[{"data":1,"prerenderedAt":4337},["ShallowReactive",2],{"application-flags":3,"navbar":7,"always-visible-banner":36,"navbar-about-highlight":108,"navbar-resource-highlight":182,"trust-badges":226,"solution-nav":247,"fa-icon-sharp-regular-faFishingRod":387,"fa-icon-solid-faUserSecret":391,"fa-icon-sharp-regular-faLaptopCode":393,"fa-icon-solid-faTabletScreenButton":395,"fa-icon-solid-faThumbsUp":397,"fa-icon-solid-faPlugCircleXmark":399,"fa-icon-sharp-regular-faPuzzlePiece":401,"fa-icon-solid-faFileCircleXmark":403,"fa-icon-solid-faGhost":406,"fa-icon-solid-faQrcode":409,"fa-icon-solid-faCookieBite":411,"fa-icon-sharp-regular-faUserSecret":413,"fa-icon-sharp-regular-faRadar":415,"fa-icon-sharp-regular-faSatelliteDish":417,"fa-icon-sharp-regular-faShieldCheck":419,"fa-icon-sharp-regular-faBrainCircuit":421,"fa-icon-solid-faMobileScreenButton":423,"fa-icon-brands-faChrome":425,"fa-icon-solid-faDisplay":427,"fa-icon-solid-faFilter":429,"fa-icon-solid-faCloudArrowUp":431,"blog\u002Fbrowser-threat-landscape-mid-year-update-2026":433,"blog-topics":3987},[4],{"name":5,"enabled":6},"maintenanceMode",false,[8],{"createdDate":9,"id":10,"name":11,"modelId":12,"published":13,"meta":14,"query":22,"data":23,"variations":28,"lastUpdated":29,"firstPublished":30,"testRatio":31,"createdBy":32,"lastUpdatedBy":33,"folders":34,"rev":35},1742208588866,"1c7a4e423bf54ac1a328bb4063459ef2","Banner","1c6207a5f24948ab82d4a0b17f251193","published",{"breakpoints":15,"hasAutosaves":19,"kind":20,"lastPreviewUrl":21},{"medium":16,"small":17,"xsmall":18},768,640,320,true,"data","",[],{"link":24,"text":25,"type":26,"url":27},{},"Get our latest report analyzing browser attack techniques in 2026","web-banner","https:\u002F\u002Fpushsecurity.com\u002Fresources\u002Fbrowser-attacks-report",{},1774258294825,1742208637545,1,"CydmZnOWU1XuAaLhEDCoYNM4Z8W2","jKjF9r5jcvXU8tzZEfFQm31Iyvr2",[],"brvjc1sslx8",{"createdBy":37,"createdDate":38,"data":39,"folders":94,"id":95,"lastUpdated":96,"lastUpdatedBy":97,"meta":98,"modelId":102,"name":103,"published":13,"query":104,"testRatio":31,"variations":105,"firstPublished":106,"stageModifiedSincePublish":6,"rev":107},"ST0tXQM8slWpFrmioqKHmENB2qe2",1774965361051,{"ctaText":40,"text":41,"url":21,"blocks":42,"state":90},"ewrererw","testrfesssssssssss",[43,70,78],{"@type":44,"@version":45,"id":46,"component":47,"responsiveStyles":60},"@builder.io\u002Fsdk:Element",2,"builder-ca12c06a52de41d7b8743da53118cd38",{"name":48,"tag":48,"options":49,"isRSC":59},"TopBannerContent",{"text":50,"ctaText":51,"url":52,"mainText":53,"cta":56},"New Webinar Series: Join John Hammond, Troy Hunt, and Matt Johansen for the State of Browser Attacks","Save Your Spot","https:\u002F\u002Fpushsecurity.com\u002Fwebinar\u002Fstate-of-browser-security",{"content":54,"fontSize":55},"\u003Cp class=\"\">Employees using shadow AI tools? Push blocks them in the browser and enforces your AI policy.\u003C\u002Fp>","text-base",{"content":57,"fontSize":55,"url":58},"\u003Cp class=\"\">Get a free trial →\u003C\u002Fp>","https:\u002F\u002Fpushsecurity.com\u002Flp\u002Fshadow-ai-trial",null,{"large":61},{"display":62,"flexDirection":63,"position":64,"flexShrink":65,"boxSizing":66,"marginTop":67,"marginBottom":67,"fontSize":68,"fontWeight":69},"flex","column","relative","0","border-box",".56rem","1.125rem","700",{"@type":44,"@version":45,"id":71,"component":72,"responsiveStyles":76},"builder-a2e1f4b9f30b464bb814d7f5de5b0aa7",{"name":73,"options":74,"isRSC":59},"Custom Code",{"code":75,"scriptsClientOnly":6},"\u003Cstyle>\n  .top-banner.bg-web-orange{background:rgb(114, 79, 255);}\n\u003C\u002Fstyle>\n",{"large":77},{"display":62,"flexDirection":63,"position":64,"flexShrink":65,"boxSizing":66},{"id":79,"@type":44,"tagName":80,"properties":81,"responsiveStyles":85},"builder-pixel-65og51xnky7","img",{"src":82,"aria-hidden":83,"alt":21,"role":84,"width":65,"height":65},"https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fpixel?apiKey=f3a1111ff5be48cdbb123cd9f5795a05","true","presentation",{"large":86},{"height":65,"width":65,"display":87,"opacity":65,"overflow":88,"pointerEvents":89},"block","hidden","none",{"deviceSize":91,"location":92},"large",{"path":21,"query":93},{},[],"fd266d0172cc47429be7ad10f48c99ad",1787595768418,"tFqFyIzyczYOCRogcShKk6KBmEB2",{"breakpoints":99,"hasAutosaves":19,"hasErrors":6,"hasLinks":6,"kind":100,"lastPreviewUrl":101},{"medium":16,"small":17,"xsmall":18},"component","https:\u002F\u002Fpushsecurity.com\u002F?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CcreateProjects%2CsendPullRequests%2CfusionHostingPublish&builder.user.role.name=Designer&builder.user.role.id=creator&builder.cachebust=true&builder.preview=always-visible-banner&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.always-visible-banner=fd266d0172cc47429be7ad10f48c99ad&builder.overrides.fd266d0172cc47429be7ad10f48c99ad=fd266d0172cc47429be7ad10f48c99ad&builder.options.locale=Default","0678d178ec8b41efb8a23c09dba7874d","always visible banner",[],{},1774968080803,"y4fj9dbjb7k",[109,145],{"createdBy":32,"createdDate":110,"data":111,"folders":134,"id":135,"lastUpdated":136,"lastUpdatedBy":32,"meta":137,"modelId":139,"name":140,"published":13,"query":141,"stageModifiedSincePublish":6,"testRatio":31,"variations":142,"firstPublished":143,"rev":144},1776247359804,{"link":112,"testimonial":113,"testimonialLink":133,"type":116},{},{"@type":114,"id":115,"model":116,"value":117},"@builder.io\u002Fcore:Reference","f028f2b685bb47cd8bf9e82a26dd5a79","testimonial",{"query":118,"folders":119,"createdDate":120,"id":115,"name":121,"modelId":122,"published":13,"data":123,"variations":127,"lastUpdated":128,"firstPublished":129,"testRatio":31,"createdBy":37,"lastUpdatedBy":37,"meta":130,"rev":132},[],[],1735823466309,"We found Push to be more accurate when compared to competitors and the browser agent offered features that others couldn’t match.","42035571a56940ac98bff4544aa79aa5",{"author":124,"jobTitle":125,"quote":121,"image":126},"Jason Waits","\u003Cp>CISO at Inductive Automation\u003C\u002Fp>","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Ff04c0c0689ce4a89ac0f0708d78c0a07",{},1735910703862,1735823501152,{"kind":20,"lastPreviewUrl":21,"breakpoints":131,"hasAutosaves":19},{"small":17,"medium":16},"8lr4aug0kgg","\u002Fcustomer-stories\u002Finductive-automation",[],"9136a8f18b3b4a6ba29b8653a99372b1",1776247404986,{"breakpoints":138,"hasAutosaves":6,"kind":20,"lastPreviewUrl":21},{"medium":16,"small":17,"xsmall":18},"20d9eaa352304613b3d1a794b400703d","testimonial-inductive-automation",[],{},1776247404973,"tmziibs9ga9",{"createdBy":32,"createdDate":146,"data":147,"folders":174,"id":175,"lastUpdated":176,"lastUpdatedBy":32,"meta":177,"modelId":139,"name":172,"published":13,"query":179,"stageModifiedSincePublish":6,"testRatio":31,"variations":180,"firstPublished":181,"rev":144},1776255761419,{"description":148,"image":149,"link":150,"testimonial":153,"title":172,"type":173},"Learn about the latest techniques being used in the wild.","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F7b4a5ebf81d64e8c9d7fc35f6c96c4a9",{"text":151,"url":152},"Download now","\u002Fresources\u002Fbrowser-attacks-report",{"@type":114,"id":154,"model":116,"value":155},"192acbb1f9ca4cac918c0ec435a8bae3",{"query":156,"folders":157,"createdDate":158,"id":154,"name":159,"modelId":122,"published":13,"data":160,"variations":166,"lastUpdated":167,"firstPublished":168,"testRatio":31,"createdBy":37,"lastUpdatedBy":32,"meta":169,"rev":171},[],[],1728981467463,"Push does for identity what CrowdStrike did for the endpoint",{"video":161,"jobTitle":162,"author":163,"qoute":21,"quote":164,"image":165},"https:\u002F\u002Fcdn.builder.io\u002Fo\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F8b30e8ca50064058bbaef0f3c6164575%2Fcompressed?apiKey=f3a1111ff5be48cdbb123cd9f5795a05&token=8b30e8ca50064058bbaef0f3c6164575&alt=media&optimized=true","\u003Cp>Deputy CISO at Microsoft\u003C\u002Fp>\u003Cp>Former LinkedIn, Slack, Palantir\u003C\u002Fp>","Geoff Belknap","Push does for identity what CrowdStrike did for the endpoint.","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F748f0ad0a5064a00a13f4721fcc8dea1",{},1742902158597,1728981782923,{"kind":20,"lastPreviewUrl":21,"breakpoints":170,"hasAutosaves":19},{"small":17,"medium":16},"w423t83vzcq","Report: 2026 Browser Attack Techniques","resource",[],"05a9322735fc427db12e2740e4302300",1776255810913,{"breakpoints":178,"hasAutosaves":6,"kind":20,"lastPreviewUrl":21},{"medium":16,"small":17,"xsmall":18},[],{},1776255810900,[183,205],{"createdBy":32,"createdDate":184,"data":185,"folders":195,"id":196,"lastUpdated":197,"lastUpdatedBy":32,"meta":198,"modelId":200,"name":172,"published":13,"query":201,"stageModifiedSincePublish":6,"testRatio":31,"variations":202,"firstPublished":203,"rev":204},1776256900280,{"description":148,"image":149,"link":186,"testimonial":187,"title":172,"type":173},{"text":151,"url":152},{"@type":114,"id":154,"model":116,"value":188},{"query":189,"folders":190,"createdDate":158,"id":154,"name":159,"modelId":122,"published":13,"data":191,"variations":192,"lastUpdated":167,"firstPublished":168,"testRatio":31,"createdBy":37,"lastUpdatedBy":32,"meta":193,"rev":171},[],[],{"video":161,"jobTitle":162,"author":163,"qoute":21,"quote":164,"image":165},{},{"kind":20,"lastPreviewUrl":21,"breakpoints":194,"hasAutosaves":19},{"small":17,"medium":16},[],"1f429607996e4e5fae8fe3f9b9610e55",1776256937553,{"breakpoints":199,"hasAutosaves":6,"kind":20,"lastPreviewUrl":21},{"medium":16,"small":17,"xsmall":18},"4829faa81e7c4ee8bd2d000e160e8d3c",[],{},1776256937540,"h00i46zz8yj",{"createdBy":32,"createdDate":206,"data":207,"folders":217,"id":218,"lastUpdated":219,"lastUpdatedBy":32,"meta":220,"modelId":200,"name":222,"published":13,"query":223,"stageModifiedSincePublish":6,"testRatio":31,"variations":224,"firstPublished":225,"rev":204},1776256949234,{"link":208,"testimonial":209,"testimonialLink":133,"type":116},{},{"@type":114,"id":115,"model":116,"value":210},{"query":211,"folders":212,"createdDate":120,"id":115,"name":121,"modelId":122,"published":13,"data":213,"variations":214,"lastUpdated":128,"firstPublished":129,"testRatio":31,"createdBy":37,"lastUpdatedBy":37,"meta":215,"rev":132},[],[],{"author":124,"jobTitle":125,"quote":121,"image":126},{},{"kind":20,"lastPreviewUrl":21,"breakpoints":216,"hasAutosaves":19},{"small":17,"medium":16},[],"ce043785b71b4ece98eac811ecf4ba10",1776256974140,{"breakpoints":221,"hasAutosaves":6,"kind":20,"lastPreviewUrl":21},{"medium":16,"small":17,"xsmall":18},"inductive-automation",[],{},1776256974130,[227,231,235,239,243],{"title":228,"logo":229,"createdDate":230},"SOC2","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fb6727a5e00004d6e9e69fc3068b8b64c",1784291539953,{"title":232,"logo":233,"createdDate":234},"GDPR","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Ffe49f53211674deaa5a6640d929cdf42?format=webp",1784291672535,{"title":236,"logo":237,"createdDate":238},"Cyber essentials","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F53558c1045a342a7a28def960cd54ae7?format=webp",1784291702710,{"title":240,"logo":241,"createdDate":242},"ISO IEC 27001","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F578a404a61cf45db951a41fe3554d12d",1784291766222,{"title":244,"logo":245,"createdDate":246},"ISO IEC 27701","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fbe219844b13242fbba531959579a753c",1784291858848,[248,317,362],{"id":249,"label":250,"text":21,"navIcon":251,"items":252},"stop-browser-based-attacks","Stop browser-based attacks","solid:faShieldHalved",[253,258,263,268,273,278,283,288,293,297,302,307,312],{"title":254,"text":255,"url":256,"navIcon":257},"Phishing","Detect phishing behaviorally in the browser, regardless of the payload or delivery channel.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fzero-day-phishing","sharp-regular:faFishingRod",{"title":259,"text":260,"url":261,"navIcon":262},"Adversary-in-the-Middle","Detect and block MFA-bypassing AiTM phishing pages in real-time.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fadversary-in-the-middle-attacks","solid:faUserSecret",{"title":264,"text":265,"url":266,"navIcon":267},"ClickFix (and variants)","Intercept malicious copy and paste attacks at the point of interaction.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fclickfix-fix-variants","sharp-regular:faLaptopCode",{"title":269,"text":270,"url":271,"navIcon":272},"Device code phishing","Detect and block device code phishing kits designed to get around passkeys.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fdevice-code-phishing","solid:faTabletScreenButton",{"title":274,"text":275,"url":276,"navIcon":277},"Consent phishing","Detect and block malicious OAuth consent grants before access is authorized.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fconsent-phishing","solid:faThumbsUp",{"title":279,"text":280,"url":281,"navIcon":282},"Malicious OAuth integrations","Detect and block the root cause of SaaS supply chain attacks.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fmalicious-oauth-integrations","solid:faPlugCircleXmark",{"title":284,"text":285,"url":286,"navIcon":287},"Malicious browser extensions","Inventory, monitor, and block risky browser extensions.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fmalicious-browser-extensions","sharp-regular:faPuzzlePiece",{"title":289,"text":290,"url":291,"navIcon":292},"Malicious file downloads","Control which files users can download by type, source, and user group.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fmalicious-file-downloads","solid:faFileCircleXmark",{"title":294,"text":295,"url":296,"navIcon":292},"Infostealers","Detect infostealer delivery and respond to a compromise.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Finfostealer-malware",{"title":298,"text":299,"url":300,"navIcon":301},"Ghost logins","Surface hidden login paths that bypass SSO and expose accounts.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fghost-logins","solid:faGhost",{"title":303,"text":304,"url":305,"navIcon":306},"Mobile phishing (QR & SMS)","Detect phishing regardless of whether it arrives via email, SMS, or QR code.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fmobile-phishing-qr-code-sms","solid:faQrcode",{"title":308,"text":309,"url":310,"navIcon":311},"Credential stuffing","Identify reused and compromised credentials across SaaS logins.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fcredential-stuffing","custom:credentialStuffing",{"title":313,"text":314,"url":315,"navIcon":316},"Session hijacking","Detect and respond to stolen session token replay with browser session markers.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fsession-hijacking","solid:faCookieBite",{"id":318,"label":319,"text":21,"navIcon":320,"items":321},"achieve-security-outcomes","Achieve security outcomes","solid:faCheckToSlot",[322,327,332,337,342,347,352,357],{"title":323,"text":324,"url":325,"navIcon":326},"Stop account takeover","Stop ATO with stolen credential and compromised token detection.","\u002Fsolution\u002Fachieve-security-outcomes\u002Fstop-account-takeover","sharp-regular:faUserSecret",{"title":328,"text":329,"url":330,"navIcon":331},"Harden unmanaged identities","Harden access paths with visibility, detection, and guardrails.","\u002Fsolution\u002Fachieve-security-outcomes\u002Fharden-unmanaged-identities","sharp-regular:faRadar",{"title":333,"text":334,"url":335,"navIcon":336},"Investigate browser-related incidents","Investigate and respond faster with unique browser telemetry.","\u002Fsolution\u002Fachieve-security-outcomes\u002Finvestigate-browser-related-incidents","sharp-regular:faSatelliteDish",{"title":338,"text":339,"url":340,"navIcon":341},"Secure shadow SaaS","See and control shadow SaaS in the browser.","\u002Fsolution\u002Fachieve-security-outcomes\u002Fsecure-shadow-saas","sharp-regular:faShieldCheck",{"title":343,"text":344,"url":345,"navIcon":346},"Secure AI","See and control AI apps in the browser.","\u002Fsolution\u002Fachieve-security-outcomes\u002Fsecure-ai","sharp-regular:faBrainCircuit",{"title":348,"text":349,"url":350,"navIcon":351},"Secure BYOD","Extend consistent browser-based protection to unmanaged devices.","\u002Fsolution\u002Fachieve-security-outcomes\u002Fsecure-bring-your-own-device","solid:faMobileScreenButton",{"title":353,"text":354,"url":355,"navIcon":356},"Secure Chromebooks","Secure browser activity on Chromebooks without endpoint agents.","\u002Fsolution\u002Fachieve-security-outcomes\u002Fsecure-chromebooks","brands:faChrome",{"title":358,"text":359,"url":360,"navIcon":361},"Investigate and stop data loss","Detect and prevent data loss across AI tools, apps, and sessions.","\u002Fsolution\u002Fachieve-security-outcomes\u002Finvestigate-and-stop-data-loss","custom:investigateAndStopDataLoss",{"id":363,"label":364,"text":21,"navIcon":365,"items":366},"tool-replacements","Tool replacements","solid:faScrewdriverWrench",[367,372,377,382],{"title":368,"text":369,"url":370,"navIcon":371},"Remote browser isolation","Detect attacks that look like normal browsing.","\u002Fsolution\u002Ftool-replacements\u002Fremote-browser-isolation","solid:faDisplay",{"title":373,"text":374,"url":375,"navIcon":376},"Secure web gateways","Detect attacks inside the browser after SWGs allowed the connection.","\u002Fsolution\u002Ftool-replacements\u002Fsecure-web-gateways","solid:faFilter",{"title":378,"text":379,"url":380,"navIcon":381},"Cloud access security broker","Catch browser-based identity threats in real time, not after the fact.","\u002Fsolution\u002Ftool-replacements\u002Fcloud-access-security-broker","solid:faCloudArrowUp",{"title":383,"text":384,"url":385,"navIcon":386},"Security awareness training","Block real phishing instead of training users on simulations.","\u002Fsolution\u002Ftool-replacements\u002Fsecurity-awareness-training","custom:securityAwareness",{"w":388,"h":389,"d":390},448,512,"M284.6 0l91.4 0 0 160-48 0 0-112-36.6 0-203.4 58.1 0 181.9 40 0 0 224-128 0 0-224 40 0 0-218.1 17.4-5 224-64 3.2-.9zM80 336l-32 0 0 128 32 0 0-128zm176 8c0-76.8 64-136 96-152 32 16 96 75.2 96 152 0 32-16 80-64 112l32 40 0 16-128 0 0-16 32-40c-48-32-64-80-64-112zm128-32a24 24 0 1 0 -48 0 24 24 0 1 0 48 0z",{"w":388,"h":389,"d":392},"M171-16c-36.4 0-57.8 58.3-68.3 112L72 96c-13.3 0-24 10.7-24 24s10.7 24 24 24l24 0 0 32c0 17 3.3 33.2 9.3 48l-9.3 0 0 0-20.5 0c-15.2 0-27.5 12.3-27.5 27.5 0 3 .5 5.9 1.4 8.7l28.9 86.6C40.2 379.6 16 428.1 16 482.3 16 498.7 29.3 512 45.7 512l356.6 0c16.4 0 29.7-13.3 29.7-29.7 0-54.2-24.2-102.7-62.3-135.4l28.9-86.6c.9-2.8 1.4-5.7 1.4-8.7 0-15.2-12.3-27.5-27.5-27.5l-20.5 0 0 0-9.3 0c6-14.8 9.3-31 9.3-48l0-32 24 0c13.3 0 24-10.7 24-24s-10.7-24-24-24l-30.7 0c-10.4-53.7-31.9-112-68.3-112-9.6 0-19 3.9-27.5 8.2-8.2 4.1-18.4 7.8-25.5 7.8s-17.3-3.7-25.5-7.8C190-12.1 180.6-16 171-16zm93.7 484.4l-24.8-70.9 27.9-32.5c2.7-3.2 4.2-7.2 4.2-11.4 0-9.7-7.8-17.5-17.5-17.5l-61 0c-9.7 0-17.5 7.8-17.5 17.5 0 4.2 1.5 8.2 4.2 11.4l27.9 32.5-24.8 70.9-57-180.4 35.7 0c18.4 10.2 39.5 16 62 16s43.6-5.8 62-16l35.7 0-57 180.4zM224 256c-34.7 0-64.2-22.1-75.3-53 5.7 3.2 12.3 5 19.3 5l12.4 0c16.5 0 31.1-10.6 36.3-26.2 2.3-7 12.2-7 14.5 0 5.2 15.6 19.9 26.2 36.3 26.2l12.4 0c7 0 13.6-1.8 19.3-5-11.1 30.9-40.6 53-75.3 53z",{"w":17,"h":389,"d":394},"M112 80l416 0 0 224 48 0 0-272-512 0 0 272 48 0 0-224zM48 404.1l0-4.1 544 0 0 4.1-27.9 27.9-488.2 0-27.9-27.9zM592 352l-592 0 0 72 56 56 528 0 56-56 0-72-48 0zM281 169l17-17-33.9-33.9c-6.1 6.1-27.8 27.8-65 65l-17 17c6.1 6.1 27.8 27.8 65 65l17 17 33.9-33.9c-9-9-25-25-48-48l31-31zM393 135l-17-17-33.9 33.9c9 9 25 25 48 48-23 23-39 39-48 48L376 281.9c6.1-6.1 27.8-27.8 65-65l17-17c-6.1-6.1-27.8-27.8-65-65z",{"w":388,"h":389,"d":396},"M0 64C0 28.7 28.7 0 64 0L384 0c35.3 0 64 28.7 64 64l0 384c0 35.3-28.7 64-64 64L64 512c-35.3 0-64-28.7-64-64L0 64zM256 432a32 32 0 1 0 -64 0 32 32 0 1 0 64 0zM384 64l-320 0 0 288 320 0 0-288z",{"w":389,"h":389,"d":398},"M80 160c17.7 0 32 14.3 32 32l0 256c0 17.7-14.3 32-32 32l-48 0c-17.7 0-32-14.3-32-32L0 192c0-17.7 14.3-32 32-32l48 0zM270.6 16C297.9 16 320 38.1 320 65.4l0 4.2c0 6.8-1.3 13.6-3.8 19.9L288 160 448 160c26.5 0 48 21.5 48 48 0 19.7-11.9 36.6-28.9 44 17 7.4 28.9 24.3 28.9 44 0 23.4-16.8 42.9-39 47.1 4.4 7.3 7 15.8 7 24.9 0 22.2-15 40.8-35.4 46.3 2.2 5.5 3.4 11.5 3.4 17.7 0 26.5-21.5 48-48 48l-87.9 0c-36.3 0-71.6-12.4-99.9-35.1L184 435.2c-15.2-12.1-24-30.5-24-50l0-186.6c0-14.9 3.5-29.6 10.1-42.9L226.3 43.3C234.7 26.6 251.8 16 270.6 16z",{"w":17,"h":389,"d":400},"M192-32c17.7 0 32 14.3 32 32l0 96 128 0 0-96c0-17.7 14.3-32 32-32s32 14.3 32 32l0 96 64 0c17.7 0 32 14.3 32 32s-14.3 32-32 32l0 48.7c-98.6 8.1-176 90.7-176 191.3 0 27.3 5.7 53.3 16 76.9l0 3.1c0 17.7-14.3 32-32 32s-32-14.3-32-32l0-66.7C165.2 398.1 96 319.1 96 224l0-64c-17.7 0-32-14.3-32-32S78.3 96 96 96l64 0 0-96c0-17.7 14.3-32 32-32zM496 256a144 144 0 1 1 0 288 144 144 0 1 1 0-288zm59.3 107.3c6.2-6.2 6.2-16.4 0-22.6s-16.4-6.2-22.6 0l-36.7 36.7-36.7-36.7c-6.2-6.2-16.4-6.2-22.6 0s-6.2 16.4 0 22.6l36.7 36.7-36.7 36.7c-6.2 6.2-6.2 16.4 0 22.6s16.4 6.2 22.6 0l36.7-36.7 36.7 36.7c6.2 6.2 16.4 6.2 22.6 0s6.2-16.4 0-22.6l-36.7-36.7 36.7-36.7z",{"w":389,"h":389,"d":402},"M201.1 57.3c-7 5.3-9.1 10.7-9.1 14.7 0 4.5 2.8 11.2 12.4 16.9l11.6 7 0 48.1-168 0 0 60.5c7.4-2.9 15.5-4.5 24-4.5 43.1 0 72 39.4 72 80s-28.9 80-72 80c-8.5 0-16.6-1.6-24-4.5l0 108.5 108.5 0c-2.9-7.4-4.5-15.5-4.5-24 0-43.1 39.4-72 80-72s80 28.9 80 72c0 8.5-1.6 16.6-4.5 24l60.5 0 0-168 48.1 0 7 11.6c5.8 9.6 12.4 12.4 16.9 12.4 4 0 9.5-2.1 14.7-9.1s9.3-17.9 9.3-30.9-4-23.8-9.3-30.9-10.7-9.1-14.7-9.1c-4.5 0-11.2 2.8-16.9 12.4l-7 11.6-48.1 0 0-120-120 0 0-48.1 11.6-7c9.6-5.8 12.4-12.4 12.4-16.9 0-4-2.1-9.5-9.1-14.7S245 48 232 48 208.2 52 201.1 57.3zM172.3 18.9C188.5 6.8 209.6 0 232 0S275.5 6.8 291.7 18.9 320 49.5 320 72c0 8.6-1.8 16.7-4.9 24l100.9 0 0 100.9c7.3-3.1 15.4-4.9 24-4.9 22.5 0 41 12.2 53.1 28.3s18.9 37.3 18.9 59.7-6.8 43.5-18.9 59.7-30.6 28.3-53.1 28.3c-8.6 0-16.7-1.8-24-4.9l0 148.9-168 0 0-49.3 8.2-7.2c5.4-4.7 7.8-10.3 7.8-15.5 0-9.9-10.7-24-32-24s-32 14.1-32 24c0 5.3 2.4 10.8 7.8 15.5l8.2 7.2 0 49.3-216 0 0-216 49.3 0 7.2 8.2c4.7 5.4 10.3 7.8 15.5 7.8 9.9 0 24-10.7 24-32s-14.1-32-24-32c-5.3 0-10.8 2.4-15.5 7.8L49.3 264 0 264 0 96 148.9 96c-3.1-7.3-4.9-15.4-4.9-24 0-22.5 12.2-41 28.3-53.1z",{"w":404,"h":389,"d":405},576,"M96 0C60.7 0 32 28.7 32 64l0 384c0 35.3 28.7 64 64 64l180 0c-22.7-31.5-36-70.2-36-112 0-100.6 77.4-183.2 176-191.3l0-38.1c0-17-6.7-33.3-18.7-45.3L290.7 18.7C278.7 6.7 262.5 0 245.5 0L96 0zM357.5 176L264 176c-13.3 0-24-10.7-24-24L240 58.5 357.5 176zM432 544a144 144 0 1 0 0-288 144 144 0 1 0 0 288zm59.3-180.7l-36.7 36.7 36.7 36.7c6.2 6.2 6.2 16.4 0 22.6s-16.4 6.2-22.6 0l-36.7-36.7-36.7 36.7c-6.2 6.2-16.4 6.2-22.6 0s-6.2-16.4 0-22.6l36.7-36.7-36.7-36.7c-6.2-6.2-6.2-16.4 0-22.6s16.4-6.2 22.6 0l36.7 36.7 36.7-36.7c6.2-6.2 16.4-6.2 22.6 0s6.2 16.4 0 22.6z",{"w":407,"h":389,"d":408},384,"M40.1 467.1l-11.2 9C25.7 478.6 21.8 480 17.8 480 8 480 0 472 0 462.2L0 192C0 86 86 0 192 0S384 86 384 192l0 270.2c0 9.8-8 17.8-17.8 17.8-4 0-7.9-1.4-11.1-3.9l-11.2-9c-13.4-10.7-32.8-9-44.1 3.9L269.3 506c-3.3 3.8-8.2 6-13.3 6s-9.9-2.2-13.3-6l-26.6-30.5c-12.7-14.6-35.4-14.6-48.2 0L141.3 506c-3.3 3.8-8.2 6-13.3 6s-9.9-2.2-13.3-6L84.2 471c-11.3-12.9-30.7-14.6-44.1-3.9zM160 192a32 32 0 1 0 -64 0 32 32 0 1 0 64 0zm96 32a32 32 0 1 0 0-64 32 32 0 1 0 0 64z",{"w":388,"h":389,"d":410},"M64 160l64 0 0-64-64 0 0 64zM0 80C0 53.5 21.5 32 48 32l96 0c26.5 0 48 21.5 48 48l0 96c0 26.5-21.5 48-48 48l-96 0c-26.5 0-48-21.5-48-48L0 80zM64 416l64 0 0-64-64 0 0 64zM0 336c0-26.5 21.5-48 48-48l96 0c26.5 0 48 21.5 48 48l0 96c0 26.5-21.5 48-48 48l-96 0c-26.5 0-48-21.5-48-48l0-96zM320 96l0 64 64 0 0-64-64 0zM304 32l96 0c26.5 0 48 21.5 48 48l0 96c0 26.5-21.5 48-48 48l-96 0c-26.5 0-48-21.5-48-48l0-96c0-26.5 21.5-48 48-48zM288 352a32 32 0 1 1 0-64 32 32 0 1 1 0 64zm0 64c17.7 0 32 14.3 32 32s-14.3 32-32 32-32-14.3-32-32 14.3-32 32-32zm96 32c0-17.7 14.3-32 32-32s32 14.3 32 32-14.3 32-32 32-32-14.3-32-32zm32-96a32 32 0 1 1 0-64 32 32 0 1 1 0 64zm-32 32a32 32 0 1 1 -64 0 32 32 0 1 1 64 0z",{"w":389,"h":389,"d":412},"M257.5 27.6c-.8-5.4-4.9-9.8-10.3-10.6-22.1-3.1-44.6 .9-64.4 11.4l-74 39.5C89.1 78.4 73.2 94.9 63.4 115L26.7 190.6c-9.8 20.1-13 42.9-9.1 64.9l14.5 82.8c3.9 22.1 14.6 42.3 30.7 57.9l60.3 58.4c16.1 15.6 36.6 25.6 58.7 28.7l83 11.7c22.1 3.1 44.6-.9 64.4-11.4l74-39.5c19.7-10.5 35.6-27 45.4-47.2l36.7-75.5c9.8-20.1 13-42.9 9.1-64.9-.9-5.3-5.3-9.3-10.6-10.1-51.5-8.2-92.8-47.1-104.5-97.4-1.8-7.6-8-13.4-15.7-14.6-54.6-8.7-97.7-52-106.2-106.8zM208 144a32 32 0 1 1 0 64 32 32 0 1 1 0-64zM144 336a32 32 0 1 1 64 0 32 32 0 1 1 -64 0zm224-64a32 32 0 1 1 0 64 32 32 0 1 1 0-64z",{"w":388,"h":389,"d":414},"M144-16l-48 112-48 0 0 48 48 0 0 32c0 17 3.3 33.2 9.3 48l-73.3 0 0 32 5.3 16 26.7 80-64 160 51.7 0 56.9-142.2 6.5-16.3c-1-3.1-10.1-30.3-27.2-81.5l51.4 0c22.6 19.9 52.2 32 84.7 32s62.1-12.1 84.7-32l51.4 0c-17.1 51.2-26.1 78.4-27.2 81.5l6.5 16.3 56.9 142.2 51.7 0-64-160 26.7-80 5.3-16 0-32-73.3 0c6-14.8 9.3-31 9.3-48l0-32 48 0 0-48-48 0-48-112-32 0-48 32-48-32-32 0zm80 272c-32.8 0-61-19.7-73.3-48l57.3 0 16-40 16 40 57.3 0c-12.3 28.3-40.5 48-73.3 48zm17.5 139.6l30.5-35.6 0-24-96 0 0 24 30.5 35.6-46.5 116.4 128 0-46.5-116.4z",{"w":389,"h":389,"d":416},"M497.4 49l17-17-33.9-33.9C473.6 4.9 453.3 25.2 419.7 58.8 375.4 22.1 318.5 0 256.4 0 115.1 0 .4 114.6 .4 256s114.6 256 256 256 256-114.6 256-256l-48 0c0 114.9-93.1 208-208 208s-208-93.1-208-208 93.1-208 208-208c48.8 0 93.7 16.8 129.1 44.9l-45.7 45.7c-23.5-16.8-52.3-26.6-83.4-26.6-79.5 0-144 64.5-144 144s64.5 144 144 144 144-64.5 144-144l-48 0c0 53-43 96-96 96s-96-43-96-96 43-96 96-96c17.8 0 34.5 4.8 48.8 13.3-52 52-79.5 79.5-82.7 82.7l33.9 33.9 17-17 224-224z",{"w":389,"h":389,"d":418},"M208 0l24 0C386.6 0 512 125.4 512 280l0 24-48 0 0-24C464 151.9 360.1 48 232 48l-24 0 0-48zm24 96c101.6 0 184 82.4 184 184l0 24-48 0 0-24c0-75.1-60.9-136-136-136l-24 0 0-48 24 0zM48 256c0 114.9 93.1 208 208 208 22.9 0 45-3.7 65.6-10.5l-263-263C51.7 211 48 233.1 48 256zM0 256c0-36.5 7.6-71.3 21.4-102.7 6.7-15.3 14.9-29.9 24.4-43.5 7.7 7.7 61.5 61.5 161.2 161.2 30.5-30.5 49.5-49.5 57-57L297.9 248c-7.5 7.5-26.5 26.5-57 57 99.7 99.7 153.5 153.5 161.2 161.2-13.6 9.5-28.2 17.7-43.5 24.4-31.4 13.8-66.2 21.4-102.7 21.4-141.4 0-256-114.6-256-256z",{"w":389,"h":389,"d":420},"M267.6 4.5l207.5 80.5 19.2 7.4 1.2 20.5c2.9 50-4.9 126.3-37.3 200.9-32.7 75.2-91.1 150-189.4 192.5l-12.7 5.5-12.7-5.5C144.9 463.9 86.6 389.2 53.9 313.9 21.5 239.3 13.7 162.9 16.6 113L17.8 92.5 37 85 244.5 4.5 256 0 267.6 4.5zM64.1 126C63.1 169.5 71 232.9 97.9 294.8 126.1 359.7 175 422.4 256 459.6 337.1 422.4 385.9 359.7 414.2 294.8 441 232.9 449 169.5 448 126L256 51.5 64.1 126zm302.3 44.7L352.3 190.1 249.8 330.9 233 354c-8.8-9.1-30.9-32-66.2-68.6l-16.7-17.3 34.5-33.3c9.5 9.8 23.9 24.7 43.2 44.7l85.6-117.7 14.1-19.4 38.8 28.2z",{"w":389,"h":389,"d":422},"M192 48l40 0 0 108-12.4 0c-7.6-16.5-24.3-28-43.6-28-26.5 0-48 21.5-48 48s21.5 48 48 48c19.4 0 36.1-11.5 43.6-28l12.4 0 0 56-92 0 0 56.4c-16.5 7.6-28 24.3-28 43.6 0 26.5 21.5 48 48 48s48-21.5 48-48c0-19.4-11.5-36.1-28-43.6l0-16.4 52 0 0 172-40 0c-16.8 0-31.2-10.3-37.1-25.1l-6.4-16-17.2 1c-1.1 .1-2.2 .1-3.2 .1-30.9 0-56-25.1-56-56 0-9.5 2.4-18.5 6.5-26.3l8.7-16.2-13.4-12.6c-11-10.2-17.8-24.8-17.8-40.9 0-21.6 12.2-40.4 30.3-49.8l22.6-11.7-13.1-21.9c-5-8.4-7.9-18.1-7.9-28.6 0-30.9 25.1-56 56-56l24 0 0-32c0-13.3 10.7-24 24-24zm88 148l12.4 0c7.6 16.5 24.3 28 43.6 28 26.5 0 48-21.5 48-48s-21.5-48-48-48c-19.4 0-36.1 11.5-43.6 28l-12.4 0 0-108 40 0c13.3 0 24 10.7 24 24l0 32 24 0c30.9 0 56 25.1 56 56 0 10.5-2.9 20.3-7.9 28.6l-13.1 21.9 22.6 11.7c18 9.3 30.3 28.1 30.3 49.8 0 16.1-6.8 30.7-17.8 40.9l-13.4 12.6 8.7 16.2c4.2 7.8 6.5 16.7 6.5 26.3 0 30.9-25.1 56-56 56-1.1 0-2.2 0-3.2-.1l-17.2-1-6.4 16C351.2 453.7 336.8 464 320 464l-40 0 0-76 92 0 0-56.4c16.5-7.6 28-24.3 28-43.6 0-26.5-21.5-48-48-48s-48 21.5-48 48c0 19.4 11.5 36.1 28 43.6l0 16.4-52 0 0-152zM192 512l128 0c31.1 0 58.4-16.2 74.1-40.5 52.7-5.1 93.9-49.5 93.9-103.5 0-11.5-1.9-22.5-5.3-32.9 13.4-17.5 21.3-39.4 21.3-63.1 0-32-14.5-60.6-37.1-79.7 3.3-10.2 5.1-21.1 5.1-32.3 0-49.6-34.8-91.1-81.3-101.5-6.3-33.3-35.6-58.5-70.7-58.5L192 0c-35.1 0-64.4 25.2-70.7 58.5-46.5 10.4-81.3 51.9-81.3 101.5 0 11.3 1.8 22.2 5.1 32.3-22.7 19.1-37.1 47.7-37.1 79.7 0 23.7 8 45.6 21.3 63.1-3.5 10.4-5.3 21.4-5.3 32.9 0 54 41.2 98.5 93.9 103.5 15.6 24.3 42.9 40.5 74.1 40.5zM336 192a16 16 0 1 1 0-32 16 16 0 1 1 0 32zm32 96a16 16 0 1 1 -32 0 16 16 0 1 1 32 0zM176 352a16 16 0 1 1 -32 0 16 16 0 1 1 32 0zm16-176a16 16 0 1 1 -32 0 16 16 0 1 1 32 0z",{"w":407,"h":389,"d":424},"M16 64C16 28.7 44.7 0 80 0L304 0c35.3 0 64 28.7 64 64l0 384c0 35.3-28.7 64-64 64L80 512c-35.3 0-64-28.7-64-64L16 64zm64 0l0 304 224 0 0-304-224 0zM192 472c17.7 0 32-14.3 32-32s-14.3-32-32-32-32 14.3-32 32 14.3 32 32 32z",{"w":389,"h":389,"d":426},"M0 256c0-46.6 12.5-90.4 34.3-128.9L144.1 318.3c21.9 39.2 63.8 65.7 111.9 65.7 14.3 0 27.1-2.3 40.8-6.6L220.5 509.6C95.9 492.3 0 385.3 0 256zm365.1 65.6c12.3-19.2 18.9-42.5 18.9-65.6 0-38.2-16.8-72.5-43.3-96l152.7 0c12 29.6 18.6 62.1 18.6 96 0 141.4-114.6 255.1-256 256L365.1 321.6zM477.8 128L256 128c-62.9 0-113.7 44.1-125.5 102.7L54.2 98.5C101 38.5 174 0 256 0 350.8 0 433.5 51.5 477.8 128zM344 256a88 88 0 1 1 -176 0 88 88 0 1 1 176 0z",{"w":389,"h":389,"d":428},"M448 96l0 256-384 0 0-256 384 0zM64 32C28.7 32 0 60.7 0 96L0 352c0 35.3 28.7 64 64 64l144 0-16 48-72 0c-13.3 0-24 10.7-24 24s10.7 24 24 24l272 0c13.3 0 24-10.7 24-24s-10.7-24-24-24l-72 0-16-48 144 0c35.3 0 64-28.7 64-64l0-256c0-35.3-28.7-64-64-64L64 32z",{"w":389,"h":389,"d":430},"M32 64C19.1 64 7.4 71.8 2.4 83.8S.2 109.5 9.4 118.6L192 301.3 192 416c0 8.5 3.4 16.6 9.4 22.6l64 64c9.2 9.2 22.9 11.9 34.9 6.9S320 492.9 320 480l0-178.7 182.6-182.6c9.2-9.2 11.9-22.9 6.9-34.9S492.9 64 480 64L32 64z",{"w":404,"h":389,"d":432},"M144 480c-79.5 0-144-64.5-144-144 0-63.4 41-117.2 97.9-136.5-1.3-7.7-1.9-15.5-1.9-23.5 0-79.5 64.5-144 144-144 55.4 0 103.5 31.3 127.6 77.1 14.2-8.3 30.8-13.1 48.4-13.1 53 0 96 43 96 96 0 15.7-3.8 30.6-10.5 43.7 44 20.3 74.5 64.7 74.5 116.3 0 70.7-57.3 128-128 128l-304 0zM305 191c-9.4-9.4-24.6-9.4-33.9 0l-72 72c-9.4 9.4-9.4 24.6 0 33.9s24.6 9.4 33.9 0l31-31 0 102.1c0 13.3 10.7 24 24 24s24-10.7 24-24l0-102.1 31 31c9.4 9.4 24.6 9.4 33.9 0s9.4-24.6 0-33.9l-72-72z",{"id":434,"title":435,"authorsCollection":436,"content":446,"extension":1849,"faqItemsCollection":1850,"faqTitle":59,"featured":6,"hashTags":59,"meta":1852,"metaTitle":1853,"ogImage":59,"postType":1854,"publishedDate":1855,"relatedBlogPostsCollection":1856,"slug":3840,"stem":3841,"subtitle":59,"summary":3842,"synopsis":3852,"sys":3853,"tagsCollection":3856,"topicsCollection":3862,"__hash__":3986},"blog\u002Fblog\u002Fbrowser-threat-landscape-mid-year-update-2026.json","Browser threat landscape: mid-year update 2026",{"items":437},[438],{"fullName":439,"firstName":440,"jobTitle":441,"socialLinks":442,"profilePicture":444},"Dan Green","Dan","Threat Research",[443],"https:\u002F\u002Fwww.linkedin.com\u002Fin\u002Fdaniel-g-\u002F",{"url":445},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F7jik1VhFgA3kgzXBXTm2Vw\u002Ffcd8c171da644903d0827eafcfbcaad0\u002FDan_Headshot_2025.png",{"json":447,"links":1760},{"data":448,"content":449,"nodeType":1759},{},[450,459,463,473,505,513,522,553,668,711,720,775,806,812,815,823,830,838,855,910,916,923,942,948,955,961,968,974,981,987,995,1038,1069,1088,1119,1127,1158,1189,1220,1228,1235,1254,1308,1339,1347,1365,1408,1411,1419,1426,1433,1451,1457,1464,1579,1622,1630,1649,1656,1659,1667,1674,1717,1724,1727,1734,1741],{"data":451,"content":452,"nodeType":458},{},[453],{"data":454,"marks":455,"value":456,"nodeType":457},{},[],"Feeling overwhelmed with the amount of cyber news stories? Tired of dodging AI vendors boasting about their agents escaping the lab? This threat landscape update cuts through the noise and covers the key developments that security teams need to be on top of.","text","paragraph",{"data":460,"content":461,"nodeType":462},{},[],"hr",{"data":464,"content":465,"nodeType":472},{},[466],{"data":467,"marks":468,"value":471,"nodeType":457},{},[469],{"type":470},"bold","The SLH playbook becomes the industry standard","heading-1",{"data":474,"content":475,"nodeType":458},{},[476,480,489,493,501],{"data":477,"marks":478,"value":479,"nodeType":457},{},[],"Criminals associated with \"The Com,\" broadly known as the ",{"data":481,"content":483,"nodeType":488},{"uri":482},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fscattered-lapsus-hunters",[484],{"data":485,"marks":486,"value":487,"nodeType":457},{},[],"Scattered Lapsus$ Hunters","hyperlink",{"data":490,"marks":491,"value":492,"nodeType":457},{},[]," collective, have spent the past three years establishing a playbook ",{"data":494,"content":496,"nodeType":488},{"uri":495},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fanalyzing-the-instructure-breach",[497],{"data":498,"marks":499,"value":500,"nodeType":457},{},[],"focused on identity compromise and cloud data theft",{"data":502,"marks":503,"value":504,"nodeType":457},{},[]," for extortion. They've dominated the news when it comes to public breaches: a sign of their effectiveness, or perhaps more their desire for notoriety (something that has come back to bite individuals later with a series of arrests, but hasn't hampered the overall trajectory of the breaches).",{"data":506,"content":507,"nodeType":458},{},[508],{"data":509,"marks":510,"value":512,"nodeType":457},{},[511],{"type":470},"Regardless, the data doesn't lie. Of the browser and identity-related breaches we've tracked, groups linked to \"The Com\" such as Scattered Spider, ShinyHunters, and Lapsus$ are responsible for roughly 70% (not just in 2026, but since the start of 2024). ",{"data":514,"content":520,"nodeType":521},{"target":515},{"sys":516},{"id":517,"type":518,"linkType":519},"3hODobO3VJr3LvbXkzso8I","Link","Entry",[],"embedded-entry-block",{"data":523,"content":524,"nodeType":458},{},[525,529,537,541,549],{"data":526,"marks":527,"value":528,"nodeType":457},{},[],"The trump card of prolific criminal groups like Scattered Spider, Lapsus$, and ShinyHunters has always been their social engineering skill. Last year, they had huge success in ",{"data":530,"content":532,"nodeType":488},{"uri":531},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fscattered-spider-defending-against-help-desk-scams",[533],{"data":534,"marks":535,"value":536,"nodeType":457},{},[],"tricking help desks into performing account resets",{"data":538,"marks":539,"value":540,"nodeType":457},{},[],". This year, they've switched to using voice-based lures in tandem with ",{"data":542,"content":544,"nodeType":488},{"uri":543},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Funpacking-the-latest-slh-campaign",[545],{"data":546,"marks":547,"value":548,"nodeType":457},{},[],"browser-based phishing payloads",{"data":550,"marks":551,"value":552,"nodeType":457},{},[]," — usually impersonating IT staff under the guise of \"setting up passkeys.\"",{"data":554,"content":555,"nodeType":458},{},[556,560,568,572,580,584,592,596,604,608,616,620,628,632,640,644,652,656,664],{"data":557,"marks":558,"value":559,"nodeType":457},{},[],"The vishing-to-SSO-takeover campaign has been prolific, running continuously since January: ",{"data":561,"content":563,"nodeType":488},{"uri":562},"https:\u002F\u002Fwww.securityweek.com\u002Fpanera-bread-data-breach-linked-to-shinyhunters-sso-campaign\u002F",[564],{"data":565,"marks":566,"value":567,"nodeType":457},{},[],"Panera Bread",{"data":569,"marks":570,"value":571,"nodeType":457},{},[]," (~14M records), ",{"data":573,"content":575,"nodeType":488},{"uri":574},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fmatch-group-breach-exposes-data-from-hinge-tinder-okcupid-and-match\u002F",[576],{"data":577,"marks":578,"value":579,"nodeType":457},{},[],"Match Group",{"data":581,"marks":582,"value":583,"nodeType":457},{},[]," (Hinge, Tinder, OkCupid; 10M+ records), ",{"data":585,"content":587,"nodeType":488},{"uri":586},"https:\u002F\u002Fcloud.google.com\u002Fblog\u002Ftopics\u002Fthreat-intelligence\u002Fexpansion-shinyhunters-saas-data-theft",[588],{"data":589,"marks":590,"value":591,"nodeType":457},{},[],"Betterment",{"data":593,"marks":594,"value":595,"nodeType":457},{},[]," (~20M records), ",{"data":597,"content":599,"nodeType":488},{"uri":598},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fshinyhunters-extortion-gang-claims-odido-breach-affecting-millions\u002F",[600],{"data":601,"marks":602,"value":603,"nodeType":457},{},[],"Odido",{"data":605,"marks":606,"value":607,"nodeType":457},{},[]," (6.2M Dutch telecom customers with BSNs and IBANs exposed), ",{"data":609,"content":611,"nodeType":488},{"uri":610},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fadt-confirms-data-breach-after-shinyhunters-leak-threat\u002F",[612],{"data":613,"marks":614,"value":615,"nodeType":457},{},[],"ADT",{"data":617,"marks":618,"value":619,"nodeType":457},{},[]," (5.5M records), ",{"data":621,"content":623,"nodeType":488},{"uri":622},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fcharter-communications-data-breach-affects-49-million-accounts\u002F",[624],{"data":625,"marks":626,"value":627,"nodeType":457},{},[],"Charter Communications",{"data":629,"marks":630,"value":631,"nodeType":457},{},[]," (4.9M accounts), ",{"data":633,"content":635,"nodeType":488},{"uri":634},"https:\u002F\u002Fwww.theregister.com\u002F2026\u002F04\u002F24\u002Fshinyhunters_claim_cruise_giant_carnivals\u002F",[636],{"data":637,"marks":638,"value":639,"nodeType":457},{},[],"Carnival Corporation",{"data":641,"marks":642,"value":643,"nodeType":457},{},[]," (6M records), and",{"data":645,"content":647,"nodeType":488},{"uri":646},"https:\u002F\u002Fwww.theregister.com\u002F2026\u002F04\u002F28\u002Fpitney_bowes_is_the_latest\u002F",[648],{"data":649,"marks":650,"value":651,"nodeType":457},{},[]," Pitney Bowes",{"data":653,"marks":654,"value":655,"nodeType":457},{},[]," (8.2M emails per HIBP). ",{"data":657,"content":659,"nodeType":488},{"uri":658},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fad-tech-firm-optimizely-confirms-data-breach-after-vishing-attack\u002F",[660],{"data":661,"marks":662,"value":663,"nodeType":457},{},[],"Optimizely",{"data":665,"marks":666,"value":667,"nodeType":457},{},[]," is notable as the first confirmed case where attackers deployed both AiTM credential harvesting and device code phishing against the same target.",{"data":669,"content":670,"nodeType":458},{},[671,675,683,687,695,699,707],{"data":672,"marks":673,"value":674,"nodeType":457},{},[],"Since mid-2025, SaaS apps like Salesforce have been a persistent target for data theft and extortion — as seen in the first large-scale criminal ",{"data":676,"content":678,"nodeType":488},{"uri":677},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fdevice-code-phishing",[679],{"data":680,"marks":681,"value":682,"nodeType":457},{},[],"device code phishing",{"data":684,"marks":685,"value":686,"nodeType":457},{},[]," campaign that preceded this year's adoption spike. ShinyHunters also led the way with OAuth supply chain abuse — compromising SaaS vendors like ",{"data":688,"content":690,"nodeType":488},{"uri":689},"https:\u002F\u002Fcloud.google.com\u002Fblog\u002Ftopics\u002Fthreat-intelligence\u002Fdata-theft-salesforce-instances-via-salesloft-drift",[691],{"data":692,"marks":693,"value":694,"nodeType":457},{},[],"Salesloft, Drift, and GainSight",{"data":696,"marks":697,"value":698,"nodeType":457},{},[]," and leveraging stored OAuth tokens to penetrate downstream customer environments, a pattern that has since ",{"data":700,"content":702,"nodeType":488},{"uri":701},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Funpacking-the-vercel-breach",[703],{"data":704,"marks":705,"value":706,"nodeType":457},{},[],"repeated at scale",{"data":708,"marks":709,"value":710,"nodeType":457},{},[],".",{"data":712,"content":713,"nodeType":719},{},[714],{"data":715,"marks":716,"value":718,"nodeType":457},{},[717],{"type":470},"Copycats and nation-state adoption","heading-2",{"data":721,"content":722,"nodeType":458},{},[723,727,735,739,747,751,759,763,771],{"data":724,"marks":725,"value":726,"nodeType":457},{},[],"Wider groups are now running the SLH playbook independently. ",{"data":728,"content":730,"nodeType":488},{"uri":729},"https:\u002F\u002Fhackread.com\u002Fpink-extortion-microsoft-365-cloud-data-vishing-scams\u002F",[731],{"data":732,"marks":733,"value":734,"nodeType":457},{},[],"Pink",{"data":736,"marks":737,"value":738,"nodeType":457},{},[]," (the latest rebrand in the",{"data":740,"content":742,"nodeType":488},{"uri":741},"https:\u002F\u002Fcloud.google.com\u002Fblog\u002Ftopics\u002Fthreat-intelligence\u002Func6671-targets-financial-services-and-enterprise-cloud-environments",[743],{"data":744,"marks":745,"value":746,"nodeType":457},{},[]," BlackFile",{"data":748,"marks":749,"value":750,"nodeType":457},{},[],"-Redact succession) runs vishing combined with passkey-themed credential phishing for M365 extortion. ",{"data":752,"content":754,"nodeType":488},{"uri":753},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fnew-helix-vishing-group-emerges-in-sharepoint-data-theft-attacks\u002F",[755],{"data":756,"marks":757,"value":758,"nodeType":457},{},[],"Helix",{"data":760,"marks":761,"value":762,"nodeType":457},{},[]," also emerged shortly after BlackFile shut down, pairing vishing with device code phishing and MFA registration for persistence. ",{"data":764,"content":766,"nodeType":488},{"uri":765},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fkongtuke-hackers-now-use-microsoft-teams-for-corporate-breaches\u002F",[767],{"data":768,"marks":769,"value":770,"nodeType":457},{},[],"KongTuke",{"data":772,"marks":773,"value":774,"nodeType":457},{},[],", an independent initial access broker, adopted a similar help-desk impersonation model via Teams external messaging.",{"data":776,"content":777,"nodeType":458},{},[778,782,790,794,802],{"data":779,"marks":780,"value":781,"nodeType":457},{},[],"It's not just criminal groups either. Recently, we saw a campaign linked to Russian actors that used ",{"data":783,"content":785,"nodeType":488},{"uri":784},"https:\u002F\u002Fwww.microsoft.com\u002Fen-us\u002Fsecurity\u002Fblog\u002F2026\u002F07\u002F31\u002Fcaptivecrunch-midnight-blizzard-targets-travelers-worldwide-for-malware-delivery-and-credential-theft\u002F",[786],{"data":787,"marks":788,"value":789,"nodeType":457},{},[],"compromised hotel and conference Wi-Fi gateways",{"data":791,"marks":792,"value":793,"nodeType":457},{},[]," to direct victims to AiTM, ClickFix, and device code phishing pages. And ",{"data":795,"content":797,"nodeType":488},{"uri":796},"https:\u002F\u002Fcloud.google.com\u002Fblog\u002Ftopics\u002Fthreat-intelligence\u002Fchinese-language-phishing-services\u002F",[798],{"data":799,"marks":800,"value":801,"nodeType":457},{},[],"Google Threat Intelligence mapped",{"data":803,"marks":804,"value":805,"nodeType":457},{},[]," a dozen Chinese-language PhaaS platforms with real-time MFA interception.",{"data":807,"content":811,"nodeType":521},{"target":808},{"sys":809},{"id":810,"type":518,"linkType":519},"6q2NwH6Q4DJE7RNeYheIvJ",[],{"data":813,"content":814,"nodeType":462},{},[],{"data":816,"content":817,"nodeType":472},{},[818],{"data":819,"marks":820,"value":822,"nodeType":457},{},[821],{"type":470},"Phishing infrastructure has reached an industrial scale",{"data":824,"content":825,"nodeType":458},{},[826],{"data":827,"marks":828,"value":829,"nodeType":457},{},[],"The SLH playbook works because it sits on top of an industrialized infrastructure layer that continues to grow. Phishing-as-a-Service platforms, device code phishing kits, ClickFix Malware-as-a-Service providers, vishing operations, and OAuth supply chain attacks have all matured into commodity services — and they're shipping faster than ever.",{"data":831,"content":832,"nodeType":719},{},[833],{"data":834,"marks":835,"value":837,"nodeType":457},{},[836],{"type":470},"Device code phishing goes mainstream",{"data":839,"content":840,"nodeType":458},{},[841,845,851],{"data":842,"marks":843,"value":844,"nodeType":457},{},[],"We're tracking a huge spike in ",{"data":846,"content":847,"nodeType":488},{"uri":677},[848],{"data":849,"marks":850,"value":682,"nodeType":457},{},[],{"data":852,"marks":853,"value":854,"nodeType":457},{},[]," since the start of 2026, with 25+ distinct kits now offering the technique. At the beginning of the year, we were tracking one or two.",{"data":856,"content":857,"nodeType":458},{},[858,862,870,874,882,886,894,898,906],{"data":859,"marks":860,"value":861,"nodeType":457},{},[],"What began with ",{"data":863,"content":865,"nodeType":488},{"uri":864},"https:\u002F\u002Fwww.microsoft.com\u002Fen-us\u002Fsecurity\u002Fblog\u002F2025\u002F02\u002F13\u002Fstorm-2372-conducts-device-code-phishing-campaign\u002F",[866],{"data":867,"marks":868,"value":869,"nodeType":457},{},[],"Storm-2372's nation-state campaigns",{"data":871,"marks":872,"value":873,"nodeType":457},{},[]," in August 2024 has proliferated through criminal kits like ",{"data":875,"content":877,"nodeType":488},{"uri":876},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F05\u002Fthe-new-phishing-click-how-oauth-consent.html",[878],{"data":879,"marks":880,"value":881,"nodeType":457},{},[],"EvilTokens",{"data":883,"marks":884,"value":885,"nodeType":457},{},[]," (340+ organizations in its first five weeks), ",{"data":887,"content":889,"nodeType":488},{"uri":888},"https:\u002F\u002Fwww.huntress.com\u002Fblog\u002Fkali365-device-code-phishing-kit",[890],{"data":891,"marks":892,"value":893,"nodeType":457},{},[],"Kali365",{"data":895,"marks":896,"value":897,"nodeType":457},{},[]," (which earned an FBI public advisory), ",{"data":899,"content":901,"nodeType":488},{"uri":900},"https:\u002F\u002Fblog.talosintelligence.com\u002Fartoken-inside-an-eviltokens-affiliate-panel-targeting-microsoft-365\u002F",[902],{"data":903,"marks":904,"value":905,"nodeType":457},{},[],"ARToken",{"data":907,"marks":908,"value":909,"nodeType":457},{},[],", DEBULL, Forg365, and many more.",{"data":911,"content":915,"nodeType":521},{"target":912},{"sys":913},{"id":914,"type":518,"linkType":519},"7G6ytXRQPWatOyYarqgMK2",[],{"data":917,"content":918,"nodeType":458},{},[919],{"data":920,"marks":921,"value":922,"nodeType":457},{},[],"The existing PhaaS marketplace, previously dominated by AiTM phishing kits as the standard, has also pivoted to take advantage of the demand for the technique.",{"data":924,"content":925,"nodeType":458},{},[926,930,938],{"data":927,"marks":928,"value":929,"nodeType":457},{},[],"Established AiTM vendors like Tycoon 2FA have ",{"data":931,"content":933,"nodeType":488},{"uri":932},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fdevice-code-phishing\u002F",[934],{"data":935,"marks":936,"value":937,"nodeType":457},{},[],"added device code phishing",{"data":939,"marks":940,"value":941,"nodeType":457},{},[]," alongside their existing credential-harvesting capabilities, meaning the same platforms now offer both techniques interchangeably based on what works against a given target. Several kits like Venom, EvilTokens, Kali365 all reportedly offer both capabilities, while many of the detections we see match the signatures for existing kits in our database (for example, with Venom triggering our existing Sneaky2FA detections) — suggesting an overlap in kit developers or their codebases.",{"data":943,"content":947,"nodeType":521},{"target":944},{"sys":945},{"id":946,"type":518,"linkType":519},"3urXbEwK0OSjXQ7lOMDEoc",[],{"data":949,"content":950,"nodeType":458},{},[951],{"data":952,"marks":953,"value":954,"nodeType":457},{},[],"When you look at the full picture, it's notable to see a mixture of AiTM and device code kits in our top detected kits, with most of the top 5 now offering both.",{"data":956,"content":960,"nodeType":521},{"target":957},{"sys":958},{"id":959,"type":518,"linkType":519},"4ipTS2U4HE1VLSLmA6DJgB",[],{"data":962,"content":963,"nodeType":458},{},[964],{"data":965,"marks":966,"value":967,"nodeType":457},{},[],"PhaaS vendors are pivoting because device code phishing defeats all MFA (including passkeys) by targeting the authorization layer rather than the login. It's also an unfamiliar phishing scenario that most people aren't really prepared for.",{"data":969,"content":973,"nodeType":521},{"target":970},{"sys":971},{"id":972,"type":518,"linkType":519},"3UDzUCCizPJhXp3SsoZuSK",[],{"data":975,"content":976,"nodeType":458},{},[977],{"data":978,"marks":979,"value":980,"nodeType":457},{},[],"And because they're being used interchangeably, there's no downside for the attacker. In one recent example, we saw the attack automatically fall back to AiTM after the device code method timed out, giving the operator two shots at the same victim without manual intervention.",{"data":982,"content":986,"nodeType":521},{"target":983},{"sys":984},{"id":985,"type":518,"linkType":519},"3SPsKzwBNxl4d9QRukBtwt",[],{"data":988,"content":989,"nodeType":719},{},[990],{"data":991,"marks":992,"value":994,"nodeType":457},{},[993],{"type":470},"PhaaS platform evolution and evasion",{"data":996,"content":997,"nodeType":458},{},[998,1002,1010,1014,1022,1026,1034],{"data":999,"marks":1000,"value":1001,"nodeType":457},{},[],"The broader PhaaS ecosystem continues to expand and evolve. New platform launches this quarter include ",{"data":1003,"content":1005,"nodeType":488},{"uri":1004},"https:\u002F\u002Fwww.cloudsek.com\u002Fblog\u002Fbluekit-phishing-as-a-service-phaas",[1006],{"data":1007,"marks":1008,"value":1009,"nodeType":457},{},[],"Bluekit",{"data":1011,"marks":1012,"value":1013,"nodeType":457},{},[],", ",{"data":1015,"content":1017,"nodeType":488},{"uri":1016},"https:\u002F\u002Fabnormal.ai\u002Fblog\u002Fblacksite-aitm-phishing-kit-cloaked-gg",[1018],{"data":1019,"marks":1020,"value":1021,"nodeType":457},{},[],"Blacksite and Cloaked.gg",{"data":1023,"marks":1024,"value":1025,"nodeType":457},{},[]," — offering dedicated anti-scanner cloaking as a service for phishing infrastructure — and ",{"data":1027,"content":1029,"nodeType":488},{"uri":1028},"https:\u002F\u002Fthreatactix.com\u002F2026\u002F07\u002F02\u002Fa-rare-look-inside-the-command-and-control-panel-behind-modern-phishing-operations\u002F",[1030],{"data":1031,"marks":1032,"value":1033,"nodeType":457},{},[],"WackoGinx",{"data":1035,"marks":1036,"value":1037,"nodeType":457},{},[],", a multi-platform C2 panel that enables operators to manage simultaneous phishing campaigns.",{"data":1039,"content":1040,"nodeType":458},{},[1041,1045,1053,1057,1065],{"data":1042,"marks":1043,"value":1044,"nodeType":457},{},[],"Sneaky 2FA changes have also been documented, with what ",{"data":1046,"content":1048,"nodeType":488},{"uri":1047},"https:\u002F\u002Fzerobec.com\u002Fblog\u002Fsneaky-2fa-returns-trusted-sender-tenant-branded-microsoft-365-replay",[1049],{"data":1050,"marks":1051,"value":1052,"nodeType":457},{},[],"ZeroBEC calls \"route polymorphism\"",{"data":1054,"marks":1055,"value":1056,"nodeType":457},{},[]," (a complicated way of saying the kit randomizes URL paths and filenames on every visit) while separately adopting ",{"data":1058,"content":1060,"nodeType":488},{"uri":1059},"https:\u002F\u002Fblog.barracuda.com\u002F2026\u002F06\u002F29\u002Femail-threat-radar-june-2026",[1061],{"data":1062,"marks":1063,"value":1064,"nodeType":457},{},[],"split-click buttons and blob URLs",{"data":1066,"marks":1067,"value":1068,"nodeType":457},{},[]," designed to evade link analysis (where buttons have two links: automated scanners interact with one and see a legitimate Microsoft page, but humans naturally click the larger, more visually prominent bottom one and get routed via a blob URL to the phishing page). ",{"data":1070,"content":1071,"nodeType":458},{},[1072,1076,1084],{"data":1073,"marks":1074,"value":1075,"nodeType":457},{},[],"The speed of technique adoption across these platforms is itself accelerating. ",{"data":1077,"content":1079,"nodeType":488},{"uri":1078},"https:\u002F\u002Fsublime.security\u002Fblog\u002Fflowerstorm-unleashes-the-krakvm-phaas-operators-turn-to-vm-based-obfuscation\u002F",[1080],{"data":1081,"marks":1082,"value":1083,"nodeType":457},{},[],"FlowerStorm adopted",{"data":1085,"marks":1086,"value":1087,"nodeType":457},{},[]," KrakVM (an open-source JavaScript VM that compiles malicious JS into encrypted bytecode, defeating email security static analysis) within a month of KrakVM's public release on GitHub. The gap between a new evasion technique appearing publicly and its incorporation into commodity phishing kits has compressed to weeks.",{"data":1089,"content":1090,"nodeType":458},{},[1091,1095,1103,1107,1115],{"data":1092,"marks":1093,"value":1094,"nodeType":457},{},[],"At the same time, target surfaces are expanding: ",{"data":1096,"content":1098,"nodeType":488},{"uri":1097},"https:\u002F\u002Fsecuritylabs.datadoghq.com\u002Farticles\u002Fbehind-the-console-aws-aitm-phishing-kit-and-beyond\u002F",[1099],{"data":1100,"marks":1101,"value":1102,"nodeType":457},{},[],"Datadog documented",{"data":1104,"marks":1105,"value":1106,"nodeType":457},{},[]," an AWS console AiTM kit that dynamically adapts to the victim's configured second factor (an example of ",{"data":1108,"content":1110,"nodeType":488},{"uri":1109},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fmfa-downgrade-attacks",[1111],{"data":1112,"marks":1113,"value":1114,"nodeType":457},{},[],"MFA downgrade",{"data":1116,"marks":1117,"value":1118,"nodeType":457},{},[]," in the wild), extending AiTM phishing from IdPs and SaaS applications to cloud infrastructure consoles.",{"data":1120,"content":1121,"nodeType":719},{},[1122],{"data":1123,"marks":1124,"value":1126,"nodeType":457},{},[1125],{"type":470},"ClickFix as a service",{"data":1128,"content":1129,"nodeType":458},{},[1130,1134,1142,1146,1154],{"data":1131,"marks":1132,"value":1133,"nodeType":457},{},[],"ClickFix has also continued to industrialize. ",{"data":1135,"content":1137,"nodeType":488},{"uri":1136},"https:\u002F\u002Fblog.sekoia.io\u002Funveiling-errtraffic-inside-a-growing-clickfix-malware-distribution-framework\u002F",[1138],{"data":1139,"marks":1140,"value":1141,"nodeType":457},{},[],"Sekoia documented",{"data":1143,"marks":1144,"value":1145,"nodeType":457},{},[]," the ErrTraffic MaaS platform achieving a 60% victim conversion rate, while researchers ",{"data":1147,"content":1149,"nodeType":488},{"uri":1148},"https:\u002F\u002Fkqlquery.com\u002Fposts\u002Fclickfix-gift-that-keeps-on-giving\u002F",[1150],{"data":1151,"marks":1152,"value":1153,"nodeType":457},{},[],"mapped approximately 3,000 live ClickFix payloads",{"data":1155,"marks":1156,"value":1157,"nodeType":457},{},[]," being served through API-driven backends that dynamically generate uniquely obfuscated payloads per victim — essentially the ClickFix PhaaS equivalent.",{"data":1159,"content":1160,"nodeType":458},{},[1161,1165,1173,1177,1185],{"data":1162,"marks":1163,"value":1164,"nodeType":457},{},[],"The technique has also expanded cross-platform, with Unit 42 documenting ",{"data":1166,"content":1168,"nodeType":488},{"uri":1167},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fnew-macos-clickfix-attack-silently-mounts-dmgs-to-push-infostealer\u002F",[1169],{"data":1170,"marks":1171,"value":1172,"nodeType":457},{},[],"macOS ClickFix variants",{"data":1174,"marks":1175,"value":1176,"nodeType":457},{},[]," that mount DMGs and bypass Gatekeeper to deliver AMOS infostealer. At the mass deployment end, over ",{"data":1178,"content":1180,"nodeType":488},{"uri":1179},"https:\u002F\u002Fblog.xlab.qianxin.com\u002Fghost-cms-mass-compromised-via-cve-2026-26980-now-fueling-clickfix-attacks\u002F",[1181],{"data":1182,"marks":1183,"value":1184,"nodeType":457},{},[],"700 Ghost CMS sites were compromised",{"data":1186,"marks":1187,"value":1188,"nodeType":457},{},[]," to serve ClickFix payloads in May, and the Gizmodo homepage was injected in June.",{"data":1190,"content":1191,"nodeType":458},{},[1192,1196,1204,1208,1216],{"data":1193,"marks":1194,"value":1195,"nodeType":457},{},[],"Nation-state actors are building around ClickFix too. Two DPRK subgroups independently stood up ClickFix infrastructure in July: ",{"data":1197,"content":1199,"nodeType":488},{"uri":1198},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F07\u002Fbluenoroff-zoom-phishing-kit-profiles.html",[1200],{"data":1201,"marks":1202,"value":1203,"nodeType":457},{},[],"BlueNoroff",{"data":1205,"marks":1206,"value":1207,"nodeType":457},{},[]," targeting crypto professionals via Zoom impersonation with wallet profiling before payload delivery, and ",{"data":1209,"content":1211,"nodeType":488},{"uri":1210},"https:\u002F\u002Fsocradar.io\u002Fblog\u002Fdprk-clickfake-pylangghost-golangghost-rats\u002F",[1212],{"data":1213,"marks":1214,"value":1215,"nodeType":457},{},[],"Famous Chollima",{"data":1217,"marks":1218,"value":1219,"nodeType":457},{},[]," embedding ClickFix in multi-stage fake job interviews.",{"data":1221,"content":1222,"nodeType":719},{},[1223],{"data":1224,"marks":1225,"value":1227,"nodeType":457},{},[1226],{"type":470},"Vishing as a payload delivery mechanism",{"data":1229,"content":1230,"nodeType":458},{},[1231],{"data":1232,"marks":1233,"value":1234,"nodeType":457},{},[],"Vishing functions as a reliable delivery mechanism for all of these payloads, leveraged by ShinyHunters, Pink, and Helix (among many others) to deliver AiTM and device code phishing. A human operator on a phone call drives the victim through a browser-based technical payload, and the vishing delivery gets around email security controls.",{"data":1236,"content":1237,"nodeType":458},{},[1238,1242,1250],{"data":1239,"marks":1240,"value":1241,"nodeType":457},{},[],"When Push researchers ",{"data":1243,"content":1245,"nodeType":488},{"uri":1244},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Finside-criminal-phishing-panel\u002F",[1246],{"data":1247,"marks":1248,"value":1249,"nodeType":457},{},[],"infiltrated the phishing panels",{"data":1251,"marks":1252,"value":1253,"nodeType":457},{},[]," linked to ShinyHunters' campaigns, we found the mechanics for a live attacker relaying credentials and pushing new prompts in real time during the call, across 400+ linked domains and four infrastructure clusters.",{"data":1255,"content":1256,"nodeType":458},{},[1257,1261,1269,1273,1281,1285,1293,1297,1305],{"data":1258,"marks":1259,"value":1260,"nodeType":457},{},[],"The financial scale is now quantifiable: ",{"data":1262,"content":1264,"nodeType":488},{"uri":1263},"https:\u002F\u002Fwww.darkreading.com\u002Fcyberattacks-data-breaches\u002Fsilent-ransom-us-law-firms-extortion-attacks",[1265],{"data":1266,"marks":1267,"value":1268,"nodeType":457},{},[],"Luna Moth",{"data":1270,"marks":1271,"value":1272,"nodeType":457},{},[]," (Silent Ransom Group), a ",{"data":1274,"content":1276,"nodeType":488},{"uri":1275},"https:\u002F\u002Fwww.crowdstrike.com\u002Fen-us\u002Fadversaries\u002Fchatty-spider\u002F",[1277],{"data":1278,"marks":1279,"value":1280,"nodeType":457},{},[],"Russia-linked Conti spinoff",{"data":1282,"marks":1283,"value":1284,"nodeType":457},{},[]," operating independently of the Com, has extracted ",{"data":1286,"content":1288,"nodeType":488},{"uri":1287},"https:\u002F\u002Fwww.theinsurer.com\u002Fti\u002Fnews\u002Fexclusive-weil-gotshal-paid-double-digit-millions-in-suppression-payment-to-luna-2026-05-27\u002F",[1289],{"data":1290,"marks":1291,"value":1292,"nodeType":457},{},[],"up to $48 million",{"data":1294,"marks":1295,"value":1296,"nodeType":457},{},[]," from Am Law 100 firms in 2026 alone, with 48 law firms on their leak site and the ",{"data":1298,"content":1300,"nodeType":488},{"uri":1299},"https:\u002F\u002Fwww.ic3.gov\u002FCSA\u002F2026\u002F260526.pdf",[1301],{"data":1302,"marks":1303,"value":1304,"nodeType":457},{},[],"FBI issuing a dedicated flash alert",{"data":1306,"marks":1307,"value":710,"nodeType":457},{},[],{"data":1309,"content":1310,"nodeType":458},{},[1311,1315,1323,1327,1335],{"data":1312,"marks":1313,"value":1314,"nodeType":457},{},[],"The infrastructure behind these campaigns is industrializing independently. ",{"data":1316,"content":1318,"nodeType":488},{"uri":1317},"https:\u002F\u002Fwww.okta.com\u002Fblog\u002Fthreat-intelligence\u002Fbehind-the-scenes-of-a-vishing-operation\u002F",[1319],{"data":1320,"marks":1321,"value":1322,"nodeType":457},{},[],"Okta obtained access to Work Panel",{"data":1324,"marks":1325,"value":1326,"nodeType":457},{},[],", a multi-tenant vishing MaaS platform where phishing site standup is a one-button operation and callers are deliberately insulated from the credentials they help steal. Zscaler separately ",{"data":1328,"content":1330,"nodeType":488},{"uri":1329},"https:\u002F\u002Fwww.zscaler.com\u002Fblogs\u002Fsecurity-research\u002Fhelpdesk-hijackers-teams-vishing-quick-assist-and-gogrpc-backdoor",[1331],{"data":1332,"marks":1333,"value":1334,"nodeType":457},{},[],"documented a dedicated Teams-vishing initial access broker",{"data":1336,"marks":1337,"value":1338,"nodeType":457},{},[]," operating since January 2026, building bespoke post-access tooling and selling access to ransomware operators.",{"data":1340,"content":1341,"nodeType":719},{},[1342],{"data":1343,"marks":1344,"value":1346,"nodeType":457},{},[1345],{"type":470},"OAuth supply chain attacks",{"data":1348,"content":1349,"nodeType":458},{},[1350,1354,1361],{"data":1351,"marks":1352,"value":1353,"nodeType":457},{},[],"The OAuth supply chain dimension has also continued to produce confirmed victims. The ",{"data":1355,"content":1356,"nodeType":488},{"uri":689},[1357],{"data":1358,"marks":1359,"value":1360,"nodeType":457},{},[],"Salesloft\u002FDrift supply chain attack",{"data":1362,"marks":1363,"value":1364,"nodeType":457},{},[]," in 2025 set the template: compromise one SaaS vendor, steal OAuth tokens, access 700+ downstream customer Salesforce environments.",{"data":1366,"content":1367,"nodeType":458},{},[1368,1372,1380,1384,1392,1396,1404],{"data":1369,"marks":1370,"value":1371,"nodeType":457},{},[],"In 2026, the ",{"data":1373,"content":1375,"nodeType":488},{"uri":1374},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fvimeo-data-breach-exposes-personal-information-of-119-000-people\u002F",[1376],{"data":1377,"marks":1378,"value":1379,"nodeType":457},{},[],"Anodot compromise",{"data":1381,"marks":1382,"value":1383,"nodeType":457},{},[]," cascaded through to Vimeo, Rockstar Games, and Zara. The ",{"data":1385,"content":1387,"nodeType":488},{"uri":1386},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Funpacking-the-vercel-breach\u002F",[1388],{"data":1389,"marks":1390,"value":1391,"nodeType":457},{},[],"Context.ai → Vercel",{"data":1393,"marks":1394,"value":1395,"nodeType":457},{},[]," breach followed the same structural pattern. And the ",{"data":1397,"content":1399,"nodeType":488},{"uri":1398},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fklue-oauth-breach-victim-list-grows-as-icarus-hackers-claim-attack\u002F",[1400],{"data":1401,"marks":1402,"value":1403,"nodeType":457},{},[],"Klue\u002FIcarus breach",{"data":1405,"marks":1406,"value":1407,"nodeType":457},{},[]," in June — where attackers pivoted from a legacy credential through stored OAuth tokens to exfiltrate Salesforce data from Huntress, Recorded Future, and Jamf among others — showed that OAuth tokens have become a tried and tested lateral movement vector in SaaS environments.",{"data":1409,"content":1410,"nodeType":462},{},[],{"data":1412,"content":1413,"nodeType":472},{},[1414],{"data":1415,"marks":1416,"value":1418,"nodeType":457},{},[1417],{"type":470},"AI is a force multiplier for attackers",{"data":1420,"content":1421,"nodeType":458},{},[1422],{"data":1423,"marks":1424,"value":1425,"nodeType":457},{},[],"Much of the security industry's AI threat discussion has focused on autonomous offensive AI and novel attack classes like prompt injection. But the place where AI is having the most measurable impact right now is less dramatic and more consequential: it's accelerating how the techniques we've already been tracking get built and operated.",{"data":1427,"content":1428,"nodeType":458},{},[1429],{"data":1430,"marks":1431,"value":1432,"nodeType":457},{},[],"The evidence is visible at every layer of the attack chain. Pretty much every phishing kit we come across in 2026 shows clear signs of vibe coding. For the classic AiTM lure, we used to find heavy obfuscation — attackers used to put a lot of effort into hiding their attacks. But now, they're essentially built to be disposable, and are full of verbose comments and nicely named unobfuscated functions. Why bother hiding when you can just spin up a new one? This is particularly notable when it comes to device code phishing, which owes its massive scale-up this year to vibecoded kits. ",{"data":1434,"content":1435,"nodeType":458},{},[1436,1440,1448],{"data":1437,"marks":1438,"value":1439,"nodeType":457},{},[],"You can see more examples of these kits under the hood in our blog post ",{"data":1441,"content":1443,"nodeType":488},{"uri":1442},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Finside-criminal-phishing-panel",[1444],{"data":1445,"marks":1446,"value":1447,"nodeType":457},{},[],"infiltrating a criminal phishing panel. ",{"data":1449,"marks":1450,"value":21,"nodeType":457},{},[],{"data":1452,"content":1456,"nodeType":521},{"target":1453},{"sys":1454},{"id":1455,"type":518,"linkType":519},"01mOiserRBXraawXwQyJNm",[],{"data":1458,"content":1459,"nodeType":458},{},[1460],{"data":1461,"marks":1462,"value":1463,"nodeType":457},{},[],"Beyond vibe-coded kits, attackers are embedding AI as an integrated operational capability. ",{"data":1465,"content":1466,"nodeType":1578},{},[1467,1490,1511,1534,1556],{"data":1468,"content":1469,"nodeType":1489},{},[1470],{"data":1471,"content":1472,"nodeType":458},{},[1473,1477,1485],{"data":1474,"marks":1475,"value":1476,"nodeType":457},{},[],"The first major device code phishing kit identified in the wild, EvilTokens, ",{"data":1478,"content":1480,"nodeType":488},{"uri":1479},"https:\u002F\u002Fwww.huntress.com\u002Fblog\u002Frailway-paas-m365-token-replay-campaign",[1481],{"data":1482,"marks":1483,"value":1484,"nodeType":457},{},[],"heavily used Railway",{"data":1486,"marks":1487,"value":1488,"nodeType":457},{},[],", a PaaS built for vibe coding with prompt-based deployment and teardown of infrastructure. EvilTokens itself packaged AI workflows for email filter bypass, lure tailoring, and identifying high-value mailboxes. ","list-item",{"data":1491,"content":1492,"nodeType":1489},{},[1493],{"data":1494,"content":1495,"nodeType":458},{},[1496,1500,1507],{"data":1497,"marks":1498,"value":1499,"nodeType":457},{},[],"Kali365's E2 edition includes an AI-powered BEC module that ",{"data":1501,"content":1502,"nodeType":488},{"uri":888},[1503],{"data":1504,"marks":1505,"value":1506,"nodeType":457},{},[],"uses Claude Sonnet",{"data":1508,"marks":1509,"value":1510,"nodeType":457},{},[]," to score intercepted conversations for fraud opportunity and draft contextual wire-transfer redirect replies — not an autonomous attack, but an AI-augmented workflow that makes an existing phishing kit more effective.",{"data":1512,"content":1513,"nodeType":1489},{},[1514],{"data":1515,"content":1516,"nodeType":458},{},[1517,1520,1530],{"data":1518,"marks":1519,"value":21,"nodeType":457},{},[],{"data":1521,"content":1523,"nodeType":488},{"uri":1522},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F07\u002Fexposed-server-reveals-ai-assisted.html",[1524],{"data":1525,"marks":1526,"value":1529,"nodeType":457},{},[1527],{"type":1528},"underline","Rapid7's analysis of an exposed server",{"data":1531,"marks":1532,"value":1533,"nodeType":457},{},[]," containing a complete phishing toolkit turned up over 1,000 delivery artifacts alongside hardcoded paths to AI coding tools and LLM-style documentation.",{"data":1535,"content":1536,"nodeType":1489},{},[1537],{"data":1538,"content":1539,"nodeType":458},{},[1540,1544,1552],{"data":1541,"marks":1542,"value":1543,"nodeType":457},{},[],"Three independent operators were ",{"data":1545,"content":1547,"nodeType":488},{"uri":1546},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F07\u002Fmisconfigured-server-reveals-three.html",[1548],{"data":1549,"marks":1550,"value":1551,"nodeType":457},{},[],"found running kits from public GitHub forks",{"data":1553,"marks":1554,"value":1555,"nodeType":457},{},[]," with minimal, AI-assisted customization: one had been operating for over a year with 218 victims across 12 countries, running infrastructure that would previously have required significantly more technical ability to maintain. ",{"data":1557,"content":1558,"nodeType":1489},{},[1559],{"data":1560,"content":1561,"nodeType":458},{},[1562,1566,1574],{"data":1563,"marks":1564,"value":1565,"nodeType":457},{},[],"The tooling itself is starting to embed AI as a product feature — ",{"data":1567,"content":1569,"nodeType":488},{"uri":1568},"https:\u002F\u002Fwww.varonis.com\u002Fblog\u002Fdolphin-x-stealer",[1570],{"data":1571,"marks":1572,"value":1573,"nodeType":457},{},[],"Dolphin X",{"data":1575,"marks":1576,"value":1577,"nodeType":457},{},[],", a new MaaS infostealer targeting 300+ applications across browsers, password managers, cloud CLI tools, and crypto wallets, ships an AI Profiler that scores infected machines by application usage and installed software, then delivers daily ranked summaries so operators can prioritize high-value victims from thousands of infections.","unordered-list",{"data":1580,"content":1581,"nodeType":458},{},[1582,1586,1594,1598,1606,1610,1618],{"data":1583,"marks":1584,"value":1585,"nodeType":457},{},[],"AI adoption itself has also become an attack surface. Users searching for AI desktop applications are already looking to download and install software, and attackers are capitalizing on that behavior: a ",{"data":1587,"content":1589,"nodeType":488},{"uri":1588},"https:\u002F\u002Fwww.huntress.com\u002Fblog\u002Ffakeagent-claude-desktop-malvertising-ends-in-dotnet-rat",[1590],{"data":1591,"marks":1592,"value":1593,"nodeType":457},{},[],"malicious Claude.ai Artifact impersonating a download portal",{"data":1595,"marks":1596,"value":1597,"nodeType":457},{},[]," drew 7,100 visits via Bing search ads and compromised 29 organizations in 48 hours, following the ",{"data":1599,"content":1601,"nodeType":488},{"uri":1600},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fllmshare-malvertising-campaign\u002F",[1602],{"data":1603,"marks":1604,"value":1605,"nodeType":457},{},[],"LLMShare attack pattern",{"data":1607,"marks":1608,"value":1609,"nodeType":457},{},[]," we documented in May. A second campaign, ",{"data":1611,"content":1613,"nodeType":488},{"uri":1612},"https:\u002F\u002Fwww.huntress.com\u002Fblog\u002Fmacsync-stealer-rat-reverse-engineering",[1614],{"data":1615,"marks":1616,"value":1617,"nodeType":457},{},[],"MacSync",{"data":1619,"marks":1620,"value":1621,"nodeType":457},{},[],", used a claude.ai conversation styled as an installation guide to deliver a macOS infostealer via a ClickFix-adjacent terminal paste, also distributed through Google Ads. In both cases, the AI platform's trusted domain carried the malicious content past URL reputation filters.",{"data":1623,"content":1624,"nodeType":719},{},[1625],{"data":1626,"marks":1627,"value":1629,"nodeType":457},{},[1628],{"type":470},"But the core techniques aren't changing",{"data":1631,"content":1632,"nodeType":458},{},[1633,1637,1645],{"data":1634,"marks":1635,"value":1636,"nodeType":457},{},[],"AI compresses the bottom layers of the ",{"data":1638,"content":1640,"nodeType":488},{"uri":1639},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fthe-pyramid-of-pain-in-the-ai-era\u002F",[1641],{"data":1642,"marks":1643,"value":1644,"nodeType":457},{},[],"Pyramid of Pain",{"data":1646,"marks":1647,"value":1648,"nodeType":457},{},[]," (unique hashes, domains, IP addresses, host artifacts) by enabling faster domain rotation, cheaper kit development, and rotating payloads, but the technique-level behaviors remain unchanged.",{"data":1650,"content":1651,"nodeType":458},{},[1652],{"data":1653,"marks":1654,"value":1655,"nodeType":457},{},[],"A phishing page still has to harvest credentials. Device code phishing still has to abuse the authorization grant. ClickFix still has to inject a clipboard payload. Those behavioral signatures are structurally resistant to AI-driven variation because changing them means changing how the attack works.",{"data":1657,"content":1658,"nodeType":462},{},[],{"data":1660,"content":1661,"nodeType":472},{},[1662],{"data":1663,"marks":1664,"value":1666,"nodeType":457},{},[1665],{"type":470},"What this means for defenders",{"data":1668,"content":1669,"nodeType":458},{},[1670],{"data":1671,"marks":1672,"value":1673,"nodeType":457},{},[],"Every trend documented here converges on the same control point: the browser. The AI acceleration that makes all of it faster and cheaper doesn't change where the attacks execute, or how Push intercepts them.",{"data":1675,"content":1676,"nodeType":1578},{},[1677,1687,1697,1707],{"data":1678,"content":1679,"nodeType":1489},{},[1680],{"data":1681,"content":1682,"nodeType":458},{},[1683],{"data":1684,"marks":1685,"value":1686,"nodeType":457},{},[],"For AiTM phishing, Push's behavioral detection analyzes and blocks the phishing page in real time, regardless of which domains or hosting infrastructure the kit uses on any given day.",{"data":1688,"content":1689,"nodeType":1489},{},[1690],{"data":1691,"content":1692,"nodeType":458},{},[1693],{"data":1694,"marks":1695,"value":1696,"nodeType":457},{},[],"For device code phishing, Push detects both the phishing pages associated with device code kits and provides an additional layer on the legitimate device code authentication pages themselves, so users cannot enter attacker-supplied codes.",{"data":1698,"content":1699,"nodeType":1489},{},[1700],{"data":1701,"content":1702,"nodeType":458},{},[1703],{"data":1704,"marks":1705,"value":1706,"nodeType":457},{},[],"For ClickFix, Push detects the clipboard injection at the moment the malicious payload is written.",{"data":1708,"content":1709,"nodeType":1489},{},[1710],{"data":1711,"content":1712,"nodeType":458},{},[1713],{"data":1714,"marks":1715,"value":1716,"nodeType":457},{},[],"For OAuth supply chain attacks, Push monitors and controls consent flows at the browser layer, so security teams can govern which applications obtain tokens in the first place.",{"data":1718,"content":1719,"nodeType":458},{},[1720],{"data":1721,"marks":1722,"value":1723,"nodeType":457},{},[],"As AI enables more kits, more operators, and faster infrastructure rotation, indicator-based defenses that target domains, IPs, and hashes become less effective by the day. Behavioral detection that targets technique-class signatures (what the attack does) is the approach that scales.",{"data":1725,"content":1726,"nodeType":462},{},[],{"data":1728,"content":1729,"nodeType":458},{},[1730],{"data":1731,"marks":1732,"value":1733,"nodeType":457},{},[],"Push Security is the most powerful AI-native security tool in the browser. Think EDR, but for the browser — high-fidelity telemetry and real-time control across every session, on every device, with no browser migration required.",{"data":1735,"content":1736,"nodeType":458},{},[1737],{"data":1738,"marks":1739,"value":1740,"nodeType":457},{},[],"Security teams use Push to detect and stop advanced browser-based attacks like AiTM phishing, ClickFix, and session hijacking; gain visibility and control over AI tool usage across their workforce; harden identities by surfacing credential reuse, SSO gaps, and shadow IT; and support data loss and insider investigations with browser-layer telemetry that other tools can't see.",{"data":1742,"content":1743,"nodeType":458},{},[1744,1747,1756],{"data":1745,"marks":1746,"value":21,"nodeType":457},{},[],{"data":1748,"content":1750,"nodeType":488},{"uri":1749},"https:\u002F\u002Fpushsecurity.com\u002Fdemo\u002F",[1751],{"data":1752,"marks":1753,"value":1755,"nodeType":457},{},[1754],{"type":1528},"Book a live demo to learn more.",{"data":1757,"marks":1758,"value":21,"nodeType":457},{},[],"document",{"entries":1761},{"hyperlink":1762,"inline":1763,"block":1764},[],[],[1765,1773,1795,1800,1826,1832,1838,1842],{"sys":1766,"__typename":1767,"title":1768,"caption":1768,"layoutMode":59,"file":1769},{"id":517},"Image"," Public breaches and campaigns with a browser and identity-related breach vector in 2026.",{"url":1770,"width":1771,"height":1772},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F7DDf4WnfcZa3U9C6Leyu14\u002Ff6b7e43f663a387ed7238e4a47e4e215\u002Fimage2.png",1999,1125,{"sys":1774,"__typename":1775,"content":1776,"name":1794,"title":59},{"id":810},"InsightTextBlockComponent",{"json":1777},{"nodeType":1759,"data":1778,"content":1779},{},[1780,1787],{"nodeType":458,"data":1781,"content":1782},{},[1783],{"nodeType":457,"value":1784,"marks":1785,"data":1786},"\"The Com\" affiliates increasingly set the playbook for other criminal groups, and even nation-state operators. It might not always be super sophisticated, but they've proven the playbook works. And from the APT's perspective, why burn an exploit if you can achieve the same with a phish kit?",[],{},{"nodeType":458,"data":1788,"content":1789},{},[1790],{"nodeType":457,"value":1791,"marks":1792,"data":1793},"\n",[],{},"Browser attacks update IB1",{"sys":1796,"__typename":1767,"title":1797,"caption":1797,"layoutMode":59,"file":1798},{"id":914},"Detections by device code phishing kit. Kits are multiplying and fragmenting each month, with a long tail of kits not named here.",{"url":1799,"width":1771,"height":1772},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F3VgSTD544VehTl3THm4zpa\u002Fdd7e8610c29b283f38a3fa17a0614c90\u002Fimage1.png",{"sys":1801,"__typename":1775,"content":1802,"name":1825,"title":59},{"id":946},{"json":1803},{"nodeType":1759,"data":1804,"content":1805},{},[1806],{"nodeType":458,"data":1807,"content":1808},{},[1809,1813,1821],{"nodeType":457,"value":1810,"marks":1811,"data":1812},"Tycoon is a particularly notable example because following a public takedown of its AiTM infrastructure, some recent reports have ",[],{},{"nodeType":488,"data":1814,"content":1816},{"uri":1815},"https:\u002F\u002Fcybersecuritynews.com\u002Ftop-10-phishing-kits-used-by-hackers\u002F",[1817],{"nodeType":457,"value":1818,"marks":1819,"data":1820},"Tycoon detections dropping",[],{},{"nodeType":457,"value":1822,"marks":1823,"data":1824},", but we're finding that actually Tycoon device code attacks in particular have bounced back in our detections. ",[],{},"Browser attacks update IB2",{"sys":1827,"__typename":1767,"title":1828,"caption":1828,"layoutMode":59,"file":1829},{"id":959},"Push Security detections by phishing kit, April-June 2026",{"url":1830,"width":1771,"height":1831},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F71NeNdtXc5hbJrhfypTFS1\u002Fb7159dc73169225ff36bbbdf75d7b059\u002Fimage3.png",1082,{"sys":1833,"__typename":1834,"title":1835,"arcadeDemoUrl":1836,"playText":1837},{"id":972},"ArcadeDemo","Tycoon2FA Device Code Phishing","https:\u002F\u002Fdemo.arcade.software\u002FSPNMxNkoyY5vTMPPlqWS?embed","30 secs",{"sys":1839,"__typename":1834,"title":1840,"arcadeDemoUrl":1841,"playText":1837},{"id":985},"Device code phishing to AITM fallback","https:\u002F\u002Fdemo.arcade.software\u002F6qbvBCrv9ncUnwSv7kQJ?embed",{"sys":1843,"__typename":1767,"title":1844,"caption":1844,"layoutMode":59,"file":1845},{"id":1455},"Verbose phishing kit comments (a clear sign of AI involvement).",{"url":1846,"width":1847,"height":1848},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F2XOX0xzOxsmBKUuQbup47x\u002Fa624c2141879f9238704167a35fdeb39\u002FScreenshot_2026-05-07_at_12.53.27.png",1100,1332,"json",{"items":1851},[],{},"How browser attacks are evolving in 2026 so far","thought-leadership","2026-08-10T00:00:00.000Z",{"items":1857},[1858,2546,2982],{"__typename":1859,"sys":1860,"content":1862,"title":2528,"synopsis":2529,"hashTags":59,"publishedDate":2530,"slug":2531,"tagsCollection":2532,"authorsCollection":2542},"BlogPosts",{"id":1861},"4NY2NbkAPucFOJY45yrrrE",{"json":1863},{"data":1864,"content":1865,"nodeType":1759},{},[1866,1873,1880,1887,1893,1896,1904,1911,1944,1951,1981,1987,1990,1998,2005,2013,2057,2063,2070,2076,2079,2087,2094,2102,2109,2116,2132,2140,2165,2172,2178,2185,2193,2208,2236,2242,2260,2266,2274,2281,2306,2313,2320,2327,2333,2336,2344,2351,2358,2377,2385,2392,2400,2423,2435,2441,2444,2452,2459,2466,2473,2493,2496,2502,2508],{"data":1867,"content":1868,"nodeType":458},{},[1869],{"data":1870,"marks":1871,"value":1872,"nodeType":457},{},[],"Employees have been self-adopting apps, creating unmanaged accounts, and introducing third-party software dependencies into their organizations for years, and the core problem hasn't changed: unmanaged software expanding your attack surface without your knowledge.",{"data":1874,"content":1875,"nodeType":458},{},[1876],{"data":1877,"marks":1878,"value":1879,"nodeType":457},{},[],"But the rate at which employees are signing up for AI tools is unprecedented, and the depth of interconnectivity those tools demand is fundamentally different from traditional shadow SaaS. ",{"data":1881,"content":1882,"nodeType":458},{},[1883],{"data":1884,"marks":1885,"value":1886,"nodeType":457},{},[],"AI tools aren't just standalone apps that employees sign into — they're increasingly used as agents that drive other applications, pulling data from one platform, acting on another — they are becoming a core that other apps are integrating to, and that users are integrating with their wider SaaS stack. It’s becoming a focal integration point for app access and functionality in a way that's more comparable to an enterprise cloud platform than a typical SaaS tool. ",{"data":1888,"content":1892,"nodeType":521},{"target":1889},{"sys":1890},{"id":1891,"type":518,"linkType":519},"2Vxb48M5JN9Jdy8BG6nbUJ",[],{"data":1894,"content":1895,"nodeType":462},{},[],{"data":1897,"content":1898,"nodeType":472},{},[1899],{"data":1900,"marks":1901,"value":1903,"nodeType":457},{},[1902],{"type":470},"What is shadow AI? A quick 101",{"data":1905,"content":1906,"nodeType":458},{},[1907],{"data":1908,"marks":1909,"value":1910,"nodeType":457},{},[],"Shadow AI is any use of AI tools, services, or integrations that happens outside an organization's security governance and visibility. Shadow AI risks cut in two directions:",{"data":1912,"content":1913,"nodeType":1578},{},[1914,1929],{"data":1915,"content":1916,"nodeType":1489},{},[1917],{"data":1918,"content":1919,"nodeType":458},{},[1920,1925],{"data":1921,"marks":1922,"value":1924,"nodeType":457},{},[1923],{"type":470},"Data exposure:",{"data":1926,"marks":1927,"value":1928,"nodeType":457},{},[]," source code, credentials, internal documents, and customer data routinely get pasted into AI prompts or uploaded as context, and once shared, that data is outside the organization's control. ",{"data":1930,"content":1931,"nodeType":1489},{},[1932],{"data":1933,"content":1934,"nodeType":458},{},[1935,1940],{"data":1936,"marks":1937,"value":1939,"nodeType":457},{},[1938],{"type":470},"Attack surface:",{"data":1941,"marks":1942,"value":1943,"nodeType":457},{},[]," Every shadow AI app is an unmanaged identity with credentials that can be phished or stuffed, OAuth grants that give persistent API access to corporate systems, and browser extensions that can be compromised in supply chain attacks. ",{"data":1945,"content":1946,"nodeType":458},{},[1947],{"data":1948,"marks":1949,"value":1950,"nodeType":457},{},[],"AI tools increasingly function as hubs, connected via OAuth and MCP to email, cloud storage, code repositories, and other high-value systems. Every app connection an employee grants turns that AI tool into a node in a web of interconnected services, which means the more you hook in, the larger the attack surface across all the connected apps — and the greater the blast radius if the account used to access the AI tool is compromised.",{"data":1952,"content":1953,"nodeType":458},{},[1954,1958,1966,1970,1977],{"data":1955,"marks":1956,"value":1957,"nodeType":457},{},[],"Each integration creates a persistent trust relationship that survives password resets and MFA changes. Compromise a single AI app and an attacker inherits whatever access the employee granted it, turning one ungoverned tool into a pivot point across the SaaS estate. Attackers are already exploiting this interconnectivity — from ",{"data":1959,"content":1961,"nodeType":488},{"uri":1960},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fllmshare-malvertising-campaign",[1962],{"data":1963,"marks":1964,"value":1965,"nodeType":457},{},[],"malvertising campaigns that impersonate AI tools",{"data":1967,"marks":1968,"value":1969,"nodeType":457},{},[]," to steal credentials, to ",{"data":1971,"content":1972,"nodeType":488},{"uri":495},[1973],{"data":1974,"marks":1975,"value":1976,"nodeType":457},{},[],"leveraging OAuth consent grants in supply chain attacks",{"data":1978,"marks":1979,"value":1980,"nodeType":457},{},[],". ",{"data":1982,"content":1986,"nodeType":521},{"target":1983},{"sys":1984},{"id":1985,"type":518,"linkType":519},"1BWCa7AHCMlYw7XgPLx3h7",[],{"data":1988,"content":1989,"nodeType":462},{},[],{"data":1991,"content":1992,"nodeType":472},{},[1993],{"data":1994,"marks":1995,"value":1997,"nodeType":457},{},[1996],{"type":470},"The state of shadow AI, using Push data",{"data":1999,"content":2000,"nodeType":458},{},[2001],{"data":2002,"marks":2003,"value":2004,"nodeType":457},{},[],"We analyzed a snapshot of AI activity across Push customers during an average week in April 2026. We wanted to make sure it captured actual activity, not just historical data on apps that were added once and no longer used.",{"data":2006,"content":2007,"nodeType":458},{},[2008],{"data":2009,"marks":2010,"value":2012,"nodeType":457},{},[2011],{"type":470},"The numbers paint a picture that most security teams will find uncomfortable.",{"data":2014,"content":2015,"nodeType":458},{},[2016,2020,2025,2029,2034,2038,2043,2047,2053],{"data":2017,"marks":2018,"value":2019,"nodeType":457},{},[],"The average organization has ",{"data":2021,"marks":2022,"value":2024,"nodeType":457},{},[2023],{"type":470},"16 unique AI apps",{"data":2026,"marks":2027,"value":2028,"nodeType":457},{},[]," in active use, ",{"data":2030,"marks":2031,"value":2033,"nodeType":457},{},[2032],{"type":470},"17 unique AI browser extensions",{"data":2035,"marks":2036,"value":2037,"nodeType":457},{},[],", and ",{"data":2039,"marks":2040,"value":2042,"nodeType":457},{},[2041],{"type":470},"17 unique AI OAuth integrations",{"data":2044,"marks":2045,"value":2046,"nodeType":457},{},[]," connected into just Google Workspace and Microsoft 365 — with some organizations reaching as high as 40 unique AI apps, 163 AI extensions, and 55 OAuth connections to AI apps respectively. At the other end, the smallest organization with the ",{"data":2048,"marks":2049,"value":2052,"nodeType":457},{},[2050],{"type":2051},"italic","lowest",{"data":2054,"marks":2055,"value":2056,"nodeType":457},{},[]," adoption level is actively using two. ",{"data":2058,"content":2062,"nodeType":521},{"target":2059},{"sys":2060},{"id":2061,"type":518,"linkType":519},"2AfeiHub5kyZN8wuf6CJch",[],{"data":2064,"content":2065,"nodeType":458},{},[2066],{"data":2067,"marks":2068,"value":2069,"nodeType":457},{},[],"If most organizations have sanctioned one or two core AI assistants\u002Fplatforms for business use, the gap between what's approved and what's actually happening is significant.",{"data":2071,"content":2075,"nodeType":521},{"target":2072},{"sys":2073},{"id":2074,"type":518,"linkType":519},"2hsKQ9DEspflhmtR0bE7QY",[],{"data":2077,"content":2078,"nodeType":462},{},[],{"data":2080,"content":2081,"nodeType":472},{},[2082],{"data":2083,"marks":2084,"value":2086,"nodeType":457},{},[2085],{"type":470},"Understanding the four categories of shadow AI",{"data":2088,"content":2089,"nodeType":458},{},[2090],{"data":2091,"marks":2092,"value":2093,"nodeType":457},{},[],"Shadow SaaS has always been a problem, but in the context of AI apps there are four categories of shadow IT that security teams need to understand, because each one introduces a different kind of risk and requires a different approach to tackling it.",{"data":2095,"content":2096,"nodeType":719},{},[2097],{"data":2098,"marks":2099,"value":2101,"nodeType":457},{},[2100],{"type":470},"Shadow AI apps",{"data":2103,"content":2104,"nodeType":458},{},[2105],{"data":2106,"marks":2107,"value":2108,"nodeType":457},{},[],"Shadow apps are AI tools that employees have signed up to and are using for business purposes without approval. This is the most visible dimension of the problem, and the one most people think of when they hear \"shadow AI\" — an employee pastes sensitive internal documents into ChatGPT, uploads confidential files to an AI assistant, or uses an unapproved coding tool to generate production code.",{"data":2110,"content":2111,"nodeType":458},{},[2112],{"data":2113,"marks":2114,"value":2115,"nodeType":457},{},[],"All of that is sensitive data leaving the organization through channels the security team can't see - and often accessible using personal accounts that can be compromised on personal devices or workstations. ",{"data":2117,"content":2118,"nodeType":458},{},[2119,2123,2128],{"data":2120,"marks":2121,"value":2122,"nodeType":457},{},[],"The 2026 DBIR's data loss prevention analysis underscores the scale — shadow AI is now the ",{"data":2124,"marks":2125,"value":2127,"nodeType":457},{},[2126],{"type":470},"third most common non-malicious insider action",{"data":2129,"marks":2130,"value":2131,"nodeType":457},{},[]," in DLP data, a 4x increase year-over-year. Across 858,000+ DLP events targeting GenAI tools, the most common data types being submitted were source code (28%), images (16%), structured data (14%), documents (13%), and PDFs (10%). That's not employees asking ChatGPT to fix their grammar — it's core intellectual property, production code, and internal documentation flowing into platforms the security team has no visibility into. But shadow apps themselves are only the most obvious part of the problem.",{"data":2133,"content":2134,"nodeType":719},{},[2135],{"data":2136,"marks":2137,"value":2139,"nodeType":457},{},[2138],{"type":470},"Shadow tenants",{"data":2141,"content":2142,"nodeType":458},{},[2143,2147,2152,2156,2161],{"data":2144,"marks":2145,"value":2146,"nodeType":457},{},[],"Even when an organization has approved an AI tool — say, an enterprise ChatGPT deployment — employees frequently access the same app with personal accounts, creating shadow tenants that sit entirely outside organizational control. The DBIR found that ",{"data":2148,"marks":2149,"value":2151,"nodeType":457},{},[2150],{"type":470},"67% of GenAI users on corporate devices are using non-corporate accounts",{"data":2153,"marks":2154,"value":2155,"nodeType":457},{},[],", and our own data shows that ",{"data":2157,"marks":2158,"value":2160,"nodeType":457},{},[2159],{"type":470},"38% of file uploads to AI tools are made from shadow accounts",{"data":2162,"marks":2163,"value":2164,"nodeType":457},{},[]," rather than approved organizational ones.",{"data":2166,"content":2167,"nodeType":458},{},[2168],{"data":2169,"marks":2170,"value":2171,"nodeType":457},{},[],"When an organization approves Claude, ChatGPT, or another core AI platform, you typically also approve the OAuth integration and browser extension for core apps (e.g. M365, Google Workspace, and so on). When that integration is approved, it is approved for all tenants — not just your corporate tenant. ",{"data":2173,"content":2177,"nodeType":521},{"target":2174},{"sys":2175},{"id":2176,"type":518,"linkType":519},"3Rvw0n28AYIM3FQXtHyafD",[],{"data":2179,"content":2180,"nodeType":458},{},[2181],{"data":2182,"marks":2183,"value":2184,"nodeType":457},{},[],"This means that even if you've deployed enterprise controls around your sanctioned AI tools — DLP policies, retention settings, admin oversight — more than a third of the file uploads hitting AI tools are bypassing those controls entirely because they're happening through personal accounts on corporate devices.",{"data":2186,"content":2187,"nodeType":719},{},[2188],{"data":2189,"marks":2190,"value":2192,"nodeType":457},{},[2191],{"type":470},"Shadow extensions",{"data":2194,"content":2195,"nodeType":458},{},[2196,2200,2204],{"data":2197,"marks":2198,"value":2199,"nodeType":457},{},[],"Many AI tools come with a browser extension counterpart, and there's a large ecosystem of third-party AI extensions that offer everything from writing assistance to automated data extraction. The average organization in our dataset has ",{"data":2201,"marks":2202,"value":2033,"nodeType":457},{},[2203],{"type":470},{"data":2205,"marks":2206,"value":2207,"nodeType":457},{},[]," deployed across its workforce, with the highest we observed reaching 163 — and since each of those average 17 different extensions may be installed by multiple employees, the actual number of individual extension installs across the organization is much higher still.",{"data":2209,"content":2210,"nodeType":458},{},[2211,2215,2223,2227,2232],{"data":2212,"marks":2213,"value":2214,"nodeType":457},{},[],"The extension dimension is particularly concerning because most extensions operate with significant privilege inside the browser — they can read and modify page content, access cookies and session tokens, and interact with virtually every web application an employee uses. As we detailed in our recent analysis of ",{"data":2216,"content":2218,"nodeType":488},{"uri":2217},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fwhy-browser-extension-risk-scoring-wont-predict-your-next-breach\u002F",[2219],{"data":2220,"marks":2221,"value":2222,"nodeType":457},{},[],"browser extension risk scoring",{"data":2224,"marks":2225,"value":2226,"nodeType":457},{},[],", at least ",{"data":2228,"marks":2229,"value":2231,"nodeType":457},{},[2230],{"type":470},"46.76% of all extensions across Push customers have the permission combinations needed to perform account takeover with no user interaction",{"data":2233,"marks":2234,"value":2235,"nodeType":457},{},[],", and the extensions involved in every major supply chain breach of the past 18 months scored as normal or low-risk beforehand.",{"data":2237,"content":2241,"nodeType":521},{"target":2238},{"sys":2239},{"id":2240,"type":518,"linkType":519},"3z4JOMALI52xoOXZkzPHLD",[],{"data":2243,"content":2244,"nodeType":458},{},[2245,2249,2256],{"data":2246,"marks":2247,"value":2248,"nodeType":457},{},[],"AI extensions add a specific wrinkle to this problem: many are branded to look like official companions to well-known AI tools but are actually third-party creations with no affiliation to the original vendor. They're not necessarily malicious at the point of installation, but they're exactly the kind of extension that's likely to be ",{"data":2250,"content":2251,"nodeType":488},{"uri":2217},[2252],{"data":2253,"marks":2254,"value":2255,"nodeType":457},{},[],"acquired and weaponized",{"data":2257,"marks":2258,"value":2259,"nodeType":457},{},[]," down the line — and in the meantime, they're collecting data that their permissions entitle them to (which, in most cases, means everything the user can see in their browser).",{"data":2261,"content":2265,"nodeType":521},{"target":2262},{"sys":2263},{"id":2264,"type":518,"linkType":519},"6K3z67rohss6H3lCsSn12B",[],{"data":2267,"content":2268,"nodeType":719},{},[2269],{"data":2270,"marks":2271,"value":2273,"nodeType":457},{},[2272],{"type":470},"Shadow integrations",{"data":2275,"content":2276,"nodeType":458},{},[2277],{"data":2278,"marks":2279,"value":2280,"nodeType":457},{},[],"The fourth dimension — and arguably the most dangerous — is shadow integrations: OAuth connections between AI tools and core enterprise apps that aren't known or approved by the security team. Even if an organization has approved an AI tool for standalone use, plugging that tool directly into Google Workspace, Microsoft 365, Salesforce, or any other one of the dozen or so SaaS apps in a typical user’s work stack is a fundamentally different risk decision, because it creates a persistent, programmatic bridge between your environment and a third party.",{"data":2282,"content":2283,"nodeType":458},{},[2284,2288,2293,2297,2302],{"data":2285,"marks":2286,"value":2287,"nodeType":457},{},[],"On average, we see ",{"data":2289,"marks":2290,"value":2292,"nodeType":457},{},[2291],{"type":470},"17 unique AI app OAuth integrations per organization",{"data":2294,"marks":2295,"value":2296,"nodeType":457},{},[]," in ",{"data":2298,"marks":2299,"value":2301,"nodeType":457},{},[2300],{"type":2051},"just",{"data":2303,"marks":2304,"value":2305,"nodeType":457},{},[]," Google Workspace and Microsoft 365 (to be clear: this number excludes the dozens of downstream apps the AI assistants are integrated with as well), with the highest reaching 55. Each of those represents a unique AI product that has been granted OAuth access — the total number of individual consent grants across users is larger, because popular integrations get authorized by multiple employees independently.",{"data":2307,"content":2308,"nodeType":458},{},[2309],{"data":2310,"marks":2311,"value":2312,"nodeType":457},{},[],"The actual number of AI-related OAuth connections across the full SaaS estate is considerably higher again, because AI tools that automate workflows need to be connected to be useful — pulling data from one app, analyzing it in another, presenting results in a third.",{"data":2314,"content":2315,"nodeType":458},{},[2316],{"data":2317,"marks":2318,"value":2319,"nodeType":457},{},[],"MCP connections use OAuth to achieve this interconnectivity in the same way, and AI coding agents create a particularly concentrated version of the risk: a single agent configuration can hold OAuth tokens for Jira, Confluence, Salesforce, GitHub, and more, meaning that compromising one agent — whether through prompt injection, a malicious repository config, or a supply chain attack on an MCP server — yields persistent, broadly scoped tokens for every service it was connected to, tokens that survive session restarts and generate audit log entries indistinguishable from legitimate user activity.",{"data":2321,"content":2322,"nodeType":458},{},[2323],{"data":2324,"marks":2325,"value":2326,"nodeType":457},{},[],"It's also worth noting that OAuth blast radius is almost always larger than organizations expect. A single well-permissioned user can expose secrets, dashboards, and internal tooling without tenant-wide admin access. And every new AI tool an employee connects makes the web of abusable permissions a little wider.",{"data":2328,"content":2332,"nodeType":521},{"target":2329},{"sys":2330},{"id":2331,"type":518,"linkType":519},"4SnzJ9T93gHzFIUASx7Yb3",[],{"data":2334,"content":2335,"nodeType":462},{},[],{"data":2337,"content":2338,"nodeType":472},{},[2339],{"data":2340,"marks":2341,"value":2343,"nodeType":457},{},[2342],{"type":470},"Why shadow AI needs a different solution to shadow SaaS",{"data":2345,"content":2346,"nodeType":458},{},[2347],{"data":2348,"marks":2349,"value":2350,"nodeType":457},{},[],"The reason it's worth distinguishing between these four dimensions isn't academic. Each one requires a different control, and addressing one doesn't solve the others.",{"data":2352,"content":2353,"nodeType":458},{},[2354],{"data":2355,"marks":2356,"value":2357,"nodeType":457},{},[],"Blocking unsanctioned AI apps does nothing for the personal accounts accessing approved ones, and neither addresses the average 17 different AI extensions running with broad browser permissions, let alone the dozens of OAuth integrations that have already been granted persistent access to core enterprise apps — and even auditing OAuth in Google Workspace and Microsoft 365, where the controls are relatively mature, leaves the broader SaaS estate unaddressed, where admin tooling is inconsistent and visibility is limited.",{"data":2359,"content":2360,"nodeType":458},{},[2361,2365,2373],{"data":2362,"marks":2363,"value":2364,"nodeType":457},{},[],"The tooling gap compounds the policy gap. ",{"data":2366,"content":2368,"nodeType":488},{"uri":2367},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002F7-things-omdias-latest-report-tells-us-about-the-secure-enterprise-browser-market\u002F",[2369],{"data":2370,"marks":2371,"value":2372,"nodeType":457},{},[],"Omdia found",{"data":2374,"marks":2375,"value":2376,"nodeType":457},{},[]," that 58% of organizations rely on secure web gateways to secure GenAI usage — but an SWG can tell you that a user visited ChatGPT, not whether they pasted your source code into the prompt. That link between knowing where data went and knowing what the user actually did is the fundamental visibility gap that makes GenAI policies unenforceable without browser-layer tooling.",{"data":2378,"content":2379,"nodeType":719},{},[2380],{"data":2381,"marks":2382,"value":2384,"nodeType":457},{},[2383],{"type":470},"Advice for security teams",{"data":2386,"content":2387,"nodeType":458},{},[2388],{"data":2389,"marks":2390,"value":2391,"nodeType":457},{},[],"The principles behind managing shadow AI are the same ones that have governed shadow SaaS and software supply chain management for years: default-deny where feasible, comprehensive inventory where it isn't, and continuous monitoring for changes that signal increased risk. But it's vital that teams act fast to stop the snowball.",{"data":2393,"content":2394,"nodeType":458},{},[2395],{"data":2396,"marks":2397,"value":2399,"nodeType":457},{},[2398],{"type":470},"That starts with visibility into which AI tools employees are actually using and which accounts they're using to access them — without that baseline, every other control is built on assumptions.",{"data":2401,"content":2402,"nodeType":458},{},[2403,2408,2412,2419],{"data":2404,"marks":2405,"value":2407,"nodeType":457},{},[2406],{"type":470},"Extensions",{"data":2409,"marks":2410,"value":2411,"nodeType":457},{},[]," need the same ",{"data":2413,"content":2414,"nodeType":488},{"uri":2217},[2415],{"data":2416,"marks":2417,"value":2418,"nodeType":457},{},[],"default-deny allowlisting approach",{"data":2420,"marks":2421,"value":2422,"nodeType":457},{},[]," that has been best practice for software management elsewhere: build a complete inventory, allowlist what's vetted, block everything else, and monitor the approved set for changes that precede weaponization.",{"data":2424,"content":2425,"nodeType":458},{},[2426,2431],{"data":2427,"marks":2428,"value":2430,"nodeType":457},{},[2429],{"type":470},"OAuth",{"data":2432,"marks":2433,"value":2434,"nodeType":457},{},[]," demands the most urgency, because each unmanaged integration is a persistent trust relationship that survives password resets and MFA changes — adopt default-deny for consent grants in your primary enterprise apps, routinely audit what's already connected, and critically extend that visibility beyond Google and Microsoft to the broader SaaS estate where the controls are weaker and the sprawl is harder to track.",{"data":2436,"content":2440,"nodeType":521},{"target":2437},{"sys":2438},{"id":2439,"type":518,"linkType":519},"3RFLFtJtDXvhTz1mVztfV9",[],{"data":2442,"content":2443,"nodeType":462},{},[],{"data":2445,"content":2446,"nodeType":472},{},[2447],{"data":2448,"marks":2449,"value":2451,"nodeType":457},{},[2450],{"type":470},"Browser visibility and control is key to de-risking AI adoption",{"data":2453,"content":2454,"nodeType":458},{},[2455],{"data":2456,"marks":2457,"value":2458,"nodeType":457},{},[],"AI usage is fundamentally browser-based activity — every LLM interaction, every prompt containing sensitive data, every AI agent authorization, every OAuth consent grant happens inside a browser session — which makes the browser the natural control point for AI governance across the workforce. ",{"data":2460,"content":2461,"nodeType":458},{},[2462],{"data":2463,"marks":2464,"value":2465,"nodeType":457},{},[],"Push tracks AI app usage and login security across the workforce, inventories and controls AI browser extensions, monitors and blocks OAuth consent flows across any app (not just the primary enterprise platforms), and gives security teams a single view of the full shadow AI picture across all four dimensions.",{"data":2467,"content":2468,"nodeType":458},{},[2469],{"data":2470,"marks":2471,"value":2472,"nodeType":457},{},[],"Shadow AI isn't a problem that will age well if ignored. Every week that passes without visibility adds more apps, more extensions, more integrations, and more potential breach paths into the environment — and as the Vercel breach demonstrated, it only takes one forgotten OAuth grant to turn an employee's idle curiosity into an organization-wide incident.",{"data":2474,"content":2475,"nodeType":458},{},[2476,2480,2489],{"data":2477,"marks":2478,"value":2479,"nodeType":457},{},[],"Learn more about how you can tackle ",{"data":2481,"content":2483,"nodeType":488},{"uri":2482},"https:\u002F\u002Fpushsecurity.com\u002Fuc\u002Fshadow-ai",[2484],{"data":2485,"marks":2486,"value":2488,"nodeType":457},{},[2487],{"type":1528},"Shadow AI",{"data":2490,"marks":2491,"value":2492,"nodeType":457},{},[]," with Push. ",{"data":2494,"content":2495,"nodeType":462},{},[],{"data":2497,"content":2498,"nodeType":458},{},[2499],{"data":2500,"marks":2501,"value":1733,"nodeType":457},{},[],{"data":2503,"content":2504,"nodeType":458},{},[2505],{"data":2506,"marks":2507,"value":1740,"nodeType":457},{},[],{"data":2509,"content":2510,"nodeType":458},{},[2511,2515,2524],{"data":2512,"marks":2513,"value":2514,"nodeType":457},{},[],"Book a ",{"data":2516,"content":2518,"nodeType":488},{"uri":2517},"https:\u002F\u002Fpushsecurity.com\u002Fdemo",[2519],{"data":2520,"marks":2521,"value":2523,"nodeType":457},{},[2522],{"type":1528},"live demo",{"data":2525,"marks":2526,"value":2527,"nodeType":457},{},[]," to learn more.","Shadow AI: what Push data reveals about the scale of the problem","Push telemetry shows the average organization has 16 AI apps, 17 AI browser extensions, and 17 AI OAuth integrations in use. Here's what it means for security.","2026-05-28T00:00:00.000Z","what-push-data-reveals-about-the-state-of-shadow-ai",{"items":2533},[2534,2538],{"sys":2535,"name":2537},{"id":2536},"1gZi8NrRy2v9OqPV7C4dwD","Risk management",{"sys":2539,"name":2541},{"id":2540},"3pjES4THCIfSAwhGdNwBcy","Browser security",{"items":2543},[2544],{"fullName":439,"firstName":440,"jobTitle":441,"profilePicture":2545},{"url":445},{"__typename":1859,"sys":2547,"content":2549,"title":2960,"synopsis":2961,"hashTags":59,"publishedDate":2962,"slug":2963,"tagsCollection":2964,"authorsCollection":2974},{"id":2548},"4fUZAVpkaksHImeoT8jp0f",{"json":2550},{"data":2551,"content":2552,"nodeType":1759},{},[2553,2560,2567,2574,2581,2588,2608,2615,2622,2629,2635,2638,2645,2664,2670,2686,2702,2718,2734,2741,2748,2755,2761,2768,2775,2782,2789,2795,2815,2830,2837,2844,2851,2858,2865,2872,2878,2885,2892,2899,2906,2913,2920,2927,2934,2941],{"data":2554,"content":2555,"nodeType":458},{},[2556],{"data":2557,"marks":2558,"value":2559,"nodeType":457},{},[],"Every security engineer has a version of this ritual. ",{"data":2561,"content":2562,"nodeType":458},{},[2563],{"data":2564,"marks":2565,"value":2566,"nodeType":457},{},[],"A new campaign hits the news, and you already hear the question coming, “Are we covered?”",{"data":2568,"content":2569,"nodeType":458},{},[2570],{"data":2571,"marks":2572,"value":2573,"nodeType":457},{},[],"So you read the writeup and quickly do the calculus on whether you can extract meaningful data, something to base a behavioral detection around — or not.",{"data":2575,"content":2576,"nodeType":458},{},[2577],{"data":2578,"marks":2579,"value":2580,"nodeType":457},{},[],"Then the choice is: Send the IOCs you can identify to your blocklists and move on for now, or try to dig deeper. The limitations of the first choice are clear; so are the challenges of the second.",{"data":2582,"content":2583,"nodeType":458},{},[2584],{"data":2585,"marks":2586,"value":2587,"nodeType":457},{},[],"That’s the uncomfortable gap between “We’re aware of this threat” and “We have strong detections around it.”",{"data":2589,"content":2590,"nodeType":458},{},[2591,2595,2604],{"data":2592,"marks":2593,"value":2594,"nodeType":457},{},[],"Because you already know that the IOCs for a novel browser-based attack are likely outdated the moment you block them. And in the case of a ",{"data":2596,"content":2598,"nodeType":488},{"uri":2597},"https:\u002F\u002Fwww.microsoft.com\u002Fen-us\u002Fsecurity\u002Fblog\u002F2026\u002F03\u002F02\u002Foauth-redirection-abuse-enables-phishing-malware-delivery\u002F",[2599],{"data":2600,"marks":2601,"value":2603,"nodeType":457},{},[2602],{"type":1528},"new technique observed by Microsoft",{"data":2605,"marks":2606,"value":2607,"nodeType":457},{},[]," earlier this year, you’d be right.",{"data":2609,"content":2610,"nodeType":458},{},[2611],{"data":2612,"marks":2613,"value":2614,"nodeType":457},{},[],"In March, Push’s AI agents took a close look at that Microsoft intel, which details a discovered campaign built around a novel OAuth redirect abuse technique used to deliver users to phishing pages under the cover of trusted services’ OAuth flows. ",{"data":2616,"content":2617,"nodeType":458},{},[2618],{"data":2619,"marks":2620,"value":2621,"nodeType":457},{},[],"What we found was indicative of how these attacks rapidly evolve: No matches for the published IOCs across our install base. But a few months later, we got a true positive. Except it was for new lures, new variants, and different IOCs. What hadn’t changed was the underlying attack delivery technique, and that’s what we used to detect a new campaign on Push customer estates.",{"data":2623,"content":2624,"nodeType":458},{},[2625],{"data":2626,"marks":2627,"value":2628,"nodeType":457},{},[],"In this article, we’ll walk through this example as a case study of how agentic threat hunting helps us go beyond IOCs to extract durable behavioral indicators that close the gap between “We’re aware of this threat” and “We’re covered.”",{"data":2630,"content":2634,"nodeType":521},{"target":2631},{"sys":2632},{"id":2633,"type":518,"linkType":519},"6X7yXNdchH1Qp2tNKRAyVP",[],{"data":2636,"content":2637,"nodeType":462},{},[],{"data":2639,"content":2640,"nodeType":472},{},[2641],{"data":2642,"marks":2643,"value":2644,"nodeType":457},{},[],"The intel: Novel abuse of OAuth redirects as a phishing delivery mechanism",{"data":2646,"content":2647,"nodeType":458},{},[2648,2652,2660],{"data":2649,"marks":2650,"value":2651,"nodeType":457},{},[],"The technique ",{"data":2653,"content":2654,"nodeType":488},{"uri":2597},[2655],{"data":2656,"marks":2657,"value":2659,"nodeType":457},{},[2658],{"type":1528},"Microsoft documented",{"data":2661,"marks":2662,"value":2663,"nodeType":457},{},[]," back in March is an interesting one. It doesn't steal tokens or abuse consent flows. Instead, it weaponizes the OAuth error-handling path itself — turning trusted identity provider domains into a delivery mechanism for phishing and malware.",{"data":2665,"content":2669,"nodeType":521},{"target":2666},{"sys":2667},{"id":2668,"type":518,"linkType":519},"486pfUpMxx15vJupxuiePn",[],{"data":2671,"content":2672,"nodeType":458},{},[2673,2677,2682],{"data":2674,"marks":2675,"value":2676,"nodeType":457},{},[],"Here's how it works. The attacker registers a malicious application in an actor-controlled tenant, pointing its redirect URI at attacker infrastructure. They craft an authorization URL using ",{"data":2678,"marks":2679,"value":2681,"nodeType":457},{},[2680],{"type":470},"prompt=none",{"data":2683,"marks":2684,"value":2685,"nodeType":457},{},[]," (forcing silent authentication) and an intentionally invalid scope, which guarantees an OAuth error. ",{"data":2687,"content":2688,"nodeType":458},{},[2689,2693,2698],{"data":2690,"marks":2691,"value":2692,"nodeType":457},{},[],"The identity provider — Microsoft Entra ID, Google Workspace, or any OAuth-compliant service — handles that error the way the spec says it should: By redirecting the browser to the application's registered redirect URI. The user clicks a link that begins at ",{"data":2694,"marks":2695,"value":2697,"nodeType":457},{},[2696],{"type":470},"login.microsoftonline.com",{"data":2699,"marks":2700,"value":2701,"nodeType":457},{},[],", passes through a legitimate authentication endpoint, and lands on an attacker-controlled page.",{"data":2703,"content":2704,"nodeType":458},{},[2705,2709,2714],{"data":2706,"marks":2707,"value":2708,"nodeType":457},{},[],"Importantly, no token is stolen during the redirect. The OAuth flow is the delivery vehicle, not the compromise mechanism. What happens ",{"data":2710,"marks":2711,"value":2713,"nodeType":457},{},[2712],{"type":2051},"after",{"data":2715,"marks":2716,"value":2717,"nodeType":457},{},[]," the redirect — phishing, malware download, credential harvesting — is where the actual attack occurs.",{"data":2719,"content":2720,"nodeType":458},{},[2721,2725,2730],{"data":2722,"marks":2723,"value":2724,"nodeType":457},{},[],"This technique is also successful because conventional URL filtering sees a legitimate authentication domain, not a phishing destination. The redirect is standards-compliant behavior, and the initial URL carries the domain reputation of a trusted identity provider — which means the usual defenses at the network layer don't fire. (No TI or domain-based detection service in the world would raise a ",{"data":2726,"marks":2727,"value":2729,"nodeType":457},{},[2728],{"type":470},"microsoft.com",{"data":2731,"marks":2732,"value":2733,"nodeType":457},{},[]," domain as suspicious!)",{"data":2735,"content":2736,"nodeType":458},{},[2737],{"data":2738,"marks":2739,"value":2740,"nodeType":457},{},[],"With this intel, Push’s agents now had some useful fodder to hunt for.",{"data":2742,"content":2743,"nodeType":472},{},[2744],{"data":2745,"marks":2746,"value":2747,"nodeType":457},{},[],"Hunting from intel: How we developed a behavioral detection",{"data":2749,"content":2750,"nodeType":458},{},[2751],{"data":2752,"marks":2753,"value":2754,"nodeType":457},{},[],"It started with ingestion. When the Microsoft blog was published, Push's TI aggregation agent flagged it as relevant to our detection surface — the technique abuses OAuth redirect behavior observable in the browser, which maps directly to the metadata that Push's browser agent captures.",{"data":2756,"content":2760,"nodeType":521},{"target":2757},{"sys":2758},{"id":2759,"type":518,"linkType":519},"26saWWXsyFAZrsrfspGwaF",[],{"data":2762,"content":2763,"nodeType":458},{},[2764],{"data":2765,"marks":2766,"value":2767,"nodeType":457},{},[],"The Push intel agent understands not to hunt for IOCs, but rather to think in terms of durable behaviors. It understands the telemetry available to the Push browser extension, and then compares that to the telemetry it would expect to be able to extract for a given technique, before deciding what to hunt for.",{"data":2769,"content":2770,"nodeType":458},{},[2771],{"data":2772,"marks":2773,"value":2774,"nodeType":457},{},[],"In this case, the intel agent extracted two distinct behavioral elements from the research to look for: the OAuth redirect technique and the page users land on after the error.",{"data":2776,"content":2777,"nodeType":458},{},[2778],{"data":2779,"marks":2780,"value":2781,"nodeType":457},{},[],"That extraction step is where surface-level details can become technique-driven hunts. Microsoft's article listed specific client IDs, redirect URLs, and PowerShell command patterns — indicators that are useful for retrospective hunting but will rotate as the campaign evolves. ",{"data":2783,"content":2784,"nodeType":458},{},[2785],{"data":2786,"marks":2787,"value":2788,"nodeType":457},{},[],"The pipeline's job was to identify what wouldn't change: The behavioral mechanics of abusing the OAuth error redirect path as a delivery mechanism, independent of which domains, client IDs, or post-redirect payloads the attacker chose to use. This is the Pyramid of Pain principle in practice: Hunt for the technique, not the indicator, because techniques are genuinely hard for attackers to change.",{"data":2790,"content":2794,"nodeType":521},{"target":2791},{"sys":2792},{"id":2793,"type":518,"linkType":519},"7qUVlKVjHMkabu0MJ1S7gC",[],{"data":2796,"content":2797,"nodeType":458},{},[2798,2802,2811],{"data":2799,"marks":2800,"value":2801,"nodeType":457},{},[],"Next, the agents verified what they already knew from Push’s internal TTP knowledge base. In this case, the agents understood the well-known technique of ",{"data":2803,"content":2805,"nodeType":488},{"uri":2804},"https:\u002F\u002Fowasp.org\u002Fwww-community\u002Fattacks\u002Fopen_redirect",[2806],{"data":2807,"marks":2808,"value":2810,"nodeType":457},{},[2809],{"type":1528},"open redirects",{"data":2812,"marks":2813,"value":2814,"nodeType":457},{},[],", where attackers leverage redirects to deliver users to a malicious page. The example originally published by Microsoft was a novel variation of that — abusing a trusted service and the open redirect technique via a legitimate OAuth error workflow to deliver a multi-stage phishing attack.",{"data":2816,"content":2817,"nodeType":458},{},[2818,2822,2826],{"data":2819,"marks":2820,"value":2821,"nodeType":457},{},[],"AI models’ deep knowledge of web programming and frameworks is a particular strength here, because they understand which OAuth redirect behavior is normal and common across diverse scenarios, and can pinpoint which elements will be the strongest signal to hunt for malicious behavior. The agents immediately recognized that hunting for ",{"data":2823,"marks":2824,"value":2681,"nodeType":457},{},[2825],{"type":470},{"data":2827,"marks":2828,"value":2829,"nodeType":457},{},[]," would be too noisy, as legitimate apps regularly use silent token refresh.",{"data":2831,"content":2832,"nodeType":458},{},[2833],{"data":2834,"marks":2835,"value":2836,"nodeType":457},{},[],"In this case, the approach was simply to find all the instances where a user hit an OAuth error page, and then landed on a login page afterward. Normal behavior for error states would be to return an error response — not send the user on to a page with a password form field or a CAPTCHA. That’s highly suspicious.",{"data":2838,"content":2839,"nodeType":458},{},[2840],{"data":2841,"marks":2842,"value":2843,"nodeType":457},{},[],"The agents then built behavioral queries targeting both behavioral attributes of the attack, and validated them across Push's install base. ",{"data":2845,"content":2846,"nodeType":458},{},[2847],{"data":2848,"marks":2849,"value":2850,"nodeType":457},{},[],"When agents first looked in March, the hunts returned no true positives — the specific campaign Microsoft documented wasn’t active against Push customers at that time.",{"data":2852,"content":2853,"nodeType":458},{},[2854],{"data":2855,"marks":2856,"value":2857,"nodeType":457},{},[],"But the query logic was sound — precise enough to avoid false positives, broad enough to catch technique variants without relying on the specific IOCs that Microsoft documented. So the pipeline promoted it to a live query — a continuing detection that would surface any future instances of the technique across the customer base.",{"data":2859,"content":2860,"nodeType":472},{},[2861],{"data":2862,"marks":2863,"value":2864,"nodeType":457},{},[],"The hunt pays off: A new variant, completely different IOCs",{"data":2866,"content":2867,"nodeType":458},{},[2868],{"data":2869,"marks":2870,"value":2871,"nodeType":457},{},[],"In June, the query fired. A single user at a single customer had been targeted, but with a completely different scenario. ",{"data":2873,"content":2877,"nodeType":521},{"target":2874},{"sys":2875},{"id":2876,"type":518,"linkType":519},"7uXgOzxemy1PaJLhUa1txV",[],{"data":2879,"content":2880,"nodeType":458},{},[2881],{"data":2882,"marks":2883,"value":2884,"nodeType":457},{},[],"Where the Microsoft-documented example used lures presented as document-sharing links, Teams meeting recordings, or password resets, and the abused trusted service was a Microsoft login link used to trigger the OAuth error, the Push-observed attack chain used different elements. However, the behavioral technique at the core was the same.",{"data":2886,"content":2887,"nodeType":458},{},[2888],{"data":2889,"marks":2890,"value":2891,"nodeType":457},{},[],"In this case, the user clicked a link in a service desk ticket, triggering an OAuth flow that used a redirect URL with parameters designed to make it look like a Grammarly link. After hitting the OAuth error, the user was redirected to a page with a CAPTCHA, and then redirected again to a second page behind a Cloudflare Turnstile that was running a phish kit. While examining the phishing page, Push’s agents found a net-new phish kit that they later added additional detections for. ",{"data":2893,"content":2894,"nodeType":458},{},[2895],{"data":2896,"marks":2897,"value":2898,"nodeType":457},{},[],"Roughly a day after the Push detection fired, Google Safe Browsing flagged both domains as phishing domains. But when the user was first targeted, neither domain had been flagged. In this case, the user exited the redirect flow before entering any credentials.",{"data":2900,"content":2901,"nodeType":458},{},[2902],{"data":2903,"marks":2904,"value":2905,"nodeType":457},{},[],"It’s important to note that this phishing technique also bypasses other controls based on network content pattern analysis or domain-based detections. For example, a network proxy is designed to look for malicious webpages based on known-bad IOCs like domains or page content that contains known-bad script files. This technique uses a dynamic obfuscated Javascript blob that unpacks and loads the webpage on the client side after checking to see if it’s running in a live browser environment, evading proxy-based analysis.",{"data":2907,"content":2908,"nodeType":458},{},[2909],{"data":2910,"marks":2911,"value":2912,"nodeType":457},{},[],"The query now serves as another early-warning flag designed to be broad enough to catch other interesting new variants of this TTP.",{"data":2914,"content":2915,"nodeType":472},{},[2916],{"data":2917,"marks":2918,"value":2919,"nodeType":457},{},[],"Why technique-level detection pays dividends",{"data":2921,"content":2922,"nodeType":458},{},[2923],{"data":2924,"marks":2925,"value":2926,"nodeType":457},{},[],"This example demonstrates the value of behavioral detection. By focusing on technique extraction, we can stay a step ahead of attack evolution, identifying other contexts and campaigns that use the same behavioral technique, without relying on stale IOCs.",{"data":2928,"content":2929,"nodeType":458},{},[2930],{"data":2931,"marks":2932,"value":2933,"nodeType":457},{},[],"For customers, this means no one has to distil the threat intel report into behavioral elements, spend time crafting detections, or work to eliminate false positives. The Push agents do all that automatically, delivering a compounding benefit the more they learn. ",{"data":2935,"content":2936,"nodeType":458},{},[2937],{"data":2938,"marks":2939,"value":2940,"nodeType":457},{},[],"Customers get a fully operationalized threat-hunting and detection engineering capability; and the Push knowledge base itself expands with each new hunt, getting better at identifying emerging threats.",{"data":2942,"content":2943,"nodeType":458},{},[2944,2948,2956],{"data":2945,"marks":2946,"value":2947,"nodeType":457},{},[],"If you'd like to see how Push's detection pipeline would work in your environment, ",{"data":2949,"content":2950,"nodeType":488},{"uri":2517},[2951],{"data":2952,"marks":2953,"value":2955,"nodeType":457},{},[2954],{"type":1528},"book a demo",{"data":2957,"marks":2958,"value":2959,"nodeType":457},{},[]," with our team.","From IOCs to TTPs: An agentic threat hunting case study","How Push’s agentic detection pipeline turns intel into huntable characteristics of attacker behavior, deriving durable detections from a range of sources.","2026-07-31T00:00:00.000Z","from-iocs-to-ttps-an-agentic-threat-hunting-case-study",{"items":2965},[2966,2970],{"sys":2967,"name":2969},{"id":2968},"6A5RXS31ZQx3PwryGb1IMy","Browser-based attacks",{"sys":2971,"name":2973},{"id":2972},"4ksQNCFeBf8H4QIORqpRLw","Detection & response",{"items":2975},[2976],{"fullName":2977,"firstName":2978,"jobTitle":2979,"profilePicture":2980},"Kelly Davenport","Kelly","Product Team",{"url":2981},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F1hi8bEuVfn5sF57LivAq6d\u002F9a3b82426c697d765e2e450e33a18424\u002Fkelly_profile_pic.jpeg",{"__typename":1859,"sys":2983,"content":2985,"title":3826,"synopsis":3827,"hashTags":59,"publishedDate":3828,"slug":3829,"tagsCollection":3830,"authorsCollection":3836},{"id":2984},"211Dd0EIrXPOFpvRgs0fEE",{"json":2986},{"data":2987,"content":2988,"nodeType":1759},{},[2989,3008,3027,3046,3052,3055,3063,3070,3077,3084,3091,3099,3102,3110,3117,3124,3131,3137,3145,3164,3171,3178,3194,3202,3233,3249,3256,3287,3295,3326,3333,3341,3359,3366,3373,3379,3386,3394,3412,3419,3438,3445,3448,3456,3463,3551,3558,3574,3577,3607,3626,3633,3640,3643,3651,3670,3677,3684,3701,3704,3712,3719,3752,3759,3776,3795,3801,3804,3811],{"data":2990,"content":2991,"nodeType":458},{},[2992,2996,3004],{"data":2993,"marks":2994,"value":2995,"nodeType":457},{},[],"When we released the ",{"data":2997,"content":2999,"nodeType":488},{"uri":2998},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fsaas-attack-techniques\u002F",[3000],{"data":3001,"marks":3002,"value":3003,"nodeType":457},{},[],"SaaS attack matrix",{"data":3005,"marks":3006,"value":3007,"nodeType":457},{},[]," in 2023, we were anticipating a shift that was just beginning to take shape. The techniques that attackers were using to compromise cloud applications and identities weren't well represented in existing frameworks, and many of the ones we documented hadn't yet been widely observed in the wild.",{"data":3009,"content":3010,"nodeType":458},{},[3011,3015,3023],{"data":3012,"marks":3013,"value":3014,"nodeType":457},{},[],"A year later, we ",{"data":3016,"content":3018,"nodeType":488},{"uri":3017},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fthe-saas-attack-matrix-one-year-on\u002F",[3019],{"data":3020,"marks":3021,"value":3022,"nodeType":457},{},[],"reviewed what had changed",{"data":3024,"marks":3025,"value":3026,"nodeType":457},{},[]," and found that the initial access phase — the techniques designed to compromise an identity in the first place — was where almost all of the attacker innovation was concentrated. And two years on, that trend has become the story of the modern threat landscape. ",{"data":3028,"content":3029,"nodeType":458},{},[3030,3034,3042],{"data":3031,"marks":3032,"value":3033,"nodeType":457},{},[],"Today, we're re-releasing the matrix as the ",{"data":3035,"content":3037,"nodeType":488},{"uri":3036},"https:\u002F\u002Fpushsecurity.com\u002Fresources\u002Fbrowser-identity-attacks-matrix\u002F",[3038],{"data":3039,"marks":3040,"value":3041,"nodeType":457},{},[],"Browser & Identity Attacks Matrix",{"data":3043,"marks":3044,"value":3045,"nodeType":457},{},[],". The name change isn't cosmetic. It reflects that the attacks driving the most consequential breaches are browser-based and identity-first.",{"data":3047,"content":3051,"nodeType":521},{"target":3048},{"sys":3049},{"id":3050,"type":518,"linkType":519},"MSnrBRJtiQxpv2qxFLCVE",[],{"data":3053,"content":3054,"nodeType":462},{},[],{"data":3056,"content":3057,"nodeType":472},{},[3058],{"data":3059,"marks":3060,"value":3062,"nodeType":457},{},[3061],{"type":470},"Why the scope needed to change",{"data":3064,"content":3065,"nodeType":458},{},[3066],{"data":3067,"marks":3068,"value":3069,"nodeType":457},{},[],"The original SaaS attack matrix was built around a specific insight: that attacks targeting modern business applications played out entirely over the internet, without touching endpoints or internal networks in any way that EDR or network detection tools would recognize.",{"data":3071,"content":3072,"nodeType":458},{},[3073],{"data":3074,"marks":3075,"value":3076,"nodeType":457},{},[],"That framing was useful, and it remains true. But it anchored the matrix to the post-access phase — what attackers do once they're inside a SaaS application — and didn't give enough weight to the initial access techniques that determine whether attackers get there in the first place.",{"data":3078,"content":3079,"nodeType":458},{},[3080],{"data":3081,"marks":3082,"value":3083,"nodeType":457},{},[],"The problem is that initial access is where the overwhelming majority of attacker innovation and investment is concentrated, and the techniques being used to achieve it are best understood as browser and identity attacks rather than SaaS-specific ones. AiTM phishing, ClickFix and its growing family of clipboard-injection variants, device code phishing, OAuth consent abuse, credential stuffing powered by infostealer supply chains, malicious browser extensions all happen in or via the browser.",{"data":3085,"content":3086,"nodeType":458},{},[3087],{"data":3088,"marks":3089,"value":3090,"nodeType":457},{},[],"Another issue is that \"SaaS\" has arguably ceased to be a meaningful category. When we consider that most organizations run the majority of their business on cloud applications, the difference between what constitutes \"SaaS\" versus cloud versus just \"business IT\" is pretty blurry (and feels like an academic rather than practical difference).",{"data":3092,"content":3093,"nodeType":458},{},[3094],{"data":3095,"marks":3096,"value":3098,"nodeType":457},{},[3097],{"type":470},"So it's less about whether an attack is a \"SaaS attack\" and more about how these attacks actually play out. ",{"data":3100,"content":3101,"nodeType":462},{},[],{"data":3103,"content":3104,"nodeType":472},{},[3105],{"data":3106,"marks":3107,"value":3109,"nodeType":457},{},[3108],{"type":470},"The technique landscape has transformed",{"data":3111,"content":3112,"nodeType":458},{},[3113],{"data":3114,"marks":3115,"value":3116,"nodeType":457},{},[],"The second part to the change is the fact that scale and speed of attacker innovation in the space justifies it.",{"data":3118,"content":3119,"nodeType":458},{},[3120],{"data":3121,"marks":3122,"value":3123,"nodeType":457},{},[],"When we launched the matrix in mid-2023, AiTM phishing was emerging as a serious concern but was far from ubiquitous. ClickFix didn't exist as a named technique. Device code phishing was a curiosity documented by a handful of researchers. ConsentFix was years away from being discovered. Browser extension supply chain attacks were rare enough to be individually notable.",{"data":3125,"content":3126,"nodeType":458},{},[3127],{"data":3128,"marks":3129,"value":3130,"nodeType":457},{},[],"In the two and a half years since, every one of these has become a mainstream, industrialized attack technique — and several have converged in ways that would have been hard to predict.",{"data":3132,"content":3136,"nodeType":521},{"target":3133},{"sys":3134},{"id":3135,"type":518,"linkType":519},"5Kw2kSrL8u4VyslxK8HCtR",[],{"data":3138,"content":3139,"nodeType":719},{},[3140],{"data":3141,"marks":3142,"value":3144,"nodeType":457},{},[3143],{"type":470},"AiTM phishing has become the default phishing method",{"data":3146,"content":3147,"nodeType":458},{},[3148,3152,3160],{"data":3149,"marks":3150,"value":3151,"nodeType":457},{},[],"AiTM phishing is now the standard, powered by Phishing-as-a-Service kits that operate with the release cycles and customer support of legitimate SaaS products. Tycoon 2FA alone accounted for ",{"data":3153,"content":3155,"nodeType":488},{"uri":3154},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002F2025-top-phishing-trends\u002F",[3156],{"data":3157,"marks":3158,"value":3159,"nodeType":457},{},[],"62% of phishing detected by Microsoft",{"data":3161,"marks":3162,"value":3163,"nodeType":457},{},[]," and over 64,000 confirmed incidents, with Sneaky2FA, FlowerStorm, Evilginx, and a growing roster of competitors filling out the marketplace.",{"data":3165,"content":3166,"nodeType":458},{},[3167],{"data":3168,"marks":3169,"value":3170,"nodeType":457},{},[],"AiTM is constantly evolving, with vendors adding new features, capabilities, detection evasion techniques, and so on. Abuse of legitimate platforms, and increasingly AI-assisted development means that it’s trivial for attackers to spin up and tear down infrastructure, scale their campaigns, target specific organizations with crafted pages and lures, and generally means that attackers can operate highly sophisticated attacks with minimal effort and complexity. This makes AiTM and other PhaaS-powered techniques extremely accessible to all kinds of criminals.  ",{"data":3172,"content":3173,"nodeType":458},{},[3174],{"data":3175,"marks":3176,"value":3177,"nodeType":457},{},[],"These kits are delivered across several browser-based channels — not just email. Push data consistently shows that roughly 1 in 3 phishing payloads we intercept arrive via social media, search ads, messaging apps, or other non-email vectors.",{"data":3179,"content":3180,"nodeType":458},{},[3181,3185,3190],{"data":3182,"marks":3183,"value":3184,"nodeType":457},{},[],"Vishing has also surged as a delivery channel — CrowdStrike documented a ",{"data":3186,"marks":3187,"value":3189,"nodeType":457},{},[3188],{"type":470},"442% year-over-year increase",{"data":3191,"marks":3192,"value":3193,"nodeType":457},{},[],", and Mandiant found it was the single most common initial vector in cloud compromises at 23%. But the trend that matters isn't voice calls in isolation; it's voice calls combined with browser-based payloads, where a live operator guides the victim into an AiTM page or device code flow that the call alone could not execute.",{"data":3195,"content":3196,"nodeType":719},{},[3197],{"data":3198,"marks":3199,"value":3201,"nodeType":457},{},[3200],{"type":470},"ClickFix is the top reported initial access vector",{"data":3203,"content":3204,"nodeType":458},{},[3205,3209,3217,3221,3229],{"data":3206,"marks":3207,"value":3208,"nodeType":457},{},[],"ClickFix has gone from nonexistent to one of the most prevalent initial access techniques in under 18 months. Microsoft reported it as the ",{"data":3210,"content":3212,"nodeType":488},{"uri":3211},"https:\u002F\u002Fcdn-dynmedia-1.microsoft.com\u002Fis\u002Fcontent\u002Fmicrosoftcorp\u002Fmicrosoft\u002Fmsc\u002Fdocuments\u002Fpresentations\u002FCSR\u002FMicrosoft-Digital-Defense-Report-2025.pdf",[3213],{"data":3214,"marks":3215,"value":3216,"nodeType":457},{},[],"most common initial access vector in 2025",{"data":3218,"marks":3219,"value":3220,"nodeType":457},{},[],", accounting for 47% of observed attacks, while CrowdStrike documented a ",{"data":3222,"content":3224,"nodeType":488},{"uri":3223},"https:\u002F\u002Fwww.crowdstrike.com\u002Fexplore\u002F2026-global-threat-report",[3225],{"data":3226,"marks":3227,"value":3228,"nodeType":457},{},[],"563% increase",{"data":3230,"marks":3231,"value":3232,"nodeType":457},{},[]," in fake CAPTCHA lures (a top ClickFix style).",{"data":3234,"content":3235,"nodeType":458},{},[3236,3240,3245],{"data":3237,"marks":3238,"value":3239,"nodeType":457},{},[],"ClickFix is admittedly an outlier in a browser attacks matrix — the payload ultimately executes on the endpoint, not in the browser — but the delivery is overwhelmingly browser-based: ",{"data":3241,"marks":3242,"value":3244,"nodeType":457},{},[3243],{"type":470},"4 in 5 ClickFix payloads",{"data":3246,"marks":3247,"value":3248,"nodeType":457},{},[]," intercepted by Push arrive via search engines as a result of malvertising or compromised web pages, not email, which means the browser is the only control point that actually sees the attack before the user pastes the malicious command.",{"data":3250,"content":3251,"nodeType":458},{},[3252],{"data":3253,"marks":3254,"value":3255,"nodeType":457},{},[],"ClickFix is now the primary delivery mechanism for infostealer malware, which is in turn the primary source of the stolen credentials and session tokens that power credential stuffing and session hijacking — which means the technique sits at the start of a cycle where one class of browser-delivered attack generates the raw material for the next.",{"data":3257,"content":3258,"nodeType":458},{},[3259,3263,3271,3275,3283],{"data":3260,"marks":3261,"value":3262,"nodeType":457},{},[],"The success of ClickFix has predictably spawned a growing family of derivatives — FileFix, CrashFix, ",{"data":3264,"content":3266,"nodeType":488},{"uri":3265},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Finstallfix\u002F",[3267],{"data":3268,"marks":3269,"value":3270,"nodeType":457},{},[],"InstallFix",{"data":3272,"marks":3273,"value":3274,"nodeType":457},{},[]," — and much of the naming is marketing hype around variations on the same clipboard-injection mechanic. But ",{"data":3276,"content":3278,"nodeType":488},{"uri":3277},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fconsentfix\u002F",[3279],{"data":3280,"marks":3281,"value":3282,"nodeType":457},{},[],"ConsentFix",{"data":3284,"marks":3285,"value":3286,"nodeType":457},{},[]," was a genuinely novel development.",{"data":3288,"content":3289,"nodeType":719},{},[3290],{"data":3291,"marks":3292,"value":3294,"nodeType":457},{},[3293],{"type":470},"Browser-native ClickFix: ConsentFix",{"data":3296,"content":3297,"nodeType":458},{},[3298,3302,3310,3314,3322],{"data":3299,"marks":3300,"value":3301,"nodeType":457},{},[],"ConsentFix is a fully browser-native attack that merged ClickFix-style social engineering with OAuth consent abuse, compromising accounts through a legitimate Microsoft authorization flow with no endpoint component at all. ConsentFix was ",{"data":3303,"content":3305,"nodeType":488},{"uri":3304},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fconsentfix-debrief\u002F",[3306],{"data":3307,"marks":3308,"value":3309,"nodeType":457},{},[],"traced to APT29",{"data":3311,"marks":3312,"value":3313,"nodeType":457},{},[]," and has since been ",{"data":3315,"content":3317,"nodeType":488},{"uri":3316},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fconsentfix-v3-analyzing-a-new-toolkit\u002F",[3318],{"data":3319,"marks":3320,"value":3321,"nodeType":457},{},[],"commercialized on criminal forums",{"data":3323,"marks":3324,"value":3325,"nodeType":457},{},[],", following the same path from state-sponsored technique to commodity criminal tooling that we've seen repeatedly in this space.",{"data":3327,"content":3328,"nodeType":458},{},[3329],{"data":3330,"marks":3331,"value":3332,"nodeType":457},{},[],"ConsentFix demonstrates that the clipboard-injection mechanic can evolve into something that operates entirely within the browser, eliminating the endpoint detection surface that traditional ClickFix still exposed.",{"data":3334,"content":3335,"nodeType":719},{},[3336],{"data":3337,"marks":3338,"value":3340,"nodeType":457},{},[3339],{"type":470},"Attackers have pivoted to authorization attacks to get around login controls",{"data":3342,"content":3343,"nodeType":458},{},[3344,3348,3355],{"data":3345,"marks":3346,"value":3347,"nodeType":457},{},[],"Authorization attacks like device code phishing have seen a ",{"data":3349,"content":3350,"nodeType":488},{"uri":932},[3351],{"data":3352,"marks":3353,"value":3354,"nodeType":457},{},[],"37.5x increase",{"data":3356,"marks":3357,"value":3358,"nodeType":457},{},[]," since the start of 2026, with at least 12 distinct kits now offering the technique. It bypasses standard authentication controls — including passkeys — because the attack occurs through the OAuth device authorization flow rather than the standard login flow. ",{"data":3360,"content":3361,"nodeType":458},{},[3362],{"data":3363,"marks":3364,"value":3365,"nodeType":457},{},[],"The technique was first associated with nation-state actors like Storm-2372, but went from espionage-grade to commodity PhaaS tooling in roughly eighteen months, with kits like EvilTokens and Venom now offering turnkey device code phishing as a service.",{"data":3367,"content":3368,"nodeType":458},{},[3369],{"data":3370,"marks":3371,"value":3372,"nodeType":457},{},[],"The device code authorization is effectively performed post-authentication. If you already have an active session in your browser, entering the device code and selecting your account from a drop-down menu is all that's needed. No password or MFA required. You can see an example in the video below.",{"data":3374,"content":3378,"nodeType":521},{"target":3375},{"sys":3376},{"id":3377,"type":518,"linkType":519},"2WPb41lNRajdpt5pogQg8M",[],{"data":3380,"content":3381,"nodeType":458},{},[3382],{"data":3383,"marks":3384,"value":3385,"nodeType":457},{},[],"And the ecosystem is adapting to this opportunity: established AiTM vendors like Tycoon are adding authorization-focused options alongside their existing credential-harvesting capabilities, which points toward multi-technique platforms where operators pick the right tool for whatever defenses the target has in place.",{"data":3387,"content":3388,"nodeType":719},{},[3389],{"data":3390,"marks":3391,"value":3393,"nodeType":457},{},[3392],{"type":470},"Malicious and hacked browser extensions are one of the fastest growing threats",{"data":3395,"content":3396,"nodeType":458},{},[3397,3401,3408],{"data":3398,"marks":3399,"value":3400,"nodeType":457},{},[],"Malicious browser extensions have matured from an occasional nuisance into a scalable supply chain attack vector. The ",{"data":3402,"content":3403,"nodeType":488},{"uri":2217},[3404],{"data":3405,"marks":3406,"value":3407,"nodeType":457},{},[],"Cyberhaven compromise",{"data":3409,"marks":3410,"value":3411,"nodeType":457},{},[]," in December 2024 — where approximately 35 extensions were weaponized through a single OAuth phishing campaign targeting developers — impacted 2.6 million users and demonstrated that extension supply chain attacks can achieve the kind of reach that used to require a compromised software update server.",{"data":3413,"content":3414,"nodeType":458},{},[3415],{"data":3416,"marks":3417,"value":3418,"nodeType":457},{},[],"Since Cyberhaven, the pace has only accelerated. In 2026 alone, researchers have publicly disclosed at least 250 confirmed malicious browser extensions affecting roughly 1.75 million users, alongside a further 370+ extensions engaged in undisclosed or policy-disclosed data harvesting affecting an additional 44 million users. That doesn't count the extensions from late-2025 campaigns (DarkSpectre, AITOPIA, Trust Wallet) whose impacts carried into 2026.",{"data":3420,"content":3421,"nodeType":458},{},[3422,3426,3434],{"data":3423,"marks":3424,"value":3425,"nodeType":457},{},[],"The attack paths have also expanded. Beyond phishing developers for take over Web Store accounts (the Cyberhaven playbook), attackers are buying existing extensions from developers, waiting for ownership transfers or abandonments to take over, and increasingly vibe-coding their own functional extensions from scratch to build an audience that can later be weaponized. The common thread is that ",{"data":3427,"content":3428,"nodeType":488},{"uri":2217},[3429],{"data":3430,"marks":3431,"value":3433,"nodeType":457},{},[3432],{"type":1528},"most malicious extensions didn't start out malicious",{"data":3435,"marks":3436,"value":3437,"nodeType":457},{},[]," — they started as legitimate tools and were turned into weapons after the fact.",{"data":3439,"content":3440,"nodeType":458},{},[3441],{"data":3442,"marks":3443,"value":3444,"nodeType":457},{},[],"None of this is happening in isolation. The threat landscape has reoriented around browser-based initial access and identity compromise — and the matrix needed to catch up.",{"data":3446,"content":3447,"nodeType":462},{},[],{"data":3449,"content":3450,"nodeType":472},{},[3451],{"data":3452,"marks":3453,"value":3455,"nodeType":457},{},[3454],{"type":470},"The evolution is playing out in public breaches",{"data":3457,"content":3458,"nodeType":458},{},[3459],{"data":3460,"marks":3461,"value":3462,"nodeType":457},{},[],"It’s worth reinforcing that when the SaaS matrix was first released, many of these attacks hadn’t been seen in the wild. The change today is staggering:",{"data":3464,"content":3465,"nodeType":1578},{},[3466,3487,3509,3529],{"data":3467,"content":3468,"nodeType":1489},{},[3469],{"data":3470,"content":3471,"nodeType":458},{},[3472,3476,3483],{"data":3473,"marks":3474,"value":3475,"nodeType":457},{},[],"When ",{"data":3477,"content":3479,"nodeType":488},{"uri":3478},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fscattered-lapsus-hunters\u002F",[3480],{"data":3481,"marks":3482,"value":487,"nodeType":457},{},[],{"data":3484,"marks":3485,"value":3486,"nodeType":457},{},[]," compromised over a thousand organizations' Salesforce tenants through device code phishing, the attack started with a phone call, moved through a browser-based authorization flow for the attacker’s app, and ended with mass data exfiltration via API.",{"data":3488,"content":3489,"nodeType":1489},{},[3490],{"data":3491,"content":3492,"nodeType":458},{},[3493,3497,3505],{"data":3494,"marks":3495,"value":3496,"nodeType":457},{},[],"When the same collective launched ",{"data":3498,"content":3500,"nodeType":488},{"uri":3499},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Funpacking-the-latest-slh-campaign\u002F",[3501],{"data":3502,"marks":3503,"value":3504,"nodeType":457},{},[],"AiTM phishing campaigns",{"data":3506,"marks":3507,"value":3508,"nodeType":457},{},[]," targeting Okta and Entra SSO, the phishing page was operated by a human in real time and delivered over a voice call — not email.",{"data":3510,"content":3511,"nodeType":1489},{},[3512],{"data":3513,"content":3514,"nodeType":458},{},[3515,3518,3525],{"data":3516,"marks":3517,"value":3475,"nodeType":457},{},[],{"data":3519,"content":3520,"nodeType":488},{"uri":3277},[3521],{"data":3522,"marks":3523,"value":3524,"nodeType":457},{},[],"APT29 deployed ConsentFix",{"data":3526,"marks":3527,"value":3528,"nodeType":457},{},[]," across dozens of compromised websites, the entire attack chain was browser-native, abusing a legitimate Microsoft OAuth flow to bypass MFA without proxying a single credential.",{"data":3530,"content":3531,"nodeType":1489},{},[3532],{"data":3533,"content":3534,"nodeType":458},{},[3535,3539,3547],{"data":3536,"marks":3537,"value":3538,"nodeType":457},{},[],"The ",{"data":3540,"content":3542,"nodeType":488},{"uri":3541},"https:\u002F\u002Fpushsecurity.com\u002Fblog\u002Fidentity-attacks-in-the-wild\u002F#id-snowflake-june-2024",[3543],{"data":3544,"marks":3545,"value":3546,"nodeType":457},{},[],"Snowflake breach",{"data":3548,"marks":3549,"value":3550,"nodeType":457},{},[]," — arguably the most consequential credential-based campaign of the past several years — saw 165 organizations breached using credentials that had been sitting in infostealer dumps for years, replayed against Snowflake tenants that lacked mandatory MFA. The attack surface wasn't Snowflake's application logic; it was the identity hygiene gap that every organization carries across hundreds of apps.",{"data":3552,"content":3553,"nodeType":458},{},[3554],{"data":3555,"marks":3556,"value":3557,"nodeType":457},{},[],"And that’s just the big picture. Every month we’re tracking new public breaches involving browser and identity TTPs — which again, are just the tip of the iceberg when you consider that many breaches are settled quietly without hitting the headlines. ",{"data":3559,"content":3560,"nodeType":458},{},[3561,3565,3570],{"data":3562,"marks":3563,"value":3564,"nodeType":457},{},[],"One of the key drivers here is the shrinking time-to-exploit. CrowdStrike's average e-crime breakout time is down to ",{"data":3566,"marks":3567,"value":3569,"nodeType":457},{},[3568],{"type":470},"29 minutes",{"data":3571,"marks":3572,"value":3573,"nodeType":457},{},[],", with the fastest recorded at 27 seconds. When attackers can move from initial access to data exfiltration within minutes, the window for post-compromise detection collapses to near zero. The best chance of stopping the attack is at the point of initial access before the identity is compromised.",{"data":3575,"content":3576,"nodeType":462},{},[],{"data":3578,"content":3579,"nodeType":472},{},[3580,3585,3591,3596,3602],{"data":3581,"marks":3582,"value":3584,"nodeType":457},{},[3583],{"type":470},"Sidenote: why we're looking at attacks ",{"data":3586,"marks":3587,"value":3590,"nodeType":457},{},[3588,3589],{"type":2051},{"type":470},"in",{"data":3592,"marks":3593,"value":3595,"nodeType":457},{},[3594],{"type":470}," the browser, not ",{"data":3597,"marks":3598,"value":3601,"nodeType":457},{},[3599,3600],{"type":2051},{"type":470},"on",{"data":3603,"marks":3604,"value":3606,"nodeType":457},{},[3605],{"type":470}," the browser",{"data":3608,"content":3609,"nodeType":458},{},[3610,3614,3622],{"data":3611,"marks":3612,"value":3613,"nodeType":457},{},[],"Calling this a \"browser attacks\" matrix needs clarification. We're not talking about browser exploits — RCE vulnerabilities, sandbox escapes, memory corruption bugs. Those attacks target the browser itself, they're extraordinarily expensive to develop, and they're increasingly rare. Browser zero-days hit a ",{"data":3615,"content":3617,"nodeType":488},{"uri":3616},"https:\u002F\u002Fcloud.google.com\u002Fblog\u002Ftopics\u002Fthreat-intelligence\u002F2025-zero-day-review",[3618],{"data":3619,"marks":3620,"value":3621,"nodeType":457},{},[],"historic low of 9%",{"data":3623,"marks":3624,"value":3625,"nodeType":457},{},[]," of all zero-days reported to Google, and a Chrome RCE commands a $250,000 bug bounty.",{"data":3627,"content":3628,"nodeType":458},{},[3629],{"data":3630,"marks":3631,"value":3632,"nodeType":457},{},[],"In comparison, a one-year phishing kit rental costs $1,000. A bulk stolen credential list costs $15. An initial-access-broker-provided IdP admin account costs $3,000. When it costs orders of magnitude less to exploit the person using the browser than to exploit the browser itself, attackers will take the cheaper option every time.",{"data":3634,"content":3635,"nodeType":458},{},[3636],{"data":3637,"marks":3638,"value":3639,"nodeType":457},{},[],"It's worth heading off the obvious counterargument: won't AI-assisted vulnerability discovery eventually make browser exploits cheaper? Perhaps — but it will simultaneously make them easier for browser vendors to find and patch, and vendors like Google and Microsoft have the engineering capacity and financial incentive to scale AI-driven remediation far faster than attackers can scale exploit development.",{"data":3641,"content":3642,"nodeType":462},{},[],{"data":3644,"content":3645,"nodeType":472},{},[3646],{"data":3647,"marks":3648,"value":3650,"nodeType":457},{},[3649],{"type":470},"What hasn't changed",{"data":3652,"content":3653,"nodeType":458},{},[3654,3658,3666],{"data":3655,"marks":3656,"value":3657,"nodeType":457},{},[],"The matrix remains open-source, community-maintained, and available on ",{"data":3659,"content":3661,"nodeType":488},{"uri":3660},"https:\u002F\u002Fgithub.com\u002Fpushsecurity\u002Fsaas-attacks",[3662],{"data":3663,"marks":3664,"value":3665,"nodeType":457},{},[],"GitHub",{"data":3667,"marks":3668,"value":3669,"nodeType":457},{},[],". The goal is the same as it was in 2023: to give offensive and defensive security teams a shared reference point for the techniques that matter most.",{"data":3671,"content":3672,"nodeType":458},{},[3673],{"data":3674,"marks":3675,"value":3676,"nodeType":457},{},[],"We built it because there was a gap in how the industry talked about these techniques, and that gap still exists — MITRE ATT&CK remains essential for endpoint and network TTPs, but the browser-based, identity-first techniques behind most modern breaches are still underrepresented in traditional frameworks.",{"data":3678,"content":3679,"nodeType":458},{},[3680],{"data":3681,"marks":3682,"value":3683,"nodeType":457},{},[],"We continue to maintain the matrix with input from red teams, detection engineers, and threat researchers across the community. Some of the most valuable additions over the past two years have come from practitioners who encountered a technique on an engagement or in an investigation and contributed it back to the repository.",{"data":3685,"content":3686,"nodeType":458},{},[3687,3691,3698],{"data":3688,"marks":3689,"value":3690,"nodeType":457},{},[],"If you're an offensive security professional using these techniques on engagements, or a defender building detections against them, we want to hear from you. Submit a PR, open a discussion, or flag a technique we've missed on ",{"data":3692,"content":3694,"nodeType":488},{"uri":3693},"https:\u002F\u002Fgithub.com\u002Fpushsecurity\u002Fbrowser-identity-attacks-matrix",[3695],{"data":3696,"marks":3697,"value":3665,"nodeType":457},{},[],{"data":3699,"marks":3700,"value":710,"nodeType":457},{},[],{"data":3702,"content":3703,"nodeType":462},{},[],{"data":3705,"content":3706,"nodeType":472},{},[3707],{"data":3708,"marks":3709,"value":3711,"nodeType":457},{},[3710],{"type":470},"Looking ahead",{"data":3713,"content":3714,"nodeType":458},{},[3715],{"data":3716,"marks":3717,"value":3718,"nodeType":457},{},[],"The pace of attacker innovation in browser-based initial access techniques over the past 18 months has been unlike anything we've tracked before — technique after technique moving from research curiosity to industrialized criminal tooling within months, not years.",{"data":3720,"content":3721,"nodeType":1578},{},[3722,3732,3742],{"data":3723,"content":3724,"nodeType":1489},{},[3725],{"data":3726,"content":3727,"nodeType":458},{},[3728],{"data":3729,"marks":3730,"value":3731,"nodeType":457},{},[],"AiTM platforms are adding authorization-based attack options alongside their credential-harvesting capabilities.",{"data":3733,"content":3734,"nodeType":1489},{},[3735],{"data":3736,"content":3737,"nodeType":458},{},[3738],{"data":3739,"marks":3740,"value":3741,"nodeType":457},{},[],"ClickFix has spawned fully browser-native variants.",{"data":3743,"content":3744,"nodeType":1489},{},[3745],{"data":3746,"content":3747,"nodeType":458},{},[3748],{"data":3749,"marks":3750,"value":3751,"nodeType":457},{},[],"AI is lowering the cost of producing convincing social engineering and phishing infrastructure at scale.",{"data":3753,"content":3754,"nodeType":458},{},[3755],{"data":3756,"marks":3757,"value":3758,"nodeType":457},{},[],"We don't see any of this slowing down, and that's exactly why thinking about these attacks as a browser problem instead of siloing them across email, endpoint, network, and cloud categories, each with a partial view of the picture (and still missing the whole when combined).",{"data":3760,"content":3761,"nodeType":458},{},[3762,3766,3773],{"data":3763,"marks":3764,"value":3765,"nodeType":457},{},[],"The Browser & Identity Attacks Matrix is our contribution to keeping that shared understanding current. You can ",{"data":3767,"content":3768,"nodeType":488},{"uri":3036},[3769],{"data":3770,"marks":3771,"value":3772,"nodeType":457},{},[],"explore the matrix here",{"data":3774,"marks":3775,"value":710,"nodeType":457},{},[],{"data":3777,"content":3778,"nodeType":458},{},[3779,3783,3791],{"data":3780,"marks":3781,"value":3782,"nodeType":457},{},[],"You can also read our recent ",{"data":3784,"content":3786,"nodeType":488},{"uri":3785},"https:\u002F\u002Fpushsecurity.com\u002Fthank-you\u002Fbrowser-attacks-report",[3787],{"data":3788,"marks":3789,"value":3790,"nodeType":457},{},[],"browser attack techniques report",{"data":3792,"marks":3793,"value":3794,"nodeType":457},{},[]," for more information.",{"data":3796,"content":3800,"nodeType":521},{"target":3797},{"sys":3798},{"id":3799,"type":518,"linkType":519},"1hx6sxpyEzxn4F4jc1RGQi",[],{"data":3802,"content":3803,"nodeType":462},{},[],{"data":3805,"content":3806,"nodeType":458},{},[3807],{"data":3808,"marks":3809,"value":3810,"nodeType":457},{},[],"Push Security is the most powerful AI-native security tool in the browser. Think EDR, but for the browser — high-fidelity telemetry and real-time control across every session, on every device, with no browser migration required. Security teams use Push to detect and stop advanced browser-based attacks like AiTM phishing, ClickFix, and session hijacking; gain visibility and control over AI tool usage across their workforce; harden identities by surfacing credential reuse, SSO gaps, and shadow IT; and support data loss and insider investigations with browser-layer telemetry that other tools can't see.",{"data":3812,"content":3813,"nodeType":458},{},[3814,3817,3823],{"data":3815,"marks":3816,"value":2514,"nodeType":457},{},[],{"data":3818,"content":3819,"nodeType":488},{"uri":2517},[3820],{"data":3821,"marks":3822,"value":2523,"nodeType":457},{},[],{"data":3824,"marks":3825,"value":2527,"nodeType":457},{},[],"Introducing the Browser & Identity Attacks Matrix","We're re-releasing the SaaS attack matrix as the Browser & Identity Attacks Matrix. Here's why we've decided to make the change and what it means.","2026-05-08T00:00:00.000Z","introducing-the-browser-and-identity-attacks-matrix",{"items":3831},[3832,3834],{"sys":3833,"name":2969},{"id":2968},{"sys":3835,"name":2973},{"id":2972},{"items":3837},[3838],{"fullName":439,"firstName":440,"jobTitle":441,"profilePicture":3839},{"url":445},"browser-threat-landscape-mid-year-update-2026","blog\u002Fbrowser-threat-landscape-mid-year-update-2026",{"json":3843},{"data":3844,"content":3845,"nodeType":1759},{},[3846],{"data":3847,"content":3848,"nodeType":458},{},[3849],{"data":3850,"marks":3851,"value":3852,"nodeType":457},{},[],"PhaaS industrialization, Scattered Spider copycats, and AI-augmented tooling — what the threat landscape looks like in 2026 so far.",{"id":3854,"publishedAt":3855},"vLb3RhwYt7Xc6mkX3pWyI","2026-08-26T11:56:53.261Z",{"items":3857},[3858,3860],{"sys":3859,"name":2969},{"id":2968},{"sys":3861,"name":2973},{"id":2972},{"items":3863},[3864,3869,3874,3879,3884,3889,3894,3899,3904,3909,3914,3918,3923,3928,3933,3938,3942,3947,3952,3957,3962,3967,3972,3976,3981],{"sys":3865,"name":3867,"slug":3868,"tier":45},{"id":3866},"topic-ai-attacks","AI attacks","ai-attacks",{"sys":3870,"name":3872,"slug":3873,"tier":45},{"id":3871},"topic-public-breach","Public breach","public-breach",{"sys":3875,"name":3877,"slug":3878,"tier":45},{"id":3876},"topic-legitimate-service-abuse","Legitimate service abuse","legitimate-service-abuse",{"sys":3880,"name":3882,"slug":3883,"tier":45},{"id":3881},"topic-bec","BEC","bec",{"sys":3885,"name":3887,"slug":3888,"tier":45},{"id":3886},"topic-ransomware","Ransomware","ransomware",{"sys":3890,"name":3892,"slug":3893,"tier":45},{"id":3891},"topic-vishing","Vishing","vishing",{"sys":3895,"name":3897,"slug":3898,"tier":45},{"id":3896},"topic-social-engineering","Social engineering","social-engineering",{"sys":3900,"name":3902,"slug":3903,"tier":45},{"id":3901},"topic-malware-delivery","Malware delivery","malware-delivery",{"sys":3905,"name":3907,"slug":3908,"tier":45},{"id":3906},"topic-infostealer","Infostealer","infostealer",{"sys":3910,"name":3912,"slug":3913,"tier":45},{"id":3911},"topic-identity-attacks","Identity attacks","identity-attacks",{"sys":3915,"name":313,"slug":3917,"tier":45},{"id":3916},"topic-session-hijacking","session-hijacking",{"sys":3919,"name":3921,"slug":3922,"tier":45},{"id":3920},"topic-passkeys","Passkeys","passkeys",{"sys":3924,"name":3926,"slug":3927,"tier":45},{"id":3925},"topic-mfa-bypass","MFA bypass","mfa-bypass",{"sys":3929,"name":3931,"slug":3932,"tier":45},{"id":3930},"topic-malvertising","Malvertising","malvertising",{"sys":3934,"name":3936,"slug":3937,"tier":45},{"id":3935},"topic-seo-poisoning","SEO poisoning","seo-poisoning",{"sys":3939,"name":269,"slug":3941,"tier":45},{"id":3940},"topic-device-code-phishing","device-code-phishing",{"sys":3943,"name":3945,"slug":3946,"tier":45},{"id":3944},"topic-non-email-phishing","Non-email phishing","non-email-phishing",{"sys":3948,"name":3950,"slug":3951,"tier":45},{"id":3949},"topic-phaas","PhaaS","phaas",{"sys":3953,"name":3955,"slug":3956,"tier":45},{"id":3954},"topic-credential-phishing","Credential phishing","credential-phishing",{"sys":3958,"name":3960,"slug":3961,"tier":45},{"id":3959},"topic-clickfix","ClickFix","clickfix",{"sys":3963,"name":3965,"slug":3966,"tier":45},{"id":3964},"topic-aitm","AiTM phishing","aitm",{"sys":3968,"name":3970,"slug":3971,"tier":31},{"id":3969},"topic-threat-landscape","Threat landscape","threat-landscape",{"sys":3973,"name":254,"slug":3975,"tier":31},{"id":3974},"topic-phishing","phishing",{"sys":3977,"name":3979,"slug":3980,"tier":31},{"id":3978},"topic-saas-security","SaaS security","saas-security",{"sys":3982,"name":3984,"slug":3985,"tier":31},{"id":3983},"topic-browser-attacks","Browser attacks","browser-attacks","s-m4f3m6SWAIErhOTXNAHECtIUwlHBoZ_uFaPQsee20",{"id":3988,"extension":1849,"items":3989,"meta":4334,"stem":4335,"__hash__":4336},"blogTopics\u002Fblogtopics.json",[3990,3999,4005,4014,4020,4026,4032,4041,4049,4058,4064,4070,4078,4086,4095,4101,4110,4119,4128,4136,4142,4151,4157,4163,4168,4174,4183,4189,4195,4204,4209,4218,4224,4230,4236,4241,4247,4255,4261,4267,4275,4283,4291,4296,4304,4313,4322,4328],{"sys":3991,"faqItemsCollection":3993,"name":3995,"slug":3996,"tier":31,"intro":3997,"faqTitle":59,"postCount":3998,"hasPage":19},{"id":3992},"topic-ai",{"items":3994},[],"AI","ai","AI is reshaping both sides of the security equation: employees adopt AI tools faster than security teams can track them, while attackers use AI to scale and automate campaigns. Shadow AI adoption may now outpace wider shadow SaaS, and attackers are already turning AI chatbot platforms into malware delivery channels. Push has researched the offensive potential of computer-using agents and now applies AI agents to its own threat hunting. This hub covers AI as risk, target, and defensive tool.",22,{"sys":4000,"faqItemsCollection":4001,"name":3867,"slug":3868,"tier":45,"intro":4003,"faqTitle":59,"postCount":4004,"hasPage":19},{"id":3866},{"items":4002},[],"AI attacks run in both directions: attackers using AI to scale phishing, malware delivery, and identity attacks, and AI platforms themselves becoming the attack surface. Push has researched how computer-using agents can automate identity attacks, and has seen the poisoned tenant technique it coined used against its own employees in the wild.",23,{"sys":4006,"faqItemsCollection":4008,"name":4010,"slug":4011,"tier":45,"intro":4012,"faqTitle":59,"postCount":4013,"hasPage":19},{"id":4007},"topic-ai-governance",{"items":4009},[],"AI governance","ai-governance","AI governance is how organizations set and enforce rules for workplace AI use — which tools are allowed, what data can enter them, and how to evidence it to regulators. With US, EU, and UK AI regulations converging on obligations most organizations can’t yet meet, Push’s research makes the case that enforcement starts in the browser, where AI tools are actually used.",9,{"sys":4015,"faqItemsCollection":4016,"name":3965,"slug":3966,"tier":45,"intro":4018,"faqTitle":59,"postCount":4019,"hasPage":19},{"id":3964},{"items":4017},[],"Adversary-in-the-middle (AiTM) phishing proxies a real login page through an attacker-controlled site, capturing credentials, MFA codes, and session tokens in real time to bypass multi-factor authentication. Push’s research into kits like Evilginx and Sneaky2FA documents how they evade URL- and signature-based detection — and why analyzing toolkit behavior in the browser catches attacks that blocklists miss.",78,{"sys":4021,"faqItemsCollection":4022,"name":3882,"slug":3883,"tier":45,"intro":4024,"faqTitle":59,"postCount":4025,"hasPage":6},{"id":3881},{"items":4023},[],"Business email compromise (BEC) turns a hijacked mailbox into a fraud tool: attackers use mail rules, auto-forwarding, and payment redirection to steal money while staying invisible to the account owner. Alongside a first-hand case study of a BEC attack that nearly cost an engineering firm millions, Push breaks down these mailbox persistence tricks and how to detect them.",4,{"sys":4027,"faqItemsCollection":4028,"name":3984,"slug":3985,"tier":31,"intro":4030,"faqTitle":59,"postCount":4031,"hasPage":19},{"id":3983},{"items":4029},[],"Browser attacks target users through the web pages, sessions, and extensions they rely on every day — bypassing endpoint and network defenses that never see inside the browser. Techniques like AiTM phishing kits, ClickFix-style copy-paste attacks, OAuth consent abuse, malvertising, and browser sync abuse have become a leading path to account takeover. Push researchers analyze these attacks in the wild, from infiltrating criminal phishing panels to dissecting toolkits like ConsentFix and Sneaky2FA. Use this hub to track how the techniques evolve and how to defend against them.",122,{"sys":4033,"faqItemsCollection":4035,"name":4037,"slug":4038,"tier":45,"intro":4039,"faqTitle":59,"postCount":4040,"hasPage":19},{"id":4034},"topic-browser-extensions",{"items":4036},[],"Browser extensions","browser-extensions","Browser extensions cut both ways for security teams: malicious or compromised extensions are a growing attack vector, while an extension is also the lightest-weight way to deploy security controls into the browsers employees already use. These posts cover both sides — extension-borne risks like browser sync attacks and the limits of risk scoring, and how Push uses its extension to detect threats and block risky extensions.",31,{"sys":4042,"faqItemsCollection":4044,"name":2541,"slug":4046,"tier":31,"intro":4047,"faqTitle":59,"postCount":4048,"hasPage":19},{"id":4043},"topic-browser-security",{"items":4045},[],"browser-security","Work now happens in the browser, making browser security — visibility and control at the point where users meet the web — a core layer of enterprise defense. Endpoint, network, and email tools miss attacks that unfold inside the browser session, from AiTM phishing to risky extensions and shadow SaaS. Push has published extensively on choosing between enterprise browsers and browser extensions, using browser telemetry, and making the business case for browser security. Start here for both strategy and hands-on guidance.",129,{"sys":4050,"faqItemsCollection":4052,"name":4054,"slug":4055,"tier":45,"intro":4056,"faqTitle":59,"postCount":4057,"hasPage":19},{"id":4051},"topic-casb",{"items":4053},[],"CASB","casb","Cloud access security brokers (CASBs) govern cloud app usage through API integrations and network proxies — an approach that works for sanctioned apps but struggles with the long tail of shadow SaaS employees adopt on their own. Because every SaaS signup happens in a browser, Push captures that adoption in real time at the point of login, and these posts cover what proxy-based discovery misses.",12,{"sys":4059,"faqItemsCollection":4060,"name":3960,"slug":3961,"tier":45,"intro":4062,"faqTitle":59,"postCount":4063,"hasPage":19},{"id":3959},{"items":4061},[],"ClickFix attacks trick users into copying and running malicious commands themselves — typically through fake CAPTCHA, error, or fix-it prompts — so malware executes without a download for security tools to scan. Push researchers track the technique’s evolution in the wild and identified the ConsentFix and InstallFix variants, which extend it to OAuth consent grants and fake install guides.",40,{"sys":4065,"faqItemsCollection":4066,"name":3955,"slug":3956,"tier":45,"intro":4068,"faqTitle":59,"postCount":4069,"hasPage":19},{"id":3954},{"items":4067},[],"Credential phishing steals usernames and passwords through fake login pages impersonating the services employees use, handing attackers direct access to corporate accounts. Attackers don’t hack in — they log in. Push’s browser extension analyzes login pages as users actually see them, blocking cloned pages and stopping employees from entering company passwords on lookalike sites.",90,{"sys":4071,"faqItemsCollection":4073,"name":308,"slug":4075,"tier":45,"intro":4076,"faqTitle":59,"postCount":4077,"hasPage":19},{"id":4072},"topic-credential-stuffing",{"items":4074},[],"credential-stuffing","Credential stuffing is an attack where criminals replay username-password pairs stolen from one breach against other services, exploiting password reuse to take over accounts. Major breaches have shown how far a single set of stolen credentials can travel. Push detects verified stolen credentials by comparing employee passwords against breach datasets and dark-web threat intelligence, eliminating false positives.",64,{"sys":4079,"faqItemsCollection":4081,"name":2973,"slug":4083,"tier":31,"intro":4084,"faqTitle":59,"postCount":4085,"hasPage":19},{"id":4080},"topic-detection-and-response",{"items":4082},[],"detection-and-response","Detection and response is being reshaped as attacks move into the browser, where EDR, SIEM, and network tools have limited visibility. Modern phishing kits evade signature-based detection, and most malicious pages have never been seen before — so technique-level, in-browser detection matters more than known-bad indicators. Push’s work here spans high-fidelity browser telemetry, session token theft detection, and agentic threat hunting, plus practical IR guidance for compromised SaaS accounts and malicious OAuth apps. These posts cover both the philosophy and the workflows.",102,{"sys":4087,"faqItemsCollection":4089,"name":4091,"slug":4092,"tier":45,"intro":4093,"faqTitle":59,"postCount":4094,"hasPage":19},{"id":4088},"topic-detection-engineering",{"items":4090},[],"Detection engineering","detection-engineering","Detection engineering turns threat research into reliable, high-fidelity detections — and as AI accelerates the churn of attacker infrastructure, indicator-based detection is collapsing in favor of technique-level approaches. Here you’ll find teardowns of AiTM kits, ClickFix pages, and malvertising campaigns, alongside Push’s own account of building an agentic threat hunting pipeline that turns hunts into shipped detections.",43,{"sys":4096,"faqItemsCollection":4097,"name":269,"slug":3941,"tier":45,"intro":4099,"faqTitle":59,"postCount":4100,"hasPage":19},{"id":3940},{"items":4098},[],"Device code phishing abuses the OAuth device authorization flow: attackers generate a legitimate sign-in code, trick the victim into entering it on the vendor’s real login page, and walk away with access tokens — no fake site or password capture required. Push research tracked a sharp spike in adoption during 2026 as attackers use the technique to sidestep standard access controls.",24,{"sys":4102,"faqItemsCollection":4104,"name":4106,"slug":4107,"tier":45,"intro":4108,"faqTitle":59,"postCount":4109,"hasPage":19},{"id":4103},"topic-dlp",{"items":4105},[],"DLP","dlp","Data loss prevention (DLP) is the practice of stopping sensitive data from leaving your control — a problem that has shifted from email and endpoints to the browser, where employees move data into SaaS and AI tools. Push applies controls at that point of use, from keeping corporate credentials out of personal password managers to governing what flows into unsanctioned apps.",15,{"sys":4111,"faqItemsCollection":4113,"name":4115,"slug":4116,"tier":45,"intro":4117,"faqTitle":59,"postCount":4118,"hasPage":19},{"id":4112},"topic-edr",{"items":4114},[],"EDR","edr","Endpoint detection and response (EDR) watches processes, files, and memory on the device — a vantage point that never sees the phishing pages, stolen sessions, and identity attacks playing out inside the browser. That’s not an EDR failure; attackers have simply moved where it can’t follow. These posts map that gap and show how Push pairs browser-level detection and response with endpoint security to close it.",25,{"sys":4120,"faqItemsCollection":4122,"name":4124,"slug":4125,"tier":45,"intro":4126,"faqTitle":59,"postCount":4127,"hasPage":19},{"id":4121},"topic-enterprise-browser",{"items":4123},[],"Enterprise browser","enterprise-browser","An enterprise browser is a standalone, security-hardened browser that organizations deploy in place of Chrome, Edge, or other defaults. The real buying question is whether replacing the browser beats securing the browsers employees already use — a trade-off these posts examine directly, alongside analysis of Omdia’s secure enterprise browser market report and Push’s framework for weighing full browsers against extension-based deployment.",8,{"sys":4129,"faqItemsCollection":4131,"name":298,"slug":4133,"tier":45,"intro":4134,"faqTitle":59,"postCount":4135,"hasPage":19},{"id":4130},"topic-ghost-logins",{"items":4132},[],"ghost-logins","Ghost logins are overlooked authentication routes into an account — like a password login lingering behind SSO, or a forgotten secondary auth method — that attackers exploit for account takeover and persistence. Push coined the term after research showing how these forgotten login paths let attackers sidestep the MFA and SSO controls guarding an account’s primary sign-in method.",48,{"sys":4137,"faqItemsCollection":4138,"name":3912,"slug":3913,"tier":45,"intro":4140,"faqTitle":59,"postCount":4141,"hasPage":19},{"id":3911},{"items":4139},[],"Identity attacks target user accounts rather than infrastructure — phishing credentials, stealing sessions, abusing OAuth grants — because logging in is easier than hacking in. Identity-based techniques are now the leading cause of breaches. Push’s offensive research maps these techniques continuously, coining attacks like SAMLjacking and the poisoned tenant before they appeared in the wild.",58,{"sys":4143,"faqItemsCollection":4145,"name":4147,"slug":4148,"tier":31,"intro":4149,"faqTitle":59,"postCount":4150,"hasPage":19},{"id":4144},"topic-identity-security",{"items":4146},[],"Identity security","identity-security","Identity security is the practice of protecting workforce accounts, credentials, and sessions — the primary route attackers now use to breach organizations. Instead of hacking in, attackers log in: through phished credentials, stolen session tokens, MFA bypass, and forgotten ghost logins. Push’s research team documents these techniques continuously, from cross-IdP impersonation and SAMLjacking to analyses of major identity-driven breaches. This hub collects that research alongside practical guidance on MFA, SSO, and stopping account takeover.",154,{"sys":4152,"faqItemsCollection":4153,"name":3907,"slug":3908,"tier":45,"intro":4155,"faqTitle":59,"postCount":4156,"hasPage":19},{"id":3906},{"items":4154},[],"Infostealers are malware built to harvest saved passwords, cookies, and session tokens from infected devices, supplying the stolen credentials behind some of the most consequential breaches of recent years. Push traces the ecosystem trading this data and checks employee passwords against threat intel feeds, flagging verified stolen credentials before attackers can log in with them.",53,{"sys":4158,"faqItemsCollection":4159,"name":3877,"slug":3878,"tier":45,"intro":4161,"faqTitle":59,"postCount":4162,"hasPage":19},{"id":3876},{"items":4160},[],"Legitimate service abuse means staging attacks on trusted platforms — Google Ads, AI chatbot share pages, office.com links, Slack, SaaS tenants — so malicious content inherits the reputation of the service hosting it. Push research has documented the pattern repeatedly, from malvertising run through hijacked Google Ad Manager accounts to phishing links generated by Active Directory Federation Services.",29,{"sys":4164,"faqItemsCollection":4165,"name":3931,"slug":3932,"tier":45,"intro":4167,"faqTitle":59,"postCount":4040,"hasPage":19},{"id":3930},{"items":4166},[],"Malvertising uses paid search and display ads to put phishing pages and malware in front of users, often by impersonating trusted brands at the top of Google results. Push tracks these campaigns continuously — intercepting live attacks spoofing well-known brands — and has documented how criminals hijack Google Ads accounts to fund and run them.",{"sys":4169,"faqItemsCollection":4170,"name":3902,"slug":3903,"tier":45,"intro":4172,"faqTitle":59,"postCount":4173,"hasPage":19},{"id":3901},{"items":4171},[],"Malware delivery has moved into the browser: rather than email attachments, attackers now rely on malvertising, fake install guides, and ClickFix-style copy-paste lures to get code running on endpoints. Push research on techniques like InstallFix maps the playbook, and in-browser detection of malicious copy and paste blocks these attacks before commands reach the endpoint.",14,{"sys":4175,"faqItemsCollection":4177,"name":4179,"slug":4180,"tier":45,"intro":4181,"faqTitle":59,"postCount":4182,"hasPage":19},{"id":4176},"topic-mfa",{"items":4178},[],"MFA","mfa","Multi-factor authentication (MFA) requires a second proof of identity beyond a password, and it remains one of the most effective controls against account takeover. Regulators from Cyber Essentials to NYDFS now mandate it across cloud services. Push enforces MFA in the browser on third-party apps — even those with no native enforcement option — and shows security teams where coverage gaps remain.",83,{"sys":4184,"faqItemsCollection":4185,"name":3926,"slug":3927,"tier":45,"intro":4187,"faqTitle":59,"postCount":4188,"hasPage":19},{"id":3925},{"items":4186},[],"MFA bypass covers the techniques attackers use to defeat multi-factor authentication — AiTM phishing kits, consent phishing, device code phishing, and MFA downgrade attacks among them. None of these break the second factor; they route around it. Push researchers regularly get hands-on with phishing kits like Evilginx and Sneaky2FA, analyzing how these attacks work in the wild and how they evolve.",60,{"sys":4190,"faqItemsCollection":4191,"name":3945,"slug":3946,"tier":45,"intro":4193,"faqTitle":59,"postCount":4194,"hasPage":19},{"id":3944},{"items":4192},[],"Non-email phishing delivers malicious links through channels your secure email gateway never sees — social media messages, IM apps like Slack and Teams, search ads, and SMS. Push has intercepted live campaigns arriving via LinkedIn DMs, malvertising, and messaging platforms, which is why it detects phishing pages in the browser at the point of click, regardless of delivery channel.",52,{"sys":4196,"faqItemsCollection":4198,"name":4200,"slug":4201,"tier":45,"intro":4202,"faqTitle":59,"postCount":4203,"hasPage":19},{"id":4197},"topic-oauth-abuse",{"items":4199},[],"OAuth abuse","oauth-abuse","OAuth abuse is attackers exploiting app-to-app authorization — consent phishing, malicious OAuth apps, stolen tokens, and device code flows — to gain persistent access to cloud tenants without touching a password or MFA prompt. Push tracks these techniques continuously and discovered ConsentFix, a browser-native attack in the wild that pairs OAuth consent phishing with a ClickFix-style prompt.",70,{"sys":4205,"faqItemsCollection":4206,"name":3921,"slug":3922,"tier":45,"intro":4208,"faqTitle":59,"postCount":4004,"hasPage":19},{"id":3920},{"items":4207},[],"Passkeys are phishing-resistant credentials that replace passwords with cryptographic key pairs bound to a user’s device. They defeat conventional credential phishing, but attackers adapt: Push research has documented MFA downgrade, app-specific password phishing, and device code phishing being used in the wild to route around passkey-protected accounts. Deploying passkeys is step one; closing those fallback paths is step two.",{"sys":4210,"faqItemsCollection":4212,"name":4214,"slug":4215,"tier":45,"intro":4216,"faqTitle":59,"postCount":4217,"hasPage":19},{"id":4211},"topic-password-security",{"items":4213},[],"Password security","password-security","Password security is the practice of keeping workforce credentials strong, unique, and out of attackers’ hands — still a frontline defense while most SaaS logins depend on passwords. Expiration policies don’t fix weak or reused passwords; visibility does. Push observes real logins in the browser to flag weak, reused, and breached passwords and guide employees to reset them on any app.",80,{"sys":4219,"faqItemsCollection":4220,"name":3950,"slug":3951,"tier":45,"intro":4222,"faqTitle":59,"postCount":4223,"hasPage":19},{"id":3949},{"items":4221},[],"Phishing-as-a-service (PhaaS) platforms sell ready-made phishing kits, hosted infrastructure, and management panels on subscription, letting low-skill criminals run MFA-bypassing campaigns at scale. Kits like Evilginx, Tycoon2FA, Sneaky2FA, FlowerStorm, and EvilTokens each add their own evasion and session-theft capabilities, and new entrants appear regularly. Push researchers continuously get hands-on with these tools — investigating attacks in the wild, reverse-engineering kit behavior, and turning that research into detections.",41,{"sys":4225,"faqItemsCollection":4226,"name":254,"slug":3975,"tier":31,"intro":4228,"faqTitle":59,"postCount":4229,"hasPage":19},{"id":3974},{"items":4227},[],"Phishing remains the most common way attackers compromise business accounts — and it has moved far beyond suspicious emails. Modern campaigns use AiTM toolkits that bypass MFA, consent phishing against OAuth, device code phishing, and lures delivered through malvertising, LinkedIn, and Slack. Push detects and blocks these attacks in the browser, and its researchers publish teardowns of live campaigns and kits like Evilginx and Sneaky2FA. Read on for how phishing actually works today and what stops it.",93,{"sys":4231,"faqItemsCollection":4232,"name":3872,"slug":3873,"tier":45,"intro":4234,"faqTitle":59,"postCount":4235,"hasPage":19},{"id":3871},{"items":4233},[],"Public breaches are the disclosed incidents that show how attacks actually unfold once the headlines fade. Push’s breach analyses keep finding identity at the entry point: stolen credentials, OAuth abuse, and missing MFA recur across the incidents analyzed here.",30,{"sys":4237,"faqItemsCollection":4238,"name":3887,"slug":3888,"tier":45,"intro":4240,"faqTitle":59,"postCount":4173,"hasPage":19},{"id":3886},{"items":4239},[],"Ransomware attacks increasingly begin with an identity, not an exploit: stolen credentials, MFA bypass, and help desk scams give operators their initial foothold. The analysis here follows that front end of the kill chain — how identity compromise leads to ransomware deployment, and the breaches driving regulators toward tighter MFA requirements.",{"sys":4242,"faqItemsCollection":4243,"name":3979,"slug":3980,"tier":31,"intro":4245,"faqTitle":59,"postCount":4246,"hasPage":19},{"id":3978},{"items":4244},[],"SaaS security means protecting the sprawl of cloud apps, accounts, and integrations your employees adopt — often without IT ever knowing. Shadow SaaS, risky OAuth grants, ghost logins, and unmanaged third-party access create attack paths traditional controls can’t see, as recent high-profile breaches have demonstrated. Building on the original SaaS attack matrix, Push continues to map SaaS-native attack techniques alongside practical guides for discovering and securing unsanctioned apps, and this hub gathers all of it.",97,{"sys":4248,"faqItemsCollection":4250,"name":4252,"slug":4253,"tier":45,"intro":4254,"faqTitle":59,"postCount":4025,"hasPage":6},{"id":4249},"topic-security-training",{"items":4251},[],"Security training","security-training","Security training aims to teach employees to recognize and avoid attacks — yet modern phishing routinely fools even seasoned security professionals. Push argues that training budgets work harder as real-time, in-browser intervention: guardrails and warnings at the moment of risk, rather than lessons employees must recall under pressure.",{"sys":4256,"faqItemsCollection":4257,"name":3936,"slug":3937,"tier":45,"intro":4259,"faqTitle":59,"postCount":4260,"hasPage":19},{"id":3935},{"items":4258},[],"SEO poisoning manipulates search engine results so malicious pages rank prominently for the software, tools, or services users are actively searching for, turning a routine search into an infection vector. It often pairs with malvertising and ClickFix-style payloads — Push has documented attackers abusing shared pages on legitimate AI chatbot domains to deliver malware from trusted infrastructure.",7,{"sys":4262,"faqItemsCollection":4263,"name":313,"slug":3917,"tier":45,"intro":4265,"faqTitle":59,"postCount":4266,"hasPage":19},{"id":3916},{"items":4264},[],"Session hijacking is the theft of an authenticated session — usually via stolen session cookies or tokens — letting attackers walk past passwords and MFA into a live account. AiTM phishing kits and infostealers have made it a mainstream attack technique across both criminal and targeted intrusions. Push’s browser agent detects session token theft by adding telemetry to the user agent string, creating a high-fidelity signal for security teams.",75,{"sys":4268,"faqItemsCollection":4270,"name":2488,"slug":4272,"tier":45,"intro":4273,"faqTitle":59,"postCount":4274,"hasPage":19},{"id":4269},"topic-shadow-ai",{"items":4271},[],"shadow-ai","Shadow AI is employees’ unsanctioned use of AI tools at work, putting corporate data into chatbots and assistants that security teams never approved and can’t see. Push’s own browser telemetry shows AI adoption acting as a force multiplier for shadow IT — potentially now outscaling shadow SaaS — and this hub tracks that research, real-world breach examples, and practical controls.",20,{"sys":4276,"faqItemsCollection":4278,"name":4280,"slug":4281,"tier":45,"intro":4282,"faqTitle":59,"postCount":4266,"hasPage":19},{"id":4277},"topic-shadow-saas",{"items":4279},[],"Shadow SaaS","shadow-saas","Shadow SaaS is the cloud applications employees adopt for work without IT approval, each one creating unmanaged accounts, identities, and data outside your security controls. Push covers the problem end to end — from browser-based SaaS discovery to in-browser app banners and MFA enforcement — alongside breach analyses that show where unmanaged accounts lead.",{"sys":4284,"faqItemsCollection":4286,"name":4288,"slug":4289,"tier":45,"intro":4290,"faqTitle":59,"postCount":4274,"hasPage":19},{"id":4285},"topic-siem",{"items":4287},[],"SIEM","siem","A SIEM is only as good as the telemetry feeding it, and most log sources never see what happens inside the browser — where phishing, session token theft, and account takeover actually play out. Push streams browser-level detections and identity telemetry into SIEMs, and these posts show how that data improves detection fidelity and cuts alert fatigue.",{"sys":4292,"faqItemsCollection":4293,"name":3897,"slug":3898,"tier":45,"intro":4295,"faqTitle":59,"postCount":4188,"hasPage":19},{"id":3896},{"items":4294},[],"Social engineering is the manipulation of people — through phishing pages, help desk impersonation, vishing calls, and poisoned tenant invites — into handing over access that no exploit could take. Coverage here tracks how threat actors run these plays — drawing on Push’s ongoing investigation of live phishing infrastructure and criminal tooling.",{"sys":4297,"faqItemsCollection":4299,"name":4301,"slug":4302,"tier":31,"intro":4303,"faqTitle":59,"postCount":4025,"hasPage":6},{"id":4298},"topic-supply-chain-security",{"items":4300},[],"Supply chain security","supply-chain-security","Supply chain security extends beyond your own perimeter to the vendors, platforms, and browser extensions your organization depends on. A compromised third party can hand attackers legitimate access — as recent campaigns against SaaS providers have shown. Push’s research examines the browser-extension supply chain in particular: why extension risk scores fail to predict compromise, and how developers can harden extensions against takeover. These posts frame supply chain risk through a browser and identity lens.",{"sys":4305,"faqItemsCollection":4307,"name":4309,"slug":4310,"tier":45,"intro":4311,"faqTitle":59,"postCount":4312,"hasPage":19},{"id":4306},"topic-swg",{"items":4308},[],"SWG","swg","A secure web gateway (SWG) filters and inspects web traffic in transit, sitting in the network path between users and the internet. That position shows you the packet but not the session: Push’s research on AitM phishing kits documents how attackers break the signatures proxies rely on, and these posts explain why phishing detection is moving from the network path into the browser itself.",18,{"sys":4314,"faqItemsCollection":4316,"name":4318,"slug":4319,"tier":45,"intro":4320,"faqTitle":59,"postCount":4321,"hasPage":19},{"id":4315},"topic-third-party-risk",{"items":4317},[],"Third-party risk","third-party-risk","Third-party risk is the exposure your organization inherits from vendors, SaaS providers, and integrations that hold your data or access your tenants — a chain now extended one employee sign-up at a time. This hub collects Push’s breach analyses and guides for assessing OAuth integrations, managing browser extensions, and responding when a supplier is compromised.",44,{"sys":4323,"faqItemsCollection":4324,"name":3970,"slug":3971,"tier":31,"intro":4326,"faqTitle":59,"postCount":4327,"hasPage":19},{"id":3969},{"items":4325},[],"The enterprise threat landscape is now defined by identity attacks: criminals log in with phished, stolen, or stuffed credentials rather than breaking infrastructure. Threat actors keep proving how effective help desk scams, MFA bypass, and session theft are against well-defended organizations. Drawing on breach analyses, annual phishing trend reviews, and in-the-wild campaign tracking, Push documents how attacker TTPs are shifting. This hub is where to follow those changes.",49,{"sys":4329,"faqItemsCollection":4330,"name":3892,"slug":3893,"tier":45,"intro":4332,"faqTitle":59,"postCount":4333,"hasPage":19},{"id":3891},{"items":4331},[],"Vishing — voice phishing — uses phone calls to impersonate IT support, help desks, or employees, talking targets into password resets, MFA approvals, or opening attacker-controlled pages. Threat actors now routinely pair calls with AiTM phishing to hijack SSO accounts, a chain Push has analyzed across campaigns targeting hundreds of organizations.",16,{},"blogtopics","9aR-7_LhDkRRXRaED83WYgKvhxkN_ODLJNuDH339OG0",1789500287651]