marks":46599,"value":46600,"nodeType":867},{},[],"Ticketmaster: 560 million customer details for sale, disruption to events and ticketing worldwide, increasing in scam ticket production.",{"data":46602,"content":46603,"nodeType":3061},{},[46604],{"data":46605,"content":46606,"nodeType":881},{},[46607],{"data":46608,"marks":46609,"value":46610,"nodeType":867},{},[],"AT&T: Call logs stolen for approximately 109 million customers (nearly all of its mobile customers). AT&T paid an undisclosed ransom fee. ",{"data":46612,"content":46613,"nodeType":908},{},[],{"data":46615,"content":46616,"nodeType":918},{},[46617],{"data":46618,"marks":46619,"value":46621,"nodeType":867},{},[46620],{"type":916},"The Snowflake attacks step-by-step",{"data":46623,"content":46624,"nodeType":3126},{},[46625,46635,46645,46655,46665,46675,46685,46695],{"data":46626,"content":46627,"nodeType":3061},{},[46628],{"data":46629,"content":46630,"nodeType":881},{},[46631],{"data":46632,"marks":46633,"value":46634,"nodeType":867},{},[],"Snowflake users were infected with infostealer malware that harvested credentials from user devices over an extended period via several infostealer malware variants, including; VIDAR, RISEPRO, REDLINE, RACOON STEALER, LUMMA and METASTEALER.",{"data":46636,"content":46637,"nodeType":3061},{},[46638],{"data":46639,"content":46640,"nodeType":881},{},[46641],{"data":46642,"marks":46643,"value":46644,"nodeType":867},{},[],"Credentials appeared on criminal marketplaces e.g. dark web forums and Telegram channels.",{"data":46646,"content":46647,"nodeType":3061},{},[46648],{"data":46649,"content":46650,"nodeType":881},{},[46651],{"data":46652,"marks":46653,"value":46654,"nodeType":867},{},[],"ShinyHunters saw the potential in targeting Snowflake users, based on the availability of credentials, number of customer organizations, and the value of the data that can be accessed in Snowflake. ",{"data":46656,"content":46657,"nodeType":3061},{},[46658],{"data":46659,"content":46660,"nodeType":881},{},[46661],{"data":46662,"marks":46663,"value":46664,"nodeType":867},{},[],"ShinyHunters embarked on a large-scale campaign targeting Snowflake customer accounts using previously breached credentials. ",{"data":46666,"content":46667,"nodeType":3061},{},[46668],{"data":46669,"content":46670,"nodeType":881},{},[46671],{"data":46672,"marks":46673,"value":46674,"nodeType":867},{},[],"ShinyHunters accessed user accounts that lacked MFA, belonging to approximately 165 Snowflake customers. ",{"data":46676,"content":46677,"nodeType":3061},{},[46678],{"data":46679,"content":46680,"nodeType":881},{},[46681],{"data":46682,"marks":46683,"value":46684,"nodeType":867},{},[],"ShinyHunters used SQL-based reconnaissance, staging, and data exfiltration techniques, expedited by custom hacker tooling developed specifically for Snowflake, to conduct attacks at scale.",{"data":46686,"content":46687,"nodeType":3061},{},[46688],{"data":46689,"content":46690,"nodeType":881},{},[46691],{"data":46692,"marks":46693,"value":46694,"nodeType":867},{},[],"ShinyHunters acquired massive quantities of Snowflake data based on the information that each customer stored in Snowflake or connected apps. ",{"data":46696,"content":46697,"nodeType":3061},{},[46698],{"data":46699,"content":46700,"nodeType":881},{},[46701],{"data":46702,"marks":46703,"value":46704,"nodeType":867},{},[],"ShinyHunters began attempts to extort Snowflake and end-customers using the data acquired.",{"data":46706,"content":46710,"nodeType":890},{"target":46707},{"sys":46708},{"id":46709,"type":887,"linkType":888},"2J92gFLs1wAAGC4nQTaiWu",[],{"data":46712,"content":46713,"nodeType":908},{},[],{"data":46715,"content":46716,"nodeType":918},{},[46717],{"data":46718,"marks":46719,"value":46721,"nodeType":867},{},[46720],{"type":916},"Why did the Snowflake breaches happen?",{"data":46723,"content":46724,"nodeType":998},{},[46725],{"data":46726,"marks":46727,"value":46729,"nodeType":867},{},[46728],{"type":916},"Stolen credentials remained valid for years",{"data":46731,"content":46732,"nodeType":881},{},[46733],{"data":46734,"marks":46735,"value":46736,"nodeType":867},{},[],"The credentials used to access Snowflake accounts from historical infostealer infections had not been changed or rotated despite dating back as far as 2020, and remained valid. ",{"data":46738,"content":46739,"nodeType":881},{},[46740],{"data":46741,"marks":46742,"value":46743,"nodeType":867},{},[],"This highlights the potential risk of breached credentials already in the public domain, particularly in the case of cloud services like Snowflake that may not be subject to the same levels of credential hygiene as other traditional enterprise domain accounts. ",{"data":46745,"content":46746,"nodeType":998},{},[46747],{"data":46748,"marks":46749,"value":46751,"nodeType":867},{},[46750],{"type":916},"Local logins lacked MFA ",{"data":46753,"content":46754,"nodeType":881},{},[46755,46759,46766],{"data":46756,"marks":46757,"value":46758,"nodeType":867},{},[],"Even where organizations were primarily encouraging employees to use SSO to access their Snowflake tenant, previously created local logins with a username and password continue to exist even after introducing SSO-based logins. Further, MFA was not globally enforceable at the application level, meaning that MFA was only set when logging into an IdP account for SSO, but not for local logins. We call this problem ",{"data":46760,"content":46761,"nodeType":876},{"uri":6845},[46762],{"data":46763,"marks":46764,"value":6850,"nodeType":867},{},[46765],{"type":1040},{"data":46767,"marks":46768,"value":10110,"nodeType":867},{},[],{"data":46770,"content":46771,"nodeType":881},{},[46772],{"data":46773,"marks":46774,"value":46775,"nodeType":867},{},[],"This meant that attackers were able to take over Snowflake accounts with only a single authentication factor (username & password). ",{"data":46777,"content":46778,"nodeType":998},{},[46779],{"data":46780,"marks":46781,"value":46783,"nodeType":867},{},[46782],{"type":916},"Snowflake was a high-value target used by many organizations",{"data":46785,"content":46786,"nodeType":881},{},[46787],{"data":46788,"marks":46789,"value":46790,"nodeType":867},{},[],"As a data warehousing platform used by a vast number of organizations, Snowflake represented a high-value target based on the data typically stored within it, and the repeatable way in which Snowflake users could be targeted. ",{"data":46792,"content":46793,"nodeType":881},{},[46794],{"data":46795,"marks":46796,"value":46797,"nodeType":867},{},[],"The attacker followed a near identical process when targeting Snowflake victims, meaning it could be scripted and executed at scale, with attacks taking a matter of minutes. ",{"data":46799,"content":46800,"nodeType":998},{},[46801],{"data":46802,"marks":46803,"value":46805,"nodeType":867},{},[46804],{"type":916},"Infostealer infections are driving credential availability",{"data":46807,"content":46808,"nodeType":881},{},[46809],{"data":46810,"marks":46811,"value":46812,"nodeType":867},{},[],"Infostealers are often seen as a low-priority issue, but are the primary source of stolen credentials used in campaigns like this one. ",{"data":46814,"content":46815,"nodeType":881},{},[46816],{"data":46817,"marks":46818,"value":46819,"nodeType":867},{},[],"EDR is a strong protection but is often bypassed by infostealers as attackers continually modify them to bypass security controls. Further, unmanaged devices such as those used by third-party contractors or BYOD employees often lack the robust controls applied to company-managed devices and are naturally more susceptible to infostealer attacks. And since browser profiles can be synced across devices, even personal device compromises can result in the capture of corporate credentials.  ",{"data":46821,"content":46822,"nodeType":881},{},[46823,46827,46836],{"data":46824,"marks":46825,"value":46826,"nodeType":867},{},[],"There is some suggestion that targeting key third-party suppliers – ",{"data":46828,"content":46830,"nodeType":876},{"uri":46829},"https://www.wired.com/story/epam-snowflake-ticketmaster-breach-shinyhunters/",[46831],{"data":46832,"marks":46833,"value":46835,"nodeType":867},{},[46834],{"type":1040},"such as EPAM Systems, a software engineering firm and Snowflake ‘Elite Tier Partner’",{"data":46837,"marks":46838,"value":46839,"nodeType":867},{},[]," – provided some of the access to Snowflake customers needed. It’s unclear what came first, but it’s possible (likely, even) that EPAM was identified as a target specifically because of its lucrative customer base and Snowflake credentials — adding another indicator that Snowflake was potentially a premeditated attack inspired by the availability of Snowflake credentials online.",{"data":46841,"content":46845,"nodeType":890},{"target":46842},{"sys":46843},{"id":46844,"type":887,"linkType":888},"4D0gjt5oJLNKJH8GzjP8Je",[],{"data":46847,"content":46848,"nodeType":908},{},[],{"data":46850,"content":46851,"nodeType":918},{},[46852],{"data":46853,"marks":46854,"value":46856,"nodeType":867},{},[46855],{"type":916},"Key takeaways from the Snowflake attacks",{"data":46858,"content":46859,"nodeType":998},{},[46860],{"data":46861,"marks":46862,"value":46864,"nodeType":867},{},[46863],{"type":916},"Securing your IdP accounts is not enough",{"data":46866,"content":46867,"nodeType":881},{},[46868],{"data":46869,"marks":46870,"value":46871,"nodeType":867},{},[],"SSO can help reduce your identity attack surface, but it's not feasible to get every workforce identity behind it.",{"data":46873,"content":46874,"nodeType":3126},{},[46875,46897,46918,46952],{"data":46876,"content":46877,"nodeType":3061},{},[46878],{"data":46879,"content":46880,"nodeType":881},{},[46881,46885,46893],{"data":46882,"marks":46883,"value":46884,"nodeType":867},{},[],"Only 1 in 3 apps support SAML SSO, and those that offer it often charge more for it; the “",{"data":46886,"content":46888,"nodeType":876},{"uri":46887},"https://ssotax.org/",[46889],{"data":46890,"marks":46891,"value":42836,"nodeType":867},{},[46892],{"type":1040},{"data":46894,"marks":46895,"value":46896,"nodeType":867},{},[],"”.",{"data":46898,"content":46899,"nodeType":3061},{},[46900],{"data":46901,"content":46902,"nodeType":881},{},[46903,46907,46915],{"data":46904,"marks":46905,"value":46906,"nodeType":867},{},[],"Many apps are self-adopted by employees, leaving security teams unaware and unable to enforce SSO.  The typical organization has ",{"data":46908,"content":46909,"nodeType":876},{"uri":6833},[46910],{"data":46911,"marks":46912,"value":46914,"nodeType":867},{},[46913],{"type":1040},"hundreds of apps and thousands of unmanaged identities outside of SSO",{"data":46916,"marks":46917,"value":1947,"nodeType":867},{},[],{"data":46919,"content":46920,"nodeType":3061},{},[46921],{"data":46922,"content":46923,"nodeType":881},{},[46924,46928,46935,46939,46948],{"data":46925,"marks":46926,"value":46927,"nodeType":867},{},[],"Most apps do not prevent users from creating additional \"",{"data":46929,"content":46930,"nodeType":876},{"uri":6845},[46931],{"data":46932,"marks":46933,"value":21439,"nodeType":867},{},[46934],{"type":1040},{"data":46936,"marks":46937,"value":46938,"nodeType":867},{},[],"\" methods outside of SSO (especially by default), accounting for around ",{"data":46940,"content":46942,"nodeType":876},{"uri":46941},"https://pushsecurity.com/blog/how-many-vulnerable-identities-do-you-have/#id-identity-configurations-and-how-they-can-be-exploited_id-many-accounts-lack-the-most-basic-protections",[46943],{"data":46944,"marks":46945,"value":46947,"nodeType":867},{},[46946],{"type":1040},"10% of all identities",{"data":46949,"marks":46950,"value":46951,"nodeType":867},{},[]," observed by Push. ",{"data":46953,"content":46954,"nodeType":3061},{},[46955],{"data":46956,"content":46957,"nodeType":881},{},[46958,46962,46970],{"data":46959,"marks":46960,"value":46961,"nodeType":867},{},[],"In total, we identified that ",{"data":46963,"content":46964,"nodeType":876},{"uri":6833},[46965],{"data":46966,"marks":46967,"value":46969,"nodeType":867},{},[46968],{"type":1040},"37% (2 in 5) accounts have a password login set with no MFA",{"data":46971,"marks":46972,"value":46973,"nodeType":867},{},[],", while 9% have no MFA AND a weak, breached, or reused password.",{"data":46975,"content":46976,"nodeType":881},{},[46977],{"data":46978,"marks":46979,"value":46980,"nodeType":867},{},[],"So, relying on locked-down IdP accounts and maximising the use of SSO is an important pillar of an effective identity security strategy, but there will always be gaps. Unless you recognize this, you may be blindsided by attackers finding them before you do. ",{"data":46982,"content":46983,"nodeType":998},{},[46984],{"data":46985,"marks":46986,"value":46988,"nodeType":867},{},[46987],{"type":916},"The threat of infostealers and stolen credentials needs to be taken seriously",{"data":46990,"content":46991,"nodeType":881},{},[46992],{"data":46993,"marks":46994,"value":46995,"nodeType":867},{},[],"Breached credentials appearing online is not always seen as a top priority for security teams, particularly when there’s so much noise from all of the outdated or simply erroneous findings (anyone that’s ever subscribed to a credential TI feed knows the pain of this). ",{"data":46997,"content":46998,"nodeType":881},{},[46999],{"data":47000,"marks":47001,"value":47002,"nodeType":867},{},[],"But Snowflake serves as a stark reminder that despite all the false positives, stolen credentials are sometimes valid — and when weaponized at-scale they can be a powerful tool for attackers. ",{"data":47004,"content":47008,"nodeType":890},{"target":47005},{"sys":47006},{"id":47007,"type":887,"linkType":888},"4EODpwKsqNivpvP2yMtZCd",[],{"data":47010,"content":47011,"nodeType":998},{},[47012],{"data":47013,"marks":47014,"value":47016,"nodeType":867},{},[47015],{"type":916},"Don’t rely on third-parties to protect your identities for you",{"data":47018,"content":47019,"nodeType":881},{},[47020],{"data":47021,"marks":47022,"value":47023,"nodeType":867},{},[],"Snowflake came under fire following the attacks for not enabling MFA by default, or giving security teams sufficient tools to deal with the incident. ",{"data":47025,"content":47026,"nodeType":881},{},[47027],{"data":47028,"marks":47029,"value":47030,"nodeType":867},{},[],"This is perhaps justifiable, but is hardly the exception. Very few apps enforce MFA by default or provide a global MFA enforcement mechanism. Most don’t even provide audit logs (and when they do, the scope of logging is pretty limited). And we regularly encounter apps that don’t give you any information about account configuration as an admin — like which accounts have MFA, or the login methods that they’re using (e.g. SSO via SAML, SSO via OIDC, password, which IdPs are being used…) which is essential information to be able to secure your identity attack surface. ",{"data":47032,"content":47033,"nodeType":881},{},[47034],{"data":47035,"marks":47036,"value":47037,"nodeType":867},{},[],"Yes, it would be great if app vendors put security first and made controls available by default, for all customers (not just the premium ones). But in the absence of an industrywide shift toward security-first product development, it’s important that organizations don’t just point the finger at service providers — and take matters into their own hands when it comes to securing their user identities. ",{"data":47039,"content":47040,"nodeType":998},{},[47041],{"data":47042,"marks":47043,"value":47045,"nodeType":867},{},[47044],{"type":916},"This isn’t a specific Snowflake problem — it could have been any application",{"data":47047,"content":47048,"nodeType":881},{},[47049],{"data":47050,"marks":47051,"value":47052,"nodeType":867},{},[],"While Snowflake was admittedly a high-value target because of the data it collected, apps with sensitive data (or with integrations connecting them to data collected in adjacent apps) are not in short supply. ",{"data":47054,"content":47055,"nodeType":881},{},[47056],{"data":47057,"marks":47058,"value":47059,"nodeType":867},{},[],"If we accept that many other apps are similarly desirable targets, then we should also consider that it’s unlikely that Snowflake is the only app that has valid credentials sitting around on the internet, waiting to be weaponized by criminals. Equally, it’s not the only app that doesn’t require mandatory MFA for user accounts, as we discussed above. The next Snowflake is likely to lurk in the same breached datasets, possibly even using the same credentials.",{"data":47061,"content":47062,"nodeType":881},{},[47063],{"data":47064,"marks":47065,"value":47066,"nodeType":867},{},[],"There’s been a clear increase in the number of infostealer and stolen credential related breaches and news stories since Snowflake as attackers wise up to the potential opportunity and start seeing the dollar signs. It would be naive to think that this was a one off event — the next Snowflake is probably not too far away. ",{"data":47068,"content":47069,"nodeType":881},{},[47070],{"data":47071,"marks":47072,"value":47073,"nodeType":867},{},[],"For a deep-dive analysis of the impact of Snowflake, check out our on-demand webinar from earlier this year.",{"data":47075,"content":47079,"nodeType":890},{"target":47076},{"sys":47077},{"id":47078,"type":887,"linkType":888},"7LkU5DqE9HJ1PQu9BTg6Mw",[],{"data":47081,"content":47082,"nodeType":908},{},[],{"data":47084,"content":47085,"nodeType":918},{},[47086],{"data":47087,"marks":47088,"value":47090,"nodeType":867},{},[47089],{"type":916},"How to protect yourself from the next Snowflake using Push",{"data":47092,"content":47093,"nodeType":881},{},[47094],{"data":47095,"marks":47096,"value":47097,"nodeType":867},{},[],"Organizations looking to reduce their exposure to account takeover using stolen credentials should look to:",{"data":47099,"content":47100,"nodeType":3126},{},[47101,47111,47121],{"data":47102,"content":47103,"nodeType":3061},{},[47104],{"data":47105,"content":47106,"nodeType":881},{},[47107],{"data":47108,"marks":47109,"value":47110,"nodeType":867},{},[],"Identify the apps being used across the business and locate vulnerable workforce identities using weak, breached, or reused credentials, and missing MFA. Where SSO is the preferred login method, local username & password logins should ideally be removed. ",{"data":47112,"content":47113,"nodeType":3061},{},[47114],{"data":47115,"content":47116,"nodeType":881},{},[47117],{"data":47118,"marks":47119,"value":47120,"nodeType":867},{},[],"Where credentials appear in third-party data breaches, verify where they are still valid and ensure that the credentials are changed. ",{"data":47122,"content":47123,"nodeType":3061},{},[47124],{"data":47125,"content":47126,"nodeType":881},{},[47127],{"data":47128,"marks":47129,"value":47130,"nodeType":867},{},[],"Detect unauthorized access to workforce identities where sessions are initiated or resumed from unusual or unexpected locations. It should be noted that while this is a fairly common feature for larger enterprise cloud platforms with configurable access control policies, this is not typically possible for most SaaS applications.  ",{"data":47132,"content":47133,"nodeType":881},{},[47134],{"data":47135,"marks":47136,"value":47137,"nodeType":867},{},[],"All of these use cases can be achieved using Push. The Push browser extension detects all logins performed in employee browsers, capturing granular information about the login method and MFA types used, and enriching this data by integrating with your preferred IdP.",{"data":47139,"content":47140,"nodeType":881},{},[47141,47145,47153],{"data":47142,"marks":47143,"value":47144,"nodeType":867},{},[],"Push’s ",{"data":47146,"content":47148,"nodeType":876},{"uri":47147},"https://pushsecurity.com/blog/verified-stolen-credential-detection",[47149],{"data":47150,"marks":47151,"value":47152,"nodeType":867},{},[],"verified stolen credential detection feature",{"data":47154,"marks":47155,"value":47156,"nodeType":867},{},[]," compares a k-anonymized hash of user passwords observed with stolen credential TI feeds to cut through the noise and identify where stolen credentials appearing online represent a genuine vulnerability.   ",{"data":47158,"content":47159,"nodeType":881},{},[47160,47164,47173],{"data":47161,"marks":47162,"value":47163,"nodeType":867},{},[],"On top of this, all logins made in browsers protected by the Push extension, across every app, are verified by ",{"data":47165,"content":47167,"nodeType":876},{"uri":47166},"https://pushsecurity.com/blog/introducing-session-token-theft-detection-why-browser-is-best/",[47168],{"data":47169,"marks":47170,"value":47172,"nodeType":867},{},[47171],{"type":1040},"adding a unique marker to the user agent string of the session",{"data":47174,"marks":47175,"value":47176,"nodeType":867},{},[],", which will then appear in your IdP logs. This means that any session occurring outside of the Push-protected estate can be flagged to your security team via SIEM alert — including where an attacker uses stolen credentials to log into an app from a browser without the Push extension running. ",{"data":47178,"content":47182,"nodeType":890},{"target":47179},{"sys":47180},{"id":47181,"type":887,"linkType":888},"3tqVk7Vr7pYLOEVukIJM2g",[],{"data":47184,"content":47185,"nodeType":881},{},[47186],{"data":47187,"marks":47188,"value":21,"nodeType":867},{},[],"165 Snowflake customers were targeted by criminals using stolen credentials from infostealer infections, impacting hundreds of millions of people. ","2024-11-29T00:00:00.000Z",{"items":47192},[47193],{"sys":47194,"name":2547},{"id":2546},{"items":47196},[47197],{"fullName":849,"firstName":850,"jobTitle":851,"profilePicture":47198},{"url":855},{"__typename":1742,"sys":47200,"content":47201,"title":37402,"synopsis":37403,"hashTags":59,"publishedDate":37404,"slug":37405,"tagsCollection":47742,"authorsCollection":47748},{"id":36786},{"json":47202},{"data":47203,"content":47204,"nodeType":1640},{},[47205,47211,47217,47224,47247,47253,47258,47261,47268,47274,47280,47319,47325,47331,47334,47341,47347,47353,47359,47375,47381,47386,47393,47399,47405,47411,47416,47419,47426,47433,47439,47446,47452,47510,47516,47523,47529,47559,47566,47572,47579,47585,47592,47598,47646,47652,47655,47662,47668,47683,47713,47731,47736],{"data":47206,"content":47207,"nodeType":881},{},[47208],{"data":47209,"marks":47210,"value":36797,"nodeType":867},{},[],{"data":47212,"content":47213,"nodeType":881},{},[47214],{"data":47215,"marks":47216,"value":36804,"nodeType":867},{},[],{"data":47218,"content":47219,"nodeType":881},{},[47220],{"data":47221,"marks":47222,"value":36812,"nodeType":867},{},[47223],{"type":916},{"data":47225,"content":47226,"nodeType":881},{},[47227,47230,47237,47240,47244],{"data":47228,"marks":47229,"value":36819,"nodeType":867},{},[],{"data":47231,"content":47232,"nodeType":876},{"uri":36822},[47233],{"data":47234,"marks":47235,"value":36828,"nodeType":867},{},[47236],{"type":1040},{"data":47238,"marks":47239,"value":36832,"nodeType":867},{},[],{"data":47241,"marks":47242,"value":36837,"nodeType":867},{},[47243],{"type":1431},{"data":47245,"marks":47246,"value":36841,"nodeType":867},{},[],{"data":47248,"content":47249,"nodeType":881},{},[47250],{"data":47251,"marks":47252,"value":36848,"nodeType":867},{},[],{"data":47254,"content":47257,"nodeType":890},{"target":47255},{"sys":47256},{"id":36853,"type":887,"linkType":888},[],{"data":47259,"content":47260,"nodeType":908},{},[],{"data":47262,"content":47263,"nodeType":918},{},[47264],{"data":47265,"marks":47266,"value":36865,"nodeType":867},{},[47267],{"type":916},{"data":47269,"content":47270,"nodeType":881},{},[47271],{"data":47272,"marks":47273,"value":36872,"nodeType":867},{},[],{"data":47275,"content":47276,"nodeType":881},{},[47277],{"data":47278,"marks":47279,"value":36879,"nodeType":867},{},[],{"data":47281,"content":47282,"nodeType":3126},{},[47283,47292,47301,47310],{"data":47284,"content":47285,"nodeType":3061},{},[47286],{"data":47287,"content":47288,"nodeType":881},{},[47289],{"data":47290,"marks":47291,"value":36892,"nodeType":867},{},[],{"data":47293,"content":47294,"nodeType":3061},{},[47295],{"data":47296,"content":47297,"nodeType":881},{},[47298],{"data":47299,"marks":47300,"value":36902,"nodeType":867},{},[],{"data":47302,"content":47303,"nodeType":3061},{},[47304],{"data":47305,"content":47306,"nodeType":881},{},[47307],{"data":47308,"marks":47309,"value":36912,"nodeType":867},{},[],{"data":47311,"content":47312,"nodeType":3061},{},[47313],{"data":47314,"content":47315,"nodeType":881},{},[47316],{"data":47317,"marks":47318,"value":36922,"nodeType":867},{},[],{"data":47320,"content":47321,"nodeType":881},{},[47322],{"data":47323,"marks":47324,"value":36929,"nodeType":867},{},[],{"data":47326,"content":47327,"nodeType":881},{},[47328],{"data":47329,"marks":47330,"value":36936,"nodeType":867},{},[],{"data":47332,"content":47333,"nodeType":908},{},[],{"data":47335,"content":47336,"nodeType":918},{},[47337],{"data":47338,"marks":47339,"value":36947,"nodeType":867},{},[47340],{"type":916},{"data":47342,"content":47343,"nodeType":881},{},[47344],{"data":47345,"marks":47346,"value":36954,"nodeType":867},{},[],{"data":47348,"content":47349,"nodeType":881},{},[47350],{"data":47351,"marks":47352,"value":36961,"nodeType":867},{},[],{"data":47354,"content":47355,"nodeType":881},{},[47356],{"data":47357,"marks":47358,"value":36968,"nodeType":867},{},[],{"data":47360,"content":47361,"nodeType":881},{},[47362,47365,47372],{"data":47363,"marks":47364,"value":36975,"nodeType":867},{},[],{"data":47366,"content":47367,"nodeType":876},{"uri":6114},[47368],{"data":47369,"marks":47370,"value":33785,"nodeType":867},{},[47371],{"type":1040},{"data":47373,"marks":47374,"value":36986,"nodeType":867},{},[],{"data":47376,"content":47377,"nodeType":881},{},[47378],{"data":47379,"marks":47380,"value":36993,"nodeType":867},{},[],{"data":47382,"content":47385,"nodeType":890},{"target":47383},{"sys":47384},{"id":36998,"type":887,"linkType":888},[],{"data":47387,"content":47388,"nodeType":918},{},[47389],{"data":47390,"marks":47391,"value":37007,"nodeType":867},{},[47392],{"type":916},{"data":47394,"content":47395,"nodeType":881},{},[47396],{"data":47397,"marks":47398,"value":37014,"nodeType":867},{},[],{"data":47400,"content":47401,"nodeType":881},{},[47402],{"data":47403,"marks":47404,"value":37021,"nodeType":867},{},[],{"data":47406,"content":47407,"nodeType":881},{},[47408],{"data":47409,"marks":47410,"value":37028,"nodeType":867},{},[],{"data":47412,"content":47415,"nodeType":890},{"target":47413},{"sys":47414},{"id":37033,"type":887,"linkType":888},[],{"data":47417,"content":47418,"nodeType":908},{},[],{"data":47420,"content":47421,"nodeType":918},{},[47422],{"data":47423,"marks":47424,"value":37045,"nodeType":867},{},[47425],{"type":916},{"data":47427,"content":47428,"nodeType":998},{},[47429],{"data":47430,"marks":47431,"value":37053,"nodeType":867},{},[47432],{"type":916},{"data":47434,"content":47435,"nodeType":881},{},[47436],{"data":47437,"marks":47438,"value":37060,"nodeType":867},{},[],{"data":47440,"content":47441,"nodeType":998},{},[47442],{"data":47443,"marks":47444,"value":37068,"nodeType":867},{},[47445],{"type":916},{"data":47447,"content":47448,"nodeType":881},{},[47449],{"data":47450,"marks":47451,"value":37075,"nodeType":867},{},[],{"data":47453,"content":47454,"nodeType":3126},{},[47455,47464,47473,47492,47501],{"data":47456,"content":47457,"nodeType":3061},{},[47458],{"data":47459,"content":47460,"nodeType":881},{},[47461],{"data":47462,"marks":47463,"value":37088,"nodeType":867},{},[],{"data":47465,"content":47466,"nodeType":3061},{},[47467],{"data":47468,"content":47469,"nodeType":881},{},[47470],{"data":47471,"marks":47472,"value":37098,"nodeType":867},{},[],{"data":47474,"content":47475,"nodeType":3061},{},[47476],{"data":47477,"content":47478,"nodeType":881},{},[47479,47482,47489],{"data":47480,"marks":47481,"value":37108,"nodeType":867},{},[],{"data":47483,"content":47484,"nodeType":876},{"uri":37111},[47485],{"data":47486,"marks":47487,"value":37117,"nodeType":867},{},[47488],{"type":1040},{"data":47490,"marks":47491,"value":21,"nodeType":867},{},[],{"data":47493,"content":47494,"nodeType":3061},{},[47495],{"data":47496,"content":47497,"nodeType":881},{},[47498],{"data":47499,"marks":47500,"value":37130,"nodeType":867},{},[],{"data":47502,"content":47503,"nodeType":3061},{},[47504],{"data":47505,"content":47506,"nodeType":881},{},[47507],{"data":47508,"marks":47509,"value":37140,"nodeType":867},{},[],{"data":47511,"content":47512,"nodeType":881},{},[47513],{"data":47514,"marks":47515,"value":37147,"nodeType":867},{},[],{"data":47517,"content":47518,"nodeType":998},{},[47519],{"data":47520,"marks":47521,"value":37155,"nodeType":867},{},[47522],{"type":916},{"data":47524,"content":47525,"nodeType":881},{},[47526],{"data":47527,"marks":47528,"value":37162,"nodeType":867},{},[],{"data":47530,"content":47531,"nodeType":3126},{},[47532,47541,47550],{"data":47533,"content":47534,"nodeType":3061},{},[47535],{"data":47536,"content":47537,"nodeType":881},{},[47538],{"data":47539,"marks":47540,"value":37175,"nodeType":867},{},[],{"data":47542,"content":47543,"nodeType":3061},{},[47544],{"data":47545,"content":47546,"nodeType":881},{},[47547],{"data":47548,"marks":47549,"value":37185,"nodeType":867},{},[],{"data":47551,"content":47552,"nodeType":3061},{},[47553],{"data":47554,"content":47555,"nodeType":881},{},[47556],{"data":47557,"marks":47558,"value":37195,"nodeType":867},{},[],{"data":47560,"content":47561,"nodeType":998},{},[47562],{"data":47563,"marks":47564,"value":37203,"nodeType":867},{},[47565],{"type":916},{"data":47567,"content":47568,"nodeType":881},{},[47569],{"data":47570,"marks":47571,"value":37210,"nodeType":867},{},[],{"data":47573,"content":47574,"nodeType":998},{},[47575],{"data":47576,"marks":47577,"value":37218,"nodeType":867},{},[47578],{"type":916},{"data":47580,"content":47581,"nodeType":881},{},[47582],{"data":47583,"marks":47584,"value":37225,"nodeType":867},{},[],{"data":47586,"content":47587,"nodeType":998},{},[47588],{"data":47589,"marks":47590,"value":37233,"nodeType":867},{},[47591],{"type":916},{"data":47593,"content":47594,"nodeType":881},{},[47595],{"data":47596,"marks":47597,"value":37240,"nodeType":867},{},[],{"data":47599,"content":47600,"nodeType":3126},{},[47601,47610,47619,47628,47637],{"data":47602,"content":47603,"nodeType":3061},{},[47604],{"data":47605,"content":47606,"nodeType":881},{},[47607],{"data":47608,"marks":47609,"value":37253,"nodeType":867},{},[],{"data":47611,"content":47612,"nodeType":3061},{},[47613],{"data":47614,"content":47615,"nodeType":881},{},[47616],{"data":47617,"marks":47618,"value":37263,"nodeType":867},{},[],{"data":47620,"content":47621,"nodeType":3061},{},[47622],{"data":47623,"content":47624,"nodeType":881},{},[47625],{"data":47626,"marks":47627,"value":37273,"nodeType":867},{},[],{"data":47629,"content":47630,"nodeType":3061},{},[47631],{"data":47632,"content":47633,"nodeType":881},{},[47634],{"data":47635,"marks":47636,"value":37283,"nodeType":867},{},[],{"data":47638,"content":47639,"nodeType":3061},{},[47640],{"data":47641,"content":47642,"nodeType":881},{},[47643],{"data":47644,"marks":47645,"value":37293,"nodeType":867},{},[],{"data":47647,"content":47648,"nodeType":881},{},[47649],{"data":47650,"marks":47651,"value":37300,"nodeType":867},{},[],{"data":47653,"content":47654,"nodeType":908},{},[],{"data":47656,"content":47657,"nodeType":918},{},[47658],{"data":47659,"marks":47660,"value":37311,"nodeType":867},{},[47661],{"type":916},{"data":47663,"content":47664,"nodeType":881},{},[47665],{"data":47666,"marks":47667,"value":37318,"nodeType":867},{},[],{"data":47669,"content":47670,"nodeType":881},{},[47671,47674,47680],{"data":47672,"marks":47673,"value":37325,"nodeType":867},{},[],{"data":47675,"content":47676,"nodeType":876},{"uri":36822},[47677],{"data":47678,"marks":47679,"value":37332,"nodeType":867},{},[],{"data":47681,"marks":47682,"value":1947,"nodeType":867},{},[],{"data":47684,"content":47685,"nodeType":3126},{},[47686,47695,47704],{"data":47687,"content":47688,"nodeType":3061},{},[47689],{"data":47690,"content":47691,"nodeType":881},{},[47692],{"data":47693,"marks":47694,"value":37348,"nodeType":867},{},[],{"data":47696,"content":47697,"nodeType":3061},{},[47698],{"data":47699,"content":47700,"nodeType":881},{},[47701],{"data":47702,"marks":47703,"value":37358,"nodeType":867},{},[],{"data":47705,"content":47706,"nodeType":3061},{},[47707],{"data":47708,"content":47709,"nodeType":881},{},[47710],{"data":47711,"marks":47712,"value":37368,"nodeType":867},{},[],{"data":47714,"content":47715,"nodeType":881},{},[47716,47720,47727],{"data":47717,"marks":47718,"value":37376,"nodeType":867},{},[47719],{"type":916},{"data":47721,"content":47722,"nodeType":876},{"uri":2362},[47723],{"data":47724,"marks":47725,"value":37384,"nodeType":867},{},[47726],{"type":916},{"data":47728,"marks":47729,"value":37389,"nodeType":867},{},[47730],{"type":916},{"data":47732,"content":47735,"nodeType":890},{"target":47733},{"sys":47734},{"id":37394,"type":887,"linkType":888},[],{"data":47737,"content":47738,"nodeType":881},{},[47739],{"data":47740,"marks":47741,"value":21,"nodeType":867},{},[],{"items":47743},[47744,47746],{"sys":47745,"name":2547},{"id":2546},{"sys":47747,"name":342},{"id":2550},{"items":47749},[47750],{"fullName":37415,"firstName":37416,"jobTitle":4374,"profilePicture":47751},{"url":37418},"blog/scattered-spider-ttp-evolution-in-2025",{"json":47754},{"data":47755,"content":47756,"nodeType":1640},{},[47757],{"data":47758,"content":47759,"nodeType":881},{},[47760],{"data":47761,"marks":47762,"value":47763,"nodeType":867},{},[],"How the notorious Scattered Spider cyber criminal group are evolving their TTPs in 2025 to bypass security controls like MFA and take over accounts on internet applications and services. ",{"id":27581,"publishedAt":47765},"2026-08-13T09:35:46.987Z",{"items":47767},[47768,47770],{"sys":47769,"name":2547},{"id":2546},{"sys":47771,"name":342},{"id":2550},{"items":47773},[47774,47776,47778,47780,47782,47784,47786,47788,47790,47792,47794,47796,47798,47800,47802,47804,47806,47808,47810,47812,47814,47816,47818,47820],{"sys":47775,"name":279,"slug":280,"tier":31},{"id":276},{"sys":47777,"name":413,"slug":414,"tier":31},{"id":410},{"sys":47779,"name":519,"slug":520,"tier":31},{"id":516},{"sys":47781,"name":642,"slug":643,"tier":31},{"id":639},{"sys":47783,"name":342,"slug":343,"tier":31},{"id":339},{"sys":47785,"name":545,"slug":546,"tier":31},{"id":542},{"sys":47787,"name":650,"slug":651,"tier":45},{"id":647},{"sys":47789,"name":261,"slug":262,"tier":45},{"id":258},{"sys":47791,"name":466,"slug":467,"tier":45},{"id":463},{"sys":47793,"name":404,"slug":405,"tier":45},{"id":401},{"sys":47795,"name":333,"slug":334,"tier":45},{"id":330},{"sys":47797,"name":324,"slug":325,"tier":45},{"id":321},{"sys":47799,"name":607,"slug":608,"tier":45},{"id":604},{"sys":47801,"name":422,"slug":423,"tier":45},{"id":419},{"sys":47803,"name":571,"slug":572,"tier":45},{"id":568},{"sys":47805,"name":395,"slug":396,"tier":45},{"id":392},{"sys":47807,"name":484,"slug":485,"tier":45},{"id":481},{"sys":47809,"name":537,"slug":538,"tier":45},{"id":534},{"sys":47811,"name":457,"slug":458,"tier":45},{"id":454},{"sys":47813,"name":511,"slug":512,"tier":45},{"id":508},{"sys":47815,"name":502,"slug":503,"tier":45},{"id":499},{"sys":47817,"name":475,"slug":476,"tier":45},{"id":472},{"sys":47819,"name":440,"slug":441,"tier":45},{"id":437},{"sys":47821,"name":528,"slug":529,"tier":45},{"id":525},"oLIODxEHsA2m841saCx3-KU2xiG-Qo5TlaPa70w1JEg",{"id":47824,"title":47825,"authorsCollection":47826,"content":47831,"extension":228,"faqItemsCollection":50795,"faqTitle":59,"featured":6,"hashTags":59,"meta":50797,"metaTitle":50798,"ogImage":50799,"postType":8156,"publishedDate":50801,"relatedBlogPostsCollection":50802,"slug":51615,"stem":51616,"subtitle":59,"summary":51617,"synopsis":51632,"sys":51633,"tagsCollection":51636,"topicsCollection":51642,"__hash__":51684},"blog/blog/identity-attacks-in-the-wild.json","Tracking identity-based attacks in the wild",{"items":47827},[47828],{"fullName":849,"firstName":850,"jobTitle":851,"socialLinks":47829,"profilePicture":47830},[853],{"url":855},{"json":47832,"links":50782},{"data":47833,"content":47834,"nodeType":1640},{},[47835,47842,47874,47881,47887,47894,47914,47937,47944,47951,47975,47991,47998,48010,48017,48020,48027,48034,48050,48062,48073,48103,48106,48113,48131,48138,48146,48239,48246,48382,48389,48509,48516,48523,48696,48703,48710,48793,48796,48803,48810,48817,48880,48887,48920,48927,48970,48976,48982,49219,49225,49233,49240,49243,49250,49257,49264,49317,49324,49367,49374,49407,49413,49419,49585,49591,49599,49606,49614,49621,49629,49636,49639,49646,49653,49660,49723,49730,49763,49770,49803,49809,49815,49921,49924,49931,49938,49945,50008,50015,50048,50055,50088,50094,50100,50275,50278,50285,50292,50299,50372,50379,50412,50419,50452,50458,50464,50696,50699,50706,50713,50720,50727,50730,50737,50744,50751,50754,50761,50768,50775],{"data":47836,"content":47837,"nodeType":918},{},[47838],{"data":47839,"marks":47840,"value":47841,"nodeType":867},{},[],"Browser-based Identity attacks on the rise?",{"data":47843,"content":47844,"nodeType":881},{},[47845,47849,47858,47862,47871],{"data":47846,"marks":47847,"value":47848,"nodeType":867},{},[],"Identity has been recorded as the #1 cyber attack vector since forever. You don’t have to look particularly hard to find statistics to support this. In 2023, one source reports that ",{"data":47850,"content":47852,"nodeType":876},{"uri":47851},"https://www.csoonline.com/article/648894/identity-based-security-threats-are-growing-rapidly-report.html",[47853],{"data":47854,"marks":47855,"value":47857,"nodeType":867},{},[47856],{"type":1040},"4/5 breaches involved identity and compromised credentials",{"data":47859,"marks":47860,"value":47861,"nodeType":867},{},[],", while another suggests that ",{"data":47863,"content":47865,"nodeType":876},{"uri":47864},"https://rakgarg.substack.com/p/identity-crisis-the-biggest-prize",[47866],{"data":47867,"marks":47868,"value":47870,"nodeType":867},{},[47869],{"type":1040},"75% of breaches are caused by mismanaged identity, access, or privileges",{"data":47872,"marks":47873,"value":1947,"nodeType":867},{},[],{"data":47875,"content":47876,"nodeType":881},{},[47877],{"data":47878,"marks":47879,"value":47880,"nodeType":867},{},[],"Phishing, social engineering, credential stuffing, and business email compromise have morphed into a homogenous understanding of identity threats that are generally tackled through a combination of email security tooling, content access controls, and user awareness. ",{"data":47882,"content":47886,"nodeType":890},{"target":47883},{"sys":47884},{"id":47885,"type":887,"linkType":888},"5NRWvCl0xsoWcpgHbcQIkf",[],{"data":47888,"content":47889,"nodeType":881},{},[47890],{"data":47891,"marks":47892,"value":47893,"nodeType":867},{},[],"The fact that such attacks have been reported as the top security threat for so long probably means that people pay less attention to identity threats. Ransomware grabs the headlines, and rightly so in many cases, but phishing feels like a “known known” that we have a plan for (even if the plan often fails). ",{"data":47895,"content":47896,"nodeType":881},{},[47897,47901,47910],{"data":47898,"marks":47899,"value":47900,"nodeType":867},{},[],"In fact, there’s a problem with messaging generally. The ",{"data":47902,"content":47904,"nodeType":876},{"uri":47903},"https://www.verizon.com/business/resources/T78/reports/data-breach-investigation-report_2015.pdf",[47905],{"data":47906,"marks":47907,"value":47909,"nodeType":867},{},[47908],{"type":1040},"2015 Verizon DBIR",{"data":47911,"marks":47912,"value":47913,"nodeType":867},{},[]," contains plenty of stats that still ring largely true today. For example:",{"data":47915,"content":47916,"nodeType":3126},{},[47917,47927],{"data":47918,"content":47919,"nodeType":3061},{},[47920],{"data":47921,"content":47922,"nodeType":881},{},[47923],{"data":47924,"marks":47925,"value":47926,"nodeType":867},{},[],"In the 2013 DBIR, phishing was associated with over 95% of incidents attributed to state sponsored actors, and for two years running, more than two-thirds of incidents have featured phishing",{"data":47928,"content":47929,"nodeType":3061},{},[47930],{"data":47931,"content":47932,"nodeType":881},{},[47933],{"data":47934,"marks":47935,"value":47936,"nodeType":867},{},[],"In 60% of cases, attackers are able to compromise an organization within minutes",{"data":47938,"content":47939,"nodeType":881},{},[47940],{"data":47941,"marks":47942,"value":47943,"nodeType":867},{},[],"Remove the dates and a lot of the report still stands up. ",{"data":47945,"content":47946,"nodeType":998},{},[47947],{"data":47948,"marks":47949,"value":47950,"nodeType":867},{},[],"Bad then, worse now",{"data":47952,"content":47953,"nodeType":881},{},[47954,47958,47963,47967,47972],{"data":47955,"marks":47956,"value":47957,"nodeType":867},{},[],"But browser-based identity attacks ",{"data":47959,"marks":47960,"value":47962,"nodeType":867},{},[47961],{"type":916},"are",{"data":47964,"marks":47965,"value":47966,"nodeType":867},{},[]," worse than they used to be. Yes, credential stuffing, phishing, and SIM swapping may not be the most sophisticated attacks, but they remain as effective as ever. ",{"data":47968,"marks":47969,"value":47971,"nodeType":867},{},[47970],{"type":1431},"As the saying goes, if it ain’t broke — don’t fix it.",{"data":47973,"marks":47974,"value":17303,"nodeType":867},{},[],{"data":47976,"content":47977,"nodeType":881},{},[47978,47982,47987],{"data":47979,"marks":47980,"value":47981,"nodeType":867},{},[],"Recent attacks have moved toward a broader targeting of the ",{"data":47983,"marks":47984,"value":47986,"nodeType":867},{},[47985],{"type":916},"identity infrastructure",{"data":47988,"marks":47989,"value":47990,"nodeType":867},{},[],". While phishing and social engineering was once primarily a delivery mechanism for malicious payloads to be executed on endpoint, it is now used to harvest credentials and secrets for identity-based attacks against cloud apps and services. ",{"data":47992,"content":47993,"nodeType":881},{},[47994],{"data":47995,"marks":47996,"value":47997,"nodeType":867},{},[],"And because businesses have migrated to more cloud-based services and infrastructure, the compromise of an identity now has different consequences.",{"data":47999,"content":48000,"nodeType":881},{},[48001,48005],{"data":48002,"marks":48003,"value":48004,"nodeType":867},{},[],"The data and functionality that attackers seek has moved off endpoints and internal networks and onto cloud systems and SaaS applications, which organizations are using in large numbers (tens to hundreds). The modern way of working means that applications are more often than not directly exposed to the internet — and the only thing needed to access these apps are identities. ",{"data":48006,"marks":48007,"value":48009,"nodeType":867},{},[48008],{"type":916},"Naturally, it's much harder to stop credential stuffing attacks against 100 SaaS apps than the single centralized external VPN/webmail endpoint of yesteryear. ",{"data":48011,"content":48012,"nodeType":881},{},[48013],{"data":48014,"marks":48015,"value":48016,"nodeType":867},{},[],"It’s clear that stats alone don’t adequately capture the identity threat. So we have to look beyond the numbers to find out why. ",{"data":48018,"content":48019,"nodeType":908},{},[],{"data":48021,"content":48022,"nodeType":918},{},[48023],{"data":48024,"marks":48025,"value":48026,"nodeType":867},{},[],"Using this resource",{"data":48028,"content":48029,"nodeType":881},{},[48030],{"data":48031,"marks":48032,"value":48033,"nodeType":867},{},[],"To cut through some of the noise, we’ve compiled this list of reported attacks and explored what they mean for the identity threat landscape. ",{"data":48035,"content":48036,"nodeType":881},{},[48037,48041,48046],{"data":48038,"marks":48039,"value":48040,"nodeType":867},{},[],"This is not intended to be an exhaustive list of all attacks involving the compromise of digital identities (the list would be endless!). Nor is it something you should read all in one go (unless you ",{"data":48042,"marks":48043,"value":48045,"nodeType":867},{},[48044],{"type":1431},"really",{"data":48047,"marks":48048,"value":48049,"nodeType":867},{},[]," want to, we won’t stop you). We want it to be a resource that you can refer back to, that we will continue to update as new attacks are recorded. ",{"data":48051,"content":48052,"nodeType":881},{},[48053,48057],{"data":48054,"marks":48055,"value":48056,"nodeType":867},{},[],"In this context we define identity attacks as ",{"data":48058,"marks":48059,"value":48061,"nodeType":867},{},[48060],{"type":916},"attacks targeting cloud identities and their associated identity management systems, protocols, applications, and infrastructure. ",{"data":48063,"content":48064,"nodeType":881},{},[48065,48069],{"data":48066,"marks":48067,"value":48068,"nodeType":867},{},[],"The attacks recorded below are high profile examples of browser-based identity attacks",{"data":48070,"marks":48071,"value":48072,"nodeType":867},{},[]," that demonstrate how threat actors are leveraging the cloud identity plane to evade established cyber defenses and traverse new attack paths to achieve their goals. We’ve focused on attacks targeting identity infrastructure itself that are notable for their bypassing of traditional environments and established controls (e.g. Networkless or SaaS-to-SaaS attack paths). ",{"data":48074,"content":48075,"nodeType":881},{},[48076,48080,48087,48091,48100],{"data":48077,"marks":48078,"value":48079,"nodeType":867},{},[],"As with all publicly disclosed breaches, the level of detail and transparency we see varies. Where possible, we've mapped the threat actor Tactics, Techniques and Procedures to our ",{"data":48081,"content":48082,"nodeType":876},{"uri":2613},[48083],{"data":48084,"marks":48085,"value":2618,"nodeType":867},{},[48086],{"type":1040},{"data":48088,"marks":48089,"value":48090,"nodeType":867},{},[]," (previously the SaaS Attack Matrix). To learn more about SaaS attack techniques ",{"data":48092,"content":48094,"nodeType":876},{"uri":48093},"https://pushsecurity.com/blog/saas-attack-techniques/#id-problems-with-observing-saas-attacks",[48095],{"data":48096,"marks":48097,"value":48099,"nodeType":867},{},[48098],{"type":1040},"read the blog",{"data":48101,"marks":48102,"value":1253,"nodeType":867},{},[],{"data":48104,"content":48105,"nodeType":908},{},[],{"data":48107,"content":48108,"nodeType":918},{},[48109],{"data":48110,"marks":48111,"value":48112,"nodeType":867},{},[],"Snowflake – June 2024",{"data":48114,"content":48115,"nodeType":881},{},[48116,48120,48128],{"data":48117,"marks":48118,"value":48119,"nodeType":867},{},[],"The threat group known as ShinyHunters (also tracked as UNC5537) has claimed responsibility for breaching multiple organizations using Snowflake, a cloud-based data warehousing and analytics platform. The breach stems from the historical compromise of credentials used to access customer-specific Snowflake tenants, via infostealer infections. These credentials were used as part of a targeted campaign against Snowflake customers, which was exacerbated by the widespread absence of MFA due to the lack of MFA enforcement by default. At the time of writing, approximately 165 customers have been impacted globally ",{"data":48121,"content":48122,"nodeType":876},{"uri":6095},[48123],{"data":48124,"marks":48125,"value":48127,"nodeType":867},{},[48126],{"type":1040},"according to a report by Mandiant",{"data":48129,"marks":48130,"value":10110,"nodeType":867},{},[],{"data":48132,"content":48133,"nodeType":998},{},[48134],{"data":48135,"marks":48136,"value":48137,"nodeType":867},{},[],"How did Snowflake get breached?",{"data":48139,"content":48140,"nodeType":881},{},[48141],{"data":48142,"marks":48143,"value":48145,"nodeType":867},{},[48144],{"type":1431},"It’s worth noting that customers/users of Snowflake were breached via their Snowflake tenants, and no central breach of Snowflake's own systems occurred.",{"data":48147,"content":48148,"nodeType":3126},{},[48149,48159,48182,48192,48201,48210,48219,48229],{"data":48150,"content":48151,"nodeType":3061},{},[48152],{"data":48153,"content":48154,"nodeType":881},{},[48155],{"data":48156,"marks":48157,"value":48158,"nodeType":867},{},[],"Snowflake users were infected with infostealer malware that harvested credentials from user devices over an extended period. The threat actor used Snowflake customer credentials that were previously exposed via several infostealer malware variants, including; VIDAR, RISEPRO, REDLINE, RACOON STEALER, LUMMA and METASTEALER.",{"data":48160,"content":48161,"nodeType":3061},{},[48162],{"data":48163,"content":48164,"nodeType":881},{},[48165,48169,48178],{"data":48166,"marks":48167,"value":48168,"nodeType":867},{},[],"Credentials appeared on criminal marketplaces e.g. dark web forums and ",{"data":48170,"content":48172,"nodeType":876},{"uri":48171},"https://www.troyhunt.com/telegram-combolists-and-361m-email-addresses/",[48173],{"data":48174,"marks":48175,"value":48177,"nodeType":867},{},[48176],{"type":1040},"Telegram channels",{"data":48179,"marks":48180,"value":48181,"nodeType":867},{},[]," as combolists (username, password, and login portal combinations). ",{"data":48183,"content":48184,"nodeType":3061},{},[48185],{"data":48186,"content":48187,"nodeType":881},{},[48188],{"data":48189,"marks":48190,"value":48191,"nodeType":867},{},[],"Criminal groups (either ShinyHunters or another organization) saw the potential in targeting Snowflake users, based on the availability of credentials, number of customer organizations, and the value of the data that can be accessed in Snowflake. ",{"data":48193,"content":48194,"nodeType":3061},{},[48195],{"data":48196,"content":48197,"nodeType":881},{},[48198],{"data":48199,"marks":48200,"value":46664,"nodeType":867},{},[],{"data":48202,"content":48203,"nodeType":3061},{},[48204],{"data":48205,"content":48206,"nodeType":881},{},[48207],{"data":48208,"marks":48209,"value":46674,"nodeType":867},{},[],{"data":48211,"content":48212,"nodeType":3061},{},[48213],{"data":48214,"content":48215,"nodeType":881},{},[48216],{"data":48217,"marks":48218,"value":46684,"nodeType":867},{},[],{"data":48220,"content":48221,"nodeType":3061},{},[48222],{"data":48223,"content":48224,"nodeType":881},{},[48225],{"data":48226,"marks":48227,"value":48228,"nodeType":867},{},[],"ShinyHunters acquired massive quantities of Snowflake data based on the information that each customer stored in Snowflake or connected apps. The most sensitive data declared so far pertains to end-customers of each victim, for example PII, bank account and card information, etc.  ",{"data":48230,"content":48231,"nodeType":3061},{},[48232],{"data":48233,"content":48234,"nodeType":881},{},[48235],{"data":48236,"marks":48237,"value":48238,"nodeType":867},{},[],"ShinyHunters began attempts to extort Snowflake and end-customers using the data acquired. ",{"data":48240,"content":48241,"nodeType":998},{},[48242],{"data":48243,"marks":48244,"value":48245,"nodeType":867},{},[],"What was the impact of the Snowflake breach?",{"data":48247,"content":48248,"nodeType":3126},{},[48249,48268,48297,48325,48344,48363],{"data":48250,"content":48251,"nodeType":3061},{},[48252],{"data":48253,"content":48254,"nodeType":881},{},[48255,48259,48264],{"data":48256,"marks":48257,"value":48258,"nodeType":867},{},[],"Approximately ",{"data":48260,"marks":48261,"value":48263,"nodeType":867},{},[48262],{"type":916},"165 victims were identified by Mandiant",{"data":48265,"marks":48266,"value":48267,"nodeType":867},{},[],". Organizations are gradually coming forward to declare the breach and release customer communications accordingly, but not all victims have been named.",{"data":48269,"content":48270,"nodeType":3061},{},[48271],{"data":48272,"content":48273,"nodeType":881},{},[48274,48278,48283,48287,48294],{"data":48275,"marks":48276,"value":48277,"nodeType":867},{},[],"Based on the figures being suggested so far, the impact upon end-customers is huge, with the data of ",{"data":48279,"marks":48280,"value":48282,"nodeType":867},{},[48281],{"type":916},"hundreds of millions of people exposed",{"data":48284,"marks":48285,"value":48286,"nodeType":867},{},[],", and has been touted by some news outlets as ‘",{"data":48288,"content":48289,"nodeType":876},{"uri":46419},[48290],{"data":48291,"marks":48292,"value":46425,"nodeType":867},{},[48293],{"type":1040},{"data":48295,"marks":48296,"value":46429,"nodeType":867},{},[],{"data":48298,"content":48299,"nodeType":3061},{},[48300],{"data":48301,"content":48302,"nodeType":881},{},[48303,48307,48312,48316,48321],{"data":48304,"marks":48305,"value":48306,"nodeType":867},{},[],"The impact on the affected businesses is largely unknown at this stage. It’s clear that the victims will suffer ",{"data":48308,"marks":48309,"value":48311,"nodeType":867},{},[48310],{"type":916},"reputational damage",{"data":48313,"marks":48314,"value":48315,"nodeType":867},{},[]," based on the extent of their individual breaches, and possibly face other ",{"data":48317,"marks":48318,"value":48320,"nodeType":867},{},[48319],{"type":916},"penalties and sanctions",{"data":48322,"marks":48323,"value":48324,"nodeType":867},{},[]," if they are found to be at fault by their respective regulators and/or national information security authorities. ",{"data":48326,"content":48327,"nodeType":3061},{},[48328],{"data":48329,"content":48330,"nodeType":881},{},[48331,48335,48340],{"data":48332,"marks":48333,"value":48334,"nodeType":867},{},[],"The impact upon individuals will be significant, with high potential for further targeting in terms of ",{"data":48336,"marks":48337,"value":48339,"nodeType":867},{},[48338],{"type":916},"identity theft, blackmail, financial crime",{"data":48341,"marks":48342,"value":48343,"nodeType":867},{},[],", etc.  ",{"data":48345,"content":48346,"nodeType":3061},{},[48347],{"data":48348,"content":48349,"nodeType":881},{},[48350,48354,48359],{"data":48351,"marks":48352,"value":48353,"nodeType":867},{},[],"It is unclear what data has been exposed in addition to personal data affecting end-customers. If other sensitive commercial or business data pertaining to ",{"data":48355,"marks":48356,"value":48358,"nodeType":867},{},[48357],{"type":916},"Intellectual Property",{"data":48360,"marks":48361,"value":48362,"nodeType":867},{},[]," has been exposed then this data may also be sold on via other nefarious channels, with a potential future impact.",{"data":48364,"content":48365,"nodeType":3061},{},[48366],{"data":48367,"content":48368,"nodeType":881},{},[48369,48373,48378],{"data":48370,"marks":48371,"value":48372,"nodeType":867},{},[],"Given the lack of MFA for the compromised accounts, there has been a general criticism of the ‘opt-in’ nature of MFA for SaaS services, with many security professionals suggesting that ",{"data":48374,"marks":48375,"value":48377,"nodeType":867},{},[48376],{"type":916},"Snowflake should enforce MFA by default",{"data":48379,"marks":48380,"value":48381,"nodeType":867},{},[]," given the critical nature of the service. ",{"data":48383,"content":48384,"nodeType":998},{},[48385],{"data":48386,"marks":48387,"value":48388,"nodeType":867},{},[],"What stands out in the Snowflake breach?",{"data":48390,"content":48391,"nodeType":3126},{},[48392,48411,48454,48481],{"data":48393,"content":48394,"nodeType":3061},{},[48395],{"data":48396,"content":48397,"nodeType":881},{},[48398,48402,48407],{"data":48399,"marks":48400,"value":48401,"nodeType":867},{},[],"The breach ",{"data":48403,"marks":48404,"value":48406,"nodeType":867},{},[48405],{"type":916},"was achieved by using stolen credentials dating back as far as 2020",{"data":48408,"marks":48409,"value":48410,"nodeType":867},{},[],", that had not been rotated or changed. This indicates that many of the credentials used were not necessarily the result of any recent data sharing. This highlights the potential risk of breached credentials already in the public domain; particularly in the case of cloud services that may not be subject to the same levels of credential hygiene as other traditional network logins. ",{"data":48412,"content":48413,"nodeType":3061},{},[48414],{"data":48415,"content":48416,"nodeType":881},{},[48417,48421,48429,48432,48437,48441,48450],{"data":48418,"marks":48419,"value":48420,"nodeType":867},{},[],"Much of the industry response has focused on ensuring that accounts are using SSO (and therefore are protected by MFA at the IdP level). However, due to the existence of ",{"data":48422,"content":48424,"nodeType":876},{"uri":48423},"https://pushsecurity.com/resources/browser-identity-attacks-matrix/ghost-logins",[48425],{"data":48426,"marks":48427,"value":6850,"nodeType":867},{},[48428],{"type":1040},{"data":48430,"marks":48431,"value":4006,"nodeType":867},{},[],{"data":48433,"marks":48434,"value":48436,"nodeType":867},{},[48435],{"type":916},"local logins without MFA can exist simultaneously with the SSO login unless expressly disabled",{"data":48438,"marks":48439,"value":48440,"nodeType":867},{},[],". Organizations using Snowflake that are looking to lock down their accounts can ",{"data":48442,"content":48444,"nodeType":876},{"uri":48443},"https://pushsecurity.com/resources/video/demonstrating-ghost-logins-in-snowflake-and-how-to-remediate-them/",[48445],{"data":48446,"marks":48447,"value":48449,"nodeType":867},{},[48448],{"type":1040},"watch our recent demo of how to effectively remediate this vulnerability in Snowflake",{"data":48451,"marks":48452,"value":48453,"nodeType":867},{},[],".  ",{"data":48455,"content":48456,"nodeType":3061},{},[48457],{"data":48458,"content":48459,"nodeType":881},{},[48460,48465,48469,48477],{"data":48461,"marks":48462,"value":48464,"nodeType":867},{},[48463],{"type":916},"80% of the credentials were gathered through infostealer malware",{"data":48466,"marks":48467,"value":48468,"nodeType":867},{},[],". Typically, this occurs when unmanaged devices are used to access company resources, or personal browser profiles are synchronized on both work and personal devices. Malware deployed to an insecure personal device can then access and steal credentials for company resources. This situation usually occurs when working with third-party contractors on a BYOD basis; ",{"data":48470,"content":48471,"nodeType":876},{"uri":46829},[48472],{"data":48473,"marks":48474,"value":48476,"nodeType":867},{},[48475],{"type":1040},"a recent article indicates that Ukraine-based EPAM Systems",{"data":48478,"marks":48479,"value":48480,"nodeType":867},{},[],", an engineering and digital service provider and “Elite Tier Partner” of Snowflake, was one such organization breached in this way. Organizations consuming Snowflake-related services from EPAM were then subsequently affected, as the compromise of EPAM users granted access to a large number of Snowflake credentials for various company tenants.  ",{"data":48482,"content":48483,"nodeType":3061},{},[48484],{"data":48485,"content":48486,"nodeType":881},{},[48487,48491,48496,48500,48505],{"data":48488,"marks":48489,"value":48490,"nodeType":867},{},[],"While attacker activity has focused on Snowflake to date, the success of this attack will signal the potential for further credential based attacks against similar apps. ",{"data":48492,"marks":48493,"value":48495,"nodeType":867},{},[48494],{"type":916},"There may already be a 'Snowflake 2.0' among the credentials already available online",{"data":48497,"marks":48498,"value":48499,"nodeType":867},{},[],". Further, credentials can be used against a wide range of apps to capitalize on potential ",{"data":48501,"marks":48502,"value":48504,"nodeType":867},{},[48503],{"type":916},"password reuse (which we see for 1 in 3 employees)",{"data":48506,"marks":48507,"value":48508,"nodeType":867},{},[],", so the exact creds for a particular app don’t have to be explicitly breached, so long as the domain for the login portal can be guessed or has been exposed elsewhere.   ",{"data":48510,"content":48511,"nodeType":998},{},[48512],{"data":48513,"marks":48514,"value":48515,"nodeType":867},{},[],"Browser & Identity Attacks Matrix mapping",{"data":48517,"content":48518,"nodeType":881},{},[48519],{"data":48520,"marks":48521,"value":48522,"nodeType":867},{},[],"For more information on each TTP please navigate to the entries linked in the table below. ",{"data":48524,"content":48525,"nodeType":2531},{},[48526,48569,48631],{"data":48527,"content":48528,"nodeType":2438},{},[48529,48539,48549,48559],{"data":48530,"content":48531,"nodeType":2426},{},[48532],{"data":48533,"content":48534,"nodeType":881},{},[48535],{"data":48536,"marks":48537,"value":48538,"nodeType":867},{},[],"ID",{"data":48540,"content":48541,"nodeType":2426},{},[48542],{"data":48543,"content":48544,"nodeType":881},{},[48545],{"data":48546,"marks":48547,"value":48548,"nodeType":867},{},[],"Name",{"data":48550,"content":48551,"nodeType":2426},{},[48552],{"data":48553,"content":48554,"nodeType":881},{},[48555],{"data":48556,"marks":48557,"value":48558,"nodeType":867},{},[],"Stage",{"data":48560,"content":48561,"nodeType":2426},{},[48562],{"data":48563,"content":48564,"nodeType":881},{},[48565],{"data":48566,"marks":48567,"value":48568,"nodeType":867},{},[],"Description",{"data":48570,"content":48571,"nodeType":2438},{},[48572,48592,48611,48621],{"data":48573,"content":48574,"nodeType":2452},{},[48575],{"data":48576,"content":48577,"nodeType":881},{},[48578,48581,48589],{"data":48579,"marks":48580,"value":21,"nodeType":867},{},[],{"data":48582,"content":48583,"nodeType":876},{"uri":14589},[48584],{"data":48585,"marks":48586,"value":48588,"nodeType":867},{},[48587],{"type":1040},"SAT1017",{"data":48590,"marks":48591,"value":21,"nodeType":867},{},[],{"data":48593,"content":48594,"nodeType":2452},{},[48595],{"data":48596,"content":48597,"nodeType":881},{},[48598,48601,48608],{"data":48599,"marks":48600,"value":21,"nodeType":867},{},[],{"data":48602,"content":48603,"nodeType":876},{"uri":48423},[48604],{"data":48605,"marks":48606,"value":395,"nodeType":867},{},[48607],{"type":1040},{"data":48609,"marks":48610,"value":21,"nodeType":867},{},[],{"data":48612,"content":48613,"nodeType":2452},{},[48614],{"data":48615,"content":48616,"nodeType":881},{},[48617],{"data":48618,"marks":48619,"value":48620,"nodeType":867},{},[],"Initial Access; Persistence; Defense Evasion",{"data":48622,"content":48623,"nodeType":2452},{},[48624],{"data":48625,"content":48626,"nodeType":881},{},[48627],{"data":48628,"marks":48629,"value":48630,"nodeType":867},{},[],"Abusing non-SSO additional login methods such as password-based authentication (local to the SaaS app), social logins, API access, etc. ",{"data":48632,"content":48633,"nodeType":2438},{},[48634,48655,48676,48686],{"data":48635,"content":48636,"nodeType":2452},{},[48637],{"data":48638,"content":48639,"nodeType":881},{},[48640,48643,48652],{"data":48641,"marks":48642,"value":21,"nodeType":867},{},[],{"data":48644,"content":48646,"nodeType":876},{"uri":48645},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/session_cookie_theft/description.md",[48647],{"data":48648,"marks":48649,"value":48651,"nodeType":867},{},[48650],{"type":1040},"SAT1044",{"data":48653,"marks":48654,"value":21,"nodeType":867},{},[],{"data":48656,"content":48657,"nodeType":2452},{},[48658],{"data":48659,"content":48660,"nodeType":881},{},[48661,48664,48673],{"data":48662,"marks":48663,"value":21,"nodeType":867},{},[],{"data":48665,"content":48667,"nodeType":876},{"uri":48666},"https://pushsecurity.com/resources/browser-identity-attacks-matrix/session-cookie-theft",[48668],{"data":48669,"marks":48670,"value":48672,"nodeType":867},{},[48671],{"type":1040},"Session cookie theft",{"data":48674,"marks":48675,"value":21,"nodeType":867},{},[],{"data":48677,"content":48678,"nodeType":2452},{},[48679],{"data":48680,"content":48681,"nodeType":881},{},[48682],{"data":48683,"marks":48684,"value":48685,"nodeType":867},{},[],"Lateral Movement; Defense Evasion",{"data":48687,"content":48688,"nodeType":2452},{},[48689],{"data":48690,"content":48691,"nodeType":881},{},[48692],{"data":48693,"marks":48694,"value":48695,"nodeType":867},{},[],"Session cookies are used to pivot from an endpoint compromise and laterally move to downstream SaaS applications.",{"data":48697,"content":48698,"nodeType":998},{},[48699],{"data":48700,"marks":48701,"value":48702,"nodeType":867},{},[],"Related breaches",{"data":48704,"content":48705,"nodeType":881},{},[48706],{"data":48707,"marks":48708,"value":48709,"nodeType":867},{},[],"Named victims are listed below:",{"data":48711,"content":48712,"nodeType":3126},{},[48713,48723,48733,48743,48753,48763,48773,48783],{"data":48714,"content":48715,"nodeType":3061},{},[48716],{"data":48717,"content":48718,"nodeType":881},{},[48719],{"data":48720,"marks":48721,"value":48722,"nodeType":867},{},[],"Ticketmaster",{"data":48724,"content":48725,"nodeType":3061},{},[48726],{"data":48727,"content":48728,"nodeType":881},{},[48729],{"data":48730,"marks":48731,"value":48732,"nodeType":867},{},[],"Santander",{"data":48734,"content":48735,"nodeType":3061},{},[48736],{"data":48737,"content":48738,"nodeType":881},{},[48739],{"data":48740,"marks":48741,"value":48742,"nodeType":867},{},[],"Neiman Marcus",{"data":48744,"content":48745,"nodeType":3061},{},[48746],{"data":48747,"content":48748,"nodeType":881},{},[48749],{"data":48750,"marks":48751,"value":48752,"nodeType":867},{},[],"Los Angeles Unified",{"data":48754,"content":48755,"nodeType":3061},{},[48756],{"data":48757,"content":48758,"nodeType":881},{},[48759],{"data":48760,"marks":48761,"value":48762,"nodeType":867},{},[],"Pure Storage",{"data":48764,"content":48765,"nodeType":3061},{},[48766],{"data":48767,"content":48768,"nodeType":881},{},[48769],{"data":48770,"marks":48771,"value":48772,"nodeType":867},{},[],"Advance Auto Parts",{"data":48774,"content":48775,"nodeType":3061},{},[48776],{"data":48777,"content":48778,"nodeType":881},{},[48779],{"data":48780,"marks":48781,"value":48782,"nodeType":867},{},[],"Truist Bank",{"data":48784,"content":48785,"nodeType":3061},{},[48786],{"data":48787,"content":48788,"nodeType":881},{},[48789],{"data":48790,"marks":48791,"value":48792,"nodeType":867},{},[],"Lending Tree",{"data":48794,"content":48795,"nodeType":908},{},[],{"data":48797,"content":48798,"nodeType":918},{},[48799],{"data":48800,"marks":48801,"value":48802,"nodeType":867},{},[],"Microsoft — January 2024",{"data":48804,"content":48805,"nodeType":881},{},[48806],{"data":48807,"marks":48808,"value":48809,"nodeType":867},{},[],"The threat group known as APT29 (also known as “The Dukes”, “Cozy Bear”, and labeled “Midnight Blizzard” by Microsoft) executed a cleverly executed password-guessing attack to compromise test cloud identities that were also lacking MFA. Attackers then leveraged this access to compromise some OAuth applications that allowed lateral movement to Microsoft’s corporate environment and the creation of other malicious OAuth applications to achieve persistence.",{"data":48811,"content":48812,"nodeType":998},{},[48813],{"data":48814,"marks":48815,"value":48816,"nodeType":867},{},[],"How did Microsoft get breached?",{"data":48818,"content":48819,"nodeType":3126},{},[48820,48830,48840,48850,48860,48870],{"data":48821,"content":48822,"nodeType":3061},{},[48823],{"data":48824,"content":48825,"nodeType":881},{},[48826],{"data":48827,"marks":48828,"value":48829,"nodeType":867},{},[],"APT29 utilized password spraying / credential stuffing attacks to compromise test cloud identities that were also lacking MFA, attached to a non-production test tenant.",{"data":48831,"content":48832,"nodeType":3061},{},[48833],{"data":48834,"content":48835,"nodeType":881},{},[48836],{"data":48837,"marks":48838,"value":48839,"nodeType":867},{},[],"APT29 leveraged their initial access to the test tenant to identify and compromise a test OAuth application that had access to the Microsoft corporate environment by leveraging permissive Entra ID roles in the test tenant.",{"data":48841,"content":48842,"nodeType":3061},{},[48843],{"data":48844,"content":48845,"nodeType":881},{},[48846],{"data":48847,"marks":48848,"value":48849,"nodeType":867},{},[],"APT29 used the existing configurations to access the Microsoft corporate Entra ID tenant whereupon the app registration from the test tenant was installed as a service principal in the corporate tenant, granting the equivalent of global admin rights.",{"data":48851,"content":48852,"nodeType":3061},{},[48853],{"data":48854,"content":48855,"nodeType":881},{},[48856],{"data":48857,"marks":48858,"value":48859,"nodeType":867},{},[],"Using these new permissions, APT29 registered additional malicious OAuth applications in the Microsoft corporate environment, and created a new user in the Microsoft corporate tenant to grant consent to the new malicious OAuth apps, thereby achieving persistent access to the environment.",{"data":48861,"content":48862,"nodeType":3061},{},[48863],{"data":48864,"content":48865,"nodeType":881},{},[48866],{"data":48867,"marks":48868,"value":48869,"nodeType":867},{},[],"APT29 leveraged the elevated (maximum) privileges assigned to the ‘test’ app service principal to grant app roles to other newly created app service principals, granting them the Office 365 Exchange Online full_access_as_app role in the corporate tenant, which allows access to mailboxes.",{"data":48871,"content":48872,"nodeType":3061},{},[48873],{"data":48874,"content":48875,"nodeType":881},{},[48876],{"data":48877,"marks":48878,"value":48879,"nodeType":867},{},[],"APT29 leveraged these malicious OAuth applications to authenticate to Microsoft Exchange Online and target Microsoft corporate email accounts.",{"data":48881,"content":48882,"nodeType":998},{},[48883],{"data":48884,"marks":48885,"value":48886,"nodeType":867},{},[],"What was the impact of the Microsoft breach?",{"data":48888,"content":48889,"nodeType":3126},{},[48890,48900,48910],{"data":48891,"content":48892,"nodeType":3061},{},[48893],{"data":48894,"content":48895,"nodeType":881},{},[48896],{"data":48897,"marks":48898,"value":48899,"nodeType":867},{},[],"APT29 had access to Microsoft corporate email accounts, including members of the senior leadership team and employees in the cybersecurity, legal, and other functions, resulting in sensitive data leakage.",{"data":48901,"content":48902,"nodeType":3061},{},[48903],{"data":48904,"content":48905,"nodeType":881},{},[48906],{"data":48907,"marks":48908,"value":48909,"nodeType":867},{},[],"Microsoft has not disclosed any further impacts at this time, but it is likely that the adversary had complete, unmitigated control of the Microsoft corporate tenant for a period of time, with global administrator level access.",{"data":48911,"content":48912,"nodeType":3061},{},[48913],{"data":48914,"content":48915,"nodeType":881},{},[48916],{"data":48917,"marks":48918,"value":48919,"nodeType":867},{},[],"Since the initial attack there has been evidence of continued targeting, with password spraying attacks reportedly increasing tenfold, likely informed by stolen information.",{"data":48921,"content":48922,"nodeType":998},{},[48923],{"data":48924,"marks":48925,"value":48926,"nodeType":867},{},[],"What stands out in the Microsoft breach?",{"data":48928,"content":48929,"nodeType":3126},{},[48930,48940,48950,48960],{"data":48931,"content":48932,"nodeType":3061},{},[48933],{"data":48934,"content":48935,"nodeType":881},{},[48936],{"data":48937,"marks":48938,"value":48939,"nodeType":867},{},[],"The attack was covert and targeted, with APT29 tailoring the attack to a limited number of accounts and using a low number of attempts to evade detection and avoid account blocks based on the volume of failures.",{"data":48941,"content":48942,"nodeType":3061},{},[48943],{"data":48944,"content":48945,"nodeType":881},{},[48946],{"data":48947,"marks":48948,"value":48949,"nodeType":867},{},[],"APT29 used residential proxy networks when interacting with the compromised tenant and, subsequently, with Exchange Online to obfuscate the source of their attack and avoid impossible travel detections. ",{"data":48951,"content":48952,"nodeType":3061},{},[48953],{"data":48954,"content":48955,"nodeType":881},{},[48956],{"data":48957,"marks":48958,"value":48959,"nodeType":867},{},[],"APT29 demonstrated mature and in-depth understanding of cloud infrastructure, protocols, and workflows, particularly in terms of privilege escalation and lateral movement.",{"data":48961,"content":48962,"nodeType":3061},{},[48963],{"data":48964,"content":48965,"nodeType":881},{},[48966],{"data":48967,"marks":48968,"value":48969,"nodeType":867},{},[],"If even Microsoft (an organization with pretty much unrivaled security resources) can’t ensure that all their accounts are protected by MFA and that there are no weak links between test/dev and prod systems, this should be a wake-up call for any company that thinks their MFA implementation is flawless. ",{"data":48971,"content":48972,"nodeType":998},{},[48973],{"data":48974,"marks":48975,"value":48515,"nodeType":867},{},[],{"data":48977,"content":48978,"nodeType":881},{},[48979],{"data":48980,"marks":48981,"value":48522,"nodeType":867},{},[],{"data":48983,"content":48984,"nodeType":2531},{},[48985,49025,49089,49154],{"data":48986,"content":48987,"nodeType":2438},{},[48988,48997,49007,49016],{"data":48989,"content":48990,"nodeType":2426},{},[48991],{"data":48992,"content":48993,"nodeType":881},{},[48994],{"data":48995,"marks":48996,"value":48538,"nodeType":867},{},[],{"data":48998,"content":48999,"nodeType":2426},{},[49000],{"data":49001,"content":49002,"nodeType":881},{},[49003],{"data":49004,"marks":49005,"value":49006,"nodeType":867},{},[],"Technique",{"data":49008,"content":49009,"nodeType":2426},{},[49010],{"data":49011,"content":49012,"nodeType":881},{},[49013],{"data":49014,"marks":49015,"value":48558,"nodeType":867},{},[],{"data":49017,"content":49018,"nodeType":2426},{},[49019],{"data":49020,"content":49021,"nodeType":881},{},[49022],{"data":49023,"marks":49024,"value":48568,"nodeType":867},{},[],{"data":49026,"content":49027,"nodeType":2438},{},[49028,49049,49069,49079],{"data":49029,"content":49030,"nodeType":2452},{},[49031],{"data":49032,"content":49033,"nodeType":881},{},[49034,49037,49046],{"data":49035,"marks":49036,"value":21,"nodeType":867},{},[],{"data":49038,"content":49040,"nodeType":876},{"uri":49039},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/credential_stuffing/description.md",[49041],{"data":49042,"marks":49043,"value":49045,"nodeType":867},{},[49044],{"type":1040},"SAT1011",{"data":49047,"marks":49048,"value":21,"nodeType":867},{},[],{"data":49050,"content":49051,"nodeType":2452},{},[49052],{"data":49053,"content":49054,"nodeType":881},{},[49055,49058,49066],{"data":49056,"marks":49057,"value":21,"nodeType":867},{},[],{"data":49059,"content":49061,"nodeType":876},{"uri":49060},"https://pushsecurity.com/resources/browser-identity-attacks-matrix/credential-stuffing",[49062],{"data":49063,"marks":49064,"value":333,"nodeType":867},{},[49065],{"type":1040},{"data":49067,"marks":49068,"value":21,"nodeType":867},{},[],{"data":49070,"content":49071,"nodeType":2452},{},[49072],{"data":49073,"content":49074,"nodeType":881},{},[49075],{"data":49076,"marks":49077,"value":49078,"nodeType":867},{},[],"Initial Access",{"data":49080,"content":49081,"nodeType":2452},{},[49082],{"data":49083,"content":49084,"nodeType":881},{},[49085],{"data":49086,"marks":49087,"value":49088,"nodeType":867},{},[],"Attempt to authenticate to a SaaS account by guessing a large number of passwords ",{"data":49090,"content":49091,"nodeType":2438},{},[49092,49113,49134,49144],{"data":49093,"content":49094,"nodeType":2452},{},[49095],{"data":49096,"content":49097,"nodeType":881},{},[49098,49101,49110],{"data":49099,"marks":49100,"value":21,"nodeType":867},{},[],{"data":49102,"content":49104,"nodeType":876},{"uri":49103},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/oauth_tokens/description.md",[49105],{"data":49106,"marks":49107,"value":49109,"nodeType":867},{},[49108],{"type":1040},"SAT1027",{"data":49111,"marks":49112,"value":21,"nodeType":867},{},[],{"data":49114,"content":49115,"nodeType":2452},{},[49116],{"data":49117,"content":49118,"nodeType":881},{},[49119,49122,49131],{"data":49120,"marks":49121,"value":21,"nodeType":867},{},[],{"data":49123,"content":49125,"nodeType":876},{"uri":49124},"https://pushsecurity.com/resources/browser-identity-attacks-matrix/oauth-tokens",[49126],{"data":49127,"marks":49128,"value":49130,"nodeType":867},{},[49129],{"type":1040},"OAuth tokens",{"data":49132,"marks":49133,"value":21,"nodeType":867},{},[],{"data":49135,"content":49136,"nodeType":2452},{},[49137],{"data":49138,"content":49139,"nodeType":881},{},[49140],{"data":49141,"marks":49142,"value":49143,"nodeType":867},{},[],"Execution; Persistence; Defense Evasion",{"data":49145,"content":49146,"nodeType":2452},{},[49147],{"data":49148,"content":49149,"nodeType":881},{},[49150],{"data":49151,"marks":49152,"value":49153,"nodeType":867},{},[],"Use a malicious OAuth app to create an OAuth token, using arbitrary permissions to maintain long-term programmatic access to a compromised user account.",{"data":49155,"content":49156,"nodeType":2438},{},[49157,49178,49199,49209],{"data":49158,"content":49159,"nodeType":2452},{},[49160],{"data":49161,"content":49162,"nodeType":881},{},[49163,49166,49175],{"data":49164,"marks":49165,"value":21,"nodeType":867},{},[],{"data":49167,"content":49169,"nodeType":876},{"uri":49168},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/abuse_existing_oauth_integrations/description.md",[49170],{"data":49171,"marks":49172,"value":49174,"nodeType":867},{},[49173],{"type":1040},"SAT1001",{"data":49176,"marks":49177,"value":21,"nodeType":867},{},[],{"data":49179,"content":49180,"nodeType":2452},{},[49181],{"data":49182,"content":49183,"nodeType":881},{},[49184,49187,49196],{"data":49185,"marks":49186,"value":21,"nodeType":867},{},[],{"data":49188,"content":49190,"nodeType":876},{"uri":49189},"https://pushsecurity.com/resources/browser-identity-attacks-matrix/abuse-existing-oauth-integrations",[49191],{"data":49192,"marks":49193,"value":49195,"nodeType":867},{},[49194],{"type":1040},"Abuse existing OAuth integrations",{"data":49197,"marks":49198,"value":21,"nodeType":867},{},[],{"data":49200,"content":49201,"nodeType":2452},{},[49202],{"data":49203,"content":49204,"nodeType":881},{},[49205],{"data":49206,"marks":49207,"value":49208,"nodeType":867},{},[],"Privilege Escalation;\nLateral Movement",{"data":49210,"content":49211,"nodeType":2452},{},[49212],{"data":49213,"content":49214,"nodeType":881},{},[49215],{"data":49216,"marks":49217,"value":49218,"nodeType":867},{},[],"If an adversary compromises a SaaS account integrated with other apps, they can escalate privileges and move laterally to other apps.",{"data":49220,"content":49221,"nodeType":998},{},[49222],{"data":49223,"marks":49224,"value":48702,"nodeType":867},{},[],{"data":49226,"content":49227,"nodeType":881},{},[49228],{"data":49229,"marks":49230,"value":49232,"nodeType":867},{},[49231],{"type":916},"Hewlett Packard Enterprise (HPE) — May 2023",{"data":49234,"content":49235,"nodeType":881},{},[49236],{"data":49237,"marks":49238,"value":49239,"nodeType":867},{},[],"At the time of the Microsoft breach becoming public knowledge, HPE disclosed that they had become aware of a historical incident in Dec 2023, involving unauthorized access to and exfiltration of a limited number of SharePoint files as early as May 2023. Hackers accessed and exfiltrated data from HPE mailboxes belonging to individuals in the cybersecurity, go-to-market, business segments, and other functions. No further information is available on the techniques used or impact of the breach. ",{"data":49241,"content":49242,"nodeType":908},{},[],{"data":49244,"content":49245,"nodeType":918},{},[49246],{"data":49247,"marks":49248,"value":49249,"nodeType":867},{},[],"Okta — October 2023",{"data":49251,"content":49252,"nodeType":881},{},[49253],{"data":49254,"marks":49255,"value":49256,"nodeType":867},{},[],"An unknown threat group compromised an Okta employee's personal Google account that was being used on a company-managed device, granting the threat actor access to a service account for Okta’s customer support system, that included session tokens for 134 customers. This was then used to hijack the legitimate Okta sessions of five customers. ",{"data":49258,"content":49259,"nodeType":998},{},[49260],{"data":49261,"marks":49262,"value":49263,"nodeType":867},{},[],"How did Okta get breached?",{"data":49265,"content":49266,"nodeType":3126},{},[49267,49277,49287,49297,49307],{"data":49268,"content":49269,"nodeType":3061},{},[49270],{"data":49271,"content":49272,"nodeType":881},{},[49273],{"data":49274,"marks":49275,"value":49276,"nodeType":867},{},[],"The threat actor compromised a personal Google account that the user had accessed from their Okta-managed work device by signing into their personal profile from the Chrome browser.",{"data":49278,"content":49279,"nodeType":3061},{},[49280],{"data":49281,"content":49282,"nodeType":881},{},[49283],{"data":49284,"marks":49285,"value":49286,"nodeType":867},{},[],"The personal account credentials are likely to have been compromised in a historical data breach and did not have MFA enabled.",{"data":49288,"content":49289,"nodeType":3061},{},[49290],{"data":49291,"content":49292,"nodeType":881},{},[49293],{"data":49294,"marks":49295,"value":49296,"nodeType":867},{},[],"The username and password of a service account for Okta’s customer support system had been saved into the employee’s personal Google account and was therefore compromised.",{"data":49298,"content":49299,"nodeType":3061},{},[49300],{"data":49301,"content":49302,"nodeType":881},{},[49303],{"data":49304,"marks":49305,"value":49306,"nodeType":867},{},[],"The threat actor was able to access the service account by logging in using the stolen credentials, which again likely did not have MFA deployed as a service account.",{"data":49308,"content":49309,"nodeType":3061},{},[49310],{"data":49311,"content":49312,"nodeType":881},{},[49313],{"data":49314,"marks":49315,"value":49316,"nodeType":867},{},[],"The threat actor was able to use session tokens in the HAR files to impersonate staff and hijack the legitimate Okta sessions of five customers, including 1Password, BeyondTrust, and Cloudflare.",{"data":49318,"content":49319,"nodeType":998},{},[49320],{"data":49321,"marks":49322,"value":49323,"nodeType":867},{},[],"What was the impact of the Okta breach?",{"data":49325,"content":49326,"nodeType":3126},{},[49327,49337,49347,49357],{"data":49328,"content":49329,"nodeType":3061},{},[49330],{"data":49331,"content":49332,"nodeType":881},{},[49333],{"data":49334,"marks":49335,"value":49336,"nodeType":867},{},[],"The threat actor gained unauthorized access to files inside Okta’s customer support system associated with 134 Okta customers.",{"data":49338,"content":49339,"nodeType":3061},{},[49340],{"data":49341,"content":49342,"nodeType":881},{},[49343],{"data":49344,"marks":49345,"value":49346,"nodeType":867},{},[],"The threat actor was able to use these session tokens to hijack the legitimate Okta sessions of 5 (publicly disclosed) customers.",{"data":49348,"content":49349,"nodeType":3061},{},[49350],{"data":49351,"content":49352,"nodeType":881},{},[49353],{"data":49354,"marks":49355,"value":49356,"nodeType":867},{},[],"Okta originally claimed the breach had impacted only 1% of customers, but later found that a report run and downloaded by the threat actor contained the names and email addresses of all 18,400 Okta customer support users, as well as some Okta employee information, meaning 100% of customer support users were impacted.",{"data":49358,"content":49359,"nodeType":3061},{},[49360],{"data":49361,"content":49362,"nodeType":881},{},[49363],{"data":49364,"marks":49365,"value":49366,"nodeType":867},{},[],"Okta users are at higher risk of phishing and credential stuffing attacks based on the data stolen by the threat actor, increasing the importance of robust MFA implementation.",{"data":49368,"content":49369,"nodeType":998},{},[49370],{"data":49371,"marks":49372,"value":49373,"nodeType":867},{},[],"What stands out in the Okta breach?",{"data":49375,"content":49376,"nodeType":3126},{},[49377,49387,49397],{"data":49378,"content":49379,"nodeType":3061},{},[49380],{"data":49381,"content":49382,"nodeType":881},{},[49383],{"data":49384,"marks":49385,"value":49386,"nodeType":867},{},[],"This attack demonstrates the risk associated with cloud Identity Providers and the potential goldmine that they are to attackers. Much in the same way that the manufacturers of physical and virtual network appliances are continuously probed for software vulnerabilities, cloud IdPs like Okta present a huge potential opportunity, both in terms of targeting specific organizational instances as well as the Okta organization. This attack showcases the possibility of third-party supply chain attacks to target downstream organizations using IdP services. ",{"data":49388,"content":49389,"nodeType":3061},{},[49390],{"data":49391,"content":49392,"nodeType":881},{},[49393],{"data":49394,"marks":49395,"value":49396,"nodeType":867},{},[],"Similar to the Microsoft breach, gaps were discovered and exploited in Okta’s MFA coverage and implementation, highlighting that there are gaps in even the most mature organizations. ",{"data":49398,"content":49399,"nodeType":3061},{},[49400],{"data":49401,"content":49402,"nodeType":881},{},[49403],{"data":49404,"marks":49405,"value":49406,"nodeType":867},{},[],"The subsequent attack on Cloudflare (see below) and the scale of the recovery effort demonstrates the significant operational overhead in responding to and recovering from a breach of identity infrastructure, with a similar or greater scale than a traditional Active Directory compromise. While addressing the incident, Cloudflare's staff rotated all production credentials (over 5,000 unique ones), physically segmented test and staging systems, performed forensic triage on 4,893 systems, reimaged and rebooted all systems on the company's global network, including all Atlassian servers (Jira, Confluence, and Bitbucket) and machines accessed by the threat actor. All equipment in Cloudflare's Brazil data center, which was unsuccessfully targeted by the threat actor, was later returned to the manufacturers to ensure that the data center was secure.",{"data":49408,"content":49409,"nodeType":998},{},[49410],{"data":49411,"marks":49412,"value":48515,"nodeType":867},{},[],{"data":49414,"content":49415,"nodeType":881},{},[49416],{"data":49417,"marks":49418,"value":48522,"nodeType":867},{},[],{"data":49420,"content":49421,"nodeType":2531},{},[49422,49461,49520],{"data":49423,"content":49424,"nodeType":2438},{},[49425,49434,49443,49452],{"data":49426,"content":49427,"nodeType":2426},{},[49428],{"data":49429,"content":49430,"nodeType":881},{},[49431],{"data":49432,"marks":49433,"value":48538,"nodeType":867},{},[],{"data":49435,"content":49436,"nodeType":2426},{},[49437],{"data":49438,"content":49439,"nodeType":881},{},[49440],{"data":49441,"marks":49442,"value":49006,"nodeType":867},{},[],{"data":49444,"content":49445,"nodeType":2426},{},[49446],{"data":49447,"content":49448,"nodeType":881},{},[49449],{"data":49450,"marks":49451,"value":48558,"nodeType":867},{},[],{"data":49453,"content":49454,"nodeType":2426},{},[49455],{"data":49456,"content":49457,"nodeType":881},{},[49458],{"data":49459,"marks":49460,"value":48568,"nodeType":867},{},[],{"data":49462,"content":49463,"nodeType":2438},{},[49464,49483,49502,49511],{"data":49465,"content":49466,"nodeType":2452},{},[49467],{"data":49468,"content":49469,"nodeType":881},{},[49470,49473,49480],{"data":49471,"marks":49472,"value":21,"nodeType":867},{},[],{"data":49474,"content":49475,"nodeType":876},{"uri":49039},[49476],{"data":49477,"marks":49478,"value":49045,"nodeType":867},{},[49479],{"type":1040},{"data":49481,"marks":49482,"value":21,"nodeType":867},{},[],{"data":49484,"content":49485,"nodeType":2452},{},[49486],{"data":49487,"content":49488,"nodeType":881},{},[49489,49492,49499],{"data":49490,"marks":49491,"value":21,"nodeType":867},{},[],{"data":49493,"content":49494,"nodeType":876},{"uri":49060},[49495],{"data":49496,"marks":49497,"value":333,"nodeType":867},{},[49498],{"type":1040},{"data":49500,"marks":49501,"value":21,"nodeType":867},{},[],{"data":49503,"content":49504,"nodeType":2452},{},[49505],{"data":49506,"content":49507,"nodeType":881},{},[49508],{"data":49509,"marks":49510,"value":49078,"nodeType":867},{},[],{"data":49512,"content":49513,"nodeType":2452},{},[49514],{"data":49515,"content":49516,"nodeType":881},{},[49517],{"data":49518,"marks":49519,"value":49088,"nodeType":867},{},[],{"data":49521,"content":49522,"nodeType":2438},{},[49523,49544,49565,49575],{"data":49524,"content":49525,"nodeType":2452},{},[49526],{"data":49527,"content":49528,"nodeType":881},{},[49529,49532,49541],{"data":49530,"marks":49531,"value":21,"nodeType":867},{},[],{"data":49533,"content":49535,"nodeType":876},{"uri":49534},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/password_scraping/description.md",[49536],{"data":49537,"marks":49538,"value":49540,"nodeType":867},{},[49539],{"type":1040},"SAT1028",{"data":49542,"marks":49543,"value":21,"nodeType":867},{},[],{"data":49545,"content":49546,"nodeType":2452},{},[49547],{"data":49548,"content":49549,"nodeType":881},{},[49550,49553,49562],{"data":49551,"marks":49552,"value":21,"nodeType":867},{},[],{"data":49554,"content":49556,"nodeType":876},{"uri":49555},"https://pushsecurity.com/resources/browser-identity-attacks-matrix/password-scraping",[49557],{"data":49558,"marks":49559,"value":49561,"nodeType":867},{},[49560],{"type":1040},"Password Scraping",{"data":49563,"marks":49564,"value":21,"nodeType":867},{},[],{"data":49566,"content":49567,"nodeType":2452},{},[49568],{"data":49569,"content":49570,"nodeType":881},{},[49571],{"data":49572,"marks":49573,"value":49574,"nodeType":867},{},[],"Credential Access",{"data":49576,"content":49577,"nodeType":2452},{},[49578],{"data":49579,"content":49580,"nodeType":881},{},[49581],{"data":49582,"marks":49583,"value":49584,"nodeType":867},{},[],"Collection of credentials and secrets from repositories e.g. password managers, SaaS file stores, etc.",{"data":49586,"content":49587,"nodeType":998},{},[49588],{"data":49589,"marks":49590,"value":48702,"nodeType":867},{},[],{"data":49592,"content":49593,"nodeType":881},{},[49594],{"data":49595,"marks":49596,"value":49598,"nodeType":867},{},[49597],{"type":916},"Cloudflare — November 2023",{"data":49600,"content":49601,"nodeType":881},{},[49602],{"data":49603,"marks":49604,"value":49605,"nodeType":867},{},[],"The threat actor used tokens and credentials that had not been rotated to breach Cloudflare’s internal Atlassian server and access its Confluence wiki, Jira bug database, and Bitbucket source code management system. The threat actor first gained access to Cloudflare's self-hosted Atlassian server and then accessed the company's Confluence and Jira systems following a reconnaissance stage. Cloudflare says that this breach did not impact customer data or systems or the provision of services.",{"data":49607,"content":49608,"nodeType":881},{},[49609],{"data":49610,"marks":49611,"value":49613,"nodeType":867},{},[49612],{"type":916},"1Password — October 2023",{"data":49615,"content":49616,"nodeType":881},{},[49617],{"data":49618,"marks":49619,"value":49620,"nodeType":867},{},[],"1Password reported unsolicited activity in their Okta environment which was traced to a suspicious IP address. Later it was confirmed that an threat actor had accessed 1Password’s Okta environment using administrative privileges. They attempted to access the IT team member’s user dashboard, but that attempt was blocked by Okta. They also requested a report of administrative users, which was identified as suspicious and triggered an investigation. 1Password says it terminated the activity, investigated, and found no compromise of user data or other sensitive systems, either employee-facing or user-facing.",{"data":49622,"content":49623,"nodeType":881},{},[49624],{"data":49625,"marks":49626,"value":49628,"nodeType":867},{},[49627],{"type":916},"BeyondTrust - October 2023",{"data":49630,"content":49631,"nodeType":881},{},[49632],{"data":49633,"marks":49634,"value":49635,"nodeType":867},{},[],"BeyondTrust security teams detected an identity-centric attack on an in-house Okta administrator account. BeyondTrust blocked all access to the threat actor, and verified that they did not gain access to any systems. BeyondTrust has confirmed that there was no additional exposure to our internal systems or BeyondTrust’s customers.",{"data":49637,"content":49638,"nodeType":908},{},[],{"data":49640,"content":49641,"nodeType":918},{},[49642],{"data":49643,"marks":49644,"value":49645,"nodeType":867},{},[],"MGM Resorts — September 2023",{"data":49647,"content":49648,"nodeType":881},{},[49649],{"data":49650,"marks":49651,"value":49652,"nodeType":867},{},[],"The threat group known as Scattered Spider socially engineered MGM help desk personnel to grant ‘super admin’ access to the Okta tenant, which was then used to steal data and deploy ransomware, resulting in significant business disruption. ",{"data":49654,"content":49655,"nodeType":998},{},[49656],{"data":49657,"marks":49658,"value":49659,"nodeType":867},{},[],"How did MGM get breached?",{"data":49661,"content":49662,"nodeType":3126},{},[49663,49673,49683,49693,49703,49713],{"data":49664,"content":49665,"nodeType":3061},{},[49666],{"data":49667,"content":49668,"nodeType":881},{},[49669],{"data":49670,"marks":49671,"value":49672,"nodeType":867},{},[],"Scattered Spider researched MGM employees on LinkedIn to identify individuals likely to have privileged Okta access, specifically Super Administrator privileges. ",{"data":49674,"content":49675,"nodeType":3061},{},[49676],{"data":49677,"content":49678,"nodeType":881},{},[49679],{"data":49680,"marks":49681,"value":49682,"nodeType":867},{},[],"Scattered Spider contacted the IT help desk impersonating an employee with a privileged account asking for an authentication reset (password and MFA).",{"data":49684,"content":49685,"nodeType":3061},{},[49686],{"data":49687,"content":49688,"nodeType":881},{},[49689],{"data":49690,"marks":49691,"value":49692,"nodeType":867},{},[],"With privileged access, the compromised Super Administrator accounts were used to assign higher privileges to other accounts, circumventing MFA by removing enrolled authenticators and/or removing MFA from authentication policies.",{"data":49694,"content":49695,"nodeType":3061},{},[49696],{"data":49697,"content":49698,"nodeType":881},{},[49699],{"data":49700,"marks":49701,"value":49702,"nodeType":867},{},[],"Scattered Spider registered a second, attacker-controlled IdP via Org2Org using inbound federation, granting the ability to impersonate users and access applications on their behalf. By matching the username of target accounts in the second IdP to the original, the attacker was able to SSO into target applications. ",{"data":49704,"content":49705,"nodeType":3061},{},[49706],{"data":49707,"content":49708,"nodeType":881},{},[49709],{"data":49710,"marks":49711,"value":49712,"nodeType":867},{},[],"Through inbound federation, Scattered Spider obtained global admin rights in Azure, effectively granting full control over connected systems and granting domain admin privileges in target environments.",{"data":49714,"content":49715,"nodeType":3061},{},[49716],{"data":49717,"content":49718,"nodeType":881},{},[49719],{"data":49720,"marks":49721,"value":49722,"nodeType":867},{},[],"Scattered Spider deployed encryption software to around 100 ESXi servers and exfiltrated data, disrupting core business operations.",{"data":49724,"content":49725,"nodeType":998},{},[49726],{"data":49727,"marks":49728,"value":49729,"nodeType":867},{},[],"What was the impact of the MGM breach?",{"data":49731,"content":49732,"nodeType":3126},{},[49733,49743,49753],{"data":49734,"content":49735,"nodeType":3061},{},[49736],{"data":49737,"content":49738,"nodeType":881},{},[49739],{"data":49740,"marks":49741,"value":49742,"nodeType":867},{},[],"Led to a 36-hour outage of multiple MGM IT systems and affected a number of its casinos on the Las Vegas strip, including the Bellagio, Excalibur, Luxor, Mandalay Bay and New York New York.",{"data":49744,"content":49745,"nodeType":3061},{},[49746],{"data":49747,"content":49748,"nodeType":881},{},[49749],{"data":49750,"marks":49751,"value":49752,"nodeType":867},{},[],"Personal data compromise of an unspecified number of customers including various contact information, dates of births, genders, driver’s license numbers, social security numbers, and passport information. ",{"data":49754,"content":49755,"nodeType":3061},{},[49756],{"data":49757,"content":49758,"nodeType":881},{},[49759],{"data":49760,"marks":49761,"value":49762,"nodeType":867},{},[],"MGM reported that the attack would cause a $100 million hit to its third-quarter results, including $10 million in one-time cyber security consulting fees. ",{"data":49764,"content":49765,"nodeType":998},{},[49766],{"data":49767,"marks":49768,"value":49769,"nodeType":867},{},[],"What stands out in the MGM breach?",{"data":49771,"content":49772,"nodeType":3126},{},[49773,49783,49793],{"data":49774,"content":49775,"nodeType":3061},{},[49776],{"data":49777,"content":49778,"nodeType":881},{},[49779],{"data":49780,"marks":49781,"value":49782,"nodeType":867},{},[],"The MGM breach demonstrates how financially motivated organized criminal groups are specifically targeting the identity infrastructure of an organization (e.g. the chosen IdP solution) and leveraging cloud-native functionality. ",{"data":49784,"content":49785,"nodeType":3061},{},[49786],{"data":49787,"content":49788,"nodeType":881},{},[49789],{"data":49790,"marks":49791,"value":49792,"nodeType":867},{},[],"The MGM breach is notable for being a hybrid attack that ended in what has become a typical “actions on objective” for ransomware operators and their affiliates - the propagation of malware and encryption of core business servers. In this way attackers are leveraging the newer functionality that cloud services provide them to target non-cloud/on-premise resources. This potentially indicates that attackers see cloud applications and services as the path of least resistance to achieving their goals, exploiting more limited security team visibility and understanding of these services compared to more traditional (now well protected) targets. ",{"data":49794,"content":49795,"nodeType":3061},{},[49796],{"data":49797,"content":49798,"nodeType":881},{},[49799],{"data":49800,"marks":49801,"value":49802,"nodeType":867},{},[],"While attackers were focused on taking control of the cloud IdP, the initial access vector was notable for being a more traditional method (vishing) to bypass the need to acquire credentials (password and MFA token). This type of technique remains consistently effective, regardless of the technology landscape and whether MFA is correctly implemented or not.    ",{"data":49804,"content":49805,"nodeType":998},{},[49806],{"data":49807,"marks":49808,"value":48515,"nodeType":867},{},[],{"data":49810,"content":49811,"nodeType":881},{},[49812],{"data":49813,"marks":49814,"value":48522,"nodeType":867},{},[],{"data":49816,"content":49817,"nodeType":2531},{},[49818,49857],{"data":49819,"content":49820,"nodeType":2438},{},[49821,49830,49839,49848],{"data":49822,"content":49823,"nodeType":2426},{},[49824],{"data":49825,"content":49826,"nodeType":881},{},[49827],{"data":49828,"marks":49829,"value":48538,"nodeType":867},{},[],{"data":49831,"content":49832,"nodeType":2426},{},[49833],{"data":49834,"content":49835,"nodeType":881},{},[49836],{"data":49837,"marks":49838,"value":49006,"nodeType":867},{},[],{"data":49840,"content":49841,"nodeType":2426},{},[49842],{"data":49843,"content":49844,"nodeType":881},{},[49845],{"data":49846,"marks":49847,"value":48558,"nodeType":867},{},[],{"data":49849,"content":49850,"nodeType":2426},{},[49851],{"data":49852,"content":49853,"nodeType":881},{},[49854],{"data":49855,"marks":49856,"value":48568,"nodeType":867},{},[],{"data":49858,"content":49859,"nodeType":2438},{},[49860,49880,49901,49911],{"data":49861,"content":49862,"nodeType":2452},{},[49863],{"data":49864,"content":49865,"nodeType":881},{},[49866,49869,49877],{"data":49867,"marks":49868,"value":21,"nodeType":867},{},[],{"data":49870,"content":49871,"nodeType":876},{"uri":14743},[49872],{"data":49873,"marks":49874,"value":49876,"nodeType":867},{},[49875],{"type":1040},"SAT1041",{"data":49878,"marks":49879,"value":21,"nodeType":867},{},[],{"data":49881,"content":49882,"nodeType":2452},{},[49883],{"data":49884,"content":49885,"nodeType":881},{},[49886,49889,49898],{"data":49887,"marks":49888,"value":21,"nodeType":867},{},[],{"data":49890,"content":49892,"nodeType":876},{"uri":49891},"https://pushsecurity.com/resources/browser-identity-attacks-matrix/inbound-federation",[49893],{"data":49894,"marks":49895,"value":49897,"nodeType":867},{},[49896],{"type":1040},"Inbound Federation",{"data":49899,"marks":49900,"value":21,"nodeType":867},{},[],{"data":49902,"content":49903,"nodeType":2452},{},[49904],{"data":49905,"content":49906,"nodeType":881},{},[49907],{"data":49908,"marks":49909,"value":49910,"nodeType":867},{},[],"Persistence; Lateral Movement",{"data":49912,"content":49913,"nodeType":2452},{},[49914],{"data":49915,"content":49916,"nodeType":881},{},[49917],{"data":49918,"marks":49919,"value":49920,"nodeType":867},{},[],"Inbound federation allows users to login to a target identity provider by authenticating with a source identity provider",{"data":49922,"content":49923,"nodeType":908},{},[],{"data":49925,"content":49926,"nodeType":918},{},[49927],{"data":49928,"marks":49929,"value":49930,"nodeType":867},{},[],"Retool — August 2023",{"data":49932,"content":49933,"nodeType":881},{},[49934],{"data":49935,"marks":49936,"value":49937,"nodeType":867},{},[],"Software development company Retool disclosed that the accounts of 27 of its cloud customers were compromised following a targeted SMS-based social engineering attack, which was enabled by Google Authenticator’s default synchronization of MFA tokens with the associated Google account.  ",{"data":49939,"content":49940,"nodeType":998},{},[49941],{"data":49942,"marks":49943,"value":49944,"nodeType":867},{},[],"How did Retool get breached?",{"data":49946,"content":49947,"nodeType":3126},{},[49948,49958,49968,49978,49988,49998],{"data":49949,"content":49950,"nodeType":3061},{},[49951],{"data":49952,"content":49953,"nodeType":881},{},[49954],{"data":49955,"marks":49956,"value":49957,"nodeType":867},{},[],"The threat actor launched a targeted SMS-based phishing campaign against Retool employees with a custom lure relating to their workplace healthcare coverage.",{"data":49959,"content":49960,"nodeType":3061},{},[49961],{"data":49962,"content":49963,"nodeType":881},{},[49964],{"data":49965,"marks":49966,"value":49967,"nodeType":867},{},[],"The timing coincided with a recently announced migration of logins to Okta, and the message contained a url disguised to look like their internal identity portal.",{"data":49969,"content":49970,"nodeType":3061},{},[49971],{"data":49972,"content":49973,"nodeType":881},{},[49974],{"data":49975,"marks":49976,"value":49977,"nodeType":867},{},[],"After logging into the fake portal – which included an MFA form – the threat actor called the employee impersonating an IT team member, deepfaking the IT employee’s real voice and using real information about the company to build trust.",{"data":49979,"content":49980,"nodeType":3061},{},[49981],{"data":49982,"content":49983,"nodeType":881},{},[49984],{"data":49985,"marks":49986,"value":49987,"nodeType":867},{},[],"The phished employee shared an MFA OTP token which allowed the threat actor to add their own personal device to the employee’s Okta account and enabled their own Okta MFA from that point forward.",{"data":49989,"content":49990,"nodeType":3061},{},[49991],{"data":49992,"content":49993,"nodeType":881},{},[49994],{"data":49995,"marks":49996,"value":49997,"nodeType":867},{},[],"Due to the Google Authenticator synchronization feature that syncs MFA codes to the cloud by default, meaning that access to a Google account immediately gave access to all MFA tokens held within that account.",{"data":49999,"content":50000,"nodeType":3061},{},[50001],{"data":50002,"content":50003,"nodeType":881},{},[50004],{"data":50005,"marks":50006,"value":50007,"nodeType":867},{},[],"This enabled the threat actor to take over a number of identities associated with a range of target apps and change the credentials.",{"data":50009,"content":50010,"nodeType":998},{},[50011],{"data":50012,"marks":50013,"value":50014,"nodeType":867},{},[],"What was the impact of the Retool breach?",{"data":50016,"content":50017,"nodeType":3126},{},[50018,50028,50038],{"data":50019,"content":50020,"nodeType":3061},{},[50021],{"data":50022,"content":50023,"nodeType":881},{},[50024],{"data":50025,"marks":50026,"value":50027,"nodeType":867},{},[],"A total of 27 customers were impacted, with the threat actor specifically targeting customers in the Crypto industry.",{"data":50029,"content":50030,"nodeType":3061},{},[50031],{"data":50032,"content":50033,"nodeType":881},{},[50034],{"data":50035,"marks":50036,"value":50037,"nodeType":867},{},[],"After taking over the accounts, the threat actor was observed gathering information and exploring the Retool apps.",{"data":50039,"content":50040,"nodeType":3061},{},[50041],{"data":50042,"content":50043,"nodeType":881},{},[50044],{"data":50045,"marks":50046,"value":50047,"nodeType":867},{},[],"After learning of the attack, Retool revoked all internal authenticated sessions (Okta, GSuite, etc.) for employees, locked down access to the affected accounts, notified the affected customers, and restored their accounts to their original state.",{"data":50049,"content":50050,"nodeType":998},{},[50051],{"data":50052,"marks":50053,"value":50054,"nodeType":867},{},[],"What stands out in the Retool breach?",{"data":50056,"content":50057,"nodeType":3126},{},[50058,50068,50078],{"data":50059,"content":50060,"nodeType":3061},{},[50061],{"data":50062,"content":50063,"nodeType":881},{},[50064],{"data":50065,"marks":50066,"value":50067,"nodeType":867},{},[],"Like the MGM breach, the Retool breach demonstrates how financially motivated organized criminal groups are specifically targeting the identity infrastructure of an organization (e.g. the chosen IdP solution) and leveraging cloud-native functionality. ",{"data":50069,"content":50070,"nodeType":3061},{},[50071],{"data":50072,"content":50073,"nodeType":881},{},[50074],{"data":50075,"marks":50076,"value":50077,"nodeType":867},{},[],"A further similarity with the MGM breach, while attackers were focused on taking control of the cloud IdP, the initial access vector was notable for being a more traditional method (SMS phishing in this case) to bypass the need to acquire credentials (password and MFA token). This type of technique remains consistently effective, regardless of the technology landscape and whether MFA is correctly implemented or not.    ",{"data":50079,"content":50080,"nodeType":3061},{},[50081],{"data":50082,"content":50083,"nodeType":881},{},[50084],{"data":50085,"marks":50086,"value":50087,"nodeType":867},{},[],"In this case, the attacker abused inherent weaknesses in Google Authenticator, which came under fire following the breach for its default synchronization of MFA codes to the cloud when connected to an account, in order to move laterally and compromise other target apps. ",{"data":50089,"content":50090,"nodeType":998},{},[50091],{"data":50092,"marks":50093,"value":48515,"nodeType":867},{},[],{"data":50095,"content":50096,"nodeType":881},{},[50097],{"data":50098,"marks":50099,"value":48522,"nodeType":867},{},[],{"data":50101,"content":50102,"nodeType":2531},{},[50103,50142,50208],{"data":50104,"content":50105,"nodeType":2438},{},[50106,50115,50124,50133],{"data":50107,"content":50108,"nodeType":2426},{},[50109],{"data":50110,"content":50111,"nodeType":881},{},[50112],{"data":50113,"marks":50114,"value":48538,"nodeType":867},{},[],{"data":50116,"content":50117,"nodeType":2426},{},[50118],{"data":50119,"content":50120,"nodeType":881},{},[50121],{"data":50122,"marks":50123,"value":49006,"nodeType":867},{},[],{"data":50125,"content":50126,"nodeType":2426},{},[50127],{"data":50128,"content":50129,"nodeType":881},{},[50130],{"data":50131,"marks":50132,"value":48558,"nodeType":867},{},[],{"data":50134,"content":50135,"nodeType":2426},{},[50136],{"data":50137,"content":50138,"nodeType":881},{},[50139],{"data":50140,"marks":50141,"value":48568,"nodeType":867},{},[],{"data":50143,"content":50144,"nodeType":2438},{},[50145,50167,50189,50198],{"data":50146,"content":50147,"nodeType":2452},{},[50148],{"data":50149,"content":50150,"nodeType":881},{},[50151,50155,50164],{"data":50152,"marks":50153,"value":21,"nodeType":867},{},[50154],{"type":1040},{"data":50156,"content":50158,"nodeType":876},{"uri":50157},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/aitm_phishing/description.md",[50159],{"data":50160,"marks":50161,"value":50163,"nodeType":867},{},[50162],{"type":1040},"SAT1042",{"data":50165,"marks":50166,"value":21,"nodeType":867},{},[],{"data":50168,"content":50169,"nodeType":2452},{},[50170],{"data":50171,"content":50172,"nodeType":881},{},[50173,50177,50186],{"data":50174,"marks":50175,"value":21,"nodeType":867},{},[50176],{"type":1040},{"data":50178,"content":50180,"nodeType":876},{"uri":50179},"https://pushsecurity.com/resources/browser-identity-attacks-matrix/aitm-phishing",[50181],{"data":50182,"marks":50183,"value":50185,"nodeType":867},{},[50184],{"type":1040},"AiTM Phishing",{"data":50187,"marks":50188,"value":21,"nodeType":867},{},[],{"data":50190,"content":50191,"nodeType":2452},{},[50192],{"data":50193,"content":50194,"nodeType":881},{},[50195],{"data":50196,"marks":50197,"value":49078,"nodeType":867},{},[],{"data":50199,"content":50200,"nodeType":2452},{},[50201],{"data":50202,"content":50203,"nodeType":881},{},[50204],{"data":50205,"marks":50206,"value":50207,"nodeType":867},{},[],"Attacker-in-the-Middle (AiTM) phishing uses dedicated tooling to act as a web proxy between the victim and a legitimate login portal for an application the victim has access to, principally to make it easier to defeat MFA protection.",{"data":50209,"content":50210,"nodeType":2438},{},[50211,50232,50255,50265],{"data":50212,"content":50213,"nodeType":2452},{},[50214],{"data":50215,"content":50216,"nodeType":881},{},[50217,50220,50229],{"data":50218,"marks":50219,"value":21,"nodeType":867},{},[],{"data":50221,"content":50223,"nodeType":876},{"uri":50222},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/device_enrollment/description.md",[50224],{"data":50225,"marks":50226,"value":50228,"nodeType":867},{},[50227],{"type":1040},"SAT1043",{"data":50230,"marks":50231,"value":21,"nodeType":867},{},[],{"data":50233,"content":50234,"nodeType":2452},{},[50235],{"data":50236,"content":50237,"nodeType":881},{},[50238,50242,50251],{"data":50239,"marks":50240,"value":21,"nodeType":867},{},[50241],{"type":1040},{"data":50243,"content":50245,"nodeType":876},{"uri":50244},"https://pushsecurity.com/resources/browser-identity-attacks-matrix/device-enrollment",[50246],{"data":50247,"marks":50248,"value":50250,"nodeType":867},{},[50249],{"type":1040},"Device Enrollment",{"data":50252,"marks":50253,"value":21,"nodeType":867},{},[50254],{"type":1040},{"data":50256,"content":50257,"nodeType":2452},{},[50258],{"data":50259,"content":50260,"nodeType":881},{},[50261],{"data":50262,"marks":50263,"value":50264,"nodeType":867},{},[],"Initial Access; Persistence",{"data":50266,"content":50267,"nodeType":2452},{},[50268],{"data":50269,"content":50270,"nodeType":881},{},[50271],{"data":50272,"marks":50273,"value":50274,"nodeType":867},{},[],"Enrollment of a new MFA device in order to allow an adversary to complete MFA challenges for future authentication. ",{"data":50276,"content":50277,"nodeType":908},{},[],{"data":50279,"content":50280,"nodeType":918},{},[50281],{"data":50282,"marks":50283,"value":50284,"nodeType":867},{},[],"GitHub / Heroku / Travis-CI / npm — April 2022",{"data":50286,"content":50287,"nodeType":881},{},[50288],{"data":50289,"marks":50290,"value":50291,"nodeType":867},{},[],"An unknown threat actor used stolen OAuth user tokens (issued to Heroku and Travis-CI) to download data from private repositories. The threat actor then compromised an internal Heroku customer database as well as accessed and stole data from dozens of downstream organizations using Heroku and Travis-CI-maintained OAuth apps.",{"data":50293,"content":50294,"nodeType":998},{},[50295],{"data":50296,"marks":50297,"value":50298,"nodeType":867},{},[],"How did they get breached?",{"data":50300,"content":50301,"nodeType":3126},{},[50302,50312,50322,50332,50342,50352,50362],{"data":50303,"content":50304,"nodeType":3061},{},[50305],{"data":50306,"content":50307,"nodeType":881},{},[50308],{"data":50309,"marks":50310,"value":50311,"nodeType":867},{},[],"The threat actor obtained access to two third-party OAuth integrators, Heroku and Travis-CI, accessing databases and downloading stored customer GitHub integration OAuth tokens. These tokens had earlier been used by Travis-CI and Heroku OAuth applications to integrate with GitHub to deploy applications.",{"data":50313,"content":50314,"nodeType":3061},{},[50315],{"data":50316,"content":50317,"nodeType":881},{},[50318],{"data":50319,"marks":50320,"value":50321,"nodeType":867},{},[],"Access to the environment was gained by leveraging a compromised token for a Heroku machine account, but it is not disclosed how the threat actor achieved this. ",{"data":50323,"content":50324,"nodeType":3061},{},[50325],{"data":50326,"content":50327,"nodeType":881},{},[50328],{"data":50329,"marks":50330,"value":50331,"nodeType":867},{},[],"The threat actor authenticated to the GitHub API using the stolen OAuth tokens issued to Heroku and Travis CI.",{"data":50333,"content":50334,"nodeType":3061},{},[50335],{"data":50336,"content":50337,"nodeType":881},{},[50338],{"data":50339,"marks":50340,"value":50341,"nodeType":867},{},[],"For users who had the affected Heroku or Travis CI OAuth apps authorized in their GitHub accounts, the threat actor listed all the user's organizations.",{"data":50343,"content":50344,"nodeType":3061},{},[50345],{"data":50346,"content":50347,"nodeType":881},{},[50348],{"data":50349,"marks":50350,"value":50351,"nodeType":867},{},[],"The threat actor then selected targets based on the listed organizations.",{"data":50353,"content":50354,"nodeType":3061},{},[50355],{"data":50356,"content":50357,"nodeType":881},{},[50358],{"data":50359,"marks":50360,"value":50361,"nodeType":867},{},[],"The threat actor listed the private repositories for user accounts of interest and proceeded to clone private repositories of interest.",{"data":50363,"content":50364,"nodeType":3061},{},[50365],{"data":50366,"content":50367,"nodeType":881},{},[50368],{"data":50369,"marks":50370,"value":50371,"nodeType":867},{},[],"GitHub identified unauthorized access to their npm production infrastructure using a compromised AWS API key, obtained by the threat actor when they downloaded a set of private npm repositories using a stolen OAuth token from one of the two affected third-party OAuth applications.",{"data":50373,"content":50374,"nodeType":998},{},[50375],{"data":50376,"marks":50377,"value":50378,"nodeType":867},{},[],"What was the impact?",{"data":50380,"content":50381,"nodeType":3126},{},[50382,50392,50402],{"data":50383,"content":50384,"nodeType":3061},{},[50385],{"data":50386,"content":50387,"nodeType":881},{},[50388],{"data":50389,"marks":50390,"value":50391,"nodeType":867},{},[],"By stealing these OAuth tokens, the threat actor could access and download data from GitHub repositories belonging to those who authorized the compromised Heroku or Travis CI OAuth apps with their accounts. ",{"data":50393,"content":50394,"nodeType":3061},{},[50395],{"data":50396,"content":50397,"nodeType":881},{},[50398],{"data":50399,"marks":50400,"value":50401,"nodeType":867},{},[],"The threat actor was able to mine the downloaded private repositories for secrets that could be used to pivot to other infrastructure, stealing data from dozens of organizations. ",{"data":50403,"content":50404,"nodeType":3061},{},[50405],{"data":50406,"content":50407,"nodeType":881},{},[50408],{"data":50409,"marks":50410,"value":50411,"nodeType":867},{},[],"In addition to user repo’s downstream, the compromised token for a Heroku machine account obtained by threat actors also allowed unauthorized access into Heroku's internal database of customer accounts, enabling the threat actor to extract the hashed and salted passwords. ",{"data":50413,"content":50414,"nodeType":998},{},[50415],{"data":50416,"marks":50417,"value":50418,"nodeType":867},{},[],"What stands out in the Github breach?",{"data":50420,"content":50421,"nodeType":3126},{},[50422,50432,50442],{"data":50423,"content":50424,"nodeType":3061},{},[50425],{"data":50426,"content":50427,"nodeType":881},{},[50428],{"data":50429,"marks":50430,"value":50431,"nodeType":867},{},[],"Similar to the Okta breach, this attack showcases the possibility of third-party supply chain attacks to target downstream organizations using cloud SaaS services. In this case, targeting OAuth integrators as opposed to IdP providers, but with a similar goal and impact of compromising the real target organizations downstream. ",{"data":50433,"content":50434,"nodeType":3061},{},[50435],{"data":50436,"content":50437,"nodeType":881},{},[50438],{"data":50439,"marks":50440,"value":50441,"nodeType":867},{},[],"Applications like Github are an obvious target for attackers due to their widespread adoption. There have been numerous attacks leveraging Github as the vehicle for attacks by compromising repo’s to insert malicious code, or registering malicious copycat repo’s to dupe users into using them. ",{"data":50443,"content":50444,"nodeType":3061},{},[50445],{"data":50446,"content":50447,"nodeType":881},{},[50448],{"data":50449,"marks":50450,"value":50451,"nodeType":867},{},[],"Unlike the attacks abusing the functionality of Github (repo poisoning) which target the legitimate developer processes when using the app, this attack could have been prevented at the identity layer before the attacker was able to breach the Heroku/Travis-CI accounts. ",{"data":50453,"content":50454,"nodeType":998},{},[50455],{"data":50456,"marks":50457,"value":48515,"nodeType":867},{},[],{"data":50459,"content":50460,"nodeType":881},{},[50461],{"data":50462,"marks":50463,"value":48522,"nodeType":867},{},[],{"data":50465,"content":50466,"nodeType":2531},{},[50467,50506,50566,50631],{"data":50468,"content":50469,"nodeType":2438},{},[50470,50479,50488,50497],{"data":50471,"content":50472,"nodeType":2426},{},[50473],{"data":50474,"content":50475,"nodeType":881},{},[50476],{"data":50477,"marks":50478,"value":48538,"nodeType":867},{},[],{"data":50480,"content":50481,"nodeType":2426},{},[50482],{"data":50483,"content":50484,"nodeType":881},{},[50485],{"data":50486,"marks":50487,"value":49006,"nodeType":867},{},[],{"data":50489,"content":50490,"nodeType":2426},{},[50491],{"data":50492,"content":50493,"nodeType":881},{},[50494],{"data":50495,"marks":50496,"value":48558,"nodeType":867},{},[],{"data":50498,"content":50499,"nodeType":2426},{},[50500],{"data":50501,"content":50502,"nodeType":881},{},[50503],{"data":50504,"marks":50505,"value":48568,"nodeType":867},{},[],{"data":50507,"content":50508,"nodeType":2438},{},[50509,50528,50547,50557],{"data":50510,"content":50511,"nodeType":2452},{},[50512],{"data":50513,"content":50514,"nodeType":881},{},[50515,50518,50525],{"data":50516,"marks":50517,"value":21,"nodeType":867},{},[],{"data":50519,"content":50520,"nodeType":876},{"uri":49168},[50521],{"data":50522,"marks":50523,"value":49174,"nodeType":867},{},[50524],{"type":1040},{"data":50526,"marks":50527,"value":21,"nodeType":867},{},[],{"data":50529,"content":50530,"nodeType":2452},{},[50531],{"data":50532,"content":50533,"nodeType":881},{},[50534,50537,50544],{"data":50535,"marks":50536,"value":21,"nodeType":867},{},[],{"data":50538,"content":50539,"nodeType":876},{"uri":49189},[50540],{"data":50541,"marks":50542,"value":49195,"nodeType":867},{},[50543],{"type":1040},{"data":50545,"marks":50546,"value":21,"nodeType":867},{},[],{"data":50548,"content":50549,"nodeType":2452},{},[50550],{"data":50551,"content":50552,"nodeType":881},{},[50553],{"data":50554,"marks":50555,"value":50556,"nodeType":867},{},[],"Privilege Escalation; Lateral Movement",{"data":50558,"content":50559,"nodeType":2452},{},[50560],{"data":50561,"content":50562,"nodeType":881},{},[50563],{"data":50564,"marks":50565,"value":49218,"nodeType":867},{},[],{"data":50567,"content":50568,"nodeType":2438},{},[50569,50590,50611,50621],{"data":50570,"content":50571,"nodeType":2452},{},[50572],{"data":50573,"content":50574,"nodeType":881},{},[50575,50578,50587],{"data":50576,"marks":50577,"value":21,"nodeType":867},{},[],{"data":50579,"content":50581,"nodeType":876},{"uri":50580},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/api_keys/description.md",[50582],{"data":50583,"marks":50584,"value":50586,"nodeType":867},{},[50585],{"type":1040},"SAT1004",{"data":50588,"marks":50589,"value":21,"nodeType":867},{},[],{"data":50591,"content":50592,"nodeType":2452},{},[50593],{"data":50594,"content":50595,"nodeType":881},{},[50596,50599,50608],{"data":50597,"marks":50598,"value":21,"nodeType":867},{},[],{"data":50600,"content":50602,"nodeType":876},{"uri":50601},"https://pushsecurity.com/resources/browser-identity-attacks-matrix/api-keys",[50603],{"data":50604,"marks":50605,"value":50607,"nodeType":867},{},[50606],{"type":1040},"API keys",{"data":50609,"marks":50610,"value":21,"nodeType":867},{},[],{"data":50612,"content":50613,"nodeType":2452},{},[50614],{"data":50615,"content":50616,"nodeType":881},{},[50617],{"data":50618,"marks":50619,"value":50620,"nodeType":867},{},[],"Persistence; Defense Evasion",{"data":50622,"content":50623,"nodeType":2452},{},[50624],{"data":50625,"content":50626,"nodeType":881},{},[50627],{"data":50628,"marks":50629,"value":50630,"nodeType":867},{},[],"An adversary that has compromised an account could then read existing API keys from the app settings, if the app allows this, or create a new API key.",{"data":50632,"content":50633,"nodeType":2438},{},[50634,50655,50676,50686],{"data":50635,"content":50636,"nodeType":2452},{},[50637],{"data":50638,"content":50639,"nodeType":881},{},[50640,50643,50652],{"data":50641,"marks":50642,"value":21,"nodeType":867},{},[],{"data":50644,"content":50646,"nodeType":876},{"uri":50645},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/app_directory_lookup/description.md#app-directory-lookup",[50647],{"data":50648,"marks":50649,"value":50651,"nodeType":867},{},[50650],{"type":1040},"SAT1006",{"data":50653,"marks":50654,"value":21,"nodeType":867},{},[],{"data":50656,"content":50657,"nodeType":2452},{},[50658],{"data":50659,"content":50660,"nodeType":881},{},[50661,50664,50673],{"data":50662,"marks":50663,"value":21,"nodeType":867},{},[],{"data":50665,"content":50667,"nodeType":876},{"uri":50666},"https://pushsecurity.com/resources/browser-identity-attacks-matrix/app-directory-lookup",[50668],{"data":50669,"marks":50670,"value":50672,"nodeType":867},{},[50671],{"type":1040},"App directory lookup",{"data":50674,"marks":50675,"value":21,"nodeType":867},{},[],{"data":50677,"content":50678,"nodeType":2452},{},[50679],{"data":50680,"content":50681,"nodeType":881},{},[50682],{"data":50683,"marks":50684,"value":50685,"nodeType":867},{},[],"Discovery",{"data":50687,"content":50688,"nodeType":2452},{},[50689],{"data":50690,"content":50691,"nodeType":881},{},[50692],{"data":50693,"marks":50694,"value":50695,"nodeType":867},{},[],"An adversary who has gained a foothold via a SaaS app could download the list of users accessible to them in order to better target attacks against other users.",{"data":50697,"content":50698,"nodeType":908},{},[],{"data":50700,"content":50701,"nodeType":918},{},[50702],{"data":50703,"marks":50704,"value":50705,"nodeType":867},{},[],"Other notable attacks",{"data":50707,"content":50708,"nodeType":998},{},[50709],{"data":50710,"marks":50711,"value":50712,"nodeType":867},{},[],"SEC X hack — January 2024",{"data":50714,"content":50715,"nodeType":881},{},[50716],{"data":50717,"marks":50718,"value":50719,"nodeType":867},{},[],"The X account for the U.S. Securities and Exchange Commission was victim to a SIM swapping attack, whereupon the attacker used the social media platform to issue a fake announcement on the approval of Bitcoin ETFs on security exchanges.",{"data":50721,"content":50722,"nodeType":881},{},[50723],{"data":50724,"marks":50725,"value":50726,"nodeType":867},{},[],"Once the threat actors controlled the number, they reset the password for the @SECGov account, and created the fake announcement. The SEC also confirmed that multi-factor authentication was not enabled on the account, as they had asked X support to disable it when they encountered problems logging into the account.",{"data":50728,"content":50729,"nodeType":908},{},[],{"data":50731,"content":50732,"nodeType":998},{},[50733],{"data":50734,"marks":50735,"value":50736,"nodeType":867},{},[],"Mandiant X hack — January 2024",{"data":50738,"content":50739,"nodeType":881},{},[50740],{"data":50741,"marks":50742,"value":50743,"nodeType":867},{},[],"The X account for Mandiant was hacked by a Drainer-as-a-Service (DaaS) gang in a brute force attack. MFA was not enabled on the account. The threat actor used the social media account to share links redirecting to a phishing page to steal cryptocurrency. ",{"data":50745,"content":50746,"nodeType":881},{},[50747],{"data":50748,"marks":50749,"value":50750,"nodeType":867},{},[],"The attacker used a wallet drainer dubbed CLINKSINK. This same drainer has been used since December to steal funds and tokens from users of Solana cryptocurrency as part of a large-scale campaign involving at least 35 affiliate IDs linked to a shared DaaS.",{"data":50752,"content":50753,"nodeType":908},{},[],{"data":50755,"content":50756,"nodeType":998},{},[50757],{"data":50758,"marks":50759,"value":50760,"nodeType":867},{},[],"23andMe data breach — April 2023",{"data":50762,"content":50763,"nodeType":881},{},[50764],{"data":50765,"marks":50766,"value":50767,"nodeType":867},{},[],"Genetic testing provider 23andMe confirmed that hackers downloaded the data of 6.9 million people of the existing 14 million customers after breaching around 14,000 user accounts. ",{"data":50769,"content":50770,"nodeType":881},{},[50771],{"data":50772,"marks":50773,"value":50774,"nodeType":867},{},[],"The attacker stole health reports and raw genotype data of customers affected by a credential stuffing attack that went unnoticed for five months, from April 29 to September 27. ",{"data":50776,"content":50777,"nodeType":881},{},[50778],{"data":50779,"marks":50780,"value":50781,"nodeType":867},{},[],"The credentials used by the attackers to breach the customers' accounts were stolen in other data breaches or used on previously compromised online platforms, and targeted accounts without MFA. ",{"entries":50783},{"hyperlink":50784,"inline":50785,"block":50786},[],[],[50787],{"sys":50788,"__typename":1648,"title":50789,"caption":50790,"layoutMode":59,"file":50791},{"id":47885},"Table of identity attacks - IDSA 2023. Includes phishing, social engineering, brute forcing, password spraying, credential stuffing, stolen credentials, third party attack, adversary in the middle AITM, insider attack","Breakdown of identity attacks from a 2023 IDSA whitepaper",{"url":50792,"width":50793,"height":50794},"https://images.ctfassets.net/y1cdw1ablpvd/2Pu4DMeLHGxRVEiqLUPtuB/f7841fe0868c7c541dd10b7ab8361d31/Image_19-03-2024_at_15.55.jpeg",2190,1210,{"items":50796},[],{},"Identity-based attack techniques as seen in public breaches",{"url":50800},"https://images.ctfassets.net/y1cdw1ablpvd/1vYl5tHrkQcrL0ALGifUCo/76a7ec344f380305a39b4edd1b992ccb/Alt_blog_image.png","2024-03-21T00:00:00.000Z",{"items":50803},[50804],{"__typename":1742,"sys":50805,"content":50807,"title":51597,"synopsis":51598,"hashTags":59,"publishedDate":51599,"slug":51600,"tagsCollection":51601,"authorsCollection":51607},{"id":50806},"6VZQJzQ2FNetGNMEjiuXB2",{"json":50808},{"data":50809,"content":50810,"nodeType":1640},{},[50811,50818,50825,50832,50839,50846,50853,50859,50876,50883,50928,50935,50942,50986,51006,51013,51020,51027,51047,51067,51074,51107,51114,51134,51141,51148,51178,51198,51205,51211,51218,51225,51232,51239,51246,51253,51260,51267,51274,51281,51288,51295,51311,51318,51388,51395,51402,51431,51446,51453,51460,51467,51500,51520,51527,51534,51541,51548,51567,51585,51591],{"data":50812,"content":50813,"nodeType":881},{},[50814],{"data":50815,"marks":50816,"value":50817,"nodeType":867},{},[],"Our goal at Push is simple — to stop identity attacks. Today, the vast majority of identity vulnerabilities exist in the context of SaaS apps. ",{"data":50819,"content":50820,"nodeType":881},{},[50821],{"data":50822,"marks":50823,"value":50824,"nodeType":867},{},[],"The reasons for this are clear: Security teams have reduced central oversight and control over SaaS apps than they are used to, these apps exist in large numbers per company, and the identities that are used to access these apps are... complicated, to say the least. Securing hundreds of apps, with thousands of associated identities, is therefore no mean feat. ",{"data":50826,"content":50827,"nodeType":881},{},[50828],{"data":50829,"marks":50830,"value":50831,"nodeType":867},{},[],"Securing SaaS use means building controls that are easy to use, easy to understand — and ultimately effective. Not just effective against the hand-wavy concept of “SaaS attacks,” but specific techniques — the most common techniques that are likely to cause real damage.",{"data":50833,"content":50834,"nodeType":881},{},[50835],{"data":50836,"marks":50837,"value":50838,"nodeType":867},{},[],"To talk about this, we need to have a shared understanding of what these techniques are. To get that conversation going, we’ve pulled together all the techniques we're aware of, and our research team has even added a bunch of new ones.",{"data":50840,"content":50841,"nodeType":918},{},[50842],{"data":50843,"marks":50844,"value":50845,"nodeType":867},{},[],"The SaaS attack matrix",{"data":50847,"content":50848,"nodeType":881},{},[50849],{"data":50850,"marks":50851,"value":50852,"nodeType":867},{},[],"We’ve taken inspiration from the MITRE ATT&CK framework (certainly intended as the sincerest form of flattery), but wanted to make a conscious break away from the endpoint-focused ATT&CK techniques and instead focus on techniques that are SaaS-specific. In fact, these techniques don’t touch endpoints (so they bypass EDR) or customer networks (so they bypass network detection) — so we’re calling them networkless attacks.",{"data":50854,"content":50858,"nodeType":890},{"target":50855},{"sys":50856},{"id":50857,"type":887,"linkType":888},"768Zv5gTVHyu5rbzJAzL4F",[],{"data":50860,"content":50861,"nodeType":881},{},[50862,50866,50873],{"data":50863,"marks":50864,"value":50865,"nodeType":867},{},[],"You can find more detailed descriptions of these techniques (and hopefully PRs for some we missed) on ",{"data":50867,"content":50868,"nodeType":876},{"uri":3236},[50869],{"data":50870,"marks":50871,"value":3241,"nodeType":867},{},[50872],{"type":1040},{"data":50874,"marks":50875,"value":1947,"nodeType":867},{},[],{"data":50877,"content":50878,"nodeType":881},{},[50879],{"data":50880,"marks":50881,"value":50882,"nodeType":867},{},[],"Since we’re not targeting endpoints, let’s talk about the new targets: The accounts/identities on SaaS apps. We found it was useful to think about these identities not as standalone isolated islands — but much more like a graph; less a single web-server on the internet and more like many Windows endpoints on an Active Directory. ",{"data":50884,"content":50885,"nodeType":881},{},[50886,50890,50899,50902,50911,50915,50924],{"data":50887,"marks":50888,"value":50889,"nodeType":867},{},[],"You can leverage this access to an identity on a trusted platform to target (so laterally move or escalate privilege to) other users or identities. For example, attacks like using access to SaaS apps to ",{"data":50891,"content":50893,"nodeType":876},{"uri":50892},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/in-app_phishing/description.md",[50894],{"data":50895,"marks":50896,"value":50898,"nodeType":867},{},[50897],{"type":1040},"phish other employees through comments",{"data":50900,"marks":50901,"value":2063,"nodeType":867},{},[],{"data":50903,"content":50905,"nodeType":876},{"uri":50904},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/im_user_spoofing/description.md",[50906],{"data":50907,"marks":50908,"value":50910,"nodeType":867},{},[50909],{"type":1040},"spoofing users on IM platforms",{"data":50912,"marks":50913,"value":50914,"nodeType":867},{},[]," to social engineer them there — or perhaps ",{"data":50916,"content":50918,"nodeType":876},{"uri":50917},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/link_backdooring/description.md",[50919],{"data":50920,"marks":50921,"value":50923,"nodeType":867},{},[50922],{"type":1040},"backdooring links",{"data":50925,"marks":50926,"value":50927,"nodeType":867},{},[]," in documents.",{"data":50929,"content":50930,"nodeType":881},{},[50931],{"data":50932,"marks":50933,"value":50934,"nodeType":867},{},[],"In this case, unusually, it’s not the data in these hundreds of SaaS apps that create risk, and you need to consider low-risk (from a data perspective) apps as a vector to pivot to higher-risk apps in your estate.",{"data":50936,"content":50937,"nodeType":998},{},[50938],{"data":50939,"marks":50940,"value":50941,"nodeType":867},{},[],"Initial access and poisoned tenants",{"data":50943,"content":50944,"nodeType":881},{},[50945,50949,50957,50960,50969,50973,50982],{"data":50946,"marks":50947,"value":50948,"nodeType":867},{},[],"Attacks like ",{"data":50950,"content":50951,"nodeType":876},{"uri":49039},[50952],{"data":50953,"marks":50954,"value":50956,"nodeType":867},{},[50955],{"type":1040},"credential stuffing",{"data":50958,"marks":50959,"value":2063,"nodeType":867},{},[],{"data":50961,"content":50963,"nodeType":876},{"uri":50962},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/email_phishing/description.md",[50964],{"data":50965,"marks":50966,"value":50968,"nodeType":867},{},[50967],{"type":1040},"email phishing",{"data":50970,"marks":50971,"value":50972,"nodeType":867},{},[]," that get you initial access to SaaS apps are fairly well known — because they work and are widely used. We’re also starting to see tools and attacks that suggest that ",{"data":50974,"content":50976,"nodeType":876},{"uri":50975},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/im_phishing/description.md",[50977],{"data":50978,"marks":50979,"value":50981,"nodeType":867},{},[50980],{"type":1040},"phishing employees through these IM apps",{"data":50983,"marks":50984,"value":50985,"nodeType":867},{},[]," is about to go mainstream.",{"data":50987,"content":50988,"nodeType":881},{},[50989,50993,51002],{"data":50990,"marks":50991,"value":50992,"nodeType":867},{},[],"Another interesting attack is a spin on the classic waterhole attack called a ",{"data":50994,"content":50996,"nodeType":876},{"uri":50995},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/poisoned_tenants/description.md",[50997],{"data":50998,"marks":50999,"value":51001,"nodeType":867},{},[51000],{"type":1040},"poisoned tenant",{"data":51003,"marks":51004,"value":51005,"nodeType":867},{},[],". Rather than attacking a customer tenant for a SaaS app, the attacker lures employees into joining an attacker-controlled tenant. ",{"data":51007,"content":51008,"nodeType":881},{},[51009],{"data":51010,"marks":51011,"value":51012,"nodeType":867},{},[],"SaaS apps allow anyone to name app tenants (a.k.a. spaces, teams, or instances) anything they like — including your company name. Attackers send invites to your employees from within the app with a customized message explaining why they should join this new tenant (or sign up to the app if they are not already a user). ",{"data":51014,"content":51015,"nodeType":881},{},[51016],{"data":51017,"marks":51018,"value":51019,"nodeType":867},{},[],"Attackers might even pay for premium licenses in the app to further entice employees to join. The attacker then waits for the employee to upload sensitive data or create integrations with other company apps containing crown jewels.",{"data":51021,"content":51022,"nodeType":998},{},[51023],{"data":51024,"marks":51025,"value":51026,"nodeType":867},{},[],"Living-off-the-(SaaS)-land to persist and avoid detection",{"data":51028,"content":51029,"nodeType":881},{},[51030,51034,51043],{"data":51031,"marks":51032,"value":51033,"nodeType":867},{},[],"In the endpoint world, a favorite technique is the use of legit OS utilities or ",{"data":51035,"content":51037,"nodeType":876},{"uri":51036},"https://lolbas-project.github.io",[51038],{"data":51039,"marks":51040,"value":51042,"nodeType":867},{},[51041],{"type":1040},"LOLBaS",{"data":51044,"marks":51045,"value":51046,"nodeType":867},{},[]," (Living-Off-the-Land Binaries and Scripts), which are often signed Microsoft utilities. Perhaps the most well-known example is executing scripts through PowerShell rather than building custom malware. That isn’t as useful these days, but there was a time when PowerShell was routinely used to bypass AV, EDR, and even app allow-listing.",{"data":51048,"content":51049,"nodeType":881},{},[51050,51054,51063],{"data":51051,"marks":51052,"value":51053,"nodeType":867},{},[],"In that same living-off-the-land mindset, an attacker trying to maintain access to each SaaS app they compromise using custom OAuth integration apps might instead choose to use legit SaaS apps that specialize in workflow automation to create ",{"data":51055,"content":51057,"nodeType":876},{"uri":51056},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/shadow_workflows/description.md",[51058],{"data":51059,"marks":51060,"value":51062,"nodeType":867},{},[51061],{"type":1040},"shadow workflows",{"data":51064,"marks":51065,"value":51066,"nodeType":867},{},[],". Utilizing legit SaaS apps also means they can hide in plain sight from incident responders, instead of having to rely on unverified or unpublished integrations.",{"data":51068,"content":51069,"nodeType":881},{},[51070],{"data":51071,"marks":51072,"value":51073,"nodeType":867},{},[],"Perhaps the best example here is using a well-known automation app like Zapier, which claims to have more than 5,000 integrations. These integrations are often verified, approved, and connected to a trusted vendor (Zapier). An attacker might create workflows to:",{"data":51075,"content":51076,"nodeType":3126},{},[51077,51087,51097],{"data":51078,"content":51079,"nodeType":3061},{},[51080],{"data":51081,"content":51082,"nodeType":881},{},[51083],{"data":51084,"marks":51085,"value":51086,"nodeType":867},{},[],"Do daily data exfiltration from a victim’s data lake.",{"data":51088,"content":51089,"nodeType":3061},{},[51090],{"data":51091,"content":51092,"nodeType":881},{},[51093],{"data":51094,"marks":51095,"value":51096,"nodeType":867},{},[],"Configure a webhook that adds malicious accounts to a Github repo on demand.",{"data":51098,"content":51099,"nodeType":3061},{},[51100],{"data":51101,"content":51102,"nodeType":881},{},[51103],{"data":51104,"marks":51105,"value":51106,"nodeType":867},{},[],"Automatically find and replace bank account numbers in emails to the finance team.",{"data":51108,"content":51109,"nodeType":881},{},[51110],{"data":51111,"marks":51112,"value":51113,"nodeType":867},{},[],"All appear as legitimate Zapier integrations. But, before you put in alerts specifically for Zapier, know that it’s one of dozens of apps that support these kinds of offensive workflows.",{"data":51115,"content":51116,"nodeType":881},{},[51117,51121,51130],{"data":51118,"marks":51119,"value":51120,"nodeType":867},{},[],"A sneaky attacker might go further and use an ",{"data":51122,"content":51124,"nodeType":876},{"uri":51123},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/evil_twin_integrations/description.md",[51125],{"data":51126,"marks":51127,"value":51129,"nodeType":867},{},[51128],{"type":1040},"evil twin integration",{"data":51131,"marks":51132,"value":51133,"nodeType":867},{},[]," to make another instance of an existing integration — making this backdoor almost impossible to discover.",{"data":51135,"content":51136,"nodeType":998},{},[51137],{"data":51138,"marks":51139,"value":51140,"nodeType":867},{},[],"Features or vulnerabilities?",{"data":51142,"content":51143,"nodeType":881},{},[51144],{"data":51145,"marks":51146,"value":51147,"nodeType":867},{},[],"When looking for attack techniques, you’re typically going after features that have weaknesses you can abuse rather than bugs in a single app that will be patched. ",{"data":51149,"content":51150,"nodeType":881},{},[51151,51155,51164,51167,51174],{"data":51152,"marks":51153,"value":51154,"nodeType":867},{},[],"It’s pretty common for SaaS apps to skip email verification or allow multiple simultaneous authentication methods. Both of these are conscious design choices in the name of lowering the friction of account creation and reducing customer support. However, these features make techniques like ",{"data":51156,"content":51158,"nodeType":876},{"uri":51157},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/account_ambushing/description.md",[51159],{"data":51160,"marks":51161,"value":51163,"nodeType":867},{},[51162],{"type":1040},"account ambushing",{"data":51165,"marks":51166,"value":2063,"nodeType":867},{},[],{"data":51168,"content":51169,"nodeType":876},{"uri":14589},[51170],{"data":51171,"marks":51172,"value":6850,"nodeType":867},{},[51173],{"type":1040},{"data":51175,"marks":51176,"value":51177,"nodeType":867},{},[]," possible. If these attacks become widespread, these might come to be seen more as bugs rather than a positive feature for users.",{"data":51179,"content":51180,"nodeType":881},{},[51181,51185,51194],{"data":51182,"marks":51183,"value":51184,"nodeType":867},{},[],"In other cases, the bugs are serious enough and hard enough to patch that they’re worth noting as a technique. The recently disclosed (and perfectly named) ",{"data":51186,"content":51188,"nodeType":876},{"uri":51187},"https://www.descope.com/blog/post/noauth",[51189],{"data":51190,"marks":51191,"value":51193,"nodeType":867},{},[51192],{"type":1040},"nOAuth",{"data":51195,"marks":51196,"value":51197,"nodeType":867},{},[]," bug fits this bill. ",{"data":51199,"content":51200,"nodeType":881},{},[51201],{"data":51202,"marks":51203,"value":51204,"nodeType":867},{},[],"The bug arises from a confusion between an email identity and email metadata field in Microsoft integrations and without a central fix from MS (the fix isn’t trivial), these bugs are likely to be discovered and re-occur on third-party OAuth apps for a while to come.",{"data":51206,"content":51210,"nodeType":890},{"target":51207},{"sys":51208},{"id":51209,"type":887,"linkType":888},"6iKFd9Qys2SSuNqKVQB7ka",[],{"data":51212,"content":51213,"nodeType":918},{},[51214],{"data":51215,"marks":51216,"value":51217,"nodeType":867},{},[],"The SaaS market is driving these offensive techniques",{"data":51219,"content":51220,"nodeType":881},{},[51221],{"data":51222,"marks":51223,"value":51224,"nodeType":867},{},[],"SaaS apps are basically web apps that are run in the cloud and accessed from endpoints, so then WebApp, endpoint, and cloud security should cover all of SaaS, right? ",{"data":51226,"content":51227,"nodeType":881},{},[51228],{"data":51229,"marks":51230,"value":51231,"nodeType":867},{},[],"That was our assumption when we started, but what we found instead was that SaaS marketing practices are driving a lot of pretty interesting techniques that you don’t run into in standalone web apps.",{"data":51233,"content":51234,"nodeType":998},{},[51235],{"data":51236,"marks":51237,"value":51238,"nodeType":867},{},[],"Modern SaaS is easy to adopt, easy to use, low friction, low cost, low overhead",{"data":51240,"content":51241,"nodeType":881},{},[51242],{"data":51243,"marks":51244,"value":51245,"nodeType":867},{},[],"Making apps easy to sign up for and low effort to support means you need to make some interesting choices when it comes to designing account creation and recovery flows. ",{"data":51247,"content":51248,"nodeType":881},{},[51249],{"data":51250,"marks":51251,"value":51252,"nodeType":867},{},[],"Many apps allow users to sign into apps using multiple methods, easily invite collaborators (internal and external) and avoid any additional friction during the signup process. ",{"data":51254,"content":51255,"nodeType":881},{},[51256],{"data":51257,"marks":51258,"value":51259,"nodeType":867},{},[],"For example, many apps avoid verifying new account email addresses. This is not laziness, these are conscious design choices — not driven by security clearly, but not accidents.",{"data":51261,"content":51262,"nodeType":998},{},[51263],{"data":51264,"marks":51265,"value":51266,"nodeType":867},{},[],"Modern SaaS is highly integrated",{"data":51268,"content":51269,"nodeType":881},{},[51270],{"data":51271,"marks":51272,"value":51273,"nodeType":867},{},[],"Most SaaS apps are trying to build app marketplaces or perform well in other apps' marketplaces (often both), and it’s rare these days to find apps that don’t integrate with other apps. ",{"data":51275,"content":51276,"nodeType":881},{},[51277],{"data":51278,"marks":51279,"value":51280,"nodeType":867},{},[],"OAuth has become the de facto standard protocol for doing this, and most users have become quite used to approving OAuth2.0 consent flows. These integrations have opened up lots of incredibly useful doors for attackers to persist access and move laterally across SaaS apps that few incident response teams have run into yet. These tokens don’t expire when you reset passwords, aren’t protected by MFA, and actions they performed are rarely logged. ",{"data":51282,"content":51283,"nodeType":881},{},[51284],{"data":51285,"marks":51286,"value":51287,"nodeType":867},{},[],"These are not bugs or oversights but rather a consequence of how these APIs are intended to be used (by machines, not human adversaries).",{"data":51289,"content":51290,"nodeType":918},{},[51291],{"data":51292,"marks":51293,"value":51294,"nodeType":867},{},[],"Problems with observing SaaS attacks ",{"data":51296,"content":51297,"nodeType":881},{},[51298,51302,51307],{"data":51299,"marks":51300,"value":51301,"nodeType":867},{},[],"This research begs one question above others: ",{"data":51303,"marks":51304,"value":51306,"nodeType":867},{},[51305],{"type":1431},"“Are we seeing these attacks in the wild?",{"data":51308,"marks":51309,"value":51310,"nodeType":867},{},[],"” ",{"data":51312,"content":51313,"nodeType":998},{},[51314],{"data":51315,"marks":51316,"value":51317,"nodeType":867},{},[],"Yes, definitely",{"data":51319,"content":51320,"nodeType":881},{},[51321,51325,51334,51337,51346,51350,51359,51363,51371,51375,51384],{"data":51322,"marks":51323,"value":51324,"nodeType":867},{},[],"For some of the better-known techniques, like credential stuffing and email phishing, the answer is an easy yes. Stats from ",{"data":51326,"content":51328,"nodeType":876},{"uri":51327},"https://www.microsoft.com/en-us/security/blog/2023/05/04/how-microsoft-can-help-you-go-passwordless-this-world-password-day/",[51329],{"data":51330,"marks":51331,"value":51333,"nodeType":867},{},[51332],{"type":1040},"Microsoft (1,287 password attacks every second)",{"data":51335,"marks":51336,"value":2063,"nodeType":867},{},[],{"data":51338,"content":51340,"nodeType":876},{"uri":51339},"https://auth0.com/blog/top-insights-from-our-2022-state-of-secure-identity-report/",[51341],{"data":51342,"marks":51343,"value":51345,"nodeType":867},{},[51344],{"type":1040},"Auth0 (a third of their traffic is credential stuffing)",{"data":51347,"marks":51348,"value":51349,"nodeType":867},{},[]," speaks volumes. Other sources like the ",{"data":51351,"content":51353,"nodeType":876},{"uri":51352},"https://www.gov.uk/government/statistics/cyber-security-breaches-survey-2022/cyber-security-breaches-survey-2022",[51354],{"data":51355,"marks":51356,"value":51358,"nodeType":867},{},[51357],{"type":1040},"NCSC's Cyber Security Breaches Survey 2022",{"data":51360,"marks":51361,"value":51362,"nodeType":867},{},[]," and the ",{"data":51364,"content":51365,"nodeType":876},{"uri":15048},[51366],{"data":51367,"marks":51368,"value":51370,"nodeType":867},{},[51369],{"type":1040},"Verizon 2023 Data Breach Investigations Report",{"data":51372,"marks":51373,"value":51374,"nodeType":867},{},[]," suggest that phishing is also a major cause of SaaS breaches. Anecdotal reports from colleagues in the Incident Response field suggest that malicious mail forwarding rules are seen a lot, something which is supported by the ",{"data":51376,"content":51378,"nodeType":876},{"uri":51377},"https://expel.com/expel-quarterly-threat-report/",[51379],{"data":51380,"marks":51381,"value":51383,"nodeType":867},{},[51382],{"type":1040},"Expel Quarterly Threat Report for Q1 2023",{"data":51385,"marks":51386,"value":51387,"nodeType":867},{},[]," (see page 6).",{"data":51389,"content":51390,"nodeType":881},{},[51391],{"data":51392,"marks":51393,"value":51394,"nodeType":867},{},[],"The takeaway is that the current focus for defenders should be to ensure users have good phishing-resistant account security in place — make sure you have basics like strong unique passwords and MFA in place across your entire SaaS estate.",{"data":51396,"content":51397,"nodeType":998},{},[51398],{"data":51399,"marks":51400,"value":51401,"nodeType":867},{},[],"For newer OAuth attacks, it’s a lot less clear …",{"data":51403,"content":51404,"nodeType":881},{},[51405,51409,51414,51418,51427],{"data":51406,"marks":51407,"value":51408,"nodeType":867},{},[],"Other techniques like consent phishing have been discussed in some breach disclosures like the ",{"data":51410,"marks":51411,"value":51413,"nodeType":867},{},[51412],{"type":1040},"2020 SANS breach",{"data":51415,"marks":51416,"value":51417,"nodeType":867},{},[],". These OAuth techniques also pop up in the news (for example, the ",{"data":51419,"content":51421,"nodeType":876},{"uri":51420},"https://www.bleepingcomputer.com/news/security/github-how-stolen-oauth-tokens-helped-breach-dozens-of-orgs/",[51422],{"data":51423,"marks":51424,"value":51426,"nodeType":867},{},[51425],{"type":1040},"2022 Github/Heroku/Travis-CI breach",{"data":51428,"marks":51429,"value":51430,"nodeType":867},{},[]," where GitHub accounts were breached using stolen Heroku and Travis-CI OAuth tokens). ",{"data":51432,"content":51433,"nodeType":881},{},[51434,51438,51443],{"data":51435,"marks":51436,"value":51437,"nodeType":867},{},[],"That said, none of these techniques come up as frequently as their usefulness would suggest. This means one of two things: ",{"data":51439,"marks":51440,"value":51442,"nodeType":867},{},[51441],{"type":1431},"Either attackers aren’t yet using them widely, or they are and we aren’t detecting them",{"data":51444,"marks":51445,"value":1947,"nodeType":867},{},[],{"data":51447,"content":51448,"nodeType":881},{},[51449],{"data":51450,"marks":51451,"value":51452,"nodeType":867},{},[],"There is certainly a case to be made that attackers simply don’t need these newer techniques yet. Many organizations don’t have a way of discovering SaaS use in their organization yet, never mind breached accounts, so new persistence techniques might be a bit more than necessary at the moment.",{"data":51454,"content":51455,"nodeType":998},{},[51456],{"data":51457,"marks":51458,"value":51459,"nodeType":867},{},[],"But would we know if it was happening?",{"data":51461,"content":51462,"nodeType":881},{},[51463],{"data":51464,"marks":51465,"value":51466,"nodeType":867},{},[],"On the other hand, there is certainly the possibility that these attacks are increasingly used, but are simply not being discovered. A strong argument in favor of this view is the difficulty in investigating these attacks. Very few SaaS apps provide enough logging capability to discover these attacks as a customer. This is true even for the biggest, most mature apps like Office 365 and Google Workspace unless you are on top license tiers. This is doubly true for attacks that use OAuth, with many apps providing no insight or details into actions made using OAuth-authenticated APIs. ",{"data":51468,"content":51469,"nodeType":881},{},[51470,51474,51483,51487,51496],{"data":51471,"marks":51472,"value":51473,"nodeType":867},{},[],"This suggests only the SaaS providers for these apps are really in a position to discover and investigate them. This does ring true when you consider that ",{"data":51475,"content":51477,"nodeType":876},{"uri":51476},"https://blog.heroku.com/april-2022-incident-review",[51478],{"data":51479,"marks":51480,"value":51482,"nodeType":867},{},[51481],{"type":1040},"Heroku",{"data":51484,"marks":51485,"value":51486,"nodeType":867},{},[]," relied heavily on Github during the investigation (and in one case even the detection of) their 2022 breaches, and the same seems true for a similar breach affecting ",{"data":51488,"content":51490,"nodeType":876},{"uri":51489},"https://circleci.com/blog/jan-4-2023-incident-report/",[51491],{"data":51492,"marks":51493,"value":51495,"nodeType":867},{},[51494],{"type":1040},"CircleCI",{"data":51497,"marks":51498,"value":51499,"nodeType":867},{},[]," later that year. Github and CircleCI’s customers prompted the investigation after seeing strange behavior, but Github had access to the logs to investigate. It’s difficult to imagine that most or even many SaaS vendors have the resources or inclination to run these investigations effectively as GitHub appears to have.",{"data":51501,"content":51502,"nodeType":881},{},[51503,51507,51517],{"data":51504,"marks":51505,"value":51506,"nodeType":867},{},[],"So, are these attacks happening in the real world? My best guess is it’s a little bit of column A and a little bit of column B — there are likely not so many of these attacks happening yet, and when they do, I suspect the vast majority go undetected. ",{"data":51508,"content":51510,"nodeType":876},{"uri":51509},"https://www.youtube.com/watch?v=j95kNwZw8YY",[51511],{"data":51512,"marks":51513,"value":51516,"nodeType":867},{},[51514,51515],{"type":1040},{"type":1431},"But that’s just like my opinion, man.",{"data":51518,"marks":51519,"value":21,"nodeType":867},{},[],{"data":51521,"content":51522,"nodeType":881},{},[51523],{"data":51524,"marks":51525,"value":51526,"nodeType":867},{},[],"This is part of the reason we think enabling red teamers to try these techniques in anger is useful — this is the time-proven way to understand these risks.",{"data":51528,"content":51529,"nodeType":918},{},[51530],{"data":51531,"marks":51532,"value":51533,"nodeType":867},{},[],"What’s next?",{"data":51535,"content":51536,"nodeType":881},{},[51537],{"data":51538,"marks":51539,"value":51540,"nodeType":867},{},[],"We’ve barely scratched the surface, but perhaps there is enough here to get the discussion going. From past experience, discussion may not be enough, and it’s likely that live offensive work like penetration tests or more likely red team exercises will be required to make the risks of using these techniques real for the wider security community. ",{"data":51542,"content":51543,"nodeType":881},{},[51544],{"data":51545,"marks":51546,"value":51547,"nodeType":867},{},[],"After all, seeing is believing. We think some more practical examples and tools to help red  teamers use these techniques on engagements will help drive awareness forward, so we’ll be looking to build out this content.",{"data":51549,"content":51550,"nodeType":881},{},[51551,51555,51564],{"data":51552,"marks":51553,"value":51554,"nodeType":867},{},[],"We’ve started with pure networkless attacks that don’t touch customer networks or endpoints, but there are many useful techniques to connect the old endpoint world to the SaaS world. Consider stealing OAuth tokens from a thick client on an endpoint, or using a ",{"data":51556,"content":51558,"nodeType":876},{"uri":51557},"https://github.blog/2023-07-18-security-alert-social-engineering-campaign-targets-technology-industry-employees/",[51559],{"data":51560,"marks":51561,"value":51563,"nodeType":867},{},[51562],{"type":1040},"backdoored GitHub repo to get code execution on endpoints",{"data":51565,"marks":51566,"value":1947,"nodeType":867},{},[],{"data":51568,"content":51569,"nodeType":881},{},[51570,51574,51581],{"data":51571,"marks":51572,"value":51573,"nodeType":867},{},[],"Help us all better understand how widespread these attacks are by sharing some war stories. We’d love some comments, discussions, or PRs on ",{"data":51575,"content":51576,"nodeType":876},{"uri":3236},[51577],{"data":51578,"marks":51579,"value":3241,"nodeType":867},{},[51580],{"type":1040},{"data":51582,"marks":51583,"value":51584,"nodeType":867},{},[],"!",{"data":51586,"content":51590,"nodeType":890},{"target":51587},{"sys":51588},{"id":51589,"type":887,"linkType":888},"2y0INxqAi594O7rCAVKhTI",[],{"data":51592,"content":51593,"nodeType":881},{},[51594],{"data":51595,"marks":51596,"value":21,"nodeType":867},{},[],"Let’s talk about SaaS attack techniques","Offensive security drives defensive security. We're sharing a collection of SaaS attack techniques to help defenders understand the threats they face.","2023-07-27T00:00:00.000Z","saas-attack-techniques",{"items":51602},[51603,51605],{"sys":51604,"name":2547},{"id":2546},{"sys":51606,"name":342},{"id":2550},{"items":51608},[51609],{"fullName":51610,"firstName":51611,"jobTitle":51612,"profilePicture":51613},"Jacques Louw","Jacques","Co-founder / CRO",{"url":51614},"https://images.ctfassets.net/y1cdw1ablpvd/39m8bektV23lnCRcEq0G8h/2a08f6276a50744f1a4b499b273f6bb2/Push_Founders_at_Cahoots_October_28_2022_by_Doug_Coombe-21.jpg","identity-attacks-in-the-wild","blog/identity-attacks-in-the-wild",{"json":51618},{"data":51619,"content":51620,"nodeType":1640},{},[51621],{"data":51622,"content":51623,"nodeType":881},{},[51624,51628],{"data":51625,"marks":51626,"value":51627,"nodeType":867},{},[],"To help organizations keep track of how browser-based identity attacks are evolving, we've put together this index of recent breaches",{"data":51629,"marks":51630,"value":51631,"nodeType":867},{},[],". In particular we’re focused on tracking attacks in the public domain that demonstrate the very latest techniques being used in the wild, such as those targeting identity infrastructure itself. ","To help organizations keep track of how browser-based identity attacks are evolving, we've put together this index of recent breaches.",{"id":51634,"publishedAt":51635},"6XIts2UEnrsJDki8gKDXyI","2026-08-12T11:55:31.114Z",{"items":51637},[51638,51640],{"sys":51639,"name":2547},{"id":2546},{"sys":51641,"name":342},{"id":2550},{"items":51643},[51644,51646,51648,51650,51652,51654,51656,51658,51660,51662,51664,51666,51668,51670,51672,51674,51676,51678,51680,51682],{"sys":51645,"name":279,"slug":280,"tier":31},{"id":276},{"sys":51647,"name":413,"slug":414,"tier":31},{"id":410},{"sys":51649,"name":642,"slug":643,"tier":31},{"id":639},{"sys":51651,"name":519,"slug":520,"tier":31},{"id":516},{"sys":51653,"name":545,"slug":546,"tier":31},{"id":542},{"sys":51655,"name":342,"slug":343,"tier":31},{"id":339},{"sys":51657,"name":404,"slug":405,"tier":45},{"id":401},{"sys":51659,"name":528,"slug":529,"tier":45},{"id":525},{"sys":51661,"name":333,"slug":334,"tier":45},{"id":330},{"sys":51663,"name":422,"slug":423,"tier":45},{"id":419},{"sys":51665,"name":395,"slug":396,"tier":45},{"id":392},{"sys":51667,"name":571,"slug":572,"tier":45},{"id":568},{"sys":51669,"name":484,"slug":485,"tier":45},{"id":481},{"sys":51671,"name":466,"slug":467,"tier":45},{"id":463},{"sys":51673,"name":607,"slug":608,"tier":45},{"id":604},{"sys":51675,"name":261,"slug":262,"tier":45},{"id":258},{"sys":51677,"name":650,"slug":651,"tier":45},{"id":647},{"sys":51679,"name":537,"slug":538,"tier":45},{"id":534},{"sys":51681,"name":457,"slug":458,"tier":45},{"id":454},{"sys":51683,"name":633,"slug":634,"tier":45},{"id":630},"c-hSrKEun_EGXMqcYVqzCOnSLH9sxoS6TEl8VMIrNjA",1787040122696]