[{"data":1,"prerenderedAt":2312},["ShallowReactive",2],{"application-flags":3,"navbar":7,"always-visible-banner":36,"navbar-about-highlight":99,"navbar-resource-highlight":173,"trust-badges":217,"solution-nav":238,"fa-icon-sharp-regular-faFishingRod":378,"fa-icon-solid-faUserSecret":382,"fa-icon-sharp-regular-faLaptopCode":384,"fa-icon-solid-faTabletScreenButton":386,"fa-icon-solid-faThumbsUp":388,"fa-icon-solid-faPlugCircleXmark":390,"fa-icon-sharp-regular-faPuzzlePiece":392,"fa-icon-solid-faFileCircleXmark":394,"fa-icon-solid-faGhost":397,"fa-icon-solid-faQrcode":400,"fa-icon-solid-faCookieBite":402,"fa-icon-sharp-regular-faUserSecret":404,"fa-icon-sharp-regular-faRadar":406,"fa-icon-sharp-regular-faSatelliteDish":408,"fa-icon-sharp-regular-faShieldCheck":410,"fa-icon-sharp-regular-faBrainCircuit":412,"fa-icon-solid-faMobileScreenButton":414,"fa-icon-brands-faChrome":416,"fa-icon-solid-faDisplay":418,"fa-icon-solid-faFilter":420,"fa-icon-solid-faCloudArrowUp":422,"browser-attacks":424,"fa-icon-regular-faArrowRightArrowLeft":1149,"fa-icon-regular-faInputNumeric":1151,"fa-icon-regular-faWindowRestore":1153,"fa-icon-regular-faUserCheck":1155,"fa-icon-regular-faMessage":1157,"fa-icon-regular-faPuzzlePiece":1159,"fa-icon-regular-faMegaphone":1161,"fa-icon-regular-faDownload":1163,"fa-icon-regular-faClipboardCheck":1165,"fa-icon-regular-faArrowPointer":1167,"fa-icon-regular-faCookieBite":1169,"fa-icon-regular-faKey":1171,"breach-technique":1173,"breach-month":1279,"breach-campaign":2124},[4],{"name":5,"enabled":6},"maintenanceMode",false,[8],{"createdDate":9,"id":10,"name":11,"modelId":12,"published":13,"meta":14,"query":22,"data":23,"variations":28,"lastUpdated":29,"firstPublished":30,"testRatio":31,"createdBy":32,"lastUpdatedBy":33,"folders":34,"rev":35},1742208588866,"1c7a4e423bf54ac1a328bb4063459ef2","Banner","1c6207a5f24948ab82d4a0b17f251193","published",{"breakpoints":15,"hasAutosaves":19,"kind":20,"lastPreviewUrl":21},{"medium":16,"small":17,"xsmall":18},768,640,320,true,"data","",[],{"link":24,"text":25,"type":26,"url":27},{},"Get our latest report analyzing browser attack techniques in 2026","web-banner","https:\u002F\u002Fpushsecurity.com\u002Fresources\u002Fbrowser-attacks-report",{},1774258294825,1742208637545,1,"CydmZnOWU1XuAaLhEDCoYNM4Z8W2","jKjF9r5jcvXU8tzZEfFQm31Iyvr2",[],"y84t8vdyew",{"createdBy":37,"createdDate":38,"data":39,"folders":86,"id":87,"lastUpdated":88,"lastUpdatedBy":37,"meta":89,"modelId":93,"name":94,"published":13,"query":95,"testRatio":31,"variations":96,"firstPublished":97,"stageModifiedSincePublish":6,"lastUpdateSource":60,"rev":98},"ST0tXQM8slWpFrmioqKHmENB2qe2",1774965361051,{"ctaText":40,"text":41,"url":21,"blocks":42,"state":82},"ewrererw","testrfesssssssssss",[43,71],{"@type":44,"@version":45,"id":46,"component":47,"responsiveStyles":61},"@builder.io\u002Fsdk:Element",2,"builder-ca12c06a52de41d7b8743da53118cd38",{"name":48,"tag":48,"options":49,"isRSC":60},"TopBannerContent",{"text":50,"ctaText":51,"url":52,"mainText":53,"cta":56,"styleVariant":59,"showMonsters":19},"New Webinar Series: Join John Hammond, Troy Hunt, and Matt Johansen for the State of Browser Attacks","Save Your Spot","https:\u002F\u002Fpushsecurity.com\u002Fwebinar\u002Fstate-of-browser-security",{"content":54,"fontSize":55},"\u003Cp class=\"\">Shadow AI monsters are lurking in the dark! Bust them all in our retro-inspired arcade game.\u003C\u002Fp>","text-base",{"content":57,"fontSize":55,"url":58},"\u003Cp class=\"\">Press start &gt;&gt;\u003C\u002Fp>","https:\u002F\u002Fpushsecurity.com\u002Flp\u002Fshadow-ai-busters","arcade",null,{"large":62},{"display":63,"flexDirection":64,"position":65,"flexShrink":66,"boxSizing":67,"marginTop":68,"marginBottom":68,"fontSize":69,"fontWeight":70},"flex","column","relative","0","border-box",".56rem","1.125rem","700",{"id":72,"@type":44,"tagName":73,"properties":74,"responsiveStyles":77},"builder-pixel-ws0avkvus4m","img",{"src":75,"aria-hidden":76,"alt":21,"width":66,"height":66},"https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fpixel?apiKey=f3a1111ff5be48cdbb123cd9f5795a05","true",{"large":78},{"height":66,"width":66,"display":79,"opacity":66,"overflow":80,"pointerEvents":81},"block","hidden","none",{"deviceSize":83,"location":84},"large",{"path":21,"query":85},{},[],"fd266d0172cc47429be7ad10f48c99ad",1789552629325,{"breakpoints":90,"hasAutosaves":19,"hasErrors":6,"hasLinks":6,"kind":91,"lastPreviewUrl":92},{"medium":16,"small":17,"xsmall":18},"component","https:\u002F\u002Fsite.dev.pushsecurity.com\u002F?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2Cadmin%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests%2CmergePullRequests%2CfusionHostingPublish%2CfusionHostingRevokeAiToken&builder.user.role.name=Admin&builder.user.role.id=admin&builder.cachebust=true&builder.preview=always-visible-banner&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.always-visible-banner=fd266d0172cc47429be7ad10f48c99ad&builder.overrides.fd266d0172cc47429be7ad10f48c99ad=fd266d0172cc47429be7ad10f48c99ad&builder.options.locale=Default","0678d178ec8b41efb8a23c09dba7874d","always visible banner",[],{},1774968080803,"hrlckazo2uk",[100,136],{"createdBy":32,"createdDate":101,"data":102,"folders":125,"id":126,"lastUpdated":127,"lastUpdatedBy":32,"meta":128,"modelId":130,"name":131,"published":13,"query":132,"stageModifiedSincePublish":6,"testRatio":31,"variations":133,"firstPublished":134,"rev":135},1776247359804,{"link":103,"testimonial":104,"testimonialLink":124,"type":107},{},{"@type":105,"id":106,"model":107,"value":108},"@builder.io\u002Fcore:Reference","f028f2b685bb47cd8bf9e82a26dd5a79","testimonial",{"query":109,"folders":110,"createdDate":111,"id":106,"name":112,"modelId":113,"published":13,"data":114,"variations":118,"lastUpdated":119,"firstPublished":120,"testRatio":31,"createdBy":37,"lastUpdatedBy":37,"meta":121,"rev":123},[],[],1735823466309,"We found Push to be more accurate when compared to competitors and the browser agent offered features that others couldn’t match.","42035571a56940ac98bff4544aa79aa5",{"author":115,"jobTitle":116,"quote":112,"image":117},"Jason Waits","\u003Cp>CISO at Inductive Automation\u003C\u002Fp>","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Ff04c0c0689ce4a89ac0f0708d78c0a07",{},1735910703862,1735823501152,{"kind":20,"lastPreviewUrl":21,"breakpoints":122,"hasAutosaves":19},{"small":17,"medium":16},"ejt44b3n716","\u002Fcustomer-stories\u002Finductive-automation",[],"9136a8f18b3b4a6ba29b8653a99372b1",1776247404986,{"breakpoints":129,"hasAutosaves":6,"kind":20,"lastPreviewUrl":21},{"medium":16,"small":17,"xsmall":18},"20d9eaa352304613b3d1a794b400703d","testimonial-inductive-automation",[],{},1776247404973,"c0e0c6itmu",{"createdBy":32,"createdDate":137,"data":138,"folders":165,"id":166,"lastUpdated":167,"lastUpdatedBy":32,"meta":168,"modelId":130,"name":163,"published":13,"query":170,"stageModifiedSincePublish":6,"testRatio":31,"variations":171,"firstPublished":172,"rev":135},1776255761419,{"description":139,"image":140,"link":141,"testimonial":144,"title":163,"type":164},"Learn about the latest techniques being used in the wild.","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F7b4a5ebf81d64e8c9d7fc35f6c96c4a9",{"text":142,"url":143},"Download now","\u002Fresources\u002Fbrowser-attacks-report",{"@type":105,"id":145,"model":107,"value":146},"192acbb1f9ca4cac918c0ec435a8bae3",{"query":147,"folders":148,"createdDate":149,"id":145,"name":150,"modelId":113,"published":13,"data":151,"variations":157,"lastUpdated":158,"firstPublished":159,"testRatio":31,"createdBy":37,"lastUpdatedBy":32,"meta":160,"rev":162},[],[],1728981467463,"Push does for identity what CrowdStrike did for the endpoint",{"video":152,"jobTitle":153,"author":154,"qoute":21,"quote":155,"image":156},"https:\u002F\u002Fcdn.builder.io\u002Fo\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F8b30e8ca50064058bbaef0f3c6164575%2Fcompressed?apiKey=f3a1111ff5be48cdbb123cd9f5795a05&token=8b30e8ca50064058bbaef0f3c6164575&alt=media&optimized=true","\u003Cp>Deputy CISO at Microsoft\u003C\u002Fp>\u003Cp>Former LinkedIn, Slack, Palantir\u003C\u002Fp>","Geoff Belknap","Push does for identity what CrowdStrike did for the endpoint.","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F748f0ad0a5064a00a13f4721fcc8dea1",{},1742902158597,1728981782923,{"kind":20,"lastPreviewUrl":21,"breakpoints":161,"hasAutosaves":19},{"small":17,"medium":16},"kxj3j9ybvds","Report: 2026 Browser Attack Techniques","resource",[],"05a9322735fc427db12e2740e4302300",1776255810913,{"breakpoints":169,"hasAutosaves":6,"kind":20,"lastPreviewUrl":21},{"medium":16,"small":17,"xsmall":18},[],{},1776255810900,[174,196],{"createdBy":32,"createdDate":175,"data":176,"folders":186,"id":187,"lastUpdated":188,"lastUpdatedBy":32,"meta":189,"modelId":191,"name":163,"published":13,"query":192,"stageModifiedSincePublish":6,"testRatio":31,"variations":193,"firstPublished":194,"rev":195},1776256900280,{"description":139,"image":140,"link":177,"testimonial":178,"title":163,"type":164},{"text":142,"url":143},{"@type":105,"id":145,"model":107,"value":179},{"query":180,"folders":181,"createdDate":149,"id":145,"name":150,"modelId":113,"published":13,"data":182,"variations":183,"lastUpdated":158,"firstPublished":159,"testRatio":31,"createdBy":37,"lastUpdatedBy":32,"meta":184,"rev":162},[],[],{"video":152,"jobTitle":153,"author":154,"qoute":21,"quote":155,"image":156},{},{"kind":20,"lastPreviewUrl":21,"breakpoints":185,"hasAutosaves":19},{"small":17,"medium":16},[],"1f429607996e4e5fae8fe3f9b9610e55",1776256937553,{"breakpoints":190,"hasAutosaves":6,"kind":20,"lastPreviewUrl":21},{"medium":16,"small":17,"xsmall":18},"4829faa81e7c4ee8bd2d000e160e8d3c",[],{},1776256937540,"dv7taxcdgne",{"createdBy":32,"createdDate":197,"data":198,"folders":208,"id":209,"lastUpdated":210,"lastUpdatedBy":32,"meta":211,"modelId":191,"name":213,"published":13,"query":214,"stageModifiedSincePublish":6,"testRatio":31,"variations":215,"firstPublished":216,"rev":195},1776256949234,{"link":199,"testimonial":200,"testimonialLink":124,"type":107},{},{"@type":105,"id":106,"model":107,"value":201},{"query":202,"folders":203,"createdDate":111,"id":106,"name":112,"modelId":113,"published":13,"data":204,"variations":205,"lastUpdated":119,"firstPublished":120,"testRatio":31,"createdBy":37,"lastUpdatedBy":37,"meta":206,"rev":123},[],[],{"author":115,"jobTitle":116,"quote":112,"image":117},{},{"kind":20,"lastPreviewUrl":21,"breakpoints":207,"hasAutosaves":19},{"small":17,"medium":16},[],"ce043785b71b4ece98eac811ecf4ba10",1776256974140,{"breakpoints":212,"hasAutosaves":6,"kind":20,"lastPreviewUrl":21},{"medium":16,"small":17,"xsmall":18},"inductive-automation",[],{},1776256974130,[218,222,226,230,234],{"title":219,"logo":220,"createdDate":221},"SOC2","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fb6727a5e00004d6e9e69fc3068b8b64c",1784291539953,{"title":223,"logo":224,"createdDate":225},"GDPR","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Ffe49f53211674deaa5a6640d929cdf42?format=webp",1784291672535,{"title":227,"logo":228,"createdDate":229},"Cyber essentials","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F53558c1045a342a7a28def960cd54ae7?format=webp",1784291702710,{"title":231,"logo":232,"createdDate":233},"ISO IEC 27001","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F578a404a61cf45db951a41fe3554d12d",1784291766222,{"title":235,"logo":236,"createdDate":237},"ISO IEC 27701","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fbe219844b13242fbba531959579a753c",1784291858848,[239,308,353],{"id":240,"label":241,"text":21,"navIcon":242,"items":243},"stop-browser-based-attacks","Stop browser-based attacks","solid:faShieldHalved",[244,249,254,259,264,269,274,279,284,288,293,298,303],{"title":245,"text":246,"url":247,"navIcon":248},"Phishing","Detect phishing behaviorally in the browser, regardless of the payload or delivery channel.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fzero-day-phishing","sharp-regular:faFishingRod",{"title":250,"text":251,"url":252,"navIcon":253},"Adversary-in-the-Middle","Detect and block MFA-bypassing AiTM phishing pages in real-time.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fadversary-in-the-middle-attacks","solid:faUserSecret",{"title":255,"text":256,"url":257,"navIcon":258},"ClickFix (and variants)","Intercept malicious copy and paste attacks at the point of interaction.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fclickfix-fix-variants","sharp-regular:faLaptopCode",{"title":260,"text":261,"url":262,"navIcon":263},"Device code phishing","Detect and block device code phishing kits designed to get around passkeys.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fdevice-code-phishing","solid:faTabletScreenButton",{"title":265,"text":266,"url":267,"navIcon":268},"Consent phishing","Detect and block malicious OAuth consent grants before access is authorized.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fconsent-phishing","solid:faThumbsUp",{"title":270,"text":271,"url":272,"navIcon":273},"Malicious OAuth integrations","Detect and block the root cause of SaaS supply chain attacks.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fmalicious-oauth-integrations","solid:faPlugCircleXmark",{"title":275,"text":276,"url":277,"navIcon":278},"Malicious browser extensions","Inventory, monitor, and block risky browser extensions.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fmalicious-browser-extensions","sharp-regular:faPuzzlePiece",{"title":280,"text":281,"url":282,"navIcon":283},"Malicious file downloads","Control which files users can download by type, source, and user group.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fmalicious-file-downloads","solid:faFileCircleXmark",{"title":285,"text":286,"url":287,"navIcon":283},"Infostealers","Detect infostealer delivery and respond to a compromise.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Finfostealer-malware",{"title":289,"text":290,"url":291,"navIcon":292},"Ghost logins","Surface hidden login paths that bypass SSO and expose accounts.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fghost-logins","solid:faGhost",{"title":294,"text":295,"url":296,"navIcon":297},"Mobile phishing (QR & SMS)","Detect phishing regardless of whether it arrives via email, SMS, or QR code.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fmobile-phishing-qr-code-sms","solid:faQrcode",{"title":299,"text":300,"url":301,"navIcon":302},"Credential stuffing","Identify reused and compromised credentials across SaaS logins.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fcredential-stuffing","custom:credentialStuffing",{"title":304,"text":305,"url":306,"navIcon":307},"Session hijacking","Detect and respond to stolen session token replay with browser session markers.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fsession-hijacking","solid:faCookieBite",{"id":309,"label":310,"text":21,"navIcon":311,"items":312},"achieve-security-outcomes","Achieve security outcomes","solid:faCheckToSlot",[313,318,323,328,333,338,343,348],{"title":314,"text":315,"url":316,"navIcon":317},"Stop account takeover","Stop ATO with stolen credential and compromised token detection.","\u002Fsolution\u002Fachieve-security-outcomes\u002Fstop-account-takeover","sharp-regular:faUserSecret",{"title":319,"text":320,"url":321,"navIcon":322},"Harden unmanaged identities","Harden access paths with visibility, detection, and guardrails.","\u002Fsolution\u002Fachieve-security-outcomes\u002Fharden-unmanaged-identities","sharp-regular:faRadar",{"title":324,"text":325,"url":326,"navIcon":327},"Investigate browser-related incidents","Investigate and respond faster with unique browser telemetry.","\u002Fsolution\u002Fachieve-security-outcomes\u002Finvestigate-browser-related-incidents","sharp-regular:faSatelliteDish",{"title":329,"text":330,"url":331,"navIcon":332},"Secure shadow IT","See and control shadow SaaS in the browser.","\u002Fsolution\u002Fachieve-security-outcomes\u002Fsecure-shadow-saas","sharp-regular:faShieldCheck",{"title":334,"text":335,"url":336,"navIcon":337},"Secure AI","See and control AI apps in the browser.","\u002Fsolution\u002Fachieve-security-outcomes\u002Fsecure-ai","sharp-regular:faBrainCircuit",{"title":339,"text":340,"url":341,"navIcon":342},"Secure BYOD","Extend security to unmanaged devices without MDM.","\u002Fsolution\u002Fachieve-security-outcomes\u002Fsecure-bring-your-own-device","solid:faMobileScreenButton",{"title":344,"text":345,"url":346,"navIcon":347},"Secure Chromebooks","Secure Chromebooks in the enterprise without endpoint agents. Push deploys as a browser extension — phishing detection, credential monitoring, and SaaS visibility via browser extension that works with Chrome OS.","\u002Fsolution\u002Fachieve-security-outcomes\u002Fsecure-chromebooks","brands:faChrome",{"title":349,"text":350,"url":351,"navIcon":352},"Data loss prevention","Enforce DLP at the point of interaction in the browser","\u002Fsolution\u002Fachieve-security-outcomes\u002Finvestigate-and-stop-data-loss","custom:investigateAndStopDataLoss",{"id":354,"label":355,"text":21,"navIcon":356,"items":357},"tool-replacements","Tool replacements","solid:faScrewdriverWrench",[358,363,368,373],{"title":359,"text":360,"url":361,"navIcon":362},"Remote browser isolation","Detect attacks that look like normal browsing.","\u002Fsolution\u002Ftool-replacements\u002Fremote-browser-isolation","solid:faDisplay",{"title":364,"text":365,"url":366,"navIcon":367},"Secure web gateways","Detect attacks inside the browser after SWGs allowed the connection.","\u002Fsolution\u002Ftool-replacements\u002Fsecure-web-gateways","solid:faFilter",{"title":369,"text":370,"url":371,"navIcon":372},"Cloud access security broker","Catch browser-based identity threats in real time, not after the fact.","\u002Fsolution\u002Ftool-replacements\u002Fcloud-access-security-broker","solid:faCloudArrowUp",{"title":374,"text":375,"url":376,"navIcon":377},"Security awareness training","Block real phishing instead of training users on simulations.","\u002Fsolution\u002Ftool-replacements\u002Fsecurity-awareness-training","custom:securityAwareness",{"w":379,"h":380,"d":381},448,512,"M284.6 0l91.4 0 0 160-48 0 0-112-36.6 0-203.4 58.1 0 181.9 40 0 0 224-128 0 0-224 40 0 0-218.1 17.4-5 224-64 3.2-.9zM80 336l-32 0 0 128 32 0 0-128zm176 8c0-76.8 64-136 96-152 32 16 96 75.2 96 152 0 32-16 80-64 112l32 40 0 16-128 0 0-16 32-40c-48-32-64-80-64-112zm128-32a24 24 0 1 0 -48 0 24 24 0 1 0 48 0z",{"w":379,"h":380,"d":383},"M171-16c-36.4 0-57.8 58.3-68.3 112L72 96c-13.3 0-24 10.7-24 24s10.7 24 24 24l24 0 0 32c0 17 3.3 33.2 9.3 48l-9.3 0 0 0-20.5 0c-15.2 0-27.5 12.3-27.5 27.5 0 3 .5 5.9 1.4 8.7l28.9 86.6C40.2 379.6 16 428.1 16 482.3 16 498.7 29.3 512 45.7 512l356.6 0c16.4 0 29.7-13.3 29.7-29.7 0-54.2-24.2-102.7-62.3-135.4l28.9-86.6c.9-2.8 1.4-5.7 1.4-8.7 0-15.2-12.3-27.5-27.5-27.5l-20.5 0 0 0-9.3 0c6-14.8 9.3-31 9.3-48l0-32 24 0c13.3 0 24-10.7 24-24s-10.7-24-24-24l-30.7 0c-10.4-53.7-31.9-112-68.3-112-9.6 0-19 3.9-27.5 8.2-8.2 4.1-18.4 7.8-25.5 7.8s-17.3-3.7-25.5-7.8C190-12.1 180.6-16 171-16zm93.7 484.4l-24.8-70.9 27.9-32.5c2.7-3.2 4.2-7.2 4.2-11.4 0-9.7-7.8-17.5-17.5-17.5l-61 0c-9.7 0-17.5 7.8-17.5 17.5 0 4.2 1.5 8.2 4.2 11.4l27.9 32.5-24.8 70.9-57-180.4 35.7 0c18.4 10.2 39.5 16 62 16s43.6-5.8 62-16l35.7 0-57 180.4zM224 256c-34.7 0-64.2-22.1-75.3-53 5.7 3.2 12.3 5 19.3 5l12.4 0c16.5 0 31.1-10.6 36.3-26.2 2.3-7 12.2-7 14.5 0 5.2 15.6 19.9 26.2 36.3 26.2l12.4 0c7 0 13.6-1.8 19.3-5-11.1 30.9-40.6 53-75.3 53z",{"w":17,"h":380,"d":385},"M112 80l416 0 0 224 48 0 0-272-512 0 0 272 48 0 0-224zM48 404.1l0-4.1 544 0 0 4.1-27.9 27.9-488.2 0-27.9-27.9zM592 352l-592 0 0 72 56 56 528 0 56-56 0-72-48 0zM281 169l17-17-33.9-33.9c-6.1 6.1-27.8 27.8-65 65l-17 17c6.1 6.1 27.8 27.8 65 65l17 17 33.9-33.9c-9-9-25-25-48-48l31-31zM393 135l-17-17-33.9 33.9c9 9 25 25 48 48-23 23-39 39-48 48L376 281.9c6.1-6.1 27.8-27.8 65-65l17-17c-6.1-6.1-27.8-27.8-65-65z",{"w":379,"h":380,"d":387},"M0 64C0 28.7 28.7 0 64 0L384 0c35.3 0 64 28.7 64 64l0 384c0 35.3-28.7 64-64 64L64 512c-35.3 0-64-28.7-64-64L0 64zM256 432a32 32 0 1 0 -64 0 32 32 0 1 0 64 0zM384 64l-320 0 0 288 320 0 0-288z",{"w":380,"h":380,"d":389},"M80 160c17.7 0 32 14.3 32 32l0 256c0 17.7-14.3 32-32 32l-48 0c-17.7 0-32-14.3-32-32L0 192c0-17.7 14.3-32 32-32l48 0zM270.6 16C297.9 16 320 38.1 320 65.4l0 4.2c0 6.8-1.3 13.6-3.8 19.9L288 160 448 160c26.5 0 48 21.5 48 48 0 19.7-11.9 36.6-28.9 44 17 7.4 28.9 24.3 28.9 44 0 23.4-16.8 42.9-39 47.1 4.4 7.3 7 15.8 7 24.9 0 22.2-15 40.8-35.4 46.3 2.2 5.5 3.4 11.5 3.4 17.7 0 26.5-21.5 48-48 48l-87.9 0c-36.3 0-71.6-12.4-99.9-35.1L184 435.2c-15.2-12.1-24-30.5-24-50l0-186.6c0-14.9 3.5-29.6 10.1-42.9L226.3 43.3C234.7 26.6 251.8 16 270.6 16z",{"w":17,"h":380,"d":391},"M192-32c17.7 0 32 14.3 32 32l0 96 128 0 0-96c0-17.7 14.3-32 32-32s32 14.3 32 32l0 96 64 0c17.7 0 32 14.3 32 32s-14.3 32-32 32l0 48.7c-98.6 8.1-176 90.7-176 191.3 0 27.3 5.7 53.3 16 76.9l0 3.1c0 17.7-14.3 32-32 32s-32-14.3-32-32l0-66.7C165.2 398.1 96 319.1 96 224l0-64c-17.7 0-32-14.3-32-32S78.3 96 96 96l64 0 0-96c0-17.7 14.3-32 32-32zM496 256a144 144 0 1 1 0 288 144 144 0 1 1 0-288zm59.3 107.3c6.2-6.2 6.2-16.4 0-22.6s-16.4-6.2-22.6 0l-36.7 36.7-36.7-36.7c-6.2-6.2-16.4-6.2-22.6 0s-6.2 16.4 0 22.6l36.7 36.7-36.7 36.7c-6.2 6.2-6.2 16.4 0 22.6s16.4 6.2 22.6 0l36.7-36.7 36.7 36.7c6.2 6.2 16.4 6.2 22.6 0s6.2-16.4 0-22.6l-36.7-36.7 36.7-36.7z",{"w":380,"h":380,"d":393},"M201.1 57.3c-7 5.3-9.1 10.7-9.1 14.7 0 4.5 2.8 11.2 12.4 16.9l11.6 7 0 48.1-168 0 0 60.5c7.4-2.9 15.5-4.5 24-4.5 43.1 0 72 39.4 72 80s-28.9 80-72 80c-8.5 0-16.6-1.6-24-4.5l0 108.5 108.5 0c-2.9-7.4-4.5-15.5-4.5-24 0-43.1 39.4-72 80-72s80 28.9 80 72c0 8.5-1.6 16.6-4.5 24l60.5 0 0-168 48.1 0 7 11.6c5.8 9.6 12.4 12.4 16.9 12.4 4 0 9.5-2.1 14.7-9.1s9.3-17.9 9.3-30.9-4-23.8-9.3-30.9-10.7-9.1-14.7-9.1c-4.5 0-11.2 2.8-16.9 12.4l-7 11.6-48.1 0 0-120-120 0 0-48.1 11.6-7c9.6-5.8 12.4-12.4 12.4-16.9 0-4-2.1-9.5-9.1-14.7S245 48 232 48 208.2 52 201.1 57.3zM172.3 18.9C188.5 6.8 209.6 0 232 0S275.5 6.8 291.7 18.9 320 49.5 320 72c0 8.6-1.8 16.7-4.9 24l100.9 0 0 100.9c7.3-3.1 15.4-4.9 24-4.9 22.5 0 41 12.2 53.1 28.3s18.9 37.3 18.9 59.7-6.8 43.5-18.9 59.7-30.6 28.3-53.1 28.3c-8.6 0-16.7-1.8-24-4.9l0 148.9-168 0 0-49.3 8.2-7.2c5.4-4.7 7.8-10.3 7.8-15.5 0-9.9-10.7-24-32-24s-32 14.1-32 24c0 5.3 2.4 10.8 7.8 15.5l8.2 7.2 0 49.3-216 0 0-216 49.3 0 7.2 8.2c4.7 5.4 10.3 7.8 15.5 7.8 9.9 0 24-10.7 24-32s-14.1-32-24-32c-5.3 0-10.8 2.4-15.5 7.8L49.3 264 0 264 0 96 148.9 96c-3.1-7.3-4.9-15.4-4.9-24 0-22.5 12.2-41 28.3-53.1z",{"w":395,"h":380,"d":396},576,"M96 0C60.7 0 32 28.7 32 64l0 384c0 35.3 28.7 64 64 64l180 0c-22.7-31.5-36-70.2-36-112 0-100.6 77.4-183.2 176-191.3l0-38.1c0-17-6.7-33.3-18.7-45.3L290.7 18.7C278.7 6.7 262.5 0 245.5 0L96 0zM357.5 176L264 176c-13.3 0-24-10.7-24-24L240 58.5 357.5 176zM432 544a144 144 0 1 0 0-288 144 144 0 1 0 0 288zm59.3-180.7l-36.7 36.7 36.7 36.7c6.2 6.2 6.2 16.4 0 22.6s-16.4 6.2-22.6 0l-36.7-36.7-36.7 36.7c-6.2 6.2-16.4 6.2-22.6 0s-6.2-16.4 0-22.6l36.7-36.7-36.7-36.7c-6.2-6.2-6.2-16.4 0-22.6s16.4-6.2 22.6 0l36.7 36.7 36.7-36.7c6.2-6.2 16.4-6.2 22.6 0s6.2 16.4 0 22.6z",{"w":398,"h":380,"d":399},384,"M40.1 467.1l-11.2 9C25.7 478.6 21.8 480 17.8 480 8 480 0 472 0 462.2L0 192C0 86 86 0 192 0S384 86 384 192l0 270.2c0 9.8-8 17.8-17.8 17.8-4 0-7.9-1.4-11.1-3.9l-11.2-9c-13.4-10.7-32.8-9-44.1 3.9L269.3 506c-3.3 3.8-8.2 6-13.3 6s-9.9-2.2-13.3-6l-26.6-30.5c-12.7-14.6-35.4-14.6-48.2 0L141.3 506c-3.3 3.8-8.2 6-13.3 6s-9.9-2.2-13.3-6L84.2 471c-11.3-12.9-30.7-14.6-44.1-3.9zM160 192a32 32 0 1 0 -64 0 32 32 0 1 0 64 0zm96 32a32 32 0 1 0 0-64 32 32 0 1 0 0 64z",{"w":379,"h":380,"d":401},"M64 160l64 0 0-64-64 0 0 64zM0 80C0 53.5 21.5 32 48 32l96 0c26.5 0 48 21.5 48 48l0 96c0 26.5-21.5 48-48 48l-96 0c-26.5 0-48-21.5-48-48L0 80zM64 416l64 0 0-64-64 0 0 64zM0 336c0-26.5 21.5-48 48-48l96 0c26.5 0 48 21.5 48 48l0 96c0 26.5-21.5 48-48 48l-96 0c-26.5 0-48-21.5-48-48l0-96zM320 96l0 64 64 0 0-64-64 0zM304 32l96 0c26.5 0 48 21.5 48 48l0 96c0 26.5-21.5 48-48 48l-96 0c-26.5 0-48-21.5-48-48l0-96c0-26.5 21.5-48 48-48zM288 352a32 32 0 1 1 0-64 32 32 0 1 1 0 64zm0 64c17.7 0 32 14.3 32 32s-14.3 32-32 32-32-14.3-32-32 14.3-32 32-32zm96 32c0-17.7 14.3-32 32-32s32 14.3 32 32-14.3 32-32 32-32-14.3-32-32zm32-96a32 32 0 1 1 0-64 32 32 0 1 1 0 64zm-32 32a32 32 0 1 1 -64 0 32 32 0 1 1 64 0z",{"w":380,"h":380,"d":403},"M257.5 27.6c-.8-5.4-4.9-9.8-10.3-10.6-22.1-3.1-44.6 .9-64.4 11.4l-74 39.5C89.1 78.4 73.2 94.9 63.4 115L26.7 190.6c-9.8 20.1-13 42.9-9.1 64.9l14.5 82.8c3.9 22.1 14.6 42.3 30.7 57.9l60.3 58.4c16.1 15.6 36.6 25.6 58.7 28.7l83 11.7c22.1 3.1 44.6-.9 64.4-11.4l74-39.5c19.7-10.5 35.6-27 45.4-47.2l36.7-75.5c9.8-20.1 13-42.9 9.1-64.9-.9-5.3-5.3-9.3-10.6-10.1-51.5-8.2-92.8-47.1-104.5-97.4-1.8-7.6-8-13.4-15.7-14.6-54.6-8.7-97.7-52-106.2-106.8zM208 144a32 32 0 1 1 0 64 32 32 0 1 1 0-64zM144 336a32 32 0 1 1 64 0 32 32 0 1 1 -64 0zm224-64a32 32 0 1 1 0 64 32 32 0 1 1 0-64z",{"w":379,"h":380,"d":405},"M144-16l-48 112-48 0 0 48 48 0 0 32c0 17 3.3 33.2 9.3 48l-73.3 0 0 32 5.3 16 26.7 80-64 160 51.7 0 56.9-142.2 6.5-16.3c-1-3.1-10.1-30.3-27.2-81.5l51.4 0c22.6 19.9 52.2 32 84.7 32s62.1-12.1 84.7-32l51.4 0c-17.1 51.2-26.1 78.4-27.2 81.5l6.5 16.3 56.9 142.2 51.7 0-64-160 26.7-80 5.3-16 0-32-73.3 0c6-14.8 9.3-31 9.3-48l0-32 48 0 0-48-48 0-48-112-32 0-48 32-48-32-32 0zm80 272c-32.8 0-61-19.7-73.3-48l57.3 0 16-40 16 40 57.3 0c-12.3 28.3-40.5 48-73.3 48zm17.5 139.6l30.5-35.6 0-24-96 0 0 24 30.5 35.6-46.5 116.4 128 0-46.5-116.4z",{"w":380,"h":380,"d":407},"M497.4 49l17-17-33.9-33.9C473.6 4.9 453.3 25.2 419.7 58.8 375.4 22.1 318.5 0 256.4 0 115.1 0 .4 114.6 .4 256s114.6 256 256 256 256-114.6 256-256l-48 0c0 114.9-93.1 208-208 208s-208-93.1-208-208 93.1-208 208-208c48.8 0 93.7 16.8 129.1 44.9l-45.7 45.7c-23.5-16.8-52.3-26.6-83.4-26.6-79.5 0-144 64.5-144 144s64.5 144 144 144 144-64.5 144-144l-48 0c0 53-43 96-96 96s-96-43-96-96 43-96 96-96c17.8 0 34.5 4.8 48.8 13.3-52 52-79.5 79.5-82.7 82.7l33.9 33.9 17-17 224-224z",{"w":380,"h":380,"d":409},"M208 0l24 0C386.6 0 512 125.4 512 280l0 24-48 0 0-24C464 151.9 360.1 48 232 48l-24 0 0-48zm24 96c101.6 0 184 82.4 184 184l0 24-48 0 0-24c0-75.1-60.9-136-136-136l-24 0 0-48 24 0zM48 256c0 114.9 93.1 208 208 208 22.9 0 45-3.7 65.6-10.5l-263-263C51.7 211 48 233.1 48 256zM0 256c0-36.5 7.6-71.3 21.4-102.7 6.7-15.3 14.9-29.9 24.4-43.5 7.7 7.7 61.5 61.5 161.2 161.2 30.5-30.5 49.5-49.5 57-57L297.9 248c-7.5 7.5-26.5 26.5-57 57 99.7 99.7 153.5 153.5 161.2 161.2-13.6 9.5-28.2 17.7-43.5 24.4-31.4 13.8-66.2 21.4-102.7 21.4-141.4 0-256-114.6-256-256z",{"w":380,"h":380,"d":411},"M267.6 4.5l207.5 80.5 19.2 7.4 1.2 20.5c2.9 50-4.9 126.3-37.3 200.9-32.7 75.2-91.1 150-189.4 192.5l-12.7 5.5-12.7-5.5C144.9 463.9 86.6 389.2 53.9 313.9 21.5 239.3 13.7 162.9 16.6 113L17.8 92.5 37 85 244.5 4.5 256 0 267.6 4.5zM64.1 126C63.1 169.5 71 232.9 97.9 294.8 126.1 359.7 175 422.4 256 459.6 337.1 422.4 385.9 359.7 414.2 294.8 441 232.9 449 169.5 448 126L256 51.5 64.1 126zm302.3 44.7L352.3 190.1 249.8 330.9 233 354c-8.8-9.1-30.9-32-66.2-68.6l-16.7-17.3 34.5-33.3c9.5 9.8 23.9 24.7 43.2 44.7l85.6-117.7 14.1-19.4 38.8 28.2z",{"w":380,"h":380,"d":413},"M192 48l40 0 0 108-12.4 0c-7.6-16.5-24.3-28-43.6-28-26.5 0-48 21.5-48 48s21.5 48 48 48c19.4 0 36.1-11.5 43.6-28l12.4 0 0 56-92 0 0 56.4c-16.5 7.6-28 24.3-28 43.6 0 26.5 21.5 48 48 48s48-21.5 48-48c0-19.4-11.5-36.1-28-43.6l0-16.4 52 0 0 172-40 0c-16.8 0-31.2-10.3-37.1-25.1l-6.4-16-17.2 1c-1.1 .1-2.2 .1-3.2 .1-30.9 0-56-25.1-56-56 0-9.5 2.4-18.5 6.5-26.3l8.7-16.2-13.4-12.6c-11-10.2-17.8-24.8-17.8-40.9 0-21.6 12.2-40.4 30.3-49.8l22.6-11.7-13.1-21.9c-5-8.4-7.9-18.1-7.9-28.6 0-30.9 25.1-56 56-56l24 0 0-32c0-13.3 10.7-24 24-24zm88 148l12.4 0c7.6 16.5 24.3 28 43.6 28 26.5 0 48-21.5 48-48s-21.5-48-48-48c-19.4 0-36.1 11.5-43.6 28l-12.4 0 0-108 40 0c13.3 0 24 10.7 24 24l0 32 24 0c30.9 0 56 25.1 56 56 0 10.5-2.9 20.3-7.9 28.6l-13.1 21.9 22.6 11.7c18 9.3 30.3 28.1 30.3 49.8 0 16.1-6.8 30.7-17.8 40.9l-13.4 12.6 8.7 16.2c4.2 7.8 6.5 16.7 6.5 26.3 0 30.9-25.1 56-56 56-1.1 0-2.2 0-3.2-.1l-17.2-1-6.4 16C351.2 453.7 336.8 464 320 464l-40 0 0-76 92 0 0-56.4c16.5-7.6 28-24.3 28-43.6 0-26.5-21.5-48-48-48s-48 21.5-48 48c0 19.4 11.5 36.1 28 43.6l0 16.4-52 0 0-152zM192 512l128 0c31.1 0 58.4-16.2 74.1-40.5 52.7-5.1 93.9-49.5 93.9-103.5 0-11.5-1.9-22.5-5.3-32.9 13.4-17.5 21.3-39.4 21.3-63.1 0-32-14.5-60.6-37.1-79.7 3.3-10.2 5.1-21.1 5.1-32.3 0-49.6-34.8-91.1-81.3-101.5-6.3-33.3-35.6-58.5-70.7-58.5L192 0c-35.1 0-64.4 25.2-70.7 58.5-46.5 10.4-81.3 51.9-81.3 101.5 0 11.3 1.8 22.2 5.1 32.3-22.7 19.1-37.1 47.7-37.1 79.7 0 23.7 8 45.6 21.3 63.1-3.5 10.4-5.3 21.4-5.3 32.9 0 54 41.2 98.5 93.9 103.5 15.6 24.3 42.9 40.5 74.1 40.5zM336 192a16 16 0 1 1 0-32 16 16 0 1 1 0 32zm32 96a16 16 0 1 1 -32 0 16 16 0 1 1 32 0zM176 352a16 16 0 1 1 -32 0 16 16 0 1 1 32 0zm16-176a16 16 0 1 1 -32 0 16 16 0 1 1 32 0z",{"w":398,"h":380,"d":415},"M16 64C16 28.7 44.7 0 80 0L304 0c35.3 0 64 28.7 64 64l0 384c0 35.3-28.7 64-64 64L80 512c-35.3 0-64-28.7-64-64L16 64zm64 0l0 304 224 0 0-304-224 0zM192 472c17.7 0 32-14.3 32-32s-14.3-32-32-32-32 14.3-32 32 14.3 32 32 32z",{"w":380,"h":380,"d":417},"M0 256c0-46.6 12.5-90.4 34.3-128.9L144.1 318.3c21.9 39.2 63.8 65.7 111.9 65.7 14.3 0 27.1-2.3 40.8-6.6L220.5 509.6C95.9 492.3 0 385.3 0 256zm365.1 65.6c12.3-19.2 18.9-42.5 18.9-65.6 0-38.2-16.8-72.5-43.3-96l152.7 0c12 29.6 18.6 62.1 18.6 96 0 141.4-114.6 255.1-256 256L365.1 321.6zM477.8 128L256 128c-62.9 0-113.7 44.1-125.5 102.7L54.2 98.5C101 38.5 174 0 256 0 350.8 0 433.5 51.5 477.8 128zM344 256a88 88 0 1 1 -176 0 88 88 0 1 1 176 0z",{"w":380,"h":380,"d":419},"M448 96l0 256-384 0 0-256 384 0zM64 32C28.7 32 0 60.7 0 96L0 352c0 35.3 28.7 64 64 64l144 0-16 48-72 0c-13.3 0-24 10.7-24 24s10.7 24 24 24l272 0c13.3 0 24-10.7 24-24s-10.7-24-24-24l-72 0-16-48 144 0c35.3 0 64-28.7 64-64l0-256c0-35.3-28.7-64-64-64L64 32z",{"w":380,"h":380,"d":421},"M32 64C19.1 64 7.4 71.8 2.4 83.8S.2 109.5 9.4 118.6L192 301.3 192 416c0 8.5 3.4 16.6 9.4 22.6l64 64c9.2 9.2 22.9 11.9 34.9 6.9S320 492.9 320 480l0-178.7 182.6-182.6c9.2-9.2 11.9-22.9 6.9-34.9S492.9 64 480 64L32 64z",{"w":395,"h":380,"d":423},"M144 480c-79.5 0-144-64.5-144-144 0-63.4 41-117.2 97.9-136.5-1.3-7.7-1.9-15.5-1.9-23.5 0-79.5 64.5-144 144-144 55.4 0 103.5 31.3 127.6 77.1 14.2-8.3 30.8-13.1 48.4-13.1 53 0 96 43 96 96 0 15.7-3.8 30.6-10.5 43.7 44 20.3 74.5 64.7 74.5 116.3 0 70.7-57.3 128-128 128l-304 0zM305 191c-9.4-9.4-24.6-9.4-33.9 0l-72 72c-9.4 9.4-9.4 24.6 0 33.9s24.6 9.4 33.9 0l31-31 0 102.1c0 13.3 10.7 24 24 24s24-10.7 24-24l0-102.1 31 31c9.4 9.4 24.6 9.4 33.9 0s9.4-24.6 0-33.9l-72-72z",{"createdBy":425,"createdDate":426,"data":427,"folders":1132,"id":1133,"lastUpdated":1134,"lastUpdatedBy":425,"meta":1135,"modelId":1139,"name":435,"published":13,"query":1140,"stageModifiedSincePublish":6,"testRatio":31,"variations":1145,"lastUpdateSource":60,"firstPublished":1146,"screenshot":1147,"rev":1148},"SfUPqW5tkibIPby49keNFMdHFTr1",1787745962646,{"dateModified":428,"datePublished":428,"ogImage":429,"seoDescription":430,"seoTitle":431,"state":432,"themeId":6,"title":435,"url":436,"blocks":437},"Fri Sep 25 2026 00:00:00 GMT+0100 (British Summer Time)","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F32dca4101c7f48aa8e4b126ee1f4e73f","Browser attacks techniques","Browser Attack Techniques",{"deviceSize":83,"location":433},{"path":21,"query":434},{},"Browser Attacks Experience","\u002Fresources\u002Fbrowser-attacks",[438,447,471,501,542,557,601,619,635,649,671,683,889,953,967,1113,1127],{"@type":44,"@version":45,"id":439,"component":440,"responsiveStyles":445},"builder-e91a3c2bdc214502a80ef0511579b3b0",{"name":441,"tag":441,"options":442,"isRSC":60},"AttackTechniquesHero",{"title":443,"bodyText":444},"\u003Cp>The \u003Cstrong>browser\u003C\u002Fstrong> is\u003Cbr>the new \u003Cstrong>battleground\u003C\u002Fstrong>\u003C\u002Fp>\n","\u003Cp>This is your 2026 guide to the browser-based attack techniques behind today's biggest breaches, and why traditional security tools don’t detect them until it’s too late.\u003C\u002Fp>",{"large":446},{"display":63,"flexDirection":64,"position":65,"flexShrink":66,"boxSizing":67},{"@type":44,"@version":45,"id":448,"component":449,"responsiveStyles":469},"builder-0d4408fcaab14bc39eced814241f7fc3",{"name":450,"tag":450,"options":451,"isRSC":60},"AttackTechniquesStatBand",{"stats":452},[453,457,461,465],{"value":454,"label":455,"description":456},"29 min","Breakout time","The average time for hackers to\u2028move from initial access to high-\u2028value assets, meaning most teams can’t respond in time.",{"value":458,"label":459,"description":460},"1 in 2","Phishing delivery channels","Payloads intercepted by Push were sent over unmonitored channels like search engines and social media, so email tools don’t see them.",{"value":462,"label":463,"description":464},"2 days","Domain rotation","The time that most phishing  domains remain active before being rotated for a fresh one, evading blocked URL detections.",{"value":466,"label":467,"description":468},"95%","Detection evasion","Of in-browser attacks detected by Push used bot-protection services to hide, preventing security tools from analysing the page.",{"large":470},{"display":63,"flexDirection":64,"position":65,"flexShrink":66,"boxSizing":67},{"@type":44,"@version":45,"id":472,"component":473,"responsiveStyles":499},"builder-1e50adaa230f4abd94bd0663bd23f5fa",{"name":474,"tag":474,"options":475,"isRSC":60},"AttackTechniquesFloatingNav",{"ariaLabel":476,"items":477},"Page contents",[478,481,484,487,490,493,496],{"label":479,"section":480},"The Shift","modern-breaches",{"label":482,"section":483},"Delivery","phishing-payloads",{"label":485,"section":486},"Economics","attack-economics",{"label":488,"section":489},"Evolution","attack-evolution",{"label":491,"section":492},"Controls","bypassing-controls",{"label":494,"section":495},"Breaches","public-breaches",{"label":497,"section":498},"Defend","push-in-action",{"large":500},{"display":63,"flexDirection":64,"position":65,"flexShrink":66,"boxSizing":67},{"@type":44,"@version":45,"id":502,"component":503,"responsiveStyles":540},"builder-e6326e9cbef34fac8e2369cee1695579",{"name":504,"tag":504,"options":505,"isRSC":60},"AttackTechniquesModernBreaches",{"title":506,"attackSteps":507,"bodyText":514,"evidenceCardOne":515,"evidenceCardTwo":524,"evidenceCardThree":531},"\u003Cp>Modern breaches happen in the browser.\u003C\u002Fp>",[508,510,512],{"label":509},"Malicious JavaScript runs",{"label":511},"Browser payload triggered",{"label":513},"Apps & accounts hijacked","\u003Cp class=\"\">At the risk of using a few too many buzzwords: we've lived through a paradigm    shift. Where we used to talk about novel software exploits and advanced     endpoint malware, in 2026 we're talking about cloud apps and identities as            the \"patient zero\" of modern breaches.\u003C\u002Fp>\u003Cp class=\"\">But there's more to it. This shift has been accompanied by an evolution in attack paths                                themselves — one that many security teams haven't adjusted to. \u003C\u002Fp>\u003Cp class=\"\">The best way to understand this shift is that&nbsp;the browser is the new endpoint. Once you frame modern attacks   as being browser-based, it's easy to see why existing security tools are failing to intercept them — because        they have partial visibility at best. \u003C\u002Fp>",{"title":516,"points":517},"Traffic looks legitimate",[518,520,522],{"text":519},"Sites not known bad",{"text":521},"No malware in sandbox",{"text":523},"Requests seem legitimate",{"title":525,"points":526},"No endpoint alerts",[527,529],{"text":528},"No malware detected on device",{"text":530},"User activity looks normal",{"title":532,"points":533},"Activity looks legitimate",[534,536,538],{"text":535},"Successful authentication",{"text":537},"Expected behavior",{"text":539},"Legitimate API use",{"large":541},{"display":63,"flexDirection":64,"position":65,"flexShrink":66,"boxSizing":67},{"@type":44,"@version":45,"id":543,"component":544,"responsiveStyles":555},"builder-f6abfa982a274863b1af1c629aa0f3e5",{"name":545,"tag":545,"options":546,"isRSC":60},"AttackTechniquesPhishingPayloads",{"title":547,"stats":548,"bodyText":553,"image":554},"\u003Cp>Phishing isn't just about credentials now.\u003C\u002Fp>",[549],{"label":550,"value":551,"description":552},"Payload variation","3 in 5","of Push’s monthly phishing detections now involve kits with device code phishing capabilities, alongside the standard attacker-in-the-middle method.","\u003Cp>Modern phishing isn’t just credential theft. \u003C\u002Fp>\u003Cp>Phishing techniques look very different to what they did even  a few years ago. Once upon a time, phishing just meant stealing credentials or sending malware via email. \u003C\u002Fp>\u003Cp>Now, phishing attacks routinely bypass MFA by targeting tokens, not credentials, and take several different forms — like entering a device code, authorizing a consent grant, installing a browser extension, or even directly running malicious code on your machine. \u003C\u002Fp>\u003Cp>Users aren’t (and can’t be) trained to spot modern phishing, while typical technical controls weren’t designed for it — creating blind spots on multiple fronts. \u003C\u002Fp>","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F0ea7838da0d24e29a75e589b190e6aa3",{"large":556},{"display":63,"flexDirection":64,"position":65,"flexShrink":66,"boxSizing":67},{"@type":44,"@version":45,"id":558,"component":559,"responsiveStyles":599},"builder-8df4d7ae3d984d6fafd2855956fb3fbd",{"name":560,"tag":560,"options":561,"isRSC":60},"AttackTechniquesHidingInPlainSight",{"title":562,"stats":563,"bodyText":566,"categories":567},"\u003Cp>Hiding in plain sight.\u003C\u002Fp>",[564],{"label":467,"value":466,"description":565},"Of in-browser attacks detected by Push used bot-protection services to hide, preventing security tools from analyzing the page.","\u003Cp>Attackers abuse a wide range of legitimate, trusted services to host malicious content, benign decoy pages, and redirect chains — allowing them to blend in with normal web traffic and fly under the radar.\u003C\u002Fp>\n\u003Cp>Services like Microsoft Dynamics, SharePoint, Adobe, Google Firebase, Google Sites, Jotform, Linode, Azure, Cloudflare, Atlassian, and many more are commonly abused.\u003C\u002Fp>\n\u003Cp>They’re even using legitimate bot protection tools to bypass other legitimate security tools for web content scanning and analysis, meaning pages go undetected until it’s too late.\u003C\u002Fp>\n",[568,571,574,577,579,582,584,587,590,592,594,597],{"label":569,"value":570},"Web hosting & cloud infra","22.2",{"label":572,"value":573},"Cloud storage","5.1",{"label":575,"value":576},"Forms & surveys","17.2",{"label":578,"value":573},"Marketing & ads",{"label":580,"value":581},"Design","12.1",{"label":583,"value":573},"Document mgmt",{"label":585,"value":586},"Automation & dev","10.1",{"label":588,"value":589},"Scheduling & booking","2",{"label":591,"value":586},"Project management",{"label":593,"value":589},"CRM",{"label":595,"value":596},"Collaboration","7.1",{"label":598,"value":589},"IT service mgmt",{"large":600},{"display":63,"flexDirection":64,"position":65,"flexShrink":66,"boxSizing":67},{"@type":44,"@version":45,"id":602,"component":603,"responsiveStyles":617},"builder-ae2a82643f9e4f4692c493c8ca84b7fe",{"name":604,"tag":604,"options":605,"isRSC":60},"AttackTechniquesDetectionEvasion",{"title":606,"stats":607,"exampleDomains":609,"bodyText":616},"\u003Cp>Standard detections can't keep up.\u003C\u002Fp>",[608],{"label":463,"value":462,"description":464},[610,612,614],{"domain":611},"sso-session-fix.com",{"domain":613},"verify-payroll.net",{"domain":615},"account-reauth.io","\u003Cp class=\"\">Not only are attackers utilizing trusted sites and bot protection, they’re combining them with detection evasion techniques like rapid domain rotation, complex redirect chains, and screening checks to filter out unwanted visitors.\u003C\u002Fp>\u003Cp class=\"\">Meanwhile, modern phishing pages are designed to be disposable. So even if they do get detected, attackers are proactively tearing down and spinning up new pages to stay ahead of blocklists.\u003C\u002Fp>\u003Cp class=\"\">\u003Cstrong>If you’re primarily looking at static IoCs, pretty much every attack is a “zero-day” and will catch you off-guard.\u003C\u002Fstrong>\u003C\u002Fp>",{"large":618},{"display":63,"flexDirection":64,"position":65,"flexShrink":66,"boxSizing":67},{"@type":44,"@version":45,"id":620,"component":621,"responsiveStyles":633},"builder-1ad1afd3c2774ae08ea8960f85e37b3d",{"name":622,"tag":622,"options":623,"isRSC":60},"AttackTechniquesDeliveryChannels",{"title":624,"stats":625,"bodyText":632},"\u003Cp>You can find bad anywhere.\u003C\u002Fp>",[626,629],{"label":459,"value":627,"description":628},"1 in 3","Payloads intercepted by Push were sent over unmonitored channels like search engines and social media. The remainder bypassed email controls anyway.",{"label":459,"value":630,"description":631},"4 in 5","ClickFix-style social engineering attacks intercepted by Push happened because users clicked on a normal-looking search engine result.","\u003Cp>Attackers are reaching their targets in lots of different places, not just email. \u003C\u002Fp>\u003Cp>Users can stumble upon malicious content pretty much everywhere they work in the browser. Search engines, IM platforms, and social media apps are increasingly popular delivery vectors as an alternative to email. Malicious ads are being delivered across Google Search and Facebook, LinkedIn DM’s and job posts are being used to distribute phishing links. \u003C\u002Fp>\u003Cp>These channels have virtually no screening of content or messages and are invisible to security tools, while also being places users aren’t trained to suspect foul play. \u003C\u002Fp>\u003Cp>Modern phishing isn’t obvious or predictable. It can hit your users anywhere they work, comes in many different forms, and exploits normal user behaviors. \u003C\u002Fp>",{"large":634},{"display":63,"flexDirection":64,"position":65,"flexShrink":66,"boxSizing":67},{"@type":44,"@version":45,"id":636,"component":637,"responsiveStyles":647},"builder-5296cd04168a4f7188166bb70921c97a",{"name":638,"tag":638,"options":639,"isRSC":60},"AttackTechniquesAiInnovation",{"title":640,"stats":641,"bodyText":646},"\u003Cp>Attackers are innovating faster than ever.\u003C\u002Fp>",[642],{"label":643,"value":644,"description":645},"AI abuse","90%","of phishing kits analyzed by \nPush in 2026 involve some kind \nof AI-generated tell. ","\u003Cp class=\"\">Like your employees, attackers are harnessing the power of AI.\u003C\u002Fp>\u003Cp class=\"\">This means better quality phishing messages and AI-powered social engineering scams, but most importantly every attacker has become a way better developer overnight. This means new and improved phishing kits-for-hire, as well as the ability for attackers to simply vibe-code their own tools.\u003C\u002Fp>\u003Cp class=\"\">AI adoption also opens up a \u003Ca href=\"\u002Fblog\u002Fwhat-push-data-reveals-about-the-state-of-shadow-ai\" rel=\"noopener noreferrer\" class=\"\">whole new attack surface of AI apps\u003C\u002Fa> to target that concentrate application access and integrations, with new “normal” user behaviors to take advantage of around AI use too (as we covered in our \u003Ca href=\"\u002Fblog\u002Fllmshare-malvertising-campaign\" rel=\"noopener noreferrer\" class=\"\">LLMShare\u003C\u002Fa> and \u003Ca href=\"\u002Fblog\u002Finstallfix\" rel=\"noopener noreferrer\" class=\"\">InstallFix\u003C\u002Fa> campaign teardowns).\u003C\u002Fp>\u003Cp class=\"\">Overall, this means new techniques can reach mass adoption faster. For example, the explosion of \u003Ca href=\"\u002Fblog\u002Fdevice-code-phishing\" rel=\"noopener noreferrer\">device code phishing\u003C\u002Fa> attacks this year is enabled by AI-assisted development, as existing phishing tool vendors quickly add it to their existing stack to maintain feature parity with the criminal market.\u003C\u002Fp>",{"large":648},{"display":63,"flexDirection":64,"position":65,"flexShrink":66,"boxSizing":67},{"@type":44,"@version":45,"id":650,"component":651,"responsiveStyles":669},"builder-de16fd22fb0e46bebda74aed1b125cdf",{"name":652,"tag":652,"options":653,"isRSC":60},"AttackTechniquesAttackEconomics",{"title":654,"costs":655,"bodyText":668},"\u003Cp class=\"\">Attacks \u003Cstrong>in the browser\u003C\u002Fstrong>, not on it.\u003C\u002Fp>",[656,659,662,665],{"value":657,"label":658},"$15","stolen credential list",{"value":660,"label":661},"$1K","admin account from an access broker",{"value":663,"label":664},"$3K","1-year phish kit rental",{"value":666,"label":667},"$250K","Chrome RCE bug bounty","\u003Cp>Exploiting the browser itself is way more expensive than buying a set of infostealer logs with stolen credentials and sessions, renting a phishing service, or just vibe-coding your own tool.\u003C\u002Fp>\u003Cp>AI is making software exploits more accessible, but for well-resourced browser vendors it also makes them much easier to find and fix. This is already happening. \u003C\u002Fp>\u003Cp>Identities can’t be patched in the same way as a software exploit. There’s a way in to pretty much every account (yes, even if you’re using passkeys). And most identity configurations fall way short of the ideal. \u003C\u002Fp>\u003Cp>That’s why identity attacks remain one of the most useful tools in the attacker’s toolkit, and why the criminal ecosystem continues to double down on them.\u003C\u002Fp>\u003Cp>Attacks on the browser are beyond most criminals — but attacks in the browser are within reach for all.\u003C\u002Fp>",{"large":670},{"display":63,"flexDirection":64,"position":65,"flexShrink":66,"boxSizing":67},{"@type":44,"@version":45,"id":672,"component":673,"responsiveStyles":681},"builder-d4ece454d1b8405fb7a8d1fdc715b9f2",{"name":674,"tag":674,"options":675,"isRSC":60},"AttackTechniquesAttackEvolution",{"title":676,"stepOne":677,"stepTwo":678,"stepThree":679,"bodyText":680},"\u003Cp>The result?\u003C\u002Fp>","Malicious links delivered over many channels","Redirect chains through legitimate, trusted sites","Evolving payloads, rotating domains and infrastructure.","\u003Cp>More delivery channels, more techniques, more payloads, with controls lagging behind.\u003C\u002Fp>",{"large":682},{"display":63,"flexDirection":64,"position":65,"flexShrink":66,"boxSizing":67},{"@type":44,"@version":45,"id":684,"component":685,"responsiveStyles":887},"builder-efff32400c544d22912b05a075658344",{"name":686,"tag":686,"options":687,"isRSC":60},"AttackTechniquesTopTechniques",{"title":688,"techniques":689,"bodyText":880,"callout":881,"hidden":19},"\u003Cp>The 6 browser-based attack techniques behind today's biggest breaches.\u003C\u002Fp>",[690,717,758,789,823,860],{"label":691,"title":692,"tagline":693,"body":694,"caseStudies":695},"AitM Phishing","Adversary-in-the-Middle phishing","MFA-bypassing AitM attacks are the standard phishing method today.","\u003Cp>Attackers relay traffic between a phishing site and the real app in real time, capturing credentials, MFA, and session tokens as victims log in, then redirect them to the real site to lower suspicion. \u003C\u002Fp>\u003Cp>It typically targets SSO providers — Google, Microsoft Entra, Okta — since one compromise cascades across the whole SaaS stack, enabling attackers to pivot across downstream apps to steal data and abuse functionality. Cheap, rented PhaaS kits make AitM easy to run and hard to catch, with detection evasion capabilities continually improving over time.\u003C\u002Fp>\u003Cp>Unless the user is using a phishing-resistant authentication method (and does not have a phishable backup method available) the attack can succeed despite the presence of MFA. \u003C\u002Fp>",[696],{"title":697,"body":698,"bullets":699},"Scattered Lapsus$ Hunters' real-time AitM campaign","\u003Cp>Their latest campaign has targeted 100+ companies — including Betterment, Crunchbase, SoundCloud, and Match Group — with tens of millions of stolen records, powered by real-time operated kits that attackers walk victim’s through in real time. Because the domains only load when activated by the attacker, the \u003C\u002Fp>",[700,703,706,708,711,714],{"title":701,"text":702},"Voice pretext.","Attacker calls victim impersonating IT, offering to set up a \"secure passkey login.",{"title":704,"text":705},"Branded phishing page.","Victim is directed to a company-branded domain that looks legitimate.",{"title":707,"text":702},"Victim logs in and completes MFA. Attacker captures the live session.",{"title":709,"text":710},"Persistent passkey.","Victim is guided to register a passkey — the attacker intercepts it for persistence.",{"title":712,"text":713},"Confirmation email.","A fake ticket-closure email is sent to reduce suspicion.",{"title":715,"text":716},"Exfil & extort.","Data is stolen from enterprise cloud and SaaS, victim is extorted.",{"label":718,"title":719,"tagline":720,"body":721,"stats":722,"caseStudies":725},"ClickFix","ClickFix & *Fix variants","ClickFix, FileFix, CrashFix, ConsentFix, InstallFix  — the family keeps evolving.","\u003Cp>Since late 2024, attackers have been tricking users into performing malicious actions under the pretext of “fixing” an issue for the webpage to be able to load. The most common scenarios relate to “verifying that you are human,” styled as a version of the bot protection challenges that we’re all used to encountering on the internet today. However, newer forms are capitalizing on other lures, such as pretending to be the install page for legitimate AI tools.\u003C\u002Fp>\u003Cp>Traditional ClickFix-style attacks are a hybrid of browser and endpoint targeting. While delivered via the browser, the user is required to copy and run malicious scripts on their endpoint, targeting a wide range of legitimate, pre-installed system tools that allow commands to be run, aka Living Off the Land Binaries (LOLBins). This results in the user installing malicious software on their machine — typically Remote Access Tools (RATs) and infostealer malware.\u003C\u002Fp>",[723],{"label":459,"value":630,"description":724},"ClickFix-style social engineering attacks intercepted by Push happened because users clicked on a normal-looking search engine result, in the form of malvertising, SEO poisoning, and compromised websites.",[726,742],{"title":727,"body":728,"bullets":729},"InstallFix: AI-themed lures take advantage of users looking to install AI tools","\u003Cp class=\"\">Push discovered and named \u003Ca href=\"\u002Fblog\u002Finstallfix\" rel=\"noopener noreferrer\">InstallFix\u003C\u002Fa>, involving malicious imitations of popular AI tool pages, including Claude Code and NotebookLM, being distributed over search engines via malvertising. \u003C\u002Fp>\u003Cp class=\"\">Because these tools are often installed via command line script, attackers had created pixel-perfect clones of real pages where the install instructions had been replaced with a malicious command instead. Running the command installed infostealer malware on the victim’s machine. \u003C\u002Fp>",[730,733,736,739],{"title":731,"text":732},"Malicious search result.","Victim searching for “Claude Code” was returned a top-ranked advert for the malicious page. ",{"title":734,"text":735},"Cloned install page.","The page was an exact replica of the real page, but with one difference — the install command had been replaced with a malicious script. ",{"title":737,"text":738},"Paste the command.","Victim copies and pastes the command and runs it locally.",{"title":740,"text":741},"Infostealer malware installed.","The victim’s machine is infected and credentials and cookies are stolen, enabling further identity takeover attacks.",{"title":743,"body":744,"bullets":745},"ConsentFix: browser-native ClickFix linked to Russian state actors","\u003Cp>In late 2025, Push researchers uncovered ConsentFix — merging ClickFix-style social engineering with OAuth consent grant abuse. Traced to Russian state-affiliated APT29. \u003C\u002Fp>",[746,749,752,755],{"title":747,"text":748},"Fake CAPTCHA.","Victim asked to sign in to their Microsoft account to \"verify identity.\"",{"title":750,"text":751},"localhost redirect.","Page redirects to a localhost URL containing sensitive OAuth key material.",{"title":753,"text":754},"Paste the URL.","Victim copies the localhost URL and pastes it into the phishing page.",{"title":756,"text":757},"Attacker takes over.","OAuth key material enables Azure CLI takeover, depending on the specific app and scopes requested by the attacker.",{"label":759,"title":760,"tagline":761,"body":762,"bullets":763,"closingBody":770,"caseStudies":771},"Malicious OAuth","Malicious OAuth app integrations","OAuth attacks bypass login controls like passwords, MFA, even passkeys","\u003Cp>Attackers are increasingly launching phishing campaigns via malicious OAuth consent grants — establishing a malicious connection to a business app tenant. These are effectively post-authentication attacks focused on the authorization layer. \u003C\u002Fp>",[764,767],{"title":765,"text":766},"Consent phishing:","victim authorizes a third-party app via an OAuth consent grant. This can either be an app the attacker has created, or a legitimate SaaS app tenant (you can simply sign up for an account and invite targets to your app tenant). ",{"title":768,"text":769},"Device code phishing:","victim is tricked into performing a device code login, where the attacker provides an authorization code that the victim enters on a genuine login page. This grants the attacker access to the victim’s account by connecting an attacker-controlled app. ","\u003Cp>Either way, the attacker gets access to the target app without needing to authenticate normally. Normal login protections are circumvented — including phishing-resistant methods like passkeys. And because the victim is just \"clicking a button\" or \"entering a code\" on a legitimate page, most users won’t realize that they’re being phished. \u003C\u002Fp>",[772],{"body":773,"title":774,"bullets":775,"closingBody":788},"\u003Cp class=\"\">Scattered Lapsus$ Hunters' 2025 Salesforce campaign resulted in a claimed 1000+ organizations compromised and 1.5 billion records stolen — used to extort victims en masse, including an attempt against Salesforce directly.\u003C\u002Fp>","Mass Salesforce breaches via device code phishing",[776,778,780,782,784,786],{"text":777},"Attacker registered a malicious Salesforce app called \"DataLoader\" \n— a fake version of the legitimate app.",{"text":779},"Victims were called by attackers impersonating IT, with a pretext of installing the app.",{"text":781},"Over the phone, the victim was talked through opening Salesforce and authorizing the new app.",{"text":783},"The app had broad OAuth scopes — full Salesforce API access and refresh tokens without re-auth.",{"text":785},"Data and secrets were mass-exfiltrated from Salesforce via API.",{"text":787},"The stolen data and secrets were then used in further supply chain attacks against downstream organizations. ","\u003Cp>Device code phishing attacks have now become a core phishing technique in 2026, with Push now tracking 25+ kits in the wild as PhaaS vendors quickly adapt to the success that ShinyHunters and other criminals have had with the technique. \u003C\u002Fp>",{"label":790,"title":275,"tagline":791,"body":792,"bullets":793,"closingBody":802,"caseStudies":803},"Malicious Extensions","Attackers are doubling down on extensions as their method of choice.","\u003Cp class=\"\">\u003Cspan style=\"font-size: 16px;\" class=\"\">Attackers use malicious extensions to steal data, log keystrokes, and intercept credentials and tokens as they transit the browser. Most malicious extensions didn't start that way — attackers begin with a legitimate extension and bide their time, waiting until install counts reach maximum impact before deploying a malicious update.\u003C\u002Fspan>\u003C\u002Fp>\u003Cp class=\"\">\u003Cstrong style=\"font-size: 16px;\">There are four common entry paths:\u003C\u002Fstrong>\u003C\u002Fp>",[794,796,798,800],{"text":795},"Phish the developer of a popular extension.",{"text":797},"Offer to buy a widely-installed extension outright.",{"text":799},"Vibe-code your own extension and market it to users.",{"text":801},"Upload a malicious version; user browsers auto-update on next launch.","\u003Cp>Permissions alone don't indicate risk, since nearly every extension has exploitable ones — the most dangerous let attackers intercept sensitive data, credentials, and session tokens in transit. Malicious extensions routinely evade static and sandbox analysis via dynamically compiled, smuggled code, letting them reach official stores and even earn \"Featured\" or \"Verified\" status.\u003C\u002Fp>",[804],{"title":805,"body":806,"bullets":807},"DarkSpectre: China-linked extension campaign spanning 7 years and 8.8 million victims","\u003Cp>DarkSpectre is a China-attributed threat actor that operated three coordinated malicious browser extension campaigns across Chrome, Edge, and Firefox for over seven years, compromising 8.8 million users before being exposed in December 2025.\u003C\u002Fp>",[808,811,814,817,820],{"title":809,"text":810},"Built legitimate extensions.","The actor published functional browser extensions — new tab dashboards, video downloaders, meeting productivity tools — across official browser stores, delivering real features that attracted genuine users and positive reviews.",{"title":812,"text":813},"Accumulated trust over years.","Extensions operated legitimately for 3–5 years, building install bases in the millions and earning Chrome Web Store \"Verified\" badges. At discovery, 85 additional \"sleeper\" extensions were still in this trust-building phase.",{"title":815,"text":816},"Activated via server-side updates.","Once an extension had a large enough user base, the actor pushed malicious payloads through server-side configuration changes.",{"title":818,"text":819},"Evaded detection through multiple layers.","Malicious behavior was gated behind a 3-day dormancy timer after installation, executed on only ~10% of page loads to reduce detection surface.",{"title":821,"text":822},"Harvested data across three campaigns.","ShadyPanda (5.6M users), GhostPoster (1.05M users), and Zoom Stealer (2.2M users).",{"label":824,"title":825,"tagline":826,"body":827,"bullets":828,"closingBody":838,"caseStudies":839},"Credential Stuffing","Credential stuffing & ghost logins","The oldest trick in the book — and it works better than ever.","\u003Cp>Password-based compromise remains one of the leading causes of breaches. It's arguably worse than ever in sprawling SaaS environments: users log into tens (sometimes hundreds) of apps, and billions of stolen credentials circulate on the internet, fuelled by infostealer infections and data breaches.\u003C\u002Fp>\u003Cp>\"But our users log in via SSO and those accounts are MFA-protected, right?\" The reality might surprise you. Of the last million logins observed by Push:\u003C\u002Fp>",[829,832,835],{"title":830,"text":831},"1 in 4","were password logins, not SSO",{"title":833,"text":834},"2 in 5","were not protected by MFA",{"title":836,"text":837},"1 in 5","used a weak, breached, or reused password","\u003Cp>SSO isn't universal — SAML often costs extra, requires admin setup, and self-adopted apps rarely get configured, while most apps allow simultaneous logins and don't restrict login methods. The result is ghost logins: backup credentials outside SSO, invisible to IdP logs, created at adoption and still active unless disabled — gaps that stay hidden since most orgs focus MFA at the IdP layer, not on local app config, until an attacker finds them.\u003C\u002Fp>",[840],{"title":841,"body":842,"bullets":843,"closingBody":859},"Snowflake — 2024's landmark breach","\u003Cp>ShinyHunters (part of Scattered Lapsus$ Hunters) breached 165+ organizations using stolen credentials, logging into their Snowflake tenants and mass-dumping data via direct SQL commands on the Snowflake platform.\u003C\u002Fp>",[844,847,850,853,856],{"title":845,"text":846},"Mined infostealer dumps:","The attacker harvested stolen credentials from underground marketplaces.  ",{"title":848,"text":849},"Identified MFA gaps:","On testing credentials against Snowflake, platform-wide MFA gaps were identified.",{"title":851,"text":852},"Script development:","The attacker developed an exploit script that could be used to rapidly compromise accounts once access was established. ",{"title":854,"text":855},"Mass account takeover:","A mass credential stuffing campaign was orchestrated and exploited in a short time period. ",{"title":857,"text":858},"Theft and extortion:","Over 1 billion records stolen from just 9 publicly named victims: the real impact is likely to be far greater.","\u003Cp>Snowflake demonstrates how little control or visibility organizations have over downstream SaaS logins. Not only did accounts lack MFA — they were using credentials that had been online for years without being spotted or rotated. \u003C\u002Fp>",{"label":861,"title":304,"tagline":862,"body":863,"caseStudies":864},"Session Hijacking","Sidestepping authentication controls by replaying stolen session tokens.","\u003Cp class=\"\">Session hijacking (aka token replay) allows attackers to bypass the authentication process by taking an already-approved session token that they’ve stolen from the victim’s device or browser, and reusing it in their own browser. \u003Cstrong>This enables them to get around even phishing-resistant authentication controls like passkeys.\u003C\u002Fstrong> \u003C\u002Fp>\u003Cp class=\"\">This is different to AITM attacks, which see a new session created via the attacker’s reverse-proxy connection to the target app.  Sessions can be stolen using a variety of methods, some of which we’ve already discussed. Malicious browser extensions can extract them from webpages visited by the user, for example. But the most prominent source of stolen tokens is infostealer malware (also the leading source of stolen credentials powering credential stuffing attacks). \u003C\u002Fp>\u003Cp class=\"\">As mentioned previously, ClickFix is now the go-to method for delivering malware like infostealers. ClickFix is more detection resistant than a normal file download, which is more likely to be intercepted and analysed by controls like a web sandbox before hitting the endpoint, and are more likely to trigger endpoint alarms during execution.\u003C\u002Fp>",[865],{"title":866,"body":867,"bullets":868,"closingBody":879},"Okta session theft cascades into customer compromise","\u003Cp>Late 2023. An Okta support engineer was infected with infostealer malware. The attacker (reportedly Scattered Spider) accessed Okta's customer support system and exfiltrated sensitive files containing session tokens — then replayed those tokens to access customer environments.\u003C\u002Fp>",[869,871,873,875,877],{"text":870},"Infostealer executed on the Okta engineer's personal device.",{"text":872},"Corporate credentials had been synced to the engineer's personal Google account via Chrome profile sync — and were stolen along with everything else.",{"text":874},"Attacker signed into Okta's customer support portal using the synced creds.",{"text":876},"Downloaded HAR files containing active customer session tokens.",{"text":878},"Accessed 134 downstream customer Okta tenants; moved laterally into connected apps.","\u003Cp>BeyondTrust, 1Password, and Cloudflare all reported further activity. Cloudflare saw attackers access their internal Atlassian, including Confluence, Jira, and Bitbucket source code. A key lesson: business credentials can transit personal and managed devices through features like Chrome profile sync — easy to enable, hard to track.\u003C\u002Fp>","\u003Cp>Attackers in 2026 use a wide and growing range of browser-based techniques to achieve a common goal: compromise cloud applications and services, then monetize via data theft, disruption, and extortion.\u003C\u002Fp>",{"title":882,"bodyText":883,"cta":884},"See Push in action","Want to see these attacks in action and how Push stops them?",{"label":885,"url":886},"See how it's done","\u002Fdemo",{"large":888},{"display":63,"flexDirection":64,"position":65,"flexShrink":66,"boxSizing":67},{"@type":44,"@version":45,"id":890,"component":891,"responsiveStyles":951},"builder-d51b0bf934404644b19b38f581295581",{"name":892,"tag":892,"options":893,"isRSC":60},"AttackTechniquesBypassingControls",{"title":894,"instruction":895,"controls":896,"bodyText":950},"\u003Cp>How browser-based attacks bypass traditional controls.\u003C\u002Fp>","Click any control above to see how modern browser attacks get around it",[897,907,917,922,927,934,943],{"name":898,"bypassMode":899,"bypassPoints":900},"Email","throughAndAround",[901,903,905],{"text":902},"\u003Cp>Deliver over non-email channel\u003C\u002Fp>",{"text":904},"\u003Cp class=\"\">Send emails from trusted apps\u003C\u002Fp>",{"text":906},"\u003Cp class=\"\">Don’t use known-bad domains — constant rotation\u003C\u002Fp>",{"name":908,"bypassMode":909,"bypassPoints":910},"Secure Web Gateway","through",[911,913,915],{"text":912},"\u003Cp>Evade malicious download detections through HTML smuggling\u003C\u002Fp>",{"text":914},"\u003Cp class=\"\">Client-side reassembly of complex encoded web pages bypasses traffic signatures\u003C\u002Fp>",{"text":916},"\u003Cp class=\"\">Rapid domain rotation  effectively bypasses domain blocklists\u003C\u002Fp>",{"name":918,"bypassMode":899,"bypassPoints":919},"Remote Browser Isolation",[920],{"text":921},"\u003Cp>RBI is designed to protect against exploits, not attacks happening inside the browser e.g. account takeover\u003C\u002Fp>",{"name":923,"bypassMode":899,"bypassPoints":924},"File Sandbox",[925],{"text":926},"\u003Cp>Evade malicious download detections through HTML smuggling, or fileless malware delivery methods like ClickFix\u003C\u002Fp>",{"name":928,"bypassMode":899,"bypassPoints":929},"Endpoint Security",[930,932],{"text":931},"\u003Cp>Most attacks now don’t touch the endpoint\u003C\u002Fp>",{"text":933},"\u003Cp class=\"\">When they do, methods like ClickFix enable stealthy malware execution\u003C\u002Fp>",{"name":935,"bypassMode":909,"bypassPoints":936},"Identity & Authentication",[937,939,941],{"text":938},"\u003Cp>2 in 5 logins not protected by MFA, “ghost logins” circumvent SSO\u003C\u002Fp>",{"text":940},"\u003Cp class=\"\">\u003Ca href=\"\u002Fblog\u002Fmfa-downgrade-attacks\u002F\" rel=\"noopener noreferrer\">Downgrade attacks\u003C\u002Fa> can circumvent phishing-resistant auth\u003C\u002Fp>",{"text":942},"\u003Cp>Many attacks are post-auth, meaning they succeed regardless of login controls e.g. passkeys\u003C\u002Fp>\n",{"name":944,"bypassMode":909,"bypassPoints":945},"Cloud Security",[946,948],{"text":947},"\u003Cp>In-app exploitation blends in with normal user activity\u003C\u002Fp>",{"text":949},"\u003Cp class=\"\">Cloud logging is inconsistent from app to app, creating visibility gaps\u003C\u002Fp>","\u003Cp>Most of your existing controls weren't designed with browser-based attacks in mind. Any red teamer will tell you: just because a tool counters an attack on paper, doesn't mean there isn't a way around it in practice.\u003C\u002Fp>",{"large":952},{"display":63,"flexDirection":64,"position":65,"flexShrink":66,"boxSizing":67},{"@type":44,"@version":45,"id":954,"component":955,"responsiveStyles":965},"builder-cdce6999b63644938d403c5588390295",{"name":956,"tag":956,"options":957,"isRSC":60},"AttackTechniquesPublicBreaches",{"title":958,"chartLabel":959,"startYear":960,"startMonth":961,"endYear":962,"endMonth":963,"bodyText":964},"\u003Cp>Public breaches tell the story.\u003C\u002Fp>","Public breaches by month",2024,"1",2026,"6","\u003Cp>Browser-based techniques have been behind some of the biggest public cybercriminal campaigns and breaches of recent years. Attacks that make it into the public domain are in the minority, but give an indicator of the patterns of criminal behavior happening behind the scenes. \u003C\u002Fp>",{"large":966},{"display":63,"flexDirection":64,"position":65,"flexShrink":66,"boxSizing":67},{"@type":44,"@version":45,"id":968,"component":969,"responsiveStyles":1111},"builder-2ec4df48c8494dbaa89aef227b8d54a6",{"name":970,"tag":970,"options":971,"isRSC":60},"AttackTechniquesPushInAction",{"title":972,"bodyText":973,"screenTitle":974,"attacks":975,"mitigationsHeading":1110},"\u003Cp>Watch Push in action\u003C\u002Fp>","\u003Cp>Push intercepts browser attacks in real time, before they hit the user\u003C\u002Fp>","See how Push stops browser attacks",[976,989,999,1010,1021,1032,1042,1054,1066,1077,1088,1099],{"label":977,"description":978,"mitigations":979,"attackScreenshotImage":984,"alertTitle":985,"alertMessage":986,"navIcon":987,"attackPageLink":988},"AiTM phishing","Adversary-in-the-middle phishing uses a reverse proxy to sit between the victim and a legitimate login page, relaying credentials and MFA challenges in real time to steal the resulting session token.",[980,982],{"text":981},"Push detects AITM phishing pages behaviorally — analyzing page structure, script behavior, and credential-harvesting mechanics rather than relying on domain blocklists or known kit signatures",{"text":983},"SSO password protection blocks credential entry on pages that don't belong to that credential's identity provider","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F476d442978bd4bab829adb4597b59432","Phishing danger detected","The website you are trying to access is using phishing software that can steal your credentials.","regular:faArrowRightArrowLeft",{"label":21,"url":21},{"label":260,"description":990,"mitigations":991,"alertTitle":985,"alertMessage":996,"attackScreenshotImage":997,"navIcon":998},"Device code phishing abuses the OAuth 2.0 device authorization flow — the attacker generates a legitimate device code and tricks the victim into entering it, granting the attacker a valid access token without ever touching the victim's credentials.",[992,994],{"text":993},"Push detects and blocks device code phishing kits, stopping the attack before the user completes the authorization flow",{"text":995},"Push delivers app-agnostic warnings during the device code authentication flow, alerting users before they authorize a device they don't control","This device code login was trying to hijack your account. Push blocked the attack.","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F546632d9ac7746c3b16c30fa260a1ad6","regular:faInputNumeric",{"label":1000,"description":1001,"mitigations":1002,"attackScreenshotImage":1007,"alertTitle":985,"alertMessage":1008,"navIcon":1009},"BITB phishing","Browser-in-the-browser (BITB) attacks render a fake browser popup inside the page — complete with a spoofed address bar showing a legitimate login URL — so victims believe they're signing in through a real SSO window.",[1003,1005],{"text":1004},"Push analyzes the actual page, not the pixels drawn on it — the credential-harvesting form is detected behaviorally no matter what fake window chrome surrounds it",{"text":1006},"SSO password protection blocks entry of corporate credentials on pages that don't belong to the real identity provider, whatever URL the fake address bar displays","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fd4cdd5332b8a4e95a481b723a9f37e12","This sign-in window is fake — it's drawn by the page to steal your credentials","regular:faWindowRestore",{"label":265,"description":1011,"mitigations":1012,"alertTitle":1017,"alertMessage":1018,"attackScreenshotImage":1019,"navIcon":1020},"Consent phishing tricks users into granting OAuth permissions to a malicious application, giving the attacker persistent API-level access to the victim's data without needing their password.",[1013,1015],{"text":1014},"Push monitors and can block OAuth consent flows across 20+ authorization servers, recording client ID, scopes, and outcome in real time",{"text":1016},"Security teams can manage and remove malicious OAuth apps from the Push console","Malicious OAuth grant blocked","This app is requesting permissions that would give it access to your account","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F86e8bb1e840144678983daedff8e9108","regular:faUserCheck",{"label":1022,"description":1023,"mitigations":1024,"alertTitle":985,"alertMessage":1029,"attackScreenshotImage":1030,"navIcon":1031},"Social media phishing","Social media phishing delivers malicious links through trusted platforms like LinkedIn — recruiter outreach, direct messages, and connection requests lead victims to phishing pages, malware downloads, or other payloads, entirely outside email security's view.",[1025,1027],{"text":1026},"Push detects the malicious destination behaviorally at the moment it loads — regardless of delivery channel, so links from LinkedIn DMs are caught just like email phishing",{"text":1028},"Protection covers whatever the payload is: credential phishing, ClickFix-style clipboard hijacks, malicious OAuth grants, or file downloads","The link you opened from a LinkedIn message leads to a malicious page. Push has blocked it.","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F167232f4b81e44259d4f0b4146aaaa91","regular:faMessage",{"label":1033,"description":1034,"mitigations":1035,"attackScreenshotImage":1038,"alertTitle":1039,"alertMessage":1040,"navIcon":1041},"Malvertising","Malvertising uses paid search ads or display ads to place malicious links above legitimate results, directing victims to phishing pages or malware downloads through a trusted delivery channel.",[1036],{"text":1037},"Push detects the phishing destination page behaviorally, regardless of how the user arrived — whether via a search ad, display ad, email, or any other channel","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F3deb8d22936f4a749fe98562bc91b93c","Malicious redirect blocked","An ad on this page attempted to redirect you to a malicious site.","regular:faMegaphone",{"label":1043,"description":1044,"mitigations":1045,"attackScreenshotImage":1050,"alertTitle":1051,"alertMessage":1052,"navIcon":1053},"Malicious extensions","Malicious browser extensions either start as outright malware or become compromised through supply chain attacks like ownership transfers and permission escalations, gaining broad access to browsing data and credentials.",[1046,1048],{"text":1047},"Push inventories all browser extensions across the organization with full permissions analysis, giving security teams visibility into what's installed",{"text":1049},"Malicious extension detection and blocking identifies and removes known-malicious extensions across any browser in the environment","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F3196d37432a945f88ad01dcf22d2cc61","Malicious extension blocked","This extension has been flagged as malicious and is known for stealing data and credentials","regular:faPuzzlePiece",{"label":1055,"description":1056,"mitigations":1057,"attackScreenshotImage":1062,"alertTitle":1063,"alertMessage":1064,"navIcon":1065},"File downloads","Malicious file downloads deliver malware payloads through the browser, often via phishing pages, compromised websites, or drive-by downloads that exploit user trust or curiosity.",[1058,1060],{"text":1059},"Push streams all file download events to SIEM with full metadata, giving security teams visibility into what's being downloaded and where from",{"text":1061},"Configurable blocking rules prevent risky downloads based on file type, extension, file name patterns, browser profile, and user group","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fc9761a4c7de74c658b517f9cc2d8da5b","Malicious download blocked","This file matches a known-malicious signature and has been quarantined.","regular:faDownload",{"label":718,"description":1067,"mitigations":1068,"alertTitle":1073,"alertMessage":1074,"attackScreenshotImage":1075,"navIcon":1076},"ClickFix attacks use fake CAPTCHA pages, error messages, or install prompts to silently load malicious commands into the victim's clipboard and instruct them to paste and execute the payload — typically PowerShell or mshta commands.",[1069,1071],{"text":1070},"Push detects when a page silently writes malicious commands to the clipboard, identifying the technique regardless of the social engineering wrapper (fake CAPTCHAs, fake errors, fake install prompts)",{"text":1072},"Detection covers the entire x-Fix family — ClickFix, FileFix, CrashFix, ConsentFix, and InstallFix — through a single technique-class detection","Clipboard hijack blocked","This page attempted to copy a malicious command to your clipboard.","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F3cdf008d3e8047348af6b61239962f22","regular:faArrowPointer",{"label":1078,"description":1079,"mitigations":1080,"attackScreenshotImage":1085,"alertTitle":1017,"alertMessage":1086,"navIcon":1087},"ConsentFix","ConsentFix wraps OAuth consent abuse in a ClickFix-style lure — a fake verification page walks the victim through approving a malicious consent grant.",[1081,1083],{"text":1082},"Push detects the fake verification pattern and page behavior behind ConsentFix lures, regardless of the social engineering wrapper",{"text":1084},"Risky consent grants can be blocked at the point of authorization, and security teams can revoke malicious grants from the Push console","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F39fb2686dc4443c7b27461b1892b3059","This page tried to trick you into granting an attacker access to your account. Push has stopped the consent flow.","regular:faClipboardCheck",{"label":304,"description":1089,"mitigations":1090,"alertTitle":1095,"alertMessage":1096,"attackScreenshotImage":1097,"navIcon":1098},"Session hijacking occurs when an attacker steals a valid session token — typically via infostealer malware, AITM phishing, or cross-site scripting — and replays it from their own browser to take over an authenticated session.",[1091,1093],{"text":1092},"Push injects a unique marker into every session originating from a Push-protected browser — if that session token later appears in an uninstrumented browser, it's confirmed stolen",{"text":1094},"Browser sync detection catches corporate credentials syncing to personal browser profiles, closing a common token and credential leakage path","Session terminated","This session was used from an unrecognized device and has been signed out.","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F0650cea0980e490bbfe227e6a309194f","regular:faCookieBite",{"label":299,"description":1100,"mitigations":1101,"attackScreenshotImage":1106,"alertTitle":1107,"alertMessage":1108,"navIcon":1109},"Credential stuffing uses stolen username-password pairs from breached databases and infostealer logs to attempt logins at scale, exploiting password reuse across services.",[1102,1104],{"text":1103},"Push detects when employees log in with weak, reused, or breached passwords that have appeared in infostealer logs, enabling remediation before they become attack vectors",{"text":1105},"MFA enforcement via in-browser guardrails ensures employees enroll in MFA, closing the gaps that credential stuffing relies on","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F1fa20d0b99724cbc9e7ad842bd95ee91","Change your password and enable MFA","Your password for this app was found in a breach. Your security team needs you to change it and register for multi-factor authentication to protect your account.","regular:faKey","How Push stops it",{"large":1112},{"display":63,"flexDirection":64,"position":65,"flexShrink":66,"boxSizing":67},{"@type":44,"@version":45,"id":1114,"component":1115,"responsiveStyles":1125},"builder-8db25b9326af487a9fa83286b5c79633",{"name":1116,"tag":1116,"options":1117,"isRSC":60},"AttackTechniquesCtaBanner",{"title":1118,"bodyText":1119,"primaryCta":1120,"secondaryCta":1122},"\u003Cp class=\"\">See Push in action\u003C\u002Fp>","\u003Cp>Browser security that detects and blocks the attacks in this report — in real time, without ripping out your existing stack.\u003C\u002Fp>",{"label":1121,"url":886},"Book a demo",{"label":1123,"url":1124},"Product overview","\u002Fproduct",{"large":1126},{"display":63,"flexDirection":64,"position":65,"flexShrink":66,"boxSizing":67},{"id":1128,"@type":44,"tagName":73,"properties":1129,"responsiveStyles":1130},"builder-pixel-y8yd9m1595",{"src":75,"aria-hidden":76,"alt":21,"width":66,"height":66},{"large":1131},{"height":66,"width":66,"display":79,"opacity":66,"overflow":80,"pointerEvents":81},[],"eb36042e7e994997a1ce6d5b18f2cb3e",1790671262642,{"breakpoints":1136,"hasAutosaves":6,"hasErrors":6,"hasLinks":6,"kind":1137,"lastPreviewUrl":1138},{"medium":16,"small":17,"xsmall":18},"page","http:\u002F\u002Flocalhost:8081\u002Fresources\u002Fbrowser-attacks?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditCode%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CeditProjects%2CmodifyMcpServers%2CmodifyWorkflowIntegrations%2CmodifyProjectSettings%2CconnectCodeRepository%2CcreateProjects%2CindexDesignSystems%2CsendPullRequests%2CmergePullRequests%2CfusionHostingPublish%2CfusionHostingRevokeAiToken&builder.user.role.name=Developer&builder.user.role.id=developer&builder.cachebust=true&builder.preview=browser-attacks&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.browser-attacks=eb36042e7e994997a1ce6d5b18f2cb3e&builder.overrides.eb36042e7e994997a1ce6d5b18f2cb3e=eb36042e7e994997a1ce6d5b18f2cb3e&builder.options.includeRefs=true&builder.options.enrich=true&builder.options.locale=Default","f34082378f1f4783b0251286622c7029",[1141],{"@type":1142,"operator":1143,"property":1144,"value":436},"@builder.io\u002Fcore:Query","is","urlPath",{},1790340710658,"https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F5be2b8bdbb1042e38a3ff9005830be67","zvn1ula8ex",{"w":380,"h":380,"d":1150},"M367 41l63 63-406.1 0c-13.3 0-24 10.7-24 24s10.7 24 24 24l406.1 0-63 63c-9.4 9.4-9.4 24.6 0 33.9s24.6 9.4 33.9 0L505 145c9.4-9.4 9.4-24.6 0-33.9L401 7c-9.4-9.4-24.6-9.4-33.9 0s-9.4 24.6 0 33.9zM145 297c9.4-9.4 9.4-24.6 0-33.9s-24.6-9.4-33.9 0L7 367c-9.4 9.4-9.4 24.6 0 33.9L111 505c9.4 9.4 24.6 9.4 33.9 0s9.4-24.6 0-33.9l-63-63 406.1 0c13.3 0 24-10.7 24-24s-10.7-24-24-24l-406.1 0 63-63z",{"w":395,"h":380,"d":1152},"M512 112c8.8 0 16 7.2 16 16l0 256c0 8.8-7.2 16-16 16L64 400c-8.8 0-16-7.2-16-16l0-256c0-8.8 7.2-16 16-16l448 0zM64 64C28.7 64 0 92.7 0 128L0 384c0 35.3 28.7 64 64 64l448 0c35.3 0 64-28.7 64-64l0-256c0-35.3-28.7-64-64-64L64 64zm40 120c0 13.3 10.7 24 24 24l8 0 0 96-16 0c-13.3 0-24 10.7-24 24s10.7 24 24 24l80 0c13.3 0 24-10.7 24-24s-10.7-24-24-24l-16 0 0-120c0-13.3-10.7-24-24-24l-32 0c-13.3 0-24 10.7-24 24zm190.6 30.4c5.8-8 17.5-8.6 24-1.2 5.2 5.9 5 14.7-.3 20.5l-72 78c-6.5 7-8.2 17.2-4.3 25.9S254.5 352 264 352l88 0c13.3 0 24-10.7 24-24s-10.7-24-24-24l-33.2 0 34.8-37.7c22-23.8 22.4-60.3 1.1-84.7-26.9-30.7-75.4-28.4-99.2 4.9l-11.1 15.6c-7.7 10.8-5.2 25.8 5.6 33.5s25.8 5.2 33.5-5.6l11.1-15.6z",{"w":395,"h":380,"d":1154},"M512 80L224 80c-8.8 0-16 7.2-16 16l0 16-48 0 0-16c0-35.3 28.7-64 64-64l288 0c35.3 0 64 28.7 64 64l0 192c0 35.3-28.7 64-64 64l-48 0 0-48 48 0c8.8 0 16-7.2 16-16l0-192c0-8.8-7.2-16-16-16zM368 288l-320 0 0 128c0 8.8 7.2 16 16 16l288 0c8.8 0 16-7.2 16-16l0-128zM64 160l288 0c35.3 0 64 28.7 64 64l0 192c0 35.3-28.7 64-64 64L64 480c-35.3 0-64-28.7-64-64L0 224c0-35.3 28.7-64 64-64z",{"w":17,"h":380,"d":1156},"M304.3 304c97.2 0 176 78.8 176 176l0 8c0 13.3-10.7 24-24 24s-24-10.7-24-24l0-8c0-70.7-57.3-128-128-128l-96 0c-70.7 0-128 57.3-128 128l0 8c0 13.3-10.7 24-24 24s-24-10.7-24-24l0-8c0-97.2 78.8-176 176-176l96 0zM585.7 105.9c7.8-10.7 22.8-13.1 33.5-5.3s13.1 22.8 5.3 33.5L522.1 274.9c-4.2 5.7-10.7 9.4-17.7 9.8s-14-2.2-18.9-7.3l-46.4-48c-9.2-9.5-9-24.7 .6-33.9 9.5-9.2 24.7-8.9 33.9 .6l26.5 27.4 85.6-117.7zM256.3 256a128 128 0 1 1 0-256 128 128 0 1 1 0 256zm0-208a80 80 0 1 0 0 160 80 80 0 1 0 0-160z",{"w":380,"h":380,"d":1158},"M203.7 512.9s0 0 0 0l-37.8 26.7c-7.3 5.2-16.9 5.8-24.9 1.7S128 529 128 520l0-72-32 0c-53 0-96-43-96-96L0 128C0 75 43 32 96 32l320 0c53 0 96 43 96 96l0 224c0 53-43 96-96 96l-120.4 0-91.9 64.9zm64.3-104.1c8.1-5.7 17.8-8.8 27.7-8.8L416 400c26.5 0 48-21.5 48-48l0-224c0-26.5-21.5-48-48-48L96 80c-26.5 0-48 21.5-48 48l0 224c0 26.5 21.5 48 48 48l56 0c10.4 0 19.3 6.6 22.6 15.9 .9 2.5 1.4 5.2 1.4 8.1l0 49.7c32.7-23.1 63.3-44.7 91.9-64.9z",{"w":380,"h":380,"d":1160},"M201.1 57.3c-7 5.3-9.1 10.7-9.1 14.7 0 4.2 2.4 10.1 10.4 15.6 7.8 5.3 13.6 14.6 13.6 25.6 0 17-13.8 30.7-30.7 30.7L56 144c-4.4 0-8 3.6-8 8l0 52.5c7.4-2.9 15.5-4.5 24-4.5 43.1 0 72 39.4 72 80s-28.9 80-72 80c-8.5 0-16.6-1.6-24-4.5L48 456c0 4.4 3.6 8 8 8l100.5 0c-2.9-7.4-4.5-15.5-4.5-24 0-43.1 39.4-72 80-72s80 28.9 80 72c0 8.5-1.6 16.6-4.5 24l52.5 0c4.4 0 8-3.6 8-8l0-129.3c0-17 13.8-30.7 30.7-30.7 11.1 0 20.3 5.8 25.6 13.6 5.5 8 11.4 10.4 15.6 10.4 4 0 9.5-2.1 14.7-9.1s9.3-17.9 9.3-30.9-4-23.8-9.3-30.9-10.7-9.1-14.7-9.1c-4.2 0-10.1 2.4-15.6 10.4-5.3 7.8-14.6 13.6-25.6 13.6-17 0-30.7-13.8-30.7-30.7l0-81.3c0-4.4-3.6-8-8-8l-81.3 0c-17 0-30.7-13.8-30.7-30.7 0-11.1 5.8-20.3 13.6-25.6 8-5.5 10.4-11.4 10.4-15.6 0-4-2.1-9.5-9.1-14.7S245 48 232 48 208.2 52 201.1 57.3zM172.3 18.9C188.5 6.8 209.6 0 232 0S275.5 6.8 291.7 18.9 320 49.5 320 72c0 8.6-1.8 16.7-4.9 24L360 96c30.9 0 56 25.1 56 56l0 44.9c7.3-3.1 15.4-4.9 24-4.9 22.5 0 41 12.2 53.1 28.3s18.9 37.3 18.9 59.7-6.8 43.5-18.9 59.7-30.6 28.3-53.1 28.3c-8.6 0-16.7-1.8-24-4.9l0 92.9c0 30.9-25.1 56-56 56l-78.1 0c-18.7 0-33.9-15.2-33.9-33.9 0-10.1 4.5-18.5 9.9-24.2 4.2-4.3 6.1-9.2 6.1-13.9 0-9.9-10.7-24-32-24s-32 14.1-32 24c0 4.7 1.9 9.5 6.1 13.9 5.5 5.7 9.9 14.1 9.9 24.2 0 18.7-15.2 33.9-33.9 33.9L56 512c-30.9 0-56-25.1-56-56L0 329.9c0-18.7 15.2-33.9 33.9-33.9 10.1 0 18.5 4.5 24.2 9.9 4.3 4.2 9.2 6.1 13.9 6.1 9.9 0 24-10.7 24-32s-14.1-32-24-32c-4.7 0-9.5 1.9-13.9 6.1-5.7 5.5-14.1 9.9-24.2 9.9-18.7 0-33.9-15.2-33.9-33.9L0 152c0-30.9 25.1-56 56-56l92.9 0c-3.1-7.3-4.9-15.4-4.9-24 0-22.5 12.2-41 28.3-53.1z",{"w":380,"h":380,"d":1162},"M488 32c-13.3 0-24 10.7-24 24l0 13.5-416 117 0-2.5c0-13.3-10.7-24-24-24S0 170.7 0 184L0 328c0 13.3 10.7 24 24 24s24-10.7 24-24l0-2.5 86.3 24.3c-4.1 10.6-6.3 22.2-6.3 34.2 0 53 43 96 96 96 47 0 86.2-33.8 94.4-78.5l145.6 41 0 13.5c0 13.3 10.7 24 24 24s24-10.7 24-24l0-400c0-13.3-10.7-24-24-24zM464 392.6l-416-117 0-39.3 416-117 0 273.3zm-192.2-4.2c-2.2 24.4-22.8 43.6-47.8 43.6-26.5 0-48-21.5-48-48 0-7.6 1.8-14.8 4.9-21.1l90.9 25.6z",{"w":379,"h":380,"d":1164},"M248 24c0-13.3-10.7-24-24-24s-24 10.7-24 24l0 246.1-63-63c-9.4-9.4-24.6-9.4-33.9 0s-9.4 24.6 0 33.9L207 345c9.4 9.4 24.6 9.4 33.9 0L345 241c9.4-9.4 9.4-24.6 0-33.9s-24.6-9.4-33.9 0l-63 63 0-246.1zM66.2 272L64 272c-35.3 0-64 28.7-64 64l0 80c0 35.3 28.7 64 64 64l320 0c35.3 0 64-28.7 64-64l0-80c0-35.3-28.7-64-64-64l-2.2 0-48 48 50.2 0c8.8 0 16 7.2 16 16l0 80c0 8.8-7.2 16-16 16L64 432c-8.8 0-16-7.2-16-16l0-80c0-8.8 7.2-16 16-16l50.2 0-48-48zM368 376a24 24 0 1 0 -48 0 24 24 0 1 0 48 0z",{"w":398,"h":380,"d":1166},"M232 0c25 0 47 12.7 59.9 32L320 32c35.3 0 64 28.7 64 64l0 352c0 35.3-28.7 64-64 64L64 512c-35.3 0-64-28.7-64-64L0 96C0 60.7 28.7 32 64 32l28.1 0C105 12.7 127 0 152 0l80 0zM64 80c-8.8 0-16 7.2-16 16l0 352c0 8.8 7.2 16 16 16l256 0c8.8 0 16-7.2 16-16l0-352c0-8.8-7.2-16-16-16l-16.4 0c-4 36-34.5 64-71.6 64l-80 0c-37.1 0-67.6-28-71.6-64L64 80zM228.7 239.9c7.8-10.7 22.8-13.1 33.5-5.3s13.1 22.8 5.3 33.5L191.4 372.8c-4.2 5.7-10.7 9.3-17.8 9.8-7.1 .5-14-2.2-18.9-7.3l-35.9-37.2c-9.2-9.5-8.9-24.7 .6-33.9 9.5-9.2 24.7-9 33.9 .6l16.1 16.6 59.3-81.6zM152 48c-13.3 0-24 10.7-24 24s10.7 24 24 24l80 0c13.3 0 24-10.7 24-24s-10.7-24-24-24l-80 0z",{"w":379,"h":380,"d":1168},"M102.4 4.8c-7.3-5.5-17-6.3-25.1-2.3S64 14.9 64 24l0 400c0 10.3 6.6 19.5 16.4 22.8s20.6-.1 26.8-8.4l96.7-129 94.6 189.3c5.9 11.9 20.3 16.7 32.2 10.7s16.7-20.3 10.7-32.2l-94.7-189.3 161.2 0c10.3 0 19.5-6.6 22.8-16.4s-.1-20.6-8.4-26.8L102.4 4.8zM112 352l0-280 224 168-128 0c-7.6 0-14.7 3.6-19.2 9.6L112 352z",{"w":380,"h":380,"d":1170},"M181.9 483.3c-22.1-3.1-42.7-13.2-58.7-28.7L62.8 396.2C46.8 380.6 36 360.3 32.2 338.3L17.6 255.5c-3.9-22.1-.7-44.8 9.1-64.9L63.4 115c9.8-20.1 25.7-36.6 45.4-47.2l74-39.5c19.7-10.5 42.3-14.5 64.4-11.4 5.4 .8 9.5 5.2 10.3 10.6 8.4 54.7 51.5 98.1 106.2 106.8 7.7 1.2 13.9 7.1 15.7 14.6 11.6 50.3 52.9 89.2 104.5 97.4 5.3 .8 9.7 4.8 10.6 10.1 3.9 22.1 .7 44.8-9.1 64.9L448.6 397c-9.8 20.1-25.7 36.6-45.4 47.2l-74 39.5c-19.7 10.5-42.3 14.5-64.4 11.4l-83-11.7zM205.4 70.8l-74 39.5C120.7 116 112 125 106.6 136L69.9 211.6c-5.4 11-7.1 23.5-5 35.6L79.4 330c2.1 12.1 8 23.2 16.8 31.7l60.3 58.4c8.8 8.5 20 14 32 15.7l83 11.7c12 1.7 24.3-.5 35.1-6.2l74-39.5C391.3 396 400 387 405.4 376l36.7-75.5c2.2-4.5 3.7-9.1 4.7-13.9-51-17.5-91.4-57.7-109.1-108.7-56.1-15.2-101-57.5-120-111.9-4.3 1.1-8.4 2.8-12.4 4.9zM208 144a32 32 0 1 1 0 64 32 32 0 1 1 0-64zM176 304a32 32 0 1 1 0 64 32 32 0 1 1 0-64zm128 0a32 32 0 1 1 64 0 32 32 0 1 1 -64 0z",{"w":380,"h":380,"d":1172},"M208 176c0-70.7 57.3-128 128-128s128 57.3 128 128-57.3 128-128 128c-10.4 0-20.5-1.2-30.1-3.6-8.1-2-16.7 .5-22.6 6.4L254.1 336 200 336c-13.3 0-24 10.7-24 24l0 40-40 0c-13.3 0-24 10.7-24 24l0 40-64 0 0-78.1 157.2-157.2c5.9-5.9 8.3-14.5 6.4-22.6-2.3-9.6-3.6-19.7-3.6-30.1zM336 0c-97.2 0-176 78.8-176 176 0 9.5 .7 18.8 2.2 27.9L7 359c-4.5 4.5-7 10.6-7 17L0 488c0 13.3 10.7 24 24 24l112 0c13.3 0 24-10.7 24-24l0-40 40 0c13.3 0 24-10.7 24-24l0-40 40 0c6.4 0 12.5-2.5 17-7l27.2-27.2c9.1 1.4 18.4 2.2 27.9 2.2 97.2 0 176-78.8 176-176S433.2 0 336 0zm32 176a32 32 0 1 0 0-64 32 32 0 1 0 0 64z",[1174,1189,1202,1215,1227,1240,1253,1266],{"createdBy":425,"createdDate":1175,"data":1176,"folders":1179,"id":1180,"lastUpdateSource":60,"lastUpdated":1181,"lastUpdatedBy":425,"meta":1182,"modelId":1184,"name":1178,"published":13,"query":1185,"stageModifiedSincePublish":6,"testRatio":31,"variations":1186,"firstPublished":1187,"rev":1188},1789658775871,{"color":1177,"name":1178},"#666666","Other",[],"08c1b772913b46ab9c1f24a635afe924",1789659205359,{"breakpoints":1183,"hasAutosaves":6,"hasErrors":6,"kind":20,"lastPreviewUrl":21},{"medium":16,"small":17,"xsmall":18},"091d8baaa7f740e58842de2f035a4e8b",[],{},1789659205354,"6aeapzz5gsy",{"createdBy":425,"createdDate":1190,"data":1191,"folders":1194,"id":1195,"lastUpdateSource":60,"lastUpdated":1196,"lastUpdatedBy":425,"meta":1197,"modelId":1184,"name":1193,"published":13,"query":1199,"stageModifiedSincePublish":6,"testRatio":31,"variations":1200,"firstPublished":1201,"rev":1188},1789659220443,{"color":1192,"name":1193},"#0DB0E0","OAuth supply chain",[],"61b1060ec3fb43498fd3d30bdb294f9b",1789659238920,{"breakpoints":1198,"hasAutosaves":6,"hasErrors":6,"kind":20,"lastPreviewUrl":21},{"medium":16,"small":17,"xsmall":18},[],{},1789659238913,{"createdBy":425,"createdDate":1203,"data":1204,"folders":1207,"id":1208,"lastUpdateSource":60,"lastUpdated":1209,"lastUpdatedBy":425,"meta":1210,"modelId":1184,"name":1206,"published":13,"query":1212,"stageModifiedSincePublish":6,"testRatio":31,"variations":1213,"firstPublished":1214,"rev":1188},1789659251281,{"color":1205,"name":1206},"#FD7452","Consent & device code phishing",[],"9ad487971b314de483af1b6db8902113",1789659264041,{"breakpoints":1211,"hasAutosaves":19,"hasErrors":6,"kind":20,"lastPreviewUrl":21},{"medium":16,"small":17,"xsmall":18},[],{},1789659264036,{"createdBy":425,"createdDate":1216,"data":1217,"folders":1219,"id":1220,"lastUpdateSource":60,"lastUpdated":1221,"lastUpdatedBy":425,"meta":1222,"modelId":1184,"name":718,"published":13,"query":1224,"stageModifiedSincePublish":6,"testRatio":31,"variations":1225,"firstPublished":1226,"rev":1188},1789659273915,{"color":1218,"name":718},"#FFB65C",[],"be62c987dd3a4d6fad72c91c41edbe11",1789659285908,{"breakpoints":1223,"hasAutosaves":6,"hasErrors":6,"kind":20,"lastPreviewUrl":21},{"medium":16,"small":17,"xsmall":18},[],{},1789659285895,{"createdBy":425,"createdDate":1228,"data":1229,"folders":1232,"id":1233,"lastUpdateSource":60,"lastUpdated":1234,"lastUpdatedBy":425,"meta":1235,"modelId":1184,"name":1231,"published":13,"query":1237,"stageModifiedSincePublish":6,"testRatio":31,"variations":1238,"firstPublished":1239,"rev":1188},1789659299401,{"color":1230,"name":1231},"#724FFF","AitM phishing",[],"ce2acd6ab2594adfa3b6226d5aa91850",1789659313073,{"breakpoints":1236,"hasAutosaves":6,"hasErrors":6,"kind":20,"lastPreviewUrl":21},{"medium":16,"small":17,"xsmall":18},[],{},1789659313068,{"createdBy":425,"createdDate":1241,"data":1242,"folders":1245,"id":1246,"lastUpdateSource":60,"lastUpdated":1247,"lastUpdatedBy":425,"meta":1248,"modelId":1184,"name":1244,"published":13,"query":1250,"stageModifiedSincePublish":6,"testRatio":31,"variations":1251,"firstPublished":1252,"rev":1188},1789659330619,{"color":1243,"name":1244},"#EE4323","Help desk vishing",[],"2279889718ed4507a9bb9d64690dad62",1789659343765,{"breakpoints":1249,"hasAutosaves":6,"hasErrors":6,"kind":20,"lastPreviewUrl":21},{"medium":16,"small":17,"xsmall":18},[],{},1789659343760,{"createdBy":425,"createdDate":1254,"data":1255,"folders":1258,"id":1259,"lastUpdateSource":60,"lastUpdated":1260,"lastUpdatedBy":425,"meta":1261,"modelId":1184,"name":1257,"published":13,"query":1263,"stageModifiedSincePublish":6,"testRatio":31,"variations":1264,"firstPublished":1265,"rev":1188},1789659360123,{"color":1256,"name":1257},"#EB999D","Phishing*",[],"cafb7d1f71cb4975a5120041d87ad6df",1789672173489,{"breakpoints":1262,"hasAutosaves":6,"hasErrors":6,"kind":20,"lastPreviewUrl":21},{"medium":16,"small":17,"xsmall":18},[],{},1789659373886,{"createdBy":425,"createdDate":1267,"data":1268,"folders":1271,"id":1272,"lastUpdateSource":60,"lastUpdated":1273,"lastUpdatedBy":425,"meta":1274,"modelId":1184,"name":1270,"published":13,"query":1276,"stageModifiedSincePublish":6,"testRatio":31,"variations":1277,"firstPublished":1278,"rev":1188},1789659392555,{"color":1269,"name":1270},"#6FBD61","Stolen credentials",[],"3cf344b126d544ceb4273c344a99819e",1789659407553,{"breakpoints":1275,"hasAutosaves":6,"hasErrors":6,"kind":20,"lastPreviewUrl":21},{"medium":16,"small":17,"xsmall":18},[],{},1789659407549,[1280,1338,1387,1445,1500,1529,1557,1605,1644,1674,1693,1712,1767,1813,1841,1869,1888,1916,1935,1955,1983,2011,2039,2067,2086,2105],{"createdDate":1281,"data":1282,"id":1327,"lastUpdated":1328,"modelId":1329,"name":1330,"published":13,"createdBy":425,"folders":1331,"lastUpdateSource":60,"lastUpdatedBy":425,"meta":1332,"query":1334,"stageModifiedSincePublish":6,"testRatio":31,"variations":1335,"firstPublished":1336,"rev":1337},1789724670476,{"month":1283,"segments":1284,"year":962},6,[1285,1296,1307,1317],{"count":45,"technique":1286},{"@type":105,"id":1180,"model":1287,"value":1288},"breach-technique",{"createdDate":1175,"id":1180,"name":1178,"modelId":1184,"published":13,"stageModifiedSincePublish":6,"query":1289,"data":1290,"variations":1291,"lastUpdated":1181,"firstPublished":1187,"testRatio":31,"createdBy":425,"lastUpdatedBy":425,"folders":1292,"lastUpdateSource":60,"meta":1293,"rev":1295},[],{"name":1178,"color":1177},{},[],{"breakpoints":1294,"hasErrors":6,"kind":20,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},"c2lrurbcrkk",{"count":1297,"technique":1298},12,{"@type":105,"id":1195,"model":1287,"value":1299},{"createdDate":1190,"id":1195,"name":1193,"modelId":1184,"published":13,"stageModifiedSincePublish":6,"query":1300,"data":1301,"variations":1302,"lastUpdated":1196,"firstPublished":1201,"testRatio":31,"createdBy":425,"lastUpdatedBy":425,"folders":1303,"lastUpdateSource":60,"meta":1304,"rev":1306},[],{"name":1193,"color":1192},{},[],{"breakpoints":1305,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},"q8lr75q9wh",{"count":31,"technique":1308},{"@type":105,"id":1233,"model":1287,"value":1309},{"createdDate":1228,"id":1233,"name":1231,"modelId":1184,"published":13,"stageModifiedSincePublish":6,"query":1310,"data":1311,"variations":1312,"lastUpdated":1234,"firstPublished":1239,"testRatio":31,"createdBy":425,"lastUpdatedBy":425,"folders":1313,"lastUpdateSource":60,"meta":1314,"rev":1316},[],{"name":1231,"color":1230},{},[],{"breakpoints":1315,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},"y4msqvlhkm",{"count":31,"technique":1318},{"@type":105,"id":1259,"model":1287,"value":1319},{"createdDate":1254,"id":1259,"name":1257,"modelId":1184,"published":13,"stageModifiedSincePublish":6,"query":1320,"data":1321,"variations":1322,"lastUpdated":1260,"firstPublished":1265,"testRatio":31,"createdBy":425,"lastUpdatedBy":425,"folders":1323,"lastUpdateSource":60,"meta":1324,"rev":1326},[],{"color":1256,"name":1257},{},[],{"breakpoints":1325,"lastPreviewUrl":21,"hasErrors":6,"kind":20,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},"x4na76d2xc","c78b4d7cdf7b46638296c404bb2e0a9a",1789724740191,"c4d4a349c83f4a2ebfdabd936626a207","2026-06",[],{"breakpoints":1333,"hasAutosaves":19,"hasErrors":6,"kind":20},{"medium":16,"small":17,"xsmall":18},[],{},1789724759065,"pa7sqn9ax3",{"createdDate":1339,"data":1340,"id":1381,"lastUpdated":1382,"modelId":1329,"name":1383,"published":13,"firstPublished":1384,"meta":1385,"query":1386,"rev":1337},1789724670125,{"month":1341,"segments":1342,"year":962},5,[1343,1353,1362,1371],{"count":1344,"technique":1345},3,{"@type":105,"id":1180,"model":1287,"value":1346},{"createdDate":1175,"id":1180,"name":1178,"modelId":1184,"published":13,"stageModifiedSincePublish":6,"query":1347,"data":1348,"variations":1349,"lastUpdated":1181,"firstPublished":1187,"testRatio":31,"createdBy":425,"lastUpdatedBy":425,"folders":1350,"lastUpdateSource":60,"meta":1351,"rev":1295},[],{"name":1178,"color":1177},{},[],{"breakpoints":1352,"hasErrors":6,"kind":20,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},{"count":31,"technique":1354},{"@type":105,"id":1233,"model":1287,"value":1355},{"createdDate":1228,"id":1233,"name":1231,"modelId":1184,"published":13,"stageModifiedSincePublish":6,"query":1356,"data":1357,"variations":1358,"lastUpdated":1234,"firstPublished":1239,"testRatio":31,"createdBy":425,"lastUpdatedBy":425,"folders":1359,"lastUpdateSource":60,"meta":1360,"rev":1316},[],{"name":1231,"color":1230},{},[],{"breakpoints":1361,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},{"count":31,"technique":1363},{"@type":105,"id":1259,"model":1287,"value":1364},{"createdDate":1254,"id":1259,"name":1257,"modelId":1184,"published":13,"stageModifiedSincePublish":6,"query":1365,"data":1366,"variations":1367,"lastUpdated":1260,"firstPublished":1265,"testRatio":31,"createdBy":425,"lastUpdatedBy":425,"folders":1368,"lastUpdateSource":60,"meta":1369,"rev":1326},[],{"color":1256,"name":1257},{},[],{"breakpoints":1370,"lastPreviewUrl":21,"hasErrors":6,"kind":20,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},{"count":31,"technique":1372},{"@type":105,"id":1272,"model":1287,"value":1373},{"createdDate":1267,"id":1272,"name":1270,"modelId":1184,"published":13,"stageModifiedSincePublish":6,"query":1374,"data":1375,"variations":1376,"lastUpdated":1273,"firstPublished":1278,"testRatio":31,"createdBy":425,"lastUpdatedBy":425,"folders":1377,"lastUpdateSource":60,"meta":1378,"rev":1380},[],{"name":1270,"color":1269},{},[],{"breakpoints":1379,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},"7ih56xcvvby","87c55fdd6d154c5a8c0a3f81d1e69a61",1789724670105,"2026-05",1789724759082,{},[],{"createdDate":1388,"data":1389,"id":1439,"lastUpdated":1440,"modelId":1329,"name":1441,"published":13,"firstPublished":1442,"meta":1443,"query":1444,"rev":1337},1789724669764,{"month":1390,"segments":1391,"year":962},4,[1392,1401,1410,1420,1429],{"count":45,"technique":1393},{"@type":105,"id":1180,"model":1287,"value":1394},{"createdDate":1175,"id":1180,"name":1178,"modelId":1184,"published":13,"stageModifiedSincePublish":6,"query":1395,"data":1396,"variations":1397,"lastUpdated":1181,"firstPublished":1187,"testRatio":31,"createdBy":425,"lastUpdatedBy":425,"folders":1398,"lastUpdateSource":60,"meta":1399,"rev":1295},[],{"name":1178,"color":1177},{},[],{"breakpoints":1400,"hasErrors":6,"kind":20,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},{"count":1341,"technique":1402},{"@type":105,"id":1195,"model":1287,"value":1403},{"createdDate":1190,"id":1195,"name":1193,"modelId":1184,"published":13,"stageModifiedSincePublish":6,"query":1404,"data":1405,"variations":1406,"lastUpdated":1196,"firstPublished":1201,"testRatio":31,"createdBy":425,"lastUpdatedBy":425,"folders":1407,"lastUpdateSource":60,"meta":1408,"rev":1306},[],{"name":1193,"color":1192},{},[],{"breakpoints":1409,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},{"count":31,"technique":1411},{"@type":105,"id":1220,"model":1287,"value":1412},{"createdDate":1216,"id":1220,"name":718,"modelId":1184,"published":13,"meta":1413,"stageModifiedSincePublish":6,"query":1415,"data":1416,"variations":1417,"lastUpdated":1221,"firstPublished":1226,"testRatio":31,"createdBy":425,"lastUpdatedBy":425,"folders":1418,"lastUpdateSource":60,"rev":1419},{"breakpoints":1414,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},[],{"name":718,"color":1218},{},[],"m6qrkg00upn",{"count":31,"technique":1421},{"@type":105,"id":1233,"model":1287,"value":1422},{"createdDate":1228,"id":1233,"name":1231,"modelId":1184,"published":13,"stageModifiedSincePublish":6,"query":1423,"data":1424,"variations":1425,"lastUpdated":1234,"firstPublished":1239,"testRatio":31,"createdBy":425,"lastUpdatedBy":425,"folders":1426,"lastUpdateSource":60,"meta":1427,"rev":1316},[],{"name":1231,"color":1230},{},[],{"breakpoints":1428,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},{"count":1430,"technique":1431},11,{"@type":105,"id":1259,"model":1287,"value":1432},{"createdDate":1254,"id":1259,"name":1257,"modelId":1184,"published":13,"stageModifiedSincePublish":6,"query":1433,"data":1434,"variations":1435,"lastUpdated":1260,"firstPublished":1265,"testRatio":31,"createdBy":425,"lastUpdatedBy":425,"folders":1436,"lastUpdateSource":60,"meta":1437,"rev":1326},[],{"color":1256,"name":1257},{},[],{"breakpoints":1438,"lastPreviewUrl":21,"hasErrors":6,"kind":20,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},"8b01b54e31b748868dd9e696062ef793",1789724669747,"2026-04",1789724759093,{},[],{"createdDate":1446,"data":1447,"id":1494,"lastUpdated":1495,"modelId":1329,"name":1496,"published":13,"firstPublished":1497,"meta":1498,"query":1499,"rev":1337},1789724669332,{"month":1344,"segments":1448,"year":962},[1449,1458,1467,1476,1485],{"count":45,"technique":1450},{"@type":105,"id":1180,"model":1287,"value":1451},{"createdDate":1175,"id":1180,"name":1178,"modelId":1184,"published":13,"stageModifiedSincePublish":6,"query":1452,"data":1453,"variations":1454,"lastUpdated":1181,"firstPublished":1187,"testRatio":31,"createdBy":425,"lastUpdatedBy":425,"folders":1455,"lastUpdateSource":60,"meta":1456,"rev":1295},[],{"name":1178,"color":1177},{},[],{"breakpoints":1457,"hasErrors":6,"kind":20,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},{"count":31,"technique":1459},{"@type":105,"id":1195,"model":1287,"value":1460},{"createdDate":1190,"id":1195,"name":1193,"modelId":1184,"published":13,"stageModifiedSincePublish":6,"query":1461,"data":1462,"variations":1463,"lastUpdated":1196,"firstPublished":1201,"testRatio":31,"createdBy":425,"lastUpdatedBy":425,"folders":1464,"lastUpdateSource":60,"meta":1465,"rev":1306},[],{"name":1193,"color":1192},{},[],{"breakpoints":1466,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},{"count":45,"technique":1468},{"@type":105,"id":1233,"model":1287,"value":1469},{"createdDate":1228,"id":1233,"name":1231,"modelId":1184,"published":13,"stageModifiedSincePublish":6,"query":1470,"data":1471,"variations":1472,"lastUpdated":1234,"firstPublished":1239,"testRatio":31,"createdBy":425,"lastUpdatedBy":425,"folders":1473,"lastUpdateSource":60,"meta":1474,"rev":1316},[],{"name":1231,"color":1230},{},[],{"breakpoints":1475,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},{"count":45,"technique":1477},{"@type":105,"id":1259,"model":1287,"value":1478},{"createdDate":1254,"id":1259,"name":1257,"modelId":1184,"published":13,"stageModifiedSincePublish":6,"query":1479,"data":1480,"variations":1481,"lastUpdated":1260,"firstPublished":1265,"testRatio":31,"createdBy":425,"lastUpdatedBy":425,"folders":1482,"lastUpdateSource":60,"meta":1483,"rev":1326},[],{"color":1256,"name":1257},{},[],{"breakpoints":1484,"lastPreviewUrl":21,"hasErrors":6,"kind":20,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},{"count":45,"technique":1486},{"@type":105,"id":1272,"model":1287,"value":1487},{"createdDate":1267,"id":1272,"name":1270,"modelId":1184,"published":13,"stageModifiedSincePublish":6,"query":1488,"data":1489,"variations":1490,"lastUpdated":1273,"firstPublished":1278,"testRatio":31,"createdBy":425,"lastUpdatedBy":425,"folders":1491,"lastUpdateSource":60,"meta":1492,"rev":1380},[],{"name":1270,"color":1269},{},[],{"breakpoints":1493,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},"39d77416cc5f48c89c09071c58ecabcc",1789724669307,"2026-03",1789724759119,{},[],{"createdDate":1501,"data":1502,"id":1523,"lastUpdated":1524,"modelId":1329,"name":1525,"published":13,"firstPublished":1526,"meta":1527,"query":1528,"rev":1337},1789724668907,{"month":45,"segments":1503,"year":962},[1504,1513],{"count":45,"technique":1505},{"@type":105,"id":1180,"model":1287,"value":1506},{"createdDate":1175,"id":1180,"name":1178,"modelId":1184,"published":13,"stageModifiedSincePublish":6,"query":1507,"data":1508,"variations":1509,"lastUpdated":1181,"firstPublished":1187,"testRatio":31,"createdBy":425,"lastUpdatedBy":425,"folders":1510,"lastUpdateSource":60,"meta":1511,"rev":1295},[],{"name":1178,"color":1177},{},[],{"breakpoints":1512,"hasErrors":6,"kind":20,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},{"count":1514,"technique":1515},7,{"@type":105,"id":1259,"model":1287,"value":1516},{"createdDate":1254,"id":1259,"name":1257,"modelId":1184,"published":13,"stageModifiedSincePublish":6,"query":1517,"data":1518,"variations":1519,"lastUpdated":1260,"firstPublished":1265,"testRatio":31,"createdBy":425,"lastUpdatedBy":425,"folders":1520,"lastUpdateSource":60,"meta":1521,"rev":1326},[],{"color":1256,"name":1257},{},[],{"breakpoints":1522,"lastPreviewUrl":21,"hasErrors":6,"kind":20,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},"c73bf3c62a94411db061f2e1e28c0c4f",1789724668876,"2026-02",1789724759145,{},[],{"createdDate":1530,"data":1531,"id":1551,"lastUpdated":1552,"modelId":1329,"name":1553,"published":13,"firstPublished":1554,"meta":1555,"query":1556,"rev":1337},1789724668466,{"month":31,"segments":1532,"year":962},[1533,1542],{"count":31,"technique":1534},{"@type":105,"id":1195,"model":1287,"value":1535},{"createdDate":1190,"id":1195,"name":1193,"modelId":1184,"published":13,"stageModifiedSincePublish":6,"query":1536,"data":1537,"variations":1538,"lastUpdated":1196,"firstPublished":1201,"testRatio":31,"createdBy":425,"lastUpdatedBy":425,"folders":1539,"lastUpdateSource":60,"meta":1540,"rev":1306},[],{"name":1193,"color":1192},{},[],{"breakpoints":1541,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},{"count":1514,"technique":1543},{"@type":105,"id":1233,"model":1287,"value":1544},{"createdDate":1228,"id":1233,"name":1231,"modelId":1184,"published":13,"stageModifiedSincePublish":6,"query":1545,"data":1546,"variations":1547,"lastUpdated":1234,"firstPublished":1239,"testRatio":31,"createdBy":425,"lastUpdatedBy":425,"folders":1548,"lastUpdateSource":60,"meta":1549,"rev":1316},[],{"name":1231,"color":1230},{},[],{"breakpoints":1550,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},"06b00a0d1162458882071d3555b80ce6",1789724668448,"2026-01",1789724759169,{},[],{"createdDate":1558,"data":1559,"id":1599,"lastUpdated":1600,"modelId":1329,"name":1601,"published":13,"firstPublished":1602,"meta":1603,"query":1604,"rev":1337},1789724667514,{"month":1430,"segments":1560,"year":1598},[1561,1570,1579,1589],{"count":31,"technique":1562},{"@type":105,"id":1195,"model":1287,"value":1563},{"createdDate":1190,"id":1195,"name":1193,"modelId":1184,"published":13,"stageModifiedSincePublish":6,"query":1564,"data":1565,"variations":1566,"lastUpdated":1196,"firstPublished":1201,"testRatio":31,"createdBy":425,"lastUpdatedBy":425,"folders":1567,"lastUpdateSource":60,"meta":1568,"rev":1306},[],{"name":1193,"color":1192},{},[],{"breakpoints":1569,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},{"count":31,"technique":1571},{"@type":105,"id":1233,"model":1287,"value":1572},{"createdDate":1228,"id":1233,"name":1231,"modelId":1184,"published":13,"stageModifiedSincePublish":6,"query":1573,"data":1574,"variations":1575,"lastUpdated":1234,"firstPublished":1239,"testRatio":31,"createdBy":425,"lastUpdatedBy":425,"folders":1576,"lastUpdateSource":60,"meta":1577,"rev":1316},[],{"name":1231,"color":1230},{},[],{"breakpoints":1578,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},{"count":31,"technique":1580},{"@type":105,"id":1246,"model":1287,"value":1581},{"createdDate":1241,"id":1246,"name":1244,"modelId":1184,"published":13,"stageModifiedSincePublish":6,"query":1582,"data":1583,"variations":1584,"lastUpdated":1247,"firstPublished":1252,"testRatio":31,"createdBy":425,"lastUpdatedBy":425,"folders":1585,"lastUpdateSource":60,"meta":1586,"rev":1588},[],{"name":1244,"color":1243},{},[],{"breakpoints":1587,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},"itk9wlf60ii",{"count":31,"technique":1590},{"@type":105,"id":1272,"model":1287,"value":1591},{"createdDate":1267,"id":1272,"name":1270,"modelId":1184,"published":13,"stageModifiedSincePublish":6,"query":1592,"data":1593,"variations":1594,"lastUpdated":1273,"firstPublished":1278,"testRatio":31,"createdBy":425,"lastUpdatedBy":425,"folders":1595,"lastUpdateSource":60,"meta":1596,"rev":1380},[],{"name":1270,"color":1269},{},[],{"breakpoints":1597,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},2025,"5b504945b65f48e0bd3478de2d4347e3",1789724667488,"2025-11",1789724759189,{},[],{"createdDate":1606,"data":1607,"id":1638,"lastUpdated":1639,"modelId":1329,"name":1640,"published":13,"firstPublished":1641,"meta":1642,"query":1643,"rev":1337},1789724666999,{"month":1608,"segments":1609,"year":1598},9,[1610,1619,1629],{"count":45,"technique":1611},{"@type":105,"id":1195,"model":1287,"value":1612},{"createdDate":1190,"id":1195,"name":1193,"modelId":1184,"published":13,"stageModifiedSincePublish":6,"query":1613,"data":1614,"variations":1615,"lastUpdated":1196,"firstPublished":1201,"testRatio":31,"createdBy":425,"lastUpdatedBy":425,"folders":1616,"lastUpdateSource":60,"meta":1617,"rev":1306},[],{"name":1193,"color":1192},{},[],{"breakpoints":1618,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},{"count":31,"technique":1620},{"@type":105,"id":1208,"model":1287,"value":1621},{"createdDate":1203,"id":1208,"name":1206,"modelId":1184,"published":13,"stageModifiedSincePublish":6,"query":1622,"data":1623,"variations":1624,"lastUpdated":1209,"firstPublished":1214,"testRatio":31,"createdBy":425,"lastUpdatedBy":425,"folders":1625,"lastUpdateSource":60,"meta":1626,"rev":1628},[],{"name":1206,"color":1205},{},[],{"breakpoints":1627,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":19},{"xsmall":18,"small":17,"medium":16},"7zka3up4t73",{"count":45,"technique":1630},{"@type":105,"id":1246,"model":1287,"value":1631},{"createdDate":1241,"id":1246,"name":1244,"modelId":1184,"published":13,"stageModifiedSincePublish":6,"query":1632,"data":1633,"variations":1634,"lastUpdated":1247,"firstPublished":1252,"testRatio":31,"createdBy":425,"lastUpdatedBy":425,"folders":1635,"lastUpdateSource":60,"meta":1636,"rev":1588},[],{"name":1244,"color":1243},{},[],{"breakpoints":1637,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},"aa58f38f9ef44343a6468cbf3acbaa23",1789724666921,"2025-09",1789724759209,{},[],{"createdDate":1645,"data":1646,"id":1668,"lastUpdated":1669,"modelId":1329,"name":1670,"published":13,"firstPublished":1671,"meta":1672,"query":1673,"rev":1337},1789724666522,{"month":1647,"segments":1648,"year":1598},8,[1649,1659],{"count":1650,"technique":1651},15,{"@type":105,"id":1195,"model":1287,"value":1652},{"createdDate":1190,"id":1195,"name":1193,"modelId":1184,"published":13,"stageModifiedSincePublish":6,"query":1653,"data":1654,"variations":1655,"lastUpdated":1196,"firstPublished":1201,"testRatio":31,"createdBy":425,"lastUpdatedBy":425,"folders":1656,"lastUpdateSource":60,"meta":1657,"rev":1306},[],{"name":1193,"color":1192},{},[],{"breakpoints":1658,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},{"count":1647,"technique":1660},{"@type":105,"id":1208,"model":1287,"value":1661},{"createdDate":1203,"id":1208,"name":1206,"modelId":1184,"published":13,"stageModifiedSincePublish":6,"query":1662,"data":1663,"variations":1664,"lastUpdated":1209,"firstPublished":1214,"testRatio":31,"createdBy":425,"lastUpdatedBy":425,"folders":1665,"lastUpdateSource":60,"meta":1666,"rev":1628},[],{"name":1206,"color":1205},{},[],{"breakpoints":1667,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":19},{"xsmall":18,"small":17,"medium":16},"924aae7580474c19aa7d6aa72c03c2c5",1789724666492,"2025-08",1789724759224,{},[],{"createdDate":1675,"data":1676,"id":1687,"lastUpdated":1688,"modelId":1329,"name":1689,"published":13,"firstPublished":1690,"meta":1691,"query":1692,"rev":1337},1789724666090,{"month":1514,"segments":1677,"year":1598},[1678],{"count":1390,"technique":1679},{"@type":105,"id":1208,"model":1287,"value":1680},{"createdDate":1203,"id":1208,"name":1206,"modelId":1184,"published":13,"stageModifiedSincePublish":6,"query":1681,"data":1682,"variations":1683,"lastUpdated":1209,"firstPublished":1214,"testRatio":31,"createdBy":425,"lastUpdatedBy":425,"folders":1684,"lastUpdateSource":60,"meta":1685,"rev":1628},[],{"name":1206,"color":1205},{},[],{"breakpoints":1686,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":19},{"xsmall":18,"small":17,"medium":16},"c3990b7a471447069272c6ebf32689c0",1789724666070,"2025-07",1789724759239,{},[],{"createdDate":1694,"data":1695,"id":1706,"lastUpdated":1707,"modelId":1329,"name":1708,"published":13,"firstPublished":1709,"meta":1710,"query":1711,"rev":1337},1789724665714,{"month":1283,"segments":1696,"year":1598},[1697],{"count":1283,"technique":1698},{"@type":105,"id":1246,"model":1287,"value":1699},{"createdDate":1241,"id":1246,"name":1244,"modelId":1184,"published":13,"stageModifiedSincePublish":6,"query":1700,"data":1701,"variations":1702,"lastUpdated":1247,"firstPublished":1252,"testRatio":31,"createdBy":425,"lastUpdatedBy":425,"folders":1703,"lastUpdateSource":60,"meta":1704,"rev":1588},[],{"name":1244,"color":1243},{},[],{"breakpoints":1705,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},"0efc06a1266345e49e9c9a85abe6fcaf",1789724665688,"2025-06",1789724759246,{},[],{"createdDate":1713,"data":1714,"id":1761,"lastUpdated":1762,"modelId":1329,"name":1763,"published":13,"firstPublished":1764,"meta":1765,"query":1766,"rev":1337},1789724665220,{"month":1341,"segments":1715,"year":1598},[1716,1725,1734,1743,1752],{"count":45,"technique":1717},{"@type":105,"id":1180,"model":1287,"value":1718},{"createdDate":1175,"id":1180,"name":1178,"modelId":1184,"published":13,"stageModifiedSincePublish":6,"query":1719,"data":1720,"variations":1721,"lastUpdated":1181,"firstPublished":1187,"testRatio":31,"createdBy":425,"lastUpdatedBy":425,"folders":1722,"lastUpdateSource":60,"meta":1723,"rev":1295},[],{"name":1178,"color":1177},{},[],{"breakpoints":1724,"hasErrors":6,"kind":20,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},{"count":31,"technique":1726},{"@type":105,"id":1208,"model":1287,"value":1727},{"createdDate":1203,"id":1208,"name":1206,"modelId":1184,"published":13,"stageModifiedSincePublish":6,"query":1728,"data":1729,"variations":1730,"lastUpdated":1209,"firstPublished":1214,"testRatio":31,"createdBy":425,"lastUpdatedBy":425,"folders":1731,"lastUpdateSource":60,"meta":1732,"rev":1628},[],{"name":1206,"color":1205},{},[],{"breakpoints":1733,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":19},{"xsmall":18,"small":17,"medium":16},{"count":31,"technique":1735},{"@type":105,"id":1220,"model":1287,"value":1736},{"createdDate":1216,"id":1220,"name":718,"modelId":1184,"published":13,"meta":1737,"stageModifiedSincePublish":6,"query":1739,"data":1740,"variations":1741,"lastUpdated":1221,"firstPublished":1226,"testRatio":31,"createdBy":425,"lastUpdatedBy":425,"folders":1742,"lastUpdateSource":60,"rev":1419},{"breakpoints":1738,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},[],{"name":718,"color":1218},{},[],{"count":45,"technique":1744},{"@type":105,"id":1246,"model":1287,"value":1745},{"createdDate":1241,"id":1246,"name":1244,"modelId":1184,"published":13,"stageModifiedSincePublish":6,"query":1746,"data":1747,"variations":1748,"lastUpdated":1247,"firstPublished":1252,"testRatio":31,"createdBy":425,"lastUpdatedBy":425,"folders":1749,"lastUpdateSource":60,"meta":1750,"rev":1588},[],{"name":1244,"color":1243},{},[],{"breakpoints":1751,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},{"count":45,"technique":1753},{"@type":105,"id":1272,"model":1287,"value":1754},{"createdDate":1267,"id":1272,"name":1270,"modelId":1184,"published":13,"stageModifiedSincePublish":6,"query":1755,"data":1756,"variations":1757,"lastUpdated":1273,"firstPublished":1278,"testRatio":31,"createdBy":425,"lastUpdatedBy":425,"folders":1758,"lastUpdateSource":60,"meta":1759,"rev":1380},[],{"name":1270,"color":1269},{},[],{"breakpoints":1760,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},"1b633afd3a6342ddb6c554ac0097c98b",1789724665199,"2025-05",1789724759253,{},[],{"createdDate":1768,"data":1769,"id":1807,"lastUpdated":1808,"modelId":1329,"name":1809,"published":13,"firstPublished":1810,"meta":1811,"query":1812,"rev":1337},1789724664830,{"month":1390,"segments":1770,"year":1598},[1771,1780,1789,1798],{"count":31,"technique":1772},{"@type":105,"id":1220,"model":1287,"value":1773},{"createdDate":1216,"id":1220,"name":718,"modelId":1184,"published":13,"meta":1774,"stageModifiedSincePublish":6,"query":1776,"data":1777,"variations":1778,"lastUpdated":1221,"firstPublished":1226,"testRatio":31,"createdBy":425,"lastUpdatedBy":425,"folders":1779,"lastUpdateSource":60,"rev":1419},{"breakpoints":1775,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},[],{"name":718,"color":1218},{},[],{"count":31,"technique":1781},{"@type":105,"id":1233,"model":1287,"value":1782},{"createdDate":1228,"id":1233,"name":1231,"modelId":1184,"published":13,"stageModifiedSincePublish":6,"query":1783,"data":1784,"variations":1785,"lastUpdated":1234,"firstPublished":1239,"testRatio":31,"createdBy":425,"lastUpdatedBy":425,"folders":1786,"lastUpdateSource":60,"meta":1787,"rev":1316},[],{"name":1231,"color":1230},{},[],{"breakpoints":1788,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},{"count":1344,"technique":1790},{"@type":105,"id":1246,"model":1287,"value":1791},{"createdDate":1241,"id":1246,"name":1244,"modelId":1184,"published":13,"stageModifiedSincePublish":6,"query":1792,"data":1793,"variations":1794,"lastUpdated":1247,"firstPublished":1252,"testRatio":31,"createdBy":425,"lastUpdatedBy":425,"folders":1795,"lastUpdateSource":60,"meta":1796,"rev":1588},[],{"name":1244,"color":1243},{},[],{"breakpoints":1797,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},{"count":1344,"technique":1799},{"@type":105,"id":1272,"model":1287,"value":1800},{"createdDate":1267,"id":1272,"name":1270,"modelId":1184,"published":13,"stageModifiedSincePublish":6,"query":1801,"data":1802,"variations":1803,"lastUpdated":1273,"firstPublished":1278,"testRatio":31,"createdBy":425,"lastUpdatedBy":425,"folders":1804,"lastUpdateSource":60,"meta":1805,"rev":1380},[],{"name":1270,"color":1269},{},[],{"breakpoints":1806,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},"f698d0425a73498ebb2f7c68c44913fd",1789724664810,"2025-04",1789724759259,{},[],{"createdDate":1814,"data":1815,"id":1835,"lastUpdated":1836,"modelId":1329,"name":1837,"published":13,"firstPublished":1838,"meta":1839,"query":1840,"rev":1337},1789724664473,{"month":1344,"segments":1816,"year":1598},[1817,1826],{"count":31,"technique":1818},{"@type":105,"id":1233,"model":1287,"value":1819},{"createdDate":1228,"id":1233,"name":1231,"modelId":1184,"published":13,"stageModifiedSincePublish":6,"query":1820,"data":1821,"variations":1822,"lastUpdated":1234,"firstPublished":1239,"testRatio":31,"createdBy":425,"lastUpdatedBy":425,"folders":1823,"lastUpdateSource":60,"meta":1824,"rev":1316},[],{"name":1231,"color":1230},{},[],{"breakpoints":1825,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},{"count":1390,"technique":1827},{"@type":105,"id":1272,"model":1287,"value":1828},{"createdDate":1267,"id":1272,"name":1270,"modelId":1184,"published":13,"stageModifiedSincePublish":6,"query":1829,"data":1830,"variations":1831,"lastUpdated":1273,"firstPublished":1278,"testRatio":31,"createdBy":425,"lastUpdatedBy":425,"folders":1832,"lastUpdateSource":60,"meta":1833,"rev":1380},[],{"name":1270,"color":1269},{},[],{"breakpoints":1834,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},"a7285a12683b43c8826a2567811be2e9",1789724664447,"2025-03",1789724759273,{},[],{"createdDate":1842,"data":1843,"id":1863,"lastUpdated":1864,"modelId":1329,"name":1865,"published":13,"firstPublished":1866,"meta":1867,"query":1868,"rev":1337},1789724663923,{"month":45,"segments":1844,"year":1598},[1845,1854],{"count":31,"technique":1846},{"@type":105,"id":1208,"model":1287,"value":1847},{"createdDate":1203,"id":1208,"name":1206,"modelId":1184,"published":13,"stageModifiedSincePublish":6,"query":1848,"data":1849,"variations":1850,"lastUpdated":1209,"firstPublished":1214,"testRatio":31,"createdBy":425,"lastUpdatedBy":425,"folders":1851,"lastUpdateSource":60,"meta":1852,"rev":1628},[],{"name":1206,"color":1205},{},[],{"breakpoints":1853,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":19},{"xsmall":18,"small":17,"medium":16},{"count":31,"technique":1855},{"@type":105,"id":1272,"model":1287,"value":1856},{"createdDate":1267,"id":1272,"name":1270,"modelId":1184,"published":13,"stageModifiedSincePublish":6,"query":1857,"data":1858,"variations":1859,"lastUpdated":1273,"firstPublished":1278,"testRatio":31,"createdBy":425,"lastUpdatedBy":425,"folders":1860,"lastUpdateSource":60,"meta":1861,"rev":1380},[],{"name":1270,"color":1269},{},[],{"breakpoints":1862,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},"49137c1e2f104e77a9f9eeae0be05fd0",1789724663903,"2025-02",1789724759293,{},[],{"createdDate":1870,"data":1871,"id":1882,"lastUpdated":1883,"modelId":1329,"name":1884,"published":13,"firstPublished":1885,"meta":1886,"query":1887,"rev":1337},1789724663548,{"month":31,"segments":1872,"year":1598},[1873],{"count":31,"technique":1874},{"@type":105,"id":1272,"model":1287,"value":1875},{"createdDate":1267,"id":1272,"name":1270,"modelId":1184,"published":13,"stageModifiedSincePublish":6,"query":1876,"data":1877,"variations":1878,"lastUpdated":1273,"firstPublished":1278,"testRatio":31,"createdBy":425,"lastUpdatedBy":425,"folders":1879,"lastUpdateSource":60,"meta":1880,"rev":1380},[],{"name":1270,"color":1269},{},[],{"breakpoints":1881,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},"4a6a3796c05045bf93974e58276d85f0",1789724663522,"2025-01",1789724759309,{},[],{"createdDate":1889,"data":1890,"id":1910,"lastUpdated":1911,"modelId":1329,"name":1912,"published":13,"firstPublished":1913,"meta":1914,"query":1915,"rev":1337},1789724663165,{"month":1297,"segments":1891,"year":960},[1892,1901],{"count":31,"technique":1893},{"@type":105,"id":1208,"model":1287,"value":1894},{"createdDate":1203,"id":1208,"name":1206,"modelId":1184,"published":13,"stageModifiedSincePublish":6,"query":1895,"data":1896,"variations":1897,"lastUpdated":1209,"firstPublished":1214,"testRatio":31,"createdBy":425,"lastUpdatedBy":425,"folders":1898,"lastUpdateSource":60,"meta":1899,"rev":1628},[],{"name":1206,"color":1205},{},[],{"breakpoints":1900,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":19},{"xsmall":18,"small":17,"medium":16},{"count":31,"technique":1902},{"@type":105,"id":1272,"model":1287,"value":1903},{"createdDate":1267,"id":1272,"name":1270,"modelId":1184,"published":13,"stageModifiedSincePublish":6,"query":1904,"data":1905,"variations":1906,"lastUpdated":1273,"firstPublished":1278,"testRatio":31,"createdBy":425,"lastUpdatedBy":425,"folders":1907,"lastUpdateSource":60,"meta":1908,"rev":1380},[],{"name":1270,"color":1269},{},[],{"breakpoints":1909,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},"f9dfe7c9883f4381b7a19b495c620d0f",1789724663145,"2024-12",1789724759322,{},[],{"createdDate":1917,"data":1918,"id":1929,"lastUpdated":1930,"modelId":1329,"name":1931,"published":13,"firstPublished":1932,"meta":1933,"query":1934,"rev":1337},1789724662289,{"month":1430,"segments":1919,"year":960},[1920],{"count":45,"technique":1921},{"@type":105,"id":1272,"model":1287,"value":1922},{"createdDate":1267,"id":1272,"name":1270,"modelId":1184,"published":13,"stageModifiedSincePublish":6,"query":1923,"data":1924,"variations":1925,"lastUpdated":1273,"firstPublished":1278,"testRatio":31,"createdBy":425,"lastUpdatedBy":425,"folders":1926,"lastUpdateSource":60,"meta":1927,"rev":1380},[],{"name":1270,"color":1269},{},[],{"breakpoints":1928,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},"50c34b5e0401446eb3176f30c0cb92cf",1789724662006,"2024-11",1789724759338,{},[],{"createdDate":1936,"data":1937,"id":1949,"lastUpdated":1950,"modelId":1329,"name":1951,"published":13,"firstPublished":1952,"meta":1953,"query":1954,"rev":1337},1789724661458,{"month":1938,"segments":1939,"year":960},10,[1940],{"count":31,"technique":1941},{"@type":105,"id":1233,"model":1287,"value":1942},{"createdDate":1228,"id":1233,"name":1231,"modelId":1184,"published":13,"stageModifiedSincePublish":6,"query":1943,"data":1944,"variations":1945,"lastUpdated":1234,"firstPublished":1239,"testRatio":31,"createdBy":425,"lastUpdatedBy":425,"folders":1946,"lastUpdateSource":60,"meta":1947,"rev":1316},[],{"name":1231,"color":1230},{},[],{"breakpoints":1948,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},"0fe6fb651b844252b5bf99d3d1153e25",1789724661435,"2024-10",1789724759351,{},[],{"createdDate":1956,"data":1957,"id":1977,"lastUpdated":1978,"modelId":1329,"name":1979,"published":13,"firstPublished":1980,"meta":1981,"query":1982,"rev":1337},1789724661095,{"month":1608,"segments":1958,"year":960},[1959,1968],{"count":31,"technique":1960},{"@type":105,"id":1233,"model":1287,"value":1961},{"createdDate":1228,"id":1233,"name":1231,"modelId":1184,"published":13,"stageModifiedSincePublish":6,"query":1962,"data":1963,"variations":1964,"lastUpdated":1234,"firstPublished":1239,"testRatio":31,"createdBy":425,"lastUpdatedBy":425,"folders":1965,"lastUpdateSource":60,"meta":1966,"rev":1316},[],{"name":1231,"color":1230},{},[],{"breakpoints":1967,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},{"count":31,"technique":1969},{"@type":105,"id":1246,"model":1287,"value":1970},{"createdDate":1241,"id":1246,"name":1244,"modelId":1184,"published":13,"stageModifiedSincePublish":6,"query":1971,"data":1972,"variations":1973,"lastUpdated":1247,"firstPublished":1252,"testRatio":31,"createdBy":425,"lastUpdatedBy":425,"folders":1974,"lastUpdateSource":60,"meta":1975,"rev":1588},[],{"name":1244,"color":1243},{},[],{"breakpoints":1976,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},"572f765700444cf4b776738d8f924014",1789724661071,"2024-09",1789724759366,{},[],{"createdDate":1984,"data":1985,"id":2005,"lastUpdated":2006,"modelId":1329,"name":2007,"published":13,"firstPublished":2008,"meta":2009,"query":2010,"rev":1337},1789724660727,{"month":1514,"segments":1986,"year":960},[1987,1996],{"count":31,"technique":1988},{"@type":105,"id":1180,"model":1287,"value":1989},{"createdDate":1175,"id":1180,"name":1178,"modelId":1184,"published":13,"stageModifiedSincePublish":6,"query":1990,"data":1991,"variations":1992,"lastUpdated":1181,"firstPublished":1187,"testRatio":31,"createdBy":425,"lastUpdatedBy":425,"folders":1993,"lastUpdateSource":60,"meta":1994,"rev":1295},[],{"name":1178,"color":1177},{},[],{"breakpoints":1995,"hasErrors":6,"kind":20,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},{"count":31,"technique":1997},{"@type":105,"id":1272,"model":1287,"value":1998},{"createdDate":1267,"id":1272,"name":1270,"modelId":1184,"published":13,"stageModifiedSincePublish":6,"query":1999,"data":2000,"variations":2001,"lastUpdated":1273,"firstPublished":1278,"testRatio":31,"createdBy":425,"lastUpdatedBy":425,"folders":2002,"lastUpdateSource":60,"meta":2003,"rev":1380},[],{"name":1270,"color":1269},{},[],{"breakpoints":2004,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},"619c18e8314546958640993f524cb869",1789724660708,"2024-07",1789724759382,{},[],{"createdDate":2012,"data":2013,"id":2033,"lastUpdated":2034,"modelId":1329,"name":2035,"published":13,"firstPublished":2036,"meta":2037,"query":2038,"rev":1337},1789724660258,{"month":1283,"segments":2014,"year":960},[2015,2024],{"count":31,"technique":2016},{"@type":105,"id":1233,"model":1287,"value":2017},{"createdDate":1228,"id":1233,"name":1231,"modelId":1184,"published":13,"stageModifiedSincePublish":6,"query":2018,"data":2019,"variations":2020,"lastUpdated":1234,"firstPublished":1239,"testRatio":31,"createdBy":425,"lastUpdatedBy":425,"folders":2021,"lastUpdateSource":60,"meta":2022,"rev":1316},[],{"name":1231,"color":1230},{},[],{"breakpoints":2023,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},{"count":1647,"technique":2025},{"@type":105,"id":1272,"model":1287,"value":2026},{"createdDate":1267,"id":1272,"name":1270,"modelId":1184,"published":13,"stageModifiedSincePublish":6,"query":2027,"data":2028,"variations":2029,"lastUpdated":1273,"firstPublished":1278,"testRatio":31,"createdBy":425,"lastUpdatedBy":425,"folders":2030,"lastUpdateSource":60,"meta":2031,"rev":1380},[],{"name":1270,"color":1269},{},[],{"breakpoints":2032,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},"4298543f6f604c7888fbff761a94d803",1789724660216,"2024-06",1789724759390,{},[],{"createdDate":2040,"data":2041,"id":2061,"lastUpdated":2062,"modelId":1329,"name":2063,"published":13,"firstPublished":2064,"meta":2065,"query":2066,"rev":1337},1789724659855,{"month":1341,"segments":2042,"year":960},[2043,2052],{"count":31,"technique":2044},{"@type":105,"id":1180,"model":1287,"value":2045},{"createdDate":1175,"id":1180,"name":1178,"modelId":1184,"published":13,"stageModifiedSincePublish":6,"query":2046,"data":2047,"variations":2048,"lastUpdated":1181,"firstPublished":1187,"testRatio":31,"createdBy":425,"lastUpdatedBy":425,"folders":2049,"lastUpdateSource":60,"meta":2050,"rev":1295},[],{"name":1178,"color":1177},{},[],{"breakpoints":2051,"hasErrors":6,"kind":20,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},{"count":45,"technique":2053},{"@type":105,"id":1272,"model":1287,"value":2054},{"createdDate":1267,"id":1272,"name":1270,"modelId":1184,"published":13,"stageModifiedSincePublish":6,"query":2055,"data":2056,"variations":2057,"lastUpdated":1273,"firstPublished":1278,"testRatio":31,"createdBy":425,"lastUpdatedBy":425,"folders":2058,"lastUpdateSource":60,"meta":2059,"rev":1380},[],{"name":1270,"color":1269},{},[],{"breakpoints":2060,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},"0c3f84ad9ceb417a9848243df8188d0c",1789724659824,"2024-05",1789724759395,{},[],{"createdDate":2068,"data":2069,"id":2080,"lastUpdated":2081,"modelId":1329,"name":2082,"published":13,"firstPublished":2083,"meta":2084,"query":2085,"rev":1337},1789724659433,{"month":1390,"segments":2070,"year":960},[2071],{"count":31,"technique":2072},{"@type":105,"id":1272,"model":1287,"value":2073},{"createdDate":1267,"id":1272,"name":1270,"modelId":1184,"published":13,"stageModifiedSincePublish":6,"query":2074,"data":2075,"variations":2076,"lastUpdated":1273,"firstPublished":1278,"testRatio":31,"createdBy":425,"lastUpdatedBy":425,"folders":2077,"lastUpdateSource":60,"meta":2078,"rev":1380},[],{"name":1270,"color":1269},{},[],{"breakpoints":2079,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},"bb29820a64b34fd2acf88df292a248c7",1789724659406,"2024-04",1789724759400,{},[],{"createdDate":2087,"data":2088,"id":2099,"lastUpdated":2100,"modelId":1329,"name":2101,"published":13,"firstPublished":2102,"meta":2103,"query":2104,"rev":1337},1789724659013,{"month":45,"segments":2089,"year":960},[2090],{"count":31,"technique":2091},{"@type":105,"id":1272,"model":1287,"value":2092},{"createdDate":1267,"id":1272,"name":1270,"modelId":1184,"published":13,"stageModifiedSincePublish":6,"query":2093,"data":2094,"variations":2095,"lastUpdated":1273,"firstPublished":1278,"testRatio":31,"createdBy":425,"lastUpdatedBy":425,"folders":2096,"lastUpdateSource":60,"meta":2097,"rev":1380},[],{"name":1270,"color":1269},{},[],{"breakpoints":2098,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},"4fe0488c6a5940a88c02441a66dd68fc",1789724658977,"2024-02",1789724759406,{},[],{"createdDate":2106,"data":2107,"id":2118,"lastUpdated":2119,"modelId":1329,"name":2120,"published":13,"firstPublished":2121,"meta":2122,"query":2123,"rev":1337},1789724658501,{"month":31,"segments":2108,"year":960},[2109],{"count":1344,"technique":2110},{"@type":105,"id":1272,"model":1287,"value":2111},{"createdDate":1267,"id":1272,"name":1270,"modelId":1184,"published":13,"stageModifiedSincePublish":6,"query":2112,"data":2113,"variations":2114,"lastUpdated":1273,"firstPublished":1278,"testRatio":31,"createdBy":425,"lastUpdatedBy":425,"folders":2115,"lastUpdateSource":60,"meta":2116,"rev":1380},[],{"name":1270,"color":1269},{},[],{"breakpoints":2117,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},"b71e54a546be492ab2312690eb471869",1789724658480,"2024-01",1789724759421,{},[],[2125,2150,2174,2206,2228,2247,2269,2290],{"createdDate":2126,"data":2127,"id":2140,"lastUpdated":2141,"modelId":2142,"name":2129,"published":13,"firstPublished":2143,"meta":2144,"query":2146,"createdBy":425,"folders":2147,"lastUpdateSource":60,"lastUpdatedBy":425,"stageModifiedSincePublish":6,"testRatio":31,"variations":2148,"rev":2149},1789725261452,{"description":2128,"endMonth":963,"endYear":962,"label":2129,"startMonth":2130,"startYear":962,"technique":2131,"tier":963},"Stolen vendor auth tokens → downstream Snowflake\u002FBigQuery\u002FSalesforce access.\u2028Top breaches: Anodot\u002FGlassbox, Zara\u002FInditex, Rockstar Games, Vimeo, Booking.com, Klue, Recorded Future, Hugging Face, Vercel.","Anodot \u002F Klue \u002F Context.ai OAuth","3",{"@type":105,"id":1195,"model":1287,"value":2132},{"createdDate":1190,"id":1195,"name":1193,"modelId":1184,"published":13,"stageModifiedSincePublish":6,"query":2133,"data":2134,"variations":2135,"lastUpdated":1196,"firstPublished":1201,"testRatio":31,"createdBy":425,"lastUpdatedBy":425,"folders":2136,"lastUpdateSource":60,"meta":2137,"rev":2139},[],{"name":1193,"color":1192},{},[],{"breakpoints":2138,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},"gf563bz67pw","c08a8ae62c834654bf467666e3858991",1789727189525,"0a711a20bc4f4fb6b0444d7da0253411",1789725287407,{"breakpoints":2145,"hasAutosaves":6,"hasErrors":6,"kind":20,"lastPreviewUrl":21},{"medium":16,"small":17,"xsmall":18},[],[],{},"nrvanvanz1e",{"createdDate":2151,"data":2152,"id":2166,"lastUpdated":2167,"modelId":2142,"name":2155,"published":13,"firstPublished":2168,"meta":2169,"query":2171,"createdBy":425,"folders":2172,"lastUpdateSource":60,"lastUpdatedBy":425,"stageModifiedSincePublish":6,"testRatio":31,"variations":2173,"rev":2149},1789725261029,{"description":2153,"endMonth":2154,"endYear":1598,"label":2155,"startMonth":2156,"startYear":1598,"technique":2157,"tier":2156},"Vishing → Salesforce DataLoader App device code authorization → CRM data exfiltration. Top breaches: Qantas, LVMH, Chanel, Allianz Life, Air France-KLM, Farmers Insurance.","8","ShinyHunters Device Code Phishing","5",{"@type":105,"id":1208,"model":1287,"value":2158},{"createdDate":1203,"id":1208,"name":1206,"modelId":1184,"published":13,"stageModifiedSincePublish":6,"query":2159,"data":2160,"variations":2161,"lastUpdated":1209,"firstPublished":1214,"testRatio":31,"createdBy":425,"lastUpdatedBy":425,"folders":2162,"lastUpdateSource":60,"meta":2163,"rev":2165},[],{"name":1206,"color":1205},{},[],{"breakpoints":2164,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":19},{"xsmall":18,"small":17,"medium":16},"i3k7iidt5be","e21e56660c7943839b82e37d96724cb9",1789727208918,1789725287419,{"breakpoints":2170,"hasAutosaves":6,"hasErrors":6,"kind":20,"lastPreviewUrl":21},{"medium":16,"small":17,"xsmall":18},[],[],{},{"createdDate":2175,"data":2176,"id":2198,"lastUpdated":2199,"modelId":2142,"name":2178,"published":13,"firstPublished":2200,"meta":2201,"query":2203,"createdBy":425,"folders":2204,"lastUpdateSource":60,"lastUpdatedBy":425,"stageModifiedSincePublish":6,"testRatio":31,"variations":2205,"rev":2149},1789725260622,{"description":2177,"endMonth":963,"endYear":962,"label":2178,"startMonth":961,"startYear":962,"technique":2179,"techniqueTo":2188,"tier":2197},"Breaches linked to vishing + browser-based payload (combination of AITM phishing & device code phishing). Top breaches: Panera Bread, Match Group, SoundCloud, Crunchbase, Optimizely.","SLH Vishing + Phishing",{"@type":105,"id":1233,"model":1287,"value":2180},{"createdDate":1228,"id":1233,"name":1231,"modelId":1184,"published":13,"stageModifiedSincePublish":6,"query":2181,"data":2182,"variations":2183,"lastUpdated":1234,"firstPublished":1239,"testRatio":31,"createdBy":425,"lastUpdatedBy":425,"folders":2184,"lastUpdateSource":60,"meta":2185,"rev":2187},[],{"name":1231,"color":1230},{},[],{"breakpoints":2186,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},"tln1xe0qx8f",{"@type":105,"id":1259,"model":1287,"value":2189},{"createdDate":1254,"id":1259,"name":1257,"modelId":1184,"published":13,"stageModifiedSincePublish":6,"query":2190,"data":2191,"variations":2192,"lastUpdated":1260,"firstPublished":1265,"testRatio":31,"createdBy":425,"lastUpdatedBy":425,"folders":2193,"lastUpdateSource":60,"meta":2194,"rev":2196},[],{"color":1256,"name":1257},{},[],{"breakpoints":2195,"lastPreviewUrl":21,"hasErrors":6,"kind":20,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},"anlnepcbacq","4","ac1410558f2241e6a4bb921628ecf7a3",1789727224030,1789725287421,{"breakpoints":2202,"hasAutosaves":6,"hasErrors":6,"kind":20,"lastPreviewUrl":21},{"medium":16,"small":17,"xsmall":18},[],[],{},{"createdDate":2207,"data":2208,"id":2220,"lastUpdated":2221,"modelId":2142,"name":2211,"published":13,"firstPublished":2222,"meta":2223,"query":2225,"createdBy":425,"folders":2226,"lastUpdateSource":60,"lastUpdatedBy":425,"stageModifiedSincePublish":6,"testRatio":31,"variations":2227,"rev":2149},1789725260206,{"description":2209,"endMonth":2210,"endYear":1598,"label":2211,"startMonth":2154,"startYear":1598,"technique":2212,"tier":2130},"Compromised SaaS vendors → stolen OAuth tokens → downstream Salesforce access.\u2028Top breaches: Cloudflare, Palo Alto Networks, Zscaler, CyberArk, Proofpoint. More than 1000 victims claimed. ","11","Salesloft Drift \u002F Gainsight OAuth",{"@type":105,"id":1195,"model":1287,"value":2213},{"createdDate":1190,"id":1195,"name":1193,"modelId":1184,"published":13,"stageModifiedSincePublish":6,"query":2214,"data":2215,"variations":2216,"lastUpdated":1196,"firstPublished":1201,"testRatio":31,"createdBy":425,"lastUpdatedBy":425,"folders":2217,"lastUpdateSource":60,"meta":2218,"rev":2139},[],{"name":1193,"color":1192},{},[],{"breakpoints":2219,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},"c1decc00b9e5413e96ece4207f8f0e0c",1789727239802,1789725287544,{"breakpoints":2224,"hasAutosaves":6,"hasErrors":6,"kind":20,"lastPreviewUrl":21},{"medium":16,"small":17,"xsmall":18},[],[],{},{"createdDate":2229,"data":2230,"id":2242,"lastUpdated":2243,"modelId":2142,"name":2232,"published":13,"firstPublished":2244,"meta":2245,"query":2246,"rev":2149},1789725259752,{"description":2231,"endMonth":589,"endYear":960,"label":2232,"startMonth":961,"startYear":960,"technique":2233,"tier":2130},"Password spray → OAuth app abuse → email exfiltration (APT29). Top breaches: Microsoft, HPE.","Midnight Blizzard",{"@type":105,"id":1272,"model":1287,"value":2234},{"createdDate":1267,"id":1272,"name":1270,"modelId":1184,"published":13,"stageModifiedSincePublish":6,"query":2235,"data":2236,"variations":2237,"lastUpdated":1273,"firstPublished":1278,"testRatio":31,"createdBy":425,"lastUpdatedBy":425,"folders":2238,"lastUpdateSource":60,"meta":2239,"rev":2241},[],{"name":1270,"color":1269},{},[],{"breakpoints":2240,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},"ryusua5pzus","84ac55a5037a4a80898c104735d0ad30",1789725259733,1789725287546,{"hasAutosaves":19},[],{"createdDate":2248,"data":2249,"id":2261,"lastUpdated":2262,"modelId":2142,"name":2251,"published":13,"firstPublished":2263,"meta":2264,"query":2266,"createdBy":425,"folders":2267,"lastUpdateSource":60,"lastUpdatedBy":425,"stageModifiedSincePublish":6,"testRatio":31,"variations":2268,"rev":2149},1789725259339,{"description":2250,"endMonth":963,"endYear":1598,"label":2251,"startMonth":2197,"startYear":1598,"technique":2252,"tier":589},"Vishing outsourced help desks → IdP compromise → ransomware\u002Fdata theft. Top breaches: M&S, Co-op, Hawaiian Airlines, WestJet, Aflac, Erie Insurance, Philadelphia Insurance.","Scattered Spider Help Desk",{"@type":105,"id":1246,"model":1287,"value":2253},{"createdDate":1241,"id":1246,"name":1244,"modelId":1184,"published":13,"stageModifiedSincePublish":6,"query":2254,"data":2255,"variations":2256,"lastUpdated":1247,"firstPublished":1252,"testRatio":31,"createdBy":425,"lastUpdatedBy":425,"folders":2257,"lastUpdateSource":60,"meta":2258,"rev":2260},[],{"name":1244,"color":1243},{},[],{"breakpoints":2259,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},"235z52x93eq","2817de6536614e5399acd362e92e5833",1789727268875,1789725287565,{"breakpoints":2265,"hasAutosaves":6,"hasErrors":6,"kind":20,"lastPreviewUrl":21},{"medium":16,"small":17,"xsmall":18},[],[],{},{"createdDate":2270,"data":2271,"id":2283,"lastUpdated":2284,"modelId":2142,"name":2274,"published":13,"firstPublished":2263,"meta":2285,"query":2287,"createdBy":425,"folders":2288,"lastUpdateSource":60,"lastUpdatedBy":425,"stageModifiedSincePublish":6,"testRatio":31,"variations":2289,"rev":2149},1789725258905,{"description":2272,"endMonth":2273,"endYear":960,"label":2274,"startMonth":2197,"startYear":960,"technique":2275,"tier":589},"Infostealer-harvested credentials → credential stuffing against MFA-less Snowflake tenants. Top breaches: AT&T, Ticketmaster. 1B+ records stolen, 165 victims total (not all publicly disclosed).  ","7","ShinyHunters Snowflake",{"@type":105,"id":1272,"model":1287,"value":2276},{"createdDate":1267,"id":1272,"name":1270,"modelId":1184,"published":13,"stageModifiedSincePublish":6,"query":2277,"data":2278,"variations":2279,"lastUpdated":1273,"firstPublished":1278,"testRatio":31,"createdBy":425,"lastUpdatedBy":425,"folders":2280,"lastUpdateSource":60,"meta":2281,"rev":2241},[],{"name":1270,"color":1269},{},[],{"breakpoints":2282,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},"506851cba2e44c4ab0ddbfd5dacd727d",1789727286877,{"breakpoints":2286,"hasAutosaves":6,"hasErrors":6,"kind":20,"lastPreviewUrl":21},{"medium":16,"small":17,"xsmall":18},[],[],{},{"createdDate":2291,"data":2292,"id":2304,"lastUpdated":2305,"modelId":2142,"name":2294,"published":13,"firstPublished":2306,"meta":2307,"query":2309,"createdBy":425,"folders":2310,"lastUpdateSource":60,"lastUpdatedBy":425,"stageModifiedSincePublish":6,"testRatio":31,"variations":2311,"rev":2149},1789725258013,{"description":2293,"endMonth":2130,"endYear":1598,"label":2294,"startMonth":2295,"startYear":960,"technique":2296,"tier":961},"Infostealer-sourced Jira credentials → data exfiltration. Top breaches: Telefónica, Jaguar Land Rover","HellCat Jira","10",{"@type":105,"id":1272,"model":1287,"value":2297},{"createdDate":1267,"id":1272,"name":1270,"modelId":1184,"published":13,"stageModifiedSincePublish":6,"query":2298,"data":2299,"variations":2300,"lastUpdated":1273,"firstPublished":1278,"testRatio":31,"createdBy":425,"lastUpdatedBy":425,"folders":2301,"lastUpdateSource":60,"meta":2302,"rev":2241},[],{"name":1270,"color":1269},{},[],{"breakpoints":2303,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},"cb4c608fea8a404687e96d825216b51d",1789727303805,1789725287580,{"breakpoints":2308,"hasAutosaves":6,"hasErrors":6,"kind":20,"lastPreviewUrl":21},{"medium":16,"small":17,"xsmall":18},[],[],{},1790693850486]