[{"data":1,"prerenderedAt":16806},["ShallowReactive",2],{"application-flags":3,"navbar":7,"always-visible-banner":36,"navbar-about-highlight":108,"navbar-resource-highlight":182,"trust-badges":226,"solution-nav":247,"fa-icon-sharp-regular-faFishingRod":378,"fa-icon-solid-faUserSecret":382,"fa-icon-sharp-regular-faLaptopCode":384,"fa-icon-solid-faTabletScreenButton":386,"fa-icon-solid-faPlugCircleXmark":388,"fa-icon-sharp-regular-faPuzzlePiece":390,"fa-icon-solid-faFileCircleXmark":392,"fa-icon-solid-faGhost":395,"fa-icon-solid-faQrcode":398,"fa-icon-solid-faCookieBite":400,"fa-icon-sharp-regular-faUserSecret":402,"fa-icon-sharp-regular-faRadar":404,"fa-icon-sharp-regular-faSatelliteDish":406,"fa-icon-sharp-regular-faShieldCheck":408,"fa-icon-sharp-regular-faBrainCircuit":410,"fa-icon-solid-faMobileScreenButton":412,"fa-icon-brands-faChrome":414,"fa-icon-solid-faDisplay":416,"fa-icon-solid-faFilter":418,"fa-icon-solid-faCloudArrowUp":420,"solution-page-/solution/stop-browser-based-attacks/zero-day-phishing":422,"latestResourcesBlogPosts":653,"builder-image-sizes-1b40ecg":16798},[4],{"name":5,"enabled":6},"maintenanceMode",false,[8],{"createdDate":9,"id":10,"name":11,"modelId":12,"published":13,"meta":14,"query":22,"data":23,"variations":28,"lastUpdated":29,"firstPublished":30,"testRatio":31,"createdBy":32,"lastUpdatedBy":33,"folders":34,"rev":35},1742208588866,"1c7a4e423bf54ac1a328bb4063459ef2","Banner","1c6207a5f24948ab82d4a0b17f251193","published",{"breakpoints":15,"hasAutosaves":19,"kind":20,"lastPreviewUrl":21},{"medium":16,"small":17,"xsmall":18},768,640,320,true,"data","",[],{"link":24,"text":25,"type":26,"url":27},{},"Get our latest report analyzing browser attack techniques in 2026","web-banner","https://pushsecurity.com/resources/browser-attacks-report",{},1774258294825,1742208637545,1,"CydmZnOWU1XuAaLhEDCoYNM4Z8W2","jKjF9r5jcvXU8tzZEfFQm31Iyvr2",[],"mxni9u477k",{"createdBy":37,"createdDate":38,"data":39,"folders":94,"id":95,"lastUpdated":96,"lastUpdatedBy":97,"meta":98,"modelId":102,"name":103,"published":13,"query":104,"testRatio":31,"variations":105,"firstPublished":106,"stageModifiedSincePublish":6,"rev":107},"ST0tXQM8slWpFrmioqKHmENB2qe2",1774965361051,{"ctaText":40,"text":41,"url":21,"blocks":42,"state":90},"ewrererw","testrfesssssssssss",[43,70,78],{"@type":44,"@version":45,"id":46,"component":47,"responsiveStyles":60},"@builder.io/sdk:Element",2,"builder-ca12c06a52de41d7b8743da53118cd38",{"name":48,"tag":48,"options":49,"isRSC":59},"TopBannerContent",{"text":50,"ctaText":51,"url":52,"mainText":53,"cta":56},"New Webinar Series: Join John Hammond, Troy Hunt, and Matt Johansen for the State of Browser Attacks","Save Your Spot","https://pushsecurity.com/webinar/state-of-browser-security",{"content":54,"fontSize":55},"\u003Cp class=\"\">Employees using shadow AI tools? Push blocks them in the browser and enforces your AI policy.\u003C/p>","text-base",{"content":57,"fontSize":55,"url":58},"\u003Cp class=\"\">Get a free trial →\u003C/p>","https://pushsecurity.com/lp/shadow-ai-trial",null,{"large":61},{"display":62,"flexDirection":63,"position":64,"flexShrink":65,"boxSizing":66,"marginTop":67,"marginBottom":67,"fontSize":68,"fontWeight":69},"flex","column","relative","0","border-box",".56rem","1.125rem","700",{"@type":44,"@version":45,"id":71,"component":72,"responsiveStyles":76},"builder-a2e1f4b9f30b464bb814d7f5de5b0aa7",{"name":73,"options":74,"isRSC":59},"Custom Code",{"code":75,"scriptsClientOnly":6},"\u003Cstyle>\n  .top-banner.bg-web-orange{background:rgb(114, 79, 255);}\n\u003C/style>\n",{"large":77},{"display":62,"flexDirection":63,"position":64,"flexShrink":65,"boxSizing":66},{"id":79,"@type":44,"tagName":80,"properties":81,"responsiveStyles":85},"builder-pixel-1ed55qebyjy","img",{"src":82,"aria-hidden":83,"alt":21,"role":84,"width":65,"height":65},"https://cdn.builder.io/api/v1/pixel?apiKey=f3a1111ff5be48cdbb123cd9f5795a05","true","presentation",{"large":86},{"height":65,"width":65,"display":87,"opacity":65,"overflow":88,"pointerEvents":89},"block","hidden","none",{"deviceSize":91,"location":92},"large",{"path":21,"query":93},{},[],"fd266d0172cc47429be7ad10f48c99ad",1787595768418,"tFqFyIzyczYOCRogcShKk6KBmEB2",{"breakpoints":99,"hasAutosaves":6,"hasErrors":6,"hasLinks":6,"kind":100,"lastPreviewUrl":101},{"medium":16,"small":17,"xsmall":18},"component","https://pushsecurity.com/?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CcreateProjects%2CsendPullRequests%2CfusionHostingPublish&builder.user.role.name=Designer&builder.user.role.id=creator&builder.cachebust=true&builder.preview=always-visible-banner&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.always-visible-banner=fd266d0172cc47429be7ad10f48c99ad&builder.overrides.fd266d0172cc47429be7ad10f48c99ad=fd266d0172cc47429be7ad10f48c99ad&builder.options.locale=Default","0678d178ec8b41efb8a23c09dba7874d","always visible banner",[],{},1774968080803,"2oahdv55rpx",[109,145],{"createdBy":32,"createdDate":110,"data":111,"folders":134,"id":135,"lastUpdated":136,"lastUpdatedBy":32,"meta":137,"modelId":139,"name":140,"published":13,"query":141,"stageModifiedSincePublish":6,"testRatio":31,"variations":142,"firstPublished":143,"rev":144},1776247359804,{"link":112,"testimonial":113,"testimonialLink":133,"type":116},{},{"@type":114,"id":115,"model":116,"value":117},"@builder.io/core:Reference","f028f2b685bb47cd8bf9e82a26dd5a79","testimonial",{"query":118,"folders":119,"createdDate":120,"id":115,"name":121,"modelId":122,"published":13,"data":123,"variations":127,"lastUpdated":128,"firstPublished":129,"testRatio":31,"createdBy":37,"lastUpdatedBy":37,"meta":130,"rev":132},[],[],1735823466309,"We found Push to be more accurate when compared to competitors and the browser agent offered features that others couldn’t match.","42035571a56940ac98bff4544aa79aa5",{"author":124,"jobTitle":125,"quote":121,"image":126},"Jason Waits","\u003Cp>CISO at Inductive Automation\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Ff04c0c0689ce4a89ac0f0708d78c0a07",{},1735910703862,1735823501152,{"kind":20,"lastPreviewUrl":21,"breakpoints":131,"hasAutosaves":19},{"small":17,"medium":16},"bnrq6ft9pc9","/customer-stories/inductive-automation",[],"9136a8f18b3b4a6ba29b8653a99372b1",1776247404986,{"breakpoints":138,"hasAutosaves":6,"kind":20,"lastPreviewUrl":21},{"medium":16,"small":17,"xsmall":18},"20d9eaa352304613b3d1a794b400703d","testimonial-inductive-automation",[],{},1776247404973,"p98tbup8mv",{"createdBy":32,"createdDate":146,"data":147,"folders":174,"id":175,"lastUpdated":176,"lastUpdatedBy":32,"meta":177,"modelId":139,"name":172,"published":13,"query":179,"stageModifiedSincePublish":6,"testRatio":31,"variations":180,"firstPublished":181,"rev":144},1776255761419,{"description":148,"image":149,"link":150,"testimonial":153,"title":172,"type":173},"Learn about the latest techniques being used in the wild.","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F7b4a5ebf81d64e8c9d7fc35f6c96c4a9",{"text":151,"url":152},"Download now","/resources/browser-attacks-report",{"@type":114,"id":154,"model":116,"value":155},"192acbb1f9ca4cac918c0ec435a8bae3",{"query":156,"folders":157,"createdDate":158,"id":154,"name":159,"modelId":122,"published":13,"data":160,"variations":166,"lastUpdated":167,"firstPublished":168,"testRatio":31,"createdBy":37,"lastUpdatedBy":32,"meta":169,"rev":171},[],[],1728981467463,"Push does for identity what CrowdStrike did for the endpoint",{"video":161,"jobTitle":162,"author":163,"qoute":21,"quote":164,"image":165},"https://cdn.builder.io/o/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F8b30e8ca50064058bbaef0f3c6164575%2Fcompressed?apiKey=f3a1111ff5be48cdbb123cd9f5795a05&token=8b30e8ca50064058bbaef0f3c6164575&alt=media&optimized=true","\u003Cp>Deputy CISO at Microsoft\u003C/p>\u003Cp>Former LinkedIn, Slack, Palantir\u003C/p>","Geoff Belknap","Push does for identity what CrowdStrike did for the endpoint.","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F748f0ad0a5064a00a13f4721fcc8dea1",{},1742902158597,1728981782923,{"kind":20,"lastPreviewUrl":21,"breakpoints":170,"hasAutosaves":19},{"small":17,"medium":16},"f5pizmc5i68","Report: 2026 Browser Attack Techniques","resource",[],"05a9322735fc427db12e2740e4302300",1776255810913,{"breakpoints":178,"hasAutosaves":6,"kind":20,"lastPreviewUrl":21},{"medium":16,"small":17,"xsmall":18},[],{},1776255810900,[183,205],{"createdBy":32,"createdDate":184,"data":185,"folders":195,"id":196,"lastUpdated":197,"lastUpdatedBy":32,"meta":198,"modelId":200,"name":172,"published":13,"query":201,"stageModifiedSincePublish":6,"testRatio":31,"variations":202,"firstPublished":203,"rev":204},1776256900280,{"description":148,"image":149,"link":186,"testimonial":187,"title":172,"type":173},{"text":151,"url":152},{"@type":114,"id":154,"model":116,"value":188},{"query":189,"folders":190,"createdDate":158,"id":154,"name":159,"modelId":122,"published":13,"data":191,"variations":192,"lastUpdated":167,"firstPublished":168,"testRatio":31,"createdBy":37,"lastUpdatedBy":32,"meta":193,"rev":171},[],[],{"video":161,"jobTitle":162,"author":163,"qoute":21,"quote":164,"image":165},{},{"kind":20,"lastPreviewUrl":21,"breakpoints":194,"hasAutosaves":19},{"small":17,"medium":16},[],"1f429607996e4e5fae8fe3f9b9610e55",1776256937553,{"breakpoints":199,"hasAutosaves":6,"kind":20,"lastPreviewUrl":21},{"medium":16,"small":17,"xsmall":18},"4829faa81e7c4ee8bd2d000e160e8d3c",[],{},1776256937540,"387awcm82j8",{"createdBy":32,"createdDate":206,"data":207,"folders":217,"id":218,"lastUpdated":219,"lastUpdatedBy":32,"meta":220,"modelId":200,"name":222,"published":13,"query":223,"stageModifiedSincePublish":6,"testRatio":31,"variations":224,"firstPublished":225,"rev":204},1776256949234,{"link":208,"testimonial":209,"testimonialLink":133,"type":116},{},{"@type":114,"id":115,"model":116,"value":210},{"query":211,"folders":212,"createdDate":120,"id":115,"name":121,"modelId":122,"published":13,"data":213,"variations":214,"lastUpdated":128,"firstPublished":129,"testRatio":31,"createdBy":37,"lastUpdatedBy":37,"meta":215,"rev":132},[],[],{"author":124,"jobTitle":125,"quote":121,"image":126},{},{"kind":20,"lastPreviewUrl":21,"breakpoints":216,"hasAutosaves":19},{"small":17,"medium":16},[],"ce043785b71b4ece98eac811ecf4ba10",1776256974140,{"breakpoints":221,"hasAutosaves":6,"kind":20,"lastPreviewUrl":21},{"medium":16,"small":17,"xsmall":18},"inductive-automation",[],{},1776256974130,[227,231,235,239,243],{"title":228,"logo":229,"createdDate":230},"SOC2","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fb6727a5e00004d6e9e69fc3068b8b64c",1784291539953,{"title":232,"logo":233,"createdDate":234},"GDPR","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Ffe49f53211674deaa5a6640d929cdf42?format=webp",1784291672535,{"title":236,"logo":237,"createdDate":238},"Cyber essentials","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F53558c1045a342a7a28def960cd54ae7?format=webp",1784291702710,{"title":240,"logo":241,"createdDate":242},"ISO IEC 27001","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F578a404a61cf45db951a41fe3554d12d",1784291766222,{"title":244,"logo":245,"createdDate":246},"ISO IEC 27701","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fbe219844b13242fbba531959579a753c",1784291858848,[248,308,353],{"id":249,"label":250,"text":21,"navIcon":251,"items":252},"stop-browser-based-attacks","Stop browser-based attacks","solid:faShieldHalved",[253,258,263,268,273,278,283,288,293,298,303],{"title":254,"text":255,"url":256,"navIcon":257},"Phishing","Detect phishing behaviorally in the browser, regardless of the payload or delivery channel.","/solution/stop-browser-based-attacks/zero-day-phishing","sharp-regular:faFishingRod",{"title":259,"text":260,"url":261,"navIcon":262},"Adversary-in-the-Middle","Detect and block MFA-bypassing AiTM phishing pages in real-time.","/solution/stop-browser-based-attacks/adversary-in-the-middle-attacks","solid:faUserSecret",{"title":264,"text":265,"url":266,"navIcon":267},"ClickFix (and variants)","Intercept malicious copy and paste attacks at the point of interaction.","/solution/stop-browser-based-attacks/clickfix-fix-variants","sharp-regular:faLaptopCode",{"title":269,"text":270,"url":271,"navIcon":272},"Device code phishing","Detect and block device code phishing kits designed to get around passkeys.","/solution/stop-browser-based-attacks/device-code-phishing","solid:faTabletScreenButton",{"title":274,"text":275,"url":276,"navIcon":277},"Malicious OAuth integrations","Detect and block the root cause of SaaS supply chain attacks.","/solution/stop-browser-based-attacks/malicious-oauth-integrations","solid:faPlugCircleXmark",{"title":279,"text":280,"url":281,"navIcon":282},"Malicious browser extensions","Inventory, monitor, and block risky browser extensions.","/solution/stop-browser-based-attacks/malicious-browser-extensions","sharp-regular:faPuzzlePiece",{"title":284,"text":285,"url":286,"navIcon":287},"Malicious file downloads","Control which files users can download by type, source, and user group.","/solution/stop-browser-based-attacks/malicious-file-downloads","solid:faFileCircleXmark",{"title":289,"text":290,"url":291,"navIcon":292},"Ghost logins","Surface hidden login paths that bypass SSO and expose accounts.","/solution/stop-browser-based-attacks/ghost-logins","solid:faGhost",{"title":294,"text":295,"url":296,"navIcon":297},"Mobile phishing (QR & SMS)","Detect phishing regardless of whether it arrives via email, SMS, or QR code.","/solution/stop-browser-based-attacks/mobile-phishing-qr-code-sms","solid:faQrcode",{"title":299,"text":300,"url":301,"navIcon":302},"Credential stuffing","Identify reused and compromised credentials across SaaS logins.","/solution/stop-browser-based-attacks/credential-stuffing","custom:credentialStuffing",{"title":304,"text":305,"url":306,"navIcon":307},"Session hijacking","Detect and respond to stolen session token replay with browser session markers.","/solution/stop-browser-based-attacks/session-hijacking","solid:faCookieBite",{"id":309,"label":310,"text":21,"navIcon":311,"items":312},"achieve-security-outcomes","Achieve security outcomes","solid:faCheckToSlot",[313,318,323,328,333,338,343,348],{"title":314,"text":315,"url":316,"navIcon":317},"Stop account takeover","Stop ATO with stolen credential and compromised token detection.","/solution/achieve-security-outcomes/stop-account-takeover","sharp-regular:faUserSecret",{"title":319,"text":320,"url":321,"navIcon":322},"Harden unmanaged identities","Harden access paths with visibility, detection, and guardrails.","/solution/achieve-security-outcomes/harden-unmanaged-identities","sharp-regular:faRadar",{"title":324,"text":325,"url":326,"navIcon":327},"Investigate browser-related incidents","Investigate and respond faster with unique browser telemetry.","/solution/achieve-security-outcomes/investigate-browser-related-incidents","sharp-regular:faSatelliteDish",{"title":329,"text":330,"url":331,"navIcon":332},"Secure shadow SaaS","See and control shadow SaaS in the browser.","/solution/achieve-security-outcomes/secure-shadow-saas","sharp-regular:faShieldCheck",{"title":334,"text":335,"url":336,"navIcon":337},"Secure AI","See and control AI apps in the browser.","/solution/achieve-security-outcomes/secure-ai","sharp-regular:faBrainCircuit",{"title":339,"text":340,"url":341,"navIcon":342},"Secure BYOD","Extend consistent browser-based protection to unmanaged devices.","/solution/achieve-security-outcomes/secure-bring-your-own-device","solid:faMobileScreenButton",{"title":344,"text":345,"url":346,"navIcon":347},"Secure Chromebooks","Secure browser activity on Chromebooks without endpoint agents.","/solution/achieve-security-outcomes/secure-chromebooks","brands:faChrome",{"title":349,"text":350,"url":351,"navIcon":352},"Investigate and stop data loss","Detect and prevent data loss across AI tools, apps, and sessions.","/solution/achieve-security-outcomes/investigate-and-stop-data-loss","custom:investigateAndStopDataLoss",{"id":354,"label":355,"text":21,"navIcon":356,"items":357},"tool-replacements","Tool replacements","solid:faScrewdriverWrench",[358,363,368,373],{"title":359,"text":360,"url":361,"navIcon":362},"Remote browser isolation","Detect attacks that look like normal browsing.","/solution/tool-replacements/remote-browser-isolation","solid:faDisplay",{"title":364,"text":365,"url":366,"navIcon":367},"Secure web gateways","Detect attacks inside the browser after SWGs allowed the connection.","/solution/tool-replacements/secure-web-gateways","solid:faFilter",{"title":369,"text":370,"url":371,"navIcon":372},"Cloud access security broker","Catch browser-based identity threats in real time, not after the fact.","/solution/tool-replacements/cloud-access-security-broker","solid:faCloudArrowUp",{"title":374,"text":375,"url":376,"navIcon":377},"Security awareness training","Block real phishing instead of training users on simulations.","/solution/tool-replacements/security-awareness-training","custom:securityAwareness",{"w":379,"h":380,"d":381},448,512,"M284.6 0l91.4 0 0 160-48 0 0-112-36.6 0-203.4 58.1 0 181.9 40 0 0 224-128 0 0-224 40 0 0-218.1 17.4-5 224-64 3.2-.9zM80 336l-32 0 0 128 32 0 0-128zm176 8c0-76.8 64-136 96-152 32 16 96 75.2 96 152 0 32-16 80-64 112l32 40 0 16-128 0 0-16 32-40c-48-32-64-80-64-112zm128-32a24 24 0 1 0 -48 0 24 24 0 1 0 48 0z",{"w":379,"h":380,"d":383},"M171-16c-36.4 0-57.8 58.3-68.3 112L72 96c-13.3 0-24 10.7-24 24s10.7 24 24 24l24 0 0 32c0 17 3.3 33.2 9.3 48l-9.3 0 0 0-20.5 0c-15.2 0-27.5 12.3-27.5 27.5 0 3 .5 5.9 1.4 8.7l28.9 86.6C40.2 379.6 16 428.1 16 482.3 16 498.7 29.3 512 45.7 512l356.6 0c16.4 0 29.7-13.3 29.7-29.7 0-54.2-24.2-102.7-62.3-135.4l28.9-86.6c.9-2.8 1.4-5.7 1.4-8.7 0-15.2-12.3-27.5-27.5-27.5l-20.5 0 0 0-9.3 0c6-14.8 9.3-31 9.3-48l0-32 24 0c13.3 0 24-10.7 24-24s-10.7-24-24-24l-30.7 0c-10.4-53.7-31.9-112-68.3-112-9.6 0-19 3.9-27.5 8.2-8.2 4.1-18.4 7.8-25.5 7.8s-17.3-3.7-25.5-7.8C190-12.1 180.6-16 171-16zm93.7 484.4l-24.8-70.9 27.9-32.5c2.7-3.2 4.2-7.2 4.2-11.4 0-9.7-7.8-17.5-17.5-17.5l-61 0c-9.7 0-17.5 7.8-17.5 17.5 0 4.2 1.5 8.2 4.2 11.4l27.9 32.5-24.8 70.9-57-180.4 35.7 0c18.4 10.2 39.5 16 62 16s43.6-5.8 62-16l35.7 0-57 180.4zM224 256c-34.7 0-64.2-22.1-75.3-53 5.7 3.2 12.3 5 19.3 5l12.4 0c16.5 0 31.1-10.6 36.3-26.2 2.3-7 12.2-7 14.5 0 5.2 15.6 19.9 26.2 36.3 26.2l12.4 0c7 0 13.6-1.8 19.3-5-11.1 30.9-40.6 53-75.3 53z",{"w":17,"h":380,"d":385},"M112 80l416 0 0 224 48 0 0-272-512 0 0 272 48 0 0-224zM48 404.1l0-4.1 544 0 0 4.1-27.9 27.9-488.2 0-27.9-27.9zM592 352l-592 0 0 72 56 56 528 0 56-56 0-72-48 0zM281 169l17-17-33.9-33.9c-6.1 6.1-27.8 27.8-65 65l-17 17c6.1 6.1 27.8 27.8 65 65l17 17 33.9-33.9c-9-9-25-25-48-48l31-31zM393 135l-17-17-33.9 33.9c9 9 25 25 48 48-23 23-39 39-48 48L376 281.9c6.1-6.1 27.8-27.8 65-65l17-17c-6.1-6.1-27.8-27.8-65-65z",{"w":379,"h":380,"d":387},"M0 64C0 28.7 28.7 0 64 0L384 0c35.3 0 64 28.7 64 64l0 384c0 35.3-28.7 64-64 64L64 512c-35.3 0-64-28.7-64-64L0 64zM256 432a32 32 0 1 0 -64 0 32 32 0 1 0 64 0zM384 64l-320 0 0 288 320 0 0-288z",{"w":17,"h":380,"d":389},"M192-32c17.7 0 32 14.3 32 32l0 96 128 0 0-96c0-17.7 14.3-32 32-32s32 14.3 32 32l0 96 64 0c17.7 0 32 14.3 32 32s-14.3 32-32 32l0 48.7c-98.6 8.1-176 90.7-176 191.3 0 27.3 5.7 53.3 16 76.9l0 3.1c0 17.7-14.3 32-32 32s-32-14.3-32-32l0-66.7C165.2 398.1 96 319.1 96 224l0-64c-17.7 0-32-14.3-32-32S78.3 96 96 96l64 0 0-96c0-17.7 14.3-32 32-32zM496 256a144 144 0 1 1 0 288 144 144 0 1 1 0-288zm59.3 107.3c6.2-6.2 6.2-16.4 0-22.6s-16.4-6.2-22.6 0l-36.7 36.7-36.7-36.7c-6.2-6.2-16.4-6.2-22.6 0s-6.2 16.4 0 22.6l36.7 36.7-36.7 36.7c-6.2 6.2-6.2 16.4 0 22.6s16.4 6.2 22.6 0l36.7-36.7 36.7 36.7c6.2 6.2 16.4 6.2 22.6 0s6.2-16.4 0-22.6l-36.7-36.7 36.7-36.7z",{"w":380,"h":380,"d":391},"M201.1 57.3c-7 5.3-9.1 10.7-9.1 14.7 0 4.5 2.8 11.2 12.4 16.9l11.6 7 0 48.1-168 0 0 60.5c7.4-2.9 15.5-4.5 24-4.5 43.1 0 72 39.4 72 80s-28.9 80-72 80c-8.5 0-16.6-1.6-24-4.5l0 108.5 108.5 0c-2.9-7.4-4.5-15.5-4.5-24 0-43.1 39.4-72 80-72s80 28.9 80 72c0 8.5-1.6 16.6-4.5 24l60.5 0 0-168 48.1 0 7 11.6c5.8 9.6 12.4 12.4 16.9 12.4 4 0 9.5-2.1 14.7-9.1s9.3-17.9 9.3-30.9-4-23.8-9.3-30.9-10.7-9.1-14.7-9.1c-4.5 0-11.2 2.8-16.9 12.4l-7 11.6-48.1 0 0-120-120 0 0-48.1 11.6-7c9.6-5.8 12.4-12.4 12.4-16.9 0-4-2.1-9.5-9.1-14.7S245 48 232 48 208.2 52 201.1 57.3zM172.3 18.9C188.5 6.8 209.6 0 232 0S275.5 6.8 291.7 18.9 320 49.5 320 72c0 8.6-1.8 16.7-4.9 24l100.9 0 0 100.9c7.3-3.1 15.4-4.9 24-4.9 22.5 0 41 12.2 53.1 28.3s18.9 37.3 18.9 59.7-6.8 43.5-18.9 59.7-30.6 28.3-53.1 28.3c-8.6 0-16.7-1.8-24-4.9l0 148.9-168 0 0-49.3 8.2-7.2c5.4-4.7 7.8-10.3 7.8-15.5 0-9.9-10.7-24-32-24s-32 14.1-32 24c0 5.3 2.4 10.8 7.8 15.5l8.2 7.2 0 49.3-216 0 0-216 49.3 0 7.2 8.2c4.7 5.4 10.3 7.8 15.5 7.8 9.9 0 24-10.7 24-32s-14.1-32-24-32c-5.3 0-10.8 2.4-15.5 7.8L49.3 264 0 264 0 96 148.9 96c-3.1-7.3-4.9-15.4-4.9-24 0-22.5 12.2-41 28.3-53.1z",{"w":393,"h":380,"d":394},576,"M96 0C60.7 0 32 28.7 32 64l0 384c0 35.3 28.7 64 64 64l180 0c-22.7-31.5-36-70.2-36-112 0-100.6 77.4-183.2 176-191.3l0-38.1c0-17-6.7-33.3-18.7-45.3L290.7 18.7C278.7 6.7 262.5 0 245.5 0L96 0zM357.5 176L264 176c-13.3 0-24-10.7-24-24L240 58.5 357.5 176zM432 544a144 144 0 1 0 0-288 144 144 0 1 0 0 288zm59.3-180.7l-36.7 36.7 36.7 36.7c6.2 6.2 6.2 16.4 0 22.6s-16.4 6.2-22.6 0l-36.7-36.7-36.7 36.7c-6.2 6.2-16.4 6.2-22.6 0s-6.2-16.4 0-22.6l36.7-36.7-36.7-36.7c-6.2-6.2-6.2-16.4 0-22.6s16.4-6.2 22.6 0l36.7 36.7 36.7-36.7c6.2-6.2 16.4-6.2 22.6 0s6.2 16.4 0 22.6z",{"w":396,"h":380,"d":397},384,"M40.1 467.1l-11.2 9C25.7 478.6 21.8 480 17.8 480 8 480 0 472 0 462.2L0 192C0 86 86 0 192 0S384 86 384 192l0 270.2c0 9.8-8 17.8-17.8 17.8-4 0-7.9-1.4-11.1-3.9l-11.2-9c-13.4-10.7-32.8-9-44.1 3.9L269.3 506c-3.3 3.8-8.2 6-13.3 6s-9.9-2.2-13.3-6l-26.6-30.5c-12.7-14.6-35.4-14.6-48.2 0L141.3 506c-3.3 3.8-8.2 6-13.3 6s-9.9-2.2-13.3-6L84.2 471c-11.3-12.9-30.7-14.6-44.1-3.9zM160 192a32 32 0 1 0 -64 0 32 32 0 1 0 64 0zm96 32a32 32 0 1 0 0-64 32 32 0 1 0 0 64z",{"w":379,"h":380,"d":399},"M64 160l64 0 0-64-64 0 0 64zM0 80C0 53.5 21.5 32 48 32l96 0c26.5 0 48 21.5 48 48l0 96c0 26.5-21.5 48-48 48l-96 0c-26.5 0-48-21.5-48-48L0 80zM64 416l64 0 0-64-64 0 0 64zM0 336c0-26.5 21.5-48 48-48l96 0c26.5 0 48 21.5 48 48l0 96c0 26.5-21.5 48-48 48l-96 0c-26.5 0-48-21.5-48-48l0-96zM320 96l0 64 64 0 0-64-64 0zM304 32l96 0c26.5 0 48 21.5 48 48l0 96c0 26.5-21.5 48-48 48l-96 0c-26.5 0-48-21.5-48-48l0-96c0-26.5 21.5-48 48-48zM288 352a32 32 0 1 1 0-64 32 32 0 1 1 0 64zm0 64c17.7 0 32 14.3 32 32s-14.3 32-32 32-32-14.3-32-32 14.3-32 32-32zm96 32c0-17.7 14.3-32 32-32s32 14.3 32 32-14.3 32-32 32-32-14.3-32-32zm32-96a32 32 0 1 1 0-64 32 32 0 1 1 0 64zm-32 32a32 32 0 1 1 -64 0 32 32 0 1 1 64 0z",{"w":380,"h":380,"d":401},"M257.5 27.6c-.8-5.4-4.9-9.8-10.3-10.6-22.1-3.1-44.6 .9-64.4 11.4l-74 39.5C89.1 78.4 73.2 94.9 63.4 115L26.7 190.6c-9.8 20.1-13 42.9-9.1 64.9l14.5 82.8c3.9 22.1 14.6 42.3 30.7 57.9l60.3 58.4c16.1 15.6 36.6 25.6 58.7 28.7l83 11.7c22.1 3.1 44.6-.9 64.4-11.4l74-39.5c19.7-10.5 35.6-27 45.4-47.2l36.7-75.5c9.8-20.1 13-42.9 9.1-64.9-.9-5.3-5.3-9.3-10.6-10.1-51.5-8.2-92.8-47.1-104.5-97.4-1.8-7.6-8-13.4-15.7-14.6-54.6-8.7-97.7-52-106.2-106.8zM208 144a32 32 0 1 1 0 64 32 32 0 1 1 0-64zM144 336a32 32 0 1 1 64 0 32 32 0 1 1 -64 0zm224-64a32 32 0 1 1 0 64 32 32 0 1 1 0-64z",{"w":379,"h":380,"d":403},"M144-16l-48 112-48 0 0 48 48 0 0 32c0 17 3.3 33.2 9.3 48l-73.3 0 0 32 5.3 16 26.7 80-64 160 51.7 0 56.9-142.2 6.5-16.3c-1-3.1-10.1-30.3-27.2-81.5l51.4 0c22.6 19.9 52.2 32 84.7 32s62.1-12.1 84.7-32l51.4 0c-17.1 51.2-26.1 78.4-27.2 81.5l6.5 16.3 56.9 142.2 51.7 0-64-160 26.7-80 5.3-16 0-32-73.3 0c6-14.8 9.3-31 9.3-48l0-32 48 0 0-48-48 0-48-112-32 0-48 32-48-32-32 0zm80 272c-32.8 0-61-19.7-73.3-48l57.3 0 16-40 16 40 57.3 0c-12.3 28.3-40.5 48-73.3 48zm17.5 139.6l30.5-35.6 0-24-96 0 0 24 30.5 35.6-46.5 116.4 128 0-46.5-116.4z",{"w":380,"h":380,"d":405},"M497.4 49l17-17-33.9-33.9C473.6 4.9 453.3 25.2 419.7 58.8 375.4 22.1 318.5 0 256.4 0 115.1 0 .4 114.6 .4 256s114.6 256 256 256 256-114.6 256-256l-48 0c0 114.9-93.1 208-208 208s-208-93.1-208-208 93.1-208 208-208c48.8 0 93.7 16.8 129.1 44.9l-45.7 45.7c-23.5-16.8-52.3-26.6-83.4-26.6-79.5 0-144 64.5-144 144s64.5 144 144 144 144-64.5 144-144l-48 0c0 53-43 96-96 96s-96-43-96-96 43-96 96-96c17.8 0 34.5 4.8 48.8 13.3-52 52-79.5 79.5-82.7 82.7l33.9 33.9 17-17 224-224z",{"w":380,"h":380,"d":407},"M208 0l24 0C386.6 0 512 125.4 512 280l0 24-48 0 0-24C464 151.9 360.1 48 232 48l-24 0 0-48zm24 96c101.6 0 184 82.4 184 184l0 24-48 0 0-24c0-75.1-60.9-136-136-136l-24 0 0-48 24 0zM48 256c0 114.9 93.1 208 208 208 22.9 0 45-3.7 65.6-10.5l-263-263C51.7 211 48 233.1 48 256zM0 256c0-36.5 7.6-71.3 21.4-102.7 6.7-15.3 14.9-29.9 24.4-43.5 7.7 7.7 61.5 61.5 161.2 161.2 30.5-30.5 49.5-49.5 57-57L297.9 248c-7.5 7.5-26.5 26.5-57 57 99.7 99.7 153.5 153.5 161.2 161.2-13.6 9.5-28.2 17.7-43.5 24.4-31.4 13.8-66.2 21.4-102.7 21.4-141.4 0-256-114.6-256-256z",{"w":380,"h":380,"d":409},"M267.6 4.5l207.5 80.5 19.2 7.4 1.2 20.5c2.9 50-4.9 126.3-37.3 200.9-32.7 75.2-91.1 150-189.4 192.5l-12.7 5.5-12.7-5.5C144.9 463.9 86.6 389.2 53.9 313.9 21.5 239.3 13.7 162.9 16.6 113L17.8 92.5 37 85 244.5 4.5 256 0 267.6 4.5zM64.1 126C63.1 169.5 71 232.9 97.9 294.8 126.1 359.7 175 422.4 256 459.6 337.1 422.4 385.9 359.7 414.2 294.8 441 232.9 449 169.5 448 126L256 51.5 64.1 126zm302.3 44.7L352.3 190.1 249.8 330.9 233 354c-8.8-9.1-30.9-32-66.2-68.6l-16.7-17.3 34.5-33.3c9.5 9.8 23.9 24.7 43.2 44.7l85.6-117.7 14.1-19.4 38.8 28.2z",{"w":380,"h":380,"d":411},"M192 48l40 0 0 108-12.4 0c-7.6-16.5-24.3-28-43.6-28-26.5 0-48 21.5-48 48s21.5 48 48 48c19.4 0 36.1-11.5 43.6-28l12.4 0 0 56-92 0 0 56.4c-16.5 7.6-28 24.3-28 43.6 0 26.5 21.5 48 48 48s48-21.5 48-48c0-19.4-11.5-36.1-28-43.6l0-16.4 52 0 0 172-40 0c-16.8 0-31.2-10.3-37.1-25.1l-6.4-16-17.2 1c-1.1 .1-2.2 .1-3.2 .1-30.9 0-56-25.1-56-56 0-9.5 2.4-18.5 6.5-26.3l8.7-16.2-13.4-12.6c-11-10.2-17.8-24.8-17.8-40.9 0-21.6 12.2-40.4 30.3-49.8l22.6-11.7-13.1-21.9c-5-8.4-7.9-18.1-7.9-28.6 0-30.9 25.1-56 56-56l24 0 0-32c0-13.3 10.7-24 24-24zm88 148l12.4 0c7.6 16.5 24.3 28 43.6 28 26.5 0 48-21.5 48-48s-21.5-48-48-48c-19.4 0-36.1 11.5-43.6 28l-12.4 0 0-108 40 0c13.3 0 24 10.7 24 24l0 32 24 0c30.9 0 56 25.1 56 56 0 10.5-2.9 20.3-7.9 28.6l-13.1 21.9 22.6 11.7c18 9.3 30.3 28.1 30.3 49.8 0 16.1-6.8 30.7-17.8 40.9l-13.4 12.6 8.7 16.2c4.2 7.8 6.5 16.7 6.5 26.3 0 30.9-25.1 56-56 56-1.1 0-2.2 0-3.2-.1l-17.2-1-6.4 16C351.2 453.7 336.8 464 320 464l-40 0 0-76 92 0 0-56.4c16.5-7.6 28-24.3 28-43.6 0-26.5-21.5-48-48-48s-48 21.5-48 48c0 19.4 11.5 36.1 28 43.6l0 16.4-52 0 0-152zM192 512l128 0c31.1 0 58.4-16.2 74.1-40.5 52.7-5.1 93.9-49.5 93.9-103.5 0-11.5-1.9-22.5-5.3-32.9 13.4-17.5 21.3-39.4 21.3-63.1 0-32-14.5-60.6-37.1-79.7 3.3-10.2 5.1-21.1 5.1-32.3 0-49.6-34.8-91.1-81.3-101.5-6.3-33.3-35.6-58.5-70.7-58.5L192 0c-35.1 0-64.4 25.2-70.7 58.5-46.5 10.4-81.3 51.9-81.3 101.5 0 11.3 1.8 22.2 5.1 32.3-22.7 19.1-37.1 47.7-37.1 79.7 0 23.7 8 45.6 21.3 63.1-3.5 10.4-5.3 21.4-5.3 32.9 0 54 41.2 98.5 93.9 103.5 15.6 24.3 42.9 40.5 74.1 40.5zM336 192a16 16 0 1 1 0-32 16 16 0 1 1 0 32zm32 96a16 16 0 1 1 -32 0 16 16 0 1 1 32 0zM176 352a16 16 0 1 1 -32 0 16 16 0 1 1 32 0zm16-176a16 16 0 1 1 -32 0 16 16 0 1 1 32 0z",{"w":396,"h":380,"d":413},"M16 64C16 28.7 44.7 0 80 0L304 0c35.3 0 64 28.7 64 64l0 384c0 35.3-28.7 64-64 64L80 512c-35.3 0-64-28.7-64-64L16 64zm64 0l0 304 224 0 0-304-224 0zM192 472c17.7 0 32-14.3 32-32s-14.3-32-32-32-32 14.3-32 32 14.3 32 32 32z",{"w":380,"h":380,"d":415},"M0 256c0-46.6 12.5-90.4 34.3-128.9L144.1 318.3c21.9 39.2 63.8 65.7 111.9 65.7 14.3 0 27.1-2.3 40.8-6.6L220.5 509.6C95.9 492.3 0 385.3 0 256zm365.1 65.6c12.3-19.2 18.9-42.5 18.9-65.6 0-38.2-16.8-72.5-43.3-96l152.7 0c12 29.6 18.6 62.1 18.6 96 0 141.4-114.6 255.1-256 256L365.1 321.6zM477.8 128L256 128c-62.9 0-113.7 44.1-125.5 102.7L54.2 98.5C101 38.5 174 0 256 0 350.8 0 433.5 51.5 477.8 128zM344 256a88 88 0 1 1 -176 0 88 88 0 1 1 176 0z",{"w":380,"h":380,"d":417},"M448 96l0 256-384 0 0-256 384 0zM64 32C28.7 32 0 60.7 0 96L0 352c0 35.3 28.7 64 64 64l144 0-16 48-72 0c-13.3 0-24 10.7-24 24s10.7 24 24 24l272 0c13.3 0 24-10.7 24-24s-10.7-24-24-24l-72 0-16-48 144 0c35.3 0 64-28.7 64-64l0-256c0-35.3-28.7-64-64-64L64 32z",{"w":380,"h":380,"d":419},"M32 64C19.1 64 7.4 71.8 2.4 83.8S.2 109.5 9.4 118.6L192 301.3 192 416c0 8.5 3.4 16.6 9.4 22.6l64 64c9.2 9.2 22.9 11.9 34.9 6.9S320 492.9 320 480l0-178.7 182.6-182.6c9.2-9.2 11.9-22.9 6.9-34.9S492.9 64 480 64L32 64z",{"w":393,"h":380,"d":421},"M144 480c-79.5 0-144-64.5-144-144 0-63.4 41-117.2 97.9-136.5-1.3-7.7-1.9-15.5-1.9-23.5 0-79.5 64.5-144 144-144 55.4 0 103.5 31.3 127.6 77.1 14.2-8.3 30.8-13.1 48.4-13.1 53 0 96 43 96 96 0 15.7-3.8 30.6-10.5 43.7 44 20.3 74.5 64.7 74.5 116.3 0 70.7-57.3 128-128 128l-304 0zM305 191c-9.4-9.4-24.6-9.4-33.9 0l-72 72c-9.4 9.4-9.4 24.6 0 33.9s24.6 9.4 33.9 0l31-31 0 102.1c0 13.3 10.7 24 24 24s24-10.7 24-24l0-102.1 31 31c9.4 9.4 24.6 9.4 33.9 0s9.4-24.6 0-33.9l-72-72z",{"createdDate":423,"data":424,"id":636,"lastUpdated":637,"meta":638,"modelId":642,"name":450,"published":13,"query":643,"createdBy":437,"folders":648,"lastUpdatedBy":33,"stageModifiedSincePublish":6,"testRatio":31,"variations":649,"firstPublished":650,"screenshot":651,"rev":652},1785844281858,{"family":425,"navIcon":257,"navText":255,"navTitle":254,"seoDescription":442,"seoTitle":443,"state":444,"themeId":6,"title":450,"url":256,"blocks":451},{"@type":114,"id":426,"model":427,"value":428},"c14dccfdfec140d1a8f5659be2f1374b","solution-family",{"createdDate":429,"id":426,"name":250,"modelId":430,"published":13,"stageModifiedSincePublish":6,"query":431,"data":432,"variations":434,"lastUpdated":435,"firstPublished":436,"testRatio":31,"createdBy":437,"lastUpdatedBy":437,"folders":438,"meta":439,"rev":441},1786446972915,"0b5c4d3a8ecb40a5ace2da0332804a47",[],{"label":250,"slug":249,"tagLine":433,"navIcon":251},"Stop attacks that bypass your existing controls.",{},1786447017070,1786447017059,"SfUPqW5tkibIPby49keNFMdHFTr1",[],{"breakpoints":440,"kind":20,"hasErrors":6,"lastPreviewUrl":21,"hasAutosaves":6},{"xsmall":18,"small":17,"medium":16},"s1irnmxrcfe","Traditional phishing defenses rely on known indicators. Push detects phishing through behavior inside the browser, catching attacks that reputation tools never see.","Zero-day phishing evades detection by design",{"deviceSize":91,"location":445},{"pathname":256,"path":446,"query":449},[447,249,448],"solution","zero-day-phishing",{},"Stop Browser-based Attacks / Zero-day phishing",[452,472,482,495,501,526,534,565,573,621,631],{"@type":44,"@version":45,"id":453,"meta":454,"component":456,"responsiveStyles":470},"builder-9b27687fbe9bdff51def7b737529b8cb",{"previousId":455},"builder-5bfd2b742f4a4ddba11b6c784661734d",{"name":457,"tag":457,"options":458,"isRSC":59},"SolutionHero",{"headingLevel":459,"showTrustedBy":6,"title":460,"headingSize":461,"bodyText":462,"bullets":463,"cta":464,"graphic":467,"graphicAltText":468,"spacingBottom":469},"h1","\u003Cp class=\"\">Phishing attacks: how to detect and stop modern phishing\u003C/p>","2xl","\u003Cp class=\"\">Modern phishing attacks evade email security, SWGs, and blocklists. Learn how behavioral phishing detection in the browser catches attacks that traditional tools miss.\u003C/p>",[],{"label":465,"url":466},"Book a demo","/demo","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F8a1f3ab3f1614290b8c9ebbaad6d8690","Geometry graphic","medium",{"large":471},{"display":62,"flexDirection":63,"position":64,"flexShrink":65,"boxSizing":66},{"@type":44,"@version":45,"id":473,"component":474,"responsiveStyles":480},"builder-4bb5b65895684130b9c7a2aabc214975",{"name":475,"tag":475,"options":476,"isRSC":59},"CurvedDiagonalUp",{"colourAbove":477,"colourBelow":478,"showAccentLine":19,"spacingBottom":479},"transparent","white","small",{"large":481},{"display":62,"flexDirection":63,"position":64,"flexShrink":65,"boxSizing":66},{"@type":44,"@version":45,"id":483,"component":484,"responsiveStyles":493},"builder-cdd8e284dee04e28a2d2dbf87a28900b",{"name":485,"tag":485,"options":486,"isRSC":59},"FlexiContentBlock",{"headingLevel":487,"alignment":488,"backgroundColour":478,"textColour":489,"spacingBottom":89,"title":490,"content":491,"headingSize":492},"h2","center","black","\u003Cp class=\"\">Phishing attacks are outpacing the tools built to stop them\u003C/p>","\u003Cp>Phishing is a social engineering attack that tricks people into revealing credentials, authorizing access, or executing malicious actions by impersonating a trusted entity. For most of its history, phishing meant a fraudulent email containing a link to a fake login page — and the defenses built to stop it reflected that: email gateways scanned messages, URL reputation services flagged known-bad domains, and blocklists catalogued reported phishing infrastructure.\u003C/p>\u003Cp>That model no longer matches how phishing works. Modern phishing is multi-channel (delivered through search ads, \u003Ca href=\"/solution/stop-browser-based-attacks/mobile-phishing-qr-code-sms\" rel=\"noopener noreferrer\">QR codes\u003C/a>, messaging apps, and social platforms as well as email), industrialized (Phishing-as-a-Service platforms automate infrastructure rotation and provide subscription access to \u003Ca href=\"/solution/stop-browser-based-attacks/adversary-in-the-middle-attacks\" rel=\"noopener noreferrer\">AiTM\u003C/a> reverse proxies that bypass MFA), and evasive (89% of phishing domains are active for fewer than two days, and 95% of in-browser attacks detected by Push used bot protection to block automated scanning). The defenses built around email gateways and domain reputation address one delivery channel using indicators that attackers rotate faster than defenses can track.\u003C/p>","xl",{"large":494},{"display":62,"flexDirection":63,"position":64,"flexShrink":65,"boxSizing":66},{"@type":44,"@version":45,"id":496,"component":497,"responsiveStyles":499},"builder-3454d25139db438aa3345414f3813219",{"name":475,"tag":475,"options":498,"isRSC":59},{"colourAbove":478,"colourBelow":489,"showAccentLine":19,"spacingBottom":479},{"large":500},{"display":62,"flexDirection":63,"position":64,"flexShrink":65,"boxSizing":66},{"@type":44,"@version":45,"id":502,"component":503,"responsiveStyles":524},"builder-79c098f1c59e171316f6a62c4e51e76b",{"name":504,"tag":504,"options":505,"isRSC":59},"HowTheAttackWorks",{"headingLevel":487,"spacingBottom":89,"title":506,"headingSize":492,"subtext":507,"steps":508,"endtext":523},"\u003Cp class=\"\">How modern phishing attacks work\u003C/p>","\u003Cp class=\"\">Phishing infrastructure is no longer static. Attackers generate new domains, pages, and delivery methods continuously, often for a single campaign or even a single target.\u003C/p>",[509,512,515,518,520],{"icon":510,"text":511},"browser","The attacker creates a phishing page using a kit or AI-generated template",{"icon":513,"text":514},"bolt","Infrastructure is spun up on trusted or newly registered domains",{"icon":516,"text":517},"relay","The lure is delivered through email, messaging apps, search ads, or social platforms",{"icon":510,"text":519},"The page is only active when triggered, often disappearing after use",{"icon":521,"text":522},"warning","The attacker rotates infrastructure and repeats the process","\u003Cp class=\"\">The dominant phishing technique is \u003Ca href=\"/solution/stop-browser-based-attacks/adversary-in-the-middle-attacks\" rel=\"noopener noreferrer\">adversary-in-the-middle\u003C/a> — a reverse proxy sits between the user and the real login page, capturing credentials, MFA tokens, and \u003Ca href=\"/solution/stop-browser-based-attacks/session-hijacking\" rel=\"noopener noreferrer\">session cookies\u003C/a> in real time. AiTM kits like Tycoon 2FA, Evilginx, and EvilProxy are sold as PhaaS subscriptions, lowering the barrier to entry and increasing campaign volume.\u003C/p>\u003Cp class=\"\">Phishing is no longer just an email problem. Push data shows one in three phishing payloads originates outside email — through search ads, \u003Ca href=\"/solution/stop-browser-based-attacks/mobile-phishing-qr-code-sms\" rel=\"noopener noreferrer\">QR codes, SMS\u003C/a>, messaging apps, and social platforms. Many attacks exist for minutes or hours, not days. By the time a domain is identified and blocked, the attacker has already moved on.\u003C/p>",{"large":525},{"display":62,"flexDirection":63,"position":64,"flexShrink":65,"boxSizing":66},{"@type":44,"@version":45,"id":527,"meta":528,"component":530,"responsiveStyles":532},"builder-ba049f9389f3bec3bd15c528e1dd30a8",{"previousId":529},"builder-a4c7d322c52f40dc8b360f5359ad06d9",{"name":475,"tag":475,"options":531,"isRSC":59},{"colourAbove":477,"colourBelow":478,"showAccentLine":19,"spacingBottom":479},{"large":533},{"display":62,"flexDirection":63,"position":64,"flexShrink":65,"boxSizing":66},{"@type":44,"@version":45,"id":535,"meta":536,"component":538,"responsiveStyles":563},"builder-2c3d4bfb132249cd52d62babec9942ad",{"previousId":537},"builder-92d11bc52a3a458cb54252cb9f8dead5",{"name":539,"tag":539,"options":540,"isRSC":59},"AlternatingRows",{"headingLevel":487,"backgroundColour":541,"defaultTextColour":542,"mobileStart":543,"desktopStart":544,"desktopBreakpoint":545,"spacingBottom":479,"headingSize":492,"rows":546,"imageFrame":561},"#ffffff","#000000","text","image","lg",[547,552,557],{"title":548,"content":549,"image":550,"imageAltText":551},"\u003Ch2 class=\"\">Why traditional phishing defenses fall short\u003C/h2>","\u003Cp class=\"\">Traditional phishing defenses rely on known indicators: domains, URLs, signatures, and reputation. Modern phishing avoids all of them. Domains are newly created or short-lived — 89% of phishing domains are active for fewer than two days. Pages are dynamically generated. Infrastructure is rotated constantly. There is nothing stable to block.\u003C/p>\u003Cp class=\"\">In 2025, 95% of in-browser attacks detected by Push used bot protection services to actively block web scanning tools. The phishing page only appears when the attacker allows it — preventing automated scanning and analysis. Even when a link is analyzed, it may appear harmless; the malicious behavior only occurs when a real user interacts with the page in a browser session.\u003C/p>\u003Cp class=\"\">Email security is structurally limited to one delivery channel. It can't inspect \u003Ca href=\"/solution/stop-browser-based-attacks/mobile-phishing-qr-code-sms\" rel=\"noopener noreferrer\" class=\"\">QR codes\u003C/a>, SMS links, search ads, or social media messages. \u003Ca href=\"/solution/tool-replacements/secure-web-gateways\" rel=\"noopener noreferrer\" class=\"\">Secure web gateways\u003C/a> rely on URL categorization and domain reputation that don't exist for zero-day infrastructure, and phishing kits evade scanners by using bot protection tools. The underlying problem is that most phishing defenses analyze indicators rather than behavior.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F257f2ac90b6a4503bee4181cbd959a5f","Diagram showing how zero-day phishing evades email filters and URL reputation tools by using newly registered domains, dynamic pages, and bot detection.",{"title":553,"content":554,"image":555,"imageAltText":556},"\u003Ch2 class=\"\">How do you detect and stop modern phishing?\u003C/h2>","\u003Cp class=\"\">You can't block modern phishing by cataloguing known-bad infrastructure — attackers generate and discard it faster than any feed can track — so detection has to shift from indicators to behavior: analyzing what a page does rather than where it's hosted or how the link was delivered.\u003C/p>\u003Cp>Email security, SWGs, and URL reputation services still catch a portion of phishing — particularly campaigns that reuse infrastructure or target organizations without advanced defenses. They're worth keeping as a first layer. But the attacks that get through are the ones using fresh infrastructure, trusted domain hosting, bot protection, and non-email delivery channels. Catching those requires a detection layer that operates at the destination page — inside the browser, where the phishing page renders and where the user interacts with it — rather than at the delivery channel or network layer. \u003C/p>\u003Cp>Browser-level behavioral detection is the layer that closes this gap: it sees the page as the user sees it, after JavaScript execution and bot protection checks, and it applies regardless of delivery channel or device management status.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fc06aec22e0754904a3ecd9473983fe63","Push Security real-time browser alert detecting zero-day phishing behavior and blocking credential theft before the user submits their login details.",{"title":558,"content":559,"image":560,"imageAltText":556},"\u003Ch2 class=\"\">How Push detects and stops phishing, regardless of technique, payload, or delivery channel\u003C/h2>","\u003Cp class=\"\">Push detects phishing based on behavior, not static indicators. By operating inside the browser, it observes how pages load, how users interact with them, and when the page attempts to capture credentials or session data. Push targets techniques: \u003Ca href=\"/solution/stop-browser-based-attacks/adversary-in-the-middle-attacks\" rel=\"noopener noreferrer\" class=\"\">AiTM\u003C/a> reverse proxy behavior, cloned login page construction, Browser-in-the-Browser pop-ups, credential harvesting mechanics, and bot protection/anti-analysis evasion.\u003C/p>\u003Cp class=\"\">Push also detects the phishing-adjacent social engineering techniques that traditional phishing tools miss entirely. Device code phishing — where attackers abuse the OAuth device authorization grant to redirect tokens to attacker-controlled infrastructure — is detected and blocked in real time through behavioral detection of device code phishing kits. \u003Ca href=\"/solution/stop-browser-based-attacks/clickfix-fix-variants\" rel=\"noopener noreferrer\" class=\"\">ClickFix\u003C/a> attacks, which trick users into executing malicious clipboard commands rather than entering credentials, are caught through malicious copy-and-paste detection.\u003C/p>\u003Cp class=\"\">Detection happens at the point of interaction — when the user visits the page, before credentials are entered. This is real-time phishing detection, not after-the-fact alerting. Security teams can view additional information about the detection in the Push platform, and can easily feed these alerts to their SIEM or SOAR of choice via webhook or API.\u003C/p>","https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fe276e444dbf64f5e9258627989aeedb4",{"border":489,"borderStyle":562,"corners":461,"shadow":492},"offsetThick",{"large":564},{"display":62,"flexDirection":63,"position":64,"flexShrink":65,"boxSizing":66},{"@type":44,"@version":45,"id":566,"meta":567,"component":569,"responsiveStyles":571},"builder-ff422114573ceabcc284f2765062490f",{"previousId":568},"builder-54f7635f925c4d859361127f34a19d4b",{"name":475,"tag":475,"options":570,"isRSC":59},{"colourAbove":478,"colourBelow":489,"showAccentLine":19,"spacingBottom":469},{"large":572},{"display":62,"flexDirection":63,"position":64,"flexShrink":65,"boxSizing":66},{"@type":44,"@version":45,"id":574,"component":575,"responsiveStyles":619},"builder-a5d45b49e0150c0555ea3bee2f70507a",{"name":576,"tag":576,"options":577,"isRSC":59},"Faqs",{"eyebrow":21,"title":578,"headingLevel":487,"spacingBottom":479,"headingSize":492,"faqs":579},"Frequently asked questions",[580,583,586,589,592,595,598,601,604,607,610,613,616],{"question":581,"answer":582},"What is a phishing kit?","\u003Cp class=\"\">A pre-packaged toolkit that enables attackers to deploy phishing infrastructure quickly — typically including cloned login page templates, credential capture mechanisms, hosting automation, and anti-detection features. Modern phishing kits operate as Phishing-as-a-Service (PhaaS) platforms with subscription access, customer support, and automated infrastructure rotation.\u003C/p>\u003Cp class=\"\">AiTM kits (such as Tycoon 2FA, Evilginx, Sneaky 2FA) include reverse proxy functionality that captures post-MFA session tokens. \u003Ca href=\"/solution/stop-browser-based-attacks/clickfix-fix-variants\" rel=\"noopener noreferrer\" class=\"\">ClickFix\u003C/a> kits include clipboard hijacking and fake CAPTCHA templates. \u003C/p>\u003Cp class=\"\">Push detects phishing kits at the technique-class level — targeting behavioral signatures (reverse proxy behavior, credential harvesting, clipboard manipulation) — meaning detections remain effective across many kits and configurations.\u003C/p>",{"question":584,"answer":585},"What is zero-day phishing?","\u003Cp>Phishing attacks using newly created infrastructure — domains, pages, and kits — that haven&#39;t been identified or blocklisted by any security vendor. The phishing page is &quot;zero-day&quot; in the sense that no threat intelligence exists for it when the user encounters it.\u003C/p>\u003Cp>This isn&#39;t a niche problem — 89% of phishing domains are active for fewer than two days. Attackers spin up infrastructure, use it for a campaign, and discard it before blocklists react. Any defense relying on &quot;known-bad&quot; indicators has a structural detection lag. Push detects phishing behaviorally — analyzing page structure and phishing kit mechanics at the rendered-page level.\u003C/p>",{"question":587,"answer":588},"How do I stop phishing attacks that bypass my security tools?","\u003Cp class=\"\">Phishing succeeds because the defenses most organizations have deployed rely on known indicators — domains, URLs, and file hashes — and modern phishing operations rotate those indicators faster than any blocklist or reputation service can track. The tools aren't failing at what they do; the attack has moved beyond what they were designed to catch.\u003C/p>\u003Cp class=\"\">Infrastructure rotation means phishing domains are discarded and replaced before blocklists react. Trusted domain abuse means attackers host phishing pages on microsoft.com, google.com, chatgpt.com, and other domains that no reputation filter would block. Bot protection means the phishing page only appears to real users — 95% of in-browser attacks detected by Push used anti-analysis services that serve benign content to automated scanners. And multi-channel delivery means phishing arrives through search ads, \u003Ca href=\"/solution/stop-browser-based-attacks/mobile-phishing-qr-code-sms\" rel=\"noopener noreferrer\" class=\"\">QR codes\u003C/a>, SMS, messaging apps, and social platforms as well as email — but email security only covers one of those channels. The root cause is that most phishing defenses analyze indicators rather than behavior.\u003C/p>",{"question":590,"answer":591},"How do I detect phishing sites that haven't been reported yet?","\u003Cp class=\"\">Blocklist-based detection requires someone to report a site before it can be blocked — which means every new phishing page gets at least one victim before defenses react. Behavioral phishing detection eliminates that gap by analyzing page behavior in real time, identifying phishing kit mechanics regardless of whether the domain has been seen before.\u003C/p>\u003Cp class=\"\">Push detects unreported phishing sites because phishing kits have behavioral signatures that persist across campaigns, domains, and infrastructure rotation. Even on a brand-new domain with no threat intelligence, the kit's mechanics are recognizable.\u003C/p>",{"question":593,"answer":594},"Can a secure web gateway stop modern phishing?","\u003Cp class=\"\">No. SWGs rely on URL categorization and domain reputation — indicators that don't exist for zero-day infrastructure. Some SWGs offer real-time URL analysis, but phishing kits with bot protection serve benign content to automated scanners.\u003C/p>\u003Cp class=\"\">Push operates inside the browser as the user sees it, detecting phishing kit behavior at the rendered-page level. The two are complementary: \u003Ca href=\"/solution/tool-replacements/secure-web-gateways\" rel=\"noopener noreferrer\" class=\"\">SWGs\u003C/a> for known-bad blocking, Push for zero-day behavioral detection. Read about SWG limitations.\u003C/p>",{"question":596,"answer":597},"Can email security stop modern phishing links?","\u003Cp class=\"\">Email security can catch some through time-of-click URL analysis and sandboxing, but effectiveness is limited. Phishing kits with bot protection defeat automated scanners. URL reputation checks miss newly created domains. And a growing share of phishing arrives outside email entirely.\u003C/p>\u003Cp class=\"\">Push detects the phishing page itself, regardless of whether the link was already known-bad and regardless of delivery method.\u003C/p>",{"question":599,"answer":600},"What is behavioral phishing detection?","\u003Cp class=\"\">Identifying phishing by analyzing what a page does — its DOM structure, script behavior, credential-harvesting mechanics, and user interaction patterns — rather than matching against known indicators. It detects the technique, not the specific instance.\u003C/p>\u003Cp class=\"\">Push targets technique-class signatures: AiTM reverse proxy behavior, cloned login page construction, Browser-in-the-Browser pop-ups, ClickFix clipboard manipulation, and credential-harvesting patterns. These remain consistent even as attackers rotate infrastructure. \u003Ca href=\"/blog/the-pyramid-of-pain-in-the-ai-era\" rel=\"noopener noreferrer\" class=\"\">Read about the Pyramid of Pain and behavioral detection\u003C/a>.\u003C/p>",{"question":602,"answer":603},"Why do phishing attacks get through my email filter?","\u003Cp>Infrastructure rotation: phishing domains are active fewer than two days, outpacing blocklists. Trusted domain abuse: hosting phishing on microsoft.com, google.com, or chatgpt.com. Bot protection: serving benign content to automated scanners. Non-email delivery: a significant share of phishing arrives via channels email filters never see.\u003C/p>\u003Cp>The underlying problem is structural — email filters analyze links, but the phishing attack lives in the rendered page. Push operates at the destination, detecting phishing behavior inside the browser. \u003Ca href=\"/blog/phishing-detection-evasion-launch\">Read about phishing evasion techniques\u003C/a>.\u003C/p>",{"question":605,"answer":606},"How long are phishing pages active for before being taken down?","\u003Cp>89% of phishing domains are active for fewer than two days, with just 6.5% surviving more than 15 days. PhaaS platforms automate this rotation — generating fresh infrastructure for each campaign and discarding it before blocklists react.\u003C/p>\u003Cp>This speed makes any indicator-based defense structurally too slow. Push detects phishing behaviorally at the page level, so domain rotation is irrelevant. \u003Ca href=\"/blog/the-pyramid-of-pain-in-the-ai-era\">Read about the Pyramid of Pain\u003C/a>.\u003C/p>",{"question":608,"answer":609},"How do I detect AI-generated phishing pages?","\u003Cp>Focus on page behavior, not content quality. AI-generated phishing pages can look visually identical to the real login page while having no resemblance to its underlying code — the attacker describes what they want and the AI builds it from scratch. This defeats detection that relies on visual tells (grammar errors, awkward branding) and makes template-matching against known page structures less reliable. But AI doesn&#39;t change the underlying phishing mechanics. The page still needs to harvest credentials, proxy authentication, or execute malicious code.\u003C/p>\u003Cp>Push&#39;s behavioral detection targets those mechanics. An AI-generated AiTM proxy still exhibits reverse proxy behavior. An AI-generated ClickFix page still manipulates the clipboard. Content quality is irrelevant to the detection model. \u003Ca href=\"/blog/the-pyramid-of-pain-in-the-ai-era\">Read about AI and phishing\u003C/a>.\u003C/p>",{"question":611,"answer":612},"How do attackers create convincing Microsoft 365 phishing pages?","\u003Cp class=\"\">AiTM kits like Tycoon 2FA and Evilginx proxy the real login page from a cloned frontend, either by literally cloning the real page (with some changes to evade fingerprinting controls looking for this) or asking an AI tool to recreate a page from a screenshot. The latter approach usually results in a convincing appearance without any overlap in the codebase or structure of the page, and is a highly effective way of evading detection controls based on cloned page signatures. \u003C/p>\u003Cp class=\"\">Push detects both — AiTM reverse proxy behavior and cloned login page signatures — regardless of the domain hosting them. \u003Ca href=\"/blog/2025-top-phishing-trends\" rel=\"noopener noreferrer\" class=\"\">Read about phishing kit techniques\u003C/a>.\u003C/p>",{"question":614,"answer":615},"How do I detect phishing pages that target Okta or Google Workspace credentials?","\u003Cp class=\"\">The approaches most organizations rely on don't hold up well here. URL blocklists and Safe Browsing miss phishing on newly registered domains — most are active for less than two days. Domain monitoring and brand protection only catch typosquatting, not phishing hosted on unrelated or legitimate domains. Email link scanning only covers email-delivered phishing, missing search ads, QR codes, social media, and direct navigation. IdP-side defenses like Okta ThreatInsight use IP reputation, which residential proxies defeat.\u003C/p>\u003Cp class=\"\">Behavioral detection in the browser is the approach that works regardless of IdP. Push identifies AiTM reverse proxy behavior, cloned login page signatures, and credential harvesting patterns at the rendered-page level — the phishing technique is the same whether the kit impersonates Microsoft, Okta, or Google. Read about behavioral phishing detection.\u003C/p>",{"question":617,"answer":618},"What are the most common phishing kits targeting enterprise SSO providers?","\u003Cp class=\"\">For Microsoft 365: Tycoon 2FA, Sneaky 2FA, FlowerStorm, Evilginx, EvilProxy, and NakedPages. For Google Workspace: Evilginx, EvilProxy, and NakedPages. For Okta: Evilginx and real-time operated panels like Doko's Panel. Most kits — such as Evilginx, EvilProxy, and Doko's Panel — support multiple targets.\u003C/p>\u003Cp class=\"\">Push detects phishing kits at the technique-class level — targeting reverse proxy behavior, credential harvesting, and cloned login page signatures.\u003C/p>",{"large":620},{"display":62,"flexDirection":63,"position":64,"flexShrink":65,"boxSizing":66},{"@type":44,"@version":45,"id":622,"meta":623,"component":625,"responsiveStyles":629},"builder-578ab374aa43eabfc6365d5570a79547",{"previousId":624},"builder-3ab9ff8f2d2c487cac928bac24d7ace1",{"name":626,"tag":626,"options":627,"isRSC":59},"LatestResources",{"sectionHeading":628,"customClass":21},"Latest resources",{"large":630},{"display":62,"flexDirection":63,"position":64,"flexShrink":65,"boxSizing":66},{"id":632,"@type":44,"tagName":80,"properties":633,"responsiveStyles":634},"builder-pixel-e6138xlfbbm",{"src":82,"aria-hidden":83,"alt":21,"role":84,"width":65,"height":65},{"large":635},{"height":65,"width":65,"display":87,"opacity":65,"overflow":88,"pointerEvents":89},"85107fa5109a4a2fa29f4d32c1d14a6c",1787823919946,{"breakpoints":639,"hasAutosaves":6,"hasErrors":6,"hasLinks":6,"kind":640,"lastPreviewUrl":641},{"medium":16,"small":17,"xsmall":18},"page","https://pushsecurity.com/solution/stop-browser-based-attacks/zero-day-phishing?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CcreateProjects%2CsendPullRequests%2CfusionHostingPublish&builder.user.role.name=Designer&builder.user.role.id=creator&builder.cachebust=true&builder.preview=solution-page&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.solution-page=85107fa5109a4a2fa29f4d32c1d14a6c&builder.overrides.85107fa5109a4a2fa29f4d32c1d14a6c=85107fa5109a4a2fa29f4d32c1d14a6c&builder.overrides.solution-page:/solution/stop-browser-based-attacks/zero-day-phishing=85107fa5109a4a2fa29f4d32c1d14a6c&builder.options.includeRefs=true&builder.options.enrich=true&builder.options.locale=Default","cec930b3522a47c7b449e8acbeec909c",[644],{"@type":645,"operator":646,"property":647,"value":256},"@builder.io/core:Query","is","urlPath",[],{},1785856976395,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F92b0b7bd24da4f94ac87b6080891c0a8","d71hhrr022d",[654,6592,10713,13823],{"id":655,"title":656,"authorsCollection":657,"content":667,"extension":1410,"faqItemsCollection":1411,"faqTitle":1600,"featured":6,"hashTags":59,"meta":1601,"metaTitle":1602,"ogImage":59,"postType":1603,"publishedDate":1604,"relatedBlogPostsCollection":1605,"slug":6529,"stem":6530,"subtitle":59,"summary":6531,"synopsis":6542,"sys":6543,"tagsCollection":6546,"topicsCollection":6552,"__hash__":6591},"blog/blog/authorization-phishing.json","Authorization phishing: why attackers stopped targeting the login",{"items":658},[659],{"fullName":660,"firstName":661,"jobTitle":662,"socialLinks":663,"profilePicture":665},"Luke Jennings","Luke","Vice President, R&D",[664],"https://www.linkedin.com/in/luke-jennings-042b5619b/",{"url":666},"https://images.ctfassets.net/y1cdw1ablpvd/4Hosb4zKi1dA0PUyDLMe1h/27e09d894861f2196ba794037986fb08/T016S22KZ96-U02NVQM7ZD4-57761d542d83-512.jpeg",{"json":668,"links":1325},{"nodeType":669,"data":670,"content":671},"document",{},[672,680,687,707,728,755,786,795,799,808,815,822,828,837,849,868,874,882,917,923,930,937,945,957,975,993,996,1004,1011,1018,1026,1033,1049,1061,1073,1080,1092,1099,1106,1112,1120,1127,1134,1137,1145,1152,1159,1165,1189,1208,1226,1232,1235,1243,1255,1267,1279,1286,1294],{"nodeType":673,"data":674,"content":675},"paragraph",{},[676],{"nodeType":543,"value":677,"marks":678,"data":679},"For most of phishing's history, the objective was simple: steal the credential. Whether through a fake login page twenty years ago or through an attacker in the middle (AiTM) reverse proxy today, the entire attack chain has been oriented around defeating authentication. So defenders have focused on making the login harder to compromise.",[],{},{"nodeType":673,"data":681,"content":682},{},[683],{"nodeType":543,"value":684,"marks":685,"data":686},"This investment is starting to pay off. While MFA as a blanket control is routinely defeated by AiTM attacks (the default phishing method today), phishing-resistant passkeys are used in a relatively small number of logins, but growing steadily each year. And core identity platforms are taking steps to make them the default method. For example, Microsoft is making passkeys the default sign-in method for Entra ID from September 2026, and users stuck on SMS or voice authentication will be force-migrated. ",[],{},{"nodeType":673,"data":688,"content":689},{},[690,694,703],{"nodeType":543,"value":691,"marks":692,"data":693},"AiTM phishing kits remain dominant, but the detection surface is improving — behavioral detections now catch the kit's page behavior regardless of the domain it's hosted on. Authentication controls are genuinely getting harder to beat (though even with passkeys, not impossible, as shown in ",[],{},{"nodeType":695,"data":696,"content":698},"hyperlink",{"uri":697},"https://pushsecurity.com/blog/mfa-downgrade-attacks",[699],{"nodeType":543,"value":700,"marks":701,"data":702},"downgrade attacks",[],{},{"nodeType":543,"value":704,"marks":705,"data":706}," — shown in the video below).",[],{},{"nodeType":673,"data":708,"content":709},{},[710,714,724],{"nodeType":543,"value":711,"marks":712,"data":713},"So it makes sense that attackers are looking for alternatives. In 2026, we’ve seen ",[],{},{"nodeType":695,"data":715,"content":717},{"uri":716},"https://pushsecurity.com/blog/device-code-phishing",[718],{"nodeType":543,"value":719,"marks":720,"data":723},"device code phishing",[721],{"type":722},"underline",{},{"nodeType":543,"value":725,"marks":726,"data":727}," explode into mainstream adoption, with 30+ distinct kits now offering the technique (this number jumps every time we write a new update). ",[],{},{"nodeType":673,"data":729,"content":730},{},[731,735,741,745,751],{"nodeType":543,"value":732,"marks":733,"data":734},"Device code phishing sees the attacker target the authorization layer instead — OAuth consent flows that operate ",[],{},{"nodeType":543,"value":736,"marks":737,"data":740},"after",[738],{"type":739},"italic",{},{"nodeType":543,"value":742,"marks":743,"data":744}," authentication has already succeeded. We're calling this class of attack ",[],{},{"nodeType":543,"value":746,"marks":747,"data":750},"authorization phishing",[748],{"type":749},"bold",{},{"nodeType":543,"value":752,"marks":753,"data":754},", and it represents a structural shift in how identity attacks work.",[],{},{"nodeType":673,"data":756,"content":757},{},[758,762,770,774,782],{"nodeType":543,"value":759,"marks":760,"data":761},"But device code phishing is one technique in a broader shift. ConsentFix, ",[],{},{"nodeType":695,"data":763,"content":765},{"uri":764},"https://pushsecurity.com/blog/consentfix/",[766],{"nodeType":543,"value":767,"marks":768,"data":769},"first discovered by Push in December 2025",[],{},{"nodeType":543,"value":771,"marks":772,"data":773},", has already been ",[],{},{"nodeType":695,"data":775,"content":777},{"uri":776},"https://pushsecurity.com/blog/consentfix-v3-analyzing-a-new-toolkit/",[778],{"nodeType":543,"value":779,"marks":780,"data":781},"commoditized into criminal tooling",[],{},{"nodeType":543,"value":783,"marks":784,"data":785},". ",[],{},{"nodeType":787,"data":788,"content":794},"embedded-entry-block",{"target":789},{"sys":790},{"id":791,"type":792,"linkType":793},"3tRYNcUvN7KeFqzaGb2Cmn","Link","Entry",[],{"nodeType":796,"data":797,"content":798},"hr",{},[],{"nodeType":800,"data":801,"content":802},"heading-1",{},[803],{"nodeType":543,"value":804,"marks":805,"data":807},"Authentication phishing vs. authorization phishing",[806],{"type":749},{},{"nodeType":673,"data":809,"content":810},{},[811],{"nodeType":543,"value":812,"marks":813,"data":814},"Authentication phishing targets the login — the moment a user proves their identity. AiTM reverse-proxy kits like Tycoon2FA and Sneaky2FA relay credentials and session tokens in real time, effectively defeating MFA by capturing the authenticated session as it's created. This has been the dominant phishing technique since roughly 2023, and it remains the most common attack we come up against in the wild.",[],{},{"nodeType":673,"data":816,"content":817},{},[818],{"nodeType":543,"value":819,"marks":820,"data":821},"Authorization phishing targets what happens after the login. Instead of stealing a session from the authentication flow, these attacks abuse OAuth authorization mechanisms — consent grants, device code flows, and token exchanges. The attacker never touches the authentication flow at all.",[],{},{"nodeType":787,"data":823,"content":827},{"target":824},{"sys":825},{"id":826,"type":792,"linkType":793},"3ADEkZ8KQKs4ndH1T7PdaX",[],{"nodeType":829,"data":830,"content":831},"heading-2",{},[832],{"nodeType":543,"value":833,"marks":834,"data":836},"Consent phishing: the classic OAuth attack",[835],{"type":749},{},{"nodeType":673,"data":838,"content":839},{},[840,845],{"nodeType":543,"value":841,"marks":842,"data":844},"Consent phishing",[843],{"type":749},{},{"nodeType":543,"value":846,"marks":847,"data":848}," is the oldest of the three, and the classic OAuth attack. The attacker creates a malicious third-party application and tricks the user into granting it permissions via an OAuth consent prompt. The app then uses those permissions to access the user's data via API.",[],{},{"nodeType":673,"data":850,"content":851},{},[852,856,864],{"nodeType":543,"value":853,"marks":854,"data":855},"Identity providers have substantially hardened their default configurations against consent phishing. Most platforms today do not allow users to consent to apps that have not already been admin-consented into the tenant. For example, ",[],{},{"nodeType":695,"data":857,"content":859},{"uri":858},"https://pushsecurity.com/blog/how-consent-phishing-is-evolving/",[860],{"nodeType":543,"value":861,"marks":862,"data":863},"Microsoft now blocks unverified third-party app consent by default",[],{},{"nodeType":543,"value":865,"marks":866,"data":867},", as does Google, and GitHub restricts OAuth apps to org-owner approval. ",[],{},{"nodeType":787,"data":869,"content":873},{"target":870},{"sys":871},{"id":872,"type":792,"linkType":793},"1KJGoZABIAsuXG5QjBVWOY",[],{"nodeType":829,"data":875,"content":876},{},[877],{"nodeType":543,"value":878,"marks":879,"data":881},"Device code phishing: the breakout threat of 2026",[880],{"type":749},{},{"nodeType":673,"data":883,"content":884},{},[885,889,893,901,905,913],{"nodeType":543,"value":269,"marks":886,"data":888},[887],{"type":749},{},{"nodeType":543,"value":890,"marks":891,"data":892}," targets a different OAuth flow entirely: the ",[],{},{"nodeType":695,"data":894,"content":896},{"uri":895},"https://pushsecurity.com/blog/device-code-phishing/",[897],{"nodeType":543,"value":898,"marks":899,"data":900},"RFC 8628 device authorization grant",[],{},{"nodeType":543,"value":902,"marks":903,"data":904},", originally designed for input-constrained devices like smart TVs and IoT hardware. The attacker generates a code, delivers it to the victim via a phishing page that auto-polls for a fresh code on page load (which can arrive over email, Teams messages, LinkedIn DMs, voice calls, malvertising, or compromised websites), and the victim enters the code on the real device code for the target app. In the wild this is usually Microsoft, but last year's ",[],{},{"nodeType":695,"data":906,"content":908},{"uri":907},"https://pushsecurity.com/blog/analyzing-the-instructure-breach",[909],{"nodeType":543,"value":910,"marks":911,"data":912},"ShinyHunters",[],{},{"nodeType":543,"value":914,"marks":915,"data":916}," campaign saw Salesforce targeted too.",[],{},{"nodeType":787,"data":918,"content":922},{"target":919},{"sys":920},{"id":921,"type":792,"linkType":793},"79aVRaPAuAaiNZvTspbmHK",[],{"nodeType":673,"data":924,"content":925},{},[926],{"nodeType":543,"value":927,"marks":928,"data":929},"This grants the attacker an access token scoped to whichever application was targeted, and critically, because device code phishing targets apps that are already consented in the user's tenant (usually first-party Microsoft apps), it sidesteps the consent restrictions that have made traditional consent phishing harder. ",[],{},{"nodeType":673,"data":931,"content":932},{},[933],{"nodeType":543,"value":934,"marks":935,"data":936},"In Microsoft environments, the impact can extend beyond API access — if the attacker targets the Microsoft Authentication Broker, they can register a virtual device against the victim's account and escalate to a full Primary Refresh Token, gaining an interactive SSO-enabled session that can laterally move across any SSO-joined application.",[],{},{"nodeType":829,"data":938,"content":939},{},[940],{"nodeType":543,"value":941,"marks":942,"data":944},"ConsentFix: the new ClickFix-OAuth hybrid",[943],{"type":749},{},{"nodeType":673,"data":946,"content":947},{},[948,953],{"nodeType":543,"value":949,"marks":950,"data":952},"ConsentFix",[951],{"type":749},{},{"nodeType":543,"value":954,"marks":955,"data":956}," occupies an interesting middle ground. It targets the same OAuth flow as consent phishing — the authorization code grant (RFC 6749) — but it targets pre-approved first-party apps rather than attacker-created third-party apps, which means the consent restrictions that shut down traditional consent phishing don't apply.",[],{},{"nodeType":673,"data":958,"content":959},{},[960,963,971],{"nodeType":543,"value":21,"marks":961,"data":962},[],{},{"nodeType":695,"data":964,"content":965},{"uri":764},[966],{"nodeType":543,"value":967,"marks":968,"data":970},"First observed in Russia-linked APT29 campaigns in late 2025",[969],{"type":722},{},{"nodeType":543,"value":972,"marks":973,"data":974},", the original attacks appeared on compromised websites and were tightly targeted — the attack only activated for specific email domains, allowing non-targets to use the site as normal. ConsentFix combines ClickFix-style clipboard injection with OAuth consent abuse, exploiting apps that use a localhost redirect URI as part of the handshake to capture authorization codes that are usually picked up by a server-side callback.",[],{},{"nodeType":673,"data":976,"content":977},{},[978,982,989],{"nodeType":543,"value":979,"marks":980,"data":981},"Push detected and blocked ConsentFix the first time it was seen in the wild, and within months of disclosure, a ",[],{},{"nodeType":695,"data":983,"content":984},{"uri":776},[985],{"nodeType":543,"value":986,"marks":987,"data":988},"criminal ConsentFix toolkit",[],{},{"nodeType":543,"value":990,"marks":991,"data":992}," appeared on the XSS forum, making the technique more widely available.",[],{},{"nodeType":796,"data":994,"content":995},{},[],{"nodeType":800,"data":997,"content":998},{},[999],{"nodeType":543,"value":1000,"marks":1001,"data":1003},"What defenders think works (and what actually does)",[1002],{"type":749},{},{"nodeType":673,"data":1005,"content":1006},{},[1007],{"nodeType":543,"value":1008,"marks":1009,"data":1010},"As we've already established, authentication controls like passkeys have no impact on these attacks, which can come as a surprise for those that have bought into the \"phishing-resistant\" tag of passkeys at face value. That isn't to diminish their value, the passkey isn't phished in this scenario, it's just being circumvented.",[],{},{"nodeType":673,"data":1012,"content":1013},{},[1014],{"nodeType":543,"value":1015,"marks":1016,"data":1017},"Passkeys remain the strongest available protection against AiTM and credential theft. But they address a different layer of the problem, and treating them as a complete answer to phishing creates a dangerous blind spot as attackers shift to authorization-layer techniques.",[],{},{"nodeType":829,"data":1019,"content":1020},{},[1021],{"nodeType":543,"value":1022,"marks":1023,"data":1025},"Evaluating post-authentication controls like Conditional Access Policies",[1024],{"type":749},{},{"nodeType":673,"data":1027,"content":1028},{},[1029],{"nodeType":543,"value":1030,"marks":1031,"data":1032},"Conditional access policies are the primary layer of defense cited against these authorization-layer attacks. We tested the most cited conditional access controls against both device code phishing and ConsentFix, and the results vary significantly.",[],{},{"nodeType":673,"data":1034,"content":1035},{},[1036,1040,1045],{"nodeType":543,"value":1037,"marks":1038,"data":1039},"Since the policy for ",[],{},{"nodeType":543,"value":1041,"marks":1042,"data":1044},"require phishing-resistant authentication",[1043],{"type":749},{},{"nodeType":543,"value":1046,"marks":1047,"data":1048}," pertains to the enforcement of passkey-based logins, this has no impact here as we discussed above.",[],{},{"nodeType":673,"data":1050,"content":1051},{},[1052,1057],{"nodeType":543,"value":1053,"marks":1054,"data":1056},"Block device code flow",[1055],{"type":749},{},{"nodeType":543,"value":1058,"marks":1059,"data":1060}," is the most direct control, and it works — but only against device code phishing, not ConsentFix. It also blocks legitimate device code use cases (Azure CLI, conference room hardware, developer tooling), so organizations with real device code dependencies need per-user group or per-app exceptions that create potential gaps.",[],{},{"nodeType":673,"data":1062,"content":1063},{},[1064,1069],{"nodeType":543,"value":1065,"marks":1066,"data":1068},"Require compliant device",[1067],{"type":749},{},{"nodeType":543,"value":1070,"marks":1071,"data":1072}," is the most effective broad control. Device code flows can't present the TPM-bound proof-of-possession that device compliance requires, so they're blocked outright. However, as above, if you have legitimate uses for device code logins in your environment, you’d need to implement exceptions to this policy. ",[],{},{"nodeType":673,"data":1074,"content":1075},{},[1076],{"nodeType":543,"value":1077,"marks":1078,"data":1079},"ConsentFix, on the other hand, passes through this check. BYOD scenarios also create gaps — personal devices authenticating via browser without a Primary Refresh Token won't satisfy the compliance requirement either, for legitimate and malicious flows alike.",[],{},{"nodeType":673,"data":1081,"content":1082},{},[1083,1088],{"nodeType":543,"value":1084,"marks":1085,"data":1087},"Token protection",[1086],{"type":749},{},{"nodeType":543,"value":1089,"marks":1090,"data":1091},", currently in preview, binds refresh tokens to the device's TPM. It performed better in testing than expected for some ConsentFix scenarios — depending on the scopes requested and the target app — but it doesn't apply to all apps and resources.",[],{},{"nodeType":673,"data":1093,"content":1094},{},[1095],{"nodeType":543,"value":1096,"marks":1097,"data":1098},"Conditional access can be tricky to manage, however, particularly for larger organizations. User groups need maintaining, new apps need scoping, exceptions accumulate, and policies interact in ways that aren't always obvious from the admin console. It's easy to accidentally leave policies in report-only mode (I found this myself during testing) or create exceptions for specific apps that inadvertently open the authorization attack surface. And ticking the box doesn't tell you whether it works in practice.",[],{},{"nodeType":673,"data":1100,"content":1101},{},[1102],{"nodeType":543,"value":1103,"marks":1104,"data":1105},"Microsoft is taking additional steps to reduce the attack surface here — device code flow is blocked by default in new tenants, and they appear to be locking down apps and reply URLs to reduce the ConsentFix attack surface, including adding explicit \"this might be a phishing attack\" warnings on certain reply URLs used in ConsentFix scenarios. But the gap between a default deployment and a hardened one remains wide.",[],{},{"nodeType":787,"data":1107,"content":1111},{"target":1108},{"sys":1109},{"id":1110,"type":792,"linkType":793},"3FguCE9HzDsj94TgRzZSk6",[],{"nodeType":829,"data":1113,"content":1114},{},[1115],{"nodeType":543,"value":1116,"marks":1117,"data":1119},"What about blocking the apps themselves?",[1118],{"type":749},{},{"nodeType":673,"data":1121,"content":1122},{},[1123],{"nodeType":543,"value":1124,"marks":1125,"data":1126},"The challenge is that the apps being abused aren't malicious — they're legitimate first-party Microsoft applications like Azure CLI, Microsoft Office, and Teams. They exist in every Entra tenant by default, are pre-consented with broad permissions, and can't simply be removed.",[],{},{"nodeType":673,"data":1128,"content":1129},{},[1130],{"nodeType":543,"value":1131,"marks":1132,"data":1133},"An admin can toggle \"assignment required\" on a service principal and restrict which users can authenticate through that app, but that means pre-creating and managing user assignments for every first-party app that could be targeted. Over-restricting broadly used apps like Teams or Office may break core workflows.",[],{},{"nodeType":796,"data":1135,"content":1136},{},[],{"nodeType":800,"data":1138,"content":1139},{},[1140],{"nodeType":543,"value":1141,"marks":1142,"data":1144},"The future of authorization phishing",[1143],{"type":749},{},{"nodeType":673,"data":1146,"content":1147},{},[1148],{"nodeType":543,"value":1149,"marks":1150,"data":1151},"Several developments will determine how fast this category matures. Device code phishing is a core technique now, supported by most PhaaS vendors and bolted onto AiTM kits. ConsentFix criminal adoption is still early but could follow suit at any time. ",[],{},{"nodeType":673,"data":1153,"content":1154},{},[1155],{"nodeType":543,"value":1156,"marks":1157,"data":1158},"Non-Microsoft targets are the logical next step — device code phishing has already been demonstrated against Salesforce, and I showed off GitHub targeting in my recent webinar. Any platform that supports the authorization code grant with localhost redirect or the device authorization grant is a potential target. ",[],{},{"nodeType":787,"data":1160,"content":1164},{"target":1161},{"sys":1162},{"id":1163,"type":792,"linkType":793},"UIOVxK4yPURUu8slsKWMu",[],{"nodeType":673,"data":1166,"content":1167},{},[1168,1173,1177,1185],{"nodeType":543,"value":1169,"marks":1170,"data":1172},"But OAuth is complex, and the authorization mechanisms that have been abused so far likely don't represent the full attack surface. ",[1171],{"type":749},{},{"nodeType":543,"value":1174,"marks":1175,"data":1176},"Everything discussed so far has been initial access, but OAuth is also powerful at the persistence and lateral movement layers — an attacker who plants a malicious OAuth grant during a compromise has a ",[],{},{"nodeType":695,"data":1178,"content":1180},{"uri":1179},"https://pushsecurity.com/blog/nearly-invisible-attack-chain/",[1181],{"nodeType":543,"value":1182,"marks":1183,"data":1184},"stealthy persistence mechanism",[],{},{"nodeType":543,"value":1186,"marks":1187,"data":1188}," that survives credential resets and password changes, and can be extremely difficult to detect. As authorization phishing matures, we expect these post-compromise OAuth techniques to become more common too.",[],{},{"nodeType":673,"data":1190,"content":1191},{},[1192,1196,1204],{"nodeType":543,"value":1193,"marks":1194,"data":1195},"The ",[],{},{"nodeType":695,"data":1197,"content":1199},{"uri":1198},"https://pushsecurity.com/blog/openai-poisoned-tenant-attack",[1200],{"nodeType":543,"value":1201,"marks":1202,"data":1203},"poisoned tenant attack surface",[],{},{"nodeType":543,"value":1205,"marks":1206,"data":1207}," also remains largely undefended, which could see more typical consent phishing come back around. Historically, consent phishing involved an attacker creating a malicious app and inviting their targets to it. But you can just set up a tenant on a legit SaaS app and use that instead.",[],{},{"nodeType":673,"data":1209,"content":1210},{},[1211,1215,1222],{"nodeType":543,"value":1212,"marks":1213,"data":1214},"Most SaaS platforms let anyone create a workspace impersonating any organization, and few offer controls for admins to restrict which tenants their employees can join. We ",[],{},{"nodeType":695,"data":1216,"content":1217},{"uri":1198},[1218],{"nodeType":543,"value":1219,"marks":1220,"data":1221},"recently experienced this directly",[],{},{"nodeType":543,"value":1223,"marks":1224,"data":1225}," when an attacker created a fake OpenAI organization under our company's name and invited specific employees to join it.",[],{},{"nodeType":787,"data":1227,"content":1231},{"target":1228},{"sys":1229},{"id":1230,"type":792,"linkType":793},"1YPMilWhyTSV860PCFXxmx",[],{"nodeType":796,"data":1233,"content":1234},{},[],{"nodeType":800,"data":1236,"content":1237},{},[1238],{"nodeType":543,"value":1239,"marks":1240,"data":1242},"What defenders should actually do",[1241],{"type":749},{},{"nodeType":673,"data":1244,"content":1245},{},[1246,1251],{"nodeType":543,"value":1247,"marks":1248,"data":1250},"First, test your defenses against authorization attacks specifically.",[1249],{"type":749},{},{"nodeType":543,"value":1252,"marks":1253,"data":1254}," Don't assume that MFA, passkeys, or conditional access policies handle this. Run a device code phishing simulation against your environment and verify that your conditional access configuration actually blocks it. Test ConsentFix scenarios. If your controls rely on configuration assumptions you haven't validated, you have a gap.",[],{},{"nodeType":673,"data":1256,"content":1257},{},[1258,1263],{"nodeType":543,"value":1259,"marks":1260,"data":1262},"Second, don't treat this as exclusively a Microsoft problem. ",[1261],{"type":749},{},{"nodeType":543,"value":1264,"marks":1265,"data":1266},"Device code phishing can work against several apps. GitHub exposes broad scopes including full repository access and uses device code as the default CLI sign-in method — meaning developers encounter legitimate device code flows routinely, making phishing lures harder to distinguish from normal workflow. ConsentFix-style attacks targeting authorization code grants with localhost redirects could also expand beyond Microsoft as the technique matures.",[],{},{"nodeType":673,"data":1268,"content":1269},{},[1270,1275],{"nodeType":543,"value":1271,"marks":1272,"data":1274},"Third, update your security awareness training.",[1273],{"type":749},{},{"nodeType":543,"value":1276,"marks":1277,"data":1278}," Most employees have no concept of authorization phishing — it doesn't look or feel like any phishing that they're used to. There's no suspicious login page, no credential entry on an unfamiliar domain. Traditional awareness training does not prepare users for this.",[],{},{"nodeType":673,"data":1280,"content":1281},{},[1282],{"nodeType":543,"value":1283,"marks":1284,"data":1285},"But to detect and block these attacks as they happen, you need to be in the browser. Push detects and blocks authorization attacks in real time, when the user is tricked into performing the malicious consent grant. We detected ConsentFix the first time it appeared in the wild, before any other vendor, and device code phishing detection has been live since the technique first entered mainstream use.",[],{},{"nodeType":829,"data":1287,"content":1288},{},[1289],{"nodeType":543,"value":1290,"marks":1291,"data":1293},"Watch the research",[1292],{"type":749},{},{"nodeType":673,"data":1295,"content":1296},{},[1297,1301,1309,1313,1321],{"nodeType":543,"value":1298,"marks":1299,"data":1300},"I recently talked about authorization phishing at ",[],{},{"nodeType":695,"data":1302,"content":1304},{"uri":1303},"https://bsideslv.org/schedule3#PA",[1305],{"nodeType":543,"value":1306,"marks":1307,"data":1308},"BSides Las Vegas 2026",[],{},{"nodeType":543,"value":1310,"marks":1311,"data":1312},", walking through live demonstrations of device code phishing (including against passkey-protected accounts), ConsentFix, and conditional access policy bypass testing. The full talk is available to ",[],{},{"nodeType":695,"data":1314,"content":1316},{"uri":1315},"https://www.youtube.com/live/9wx9Nt3JWSs",[1317],{"nodeType":543,"value":1318,"marks":1319,"data":1320},"watch on YouTube",[],{},{"nodeType":543,"value":1322,"marks":1323,"data":1324}," (starts at 27:12).",[],{},{"entries":1326},{"hyperlink":1327,"inline":1328,"block":1329},[],[],[1330,1345,1371,1385,1391,1399,1403],{"sys":1331,"__typename":1332,"content":1333,"name":1344,"title":59},{"id":791},"InsightTextBlockComponent",{"json":1334},{"nodeType":669,"data":1335,"content":1336},{},[1337],{"nodeType":673,"data":1338,"content":1339},{},[1340],{"nodeType":543,"value":1341,"marks":1342,"data":1343},"In this blog post, we’ll talk about the different authorization attacks used by attackers in the wild and what this means for security teams looking to detect and block these attacks.",[],{},"Authorization phishing IB2",{"sys":1346,"__typename":1332,"content":1347,"name":1370,"title":59},{"id":826},{"json":1348},{"data":1349,"content":1350,"nodeType":669},{},[1351],{"data":1352,"content":1353,"nodeType":673},{},[1354,1358,1366],{"data":1355,"marks":1356,"value":1357,"nodeType":543},{},[],"Three techniques currently fall under the authorization phishing umbrella. Most of them are exactly new, either — Push cataloged consent phishing and device code phishing in the ",{"data":1359,"content":1361,"nodeType":695},{"uri":1360},"https://pushsecurity.com/resources/browser-identity-attacks-matrix",[1362],{"data":1363,"marks":1364,"value":1365,"nodeType":543},{},[],"Browser & Identity Attacks Matrix",{"data":1367,"marks":1368,"value":1369,"nodeType":543},{},[]," back in 2023. What's changed in 2026 is that they've moved from isolated, targeted operations to widespread adoption across the phishing-as-a-service ecosystem.","Authorization phishing IB1",{"sys":1372,"__typename":1332,"content":1373,"name":1384,"title":59},{"id":872},{"json":1374},{"nodeType":669,"data":1375,"content":1376},{},[1377],{"nodeType":673,"data":1378,"content":1379},{},[1380],{"nodeType":543,"value":1381,"marks":1382,"data":1383},"And even if you can get in, once a malicious app is flagged, it's burned — and unlike domains and IP addresses, it's not easy to rotate. The vendor can ban the app, ban the entire tenant associated with it, and block the attacker's registration infrastructure. Setting up new apps at scale requires new verified tenants, which makes the economics of consent phishing significantly worse than other techniques. These controls are the main reason we don't see it much in the wild anymore.",[],{},"Authorization phishing IB3",{"sys":1386,"__typename":1387,"title":1388,"arcadeDemoUrl":1389,"playText":1390},{"id":921},"ArcadeDemo","Device code phishing: In the wild examples","https://demo.arcade.software/Fx5XuPm0JCceQRgAvH9C?embed","2 mins",{"sys":1392,"__typename":1393,"title":1394,"caption":1394,"layoutMode":59,"file":1395},{"id":1110},"Image","Native client warning displayed for ConsentFix attacks requesting certain scope and app combinations. ",{"url":1396,"width":1397,"height":1398},"https://images.ctfassets.net/y1cdw1ablpvd/3bV6Kt6BQqseSGPRmNeqYT/e93466e14eeb45fb9d07fa135d6b80e4/nativeclient_warning.png",1278,987,{"sys":1400,"__typename":1387,"title":1401,"arcadeDemoUrl":1402,"playText":1390},{"id":1163},"Device Code Phishing Demo: GitHub","https://demo.arcade.software/8WVq7zlbQYahwpDLs6ly?embed",{"sys":1404,"__typename":1393,"title":1405,"caption":1405,"layoutMode":59,"file":1406},{"id":1230},"\"Invite accepted\" confirmation page for the poisoned OpenAI tenant.",{"url":1407,"width":1408,"height":1409},"https://images.ctfassets.net/y1cdw1ablpvd/38N7FnCMSQz519ZXQfpXo4/f848d30b238b943a47efa29d12b68b87/image5.png",1999,1031,"json",{"items":1412},[1413,1426,1439,1452,1465,1478,1491,1525,1559],{"answer":1414,"question":1425},{"json":1415},{"nodeType":669,"data":1416,"content":1417},{},[1418],{"nodeType":673,"data":1419,"content":1420},{},[1421],{"nodeType":543,"value":1422,"marks":1423,"data":1424},"Authorization phishing is a category of phishing attacks that target OAuth authorization flows rather than the authentication (login) process. Instead of stealing credentials or session tokens, authorization phishing tricks users into granting attacker-controlled applications access to their accounts through legitimate OAuth consent prompts or device code flows. The user authenticates normally — on the real identity provider, with their real credentials and MFA — and the attack exploits the authorization decision that follows.",[],{},"What is authorization phishing?",{"answer":1427,"question":1438},{"json":1428},{"nodeType":669,"data":1429,"content":1430},{},[1431],{"nodeType":673,"data":1432,"content":1433},{},[1434],{"nodeType":543,"value":1435,"marks":1436,"data":1437},"Authentication phishing attacks the login — the moment a user proves their identity. Techniques like AiTM (adversary-in-the-middle) phishing use reverse-proxy kits to intercept credentials and session tokens during the authentication flow. Authorization phishing attacks what happens after the login. The user authenticates legitimately, and the attacker abuses OAuth mechanisms (consent grants, device code flows, token exchanges) to obtain access tokens. The key difference: authentication phishing defeats MFA by proxying the login and intercepting the session token, while authorization phishing makes MFA irrelevant because the authentication succeeds normally.",[],{},"What's the difference between authentication phishing and authorization phishing?",{"answer":1440,"question":1451},{"json":1441},{"nodeType":669,"data":1442,"content":1443},{},[1444],{"nodeType":673,"data":1445,"content":1446},{},[1447],{"nodeType":543,"value":1448,"marks":1449,"data":1450},"No. All forms of MFA — including passkeys, FIDO2 keys, authenticator apps, and SMS codes — protect the authentication flow. Authorization phishing targets the authorization layer, which operates after authentication has already succeeded. The user completes MFA normally, and the attack exploits the subsequent OAuth consent or device code flow. Passkeys remain the strongest defense against authentication phishing (AiTM, credential theft), but they don't address authorization-layer attacks.",[],{},"Can MFA and passkeys stop authorization phishing?",{"answer":1453,"question":1464},{"json":1454},{"nodeType":669,"data":1455,"content":1456},{},[1457],{"nodeType":673,"data":1458,"content":1459},{},[1460],{"nodeType":543,"value":1461,"marks":1462,"data":1463},"Some conditional access policies can block device code phishing, but effectiveness is highly configuration-dependent. \"Block device code flow\" is effective but also blocks legitimate use cases. \"Require compliant device\" blocks device code phishing because the flow can't present device compliance proofs, but doesn't stop ConsentFix. \"Token protection\" (currently in preview) has limited applicability. \"Require phishing-resistant authentication\" is not applicable because the authentication in device code phishing is already legitimate. The gap between a default conditional access deployment and a hardened one is significant.",[],{},"Can conditional access policies stop device code phishing?",{"answer":1466,"question":1477},{"json":1467},{"nodeType":669,"data":1468,"content":1469},{},[1470],{"nodeType":673,"data":1471,"content":1472},{},[1473],{"nodeType":543,"value":1474,"marks":1475,"data":1476},"ConsentFix is harder to block with conditional access because it uses the standard authorization code grant flow rather than the device code flow. \"Block device code flow\" doesn't apply. \"Require compliant device\" doesn't stop ConsentFix. \"Token protection\" mitigates some ConsentFix scenarios depending on scopes requested, but it's in preview and limited in scope. Microsoft appears to be reducing the ConsentFix attack surface by locking down apps and reply URLs, but there is currently no single conditional access policy that reliably blocks all ConsentFix variants.",[],{},"Can conditional access policies stop ConsentFix?",{"answer":1479,"question":1490},{"json":1480},{"nodeType":669,"data":1481,"content":1482},{},[1483],{"nodeType":673,"data":1484,"content":1485},{},[1486],{"nodeType":543,"value":1487,"marks":1488,"data":1489},"Authorization phishing detection requires visibility at the browser layer, where the OAuth consent and device code flows actually execute. This includes monitoring device code authorization pages for suspicious activity, capturing OAuth consent flows (client ID, scopes requested, authorization server, outcome), and detecting browser-native attacks like ConsentFix that combine clipboard injection with OAuth abuse. Network-layer and endpoint-layer tools don't have visibility into these browser-rendered authorization flows.",[],{},"How do you detect authorization phishing?",{"answer":1492,"question":1524},{"json":1493},{"nodeType":669,"data":1494,"content":1495},{},[1496,1503,1510,1517],{"nodeType":673,"data":1497,"content":1498},{},[1499],{"nodeType":543,"value":1500,"marks":1501,"data":1502},"No. Email gateways won't catch it — a device code phishing lure asks the user to visit a legitimate URL (like microsoft.com/devicelogin) and enter a code. There's no malicious link, no credential-harvesting page, and no suspicious attachment for the gateway to flag. The pages and infrastructure used as part of these campaigns are frequently rotated to evade blocklists. ",[],{},{"nodeType":673,"data":1504,"content":1505},{},[1506],{"nodeType":543,"value":1507,"marks":1508,"data":1509},"SWGs inspect network traffic and enforce access policies, but the authorization flow happens on the real identity provider's domain over a legitimate connection — indistinguishable from a normal sign-in. ",[],{},{"nodeType":673,"data":1511,"content":1512},{},[1513],{"nodeType":543,"value":1514,"marks":1515,"data":1516},"EDR won't see it either, because the entire attack plays out in the browser via standard web requests — no malicious payload touches the filesystem or triggers OS-level detection. These tools are built to detect authentication phishing — malicious URLs, cloned login pages, known-bad infrastructure — and authorization phishing doesn't produce any of those artifacts. ",[],{},{"nodeType":673,"data":1518,"content":1519},{},[1520],{"nodeType":543,"value":1521,"marks":1522,"data":1523},"Browser-layer detection closes the gap, because it has visibility into the authorization flow itself, tab metadata, and page context that makes bad activity identifiable from normal behavior.",[],{},"Can I detect authorization attacks with my email gateway, SWG, or EDR?",{"answer":1526,"question":1558},{"json":1527},{"nodeType":669,"data":1528,"content":1529},{},[1530,1537,1544,1551],{"nodeType":673,"data":1531,"content":1532},{},[1533],{"nodeType":543,"value":1534,"marks":1535,"data":1536},"Yes, in Microsoft environments. Entra ID conditional access includes a \"block device code flow\" policy that prevents device code authorizations outright, and Microsoft now recommends enabling it for any tenant that hasn't used the flow in the past 25 days. ",[],{},{"nodeType":673,"data":1538,"content":1539},{},[1540],{"nodeType":543,"value":1541,"marks":1542,"data":1543},"The main operational cost is that Azure CLI, developer tooling, and conference room hardware often depend on device code flow, so developer-heavy organizations may need exclusions that increase susceptibility to this technique. ",[],{},{"nodeType":673,"data":1545,"content":1546},{},[1547],{"nodeType":543,"value":1548,"marks":1549,"data":1550},"\"Require compliant device\" also blocks device code phishing indirectly, since the flow can't present the TPM-bound proof that compliance requires. Two important caveats: blocking device code flow doesn't block ConsentFix or other authorization code grant attacks, so it's a partial solution to the broader authorization phishing category. ",[],{},{"nodeType":673,"data":1552,"content":1553},{},[1554],{"nodeType":543,"value":1555,"marks":1556,"data":1557},"Outside Microsoft, options are more limited — Google mitigates the risk by restricting which scopes are available through device code, but GitHub and other platforms that support the flow don't offer equivalent blocking controls, leaving you reliant on monitoring and detection rather than prevention.",[],{},"Can you block device code phishing?",{"answer":1560,"question":1599},{"json":1561},{"nodeType":669,"data":1562,"content":1563},{},[1564,1571,1578,1585,1592],{"nodeType":673,"data":1565,"content":1566},{},[1567],{"nodeType":543,"value":1568,"marks":1569,"data":1570},"The attack isn't Microsoft-exclusive, but the exposure varies across different platforms. Microsoft has the broadest exposure because of unrestricted scopes, reusable first-party client IDs, and FOCI token exchange. This, combined with the prevalence of Microsoft, is why the overwhelming majority of observed attacks target Entra ID.",[],{},{"nodeType":673,"data":1572,"content":1573},{},[1574],{"nodeType":543,"value":1575,"marks":1576,"data":1577},"GitHub is also an obvious target: device code flow is the default CLI sign-in method, and broad scopes including full repository access are available, though the attacker must control their own OAuth app and the victim sees an explicit consent screen. ",[],{},{"nodeType":673,"data":1579,"content":1580},{},[1581],{"nodeType":543,"value":1582,"marks":1583,"data":1584},"Google is lower risk for device code phishing specifically — Google explicitly limits which scopes are accessible through the device code flow, making Gmail, Calendar, and most Workspace APIs unavailable through this mechanism. ",[],{},{"nodeType":673,"data":1586,"content":1587},{},[1588],{"nodeType":543,"value":1589,"marks":1590,"data":1591},"Salesforce and AWS also support the flow. However Salesforce implemented changes to app approvals and permissions following the large-scale campaign in 2025 to reduce the scope for abuse in future.",[],{},{"nodeType":673,"data":1593,"content":1594},{},[1595],{"nodeType":543,"value":1596,"marks":1597,"data":1598},"If your environment relies on any platform that supports OAuth device authorization grants or authorization code grants with localhost redirect URIs, the attack surface exists.",[],{},"We're not a Microsoft shop — do we still need to worry about authorization phishing?","Authorization Phishing: Frequently Asked Questions",{},"How authorization phishing attacks bypass MFA and passkeys","threat-research","2026-08-24T00:00:00.000Z",{"items":1606},[1607,2930,5950],{"__typename":1608,"sys":1609,"content":1611,"title":2908,"synopsis":2909,"hashTags":59,"publishedDate":2910,"slug":2911,"tagsCollection":2912,"authorsCollection":2922},"BlogPosts",{"id":1610},"vLb3RhwYt7Xc6mkX3pWyI",{"json":1612},{"data":1613,"content":1614,"nodeType":669},{},[1615,1622,1625,1633,1663,1671,1677,1708,1823,1864,1872,1927,1958,1964,1967,1975,1982,1990,2007,2062,2068,2075,2093,2099,2106,2112,2119,2125,2132,2138,2146,2189,2220,2239,2269,2277,2308,2339,2370,2378,2385,2404,2458,2489,2497,2515,2558,2561,2569,2576,2583,2601,2607,2614,2728,2771,2779,2798,2805,2808,2816,2823,2866,2873,2876,2883,2890],{"data":1616,"content":1617,"nodeType":673},{},[1618],{"data":1619,"marks":1620,"value":1621,"nodeType":543},{},[],"Feeling overwhelmed with the amount of cyber news stories? Tired of dodging AI vendors boasting about their agents escaping the lab? This threat landscape update cuts through the noise and covers the key developments that security teams need to be on top of.",{"data":1623,"content":1624,"nodeType":796},{},[],{"data":1626,"content":1627,"nodeType":800},{},[1628],{"data":1629,"marks":1630,"value":1632,"nodeType":543},{},[1631],{"type":749},"The SLH playbook becomes the industry standard",{"data":1634,"content":1635,"nodeType":673},{},[1636,1640,1648,1652,1659],{"data":1637,"marks":1638,"value":1639,"nodeType":543},{},[],"Criminals associated with \"The Com,\" broadly known as the ",{"data":1641,"content":1643,"nodeType":695},{"uri":1642},"https://pushsecurity.com/blog/scattered-lapsus-hunters",[1644],{"data":1645,"marks":1646,"value":1647,"nodeType":543},{},[],"Scattered Lapsus$ Hunters",{"data":1649,"marks":1650,"value":1651,"nodeType":543},{},[]," collective, have spent the past three years establishing a playbook ",{"data":1653,"content":1654,"nodeType":695},{"uri":907},[1655],{"data":1656,"marks":1657,"value":1658,"nodeType":543},{},[],"focused on identity compromise and cloud data theft",{"data":1660,"marks":1661,"value":1662,"nodeType":543},{},[]," for extortion. They've dominated the news when it comes to public breaches: a sign of their effectiveness, or perhaps more their desire for notoriety (something that has come back to bite individuals later with a series of arrests, but hasn't hampered the overall trajectory of the breaches).",{"data":1664,"content":1665,"nodeType":673},{},[1666],{"data":1667,"marks":1668,"value":1670,"nodeType":543},{},[1669],{"type":749},"Regardless, the data doesn't lie. Of the browser and identity-related breaches we've tracked, groups linked to \"The Com\" such as Scattered Spider, ShinyHunters, and Lapsus$ are responsible for roughly 70% (not just in 2026, but since the start of 2024). ",{"data":1672,"content":1676,"nodeType":787},{"target":1673},{"sys":1674},{"id":1675,"type":792,"linkType":793},"3hODobO3VJr3LvbXkzso8I",[],{"data":1678,"content":1679,"nodeType":673},{},[1680,1684,1692,1696,1704],{"data":1681,"marks":1682,"value":1683,"nodeType":543},{},[],"The trump card of prolific criminal groups like Scattered Spider, Lapsus$, and ShinyHunters has always been their social engineering skill. Last year, they had huge success in ",{"data":1685,"content":1687,"nodeType":695},{"uri":1686},"https://pushsecurity.com/blog/scattered-spider-defending-against-help-desk-scams",[1688],{"data":1689,"marks":1690,"value":1691,"nodeType":543},{},[],"tricking help desks into performing account resets",{"data":1693,"marks":1694,"value":1695,"nodeType":543},{},[],". This year, they've switched to using voice-based lures in tandem with ",{"data":1697,"content":1699,"nodeType":695},{"uri":1698},"https://pushsecurity.com/blog/unpacking-the-latest-slh-campaign",[1700],{"data":1701,"marks":1702,"value":1703,"nodeType":543},{},[],"browser-based phishing payloads",{"data":1705,"marks":1706,"value":1707,"nodeType":543},{},[]," — usually impersonating IT staff under the guise of \"setting up passkeys.\"",{"data":1709,"content":1710,"nodeType":673},{},[1711,1715,1723,1727,1735,1739,1747,1751,1759,1763,1771,1775,1783,1787,1795,1799,1807,1811,1819],{"data":1712,"marks":1713,"value":1714,"nodeType":543},{},[],"The vishing-to-SSO-takeover campaign has been prolific, running continuously since January: ",{"data":1716,"content":1718,"nodeType":695},{"uri":1717},"https://www.securityweek.com/panera-bread-data-breach-linked-to-shinyhunters-sso-campaign/",[1719],{"data":1720,"marks":1721,"value":1722,"nodeType":543},{},[],"Panera Bread",{"data":1724,"marks":1725,"value":1726,"nodeType":543},{},[]," (~14M records), ",{"data":1728,"content":1730,"nodeType":695},{"uri":1729},"https://www.bleepingcomputer.com/news/security/match-group-breach-exposes-data-from-hinge-tinder-okcupid-and-match/",[1731],{"data":1732,"marks":1733,"value":1734,"nodeType":543},{},[],"Match Group",{"data":1736,"marks":1737,"value":1738,"nodeType":543},{},[]," (Hinge, Tinder, OkCupid; 10M+ records), ",{"data":1740,"content":1742,"nodeType":695},{"uri":1741},"https://cloud.google.com/blog/topics/threat-intelligence/expansion-shinyhunters-saas-data-theft",[1743],{"data":1744,"marks":1745,"value":1746,"nodeType":543},{},[],"Betterment",{"data":1748,"marks":1749,"value":1750,"nodeType":543},{},[]," (~20M records), ",{"data":1752,"content":1754,"nodeType":695},{"uri":1753},"https://www.bleepingcomputer.com/news/security/shinyhunters-extortion-gang-claims-odido-breach-affecting-millions/",[1755],{"data":1756,"marks":1757,"value":1758,"nodeType":543},{},[],"Odido",{"data":1760,"marks":1761,"value":1762,"nodeType":543},{},[]," (6.2M Dutch telecom customers with BSNs and IBANs exposed), ",{"data":1764,"content":1766,"nodeType":695},{"uri":1765},"https://www.bleepingcomputer.com/news/security/adt-confirms-data-breach-after-shinyhunters-leak-threat/",[1767],{"data":1768,"marks":1769,"value":1770,"nodeType":543},{},[],"ADT",{"data":1772,"marks":1773,"value":1774,"nodeType":543},{},[]," (5.5M records), ",{"data":1776,"content":1778,"nodeType":695},{"uri":1777},"https://www.bleepingcomputer.com/news/security/charter-communications-data-breach-affects-49-million-accounts/",[1779],{"data":1780,"marks":1781,"value":1782,"nodeType":543},{},[],"Charter Communications",{"data":1784,"marks":1785,"value":1786,"nodeType":543},{},[]," (4.9M accounts), ",{"data":1788,"content":1790,"nodeType":695},{"uri":1789},"https://www.theregister.com/2026/04/24/shinyhunters_claim_cruise_giant_carnivals/",[1791],{"data":1792,"marks":1793,"value":1794,"nodeType":543},{},[],"Carnival Corporation",{"data":1796,"marks":1797,"value":1798,"nodeType":543},{},[]," (6M records), and",{"data":1800,"content":1802,"nodeType":695},{"uri":1801},"https://www.theregister.com/2026/04/28/pitney_bowes_is_the_latest/",[1803],{"data":1804,"marks":1805,"value":1806,"nodeType":543},{},[]," Pitney Bowes",{"data":1808,"marks":1809,"value":1810,"nodeType":543},{},[]," (8.2M emails per HIBP). ",{"data":1812,"content":1814,"nodeType":695},{"uri":1813},"https://www.bleepingcomputer.com/news/security/ad-tech-firm-optimizely-confirms-data-breach-after-vishing-attack/",[1815],{"data":1816,"marks":1817,"value":1818,"nodeType":543},{},[],"Optimizely",{"data":1820,"marks":1821,"value":1822,"nodeType":543},{},[]," is notable as the first confirmed case where attackers deployed both AiTM credential harvesting and device code phishing against the same target.",{"data":1824,"content":1825,"nodeType":673},{},[1826,1830,1836,1840,1848,1852,1860],{"data":1827,"marks":1828,"value":1829,"nodeType":543},{},[],"Since mid-2025, SaaS apps like Salesforce have been a persistent target for data theft and extortion — as seen in the first large-scale criminal ",{"data":1831,"content":1832,"nodeType":695},{"uri":716},[1833],{"data":1834,"marks":1835,"value":719,"nodeType":543},{},[],{"data":1837,"marks":1838,"value":1839,"nodeType":543},{},[]," campaign that preceded this year's adoption spike. ShinyHunters also led the way with OAuth supply chain abuse — compromising SaaS vendors like ",{"data":1841,"content":1843,"nodeType":695},{"uri":1842},"https://cloud.google.com/blog/topics/threat-intelligence/data-theft-salesforce-instances-via-salesloft-drift",[1844],{"data":1845,"marks":1846,"value":1847,"nodeType":543},{},[],"Salesloft, Drift, and GainSight",{"data":1849,"marks":1850,"value":1851,"nodeType":543},{},[]," and leveraging stored OAuth tokens to penetrate downstream customer environments, a pattern that has since ",{"data":1853,"content":1855,"nodeType":695},{"uri":1854},"https://pushsecurity.com/blog/unpacking-the-vercel-breach",[1856],{"data":1857,"marks":1858,"value":1859,"nodeType":543},{},[],"repeated at scale",{"data":1861,"marks":1862,"value":1863,"nodeType":543},{},[],".",{"data":1865,"content":1866,"nodeType":829},{},[1867],{"data":1868,"marks":1869,"value":1871,"nodeType":543},{},[1870],{"type":749},"Copycats and nation-state adoption",{"data":1873,"content":1874,"nodeType":673},{},[1875,1879,1887,1891,1899,1903,1911,1915,1923],{"data":1876,"marks":1877,"value":1878,"nodeType":543},{},[],"Wider groups are now running the SLH playbook independently. ",{"data":1880,"content":1882,"nodeType":695},{"uri":1881},"https://hackread.com/pink-extortion-microsoft-365-cloud-data-vishing-scams/",[1883],{"data":1884,"marks":1885,"value":1886,"nodeType":543},{},[],"Pink",{"data":1888,"marks":1889,"value":1890,"nodeType":543},{},[]," (the latest rebrand in the",{"data":1892,"content":1894,"nodeType":695},{"uri":1893},"https://cloud.google.com/blog/topics/threat-intelligence/unc6671-targets-financial-services-and-enterprise-cloud-environments",[1895],{"data":1896,"marks":1897,"value":1898,"nodeType":543},{},[]," BlackFile",{"data":1900,"marks":1901,"value":1902,"nodeType":543},{},[],"-Redact succession) runs vishing combined with passkey-themed credential phishing for M365 extortion. ",{"data":1904,"content":1906,"nodeType":695},{"uri":1905},"https://www.bleepingcomputer.com/news/security/new-helix-vishing-group-emerges-in-sharepoint-data-theft-attacks/",[1907],{"data":1908,"marks":1909,"value":1910,"nodeType":543},{},[],"Helix",{"data":1912,"marks":1913,"value":1914,"nodeType":543},{},[]," also emerged shortly after BlackFile shut down, pairing vishing with device code phishing and MFA registration for persistence. ",{"data":1916,"content":1918,"nodeType":695},{"uri":1917},"https://www.bleepingcomputer.com/news/security/kongtuke-hackers-now-use-microsoft-teams-for-corporate-breaches/",[1919],{"data":1920,"marks":1921,"value":1922,"nodeType":543},{},[],"KongTuke",{"data":1924,"marks":1925,"value":1926,"nodeType":543},{},[],", an independent initial access broker, adopted a similar help-desk impersonation model via Teams external messaging.",{"data":1928,"content":1929,"nodeType":673},{},[1930,1934,1942,1946,1954],{"data":1931,"marks":1932,"value":1933,"nodeType":543},{},[],"It's not just criminal groups either. Recently, we saw a campaign linked to Russian actors that used ",{"data":1935,"content":1937,"nodeType":695},{"uri":1936},"https://www.microsoft.com/en-us/security/blog/2026/07/31/captivecrunch-midnight-blizzard-targets-travelers-worldwide-for-malware-delivery-and-credential-theft/",[1938],{"data":1939,"marks":1940,"value":1941,"nodeType":543},{},[],"compromised hotel and conference Wi-Fi gateways",{"data":1943,"marks":1944,"value":1945,"nodeType":543},{},[]," to direct victims to AiTM, ClickFix, and device code phishing pages. And ",{"data":1947,"content":1949,"nodeType":695},{"uri":1948},"https://cloud.google.com/blog/topics/threat-intelligence/chinese-language-phishing-services/",[1950],{"data":1951,"marks":1952,"value":1953,"nodeType":543},{},[],"Google Threat Intelligence mapped",{"data":1955,"marks":1956,"value":1957,"nodeType":543},{},[]," a dozen Chinese-language PhaaS platforms with real-time MFA interception.",{"data":1959,"content":1963,"nodeType":787},{"target":1960},{"sys":1961},{"id":1962,"type":792,"linkType":793},"6q2NwH6Q4DJE7RNeYheIvJ",[],{"data":1965,"content":1966,"nodeType":796},{},[],{"data":1968,"content":1969,"nodeType":800},{},[1970],{"data":1971,"marks":1972,"value":1974,"nodeType":543},{},[1973],{"type":749},"Phishing infrastructure has reached an industrial scale",{"data":1976,"content":1977,"nodeType":673},{},[1978],{"data":1979,"marks":1980,"value":1981,"nodeType":543},{},[],"The SLH playbook works because it sits on top of an industrialized infrastructure layer that continues to grow. Phishing-as-a-Service platforms, device code phishing kits, ClickFix Malware-as-a-Service providers, vishing operations, and OAuth supply chain attacks have all matured into commodity services — and they're shipping faster than ever.",{"data":1983,"content":1984,"nodeType":829},{},[1985],{"data":1986,"marks":1987,"value":1989,"nodeType":543},{},[1988],{"type":749},"Device code phishing goes mainstream",{"data":1991,"content":1992,"nodeType":673},{},[1993,1997,2003],{"data":1994,"marks":1995,"value":1996,"nodeType":543},{},[],"We're tracking a huge spike in ",{"data":1998,"content":1999,"nodeType":695},{"uri":716},[2000],{"data":2001,"marks":2002,"value":719,"nodeType":543},{},[],{"data":2004,"marks":2005,"value":2006,"nodeType":543},{},[]," since the start of 2026, with 25+ distinct kits now offering the technique. At the beginning of the year, we were tracking one or two.",{"data":2008,"content":2009,"nodeType":673},{},[2010,2014,2022,2026,2034,2038,2046,2050,2058],{"data":2011,"marks":2012,"value":2013,"nodeType":543},{},[],"What began with ",{"data":2015,"content":2017,"nodeType":695},{"uri":2016},"https://www.microsoft.com/en-us/security/blog/2025/02/13/storm-2372-conducts-device-code-phishing-campaign/",[2018],{"data":2019,"marks":2020,"value":2021,"nodeType":543},{},[],"Storm-2372's nation-state campaigns",{"data":2023,"marks":2024,"value":2025,"nodeType":543},{},[]," in August 2024 has proliferated through criminal kits like ",{"data":2027,"content":2029,"nodeType":695},{"uri":2028},"https://thehackernews.com/2026/05/the-new-phishing-click-how-oauth-consent.html",[2030],{"data":2031,"marks":2032,"value":2033,"nodeType":543},{},[],"EvilTokens",{"data":2035,"marks":2036,"value":2037,"nodeType":543},{},[]," (340+ organizations in its first five weeks), ",{"data":2039,"content":2041,"nodeType":695},{"uri":2040},"https://www.huntress.com/blog/kali365-device-code-phishing-kit",[2042],{"data":2043,"marks":2044,"value":2045,"nodeType":543},{},[],"Kali365",{"data":2047,"marks":2048,"value":2049,"nodeType":543},{},[]," (which earned an FBI public advisory), ",{"data":2051,"content":2053,"nodeType":695},{"uri":2052},"https://blog.talosintelligence.com/artoken-inside-an-eviltokens-affiliate-panel-targeting-microsoft-365/",[2054],{"data":2055,"marks":2056,"value":2057,"nodeType":543},{},[],"ARToken",{"data":2059,"marks":2060,"value":2061,"nodeType":543},{},[],", DEBULL, Forg365, and many more.",{"data":2063,"content":2067,"nodeType":787},{"target":2064},{"sys":2065},{"id":2066,"type":792,"linkType":793},"7G6ytXRQPWatOyYarqgMK2",[],{"data":2069,"content":2070,"nodeType":673},{},[2071],{"data":2072,"marks":2073,"value":2074,"nodeType":543},{},[],"The existing PhaaS marketplace, previously dominated by AiTM phishing kits as the standard, has also pivoted to take advantage of the demand for the technique.",{"data":2076,"content":2077,"nodeType":673},{},[2078,2082,2089],{"data":2079,"marks":2080,"value":2081,"nodeType":543},{},[],"Established AiTM vendors like Tycoon 2FA have ",{"data":2083,"content":2084,"nodeType":695},{"uri":895},[2085],{"data":2086,"marks":2087,"value":2088,"nodeType":543},{},[],"added device code phishing",{"data":2090,"marks":2091,"value":2092,"nodeType":543},{},[]," alongside their existing credential-harvesting capabilities, meaning the same platforms now offer both techniques interchangeably based on what works against a given target. Several kits like Venom, EvilTokens, Kali365 all reportedly offer both capabilities, while many of the detections we see match the signatures for existing kits in our database (for example, with Venom triggering our existing Sneaky2FA detections) — suggesting an overlap in kit developers or their codebases.",{"data":2094,"content":2098,"nodeType":787},{"target":2095},{"sys":2096},{"id":2097,"type":792,"linkType":793},"3urXbEwK0OSjXQ7lOMDEoc",[],{"data":2100,"content":2101,"nodeType":673},{},[2102],{"data":2103,"marks":2104,"value":2105,"nodeType":543},{},[],"When you look at the full picture, it's notable to see a mixture of AiTM and device code kits in our top detected kits, with most of the top 5 now offering both.",{"data":2107,"content":2111,"nodeType":787},{"target":2108},{"sys":2109},{"id":2110,"type":792,"linkType":793},"4ipTS2U4HE1VLSLmA6DJgB",[],{"data":2113,"content":2114,"nodeType":673},{},[2115],{"data":2116,"marks":2117,"value":2118,"nodeType":543},{},[],"PhaaS vendors are pivoting because device code phishing defeats all MFA (including passkeys) by targeting the authorization layer rather than the login. It's also an unfamiliar phishing scenario that most people aren't really prepared for.",{"data":2120,"content":2124,"nodeType":787},{"target":2121},{"sys":2122},{"id":2123,"type":792,"linkType":793},"3UDzUCCizPJhXp3SsoZuSK",[],{"data":2126,"content":2127,"nodeType":673},{},[2128],{"data":2129,"marks":2130,"value":2131,"nodeType":543},{},[],"And because they're being used interchangeably, there's no downside for the attacker. In one recent example, we saw the attack automatically fall back to AiTM after the device code method timed out, giving the operator two shots at the same victim without manual intervention.",{"data":2133,"content":2137,"nodeType":787},{"target":2134},{"sys":2135},{"id":2136,"type":792,"linkType":793},"3SPsKzwBNxl4d9QRukBtwt",[],{"data":2139,"content":2140,"nodeType":829},{},[2141],{"data":2142,"marks":2143,"value":2145,"nodeType":543},{},[2144],{"type":749},"PhaaS platform evolution and evasion",{"data":2147,"content":2148,"nodeType":673},{},[2149,2153,2161,2165,2173,2177,2185],{"data":2150,"marks":2151,"value":2152,"nodeType":543},{},[],"The broader PhaaS ecosystem continues to expand and evolve. New platform launches this quarter include ",{"data":2154,"content":2156,"nodeType":695},{"uri":2155},"https://www.cloudsek.com/blog/bluekit-phishing-as-a-service-phaas",[2157],{"data":2158,"marks":2159,"value":2160,"nodeType":543},{},[],"Bluekit",{"data":2162,"marks":2163,"value":2164,"nodeType":543},{},[],", ",{"data":2166,"content":2168,"nodeType":695},{"uri":2167},"https://abnormal.ai/blog/blacksite-aitm-phishing-kit-cloaked-gg",[2169],{"data":2170,"marks":2171,"value":2172,"nodeType":543},{},[],"Blacksite and Cloaked.gg",{"data":2174,"marks":2175,"value":2176,"nodeType":543},{},[]," — offering dedicated anti-scanner cloaking as a service for phishing infrastructure — and ",{"data":2178,"content":2180,"nodeType":695},{"uri":2179},"https://threatactix.com/2026/07/02/a-rare-look-inside-the-command-and-control-panel-behind-modern-phishing-operations/",[2181],{"data":2182,"marks":2183,"value":2184,"nodeType":543},{},[],"WackoGinx",{"data":2186,"marks":2187,"value":2188,"nodeType":543},{},[],", a multi-platform C2 panel that enables operators to manage simultaneous phishing campaigns.",{"data":2190,"content":2191,"nodeType":673},{},[2192,2196,2204,2208,2216],{"data":2193,"marks":2194,"value":2195,"nodeType":543},{},[],"Sneaky 2FA changes have also been documented, with what ",{"data":2197,"content":2199,"nodeType":695},{"uri":2198},"https://zerobec.com/blog/sneaky-2fa-returns-trusted-sender-tenant-branded-microsoft-365-replay",[2200],{"data":2201,"marks":2202,"value":2203,"nodeType":543},{},[],"ZeroBEC calls \"route polymorphism\"",{"data":2205,"marks":2206,"value":2207,"nodeType":543},{},[]," (a complicated way of saying the kit randomizes URL paths and filenames on every visit) while separately adopting ",{"data":2209,"content":2211,"nodeType":695},{"uri":2210},"https://blog.barracuda.com/2026/06/29/email-threat-radar-june-2026",[2212],{"data":2213,"marks":2214,"value":2215,"nodeType":543},{},[],"split-click buttons and blob URLs",{"data":2217,"marks":2218,"value":2219,"nodeType":543},{},[]," designed to evade link analysis (where buttons have two links: automated scanners interact with one and see a legitimate Microsoft page, but humans naturally click the larger, more visually prominent bottom one and get routed via a blob URL to the phishing page). ",{"data":2221,"content":2222,"nodeType":673},{},[2223,2227,2235],{"data":2224,"marks":2225,"value":2226,"nodeType":543},{},[],"The speed of technique adoption across these platforms is itself accelerating. ",{"data":2228,"content":2230,"nodeType":695},{"uri":2229},"https://sublime.security/blog/flowerstorm-unleashes-the-krakvm-phaas-operators-turn-to-vm-based-obfuscation/",[2231],{"data":2232,"marks":2233,"value":2234,"nodeType":543},{},[],"FlowerStorm adopted",{"data":2236,"marks":2237,"value":2238,"nodeType":543},{},[]," KrakVM (an open-source JavaScript VM that compiles malicious JS into encrypted bytecode, defeating email security static analysis) within a month of KrakVM's public release on GitHub. The gap between a new evasion technique appearing publicly and its incorporation into commodity phishing kits has compressed to weeks.",{"data":2240,"content":2241,"nodeType":673},{},[2242,2246,2254,2258,2265],{"data":2243,"marks":2244,"value":2245,"nodeType":543},{},[],"At the same time, target surfaces are expanding: ",{"data":2247,"content":2249,"nodeType":695},{"uri":2248},"https://securitylabs.datadoghq.com/articles/behind-the-console-aws-aitm-phishing-kit-and-beyond/",[2250],{"data":2251,"marks":2252,"value":2253,"nodeType":543},{},[],"Datadog documented",{"data":2255,"marks":2256,"value":2257,"nodeType":543},{},[]," an AWS console AiTM kit that dynamically adapts to the victim's configured second factor (an example of ",{"data":2259,"content":2260,"nodeType":695},{"uri":697},[2261],{"data":2262,"marks":2263,"value":2264,"nodeType":543},{},[],"MFA downgrade",{"data":2266,"marks":2267,"value":2268,"nodeType":543},{},[]," in the wild), extending AiTM phishing from IdPs and SaaS applications to cloud infrastructure consoles.",{"data":2270,"content":2271,"nodeType":829},{},[2272],{"data":2273,"marks":2274,"value":2276,"nodeType":543},{},[2275],{"type":749},"ClickFix as a service",{"data":2278,"content":2279,"nodeType":673},{},[2280,2284,2292,2296,2304],{"data":2281,"marks":2282,"value":2283,"nodeType":543},{},[],"ClickFix has also continued to industrialize. ",{"data":2285,"content":2287,"nodeType":695},{"uri":2286},"https://blog.sekoia.io/unveiling-errtraffic-inside-a-growing-clickfix-malware-distribution-framework/",[2288],{"data":2289,"marks":2290,"value":2291,"nodeType":543},{},[],"Sekoia documented",{"data":2293,"marks":2294,"value":2295,"nodeType":543},{},[]," the ErrTraffic MaaS platform achieving a 60% victim conversion rate, while researchers ",{"data":2297,"content":2299,"nodeType":695},{"uri":2298},"https://kqlquery.com/posts/clickfix-gift-that-keeps-on-giving/",[2300],{"data":2301,"marks":2302,"value":2303,"nodeType":543},{},[],"mapped approximately 3,000 live ClickFix payloads",{"data":2305,"marks":2306,"value":2307,"nodeType":543},{},[]," being served through API-driven backends that dynamically generate uniquely obfuscated payloads per victim — essentially the ClickFix PhaaS equivalent.",{"data":2309,"content":2310,"nodeType":673},{},[2311,2315,2323,2327,2335],{"data":2312,"marks":2313,"value":2314,"nodeType":543},{},[],"The technique has also expanded cross-platform, with Unit 42 documenting ",{"data":2316,"content":2318,"nodeType":695},{"uri":2317},"https://www.bleepingcomputer.com/news/security/new-macos-clickfix-attack-silently-mounts-dmgs-to-push-infostealer/",[2319],{"data":2320,"marks":2321,"value":2322,"nodeType":543},{},[],"macOS ClickFix variants",{"data":2324,"marks":2325,"value":2326,"nodeType":543},{},[]," that mount DMGs and bypass Gatekeeper to deliver AMOS infostealer. At the mass deployment end, over ",{"data":2328,"content":2330,"nodeType":695},{"uri":2329},"https://blog.xlab.qianxin.com/ghost-cms-mass-compromised-via-cve-2026-26980-now-fueling-clickfix-attacks/",[2331],{"data":2332,"marks":2333,"value":2334,"nodeType":543},{},[],"700 Ghost CMS sites were compromised",{"data":2336,"marks":2337,"value":2338,"nodeType":543},{},[]," to serve ClickFix payloads in May, and the Gizmodo homepage was injected in June.",{"data":2340,"content":2341,"nodeType":673},{},[2342,2346,2354,2358,2366],{"data":2343,"marks":2344,"value":2345,"nodeType":543},{},[],"Nation-state actors are building around ClickFix too. Two DPRK subgroups independently stood up ClickFix infrastructure in July: ",{"data":2347,"content":2349,"nodeType":695},{"uri":2348},"https://thehackernews.com/2026/07/bluenoroff-zoom-phishing-kit-profiles.html",[2350],{"data":2351,"marks":2352,"value":2353,"nodeType":543},{},[],"BlueNoroff",{"data":2355,"marks":2356,"value":2357,"nodeType":543},{},[]," targeting crypto professionals via Zoom impersonation with wallet profiling before payload delivery, and ",{"data":2359,"content":2361,"nodeType":695},{"uri":2360},"https://socradar.io/blog/dprk-clickfake-pylangghost-golangghost-rats/",[2362],{"data":2363,"marks":2364,"value":2365,"nodeType":543},{},[],"Famous Chollima",{"data":2367,"marks":2368,"value":2369,"nodeType":543},{},[]," embedding ClickFix in multi-stage fake job interviews.",{"data":2371,"content":2372,"nodeType":829},{},[2373],{"data":2374,"marks":2375,"value":2377,"nodeType":543},{},[2376],{"type":749},"Vishing as a payload delivery mechanism",{"data":2379,"content":2380,"nodeType":673},{},[2381],{"data":2382,"marks":2383,"value":2384,"nodeType":543},{},[],"Vishing functions as a reliable delivery mechanism for all of these payloads, leveraged by ShinyHunters, Pink, and Helix (among many others) to deliver AiTM and device code phishing. A human operator on a phone call drives the victim through a browser-based technical payload, and the vishing delivery gets around email security controls.",{"data":2386,"content":2387,"nodeType":673},{},[2388,2392,2400],{"data":2389,"marks":2390,"value":2391,"nodeType":543},{},[],"When Push researchers ",{"data":2393,"content":2395,"nodeType":695},{"uri":2394},"https://pushsecurity.com/blog/inside-criminal-phishing-panel/",[2396],{"data":2397,"marks":2398,"value":2399,"nodeType":543},{},[],"infiltrated the phishing panels",{"data":2401,"marks":2402,"value":2403,"nodeType":543},{},[]," linked to ShinyHunters' campaigns, we found the mechanics for a live attacker relaying credentials and pushing new prompts in real time during the call, across 400+ linked domains and four infrastructure clusters.",{"data":2405,"content":2406,"nodeType":673},{},[2407,2411,2419,2423,2431,2435,2443,2447,2455],{"data":2408,"marks":2409,"value":2410,"nodeType":543},{},[],"The financial scale is now quantifiable: ",{"data":2412,"content":2414,"nodeType":695},{"uri":2413},"https://www.darkreading.com/cyberattacks-data-breaches/silent-ransom-us-law-firms-extortion-attacks",[2415],{"data":2416,"marks":2417,"value":2418,"nodeType":543},{},[],"Luna Moth",{"data":2420,"marks":2421,"value":2422,"nodeType":543},{},[]," (Silent Ransom Group), a ",{"data":2424,"content":2426,"nodeType":695},{"uri":2425},"https://www.crowdstrike.com/en-us/adversaries/chatty-spider/",[2427],{"data":2428,"marks":2429,"value":2430,"nodeType":543},{},[],"Russia-linked Conti spinoff",{"data":2432,"marks":2433,"value":2434,"nodeType":543},{},[]," operating independently of the Com, has extracted ",{"data":2436,"content":2438,"nodeType":695},{"uri":2437},"https://www.theinsurer.com/ti/news/exclusive-weil-gotshal-paid-double-digit-millions-in-suppression-payment-to-luna-2026-05-27/",[2439],{"data":2440,"marks":2441,"value":2442,"nodeType":543},{},[],"up to $48 million",{"data":2444,"marks":2445,"value":2446,"nodeType":543},{},[]," from Am Law 100 firms in 2026 alone, with 48 law firms on their leak site and the ",{"data":2448,"content":2450,"nodeType":695},{"uri":2449},"https://www.ic3.gov/CSA/2026/260526.pdf",[2451],{"data":2452,"marks":2453,"value":2454,"nodeType":543},{},[],"FBI issuing a dedicated flash alert",{"data":2456,"marks":2457,"value":1863,"nodeType":543},{},[],{"data":2459,"content":2460,"nodeType":673},{},[2461,2465,2473,2477,2485],{"data":2462,"marks":2463,"value":2464,"nodeType":543},{},[],"The infrastructure behind these campaigns is industrializing independently. ",{"data":2466,"content":2468,"nodeType":695},{"uri":2467},"https://www.okta.com/blog/threat-intelligence/behind-the-scenes-of-a-vishing-operation/",[2469],{"data":2470,"marks":2471,"value":2472,"nodeType":543},{},[],"Okta obtained access to Work Panel",{"data":2474,"marks":2475,"value":2476,"nodeType":543},{},[],", a multi-tenant vishing MaaS platform where phishing site standup is a one-button operation and callers are deliberately insulated from the credentials they help steal. Zscaler separately ",{"data":2478,"content":2480,"nodeType":695},{"uri":2479},"https://www.zscaler.com/blogs/security-research/helpdesk-hijackers-teams-vishing-quick-assist-and-gogrpc-backdoor",[2481],{"data":2482,"marks":2483,"value":2484,"nodeType":543},{},[],"documented a dedicated Teams-vishing initial access broker",{"data":2486,"marks":2487,"value":2488,"nodeType":543},{},[]," operating since January 2026, building bespoke post-access tooling and selling access to ransomware operators.",{"data":2490,"content":2491,"nodeType":829},{},[2492],{"data":2493,"marks":2494,"value":2496,"nodeType":543},{},[2495],{"type":749},"OAuth supply chain attacks",{"data":2498,"content":2499,"nodeType":673},{},[2500,2504,2511],{"data":2501,"marks":2502,"value":2503,"nodeType":543},{},[],"The OAuth supply chain dimension has also continued to produce confirmed victims. The ",{"data":2505,"content":2506,"nodeType":695},{"uri":1842},[2507],{"data":2508,"marks":2509,"value":2510,"nodeType":543},{},[],"Salesloft/Drift supply chain attack",{"data":2512,"marks":2513,"value":2514,"nodeType":543},{},[]," in 2025 set the template: compromise one SaaS vendor, steal OAuth tokens, access 700+ downstream customer Salesforce environments.",{"data":2516,"content":2517,"nodeType":673},{},[2518,2522,2530,2534,2542,2546,2554],{"data":2519,"marks":2520,"value":2521,"nodeType":543},{},[],"In 2026, the ",{"data":2523,"content":2525,"nodeType":695},{"uri":2524},"https://www.bleepingcomputer.com/news/security/vimeo-data-breach-exposes-personal-information-of-119-000-people/",[2526],{"data":2527,"marks":2528,"value":2529,"nodeType":543},{},[],"Anodot compromise",{"data":2531,"marks":2532,"value":2533,"nodeType":543},{},[]," cascaded through to Vimeo, Rockstar Games, and Zara. The ",{"data":2535,"content":2537,"nodeType":695},{"uri":2536},"https://pushsecurity.com/blog/unpacking-the-vercel-breach/",[2538],{"data":2539,"marks":2540,"value":2541,"nodeType":543},{},[],"Context.ai → Vercel",{"data":2543,"marks":2544,"value":2545,"nodeType":543},{},[]," breach followed the same structural pattern. And the ",{"data":2547,"content":2549,"nodeType":695},{"uri":2548},"https://www.bleepingcomputer.com/news/security/klue-oauth-breach-victim-list-grows-as-icarus-hackers-claim-attack/",[2550],{"data":2551,"marks":2552,"value":2553,"nodeType":543},{},[],"Klue/Icarus breach",{"data":2555,"marks":2556,"value":2557,"nodeType":543},{},[]," in June — where attackers pivoted from a legacy credential through stored OAuth tokens to exfiltrate Salesforce data from Huntress, Recorded Future, and Jamf among others — showed that OAuth tokens have become a tried and tested lateral movement vector in SaaS environments.",{"data":2559,"content":2560,"nodeType":796},{},[],{"data":2562,"content":2563,"nodeType":800},{},[2564],{"data":2565,"marks":2566,"value":2568,"nodeType":543},{},[2567],{"type":749},"AI is a force multiplier for attackers",{"data":2570,"content":2571,"nodeType":673},{},[2572],{"data":2573,"marks":2574,"value":2575,"nodeType":543},{},[],"Much of the security industry's AI threat discussion has focused on autonomous offensive AI and novel attack classes like prompt injection. But the place where AI is having the most measurable impact right now is less dramatic and more consequential: it's accelerating how the techniques we've already been tracking get built and operated.",{"data":2577,"content":2578,"nodeType":673},{},[2579],{"data":2580,"marks":2581,"value":2582,"nodeType":543},{},[],"The evidence is visible at every layer of the attack chain. Pretty much every phishing kit we come across in 2026 shows clear signs of vibe coding. For the classic AiTM lure, we used to find heavy obfuscation — attackers used to put a lot of effort into hiding their attacks. But now, they're essentially built to be disposable, and are full of verbose comments and nicely named unobfuscated functions. Why bother hiding when you can just spin up a new one? This is particularly notable when it comes to device code phishing, which owes its massive scale-up this year to vibecoded kits. ",{"data":2584,"content":2585,"nodeType":673},{},[2586,2590,2598],{"data":2587,"marks":2588,"value":2589,"nodeType":543},{},[],"You can see more examples of these kits under the hood in our blog post ",{"data":2591,"content":2593,"nodeType":695},{"uri":2592},"https://pushsecurity.com/blog/inside-criminal-phishing-panel",[2594],{"data":2595,"marks":2596,"value":2597,"nodeType":543},{},[],"infiltrating a criminal phishing panel. ",{"data":2599,"marks":2600,"value":21,"nodeType":543},{},[],{"data":2602,"content":2606,"nodeType":787},{"target":2603},{"sys":2604},{"id":2605,"type":792,"linkType":793},"01mOiserRBXraawXwQyJNm",[],{"data":2608,"content":2609,"nodeType":673},{},[2610],{"data":2611,"marks":2612,"value":2613,"nodeType":543},{},[],"Beyond vibe-coded kits, attackers are embedding AI as an integrated operational capability. ",{"data":2615,"content":2616,"nodeType":2727},{},[2617,2640,2661,2683,2705],{"data":2618,"content":2619,"nodeType":2639},{},[2620],{"data":2621,"content":2622,"nodeType":673},{},[2623,2627,2635],{"data":2624,"marks":2625,"value":2626,"nodeType":543},{},[],"The first major device code phishing kit identified in the wild, EvilTokens, ",{"data":2628,"content":2630,"nodeType":695},{"uri":2629},"https://www.huntress.com/blog/railway-paas-m365-token-replay-campaign",[2631],{"data":2632,"marks":2633,"value":2634,"nodeType":543},{},[],"heavily used Railway",{"data":2636,"marks":2637,"value":2638,"nodeType":543},{},[],", a PaaS built for vibe coding with prompt-based deployment and teardown of infrastructure. EvilTokens itself packaged AI workflows for email filter bypass, lure tailoring, and identifying high-value mailboxes. ","list-item",{"data":2641,"content":2642,"nodeType":2639},{},[2643],{"data":2644,"content":2645,"nodeType":673},{},[2646,2650,2657],{"data":2647,"marks":2648,"value":2649,"nodeType":543},{},[],"Kali365's E2 edition includes an AI-powered BEC module that ",{"data":2651,"content":2652,"nodeType":695},{"uri":2040},[2653],{"data":2654,"marks":2655,"value":2656,"nodeType":543},{},[],"uses Claude Sonnet",{"data":2658,"marks":2659,"value":2660,"nodeType":543},{},[]," to score intercepted conversations for fraud opportunity and draft contextual wire-transfer redirect replies — not an autonomous attack, but an AI-augmented workflow that makes an existing phishing kit more effective.",{"data":2662,"content":2663,"nodeType":2639},{},[2664],{"data":2665,"content":2666,"nodeType":673},{},[2667,2670,2679],{"data":2668,"marks":2669,"value":21,"nodeType":543},{},[],{"data":2671,"content":2673,"nodeType":695},{"uri":2672},"https://thehackernews.com/2026/07/exposed-server-reveals-ai-assisted.html",[2674],{"data":2675,"marks":2676,"value":2678,"nodeType":543},{},[2677],{"type":722},"Rapid7's analysis of an exposed server",{"data":2680,"marks":2681,"value":2682,"nodeType":543},{},[]," containing a complete phishing toolkit turned up over 1,000 delivery artifacts alongside hardcoded paths to AI coding tools and LLM-style documentation.",{"data":2684,"content":2685,"nodeType":2639},{},[2686],{"data":2687,"content":2688,"nodeType":673},{},[2689,2693,2701],{"data":2690,"marks":2691,"value":2692,"nodeType":543},{},[],"Three independent operators were ",{"data":2694,"content":2696,"nodeType":695},{"uri":2695},"https://thehackernews.com/2026/07/misconfigured-server-reveals-three.html",[2697],{"data":2698,"marks":2699,"value":2700,"nodeType":543},{},[],"found running kits from public GitHub forks",{"data":2702,"marks":2703,"value":2704,"nodeType":543},{},[]," with minimal, AI-assisted customization: one had been operating for over a year with 218 victims across 12 countries, running infrastructure that would previously have required significantly more technical ability to maintain. ",{"data":2706,"content":2707,"nodeType":2639},{},[2708],{"data":2709,"content":2710,"nodeType":673},{},[2711,2715,2723],{"data":2712,"marks":2713,"value":2714,"nodeType":543},{},[],"The tooling itself is starting to embed AI as a product feature — ",{"data":2716,"content":2718,"nodeType":695},{"uri":2717},"https://www.varonis.com/blog/dolphin-x-stealer",[2719],{"data":2720,"marks":2721,"value":2722,"nodeType":543},{},[],"Dolphin X",{"data":2724,"marks":2725,"value":2726,"nodeType":543},{},[],", a new MaaS infostealer targeting 300+ applications across browsers, password managers, cloud CLI tools, and crypto wallets, ships an AI Profiler that scores infected machines by application usage and installed software, then delivers daily ranked summaries so operators can prioritize high-value victims from thousands of infections.","unordered-list",{"data":2729,"content":2730,"nodeType":673},{},[2731,2735,2743,2747,2755,2759,2767],{"data":2732,"marks":2733,"value":2734,"nodeType":543},{},[],"AI adoption itself has also become an attack surface. Users searching for AI desktop applications are already looking to download and install software, and attackers are capitalizing on that behavior: a ",{"data":2736,"content":2738,"nodeType":695},{"uri":2737},"https://www.huntress.com/blog/fakeagent-claude-desktop-malvertising-ends-in-dotnet-rat",[2739],{"data":2740,"marks":2741,"value":2742,"nodeType":543},{},[],"malicious Claude.ai Artifact impersonating a download portal",{"data":2744,"marks":2745,"value":2746,"nodeType":543},{},[]," drew 7,100 visits via Bing search ads and compromised 29 organizations in 48 hours, following the ",{"data":2748,"content":2750,"nodeType":695},{"uri":2749},"https://pushsecurity.com/blog/llmshare-malvertising-campaign/",[2751],{"data":2752,"marks":2753,"value":2754,"nodeType":543},{},[],"LLMShare attack pattern",{"data":2756,"marks":2757,"value":2758,"nodeType":543},{},[]," we documented in May. A second campaign, ",{"data":2760,"content":2762,"nodeType":695},{"uri":2761},"https://www.huntress.com/blog/macsync-stealer-rat-reverse-engineering",[2763],{"data":2764,"marks":2765,"value":2766,"nodeType":543},{},[],"MacSync",{"data":2768,"marks":2769,"value":2770,"nodeType":543},{},[],", used a claude.ai conversation styled as an installation guide to deliver a macOS infostealer via a ClickFix-adjacent terminal paste, also distributed through Google Ads. In both cases, the AI platform's trusted domain carried the malicious content past URL reputation filters.",{"data":2772,"content":2773,"nodeType":829},{},[2774],{"data":2775,"marks":2776,"value":2778,"nodeType":543},{},[2777],{"type":749},"But the core techniques aren't changing",{"data":2780,"content":2781,"nodeType":673},{},[2782,2786,2794],{"data":2783,"marks":2784,"value":2785,"nodeType":543},{},[],"AI compresses the bottom layers of the ",{"data":2787,"content":2789,"nodeType":695},{"uri":2788},"https://pushsecurity.com/blog/the-pyramid-of-pain-in-the-ai-era/",[2790],{"data":2791,"marks":2792,"value":2793,"nodeType":543},{},[],"Pyramid of Pain",{"data":2795,"marks":2796,"value":2797,"nodeType":543},{},[]," (unique hashes, domains, IP addresses, host artifacts) by enabling faster domain rotation, cheaper kit development, and rotating payloads, but the technique-level behaviors remain unchanged.",{"data":2799,"content":2800,"nodeType":673},{},[2801],{"data":2802,"marks":2803,"value":2804,"nodeType":543},{},[],"A phishing page still has to harvest credentials. Device code phishing still has to abuse the authorization grant. ClickFix still has to inject a clipboard payload. Those behavioral signatures are structurally resistant to AI-driven variation because changing them means changing how the attack works.",{"data":2806,"content":2807,"nodeType":796},{},[],{"data":2809,"content":2810,"nodeType":800},{},[2811],{"data":2812,"marks":2813,"value":2815,"nodeType":543},{},[2814],{"type":749},"What this means for defenders",{"data":2817,"content":2818,"nodeType":673},{},[2819],{"data":2820,"marks":2821,"value":2822,"nodeType":543},{},[],"Every trend documented here converges on the same control point: the browser. The AI acceleration that makes all of it faster and cheaper doesn't change where the attacks execute, or how Push intercepts them.",{"data":2824,"content":2825,"nodeType":2727},{},[2826,2836,2846,2856],{"data":2827,"content":2828,"nodeType":2639},{},[2829],{"data":2830,"content":2831,"nodeType":673},{},[2832],{"data":2833,"marks":2834,"value":2835,"nodeType":543},{},[],"For AiTM phishing, Push's behavioral detection analyzes and blocks the phishing page in real time, regardless of which domains or hosting infrastructure the kit uses on any given day.",{"data":2837,"content":2838,"nodeType":2639},{},[2839],{"data":2840,"content":2841,"nodeType":673},{},[2842],{"data":2843,"marks":2844,"value":2845,"nodeType":543},{},[],"For device code phishing, Push detects both the phishing pages associated with device code kits and provides an additional layer on the legitimate device code authentication pages themselves, so users cannot enter attacker-supplied codes.",{"data":2847,"content":2848,"nodeType":2639},{},[2849],{"data":2850,"content":2851,"nodeType":673},{},[2852],{"data":2853,"marks":2854,"value":2855,"nodeType":543},{},[],"For ClickFix, Push detects the clipboard injection at the moment the malicious payload is written.",{"data":2857,"content":2858,"nodeType":2639},{},[2859],{"data":2860,"content":2861,"nodeType":673},{},[2862],{"data":2863,"marks":2864,"value":2865,"nodeType":543},{},[],"For OAuth supply chain attacks, Push monitors and controls consent flows at the browser layer, so security teams can govern which applications obtain tokens in the first place.",{"data":2867,"content":2868,"nodeType":673},{},[2869],{"data":2870,"marks":2871,"value":2872,"nodeType":543},{},[],"As AI enables more kits, more operators, and faster infrastructure rotation, indicator-based defenses that target domains, IPs, and hashes become less effective by the day. Behavioral detection that targets technique-class signatures (what the attack does) is the approach that scales.",{"data":2874,"content":2875,"nodeType":796},{},[],{"data":2877,"content":2878,"nodeType":673},{},[2879],{"data":2880,"marks":2881,"value":2882,"nodeType":543},{},[],"Push Security is the most powerful AI-native security tool in the browser. Think EDR, but for the browser — high-fidelity telemetry and real-time control across every session, on every device, with no browser migration required.",{"data":2884,"content":2885,"nodeType":673},{},[2886],{"data":2887,"marks":2888,"value":2889,"nodeType":543},{},[],"Security teams use Push to detect and stop advanced browser-based attacks like AiTM phishing, ClickFix, and session hijacking; gain visibility and control over AI tool usage across their workforce; harden identities by surfacing credential reuse, SSO gaps, and shadow IT; and support data loss and insider investigations with browser-layer telemetry that other tools can't see.",{"data":2891,"content":2892,"nodeType":673},{},[2893,2896,2905],{"data":2894,"marks":2895,"value":21,"nodeType":543},{},[],{"data":2897,"content":2899,"nodeType":695},{"uri":2898},"https://pushsecurity.com/demo/",[2900],{"data":2901,"marks":2902,"value":2904,"nodeType":543},{},[2903],{"type":722},"Book a live demo to learn more.",{"data":2906,"marks":2907,"value":21,"nodeType":543},{},[],"Browser threat landscape: mid-year update 2026","PhaaS industrialization, Scattered Spider copycats, and AI-augmented tooling — what the threat landscape looks like in 2026 so far.","2026-08-10T00:00:00.000Z","browser-threat-landscape-mid-year-update-2026",{"items":2913},[2914,2918],{"sys":2915,"name":2917},{"id":2916},"6A5RXS31ZQx3PwryGb1IMy","Browser-based attacks",{"sys":2919,"name":2921},{"id":2920},"4ksQNCFeBf8H4QIORqpRLw","Detection & response",{"items":2923},[2924],{"fullName":2925,"firstName":2926,"jobTitle":2927,"profilePicture":2928},"Dan Green","Dan","Threat Research",{"url":2929},"https://images.ctfassets.net/y1cdw1ablpvd/7jik1VhFgA3kgzXBXTm2Vw/fcd8c171da644903d0827eafcfbcaad0/Dan_Headshot_2025.png",{"__typename":1608,"sys":2931,"content":2933,"title":5936,"synopsis":5937,"hashTags":59,"publishedDate":5938,"slug":5939,"tagsCollection":5940,"authorsCollection":5946},{"id":2932},"5DmCqTU2Tg4adYScA5vT2x",{"json":2934},{"data":2935,"content":2936,"nodeType":669},{},[2937,2943,2963,2981,2988,2994,3001,3008,3011,3019,3025,3110,3129,3135,3142,3258,3264,3267,3275,3282,3288,3291,3299,3340,3346,3353,3360,3367,3374,3394,3400,3406,3412,3418,3424,3430,3436,3442,3709,3712,3720,3855,3861,3864,3872,3911,4045,4051,4054,4062,4209,4215,4218,4226,4232,4373,4379,4385,4388,4396,4543,4549,4552,4560,4706,4712,4715,4723,4818,4824,4827,4835,4929,4935,4938,4946,4952,5085,5091,5094,5102,5151,5157,5160,5168,5307,5312,5315,5323,5455,5461,5464,5472,5484,5491,5497,5503,5510,5531,5547,5553,5556,5564,5572,5593,5614,5619,5626,5633,5641,5648,5655,5662,5670,5677,5728,5734,5737,5745,5752,5759,5806,5812,5819,5822,5830,5837,5844,5864,5870,5877,5885,5892],{"data":2938,"content":2942,"nodeType":787},{"target":2939},{"sys":2940},{"id":2941,"type":792,"linkType":793},"XOFOeNqmRHeiRbkPOJrP1",[],{"data":2944,"content":2945,"nodeType":673},{},[2946,2950,2959],{"data":2947,"marks":2948,"value":2949,"nodeType":543},{},[],"The OAuth 2.0 ",{"data":2951,"content":2953,"nodeType":695},{"uri":2952},"https://www.rfc-editor.org/rfc/rfc8628",[2954],{"data":2955,"marks":2956,"value":2958,"nodeType":543},{},[2957],{"type":722},"device authorization grant",{"data":2960,"marks":2961,"value":2962,"nodeType":543},{},[]," was designed to enable input-constrained devices to sign-in to apps by asking the user to complete the login on a separate device by entering a code. But today, it’s mainly used when accessing CLI tools, meaning that many users encounter the device code flow daily. ",{"data":2964,"content":2965,"nodeType":673},{},[2966,2969,2977],{"data":2967,"marks":2968,"value":21,"nodeType":543},{},[],{"data":2970,"content":2972,"nodeType":695},{"uri":2971},"https://github.com/pushsecurity/saas-attacks/blob/main/techniques/device_code_phishing/description.md",[2973],{"data":2974,"marks":2975,"value":269,"nodeType":543},{},[2976],{"type":722},{"data":2978,"marks":2979,"value":2980,"nodeType":543},{},[]," attacks designed to exploit this authorization flow are not new — it was among the first techniques that we added to the SaaS attacks matrix back in 2023. But it’s taken until now for it to really enter mainstream adoption. ",{"data":2982,"content":2983,"nodeType":673},{},[2984],{"data":2985,"marks":2986,"value":2987,"nodeType":543},{},[],"The technique tricks a user into issuing access tokens for an attacker-controlled application (not a device, confusingly). Any app that supports device code logins can be a target. Popular examples include Microsoft, Google, Salesforce, GitHub, and AWS. That said, Microsoft is, as always, much more heavily targeted at scale now than any other app.",{"data":2989,"content":2993,"nodeType":787},{"target":2990},{"sys":2991},{"id":2992,"type":792,"linkType":793},"Al0pGH8vmOYiufDFiAbt0",[],{"data":2995,"content":2996,"nodeType":673},{},[2997],{"data":2998,"marks":2999,"value":3000,"nodeType":543},{},[],"We’ve always been surprised that attackers haven’t commonly used device code phishing in their standard toolkit, preferring session-stealing AITM phishing and other social engineering attacks like ClickFix. But it’s pretty clear from the recent data that the shift to mainstream adoption has now happened. ",{"data":3002,"content":3003,"nodeType":673},{},[3004],{"data":3005,"marks":3006,"value":3007,"nodeType":543},{},[],"In this blog post, we’ll explore the history of device code phishing, what’s changed for it to enter mainstream adoption, how it works under the hood (with recent examples), and what security teams can do about it. ",{"data":3009,"content":3010,"nodeType":796},{},[],{"data":3012,"content":3013,"nodeType":800},{},[3014],{"data":3015,"marks":3016,"value":3018,"nodeType":543},{},[3017],{"type":749},"A brief history of device code phishing",{"data":3020,"content":3024,"nodeType":787},{"target":3021},{"sys":3022},{"id":3023,"type":792,"linkType":793},"6u3DgvSGChtTJu7l9I7PG1",[],{"data":3026,"content":3027,"nodeType":673},{},[3028,3032,3041,3045,3054,3058,3067,3071,3080,3084,3093,3097,3106],{"data":3029,"marks":3030,"value":3031,"nodeType":543},{},[],"The technique was first documented in 2020, before Secureworks released the first tooling framework ",{"data":3033,"content":3035,"nodeType":695},{"uri":3034},"https://github.com/secureworks/PhishInSuits",[3036],{"data":3037,"marks":3038,"value":3040,"nodeType":543},{},[3039],{"type":722},"PhishInSuits",{"data":3042,"marks":3043,"value":3044,"nodeType":543},{},[]," a year later. A host of research followed, including ",{"data":3046,"content":3048,"nodeType":695},{"uri":3047},"https://github.com/secureworks/squarephish",[3049],{"data":3050,"marks":3051,"value":3053,"nodeType":543},{},[3052],{"type":722},"SquarePhish",{"data":3055,"marks":3056,"value":3057,"nodeType":543},{},[]," v1 (using QR codes to trigger the 15 minute code expiration window), Dirk-Jan Mollema’s ",{"data":3059,"content":3061,"nodeType":695},{"uri":3060},"https://dirkjanm.io/phishing-for-microsoft-entra-primary-refresh-tokens/",[3062],{"data":3063,"marks":3064,"value":3066,"nodeType":543},{},[3065],{"type":722},"key research",{"data":3068,"marks":3069,"value":3070,"nodeType":543},{},[]," (chaining device code phishing via Microsoft apps into Primary Refresh Token (PRT) acquisition to gain full browser-level access) and Dennis Kniep’s ",{"data":3072,"content":3074,"nodeType":695},{"uri":3073},"https://github.com/denniskniep/DeviceCodePhishing",[3075],{"data":3076,"marks":3077,"value":3079,"nodeType":543},{},[3078],{"type":722},"DeviceCodePhishing tool",{"data":3081,"marks":3082,"value":3083,"nodeType":543},{},[]," which automates the entire flow with a headless browser. (Other recent noteworthy tools include ",{"data":3085,"content":3087,"nodeType":695},{"uri":3086},"https://github.com/nromsdahl/squarephish2",[3088],{"data":3089,"marks":3090,"value":3092,"nodeType":543},{},[3091],{"type":722},"SquarePhish2",{"data":3094,"marks":3095,"value":3096,"nodeType":543},{},[]," and ",{"data":3098,"content":3100,"nodeType":695},{"uri":3099},"https://github.com/praetorian-inc/GitPhish",[3101],{"data":3102,"marks":3103,"value":3105,"nodeType":543},{},[3104],{"type":722},"GitPhish",{"data":3107,"marks":3108,"value":3109,"nodeType":543},{},[],", so shout out to those too). ",{"data":3111,"content":3112,"nodeType":673},{},[3113,3117,3125],{"data":3114,"marks":3115,"value":3116,"nodeType":543},{},[],"It wasn’t until August 2024 that in-the-wild exploitation was first identified, with Russia-linked campaigns then continuing into 2025 before entering mainstream criminal adoption. This trend has continued to gather momentum in 2026 with ",{"data":3118,"content":3120,"nodeType":695},{"uri":3119},"https://thehackernews.com/2026/03/device-code-phishing-hits-340-microsoft.html",[3121],{"data":3122,"marks":3123,"value":2033,"nodeType":543},{},[3124],{"type":722},{"data":3126,"marks":3127,"value":3128,"nodeType":543},{},[],", the first reported criminal PhaaS kit for device code phishing, already powering massive campaigns after launching in February. ",{"data":3130,"content":3134,"nodeType":787},{"target":3131},{"sys":3132},{"id":3133,"type":792,"linkType":793},"6xsfmbYEzpW7CdDiNzO6cu",[],{"data":3136,"content":3137,"nodeType":673},{},[3138],{"data":3139,"marks":3140,"value":3141,"nodeType":543},{},[],"Some of the noteworthy in-the-wild campaigns include:",{"data":3143,"content":3144,"nodeType":2727},{},[3145,3177,3198],{"data":3146,"content":3147,"nodeType":2639},{},[3148],{"data":3149,"content":3150,"nodeType":673},{},[3151,3155,3162,3165,3173],{"data":3152,"marks":3153,"value":3154,"nodeType":543},{},[],"Storm-2372, tracked by ",{"data":3156,"content":3157,"nodeType":695},{"uri":2016},[3158],{"data":3159,"marks":3160,"value":3161,"nodeType":543},{},[],"Microsoft",{"data":3163,"marks":3164,"value":3096,"nodeType":543},{},[],{"data":3166,"content":3168,"nodeType":695},{"uri":3167},"https://www.volexity.com/blog/2025/02/13/multiple-russian-threat-actors-targeting-microsoft-device-code-authentication/",[3169],{"data":3170,"marks":3171,"value":3172,"nodeType":543},{},[],"Volexity",{"data":3174,"marks":3175,"value":3176,"nodeType":543},{},[],", linked to multiple Russia-aligned clusters, combining spear-phishing and social engineering with device code phishing payloads against strategic intelligence targets.",{"data":3178,"content":3179,"nodeType":2639},{},[3180],{"data":3181,"content":3182,"nodeType":673},{},[3183,3187,3194],{"data":3184,"marks":3185,"value":3186,"nodeType":543},{},[],"The massive Salesforce campaign operated by ",{"data":3188,"content":3190,"nodeType":695},{"uri":3189},"https://pushsecurity.com/blog/scattered-lapsus-hunters/",[3191],{"data":3192,"marks":3193,"value":1647,"nodeType":543},{},[],{"data":3195,"marks":3196,"value":3197,"nodeType":543},{},[]," (SLH) combined vishing with a device code phishing payload targeting Salesforce. The attacks morphed into a broader supply chain campaign using stolen credentials, ultimately resulting in 1000+ organizations being compromised and over 1.5 billion stolen records claimed. ",{"data":3199,"content":3200,"nodeType":2639},{},[3201],{"data":3202,"content":3203,"nodeType":673},{},[3204,3208,3216,3220,3229,3233,3242,3246,3254],{"data":3205,"marks":3206,"value":3207,"nodeType":543},{},[],"A massive spike in activity in late 2025 and 2026. This includes ",{"data":3209,"content":3211,"nodeType":695},{"uri":3210},"https://www.proofpoint.com/us/blog/threat-insight/access-granted-phishing-device-code-authorization-account-takeover",[3212],{"data":3213,"marks":3214,"value":3215,"nodeType":543},{},[],"multiple threat clusters",{"data":3217,"marks":3218,"value":3219,"nodeType":543},{},[]," tracked using device code phishing techniques, more ",{"data":3221,"content":3223,"nodeType":695},{"uri":3222},"https://www.bleepingcomputer.com/news/security/hackers-target-microsoft-entra-accounts-in-device-code-vishing-attacks/",[3224],{"data":3225,"marks":3226,"value":3228,"nodeType":543},{},[3227],{"type":722},"criminal operations linked to SLH",{"data":3230,"marks":3231,"value":3232,"nodeType":543},{},[],", and ",{"data":3234,"content":3236,"nodeType":695},{"uri":3235},"https://newtonpaul.com/blog/device-code-phish-update/",[3237],{"data":3238,"marks":3239,"value":3241,"nodeType":543},{},[3240],{"type":722},"hundreds of organizations being targeted via PhaaS architecture,",{"data":3243,"marks":3244,"value":3245,"nodeType":543},{},[]," which looks to be the same campaign as the recently uncovered EvilTokens PhaaS reported by ",{"data":3247,"content":3248,"nodeType":695},{"uri":2629},[3249],{"data":3250,"marks":3251,"value":3253,"nodeType":543},{},[3252],{"type":722},"Huntress",{"data":3255,"marks":3256,"value":3257,"nodeType":543},{},[]," (featuring abuse of the Railway PaaS platform). ",{"data":3259,"content":3263,"nodeType":787},{"target":3260},{"sys":3261},{"id":3262,"type":792,"linkType":793},"3WLt6qLCK8CSwr0QZxZiMv",[],{"data":3265,"content":3266,"nodeType":796},{},[],{"data":3268,"content":3269,"nodeType":800},{},[3270],{"data":3271,"marks":3272,"value":3274,"nodeType":543},{},[3273],{"type":749},"What we’re seeing in the wild",{"data":3276,"content":3277,"nodeType":673},{},[3278],{"data":3279,"marks":3280,"value":3281,"nodeType":543},{},[],"As mentioned, we’ve also seen a huge spike in device code phishing activity this year, with multiple kits, page designs, and lure types. We’ve now identified 14+ distinct kits in circulation in the wild, with EvilTokens being the most prevalent. It’s clear that attackers are both spinning up their own kits and creative derivatives of others — we’ve seen kits that are visually similar to EvilTokens (close enough to be clones or forks) but with very different backends, for example AWS, Digital Ocean, 2cloud, and more. ",{"data":3283,"content":3287,"nodeType":787},{"target":3284},{"sys":3285},{"id":3286,"type":792,"linkType":793},"nJCbTw85GKXdqrlIkzZwi",[],{"data":3289,"content":3290,"nodeType":796},{},[],{"data":3292,"content":3293,"nodeType":829},{},[3294],{"data":3295,"marks":3296,"value":3298,"nodeType":543},{},[3297],{"type":749},"“ANTIBOT” (EvilTokens)",{"data":3300,"content":3301,"nodeType":673},{},[3302,3305,3312,3315,3324,3328,3336],{"data":3303,"marks":3304,"value":21,"nodeType":543},{},[],{"data":3306,"content":3307,"nodeType":695},{"uri":2629},[3308],{"data":3309,"marks":3310,"value":3253,"nodeType":543},{},[3311],{"type":722},{"data":3313,"marks":3314,"value":2164,"nodeType":543},{},[],{"data":3316,"content":3318,"nodeType":695},{"uri":3317},"https://blog.sekoia.io/new-widespread-eviltokens-kit-device-code-phishing-as-a-service-part-1/",[3319],{"data":3320,"marks":3321,"value":3323,"nodeType":543},{},[3322],{"type":722},"Sekoia",{"data":3325,"marks":3326,"value":3327,"nodeType":543},{},[],", and researcher ",{"data":3329,"content":3330,"nodeType":695},{"uri":3235},[3331],{"data":3332,"marks":3333,"value":3335,"nodeType":543},{},[3334],{"type":722},"Paul Newton",{"data":3337,"marks":3338,"value":3339,"nodeType":543},{},[]," have already done a great job of providing IOCs for the recent EvilTokens activity spike, including multiple backend Railway IPs in authentication events. ",{"data":3341,"content":3345,"nodeType":787},{"target":3342},{"sys":3343},{"id":3344,"type":792,"linkType":793},"1XNviq5OvMf5TEAc59F6g5",[],{"data":3347,"content":3348,"nodeType":673},{},[3349],{"data":3350,"marks":3351,"value":3352,"nodeType":543},{},[],"Beyond the most widely observed implementation featuring a Cloudflare Workers frontend and Railway backend for authentication, we’ve also tracked additional versions of EvilTokens in circulation since January 2026 (many of which remain live along with the current “production” version of the kit). ",{"data":3354,"content":3355,"nodeType":673},{},[3356],{"data":3357,"marks":3358,"value":3359,"nodeType":543},{},[],"You can see an evolution of the kit in the videos and screenshots below, from early precursors seen in mid-January, the first mentions of ANTIBOT in the page code in late-January, the parallel development of a “Courts Access” fork that lacks the ANTIBOT references, and finally production EvilTokens in February. One of the key threads between the versions is the presence of a generateFallbackCode() JS function and use of a /generate-codes API call. ",{"data":3361,"content":3362,"nodeType":673},{},[3363],{"data":3364,"marks":3365,"value":3366,"nodeType":543},{},[],"Early implementations were quite different, for example using ScrapingBee to generate the displayed code, and varied hosting on vercel, fastly, edgeone, and others. ",{"data":3368,"content":3369,"nodeType":673},{},[3370],{"data":3371,"marks":3372,"value":3373,"nodeType":543},{},[],"After initially appearing on custom domains, the production version is now predominantly hosted on Cloudflare Workers, as per the broader tracking of the campaign. The descriptive HTML comments around ANTIBOT functions have also been removed in later versions. ",{"data":3375,"content":3376,"nodeType":673},{},[3377,3381,3390],{"data":3378,"marks":3379,"value":3380,"nodeType":543},{},[],"The production version of EvilTokens showcases common ",{"data":3382,"content":3384,"nodeType":695},{"uri":3383},"https://phishing-techniques.pushsecurity.com/",[3385],{"data":3386,"marks":3387,"value":3389,"nodeType":543},{},[3388],{"type":722},"detection evasion techniques",{"data":3391,"marks":3392,"value":3393,"nodeType":543},{},[]," we've come to associate with PhaaS kits in the AiTM space — using multiple redirects through trusted sites before serving the malicious page, using bot protection to block security tools from analyzing the page, and so on. It also uses a pop-up window for the device code entry rather than a redirect, reducing the friction for the victim (it looks pretty convincing, too).",{"data":3395,"content":3399,"nodeType":787},{"target":3396},{"sys":3397},{"id":3398,"type":792,"linkType":793},"73rNOIEDPfP5IJwpFaxVc2",[],{"data":3401,"content":3405,"nodeType":787},{"target":3402},{"sys":3403},{"id":3404,"type":792,"linkType":793},"5BJSvOQUW9UpsQtoDNtgTC",[],{"data":3407,"content":3411,"nodeType":787},{"target":3408},{"sys":3409},{"id":3410,"type":792,"linkType":793},"3dbePPxVb4h4SauGg3glIL",[],{"data":3413,"content":3417,"nodeType":787},{"target":3414},{"sys":3415},{"id":3416,"type":792,"linkType":793},"1UOLcmNQvOsL5tdLSVuviq",[],{"data":3419,"content":3423,"nodeType":787},{"target":3420},{"sys":3421},{"id":3422,"type":792,"linkType":793},"55XRqLSwUUi2D4ZVpJboml",[],{"data":3425,"content":3429,"nodeType":787},{"target":3426},{"sys":3427},{"id":3428,"type":792,"linkType":793},"5wg5yr2Lo8t3f72ZV815c",[],{"data":3431,"content":3435,"nodeType":787},{"target":3432},{"sys":3433},{"id":3434,"type":792,"linkType":793},"35cowlL6i3rkGXOGmSxlI1",[],{"data":3437,"content":3438,"nodeType":673},{},[3439],{"data":3440,"marks":3441,"value":21,"nodeType":543},{},[],{"data":3443,"content":3444,"nodeType":3708},{},[3445,3471,3555,3607,3631],{"data":3446,"content":3447,"nodeType":3470},{},[3448,3460],{"data":3449,"content":3450,"nodeType":3459},{},[3451],{"data":3452,"content":3453,"nodeType":673},{},[3454],{"data":3455,"marks":3456,"value":3458,"nodeType":543},{},[3457],{"type":749},"Frontend infrastructure","table-cell",{"data":3461,"content":3462,"nodeType":3459},{},[3463],{"data":3464,"content":3465,"nodeType":673},{},[3466],{"data":3467,"marks":3468,"value":3469,"nodeType":543},{},[],"Workers.dev, vercel.app, github.io, fastly.net, edgeone.dev","table-row",{"data":3472,"content":3473,"nodeType":3470},{},[3474,3485],{"data":3475,"content":3476,"nodeType":3459},{},[3477],{"data":3478,"content":3479,"nodeType":673},{},[3480],{"data":3481,"marks":3482,"value":3484,"nodeType":543},{},[3483],{"type":749},"Backend infrastructure",{"data":3486,"content":3487,"nodeType":3459},{},[3488,3518],{"data":3489,"content":3490,"nodeType":673},{},[3491,3496,3500,3505,3509,3514],{"data":3492,"marks":3493,"value":3495,"nodeType":543},{},[3494],{"type":749},"Example IP: (V3) ",{"data":3497,"marks":3498,"value":3499,"nodeType":543},{},[],"162.220.232.71 (Railway AS400940) ",{"data":3501,"marks":3502,"value":3504,"nodeType":543},{},[3503],{"type":749},"(V2)",{"data":3506,"marks":3507,"value":3508,"nodeType":543},{},[]," 71.11.42.193 ",{"data":3510,"marks":3511,"value":3513,"nodeType":543},{},[3512],{"type":749},"(V1) ",{"data":3515,"marks":3516,"value":3517,"nodeType":543},{},[],"72.218.25.107",{"data":3519,"content":3520,"nodeType":673},{},[3521,3526,3530,3535,3539,3543,3547,3551],{"data":3522,"marks":3523,"value":3525,"nodeType":543},{},[3524],{"type":749},"Backend User Agent:",{"data":3527,"marks":3528,"value":3529,"nodeType":543},{},[]," ",{"data":3531,"marks":3532,"value":3534,"nodeType":543},{},[3533],{"type":749},"(V3) ",{"data":3536,"marks":3537,"value":3538,"nodeType":543},{},[],"node, ",{"data":3540,"marks":3541,"value":3504,"nodeType":543},{},[3542],{"type":749},{"data":3544,"marks":3545,"value":3546,"nodeType":543},{},[],", Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_4) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/73.0.3683 Safari/537.36 OPR/57.0.3098.91 ",{"data":3548,"marks":3549,"value":3513,"nodeType":543},{},[3550],{"type":749},{"data":3552,"marks":3553,"value":3554,"nodeType":543},{},[],"Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/71.0.3578.98 Safari/537.36 OPR/56.0.3051.52 ",{"data":3556,"content":3557,"nodeType":3470},{},[3558,3569],{"data":3559,"content":3560,"nodeType":3459},{},[3561],{"data":3562,"content":3563,"nodeType":673},{},[3564],{"data":3565,"marks":3566,"value":3568,"nodeType":543},{},[3567],{"type":749},"Network paths",{"data":3570,"content":3571,"nodeType":3459},{},[3572,3579,3586,3593,3600],{"data":3573,"content":3574,"nodeType":673},{},[3575],{"data":3576,"marks":3577,"value":3578,"nodeType":543},{},[],"/api/rate-limit ",{"data":3580,"content":3581,"nodeType":673},{},[3582],{"data":3583,"marks":3584,"value":3585,"nodeType":543},{},[],"/api/fingerprint ",{"data":3587,"content":3588,"nodeType":673},{},[3589],{"data":3590,"marks":3591,"value":3592,"nodeType":543},{},[],"/api/captcha-verify ",{"data":3594,"content":3595,"nodeType":673},{},[3596],{"data":3597,"marks":3598,"value":3599,"nodeType":543},{},[],"/api/init /api/generate-code ",{"data":3601,"content":3602,"nodeType":673},{},[3603],{"data":3604,"marks":3605,"value":3606,"nodeType":543},{},[],"/api/check-auth",{"data":3608,"content":3609,"nodeType":3470},{},[3610,3621],{"data":3611,"content":3612,"nodeType":3459},{},[3613],{"data":3614,"content":3615,"nodeType":673},{},[3616],{"data":3617,"marks":3618,"value":3620,"nodeType":543},{},[3619],{"type":749},"Lure themes",{"data":3622,"content":3623,"nodeType":3459},{},[3624],{"data":3625,"content":3626,"nodeType":673},{},[3627],{"data":3628,"marks":3629,"value":3630,"nodeType":543},{},[],"Various MS lures (e.g. Outlook, SharePoint, Teams) DocuSign, Adobe",{"data":3632,"content":3633,"nodeType":3470},{},[3634,3645],{"data":3635,"content":3636,"nodeType":3459},{},[3637],{"data":3638,"content":3639,"nodeType":673},{},[3640],{"data":3641,"marks":3642,"value":3644,"nodeType":543},{},[3643],{"type":749},"Example Domain",{"data":3646,"content":3647,"nodeType":3459},{},[3648,3660,3672,3684,3696],{"data":3649,"content":3650,"nodeType":673},{},[3651,3656],{"data":3652,"marks":3653,"value":3655,"nodeType":543},{},[3654],{"type":749},"Precursor A:",{"data":3657,"marks":3658,"value":3659,"nodeType":543},{},[]," teams-zpfvwnpxuc[.]edgeone.dev",{"data":3661,"content":3662,"nodeType":673},{},[3663,3668],{"data":3664,"marks":3665,"value":3667,"nodeType":543},{},[3666],{"type":749},"Precursor B: ",{"data":3669,"marks":3670,"value":3671,"nodeType":543},{},[],"authenticate-m365-accountsecurity-m-pi[.]vercel.app",{"data":3673,"content":3674,"nodeType":673},{},[3675,3680],{"data":3676,"marks":3677,"value":3679,"nodeType":543},{},[3678],{"type":749},"Courts Access: ",{"data":3681,"marks":3682,"value":3683,"nodeType":543},{},[],"secure-systems-validations-courts[.]vercel.app",{"data":3685,"content":3686,"nodeType":673},{},[3687,3692],{"data":3688,"marks":3689,"value":3691,"nodeType":543},{},[3690],{"type":749},"Early ANTIBOT:",{"data":3693,"marks":3694,"value":3695,"nodeType":543},{},[]," interface-auth-en-useast[.]global.ssl.fastly.net",{"data":3697,"content":3698,"nodeType":673},{},[3699,3704],{"data":3700,"marks":3701,"value":3703,"nodeType":543},{},[3702],{"type":749},"Production ANTIBOT: ",{"data":3705,"marks":3706,"value":3707,"nodeType":543},{},[],"index-z059-document-pending-reviewsign-xlss7994824[.]awalizer[.]workers.dev","table",{"data":3710,"content":3711,"nodeType":796},{},[],{"data":3713,"content":3714,"nodeType":829},{},[3715],{"data":3716,"marks":3717,"value":3719,"nodeType":543},{},[3718],{"type":749},"“SHAREFILE”",{"data":3721,"content":3722,"nodeType":3708},{},[3723,3746,3785,3808,3831],{"data":3724,"content":3725,"nodeType":3470},{},[3726,3736],{"data":3727,"content":3728,"nodeType":3459},{},[3729],{"data":3730,"content":3731,"nodeType":673},{},[3732],{"data":3733,"marks":3734,"value":3458,"nodeType":543},{},[3735],{"type":749},{"data":3737,"content":3738,"nodeType":3459},{},[3739],{"data":3740,"content":3741,"nodeType":673},{},[3742],{"data":3743,"marks":3744,"value":3745,"nodeType":543},{},[],"No hosting markers visible.",{"data":3747,"content":3748,"nodeType":3470},{},[3749,3759],{"data":3750,"content":3751,"nodeType":3459},{},[3752],{"data":3753,"content":3754,"nodeType":673},{},[3755],{"data":3756,"marks":3757,"value":3484,"nodeType":543},{},[3758],{"type":749},{"data":3760,"content":3761,"nodeType":3459},{},[3762,3774],{"data":3763,"content":3764,"nodeType":673},{},[3765,3770],{"data":3766,"marks":3767,"value":3769,"nodeType":543},{},[3768],{"type":749},"Example IP:",{"data":3771,"marks":3772,"value":3773,"nodeType":543},{},[]," 147.45.60.47 (Global Connectivity Solutions LLP AS215540)",{"data":3775,"content":3776,"nodeType":673},{},[3777,3781],{"data":3778,"marks":3779,"value":3525,"nodeType":543},{},[3780],{"type":749},{"data":3782,"marks":3783,"value":3784,"nodeType":543},{},[]," node",{"data":3786,"content":3787,"nodeType":3470},{},[3788,3798],{"data":3789,"content":3790,"nodeType":3459},{},[3791],{"data":3792,"content":3793,"nodeType":673},{},[3794],{"data":3795,"marks":3796,"value":3568,"nodeType":543},{},[3797],{"type":749},{"data":3799,"content":3800,"nodeType":3459},{},[3801],{"data":3802,"content":3803,"nodeType":673},{},[3804],{"data":3805,"marks":3806,"value":3807,"nodeType":543},{},[],"POST /api/device/start  POST /api/device/poll",{"data":3809,"content":3810,"nodeType":3470},{},[3811,3821],{"data":3812,"content":3813,"nodeType":3459},{},[3814],{"data":3815,"content":3816,"nodeType":673},{},[3817],{"data":3818,"marks":3819,"value":3620,"nodeType":543},{},[3820],{"type":749},{"data":3822,"content":3823,"nodeType":3459},{},[3824],{"data":3825,"content":3826,"nodeType":673},{},[3827],{"data":3828,"marks":3829,"value":3830,"nodeType":543},{},[],"Citrix ShareFile document transfer — file card with sender info, expiry warning, download/preview buttons",{"data":3832,"content":3833,"nodeType":3470},{},[3834,3845],{"data":3835,"content":3836,"nodeType":3459},{},[3837],{"data":3838,"content":3839,"nodeType":673},{},[3840],{"data":3841,"marks":3842,"value":3844,"nodeType":543},{},[3843],{"type":749},"Example domain",{"data":3846,"content":3847,"nodeType":3459},{},[3848],{"data":3849,"content":3850,"nodeType":673},{},[3851],{"data":3852,"marks":3853,"value":3854,"nodeType":543},{},[],"cghdfg[.]vbchkioi[.]su",{"data":3856,"content":3860,"nodeType":787},{"target":3857},{"sys":3858},{"id":3859,"type":792,"linkType":793},"1TtZ6VsMSTlPvy7W996w9E",[],{"data":3862,"content":3863,"nodeType":796},{},[],{"data":3865,"content":3866,"nodeType":829},{},[3867],{"data":3868,"marks":3869,"value":3871,"nodeType":543},{},[3870],{"type":749},"Kali365 (internal name “CLURE”)",{"data":3873,"content":3874,"nodeType":673},{},[3875,3879,3883,3887,3895,3899,3907],{"data":3876,"marks":3877,"value":3878,"nodeType":543},{},[],"Clure was recently linked to the ",{"data":3880,"marks":3881,"value":2045,"nodeType":543},{},[3882],{"type":749},{"data":3884,"marks":3885,"value":3886,"nodeType":543},{},[]," PhaaS platform based on an ",{"data":3888,"content":3890,"nodeType":695},{"uri":3889},"https://www.ic3.gov/PSA/2026/PSA260521",[3891],{"data":3892,"marks":3893,"value":3894,"nodeType":543},{},[],"FBI advisory",{"data":3896,"marks":3897,"value":3898,"nodeType":543},{},[]," and additional research from ",{"data":3900,"content":3902,"nodeType":695},{"uri":3901},"https://arcticwolf.com/resources/blog/token-bingo-dont-let-your-code-be-the-winner/",[3903],{"data":3904,"marks":3905,"value":3906,"nodeType":543},{},[],"Arctic Wolf",{"data":3908,"marks":3909,"value":3910,"nodeType":543},{},[],". This is yet another example of Device Code Phishing and AiTM phishing capabilities being integrated into unified phishing platforms. ",{"data":3912,"content":3913,"nodeType":3708},{},[3914,3937,3976,3999,4022],{"data":3915,"content":3916,"nodeType":3470},{},[3917,3927],{"data":3918,"content":3919,"nodeType":3459},{},[3920],{"data":3921,"content":3922,"nodeType":673},{},[3923],{"data":3924,"marks":3925,"value":3458,"nodeType":543},{},[3926],{"type":749},{"data":3928,"content":3929,"nodeType":3459},{},[3930],{"data":3931,"content":3932,"nodeType":673},{},[3933],{"data":3934,"marks":3935,"value":3936,"nodeType":543},{},[],"API on api.duemineral.uk:8443 and api.loadingdocuments.uk:8443 (rotates). ",{"data":3938,"content":3939,"nodeType":3470},{},[3940,3950],{"data":3941,"content":3942,"nodeType":3459},{},[3943],{"data":3944,"content":3945,"nodeType":673},{},[3946],{"data":3947,"marks":3948,"value":3484,"nodeType":543},{},[3949],{"type":749},{"data":3951,"content":3952,"nodeType":3459},{},[3953,3965],{"data":3954,"content":3955,"nodeType":673},{},[3956,3961],{"data":3957,"marks":3958,"value":3960,"nodeType":543},{},[3959],{"type":749},"Example IP: ",{"data":3962,"marks":3963,"value":3964,"nodeType":543},{},[],"162.243.166.119 (DigitalOcean AS14061)",{"data":3966,"content":3967,"nodeType":673},{},[3968,3972],{"data":3969,"marks":3970,"value":3525,"nodeType":543},{},[3971],{"type":749},{"data":3973,"marks":3974,"value":3975,"nodeType":543},{},[]," python-requests/2.32.5",{"data":3977,"content":3978,"nodeType":3470},{},[3979,3989],{"data":3980,"content":3981,"nodeType":3459},{},[3982],{"data":3983,"content":3984,"nodeType":673},{},[3985],{"data":3986,"marks":3987,"value":3568,"nodeType":543},{},[3988],{"type":749},{"data":3990,"content":3991,"nodeType":3459},{},[3992],{"data":3993,"content":3994,"nodeType":673},{},[3995],{"data":3996,"marks":3997,"value":3998,"nodeType":543},{},[],"GET /api/status/{numeric_SID} (port :8443)",{"data":4000,"content":4001,"nodeType":3470},{},[4002,4012],{"data":4003,"content":4004,"nodeType":3459},{},[4005],{"data":4006,"content":4007,"nodeType":673},{},[4008],{"data":4009,"marks":4010,"value":3620,"nodeType":543},{},[4011],{"type":749},{"data":4013,"content":4014,"nodeType":3459},{},[4015],{"data":4016,"content":4017,"nodeType":673},{},[4018],{"data":4019,"marks":4020,"value":4021,"nodeType":543},{},[],"SharePoint \"Team Site\" doc library, SharePoint \"Shared Document\" individual share",{"data":4023,"content":4024,"nodeType":3470},{},[4025,4035],{"data":4026,"content":4027,"nodeType":3459},{},[4028],{"data":4029,"content":4030,"nodeType":673},{},[4031],{"data":4032,"marks":4033,"value":3844,"nodeType":543},{},[4034],{"type":749},{"data":4036,"content":4037,"nodeType":3459},{},[4038],{"data":4039,"content":4040,"nodeType":673},{},[4041],{"data":4042,"marks":4043,"value":4044,"nodeType":543},{},[],"auth[.]duemineral[.]uk",{"data":4046,"content":4050,"nodeType":787},{"target":4047},{"sys":4048},{"id":4049,"type":792,"linkType":793},"Y1AiT3dJRTXz64pb68kca",[],{"data":4052,"content":4053,"nodeType":796},{},[],{"data":4055,"content":4056,"nodeType":829},{},[4057],{"data":4058,"marks":4059,"value":4061,"nodeType":543},{},[4060],{"type":749},"“LINKID”",{"data":4063,"content":4064,"nodeType":3708},{},[4065,4088,4133,4163,4186],{"data":4066,"content":4067,"nodeType":3470},{},[4068,4078],{"data":4069,"content":4070,"nodeType":3459},{},[4071],{"data":4072,"content":4073,"nodeType":673},{},[4074],{"data":4075,"marks":4076,"value":3458,"nodeType":543},{},[4077],{"type":749},{"data":4079,"content":4080,"nodeType":3459},{},[4081],{"data":4082,"content":4083,"nodeType":673},{},[4084],{"data":4085,"marks":4086,"value":4087,"nodeType":543},{},[],"Adobe variant has Cloudflare challenge-platform iframe (CF-protected origin). Relative API paths — self-hosted.",{"data":4089,"content":4090,"nodeType":3470},{},[4091,4101],{"data":4092,"content":4093,"nodeType":3459},{},[4094],{"data":4095,"content":4096,"nodeType":673},{},[4097],{"data":4098,"marks":4099,"value":3484,"nodeType":543},{},[4100],{"type":749},{"data":4102,"content":4103,"nodeType":3459},{},[4104,4115,4122],{"data":4105,"content":4106,"nodeType":673},{},[4107,4111],{"data":4108,"marks":4109,"value":3960,"nodeType":543},{},[4110],{"type":749},{"data":4112,"marks":4113,"value":4114,"nodeType":543},{},[],"185.176.220.22 (2cloud.eu AS39845)",{"data":4116,"content":4117,"nodeType":673},{},[4118],{"data":4119,"marks":4120,"value":4121,"nodeType":543},{},[],"2600:1f10:470d:9a00:1437:ec30:be61:3494 (AWS AS16509)",{"data":4123,"content":4124,"nodeType":673},{},[4125,4129],{"data":4126,"marks":4127,"value":3525,"nodeType":543},{},[4128],{"type":749},{"data":4130,"marks":4131,"value":4132,"nodeType":543},{},[]," axios/1.10.0 , axios/1.13.6",{"data":4134,"content":4135,"nodeType":3470},{},[4136,4146],{"data":4137,"content":4138,"nodeType":3459},{},[4139],{"data":4140,"content":4141,"nodeType":673},{},[4142],{"data":4143,"marks":4144,"value":3568,"nodeType":543},{},[4145],{"type":749},{"data":4147,"content":4148,"nodeType":3459},{},[4149,4156],{"data":4150,"content":4151,"nodeType":673},{},[4152],{"data":4153,"marks":4154,"value":4155,"nodeType":543},{},[],"POST /api/device/start",{"data":4157,"content":4158,"nodeType":673},{},[4159],{"data":4160,"marks":4161,"value":4162,"nodeType":543},{},[],"GET /api/device/status/{sessionId}",{"data":4164,"content":4165,"nodeType":3470},{},[4166,4176],{"data":4167,"content":4168,"nodeType":3459},{},[4169],{"data":4170,"content":4171,"nodeType":673},{},[4172],{"data":4173,"marks":4174,"value":3620,"nodeType":543},{},[4175],{"type":749},{"data":4177,"content":4178,"nodeType":3459},{},[4179],{"data":4180,"content":4181,"nodeType":673},{},[4182],{"data":4183,"marks":4184,"value":4185,"nodeType":543},{},[],"MS Teams meeting invitation (with interactive date/time picker), Adobe Acrobat Sign document review",{"data":4187,"content":4188,"nodeType":3470},{},[4189,4199],{"data":4190,"content":4191,"nodeType":3459},{},[4192],{"data":4193,"content":4194,"nodeType":673},{},[4195],{"data":4196,"marks":4197,"value":3844,"nodeType":543},{},[4198],{"type":749},{"data":4200,"content":4201,"nodeType":3459},{},[4202],{"data":4203,"content":4204,"nodeType":673},{},[4205],{"data":4206,"marks":4207,"value":4208,"nodeType":543},{},[],"sdtr-site[.]cfd",{"data":4210,"content":4214,"nodeType":787},{"target":4211},{"sys":4212},{"id":4213,"type":792,"linkType":793},"22hsIzlkptC2JTIUtbOuUn",[],{"data":4216,"content":4217,"nodeType":796},{},[],{"data":4219,"content":4220,"nodeType":829},{},[4221],{"data":4222,"marks":4223,"value":4225,"nodeType":543},{},[4224],{"type":749},"Device Code Lab (formerly codename \"AUTHOV”)",{"data":4227,"content":4231,"nodeType":787},{"target":4228},{"sys":4229},{"id":4230,"type":792,"linkType":793},"5vllVaa0Ry0wKs46ssrZLC",[],{"data":4233,"content":4234,"nodeType":3708},{},[4235,4258,4304,4327,4350],{"data":4236,"content":4237,"nodeType":3470},{},[4238,4248],{"data":4239,"content":4240,"nodeType":3459},{},[4241],{"data":4242,"content":4243,"nodeType":673},{},[4244],{"data":4245,"marks":4246,"value":3458,"nodeType":543},{},[4247],{"type":749},{"data":4249,"content":4250,"nodeType":3459},{},[4251],{"data":4252,"content":4253,"nodeType":673},{},[4254],{"data":4255,"marks":4256,"value":4257,"nodeType":543},{},[],"workers.dev",{"data":4259,"content":4260,"nodeType":3470},{},[4261,4271],{"data":4262,"content":4263,"nodeType":3459},{},[4264],{"data":4265,"content":4266,"nodeType":673},{},[4267],{"data":4268,"marks":4269,"value":3484,"nodeType":543},{},[4270],{"type":749},{"data":4272,"content":4273,"nodeType":3459},{},[4274,4285],{"data":4275,"content":4276,"nodeType":673},{},[4277,4281],{"data":4278,"marks":4279,"value":3960,"nodeType":543},{},[4280],{"type":749},{"data":4282,"marks":4283,"value":4284,"nodeType":543},{},[],"192.3.225.100 (HostPapa / ColoCrossing AS36352)",{"data":4286,"content":4287,"nodeType":673},{},[4288,4292,4295,4300],{"data":4289,"marks":4290,"value":3525,"nodeType":543},{},[4291],{"type":749},{"data":4293,"marks":4294,"value":3529,"nodeType":543},{},[],{"data":4296,"marks":4297,"value":4299,"nodeType":543},{},[4298],{"type":749}," ",{"data":4301,"marks":4302,"value":4303,"nodeType":543},{},[],"python-httpx/0.28.1",{"data":4305,"content":4306,"nodeType":3470},{},[4307,4317],{"data":4308,"content":4309,"nodeType":3459},{},[4310],{"data":4311,"content":4312,"nodeType":673},{},[4313],{"data":4314,"marks":4315,"value":3568,"nodeType":543},{},[4316],{"type":749},{"data":4318,"content":4319,"nodeType":3459},{},[4320],{"data":4321,"content":4322,"nodeType":673},{},[4323],{"data":4324,"marks":4325,"value":4326,"nodeType":543},{},[],"GET /landing/api/session-status?session_id=&token=",{"data":4328,"content":4329,"nodeType":3470},{},[4330,4340],{"data":4331,"content":4332,"nodeType":3459},{},[4333],{"data":4334,"content":4335,"nodeType":673},{},[4336],{"data":4337,"marks":4338,"value":3620,"nodeType":543},{},[4339],{"type":749},{"data":4341,"content":4342,"nodeType":3459},{},[4343],{"data":4344,"content":4345,"nodeType":673},{},[4346],{"data":4347,"marks":4348,"value":4349,"nodeType":543},{},[],"Adobe Acrobat document sharing (PDF preview, sender avatar)",{"data":4351,"content":4352,"nodeType":3470},{},[4353,4363],{"data":4354,"content":4355,"nodeType":3459},{},[4356],{"data":4357,"content":4358,"nodeType":673},{},[4359],{"data":4360,"marks":4361,"value":3844,"nodeType":543},{},[4362],{"type":749},{"data":4364,"content":4365,"nodeType":3459},{},[4366],{"data":4367,"content":4368,"nodeType":673},{},[4369],{"data":4370,"marks":4371,"value":4372,"nodeType":543},{},[],"milosh-solibella-0dcio[.]sgttommy.workers.dev",{"data":4374,"content":4378,"nodeType":787},{"target":4375},{"sys":4376},{"id":4377,"type":792,"linkType":793},"6szO6IKJ32usyxIKX1efZy",[],{"data":4380,"content":4384,"nodeType":787},{"target":4381},{"sys":4382},{"id":4383,"type":792,"linkType":793},"lEqV3RTMIY8y011lnhX7P",[],{"data":4386,"content":4387,"nodeType":796},{},[],{"data":4389,"content":4390,"nodeType":829},{},[4391],{"data":4392,"marks":4393,"value":4395,"nodeType":543},{},[4394],{"type":749},"“DOCUPOLL”",{"data":4397,"content":4398,"nodeType":3708},{},[4399,4422,4460,4497,4520],{"data":4400,"content":4401,"nodeType":3470},{},[4402,4412],{"data":4403,"content":4404,"nodeType":3459},{},[4405],{"data":4406,"content":4407,"nodeType":673},{},[4408],{"data":4409,"marks":4410,"value":3458,"nodeType":543},{},[4411],{"type":749},{"data":4413,"content":4414,"nodeType":3459},{},[4415],{"data":4416,"content":4417,"nodeType":673},{},[4418],{"data":4419,"marks":4420,"value":4421,"nodeType":543},{},[],"Github.io and workers.dev hosting",{"data":4423,"content":4424,"nodeType":3470},{},[4425,4435],{"data":4426,"content":4427,"nodeType":3459},{},[4428],{"data":4429,"content":4430,"nodeType":673},{},[4431],{"data":4432,"marks":4433,"value":3484,"nodeType":543},{},[4434],{"type":749},{"data":4436,"content":4437,"nodeType":3459},{},[4438,4449],{"data":4439,"content":4440,"nodeType":673},{},[4441,4445],{"data":4442,"marks":4443,"value":3960,"nodeType":543},{},[4444],{"type":749},{"data":4446,"marks":4447,"value":4448,"nodeType":543},{},[],"144.172.103.240 (FranTech Solutions / RouterHosting / Cloudzy AS14956)",{"data":4450,"content":4451,"nodeType":673},{},[4452,4456],{"data":4453,"marks":4454,"value":3525,"nodeType":543},{},[4455],{"type":749},{"data":4457,"marks":4458,"value":4459,"nodeType":543},{},[]," Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.102 Safari/537.36 Edge/18.19042",{"data":4461,"content":4462,"nodeType":3470},{},[4463,4473],{"data":4464,"content":4465,"nodeType":3459},{},[4466],{"data":4467,"content":4468,"nodeType":673},{},[4469],{"data":4470,"marks":4471,"value":3568,"nodeType":543},{},[4472],{"type":749},{"data":4474,"content":4475,"nodeType":3459},{},[4476,4483,4490],{"data":4477,"content":4478,"nodeType":673},{},[4479],{"data":4480,"marks":4481,"value":4482,"nodeType":543},{},[],"POST /api/v1/landing-pages/public/{slug}/init",{"data":4484,"content":4485,"nodeType":673},{},[4486],{"data":4487,"marks":4488,"value":4489,"nodeType":543},{},[],"POST .../poll",{"data":4491,"content":4492,"nodeType":673},{},[4493],{"data":4494,"marks":4495,"value":4496,"nodeType":543},{},[],"POST .../track",{"data":4498,"content":4499,"nodeType":3470},{},[4500,4510],{"data":4501,"content":4502,"nodeType":3459},{},[4503],{"data":4504,"content":4505,"nodeType":673},{},[4506],{"data":4507,"marks":4508,"value":3620,"nodeType":543},{},[4509],{"type":749},{"data":4511,"content":4512,"nodeType":3459},{},[4513],{"data":4514,"content":4515,"nodeType":673},{},[4516],{"data":4517,"marks":4518,"value":4519,"nodeType":543},{},[],"DocuSign document signing. One sample is a full scrape of real docusign.com (free-account page) with kit injected.",{"data":4521,"content":4522,"nodeType":3470},{},[4523,4533],{"data":4524,"content":4525,"nodeType":3459},{},[4526],{"data":4527,"content":4528,"nodeType":673},{},[4529],{"data":4530,"marks":4531,"value":3844,"nodeType":543},{},[4532],{"type":749},{"data":4534,"content":4535,"nodeType":3459},{},[4536],{"data":4537,"content":4538,"nodeType":673},{},[4539],{"data":4540,"marks":4541,"value":4542,"nodeType":543},{},[],"docufirmar[.]github.io",{"data":4544,"content":4548,"nodeType":787},{"target":4545},{"sys":4546},{"id":4547,"type":792,"linkType":793},"6Y1XABHnQD82R3MW80HnQZ",[],{"data":4550,"content":4551,"nodeType":796},{},[],{"data":4553,"content":4554,"nodeType":829},{},[4555],{"data":4556,"marks":4557,"value":4559,"nodeType":543},{},[4558],{"type":749},"“FLOW_TOKEN”",{"data":4561,"content":4562,"nodeType":3708},{},[4563,4585,4630,4660,4683],{"data":4564,"content":4565,"nodeType":3470},{},[4566,4576],{"data":4567,"content":4568,"nodeType":3459},{},[4569],{"data":4570,"content":4571,"nodeType":673},{},[4572],{"data":4573,"marks":4574,"value":3458,"nodeType":543},{},[4575],{"type":749},{"data":4577,"content":4578,"nodeType":3459},{},[4579],{"data":4580,"content":4581,"nodeType":673},{},[4582],{"data":4583,"marks":4584,"value":4257,"nodeType":543},{},[],{"data":4586,"content":4587,"nodeType":3470},{},[4588,4598],{"data":4589,"content":4590,"nodeType":3459},{},[4591],{"data":4592,"content":4593,"nodeType":673},{},[4594],{"data":4595,"marks":4596,"value":3484,"nodeType":543},{},[4597],{"type":749},{"data":4599,"content":4600,"nodeType":3459},{},[4601,4612],{"data":4602,"content":4603,"nodeType":673},{},[4604,4608],{"data":4605,"marks":4606,"value":3960,"nodeType":543},{},[4607],{"type":749},{"data":4609,"marks":4610,"value":4611,"nodeType":543},{},[],"43.166.163.163 (Tencent Cloud AS132203)",{"data":4613,"content":4614,"nodeType":673},{},[4615,4619,4622,4626],{"data":4616,"marks":4617,"value":3525,"nodeType":543},{},[4618],{"type":749},{"data":4620,"marks":4621,"value":3529,"nodeType":543},{},[],{"data":4623,"marks":4624,"value":4299,"nodeType":543},{},[4625],{"type":749},{"data":4627,"marks":4628,"value":4629,"nodeType":543},{},[],"(null)",{"data":4631,"content":4632,"nodeType":3470},{},[4633,4643],{"data":4634,"content":4635,"nodeType":3459},{},[4636],{"data":4637,"content":4638,"nodeType":673},{},[4639],{"data":4640,"marks":4641,"value":3568,"nodeType":543},{},[4642],{"type":749},{"data":4644,"content":4645,"nodeType":3459},{},[4646,4653],{"data":4647,"content":4648,"nodeType":673},{},[4649],{"data":4650,"marks":4651,"value":4652,"nodeType":543},{},[],"POST /api/handler.php ",{"data":4654,"content":4655,"nodeType":673},{},[4656],{"data":4657,"marks":4658,"value":4659,"nodeType":543},{},[],"(actions: device_code_generate, device_code_poll_public)",{"data":4661,"content":4662,"nodeType":3470},{},[4663,4673],{"data":4664,"content":4665,"nodeType":3459},{},[4666],{"data":4667,"content":4668,"nodeType":673},{},[4669],{"data":4670,"marks":4671,"value":3620,"nodeType":543},{},[4672],{"type":749},{"data":4674,"content":4675,"nodeType":3459},{},[4676],{"data":4677,"content":4678,"nodeType":673},{},[4679],{"data":4680,"marks":4681,"value":4682,"nodeType":543},{},[],"DocuSign \"Salary Adjustment Document — 2026\", Microsoft banner · HR Department sender",{"data":4684,"content":4685,"nodeType":3470},{},[4686,4696],{"data":4687,"content":4688,"nodeType":3459},{},[4689],{"data":4690,"content":4691,"nodeType":673},{},[4692],{"data":4693,"marks":4694,"value":3844,"nodeType":543},{},[4695],{"type":749},{"data":4697,"content":4698,"nodeType":3459},{},[4699],{"data":4700,"content":4701,"nodeType":673},{},[4702],{"data":4703,"marks":4704,"value":4705,"nodeType":543},{},[],"salaryadjustment-2afb52.pmb6fefc52b3f9aa5c2dbf[.]workers.dev",{"data":4707,"content":4711,"nodeType":787},{"target":4708},{"sys":4709},{"id":4710,"type":792,"linkType":793},"6xiTDHStbiJh7LMhjAZcPd",[],{"data":4713,"content":4714,"nodeType":796},{},[],{"data":4716,"content":4717,"nodeType":829},{},[4718],{"data":4719,"marks":4720,"value":4722,"nodeType":543},{},[4721],{"type":749},"“PAPRIKA”",{"data":4724,"content":4725,"nodeType":3708},{},[4726,4749,4772,4795],{"data":4727,"content":4728,"nodeType":3470},{},[4729,4739],{"data":4730,"content":4731,"nodeType":3459},{},[4732],{"data":4733,"content":4734,"nodeType":673},{},[4735],{"data":4736,"marks":4737,"value":3458,"nodeType":543},{},[4738],{"type":749},{"data":4740,"content":4741,"nodeType":3459},{},[4742],{"data":4743,"content":4744,"nodeType":673},{},[4745],{"data":4746,"marks":4747,"value":4748,"nodeType":543},{},[],"AWS S3 hosting",{"data":4750,"content":4751,"nodeType":3470},{},[4752,4762],{"data":4753,"content":4754,"nodeType":3459},{},[4755],{"data":4756,"content":4757,"nodeType":673},{},[4758],{"data":4759,"marks":4760,"value":3568,"nodeType":543},{},[4761],{"type":749},{"data":4763,"content":4764,"nodeType":3459},{},[4765],{"data":4766,"content":4767,"nodeType":673},{},[4768],{"data":4769,"marks":4770,"value":4771,"nodeType":543},{},[],"POST /api/v1/loader",{"data":4773,"content":4774,"nodeType":3470},{},[4775,4785],{"data":4776,"content":4777,"nodeType":3459},{},[4778],{"data":4779,"content":4780,"nodeType":673},{},[4781],{"data":4782,"marks":4783,"value":3620,"nodeType":543},{},[4784],{"type":749},{"data":4786,"content":4787,"nodeType":3459},{},[4788],{"data":4789,"content":4790,"nodeType":673},{},[4791],{"data":4792,"marks":4793,"value":4794,"nodeType":543},{},[],"MS login clone (\"Sign in to your account\"), \"Office 365\" branding, fake \"Powered by Okta\" footer",{"data":4796,"content":4797,"nodeType":3470},{},[4798,4808],{"data":4799,"content":4800,"nodeType":3459},{},[4801],{"data":4802,"content":4803,"nodeType":673},{},[4804],{"data":4805,"marks":4806,"value":3844,"nodeType":543},{},[4807],{"type":749},{"data":4809,"content":4810,"nodeType":3459},{},[4811],{"data":4812,"content":4813,"nodeType":673},{},[4814],{"data":4815,"marks":4816,"value":4817,"nodeType":543},{},[],"redirect-523346-d95027ec[.]s3.amazonaws.com",{"data":4819,"content":4823,"nodeType":787},{"target":4820},{"sys":4821},{"id":4822,"type":792,"linkType":793},"6WFXqUDzcJHKWSwVIcDZAf",[],{"data":4825,"content":4826,"nodeType":796},{},[],{"data":4828,"content":4829,"nodeType":829},{},[4830],{"data":4831,"marks":4832,"value":4834,"nodeType":543},{},[4833],{"type":749},"“DCSTATUS”",{"data":4836,"content":4837,"nodeType":3708},{},[4838,4860,4883,4906],{"data":4839,"content":4840,"nodeType":3470},{},[4841,4851],{"data":4842,"content":4843,"nodeType":3459},{},[4844],{"data":4845,"content":4846,"nodeType":673},{},[4847],{"data":4848,"marks":4849,"value":3458,"nodeType":543},{},[4850],{"type":749},{"data":4852,"content":4853,"nodeType":3459},{},[4854],{"data":4855,"content":4856,"nodeType":673},{},[4857],{"data":4858,"marks":4859,"value":3745,"nodeType":543},{},[],{"data":4861,"content":4862,"nodeType":3470},{},[4863,4873],{"data":4864,"content":4865,"nodeType":3459},{},[4866],{"data":4867,"content":4868,"nodeType":673},{},[4869],{"data":4870,"marks":4871,"value":3568,"nodeType":543},{},[4872],{"type":749},{"data":4874,"content":4875,"nodeType":3459},{},[4876],{"data":4877,"content":4878,"nodeType":673},{},[4879],{"data":4880,"marks":4881,"value":4882,"nodeType":543},{},[],"GET /dc/status/{base64url_sid}",{"data":4884,"content":4885,"nodeType":3470},{},[4886,4896],{"data":4887,"content":4888,"nodeType":3459},{},[4889],{"data":4890,"content":4891,"nodeType":673},{},[4892],{"data":4893,"marks":4894,"value":3620,"nodeType":543},{},[4895],{"type":749},{"data":4897,"content":4898,"nodeType":3459},{},[4899],{"data":4900,"content":4901,"nodeType":673},{},[4902],{"data":4903,"marks":4904,"value":4905,"nodeType":543},{},[],"Generic \"Microsoft 365 - Secure Access\" verification page",{"data":4907,"content":4908,"nodeType":3470},{},[4909,4919],{"data":4910,"content":4911,"nodeType":3459},{},[4912],{"data":4913,"content":4914,"nodeType":673},{},[4915],{"data":4916,"marks":4917,"value":3844,"nodeType":543},{},[4918],{"type":749},{"data":4920,"content":4921,"nodeType":3459},{},[4922],{"data":4923,"content":4924,"nodeType":673},{},[4925],{"data":4926,"marks":4927,"value":4928,"nodeType":543},{},[],"owa[.]apmmacleans[.]ca",{"data":4930,"content":4934,"nodeType":787},{"target":4931},{"sys":4932},{"id":4933,"type":792,"linkType":793},"ugYhHeXY1lQdKooALmrIs",[],{"data":4936,"content":4937,"nodeType":796},{},[],{"data":4939,"content":4940,"nodeType":829},{},[4941],{"data":4942,"marks":4943,"value":4945,"nodeType":543},{},[4944],{"type":749},"“DOLCE”",{"data":4947,"content":4951,"nodeType":787},{"target":4948},{"sys":4949},{"id":4950,"type":792,"linkType":793},"7TzU6kk01Un45NB0buEz2",[],{"data":4953,"content":4954,"nodeType":3708},{},[4955,4978,5016,5039,5062],{"data":4956,"content":4957,"nodeType":3470},{},[4958,4968],{"data":4959,"content":4960,"nodeType":3459},{},[4961],{"data":4962,"content":4963,"nodeType":673},{},[4964],{"data":4965,"marks":4966,"value":3458,"nodeType":543},{},[4967],{"type":749},{"data":4969,"content":4970,"nodeType":3459},{},[4971],{"data":4972,"content":4973,"nodeType":673},{},[4974],{"data":4975,"marks":4976,"value":4977,"nodeType":543},{},[],"Microsoft PowerApps hosting",{"data":4979,"content":4980,"nodeType":3470},{},[4981,4991],{"data":4982,"content":4983,"nodeType":3459},{},[4984],{"data":4985,"content":4986,"nodeType":673},{},[4987],{"data":4988,"marks":4989,"value":3484,"nodeType":543},{},[4990],{"type":749},{"data":4992,"content":4993,"nodeType":3459},{},[4994,5005],{"data":4995,"content":4996,"nodeType":673},{},[4997,5001],{"data":4998,"marks":4999,"value":3960,"nodeType":543},{},[5000],{"type":749},{"data":5002,"marks":5003,"value":5004,"nodeType":543},{},[],"34.53.159.84 (Google Cloud AS396982)",{"data":5006,"content":5007,"nodeType":673},{},[5008,5012],{"data":5009,"marks":5010,"value":3525,"nodeType":543},{},[5011],{"type":749},{"data":5013,"marks":5014,"value":5015,"nodeType":543},{},[]," Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/123.0.0.0 Safari/537.36",{"data":5017,"content":5018,"nodeType":3470},{},[5019,5029],{"data":5020,"content":5021,"nodeType":3459},{},[5022],{"data":5023,"content":5024,"nodeType":673},{},[5025],{"data":5026,"marks":5027,"value":3568,"nodeType":543},{},[5028],{"type":749},{"data":5030,"content":5031,"nodeType":3459},{},[5032],{"data":5033,"content":5034,"nodeType":673},{},[5035],{"data":5036,"marks":5037,"value":5038,"nodeType":543},{},[],"GET /api/generatecode (CloudFront)",{"data":5040,"content":5041,"nodeType":3470},{},[5042,5052],{"data":5043,"content":5044,"nodeType":3459},{},[5045],{"data":5046,"content":5047,"nodeType":673},{},[5048],{"data":5049,"marks":5050,"value":3620,"nodeType":543},{},[5051],{"type":749},{"data":5053,"content":5054,"nodeType":3459},{},[5055],{"data":5056,"content":5057,"nodeType":673},{},[5058],{"data":5059,"marks":5060,"value":5061,"nodeType":543},{},[],"Dolce & Gabbana branded, Italian language, MS account verification",{"data":5063,"content":5064,"nodeType":3470},{},[5065,5075],{"data":5066,"content":5067,"nodeType":3459},{},[5068],{"data":5069,"content":5070,"nodeType":673},{},[5071],{"data":5072,"marks":5073,"value":3844,"nodeType":543},{},[5074],{"type":749},{"data":5076,"content":5077,"nodeType":3459},{},[5078],{"data":5079,"content":5080,"nodeType":673},{},[5081],{"data":5082,"marks":5083,"value":5084,"nodeType":543},{},[],"data-migration-dolcegabbana[.]powerappsportals.com",{"data":5086,"content":5090,"nodeType":787},{"target":5087},{"sys":5088},{"id":5089,"type":792,"linkType":793},"4ayQDvpf5NNOBrj9wZZRiO",[],{"data":5092,"content":5093,"nodeType":796},{},[],{"data":5095,"content":5096,"nodeType":829},{},[5097],{"data":5098,"marks":5099,"value":5101,"nodeType":543},{},[5100],{"type":749},"Venom",{"data":5103,"content":5104,"nodeType":3708},{},[5105,5128],{"data":5106,"content":5107,"nodeType":3470},{},[5108,5118],{"data":5109,"content":5110,"nodeType":3459},{},[5111],{"data":5112,"content":5113,"nodeType":673},{},[5114],{"data":5115,"marks":5116,"value":3568,"nodeType":543},{},[5117],{"type":749},{"data":5119,"content":5120,"nodeType":3459},{},[5121],{"data":5122,"content":5123,"nodeType":673},{},[5124],{"data":5125,"marks":5126,"value":5127,"nodeType":543},{},[],"POST /token/api/device/start\nGET /token/api/device/status/{sessionId}",{"data":5129,"content":5130,"nodeType":3470},{},[5131,5141],{"data":5132,"content":5133,"nodeType":3459},{},[5134],{"data":5135,"content":5136,"nodeType":673},{},[5137],{"data":5138,"marks":5139,"value":3620,"nodeType":543},{},[5140],{"type":749},{"data":5142,"content":5143,"nodeType":3459},{},[5144],{"data":5145,"content":5146,"nodeType":673},{},[5147],{"data":5148,"marks":5149,"value":5150,"nodeType":543},{},[],"Various: examples include DocuSign \"Verification\" (Microsoft sign-in pretext); DHL \"Delivery Checkpoint\" package shipment pretext",{"data":5152,"content":5156,"nodeType":787},{"target":5153},{"sys":5154},{"id":5155,"type":792,"linkType":793},"79C3fces0hgTdf3G68cIrf",[],{"data":5158,"content":5159,"nodeType":796},{},[],{"data":5161,"content":5162,"nodeType":829},{},[5163],{"data":5164,"marks":5165,"value":5167,"nodeType":543},{},[5166],{"type":749},"Tycoon2FA",{"data":5169,"content":5170,"nodeType":3708},{},[5171,5201,5238,5261,5284],{"data":5172,"content":5173,"nodeType":3470},{},[5174,5184],{"data":5175,"content":5176,"nodeType":3459},{},[5177],{"data":5178,"content":5179,"nodeType":673},{},[5180],{"data":5181,"marks":5182,"value":3458,"nodeType":543},{},[5183],{"type":749},{"data":5185,"content":5186,"nodeType":3459},{},[5187,5194],{"data":5188,"content":5189,"nodeType":673},{},[5190],{"data":5191,"marks":5192,"value":5193,"nodeType":543},{},[],"Github.io and Cloudflare Workers (workers.dev) hosting",{"data":5195,"content":5196,"nodeType":673},{},[5197],{"data":5198,"marks":5199,"value":5200,"nodeType":543},{},[],"Compromised-site landing pages and CF Workers (*.workers.dev) used as frontends; victim email passed in URL as last path segment ($base64) or ?acct/?encoded query",{"data":5202,"content":5203,"nodeType":3470},{},[5204,5214],{"data":5205,"content":5206,"nodeType":3459},{},[5207],{"data":5208,"content":5209,"nodeType":673},{},[5210],{"data":5211,"marks":5212,"value":3484,"nodeType":543},{},[5213],{"type":749},{"data":5215,"content":5216,"nodeType":3459},{},[5217,5228],{"data":5218,"content":5219,"nodeType":673},{},[5220,5224],{"data":5221,"marks":5222,"value":3960,"nodeType":543},{},[5223],{"type":749},{"data":5225,"marks":5226,"value":5227,"nodeType":543},{},[],"47.253.5.88 (Alibaba Cloud)",{"data":5229,"content":5230,"nodeType":673},{},[5231,5235],{"data":5232,"marks":5233,"value":3525,"nodeType":543},{},[5234],{"type":749},{"data":5236,"marks":5237,"value":3784,"nodeType":543},{},[],{"data":5239,"content":5240,"nodeType":3470},{},[5241,5251],{"data":5242,"content":5243,"nodeType":3459},{},[5244],{"data":5245,"content":5246,"nodeType":673},{},[5247],{"data":5248,"marks":5249,"value":3568,"nodeType":543},{},[5250],{"type":749},{"data":5252,"content":5253,"nodeType":3459},{},[5254],{"data":5255,"content":5256,"nodeType":673},{},[5257],{"data":5258,"marks":5259,"value":5260,"nodeType":543},{},[],"GET /api/session/{UUIDv4} polled with header X-API-Key: \u003Cprefix>_\u003C64-hex> (key materialised at runtime via atob(window.__cyb3r.k)) \nPOST /api/device-code with body {\"prt_foci_session_id\": \"\u003CUUID>\"} (second-stage code retrieval after initial session error)",{"data":5262,"content":5263,"nodeType":3470},{},[5264,5274],{"data":5265,"content":5266,"nodeType":3459},{},[5267],{"data":5268,"content":5269,"nodeType":673},{},[5270],{"data":5271,"marks":5272,"value":3620,"nodeType":543},{},[5273],{"type":749},{"data":5275,"content":5276,"nodeType":3459},{},[5277],{"data":5278,"content":5279,"nodeType":673},{},[5280],{"data":5281,"marks":5282,"value":5283,"nodeType":543},{},[],"Various: SharePoint \"Remittance Advice\"; Microsoft 365 generic sign-in; Microsoft 365 Voicemail (.mp3 attachment); OneDrive \"Shared file\"; German \"Sicheres Dokumentenportal\" PDF lure",{"data":5285,"content":5286,"nodeType":3470},{},[5287,5297],{"data":5288,"content":5289,"nodeType":3459},{},[5290],{"data":5291,"content":5292,"nodeType":673},{},[5293],{"data":5294,"marks":5295,"value":3844,"nodeType":543},{},[5296],{"type":749},{"data":5298,"content":5299,"nodeType":3459},{},[5300],{"data":5301,"content":5302,"nodeType":673},{},[5303],{"data":5304,"marks":5305,"value":5306,"nodeType":543},{},[],"afriqbeauglobal[.]com/homepage/index[.]html",{"data":5308,"content":5311,"nodeType":787},{"target":5309},{"sys":5310},{"id":2123,"type":792,"linkType":793},[],{"data":5313,"content":5314,"nodeType":796},{},[],{"data":5316,"content":5317,"nodeType":829},{},[5318],{"data":5319,"marks":5320,"value":5322,"nodeType":543},{},[5321],{"type":749},"\"CYB3R\"",{"data":5324,"content":5325,"nodeType":3708},{},[5326,5349,5387,5409,5432],{"data":5327,"content":5328,"nodeType":3470},{},[5329,5339],{"data":5330,"content":5331,"nodeType":3459},{},[5332],{"data":5333,"content":5334,"nodeType":673},{},[5335],{"data":5336,"marks":5337,"value":3458,"nodeType":543},{},[5338],{"type":749},{"data":5340,"content":5341,"nodeType":3459},{},[5342],{"data":5343,"content":5344,"nodeType":673},{},[5345],{"data":5346,"marks":5347,"value":5348,"nodeType":543},{},[],"Cloudflare Workers (workers.dev) hosting",{"data":5350,"content":5351,"nodeType":3470},{},[5352,5362],{"data":5353,"content":5354,"nodeType":3459},{},[5355],{"data":5356,"content":5357,"nodeType":673},{},[5358],{"data":5359,"marks":5360,"value":3484,"nodeType":543},{},[5361],{"type":749},{"data":5363,"content":5364,"nodeType":3459},{},[5365,5376],{"data":5366,"content":5367,"nodeType":673},{},[5368,5372],{"data":5369,"marks":5370,"value":3960,"nodeType":543},{},[5371],{"type":749},{"data":5373,"marks":5374,"value":5375,"nodeType":543},{},[],"2400:8d60:2::1:c116:843e (Evoxt VPS)",{"data":5377,"content":5378,"nodeType":673},{},[5379,5383],{"data":5380,"marks":5381,"value":3525,"nodeType":543},{},[5382],{"type":749},{"data":5384,"marks":5385,"value":5386,"nodeType":543},{},[]," axios/1.13.6",{"data":5388,"content":5389,"nodeType":3470},{},[5390,5400],{"data":5391,"content":5392,"nodeType":3459},{},[5393],{"data":5394,"content":5395,"nodeType":673},{},[5396],{"data":5397,"marks":5398,"value":3568,"nodeType":543},{},[5399],{"type":749},{"data":5401,"content":5402,"nodeType":3459},{},[5403],{"data":5404,"content":5405,"nodeType":673},{},[5406],{"data":5407,"marks":5408,"value":5260,"nodeType":543},{},[],{"data":5410,"content":5411,"nodeType":3470},{},[5412,5422],{"data":5413,"content":5414,"nodeType":3459},{},[5415],{"data":5416,"content":5417,"nodeType":673},{},[5418],{"data":5419,"marks":5420,"value":3620,"nodeType":543},{},[5421],{"type":749},{"data":5423,"content":5424,"nodeType":3459},{},[5425],{"data":5426,"content":5427,"nodeType":673},{},[5428],{"data":5429,"marks":5430,"value":5431,"nodeType":543},{},[],"DocuSign in Spanish (\"Documento Firmar — COTIZACIÓN/ESTIMACIÓN.pdf\", \"Complete su firma\", \"Verifique su identidad\", \"Continuar a Microsoft\").",{"data":5433,"content":5434,"nodeType":3470},{},[5435,5445],{"data":5436,"content":5437,"nodeType":3459},{},[5438],{"data":5439,"content":5440,"nodeType":673},{},[5441],{"data":5442,"marks":5443,"value":3844,"nodeType":543},{},[5444],{"type":749},{"data":5446,"content":5447,"nodeType":3459},{},[5448],{"data":5449,"content":5450,"nodeType":673},{},[5451],{"data":5452,"marks":5453,"value":5454,"nodeType":543},{},[],"muzagestion[.]secure-share[.]workers.dev",{"data":5456,"content":5460,"nodeType":787},{"target":5457},{"sys":5458},{"id":5459,"type":792,"linkType":793},"5EU0QNteiQcYybKG1W1cS3",[],{"data":5462,"content":5463,"nodeType":796},{},[],{"data":5465,"content":5466,"nodeType":800},{},[5467],{"data":5468,"marks":5469,"value":5471,"nodeType":543},{},[5470],{"type":749},"Device code phishing under the hood",{"data":5473,"content":5474,"nodeType":673},{},[5475,5479],{"data":5476,"marks":5477,"value":5478,"nodeType":543},{},[],"The attacker POSTs to the authorization server's device authorization endpoint with its client_id (i.e. an application ID) and requested scopes or resources. The server responds with a device_code (used for polling), a user_code, a verification_uri, an expires_in value, and a polling interval. The user visits the URL, enters the code and approves the request. Meanwhile, the device polls the token endpoint. Once approved, the server returns an access token, a refresh token (if offline_access was requested), and an ID token (if openid was included). ",{"data":5480,"marks":5481,"value":5483,"nodeType":543},{},[5482],{"type":749},"The attacker now has API access to the victim's account. ",{"data":5485,"content":5486,"nodeType":673},{},[5487],{"data":5488,"marks":5489,"value":5490,"nodeType":543},{},[],"Broadly, this gives the attacker a comparable level of control to a “normal” phishing attack (with conditions based on the scopes granted and specific app being targeted) while API access grants additional capabilities beyond standard browser sessions. When combined with other techniques, this access can be exchanged to open normal browser app sessions and access SSO connected apps.",{"data":5492,"content":5496,"nodeType":787},{"target":5493},{"sys":5494},{"id":5495,"type":792,"linkType":793},"4WtQR2xsE236yoyhSXj58Z",[],{"data":5498,"content":5502,"nodeType":787},{"target":5499},{"sys":5500},{"id":5501,"type":792,"linkType":793},"1x7Lip7JdY2xlHKKurT7qJ",[],{"data":5504,"content":5505,"nodeType":673},{},[5506],{"data":5507,"marks":5508,"value":5509,"nodeType":543},{},[],"At this point, you can achieve a number of objectives both inside the app ecosystem and across SSO connected apps — e.g. data theft, disruption, and ultimately extortion.",{"data":5511,"content":5512,"nodeType":673},{},[5513,5517,5522,5526],{"data":5514,"marks":5515,"value":5516,"nodeType":543},{},[],"Critically, the initial request to generate a device code is typically ",{"data":5518,"marks":5519,"value":5521,"nodeType":543},{},[5520],{"type":749},"unauthenticated",{"data":5523,"marks":5524,"value":5525,"nodeType":543},{},[]," across all providers — ",{"data":5527,"marks":5528,"value":5530,"nodeType":543},{},[5529],{"type":749},"anyone can generate one, from any machine, without proving any relationship to the target organization.",{"data":5532,"content":5533,"nodeType":673},{},[5534,5538,5543],{"data":5535,"marks":5536,"value":5537,"nodeType":543},{},[],"So, the attacker has to deliver a set of instructions via a phishing channel (e.g. email, social media DM, corp IM platform, and so on) with a device code that they have generated. The victim then enters this code on the ",{"data":5539,"marks":5540,"value":5542,"nodeType":543},{},[5541],{"type":749},"legitimate device code login page",{"data":5544,"marks":5545,"value":5546,"nodeType":543},{},[]," for that app and issues the tokens to the attacker.",{"data":5548,"content":5552,"nodeType":787},{"target":5549},{"sys":5550},{"id":5551,"type":792,"linkType":793},"1txUYuQjH9FlbDGTo8AbZB",[],{"data":5554,"content":5555,"nodeType":796},{},[],{"data":5557,"content":5558,"nodeType":800},{},[5559],{"data":5560,"marks":5561,"value":5563,"nodeType":543},{},[5562],{"type":749},"Why device code phishing is so dangerous",{"data":5565,"content":5566,"nodeType":829},{},[5567],{"data":5568,"marks":5569,"value":5571,"nodeType":543},{},[5570],{"type":749},"Device code phishing bypasses authentication controls (including passkeys)",{"data":5573,"content":5574,"nodeType":673},{},[5575,5579,5584,5588],{"data":5576,"marks":5577,"value":5578,"nodeType":543},{},[],"A device code phishing attack ",{"data":5580,"marks":5581,"value":5583,"nodeType":543},{},[5582],{"type":749},"cannot be prevented with authentication controls",{"data":5585,"marks":5586,"value":5587,"nodeType":543},{},[],". This includes all forms of MFA and ",{"data":5589,"marks":5590,"value":5592,"nodeType":543},{},[5591],{"type":749},"even “phishing-resistant” authentication methods such as passkeys. ",{"data":5594,"content":5595,"nodeType":673},{},[5596,5601,5605,5610],{"data":5597,"marks":5598,"value":5600,"nodeType":543},{},[5599],{"type":749},"The device code authorization is effectively performed post-authentication. ",{"data":5602,"marks":5603,"value":5604,"nodeType":543},{},[],"If you already have an active session in your browser, entering the device code and selecting your account from a drop-down menu is all that's needed. ",{"data":5606,"marks":5607,"value":5609,"nodeType":543},{},[5608],{"type":749},"No password or MFA required. ",{"data":5611,"marks":5612,"value":5613,"nodeType":543},{},[],"You can see an example in the video below.",{"data":5615,"content":5618,"nodeType":787},{"target":5616},{"sys":5617},{"id":4547,"type":792,"linkType":793},[],{"data":5620,"content":5621,"nodeType":673},{},[5622],{"data":5623,"marks":5624,"value":5625,"nodeType":543},{},[],"Even if you do have to sign in again (because you're not already signed in for some reason), the attack still works because it isn't targeting the login — it's targeting the authorization layer instead.",{"data":5627,"content":5628,"nodeType":673},{},[5629],{"data":5630,"marks":5631,"value":5632,"nodeType":543},{},[],"This is what makes device code phishing different to other standard phishing methods like AiTM phishing (and arguably even more effective in environments with strict identity control enforcement). ",{"data":5634,"content":5635,"nodeType":829},{},[5636],{"data":5637,"marks":5638,"value":5640,"nodeType":543},{},[5639],{"type":749},"Device code logins are a feature, not a vulnerability, making attacks difficult to block",{"data":5642,"content":5643,"nodeType":673},{},[5644],{"data":5645,"marks":5646,"value":5647,"nodeType":543},{},[],"Device code authorization is a legitimate mechanism regularly used in enterprise environments, particularly for CLI logins. Tools like Azure CLI, GitHub CLI, and AWS CLI all use (or have used) the device code flow as a primary or fallback authentication method. This creates a dual problem for defenders. ",{"data":5649,"content":5650,"nodeType":673},{},[5651],{"data":5652,"marks":5653,"value":5654,"nodeType":543},{},[],"First, the phishing attack happens entirely on a legitimate site — there's no fake login page, no malicious payload to scan for, and the URL in the browser is genuine. Since there's no traditional phishing content being delivered, these attacks are more resistant to detection by email and network security tools.",{"data":5656,"content":5657,"nodeType":673},{},[5658],{"data":5659,"marks":5660,"value":5661,"nodeType":543},{},[],"Second, the widespread legitimate use of device code flow — particularly among developers and technical users — normalizes the experience of entering device codes. A phishing lure asking them to do the same thing is indistinguishable from a legitimate IT request. And for non-technical users, this experience isn't much different to, for example, entering a code sent via email or authenticator app. ",{"data":5663,"content":5664,"nodeType":829},{},[5665],{"data":5666,"marks":5667,"value":5669,"nodeType":543},{},[5668],{"type":749},"Multiple apps are vulnerable, with different risk profiles",{"data":5671,"content":5672,"nodeType":673},{},[5673],{"data":5674,"marks":5675,"value":5676,"nodeType":543},{},[],"Various apps implement the device code flow, each with different levels of control and default security, but the risk is not uniform across platforms. ",{"data":5678,"content":5679,"nodeType":2727},{},[5680,5695,5709],{"data":5681,"content":5682,"nodeType":2639},{},[5683],{"data":5684,"content":5685,"nodeType":673},{},[5686,5691],{"data":5687,"marks":5688,"value":5690,"nodeType":543},{},[5689],{"type":749},"Google Workspace ",{"data":5692,"marks":5693,"value":5694,"nodeType":543},{},[],"is a significantly lower-risk target because Google explicitly limits which scopes are available to the device code flow — Gmail, Calendar, and most Workspace APIs are simply unavailable through this mechanism. ",{"data":5696,"content":5697,"nodeType":2639},{},[5698],{"data":5699,"content":5700,"nodeType":673},{},[5701,5705],{"data":5702,"marks":5703,"value":3161,"nodeType":543},{},[5704],{"type":749},{"data":5706,"marks":5707,"value":5708,"nodeType":543},{},[]," offers the broadest attack surface due to unrestricted scopes, reusable first-party client IDs, and the FOCI/PRT escalation paths. ",{"data":5710,"content":5711,"nodeType":2639},{},[5712],{"data":5713,"content":5714,"nodeType":673},{},[5715,5719,5724],{"data":5716,"marks":5717,"value":5718,"nodeType":543},{},[],"Apps like ",{"data":5720,"marks":5721,"value":5723,"nodeType":543},{},[5722],{"type":749},"GitHub",{"data":5725,"marks":5726,"value":5727,"nodeType":543},{},[]," sit in between — broad scopes are available (including full repository access), but the attacker must control their own OAuth app and the victim sees an explicit consent screen. ",{"data":5729,"content":5733,"nodeType":787},{"target":5730},{"sys":5731},{"id":5732,"type":792,"linkType":793},"ejNSC76jge1p1zzz9wwiG",[],{"data":5735,"content":5736,"nodeType":796},{},[],{"data":5738,"content":5739,"nodeType":800},{},[5740],{"data":5741,"marks":5742,"value":5744,"nodeType":543},{},[5743],{"type":749},"Security recommendations",{"data":5746,"content":5747,"nodeType":673},{},[5748],{"data":5749,"marks":5750,"value":5751,"nodeType":543},{},[],"Security teams need to consider the risk posed by device code phishing across multiple apps where device code authorization grants are common, particularly for developers and technical users. ",{"data":5753,"content":5754,"nodeType":673},{},[5755],{"data":5756,"marks":5757,"value":5758,"nodeType":543},{},[],"In an ideal world, you would simply block device code logins. But this can’t be done without causing serious disruption in some environments, while some apps simply don’t provide the tools required to do so. For example, device code is the default CLI sign-in method for GitHub. Developer-heavy organizations are likely to encounter higher levels of legitimate use.",{"data":5760,"content":5761,"nodeType":673},{},[5762,5766,5775,5779,5784,5788,5793,5797,5802],{"data":5763,"marks":5764,"value":5765,"nodeType":543},{},[],"Microsoft arguably offers the strongest control options (other than Google, who negate it right out of the gate), though they do require a fair amount of work. ",{"data":5767,"content":5769,"nodeType":695},{"uri":5768},"https://techcommunity.microsoft.com/blog/microsoft-entra-blog/new-microsoft-managed-policies-to-raise-your-identity-security-posture/4286758",[5770],{"data":5771,"marks":5772,"value":5774,"nodeType":543},{},[5773],{"type":722},"Microsoft now explicitly recommends",{"data":5776,"marks":5777,"value":5778,"nodeType":543},{},[]," blocking device code flow for tenants that haven't used it in the past 25 days. Their guidance is to create a custom CA policy: target relevant users, set the ",{"data":5780,"marks":5781,"value":5783,"nodeType":543},{},[5782],{"type":749},"Authentication Flows",{"data":5785,"marks":5786,"value":5787,"nodeType":543},{},[]," condition to block ",{"data":5789,"marks":5790,"value":5792,"nodeType":543},{},[5791],{"type":749},"Device Code Flow",{"data":5794,"marks":5795,"value":5796,"nodeType":543},{},[],", and set the grant control to ",{"data":5798,"marks":5799,"value":5801,"nodeType":543},{},[5800],{"type":749},"Block Access",{"data":5803,"marks":5804,"value":5805,"nodeType":543},{},[],". Deploy in report-only mode first to identify any legitimate device code usage, then enforce with narrow exceptions.",{"data":5807,"content":5811,"nodeType":787},{"target":5808},{"sys":5809},{"id":5810,"type":792,"linkType":793},"mQIj2o9xRzkZYKNmanB25",[],{"data":5813,"content":5814,"nodeType":673},{},[5815],{"data":5816,"marks":5817,"value":5818,"nodeType":543},{},[],"For other apps, you’re mainly limited to monitoring and response. Ensuring you’re getting authentication logs for these apps is vital, and searching for unusual access patterns (e.g. unusual login protocols, having different IPs for the authorization grant and subsequent account activity). ",{"data":5820,"content":5821,"nodeType":796},{},[],{"data":5823,"content":5824,"nodeType":800},{},[5825],{"data":5826,"marks":5827,"value":5829,"nodeType":543},{},[5828],{"type":749},"How Push Security can help",{"data":5831,"content":5832,"nodeType":673},{},[5833],{"data":5834,"marks":5835,"value":5836,"nodeType":543},{},[],"Push customers can use our browser-based capabilities to overcome the limitations of app-level controls and detect, intercept, and shut down attacks in real time. ",{"data":5838,"content":5839,"nodeType":673},{},[5840],{"data":5841,"marks":5842,"value":5843,"nodeType":543},{},[],"Our research team is already tracking multiple device code phishing campaigns and toolkits, including the EvilTokens kit. Blocking controls are already in place to prevent customers from interacting with malicious pages that match our detections for these new toolkits, ensuring that these pages can be identified and blocked in real time regardless of the infrastructure. ",{"data":5845,"content":5846,"nodeType":673},{},[5847,5851,5860],{"data":5848,"marks":5849,"value":5850,"nodeType":543},{},[],"Using Push you can also ",{"data":5852,"content":5854,"nodeType":695},{"uri":5853},"https://pushsecurity.com/help/can-i-use-push-to-help-protect-against-device-code-phishing-scenarios/",[5855],{"data":5856,"marks":5857,"value":5859,"nodeType":543},{},[5858],{"type":722},"configure in-browser warnings",{"data":5861,"marks":5862,"value":5863,"nodeType":543},{},[]," whenever a user accesses a URL used for device code logins. This provides universal, last-mile protection against even ‘zero-day’ device code phishing attacks using previously unidentified toolkits.  ",{"data":5865,"content":5869,"nodeType":787},{"target":5866},{"sys":5867},{"id":5868,"type":792,"linkType":793},"3JsbGaOKSS3INzBUJpoh1W",[],{"data":5871,"content":5872,"nodeType":673},{},[5873],{"data":5874,"marks":5875,"value":5876,"nodeType":543},{},[],"When a user visits those URLs, Push will also emit a webhook event that the banner was shown and acknowledged. If a user opts to proceed, you can treat this as a high-fidelity alert for your security team to investigate, providing app-agnostic telemetry that may not already be provided in your logs from that particular vendor. You can also simply use Push to block users from accessing device login pages if you’re confident that disruption won’t be caused. ",{"data":5878,"content":5879,"nodeType":829},{},[5880],{"data":5881,"marks":5882,"value":5884,"nodeType":543},{},[5883],{"type":749},"Learn more about Push",{"data":5886,"content":5887,"nodeType":673},{},[5888],{"data":5889,"marks":5890,"value":5891,"nodeType":543},{},[],"Push Security's browser-based security platform detects and blocks browser-based attacks like AiTM phishing, credential stuffing, malicious browser extensions, ClickFix, and session hijacking. You don't need to wait until it all goes wrong either — you can use Push to proactively find and fix vulnerabilities across the apps that your employees use, like ghost logins, SSO coverage gaps, MFA gaps, vulnerable passwords, and more to harden your attack surface.",{"data":5893,"content":5894,"nodeType":673},{},[5895,5899,5908,5911,5920,5924,5933],{"data":5896,"marks":5897,"value":5898,"nodeType":543},{},[],"To learn more about Push, ",{"data":5900,"content":5902,"nodeType":695},{"uri":5901},"https://pushsecurity.com/resources/product-brochure",[5903],{"data":5904,"marks":5905,"value":5907,"nodeType":543},{},[5906],{"type":722},"check out our latest product overview",{"data":5909,"marks":5910,"value":2164,"nodeType":543},{},[],{"data":5912,"content":5914,"nodeType":695},{"uri":5913},"https://pushsecurity.com/product-demo/",[5915],{"data":5916,"marks":5917,"value":5919,"nodeType":543},{},[5918],{"type":722},"view our demo library",{"data":5921,"marks":5922,"value":5923,"nodeType":543},{},[],", or ",{"data":5925,"content":5927,"nodeType":695},{"uri":5926},"https://pushsecurity.com/demo",[5928],{"data":5929,"marks":5930,"value":5932,"nodeType":543},{},[5931],{"type":722},"book some time with one of our team for a live demo",{"data":5934,"marks":5935,"value":1863,"nodeType":543},{},[],"Device code phishing attacks have skyrocketed: here’s what you need to know","Device code phishing is seeing a huge spike in adoption in 2026, enabling attackers to steal access tokens while bypassing standard access controls.","2026-04-04T00:00:00.000Z","device-code-phishing",{"items":5941},[5942,5944],{"sys":5943,"name":2917},{"id":2916},{"sys":5945,"name":2921},{"id":2920},{"items":5947},[5948],{"fullName":660,"firstName":661,"jobTitle":662,"profilePicture":5949},{"url":666},{"__typename":1608,"sys":5951,"content":5953,"title":6515,"synopsis":6516,"hashTags":59,"publishedDate":6517,"slug":6518,"tagsCollection":6519,"authorsCollection":6525},{"id":5952},"27Z1JlNtpGTPyarh393sHK",{"json":5954},{"data":5955,"content":5956,"nodeType":669},{},[5957,5975,5982,5988,5995,6001,6021,6027,6033,6036,6044,6064,6070,6076,6082,6099,6106,6114,6121,6128,6135,6138,6146,6164,6187,6192,6198,6205,6212,6219,6222,6230,6248,6281,6288,6294,6297,6305,6312,6315,6322,6329,6337,6356,6376,6383,6389,6397,6404,6411,6414,6422,6429,6435,6452,6458,6465,6472,6479],{"data":5958,"content":5959,"nodeType":673},{},[5960,5964,5971],{"data":5961,"marks":5962,"value":5963,"nodeType":543},{},[],"In December 2025, we uncovered a state-sponsored campaign linked to Russian state-affiliated APT29 that used a new technique we called ",{"data":5965,"content":5966,"nodeType":695},{"uri":764},[5967],{"data":5968,"marks":5969,"value":949,"nodeType":543},{},[5970],{"type":722},{"data":5972,"marks":5973,"value":5974,"nodeType":543},{},[],". This technique merged ClickFix-style social engineering with OAuth consent phishing to hijack Microsoft accounts. Effectively, ConsentFix is a browser-native attack that results in account takeover, without the downside of needing to touch the endpoint like typical ClickFix (really, the point that it's most likely to be detected and blocked). ",{"data":5976,"content":5977,"nodeType":673},{},[5978],{"data":5979,"marks":5980,"value":5981,"nodeType":543},{},[],"The quick 101 is that victims are tricked into copy-and-pasting a legitimate Microsoft URL into the phishing page. This URL contains an OAuth authorization code that the attacker uses to sign in to a first-party Microsoft application like Azure CLI — specifically targeting apps with known Conditional Access exclusions. ",{"data":5983,"content":5987,"nodeType":787},{"target":5984},{"sys":5985},{"id":5986,"type":792,"linkType":793},"7s4kF5CUFUmdkhpzuwNalX",[],{"data":5989,"content":5990,"nodeType":673},{},[5991],{"data":5992,"marks":5993,"value":5994,"nodeType":543},{},[],"At the end of the attack chain, the attacker is effectively granted API access to the victim's Entra account, while sidestepping MFA (even passkeys), device compliance checks, and in some cases conditional access controls (depending on the application ID targeted by the attacker). ",{"data":5996,"content":6000,"nodeType":787},{"target":5997},{"sys":5998},{"id":5999,"type":792,"linkType":793},"IMtJXMWeaIbRsWxuQ1CaS",[],{"data":6002,"content":6003,"nodeType":673},{},[6004,6008,6017],{"data":6005,"marks":6006,"value":6007,"nodeType":543},{},[],"It didn’t take long for security researchers to jump on this new technique. Lots of contributors rallied round the security recommendations (which we covered in a ",{"data":6009,"content":6011,"nodeType":695},{"uri":6010},"https://pushsecurity.com/blog/consentfix-debrief/",[6012],{"data":6013,"marks":6014,"value":6016,"nodeType":543},{},[6015],{"type":722},"follow-up blog post",{"data":6018,"marks":6019,"value":6020,"nodeType":543},{},[],") but the most notable contribution came from John Hammond, who took the attacker’s implementation and said “I can do better”. His v2 replaced a somewhat clunky implementation with a slick drag-and-drop function. But now, attackers have taken it one step further.",{"data":6022,"content":6026,"nodeType":787},{"target":6023},{"sys":6024},{"id":6025,"type":792,"linkType":793},"59tfJDRhGThKD48Wjg7uY2",[],{"data":6028,"content":6032,"nodeType":787},{"target":6029},{"sys":6030},{"id":6031,"type":792,"linkType":793},"6mEpyVD6f13ZttFmaBcxNm",[],{"data":6034,"content":6035,"nodeType":796},{},[],{"data":6037,"content":6038,"nodeType":800},{},[6039],{"data":6040,"marks":6041,"value":6043,"nodeType":543},{},[6042],{"type":749},"Introducing: ConsentFix v3",{"data":6045,"content":6046,"nodeType":673},{},[6047,6051,6060],{"data":6048,"marks":6049,"value":6050,"nodeType":543},{},[],"The latest development is that a member of the XSS criminal forum, a site strongly suspected to have ",{"data":6052,"content":6054,"nodeType":695},{"uri":6053},"https://flare.io/learn/resources/blog/state-of-the-dark-web-2026",[6055],{"data":6056,"marks":6057,"value":6059,"nodeType":543},{},[6058],{"type":722},"Russian state involvement",{"data":6061,"marks":6062,"value":6063,"nodeType":543},{},[],", has released a new tool “ConsentFix v3”, building on the v1 we saw in the wild, and John’s v2. ",{"data":6065,"content":6069,"nodeType":787},{"target":6066},{"sys":6067},{"id":6068,"type":792,"linkType":793},"4AW0UnBlIaXbIFZjy8ObY1",[],{"data":6071,"content":6075,"nodeType":787},{"target":6072},{"sys":6073},{"id":6074,"type":792,"linkType":793},"1b36XjqBpPx7wteBu6OA6h",[],{"data":6077,"content":6081,"nodeType":787},{"target":6078},{"sys":6079},{"id":6080,"type":792,"linkType":793},"4kbiWA3b096BAFGQuozPaK",[],{"data":6083,"content":6084,"nodeType":673},{},[6085,6089,6095],{"data":6086,"marks":6087,"value":6088,"nodeType":543},{},[],"It looks like broader cybercriminals are starting to take note of ConsentFix, and with the release of public tools like this one, it could be about to go mainstream — like ",{"data":6090,"content":6091,"nodeType":695},{"uri":895},[6092],{"data":6093,"marks":6094,"value":719,"nodeType":543},{},[],{"data":6096,"marks":6097,"value":6098,"nodeType":543},{},[]," has this year. ",{"data":6100,"content":6101,"nodeType":673},{},[6102],{"data":6103,"marks":6104,"value":6105,"nodeType":543},{},[],"Let’s take a closer look at some of the more interesting details of the ConsentFix v3 implementation before considering the bigger picture.  ",{"data":6107,"content":6108,"nodeType":829},{},[6109],{"data":6110,"marks":6111,"value":6113,"nodeType":543},{},[6112],{"type":749},"ConsentFix v3 under the hood",{"data":6115,"content":6116,"nodeType":673},{},[6117],{"data":6118,"marks":6119,"value":6120,"nodeType":543},{},[],"The first thing that jumps out is just how detailed this forum post is. It reads like a security vendor blog post. It walks through the key technical concepts that the reader needs to know, breaking down OAuth grants, consent phishing, refresh tokens, and FOCI (or 'Family of Client IDs' — basically, the feature that allows attackers to use a refresh token obtained for one Microsoft app to be exchanged for access tokens to other FOCI apps without re-authentication). It then walks through the history of ClickFix and ConsentFix before providing step-by-step guidance for users. ",{"data":6122,"content":6123,"nodeType":673},{},[6124],{"data":6125,"marks":6126,"value":6127,"nodeType":543},{},[],"ConsentFix v3 allows users to instrument the entire attack chain, enabling users to spin up ConsentFix infrastructure, create believable personas with which to interact with victims, craft and manage email campaigns, and automate the process of exchanging the captured OAuth token for session and refresh tokens to establish access to the compromised account. ",{"data":6129,"content":6130,"nodeType":673},{},[6131],{"data":6132,"marks":6133,"value":6134,"nodeType":543},{},[],"A combination of SaaS and open-source tools are used to perform the attack, including Cloudflare Workers for hosting, ZoomInfo for target identification, Dropbox for PDF hosting, and Pipedream as an exfiltration channel (effectively creating a webhook to automatically exchange the OAuth material in the URL for a refresh token). They also use hacker tools like SpecterPortal for post exploitation activity.",{"data":6136,"content":6137,"nodeType":796},{},[],{"data":6139,"content":6140,"nodeType":800},{},[6141],{"data":6142,"marks":6143,"value":6145,"nodeType":543},{},[6144],{"type":749},"Why attackers are turning to OAuth-based attacks",{"data":6147,"content":6148,"nodeType":673},{},[6149,6153,6160],{"data":6150,"marks":6151,"value":6152,"nodeType":543},{},[],"Attackers are increasingly turning to OAuth based techniques in 2026. Not only are “legit” OAuth connections being abused in supply chain attacks, but attacks targeting OAuth mechanisms have significantly increased with the rise of ",{"data":6154,"content":6155,"nodeType":695},{"uri":895},[6156],{"data":6157,"marks":6158,"value":719,"nodeType":543},{},[6159],{"type":722},{"data":6161,"marks":6162,"value":6163,"nodeType":543},{},[],". This is because:",{"data":6165,"content":6166,"nodeType":2727},{},[6167,6177],{"data":6168,"content":6169,"nodeType":2639},{},[6170],{"data":6171,"content":6172,"nodeType":673},{},[6173],{"data":6174,"marks":6175,"value":6176,"nodeType":543},{},[],"OAuth attacks defeat standard access controls (including passkeys)",{"data":6178,"content":6179,"nodeType":2639},{},[6180],{"data":6181,"content":6182,"nodeType":673},{},[6183],{"data":6184,"marks":6185,"value":6186,"nodeType":543},{},[],"It’s very low friction, and less likely that users will identify it as phishing (see examples below)",{"data":6188,"content":6191,"nodeType":787},{"target":6189},{"sys":6190},{"id":6025,"type":792,"linkType":793},[],{"data":6193,"content":6197,"nodeType":787},{"target":6194},{"sys":6195},{"id":6196,"type":792,"linkType":793},"2WPb41lNRajdpt5pogQg8M",[],{"data":6199,"content":6200,"nodeType":673},{},[6201],{"data":6202,"marks":6203,"value":6204,"nodeType":543},{},[],"From the user’s perspective, these aren’t situations that users are trained to treat as suspicious. In one case, the victim copies a URL (or simply drag-and-drops a box on the page). In another, they enter a short passcode that’s visible on the page. ",{"data":6206,"content":6207,"nodeType":673},{},[6208],{"data":6209,"marks":6210,"value":6211,"nodeType":543},{},[],"Both are using pop-up windows that look very convincing — and point to legitimate Microsoft pages/URLs. Even users scrutinizing the domain won’t see anything out of place. And as you can see, if the user is already signed into their Microsoft account in the browser, there’s no credential entry or MFA checks to pass through. Simply select your account from the drop down menu and … that’s it.",{"data":6213,"content":6214,"nodeType":673},{},[6215],{"data":6216,"marks":6217,"value":6218,"nodeType":543},{},[],"This unfamiliarity is the same reason that attacks like ClickFix have been so successful. In general, convincing social engineering — well crafted comms, legit-looking pages hosted on trusted sites — combined with unfamiliar payloads makes for a clever attack. And when these attacks play out entirely in the browser (circumventing endpoint controls) and sidestep identity controls, the impact is dialled up even further. ",{"data":6220,"content":6221,"nodeType":796},{},[],{"data":6223,"content":6224,"nodeType":800},{},[6225],{"data":6226,"marks":6227,"value":6229,"nodeType":543},{},[6228],{"type":749},"How ConsentFix and device code phishing overlap",{"data":6231,"content":6232,"nodeType":673},{},[6233,6237,6244],{"data":6234,"marks":6235,"value":6236,"nodeType":543},{},[],"It was only ever going to be a matter of time before ConsentFix was adopted by the mass market. But these things don’t always happen particularly fast. ",{"data":6238,"content":6239,"nodeType":695},{"uri":895},[6240],{"data":6241,"marks":6242,"value":269,"nodeType":543},{},[6243],{"type":722},{"data":6245,"marks":6246,"value":6247,"nodeType":543},{},[]," is probably the best example of this — it’s been a known technique since 2021, but it took until this year to enter mainstream adoption. A big part of that has been the availability of criminal toolkits, and also the rise in AI-assisted capabilities for tool creation (clearly at play here too). The similarity with device code phishing doesn’t end there. ",{"data":6249,"content":6250,"nodeType":673},{},[6251,6255,6264,6268,6277],{"data":6252,"marks":6253,"value":6254,"nodeType":543},{},[],"Both ConsentFix and device code phishing are OAuth attacks. They both find ways of bypassing the standard login procedure (and controls) by targeting different authorization flows, but with a similar outcome and the same advantages to an attacker. Device code phishing exploits the device authorization grant (",{"data":6256,"content":6258,"nodeType":695},{"uri":6257},"https://datatracker.ietf.org/doc/html/rfc8628",[6259],{"data":6260,"marks":6261,"value":6263,"nodeType":543},{},[6262],{"type":722},"RFC 8628",{"data":6265,"marks":6266,"value":6267,"nodeType":543},{},[],"). ConsentFix exploits the authorization code grant (",{"data":6269,"content":6271,"nodeType":695},{"uri":6270},"https://datatracker.ietf.org/doc/html/rfc6749#section-4.1",[6272],{"data":6273,"marks":6274,"value":6276,"nodeType":543},{},[6275],{"type":722},"RFC 6749",{"data":6278,"marks":6279,"value":6280,"nodeType":543},{},[],") as implemented for native/desktop apps with localhost redirects. ",{"data":6282,"content":6283,"nodeType":673},{},[6284],{"data":6285,"marks":6286,"value":6287,"nodeType":543},{},[],"The post-compromise paths are essentially identical because the tokens you get are determined by which app you target, what scopes it has, and the victim user’s permissions, not by which OAuth flow you used to obtain them. The authorization code flow and the device code flow are just different front doors into the same token issuance system.",{"data":6289,"content":6293,"nodeType":787},{"target":6290},{"sys":6291},{"id":6292,"type":792,"linkType":793},"7np3j139dWMP7sLlUQwEFC",[],{"data":6295,"content":6296,"nodeType":796},{},[],{"data":6298,"content":6299,"nodeType":800},{},[6300],{"data":6301,"marks":6302,"value":6304,"nodeType":543},{},[6303],{"type":749},"The verdict: An interesting sign of what’s coming, but maybe not the final form",{"data":6306,"content":6307,"nodeType":673},{},[6308],{"data":6309,"marks":6310,"value":6311,"nodeType":543},{},[],"It’s clear that ConsentFix v3 isn’t exactly an industrialized PhaaS-scale offering. It’s probably closer to a red team-esque proof of concept. But it is a good example of how attackers could operationalize ConsentFix campaigns using largely off-the-shelf tooling and legit SaaS tools. And an indicator of what might be coming soon. ",{"data":6313,"content":6314,"nodeType":796},{},[],{"data":6316,"content":6317,"nodeType":800},{},[6318],{"data":6319,"marks":6320,"value":5744,"nodeType":543},{},[6321],{"type":749},{"data":6323,"content":6324,"nodeType":673},{},[6325],{"data":6326,"marks":6327,"value":6328,"nodeType":543},{},[],"To be able to tackle modern attacks like ConsentFix that occur entirely within the browser context, it is vital that organizations look to monitor the browser as a detection surface, hunt for signs of malicious activity, and block attacks in real-time — in the same way that you would expect EDR to work for endpoint attacks. We’ll talk about how we do this below, but first here’s some general recommendations. ",{"data":6330,"content":6331,"nodeType":829},{},[6332],{"data":6333,"marks":6334,"value":6336,"nodeType":543},{},[6335],{"type":749},"Microsoft ecosystem",{"data":6338,"content":6339,"nodeType":673},{},[6340,6344,6352],{"data":6341,"marks":6342,"value":6343,"nodeType":543},{},[],"Despite the similarity with device code phishing, the ",{"data":6345,"content":6346,"nodeType":695},{"uri":5768},[6347],{"data":6348,"marks":6349,"value":6351,"nodeType":543},{},[6350],{"type":722},"primary recommendation from Microsoft for device code attacks",{"data":6353,"marks":6354,"value":6355,"nodeType":543},{},[]," — disable the device code flow via conditional access — doesn’t apply to ConsentFix (because, as mentioned, it uses a different login flow).",{"data":6357,"content":6358,"nodeType":673},{},[6359,6363,6372],{"data":6360,"marks":6361,"value":6362,"nodeType":543},{},[],"For both ConsentFix and device code phishing, the ",{"data":6364,"content":6366,"nodeType":695},{"uri":6365},"https://msendpointmgr.com/2026/01/08/consentfix-quickfix/",[6367],{"data":6368,"marks":6369,"value":6371,"nodeType":543},{},[6370],{"type":722},"strongest recommendation",{"data":6373,"marks":6374,"value":6375,"nodeType":543},{},[]," is to create Service Principals for each of the vulnerable apps and restrict the users that are authorized to access them to reduce the attack surface of users that can be phished with this method.",{"data":6377,"content":6378,"nodeType":673},{},[6379],{"data":6380,"marks":6381,"value":6382,"nodeType":543},{},[],"You should also hunt in logs for relevant application IDs and resource IDs, and look for mismatches in terms of the initial access IP and subsequent activity, because while the initial login is performed by the user, subsequent actions will be performed by the attacker.  ",{"data":6384,"content":6388,"nodeType":787},{"target":6385},{"sys":6386},{"id":6387,"type":792,"linkType":793},"49Y7NXpnAeAYe9fCp1oyKn",[],{"data":6390,"content":6391,"nodeType":829},{},[6392],{"data":6393,"marks":6394,"value":6396,"nodeType":543},{},[6395],{"type":749},"Beyond Microsoft — Google, GitHub, Salesforce, AWS",{"data":6398,"content":6399,"nodeType":673},{},[6400],{"data":6401,"marks":6402,"value":6403,"nodeType":543},{},[],"It’s worth calling out that these recommendations are Microsoft specific. While in-the-wild exploitation has focused on Microsoft, GitHub, Salesforce, AWS and others are also impacted by device code phishing, supporting device code flow either as a primary or fallback mechanism (Google less so due to inherent restrictions on scopes authorized in the context of device code logins). ",{"data":6405,"content":6406,"nodeType":673},{},[6407],{"data":6408,"marks":6409,"value":6410,"nodeType":543},{},[],"Similarly, ConsentFix principles can be applied beyond Microsoft too. The core requirement is that an OAuth code ends up in a location the victim can manually see and share, e.g. a localhost redirect where no listener is present to complete the handshake. Google Cloud CLI, GitHub CLI, and others support the auth code grant and allow localhost as a redirect URI. ",{"data":6412,"content":6413,"nodeType":796},{},[],{"data":6415,"content":6416,"nodeType":800},{},[6417],{"data":6418,"marks":6419,"value":6421,"nodeType":543},{},[6420],{"type":749},"How Push can help",{"data":6423,"content":6424,"nodeType":673},{},[6425],{"data":6426,"marks":6427,"value":6428,"nodeType":543},{},[],"We’re already detecting and blocking both ConsentFix and device code phishing attacks as they target users in their web browser. When a page matches our detections for a device code or ConsentFix phishing kit (not limited to things like known-bad IPs and domains, but DOM-level analysis of the web page) Push detects and blocks it. Unlike an SWG or RBI type solution, Push analyzes every web page in every browser session and tab, in real time, with no latency. ",{"data":6430,"content":6434,"nodeType":787},{"target":6431},{"sys":6432},{"id":6433,"type":792,"linkType":793},"63EwHbmFZVAlhoXl17Xjfi",[],{"data":6436,"content":6437,"nodeType":673},{},[6438,6441,6448],{"data":6439,"marks":6440,"value":5850,"nodeType":543},{},[],{"data":6442,"content":6443,"nodeType":695},{"uri":5853},[6444],{"data":6445,"marks":6446,"value":5859,"nodeType":543},{},[6447],{"type":722},{"data":6449,"marks":6450,"value":6451,"nodeType":543},{},[]," whenever a user accesses a URL used for device code logins, across any app that supports them. This provides universal, last-mile protection against even ‘zero-day’ device code phishing attacks using previously unidentified toolkits.  ",{"data":6453,"content":6457,"nodeType":787},{"target":6454},{"sys":6455},{"id":6456,"type":792,"linkType":793},"3baS2yqvJd2e4aczw73PTF",[],{"data":6459,"content":6460,"nodeType":673},{},[6461],{"data":6462,"marks":6463,"value":6464,"nodeType":543},{},[],"When a user visits those URLs, Push will also emit a webhook event that the banner was shown and acknowledged. If a user opts to proceed, you can treat this as a high-fidelity alert for your security team to investigate, providing app-agnostic telemetry that may not already be provided in your logs from that particular vendor. You can also simply use Push to block users from accessing these pages if you’re confident that disruption won’t be caused. ",{"data":6466,"content":6467,"nodeType":829},{},[6468],{"data":6469,"marks":6470,"value":5884,"nodeType":543},{},[6471],{"type":749},{"data":6473,"content":6474,"nodeType":673},{},[6475],{"data":6476,"marks":6477,"value":6478,"nodeType":543},{},[],"Push Security's browser-based security platform detects and blocks browser-based attacks like AiTM phishing, credential stuffing, malicious browser extensions, device code phishing, ClickFix, and session hijacking. You don't need to wait until it all goes wrong either — you can use Push to proactively find and fix vulnerabilities across the apps that your employees use, like ghost logins, SSO coverage gaps, MFA gaps, vulnerable passwords, risky OAuth integrations, and more to harden your attack surface.",{"data":6480,"content":6481,"nodeType":673},{},[6482,6485,6492,6495,6502,6505,6512],{"data":6483,"marks":6484,"value":5898,"nodeType":543},{},[],{"data":6486,"content":6487,"nodeType":695},{"uri":5901},[6488],{"data":6489,"marks":6490,"value":5907,"nodeType":543},{},[6491],{"type":722},{"data":6493,"marks":6494,"value":2164,"nodeType":543},{},[],{"data":6496,"content":6497,"nodeType":695},{"uri":5913},[6498],{"data":6499,"marks":6500,"value":5919,"nodeType":543},{},[6501],{"type":722},{"data":6503,"marks":6504,"value":5923,"nodeType":543},{},[],{"data":6506,"content":6507,"nodeType":695},{"uri":5926},[6508],{"data":6509,"marks":6510,"value":5932,"nodeType":543},{},[6511],{"type":722},{"data":6513,"marks":6514,"value":1863,"nodeType":543},{},[],"ConsentFix v3: Analyzing a new criminal toolkit","Investigating a new criminal toolkit for ConsentFix being promoted on criminal forums. ","2026-04-23T00:00:00.000Z","consentfix-v3-analyzing-a-new-toolkit",{"items":6520},[6521,6523],{"sys":6522,"name":2917},{"id":2916},{"sys":6524,"name":2921},{"id":2920},{"items":6526},[6527],{"fullName":2925,"firstName":2926,"jobTitle":2927,"profilePicture":6528},{"url":2929},"authorization-phishing","blog/authorization-phishing",{"json":6532},{"data":6533,"content":6534,"nodeType":669},{},[6535],{"data":6536,"content":6537,"nodeType":673},{},[6538],{"data":6539,"marks":6540,"value":6541,"nodeType":543},{},[],"Why attackers are pivoting to authorization-layer attacks to get around authentication controls that are resistant to traditional phishing and account takeover techniques. ","Why attackers are pivoting to authorization attacks to get around authentication controls, how they work, and what security teams can do about them.",{"id":6544,"publishedAt":6545},"1m3Hh9Gg9aHXFckcnlDi4V","2026-08-24T14:23:40.262Z",{"items":6547},[6548,6550],{"sys":6549,"name":2917},{"id":2916},{"sys":6551,"name":2921},{"id":2920},{"items":6553},[6554,6559,6564,6569,6574,6579,6582,6586],{"sys":6555,"name":6557,"slug":6558,"tier":45},{"id":6556},"topic-identity-attacks","Identity attacks","identity-attacks",{"sys":6560,"name":6562,"slug":6563,"tier":45},{"id":6561},"topic-passkeys","Passkeys","passkeys",{"sys":6565,"name":6567,"slug":6568,"tier":45},{"id":6566},"topic-mfa-bypass","MFA bypass","mfa-bypass",{"sys":6570,"name":6572,"slug":6573,"tier":45},{"id":6571},"topic-password-security","Password security","password-security",{"sys":6575,"name":6577,"slug":6578,"tier":45},{"id":6576},"topic-phaas","PhaaS","phaas",{"sys":6580,"name":269,"slug":5939,"tier":45},{"id":6581},"topic-device-code-phishing",{"sys":6583,"name":254,"slug":6585,"tier":31},{"id":6584},"topic-phishing","phishing",{"sys":6587,"name":6589,"slug":6590,"tier":31},{"id":6588},"topic-browser-attacks","Browser attacks","browser-attacks","WpiA16cnJfSz7tEeimbZpsWFy_s2G60-DdfTujbsr3g",{"id":6593,"title":6594,"authorsCollection":6595,"content":6603,"extension":1410,"faqItemsCollection":7603,"faqTitle":7791,"featured":6,"hashTags":59,"meta":7792,"metaTitle":7793,"ogImage":59,"postType":7794,"publishedDate":7795,"relatedBlogPostsCollection":7796,"slug":10606,"stem":10607,"subtitle":10608,"summary":10609,"synopsis":10619,"sys":10620,"tagsCollection":10623,"topicsCollection":10633,"__hash__":10712},"blog/blog/shadow-ai-how-to-discover-govern-and-secure-ai-apps.json","Shadow AI: how to discover, govern, and secure AI apps",{"items":6596},[6597],{"fullName":6598,"firstName":6599,"jobTitle":6600,"socialLinks":59,"profilePicture":6601},"Kelly Davenport","Kelly","Product Team",{"url":6602},"https://images.ctfassets.net/y1cdw1ablpvd/1hi8bEuVfn5sF57LivAq6d/9a3b82426c697d765e2e450e33a18424/kelly_profile_pic.jpeg",{"json":6604,"links":7445},{"data":6605,"content":6606,"nodeType":669},{},[6607,6614,6621,6669,6676,6683,6736,6742,6745,6753,6760,6772,6778,6790,6796,6808,6814,6817,6825,6832,6851,6862,6869,6876,6879,6887,6894,6918,6924,6931,6947,6963,6969,6985,7001,7008,7015,7022,7028,7031,7039,7046,7053,7060,7076,7083,7108,7114,7121,7127,7139,7146,7152,7158,7161,7169,7176,7194,7201,7209,7216,7228,7244,7250,7262,7296,7303,7319,7325,7341,7347,7354,7361,7364,7372,7379,7386,7393,7400,7407,7414,7417,7423,7429],{"data":6608,"content":6609,"nodeType":673},{},[6610],{"data":6611,"marks":6612,"value":6613,"nodeType":543},{},[],"Every security team that's blocked an AI tool at the network level has had the same experience three months later: The tool they blocked isn't in use, but a dozen they've never heard of are.",{"data":6615,"content":6616,"nodeType":673},{},[6617],{"data":6618,"marks":6619,"value":6620,"nodeType":543},{},[],"The block didn't stop employees from using AI. It just prevented the security team from seeing what’s actually happening.",{"data":6622,"content":6623,"nodeType":673},{},[6624,6628,6636,6640,6645,6648,6653,6657,6665],{"data":6625,"marks":6626,"value":6627,"nodeType":543},{},[],"The data backs up this pattern. ",{"data":6629,"content":6631,"nodeType":695},{"uri":6630},"https://pushsecurity.com/blog/what-push-data-reveals-about-the-state-of-shadow-ai/",[6632],{"data":6633,"marks":6634,"value":6635,"nodeType":543},{},[],"Push telemetry",{"data":6637,"marks":6638,"value":6639,"nodeType":543},{},[]," shows that the average organization has ",{"data":6641,"marks":6642,"value":6644,"nodeType":543},{},[6643],{"type":749},"16 AI apps, 17 AI browser extensions,",{"data":6646,"marks":6647,"value":3096,"nodeType":543},{},[],{"data":6649,"marks":6650,"value":6652,"nodeType":543},{},[6651],{"type":749},"17 AI OAuth integrations",{"data":6654,"marks":6655,"value":6656,"nodeType":543},{},[]," in active use during a typical week — most unapproved. Meanwhile, ",{"data":6658,"content":6660,"nodeType":695},{"uri":6659},"https://www.okta.com/newsroom/articles/ai-agents-at-work-2026-agentic-enterprise-security/",[6661],{"data":6662,"marks":6663,"value":6664,"nodeType":543},{},[],"Okta found",{"data":6666,"marks":6667,"value":6668,"nodeType":543},{},[]," that 80% of employees who use unapproved AI tools do so because it's easier to use their own accounts, and 57% because the approval process is too slow.",{"data":6670,"content":6671,"nodeType":673},{},[6672],{"data":6673,"marks":6674,"value":6675,"nodeType":543},{},[],"The organizations getting this right have stopped treating AI governance as an access-control problem — which tools to allow, which to block — and started treating it as an invitation to build out an infrastructure to enable appropriate use. Employees are going to use the tools they need to get their work done. The question is whether they'll use them on a path you built and instrumented, or on one they carved themselves.",{"data":6677,"content":6678,"nodeType":673},{},[6679],{"data":6680,"marks":6681,"value":6682,"nodeType":543},{},[],"This guide walks through how to build that paved path. Using Push, you can:",{"data":6684,"content":6685,"nodeType":2727},{},[6686,6696,6706,6716,6726],{"data":6687,"content":6688,"nodeType":2639},{},[6689],{"data":6690,"content":6691,"nodeType":673},{},[6692],{"data":6693,"marks":6694,"value":6695,"nodeType":543},{},[],"Identify shadow AI, including personal accounts on approved corporate apps, AI browser extensions, OAuth integrations into sensitive systems, and AI browser usage.",{"data":6697,"content":6698,"nodeType":2639},{},[6699],{"data":6700,"content":6701,"nodeType":673},{},[6702],{"data":6703,"marks":6704,"value":6705,"nodeType":543},{},[],"Enforce policies on data flows into and out of AI apps, including blocking unapproved file uploads, downloads, and clipboard pastes; and monitoring AI chat transcripts.",{"data":6707,"content":6708,"nodeType":2639},{},[6709],{"data":6710,"content":6711,"nodeType":673},{},[6712],{"data":6713,"marks":6714,"value":6715,"nodeType":543},{},[],"Use just-in-time guardrails to intercept users accessing unapproved AI tools and point them at approved alternatives.",{"data":6717,"content":6718,"nodeType":2639},{},[6719],{"data":6720,"content":6721,"nodeType":673},{},[6722],{"data":6723,"marks":6724,"value":6725,"nodeType":543},{},[],"Prevent unwanted MCP connections with app-agnostic controls.",{"data":6727,"content":6728,"nodeType":2639},{},[6729],{"data":6730,"content":6731,"nodeType":673},{},[6732],{"data":6733,"marks":6734,"value":6735,"nodeType":543},{},[],"Automate a lot of the work so you don’t burn out your team as the AI landscape continues to shift.",{"data":6737,"content":6741,"nodeType":787},{"target":6738},{"sys":6739},{"id":6740,"type":792,"linkType":793},"29N8YH9As3GHypOve3br80",[],{"data":6743,"content":6744,"nodeType":796},{},[],{"data":6746,"content":6747,"nodeType":800},{},[6748],{"data":6749,"marks":6750,"value":6752,"nodeType":543},{},[6751],{"type":749},"What is shadow AI, and why can't you manage it like shadow IT?",{"data":6754,"content":6755,"nodeType":673},{},[6756],{"data":6757,"marks":6758,"value":6759,"nodeType":543},{},[],"Shadow AI is any use of AI tools, services, or integrations that happens outside an organization's security governance and visibility. Security teams have been managing shadow SaaS for years, but shadow AI can't be addressed with the same playbook — for three reasons.",{"data":6761,"content":6762,"nodeType":673},{},[6763,6768],{"data":6764,"marks":6765,"value":6767,"nodeType":543},{},[6766],{"type":749},"First",{"data":6769,"marks":6770,"value":6771,"nodeType":543},{},[],", it spans multiple categories that each need different controls: unapproved AI apps, personal accounts on approved corporate AI tools, AI browser extensions, and OAuth integrations into corporate systems. Blocking unapproved apps doesn't address personal accounts on approved ones, and neither solves the extension or OAuth problem. ",{"data":6773,"content":6777,"nodeType":787},{"target":6774},{"sys":6775},{"id":6776,"type":792,"linkType":793},"2hsKQ9DEspflhmtR0bE7QY",[],{"data":6779,"content":6780,"nodeType":673},{},[6781,6786],{"data":6782,"marks":6783,"value":6785,"nodeType":543},{},[6784],{"type":749},"Second",{"data":6787,"marks":6788,"value":6789,"nodeType":543},{},[],", the tools most organizations rely on to manage shadow SaaS — SWGs, CASBs, EDR, IdP logs — are structurally blind to shadow AI. An SWG sees that someone visited an AI domain but can't tell you whether they logged in, pasted source code into a prompt, or granted OAuth access to your Google Workspace tenant. EDR doesn't see browser-layer activity at all. IdP logs capture OAuth grants routed through the identity provider but miss tools accessed via direct signup or personal accounts. Instead, the activity security teams need to see happens primarily inside the browser.",{"data":6791,"content":6795,"nodeType":787},{"target":6792},{"sys":6793},{"id":6794,"type":792,"linkType":793},"1vE0dyAKdnTSjyAJ4Xoadd",[],{"data":6797,"content":6798,"nodeType":673},{},[6799,6804],{"data":6800,"marks":6801,"value":6803,"nodeType":543},{},[6802],{"type":749},"Third",{"data":6805,"marks":6806,"value":6807,"nodeType":543},{},[],", the risk profile is different. Shadow AI tools increasingly function as hubs — connected via OAuth integrations and MCP to email, cloud storage, code repositories, and other high-value systems. They leak sensitive data outward (employees paste source code, credentials, and internal documents into prompts daily) while simultaneously expanding the attack surface inward (compromise a single AI app and an attacker inherits whatever access the employee granted it, turning one ungoverned tool into a pivot point across the SaaS estate). ",{"data":6809,"content":6813,"nodeType":787},{"target":6810},{"sys":6811},{"id":6812,"type":792,"linkType":793},"3ldZ23OORTu7INBfSnE7R7",[],{"data":6815,"content":6816,"nodeType":796},{},[],{"data":6818,"content":6819,"nodeType":800},{},[6820],{"data":6821,"marks":6822,"value":6824,"nodeType":543},{},[6823],{"type":749},"Why blocking AI usage fails",{"data":6826,"content":6827,"nodeType":673},{},[6828],{"data":6829,"marks":6830,"value":6831,"nodeType":543},{},[],"The instinct to block AI tools makes sense. Executives are asking about AI risk to the business, a new tool appears every week, and blocking unapproved apps feels like a quick way to stop the bleeding.",{"data":6833,"content":6834,"nodeType":673},{},[6835,6839,6847],{"data":6836,"marks":6837,"value":6838,"nodeType":543},{},[],"Unfortunately, blocking doesn't work for long. The latest security frameworks — including the ",{"data":6840,"content":6842,"nodeType":695},{"uri":6841},"https://www.sans.org/mlp/2026-ai-security-maturity-model-ebook",[6843],{"data":6844,"marks":6845,"value":6846,"nodeType":543},{},[],"SANS AI Security Maturity Model",{"data":6848,"marks":6849,"value":6850,"nodeType":543},{},[]," — all agree: Block-based AI policies drive usage underground rather than preventing it. ",{"data":6852,"content":6853,"nodeType":6861},{},[6854],{"data":6855,"content":6856,"nodeType":673},{},[6857],{"data":6858,"marks":6859,"value":6860,"nodeType":543},{},[],"A block-based AI policy may feel like risk management, but practitioner experience shows that it typically drives AI usage underground rather than preventing it. The goal is not to eliminate AI use; it is to bring it into visibility where it can be governed.","blockquote",{"data":6863,"content":6864,"nodeType":673},{},[6865],{"data":6866,"marks":6867,"value":6868,"nodeType":543},{},[],"These kinds of barricades also fail for a structural reason: They're built on the network perimeter, and AI usage doesn't cross the perimeter in ways network tools can inspect.",{"data":6870,"content":6871,"nodeType":673},{},[6872],{"data":6873,"marks":6874,"value":6875,"nodeType":543},{},[],"The most damaging consequence of blocking isn't the workarounds themselves — it's the loss of visibility. To begin building a better path for employees, you have to start with seeing what's actually happening.",{"data":6877,"content":6878,"nodeType":796},{},[],{"data":6880,"content":6881,"nodeType":800},{},[6882],{"data":6883,"marks":6884,"value":6886,"nodeType":543},{},[6885],{"type":749},"Using Push to discover, govern, and control shadow AI",{"data":6888,"content":6889,"nodeType":673},{},[6890],{"data":6891,"marks":6892,"value":6893,"nodeType":543},{},[],"Push Security is a browser security platform that gets you the vantage point you need to start addressing shadow AI. Push deploys as a lightweight extension to employees' existing browsers rather than requiring a full browser migration, giving security teams visibility into browser-layer activity that network and endpoint tools structurally lack.",{"data":6895,"content":6896,"nodeType":673},{},[6897,6901,6906,6909,6914],{"data":6898,"marks":6899,"value":6900,"nodeType":543},{},[],"Push discovers AI tools through ",{"data":6902,"marks":6903,"value":6905,"nodeType":543},{},[6904],{"type":749},"automatic",{"data":6907,"marks":6908,"value":3529,"nodeType":543},{},[],{"data":6910,"marks":6911,"value":6913,"nodeType":543},{},[6912],{"type":749},"app discovery",{"data":6915,"marks":6916,"value":6917,"nodeType":543},{},[],", allowing you to identify applications from actual browser login events rather than network traffic logs. ",{"data":6919,"content":6923,"nodeType":787},{"target":6920},{"sys":6921},{"id":6922,"type":792,"linkType":793},"4eTkgU2dxhMueHPiwuCWDl",[],{"data":6925,"content":6926,"nodeType":673},{},[6927],{"data":6928,"marks":6929,"value":6930,"nodeType":543},{},[],"When an employee signs into a new AI service, Push registers the authentication event, identifies the application, and logs how the employee authenticated — corporate SSO, OIDC, a standalone password, or a personal account. ",{"data":6932,"content":6933,"nodeType":673},{},[6934,6938,6943],{"data":6935,"marks":6936,"value":6937,"nodeType":543},{},[],"Push then applies ",{"data":6939,"marks":6940,"value":6942,"nodeType":543},{},[6941],{"type":749},"app categories ",{"data":6944,"marks":6945,"value":6946,"nodeType":543},{},[],"automatically, classifying the discovered application by type without requiring security teams to build or maintain manual lists.",{"data":6948,"content":6949,"nodeType":673},{},[6950,6954,6959],{"data":6951,"marks":6952,"value":6953,"nodeType":543},{},[],"Push extends the same discovery across the other three shadow AI dimensions. The platform’s ",{"data":6955,"marks":6956,"value":6958,"nodeType":543},{},[6957],{"type":749},"browser extension discovery ",{"data":6960,"marks":6961,"value":6962,"nodeType":543},{},[],"capability catalogs every AI-related extension installed across the workforce, including the specific permissions each extension has requested (access to page content, browsing history, clipboard data), allowing you to review whether those permission combinations could enable data exfiltration or account takeover. ",{"data":6964,"content":6968,"nodeType":787},{"target":6965},{"sys":6966},{"id":6967,"type":792,"linkType":793},"1z56sTWWN9E35dE3HhbRNY",[],{"data":6970,"content":6971,"nodeType":673},{},[6972,6976,6981],{"data":6973,"marks":6974,"value":6975,"nodeType":543},{},[],"Push’s ",{"data":6977,"marks":6978,"value":6980,"nodeType":543},{},[6979],{"type":749},"OAuth integration discovery",{"data":6982,"marks":6983,"value":6984,"nodeType":543},{},[]," identifies OAuth connections between AI tools and corporate systems — the grants that create persistent API-level access to platforms like Google Workspace.",{"data":6986,"content":6987,"nodeType":673},{},[6988,6992,6997],{"data":6989,"marks":6990,"value":6991,"nodeType":543},{},[],"For each discovered tool, Push also captures authentication context that points to ",{"data":6993,"marks":6994,"value":6996,"nodeType":543},{},[6995],{"type":749},"where hidden security risks lie",{"data":6998,"marks":6999,"value":7000,"nodeType":543},{},[],": SSO vs. password vs. personal account, MFA status, and password strength. An AI tool accessed via corporate SSO with MFA is a different risk than the same tool accessed through a personal Gmail account with a reused password. Similarly, employees using only a password to access AI tools that they’ve integrated with other sensitive corporate systems introduces another level of downstream risk. That context is what makes the inventory actionable.",{"data":7002,"content":7003,"nodeType":673},{},[7004],{"data":7005,"marks":7006,"value":7007,"nodeType":543},{},[],"Push also detects when employees are adopting agentic browsers — autonomous AI-powered browsers like Comet, Atlas, and Dia that browse the web and interact with applications on behalf of users or automated workflows. ",{"data":7009,"content":7010,"nodeType":673},{},[7011],{"data":7012,"marks":7013,"value":7014,"nodeType":543},{},[],"These represent an emerging category of non-human AI identity. They authenticate to SaaS applications, access corporate data, and make API calls, but they aren't managed through traditional identity infrastructure. Push helps you identify these agentic browsers as they appear in the environment, before they become a blind spot.",{"data":7016,"content":7017,"nodeType":673},{},[7018],{"data":7019,"marks":7020,"value":7021,"nodeType":543},{},[],"Returning to the paved path metaphor, this step is about surveying the site before you figure out where to put in the path. You need to understand who’s already doing what, where, so you can find the risks you need to address.",{"data":7023,"content":7027,"nodeType":787},{"target":7024},{"sys":7025},{"id":7026,"type":792,"linkType":793},"5iXyJbxwWiUt7WoP7FF0Y2",[],{"data":7029,"content":7030,"nodeType":796},{},[],{"data":7032,"content":7033,"nodeType":800},{},[7034],{"data":7035,"marks":7036,"value":7038,"nodeType":543},{},[7037],{"type":749},"Step-by-step guide to enforcing AI governance without blocking everything",{"data":7040,"content":7041,"nodeType":673},{},[7042],{"data":7043,"marks":7044,"value":7045,"nodeType":543},{},[],"The barricade approach favored by existing solutions like network proxies gives you two options: Allow or block. Enforcing AI policy effectively requires a third approach with a bit more nuance: Guide the user to do the right thing. ",{"data":7047,"content":7048,"nodeType":829},{},[7049],{"data":7050,"marks":7051,"value":7052,"nodeType":543},{},[],"Building the \"paved path\" with Push",{"data":7054,"content":7055,"nodeType":673},{},[7056],{"data":7057,"marks":7058,"value":7059,"nodeType":543},{},[],"Push provides all three options as configurable enforcement modes for a variety of readymade controls. Progressing between them is how organizations can move from \"we don't know what people are doing with AI\" to evidence-based governance.",{"data":7061,"content":7062,"nodeType":673},{},[7063,7067,7072],{"data":7064,"marks":7065,"value":7066,"nodeType":543},{},[],"Push can be deployed silently and begin observing AI usage with no employee-facing intervention. This is effectively Push in ",{"data":7068,"marks":7069,"value":7071,"nodeType":543},{},[7070],{"type":749},"Monitor",{"data":7073,"marks":7074,"value":7075,"nodeType":543},{},[]," mode.",{"data":7077,"content":7078,"nodeType":673},{},[7079],{"data":7080,"marks":7081,"value":7082,"nodeType":543},{},[],"The platform records which tools are in use, how employees authenticated, and what usage patterns are emerging. Most organizations should start here to generate a baseline. Telemetry can be streamed to your SIEM or other downstream system to get alerted to newly adopted apps and extensions, and to surface security risks like insecure accounts.",{"data":7084,"content":7085,"nodeType":673},{},[7086,7090,7095,7099,7104],{"data":7087,"marks":7088,"value":7089,"nodeType":543},{},[],"Next, most organizations will transition to ",{"data":7091,"marks":7092,"value":7094,"nodeType":543},{},[7093],{"type":749},"Acknowledge",{"data":7096,"marks":7097,"value":7098,"nodeType":543},{},[]," mode for controls like in-browser ",{"data":7100,"marks":7101,"value":7103,"nodeType":543},{},[7102],{"type":749},"App banners",{"data":7105,"marks":7106,"value":7107,"nodeType":543},{},[],". With this control, you can warn employees when they attempt to use an unapproved AI tool and point them to approved alternatives.",{"data":7109,"content":7113,"nodeType":787},{"target":7110},{"sys":7111},{"id":7112,"type":792,"linkType":793},"17nT8JDTyHLExwhb2upb6T",[],{"data":7115,"content":7116,"nodeType":673},{},[7117],{"data":7118,"marks":7119,"value":7120,"nodeType":543},{},[],"The employee isn't blocked — they're guided toward the governed path at the moment they're about to step off it. This is more effective than a policy document because it arrives right when they need the reminder. ",{"data":7122,"content":7126,"nodeType":787},{"target":7123},{"sys":7124},{"id":7125,"type":792,"linkType":793},"2lDFCuc48jcGODcwD6nYhK",[],{"data":7128,"content":7129,"nodeType":673},{},[7130,7135],{"data":7131,"marks":7132,"value":7134,"nodeType":543},{},[7133],{"type":749},"Block",{"data":7136,"marks":7137,"value":7138,"nodeType":543},{},[]," mode prevents access entirely — Push presents a blocking banner to users who attempt to log in to unapproved apps. ",{"data":7140,"content":7141,"nodeType":673},{},[7142],{"data":7143,"marks":7144,"value":7145,"nodeType":543},{},[],"Push makes the Monitor → Acknowledge → Block progression practical through automatic app categorization. This means that new AI tools inherit whatever governance mode the team has set for that category, without manual blocklist updates. All controls are configurable per user group — the data science team can use AI coding assistants while uploads from finance are restricted — because different teams have different risk profiles.",{"data":7147,"content":7151,"nodeType":787},{"target":7148},{"sys":7149},{"id":7150,"type":792,"linkType":793},"5EBOHy6X6iJfmzJ65txGOv",[],{"data":7153,"content":7157,"nodeType":787},{"target":7154},{"sys":7155},{"id":7156,"type":792,"linkType":793},"31JnX2KNCAnlaVS9Qqqh8W",[],{"data":7159,"content":7160,"nodeType":796},{},[],{"data":7162,"content":7163,"nodeType":800},{},[7164],{"data":7165,"marks":7166,"value":7168,"nodeType":543},{},[7167],{"type":749},"Guardrails: how to prevent data loss to AI tools",{"data":7170,"content":7171,"nodeType":673},{},[7172],{"data":7173,"marks":7174,"value":7175,"nodeType":543},{},[],"Even on the paved path, you need guardrails because preventing data loss to AI tools is a separate problem from controlling which tools employees use. An employee on an approved AI tool can still paste an AWS access key into a prompt, upload a customer spreadsheet, or share confidential documents in a conversation.",{"data":7177,"content":7178,"nodeType":673},{},[7179,7182,7190],{"data":7180,"marks":7181,"value":21,"nodeType":543},{},[],{"data":7183,"content":7184,"nodeType":695},{"uri":6659},[7185],{"data":7186,"marks":7187,"value":7189,"nodeType":543},{},[7188],{"type":722},"Okta's data",{"data":7191,"marks":7192,"value":7193,"nodeType":543},{},[]," on what employees actually share shows what’s at stake: 54% share internal messages and emails with AI tools, 39% share confidential company documents, and 28% share banking and payment information.",{"data":7195,"content":7196,"nodeType":673},{},[7197],{"data":7198,"marks":7199,"value":7200,"nodeType":543},{},[],"Blocking is too much of a blunt instrument here, as obviously, you want employees to be able to use approved tools. The answer is controlling what data enters them.",{"data":7202,"content":7203,"nodeType":829},{},[7204],{"data":7205,"marks":7206,"value":7208,"nodeType":543},{},[7207],{"type":749},"Browser-layer controls for AI data leakage",{"data":7210,"content":7211,"nodeType":673},{},[7212],{"data":7213,"marks":7214,"value":7215,"nodeType":543},{},[],"Push addresses this problem with four browser-layer data controls, each targeting a distinct exfiltration path and supporting the same Monitor → Warn → Block enforcement modes:",{"data":7217,"content":7218,"nodeType":673},{},[7219,7224],{"data":7220,"marks":7221,"value":7223,"nodeType":543},{},[7222],{"type":749},"Clipboard blocking",{"data":7225,"marks":7226,"value":7227,"nodeType":543},{},[]," addresses the most common path for sensitive data into AI tools: copy-paste. Push matches clipboard content against preconfigured patterns for AWS access keys, GitHub tokens, API keys, credit card numbers, and personal identifiers, plus custom content rules for organization-specific data like internal project codes. ",{"data":7229,"content":7230,"nodeType":673},{},[7231,7235,7240],{"data":7232,"marks":7233,"value":7234,"nodeType":543},{},[],"In ",{"data":7236,"marks":7237,"value":7239,"nodeType":543},{},[7238],{"type":749},"Warn",{"data":7241,"marks":7242,"value":7243,"nodeType":543},{},[]," mode, Push offers a redacted version of the sensitive data so the employee can continue their work — getting help with their code, for instance — without exposing the actual credential.",{"data":7245,"content":7249,"nodeType":787},{"target":7246},{"sys":7247},{"id":7248,"type":792,"linkType":793},"1JarUdbe8AkJlgB0LjchNR",[],{"data":7251,"content":7252,"nodeType":673},{},[7253,7258],{"data":7254,"marks":7255,"value":7257,"nodeType":543},{},[7256],{"type":749},"File upload blocking",{"data":7259,"marks":7260,"value":7261,"nodeType":543},{},[]," prevents files from being uploaded to specific AI apps, configurable by app, user group, and file type (Push provides a list for fast configuration).",{"data":7263,"content":7264,"nodeType":673},{},[7265,7270,7274,7283,7287,7292],{"data":7266,"marks":7267,"value":7269,"nodeType":543},{},[7268],{"type":749},"File download blocking",{"data":7271,"marks":7272,"value":7273,"nodeType":543},{},[]," addresses a different common risk: Employees downloading desktop versions of AI tools, which moves usage outside the browser where Push has visibility. Download blocking also covers files generated inside web applications, such as an AI tool that produces a downloadable asset. (Push’s detection and response capabilities also protect against scenarios in which attackers present users with ",{"data":7275,"content":7277,"nodeType":695},{"uri":7276},"https://pushsecurity.com/blog/llmshare-malvertising-campaign",[7278],{"data":7279,"marks":7280,"value":7282,"nodeType":543},{},[7281],{"type":722},"faked AI tool download pages",{"data":7284,"marks":7285,"value":7286,"nodeType":543},{},[]," as part of phishing campaigns, a technique we dubbed ",{"data":7288,"marks":7289,"value":7291,"nodeType":543},{},[7290],{"type":749},"LLMShare",{"data":7293,"marks":7294,"value":7295,"nodeType":543},{},[],".)",{"data":7297,"content":7298,"nodeType":673},{},[7299],{"data":7300,"marks":7301,"value":7302,"nodeType":543},{},[],"Push also provides telemetry streams on all file upload and download events in your environment, so you can get a baseline pattern of life and identify anomalies that could indicate insider risk. ",{"data":7304,"content":7305,"nodeType":673},{},[7306,7310,7315],{"data":7307,"marks":7308,"value":7309,"nodeType":543},{},[],"The Push platform also provides the capability to write your own ",{"data":7311,"marks":7312,"value":7314,"nodeType":543},{},[7313],{"type":749},"custom detections",{"data":7316,"marks":7317,"value":7318,"nodeType":543},{},[],", which you can use for other organization-specific use cases, or even to extend your control over GenAI tool usage, such as by blocking unapproved MCP server connections.",{"data":7320,"content":7324,"nodeType":787},{"target":7321},{"sys":7322},{"id":7323,"type":792,"linkType":793},"5XYVgJjgUPUfY1W1Zcgrvm",[],{"data":7326,"content":7327,"nodeType":673},{},[7328,7332,7337],{"data":7329,"marks":7330,"value":7331,"nodeType":543},{},[],"Finally, ",{"data":7333,"marks":7334,"value":7336,"nodeType":543},{},[7335],{"type":749},"AI conversation visibility",{"data":7338,"marks":7339,"value":7340,"nodeType":543},{},[]," gives you a window into what is being shared in AI chats, consumable as a stream of events to your SIEM or SOAR. Over time, you can build up a picture of what’s normal or what violates company policy, and create a queryable history to identify potential data loss during an incident response process.",{"data":7342,"content":7346,"nodeType":787},{"target":7343},{"sys":7344},{"id":7345,"type":792,"linkType":793},"3ELxGNAa8YaVQR96IuWifj",[],{"data":7348,"content":7349,"nodeType":673},{},[7350],{"data":7351,"marks":7352,"value":7353,"nodeType":543},{},[],"Traditional DLP at the endpoint or network layer misses these paths. Network DLP and SWGs can't inspect clipboard pastes into AI prompts — there's no network event to intercept. Endpoint DLP sees file-system operations but not in-browser activity. ",{"data":7355,"content":7356,"nodeType":673},{},[7357],{"data":7358,"marks":7359,"value":7360,"nodeType":543},{},[],"Push's controls operate where the data is flowing — inside the browser session.",{"data":7362,"content":7363,"nodeType":796},{},[],{"data":7365,"content":7366,"nodeType":829},{},[7367],{"data":7368,"marks":7369,"value":7371,"nodeType":543},{},[7370],{"type":749},"How to keep up with AI tool sprawl",{"data":7373,"content":7374,"nodeType":673},{},[7375],{"data":7376,"marks":7377,"value":7378,"nodeType":543},{},[],"Pragmatically, the hardest part of generative AI security isn't the initial steps you take — it's keeping up with the sprawl. Point-in-time audits quickly become outdated when the landscape changes so quickly.",{"data":7380,"content":7381,"nodeType":673},{},[7382],{"data":7383,"marks":7384,"value":7385,"nodeType":543},{},[],"Push addresses this with continuous discovery, telemetry streams for the most important points of user interaction with AI apps, and controls that allow you to adapt quickly with simple configuration changes.",{"data":7387,"content":7388,"nodeType":673},{},[7389],{"data":7390,"marks":7391,"value":7392,"nodeType":543},{},[],"With automatic app categorization, if an employee starts using a new AI code assistant that didn't exist last quarter, Push discovers it, classifies it, and applies your governance rules — no manual intervention required.",{"data":7394,"content":7395,"nodeType":673},{},[7396],{"data":7397,"marks":7398,"value":7399,"nodeType":543},{},[],"All AI-related telemetry — app logins, file uploads and downloads, clipboard events, browser extensions, AI chat transcripts — can be sent as structured data to your SIEM.",{"data":7401,"content":7402,"nodeType":673},{},[7403],{"data":7404,"marks":7405,"value":7406,"nodeType":543},{},[],"This gives you all the information you need to track your progress, check your compliance status, and identify trends in AI usage and risk across your business as you make progress toward your goal, armed with the right data you didn't have before.",{"data":7408,"content":7409,"nodeType":673},{},[7410],{"data":7411,"marks":7412,"value":7413,"nodeType":543},{},[],"The goal isn't perfect control over every AI interaction. It's having enough visibility to make informed decisions and enough control to enforce them, without intensifying the shadow AI usage problem you set out to solve. Push can help you get there.",{"data":7415,"content":7416,"nodeType":796},{},[],{"data":7418,"content":7419,"nodeType":673},{},[7420],{"data":7421,"marks":7422,"value":2882,"nodeType":543},{},[],{"data":7424,"content":7425,"nodeType":673},{},[7426],{"data":7427,"marks":7428,"value":2889,"nodeType":543},{},[],{"data":7430,"content":7431,"nodeType":673},{},[7432,7435,7442],{"data":7433,"marks":7434,"value":21,"nodeType":543},{},[],{"data":7436,"content":7437,"nodeType":695},{"uri":5926},[7438],{"data":7439,"marks":7440,"value":2904,"nodeType":543},{},[7441],{"type":722},{"data":7443,"marks":7444,"value":21,"nodeType":543},{},[],{"entries":7446},{"hyperlink":7447,"inline":7448,"block":7449},[],[],[7450,7458,7466,7472,7508,7515,7522,7528,7535,7562,7570,7584,7590,7596],{"sys":7451,"__typename":7452,"type":7453,"ctaText":7454,"buttonLabel":7455,"buttonColour":7456,"buttonUrl":7457},{"id":6740},"CtaWidget","Custom","Don't miss our upcoming webinar on Shadow AI and how to manage it in your organization.","Register Now","sunny orange","https://pushsecurity.com/webinar/shadow-ai",{"sys":7459,"__typename":1393,"title":7460,"caption":7461,"layoutMode":59,"file":7462},{"id":6776},"ai-sprawl-infographic","AI sprawl is worse than most organizations realize. ",{"url":7463,"width":7464,"height":7465},"https://images.ctfassets.net/y1cdw1ablpvd/7vCbQdyRkjLs5EmsjBBAQp/3bfb13e7ec19be76325cdc69297c48c3/ai-sprawl-infographic_2x__3_.png",1800,1192,{"sys":7467,"__typename":1393,"title":7468,"caption":7468,"layoutMode":59,"file":7469},{"id":6794},"Shadow AI visibility gaps using traditional tools",{"url":7470,"width":1408,"height":7471},"https://images.ctfassets.net/y1cdw1ablpvd/7HQl2qfsTiCwa2pRzCVqDE/d87180dd96358326097565d8a60e8591/image9.png",1125,{"sys":7473,"__typename":1332,"content":7474,"name":7507,"title":59},{"id":6812},{"json":7475},{"data":7476,"content":7477,"nodeType":669},{},[7478],{"data":7479,"content":7480,"nodeType":673},{},[7481,7485,7492,7496,7503],{"data":7482,"marks":7483,"value":7484,"nodeType":543},{},[],"Attackers are already exploiting this interconnectivity — from ",{"data":7486,"content":7487,"nodeType":695},{"uri":7276},[7488],{"data":7489,"marks":7490,"value":7491,"nodeType":543},{},[],"malvertising campaigns that impersonate AI tools",{"data":7493,"marks":7494,"value":7495,"nodeType":543},{},[]," to steal credentials, to ",{"data":7497,"content":7498,"nodeType":695},{"uri":907},[7499],{"data":7500,"marks":7501,"value":7502,"nodeType":543},{},[],"leveraging OAuth consent grants in supply chain attacks",{"data":7504,"marks":7505,"value":7506,"nodeType":543},{},[],". ","Shadow AI guide IB3",{"sys":7509,"__typename":1393,"title":7510,"caption":7510,"layoutMode":59,"file":7511},{"id":6922},"Push automatically discovers and inventories AI apps from browser login events.",{"url":7512,"width":7513,"height":7514},"https://images.ctfassets.net/y1cdw1ablpvd/5krEecjMxIJgVCa74A79xa/3bb94ca3b496e9486f94526d708e34d5/image8.png",1469,850,{"sys":7516,"__typename":1393,"title":7517,"caption":7517,"layoutMode":59,"file":7518},{"id":6967},"Push discovers AI browser extensions used by your users, across every browser.",{"url":7519,"width":7520,"height":7521},"https://images.ctfassets.net/y1cdw1ablpvd/14lMFifCBB9RwQpt101tNd/dabe2713e58e787175701ec0d35076ca/image2.png",1470,851,{"sys":7523,"__typename":1393,"title":7524,"caption":7524,"layoutMode":59,"file":7525},{"id":7026},"Push's four-step path to secure AI adoption",{"url":7526,"width":1408,"height":7527},"https://images.ctfassets.net/y1cdw1ablpvd/E1wuJW4EzmjeLTpnHHM9f/895569f4b215b1b7b82e697c40462cbc/image3.png",1013,{"sys":7529,"__typename":1393,"title":7530,"caption":7530,"layoutMode":59,"file":7531},{"id":7112},"Push in-browser warning screen guiding the user toward the preferred AI app",{"url":7532,"width":7533,"height":7534},"https://images.ctfassets.net/y1cdw1ablpvd/3ouLBkKhiEcBmY8V2XAaUz/71a3cb221adba7d2744ff8b02bab3891/image4.png",1435,738,{"sys":7536,"__typename":1332,"content":7537,"name":7561,"title":59},{"id":7125},{"json":7538},{"data":7539,"content":7540,"nodeType":669},{},[7541],{"data":7542,"content":7543,"nodeType":673},{},[7544,7548,7557],{"data":7545,"marks":7546,"value":7547,"nodeType":543},{},[],"“A published policy is not the same thing as people actually doing that,” explains Push customer Stephen Shkardoon, cybersecurity manager at Te Herenga Waka — Victoria University of Wellington in New Zealand, on one of the drivers for their ",{"data":7549,"content":7551,"nodeType":695},{"uri":7550},"https://pushsecurity.com/customer-stories/te-herenga-waka-victoria-university-of-wellington",[7552],{"data":7553,"marks":7554,"value":7556,"nodeType":543},{},[7555],{"type":722},"selection of Push Security",{"data":7558,"marks":7559,"value":7560,"nodeType":543},{},[]," to get control of AI usage at their organization.","Shadow AI guide IB1",{"sys":7563,"__typename":1393,"title":7564,"caption":7565,"layoutMode":59,"file":7566},{"id":7150},"Rules for AI app controls can be configured on a variety of conditions, including user groups, app attributes, and what mode of enforcement you wish to use.","Rules for AI app controls can be configured on a variety of conditions, including user groups, app attributes, and the mode of enforcement.",{"url":7567,"width":7568,"height":7569},"https://images.ctfassets.net/y1cdw1ablpvd/7czh28QGwm0ZStUmeWXBaq/667ee2441911fa4006a2ec75ebf727ea/image6.png",692,830,{"sys":7571,"__typename":1332,"content":7572,"name":7583,"title":59},{"id":7156},{"json":7573},{"data":7574,"content":7575,"nodeType":669},{},[7576],{"data":7577,"content":7578,"nodeType":673},{},[7579],{"data":7580,"marks":7581,"value":7582,"nodeType":543},{},[],"Push customers love the flexibility of this control compared to an SWG or CASB, which often rely on binary enforcement at the domain level only. ","Shadow AI guide IB2",{"sys":7585,"__typename":1393,"title":7586,"caption":7586,"layoutMode":59,"file":7587},{"id":7248},"Push blocks clipboard copy events that violate your policy.",{"url":7588,"width":1408,"height":7589},"https://images.ctfassets.net/y1cdw1ablpvd/jjUt4bChHcCWQJXqNzyQ8/c16974d72ef2bbc65689bf46bcb59e6f/image5.png",1295,{"sys":7591,"__typename":1393,"title":7592,"caption":7592,"layoutMode":59,"file":7593},{"id":7323},"Push can block unapproved MCP connection requests in real time.",{"url":7594,"width":1408,"height":7595},"https://images.ctfassets.net/y1cdw1ablpvd/wTAwk90bIA1B3XSkRf4M4/e4d3630af83501e6b4b05217fdf2e600/image1.png",1203,{"sys":7597,"__typename":1393,"title":7598,"caption":7598,"layoutMode":59,"file":7599},{"id":7345},"Push gives you prompt and response visibility and logging across all approved AI apps.",{"url":7600,"width":7601,"height":7602},"https://images.ctfassets.net/y1cdw1ablpvd/7o35qBXBYUNBlQdd9xPeKG/ec7b4cb88810e8dab4a20b7288fea17e/Prompt_Visibility__1_.png",2636,1730,{"items":7604},[7605,7618,7631,7651,7671,7691,7711,7731,7751,7771],{"answer":7606,"question":7617},{"json":7607},{"nodeType":669,"data":7608,"content":7609},{},[7610],{"nodeType":673,"data":7611,"content":7612},{},[7613],{"nodeType":543,"value":7614,"marks":7615,"data":7616},"Network monitoring tools see domain-level traffic but can't tell you what's actually happening inside an AI session — whether an employee is browsing a tool's marketing page or pasting source code into a prompt. IdP logs capture OAuth grants routed through the identity provider but miss AI tools accessed via direct signup or personal accounts. Browser-based security tools like Push Security monitor AI activity where it actually happens: inside the browser session. Push captures login events, clipboard pastes, file uploads, extension installations, and OAuth grants, providing structured telemetry on what data is moving into which AI tools, through which accounts, and whether those accounts are corporate or personal.",[],{},"How do you monitor what employees are doing with AI tools?",{"answer":7619,"question":7630},{"json":7620},{"nodeType":669,"data":7621,"content":7622},{},[7623],{"nodeType":673,"data":7624,"content":7625},{},[7626],{"nodeType":543,"value":7627,"marks":7628,"data":7629},"Binary allow/block decisions — whether enforced through a SWG, CASB, or enterprise browser — treat every AI interaction as equivalent, which pushes employees toward tools you can't see at all. Graduated enforcement offers a middle path. Push Security lets teams start with monitoring to build an accurate picture of AI usage, then introduce in-browser prompts that explain why a tool hasn't been approved and direct employees toward sanctioned alternatives, before applying hard blocks only where the data sensitivity or tool risk justifies it. Controls are configurable per user group, and new AI tools automatically inherit governance rules through automatic categorization — so enforcement keeps pace with the landscape without manual blocklist updates.",[],{},"How do you restrict AI usage without blocking everything?",{"answer":7632,"question":7650},{"json":7633},{"nodeType":669,"data":7634,"content":7635},{},[7636,7643],{"nodeType":673,"data":7637,"content":7638},{},[7639],{"nodeType":543,"value":7640,"marks":7641,"data":7642},"Network monitoring tools, IdP logs, and endpoint agents each catch a slice of shadow AI but miss entire categories. SWGs see domain traffic but can't confirm whether someone authenticated or what they did after login. IdPs capture OAuth grants routed through the identity provider but miss AI tools accessed via direct signup or personal accounts. EDR is blind to browser-layer activity entirely. ",[],{},{"nodeType":673,"data":7644,"content":7645},{},[7646],{"nodeType":543,"value":7647,"marks":7648,"data":7649},"Browser-based security tools like Push Security identify AI tools from actual login events, catching the four categories other tools miss: unapproved AI apps, personal accounts on approved tools, AI browser extensions with broad permissions, and OAuth integrations granting persistent API access to corporate systems. Each discovered app is automatically categorized and enriched with authentication context — SSO vs. password, MFA status, corporate vs. personal account — so security teams can assess actual risk rather than treating every AI tool as equivalent.",[],{},"How do you discover what AI tools employees are using?",{"answer":7652,"question":7670},{"json":7653},{"nodeType":669,"data":7654,"content":7655},{},[7656,7663],{"nodeType":673,"data":7657,"content":7658},{},[7659],{"nodeType":543,"value":7660,"marks":7661,"data":7662},"This is a gap that traditional DLP architectures weren't designed for. Network DLP and SWGs can't intercept clipboard pastes into AI prompts because there's no network event to inspect — the data moves from the clipboard to the browser DOM without crossing the wire. Endpoint DLP sees file-system operations but not in-browser activity. Browser-based controls operate where the paste actually happens. ",[],{},{"nodeType":673,"data":7664,"content":7665},{},[7666],{"nodeType":543,"value":7667,"marks":7668,"data":7669},"Push Security matches clipboard content against patterns for credentials, API keys, credit card numbers, and custom content rules, then offers the employee a redacted version so they can continue working without exposing the actual sensitive data. The same approach extends to file uploads and downloads, covering the exfiltration paths that network and endpoint DLP leave open.",[],{},"How do you prevent sensitive data from being pasted into AI tools?",{"answer":7672,"question":7690},{"json":7673},{"nodeType":669,"data":7674,"content":7675},{},[7676,7683],{"nodeType":673,"data":7677,"content":7678},{},[7679],{"nodeType":543,"value":7680,"marks":7681,"data":7682},"Policy documents distributed during onboarding don't change behavior at the moment someone reaches for an unapproved AI tool. SWGs can block a domain, but they can't explain why or point to an approved alternative — the employee sees an error page. ",[],{},{"nodeType":673,"data":7684,"content":7685},{},[7686],{"nodeType":543,"value":7687,"marks":7688,"data":7689},"Enterprise browsers like Push Security can deliver policy enforcement at the point of decision: when an employee navigates to an unsanctioned AI tool, an in-browser message explains why the tool hasn't been approved and directs them to approved alternatives. Controls are configurable per user group — and new AI tools automatically inherit governance rules through automatic categorization, without manual blocklist updates.",[],{},"How do you enforce an AI acceptable use policy in real time?",{"answer":7692,"question":7710},{"json":7693},{"nodeType":669,"data":7694,"content":7695},{},[7696,7703],{"nodeType":673,"data":7697,"content":7698},{},[7699],{"nodeType":543,"value":7700,"marks":7701,"data":7702},"No single traditional tool covers all aspects of shadow AI (apps, tenants, integrations, extensions) and the user interaction with those categories of tool. SWGs and CASBs see domain-level traffic but can't identify personal account usage, extension activity, or clipboard pastes into AI prompts. IdPs capture federated logins but miss direct signups and personal accounts entirely. EDR doesn't see browser-layer activity. DSPM monitors data at rest in cloud storage but not data in motion through browser sessions. ",[],{},{"nodeType":673,"data":7704,"content":7705},{},[7706],{"nodeType":543,"value":7707,"marks":7708,"data":7709},"Most organizations will need browser-layer visibility alongside their existing stack — not as a replacement, but to close the gaps those tools weren't designed to address. Tools like Push Security operate at the layer where AI activity actually happens, covering all shadow AI categories with graduated enforcement (monitor, warn, block), per-user-group policies, and telemetry on authentication methods, clipboard events, file uploads, and OAuth grants. ",[],{},"What tools do you need to manage shadow AI?",{"answer":7712,"question":7730},{"json":7713},{"nodeType":669,"data":7714,"content":7715},{},[7716,7723],{"nodeType":673,"data":7717,"content":7718},{},[7719],{"nodeType":543,"value":7720,"marks":7721,"data":7722},"AI browser extensions are a blind spot for most security stacks. Endpoint management tools may detect that an extension is installed but typically can't evaluate what permissions it has requested or whether those permissions create data exfiltration risk. SWGs and CASBs don't see extension activity at all — extensions operate within the browser, not over the network. ",[],{},{"nodeType":673,"data":7724,"content":7725},{},[7726],{"nodeType":543,"value":7727,"marks":7728,"data":7729},"Push Security inventories every AI-related extension installed across the workforce, surfaces the specific permissions each extension has requested (access to page content, browsing history, clipboard data), and identifies permission combinations that could enable account takeover or data exfiltration. Security teams can then apply monitor, warn, or block enforcement to extension categories — and new extensions automatically inherit governance rules without maintaining manual allowlists that go stale as new AI extensions appear daily.",[],{},"How do I stop employees installing AI browser extensions?",{"answer":7732,"question":7750},{"json":7733},{"nodeType":669,"data":7734,"content":7735},{},[7736,7743],{"nodeType":673,"data":7737,"content":7738},{},[7739],{"nodeType":543,"value":7740,"marks":7741,"data":7742},"Point-in-time audits — whether run through an IdP, a CASB, or manual surveys — tell you what was true when you ran them. AI tool adoption changes weekly; Gartner projects 150,000 AI agents per Fortune 500 enterprise by 2028. SWGs can log new domains but can't classify them or apply governance rules automatically. ",[],{},{"nodeType":673,"data":7744,"content":7745},{},[7746],{"nodeType":543,"value":7747,"marks":7748,"data":7749},"Push Security discovers new AI tools as employees start using them: when someone logs in to a new AI app, Push identifies it from the login event, automatically categorizes it, and applies the organization's existing governance rules without manual intervention. All AI-related telemetry — app access, file uploads, clipboard events, extension activity — streams as structured data to the customer's SIEM, providing the material for governance dashboards and compliance reporting that stays current as the landscape shifts.",[],{},"How do you get visibility into AI tool sprawl?",{"answer":7752,"question":7770},{"json":7753},{"nodeType":669,"data":7754,"content":7755},{},[7756,7763],{"nodeType":673,"data":7757,"content":7758},{},[7759],{"nodeType":543,"value":7760,"marks":7761,"data":7762},"AI visibility means knowing which AI tools employees are using, how they're accessing them, and what data flows into those tools. AI control is the ability to enforce rules on that usage — blocking unapproved tools, restricting data flows, requiring approved accounts. AI governance is the broader program that encompasses both: defining acceptable use policies, establishing risk frameworks for evaluating new tools, and building the organizational processes that turn visibility and control into sustained security outcomes. ",[],{},{"nodeType":673,"data":7764,"content":7765},{},[7766],{"nodeType":543,"value":7767,"marks":7768,"data":7769},"Most organizations that struggle with AI governance have a visibility problem first — they're trying to write policies for tools they don't know their employees are using. But visibility without control is just watching the problem happen. Push Security provides both: discovery and monitoring across all four categories of shadow AI, plus graduated enforcement controls that let you apply different responses based on the risk profile of each tool, account, and data flow, at the point of interaction in the browser for real-time enforcement.",[],{},"What is the difference between AI governance, AI visibility, and AI control?",{"answer":7772,"question":7790},{"json":7773},{"nodeType":669,"data":7774,"content":7775},{},[7776,7783],{"nodeType":673,"data":7777,"content":7778},{},[7779],{"nodeType":543,"value":7780,"marks":7781,"data":7782},"Data Security Posture Management (DSPM) tools monitor data at rest in cloud storage and SaaS applications, identifying misconfigurations, overly permissive access, and sensitive data exposure. They don't monitor data in motion through browser sessions — which is the primary path for shadow AI risk. ",[],{},{"nodeType":673,"data":7784,"content":7785},{},[7786],{"nodeType":543,"value":7787,"marks":7788,"data":7789},"When an employee pastes source code into an AI prompt or uploads a customer spreadsheet to an unapproved AI tool, that data movement happens entirely inside the browser and never touches the cloud storage layer that DSPM tools monitor. DSPM and browser security are complementary: DSPM secures data where it is stored, while browser-layer tools like Push Security secure data where it moves.",[],{},"Does Data Security Posture Management (DSPM) prevent shadow AI?","Shadow AI discovery and governance: Frequently asked questions",{},"How to discover AI, enforce policies, and prevent data loss","guide","2026-08-13T00:00:00.000Z",{"items":7797},[7798,8476,9357],{"__typename":1608,"sys":7799,"content":7801,"title":8458,"synopsis":8459,"hashTags":59,"publishedDate":8460,"slug":8461,"tagsCollection":8462,"authorsCollection":8472},{"id":7800},"4NY2NbkAPucFOJY45yrrrE",{"json":7802},{"data":7803,"content":7804,"nodeType":669},{},[7805,7812,7819,7826,7832,7835,7843,7850,7883,7890,7915,7921,7924,7932,7939,7947,7989,7995,8002,8007,8010,8018,8025,8033,8040,8047,8063,8071,8096,8103,8109,8116,8124,8139,8167,8173,8191,8197,8205,8212,8237,8244,8251,8258,8264,8267,8275,8282,8289,8308,8316,8323,8331,8354,8366,8372,8375,8383,8390,8397,8404,8424,8427,8433,8439],{"data":7806,"content":7807,"nodeType":673},{},[7808],{"data":7809,"marks":7810,"value":7811,"nodeType":543},{},[],"Employees have been self-adopting apps, creating unmanaged accounts, and introducing third-party software dependencies into their organizations for years, and the core problem hasn't changed: unmanaged software expanding your attack surface without your knowledge.",{"data":7813,"content":7814,"nodeType":673},{},[7815],{"data":7816,"marks":7817,"value":7818,"nodeType":543},{},[],"But the rate at which employees are signing up for AI tools is unprecedented, and the depth of interconnectivity those tools demand is fundamentally different from traditional shadow SaaS. ",{"data":7820,"content":7821,"nodeType":673},{},[7822],{"data":7823,"marks":7824,"value":7825,"nodeType":543},{},[],"AI tools aren't just standalone apps that employees sign into — they're increasingly used as agents that drive other applications, pulling data from one platform, acting on another — they are becoming a core that other apps are integrating to, and that users are integrating with their wider SaaS stack. It’s becoming a focal integration point for app access and functionality in a way that's more comparable to an enterprise cloud platform than a typical SaaS tool. ",{"data":7827,"content":7831,"nodeType":787},{"target":7828},{"sys":7829},{"id":7830,"type":792,"linkType":793},"2Vxb48M5JN9Jdy8BG6nbUJ",[],{"data":7833,"content":7834,"nodeType":796},{},[],{"data":7836,"content":7837,"nodeType":800},{},[7838],{"data":7839,"marks":7840,"value":7842,"nodeType":543},{},[7841],{"type":749},"What is shadow AI? A quick 101",{"data":7844,"content":7845,"nodeType":673},{},[7846],{"data":7847,"marks":7848,"value":7849,"nodeType":543},{},[],"Shadow AI is any use of AI tools, services, or integrations that happens outside an organization's security governance and visibility. Shadow AI risks cut in two directions:",{"data":7851,"content":7852,"nodeType":2727},{},[7853,7868],{"data":7854,"content":7855,"nodeType":2639},{},[7856],{"data":7857,"content":7858,"nodeType":673},{},[7859,7864],{"data":7860,"marks":7861,"value":7863,"nodeType":543},{},[7862],{"type":749},"Data exposure:",{"data":7865,"marks":7866,"value":7867,"nodeType":543},{},[]," source code, credentials, internal documents, and customer data routinely get pasted into AI prompts or uploaded as context, and once shared, that data is outside the organization's control. ",{"data":7869,"content":7870,"nodeType":2639},{},[7871],{"data":7872,"content":7873,"nodeType":673},{},[7874,7879],{"data":7875,"marks":7876,"value":7878,"nodeType":543},{},[7877],{"type":749},"Attack surface:",{"data":7880,"marks":7881,"value":7882,"nodeType":543},{},[]," Every shadow AI app is an unmanaged identity with credentials that can be phished or stuffed, OAuth grants that give persistent API access to corporate systems, and browser extensions that can be compromised in supply chain attacks. ",{"data":7884,"content":7885,"nodeType":673},{},[7886],{"data":7887,"marks":7888,"value":7889,"nodeType":543},{},[],"AI tools increasingly function as hubs, connected via OAuth and MCP to email, cloud storage, code repositories, and other high-value systems. Every app connection an employee grants turns that AI tool into a node in a web of interconnected services, which means the more you hook in, the larger the attack surface across all the connected apps — and the greater the blast radius if the account used to access the AI tool is compromised.",{"data":7891,"content":7892,"nodeType":673},{},[7893,7897,7903,7906,7912],{"data":7894,"marks":7895,"value":7896,"nodeType":543},{},[],"Each integration creates a persistent trust relationship that survives password resets and MFA changes. Compromise a single AI app and an attacker inherits whatever access the employee granted it, turning one ungoverned tool into a pivot point across the SaaS estate. Attackers are already exploiting this interconnectivity — from ",{"data":7898,"content":7899,"nodeType":695},{"uri":7276},[7900],{"data":7901,"marks":7902,"value":7491,"nodeType":543},{},[],{"data":7904,"marks":7905,"value":7495,"nodeType":543},{},[],{"data":7907,"content":7908,"nodeType":695},{"uri":907},[7909],{"data":7910,"marks":7911,"value":7502,"nodeType":543},{},[],{"data":7913,"marks":7914,"value":7506,"nodeType":543},{},[],{"data":7916,"content":7920,"nodeType":787},{"target":7917},{"sys":7918},{"id":7919,"type":792,"linkType":793},"1BWCa7AHCMlYw7XgPLx3h7",[],{"data":7922,"content":7923,"nodeType":796},{},[],{"data":7925,"content":7926,"nodeType":800},{},[7927],{"data":7928,"marks":7929,"value":7931,"nodeType":543},{},[7930],{"type":749},"The state of shadow AI, using Push data",{"data":7933,"content":7934,"nodeType":673},{},[7935],{"data":7936,"marks":7937,"value":7938,"nodeType":543},{},[],"We analyzed a snapshot of AI activity across Push customers during an average week in April 2026. We wanted to make sure it captured actual activity, not just historical data on apps that were added once and no longer used.",{"data":7940,"content":7941,"nodeType":673},{},[7942],{"data":7943,"marks":7944,"value":7946,"nodeType":543},{},[7945],{"type":749},"The numbers paint a picture that most security teams will find uncomfortable.",{"data":7948,"content":7949,"nodeType":673},{},[7950,7954,7959,7963,7968,7971,7976,7980,7985],{"data":7951,"marks":7952,"value":7953,"nodeType":543},{},[],"The average organization has ",{"data":7955,"marks":7956,"value":7958,"nodeType":543},{},[7957],{"type":749},"16 unique AI apps",{"data":7960,"marks":7961,"value":7962,"nodeType":543},{},[]," in active use, ",{"data":7964,"marks":7965,"value":7967,"nodeType":543},{},[7966],{"type":749},"17 unique AI browser extensions",{"data":7969,"marks":7970,"value":3232,"nodeType":543},{},[],{"data":7972,"marks":7973,"value":7975,"nodeType":543},{},[7974],{"type":749},"17 unique AI OAuth integrations",{"data":7977,"marks":7978,"value":7979,"nodeType":543},{},[]," connected into just Google Workspace and Microsoft 365 — with some organizations reaching as high as 40 unique AI apps, 163 AI extensions, and 55 OAuth connections to AI apps respectively. At the other end, the smallest organization with the ",{"data":7981,"marks":7982,"value":7984,"nodeType":543},{},[7983],{"type":739},"lowest",{"data":7986,"marks":7987,"value":7988,"nodeType":543},{},[]," adoption level is actively using two. ",{"data":7990,"content":7994,"nodeType":787},{"target":7991},{"sys":7992},{"id":7993,"type":792,"linkType":793},"2AfeiHub5kyZN8wuf6CJch",[],{"data":7996,"content":7997,"nodeType":673},{},[7998],{"data":7999,"marks":8000,"value":8001,"nodeType":543},{},[],"If most organizations have sanctioned one or two core AI assistants/platforms for business use, the gap between what's approved and what's actually happening is significant.",{"data":8003,"content":8006,"nodeType":787},{"target":8004},{"sys":8005},{"id":6776,"type":792,"linkType":793},[],{"data":8008,"content":8009,"nodeType":796},{},[],{"data":8011,"content":8012,"nodeType":800},{},[8013],{"data":8014,"marks":8015,"value":8017,"nodeType":543},{},[8016],{"type":749},"Understanding the four categories of shadow AI",{"data":8019,"content":8020,"nodeType":673},{},[8021],{"data":8022,"marks":8023,"value":8024,"nodeType":543},{},[],"Shadow SaaS has always been a problem, but in the context of AI apps there are four categories of shadow IT that security teams need to understand, because each one introduces a different kind of risk and requires a different approach to tackling it.",{"data":8026,"content":8027,"nodeType":829},{},[8028],{"data":8029,"marks":8030,"value":8032,"nodeType":543},{},[8031],{"type":749},"Shadow AI apps",{"data":8034,"content":8035,"nodeType":673},{},[8036],{"data":8037,"marks":8038,"value":8039,"nodeType":543},{},[],"Shadow apps are AI tools that employees have signed up to and are using for business purposes without approval. This is the most visible dimension of the problem, and the one most people think of when they hear \"shadow AI\" — an employee pastes sensitive internal documents into ChatGPT, uploads confidential files to an AI assistant, or uses an unapproved coding tool to generate production code.",{"data":8041,"content":8042,"nodeType":673},{},[8043],{"data":8044,"marks":8045,"value":8046,"nodeType":543},{},[],"All of that is sensitive data leaving the organization through channels the security team can't see - and often accessible using personal accounts that can be compromised on personal devices or workstations. ",{"data":8048,"content":8049,"nodeType":673},{},[8050,8054,8059],{"data":8051,"marks":8052,"value":8053,"nodeType":543},{},[],"The 2026 DBIR's data loss prevention analysis underscores the scale — shadow AI is now the ",{"data":8055,"marks":8056,"value":8058,"nodeType":543},{},[8057],{"type":749},"third most common non-malicious insider action",{"data":8060,"marks":8061,"value":8062,"nodeType":543},{},[]," in DLP data, a 4x increase year-over-year. Across 858,000+ DLP events targeting GenAI tools, the most common data types being submitted were source code (28%), images (16%), structured data (14%), documents (13%), and PDFs (10%). That's not employees asking ChatGPT to fix their grammar — it's core intellectual property, production code, and internal documentation flowing into platforms the security team has no visibility into. But shadow apps themselves are only the most obvious part of the problem.",{"data":8064,"content":8065,"nodeType":829},{},[8066],{"data":8067,"marks":8068,"value":8070,"nodeType":543},{},[8069],{"type":749},"Shadow tenants",{"data":8072,"content":8073,"nodeType":673},{},[8074,8078,8083,8087,8092],{"data":8075,"marks":8076,"value":8077,"nodeType":543},{},[],"Even when an organization has approved an AI tool — say, an enterprise ChatGPT deployment — employees frequently access the same app with personal accounts, creating shadow tenants that sit entirely outside organizational control. The DBIR found that ",{"data":8079,"marks":8080,"value":8082,"nodeType":543},{},[8081],{"type":749},"67% of GenAI users on corporate devices are using non-corporate accounts",{"data":8084,"marks":8085,"value":8086,"nodeType":543},{},[],", and our own data shows that ",{"data":8088,"marks":8089,"value":8091,"nodeType":543},{},[8090],{"type":749},"38% of file uploads to AI tools are made from shadow accounts",{"data":8093,"marks":8094,"value":8095,"nodeType":543},{},[]," rather than approved organizational ones.",{"data":8097,"content":8098,"nodeType":673},{},[8099],{"data":8100,"marks":8101,"value":8102,"nodeType":543},{},[],"When an organization approves Claude, ChatGPT, or another core AI platform, you typically also approve the OAuth integration and browser extension for core apps (e.g. M365, Google Workspace, and so on). When that integration is approved, it is approved for all tenants — not just your corporate tenant. ",{"data":8104,"content":8108,"nodeType":787},{"target":8105},{"sys":8106},{"id":8107,"type":792,"linkType":793},"3Rvw0n28AYIM3FQXtHyafD",[],{"data":8110,"content":8111,"nodeType":673},{},[8112],{"data":8113,"marks":8114,"value":8115,"nodeType":543},{},[],"This means that even if you've deployed enterprise controls around your sanctioned AI tools — DLP policies, retention settings, admin oversight — more than a third of the file uploads hitting AI tools are bypassing those controls entirely because they're happening through personal accounts on corporate devices.",{"data":8117,"content":8118,"nodeType":829},{},[8119],{"data":8120,"marks":8121,"value":8123,"nodeType":543},{},[8122],{"type":749},"Shadow extensions",{"data":8125,"content":8126,"nodeType":673},{},[8127,8131,8135],{"data":8128,"marks":8129,"value":8130,"nodeType":543},{},[],"Many AI tools come with a browser extension counterpart, and there's a large ecosystem of third-party AI extensions that offer everything from writing assistance to automated data extraction. The average organization in our dataset has ",{"data":8132,"marks":8133,"value":7967,"nodeType":543},{},[8134],{"type":749},{"data":8136,"marks":8137,"value":8138,"nodeType":543},{},[]," deployed across its workforce, with the highest we observed reaching 163 — and since each of those average 17 different extensions may be installed by multiple employees, the actual number of individual extension installs across the organization is much higher still.",{"data":8140,"content":8141,"nodeType":673},{},[8142,8146,8154,8158,8163],{"data":8143,"marks":8144,"value":8145,"nodeType":543},{},[],"The extension dimension is particularly concerning because most extensions operate with significant privilege inside the browser — they can read and modify page content, access cookies and session tokens, and interact with virtually every web application an employee uses. As we detailed in our recent analysis of ",{"data":8147,"content":8149,"nodeType":695},{"uri":8148},"https://pushsecurity.com/blog/why-browser-extension-risk-scoring-wont-predict-your-next-breach/",[8150],{"data":8151,"marks":8152,"value":8153,"nodeType":543},{},[],"browser extension risk scoring",{"data":8155,"marks":8156,"value":8157,"nodeType":543},{},[],", at least ",{"data":8159,"marks":8160,"value":8162,"nodeType":543},{},[8161],{"type":749},"46.76% of all extensions across Push customers have the permission combinations needed to perform account takeover with no user interaction",{"data":8164,"marks":8165,"value":8166,"nodeType":543},{},[],", and the extensions involved in every major supply chain breach of the past 18 months scored as normal or low-risk beforehand.",{"data":8168,"content":8172,"nodeType":787},{"target":8169},{"sys":8170},{"id":8171,"type":792,"linkType":793},"3z4JOMALI52xoOXZkzPHLD",[],{"data":8174,"content":8175,"nodeType":673},{},[8176,8180,8187],{"data":8177,"marks":8178,"value":8179,"nodeType":543},{},[],"AI extensions add a specific wrinkle to this problem: many are branded to look like official companions to well-known AI tools but are actually third-party creations with no affiliation to the original vendor. They're not necessarily malicious at the point of installation, but they're exactly the kind of extension that's likely to be ",{"data":8181,"content":8182,"nodeType":695},{"uri":8148},[8183],{"data":8184,"marks":8185,"value":8186,"nodeType":543},{},[],"acquired and weaponized",{"data":8188,"marks":8189,"value":8190,"nodeType":543},{},[]," down the line — and in the meantime, they're collecting data that their permissions entitle them to (which, in most cases, means everything the user can see in their browser).",{"data":8192,"content":8196,"nodeType":787},{"target":8193},{"sys":8194},{"id":8195,"type":792,"linkType":793},"6K3z67rohss6H3lCsSn12B",[],{"data":8198,"content":8199,"nodeType":829},{},[8200],{"data":8201,"marks":8202,"value":8204,"nodeType":543},{},[8203],{"type":749},"Shadow integrations",{"data":8206,"content":8207,"nodeType":673},{},[8208],{"data":8209,"marks":8210,"value":8211,"nodeType":543},{},[],"The fourth dimension — and arguably the most dangerous — is shadow integrations: OAuth connections between AI tools and core enterprise apps that aren't known or approved by the security team. Even if an organization has approved an AI tool for standalone use, plugging that tool directly into Google Workspace, Microsoft 365, Salesforce, or any other one of the dozen or so SaaS apps in a typical user’s work stack is a fundamentally different risk decision, because it creates a persistent, programmatic bridge between your environment and a third party.",{"data":8213,"content":8214,"nodeType":673},{},[8215,8219,8224,8228,8233],{"data":8216,"marks":8217,"value":8218,"nodeType":543},{},[],"On average, we see ",{"data":8220,"marks":8221,"value":8223,"nodeType":543},{},[8222],{"type":749},"17 unique AI app OAuth integrations per organization",{"data":8225,"marks":8226,"value":8227,"nodeType":543},{},[]," in ",{"data":8229,"marks":8230,"value":8232,"nodeType":543},{},[8231],{"type":739},"just",{"data":8234,"marks":8235,"value":8236,"nodeType":543},{},[]," Google Workspace and Microsoft 365 (to be clear: this number excludes the dozens of downstream apps the AI assistants are integrated with as well), with the highest reaching 55. Each of those represents a unique AI product that has been granted OAuth access — the total number of individual consent grants across users is larger, because popular integrations get authorized by multiple employees independently.",{"data":8238,"content":8239,"nodeType":673},{},[8240],{"data":8241,"marks":8242,"value":8243,"nodeType":543},{},[],"The actual number of AI-related OAuth connections across the full SaaS estate is considerably higher again, because AI tools that automate workflows need to be connected to be useful — pulling data from one app, analyzing it in another, presenting results in a third.",{"data":8245,"content":8246,"nodeType":673},{},[8247],{"data":8248,"marks":8249,"value":8250,"nodeType":543},{},[],"MCP connections use OAuth to achieve this interconnectivity in the same way, and AI coding agents create a particularly concentrated version of the risk: a single agent configuration can hold OAuth tokens for Jira, Confluence, Salesforce, GitHub, and more, meaning that compromising one agent — whether through prompt injection, a malicious repository config, or a supply chain attack on an MCP server — yields persistent, broadly scoped tokens for every service it was connected to, tokens that survive session restarts and generate audit log entries indistinguishable from legitimate user activity.",{"data":8252,"content":8253,"nodeType":673},{},[8254],{"data":8255,"marks":8256,"value":8257,"nodeType":543},{},[],"It's also worth noting that OAuth blast radius is almost always larger than organizations expect. A single well-permissioned user can expose secrets, dashboards, and internal tooling without tenant-wide admin access. And every new AI tool an employee connects makes the web of abusable permissions a little wider.",{"data":8259,"content":8263,"nodeType":787},{"target":8260},{"sys":8261},{"id":8262,"type":792,"linkType":793},"4SnzJ9T93gHzFIUASx7Yb3",[],{"data":8265,"content":8266,"nodeType":796},{},[],{"data":8268,"content":8269,"nodeType":800},{},[8270],{"data":8271,"marks":8272,"value":8274,"nodeType":543},{},[8273],{"type":749},"Why shadow AI needs a different solution to shadow SaaS",{"data":8276,"content":8277,"nodeType":673},{},[8278],{"data":8279,"marks":8280,"value":8281,"nodeType":543},{},[],"The reason it's worth distinguishing between these four dimensions isn't academic. Each one requires a different control, and addressing one doesn't solve the others.",{"data":8283,"content":8284,"nodeType":673},{},[8285],{"data":8286,"marks":8287,"value":8288,"nodeType":543},{},[],"Blocking unsanctioned AI apps does nothing for the personal accounts accessing approved ones, and neither addresses the average 17 different AI extensions running with broad browser permissions, let alone the dozens of OAuth integrations that have already been granted persistent access to core enterprise apps — and even auditing OAuth in Google Workspace and Microsoft 365, where the controls are relatively mature, leaves the broader SaaS estate unaddressed, where admin tooling is inconsistent and visibility is limited.",{"data":8290,"content":8291,"nodeType":673},{},[8292,8296,8304],{"data":8293,"marks":8294,"value":8295,"nodeType":543},{},[],"The tooling gap compounds the policy gap. ",{"data":8297,"content":8299,"nodeType":695},{"uri":8298},"https://pushsecurity.com/blog/7-things-omdias-latest-report-tells-us-about-the-secure-enterprise-browser-market/",[8300],{"data":8301,"marks":8302,"value":8303,"nodeType":543},{},[],"Omdia found",{"data":8305,"marks":8306,"value":8307,"nodeType":543},{},[]," that 58% of organizations rely on secure web gateways to secure GenAI usage — but an SWG can tell you that a user visited ChatGPT, not whether they pasted your source code into the prompt. That link between knowing where data went and knowing what the user actually did is the fundamental visibility gap that makes GenAI policies unenforceable without browser-layer tooling.",{"data":8309,"content":8310,"nodeType":829},{},[8311],{"data":8312,"marks":8313,"value":8315,"nodeType":543},{},[8314],{"type":749},"Advice for security teams",{"data":8317,"content":8318,"nodeType":673},{},[8319],{"data":8320,"marks":8321,"value":8322,"nodeType":543},{},[],"The principles behind managing shadow AI are the same ones that have governed shadow SaaS and software supply chain management for years: default-deny where feasible, comprehensive inventory where it isn't, and continuous monitoring for changes that signal increased risk. But it's vital that teams act fast to stop the snowball.",{"data":8324,"content":8325,"nodeType":673},{},[8326],{"data":8327,"marks":8328,"value":8330,"nodeType":543},{},[8329],{"type":749},"That starts with visibility into which AI tools employees are actually using and which accounts they're using to access them — without that baseline, every other control is built on assumptions.",{"data":8332,"content":8333,"nodeType":673},{},[8334,8339,8343,8350],{"data":8335,"marks":8336,"value":8338,"nodeType":543},{},[8337],{"type":749},"Extensions",{"data":8340,"marks":8341,"value":8342,"nodeType":543},{},[]," need the same ",{"data":8344,"content":8345,"nodeType":695},{"uri":8148},[8346],{"data":8347,"marks":8348,"value":8349,"nodeType":543},{},[],"default-deny allowlisting approach",{"data":8351,"marks":8352,"value":8353,"nodeType":543},{},[]," that has been best practice for software management elsewhere: build a complete inventory, allowlist what's vetted, block everything else, and monitor the approved set for changes that precede weaponization.",{"data":8355,"content":8356,"nodeType":673},{},[8357,8362],{"data":8358,"marks":8359,"value":8361,"nodeType":543},{},[8360],{"type":749},"OAuth",{"data":8363,"marks":8364,"value":8365,"nodeType":543},{},[]," demands the most urgency, because each unmanaged integration is a persistent trust relationship that survives password resets and MFA changes — adopt default-deny for consent grants in your primary enterprise apps, routinely audit what's already connected, and critically extend that visibility beyond Google and Microsoft to the broader SaaS estate where the controls are weaker and the sprawl is harder to track.",{"data":8367,"content":8371,"nodeType":787},{"target":8368},{"sys":8369},{"id":8370,"type":792,"linkType":793},"3RFLFtJtDXvhTz1mVztfV9",[],{"data":8373,"content":8374,"nodeType":796},{},[],{"data":8376,"content":8377,"nodeType":800},{},[8378],{"data":8379,"marks":8380,"value":8382,"nodeType":543},{},[8381],{"type":749},"Browser visibility and control is key to de-risking AI adoption",{"data":8384,"content":8385,"nodeType":673},{},[8386],{"data":8387,"marks":8388,"value":8389,"nodeType":543},{},[],"AI usage is fundamentally browser-based activity — every LLM interaction, every prompt containing sensitive data, every AI agent authorization, every OAuth consent grant happens inside a browser session — which makes the browser the natural control point for AI governance across the workforce. ",{"data":8391,"content":8392,"nodeType":673},{},[8393],{"data":8394,"marks":8395,"value":8396,"nodeType":543},{},[],"Push tracks AI app usage and login security across the workforce, inventories and controls AI browser extensions, monitors and blocks OAuth consent flows across any app (not just the primary enterprise platforms), and gives security teams a single view of the full shadow AI picture across all four dimensions.",{"data":8398,"content":8399,"nodeType":673},{},[8400],{"data":8401,"marks":8402,"value":8403,"nodeType":543},{},[],"Shadow AI isn't a problem that will age well if ignored. Every week that passes without visibility adds more apps, more extensions, more integrations, and more potential breach paths into the environment — and as the Vercel breach demonstrated, it only takes one forgotten OAuth grant to turn an employee's idle curiosity into an organization-wide incident.",{"data":8405,"content":8406,"nodeType":673},{},[8407,8411,8420],{"data":8408,"marks":8409,"value":8410,"nodeType":543},{},[],"Learn more about how you can tackle ",{"data":8412,"content":8414,"nodeType":695},{"uri":8413},"https://pushsecurity.com/uc/shadow-ai",[8415],{"data":8416,"marks":8417,"value":8419,"nodeType":543},{},[8418],{"type":722},"Shadow AI",{"data":8421,"marks":8422,"value":8423,"nodeType":543},{},[]," with Push. ",{"data":8425,"content":8426,"nodeType":796},{},[],{"data":8428,"content":8429,"nodeType":673},{},[8430],{"data":8431,"marks":8432,"value":2882,"nodeType":543},{},[],{"data":8434,"content":8435,"nodeType":673},{},[8436],{"data":8437,"marks":8438,"value":2889,"nodeType":543},{},[],{"data":8440,"content":8441,"nodeType":673},{},[8442,8446,8454],{"data":8443,"marks":8444,"value":8445,"nodeType":543},{},[],"Book a ",{"data":8447,"content":8448,"nodeType":695},{"uri":5926},[8449],{"data":8450,"marks":8451,"value":8453,"nodeType":543},{},[8452],{"type":722},"live demo",{"data":8455,"marks":8456,"value":8457,"nodeType":543},{},[]," to learn more.","Shadow AI: what Push data reveals about the scale of the problem","Push telemetry shows the average organization has 16 AI apps, 17 AI browser extensions, and 17 AI OAuth integrations in use. Here's what it means for security.","2026-05-28T00:00:00.000Z","what-push-data-reveals-about-the-state-of-shadow-ai",{"items":8463},[8464,8468],{"sys":8465,"name":8467},{"id":8466},"1gZi8NrRy2v9OqPV7C4dwD","Risk management",{"sys":8469,"name":8471},{"id":8470},"3pjES4THCIfSAwhGdNwBcy","Browser security",{"items":8473},[8474],{"fullName":2925,"firstName":2926,"jobTitle":2927,"profilePicture":8475},{"url":2929},{"__typename":1608,"sys":8477,"content":8479,"title":9339,"synopsis":9340,"hashTags":59,"publishedDate":9341,"slug":9342,"tagsCollection":9343,"authorsCollection":9349},{"id":8478},"6Xn377JQfbDz49Np74cbGl",{"json":8480},{"data":8481,"content":8482,"nodeType":669},{},[8483,8490,8520,8538,8543,8550,8566,8569,8577,8595,8658,8665,8671,8678,8761,8768,8775,8791,8794,8802,8809,8816,8824,8831,8843,8849,8856,8863,8870,8873,8881,8897,8913,8920,8927,8934,8955,9040,9047,9054,9057,9065,9081,9088,9095,9103,9106,9114,9132,9139,9146,9179,9186,9193,9196,9204,9211,9223,9229,9241,9253,9259,9271,9293,9300,9303,9310,9317,9323],{"data":8484,"content":8485,"nodeType":673},{},[8486],{"data":8487,"marks":8488,"value":8489,"nodeType":543},{},[],"Most security leaders I talk to know they have an AI problem. They've seen the board questions, read the reports, maybe even drafted a policy. But when they start measuring where they stand — not plans or roadmaps, but actual current state — the gap between awareness and operational capability comes into focus.",{"data":8491,"content":8492,"nodeType":673},{},[8493,8496,8504,8508,8516],{"data":8494,"marks":8495,"value":1193,"nodeType":543},{},[],{"data":8497,"content":8499,"nodeType":695},{"uri":8498},"https://pushsecurity.com/blog/verizon-dbir-2026-review",[8500],{"data":8501,"marks":8502,"value":8503,"nodeType":543},{},[],"2026 Verizon DBIR",{"data":8505,"marks":8506,"value":8507,"nodeType":543},{},[]," quantifies the scale: 45% of employees are now regular AI users on corporate devices (up from 15% the prior year), with 67% using personal accounts. ",{"data":8509,"content":8511,"nodeType":695},{"uri":8510},"https://pushsecurity.com/blog/what-push-data-reveals-about-the-state-of-shadow-ai",[8512],{"data":8513,"marks":8514,"value":8515,"nodeType":543},{},[],"Push data",{"data":8517,"marks":8518,"value":8519,"nodeType":543},{},[]," further shows that 38% of file uploads to AI tools come from those shadow accounts rather than approved organizational ones — and the DBIR shows what's going into them: of 858,000+ DLP events targeting GenAI applications, the most common data types were source code (28%), structured data (14%), and documents and PDFs (23% combined).",{"data":8521,"content":8522,"nodeType":673},{},[8523,8527,8534],{"data":8524,"marks":8525,"value":8526,"nodeType":543},{},[],"The average organization now has ",{"data":8528,"content":8529,"nodeType":695},{"uri":8510},[8530],{"data":8531,"marks":8532,"value":8533,"nodeType":543},{},[],"16 unique AI apps, 17 AI browser extensions, and 17 AI OAuth integrations",{"data":8535,"marks":8536,"value":8537,"nodeType":543},{},[]," in active use, most unapproved. Shadow AI was the third most common non-malicious insider action in the DBIR, up 4x year over year.",{"data":8539,"content":8542,"nodeType":787},{"target":8540},{"sys":8541},{"id":6776,"type":792,"linkType":793},[],{"data":8544,"content":8545,"nodeType":673},{},[8546],{"data":8547,"marks":8548,"value":8549,"nodeType":543},{},[],"These statistics expose an attack surface and unmanaged risks at a high level. But the real problem is that most organizations can't produce a basic inventory of which AI tools are in use, let alone demonstrate controls around any of them. ",{"data":8551,"content":8552,"nodeType":673},{},[8553,8557,8562],{"data":8554,"marks":8555,"value":8556,"nodeType":543},{},[],"That gap between awareness and capability is where most organizations are stuck. And understanding ",{"data":8558,"marks":8559,"value":8561,"nodeType":543},{},[8560],{"type":739},"why",{"data":8563,"marks":8564,"value":8565,"nodeType":543},{},[]," they're stuck requires a framework for what progress actually looks like.",{"data":8567,"content":8568,"nodeType":796},{},[],{"data":8570,"content":8571,"nodeType":800},{},[8572],{"data":8573,"marks":8574,"value":8576,"nodeType":543},{},[8575],{"type":749},"A model for measuring what most organizations already feel",{"data":8578,"content":8579,"nodeType":673},{},[8580,8584,8591],{"data":8581,"marks":8582,"value":8583,"nodeType":543},{},[],"Chris Cochran's ",{"data":8585,"content":8587,"nodeType":695},{"uri":8586},"https://sansorg.egnyte.com/dl/XtgqfjkjBjp8",[8588],{"data":8589,"marks":8590,"value":6846,"nodeType":543},{},[],{"data":8592,"marks":8593,"value":8594,"nodeType":543},{},[],", published earlier this year, provides a framework for addressing this gap. It defines five stages of AI security maturity across three pillars:",{"data":8596,"content":8597,"nodeType":2727},{},[8598,8614,8630],{"data":8599,"content":8600,"nodeType":2639},{},[8601],{"data":8602,"content":8603,"nodeType":673},{},[8604,8610],{"data":8605,"marks":8606,"value":8609,"nodeType":543},{},[8607,8608],{"type":749},{"type":722},"Protect AI:",{"data":8611,"marks":8612,"value":8613,"nodeType":543},{},[]," Defending against AI-enabled threats like adversarial attacks, prompt injection, compromised browser extensions, and AI agents operating with unchecked permissions.",{"data":8615,"content":8616,"nodeType":2639},{},[8617],{"data":8618,"content":8619,"nodeType":673},{},[8620,8626],{"data":8621,"marks":8622,"value":8625,"nodeType":543},{},[8623,8624],{"type":749},{"type":722},"Utilize AI:",{"data":8627,"marks":8628,"value":8629,"nodeType":543},{},[]," Using AI to strengthen security operations by using AI-powered detection and triage, behavioral analytics, and automated response playbooks.",{"data":8631,"content":8632,"nodeType":2639},{},[8633],{"data":8634,"content":8635,"nodeType":673},{},[8636,8642,8646,8655],{"data":8637,"marks":8638,"value":8641,"nodeType":543},{},[8639,8640],{"type":749},{"type":722},"Govern AI:",{"data":8643,"marks":8644,"value":8645,"nodeType":543},{},[]," Managing how the organization adopts and uses AI tools. Things like acceptable use policies, shadow AI discovery, data classification, access controls, and risk assessment. This is the pillar that gets the most attention in boardroom conversations today, driven in part by ",{"data":8647,"content":8649,"nodeType":695},{"uri":8648},"https://pushsecurity.com/blog/browser-visibility-and-control-can-achieve-ai-compliance",[8650],{"data":8651,"marks":8652,"value":8654,"nodeType":543},{},[8653],{"type":722},"regulatory pressure",{"data":8656,"marks":8657,"value":1863,"nodeType":543},{},[],{"data":8659,"content":8660,"nodeType":673},{},[8661],{"data":8662,"marks":8663,"value":8664,"nodeType":543},{},[],"How an organization invests across these three pillars, and whether it invests across all of them, determines whether it advances toward maturity in this area or stalls out at the early steps.",{"data":8666,"content":8670,"nodeType":787},{"target":8667},{"sys":8668},{"id":8669,"type":792,"linkType":793},"1JV3KG97JQNFKwODnMCMq2",[],{"data":8672,"content":8673,"nodeType":673},{},[8674],{"data":8675,"marks":8676,"value":8677,"nodeType":543},{},[],"The SANS AI maturity model outlines 5 stages that organizations must progress through in order to reach an optimal security posture:",{"data":8679,"content":8680,"nodeType":2727},{},[8681,8697,8713,8729,8745],{"data":8682,"content":8683,"nodeType":2639},{},[8684],{"data":8685,"content":8686,"nodeType":673},{},[8687,8693],{"data":8688,"marks":8689,"value":8692,"nodeType":543},{},[8690,8691],{"type":749},{"type":722},"Stage 1 (Unaware / Ad Hoc)",{"data":8694,"marks":8695,"value":8696,"nodeType":543},{},[]," is where employees are freely using AI tools with no oversight, no inventory exists, and leadership may not even know how much AI is in use. There's no policy to violate, so technically it's not even shadow AI yet; it's just unmanaged adoption.",{"data":8698,"content":8699,"nodeType":2639},{},[8700],{"data":8701,"content":8702,"nodeType":673},{},[8703,8709],{"data":8704,"marks":8705,"value":8708,"nodeType":543},{},[8706,8707],{"type":749},{"type":722},"Stage 2 (Reactive / Policy-Emerging)",{"data":8710,"marks":8711,"value":8712,"nodeType":543},{},[]," means a policy exists, but it's course-grained: \"Don't use AI\" or \"use with caution.\" Known AI tools may be blocked at the network level. Security teams are learning about AI-specific threats but don't have dedicated expertise or tooling.",{"data":8714,"content":8715,"nodeType":2639},{},[8716],{"data":8717,"content":8718,"nodeType":673},{},[8719,8725],{"data":8720,"marks":8721,"value":8724,"nodeType":543},{},[8722,8723],{"type":749},{"type":722},"Stage 3 (Defined / Risk-Informed)",{"data":8726,"marks":8727,"value":8728,"nodeType":543},{},[]," is where things get intentional. AI usage is governed through enterprise tools rather than outright bans. AI systems are included in security assessments. The organization can demonstrate mature governance to regulators and partners. For many organizations, this is a strong and defensible operating position.",{"data":8730,"content":8731,"nodeType":2639},{},[8732],{"data":8733,"content":8734,"nodeType":673},{},[8735,8741],{"data":8736,"marks":8737,"value":8740,"nodeType":543},{},[8738,8739],{"type":749},{"type":722},"Stage 4 (Managed / Integrated)",{"data":8742,"marks":8743,"value":8744,"nodeType":543},{},[]," means AI is deeply embedded in security operations with measurable outcomes. AI systems are secured by design. Risk is quantified, not estimated. Decisions are data-driven. This is where organizations can handle AI-specific threats and operate at the tempo that AI-augmented adversaries demand.",{"data":8746,"content":8747,"nodeType":2639},{},[8748],{"data":8749,"content":8750,"nodeType":673},{},[8751,8757],{"data":8752,"marks":8753,"value":8756,"nodeType":543},{},[8754,8755],{"type":749},{"type":722},"Stage 5 (Optimizing / Adaptive)",{"data":8758,"marks":8759,"value":8760,"nodeType":543},{},[]," is the frontier of AI-native security with self-improving defenses. Elements of this stage exist primarily in large technology companies, defense contractors, and AI-native firms. For most organizations, this is a multi-year journey.",{"data":8762,"content":8763,"nodeType":673},{},[8764],{"data":8765,"marks":8766,"value":8767,"nodeType":543},{},[],"Most of the security leaders I talk to land between Stage 1 and Stage 2. They have awareness, maybe a policy, but not the tooling or telemetry to demonstrate much beyond that. ",{"data":8769,"content":8770,"nodeType":673},{},[8771],{"data":8772,"marks":8773,"value":8774,"nodeType":543},{},[],"The model is pragmatic about these challenges. It doesn't expect every organization to reach Stage 5, and it adjusts maturity targets by sector. ",{"data":8776,"content":8777,"nodeType":673},{},[8778,8782,8787],{"data":8779,"marks":8780,"value":8781,"nodeType":543},{},[],"But it ",{"data":8783,"marks":8784,"value":8786,"nodeType":543},{},[8785],{"type":739},"does",{"data":8788,"marks":8789,"value":8790,"nodeType":543},{},[]," require evidence of progress, not just intent. And for the majority sitting at Stage 2, the hard part is identifying the right steps to move from being merely reactive to a posture of operational readiness. That’s the chasm to cross.",{"data":8792,"content":8793,"nodeType":796},{},[],{"data":8795,"content":8796,"nodeType":800},{},[8797],{"data":8798,"marks":8799,"value":8801,"nodeType":543},{},[8800],{"type":749},"The chasm",{"data":8803,"content":8804,"nodeType":673},{},[8805],{"data":8806,"marks":8807,"value":8808,"nodeType":543},{},[],"For the organizations sitting at Stage 2, current state often looks like this: They've written an AI acceptable use policy, and maybe they've blocked known AI apps at the network level. They've trained employees on what's allowed and what isn't. ",{"data":8810,"content":8811,"nodeType":673},{},[8812],{"data":8813,"marks":8814,"value":8815,"nodeType":543},{},[],"To be sure, blocking is the fastest lever a security team can pull, and it represents visible progress to the business. The problem is that it rarely stays effective. ",{"data":8817,"content":8818,"nodeType":673},{},[8819],{"data":8820,"marks":8821,"value":8823,"nodeType":543},{},[8822],{"type":749},"SANS calls the pattern that traps most organizations at Stage 2 the \"Framework of No.\" ",{"data":8825,"content":8826,"nodeType":673},{},[8827],{"data":8828,"marks":8829,"value":8830,"nodeType":543},{},[],"\"A block-based AI policy may feel like risk management, but practitioner experience shows it typically drives AI usage underground rather than preventing it,” the report notes. “This is the pattern SANS has documented as the 'Framework of No,' and it is why the Stage 2 to Stage 3 transition is so critical.\"",{"data":8832,"content":8833,"nodeType":673},{},[8834,8839],{"data":8835,"marks":8836,"value":8838,"nodeType":543},{},[8837],{"type":739},"This",{"data":8840,"marks":8841,"value":8842,"nodeType":543},{},[]," is the chasm. On one side: awareness and policy. On the other: operational capability - the tooling, telemetry, and controls that let a security team see what's happening and respond to it. Most organizations are standing on the awareness side, looking across, not sure how to get over.",{"data":8844,"content":8848,"nodeType":787},{"target":8845},{"sys":8846},{"id":8847,"type":792,"linkType":793},"187mKPZV8tVbsw17L2cWIU",[],{"data":8850,"content":8851,"nodeType":673},{},[8852],{"data":8853,"marks":8854,"value":8855,"nodeType":543},{},[],"The model is specific about what crossing requires. The steps from Stage 2 to Stage 3 include technical BYOAI discovery (not a survey, but automated discovery), AI-specific data classification, AI-aware controls, and a cross-functional governance body. Data classification is a critical prerequisite: \"You cannot write an effective AI policy without knowing where sensitive data lives,\" the report emphasizes.",{"data":8857,"content":8858,"nodeType":673},{},[8859],{"data":8860,"marks":8861,"value":8862,"nodeType":543},{},[],"These are visibility and measurement problems before they're policy problems. You can't govern what you can't see. You can't classify risk you can't measure. And a blocklist that pushes usage underground doesn't give you either: it just makes the gap between your policy and your reality harder to detect.",{"data":8864,"content":8865,"nodeType":673},{},[8866],{"data":8867,"marks":8868,"value":8869,"nodeType":543},{},[],"Getting this visibility right is necessary for crossing the chasm. But it’s not the only step organizations must undertake if they want to address their AI risk.",{"data":8871,"content":8872,"nodeType":796},{},[],{"data":8874,"content":8875,"nodeType":800},{},[8876],{"data":8877,"marks":8878,"value":8880,"nodeType":543},{},[8879],{"type":749},"Governance is key, but don't forget about protection",{"data":8882,"content":8883,"nodeType":673},{},[8884,8888,8893],{"data":8885,"marks":8886,"value":8887,"nodeType":543},{},[],"Most AI security conversations today - the vendor pitches, board decks, and compliance checklists - are about the ",{"data":8889,"marks":8890,"value":8892,"nodeType":543},{},[8891],{"type":749},"Govern",{"data":8894,"marks":8895,"value":8896,"nodeType":543},{},[]," pillar. Shadow AI discovery. Usage policies. Data classification. Controls around what employees paste into AI prompts or upload to AI tools. It's important work.",{"data":8898,"content":8899,"nodeType":673},{},[8900,8904,8909],{"data":8901,"marks":8902,"value":8903,"nodeType":543},{},[],"But the SANS model gives roughly equal weight to a second pillar that gets almost no attention: ",{"data":8905,"marks":8906,"value":8908,"nodeType":543},{},[8907],{"type":749},"Protect",{"data":8910,"marks":8911,"value":8912,"nodeType":543},{},[]," - defending against AI-enabled attacks.",{"data":8914,"content":8915,"nodeType":673},{},[8916],{"data":8917,"marks":8918,"value":8919,"nodeType":543},{},[],"The Protect pillar starts from a stark baseline. At Stage 1, most organizations have no visibility into which AI agents or browser extensions have access to their corporate environment, let alone a framework for understanding how those could be attacked. ",{"data":8921,"content":8922,"nodeType":673},{},[8923],{"data":8924,"marks":8925,"value":8926,"nodeType":543},{},[],"By Stage 3, the model expects runtime validation of AI tools and plugins, detection capabilities mapped to AI-specific attack frameworks, and controls that cover the growing surface area of agentic AI. ",{"data":8928,"content":8929,"nodeType":673},{},[8930],{"data":8931,"marks":8932,"value":8933,"nodeType":543},{},[],"By Stage 4, organizations need real-time monitoring of AI agent behavior and defenses against attacks that exploit trust relationships between AI systems — capabilities most security teams haven't started scoping, much less building or procuring.",{"data":8935,"content":8936,"nodeType":673},{},[8937,8941,8951],{"data":8938,"marks":8939,"value":8940,"nodeType":543},{},[],"These are detection and response capabilities, not governance exercises — and the attacks they address are already well underway. ",{"data":8942,"content":8944,"nodeType":695},{"uri":8943},"https://pushsecurity.com/blog/the-cisos-data-problem-and-how-browser-telemetry-can-help/",[8945],{"data":8946,"marks":8947,"value":8950,"nodeType":543},{},[8948,8949],{"type":722},{"type":749},"One in three phishing payloads",{"data":8952,"marks":8953,"value":8954,"nodeType":543},{},[]," intercepted by Push arrive outside of email, through channels where most security controls don't exist. Evidence of the growth of browser-based attack methods enabled by AI tooling abounds:",{"data":8956,"content":8957,"nodeType":2727},{},[8958,8980,9001],{"data":8959,"content":8960,"nodeType":2639},{},[8961],{"data":8962,"content":8963,"nodeType":673},{},[8964,8968,8976],{"data":8965,"marks":8966,"value":8967,"nodeType":543},{},[],"CrowdStrike's 2026 Global Threat Report documented a ",{"data":8969,"content":8971,"nodeType":695},{"uri":8970},"https://www.crowdstrike.com/explore/2026-global-threat-report",[8972],{"data":8973,"marks":8974,"value":8975,"nodeType":543},{},[],"563% increase in ClickFix lures",{"data":8977,"marks":8978,"value":8979,"nodeType":543},{},[]," — fake CAPTCHA pages that trick users into executing malicious commands on their own machines.",{"data":8981,"content":8982,"nodeType":2639},{},[8983],{"data":8984,"content":8985,"nodeType":673},{},[8986,8990,8997],{"data":8987,"marks":8988,"value":8989,"nodeType":543},{},[],"Push has tracked a ",{"data":8991,"content":8992,"nodeType":695},{"uri":895},[8993],{"data":8994,"marks":8995,"value":8996,"nodeType":543},{},[],"37x increase in device code phishing",{"data":8998,"marks":8999,"value":9000,"nodeType":543},{},[]," since the start of 2026, with 18+ distinct kits now offering the technique.",{"data":9002,"content":9003,"nodeType":2639},{},[9004],{"data":9005,"content":9006,"nodeType":673},{},[9007,9010,9019,9023,9028,9032,9037],{"data":9008,"marks":9009,"value":21,"nodeType":543},{},[],{"data":9011,"content":9013,"nodeType":695},{"uri":9012},"https://www.anthropic.com/news/AI-enabled-cyber-threats-mitre-attack",[9014],{"data":9015,"marks":9016,"value":9018,"nodeType":543},{},[9017],{"type":722},"Anthropic",{"data":9020,"marks":9021,"value":9022,"nodeType":543},{},[]," identified ",{"data":9024,"marks":9025,"value":9027,"nodeType":543},{},[9026],{"type":749},"793 threat actors using AI",{"data":9029,"marks":9030,"value":9031,"nodeType":543},{},[]," for malicious cybersecurity purposes between March 2025 and February 2026, with the 2026 Verizon DBIR finding that ",{"data":9033,"marks":9034,"value":9036,"nodeType":543},{},[9035],{"type":749},"44% of AI-assisted initial access was phishing-related",{"data":9038,"marks":9039,"value":1863,"nodeType":543},{},[],{"data":9041,"content":9042,"nodeType":673},{},[9043],{"data":9044,"marks":9045,"value":9046,"nodeType":543},{},[],"Attackers are already vibecoding phishing kits, rotating infrastructure daily, and exploiting identity flows that traditional endpoint and network tools can't see.",{"data":9048,"content":9049,"nodeType":673},{},[9050],{"data":9051,"marks":9052,"value":9053,"nodeType":543},{},[],"The SANS model makes the speed argument a central focus at Stage 4: Detection built for human-pace adversaries is increasingly insufficient when threats operate at machine speed. For organizations investing exclusively in AI governance, AI-enabled threats represent an entire category of risk that is not being addressed.",{"data":9055,"content":9056,"nodeType":796},{},[],{"data":9058,"content":9059,"nodeType":829},{},[9060],{"data":9061,"marks":9062,"value":9064,"nodeType":543},{},[9063],{"type":749},"Why governance alone can't close the gap",{"data":9066,"content":9067,"nodeType":673},{},[9068,9072,9077],{"data":9069,"marks":9070,"value":9071,"nodeType":543},{},[],"An organization can have an AI policy, shadow AI discovery, data classification, and usage controls, and ",{"data":9073,"marks":9074,"value":9076,"nodeType":543},{},[9075],{"type":739},"still",{"data":9078,"marks":9079,"value":9080,"nodeType":543},{},[]," be exposed. When an employee hits a device code phishing page or a ClickFix lure, the governance program documented the risk perfectly. It just couldn't stop the attack. The policy existed but the detection (and ideally, mitigation) didn't.",{"data":9082,"content":9083,"nodeType":673},{},[9084],{"data":9085,"marks":9086,"value":9087,"nodeType":543},{},[],"The reverse is equally true, and it's why the SANS model treats the pillars as interdependent rather than sequential. Detection capabilities that fire into a void with no policy to act on findings, no classification to assess exposure, and no governance body to shape proactive policy just create alerts, not security. ",{"data":9089,"content":9090,"nodeType":673},{},[9091],{"data":9092,"marks":9093,"value":9094,"nodeType":543},{},[],"Yet most organizations are only investing heavily in one side of the solution, which is almost always Govern. The maturity model is explicit about the risks of this approach: Governance with no attack detection leaves a critical gap. ",{"data":9096,"content":9097,"nodeType":673},{},[9098],{"data":9099,"marks":9100,"value":9102,"nodeType":543},{},[9101],{"type":749},"Closing the gap requires a control point where both problems are visible and addressable.",{"data":9104,"content":9105,"nodeType":796},{},[],{"data":9107,"content":9108,"nodeType":800},{},[9109],{"data":9110,"marks":9111,"value":9113,"nodeType":543},{},[9112],{"type":749},"Crossing the chasm requires addressing both pillars at once",{"data":9115,"content":9116,"nodeType":673},{},[9117,9121,9128],{"data":9118,"marks":9119,"value":9120,"nodeType":543},{},[],"The bottleneck for most security programs ",{"data":9122,"content":9123,"nodeType":695},{"uri":8943},[9124],{"data":9125,"marks":9126,"value":9127,"nodeType":543},{},[],"isn't frameworks or strategy — it's data quality",{"data":9129,"marks":9130,"value":9131,"nodeType":543},{},[],". For teams taking on the dual problems of shadow AI and AI-enabled attacks, browser telemetry is the foundation to any meaningful solution. That’s because both problems converge in the same place.",{"data":9133,"content":9134,"nodeType":673},{},[9135],{"data":9136,"marks":9137,"value":9138,"nodeType":543},{},[],"AI-enabled phishing attacks, credential theft, malicious browser extensions, and OAuth exploitation happen in the browser. So do shadow AI adoption, sensitive data pasted into AI prompts, file uploads to unapproved tools, and unauthorized integrations. The browser is where external attacks and internal misuse are both visible and stoppable.",{"data":9140,"content":9141,"nodeType":673},{},[9142],{"data":9143,"marks":9144,"value":9145,"nodeType":543},{},[],"For the security team trying to advance past the Framework of No, browser telemetry replaces the blunt instrument of network-level blocking with actual visibility:",{"data":9147,"content":9148,"nodeType":2727},{},[9149,9159,9169],{"data":9150,"content":9151,"nodeType":2639},{},[9152],{"data":9153,"content":9154,"nodeType":673},{},[9155],{"data":9156,"marks":9157,"value":9158,"nodeType":543},{},[],"which AI apps are in use (including personal account usage)",{"data":9160,"content":9161,"nodeType":2639},{},[9162],{"data":9163,"content":9164,"nodeType":673},{},[9165],{"data":9166,"marks":9167,"value":9168,"nodeType":543},{},[],"what data is moving into them (file uploads, clipboard activity)",{"data":9170,"content":9171,"nodeType":2639},{},[9172],{"data":9173,"content":9174,"nodeType":673},{},[9175],{"data":9176,"marks":9177,"value":9178,"nodeType":543},{},[],"graduated controls - per-app, per-user group, per-content pattern - that can monitor, warn, or block based on context rather than allow/deny",{"data":9180,"content":9181,"nodeType":673},{},[9182],{"data":9183,"marks":9184,"value":9185,"nodeType":543},{},[],"The same browser-layer instrumentation can also provide real-time detection of credential phishing, ClickFix, adversary-in-the-middle attacks, and device code phishing. And it can detect and disable malicious browser extensions based on confirmed threat intelligence, monitor OAuth integrations, and generate the identity attack surface data (login behaviors, MFA gaps, SSO coverage) that the Protect pillar requires at Stage 3 maturity and beyond.",{"data":9187,"content":9188,"nodeType":673},{},[9189],{"data":9190,"marks":9191,"value":9192,"nodeType":543},{},[],"We built Push around this insight: that the browser is where both problems converge, and a single deployment can advance AI security maturity in both areas simultaneously. The SANS model makes the same argument.",{"data":9194,"content":9195,"nodeType":796},{},[],{"data":9197,"content":9198,"nodeType":800},{},[9199],{"data":9200,"marks":9201,"value":9203,"nodeType":543},{},[9202],{"type":749},"Where to start: 5 steps to maturity with Push",{"data":9205,"content":9206,"nodeType":673},{},[9207],{"data":9208,"marks":9209,"value":9210,"nodeType":543},{},[],"The chasm closes when organizations make meaningful strides forward in both AI governance and proactive defense against AI-enabled attacks. Here's the starting plan that I'd recommend, and Push can provide the tooling to automate these steps:",{"data":9212,"content":9213,"nodeType":673},{},[9214,9219],{"data":9215,"marks":9216,"value":9218,"nodeType":543},{},[9217],{"type":749},"1. Build an AI inventory automatically.",{"data":9220,"marks":9221,"value":9222,"nodeType":543},{},[]," Every stage transition in the SANS model starts with knowing what's in your environment. A manual survey won't cut it; employees won't self-report the tools they're not sure they're allowed to use, and may overlook apps where AI is a feature but not the core function (AI-enabled apps). Instead, organizations should deploy automated discovery for AI apps, browser extensions, and OAuth integrations across the workforce - including the ones using personal accounts. Until this inventory exists, every policy decision is based on incomplete information.",{"data":9224,"content":9228,"nodeType":787},{"target":9225},{"sys":9226},{"id":9227,"type":792,"linkType":793},"2t3u0NydllImv6NzvAY058",[],{"data":9230,"content":9231,"nodeType":673},{},[9232,9237],{"data":9233,"marks":9234,"value":9236,"nodeType":543},{},[9235],{"type":749},"2. Classify what you find.",{"data":9238,"marks":9239,"value":9240,"nodeType":543},{},[]," Not all AI usage carries the same risk. A developer pasting code into ChatGPT and a salesperson using an AI notetaker are different problems. Once you can see the tools, categorize them by data sensitivity, authorization status, and access scope. The SANS model calls out data classification as a critical prerequisite; you can't write an effective AI policy without knowing where sensitive data lives.",{"data":9242,"content":9243,"nodeType":673},{},[9244,9249],{"data":9245,"marks":9246,"value":9248,"nodeType":543},{},[9247],{"type":749},"3. Turn on browser-layer detection.",{"data":9250,"marks":9251,"value":9252,"nodeType":543},{},[]," This is the step most organizations skip, and it's why addressing only the Protect pillar will keep you at Stage 1. AI-enabled phishing, ClickFix attacks, device code phishing, malicious extension updates, and OAuth exploitation all execute in the browser. Without detection in that layer, there's no visibility into the fastest-growing attack category, and no path to advancing beyond basic AI usage awareness.",{"data":9254,"content":9258,"nodeType":787},{"target":9255},{"sys":9256},{"id":9257,"type":792,"linkType":793},"1fzuGjA6VSbVl1p7vM1mt7",[],{"data":9260,"content":9261,"nodeType":673},{},[9262,9267],{"data":9263,"marks":9264,"value":9266,"nodeType":543},{},[9265],{"type":749},"4. Move from blocking to graduated controls.",{"data":9268,"marks":9269,"value":9270,"nodeType":543},{},[]," The Framework of No fails because it's binary: allow or deny, with nothing in between. Organizations that cross the chasm adopt monitor, warn, and block modes — per app, per user group, per content pattern. Monitor first to see what's happening, warn to change behavior without disrupting workflows, and block only where the risk justifies it. This is the operational difference between Stage 2 and Stage 3.",{"data":9272,"content":9273,"nodeType":673},{},[9274,9279,9283,9289],{"data":9275,"marks":9276,"value":9278,"nodeType":543},{},[9277],{"type":749},"5. Assess yourself honestly against evidence, not aspiration.",{"data":9280,"marks":9281,"value":9282,"nodeType":543},{},[]," The ",{"data":9284,"content":9285,"nodeType":695},{"uri":8586},[9286],{"data":9287,"marks":9288,"value":6846,"nodeType":543},{},[],{"data":9290,"marks":9291,"value":9292,"nodeType":543},{},[]," includes a self-assessment and industry-specific weighting profiles. The value isn't in the score, but in identifying which pillar is keeping you from advancing.",{"data":9294,"content":9295,"nodeType":673},{},[9296],{"data":9297,"marks":9298,"value":9299,"nodeType":543},{},[],"The organizations that cross the AI security chasm will be the ones that recognize early that AI security isn't one problem with one solution. It's two problems that happen to share a control point. The most efficient path forward is a platform that addresses both.",{"data":9301,"content":9302,"nodeType":796},{},[],{"data":9304,"content":9305,"nodeType":800},{},[9306],{"data":9307,"marks":9308,"value":5884,"nodeType":543},{},[9309],{"type":749},{"data":9311,"content":9312,"nodeType":673},{},[9313],{"data":9314,"marks":9315,"value":9316,"nodeType":543},{},[],"Push Security is the most powerful AI-native security tool in the browser. Think EDR, but for the browser - high-fidelity telemetry and real-time control across every session, on every device, with no browser migration required.",{"data":9318,"content":9319,"nodeType":673},{},[9320],{"data":9321,"marks":9322,"value":2889,"nodeType":543},{},[],{"data":9324,"content":9325,"nodeType":673},{},[9326,9329,9336],{"data":9327,"marks":9328,"value":8445,"nodeType":543},{},[],{"data":9330,"content":9331,"nodeType":695},{"uri":5926},[9332],{"data":9333,"marks":9334,"value":8453,"nodeType":543},{},[9335],{"type":722},{"data":9337,"marks":9338,"value":8457,"nodeType":543},{},[],"Crossing the AI security chasm with the SANS AI security maturity model","Most organizations know they have an AI security problem. A new SANS framework shows why so few are making progress - and what it actually takes to get unstuck.","2026-06-24T00:00:00.000Z","crossing-the-ai-security-chasm-sans-security-maturity-model",{"items":9344},[9345,9347],{"sys":9346,"name":8471},{"id":8470},{"sys":9348,"name":8467},{"id":8466},{"items":9350},[9351],{"fullName":9352,"firstName":9353,"jobTitle":9354,"profilePicture":9355},"Mark Orlando","Mark","Field CTO",{"url":9356},"https://images.ctfassets.net/y1cdw1ablpvd/592PMwIQQFaa24k5SKBEKF/a33090d0ad95d1e3081f5d16a46ba826/image__68_.png",{"__typename":1608,"sys":9358,"content":9360,"title":10589,"synopsis":10590,"hashTags":59,"publishedDate":10591,"slug":10592,"tagsCollection":10593,"authorsCollection":10599},{"id":9359},"6MoHWfQlVildcFYKSbfMcE",{"json":9361},{"data":9362,"content":9363,"nodeType":669},{},[9364,9380,9386,9393,9400,9406,9409,9417,9425,9444,9491,9497,9512,9515,9523,9530,9558,9599,9606,9609,9617,9625,9632,9638,9645,9648,9656,9663,9705,9741,9748,9751,9759,9766,9791,9798,9840,9847,9850,9858,9866,9911,9918,9924,9927,9935,9943,9975,9982,9988,9995,9998,10006,10014,10043,10050,10057,10064,10067,10075,10083,10090,10096,10103,10126,10155,10158,10166,10174,10181,10188,10191,10199,10261,10264,10272,10279,10570,10573],{"data":9365,"content":9366,"nodeType":673},{},[9367,9371,9376],{"data":9368,"marks":9369,"value":9370,"nodeType":543},{},[],"Browser security solutions are one of the most significant additions to the enterprise security stack in recent years — and the data shows it. The browser is where ",{"data":9372,"marks":9373,"value":9375,"nodeType":543},{},[9374],{"type":749},"85% of work now happens",{"data":9377,"marks":9378,"value":9379,"nodeType":543},{},[],", where AI tools are accessed, and where attackers increasingly choose to strike.",{"data":9381,"content":9385,"nodeType":787},{"target":9382},{"sys":9383},{"id":9384,"type":792,"linkType":793},"5P6PyFbn4EakRNlIWtNzyL",[],{"data":9387,"content":9388,"nodeType":673},{},[9389],{"data":9390,"marks":9391,"value":9392,"nodeType":543},{},[],"But browser security is a nascent category. Getting a clear picture of which solution is right for your team, and how to get the most out of it, isn't straightforward. Current solutions on the market serve a wide range of IT and security use cases, with varying degrees of depth and differentiation across them. Not all use cases are equal in terms of their security value, and not all of them are best addressed in the browser.",{"data":9394,"content":9395,"nodeType":673},{},[9396],{"data":9397,"marks":9398,"value":9399,"nodeType":543},{},[],"This article ranks the security problems that browser security solutions can address by the value they deliver: a combination of the risk reduction on offer, and the degree to which the browser is genuinely the best (or only) layer to solve the problem. ",{"data":9401,"content":9405,"nodeType":787},{"target":9402},{"sys":9403},{"id":9404,"type":792,"linkType":793},"6SJPvEHizSYk29lEvVVNj",[],{"data":9407,"content":9408,"nodeType":796},{},[],{"data":9410,"content":9411,"nodeType":800},{},[9412],{"data":9413,"marks":9414,"value":9416,"nodeType":543},{},[9415],{"type":749},"#1 — Account takeover prevention: detecting credential attacks across all vectors",{"data":9418,"content":9419,"nodeType":673},{},[9420],{"data":9421,"marks":9422,"value":9424,"nodeType":543},{},[9423],{"type":749},"Security value: Very high | Browser fit: Uniquely suited",{"data":9426,"content":9427,"nodeType":673},{},[9428,9432,9440],{"data":9429,"marks":9430,"value":9431,"nodeType":543},{},[],"Account takeover (ATO) is the dominant entry point for enterprise breaches: ",{"data":9433,"content":9435,"nodeType":695},{"uri":9434},"https://www.crowdstrike.com/en-gb/resources/infographics/identity-security-risk-review/",[9436],{"data":9437,"marks":9438,"value":9439,"nodeType":543},{},[],"80% of all modern breaches involve compromised or stolen identities",{"data":9441,"marks":9442,"value":9443,"nodeType":543},{},[],". The attack surface is far wider than most identity tooling can see: credential stuffing, password spraying, ghost logins (password-based fallback authentication that persists after SSO is configured), weak or reused credentials on shadow SaaS apps, and accounts where MFA was never enforced.",{"data":9445,"content":9446,"nodeType":673},{},[9447,9451,9459,9462,9467,9470,9475,9479,9487],{"data":9448,"marks":9449,"value":9450,"nodeType":543},{},[],"According to ",{"data":9452,"content":9454,"nodeType":695},{"uri":9453},"https://cf-assets.www.cloudflare.com/slt3lc6tev37/sWDBUMNVtEJB9ZFLt1dUU/8d69e92de2edfb3bf59e7d21d57e7e1a/Cloudflare-2026-threat-report.pdf",[9455],{"data":9456,"marks":9457,"value":9458,"nodeType":543},{},[],"Cloudflare's 2026 Threat Report",{"data":9460,"marks":9461,"value":2164,"nodeType":543},{},[],{"data":9463,"marks":9464,"value":9466,"nodeType":543},{},[9465],{"type":749},"63% of all human logins involve credentials already compromised elsewhere",{"data":9468,"marks":9469,"value":3232,"nodeType":543},{},[],{"data":9471,"marks":9472,"value":9474,"nodeType":543},{},[9473],{"type":749},"94% of all login attempts originate from bots",{"data":9476,"marks":9477,"value":9478,"nodeType":543},{},[],". The ",{"data":9480,"content":9482,"nodeType":695},{"uri":9481},"https://pushsecurity.com/blog/snowflake-retro/",[9483],{"data":9484,"marks":9485,"value":9486,"nodeType":543},{},[],"Snowflake breach",{"data":9488,"marks":9489,"value":9490,"nodeType":543},{},[]," — 165+ organizations compromised, 1 billion+ records stolen — was powered almost entirely by ghost logins: accounts missing MFA that were susceptible to credential stuffing. It's particularly telling that 80% of the accounts impacted had prior breach exposure.",{"data":9492,"content":9496,"nodeType":787},{"target":9493},{"sys":9494},{"id":9495,"type":792,"linkType":793},"HbZ66kp5DiAZtwNGFJK7d",[],{"data":9498,"content":9499,"nodeType":673},{},[9500,9504,9509],{"data":9501,"marks":9502,"value":9503,"nodeType":543},{},[],"For organizations with contractors and BYOD users, the browser extension is also the only enterprise control deployable on devices that can't be MDM-enrolled — extending ATO detection to exactly the place where, per Verizon DBIR 2025, ",{"data":9505,"marks":9506,"value":9508,"nodeType":543},{},[9507],{"type":749},"46% of infostealer infections originate",{"data":9510,"marks":9511,"value":1863,"nodeType":543},{},[],{"data":9513,"content":9514,"nodeType":796},{},[],{"data":9516,"content":9517,"nodeType":800},{},[9518],{"data":9519,"marks":9520,"value":9522,"nodeType":543},{},[9521],{"type":749},"#2 — Detecting and stopping advanced phishing: AiTM, multi-channel delivery, and zero-day lures",{"data":9524,"content":9525,"nodeType":673},{},[9526],{"data":9527,"marks":9528,"value":9424,"nodeType":543},{},[9529],{"type":749},{"data":9531,"content":9532,"nodeType":673},{},[9533,9537,9545,9549,9554],{"data":9534,"marks":9535,"value":9536,"nodeType":543},{},[],"Adversary-in-the-Middle (AiTM) phishing — where an attacker's reverse proxy intercepts credentials and session tokens in real time — has become the standard technique for bypassing MFA at scale. ",{"data":9538,"content":9540,"nodeType":695},{"uri":9539},"https://www.esentire.com/resources/library/2026-threat-report",[9541],{"data":9542,"marks":9543,"value":9544,"nodeType":543},{},[],"eSentire's 2026 Threat Report",{"data":9546,"marks":9547,"value":9548,"nodeType":543},{},[]," attributes ",{"data":9550,"marks":9551,"value":9553,"nodeType":543},{},[9552],{"type":749},"63% of account compromise incidents to PhaaS kits",{"data":9555,"marks":9556,"value":9557,"nodeType":543},{},[],", with account compromise surging 389% year-over-year.",{"data":9559,"content":9560,"nodeType":673},{},[9561,9565,9573,9577,9582,9586,9595],{"data":9562,"marks":9563,"value":9564,"nodeType":543},{},[],"Traditional phishing controls are also no longer in the right place to intercept these attacks. The delivery channel has shifted decisively away from email: ",{"data":9566,"content":9568,"nodeType":695},{"uri":9567},"https://cloud.google.com/blog/topics/threat-intelligence/m-trends-2026",[9569],{"data":9570,"marks":9571,"value":9572,"nodeType":543},{},[],"Mandiant M-Trends 2026",{"data":9574,"marks":9575,"value":9576,"nodeType":543},{},[]," found email phishing dropped from 14% to 6% as an infection vector, and Push data shows ",{"data":9578,"marks":9579,"value":9581,"nodeType":543},{},[9580],{"type":749},"roughly 1 in 3 phishing payloads intercepted were delivered outside email entirely",{"data":9583,"marks":9584,"value":9585,"nodeType":543},{},[]," — via search engine malvertising, social platforms, and compromised websites. Meanwhile, ",{"data":9587,"content":9589,"nodeType":695},{"uri":9588},"https://www.spamhaus.com/resource-center/supporting-researchers-with-passive-dns/",[9590],{"data":9591,"marks":9592,"value":9594,"nodeType":543},{},[9593],{"type":749},"89% of phishing domains are active for less than two days",{"data":9596,"marks":9597,"value":9598,"nodeType":543},{},[],", making blocklist-based detection structurally too slow — attackers can spin up, tear down, and move on before blocklists can catch up.",{"data":9600,"content":9601,"nodeType":673},{},[9602],{"data":9603,"marks":9604,"value":9605,"nodeType":543},{},[],"Modern phishing plays out entirely inside the browser session. The only detection layer that can see the phishing page structure, the credential entry, and the anomalous token context is the browser itself. Browser-native detection analyses page behavior rather than matching known-bad domains, which means it fires on zero-day kits regardless of how recently the infrastructure was stood up. Controls like credential entry guardrails add an additional layer — blocking corporate passwords from being submitted to unauthorized domains independently of content and behavior-based detections.",{"data":9607,"content":9608,"nodeType":796},{},[],{"data":9610,"content":9611,"nodeType":800},{},[9612],{"data":9613,"marks":9614,"value":9616,"nodeType":543},{},[9615],{"type":749},"#3 — Identity posture hardening: enforcing security across the apps your IdP doesn't manage",{"data":9618,"content":9619,"nodeType":673},{},[9620],{"data":9621,"marks":9622,"value":9624,"nodeType":543},{},[9623],{"type":749},"Security value: High | Browser fit: Uniquely suited",{"data":9626,"content":9627,"nodeType":673},{},[9628],{"data":9629,"marks":9630,"value":9631,"nodeType":543},{},[],"The first challenge is knowing what you're protecting. Every identity an employee creates — every app they sign up to, every password they set, every login that bypasses SSO — is an authentication event that happens inside a browser session. The browser is the only layer that observes all of these events regardless of whether the app is sanctioned, managed, or even known to IT. Solutions that rely on API-level integrations with known apps, network traffic inspection, or email sign-up notifications can only ever build a partial picture, because they can only see apps they already know about. The browser sees the login itself, which means it discovers the identity at the moment it's created or used — authentication method, password strength, MFA status, and all.",{"data":9633,"content":9637,"nodeType":787},{"target":9634},{"sys":9635},{"id":9636,"type":792,"linkType":793},"HETvBCPsKGkqLVtaasXH0",[],{"data":9639,"content":9640,"nodeType":673},{},[9641],{"data":9642,"marks":9643,"value":9644,"nodeType":543},{},[],"But discovery without enforcement is just an inventory problem. Being in the browser means that you're in a great position to act on what it finds at the moment of authentication. Browser-native guardrails that prompt MFA enrollment, guide users toward stronger credentials, and redirect to SSO login paths close the gap at scale, on every app, including those the IdP has never seen. They also produce the continuous, auditable evidence of MFA coverage and credential hygiene across the full application estate that regulators, insurers, and auditors increasingly require — evidence that no IdP-centric tool can provide for apps outside its scope.",{"data":9646,"content":9647,"nodeType":796},{},[],{"data":9649,"content":9650,"nodeType":800},{},[9651],{"data":9652,"marks":9653,"value":9655,"nodeType":543},{},[9654],{"type":749},"#4 — Browser extension security",{"data":9657,"content":9658,"nodeType":673},{},[9659],{"data":9660,"marks":9661,"value":9624,"nodeType":543},{},[9662],{"type":749},{"data":9664,"content":9665,"nodeType":673},{},[9666,9670,9679,9682,9690,9693,9701],{"data":9667,"marks":9668,"value":9669,"nodeType":543},{},[],"Browser extensions have become one of the most talked-about attack surfaces in security over the past 18 months, and understandably so — a string of high-profile supply chain compromises have collectively impacted tens of millions of users since late 2024 (",{"data":9671,"content":9673,"nodeType":695},{"uri":9672},"https://www.cyberhaven.com/blog/cyberhavens-chrome-extension-security-incident-and-what-were-doing-about-it",[9674],{"data":9675,"marks":9676,"value":9678,"nodeType":543},{},[9677],{"type":722},"Cyberhaven",{"data":9680,"marks":9681,"value":2164,"nodeType":543},{},[],{"data":9683,"content":9685,"nodeType":695},{"uri":9684},"https://thehackernews.com/2025/12/darkspectre-browser-extension-campaigns.html",[9686],{"data":9687,"marks":9688,"value":9689,"nodeType":543},{},[],"DarkSpectre",{"data":9691,"marks":9692,"value":2164,"nodeType":543},{},[],{"data":9694,"content":9696,"nodeType":695},{"uri":9695},"https://thehackernews.com/2025/12/trust-wallet-chrome-extension-hack.html",[9697],{"data":9698,"marks":9699,"value":9700,"nodeType":543},{},[],"Trust Wallet",{"data":9702,"marks":9703,"value":9704,"nodeType":543},{},[],", among many others).",{"data":9706,"content":9707,"nodeType":673},{},[9708,9711,9719,9723,9728,9732,9737],{"data":9709,"marks":9710,"value":21,"nodeType":543},{},[],{"data":9712,"content":9713,"nodeType":695},{"uri":8148},[9714],{"data":9715,"marks":9716,"value":9718,"nodeType":543},{},[9717],{"type":722},"Analysis of 20,000+ extensions across Push customers",{"data":9720,"marks":9721,"value":9722,"nodeType":543},{},[]," found ",{"data":9724,"marks":9725,"value":9727,"nodeType":543},{},[9726],{"type":749},"46.76% have the permission combinations needed to perform account takeover with no user interaction",{"data":9729,"marks":9730,"value":9731,"nodeType":543},{},[],", making permissions-based risk scoring effectively useless as a triage tool. The real threat model is not malicious extensions at install time — it's legitimate extensions that ",{"data":9733,"marks":9734,"value":9736,"nodeType":543},{},[9735],{"type":739},"become",{"data":9738,"marks":9739,"value":9740,"nodeType":543},{},[]," malicious after an ownership transfer, developer account compromise, or silent update push. Every major extension supply chain breach of the past 18 months scored as low-risk immediately before compromise.",{"data":9742,"content":9743,"nodeType":673},{},[9744],{"data":9745,"marks":9746,"value":9747,"nodeType":543},{},[],"SWGs and network tools are structurally blind to this attack surface: a malicious extension exfiltrating session tokens generates no anomalous network signal — its traffic is indistinguishable from normal browsing. Endpoint agents have no visibility into extension behavior at the session level. Extension inventory, supply chain change monitoring — ownership transfers, permission escalations, developer contact changes — and enforcement all require browser-layer access by definition.",{"data":9749,"content":9750,"nodeType":796},{},[],{"data":9752,"content":9753,"nodeType":800},{},[9754],{"data":9755,"marks":9756,"value":9758,"nodeType":543},{},[9757],{"type":749},"#5 — Shadow SaaS discovery and OAuth integration governance",{"data":9760,"content":9761,"nodeType":673},{},[9762],{"data":9763,"marks":9764,"value":9624,"nodeType":543},{},[9765],{"type":749},{"data":9767,"content":9768,"nodeType":673},{},[9769,9773,9778,9782,9787],{"data":9770,"marks":9771,"value":9772,"nodeType":543},{},[],"Shadow SaaS discovery shares DNA with identity posture hardening (#3) — both start with the same browser-native visibility into login events that no other layer can replicate. Where identity posture focuses on hardening ",{"data":9774,"marks":9775,"value":9777,"nodeType":543},{},[9776],{"type":739},"how",{"data":9779,"marks":9780,"value":9781,"nodeType":543},{},[]," employees authenticate, shadow SaaS discovery focuses on ",{"data":9783,"marks":9784,"value":9786,"nodeType":543},{},[9785],{"type":739},"what",{"data":9788,"marks":9789,"value":9790,"nodeType":543},{},[]," they authenticate to: surfacing the full estate of applications in use across the organization, including those that IT has never sanctioned or even heard of.",{"data":9792,"content":9793,"nodeType":673},{},[9794],{"data":9795,"marks":9796,"value":9797,"nodeType":543},{},[],"OAuth integration governance is the component of shadow SaaS that is both the most potentially damaging and the hardest to surface through other means. The SaaS-to-SaaS OAuth pivot is now an industrialized attack pattern.",{"data":9799,"content":9800,"nodeType":2727},{},[9801,9821],{"data":9802,"content":9803,"nodeType":2639},{},[9804],{"data":9805,"content":9806,"nodeType":673},{},[9807,9810,9817],{"data":9808,"marks":9809,"value":1193,"nodeType":543},{},[],{"data":9811,"content":9813,"nodeType":695},{"uri":9812},"https://pushsecurity.com/blog/analyzing-the-instructure-breach/",[9814],{"data":9815,"marks":9816,"value":910,"nodeType":543},{},[],{"data":9818,"marks":9819,"value":9820,"nodeType":543},{},[]," Salesforce campaign — which compromised 1,000+ organizations and 1.5 billion records — demonstrated the full chain: the attacker didn't stop at stealing customer data but harvested OAuth tokens, AWS access keys, and Snowflake tokens from breached tenants and pivoted through connected services like Salesloft, Drift, and Gainsight to reach hundreds more organizations.",{"data":9822,"content":9823,"nodeType":2639},{},[9824],{"data":9825,"content":9826,"nodeType":673},{},[9827,9830,9836],{"data":9828,"marks":9829,"value":1193,"nodeType":543},{},[],{"data":9831,"content":9832,"nodeType":695},{"uri":2536},[9833],{"data":9834,"marks":9835,"value":2541,"nodeType":543},{},[],{"data":9837,"marks":9838,"value":9839,"nodeType":543},{},[]," chain followed the same logic — stored OAuth tokens from a forgotten AI app trial provided the bridge into Google Workspace, internal dashboards, and API keys. These are not isolated incidents; they are the repeatable playbook for extracting maximum value from a single compromise through the trust relationships that OAuth connections encode.",{"data":9841,"content":9842,"nodeType":673},{},[9843],{"data":9844,"marks":9845,"value":9846,"nodeType":543},{},[],"Every OAuth consent grant transits the browser — the authorization prompt, the scope disclosure, the user's approval click, and the redirect that completes the grant all happen inside a browser session — which makes the browser the only layer where an unwanted grant can be intercepted before the token is issued and the persistent access path is created. Once a token exists, the damage is done: it survives password resets, MFA changes, and session revocations, and revoking it after the fact requires first knowing it was granted, which most organizations do not.",{"data":9848,"content":9849,"nodeType":796},{},[],{"data":9851,"content":9852,"nodeType":800},{},[9853],{"data":9854,"marks":9855,"value":9857,"nodeType":543},{},[9856],{"type":749},"#6 — Blocking ClickFix and social engineering-based malware delivery",{"data":9859,"content":9860,"nodeType":673},{},[9861],{"data":9862,"marks":9863,"value":9865,"nodeType":543},{},[9864],{"type":749},"Security value: High | Browser fit: Strong for interception — shared with endpoint security for execution. ConsentFix is a browser-native exception that is T1-aligned.",{"data":9867,"content":9868,"nodeType":673},{},[9869,9873,9878,9882,9889,9893,9898,9902,9907],{"data":9870,"marks":9871,"value":9872,"nodeType":543},{},[],"ClickFix was the most common initial access vector reported by Microsoft in 2025, accounting for ",{"data":9874,"marks":9875,"value":9877,"nodeType":543},{},[9876],{"type":749},"47% of observed attacks",{"data":9879,"marks":9880,"value":9881,"nodeType":543},{},[],". CrowdStrike's ",{"data":9883,"content":9884,"nodeType":695},{"uri":8970},[9885],{"data":9886,"marks":9887,"value":9888,"nodeType":543},{},[],"2026 Global Threat Report",{"data":9890,"marks":9891,"value":9892,"nodeType":543},{},[]," identified fake CAPTCHA lures as the most common malware download type, increasing ",{"data":9894,"marks":9895,"value":9897,"nodeType":543},{},[9896],{"type":749},"563% year-over-year",{"data":9899,"marks":9900,"value":9901,"nodeType":543},{},[],". The technique writes a malicious command to the victim's clipboard and social-engineers them into executing it. It is fileless (bypassing download scanning), user-executed (bypassing endpoint behavioral detections), and ",{"data":9903,"marks":9904,"value":9906,"nodeType":543},{},[9905],{"type":749},"4 in 5 ClickFix payloads intercepted by Push arrived via search engines",{"data":9908,"marks":9909,"value":9910,"nodeType":543},{},[]," — not email (bypassing email anti-phishing controls).",{"data":9912,"content":9913,"nodeType":673},{},[9914],{"data":9915,"marks":9916,"value":9917,"nodeType":543},{},[],"The browser is the earliest and most effective intervention point — detecting the clipboard injection and social engineering lure before anything reaches the endpoint in executable form. But the problem doesn't end at the browser boundary: once the command has been pasted and run, detection and remediation become endpoint problems, and a mature defense requires both layers. The broader *Fix family — FileFix, InstallFix, and similar derivatives — follows the same pattern, with the browser providing the critical early-warning layer within a defense that spans browser and endpoint.",{"data":9919,"content":9923,"nodeType":787},{"target":9920},{"sys":9921},{"id":9922,"type":792,"linkType":793},"39alMHtw9FPHbQINqbAgBN",[],{"data":9925,"content":9926,"nodeType":796},{},[],{"data":9928,"content":9929,"nodeType":800},{},[9930],{"data":9931,"marks":9932,"value":9934,"nodeType":543},{},[9933],{"type":749},"#7 — AI visibility and control: enforcing which AI tools employees can use and how",{"data":9936,"content":9937,"nodeType":673},{},[9938],{"data":9939,"marks":9940,"value":9942,"nodeType":543},{},[9941],{"type":749},"Security value: High | Browser fit: Strong for access enforcement — but AI governance is not a new security problem so much as a force multiplier on existing ones",{"data":9944,"content":9945,"nodeType":673},{},[9946,9950,9958,9962,9971],{"data":9947,"marks":9948,"value":9949,"nodeType":543},{},[],"AI adoption is outpacing security governance at nearly every organization, and ",{"data":9951,"content":9952,"nodeType":695},{"uri":8298},[9953],{"data":9954,"marks":9955,"value":9957,"nodeType":543},{},[9956],{"type":749},"71% of organizations are concerned about data leakage via unsanctioned AI apps",{"data":9959,"marks":9960,"value":9961,"nodeType":543},{},[],". But the security problems that AI creates are not, for the most part, novel — they are existing Tier 1 problems amplified by a new category of tooling. Shadow AI apps are shadow SaaS (#5). AI OAuth integrations are OAuth governance (#5). AI browser extensions are extension security (#4). The risk of employees using personal AI accounts — ",{"data":9963,"content":9965,"nodeType":695},{"uri":9964},"https://keepaware.com/blog/46-of-sensitive-data-bypasses-your-dlp",[9966],{"data":9967,"marks":9968,"value":9970,"nodeType":543},{},[9969],{"type":749},"46% of sensitive inputs to AI tools are sent via personal accounts",{"data":9972,"marks":9973,"value":9974,"nodeType":543},{},[]," — is an identity posture problem (#3).",{"data":9976,"content":9977,"nodeType":673},{},[9978],{"data":9979,"marks":9980,"value":9981,"nodeType":543},{},[],"The component parts that allow you to govern AI are individually Tier 1 capabilities, and the browser is the best single layer for gaining visibility and control over AI usage — it sees the apps, the OAuth grants, the extensions, and the account context. But a complete end-to-end solution also requires a presence on the endpoint layer (for local AI tools, IDE-integrated agents, and API-level usage that never touches the browser), and prompt-level DLP on sanctioned tools is better handled by platform-native controls than by browser-layer observation.",{"data":9983,"content":9987,"nodeType":787},{"target":9984},{"sys":9985},{"id":9986,"type":792,"linkType":793},"6Py3z9VgjhKrchmYvhmbsq",[],{"data":9989,"content":9990,"nodeType":673},{},[9991],{"data":9992,"marks":9993,"value":9994,"nodeType":543},{},[],"The browser is what makes platform controls effective — if employees are using personal accounts, there are no enterprise audit logs to inspect. And for the growing category of AI agents, agentic browsers, and MCP-connected tools that operate through OAuth grants rather than direct user interaction, the browser is where the consent decisions that authorize those agents are made.",{"data":9996,"content":9997,"nodeType":796},{},[],{"data":9999,"content":10000,"nodeType":800},{},[10001],{"data":10002,"marks":10003,"value":10005,"nodeType":543},{},[10004],{"type":749},"#8 — Investigation acceleration and incident response: closing the missing middle",{"data":10007,"content":10008,"nodeType":673},{},[10009],{"data":10010,"marks":10011,"value":10013,"nodeType":543},{},[10012],{"type":749},"Security value: High | Browser fit: Strong — fills a structural gap complementary to endpoint, network, and identity telemetry",{"data":10015,"content":10016,"nodeType":673},{},[10017,10021,10026,10030,10039],{"data":10018,"marks":10019,"value":10020,"nodeType":543},{},[],"Endpoint logs show what processes executed. Network logs show traffic destinations. IdP logs show authentication events. None of them show what happened ",{"data":10022,"marks":10023,"value":10025,"nodeType":543},{},[10024],{"type":739},"inside the browser session",{"data":10027,"marks":10028,"value":10029,"nodeType":543},{},[]," — the phishing page the user saw, the credentials they entered, the malicious OAuth consent grant, the data uploaded or pasted to an unsanctioned service. This is the missing middle of modern incident investigations, and for the ",{"data":10031,"content":10033,"nodeType":695},{"uri":10032},"https://www.paloaltonetworks.co.uk/resources/research/unit-42-incident-response-report",[10034],{"data":10035,"marks":10036,"value":10038,"nodeType":543},{},[10037],{"type":749},"48% of intrusions involving browser-based activity",{"data":10040,"marks":10041,"value":10042,"nodeType":543},{},[],", the absence of browser telemetry is a significant investigative gap.",{"data":10044,"content":10045,"nodeType":673},{},[10046],{"data":10047,"marks":10048,"value":10049,"nodeType":543},{},[],"Browser-layer telemetry fills that gap with a fundamentally different quality of signal: what users actually clicked, what pages loaded and how they behaved, what credentials were entered, what session activity followed — structured, high-fidelity data from inside the session where the attack played out. That's the difference between inferring what happened and seeing it directly, and it determines scope, drives containment decisions, and provides the direct evidential record that neither endpoint DLP nor network monitoring can supply for browser-native attacks.",{"data":10051,"content":10052,"nodeType":673},{},[10053],{"data":10054,"marks":10055,"value":10056,"nodeType":543},{},[],"Browser telemetry is a key addition to the investigative picture. Investigations are inherently multi-source — without browser data, reconstructing an incident from EDR, network, and IdP logs won't tell you the full picture (particularly when attacks are increasingly delivered outside of email, intercepting users as they browse the internet normally).",{"data":10058,"content":10059,"nodeType":673},{},[10060],{"data":10061,"marks":10062,"value":10063,"nodeType":543},{},[],"The browser provides the causal link that other sources miss: the bridge between \"a user visited a URL\" and \"credentials were submitted to a phishing page that issued a session token now being replayed from an attacker-controlled browser.\" Integrated with SIEM and SOAR platforms, that signal enables automated response workflows to execute on high-confidence detections without waiting for manual triage.",{"data":10065,"content":10066,"nodeType":796},{},[],{"data":10068,"content":10069,"nodeType":800},{},[10070],{"data":10071,"marks":10072,"value":10074,"nodeType":543},{},[10073],{"type":749},"#9 — Infostealer defense: detecting exposure and blocking delivery",{"data":10076,"content":10077,"nodeType":673},{},[10078],{"data":10079,"marks":10080,"value":10082,"nodeType":543},{},[10081],{"type":749},"Security value: High | Browser fit: Strong for delivery interception and stolen factor detection — complementary to endpoint security for execution",{"data":10084,"content":10085,"nodeType":673},{},[10086],{"data":10087,"marks":10088,"value":10089,"nodeType":543},{},[],"Infostealers are the upstream supply chain for a disproportionate share of the most damaging enterprise attacks — harvesting credentials, session cookies, and browser profile data en masse from infected devices, then selling the outputs on infostealer markets for use in credential stuffing, ATO, and ransomware campaigns.",{"data":10091,"content":10095,"nodeType":787},{"target":10092},{"sys":10093},{"id":10094,"type":792,"linkType":793},"5NF1afwu3zFGThZTtStVQA",[],{"data":10097,"content":10098,"nodeType":673},{},[10099],{"data":10100,"marks":10101,"value":10102,"nodeType":543},{},[],"The browser is relevant at two points in the infostealer kill chain. First, delivery interception: ClickFix (covered in #6) is now the primary infostealer delivery mechanism, and the browser is the only layer that can intercept it before execution. Second, detecting stolen factors when attackers attempt to use them — and infostealers produce two categories of stolen factor that the browser can guard against.",{"data":10104,"content":10105,"nodeType":2727},{},[10106,10116],{"data":10107,"content":10108,"nodeType":2639},{},[10109],{"data":10110,"content":10111,"nodeType":673},{},[10112],{"data":10113,"marks":10114,"value":10115,"nodeType":543},{},[],"Stolen credentials can be identified at the point of login: browser-layer detection flags credentials that appear in known breach datasets, catching infostealer-harvested passwords being replayed in credential stuffing campaigns before the account is compromised.",{"data":10117,"content":10118,"nodeType":2639},{},[10119],{"data":10120,"content":10121,"nodeType":673},{},[10122],{"data":10123,"marks":10124,"value":10125,"nodeType":543},{},[],"Stolen session tokens are caught through a different mechanism: sessions originating in instrumented browsers carry a marker, and when a token subsequently appears in an un-instrumented browser it is a confirmed stolen session — catching infostealer-harvested cookies being replayed regardless of how or where the token was originally harvested.",{"data":10127,"content":10128,"nodeType":673},{},[10129,10133,10142,10146,10151],{"data":10130,"marks":10131,"value":10132,"nodeType":543},{},[],"This is particularly critical for the ",{"data":10134,"content":10136,"nodeType":695},{"uri":10135},"https://www.verizon.com/business/en-gb/resources/reports/dbir/",[10137],{"data":10138,"marks":10139,"value":10141,"nodeType":543},{},[10140],{"type":749},"46% of infected devices that are unmanaged",{"data":10143,"marks":10144,"value":10145,"nodeType":543},{},[]," where EDR is absent and the stolen credentials and session tokens will never be detected at the endpoint. Infostealer ",{"data":10147,"marks":10148,"value":10150,"nodeType":543},{},[10149],{"type":739},"execution",{"data":10152,"marks":10153,"value":10154,"nodeType":543},{},[]," remains an endpoint problem; the browser closes the delivery and replay gaps that endpoint tools miss.",{"data":10156,"content":10157,"nodeType":796},{},[],{"data":10159,"content":10160,"nodeType":800},{},[10161],{"data":10162,"marks":10163,"value":10165,"nodeType":543},{},[10164],{"type":749},"#10 — Data loss prevention: a key component of effective DLP, but not the full picture",{"data":10167,"content":10168,"nodeType":673},{},[10169],{"data":10170,"marks":10171,"value":10173,"nodeType":543},{},[10172],{"type":749},"Security value: Medium-high | Browser fit: Partial — complementary to dedicated DLP",{"data":10175,"content":10176,"nodeType":673},{},[10177],{"data":10178,"marks":10179,"value":10180,"nodeType":543},{},[],"File uploads to unsanctioned services, sensitive data pasted into AI tools, and exfiltration through personal accounts are genuine and growing risks that traditional email and endpoint-centric DLP tools were not designed to catch. Browser-layer controls provide real value here — particularly for BYOD users and contractors, where endpoint DLP agents cannot be deployed and the browser is the only available data loss visibility.",{"data":10182,"content":10183,"nodeType":673},{},[10184],{"data":10185,"marks":10186,"value":10187,"nodeType":543},{},[],"The honest scope: browser-layer DLP does not cover email-based loss, endpoint-to-endpoint transfers, or cloud API exfiltration. It closes specific and important gaps within a broader DLP strategy, not a replacement for one. A further distinction for organizations evaluating browser DLP for secure third-party access: full-stack enterprise browsers can enforce deeper output controls — watermarking, obfuscation, screenshot and print restrictions — at the OS rendering level that browser extensions cannot reliably replicate. Extension-based browser DLP is strongest for upload, input, and access control use cases rather than OS-level output restriction.",{"data":10189,"content":10190,"nodeType":796},{},[],{"data":10192,"content":10193,"nodeType":800},{},[10194],{"data":10195,"marks":10196,"value":10198,"nodeType":543},{},[10197],{"type":749},"Tier 3 — Lower Value: A problem best addressed outside of the browser",{"data":10200,"content":10201,"nodeType":2727},{},[10202,10217,10232,10247],{"data":10203,"content":10204,"nodeType":2639},{},[10205],{"data":10206,"content":10207,"nodeType":673},{},[10208,10213],{"data":10209,"marks":10210,"value":10212,"nodeType":543},{},[10211],{"type":749},"Browser exploit protection",{"data":10214,"marks":10215,"value":10216,"nodeType":543},{},[]," (narrow RCE/sandbox sense) ranks lower because browser zero-days represent just 9% of all zero-days reported to Google, and 82% of attack detections are now malware-free (CrowdStrike 2026). This is a problem for browser vendors to solve, and it's not a big enough problem to warrant enterprises investing in additional mitigating controls.",{"data":10218,"content":10219,"nodeType":2639},{},[10220],{"data":10221,"content":10222,"nodeType":673},{},[10223,10228],{"data":10224,"marks":10225,"value":10227,"nodeType":543},{},[10226],{"type":749},"Domain and URL category controls",{"data":10229,"marks":10230,"value":10231,"nodeType":543},{},[]," offer genuine browser-layer value but are commoditized by SWG and DNS filtering tools most organizations already operate. This can be provided in the browser, sure (and it's something we do at Push) but offers limited security value in terms of making a difference against modern attacks that quickly rotate these kinds of indicators and are designed to blend in.",{"data":10233,"content":10234,"nodeType":2639},{},[10235],{"data":10236,"content":10237,"nodeType":673},{},[10238,10243],{"data":10239,"marks":10240,"value":10242,"nodeType":543},{},[10241],{"type":749},"Access management",{"data":10244,"marks":10245,"value":10246,"nodeType":543},{},[]," — ZTNA, VPN replacement, PAM, BYOD access control — is an IT infrastructure and access architecture problem, not a security operations problem, and belongs to a different buyer with a different evaluation frame. There are numerous (typically full-stack) Enterprise Browser solutions on the market that address IT use cases like this well.",{"data":10248,"content":10249,"nodeType":2639},{},[10250],{"data":10251,"content":10252,"nodeType":673},{},[10253,10257],{"data":10254,"marks":10255,"value":359,"nodeType":543},{},[10256],{"type":749},{"data":10258,"marks":10259,"value":10260,"nodeType":543},{},[]," addresses browser exploit risk rather than the identity-first attacks that represent the majority of current enterprise browser risk, and introduces UX friction that limits deployment at scale. When it triggers, it introduces latency but still fails to detect and stop browser-native attacks.",{"data":10262,"content":10263,"nodeType":796},{},[],{"data":10265,"content":10266,"nodeType":800},{},[10267],{"data":10268,"marks":10269,"value":10271,"nodeType":543},{},[10270],{"type":749},"How Push Security maps to the highest-value security use cases",{"data":10273,"content":10274,"nodeType":673},{},[10275],{"data":10276,"marks":10277,"value":10278,"nodeType":543},{},[],"Push is purpose-built to address all of these problems using a flexible browser extension — plug into any browser with no migration, no host agent deployment, and no IT overhead — that delivers telemetry and control from day one, and extends coverage to every enrolled browser regardless of device ownership.",{"data":10280,"content":10281,"nodeType":3708},{},[10282,10307,10331,10355,10379,10403,10427,10451,10475,10499,10523,10547],{"data":10283,"content":10284,"nodeType":3470},{},[10285,10296],{"data":10286,"content":10287,"nodeType":3459},{},[10288],{"data":10289,"content":10290,"nodeType":673},{},[10291],{"data":10292,"marks":10293,"value":10295,"nodeType":543},{},[10294],{"type":749},"Security use case",{"data":10297,"content":10298,"nodeType":3459},{},[10299],{"data":10300,"content":10301,"nodeType":673},{},[10302],{"data":10303,"marks":10304,"value":10306,"nodeType":543},{},[10305],{"type":749},"How Push addresses it",{"data":10308,"content":10309,"nodeType":3470},{},[10310,10321],{"data":10311,"content":10312,"nodeType":3459},{},[10313],{"data":10314,"content":10315,"nodeType":673},{},[10316],{"data":10317,"marks":10318,"value":10320,"nodeType":543},{},[10319],{"type":749},"Account takeover prevention",{"data":10322,"content":10323,"nodeType":3459},{},[10324],{"data":10325,"content":10326,"nodeType":673},{},[10327],{"data":10328,"marks":10329,"value":10330,"nodeType":543},{},[],"Surfaces and fixes ghost logins, weak and breached credentials and missing MFA controls across every app and device — including shadow SaaS and unmanaged devices invisible to the IdP. Push also detects and stops the attack techniques that typically lead to ATO early in the kill chain and before an account can be compromised.",{"data":10332,"content":10333,"nodeType":3470},{},[10334,10345],{"data":10335,"content":10336,"nodeType":3459},{},[10337],{"data":10338,"content":10339,"nodeType":673},{},[10340],{"data":10341,"marks":10342,"value":10344,"nodeType":543},{},[10343],{"type":749},"Advanced phishing detection",{"data":10346,"content":10347,"nodeType":3459},{},[10348],{"data":10349,"content":10350,"nodeType":673},{},[10351],{"data":10352,"marks":10353,"value":10354,"nodeType":543},{},[],"Behavioral page analysis detects phishing kits regardless of whether the domain is known-bad. Credential entry guardrails block corporate passwords from being submitted to unauthorized domains. TTP-based detection remains effective as attacker infrastructure rotates.",{"data":10356,"content":10357,"nodeType":3470},{},[10358,10369],{"data":10359,"content":10360,"nodeType":3459},{},[10361],{"data":10362,"content":10363,"nodeType":673},{},[10364],{"data":10365,"marks":10366,"value":10368,"nodeType":543},{},[10367],{"type":749},"Identity posture hardening",{"data":10370,"content":10371,"nodeType":3459},{},[10372],{"data":10373,"content":10374,"nodeType":673},{},[10375],{"data":10376,"marks":10377,"value":10378,"nodeType":543},{},[],"Enforces MFA, strong credentials, and SSO adoption across every app the IdP doesn't manage. Produces continuous, auditable MFA coverage and credential hygiene evidence across the full application and device estate.",{"data":10380,"content":10381,"nodeType":3470},{},[10382,10393],{"data":10383,"content":10384,"nodeType":3459},{},[10385],{"data":10386,"content":10387,"nodeType":673},{},[10388],{"data":10389,"marks":10390,"value":10392,"nodeType":543},{},[10391],{"type":749},"Browser extension security",{"data":10394,"content":10395,"nodeType":3459},{},[10396],{"data":10397,"content":10398,"nodeType":673},{},[10399],{"data":10400,"marks":10401,"value":10402,"nodeType":543},{},[],"Live extension inventory with supply chain change event monitoring — ownership transfers, permission escalations, developer contact changes — rather than static risk scoring. Supports default-deny allowlisting and remote extension removal. Blocks known-bad malicious extensions automatically.",{"data":10404,"content":10405,"nodeType":3470},{},[10406,10417],{"data":10407,"content":10408,"nodeType":3459},{},[10409],{"data":10410,"content":10411,"nodeType":673},{},[10412],{"data":10413,"marks":10414,"value":10416,"nodeType":543},{},[10415],{"type":749},"Shadow SaaS and OAuth governance",{"data":10418,"content":10419,"nodeType":3459},{},[10420],{"data":10421,"content":10422,"nodeType":673},{},[10423],{"data":10424,"marks":10425,"value":10426,"nodeType":543},{},[],"Discovers shadow SaaS from actual login events with full authentication context. Monitors and blocks OAuth consent flows — including AI and MCP integrations — in real time before persistent access paths are created.",{"data":10428,"content":10429,"nodeType":3470},{},[10430,10441],{"data":10431,"content":10432,"nodeType":3459},{},[10433],{"data":10434,"content":10435,"nodeType":673},{},[10436],{"data":10437,"marks":10438,"value":10440,"nodeType":543},{},[10439],{"type":749},"ClickFix and the *Fix family",{"data":10442,"content":10443,"nodeType":3459},{},[10444],{"data":10445,"content":10446,"nodeType":673},{},[10447],{"data":10448,"marks":10449,"value":10450,"nodeType":543},{},[],"Detects and blocks ClickFix lures, clipboard injection, and browser-native variants like ConsentFix in real time — before the payload executes or OAuth key material is captured.",{"data":10452,"content":10453,"nodeType":3470},{},[10454,10465],{"data":10455,"content":10456,"nodeType":3459},{},[10457],{"data":10458,"content":10459,"nodeType":673},{},[10460],{"data":10461,"marks":10462,"value":10464,"nodeType":543},{},[10463],{"type":749},"AI visibility & control",{"data":10466,"content":10467,"nodeType":3459},{},[10468],{"data":10469,"content":10470,"nodeType":673},{},[10471],{"data":10472,"marks":10473,"value":10474,"nodeType":543},{},[],"Enforces which AI tools employees can access and routes usage to corporate tenants. Governs AI browser extensions and blocks OAuth consent grants to unapproved AI applications — drawing on the same Tier 1 capabilities (OAuth governance, extension security, shadow SaaS discovery) that make this possible.",{"data":10476,"content":10477,"nodeType":3470},{},[10478,10489],{"data":10479,"content":10480,"nodeType":3459},{},[10481],{"data":10482,"content":10483,"nodeType":673},{},[10484],{"data":10485,"marks":10486,"value":10488,"nodeType":543},{},[10487],{"type":749},"Security investigations & incident response",{"data":10490,"content":10491,"nodeType":3459},{},[10492],{"data":10493,"content":10494,"nodeType":673},{},[10495],{"data":10496,"marks":10497,"value":10498,"nodeType":543},{},[],"High-fidelity session telemetry — page loads, credential entries, DOM changes, OAuth grants — fills the missing middle that endpoint, network, and IdP logs leave open. Feeds directly into SIEM and SOAR for automated response.",{"data":10500,"content":10501,"nodeType":3470},{},[10502,10513],{"data":10503,"content":10504,"nodeType":3459},{},[10505],{"data":10506,"content":10507,"nodeType":673},{},[10508],{"data":10509,"marks":10510,"value":10512,"nodeType":543},{},[10511],{"type":749},"Infostealer defense",{"data":10514,"content":10515,"nodeType":3459},{},[10516],{"data":10517,"content":10518,"nodeType":673},{},[10519],{"data":10520,"marks":10521,"value":10522,"nodeType":543},{},[],"Intercepts ClickFix-based infostealer delivery before execution. Detects token replay in unenrolled browser contexts — catching post-theft abuse from AiTM-sourced tokens and infostealer-harvested cookies, including from unmanaged devices.",{"data":10524,"content":10525,"nodeType":3470},{},[10526,10537],{"data":10527,"content":10528,"nodeType":3459},{},[10529],{"data":10530,"content":10531,"nodeType":673},{},[10532],{"data":10533,"marks":10534,"value":10536,"nodeType":543},{},[10535],{"type":749},"Data loss prevention",{"data":10538,"content":10539,"nodeType":3459},{},[10540],{"data":10541,"content":10542,"nodeType":673},{},[10543],{"data":10544,"marks":10545,"value":10546,"nodeType":543},{},[],"Observes file uploads, downloads, and sensitive data inputs across all applications. Extends data loss visibility to BYOD and contractor devices where endpoint DLP cannot reach.",{"data":10548,"content":10549,"nodeType":3470},{},[10550,10560],{"data":10551,"content":10552,"nodeType":3459},{},[10553],{"data":10554,"content":10555,"nodeType":673},{},[10556],{"data":10557,"marks":10558,"value":10227,"nodeType":543},{},[10559],{"type":749},{"data":10561,"content":10562,"nodeType":3459},{},[10563],{"data":10564,"content":10565,"nodeType":673},{},[10566],{"data":10567,"marks":10568,"value":10569,"nodeType":543},{},[],"Custom URL blocklists with wildcard support and REST API management for threat intelligence feed sync. Application category blocking restricts access to classes of apps (file-sharing, unsanctioned AI tools) configurable by user group. Domain categorization bringing SWG-style category blocking natively to the browser without a network proxy.",{"data":10571,"content":10572,"nodeType":796},{},[],{"data":10574,"content":10575,"nodeType":673},{},[10576,10580,10586],{"data":10577,"marks":10578,"value":10579,"nodeType":543},{},[],"Push Security is the most powerful AI-native security tool in the browser. Think EDR, but for the browser — high-fidelity telemetry and real-time control across every session, on every device, with no browser migration required. ",{"data":10581,"content":10582,"nodeType":695},{"uri":5926},[10583],{"data":10584,"marks":10585,"value":2904,"nodeType":543},{},[],{"data":10587,"marks":10588,"value":21,"nodeType":543},{},[],"The top 10 security problems you can solve in the browser — ranked by value","Ranking the security problems you can solve in the browser by security value and browser fit.","2026-05-14T00:00:00.000Z","the-top-10-security-problems-you-can-solve-in-the-browser-ranked-by-value",{"items":10594},[10595,10597],{"sys":10596,"name":8471},{"id":8470},{"sys":10598,"name":8467},{"id":8466},{"items":10600},[10601],{"fullName":10602,"firstName":10603,"jobTitle":6600,"profilePicture":10604},"Alex Henshall","Alex",{"url":10605},"https://images.ctfassets.net/y1cdw1ablpvd/2rz3Pre3b1MexPIQ4hzPUe/0ef8a092b7e7df00fbce3f7d1ccb96d1/Alex_Henshall.jpeg","shadow-ai-how-to-discover-govern-and-secure-ai-apps","blog/shadow-ai-how-to-discover-govern-and-secure-ai-apps","Why you need paved paths, not barricades, for secure AI adoption",{"json":10610},{"data":10611,"content":10612,"nodeType":669},{},[10613],{"data":10614,"content":10615,"nodeType":673},{},[10616],{"data":10617,"marks":10618,"value":10619,"nodeType":543},{},[],"Blocking AI tools doesn't stop employees from using AI — it stops you seeing how they use it. The solution: make the governed path easier than the workaround.",{"id":10621,"publishedAt":10622},"7MB9tEe6mrdNXbkYVhgyWn","2026-08-19T14:18:47.442Z",{"items":10624},[10625,10629],{"sys":10626,"name":10628},{"id":10627},"3SA5H01UkKauuiTdt0KC6q","Shadow IT",{"sys":10630,"name":10632},{"id":10631},"7ohk9lIkxMvJMwnp2Lhuad","SaaS security",{"items":10634},[10635,10639,10644,10649,10654,10658,10663,10668,10673,10678,10683,10688,10693,10697,10702,10707],{"sys":10636,"name":8419,"slug":10638,"tier":45},{"id":10637},"topic-shadow-ai","shadow-ai",{"sys":10640,"name":10642,"slug":10643,"tier":45},{"id":10641},"topic-shadow-saas","Shadow SaaS","shadow-saas",{"sys":10645,"name":10647,"slug":10648,"tier":45},{"id":10646},"topic-third-party-risk","Third-party risk","third-party-risk",{"sys":10650,"name":10652,"slug":10653,"tier":45},{"id":10651},"topic-swg","SWG","swg",{"sys":10655,"name":10632,"slug":10657,"tier":31},{"id":10656},"topic-saas-security","saas-security",{"sys":10659,"name":10661,"slug":10662,"tier":45},{"id":10660},"topic-oauth-abuse","OAuth abuse","oauth-abuse",{"sys":10664,"name":10666,"slug":10667,"tier":45},{"id":10665},"topic-legitimate-service-abuse","Legitimate service abuse","legitimate-service-abuse",{"sys":10669,"name":10671,"slug":10672,"tier":31},{"id":10670},"topic-identity-security","Identity security","identity-security",{"sys":10674,"name":10676,"slug":10677,"tier":45},{"id":10675},"topic-dlp","DLP","dlp",{"sys":10679,"name":10681,"slug":10682,"tier":45},{"id":10680},"topic-detection-engineering","Detection engineering","detection-engineering",{"sys":10684,"name":10686,"slug":10687,"tier":45},{"id":10685},"topic-casb","CASB","casb",{"sys":10689,"name":10691,"slug":10692,"tier":45},{"id":10690},"topic-browser-extensions","Browser extensions","browser-extensions",{"sys":10694,"name":8471,"slug":10696,"tier":31},{"id":10695},"topic-browser-security","browser-security",{"sys":10698,"name":10700,"slug":10701,"tier":45},{"id":10699},"topic-ai-governance","AI governance","ai-governance",{"sys":10703,"name":10705,"slug":10706,"tier":31},{"id":10704},"topic-ai","AI","ai",{"sys":10708,"name":10710,"slug":10711,"tier":45},{"id":10709},"topic-ai-attacks","AI attacks","ai-attacks","eWaSy7hgQgoZrA9zfSPqvH0bDQuCRt_T6I21Gp97564",{"id":10714,"title":2908,"authorsCollection":10715,"content":10721,"extension":1410,"faqItemsCollection":11853,"faqTitle":59,"featured":6,"hashTags":59,"meta":11855,"metaTitle":11856,"ogImage":59,"postType":11857,"publishedDate":2910,"relatedBlogPostsCollection":11858,"slug":2911,"stem":13707,"subtitle":59,"summary":13708,"synopsis":2909,"sys":13718,"tagsCollection":13720,"topicsCollection":13726,"__hash__":13822},"blog/blog/browser-threat-landscape-mid-year-update-2026.json",{"items":10716},[10717],{"fullName":2925,"firstName":2926,"jobTitle":2927,"socialLinks":10718,"profilePicture":10720},[10719],"https://www.linkedin.com/in/daniel-g-/",{"url":2929},{"json":10722,"links":11769},{"data":10723,"content":10724,"nodeType":669},{},[10725,10731,10734,10741,10765,10772,10777,10801,10888,10921,10928,10970,10994,10999,11002,11009,11015,11022,11037,11079,11084,11090,11105,11110,11116,11121,11127,11132,11138,11143,11150,11183,11207,11222,11246,11253,11277,11301,11325,11332,11338,11353,11395,11419,11426,11441,11474,11477,11484,11490,11496,11511,11516,11522,11616,11649,11656,11671,11677,11680,11687,11693,11732,11738,11741,11747,11753],{"data":10726,"content":10727,"nodeType":673},{},[10728],{"data":10729,"marks":10730,"value":1621,"nodeType":543},{},[],{"data":10732,"content":10733,"nodeType":796},{},[],{"data":10735,"content":10736,"nodeType":800},{},[10737],{"data":10738,"marks":10739,"value":1632,"nodeType":543},{},[10740],{"type":749},{"data":10742,"content":10743,"nodeType":673},{},[10744,10747,10753,10756,10762],{"data":10745,"marks":10746,"value":1639,"nodeType":543},{},[],{"data":10748,"content":10749,"nodeType":695},{"uri":1642},[10750],{"data":10751,"marks":10752,"value":1647,"nodeType":543},{},[],{"data":10754,"marks":10755,"value":1651,"nodeType":543},{},[],{"data":10757,"content":10758,"nodeType":695},{"uri":907},[10759],{"data":10760,"marks":10761,"value":1658,"nodeType":543},{},[],{"data":10763,"marks":10764,"value":1662,"nodeType":543},{},[],{"data":10766,"content":10767,"nodeType":673},{},[10768],{"data":10769,"marks":10770,"value":1670,"nodeType":543},{},[10771],{"type":749},{"data":10773,"content":10776,"nodeType":787},{"target":10774},{"sys":10775},{"id":1675,"type":792,"linkType":793},[],{"data":10778,"content":10779,"nodeType":673},{},[10780,10783,10789,10792,10798],{"data":10781,"marks":10782,"value":1683,"nodeType":543},{},[],{"data":10784,"content":10785,"nodeType":695},{"uri":1686},[10786],{"data":10787,"marks":10788,"value":1691,"nodeType":543},{},[],{"data":10790,"marks":10791,"value":1695,"nodeType":543},{},[],{"data":10793,"content":10794,"nodeType":695},{"uri":1698},[10795],{"data":10796,"marks":10797,"value":1703,"nodeType":543},{},[],{"data":10799,"marks":10800,"value":1707,"nodeType":543},{},[],{"data":10802,"content":10803,"nodeType":673},{},[10804,10807,10813,10816,10822,10825,10831,10834,10840,10843,10849,10852,10858,10861,10867,10870,10876,10879,10885],{"data":10805,"marks":10806,"value":1714,"nodeType":543},{},[],{"data":10808,"content":10809,"nodeType":695},{"uri":1717},[10810],{"data":10811,"marks":10812,"value":1722,"nodeType":543},{},[],{"data":10814,"marks":10815,"value":1726,"nodeType":543},{},[],{"data":10817,"content":10818,"nodeType":695},{"uri":1729},[10819],{"data":10820,"marks":10821,"value":1734,"nodeType":543},{},[],{"data":10823,"marks":10824,"value":1738,"nodeType":543},{},[],{"data":10826,"content":10827,"nodeType":695},{"uri":1741},[10828],{"data":10829,"marks":10830,"value":1746,"nodeType":543},{},[],{"data":10832,"marks":10833,"value":1750,"nodeType":543},{},[],{"data":10835,"content":10836,"nodeType":695},{"uri":1753},[10837],{"data":10838,"marks":10839,"value":1758,"nodeType":543},{},[],{"data":10841,"marks":10842,"value":1762,"nodeType":543},{},[],{"data":10844,"content":10845,"nodeType":695},{"uri":1765},[10846],{"data":10847,"marks":10848,"value":1770,"nodeType":543},{},[],{"data":10850,"marks":10851,"value":1774,"nodeType":543},{},[],{"data":10853,"content":10854,"nodeType":695},{"uri":1777},[10855],{"data":10856,"marks":10857,"value":1782,"nodeType":543},{},[],{"data":10859,"marks":10860,"value":1786,"nodeType":543},{},[],{"data":10862,"content":10863,"nodeType":695},{"uri":1789},[10864],{"data":10865,"marks":10866,"value":1794,"nodeType":543},{},[],{"data":10868,"marks":10869,"value":1798,"nodeType":543},{},[],{"data":10871,"content":10872,"nodeType":695},{"uri":1801},[10873],{"data":10874,"marks":10875,"value":1806,"nodeType":543},{},[],{"data":10877,"marks":10878,"value":1810,"nodeType":543},{},[],{"data":10880,"content":10881,"nodeType":695},{"uri":1813},[10882],{"data":10883,"marks":10884,"value":1818,"nodeType":543},{},[],{"data":10886,"marks":10887,"value":1822,"nodeType":543},{},[],{"data":10889,"content":10890,"nodeType":673},{},[10891,10894,10900,10903,10909,10912,10918],{"data":10892,"marks":10893,"value":1829,"nodeType":543},{},[],{"data":10895,"content":10896,"nodeType":695},{"uri":716},[10897],{"data":10898,"marks":10899,"value":719,"nodeType":543},{},[],{"data":10901,"marks":10902,"value":1839,"nodeType":543},{},[],{"data":10904,"content":10905,"nodeType":695},{"uri":1842},[10906],{"data":10907,"marks":10908,"value":1847,"nodeType":543},{},[],{"data":10910,"marks":10911,"value":1851,"nodeType":543},{},[],{"data":10913,"content":10914,"nodeType":695},{"uri":1854},[10915],{"data":10916,"marks":10917,"value":1859,"nodeType":543},{},[],{"data":10919,"marks":10920,"value":1863,"nodeType":543},{},[],{"data":10922,"content":10923,"nodeType":829},{},[10924],{"data":10925,"marks":10926,"value":1871,"nodeType":543},{},[10927],{"type":749},{"data":10929,"content":10930,"nodeType":673},{},[10931,10934,10940,10943,10949,10952,10958,10961,10967],{"data":10932,"marks":10933,"value":1878,"nodeType":543},{},[],{"data":10935,"content":10936,"nodeType":695},{"uri":1881},[10937],{"data":10938,"marks":10939,"value":1886,"nodeType":543},{},[],{"data":10941,"marks":10942,"value":1890,"nodeType":543},{},[],{"data":10944,"content":10945,"nodeType":695},{"uri":1893},[10946],{"data":10947,"marks":10948,"value":1898,"nodeType":543},{},[],{"data":10950,"marks":10951,"value":1902,"nodeType":543},{},[],{"data":10953,"content":10954,"nodeType":695},{"uri":1905},[10955],{"data":10956,"marks":10957,"value":1910,"nodeType":543},{},[],{"data":10959,"marks":10960,"value":1914,"nodeType":543},{},[],{"data":10962,"content":10963,"nodeType":695},{"uri":1917},[10964],{"data":10965,"marks":10966,"value":1922,"nodeType":543},{},[],{"data":10968,"marks":10969,"value":1926,"nodeType":543},{},[],{"data":10971,"content":10972,"nodeType":673},{},[10973,10976,10982,10985,10991],{"data":10974,"marks":10975,"value":1933,"nodeType":543},{},[],{"data":10977,"content":10978,"nodeType":695},{"uri":1936},[10979],{"data":10980,"marks":10981,"value":1941,"nodeType":543},{},[],{"data":10983,"marks":10984,"value":1945,"nodeType":543},{},[],{"data":10986,"content":10987,"nodeType":695},{"uri":1948},[10988],{"data":10989,"marks":10990,"value":1953,"nodeType":543},{},[],{"data":10992,"marks":10993,"value":1957,"nodeType":543},{},[],{"data":10995,"content":10998,"nodeType":787},{"target":10996},{"sys":10997},{"id":1962,"type":792,"linkType":793},[],{"data":11000,"content":11001,"nodeType":796},{},[],{"data":11003,"content":11004,"nodeType":800},{},[11005],{"data":11006,"marks":11007,"value":1974,"nodeType":543},{},[11008],{"type":749},{"data":11010,"content":11011,"nodeType":673},{},[11012],{"data":11013,"marks":11014,"value":1981,"nodeType":543},{},[],{"data":11016,"content":11017,"nodeType":829},{},[11018],{"data":11019,"marks":11020,"value":1989,"nodeType":543},{},[11021],{"type":749},{"data":11023,"content":11024,"nodeType":673},{},[11025,11028,11034],{"data":11026,"marks":11027,"value":1996,"nodeType":543},{},[],{"data":11029,"content":11030,"nodeType":695},{"uri":716},[11031],{"data":11032,"marks":11033,"value":719,"nodeType":543},{},[],{"data":11035,"marks":11036,"value":2006,"nodeType":543},{},[],{"data":11038,"content":11039,"nodeType":673},{},[11040,11043,11049,11052,11058,11061,11067,11070,11076],{"data":11041,"marks":11042,"value":2013,"nodeType":543},{},[],{"data":11044,"content":11045,"nodeType":695},{"uri":2016},[11046],{"data":11047,"marks":11048,"value":2021,"nodeType":543},{},[],{"data":11050,"marks":11051,"value":2025,"nodeType":543},{},[],{"data":11053,"content":11054,"nodeType":695},{"uri":2028},[11055],{"data":11056,"marks":11057,"value":2033,"nodeType":543},{},[],{"data":11059,"marks":11060,"value":2037,"nodeType":543},{},[],{"data":11062,"content":11063,"nodeType":695},{"uri":2040},[11064],{"data":11065,"marks":11066,"value":2045,"nodeType":543},{},[],{"data":11068,"marks":11069,"value":2049,"nodeType":543},{},[],{"data":11071,"content":11072,"nodeType":695},{"uri":2052},[11073],{"data":11074,"marks":11075,"value":2057,"nodeType":543},{},[],{"data":11077,"marks":11078,"value":2061,"nodeType":543},{},[],{"data":11080,"content":11083,"nodeType":787},{"target":11081},{"sys":11082},{"id":2066,"type":792,"linkType":793},[],{"data":11085,"content":11086,"nodeType":673},{},[11087],{"data":11088,"marks":11089,"value":2074,"nodeType":543},{},[],{"data":11091,"content":11092,"nodeType":673},{},[11093,11096,11102],{"data":11094,"marks":11095,"value":2081,"nodeType":543},{},[],{"data":11097,"content":11098,"nodeType":695},{"uri":895},[11099],{"data":11100,"marks":11101,"value":2088,"nodeType":543},{},[],{"data":11103,"marks":11104,"value":2092,"nodeType":543},{},[],{"data":11106,"content":11109,"nodeType":787},{"target":11107},{"sys":11108},{"id":2097,"type":792,"linkType":793},[],{"data":11111,"content":11112,"nodeType":673},{},[11113],{"data":11114,"marks":11115,"value":2105,"nodeType":543},{},[],{"data":11117,"content":11120,"nodeType":787},{"target":11118},{"sys":11119},{"id":2110,"type":792,"linkType":793},[],{"data":11122,"content":11123,"nodeType":673},{},[11124],{"data":11125,"marks":11126,"value":2118,"nodeType":543},{},[],{"data":11128,"content":11131,"nodeType":787},{"target":11129},{"sys":11130},{"id":2123,"type":792,"linkType":793},[],{"data":11133,"content":11134,"nodeType":673},{},[11135],{"data":11136,"marks":11137,"value":2131,"nodeType":543},{},[],{"data":11139,"content":11142,"nodeType":787},{"target":11140},{"sys":11141},{"id":2136,"type":792,"linkType":793},[],{"data":11144,"content":11145,"nodeType":829},{},[11146],{"data":11147,"marks":11148,"value":2145,"nodeType":543},{},[11149],{"type":749},{"data":11151,"content":11152,"nodeType":673},{},[11153,11156,11162,11165,11171,11174,11180],{"data":11154,"marks":11155,"value":2152,"nodeType":543},{},[],{"data":11157,"content":11158,"nodeType":695},{"uri":2155},[11159],{"data":11160,"marks":11161,"value":2160,"nodeType":543},{},[],{"data":11163,"marks":11164,"value":2164,"nodeType":543},{},[],{"data":11166,"content":11167,"nodeType":695},{"uri":2167},[11168],{"data":11169,"marks":11170,"value":2172,"nodeType":543},{},[],{"data":11172,"marks":11173,"value":2176,"nodeType":543},{},[],{"data":11175,"content":11176,"nodeType":695},{"uri":2179},[11177],{"data":11178,"marks":11179,"value":2184,"nodeType":543},{},[],{"data":11181,"marks":11182,"value":2188,"nodeType":543},{},[],{"data":11184,"content":11185,"nodeType":673},{},[11186,11189,11195,11198,11204],{"data":11187,"marks":11188,"value":2195,"nodeType":543},{},[],{"data":11190,"content":11191,"nodeType":695},{"uri":2198},[11192],{"data":11193,"marks":11194,"value":2203,"nodeType":543},{},[],{"data":11196,"marks":11197,"value":2207,"nodeType":543},{},[],{"data":11199,"content":11200,"nodeType":695},{"uri":2210},[11201],{"data":11202,"marks":11203,"value":2215,"nodeType":543},{},[],{"data":11205,"marks":11206,"value":2219,"nodeType":543},{},[],{"data":11208,"content":11209,"nodeType":673},{},[11210,11213,11219],{"data":11211,"marks":11212,"value":2226,"nodeType":543},{},[],{"data":11214,"content":11215,"nodeType":695},{"uri":2229},[11216],{"data":11217,"marks":11218,"value":2234,"nodeType":543},{},[],{"data":11220,"marks":11221,"value":2238,"nodeType":543},{},[],{"data":11223,"content":11224,"nodeType":673},{},[11225,11228,11234,11237,11243],{"data":11226,"marks":11227,"value":2245,"nodeType":543},{},[],{"data":11229,"content":11230,"nodeType":695},{"uri":2248},[11231],{"data":11232,"marks":11233,"value":2253,"nodeType":543},{},[],{"data":11235,"marks":11236,"value":2257,"nodeType":543},{},[],{"data":11238,"content":11239,"nodeType":695},{"uri":697},[11240],{"data":11241,"marks":11242,"value":2264,"nodeType":543},{},[],{"data":11244,"marks":11245,"value":2268,"nodeType":543},{},[],{"data":11247,"content":11248,"nodeType":829},{},[11249],{"data":11250,"marks":11251,"value":2276,"nodeType":543},{},[11252],{"type":749},{"data":11254,"content":11255,"nodeType":673},{},[11256,11259,11265,11268,11274],{"data":11257,"marks":11258,"value":2283,"nodeType":543},{},[],{"data":11260,"content":11261,"nodeType":695},{"uri":2286},[11262],{"data":11263,"marks":11264,"value":2291,"nodeType":543},{},[],{"data":11266,"marks":11267,"value":2295,"nodeType":543},{},[],{"data":11269,"content":11270,"nodeType":695},{"uri":2298},[11271],{"data":11272,"marks":11273,"value":2303,"nodeType":543},{},[],{"data":11275,"marks":11276,"value":2307,"nodeType":543},{},[],{"data":11278,"content":11279,"nodeType":673},{},[11280,11283,11289,11292,11298],{"data":11281,"marks":11282,"value":2314,"nodeType":543},{},[],{"data":11284,"content":11285,"nodeType":695},{"uri":2317},[11286],{"data":11287,"marks":11288,"value":2322,"nodeType":543},{},[],{"data":11290,"marks":11291,"value":2326,"nodeType":543},{},[],{"data":11293,"content":11294,"nodeType":695},{"uri":2329},[11295],{"data":11296,"marks":11297,"value":2334,"nodeType":543},{},[],{"data":11299,"marks":11300,"value":2338,"nodeType":543},{},[],{"data":11302,"content":11303,"nodeType":673},{},[11304,11307,11313,11316,11322],{"data":11305,"marks":11306,"value":2345,"nodeType":543},{},[],{"data":11308,"content":11309,"nodeType":695},{"uri":2348},[11310],{"data":11311,"marks":11312,"value":2353,"nodeType":543},{},[],{"data":11314,"marks":11315,"value":2357,"nodeType":543},{},[],{"data":11317,"content":11318,"nodeType":695},{"uri":2360},[11319],{"data":11320,"marks":11321,"value":2365,"nodeType":543},{},[],{"data":11323,"marks":11324,"value":2369,"nodeType":543},{},[],{"data":11326,"content":11327,"nodeType":829},{},[11328],{"data":11329,"marks":11330,"value":2377,"nodeType":543},{},[11331],{"type":749},{"data":11333,"content":11334,"nodeType":673},{},[11335],{"data":11336,"marks":11337,"value":2384,"nodeType":543},{},[],{"data":11339,"content":11340,"nodeType":673},{},[11341,11344,11350],{"data":11342,"marks":11343,"value":2391,"nodeType":543},{},[],{"data":11345,"content":11346,"nodeType":695},{"uri":2394},[11347],{"data":11348,"marks":11349,"value":2399,"nodeType":543},{},[],{"data":11351,"marks":11352,"value":2403,"nodeType":543},{},[],{"data":11354,"content":11355,"nodeType":673},{},[11356,11359,11365,11368,11374,11377,11383,11386,11392],{"data":11357,"marks":11358,"value":2410,"nodeType":543},{},[],{"data":11360,"content":11361,"nodeType":695},{"uri":2413},[11362],{"data":11363,"marks":11364,"value":2418,"nodeType":543},{},[],{"data":11366,"marks":11367,"value":2422,"nodeType":543},{},[],{"data":11369,"content":11370,"nodeType":695},{"uri":2425},[11371],{"data":11372,"marks":11373,"value":2430,"nodeType":543},{},[],{"data":11375,"marks":11376,"value":2434,"nodeType":543},{},[],{"data":11378,"content":11379,"nodeType":695},{"uri":2437},[11380],{"data":11381,"marks":11382,"value":2442,"nodeType":543},{},[],{"data":11384,"marks":11385,"value":2446,"nodeType":543},{},[],{"data":11387,"content":11388,"nodeType":695},{"uri":2449},[11389],{"data":11390,"marks":11391,"value":2454,"nodeType":543},{},[],{"data":11393,"marks":11394,"value":1863,"nodeType":543},{},[],{"data":11396,"content":11397,"nodeType":673},{},[11398,11401,11407,11410,11416],{"data":11399,"marks":11400,"value":2464,"nodeType":543},{},[],{"data":11402,"content":11403,"nodeType":695},{"uri":2467},[11404],{"data":11405,"marks":11406,"value":2472,"nodeType":543},{},[],{"data":11408,"marks":11409,"value":2476,"nodeType":543},{},[],{"data":11411,"content":11412,"nodeType":695},{"uri":2479},[11413],{"data":11414,"marks":11415,"value":2484,"nodeType":543},{},[],{"data":11417,"marks":11418,"value":2488,"nodeType":543},{},[],{"data":11420,"content":11421,"nodeType":829},{},[11422],{"data":11423,"marks":11424,"value":2496,"nodeType":543},{},[11425],{"type":749},{"data":11427,"content":11428,"nodeType":673},{},[11429,11432,11438],{"data":11430,"marks":11431,"value":2503,"nodeType":543},{},[],{"data":11433,"content":11434,"nodeType":695},{"uri":1842},[11435],{"data":11436,"marks":11437,"value":2510,"nodeType":543},{},[],{"data":11439,"marks":11440,"value":2514,"nodeType":543},{},[],{"data":11442,"content":11443,"nodeType":673},{},[11444,11447,11453,11456,11462,11465,11471],{"data":11445,"marks":11446,"value":2521,"nodeType":543},{},[],{"data":11448,"content":11449,"nodeType":695},{"uri":2524},[11450],{"data":11451,"marks":11452,"value":2529,"nodeType":543},{},[],{"data":11454,"marks":11455,"value":2533,"nodeType":543},{},[],{"data":11457,"content":11458,"nodeType":695},{"uri":2536},[11459],{"data":11460,"marks":11461,"value":2541,"nodeType":543},{},[],{"data":11463,"marks":11464,"value":2545,"nodeType":543},{},[],{"data":11466,"content":11467,"nodeType":695},{"uri":2548},[11468],{"data":11469,"marks":11470,"value":2553,"nodeType":543},{},[],{"data":11472,"marks":11473,"value":2557,"nodeType":543},{},[],{"data":11475,"content":11476,"nodeType":796},{},[],{"data":11478,"content":11479,"nodeType":800},{},[11480],{"data":11481,"marks":11482,"value":2568,"nodeType":543},{},[11483],{"type":749},{"data":11485,"content":11486,"nodeType":673},{},[11487],{"data":11488,"marks":11489,"value":2575,"nodeType":543},{},[],{"data":11491,"content":11492,"nodeType":673},{},[11493],{"data":11494,"marks":11495,"value":2582,"nodeType":543},{},[],{"data":11497,"content":11498,"nodeType":673},{},[11499,11502,11508],{"data":11500,"marks":11501,"value":2589,"nodeType":543},{},[],{"data":11503,"content":11504,"nodeType":695},{"uri":2592},[11505],{"data":11506,"marks":11507,"value":2597,"nodeType":543},{},[],{"data":11509,"marks":11510,"value":21,"nodeType":543},{},[],{"data":11512,"content":11515,"nodeType":787},{"target":11513},{"sys":11514},{"id":2605,"type":792,"linkType":793},[],{"data":11517,"content":11518,"nodeType":673},{},[11519],{"data":11520,"marks":11521,"value":2613,"nodeType":543},{},[],{"data":11523,"content":11524,"nodeType":2727},{},[11525,11543,11561,11580,11598],{"data":11526,"content":11527,"nodeType":2639},{},[11528],{"data":11529,"content":11530,"nodeType":673},{},[11531,11534,11540],{"data":11532,"marks":11533,"value":2626,"nodeType":543},{},[],{"data":11535,"content":11536,"nodeType":695},{"uri":2629},[11537],{"data":11538,"marks":11539,"value":2634,"nodeType":543},{},[],{"data":11541,"marks":11542,"value":2638,"nodeType":543},{},[],{"data":11544,"content":11545,"nodeType":2639},{},[11546],{"data":11547,"content":11548,"nodeType":673},{},[11549,11552,11558],{"data":11550,"marks":11551,"value":2649,"nodeType":543},{},[],{"data":11553,"content":11554,"nodeType":695},{"uri":2040},[11555],{"data":11556,"marks":11557,"value":2656,"nodeType":543},{},[],{"data":11559,"marks":11560,"value":2660,"nodeType":543},{},[],{"data":11562,"content":11563,"nodeType":2639},{},[11564],{"data":11565,"content":11566,"nodeType":673},{},[11567,11570,11577],{"data":11568,"marks":11569,"value":21,"nodeType":543},{},[],{"data":11571,"content":11572,"nodeType":695},{"uri":2672},[11573],{"data":11574,"marks":11575,"value":2678,"nodeType":543},{},[11576],{"type":722},{"data":11578,"marks":11579,"value":2682,"nodeType":543},{},[],{"data":11581,"content":11582,"nodeType":2639},{},[11583],{"data":11584,"content":11585,"nodeType":673},{},[11586,11589,11595],{"data":11587,"marks":11588,"value":2692,"nodeType":543},{},[],{"data":11590,"content":11591,"nodeType":695},{"uri":2695},[11592],{"data":11593,"marks":11594,"value":2700,"nodeType":543},{},[],{"data":11596,"marks":11597,"value":2704,"nodeType":543},{},[],{"data":11599,"content":11600,"nodeType":2639},{},[11601],{"data":11602,"content":11603,"nodeType":673},{},[11604,11607,11613],{"data":11605,"marks":11606,"value":2714,"nodeType":543},{},[],{"data":11608,"content":11609,"nodeType":695},{"uri":2717},[11610],{"data":11611,"marks":11612,"value":2722,"nodeType":543},{},[],{"data":11614,"marks":11615,"value":2726,"nodeType":543},{},[],{"data":11617,"content":11618,"nodeType":673},{},[11619,11622,11628,11631,11637,11640,11646],{"data":11620,"marks":11621,"value":2734,"nodeType":543},{},[],{"data":11623,"content":11624,"nodeType":695},{"uri":2737},[11625],{"data":11626,"marks":11627,"value":2742,"nodeType":543},{},[],{"data":11629,"marks":11630,"value":2746,"nodeType":543},{},[],{"data":11632,"content":11633,"nodeType":695},{"uri":2749},[11634],{"data":11635,"marks":11636,"value":2754,"nodeType":543},{},[],{"data":11638,"marks":11639,"value":2758,"nodeType":543},{},[],{"data":11641,"content":11642,"nodeType":695},{"uri":2761},[11643],{"data":11644,"marks":11645,"value":2766,"nodeType":543},{},[],{"data":11647,"marks":11648,"value":2770,"nodeType":543},{},[],{"data":11650,"content":11651,"nodeType":829},{},[11652],{"data":11653,"marks":11654,"value":2778,"nodeType":543},{},[11655],{"type":749},{"data":11657,"content":11658,"nodeType":673},{},[11659,11662,11668],{"data":11660,"marks":11661,"value":2785,"nodeType":543},{},[],{"data":11663,"content":11664,"nodeType":695},{"uri":2788},[11665],{"data":11666,"marks":11667,"value":2793,"nodeType":543},{},[],{"data":11669,"marks":11670,"value":2797,"nodeType":543},{},[],{"data":11672,"content":11673,"nodeType":673},{},[11674],{"data":11675,"marks":11676,"value":2804,"nodeType":543},{},[],{"data":11678,"content":11679,"nodeType":796},{},[],{"data":11681,"content":11682,"nodeType":800},{},[11683],{"data":11684,"marks":11685,"value":2815,"nodeType":543},{},[11686],{"type":749},{"data":11688,"content":11689,"nodeType":673},{},[11690],{"data":11691,"marks":11692,"value":2822,"nodeType":543},{},[],{"data":11694,"content":11695,"nodeType":2727},{},[11696,11705,11714,11723],{"data":11697,"content":11698,"nodeType":2639},{},[11699],{"data":11700,"content":11701,"nodeType":673},{},[11702],{"data":11703,"marks":11704,"value":2835,"nodeType":543},{},[],{"data":11706,"content":11707,"nodeType":2639},{},[11708],{"data":11709,"content":11710,"nodeType":673},{},[11711],{"data":11712,"marks":11713,"value":2845,"nodeType":543},{},[],{"data":11715,"content":11716,"nodeType":2639},{},[11717],{"data":11718,"content":11719,"nodeType":673},{},[11720],{"data":11721,"marks":11722,"value":2855,"nodeType":543},{},[],{"data":11724,"content":11725,"nodeType":2639},{},[11726],{"data":11727,"content":11728,"nodeType":673},{},[11729],{"data":11730,"marks":11731,"value":2865,"nodeType":543},{},[],{"data":11733,"content":11734,"nodeType":673},{},[11735],{"data":11736,"marks":11737,"value":2872,"nodeType":543},{},[],{"data":11739,"content":11740,"nodeType":796},{},[],{"data":11742,"content":11743,"nodeType":673},{},[11744],{"data":11745,"marks":11746,"value":2882,"nodeType":543},{},[],{"data":11748,"content":11749,"nodeType":673},{},[11750],{"data":11751,"marks":11752,"value":2889,"nodeType":543},{},[],{"data":11754,"content":11755,"nodeType":673},{},[11756,11759,11766],{"data":11757,"marks":11758,"value":21,"nodeType":543},{},[],{"data":11760,"content":11761,"nodeType":695},{"uri":2898},[11762],{"data":11763,"marks":11764,"value":2904,"nodeType":543},{},[11765],{"type":722},{"data":11767,"marks":11768,"value":21,"nodeType":543},{},[],{"entries":11770},{"hyperlink":11771,"inline":11772,"block":11773},[],[],[11774,11779,11800,11805,11831,11837,11842,11846],{"sys":11775,"__typename":1393,"title":11776,"caption":11776,"layoutMode":59,"file":11777},{"id":1675}," Public breaches and campaigns with a browser and identity-related breach vector in 2026.",{"url":11778,"width":1408,"height":7471},"https://images.ctfassets.net/y1cdw1ablpvd/7DDf4WnfcZa3U9C6Leyu14/f6b7e43f663a387ed7238e4a47e4e215/image2.png",{"sys":11780,"__typename":1332,"content":11781,"name":11799,"title":59},{"id":1962},{"json":11782},{"nodeType":669,"data":11783,"content":11784},{},[11785,11792],{"nodeType":673,"data":11786,"content":11787},{},[11788],{"nodeType":543,"value":11789,"marks":11790,"data":11791},"\"The Com\" affiliates increasingly set the playbook for other criminal groups, and even nation-state operators. It might not always be super sophisticated, but they've proven the playbook works. And from the APT's perspective, why burn an exploit if you can achieve the same with a phish kit?",[],{},{"nodeType":673,"data":11793,"content":11794},{},[11795],{"nodeType":543,"value":11796,"marks":11797,"data":11798},"\n",[],{},"Browser attacks update IB1",{"sys":11801,"__typename":1393,"title":11802,"caption":11802,"layoutMode":59,"file":11803},{"id":2066},"Detections by device code phishing kit. Kits are multiplying and fragmenting each month, with a long tail of kits not named here.",{"url":11804,"width":1408,"height":7471},"https://images.ctfassets.net/y1cdw1ablpvd/3VgSTD544VehTl3THm4zpa/dd7e8610c29b283f38a3fa17a0614c90/image1.png",{"sys":11806,"__typename":1332,"content":11807,"name":11830,"title":59},{"id":2097},{"json":11808},{"nodeType":669,"data":11809,"content":11810},{},[11811],{"nodeType":673,"data":11812,"content":11813},{},[11814,11818,11826],{"nodeType":543,"value":11815,"marks":11816,"data":11817},"Tycoon is a particularly notable example because following a public takedown of its AiTM infrastructure, some recent reports have ",[],{},{"nodeType":695,"data":11819,"content":11821},{"uri":11820},"https://cybersecuritynews.com/top-10-phishing-kits-used-by-hackers/",[11822],{"nodeType":543,"value":11823,"marks":11824,"data":11825},"Tycoon detections dropping",[],{},{"nodeType":543,"value":11827,"marks":11828,"data":11829},", but we're finding that actually Tycoon device code attacks in particular have bounced back in our detections. ",[],{},"Browser attacks update IB2",{"sys":11832,"__typename":1393,"title":11833,"caption":11833,"layoutMode":59,"file":11834},{"id":2110},"Push Security detections by phishing kit, April-June 2026",{"url":11835,"width":1408,"height":11836},"https://images.ctfassets.net/y1cdw1ablpvd/71NeNdtXc5hbJrhfypTFS1/b7159dc73169225ff36bbbdf75d7b059/image3.png",1082,{"sys":11838,"__typename":1387,"title":11839,"arcadeDemoUrl":11840,"playText":11841},{"id":2123},"Tycoon2FA Device Code Phishing","https://demo.arcade.software/SPNMxNkoyY5vTMPPlqWS?embed","30 secs",{"sys":11843,"__typename":1387,"title":11844,"arcadeDemoUrl":11845,"playText":11841},{"id":2136},"Device code phishing to AITM fallback","https://demo.arcade.software/6qbvBCrv9ncUnwSv7kQJ?embed",{"sys":11847,"__typename":1393,"title":11848,"caption":11848,"layoutMode":59,"file":11849},{"id":2605},"Verbose phishing kit comments (a clear sign of AI involvement).",{"url":11850,"width":11851,"height":11852},"https://images.ctfassets.net/y1cdw1ablpvd/2XOX0xzOxsmBKUuQbup47x/a624c2141879f9238704167a35fdeb39/Screenshot_2026-05-07_at_12.53.27.png",1100,1332,{"items":11854},[],{},"How browser attacks are evolving in 2026 so far","thought-leadership",{"items":11859},[11860,12433,12860],{"__typename":1608,"sys":11861,"content":11862,"title":8458,"synopsis":8459,"hashTags":59,"publishedDate":8460,"slug":8461,"tagsCollection":12423,"authorsCollection":12429},{"id":7800},{"json":11863},{"data":11864,"content":11865,"nodeType":669},{},[11866,11872,11878,11884,11889,11892,11899,11905,11934,11940,11964,11969,11972,11979,11985,11992,12026,12031,12037,12042,12045,12052,12058,12065,12071,12077,12090,12097,12117,12123,12128,12134,12141,12154,12176,12181,12196,12201,12208,12214,12234,12240,12246,12252,12257,12260,12267,12273,12279,12294,12301,12307,12314,12333,12343,12348,12351,12358,12364,12370,12376,12392,12395,12401,12407],{"data":11867,"content":11868,"nodeType":673},{},[11869],{"data":11870,"marks":11871,"value":7811,"nodeType":543},{},[],{"data":11873,"content":11874,"nodeType":673},{},[11875],{"data":11876,"marks":11877,"value":7818,"nodeType":543},{},[],{"data":11879,"content":11880,"nodeType":673},{},[11881],{"data":11882,"marks":11883,"value":7825,"nodeType":543},{},[],{"data":11885,"content":11888,"nodeType":787},{"target":11886},{"sys":11887},{"id":7830,"type":792,"linkType":793},[],{"data":11890,"content":11891,"nodeType":796},{},[],{"data":11893,"content":11894,"nodeType":800},{},[11895],{"data":11896,"marks":11897,"value":7842,"nodeType":543},{},[11898],{"type":749},{"data":11900,"content":11901,"nodeType":673},{},[11902],{"data":11903,"marks":11904,"value":7849,"nodeType":543},{},[],{"data":11906,"content":11907,"nodeType":2727},{},[11908,11921],{"data":11909,"content":11910,"nodeType":2639},{},[11911],{"data":11912,"content":11913,"nodeType":673},{},[11914,11918],{"data":11915,"marks":11916,"value":7863,"nodeType":543},{},[11917],{"type":749},{"data":11919,"marks":11920,"value":7867,"nodeType":543},{},[],{"data":11922,"content":11923,"nodeType":2639},{},[11924],{"data":11925,"content":11926,"nodeType":673},{},[11927,11931],{"data":11928,"marks":11929,"value":7878,"nodeType":543},{},[11930],{"type":749},{"data":11932,"marks":11933,"value":7882,"nodeType":543},{},[],{"data":11935,"content":11936,"nodeType":673},{},[11937],{"data":11938,"marks":11939,"value":7889,"nodeType":543},{},[],{"data":11941,"content":11942,"nodeType":673},{},[11943,11946,11952,11955,11961],{"data":11944,"marks":11945,"value":7896,"nodeType":543},{},[],{"data":11947,"content":11948,"nodeType":695},{"uri":7276},[11949],{"data":11950,"marks":11951,"value":7491,"nodeType":543},{},[],{"data":11953,"marks":11954,"value":7495,"nodeType":543},{},[],{"data":11956,"content":11957,"nodeType":695},{"uri":907},[11958],{"data":11959,"marks":11960,"value":7502,"nodeType":543},{},[],{"data":11962,"marks":11963,"value":7506,"nodeType":543},{},[],{"data":11965,"content":11968,"nodeType":787},{"target":11966},{"sys":11967},{"id":7919,"type":792,"linkType":793},[],{"data":11970,"content":11971,"nodeType":796},{},[],{"data":11973,"content":11974,"nodeType":800},{},[11975],{"data":11976,"marks":11977,"value":7931,"nodeType":543},{},[11978],{"type":749},{"data":11980,"content":11981,"nodeType":673},{},[11982],{"data":11983,"marks":11984,"value":7938,"nodeType":543},{},[],{"data":11986,"content":11987,"nodeType":673},{},[11988],{"data":11989,"marks":11990,"value":7946,"nodeType":543},{},[11991],{"type":749},{"data":11993,"content":11994,"nodeType":673},{},[11995,11998,12002,12005,12009,12012,12016,12019,12023],{"data":11996,"marks":11997,"value":7953,"nodeType":543},{},[],{"data":11999,"marks":12000,"value":7958,"nodeType":543},{},[12001],{"type":749},{"data":12003,"marks":12004,"value":7962,"nodeType":543},{},[],{"data":12006,"marks":12007,"value":7967,"nodeType":543},{},[12008],{"type":749},{"data":12010,"marks":12011,"value":3232,"nodeType":543},{},[],{"data":12013,"marks":12014,"value":7975,"nodeType":543},{},[12015],{"type":749},{"data":12017,"marks":12018,"value":7979,"nodeType":543},{},[],{"data":12020,"marks":12021,"value":7984,"nodeType":543},{},[12022],{"type":739},{"data":12024,"marks":12025,"value":7988,"nodeType":543},{},[],{"data":12027,"content":12030,"nodeType":787},{"target":12028},{"sys":12029},{"id":7993,"type":792,"linkType":793},[],{"data":12032,"content":12033,"nodeType":673},{},[12034],{"data":12035,"marks":12036,"value":8001,"nodeType":543},{},[],{"data":12038,"content":12041,"nodeType":787},{"target":12039},{"sys":12040},{"id":6776,"type":792,"linkType":793},[],{"data":12043,"content":12044,"nodeType":796},{},[],{"data":12046,"content":12047,"nodeType":800},{},[12048],{"data":12049,"marks":12050,"value":8017,"nodeType":543},{},[12051],{"type":749},{"data":12053,"content":12054,"nodeType":673},{},[12055],{"data":12056,"marks":12057,"value":8024,"nodeType":543},{},[],{"data":12059,"content":12060,"nodeType":829},{},[12061],{"data":12062,"marks":12063,"value":8032,"nodeType":543},{},[12064],{"type":749},{"data":12066,"content":12067,"nodeType":673},{},[12068],{"data":12069,"marks":12070,"value":8039,"nodeType":543},{},[],{"data":12072,"content":12073,"nodeType":673},{},[12074],{"data":12075,"marks":12076,"value":8046,"nodeType":543},{},[],{"data":12078,"content":12079,"nodeType":673},{},[12080,12083,12087],{"data":12081,"marks":12082,"value":8053,"nodeType":543},{},[],{"data":12084,"marks":12085,"value":8058,"nodeType":543},{},[12086],{"type":749},{"data":12088,"marks":12089,"value":8062,"nodeType":543},{},[],{"data":12091,"content":12092,"nodeType":829},{},[12093],{"data":12094,"marks":12095,"value":8070,"nodeType":543},{},[12096],{"type":749},{"data":12098,"content":12099,"nodeType":673},{},[12100,12103,12107,12110,12114],{"data":12101,"marks":12102,"value":8077,"nodeType":543},{},[],{"data":12104,"marks":12105,"value":8082,"nodeType":543},{},[12106],{"type":749},{"data":12108,"marks":12109,"value":8086,"nodeType":543},{},[],{"data":12111,"marks":12112,"value":8091,"nodeType":543},{},[12113],{"type":749},{"data":12115,"marks":12116,"value":8095,"nodeType":543},{},[],{"data":12118,"content":12119,"nodeType":673},{},[12120],{"data":12121,"marks":12122,"value":8102,"nodeType":543},{},[],{"data":12124,"content":12127,"nodeType":787},{"target":12125},{"sys":12126},{"id":8107,"type":792,"linkType":793},[],{"data":12129,"content":12130,"nodeType":673},{},[12131],{"data":12132,"marks":12133,"value":8115,"nodeType":543},{},[],{"data":12135,"content":12136,"nodeType":829},{},[12137],{"data":12138,"marks":12139,"value":8123,"nodeType":543},{},[12140],{"type":749},{"data":12142,"content":12143,"nodeType":673},{},[12144,12147,12151],{"data":12145,"marks":12146,"value":8130,"nodeType":543},{},[],{"data":12148,"marks":12149,"value":7967,"nodeType":543},{},[12150],{"type":749},{"data":12152,"marks":12153,"value":8138,"nodeType":543},{},[],{"data":12155,"content":12156,"nodeType":673},{},[12157,12160,12166,12169,12173],{"data":12158,"marks":12159,"value":8145,"nodeType":543},{},[],{"data":12161,"content":12162,"nodeType":695},{"uri":8148},[12163],{"data":12164,"marks":12165,"value":8153,"nodeType":543},{},[],{"data":12167,"marks":12168,"value":8157,"nodeType":543},{},[],{"data":12170,"marks":12171,"value":8162,"nodeType":543},{},[12172],{"type":749},{"data":12174,"marks":12175,"value":8166,"nodeType":543},{},[],{"data":12177,"content":12180,"nodeType":787},{"target":12178},{"sys":12179},{"id":8171,"type":792,"linkType":793},[],{"data":12182,"content":12183,"nodeType":673},{},[12184,12187,12193],{"data":12185,"marks":12186,"value":8179,"nodeType":543},{},[],{"data":12188,"content":12189,"nodeType":695},{"uri":8148},[12190],{"data":12191,"marks":12192,"value":8186,"nodeType":543},{},[],{"data":12194,"marks":12195,"value":8190,"nodeType":543},{},[],{"data":12197,"content":12200,"nodeType":787},{"target":12198},{"sys":12199},{"id":8195,"type":792,"linkType":793},[],{"data":12202,"content":12203,"nodeType":829},{},[12204],{"data":12205,"marks":12206,"value":8204,"nodeType":543},{},[12207],{"type":749},{"data":12209,"content":12210,"nodeType":673},{},[12211],{"data":12212,"marks":12213,"value":8211,"nodeType":543},{},[],{"data":12215,"content":12216,"nodeType":673},{},[12217,12220,12224,12227,12231],{"data":12218,"marks":12219,"value":8218,"nodeType":543},{},[],{"data":12221,"marks":12222,"value":8223,"nodeType":543},{},[12223],{"type":749},{"data":12225,"marks":12226,"value":8227,"nodeType":543},{},[],{"data":12228,"marks":12229,"value":8232,"nodeType":543},{},[12230],{"type":739},{"data":12232,"marks":12233,"value":8236,"nodeType":543},{},[],{"data":12235,"content":12236,"nodeType":673},{},[12237],{"data":12238,"marks":12239,"value":8243,"nodeType":543},{},[],{"data":12241,"content":12242,"nodeType":673},{},[12243],{"data":12244,"marks":12245,"value":8250,"nodeType":543},{},[],{"data":12247,"content":12248,"nodeType":673},{},[12249],{"data":12250,"marks":12251,"value":8257,"nodeType":543},{},[],{"data":12253,"content":12256,"nodeType":787},{"target":12254},{"sys":12255},{"id":8262,"type":792,"linkType":793},[],{"data":12258,"content":12259,"nodeType":796},{},[],{"data":12261,"content":12262,"nodeType":800},{},[12263],{"data":12264,"marks":12265,"value":8274,"nodeType":543},{},[12266],{"type":749},{"data":12268,"content":12269,"nodeType":673},{},[12270],{"data":12271,"marks":12272,"value":8281,"nodeType":543},{},[],{"data":12274,"content":12275,"nodeType":673},{},[12276],{"data":12277,"marks":12278,"value":8288,"nodeType":543},{},[],{"data":12280,"content":12281,"nodeType":673},{},[12282,12285,12291],{"data":12283,"marks":12284,"value":8295,"nodeType":543},{},[],{"data":12286,"content":12287,"nodeType":695},{"uri":8298},[12288],{"data":12289,"marks":12290,"value":8303,"nodeType":543},{},[],{"data":12292,"marks":12293,"value":8307,"nodeType":543},{},[],{"data":12295,"content":12296,"nodeType":829},{},[12297],{"data":12298,"marks":12299,"value":8315,"nodeType":543},{},[12300],{"type":749},{"data":12302,"content":12303,"nodeType":673},{},[12304],{"data":12305,"marks":12306,"value":8322,"nodeType":543},{},[],{"data":12308,"content":12309,"nodeType":673},{},[12310],{"data":12311,"marks":12312,"value":8330,"nodeType":543},{},[12313],{"type":749},{"data":12315,"content":12316,"nodeType":673},{},[12317,12321,12324,12330],{"data":12318,"marks":12319,"value":8338,"nodeType":543},{},[12320],{"type":749},{"data":12322,"marks":12323,"value":8342,"nodeType":543},{},[],{"data":12325,"content":12326,"nodeType":695},{"uri":8148},[12327],{"data":12328,"marks":12329,"value":8349,"nodeType":543},{},[],{"data":12331,"marks":12332,"value":8353,"nodeType":543},{},[],{"data":12334,"content":12335,"nodeType":673},{},[12336,12340],{"data":12337,"marks":12338,"value":8361,"nodeType":543},{},[12339],{"type":749},{"data":12341,"marks":12342,"value":8365,"nodeType":543},{},[],{"data":12344,"content":12347,"nodeType":787},{"target":12345},{"sys":12346},{"id":8370,"type":792,"linkType":793},[],{"data":12349,"content":12350,"nodeType":796},{},[],{"data":12352,"content":12353,"nodeType":800},{},[12354],{"data":12355,"marks":12356,"value":8382,"nodeType":543},{},[12357],{"type":749},{"data":12359,"content":12360,"nodeType":673},{},[12361],{"data":12362,"marks":12363,"value":8389,"nodeType":543},{},[],{"data":12365,"content":12366,"nodeType":673},{},[12367],{"data":12368,"marks":12369,"value":8396,"nodeType":543},{},[],{"data":12371,"content":12372,"nodeType":673},{},[12373],{"data":12374,"marks":12375,"value":8403,"nodeType":543},{},[],{"data":12377,"content":12378,"nodeType":673},{},[12379,12382,12389],{"data":12380,"marks":12381,"value":8410,"nodeType":543},{},[],{"data":12383,"content":12384,"nodeType":695},{"uri":8413},[12385],{"data":12386,"marks":12387,"value":8419,"nodeType":543},{},[12388],{"type":722},{"data":12390,"marks":12391,"value":8423,"nodeType":543},{},[],{"data":12393,"content":12394,"nodeType":796},{},[],{"data":12396,"content":12397,"nodeType":673},{},[12398],{"data":12399,"marks":12400,"value":2882,"nodeType":543},{},[],{"data":12402,"content":12403,"nodeType":673},{},[12404],{"data":12405,"marks":12406,"value":2889,"nodeType":543},{},[],{"data":12408,"content":12409,"nodeType":673},{},[12410,12413,12420],{"data":12411,"marks":12412,"value":8445,"nodeType":543},{},[],{"data":12414,"content":12415,"nodeType":695},{"uri":5926},[12416],{"data":12417,"marks":12418,"value":8453,"nodeType":543},{},[12419],{"type":722},{"data":12421,"marks":12422,"value":8457,"nodeType":543},{},[],{"items":12424},[12425,12427],{"sys":12426,"name":8467},{"id":8466},{"sys":12428,"name":8471},{"id":8470},{"items":12430},[12431],{"fullName":2925,"firstName":2926,"jobTitle":2927,"profilePicture":12432},{"url":2929},{"__typename":1608,"sys":12434,"content":12436,"title":12846,"synopsis":12847,"hashTags":59,"publishedDate":12848,"slug":12849,"tagsCollection":12850,"authorsCollection":12856},{"id":12435},"4fUZAVpkaksHImeoT8jp0f",{"json":12437},{"data":12438,"content":12439,"nodeType":669},{},[12440,12447,12454,12461,12468,12475,12495,12502,12509,12516,12522,12525,12532,12551,12557,12573,12589,12604,12620,12627,12634,12641,12647,12654,12661,12668,12675,12681,12701,12716,12723,12730,12737,12744,12751,12758,12764,12771,12778,12785,12792,12799,12806,12813,12820,12827],{"data":12441,"content":12442,"nodeType":673},{},[12443],{"data":12444,"marks":12445,"value":12446,"nodeType":543},{},[],"Every security engineer has a version of this ritual. ",{"data":12448,"content":12449,"nodeType":673},{},[12450],{"data":12451,"marks":12452,"value":12453,"nodeType":543},{},[],"A new campaign hits the news, and you already hear the question coming, “Are we covered?”",{"data":12455,"content":12456,"nodeType":673},{},[12457],{"data":12458,"marks":12459,"value":12460,"nodeType":543},{},[],"So you read the writeup and quickly do the calculus on whether you can extract meaningful data, something to base a behavioral detection around — or not.",{"data":12462,"content":12463,"nodeType":673},{},[12464],{"data":12465,"marks":12466,"value":12467,"nodeType":543},{},[],"Then the choice is: Send the IOCs you can identify to your blocklists and move on for now, or try to dig deeper. The limitations of the first choice are clear; so are the challenges of the second.",{"data":12469,"content":12470,"nodeType":673},{},[12471],{"data":12472,"marks":12473,"value":12474,"nodeType":543},{},[],"That’s the uncomfortable gap between “We’re aware of this threat” and “We have strong detections around it.”",{"data":12476,"content":12477,"nodeType":673},{},[12478,12482,12491],{"data":12479,"marks":12480,"value":12481,"nodeType":543},{},[],"Because you already know that the IOCs for a novel browser-based attack are likely outdated the moment you block them. And in the case of a ",{"data":12483,"content":12485,"nodeType":695},{"uri":12484},"https://www.microsoft.com/en-us/security/blog/2026/03/02/oauth-redirection-abuse-enables-phishing-malware-delivery/",[12486],{"data":12487,"marks":12488,"value":12490,"nodeType":543},{},[12489],{"type":722},"new technique observed by Microsoft",{"data":12492,"marks":12493,"value":12494,"nodeType":543},{},[]," earlier this year, you’d be right.",{"data":12496,"content":12497,"nodeType":673},{},[12498],{"data":12499,"marks":12500,"value":12501,"nodeType":543},{},[],"In March, Push’s AI agents took a close look at that Microsoft intel, which details a discovered campaign built around a novel OAuth redirect abuse technique used to deliver users to phishing pages under the cover of trusted services’ OAuth flows. ",{"data":12503,"content":12504,"nodeType":673},{},[12505],{"data":12506,"marks":12507,"value":12508,"nodeType":543},{},[],"What we found was indicative of how these attacks rapidly evolve: No matches for the published IOCs across our install base. But a few months later, we got a true positive. Except it was for new lures, new variants, and different IOCs. What hadn’t changed was the underlying attack delivery technique, and that’s what we used to detect a new campaign on Push customer estates.",{"data":12510,"content":12511,"nodeType":673},{},[12512],{"data":12513,"marks":12514,"value":12515,"nodeType":543},{},[],"In this article, we’ll walk through this example as a case study of how agentic threat hunting helps us go beyond IOCs to extract durable behavioral indicators that close the gap between “We’re aware of this threat” and “We’re covered.”",{"data":12517,"content":12521,"nodeType":787},{"target":12518},{"sys":12519},{"id":12520,"type":792,"linkType":793},"6X7yXNdchH1Qp2tNKRAyVP",[],{"data":12523,"content":12524,"nodeType":796},{},[],{"data":12526,"content":12527,"nodeType":800},{},[12528],{"data":12529,"marks":12530,"value":12531,"nodeType":543},{},[],"The intel: Novel abuse of OAuth redirects as a phishing delivery mechanism",{"data":12533,"content":12534,"nodeType":673},{},[12535,12539,12547],{"data":12536,"marks":12537,"value":12538,"nodeType":543},{},[],"The technique ",{"data":12540,"content":12541,"nodeType":695},{"uri":12484},[12542],{"data":12543,"marks":12544,"value":12546,"nodeType":543},{},[12545],{"type":722},"Microsoft documented",{"data":12548,"marks":12549,"value":12550,"nodeType":543},{},[]," back in March is an interesting one. It doesn't steal tokens or abuse consent flows. Instead, it weaponizes the OAuth error-handling path itself — turning trusted identity provider domains into a delivery mechanism for phishing and malware.",{"data":12552,"content":12556,"nodeType":787},{"target":12553},{"sys":12554},{"id":12555,"type":792,"linkType":793},"486pfUpMxx15vJupxuiePn",[],{"data":12558,"content":12559,"nodeType":673},{},[12560,12564,12569],{"data":12561,"marks":12562,"value":12563,"nodeType":543},{},[],"Here's how it works. The attacker registers a malicious application in an actor-controlled tenant, pointing its redirect URI at attacker infrastructure. They craft an authorization URL using ",{"data":12565,"marks":12566,"value":12568,"nodeType":543},{},[12567],{"type":749},"prompt=none",{"data":12570,"marks":12571,"value":12572,"nodeType":543},{},[]," (forcing silent authentication) and an intentionally invalid scope, which guarantees an OAuth error. ",{"data":12574,"content":12575,"nodeType":673},{},[12576,12580,12585],{"data":12577,"marks":12578,"value":12579,"nodeType":543},{},[],"The identity provider — Microsoft Entra ID, Google Workspace, or any OAuth-compliant service — handles that error the way the spec says it should: By redirecting the browser to the application's registered redirect URI. The user clicks a link that begins at ",{"data":12581,"marks":12582,"value":12584,"nodeType":543},{},[12583],{"type":749},"login.microsoftonline.com",{"data":12586,"marks":12587,"value":12588,"nodeType":543},{},[],", passes through a legitimate authentication endpoint, and lands on an attacker-controlled page.",{"data":12590,"content":12591,"nodeType":673},{},[12592,12596,12600],{"data":12593,"marks":12594,"value":12595,"nodeType":543},{},[],"Importantly, no token is stolen during the redirect. The OAuth flow is the delivery vehicle, not the compromise mechanism. What happens ",{"data":12597,"marks":12598,"value":736,"nodeType":543},{},[12599],{"type":739},{"data":12601,"marks":12602,"value":12603,"nodeType":543},{},[]," the redirect — phishing, malware download, credential harvesting — is where the actual attack occurs.",{"data":12605,"content":12606,"nodeType":673},{},[12607,12611,12616],{"data":12608,"marks":12609,"value":12610,"nodeType":543},{},[],"This technique is also successful because conventional URL filtering sees a legitimate authentication domain, not a phishing destination. The redirect is standards-compliant behavior, and the initial URL carries the domain reputation of a trusted identity provider — which means the usual defenses at the network layer don't fire. (No TI or domain-based detection service in the world would raise a ",{"data":12612,"marks":12613,"value":12615,"nodeType":543},{},[12614],{"type":749},"microsoft.com",{"data":12617,"marks":12618,"value":12619,"nodeType":543},{},[]," domain as suspicious!)",{"data":12621,"content":12622,"nodeType":673},{},[12623],{"data":12624,"marks":12625,"value":12626,"nodeType":543},{},[],"With this intel, Push’s agents now had some useful fodder to hunt for.",{"data":12628,"content":12629,"nodeType":800},{},[12630],{"data":12631,"marks":12632,"value":12633,"nodeType":543},{},[],"Hunting from intel: How we developed a behavioral detection",{"data":12635,"content":12636,"nodeType":673},{},[12637],{"data":12638,"marks":12639,"value":12640,"nodeType":543},{},[],"It started with ingestion. When the Microsoft blog was published, Push's TI aggregation agent flagged it as relevant to our detection surface — the technique abuses OAuth redirect behavior observable in the browser, which maps directly to the metadata that Push's browser agent captures.",{"data":12642,"content":12646,"nodeType":787},{"target":12643},{"sys":12644},{"id":12645,"type":792,"linkType":793},"26saWWXsyFAZrsrfspGwaF",[],{"data":12648,"content":12649,"nodeType":673},{},[12650],{"data":12651,"marks":12652,"value":12653,"nodeType":543},{},[],"The Push intel agent understands not to hunt for IOCs, but rather to think in terms of durable behaviors. It understands the telemetry available to the Push browser extension, and then compares that to the telemetry it would expect to be able to extract for a given technique, before deciding what to hunt for.",{"data":12655,"content":12656,"nodeType":673},{},[12657],{"data":12658,"marks":12659,"value":12660,"nodeType":543},{},[],"In this case, the intel agent extracted two distinct behavioral elements from the research to look for: the OAuth redirect technique and the page users land on after the error.",{"data":12662,"content":12663,"nodeType":673},{},[12664],{"data":12665,"marks":12666,"value":12667,"nodeType":543},{},[],"That extraction step is where surface-level details can become technique-driven hunts. Microsoft's article listed specific client IDs, redirect URLs, and PowerShell command patterns — indicators that are useful for retrospective hunting but will rotate as the campaign evolves. ",{"data":12669,"content":12670,"nodeType":673},{},[12671],{"data":12672,"marks":12673,"value":12674,"nodeType":543},{},[],"The pipeline's job was to identify what wouldn't change: The behavioral mechanics of abusing the OAuth error redirect path as a delivery mechanism, independent of which domains, client IDs, or post-redirect payloads the attacker chose to use. This is the Pyramid of Pain principle in practice: Hunt for the technique, not the indicator, because techniques are genuinely hard for attackers to change.",{"data":12676,"content":12680,"nodeType":787},{"target":12677},{"sys":12678},{"id":12679,"type":792,"linkType":793},"7qUVlKVjHMkabu0MJ1S7gC",[],{"data":12682,"content":12683,"nodeType":673},{},[12684,12688,12697],{"data":12685,"marks":12686,"value":12687,"nodeType":543},{},[],"Next, the agents verified what they already knew from Push’s internal TTP knowledge base. In this case, the agents understood the well-known technique of ",{"data":12689,"content":12691,"nodeType":695},{"uri":12690},"https://owasp.org/www-community/attacks/open_redirect",[12692],{"data":12693,"marks":12694,"value":12696,"nodeType":543},{},[12695],{"type":722},"open redirects",{"data":12698,"marks":12699,"value":12700,"nodeType":543},{},[],", where attackers leverage redirects to deliver users to a malicious page. The example originally published by Microsoft was a novel variation of that — abusing a trusted service and the open redirect technique via a legitimate OAuth error workflow to deliver a multi-stage phishing attack.",{"data":12702,"content":12703,"nodeType":673},{},[12704,12708,12712],{"data":12705,"marks":12706,"value":12707,"nodeType":543},{},[],"AI models’ deep knowledge of web programming and frameworks is a particular strength here, because they understand which OAuth redirect behavior is normal and common across diverse scenarios, and can pinpoint which elements will be the strongest signal to hunt for malicious behavior. The agents immediately recognized that hunting for ",{"data":12709,"marks":12710,"value":12568,"nodeType":543},{},[12711],{"type":749},{"data":12713,"marks":12714,"value":12715,"nodeType":543},{},[]," would be too noisy, as legitimate apps regularly use silent token refresh.",{"data":12717,"content":12718,"nodeType":673},{},[12719],{"data":12720,"marks":12721,"value":12722,"nodeType":543},{},[],"In this case, the approach was simply to find all the instances where a user hit an OAuth error page, and then landed on a login page afterward. Normal behavior for error states would be to return an error response — not send the user on to a page with a password form field or a CAPTCHA. That’s highly suspicious.",{"data":12724,"content":12725,"nodeType":673},{},[12726],{"data":12727,"marks":12728,"value":12729,"nodeType":543},{},[],"The agents then built behavioral queries targeting both behavioral attributes of the attack, and validated them across Push's install base. ",{"data":12731,"content":12732,"nodeType":673},{},[12733],{"data":12734,"marks":12735,"value":12736,"nodeType":543},{},[],"When agents first looked in March, the hunts returned no true positives — the specific campaign Microsoft documented wasn’t active against Push customers at that time.",{"data":12738,"content":12739,"nodeType":673},{},[12740],{"data":12741,"marks":12742,"value":12743,"nodeType":543},{},[],"But the query logic was sound — precise enough to avoid false positives, broad enough to catch technique variants without relying on the specific IOCs that Microsoft documented. So the pipeline promoted it to a live query — a continuing detection that would surface any future instances of the technique across the customer base.",{"data":12745,"content":12746,"nodeType":800},{},[12747],{"data":12748,"marks":12749,"value":12750,"nodeType":543},{},[],"The hunt pays off: A new variant, completely different IOCs",{"data":12752,"content":12753,"nodeType":673},{},[12754],{"data":12755,"marks":12756,"value":12757,"nodeType":543},{},[],"In June, the query fired. A single user at a single customer had been targeted, but with a completely different scenario. ",{"data":12759,"content":12763,"nodeType":787},{"target":12760},{"sys":12761},{"id":12762,"type":792,"linkType":793},"7uXgOzxemy1PaJLhUa1txV",[],{"data":12765,"content":12766,"nodeType":673},{},[12767],{"data":12768,"marks":12769,"value":12770,"nodeType":543},{},[],"Where the Microsoft-documented example used lures presented as document-sharing links, Teams meeting recordings, or password resets, and the abused trusted service was a Microsoft login link used to trigger the OAuth error, the Push-observed attack chain used different elements. However, the behavioral technique at the core was the same.",{"data":12772,"content":12773,"nodeType":673},{},[12774],{"data":12775,"marks":12776,"value":12777,"nodeType":543},{},[],"In this case, the user clicked a link in a service desk ticket, triggering an OAuth flow that used a redirect URL with parameters designed to make it look like a Grammarly link. After hitting the OAuth error, the user was redirected to a page with a CAPTCHA, and then redirected again to a second page behind a Cloudflare Turnstile that was running a phish kit. While examining the phishing page, Push’s agents found a net-new phish kit that they later added additional detections for. ",{"data":12779,"content":12780,"nodeType":673},{},[12781],{"data":12782,"marks":12783,"value":12784,"nodeType":543},{},[],"Roughly a day after the Push detection fired, Google Safe Browsing flagged both domains as phishing domains. But when the user was first targeted, neither domain had been flagged. In this case, the user exited the redirect flow before entering any credentials.",{"data":12786,"content":12787,"nodeType":673},{},[12788],{"data":12789,"marks":12790,"value":12791,"nodeType":543},{},[],"It’s important to note that this phishing technique also bypasses other controls based on network content pattern analysis or domain-based detections. For example, a network proxy is designed to look for malicious webpages based on known-bad IOCs like domains or page content that contains known-bad script files. This technique uses a dynamic obfuscated Javascript blob that unpacks and loads the webpage on the client side after checking to see if it’s running in a live browser environment, evading proxy-based analysis.",{"data":12793,"content":12794,"nodeType":673},{},[12795],{"data":12796,"marks":12797,"value":12798,"nodeType":543},{},[],"The query now serves as another early-warning flag designed to be broad enough to catch other interesting new variants of this TTP.",{"data":12800,"content":12801,"nodeType":800},{},[12802],{"data":12803,"marks":12804,"value":12805,"nodeType":543},{},[],"Why technique-level detection pays dividends",{"data":12807,"content":12808,"nodeType":673},{},[12809],{"data":12810,"marks":12811,"value":12812,"nodeType":543},{},[],"This example demonstrates the value of behavioral detection. By focusing on technique extraction, we can stay a step ahead of attack evolution, identifying other contexts and campaigns that use the same behavioral technique, without relying on stale IOCs.",{"data":12814,"content":12815,"nodeType":673},{},[12816],{"data":12817,"marks":12818,"value":12819,"nodeType":543},{},[],"For customers, this means no one has to distil the threat intel report into behavioral elements, spend time crafting detections, or work to eliminate false positives. The Push agents do all that automatically, delivering a compounding benefit the more they learn. ",{"data":12821,"content":12822,"nodeType":673},{},[12823],{"data":12824,"marks":12825,"value":12826,"nodeType":543},{},[],"Customers get a fully operationalized threat-hunting and detection engineering capability; and the Push knowledge base itself expands with each new hunt, getting better at identifying emerging threats.",{"data":12828,"content":12829,"nodeType":673},{},[12830,12834,12842],{"data":12831,"marks":12832,"value":12833,"nodeType":543},{},[],"If you'd like to see how Push's detection pipeline would work in your environment, ",{"data":12835,"content":12836,"nodeType":695},{"uri":5926},[12837],{"data":12838,"marks":12839,"value":12841,"nodeType":543},{},[12840],{"type":722},"book a demo",{"data":12843,"marks":12844,"value":12845,"nodeType":543},{},[]," with our team.","From IOCs to TTPs: An agentic threat hunting case study","How Push’s agentic detection pipeline turns intel into huntable characteristics of attacker behavior, deriving durable detections from a range of sources.","2026-07-31T00:00:00.000Z","from-iocs-to-ttps-an-agentic-threat-hunting-case-study",{"items":12851},[12852,12854],{"sys":12853,"name":2917},{"id":2916},{"sys":12855,"name":2921},{"id":2920},{"items":12857},[12858],{"fullName":6598,"firstName":6599,"jobTitle":6600,"profilePicture":12859},{"url":6602},{"__typename":1608,"sys":12861,"content":12863,"title":13693,"synopsis":13694,"hashTags":59,"publishedDate":13695,"slug":13696,"tagsCollection":13697,"authorsCollection":13703},{"id":12862},"211Dd0EIrXPOFpvRgs0fEE",{"json":12864},{"data":12865,"content":12866,"nodeType":669},{},[12867,12886,12905,12923,12929,12932,12940,12947,12954,12961,12968,12976,12979,12987,12994,13001,13008,13014,13022,13041,13048,13055,13071,13079,13109,13125,13132,13161,13169,13198,13205,13213,13231,13238,13245,13250,13257,13265,13283,13290,13309,13316,13319,13327,13334,13419,13426,13442,13445,13475,13494,13501,13508,13511,13519,13537,13544,13551,13568,13571,13579,13586,13619,13626,13643,13662,13668,13671,13678],{"data":12868,"content":12869,"nodeType":673},{},[12870,12874,12882],{"data":12871,"marks":12872,"value":12873,"nodeType":543},{},[],"When we released the ",{"data":12875,"content":12877,"nodeType":695},{"uri":12876},"https://pushsecurity.com/blog/saas-attack-techniques/",[12878],{"data":12879,"marks":12880,"value":12881,"nodeType":543},{},[],"SaaS attack matrix",{"data":12883,"marks":12884,"value":12885,"nodeType":543},{},[]," in 2023, we were anticipating a shift that was just beginning to take shape. The techniques that attackers were using to compromise cloud applications and identities weren't well represented in existing frameworks, and many of the ones we documented hadn't yet been widely observed in the wild.",{"data":12887,"content":12888,"nodeType":673},{},[12889,12893,12901],{"data":12890,"marks":12891,"value":12892,"nodeType":543},{},[],"A year later, we ",{"data":12894,"content":12896,"nodeType":695},{"uri":12895},"https://pushsecurity.com/blog/the-saas-attack-matrix-one-year-on/",[12897],{"data":12898,"marks":12899,"value":12900,"nodeType":543},{},[],"reviewed what had changed",{"data":12902,"marks":12903,"value":12904,"nodeType":543},{},[]," and found that the initial access phase — the techniques designed to compromise an identity in the first place — was where almost all of the attacker innovation was concentrated. And two years on, that trend has become the story of the modern threat landscape. ",{"data":12906,"content":12907,"nodeType":673},{},[12908,12912,12919],{"data":12909,"marks":12910,"value":12911,"nodeType":543},{},[],"Today, we're re-releasing the matrix as the ",{"data":12913,"content":12915,"nodeType":695},{"uri":12914},"https://pushsecurity.com/resources/browser-identity-attacks-matrix/",[12916],{"data":12917,"marks":12918,"value":1365,"nodeType":543},{},[],{"data":12920,"marks":12921,"value":12922,"nodeType":543},{},[],". The name change isn't cosmetic. It reflects that the attacks driving the most consequential breaches are browser-based and identity-first.",{"data":12924,"content":12928,"nodeType":787},{"target":12925},{"sys":12926},{"id":12927,"type":792,"linkType":793},"MSnrBRJtiQxpv2qxFLCVE",[],{"data":12930,"content":12931,"nodeType":796},{},[],{"data":12933,"content":12934,"nodeType":800},{},[12935],{"data":12936,"marks":12937,"value":12939,"nodeType":543},{},[12938],{"type":749},"Why the scope needed to change",{"data":12941,"content":12942,"nodeType":673},{},[12943],{"data":12944,"marks":12945,"value":12946,"nodeType":543},{},[],"The original SaaS attack matrix was built around a specific insight: that attacks targeting modern business applications played out entirely over the internet, without touching endpoints or internal networks in any way that EDR or network detection tools would recognize.",{"data":12948,"content":12949,"nodeType":673},{},[12950],{"data":12951,"marks":12952,"value":12953,"nodeType":543},{},[],"That framing was useful, and it remains true. But it anchored the matrix to the post-access phase — what attackers do once they're inside a SaaS application — and didn't give enough weight to the initial access techniques that determine whether attackers get there in the first place.",{"data":12955,"content":12956,"nodeType":673},{},[12957],{"data":12958,"marks":12959,"value":12960,"nodeType":543},{},[],"The problem is that initial access is where the overwhelming majority of attacker innovation and investment is concentrated, and the techniques being used to achieve it are best understood as browser and identity attacks rather than SaaS-specific ones. AiTM phishing, ClickFix and its growing family of clipboard-injection variants, device code phishing, OAuth consent abuse, credential stuffing powered by infostealer supply chains, malicious browser extensions all happen in or via the browser.",{"data":12962,"content":12963,"nodeType":673},{},[12964],{"data":12965,"marks":12966,"value":12967,"nodeType":543},{},[],"Another issue is that \"SaaS\" has arguably ceased to be a meaningful category. When we consider that most organizations run the majority of their business on cloud applications, the difference between what constitutes \"SaaS\" versus cloud versus just \"business IT\" is pretty blurry (and feels like an academic rather than practical difference).",{"data":12969,"content":12970,"nodeType":673},{},[12971],{"data":12972,"marks":12973,"value":12975,"nodeType":543},{},[12974],{"type":749},"So it's less about whether an attack is a \"SaaS attack\" and more about how these attacks actually play out. ",{"data":12977,"content":12978,"nodeType":796},{},[],{"data":12980,"content":12981,"nodeType":800},{},[12982],{"data":12983,"marks":12984,"value":12986,"nodeType":543},{},[12985],{"type":749},"The technique landscape has transformed",{"data":12988,"content":12989,"nodeType":673},{},[12990],{"data":12991,"marks":12992,"value":12993,"nodeType":543},{},[],"The second part to the change is the fact that scale and speed of attacker innovation in the space justifies it.",{"data":12995,"content":12996,"nodeType":673},{},[12997],{"data":12998,"marks":12999,"value":13000,"nodeType":543},{},[],"When we launched the matrix in mid-2023, AiTM phishing was emerging as a serious concern but was far from ubiquitous. ClickFix didn't exist as a named technique. Device code phishing was a curiosity documented by a handful of researchers. ConsentFix was years away from being discovered. Browser extension supply chain attacks were rare enough to be individually notable.",{"data":13002,"content":13003,"nodeType":673},{},[13004],{"data":13005,"marks":13006,"value":13007,"nodeType":543},{},[],"In the two and a half years since, every one of these has become a mainstream, industrialized attack technique — and several have converged in ways that would have been hard to predict.",{"data":13009,"content":13013,"nodeType":787},{"target":13010},{"sys":13011},{"id":13012,"type":792,"linkType":793},"5Kw2kSrL8u4VyslxK8HCtR",[],{"data":13015,"content":13016,"nodeType":829},{},[13017],{"data":13018,"marks":13019,"value":13021,"nodeType":543},{},[13020],{"type":749},"AiTM phishing has become the default phishing method",{"data":13023,"content":13024,"nodeType":673},{},[13025,13029,13037],{"data":13026,"marks":13027,"value":13028,"nodeType":543},{},[],"AiTM phishing is now the standard, powered by Phishing-as-a-Service kits that operate with the release cycles and customer support of legitimate SaaS products. Tycoon 2FA alone accounted for ",{"data":13030,"content":13032,"nodeType":695},{"uri":13031},"https://pushsecurity.com/blog/2025-top-phishing-trends/",[13033],{"data":13034,"marks":13035,"value":13036,"nodeType":543},{},[],"62% of phishing detected by Microsoft",{"data":13038,"marks":13039,"value":13040,"nodeType":543},{},[]," and over 64,000 confirmed incidents, with Sneaky2FA, FlowerStorm, Evilginx, and a growing roster of competitors filling out the marketplace.",{"data":13042,"content":13043,"nodeType":673},{},[13044],{"data":13045,"marks":13046,"value":13047,"nodeType":543},{},[],"AiTM is constantly evolving, with vendors adding new features, capabilities, detection evasion techniques, and so on. Abuse of legitimate platforms, and increasingly AI-assisted development means that it’s trivial for attackers to spin up and tear down infrastructure, scale their campaigns, target specific organizations with crafted pages and lures, and generally means that attackers can operate highly sophisticated attacks with minimal effort and complexity. This makes AiTM and other PhaaS-powered techniques extremely accessible to all kinds of criminals.  ",{"data":13049,"content":13050,"nodeType":673},{},[13051],{"data":13052,"marks":13053,"value":13054,"nodeType":543},{},[],"These kits are delivered across several browser-based channels — not just email. Push data consistently shows that roughly 1 in 3 phishing payloads we intercept arrive via social media, search ads, messaging apps, or other non-email vectors.",{"data":13056,"content":13057,"nodeType":673},{},[13058,13062,13067],{"data":13059,"marks":13060,"value":13061,"nodeType":543},{},[],"Vishing has also surged as a delivery channel — CrowdStrike documented a ",{"data":13063,"marks":13064,"value":13066,"nodeType":543},{},[13065],{"type":749},"442% year-over-year increase",{"data":13068,"marks":13069,"value":13070,"nodeType":543},{},[],", and Mandiant found it was the single most common initial vector in cloud compromises at 23%. But the trend that matters isn't voice calls in isolation; it's voice calls combined with browser-based payloads, where a live operator guides the victim into an AiTM page or device code flow that the call alone could not execute.",{"data":13072,"content":13073,"nodeType":829},{},[13074],{"data":13075,"marks":13076,"value":13078,"nodeType":543},{},[13077],{"type":749},"ClickFix is the top reported initial access vector",{"data":13080,"content":13081,"nodeType":673},{},[13082,13086,13094,13098,13105],{"data":13083,"marks":13084,"value":13085,"nodeType":543},{},[],"ClickFix has gone from nonexistent to one of the most prevalent initial access techniques in under 18 months. Microsoft reported it as the ",{"data":13087,"content":13089,"nodeType":695},{"uri":13088},"https://cdn-dynmedia-1.microsoft.com/is/content/microsoftcorp/microsoft/msc/documents/presentations/CSR/Microsoft-Digital-Defense-Report-2025.pdf",[13090],{"data":13091,"marks":13092,"value":13093,"nodeType":543},{},[],"most common initial access vector in 2025",{"data":13095,"marks":13096,"value":13097,"nodeType":543},{},[],", accounting for 47% of observed attacks, while CrowdStrike documented a ",{"data":13099,"content":13100,"nodeType":695},{"uri":8970},[13101],{"data":13102,"marks":13103,"value":13104,"nodeType":543},{},[],"563% increase",{"data":13106,"marks":13107,"value":13108,"nodeType":543},{},[]," in fake CAPTCHA lures (a top ClickFix style).",{"data":13110,"content":13111,"nodeType":673},{},[13112,13116,13121],{"data":13113,"marks":13114,"value":13115,"nodeType":543},{},[],"ClickFix is admittedly an outlier in a browser attacks matrix — the payload ultimately executes on the endpoint, not in the browser — but the delivery is overwhelmingly browser-based: ",{"data":13117,"marks":13118,"value":13120,"nodeType":543},{},[13119],{"type":749},"4 in 5 ClickFix payloads",{"data":13122,"marks":13123,"value":13124,"nodeType":543},{},[]," intercepted by Push arrive via search engines as a result of malvertising or compromised web pages, not email, which means the browser is the only control point that actually sees the attack before the user pastes the malicious command.",{"data":13126,"content":13127,"nodeType":673},{},[13128],{"data":13129,"marks":13130,"value":13131,"nodeType":543},{},[],"ClickFix is now the primary delivery mechanism for infostealer malware, which is in turn the primary source of the stolen credentials and session tokens that power credential stuffing and session hijacking — which means the technique sits at the start of a cycle where one class of browser-delivered attack generates the raw material for the next.",{"data":13133,"content":13134,"nodeType":673},{},[13135,13139,13147,13151,13157],{"data":13136,"marks":13137,"value":13138,"nodeType":543},{},[],"The success of ClickFix has predictably spawned a growing family of derivatives — FileFix, CrashFix, ",{"data":13140,"content":13142,"nodeType":695},{"uri":13141},"https://pushsecurity.com/blog/installfix/",[13143],{"data":13144,"marks":13145,"value":13146,"nodeType":543},{},[],"InstallFix",{"data":13148,"marks":13149,"value":13150,"nodeType":543},{},[]," — and much of the naming is marketing hype around variations on the same clipboard-injection mechanic. But ",{"data":13152,"content":13153,"nodeType":695},{"uri":764},[13154],{"data":13155,"marks":13156,"value":949,"nodeType":543},{},[],{"data":13158,"marks":13159,"value":13160,"nodeType":543},{},[]," was a genuinely novel development.",{"data":13162,"content":13163,"nodeType":829},{},[13164],{"data":13165,"marks":13166,"value":13168,"nodeType":543},{},[13167],{"type":749},"Browser-native ClickFix: ConsentFix",{"data":13170,"content":13171,"nodeType":673},{},[13172,13176,13183,13187,13194],{"data":13173,"marks":13174,"value":13175,"nodeType":543},{},[],"ConsentFix is a fully browser-native attack that merged ClickFix-style social engineering with OAuth consent abuse, compromising accounts through a legitimate Microsoft authorization flow with no endpoint component at all. ConsentFix was ",{"data":13177,"content":13178,"nodeType":695},{"uri":6010},[13179],{"data":13180,"marks":13181,"value":13182,"nodeType":543},{},[],"traced to APT29",{"data":13184,"marks":13185,"value":13186,"nodeType":543},{},[]," and has since been ",{"data":13188,"content":13189,"nodeType":695},{"uri":776},[13190],{"data":13191,"marks":13192,"value":13193,"nodeType":543},{},[],"commercialized on criminal forums",{"data":13195,"marks":13196,"value":13197,"nodeType":543},{},[],", following the same path from state-sponsored technique to commodity criminal tooling that we've seen repeatedly in this space.",{"data":13199,"content":13200,"nodeType":673},{},[13201],{"data":13202,"marks":13203,"value":13204,"nodeType":543},{},[],"ConsentFix demonstrates that the clipboard-injection mechanic can evolve into something that operates entirely within the browser, eliminating the endpoint detection surface that traditional ClickFix still exposed.",{"data":13206,"content":13207,"nodeType":829},{},[13208],{"data":13209,"marks":13210,"value":13212,"nodeType":543},{},[13211],{"type":749},"Attackers have pivoted to authorization attacks to get around login controls",{"data":13214,"content":13215,"nodeType":673},{},[13216,13220,13227],{"data":13217,"marks":13218,"value":13219,"nodeType":543},{},[],"Authorization attacks like device code phishing have seen a ",{"data":13221,"content":13222,"nodeType":695},{"uri":895},[13223],{"data":13224,"marks":13225,"value":13226,"nodeType":543},{},[],"37.5x increase",{"data":13228,"marks":13229,"value":13230,"nodeType":543},{},[]," since the start of 2026, with at least 12 distinct kits now offering the technique. It bypasses standard authentication controls — including passkeys — because the attack occurs through the OAuth device authorization flow rather than the standard login flow. ",{"data":13232,"content":13233,"nodeType":673},{},[13234],{"data":13235,"marks":13236,"value":13237,"nodeType":543},{},[],"The technique was first associated with nation-state actors like Storm-2372, but went from espionage-grade to commodity PhaaS tooling in roughly eighteen months, with kits like EvilTokens and Venom now offering turnkey device code phishing as a service.",{"data":13239,"content":13240,"nodeType":673},{},[13241],{"data":13242,"marks":13243,"value":13244,"nodeType":543},{},[],"The device code authorization is effectively performed post-authentication. If you already have an active session in your browser, entering the device code and selecting your account from a drop-down menu is all that's needed. No password or MFA required. You can see an example in the video below.",{"data":13246,"content":13249,"nodeType":787},{"target":13247},{"sys":13248},{"id":6196,"type":792,"linkType":793},[],{"data":13251,"content":13252,"nodeType":673},{},[13253],{"data":13254,"marks":13255,"value":13256,"nodeType":543},{},[],"And the ecosystem is adapting to this opportunity: established AiTM vendors like Tycoon are adding authorization-focused options alongside their existing credential-harvesting capabilities, which points toward multi-technique platforms where operators pick the right tool for whatever defenses the target has in place.",{"data":13258,"content":13259,"nodeType":829},{},[13260],{"data":13261,"marks":13262,"value":13264,"nodeType":543},{},[13263],{"type":749},"Malicious and hacked browser extensions are one of the fastest growing threats",{"data":13266,"content":13267,"nodeType":673},{},[13268,13272,13279],{"data":13269,"marks":13270,"value":13271,"nodeType":543},{},[],"Malicious browser extensions have matured from an occasional nuisance into a scalable supply chain attack vector. The ",{"data":13273,"content":13274,"nodeType":695},{"uri":8148},[13275],{"data":13276,"marks":13277,"value":13278,"nodeType":543},{},[],"Cyberhaven compromise",{"data":13280,"marks":13281,"value":13282,"nodeType":543},{},[]," in December 2024 — where approximately 35 extensions were weaponized through a single OAuth phishing campaign targeting developers — impacted 2.6 million users and demonstrated that extension supply chain attacks can achieve the kind of reach that used to require a compromised software update server.",{"data":13284,"content":13285,"nodeType":673},{},[13286],{"data":13287,"marks":13288,"value":13289,"nodeType":543},{},[],"Since Cyberhaven, the pace has only accelerated. In 2026 alone, researchers have publicly disclosed at least 250 confirmed malicious browser extensions affecting roughly 1.75 million users, alongside a further 370+ extensions engaged in undisclosed or policy-disclosed data harvesting affecting an additional 44 million users. That doesn't count the extensions from late-2025 campaigns (DarkSpectre, AITOPIA, Trust Wallet) whose impacts carried into 2026.",{"data":13291,"content":13292,"nodeType":673},{},[13293,13297,13305],{"data":13294,"marks":13295,"value":13296,"nodeType":543},{},[],"The attack paths have also expanded. Beyond phishing developers for take over Web Store accounts (the Cyberhaven playbook), attackers are buying existing extensions from developers, waiting for ownership transfers or abandonments to take over, and increasingly vibe-coding their own functional extensions from scratch to build an audience that can later be weaponized. The common thread is that ",{"data":13298,"content":13299,"nodeType":695},{"uri":8148},[13300],{"data":13301,"marks":13302,"value":13304,"nodeType":543},{},[13303],{"type":722},"most malicious extensions didn't start out malicious",{"data":13306,"marks":13307,"value":13308,"nodeType":543},{},[]," — they started as legitimate tools and were turned into weapons after the fact.",{"data":13310,"content":13311,"nodeType":673},{},[13312],{"data":13313,"marks":13314,"value":13315,"nodeType":543},{},[],"None of this is happening in isolation. The threat landscape has reoriented around browser-based initial access and identity compromise — and the matrix needed to catch up.",{"data":13317,"content":13318,"nodeType":796},{},[],{"data":13320,"content":13321,"nodeType":800},{},[13322],{"data":13323,"marks":13324,"value":13326,"nodeType":543},{},[13325],{"type":749},"The evolution is playing out in public breaches",{"data":13328,"content":13329,"nodeType":673},{},[13330],{"data":13331,"marks":13332,"value":13333,"nodeType":543},{},[],"It’s worth reinforcing that when the SaaS matrix was first released, many of these attacks hadn’t been seen in the wild. The change today is staggering:",{"data":13335,"content":13336,"nodeType":2727},{},[13337,13357,13379,13399],{"data":13338,"content":13339,"nodeType":2639},{},[13340],{"data":13341,"content":13342,"nodeType":673},{},[13343,13347,13353],{"data":13344,"marks":13345,"value":13346,"nodeType":543},{},[],"When ",{"data":13348,"content":13349,"nodeType":695},{"uri":3189},[13350],{"data":13351,"marks":13352,"value":1647,"nodeType":543},{},[],{"data":13354,"marks":13355,"value":13356,"nodeType":543},{},[]," compromised over a thousand organizations' Salesforce tenants through device code phishing, the attack started with a phone call, moved through a browser-based authorization flow for the attacker’s app, and ended with mass data exfiltration via API.",{"data":13358,"content":13359,"nodeType":2639},{},[13360],{"data":13361,"content":13362,"nodeType":673},{},[13363,13367,13375],{"data":13364,"marks":13365,"value":13366,"nodeType":543},{},[],"When the same collective launched ",{"data":13368,"content":13370,"nodeType":695},{"uri":13369},"https://pushsecurity.com/blog/unpacking-the-latest-slh-campaign/",[13371],{"data":13372,"marks":13373,"value":13374,"nodeType":543},{},[],"AiTM phishing campaigns",{"data":13376,"marks":13377,"value":13378,"nodeType":543},{},[]," targeting Okta and Entra SSO, the phishing page was operated by a human in real time and delivered over a voice call — not email.",{"data":13380,"content":13381,"nodeType":2639},{},[13382],{"data":13383,"content":13384,"nodeType":673},{},[13385,13388,13395],{"data":13386,"marks":13387,"value":13346,"nodeType":543},{},[],{"data":13389,"content":13390,"nodeType":695},{"uri":764},[13391],{"data":13392,"marks":13393,"value":13394,"nodeType":543},{},[],"APT29 deployed ConsentFix",{"data":13396,"marks":13397,"value":13398,"nodeType":543},{},[]," across dozens of compromised websites, the entire attack chain was browser-native, abusing a legitimate Microsoft OAuth flow to bypass MFA without proxying a single credential.",{"data":13400,"content":13401,"nodeType":2639},{},[13402],{"data":13403,"content":13404,"nodeType":673},{},[13405,13408,13415],{"data":13406,"marks":13407,"value":1193,"nodeType":543},{},[],{"data":13409,"content":13411,"nodeType":695},{"uri":13410},"https://pushsecurity.com/blog/identity-attacks-in-the-wild/#id-snowflake-june-2024",[13412],{"data":13413,"marks":13414,"value":9486,"nodeType":543},{},[],{"data":13416,"marks":13417,"value":13418,"nodeType":543},{},[]," — arguably the most consequential credential-based campaign of the past several years — saw 165 organizations breached using credentials that had been sitting in infostealer dumps for years, replayed against Snowflake tenants that lacked mandatory MFA. The attack surface wasn't Snowflake's application logic; it was the identity hygiene gap that every organization carries across hundreds of apps.",{"data":13420,"content":13421,"nodeType":673},{},[13422],{"data":13423,"marks":13424,"value":13425,"nodeType":543},{},[],"And that’s just the big picture. Every month we’re tracking new public breaches involving browser and identity TTPs — which again, are just the tip of the iceberg when you consider that many breaches are settled quietly without hitting the headlines. ",{"data":13427,"content":13428,"nodeType":673},{},[13429,13433,13438],{"data":13430,"marks":13431,"value":13432,"nodeType":543},{},[],"One of the key drivers here is the shrinking time-to-exploit. CrowdStrike's average e-crime breakout time is down to ",{"data":13434,"marks":13435,"value":13437,"nodeType":543},{},[13436],{"type":749},"29 minutes",{"data":13439,"marks":13440,"value":13441,"nodeType":543},{},[],", with the fastest recorded at 27 seconds. When attackers can move from initial access to data exfiltration within minutes, the window for post-compromise detection collapses to near zero. The best chance of stopping the attack is at the point of initial access before the identity is compromised.",{"data":13443,"content":13444,"nodeType":796},{},[],{"data":13446,"content":13447,"nodeType":800},{},[13448,13453,13459,13464,13470],{"data":13449,"marks":13450,"value":13452,"nodeType":543},{},[13451],{"type":749},"Sidenote: why we're looking at attacks ",{"data":13454,"marks":13455,"value":13458,"nodeType":543},{},[13456,13457],{"type":739},{"type":749},"in",{"data":13460,"marks":13461,"value":13463,"nodeType":543},{},[13462],{"type":749}," the browser, not ",{"data":13465,"marks":13466,"value":13469,"nodeType":543},{},[13467,13468],{"type":739},{"type":749},"on",{"data":13471,"marks":13472,"value":13474,"nodeType":543},{},[13473],{"type":749}," the browser",{"data":13476,"content":13477,"nodeType":673},{},[13478,13482,13490],{"data":13479,"marks":13480,"value":13481,"nodeType":543},{},[],"Calling this a \"browser attacks\" matrix needs clarification. We're not talking about browser exploits — RCE vulnerabilities, sandbox escapes, memory corruption bugs. Those attacks target the browser itself, they're extraordinarily expensive to develop, and they're increasingly rare. Browser zero-days hit a ",{"data":13483,"content":13485,"nodeType":695},{"uri":13484},"https://cloud.google.com/blog/topics/threat-intelligence/2025-zero-day-review",[13486],{"data":13487,"marks":13488,"value":13489,"nodeType":543},{},[],"historic low of 9%",{"data":13491,"marks":13492,"value":13493,"nodeType":543},{},[]," of all zero-days reported to Google, and a Chrome RCE commands a $250,000 bug bounty.",{"data":13495,"content":13496,"nodeType":673},{},[13497],{"data":13498,"marks":13499,"value":13500,"nodeType":543},{},[],"In comparison, a one-year phishing kit rental costs $1,000. A bulk stolen credential list costs $15. An initial-access-broker-provided IdP admin account costs $3,000. When it costs orders of magnitude less to exploit the person using the browser than to exploit the browser itself, attackers will take the cheaper option every time.",{"data":13502,"content":13503,"nodeType":673},{},[13504],{"data":13505,"marks":13506,"value":13507,"nodeType":543},{},[],"It's worth heading off the obvious counterargument: won't AI-assisted vulnerability discovery eventually make browser exploits cheaper? Perhaps — but it will simultaneously make them easier for browser vendors to find and patch, and vendors like Google and Microsoft have the engineering capacity and financial incentive to scale AI-driven remediation far faster than attackers can scale exploit development.",{"data":13509,"content":13510,"nodeType":796},{},[],{"data":13512,"content":13513,"nodeType":800},{},[13514],{"data":13515,"marks":13516,"value":13518,"nodeType":543},{},[13517],{"type":749},"What hasn't changed",{"data":13520,"content":13521,"nodeType":673},{},[13522,13526,13533],{"data":13523,"marks":13524,"value":13525,"nodeType":543},{},[],"The matrix remains open-source, community-maintained, and available on ",{"data":13527,"content":13529,"nodeType":695},{"uri":13528},"https://github.com/pushsecurity/saas-attacks",[13530],{"data":13531,"marks":13532,"value":5723,"nodeType":543},{},[],{"data":13534,"marks":13535,"value":13536,"nodeType":543},{},[],". The goal is the same as it was in 2023: to give offensive and defensive security teams a shared reference point for the techniques that matter most.",{"data":13538,"content":13539,"nodeType":673},{},[13540],{"data":13541,"marks":13542,"value":13543,"nodeType":543},{},[],"We built it because there was a gap in how the industry talked about these techniques, and that gap still exists — MITRE ATT&CK remains essential for endpoint and network TTPs, but the browser-based, identity-first techniques behind most modern breaches are still underrepresented in traditional frameworks.",{"data":13545,"content":13546,"nodeType":673},{},[13547],{"data":13548,"marks":13549,"value":13550,"nodeType":543},{},[],"We continue to maintain the matrix with input from red teams, detection engineers, and threat researchers across the community. Some of the most valuable additions over the past two years have come from practitioners who encountered a technique on an engagement or in an investigation and contributed it back to the repository.",{"data":13552,"content":13553,"nodeType":673},{},[13554,13558,13565],{"data":13555,"marks":13556,"value":13557,"nodeType":543},{},[],"If you're an offensive security professional using these techniques on engagements, or a defender building detections against them, we want to hear from you. Submit a PR, open a discussion, or flag a technique we've missed on ",{"data":13559,"content":13561,"nodeType":695},{"uri":13560},"https://github.com/pushsecurity/browser-identity-attacks-matrix",[13562],{"data":13563,"marks":13564,"value":5723,"nodeType":543},{},[],{"data":13566,"marks":13567,"value":1863,"nodeType":543},{},[],{"data":13569,"content":13570,"nodeType":796},{},[],{"data":13572,"content":13573,"nodeType":800},{},[13574],{"data":13575,"marks":13576,"value":13578,"nodeType":543},{},[13577],{"type":749},"Looking ahead",{"data":13580,"content":13581,"nodeType":673},{},[13582],{"data":13583,"marks":13584,"value":13585,"nodeType":543},{},[],"The pace of attacker innovation in browser-based initial access techniques over the past 18 months has been unlike anything we've tracked before — technique after technique moving from research curiosity to industrialized criminal tooling within months, not years.",{"data":13587,"content":13588,"nodeType":2727},{},[13589,13599,13609],{"data":13590,"content":13591,"nodeType":2639},{},[13592],{"data":13593,"content":13594,"nodeType":673},{},[13595],{"data":13596,"marks":13597,"value":13598,"nodeType":543},{},[],"AiTM platforms are adding authorization-based attack options alongside their credential-harvesting capabilities.",{"data":13600,"content":13601,"nodeType":2639},{},[13602],{"data":13603,"content":13604,"nodeType":673},{},[13605],{"data":13606,"marks":13607,"value":13608,"nodeType":543},{},[],"ClickFix has spawned fully browser-native variants.",{"data":13610,"content":13611,"nodeType":2639},{},[13612],{"data":13613,"content":13614,"nodeType":673},{},[13615],{"data":13616,"marks":13617,"value":13618,"nodeType":543},{},[],"AI is lowering the cost of producing convincing social engineering and phishing infrastructure at scale.",{"data":13620,"content":13621,"nodeType":673},{},[13622],{"data":13623,"marks":13624,"value":13625,"nodeType":543},{},[],"We don't see any of this slowing down, and that's exactly why thinking about these attacks as a browser problem instead of siloing them across email, endpoint, network, and cloud categories, each with a partial view of the picture (and still missing the whole when combined).",{"data":13627,"content":13628,"nodeType":673},{},[13629,13633,13640],{"data":13630,"marks":13631,"value":13632,"nodeType":543},{},[],"The Browser & Identity Attacks Matrix is our contribution to keeping that shared understanding current. You can ",{"data":13634,"content":13635,"nodeType":695},{"uri":12914},[13636],{"data":13637,"marks":13638,"value":13639,"nodeType":543},{},[],"explore the matrix here",{"data":13641,"marks":13642,"value":1863,"nodeType":543},{},[],{"data":13644,"content":13645,"nodeType":673},{},[13646,13650,13658],{"data":13647,"marks":13648,"value":13649,"nodeType":543},{},[],"You can also read our recent ",{"data":13651,"content":13653,"nodeType":695},{"uri":13652},"https://pushsecurity.com/thank-you/browser-attacks-report",[13654],{"data":13655,"marks":13656,"value":13657,"nodeType":543},{},[],"browser attack techniques report",{"data":13659,"marks":13660,"value":13661,"nodeType":543},{},[]," for more information.",{"data":13663,"content":13667,"nodeType":787},{"target":13664},{"sys":13665},{"id":13666,"type":792,"linkType":793},"1hx6sxpyEzxn4F4jc1RGQi",[],{"data":13669,"content":13670,"nodeType":796},{},[],{"data":13672,"content":13673,"nodeType":673},{},[13674],{"data":13675,"marks":13676,"value":13677,"nodeType":543},{},[],"Push Security is the most powerful AI-native security tool in the browser. Think EDR, but for the browser — high-fidelity telemetry and real-time control across every session, on every device, with no browser migration required. Security teams use Push to detect and stop advanced browser-based attacks like AiTM phishing, ClickFix, and session hijacking; gain visibility and control over AI tool usage across their workforce; harden identities by surfacing credential reuse, SSO gaps, and shadow IT; and support data loss and insider investigations with browser-layer telemetry that other tools can't see.",{"data":13679,"content":13680,"nodeType":673},{},[13681,13684,13690],{"data":13682,"marks":13683,"value":8445,"nodeType":543},{},[],{"data":13685,"content":13686,"nodeType":695},{"uri":5926},[13687],{"data":13688,"marks":13689,"value":8453,"nodeType":543},{},[],{"data":13691,"marks":13692,"value":8457,"nodeType":543},{},[],"Introducing the Browser & Identity Attacks Matrix","We're re-releasing the SaaS attack matrix as the Browser & Identity Attacks Matrix. Here's why we've decided to make the change and what it means.","2026-05-08T00:00:00.000Z","introducing-the-browser-and-identity-attacks-matrix",{"items":13698},[13699,13701],{"sys":13700,"name":2917},{"id":2916},{"sys":13702,"name":2921},{"id":2920},{"items":13704},[13705],{"fullName":2925,"firstName":2926,"jobTitle":2927,"profilePicture":13706},{"url":2929},"blog/browser-threat-landscape-mid-year-update-2026",{"json":13709},{"data":13710,"content":13711,"nodeType":669},{},[13712],{"data":13713,"content":13714,"nodeType":673},{},[13715],{"data":13716,"marks":13717,"value":2909,"nodeType":543},{},[],{"id":1610,"publishedAt":13719},"2026-08-26T11:56:53.261Z",{"items":13721},[13722,13724],{"sys":13723,"name":2917},{"id":2916},{"sys":13725,"name":2921},{"id":2920},{"items":13727},[13728,13730,13735,13737,13742,13747,13752,13757,13762,13767,13769,13773,13775,13777,13782,13787,13789,13794,13796,13801,13806,13811,13816,13818,13820],{"sys":13729,"name":10710,"slug":10711,"tier":45},{"id":10709},{"sys":13731,"name":13733,"slug":13734,"tier":45},{"id":13732},"topic-public-breach","Public breach","public-breach",{"sys":13736,"name":10666,"slug":10667,"tier":45},{"id":10665},{"sys":13738,"name":13740,"slug":13741,"tier":45},{"id":13739},"topic-bec","BEC","bec",{"sys":13743,"name":13745,"slug":13746,"tier":45},{"id":13744},"topic-ransomware","Ransomware","ransomware",{"sys":13748,"name":13750,"slug":13751,"tier":45},{"id":13749},"topic-vishing","Vishing","vishing",{"sys":13753,"name":13755,"slug":13756,"tier":45},{"id":13754},"topic-social-engineering","Social engineering","social-engineering",{"sys":13758,"name":13760,"slug":13761,"tier":45},{"id":13759},"topic-malware-delivery","Malware delivery","malware-delivery",{"sys":13763,"name":13765,"slug":13766,"tier":45},{"id":13764},"topic-infostealer","Infostealer","infostealer",{"sys":13768,"name":6557,"slug":6558,"tier":45},{"id":6556},{"sys":13770,"name":304,"slug":13772,"tier":45},{"id":13771},"topic-session-hijacking","session-hijacking",{"sys":13774,"name":6562,"slug":6563,"tier":45},{"id":6561},{"sys":13776,"name":6567,"slug":6568,"tier":45},{"id":6566},{"sys":13778,"name":13780,"slug":13781,"tier":45},{"id":13779},"topic-malvertising","Malvertising","malvertising",{"sys":13783,"name":13785,"slug":13786,"tier":45},{"id":13784},"topic-seo-poisoning","SEO poisoning","seo-poisoning",{"sys":13788,"name":269,"slug":5939,"tier":45},{"id":6581},{"sys":13790,"name":13792,"slug":13793,"tier":45},{"id":13791},"topic-non-email-phishing","Non-email phishing","non-email-phishing",{"sys":13795,"name":6577,"slug":6578,"tier":45},{"id":6576},{"sys":13797,"name":13799,"slug":13800,"tier":45},{"id":13798},"topic-credential-phishing","Credential phishing","credential-phishing",{"sys":13802,"name":13804,"slug":13805,"tier":45},{"id":13803},"topic-clickfix","ClickFix","clickfix",{"sys":13807,"name":13809,"slug":13810,"tier":45},{"id":13808},"topic-aitm","AiTM phishing","aitm",{"sys":13812,"name":13814,"slug":13815,"tier":31},{"id":13813},"topic-threat-landscape","Threat landscape","threat-landscape",{"sys":13817,"name":254,"slug":6585,"tier":31},{"id":6584},{"sys":13819,"name":10632,"slug":10657,"tier":31},{"id":10656},{"sys":13821,"name":6589,"slug":6590,"tier":31},{"id":6588},"s-m4f3m6SWAIErhOTXNAHECtIUwlHBoZ_uFaPQsee20",{"id":13824,"title":12846,"authorsCollection":13825,"content":13829,"extension":1410,"faqItemsCollection":14234,"faqTitle":59,"featured":6,"hashTags":59,"meta":14236,"metaTitle":14237,"ogImage":59,"postType":11857,"publishedDate":12848,"relatedBlogPostsCollection":14238,"slug":12849,"stem":16748,"subtitle":59,"summary":16749,"synopsis":12847,"sys":16760,"tagsCollection":16762,"topicsCollection":16768,"__hash__":16797},"blog/blog/from-iocs-to-ttps-an-agentic-threat-hunting-case-study.json",{"items":13826},[13827],{"fullName":6598,"firstName":6599,"jobTitle":6600,"socialLinks":59,"profilePicture":13828},{"url":6602},{"json":13830,"links":14176},{"data":13831,"content":13832,"nodeType":669},{},[13833,13839,13845,13851,13857,13863,13879,13885,13891,13897,13902,13905,13911,13927,13932,13945,13958,13971,13984,13990,13996,14002,14007,14013,14019,14025,14031,14036,14052,14065,14071,14077,14083,14089,14095,14101,14106,14112,14118,14124,14130,14136,14142,14148,14154,14160],{"data":13834,"content":13835,"nodeType":673},{},[13836],{"data":13837,"marks":13838,"value":12446,"nodeType":543},{},[],{"data":13840,"content":13841,"nodeType":673},{},[13842],{"data":13843,"marks":13844,"value":12453,"nodeType":543},{},[],{"data":13846,"content":13847,"nodeType":673},{},[13848],{"data":13849,"marks":13850,"value":12460,"nodeType":543},{},[],{"data":13852,"content":13853,"nodeType":673},{},[13854],{"data":13855,"marks":13856,"value":12467,"nodeType":543},{},[],{"data":13858,"content":13859,"nodeType":673},{},[13860],{"data":13861,"marks":13862,"value":12474,"nodeType":543},{},[],{"data":13864,"content":13865,"nodeType":673},{},[13866,13869,13876],{"data":13867,"marks":13868,"value":12481,"nodeType":543},{},[],{"data":13870,"content":13871,"nodeType":695},{"uri":12484},[13872],{"data":13873,"marks":13874,"value":12490,"nodeType":543},{},[13875],{"type":722},{"data":13877,"marks":13878,"value":12494,"nodeType":543},{},[],{"data":13880,"content":13881,"nodeType":673},{},[13882],{"data":13883,"marks":13884,"value":12501,"nodeType":543},{},[],{"data":13886,"content":13887,"nodeType":673},{},[13888],{"data":13889,"marks":13890,"value":12508,"nodeType":543},{},[],{"data":13892,"content":13893,"nodeType":673},{},[13894],{"data":13895,"marks":13896,"value":12515,"nodeType":543},{},[],{"data":13898,"content":13901,"nodeType":787},{"target":13899},{"sys":13900},{"id":12520,"type":792,"linkType":793},[],{"data":13903,"content":13904,"nodeType":796},{},[],{"data":13906,"content":13907,"nodeType":800},{},[13908],{"data":13909,"marks":13910,"value":12531,"nodeType":543},{},[],{"data":13912,"content":13913,"nodeType":673},{},[13914,13917,13924],{"data":13915,"marks":13916,"value":12538,"nodeType":543},{},[],{"data":13918,"content":13919,"nodeType":695},{"uri":12484},[13920],{"data":13921,"marks":13922,"value":12546,"nodeType":543},{},[13923],{"type":722},{"data":13925,"marks":13926,"value":12550,"nodeType":543},{},[],{"data":13928,"content":13931,"nodeType":787},{"target":13929},{"sys":13930},{"id":12555,"type":792,"linkType":793},[],{"data":13933,"content":13934,"nodeType":673},{},[13935,13938,13942],{"data":13936,"marks":13937,"value":12563,"nodeType":543},{},[],{"data":13939,"marks":13940,"value":12568,"nodeType":543},{},[13941],{"type":749},{"data":13943,"marks":13944,"value":12572,"nodeType":543},{},[],{"data":13946,"content":13947,"nodeType":673},{},[13948,13951,13955],{"data":13949,"marks":13950,"value":12579,"nodeType":543},{},[],{"data":13952,"marks":13953,"value":12584,"nodeType":543},{},[13954],{"type":749},{"data":13956,"marks":13957,"value":12588,"nodeType":543},{},[],{"data":13959,"content":13960,"nodeType":673},{},[13961,13964,13968],{"data":13962,"marks":13963,"value":12595,"nodeType":543},{},[],{"data":13965,"marks":13966,"value":736,"nodeType":543},{},[13967],{"type":739},{"data":13969,"marks":13970,"value":12603,"nodeType":543},{},[],{"data":13972,"content":13973,"nodeType":673},{},[13974,13977,13981],{"data":13975,"marks":13976,"value":12610,"nodeType":543},{},[],{"data":13978,"marks":13979,"value":12615,"nodeType":543},{},[13980],{"type":749},{"data":13982,"marks":13983,"value":12619,"nodeType":543},{},[],{"data":13985,"content":13986,"nodeType":673},{},[13987],{"data":13988,"marks":13989,"value":12626,"nodeType":543},{},[],{"data":13991,"content":13992,"nodeType":800},{},[13993],{"data":13994,"marks":13995,"value":12633,"nodeType":543},{},[],{"data":13997,"content":13998,"nodeType":673},{},[13999],{"data":14000,"marks":14001,"value":12640,"nodeType":543},{},[],{"data":14003,"content":14006,"nodeType":787},{"target":14004},{"sys":14005},{"id":12645,"type":792,"linkType":793},[],{"data":14008,"content":14009,"nodeType":673},{},[14010],{"data":14011,"marks":14012,"value":12653,"nodeType":543},{},[],{"data":14014,"content":14015,"nodeType":673},{},[14016],{"data":14017,"marks":14018,"value":12660,"nodeType":543},{},[],{"data":14020,"content":14021,"nodeType":673},{},[14022],{"data":14023,"marks":14024,"value":12667,"nodeType":543},{},[],{"data":14026,"content":14027,"nodeType":673},{},[14028],{"data":14029,"marks":14030,"value":12674,"nodeType":543},{},[],{"data":14032,"content":14035,"nodeType":787},{"target":14033},{"sys":14034},{"id":12679,"type":792,"linkType":793},[],{"data":14037,"content":14038,"nodeType":673},{},[14039,14042,14049],{"data":14040,"marks":14041,"value":12687,"nodeType":543},{},[],{"data":14043,"content":14044,"nodeType":695},{"uri":12690},[14045],{"data":14046,"marks":14047,"value":12696,"nodeType":543},{},[14048],{"type":722},{"data":14050,"marks":14051,"value":12700,"nodeType":543},{},[],{"data":14053,"content":14054,"nodeType":673},{},[14055,14058,14062],{"data":14056,"marks":14057,"value":12707,"nodeType":543},{},[],{"data":14059,"marks":14060,"value":12568,"nodeType":543},{},[14061],{"type":749},{"data":14063,"marks":14064,"value":12715,"nodeType":543},{},[],{"data":14066,"content":14067,"nodeType":673},{},[14068],{"data":14069,"marks":14070,"value":12722,"nodeType":543},{},[],{"data":14072,"content":14073,"nodeType":673},{},[14074],{"data":14075,"marks":14076,"value":12729,"nodeType":543},{},[],{"data":14078,"content":14079,"nodeType":673},{},[14080],{"data":14081,"marks":14082,"value":12736,"nodeType":543},{},[],{"data":14084,"content":14085,"nodeType":673},{},[14086],{"data":14087,"marks":14088,"value":12743,"nodeType":543},{},[],{"data":14090,"content":14091,"nodeType":800},{},[14092],{"data":14093,"marks":14094,"value":12750,"nodeType":543},{},[],{"data":14096,"content":14097,"nodeType":673},{},[14098],{"data":14099,"marks":14100,"value":12757,"nodeType":543},{},[],{"data":14102,"content":14105,"nodeType":787},{"target":14103},{"sys":14104},{"id":12762,"type":792,"linkType":793},[],{"data":14107,"content":14108,"nodeType":673},{},[14109],{"data":14110,"marks":14111,"value":12770,"nodeType":543},{},[],{"data":14113,"content":14114,"nodeType":673},{},[14115],{"data":14116,"marks":14117,"value":12777,"nodeType":543},{},[],{"data":14119,"content":14120,"nodeType":673},{},[14121],{"data":14122,"marks":14123,"value":12784,"nodeType":543},{},[],{"data":14125,"content":14126,"nodeType":673},{},[14127],{"data":14128,"marks":14129,"value":12791,"nodeType":543},{},[],{"data":14131,"content":14132,"nodeType":673},{},[14133],{"data":14134,"marks":14135,"value":12798,"nodeType":543},{},[],{"data":14137,"content":14138,"nodeType":800},{},[14139],{"data":14140,"marks":14141,"value":12805,"nodeType":543},{},[],{"data":14143,"content":14144,"nodeType":673},{},[14145],{"data":14146,"marks":14147,"value":12812,"nodeType":543},{},[],{"data":14149,"content":14150,"nodeType":673},{},[14151],{"data":14152,"marks":14153,"value":12819,"nodeType":543},{},[],{"data":14155,"content":14156,"nodeType":673},{},[14157],{"data":14158,"marks":14159,"value":12826,"nodeType":543},{},[],{"data":14161,"content":14162,"nodeType":673},{},[14163,14166,14173],{"data":14164,"marks":14165,"value":12833,"nodeType":543},{},[],{"data":14167,"content":14168,"nodeType":695},{"uri":5926},[14169],{"data":14170,"marks":14171,"value":12841,"nodeType":543},{},[14172],{"type":722},{"data":14174,"marks":14175,"value":12845,"nodeType":543},{},[],{"entries":14177},{"hyperlink":14178,"inline":14179,"block":14180},[],[],[14181,14207,14214,14220,14227],{"sys":14182,"__typename":1332,"content":14183,"name":14206,"title":59},{"id":12520},{"json":14184},{"data":14185,"content":14186,"nodeType":669},{},[14187],{"data":14188,"content":14189,"nodeType":673},{},[14190,14194,14202],{"data":14191,"marks":14192,"value":14193,"nodeType":543},{},[],"Note: This is part 2 of a series. ",{"data":14195,"content":14197,"nodeType":695},{"uri":14196},"https://pushsecurity.com/blog/agentic-threat-hunting-benefits-for-customers",[14198],{"data":14199,"marks":14200,"value":14201,"nodeType":543},{},[],"Part 1",{"data":14203,"marks":14204,"value":14205,"nodeType":543},{},[]," covers the pipeline’s detection engineering principles and the security outcomes we’re achieving for Push customers.","Agentic case study IB1",{"sys":14208,"__typename":1393,"title":14209,"caption":14209,"layoutMode":59,"file":14210},{"id":12555},"The original attack chain documented in March by Microsoft.",{"url":14211,"width":14212,"height":14213},"https://images.ctfassets.net/y1cdw1ablpvd/1D3TRRoXR4Kyso7bX2ogiC/4e17fd2c068195e9959da9b633ab5f48/microsoft-attack-chain.png",3224,2020,{"sys":14215,"__typename":1393,"title":14216,"caption":14216,"layoutMode":59,"file":14217},{"id":12645},"Push’s intel agent reasoning over some ingested TI on a novel OAuth redirect abuse technique.",{"url":14218,"width":1408,"height":14219},"https://images.ctfassets.net/y1cdw1ablpvd/46ArhTRN2xiFHemmFIo1Y/3976a9c6877f08810f2eea37d306de4e/image4.png",820,{"sys":14221,"__typename":1393,"title":14222,"caption":14222,"layoutMode":59,"file":14223},{"id":12679},"Push agents summarizing the behavioral techniques of the attack and proposing hunt queries.",{"url":14224,"width":14225,"height":14226},"https://images.ctfassets.net/y1cdw1ablpvd/1knJksvSVjMoGKHyAMIN22/5727ee7ce06ddb300355eec119bab885/image3.png",1900,1466,{"sys":14228,"__typename":1393,"title":14229,"caption":14229,"layoutMode":59,"file":14230},{"id":12762},"Push observed the same technique with completely different IOCs a few months after first hunting for it based on Microsoft’s documented campaign example.",{"url":14231,"width":14232,"height":14233},"https://images.ctfassets.net/y1cdw1ablpvd/4zGCbPJbfFXhSJMAPrssTX/10759adf3d14f823209329b0c84fdea7/oauth-redirect-technique-v2.png",3400,1860,{"items":14235},[],{},"How Push turns IOC-based intel into browser TTPs for hunting",{"items":14239},[14240,15173,15980],{"__typename":1608,"sys":14241,"content":14243,"title":15159,"synopsis":15160,"hashTags":59,"publishedDate":15161,"slug":15162,"tagsCollection":15163,"authorsCollection":15169},{"id":14242},"6dJUsirH3rrhy1Stnzkfqk",{"json":14244},{"data":14245,"content":14246,"nodeType":669},{},[14247,14260,14276,14327,14334,14347,14367,14374,14380,14383,14390,14397,14426,14433,14440,14508,14515,14521,14528,14535,14538,14545,14552,14585,14605,14617,14623,14630,14636,14648,14655,14675,14681,14693,14705,14712,14718,14730,14746,14758,14770,14776,14783,14786,14793,14800,14816,14824,14831,14839,14846,14886,14889,14896,14903,14909,14916,14923,14939,14954,14961,14977,14984,15032,15039,15055,15062,15111,15118,15126,15129,15135,15142],{"data":14248,"content":14249,"nodeType":673},{},[14250,14254],{"data":14251,"marks":14252,"value":14253,"nodeType":543},{},[],"Hey all you security engineers, let’s play ",{"data":14255,"marks":14256,"value":14259,"nodeType":543},{},[14257,14258],{"type":739},{"type":749},"Would You Rather … ?",{"data":14261,"content":14262,"nodeType":673},{},[14263,14267,14272],{"data":14264,"marks":14265,"value":14266,"nodeType":543},{},[],"Would you rather spend time trying to write detections for ",{"data":14268,"marks":14269,"value":14271,"nodeType":543},{},[14270],{"type":749},"modern browser-based attacks",{"data":14273,"marks":14274,"value":14275,"nodeType":543},{},[]," by …",{"data":14277,"content":14278,"nodeType":2727},{},[14279,14294,14312],{"data":14280,"content":14281,"nodeType":2639},{},[14282],{"data":14283,"content":14284,"nodeType":673},{},[14285,14289],{"data":14286,"marks":14287,"value":14288,"nodeType":543},{},[],"Combing through MITRE looking for techniques that you can write detections on, only to find you have",{"data":14290,"marks":14291,"value":14293,"nodeType":543},{},[14292],{"type":749}," little useful telemetry from your typical sources.",{"data":14295,"content":14296,"nodeType":2639},{},[14297],{"data":14298,"content":14299,"nodeType":673},{},[14300,14304,14309],{"data":14301,"marks":14302,"value":14303,"nodeType":543},{},[],"Curating a list of malicious domain IOCs extracted from endless TI pieces, only to ",{"data":14305,"marks":14306,"value":14308,"nodeType":543},{},[14307],{"type":749},"never see a single one of them match",{"data":14310,"marks":14311,"value":1863,"nodeType":543},{},[],{"data":14313,"content":14314,"nodeType":2639},{},[14315],{"data":14316,"content":14317,"nodeType":673},{},[14318,14323],{"data":14319,"marks":14320,"value":14322,"nodeType":543},{},[14321],{"type":749},"Just giving up and blocking a bunch of domains or IPs",{"data":14324,"marks":14325,"value":14326,"nodeType":543},{},[]," from every TI feed you come across, while quietly weeping.",{"data":14328,"content":14329,"nodeType":673},{},[14330],{"data":14331,"marks":14332,"value":14333,"nodeType":543},{},[],"Or … ",{"data":14335,"content":14336,"nodeType":2727},{},[14337],{"data":14338,"content":14339,"nodeType":2639},{},[14340],{"data":14341,"content":14342,"nodeType":673},{},[14343],{"data":14344,"marks":14345,"value":14346,"nodeType":543},{},[],"Inherit constantly evolving detections validated across 3 million-plus browsers, tuned to remove false positives, informed by human threat researchers, and tailored to the known and not-yet-known threats that target account compromise and malware delivery via the browser.",{"data":14348,"content":14349,"nodeType":673},{},[14350,14354,14363],{"data":14351,"marks":14352,"value":14353,"nodeType":543},{},[],"At Push, we’ve built an ",{"data":14355,"content":14357,"nodeType":695},{"uri":14356},"https://pushsecurity.com/blog/can-ai-replace-a-threat-researcher-what-we-learned-building-an-agentic-threat-hunting-pipeline",[14358],{"data":14359,"marks":14360,"value":14362,"nodeType":543},{},[14361],{"type":722},"agentic threat hunting and detection engineering pipeline",{"data":14364,"marks":14365,"value":14366,"nodeType":543},{},[]," to take that first set of onerous tasks off your plate. The result is a process that looks a lot like the ideal described in detection engineering maturity models, achieved without any extra headcount or subject matter expertise on your team, and scaled to meet the speed and complexity of our current era of AI-enabled adversaries.",{"data":14368,"content":14369,"nodeType":673},{},[14370],{"data":14371,"marks":14372,"value":14373,"nodeType":543},{},[],"Let’s take a look at how the pipeline delivers a collective good by identifying emerging threats or new technique variants in a single customer environment and then delivering detections to everyone.",{"data":14375,"content":14379,"nodeType":787},{"target":14376},{"sys":14377},{"id":14378,"type":792,"linkType":793},"sN6q7oEwYyJTkXxyLb81m",[],{"data":14381,"content":14382,"nodeType":796},{},[],{"data":14384,"content":14385,"nodeType":800},{},[14386],{"data":14387,"marks":14388,"value":14389,"nodeType":543},{},[],"Why detection engineering from TI is hard — and why AI-enabled attacks are making it even harder",{"data":14391,"content":14392,"nodeType":673},{},[14393],{"data":14394,"marks":14395,"value":14396,"nodeType":543},{},[],"Detection engineers feel the pain that Beethoven must have felt when he got the critique: “There are just too many notes!”",{"data":14398,"content":14399,"nodeType":673},{},[14400,14404,14409,14413,14422],{"data":14401,"marks":14402,"value":14403,"nodeType":543},{},[],"Except where notes = threat intelligence, light on the ",{"data":14405,"marks":14406,"value":14408,"nodeType":543},{},[14407],{"type":739},"intelligence",{"data":14410,"marks":14411,"value":14412,"nodeType":543},{},[],". (For a great unpacking of what’s hard about transforming TI into detections, check out this ",{"data":14414,"content":14416,"nodeType":695},{"uri":14415},"https://medium.com/anton-on-security/detection-engineering-is-painful-and-it-shouldnt-be-part-1-3641d8740458",[14417],{"data":14418,"marks":14419,"value":14421,"nodeType":543},{},[14420],{"type":722},"blog series",{"data":14423,"marks":14424,"value":14425,"nodeType":543},{},[]," from Anton Chuvakin and his Google security colleagues from 2023. The challenge has only gotten harder since then!)",{"data":14427,"content":14428,"nodeType":673},{},[14429],{"data":14430,"marks":14431,"value":14432,"nodeType":543},{},[],"In short, there is too much potential TI, too little actionable detail, and a dearth of useful business-relevant context.",{"data":14434,"content":14435,"nodeType":673},{},[14436],{"data":14437,"marks":14438,"value":14439,"nodeType":543},{},[],"This often manifests as:",{"data":14441,"content":14442,"nodeType":2727},{},[14443,14471,14490],{"data":14444,"content":14445,"nodeType":2639},{},[14446],{"data":14447,"content":14448,"nodeType":673},{},[14449,14454,14458,14467],{"data":14450,"marks":14451,"value":14453,"nodeType":543},{},[14452],{"type":749},"Feeling constantly behind the threat landscape. ",{"data":14455,"marks":14456,"value":14457,"nodeType":543},{},[],"SANS Institute’s ",{"data":14459,"content":14461,"nodeType":695},{"uri":14460},"https://www.sans.org/white-papers/state-detection-engineering-2026",[14462],{"data":14463,"marks":14464,"value":14466,"nodeType":543},{},[14465],{"type":722},"State of Detection Engineering 2026",{"data":14468,"marks":14469,"value":14470,"nodeType":543},{},[]," report found that only 18% of practitioners feel like they’re staying ahead; 56% report barely keeping pace.",{"data":14472,"content":14473,"nodeType":2639},{},[14474],{"data":14475,"content":14476,"nodeType":673},{},[14477,14481,14486],{"data":14478,"marks":14479,"value":14480,"nodeType":543},{},[],"Access to a huge amount of potential TI, but ",{"data":14482,"marks":14483,"value":14485,"nodeType":543},{},[14484],{"type":749},"lacking the time, context, and tools needed to parse the data",{"data":14487,"marks":14488,"value":14489,"nodeType":543},{},[]," for threats that matter to the business.",{"data":14491,"content":14492,"nodeType":2639},{},[14493],{"data":14494,"content":14495,"nodeType":673},{},[14496,14500,14505],{"data":14497,"marks":14498,"value":14499,"nodeType":543},{},[],"More information on IOCs than TTPs, leading to ",{"data":14501,"marks":14502,"value":14504,"nodeType":543},{},[14503],{"type":749},"ever-growing blocklists and attacks that still slip through",{"data":14506,"marks":14507,"value":1863,"nodeType":543},{},[],{"data":14509,"content":14510,"nodeType":673},{},[14511],{"data":14512,"marks":14513,"value":14514,"nodeType":543},{},[],"As AI-enabled adversaries continue to make it increasingly trivial to rotate infrastructure or abuse trusted services and workflows to deliver modern attacks, the hill gets steeper. ",{"data":14516,"content":14520,"nodeType":787},{"target":14517},{"sys":14518},{"id":14519,"type":792,"linkType":793},"4xlCsISP3OT9MAj3wxw67D",[],{"data":14522,"content":14523,"nodeType":673},{},[14524],{"data":14525,"marks":14526,"value":14527,"nodeType":543},{},[],"In the case of attacks that target employees via the browser — using advanced phishing methods, commercial toolkits, abuse of OAuth, abuse of trusted services to deliver phishing lures, etc. — most security teams are also working without the right foundational visibility to even begin to mature their detection process against these TTPs.",{"data":14529,"content":14530,"nodeType":673},{},[14531],{"data":14532,"marks":14533,"value":14534,"nodeType":543},{},[],"The missing input is visibility at the layer where these attacks actually execute — the browser session. Without it, detection engineering for browser-based threats is painful guesswork.",{"data":14536,"content":14537,"nodeType":796},{},[],{"data":14539,"content":14540,"nodeType":800},{},[14541],{"data":14542,"marks":14543,"value":14544,"nodeType":543},{},[],"How Push operationalized best practices for hunting from TI using agents",{"data":14546,"content":14547,"nodeType":673},{},[14548],{"data":14549,"marks":14550,"value":14551,"nodeType":543},{},[],"In building our agentic threat hunting and detection engineering pipeline at Push, we set out to solve many of the same problems that any security team faces when maturing its processes:",{"data":14553,"content":14554,"nodeType":2727},{},[14555,14565,14575],{"data":14556,"content":14557,"nodeType":2639},{},[14558],{"data":14559,"content":14560,"nodeType":673},{},[14561],{"data":14562,"marks":14563,"value":14564,"nodeType":543},{},[],"How to transform TI into technique-level intel we could write durable detections for across a wide customer base at scale?",{"data":14566,"content":14567,"nodeType":2639},{},[14568],{"data":14569,"content":14570,"nodeType":673},{},[14571],{"data":14572,"marks":14573,"value":14574,"nodeType":543},{},[],"How to create structured internal knowledge to add context to our detection engineering process that validates the relevance of what we find?",{"data":14576,"content":14577,"nodeType":2639},{},[14578],{"data":14579,"content":14580,"nodeType":673},{},[14581],{"data":14582,"marks":14583,"value":14584,"nodeType":543},{},[],"How to verify what’s worthwhile to hunt for, remove false positives, and understand the value of a detection for a specific TTP across an install base of more than 3 million browsers?",{"data":14586,"content":14587,"nodeType":673},{},[14588,14592,14601],{"data":14589,"marks":14590,"value":14591,"nodeType":543},{},[],"The process we created looks a lot like the ",{"data":14593,"content":14595,"nodeType":695},{"uri":14594},"https://medium.com/anton-on-security/blueprint-for-threat-intel-to-detection-flow-part-7-088024be08dd",[14596],{"data":14597,"marks":14598,"value":14600,"nodeType":543},{},[14599],{"type":722},"best practices",{"data":14602,"marks":14603,"value":14604,"nodeType":543},{},[]," on how to turn intelligence into meaningful detections. The difference is that agents let us run this process continuously and at a scale that would be impossible to achieve with human analysts alone.",{"data":14606,"content":14607,"nodeType":673},{},[14608,14613],{"data":14609,"marks":14610,"value":14612,"nodeType":543},{},[14611],{"type":749},"It starts with ingestion. ",{"data":14614,"marks":14615,"value":14616,"nodeType":543},{},[],"An agent tasked with TI aggregation monitors multiple industry sources — vendor reports, researcher disclosures, campaign teardowns — and filters for intelligence relevant to browser-based attack techniques. ",{"data":14618,"content":14622,"nodeType":787},{"target":14619},{"sys":14620},{"id":14621,"type":792,"linkType":793},"7fsLEGUbOINll70ViNVVkI",[],{"data":14624,"content":14625,"nodeType":673},{},[14626],{"data":14627,"marks":14628,"value":14629,"nodeType":543},{},[],"Because this agent already understands the types of attacks and scenarios that matter to Push’s detection surface, it can distinguish signal from noise at the intake stage, flagging useful intel and proposing initial lightweight hunts based on the browser metadata Push can observe. When a potential hunt looks promising, the aggregation agent hands off to a deeper analysis agent to extract what’s actually huntable.",{"data":14631,"content":14635,"nodeType":787},{"target":14632},{"sys":14633},{"id":14634,"type":792,"linkType":793},"5vyeALIziHamJ0cLiGMdGk",[],{"data":14637,"content":14638,"nodeType":673},{},[14639,14644],{"data":14640,"marks":14641,"value":14643,"nodeType":543},{},[14642],{"type":749},"That extraction step is where a general TI feed becomes something you can build detections from. ",{"data":14645,"marks":14646,"value":14647,"nodeType":543},{},[],"Agents built on frontier models have a deep understanding of web programming languages and browser workflows can decompose the intelligence into its meaningful atomic units — the specific behavioral patterns that distinguish a malicious technique from normal browser activity. ",{"data":14649,"content":14650,"nodeType":673},{},[14651],{"data":14652,"marks":14653,"value":14654,"nodeType":543},{},[],"They compare those patterns against everything the Push browser agent can observe: tabs, windows, navigation events, downloads, network requests, DOM content, script execution. Then they discard anything too broad — observable events that are commonplace, even when connected to a malicious TTP — to avoid false positives. ",{"data":14656,"content":14657,"nodeType":673},{},[14658,14662,14671],{"data":14659,"marks":14660,"value":14661,"nodeType":543},{},[],"What survives is one or more huntable technique signatures that can be identified with a high true positive rate. This is the ",{"data":14663,"content":14665,"nodeType":695},{"uri":14664},"https://pushsecurity.com/blog/the-pyramid-of-pain-in-the-ai-era",[14666],{"data":14667,"marks":14668,"value":14670,"nodeType":543},{},[14669],{"type":722},"Pyramid of Pain principle",{"data":14672,"marks":14673,"value":14674,"nodeType":543},{},[]," operationalized at machine speed: Target the technique, not the indicator, because techniques are genuinely hard for attackers to change.",{"data":14676,"content":14680,"nodeType":787},{"target":14677},{"sys":14678},{"id":14679,"type":792,"linkType":793},"5j0mvdIMkaUwDgCu0nOqSm",[],{"data":14682,"content":14683,"nodeType":673},{},[14684,14689],{"data":14685,"marks":14686,"value":14688,"nodeType":543},{},[14687],{"type":749},"In parallel, the pipeline validates whether the identified technique is genuinely novel or a variant of something Push already detects. ",{"data":14690,"marks":14691,"value":14692,"nodeType":543},{},[],"This is where our internal knowledge base comes into play. Built over three years by Push’s in-house research team and augmented continuously by the pipeline itself, it represents what Push knows about browser-based attack behaviors — a structured corpus of TTPs that lets agents classify incoming intelligence as new territory, a known variant that needs a refined detection, or something already covered. That classification determines what happens next: A net-new technique triggers a full hunt; a known variant triggers a refinement cycle; and a duplicate gets deprioritized.",{"data":14694,"content":14695,"nodeType":673},{},[14696,14701],{"data":14697,"marks":14698,"value":14700,"nodeType":543},{},[14699],{"type":749},"The hunt itself is where hypothesis meets evidence.",{"data":14702,"marks":14703,"value":14704,"nodeType":543},{},[]," Agents develop a specific, testable prediction about what the technique looks like in browser telemetry, then validate that prediction across Push’s install base. The aim of the initial hunt is to identify any potential false positives — legitimate browser behavior that matches the pattern. Then the agents refine: adjusting the query, narrowing the behavioral fingerprints, testing again. Each iteration sharpens the detection until the false positive rate drops to a negligible, tolerable level. ",{"data":14706,"content":14707,"nodeType":673},{},[14708],{"data":14709,"marks":14710,"value":14711,"nodeType":543},{},[],"The hunts that produce relevant, high-confidence results become continuous queries — a kind of early warning system for emerging threats we’re actively watching for and learning about. The most useful and reliable of those queries become production detections that protect every Push customer in real time. ",{"data":14713,"content":14717,"nodeType":787},{"target":14714},{"sys":14715},{"id":14716,"type":792,"linkType":793},"h3MN5kaaGGuL4uvNsP9JZ",[],{"data":14719,"content":14720,"nodeType":673},{},[14721,14726],{"data":14722,"marks":14723,"value":14725,"nodeType":543},{},[14724],{"type":749},"This is what “detect what matters” looks like as an engineering discipline. ",{"data":14727,"marks":14728,"value":14729,"nodeType":543},{},[],"By the time the agents have whittled down millions or trillions of browser events into a good hunt query — where good means broad enough to cast a usefully wide net for variations — and then tuned that further into a high-fidelity detection, the result is fewer, sharper detections by design. And because Push detects at the browser session layer before a user can interact with a malicious page, almost all of those detections fire pre-compromise. ",{"data":14731,"content":14732,"nodeType":673},{},[14733,14737,14742],{"data":14734,"marks":14735,"value":14736,"nodeType":543},{},[],"The same 2026 SANS survey mentioned earlier found that ",{"data":14738,"marks":14739,"value":14741,"nodeType":543},{},[14740],{"type":749},"66% of SOC practitioners cite vendor-provided rules as their primary source of false positives",{"data":14743,"marks":14744,"value":14745,"nodeType":543},{},[]," — a structural problem that persists at every organization size. Push’s pipeline produces the opposite outcome: better detections, less noise.",{"data":14747,"content":14748,"nodeType":673},{},[14749,14754],{"data":14750,"marks":14751,"value":14753,"nodeType":543},{},[14752],{"type":749},"The result is a system with two learning loops.",{"data":14755,"marks":14756,"value":14757,"nodeType":543},{},[]," An inner loop handles real-time detection and response for known attacker techniques — the production detections already deployed across the customer base. An outer loop handles continuous discovery — agents hunting for new techniques, refining existing detections, and ingesting external intelligence. ",{"data":14759,"content":14760,"nodeType":673},{},[14761,14766],{"data":14762,"marks":14763,"value":14765,"nodeType":543},{},[14764],{"type":749},"Each loop feeds the other:",{"data":14767,"marks":14768,"value":14769,"nodeType":543},{},[]," The outer loop’s discoveries become the inner loop’s new production detections, and the inner loop’s blocked attacks become raw material for the outer loop to analyze for novel variants. The knowledge base that both loops draw on grows with every cycle, which means the pipeline's detection coverage compounds at roughly the rate the threat landscape grows more complex.",{"data":14771,"content":14775,"nodeType":787},{"target":14772},{"sys":14773},{"id":14774,"type":792,"linkType":793},"3xVLn9Ldk4cOP4uFYIYyM",[],{"data":14777,"content":14778,"nodeType":673},{},[14779],{"data":14780,"marks":14781,"value":14782,"nodeType":543},{},[],"And every validated detection produced by this process, whether it originated from a blocked attack in one customer’s environment, a proactive hunt across the telemetry corpus, or a vendor report about a campaign Push has never observed on customer estates, deploys to the entire customer base.",{"data":14784,"content":14785,"nodeType":796},{},[],{"data":14787,"content":14788,"nodeType":800},{},[14789],{"data":14790,"marks":14791,"value":14792,"nodeType":543},{},[],"Herd immunity, without all the breaches to get there",{"data":14794,"content":14795,"nodeType":673},{},[14796],{"data":14797,"marks":14798,"value":14799,"nodeType":543},{},[],"That last point is where Push’s idea of herd immunity diverges from the traditional definition.",{"data":14801,"content":14802,"nodeType":673},{},[14803,14807,14812],{"data":14804,"marks":14805,"value":14806,"nodeType":543},{},[],"Detection and response platforms and MDR services commonly describe a ",{"data":14808,"marks":14809,"value":14811,"nodeType":543},{},[14810],{"type":749},"herd immunity benefit",{"data":14813,"marks":14814,"value":14815,"nodeType":543},{},[],": What one customer encounters, every customer gets protection against. The mechanism is real, but the learning input is typically a breach or a compromise. Someone has to be the first victim.",{"data":14817,"content":14818,"nodeType":673},{},[14819],{"data":14820,"marks":14821,"value":14823,"nodeType":543},{},[14822],{"type":749},"Push’s approach is different. ",{"data":14825,"content":14826,"nodeType":673},{},[14827],{"data":14828,"marks":14829,"value":14830,"nodeType":543},{},[],"Modern browser-based attacks frequently rely on a series of techniques strung together to achieve a compromise. From its vantage point in the browser, Push catches many novel techniques with existing detections pre-compromise because it recognizes a portion of the attack techniques in the chain. The detection process then identifies what’s new about a previously unseen variation of a known TTP — perhaps an evasion technique the kit hadn’t used before, an unusual lure or infrastructure pattern, etc. ",{"data":14832,"content":14833,"nodeType":673},{},[14834],{"data":14835,"marks":14836,"value":14838,"nodeType":543},{},[14837],{"type":749},"The detection gets better for customers and no one was compromised to get there.",{"data":14840,"content":14841,"nodeType":673},{},[14842],{"data":14843,"marks":14844,"value":14845,"nodeType":543},{},[],"On the external intelligence side, the pipeline ingests published research about a campaign Push has never observed, extracts the durable behavioral characteristics, validates them against browser telemetry, refines the query to tune out false positives, and ships detections before the technique is ever used against a Push customer. The protection arrives ahead of the attack.",{"data":14847,"content":14848,"nodeType":673},{},[14849,14853,14861,14864,14872,14875,14882],{"data":14850,"marks":14851,"value":14852,"nodeType":543},{},[],"These are the processes behind Push’s identification of ",{"data":14854,"content":14856,"nodeType":695},{"uri":14855},"https://pushsecurity.com/blog/consentfix",[14857],{"data":14858,"marks":14859,"value":949,"nodeType":543},{},[14860],{"type":722},{"data":14862,"marks":14863,"value":2164,"nodeType":543},{},[],{"data":14865,"content":14867,"nodeType":695},{"uri":14866},"https://pushsecurity.com/blog/installfix",[14868],{"data":14869,"marks":14870,"value":13146,"nodeType":543},{},[14871],{"type":722},{"data":14873,"marks":14874,"value":3232,"nodeType":543},{},[],{"data":14876,"content":14877,"nodeType":695},{"uri":7276},[14878],{"data":14879,"marks":14880,"value":7291,"nodeType":543},{},[14881],{"type":722},{"data":14883,"marks":14884,"value":14885,"nodeType":543},{},[]," — three browser-based attack techniques Push's team discovered or documented for the first time. In several cases, detections were blocking active campaigns against Push customers before the technique had been publicly documented. Those detections rolled out to every customer within hours or days of first observation.",{"data":14887,"content":14888,"nodeType":796},{},[],{"data":14890,"content":14891,"nodeType":800},{},[14892],{"data":14893,"marks":14894,"value":14895,"nodeType":543},{},[],"Outcomes: By the numbers",{"data":14897,"content":14898,"nodeType":673},{},[14899],{"data":14900,"marks":14901,"value":14902,"nodeType":543},{},[],"Looking at the quantifiable outcomes of this agentic threat hunting capability over the last few months, the benefits for customers become clear.",{"data":14904,"content":14908,"nodeType":787},{"target":14905},{"sys":14906},{"id":14907,"type":792,"linkType":793},"7uNrNGUjjBiG9qEsfen7Xi",[],{"data":14910,"content":14911,"nodeType":829},{},[14912],{"data":14913,"marks":14914,"value":14915,"nodeType":543},{},[],"Velocity",{"data":14917,"content":14918,"nodeType":673},{},[14919],{"data":14920,"marks":14921,"value":14922,"nodeType":543},{},[],"Agents allow us to massively scale our research expertise, delivering detections for emerging threats or new variants much faster than humans alone can.",{"data":14924,"content":14925,"nodeType":673},{},[14926,14930,14935],{"data":14927,"marks":14928,"value":14929,"nodeType":543},{},[],"This year already, we’ve ",{"data":14931,"marks":14932,"value":14934,"nodeType":543},{},[14933],{"type":749},"tripled",{"data":14936,"marks":14937,"value":14938,"nodeType":543},{},[]," the number of new detections shipped to customers.",{"data":14940,"content":14941,"nodeType":673},{},[14942,14946,14951],{"data":14943,"marks":14944,"value":14945,"nodeType":543},{},[],"We’ve also reduced the time it takes to ship production-ready detections for new threats from weeks to ",{"data":14947,"marks":14948,"value":14950,"nodeType":543},{},[14949],{"type":749},"minutes",{"data":14952,"marks":14953,"value":1863,"nodeType":543},{},[],{"data":14955,"content":14956,"nodeType":829},{},[14957],{"data":14958,"marks":14959,"value":14960,"nodeType":543},{},[],"Detection coverage",{"data":14962,"content":14963,"nodeType":673},{},[14964,14968,14973],{"data":14965,"marks":14966,"value":14967,"nodeType":543},{},[],"With that scaled expertise comes broad coverage. We perform an average of ",{"data":14969,"marks":14970,"value":14972,"nodeType":543},{},[14971],{"type":749},"300+ hunts",{"data":14974,"marks":14975,"value":14976,"nodeType":543},{},[]," a month (a mix of live queries for identified TTPs we’re looking for, plus net-new hunts for emerging threats we identify in any given month).",{"data":14978,"content":14979,"nodeType":673},{},[14980],{"data":14981,"marks":14982,"value":14983,"nodeType":543},{},[],"A few other metrics that demonstrate the scale of our detection coverage:",{"data":14985,"content":14986,"nodeType":2727},{},[14987,15002,15017],{"data":14988,"content":14989,"nodeType":2639},{},[14990],{"data":14991,"content":14992,"nodeType":673},{},[14993,14998],{"data":14994,"marks":14995,"value":14997,"nodeType":543},{},[14996],{"type":749},"75+",{"data":14999,"marks":15000,"value":15001,"nodeType":543},{},[]," attacker tools documented in our KB so far",{"data":15003,"content":15004,"nodeType":2639},{},[15005],{"data":15006,"content":15007,"nodeType":673},{},[15008,15013],{"data":15009,"marks":15010,"value":15012,"nodeType":543},{},[15011],{"type":749},"25+",{"data":15014,"marks":15015,"value":15016,"nodeType":543},{},[]," variants of existing attacks we’ve identified and shipped detections for",{"data":15018,"content":15019,"nodeType":2639},{},[15020],{"data":15021,"content":15022,"nodeType":673},{},[15023,15028],{"data":15024,"marks":15025,"value":15027,"nodeType":543},{},[15026],{"type":749},"10,000+",{"data":15029,"marks":15030,"value":15031,"nodeType":543},{},[]," monthly sessions analyzed",{"data":15033,"content":15034,"nodeType":829},{},[15035],{"data":15036,"marks":15037,"value":15038,"nodeType":543},{},[],"Protection from emerging threats",{"data":15040,"content":15041,"nodeType":673},{},[15042,15046,15051],{"data":15043,"marks":15044,"value":15045,"nodeType":543},{},[],"On the emerging threat side, our team was the first to identify or document ",{"data":15047,"marks":15048,"value":15050,"nodeType":543},{},[15049],{"type":749},"three new browser-based attack techniques",{"data":15052,"marks":15053,"value":15054,"nodeType":543},{},[]," — ConsentFix, InstallFix, and LLMShare — shipping detections to all customers quickly after identification.",{"data":15056,"content":15057,"nodeType":673},{},[15058],{"data":15059,"marks":15060,"value":15061,"nodeType":543},{},[],"In that same time frame, we’ve also:",{"data":15063,"content":15064,"nodeType":2727},{},[15065,15092],{"data":15066,"content":15067,"nodeType":2639},{},[15068],{"data":15069,"content":15070,"nodeType":673},{},[15071,15075,15080,15083,15088],{"data":15072,"marks":15073,"value":15074,"nodeType":543},{},[],"Protected ",{"data":15076,"marks":15077,"value":15079,"nodeType":543},{},[15078],{"type":749},"60+",{"data":15081,"marks":15082,"value":3529,"nodeType":543},{},[],{"data":15084,"marks":15085,"value":15087,"nodeType":543},{},[15086],{"type":749},"customers in the last 3 months",{"data":15089,"marks":15090,"value":15091,"nodeType":543},{},[]," who’ve been targeted with novel phishing techniques — identifying never-before-seen techniques, lures, delivery mechanisms, interactions, tools, or attack chains",{"data":15093,"content":15094,"nodeType":2639},{},[15095],{"data":15096,"content":15097,"nodeType":673},{},[15098,15102,15107],{"data":15099,"marks":15100,"value":15101,"nodeType":543},{},[],"Prevented ",{"data":15103,"marks":15104,"value":15106,"nodeType":543},{},[15105],{"type":749},"225+",{"data":15108,"marks":15109,"value":15110,"nodeType":543},{},[]," instances of threats pre-compromise for novel techniques",{"data":15112,"content":15113,"nodeType":673},{},[15114],{"data":15115,"marks":15116,"value":15117,"nodeType":543},{},[],"In all of the above situations, Push customers didn’t have to do anything — no combing through TI to find relevant details, no writing their own detections and tuning out false positives, or spending cycles to unpack a particularly knotty attack chain that used techniques they had never seen before. ",{"data":15119,"content":15120,"nodeType":673},{},[15121],{"data":15122,"marks":15123,"value":15125,"nodeType":543},{},[15124],{"type":749},"That’s what operationalized intelligence looks like at scale, delivered as a product, not a project.",{"data":15127,"content":15128,"nodeType":796},{},[],{"data":15130,"content":15131,"nodeType":800},{},[15132],{"data":15133,"marks":15134,"value":5884,"nodeType":543},{},[],{"data":15136,"content":15137,"nodeType":673},{},[15138],{"data":15139,"marks":15140,"value":15141,"nodeType":543},{},[],"The same foundational capabilities that enable this agentic threat hunting pipeline also deliver other security outcomes for Push customers: gaining visibility and control over AI tool usage; hardening identities by surfacing credential reuse, SSO gaps, and shadow IT; and supporting data loss and insider investigations with browser-layer telemetry that other tools can’t see.",{"data":15143,"content":15144,"nodeType":673},{},[15145,15149,15156],{"data":15146,"marks":15147,"value":15148,"nodeType":543},{},[],"If you’d like to learn more, ",{"data":15150,"content":15151,"nodeType":695},{"uri":5926},[15152],{"data":15153,"marks":15154,"value":12841,"nodeType":543},{},[15155],{"type":722},{"data":15157,"marks":15158,"value":12845,"nodeType":543},{},[],"How Push’s agentic threat hunting in the browser benefits every customer","Security outcomes you can achieve when AI agents hunt in the browser, identify new threats, and ship detections that benefit everyone.","2026-07-23T00:00:00.000Z","agentic-threat-hunting-benefits-for-customers",{"items":15164},[15165,15167],{"sys":15166,"name":2921},{"id":2920},{"sys":15168,"name":2917},{"id":2916},{"items":15170},[15171],{"fullName":6598,"firstName":6599,"jobTitle":6600,"profilePicture":15172},{"url":6602},{"__typename":1608,"sys":15174,"content":15176,"title":15962,"synopsis":15963,"hashTags":59,"publishedDate":15964,"slug":15965,"tagsCollection":15966,"authorsCollection":15972},{"id":15175},"Gcg7PGuICrlRcqq1QFXxH",{"json":15177},{"data":15178,"content":15179,"nodeType":669},{},[15180,15187,15194,15225,15232,15238,15244,15256,15259,15267,15283,15290,15296,15303,15310,15316,15319,15327,15334,15340,15346,15353,15360,15378,15384,15387,15395,15413,15419,15426,15429,15437,15444,15451,15457,15463,15506,15513,15516,15524,15531,15538,15581,15588,15619,15626,15669,15676,15679,15687,15705,15712,15720,15735,15742,15761,15768,15771,15777,15783,15799,15802,15810,15829,15836,15956],{"data":15181,"content":15182,"nodeType":673},{},[15183],{"data":15184,"marks":15185,"value":15186,"nodeType":543},{},[],"Shared conversations on AI chatbot platforms have become the latest delivery mechanism for malware campaigns targeting macOS and Windows users. Attackers create content on platforms like ChatGPT and Claude that appears to offer installation guidance or service updates, then drive traffic to it via search engine results in the form of malvertising and SEO poisoning.  ",{"data":15188,"content":15189,"nodeType":673},{},[15190],{"data":15191,"marks":15192,"value":15193,"nodeType":543},{},[],"The content lives on chatgpt.com or claude.ai — domains that users and security tools trust implicitly — so the attack bypasses URL reputation checks before the victim even reaches the malicious payload.",{"data":15195,"content":15196,"nodeType":673},{},[15197,15201,15209,15213,15221],{"data":15198,"marks":15199,"value":15200,"nodeType":543},{},[],"Several variants of this technique have been ",{"data":15202,"content":15204,"nodeType":695},{"uri":15203},"https://www.bleepingcomputer.com/news/security/hackers-abuse-google-ads-claudeai-chats-to-push-mac-malware/",[15205],{"data":15206,"marks":15207,"value":15208,"nodeType":543},{},[],"reported over the past few months",{"data":15210,"marks":15211,"value":15212,"nodeType":543},{},[],". The earliest examples used shared Claude.ai conversations disguised as installation guides — complete with fake \"Apple Support\" attribution — that walked users through opening a terminal and pasting a curl command that downloaded and executed an infostealer. ",{"data":15214,"content":15216,"nodeType":695},{"uri":15215},"https://www.kaspersky.com/blog/share-chatgpt-chat-clickfix-macos-amos-infostealer/54928/",[15217],{"data":15218,"marks":15219,"value":15220,"nodeType":543},{},[],"Kaspersky documented a parallel campaign",{"data":15222,"marks":15223,"value":15224,"nodeType":543},{},[]," using shared ChatGPT conversations to deliver the AMOS (Atomic macOS Stealer) via the same paste-this-command social engineering pattern. ",{"data":15226,"content":15227,"nodeType":673},{},[15228],{"data":15229,"marks":15230,"value":15231,"nodeType":543},{},[],"Push has detected a new variant that goes beyond the previously reported technique of embedding terminal commands in shared conversations: the attacker has used ChatGPT's code rendering feature to build a fully designed fake page that mimics a ChatGPT service disruption, redirecting victims to a convincing clone of ChatGPT's download page that delivers a malicious executable. ",{"data":15233,"content":15237,"nodeType":787},{"target":15234},{"sys":15235},{"id":15236,"type":792,"linkType":793},"5lz9zt223pecGvdaqdvSTQ",[],{"data":15239,"content":15243,"nodeType":787},{"target":15240},{"sys":15241},{"id":15242,"type":792,"linkType":793},"51GomAj3VOjnbmgd1DWYu0",[],{"data":15245,"content":15246,"nodeType":673},{},[15247,15252],{"data":15248,"marks":15249,"value":15251,"nodeType":543},{},[15250],{"type":749},"This is a live campaign which is still generating detections across our customer base at the time of writing. ",{"data":15253,"marks":15254,"value":15255,"nodeType":543},{},[],"Push customers are already protected and do not need to take further action. The malicious page URLs can be found at the end of this report but are not exhaustive and are liable to change. ",{"data":15257,"content":15258,"nodeType":796},{},[],{"data":15260,"content":15261,"nodeType":800},{},[15262],{"data":15263,"marks":15264,"value":15266,"nodeType":543},{},[15265],{"type":749},"A fake page, not a fake conversation",{"data":15268,"content":15269,"nodeType":673},{},[15270,15274,15279],{"data":15271,"marks":15272,"value":15273,"nodeType":543},{},[],"Previously reported variants relied on shared ",{"data":15275,"marks":15276,"value":15278,"nodeType":543},{},[15277],{"type":739},"conversations",{"data":15280,"marks":15281,"value":15282,"nodeType":543},{},[]," — the attacker created a chat that contained step-by-step instructions for the victim to follow, typically involving pasting a command into their terminal. The social engineering was conversational: the \"AI assistant\" appeared to be helpfully guiding the user through an installation process.",{"data":15284,"content":15285,"nodeType":673},{},[15286],{"data":15287,"marks":15288,"value":15289,"nodeType":543},{},[],"But now, rather than a shared conversation, the attacker has used ChatGPT's code rendering feature to create a fully designed, self-contained web page hosted at a chatgpt.com/s/ URL. It renders as what appears to be a ChatGPT service disruption notice:",{"data":15291,"content":15295,"nodeType":787},{"target":15292},{"sys":15293},{"id":15294,"type":792,"linkType":793},"1O9gyQab81SnbxhQp2aa5Z",[],{"data":15297,"content":15298,"nodeType":673},{},[15299],{"data":15300,"marks":15301,"value":15302,"nodeType":543},{},[],"A professional-looking error message reads: \"We're experiencing high traffic right now. Our website is temporarily unavailable due to a large number of users. Download our desktop app to continue.\" A prominent download button sits below.",{"data":15304,"content":15305,"nodeType":673},{},[15306],{"data":15307,"marks":15308,"value":15309,"nodeType":543},{},[],"The \"Show code\" toggle at the top of the page reveals what's actually happening — the entire thing is custom HTML and CSS, authored to mimic a ChatGPT system notice, rendered using ChatGPT's code output feature. A web page inside a web page, hosted on a domain that every URL reputation system in the world considers safe.",{"data":15311,"content":15315,"nodeType":787},{"target":15312},{"sys":15313},{"id":15314,"type":792,"linkType":793},"4kQTfxB3aVH9W9BeYOuljP",[],{"data":15317,"content":15318,"nodeType":796},{},[],{"data":15320,"content":15321,"nodeType":800},{},[15322],{"data":15323,"marks":15324,"value":15326,"nodeType":543},{},[15325],{"type":749},"The download page",{"data":15328,"content":15329,"nodeType":673},{},[15330],{"data":15331,"marks":15332,"value":15333,"nodeType":543},{},[],"Clicking the download button redirects the user to openew[.]app, which presents a convincing clone of ChatGPT's official desktop application download page — complete with OpenAI branding, macOS and Windows download buttons, a Chrome extension link, and a mobile download section.",{"data":15335,"content":15339,"nodeType":787},{"target":15336},{"sys":15337},{"id":15338,"type":792,"linkType":793},"4MdFc4OB37ZihTGx506QJ6",[],{"data":15341,"content":15345,"nodeType":787},{"target":15342},{"sys":15343},{"id":15344,"type":792,"linkType":793},"LaPUy0zpIeY8s4PF2wkat",[],{"data":15347,"content":15348,"nodeType":673},{},[15349],{"data":15350,"marks":15351,"value":15352,"nodeType":543},{},[],"The site also displays differently depending on who visits it. When Push researchers examined the URL via URLScan, the scanner was redirected to a different page entirely — a generic AR/VR company website with no obvious connection to ChatGPT. ",{"data":15354,"content":15355,"nodeType":673},{},[15356],{"data":15357,"marks":15358,"value":15359,"nodeType":543},{},[],"Real users in a browser see the fake download page; automated scanners and bots see something benign. This kind of conditional rendering is a well-established evasion technique in the malvertising ecosystem, and it makes the malicious infrastructure harder for security teams and threat intelligence services to identify and analyze.",{"data":15361,"content":15362,"nodeType":673},{},[15363,15367,15375],{"data":15364,"marks":15365,"value":15366,"nodeType":543},{},[],"The downloaded executable poses as \"ChatGPT for Desktop\" and is ",{"data":15368,"content":15370,"nodeType":695},{"uri":15369},"https://www.virustotal.com/gui/file/de8c50e8ccd240ef9d10ec26c26eeb37a4d1cad7c1e0edf3bb6e5689ec2dde78",[15371],{"data":15372,"marks":15373,"value":15374,"nodeType":543},{},[],"flagged on VirusTotal",{"data":15376,"marks":15377,"value":1863,"nodeType":543},{},[],{"data":15379,"content":15383,"nodeType":787},{"target":15380},{"sys":15381},{"id":15382,"type":792,"linkType":793},"3FSbwoFJYQrcyo9uMsQIWI",[],{"data":15385,"content":15386,"nodeType":796},{},[],{"data":15388,"content":15389,"nodeType":800},{},[15390],{"data":15391,"marks":15392,"value":15394,"nodeType":543},{},[15393],{"type":749},"The Claude variant: same campaign, different platform",{"data":15396,"content":15397,"nodeType":673},{},[15398,15402,15409],{"data":15399,"marks":15400,"value":15401,"nodeType":543},{},[],"Alongside the ChatGPT rendered-page variant, Push has also detected the previously reported style of attack using shared Claude.ai conversations. These follow the pattern documented by ",{"data":15403,"content":15404,"nodeType":695},{"uri":15203},[15405],{"data":15406,"marks":15407,"value":15408,"nodeType":543},{},[],"BleepingComputer",{"data":15410,"marks":15411,"value":15412,"nodeType":543},{},[],": a shared chat disguised as a \"Claude Code on Mac\" installation guide, attributed to \"Apple Support,\" containing a curl command that downloads and executes malware.",{"data":15414,"content":15418,"nodeType":787},{"target":15415},{"sys":15416},{"id":15417,"type":792,"linkType":793},"5sWayuTsVdiLSLoS4sv2Vc",[],{"data":15420,"content":15421,"nodeType":673},{},[15422],{"data":15423,"marks":15424,"value":15425,"nodeType":543},{},[],"The fact that both the ChatGPT and Claude variants are appearing in Push customer environments suggests a campaign — or at least a shared playbook — that is actively experimenting with different platforms and different social engineering approaches to find what converts best.",{"data":15427,"content":15428,"nodeType":796},{},[],{"data":15430,"content":15431,"nodeType":800},{},[15432],{"data":15433,"marks":15434,"value":15436,"nodeType":543},{},[15435],{"type":749},"Malvertising remains one of the top phishing delivery channels",{"data":15438,"content":15439,"nodeType":673},{},[15440],{"data":15441,"marks":15442,"value":15443,"nodeType":543},{},[],"Push has detected this variant across multiple customer environments, with users arriving at these shared chat URLs after searching for terms including \"chatgpt,\" \"chatgpt free,\" \"chat gpt,\" and common typos like \"chatgo,\" \"chatgot,\" and \"cvhatgpt.\" ",{"data":15445,"content":15446,"nodeType":673},{},[15447],{"data":15448,"marks":15449,"value":15450,"nodeType":543},{},[],"You can see an example of this below: it's incredibly convincing, and uses the real ChatGPT domain — so even users that are paying attention are liable to fall for it. ",{"data":15452,"content":15456,"nodeType":787},{"target":15453},{"sys":15454},{"id":15455,"type":792,"linkType":793},"1GYWOyHpZT1rdTm6IGOKu8",[],{"data":15458,"content":15462,"nodeType":787},{"target":15459},{"sys":15460},{"id":15461,"type":792,"linkType":793},"4HpFJRAZH2lbygaEk2xOnN",[],{"data":15464,"content":15465,"nodeType":673},{},[15466,15470,15478,15482,15490,15493,15502],{"data":15467,"marks":15468,"value":15469,"nodeType":543},{},[],"This fits a pattern Push has tracked extensively. ",{"data":15471,"content":15473,"nodeType":695},{"uri":15472},"https://pushsecurity.com/blog/verizon-dbir-2026-review/",[15474],{"data":15475,"marks":15476,"value":15477,"nodeType":543},{},[],"Search-based delivery is now the dominant channel for malware distribution",{"data":15479,"marks":15480,"value":15481,"nodeType":543},{},[]," — our own data shows that ClickFix attacks are reached via search results rather than email in 4 of 5 cases, and Push's own research into ",{"data":15483,"content":15485,"nodeType":695},{"uri":15484},"https://pushsecurity.com/blog/analysing-a-sophisticated-google-malvertising-attack/",[15486],{"data":15487,"marks":15488,"value":15489,"nodeType":543},{},[],"malvertising campaigns impersonating brands like TradingView",{"data":15491,"marks":15492,"value":3096,"nodeType":543},{},[],{"data":15494,"content":15496,"nodeType":695},{"uri":15495},"https://pushsecurity.com/blog/google-search-malvertising-campaign-continues-now-impersonating-ahrefs/",[15497],{"data":15498,"marks":15499,"value":15501,"nodeType":543},{},[15500],{"type":722},"Ahrefs",{"data":15503,"marks":15504,"value":15505,"nodeType":543},{},[]," has demonstrated how effectively search ads can funnel victims to malicious pages. ",{"data":15507,"content":15508,"nodeType":673},{},[15509],{"data":15510,"marks":15511,"value":15512,"nodeType":543},{},[],"The shared-chat technique adds a new dimension: the destination URL itself is genuine (chatgpt.com, claude.ai), which means even a cautious user who checks the URL before clicking will see nothing suspicious.",{"data":15514,"content":15515,"nodeType":796},{},[],{"data":15517,"content":15518,"nodeType":800},{},[15519],{"data":15520,"marks":15521,"value":15523,"nodeType":543},{},[15522],{"type":749},"Legitimate platform abuse is everywhere",{"data":15525,"content":15526,"nodeType":673},{},[15527],{"data":15528,"marks":15529,"value":15530,"nodeType":543},{},[],"This is one example of a much broader pattern that has become one of the defining characteristics of the 2026 threat landscape: attackers systematically abusing legitimate platforms as attack infrastructure. The scale and variety of this abuse in recent months alone is striking, and it spans every stage of the phishing chain.",{"data":15532,"content":15533,"nodeType":829},{},[15534],{"data":15535,"marks":15536,"value":15537,"nodeType":543},{},[],"Legit platform abuse for delivery",{"data":15539,"content":15540,"nodeType":673},{},[15541,15545,15553,15557,15565,15569,15577],{"data":15542,"marks":15543,"value":15544,"nodeType":543},{},[],"On the delivery side, attackers have been ",{"data":15546,"content":15548,"nodeType":695},{"uri":15547},"https://www.bleepingcomputer.com/news/security/amazon-ses-increasingly-abused-in-phishing-to-evade-detection/",[15549],{"data":15550,"marks":15551,"value":15552,"nodeType":543},{},[],"weaponizing stolen AWS credentials to send phishing through Amazon SES",{"data":15554,"marks":15555,"value":15556,"nodeType":543},{},[]," that passes SPF, DKIM, and DMARC validation because SES is a legitimate Amazon service. A Vietnamese operation dubbed ",{"data":15558,"content":15560,"nodeType":695},{"uri":15559},"https://thehackernews.com/2026/05/30000-facebook-accounts-hacked-via.html",[15561],{"data":15562,"marks":15563,"value":15564,"nodeType":543},{},[],"AccountDumpling used Google AppSheet's built-in email capability",{"data":15566,"marks":15567,"value":15568,"nodeType":543},{},[]," as a phishing relay to harvest 30,000 Facebook credentials. ",{"data":15570,"content":15572,"nodeType":695},{"uri":15571},"https://techcrunch.com/2026/05/21/scammers-are-abusing-an-internal-microsoft-account-to-send-spam/",[15573],{"data":15574,"marks":15575,"value":15576,"nodeType":543},{},[],"Scammers exploited Microsoft's own internal notification pipeline",{"data":15578,"marks":15579,"value":15580,"nodeType":543},{},[]," — sending phishing from the same msonlineservicesteam@microsoftonline.com address that delivers legitimate 2FA codes — with Spamhaus confirming months of ongoing abuse.",{"data":15582,"content":15583,"nodeType":829},{},[15584],{"data":15585,"marks":15586,"value":15587,"nodeType":543},{},[],"Legit platform abuse for hosting",{"data":15589,"content":15590,"nodeType":673},{},[15591,15595,15603,15607,15615],{"data":15592,"marks":15593,"value":15594,"nodeType":543},{},[],"For hosting, the platforms being abused read like a who's who of modern web infrastructure. ",{"data":15596,"content":15598,"nodeType":695},{"uri":15597},"https://www.securityweek.com/over-500-organizations-hit-in-years-long-phishing-campaign/",[15599],{"data":15600,"marks":15601,"value":15602,"nodeType":543},{},[],"Operation HookedWing ran for four years",{"data":15604,"marks":15605,"value":15606,"nodeType":543},{},[]," on GitHub Pages and Vercel, compromising 500+ organizations across more than 100 GitHub Pages domains before anyone documented it publicly. Cofense has separately ",{"data":15608,"content":15610,"nodeType":695},{"uri":15609},"https://cofense.com/blog/steal-smarter-not-harder-malicious-use-of-vercel-for-credential-phishing/",[15611],{"data":15612,"marks":15613,"value":15614,"nodeType":543},{},[],"documented the growing abuse of Vercel",{"data":15616,"marks":15617,"value":15618,"nodeType":543},{},[]," for credential phishing hosting. Pixm's Q1 2026 phishing report tracked over 100 unique Azure Blob Storage subdomain variants hosting phishing content that carried Microsoft's own domain reputation, alongside abuse of Cloudflare CDN, Cloudflare Workers, Cloudflare R2, Backblaze B2, and Supabase. ",{"data":15620,"content":15621,"nodeType":829},{},[15622],{"data":15623,"marks":15624,"value":15625,"nodeType":543},{},[],"Abuse of compromised websites that are otherwise legit",{"data":15627,"content":15628,"nodeType":673},{},[15629,15633,15641,15645,15653,15657,15665],{"data":15630,"marks":15631,"value":15632,"nodeType":543},{},[],"Compromised legitimate sites are also being repurposed at scale. A mass exploitation of a ",{"data":15634,"content":15636,"nodeType":695},{"uri":15635},"https://www.bleepingcomputer.com/news/security/ghost-cms-sql-injection-flaw-exploited-in-large-scale-clickfix-campaign/",[15637],{"data":15638,"marks":15639,"value":15640,"nodeType":543},{},[],"Ghost CMS vulnerability planted ClickFix pages across 700+ websites",{"data":15642,"marks":15643,"value":15644,"nodeType":543},{},[]," including Harvard, Oxford, and DuckDuckGo subdomains. Microsoft recently documented a campaign where ",{"data":15646,"content":15648,"nodeType":695},{"uri":15647},"https://www.microsoft.com/en-us/security/blog/2026/05/26/poisoned-search-results-gpu-mining-cryptojacking-campaign-abusing-screenconnect-microsoft-net-utilities/",[15649],{"data":15650,"marks":15651,"value":15652,"nodeType":543},{},[],"SEO poisoning was combined with AI chatbot recommendation manipulation",{"data":15654,"marks":15655,"value":15656,"nodeType":543},{},[]," to deliver GPU mining malware — extending the poisoning from traditional search results into AI-generated software recommendations. And ",{"data":15658,"content":15660,"nodeType":695},{"uri":15659},"https://www.helpnetsecurity.com/2026/05/27/deno-rat-malware-fake-chatgpt-claude-installers/",[15661],{"data":15662,"marks":15663,"value":15664,"nodeType":543},{},[],"fake ChatGPT and Claude installers on GitHub and SourceForge",{"data":15666,"marks":15667,"value":15668,"nodeType":543},{},[]," have been delivering the DinDoor backdoor and a Deno-based RAT via repositories that mimic legitimate developer tool distributions.",{"data":15670,"content":15671,"nodeType":673},{},[15672],{"data":15673,"marks":15674,"value":15675,"nodeType":543},{},[],"The structural problem is that every one of these platforms is genuinely legitimate, and the security controls that evaluate them — domain reputation, email authentication, URL categorization — confirm them as trusted because they are trusted. This attack extends this pattern into new territory by weaponizing the content-sharing features of AI chatbot platforms specifically, but the underlying principles are the same. ",{"data":15677,"content":15678,"nodeType":796},{},[],{"data":15680,"content":15681,"nodeType":800},{},[15682],{"data":15683,"marks":15684,"value":15686,"nodeType":543},{},[15685],{"type":749},"Impact analysis",{"data":15688,"content":15689,"nodeType":673},{},[15690,15694,15701],{"data":15691,"marks":15692,"value":15693,"nodeType":543},{},[],"Shared-chat malware delivery exploits a structural property of AI platforms that traditional security controls aren't designed to handle. Domain reputation, URL categorization, and safe browsing databases all treat chatgpt.com and claude.ai as trusted — because they are. Using these trusted pages to link off to further convincing-looking pages hosting malware allows the attacker to run campaigns that blend in, as well as rotate the phishing delivery pages later in the chain should they ever be flagged, allowing the campaign to continue without interruption (a well known ",{"data":15695,"content":15696,"nodeType":695},{"uri":3383},[15697],{"data":15698,"marks":15699,"value":15700,"nodeType":543},{},[],"detection evasion technique",{"data":15702,"marks":15703,"value":15704,"nodeType":543},{},[],"). ",{"data":15706,"content":15707,"nodeType":673},{},[15708],{"data":15709,"marks":15710,"value":15711,"nodeType":543},{},[],"What makes the rendered-page variant particularly concerning is that it eliminates the most obvious red flag in the earlier attacks. The Claude.ai conversation variants required the victim to recognize that a shared chat instructing them to paste terminal commands might be suspicious — a tall order for many users, but at least the attack surface was visible. The rendered-page variant shows nothing that looks like an attack. It presents what appears to be a routine service disruption with a reasonable call to action: download the desktop app to continue using ChatGPT. ",{"data":15713,"content":15714,"nodeType":829},{},[15715],{"data":15716,"marks":15717,"value":15719,"nodeType":543},{},[15718],{"type":749},"How Push detected the attack",{"data":15721,"content":15722,"nodeType":673},{},[15723,15727,15731],{"data":15724,"marks":15725,"value":15726,"nodeType":543},{},[],"We've aligned our detection logic for this technique under the name ",{"data":15728,"marks":15729,"value":7291,"nodeType":543},{},[15730],{"type":749},{"data":15732,"marks":15733,"value":15734,"nodeType":543},{},[]," — a technique-level detection that covers shared content abuse across LLM platforms, not tied to any single campaign or set of IOCs. ",{"data":15736,"content":15737,"nodeType":673},{},[15738],{"data":15739,"marks":15740,"value":15741,"nodeType":543},{},[],"Because Push sees the full context of how a user arrived at a page and what that page does once it renders, we can identify LLMShare attacks regardless of which AI platform is being abused or what social engineering wrapper the attacker has chosen. ",{"data":15743,"content":15744,"nodeType":673},{},[15745,15749,15757],{"data":15746,"marks":15747,"value":15748,"nodeType":543},{},[],"When we identified the initial instances of this campaign, we used our ",{"data":15750,"content":15752,"nodeType":695},{"uri":15751},"https://pushsecurity.com/blog/can-ai-replace-a-threat-researcher-what-we-learned-building-an-agentic-threat-hunting-pipeline/",[15753],{"data":15754,"marks":15755,"value":15756,"nodeType":543},{},[],"agentic threat hunting pipeline",{"data":15758,"marks":15759,"value":15760,"nodeType":543},{},[]," to hunt for additional examples across our customer telemetry, develop the LLMShare detection, and rapidly deploy it to customers. Push blocks users from interacting with the page before any malicious activity can occur. ",{"data":15762,"content":15763,"nodeType":673},{},[15764],{"data":15765,"marks":15766,"value":15767,"nodeType":543},{},[],"Push customers do not need to take any further action.",{"data":15769,"content":15770,"nodeType":796},{},[],{"data":15772,"content":15773,"nodeType":673},{},[15774],{"data":15775,"marks":15776,"value":2882,"nodeType":543},{},[],{"data":15778,"content":15779,"nodeType":673},{},[15780],{"data":15781,"marks":15782,"value":2889,"nodeType":543},{},[],{"data":15784,"content":15785,"nodeType":673},{},[15786,15789,15796],{"data":15787,"marks":15788,"value":21,"nodeType":543},{},[],{"data":15790,"content":15791,"nodeType":695},{"uri":2898},[15792],{"data":15793,"marks":15794,"value":2904,"nodeType":543},{},[15795],{"type":722},{"data":15797,"marks":15798,"value":21,"nodeType":543},{},[],{"data":15800,"content":15801,"nodeType":796},{},[],{"data":15803,"content":15804,"nodeType":800},{},[15805],{"data":15806,"marks":15807,"value":15809,"nodeType":543},{},[15808],{"type":749},"Indicators of compromise",{"data":15811,"content":15812,"nodeType":673},{},[15813,15817,15825],{"data":15814,"marks":15815,"value":15816,"nodeType":543},{},[],"As we always say, short-lived IoCs are of limited value when tackling modern phishing attacks due to the rate at which attackers are able to ",{"data":15818,"content":15820,"nodeType":695},{"uri":15819},"https://phishing-techniques.pushsecurity.com/techniques/domain-rotation-redirection/",[15821],{"data":15822,"marks":15823,"value":15824,"nodeType":543},{},[],"quickly spin up and rotate the sites used",{"data":15826,"marks":15827,"value":15828,"nodeType":543},{},[]," in the attack chain. IoC-based detections for campaigns like this are of limited value.",{"data":15830,"content":15831,"nodeType":673},{},[15832],{"data":15833,"marks":15834,"value":15835,"nodeType":543},{},[],"At the time of writing, the indicators observed were:",{"data":15837,"content":15838,"nodeType":3708},{},[15839,15865,15888,15910,15933],{"data":15840,"content":15841,"nodeType":3470},{},[15842,15854],{"data":15843,"content":15844,"nodeType":15853},{},[15845],{"data":15846,"content":15847,"nodeType":673},{},[15848],{"data":15849,"marks":15850,"value":15852,"nodeType":543},{},[15851],{"type":749},"Indicator","table-header-cell",{"data":15855,"content":15856,"nodeType":15853},{},[15857],{"data":15858,"content":15859,"nodeType":673},{},[15860],{"data":15861,"marks":15862,"value":15864,"nodeType":543},{},[15863],{"type":749},"Type",{"data":15866,"content":15867,"nodeType":3470},{},[15868,15878],{"data":15869,"content":15870,"nodeType":3459},{},[15871],{"data":15872,"content":15873,"nodeType":673},{},[15874],{"data":15875,"marks":15876,"value":15877,"nodeType":543},{},[],"hxxps://claude[.]ai/share/8e6401b5-4849-46c4-a3cb-29e1c3c49131",{"data":15879,"content":15880,"nodeType":3459},{},[15881],{"data":15882,"content":15883,"nodeType":673},{},[15884],{"data":15885,"marks":15886,"value":15887,"nodeType":543},{},[],"URL",{"data":15889,"content":15890,"nodeType":3470},{},[15891,15901],{"data":15892,"content":15893,"nodeType":3459},{},[15894],{"data":15895,"content":15896,"nodeType":673},{},[15897],{"data":15898,"marks":15899,"value":15900,"nodeType":543},{},[],"hxxps://chatgpt[.]com/s/cb_6a0f1e6bbec88191aa7fede27163f08d",{"data":15902,"content":15903,"nodeType":3459},{},[15904],{"data":15905,"content":15906,"nodeType":673},{},[15907],{"data":15908,"marks":15909,"value":15887,"nodeType":543},{},[],{"data":15911,"content":15912,"nodeType":3470},{},[15913,15923],{"data":15914,"content":15915,"nodeType":3459},{},[15916],{"data":15917,"content":15918,"nodeType":673},{},[15919],{"data":15920,"marks":15921,"value":15922,"nodeType":543},{},[],"openew[.]app",{"data":15924,"content":15925,"nodeType":3459},{},[15926],{"data":15927,"content":15928,"nodeType":673},{},[15929],{"data":15930,"marks":15931,"value":15932,"nodeType":543},{},[],"Domain",{"data":15934,"content":15935,"nodeType":3470},{},[15936,15946],{"data":15937,"content":15938,"nodeType":3459},{},[15939],{"data":15940,"content":15941,"nodeType":673},{},[15942],{"data":15943,"marks":15944,"value":15945,"nodeType":543},{},[],"de8c50e8ccd240ef9d10ec26c26eeb37a4d1cad7c1e0edf3bb6e5689ec2dde78",{"data":15947,"content":15948,"nodeType":3459},{},[15949],{"data":15950,"content":15951,"nodeType":673},{},[15952],{"data":15953,"marks":15954,"value":15955,"nodeType":543},{},[],"SHA256",{"data":15957,"content":15958,"nodeType":673},{},[15959],{"data":15960,"marks":15961,"value":21,"nodeType":543},{},[],"LLMShare: how attackers are turning AI chatbot pages into malware delivery platforms","How attackers are using shared content features on AI chatbot platforms to deliver malware via pages hosted on legitimate domains, sent via malvertising.","2026-05-29T00:00:00.000Z","llmshare-malvertising-campaign",{"items":15967},[15968,15970],{"sys":15969,"name":2917},{"id":2916},{"sys":15971,"name":2921},{"id":2920},{"items":15973},[15974],{"fullName":15975,"firstName":15976,"jobTitle":15977,"profilePicture":15978},"Keanu Maharaj","Keanu","Senior Security Researcher",{"url":15979},"https://images.ctfassets.net/y1cdw1ablpvd/VCGOm62jiocjwngWTh32U/e9a30637b1c76bf988d2fec90f5b6c36/1689361049351_1.png",{"__typename":1608,"sys":15981,"content":15983,"title":16734,"synopsis":16735,"hashTags":59,"publishedDate":16736,"slug":16737,"tagsCollection":16738,"authorsCollection":16744},{"id":15982},"5RDOpmzJolwT1hk0fNIxzf",{"json":15984},{"data":15985,"content":15986,"nodeType":669},{},[15987,16006,16012,16019,16026,16029,16037,16056,16075,16082,16088,16095,16101,16108,16116,16123,16141,16171,16177,16183,16191,16198,16216,16246,16278,16285,16290,16298,16305,16316,16323,16361,16366,16406,16443,16449,16452,16460,16467,16473,16480,16487,16493,16500,16507,16534,16537,16545,16552,16560,16567,16574,16593,16600,16606,16613,16621,16628,16645,16652,16670,16673,16681,16688,16695,16702,16705,16711,16717],{"data":15988,"content":15989,"nodeType":673},{},[15990,15994,16002],{"data":15991,"marks":15992,"value":15993,"nodeType":543},{},[],"Back in 2024, we wrote about ",{"data":15995,"content":15997,"nodeType":695},{"uri":15996},"https://pushsecurity.com/blog/our-design-philosophy-detecting-what-matters/",[15998],{"data":15999,"marks":16000,"value":16001,"nodeType":543},{},[],"how the Pyramid of Pain shapes Push's detection philosophy",{"data":16003,"marks":16004,"value":16005,"nodeType":543},{},[]," — detections targeting indicators that are easy for attackers to change deliver diminishing returns, while detections targeting attacker techniques impose a cost that's hard to absorb. Two years on, every force that made IoC-based detection fragile has intensified.",{"data":16007,"content":16011,"nodeType":787},{"target":16008},{"sys":16009},{"id":16010,"type":792,"linkType":793},"1iuLYxwI8T1wDUIFSom0G0",[],{"data":16013,"content":16014,"nodeType":673},{},[16015],{"data":16016,"marks":16017,"value":16018,"nodeType":543},{},[],"AI hasn't introduced a new problem so much as it's compressed the timelines on an existing one — attackers can generate infrastructure, iterate on tooling, and industrialize newly discovered techniques faster than before. The bottom layers of the Pyramid are collapsing under the weight of machine-speed operations, and the middle layers are starting to buckle too.",{"data":16020,"content":16021,"nodeType":673},{},[16022],{"data":16023,"marks":16024,"value":16025,"nodeType":543},{},[],"These changes mean that technique-level detection is more important than ever. In this article, we’ll dig into how the Pyramid is changing, and what this means for our detection philosophy at Push (TL;DR — it reinforces the path we’re already on: building detections at the top of the Pyramid by harnessing browser visibility). ",{"data":16027,"content":16028,"nodeType":796},{},[],{"data":16030,"content":16031,"nodeType":800},{},[16032],{"data":16033,"marks":16034,"value":16036,"nodeType":543},{},[16035],{"type":749},"The bottom of the Pyramid was already crumbling",{"data":16038,"content":16039,"nodeType":673},{},[16040,16044,16052],{"data":16041,"marks":16042,"value":16043,"nodeType":543},{},[],"The case against indicator-based detection didn't need AI to be compelling. ",{"data":16045,"content":16047,"nodeType":695},{"uri":16046},"https://www.spamhaus.org/",[16048],{"data":16049,"marks":16050,"value":16051,"nodeType":543},{},[],"89% of phishing domains are active for fewer than two days",{"data":16053,"marks":16054,"value":16055,"nodeType":543},{},[],", with just 6.5% surviving past 15 days — by the time a domain makes it onto a blocklist, the campaign has moved on.",{"data":16057,"content":16058,"nodeType":673},{},[16059,16063,16071],{"data":16060,"marks":16061,"value":16062,"nodeType":543},{},[],"We've ",{"data":16064,"content":16066,"nodeType":695},{"uri":16065},"https://pushsecurity.com/blog/why-most-phishing-attacks-feel-like-a-zero-day/",[16067],{"data":16068,"marks":16069,"value":16070,"nodeType":543},{},[],"written before",{"data":16072,"marks":16073,"value":16074,"nodeType":543},{},[]," about how this makes every phishing attack effectively a zero-day for organizations relying on known-bad detection. The phishing kit's behavior — its page structure, script signatures, malicious payload mechanics — is the only detection target that outlasts a single campaign.",{"data":16076,"content":16077,"nodeType":673},{},[16078],{"data":16079,"marks":16080,"value":16081,"nodeType":543},{},[],"When we blogged about the Pyramid of Pain for modern attacks that happen predominantly over the internet, with minimal (or zero) endpoint contact, it first looked like this: ",{"data":16083,"content":16087,"nodeType":787},{"target":16084},{"sys":16085},{"id":16086,"type":792,"linkType":793},"2N04ycJ6RKGfHdX5X1TwU3",[],{"data":16089,"content":16090,"nodeType":673},{},[16091],{"data":16092,"marks":16093,"value":16094,"nodeType":543},{},[],"Now, it looks more like this:",{"data":16096,"content":16100,"nodeType":787},{"target":16097},{"sys":16098},{"id":16099,"type":792,"linkType":793},"mfhP4WToOQkrHnVkXU0tX",[],{"data":16102,"content":16103,"nodeType":673},{},[16104],{"data":16105,"marks":16106,"value":16107,"nodeType":543},{},[],"Let’s explore why. ",{"data":16109,"content":16110,"nodeType":829},{},[16111],{"data":16112,"marks":16113,"value":16115,"nodeType":543},{},[16114],{"type":749},"AI is accelerating phishing rotation and delivery",{"data":16117,"content":16118,"nodeType":673},{},[16119],{"data":16120,"marks":16121,"value":16122,"nodeType":543},{},[],"Attackers are harnessing AI at every stage, speeding up the process of creating, rotating, and replacing phishing infrastructure at every level, as well as capitalizing on AI adoption itself to enhance their lures. The operational signature is more domains, shorter lifespans, more variation, and fewer of the reuse patterns that blocklists depend on.",{"data":16124,"content":16125,"nodeType":673},{},[16126,16130,16137],{"data":16127,"marks":16128,"value":16129,"nodeType":543},{},[],"Attackers can ",{"data":16131,"content":16132,"nodeType":695},{"uri":15751},[16133],{"data":16134,"marks":16135,"value":16136,"nodeType":543},{},[],"vibe-code entire phishing pages in minutes",{"data":16138,"marks":16139,"value":16140,"nodeType":543},{},[]," — not just cloning legitimate login pages but vibe-cloning them, feeding an AI a screenshot and having it rebuild a convincing frontend with a completely unique backend. ",{"data":16142,"content":16143,"nodeType":673},{},[16144,16148,16156,16160,16167],{"data":16145,"marks":16146,"value":16147,"nodeType":543},{},[],"We've seen attackers clone free SaaS tools like background removers and PDF converters, then inject phishing components or ClickFix payloads into what looks like a functional utility. We’ve even seen attackers distributing malware using AI-generated pages shared using ",{"data":16149,"content":16150,"nodeType":695},{"uri":2749},[16151],{"data":16152,"marks":16153,"value":16155,"nodeType":543},{},[16154],{"type":722},"LLM tool sharing functionality",{"data":16157,"marks":16158,"value":16159,"nodeType":543},{},[],", resulting in phishing delivery pages hosted on real claude.ai and chatgpt.com. And legitimate cloud platforms like ",{"data":16161,"content":16162,"nodeType":695},{"uri":2629},[16163],{"data":16164,"marks":16165,"value":16166,"nodeType":543},{},[],"Railway",{"data":16168,"marks":16169,"value":16170,"nodeType":543},{},[],", Cloudflare Workers, and Vercel host and dynamically rotate attack infrastructure, so the domains feeding into blocklists often belong to reputable services that can't simply be blocked. ",{"data":16172,"content":16176,"nodeType":787},{"target":16173},{"sys":16174},{"id":16175,"type":792,"linkType":793},"5yoLmqysyQazfzLITCUTfc",[],{"data":16178,"content":16182,"nodeType":787},{"target":16179},{"sys":16180},{"id":16181,"type":792,"linkType":793},"5XK5qZMQU19xlA8L2T5y0Z",[],{"data":16184,"content":16185,"nodeType":829},{},[16186],{"data":16187,"marks":16188,"value":16190,"nodeType":543},{},[16189],{"type":749},"The kit ecosystem is fragmenting faster than anyone can track",{"data":16192,"content":16193,"nodeType":673},{},[16194],{"data":16195,"marks":16196,"value":16197,"nodeType":543},{},[],"What we see across our install base is a huge and growing variation in phishing kits — new kits, derivative kits of known platforms, derivatives of those derivatives — appearing on a weekly basis.",{"data":16199,"content":16200,"nodeType":673},{},[16201,16205,16212],{"data":16202,"marks":16203,"value":16204,"nodeType":543},{},[],"As we reported in our ",{"data":16206,"content":16207,"nodeType":695},{"uri":13652},[16208],{"data":16209,"marks":16210,"value":16211,"nodeType":543},{},[],"Browser Attacks Report",{"data":16213,"marks":16214,"value":16215,"nodeType":543},{},[],", the most common AiTM kits we detected over the last year were Tycoon 2FA (59% of detections), followed by Sneaky 2FA, FlowerStorm, Evilginx (nominally a red team tool, but widely abused by attackers), NakedPages, Gabagool, and dozens more — but those established names are just the visible layer.",{"data":16217,"content":16218,"nodeType":673},{},[16219,16223,16231,16235,16242],{"data":16220,"marks":16221,"value":16222,"nodeType":543},{},[],"Code is forked, modified, and redeployed across kits in a pattern that ",{"data":16224,"content":16226,"nodeType":695},{"uri":16225},"https://blog.barracuda.com/2026/04/16/threat-spotlight-tycoon-2fa-scattered-everywhere",[16227],{"data":16228,"marks":16229,"value":16230,"nodeType":543},{},[],"resembles open-source development",{"data":16232,"marks":16233,"value":16234,"nodeType":543},{},[]," more than traditional criminal enterprise, and the rate at which new variants appear is accelerating. The ",{"data":16236,"content":16237,"nodeType":695},{"uri":895},[16238],{"data":16239,"marks":16240,"value":16241,"nodeType":543},{},[],"Venom kit",{"data":16243,"marks":16244,"value":16245,"nodeType":543},{},[]," reuses Sneaky 2FA's AiTM infrastructure but carries different branding and adds device code phishing — whether it's the same developers, stolen code, or a deliberate fork is unclear.",{"data":16247,"content":16248,"nodeType":673},{},[16249,16253,16261,16265,16274],{"data":16250,"marks":16251,"value":16252,"nodeType":543},{},[],"Tycoon 2FA illustrates the scale of the evolution. The kit evolves continuously, addingnew capabilities, new evasion techniques, and hybridizing with other platforms. Even when Sekoia and Microsoft seized 330+ Tycoon domains in March 2026, the techniques it popularized were already embedded across competitors, and the slack was taken up by rival platforms within days. And in any case, Tycoon was back to ",{"data":16254,"content":16256,"nodeType":695},{"uri":16255},"https://www.crowdstrike.com/en-us/blog/tycoon2fa-phishing-as-a-service-platform-persists-following-takedown/",[16257],{"data":16258,"marks":16259,"value":16260,"nodeType":543},{},[],"normal levels of operation",{"data":16262,"marks":16263,"value":16264,"nodeType":543},{},[]," shortly after. It has also been observed ",{"data":16266,"content":16268,"nodeType":695},{"uri":16267},"https://www.okta.com/en-nl/blog/threat-intelligence/tycoon_2fa_phishing_actors_scatter/",[16269],{"data":16270,"marks":16271,"value":16273,"nodeType":543},{},[16272],{"type":722},"pivoting to add new device code phishing capabilities",{"data":16275,"marks":16276,"value":16277,"nodeType":543},{},[]," (more on that below). ",{"data":16279,"content":16280,"nodeType":673},{},[16281],{"data":16282,"marks":16283,"value":16284,"nodeType":543},{},[],"Tear one down and there are many more to take its place — and meanwhile the original is already evolving into something new.",{"data":16286,"content":16289,"nodeType":787},{"target":16287},{"sys":16288},{"id":2123,"type":792,"linkType":793},[],{"data":16291,"content":16292,"nodeType":829},{},[16293],{"data":16294,"marks":16295,"value":16297,"nodeType":543},{},[16296],{"type":749},"New techniques are being industrialized faster than ever",{"data":16299,"content":16300,"nodeType":673},{},[16301],{"data":16302,"marks":16303,"value":16304,"nodeType":543},{},[],"As well as the fragmentation of existing kits, we’re seeing new techniques added at an accelerating rate. ",{"data":16306,"content":16307,"nodeType":673},{},[16308,16312],{"data":16309,"marks":16310,"value":269,"nodeType":543},{},[16311],{"type":749},{"data":16313,"marks":16314,"value":16315,"nodeType":543},{},[]," is the clearest case study. From early nation state adoption in 2024, it took until 2026 for criminal adoption to really take off, but the take-up this year is unprecedented. The EvilTokens kit packaged device code phishing into a PhaaS offering with GPT-powered spear-phishing and adaptive landing pages, hitting 340+ organizations across five countries in March 2026. ",{"data":16317,"content":16318,"nodeType":673},{},[16319],{"data":16320,"marks":16321,"value":16322,"nodeType":543},{},[],"Now, device code functionality is now a core phish kit component. We’re tracking 18+ kits with device code phishing capabilities and a 37.5x increase in device code phishing detections this year alone, with the technique moving from state-sponsored exclusivity to something any PhaaS customer can rent.",{"data":16324,"content":16325,"nodeType":673},{},[16326,16330,16337,16341,16346,16350,16358],{"data":16327,"marks":16328,"value":16329,"nodeType":543},{},[],"Similarly, when we ",{"data":16331,"content":16332,"nodeType":695},{"uri":2592},[16333],{"data":16334,"marks":16335,"value":16336,"nodeType":543},{},[],"infiltrated Doko's Panel",{"data":16338,"marks":16339,"value":16340,"nodeType":543},{},[]," — a ",{"data":16342,"marks":16343,"value":16345,"nodeType":543},{},[16344],{"type":749},"real-time vishing and AiTM platform",{"data":16347,"marks":16348,"value":16349,"nodeType":543},{},[]," used by ShinyHunters and affiliated groups — the codebase was full of LLM-generated artifacts. Multiple groups were using the templated vishing panel and spinning up their own variants, but the AI-generated indicators persisted throughout. This approach to real-time vishing + browser payload has been a ",{"data":16351,"content":16352,"nodeType":695},{"uri":9812},[16353],{"data":16354,"marks":16355,"value":16357,"nodeType":543},{},[16356],{"type":722},"mainstay of the Com affiliates like ShinyHunters this year",{"data":16359,"marks":16360,"value":7506,"nodeType":543},{},[],{"data":16362,"content":16365,"nodeType":787},{"target":16363},{"sys":16364},{"id":2605,"type":792,"linkType":793},[],{"data":16367,"content":16368,"nodeType":673},{},[16369,16373,16377,16381,16390,16394,16402],{"data":16370,"marks":16371,"value":16372,"nodeType":543},{},[],"The broader ",{"data":16374,"marks":16375,"value":13804,"nodeType":543},{},[16376],{"type":749},{"data":16378,"marks":16379,"value":16380,"nodeType":543},{},[]," family shows the same acceleration: First reported in early 2024 and adopted by four nation-state groups within a single quarter. Fast forward and ",{"data":16382,"content":16384,"nodeType":695},{"uri":16383},"https://www.crowdstrike.com/en-us/global-threat-report/",[16385],{"data":16386,"marks":16387,"value":16389,"nodeType":543},{},[16388],{"type":722},"CrowdStrike's data",{"data":16391,"marks":16392,"value":16393,"nodeType":543},{},[]," shows a 563% increase in fake CAPTCHA incidents (one of the more common ClickFix lure types), while ",{"data":16395,"content":16396,"nodeType":695},{"uri":13088},[16397],{"data":16398,"marks":16399,"value":16401,"nodeType":543},{},[16400],{"type":722},"Microsoft reported",{"data":16403,"marks":16404,"value":16405,"nodeType":543},{},[]," it as making up 47% of observed attacks according to their Digital Defense Report.",{"data":16407,"content":16408,"nodeType":673},{},[16409,16413,16417,16421,16428,16432,16439],{"data":16410,"marks":16411,"value":16412,"nodeType":543},{},[],"And ",{"data":16414,"marks":16415,"value":949,"nodeType":543},{},[16416],{"type":749},{"data":16418,"marks":16419,"value":16420,"nodeType":543},{},[]," — a combination of ClickFix and OAuth consent phishing techniques — suggests the next compression is already underway. Push researchers ",{"data":16422,"content":16423,"nodeType":695},{"uri":764},[16424],{"data":16425,"marks":16426,"value":16427,"nodeType":543},{},[],"discovered the technique",{"data":16429,"marks":16430,"value":16431,"nodeType":543},{},[]," in December 2025 — a browser-native ClickFix variant hijacking OAuth consent grants via Azure CLI's localhost redirect. It was later confirmed to be tied to APT29. By January 2026, a ",{"data":16433,"content":16434,"nodeType":695},{"uri":776},[16435],{"data":16436,"marks":16437,"value":16438,"nodeType":543},{},[],"criminal ConsentFix v3 toolkit",{"data":16440,"marks":16441,"value":16442,"nodeType":543},{},[]," had appeared on the XSS forum with Cloudflare Workers, ZoomInfo targeting, and automated exfiltration via Pipedream.",{"data":16444,"content":16448,"nodeType":787},{"target":16445},{"sys":16446},{"id":16447,"type":792,"linkType":793},"41FMif4T0y1maflzonWgL8",[],{"data":16450,"content":16451,"nodeType":796},{},[],{"data":16453,"content":16454,"nodeType":800},{},[16455],{"data":16456,"marks":16457,"value":16459,"nodeType":543},{},[16458],{"type":749},"Why technique-level detection is the only layer that holds",{"data":16461,"content":16462,"nodeType":673},{},[16463],{"data":16464,"marks":16465,"value":16466,"nodeType":543},{},[],"The middle of the Pyramid — tool signatures and artifacts — used to offer much more durable detection than infrastructure indicators. Fingerprinting a specific phishing kit by its JavaScript structure or HTML patterns provided a detection target that survived across dozens or hundreds of campaigns, even as the underlying domains rotated. Tool level detections are still better, but not by quite the same margin.",{"data":16468,"content":16472,"nodeType":787},{"target":16469},{"sys":16470},{"id":16471,"type":792,"linkType":793},"5pxaYdCIFiFKLPhRaPoldX",[],{"data":16474,"content":16475,"nodeType":673},{},[16476],{"data":16477,"marks":16478,"value":16479,"nodeType":543},{},[],"When the kit landscape was dominated by a handful of platforms, you could write signatures for Tycoon, Sneaky2FA, EvilProxy, and so on, and cover the lion's share of attacks. With the ecosystem now producing new variants and entirely new kits on a weekly basis, detecting by kit fingerprint starts to look uncomfortably similar to detecting by domain.",{"data":16481,"content":16482,"nodeType":673},{},[16483],{"data":16484,"marks":16485,"value":16486,"nodeType":543},{},[],"But many of these proliferating kits do share behavioral patterns at a deeper level than their code signatures. For example, every device code phishing kit implements fundamentally the same flow: present a lure, generate a device code via the OAuth Device Authorization endpoint, get the user to enter it on the legitimate authorization page, and poll for the resulting tokens. The frontends vary, the infrastructure varies, but the behavioral pattern doesn't.",{"data":16488,"content":16492,"nodeType":787},{"target":16489},{"sys":16490},{"id":16491,"type":792,"linkType":793},"FyyHayQtsJTwoB1kluMOl",[],{"data":16494,"content":16495,"nodeType":673},{},[16496],{"data":16497,"marks":16498,"value":16499,"nodeType":543},{},[],"Genuinely new attack techniques still require human creativity — an attacker has to identify a gap in how a legitimate protocol or feature can be subverted. That kind of innovation hasn't been automated. But the window to discover a technique, build a detection, and then deploy it before it is adopted by criminals at scale is compressing with each generation.",{"data":16501,"content":16502,"nodeType":673},{},[16503],{"data":16504,"marks":16505,"value":16506,"nodeType":543},{},[],"Organizations that detect at the technique level and deploy before commoditization have a structural advantage that increases over time. Waiting for indicators — even tool-level indicators — means chasing a curve that's accelerating away from you. This is the challenge we grapple with every day as we strive for the most resilient detections possible. ",{"data":16508,"content":16509,"nodeType":6861},{},[16510],{"data":16511,"content":16512,"nodeType":673},{},[16513,16517,16525,16529],{"data":16514,"marks":16515,"value":16516,"nodeType":543},{},[],"As our CPO Jacques Louw put it on ",{"data":16518,"content":16520,"nodeType":695},{"uri":16519},"https://risky.biz/RBNEWSSI128/",[16521],{"data":16522,"marks":16523,"value":16524,"nodeType":543},{},[],"Risky Business",{"data":16526,"marks":16527,"value":16528,"nodeType":543},{},[],": ",{"data":16530,"marks":16531,"value":16533,"nodeType":543},{},[16532],{"type":739},"\"There's no list of bad domains anywhere in the product. It's a crutch — a false cheat code that stops you from doing the detection in the way that actually is resilient, because the next time you see it, it will be on a different domain.\"",{"data":16535,"content":16536,"nodeType":796},{},[],{"data":16538,"content":16539,"nodeType":800},{},[16540],{"data":16541,"marks":16542,"value":16544,"nodeType":543},{},[16543],{"type":749},"What it takes to detect at the top of the Pyramid",{"data":16546,"content":16547,"nodeType":673},{},[16548],{"data":16549,"marks":16550,"value":16551,"nodeType":543},{},[],"If technique-level detection is the only layer that holds, two things have to be true about your detection capability: You need the right vantage point, and you need the research velocity to stay ahead.",{"data":16553,"content":16554,"nodeType":829},{},[16555],{"data":16556,"marks":16557,"value":16559,"nodeType":543},{},[16558],{"type":749},"You need the right vantage point",{"data":16561,"content":16562,"nodeType":673},{},[16563],{"data":16564,"marks":16565,"value":16566,"nodeType":543},{},[],"Technique-level behaviors in browser-based identity attacks — how a phishing page orchestrates credential entry, how a device code flow presents its authorization prompt, how a ClickFix variant manipulates the clipboard — are visible in the browser session and nowhere else.",{"data":16568,"content":16569,"nodeType":673},{},[16570],{"data":16571,"marks":16572,"value":16573,"nodeType":543},{},[],"Network proxies see encrypted traffic and can attempt to reconstruct page behavior from metadata, but DOM manipulation, user interaction sequences, and script execution aren't visible from that vantage point. Email gateways see the delivery mechanism (or nothing at all in the increasing number of social media and search engine based attacks) but not the payload.",{"data":16575,"content":16576,"nodeType":673},{},[16577,16581,16589],{"data":16578,"marks":16579,"value":16580,"nodeType":543},{},[],"As we disclosed in our ",{"data":16582,"content":16583,"nodeType":695},{"uri":13652},[16584],{"data":16585,"marks":16586,"value":16588,"nodeType":543},{},[16587],{"type":722},"browser attacks report",{"data":16590,"marks":16591,"value":16592,"nodeType":543},{},[],", 95% of in-browser attacks we detect use some form of bot protection, often combined with conditional loading techniques like referrer and browser checks, reliably defeating automated analysis techniques. ",{"data":16594,"content":16595,"nodeType":673},{},[16596],{"data":16597,"marks":16598,"value":16599,"nodeType":543},{},[],"Behavioral detection at the technique level requires observing what happens on the page at the moment the user interacts with it — analyzing pages, not links. When you see the entire browsing flow — ad click, redirect chain, page render, credential prompt — an attack stands out immediately. Without that context, any detection system is forced to fill in gaps, and the gaps are where attacks hide.",{"data":16601,"content":16605,"nodeType":787},{"target":16602},{"sys":16603},{"id":16604,"type":792,"linkType":793},"4804g6u4POUDpL42bzP0EY",[],{"data":16607,"content":16608,"nodeType":673},{},[16609],{"data":16610,"marks":16611,"value":16612,"nodeType":543},{},[],"Push sits inside the browser session, observing this in real time. Its detections target the behavioral mechanics of techniques rather than the surface characteristics of individual kits or infrastructure.",{"data":16614,"content":16615,"nodeType":829},{},[16616],{"data":16617,"marks":16618,"value":16620,"nodeType":543},{},[16619],{"type":749},"You need the research expertise",{"data":16622,"content":16623,"nodeType":673},{},[16624],{"data":16625,"marks":16626,"value":16627,"nodeType":543},{},[],"When the window between technique discovery and industrialized exploitation is measured in weeks rather than years, the detection pipeline needs to operate on that same compressed timescale.",{"data":16629,"content":16630,"nodeType":673},{},[16631,16635,16641],{"data":16632,"marks":16633,"value":16634,"nodeType":543},{},[],"This is where our ",{"data":16636,"content":16637,"nodeType":695},{"uri":15751},[16638],{"data":16639,"marks":16640,"value":15756,"nodeType":543},{},[],{"data":16642,"marks":16643,"value":16644,"nodeType":543},{},[]," fits. It's tripled our monthly detection output — not by generating bigger blocklists, but by scaling the process of discovering behavioral patterns across the telemetry generated by 3+ million browser deployments.",{"data":16646,"content":16647,"nodeType":673},{},[16648],{"data":16649,"marks":16650,"value":16651,"nodeType":543},{},[],"The detections it produces are technique-class by design, targeting how attacks work rather than the infrastructure or specific tool that implements them. The goal is curation, not accumulation — hundreds of high-fidelity behavioral detections rather than the billions of signatures and domain entries that traditional approaches require.",{"data":16653,"content":16654,"nodeType":673},{},[16655,16659,16666],{"data":16656,"marks":16657,"value":16658,"nodeType":543},{},[],"When we detected the first in-the-wild ",{"data":16660,"content":16661,"nodeType":695},{"uri":13141},[16662],{"data":16663,"marks":16664,"value":16665,"nodeType":543},{},[],"InstallFix attack",{"data":16667,"marks":16668,"value":16669,"nodeType":543},{},[]," through the pipeline — a user had searched for NotebookLM, clicked a paid Google ad, and was redirected to a fake page with a WebAssembly C2 connector — the detection shipped to all customers within minutes. It didn't depend on knowing the domain, the ad creative, or the specific kit. It depended on recognizing the technique itself.",{"data":16671,"content":16672,"nodeType":796},{},[],{"data":16674,"content":16675,"nodeType":800},{},[16676],{"data":16677,"marks":16678,"value":16680,"nodeType":543},{},[16679],{"type":749},"Technique-level detection is now the only option",{"data":16682,"content":16683,"nodeType":673},{},[16684],{"data":16685,"marks":16686,"value":16687,"nodeType":543},{},[],"As a framework for detection durability, the Pyramid of Pain is more relevant than ever. ",{"data":16689,"content":16690,"nodeType":673},{},[16691],{"data":16692,"marks":16693,"value":16694,"nodeType":543},{},[],"AI has made infrastructure indicators essentially disposable. The tools tier is compressing as criminal vendors vibe-code, fork, and clone tooling at machine speed. Technique-level detection is the layer that holds long-term to be able to proactively detect and block net-new attacks and the kits that power them. ",{"data":16696,"content":16697,"nodeType":673},{},[16698],{"data":16699,"marks":16700,"value":16701,"nodeType":543},{},[],"Novel attack techniques still require human creativity to discover, and detections built around how those techniques work can survive infrastructure rotation, tool proliferation, and kit fragmentation. Defending that layer requires a vantage point inside the browser session and a research pipeline fast enough to stay ahead of the accelerating path from discovery to industrialization.",{"data":16703,"content":16704,"nodeType":796},{},[],{"data":16706,"content":16707,"nodeType":673},{},[16708],{"data":16709,"marks":16710,"value":2882,"nodeType":543},{},[],{"data":16712,"content":16713,"nodeType":673},{},[16714],{"data":16715,"marks":16716,"value":2889,"nodeType":543},{},[],{"data":16718,"content":16719,"nodeType":673},{},[16720,16723,16731],{"data":16721,"marks":16722,"value":21,"nodeType":543},{},[],{"data":16724,"content":16725,"nodeType":695},{"uri":5926},[16726],{"data":16727,"marks":16728,"value":16730,"nodeType":543},{},[16729],{"type":722},"Book a live demo",{"data":16732,"marks":16733,"value":8457,"nodeType":543},{},[],"The Pyramid of Pain in the AI era: Why technique-level detection matters more than ever","AI is accelerating the collapse of indicator-based threat detection. Here's why you need technique-level detection to stay ahead.","2026-06-01T00:00:00.000Z","the-pyramid-of-pain-in-the-ai-era",{"items":16739},[16740,16742],{"sys":16741,"name":2921},{"id":2920},{"sys":16743,"name":2917},{"id":2916},{"items":16745},[16746],{"fullName":2925,"firstName":2926,"jobTitle":2927,"profilePicture":16747},{"url":2929},"blog/from-iocs-to-ttps-an-agentic-threat-hunting-case-study",{"json":16750},{"data":16751,"content":16752,"nodeType":669},{},[16753],{"data":16754,"content":16755,"nodeType":673},{},[16756],{"data":16757,"marks":16758,"value":16759,"nodeType":543},{},[],"Here’s how Push’s agentic detection pipeline turns intel into huntable characteristics of attacker behavior, deriving durable detections from a range of sources. In this case study, we’ll look at how we were able to raise an alert the first time a novel OAuth redirect abuse technique was observed in customer environments.",{"id":12435,"publishedAt":16761},"2026-08-26T11:58:15.300Z",{"items":16763},[16764,16766],{"sys":16765,"name":2917},{"id":2916},{"sys":16767,"name":2921},{"id":2920},{"items":16769},[16770,16772,16777,16782,16784,16789,16791,16793],{"sys":16771,"name":10681,"slug":10682,"tier":45},{"id":10680},{"sys":16773,"name":16775,"slug":16776,"tier":45},{"id":16774},"topic-siem","SIEM","siem",{"sys":16778,"name":16780,"slug":16781,"tier":45},{"id":16779},"topic-edr","EDR","edr",{"sys":16783,"name":10652,"slug":10653,"tier":45},{"id":10651},{"sys":16785,"name":16787,"slug":16788,"tier":45},{"id":16786},"topic-enterprise-browser","Enterprise browser","enterprise-browser",{"sys":16790,"name":6589,"slug":6590,"tier":31},{"id":6588},{"sys":16792,"name":8471,"slug":10696,"tier":31},{"id":10695},{"sys":16794,"name":2921,"slug":16796,"tier":31},{"id":16795},"topic-detection-and-response","detection-and-response","bqRrjJoZ9alBHiGqx5wgBq-hDr1fk3FfxBhejsCjwv0",{"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F257f2ac90b6a4503bee4181cbd959a5f?format=webp&width=1000&quality=85":16799,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fc06aec22e0754904a3ecd9473983fe63?format=webp&width=1000&quality=85":16802,"https://cdn.builder.io/api/v1/image/assets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fe276e444dbf64f5e9258627989aeedb4?format=webp&width=1000&quality=85":16804},{"width":16800,"height":16801},1000,603,{"width":16800,"height":16803},750,{"width":16800,"height":16805},383,1787843959032]