[{"data":1,"prerenderedAt":2134},["ShallowReactive",2],{"application-flags":3,"navbar":7,"always-visible-banner":36,"navbar-about-highlight":108,"navbar-resource-highlight":182,"trust-badges":226,"solution-nav":247,"fa-icon-sharp-regular-faFishingRod":387,"fa-icon-solid-faUserSecret":391,"fa-icon-sharp-regular-faLaptopCode":393,"fa-icon-solid-faTabletScreenButton":395,"fa-icon-solid-faThumbsUp":397,"fa-icon-solid-faPlugCircleXmark":399,"fa-icon-sharp-regular-faPuzzlePiece":401,"fa-icon-solid-faFileCircleXmark":403,"fa-icon-solid-faGhost":406,"fa-icon-solid-faQrcode":409,"fa-icon-solid-faCookieBite":411,"fa-icon-sharp-regular-faUserSecret":413,"fa-icon-sharp-regular-faRadar":415,"fa-icon-sharp-regular-faSatelliteDish":417,"fa-icon-sharp-regular-faShieldCheck":419,"fa-icon-sharp-regular-faBrainCircuit":421,"fa-icon-solid-faMobileScreenButton":423,"fa-icon-brands-faChrome":425,"fa-icon-solid-faDisplay":427,"fa-icon-solid-faFilter":429,"fa-icon-solid-faCloudArrowUp":431,"blog\u002Fproduct-release-july-2026":433,"blog-topics":1721},[4],{"name":5,"enabled":6},"maintenanceMode",false,[8],{"createdDate":9,"id":10,"name":11,"modelId":12,"published":13,"meta":14,"query":22,"data":23,"variations":28,"lastUpdated":29,"firstPublished":30,"testRatio":31,"createdBy":32,"lastUpdatedBy":33,"folders":34,"rev":35},1742208588866,"1c7a4e423bf54ac1a328bb4063459ef2","Banner","1c6207a5f24948ab82d4a0b17f251193","published",{"breakpoints":15,"hasAutosaves":19,"kind":20,"lastPreviewUrl":21},{"medium":16,"small":17,"xsmall":18},768,640,320,true,"data","",[],{"link":24,"text":25,"type":26,"url":27},{},"Get our latest report analyzing browser attack techniques in 2026","web-banner","https:\u002F\u002Fpushsecurity.com\u002Fresources\u002Fbrowser-attacks-report",{},1774258294825,1742208637545,1,"CydmZnOWU1XuAaLhEDCoYNM4Z8W2","jKjF9r5jcvXU8tzZEfFQm31Iyvr2",[],"brvjc1sslx8",{"createdBy":37,"createdDate":38,"data":39,"folders":94,"id":95,"lastUpdated":96,"lastUpdatedBy":97,"meta":98,"modelId":102,"name":103,"published":13,"query":104,"testRatio":31,"variations":105,"firstPublished":106,"stageModifiedSincePublish":6,"rev":107},"ST0tXQM8slWpFrmioqKHmENB2qe2",1774965361051,{"ctaText":40,"text":41,"url":21,"blocks":42,"state":90},"ewrererw","testrfesssssssssss",[43,70,78],{"@type":44,"@version":45,"id":46,"component":47,"responsiveStyles":60},"@builder.io\u002Fsdk:Element",2,"builder-ca12c06a52de41d7b8743da53118cd38",{"name":48,"tag":48,"options":49,"isRSC":59},"TopBannerContent",{"text":50,"ctaText":51,"url":52,"mainText":53,"cta":56},"New Webinar Series: Join John Hammond, Troy Hunt, and Matt Johansen for the State of Browser Attacks","Save Your Spot","https:\u002F\u002Fpushsecurity.com\u002Fwebinar\u002Fstate-of-browser-security",{"content":54,"fontSize":55},"\u003Cp class=\"\">Employees using shadow AI tools? Push blocks them in the browser and enforces your AI policy.\u003C\u002Fp>","text-base",{"content":57,"fontSize":55,"url":58},"\u003Cp class=\"\">Get a free trial →\u003C\u002Fp>","https:\u002F\u002Fpushsecurity.com\u002Flp\u002Fshadow-ai-trial",null,{"large":61},{"display":62,"flexDirection":63,"position":64,"flexShrink":65,"boxSizing":66,"marginTop":67,"marginBottom":67,"fontSize":68,"fontWeight":69},"flex","column","relative","0","border-box",".56rem","1.125rem","700",{"@type":44,"@version":45,"id":71,"component":72,"responsiveStyles":76},"builder-a2e1f4b9f30b464bb814d7f5de5b0aa7",{"name":73,"options":74,"isRSC":59},"Custom Code",{"code":75,"scriptsClientOnly":6},"\u003Cstyle>\n  .top-banner.bg-web-orange{background:rgb(114, 79, 255);}\n\u003C\u002Fstyle>\n",{"large":77},{"display":62,"flexDirection":63,"position":64,"flexShrink":65,"boxSizing":66},{"id":79,"@type":44,"tagName":80,"properties":81,"responsiveStyles":85},"builder-pixel-65og51xnky7","img",{"src":82,"aria-hidden":83,"alt":21,"role":84,"width":65,"height":65},"https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fpixel?apiKey=f3a1111ff5be48cdbb123cd9f5795a05","true","presentation",{"large":86},{"height":65,"width":65,"display":87,"opacity":65,"overflow":88,"pointerEvents":89},"block","hidden","none",{"deviceSize":91,"location":92},"large",{"path":21,"query":93},{},[],"fd266d0172cc47429be7ad10f48c99ad",1787595768418,"tFqFyIzyczYOCRogcShKk6KBmEB2",{"breakpoints":99,"hasAutosaves":19,"hasErrors":6,"hasLinks":6,"kind":100,"lastPreviewUrl":101},{"medium":16,"small":17,"xsmall":18},"component","https:\u002F\u002Fpushsecurity.com\u002F?builder.space=f3a1111ff5be48cdbb123cd9f5795a05&builder.user.permissions=read%2Ccreate%2Cpublish%2CeditDesigns%2CeditLayouts%2CeditLayers%2CeditContentPriority%2CeditFolders%2CcreateProjects%2CsendPullRequests%2CfusionHostingPublish&builder.user.role.name=Designer&builder.user.role.id=creator&builder.cachebust=true&builder.preview=always-visible-banner&builder.noCache=true&builder.allowTextEdit=true&__builder_editing__=true&builder.overrides.always-visible-banner=fd266d0172cc47429be7ad10f48c99ad&builder.overrides.fd266d0172cc47429be7ad10f48c99ad=fd266d0172cc47429be7ad10f48c99ad&builder.options.locale=Default","0678d178ec8b41efb8a23c09dba7874d","always visible banner",[],{},1774968080803,"y4fj9dbjb7k",[109,145],{"createdBy":32,"createdDate":110,"data":111,"folders":134,"id":135,"lastUpdated":136,"lastUpdatedBy":32,"meta":137,"modelId":139,"name":140,"published":13,"query":141,"stageModifiedSincePublish":6,"testRatio":31,"variations":142,"firstPublished":143,"rev":144},1776247359804,{"link":112,"testimonial":113,"testimonialLink":133,"type":116},{},{"@type":114,"id":115,"model":116,"value":117},"@builder.io\u002Fcore:Reference","f028f2b685bb47cd8bf9e82a26dd5a79","testimonial",{"query":118,"folders":119,"createdDate":120,"id":115,"name":121,"modelId":122,"published":13,"data":123,"variations":127,"lastUpdated":128,"firstPublished":129,"testRatio":31,"createdBy":37,"lastUpdatedBy":37,"meta":130,"rev":132},[],[],1735823466309,"We found Push to be more accurate when compared to competitors and the browser agent offered features that others couldn’t match.","42035571a56940ac98bff4544aa79aa5",{"author":124,"jobTitle":125,"quote":121,"image":126},"Jason Waits","\u003Cp>CISO at Inductive Automation\u003C\u002Fp>","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Ff04c0c0689ce4a89ac0f0708d78c0a07",{},1735910703862,1735823501152,{"kind":20,"lastPreviewUrl":21,"breakpoints":131,"hasAutosaves":19},{"small":17,"medium":16},"8lr4aug0kgg","\u002Fcustomer-stories\u002Finductive-automation",[],"9136a8f18b3b4a6ba29b8653a99372b1",1776247404986,{"breakpoints":138,"hasAutosaves":6,"kind":20,"lastPreviewUrl":21},{"medium":16,"small":17,"xsmall":18},"20d9eaa352304613b3d1a794b400703d","testimonial-inductive-automation",[],{},1776247404973,"tmziibs9ga9",{"createdBy":32,"createdDate":146,"data":147,"folders":174,"id":175,"lastUpdated":176,"lastUpdatedBy":32,"meta":177,"modelId":139,"name":172,"published":13,"query":179,"stageModifiedSincePublish":6,"testRatio":31,"variations":180,"firstPublished":181,"rev":144},1776255761419,{"description":148,"image":149,"link":150,"testimonial":153,"title":172,"type":173},"Learn about the latest techniques being used in the wild.","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F7b4a5ebf81d64e8c9d7fc35f6c96c4a9",{"text":151,"url":152},"Download now","\u002Fresources\u002Fbrowser-attacks-report",{"@type":114,"id":154,"model":116,"value":155},"192acbb1f9ca4cac918c0ec435a8bae3",{"query":156,"folders":157,"createdDate":158,"id":154,"name":159,"modelId":122,"published":13,"data":160,"variations":166,"lastUpdated":167,"firstPublished":168,"testRatio":31,"createdBy":37,"lastUpdatedBy":32,"meta":169,"rev":171},[],[],1728981467463,"Push does for identity what CrowdStrike did for the endpoint",{"video":161,"jobTitle":162,"author":163,"qoute":21,"quote":164,"image":165},"https:\u002F\u002Fcdn.builder.io\u002Fo\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F8b30e8ca50064058bbaef0f3c6164575%2Fcompressed?apiKey=f3a1111ff5be48cdbb123cd9f5795a05&token=8b30e8ca50064058bbaef0f3c6164575&alt=media&optimized=true","\u003Cp>Deputy CISO at Microsoft\u003C\u002Fp>\u003Cp>Former LinkedIn, Slack, Palantir\u003C\u002Fp>","Geoff Belknap","Push does for identity what CrowdStrike did for the endpoint.","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F748f0ad0a5064a00a13f4721fcc8dea1",{},1742902158597,1728981782923,{"kind":20,"lastPreviewUrl":21,"breakpoints":170,"hasAutosaves":19},{"small":17,"medium":16},"w423t83vzcq","Report: 2026 Browser Attack Techniques","resource",[],"05a9322735fc427db12e2740e4302300",1776255810913,{"breakpoints":178,"hasAutosaves":6,"kind":20,"lastPreviewUrl":21},{"medium":16,"small":17,"xsmall":18},[],{},1776255810900,[183,205],{"createdBy":32,"createdDate":184,"data":185,"folders":195,"id":196,"lastUpdated":197,"lastUpdatedBy":32,"meta":198,"modelId":200,"name":172,"published":13,"query":201,"stageModifiedSincePublish":6,"testRatio":31,"variations":202,"firstPublished":203,"rev":204},1776256900280,{"description":148,"image":149,"link":186,"testimonial":187,"title":172,"type":173},{"text":151,"url":152},{"@type":114,"id":154,"model":116,"value":188},{"query":189,"folders":190,"createdDate":158,"id":154,"name":159,"modelId":122,"published":13,"data":191,"variations":192,"lastUpdated":167,"firstPublished":168,"testRatio":31,"createdBy":37,"lastUpdatedBy":32,"meta":193,"rev":171},[],[],{"video":161,"jobTitle":162,"author":163,"qoute":21,"quote":164,"image":165},{},{"kind":20,"lastPreviewUrl":21,"breakpoints":194,"hasAutosaves":19},{"small":17,"medium":16},[],"1f429607996e4e5fae8fe3f9b9610e55",1776256937553,{"breakpoints":199,"hasAutosaves":6,"kind":20,"lastPreviewUrl":21},{"medium":16,"small":17,"xsmall":18},"4829faa81e7c4ee8bd2d000e160e8d3c",[],{},1776256937540,"h00i46zz8yj",{"createdBy":32,"createdDate":206,"data":207,"folders":217,"id":218,"lastUpdated":219,"lastUpdatedBy":32,"meta":220,"modelId":200,"name":222,"published":13,"query":223,"stageModifiedSincePublish":6,"testRatio":31,"variations":224,"firstPublished":225,"rev":204},1776256949234,{"link":208,"testimonial":209,"testimonialLink":133,"type":116},{},{"@type":114,"id":115,"model":116,"value":210},{"query":211,"folders":212,"createdDate":120,"id":115,"name":121,"modelId":122,"published":13,"data":213,"variations":214,"lastUpdated":128,"firstPublished":129,"testRatio":31,"createdBy":37,"lastUpdatedBy":37,"meta":215,"rev":132},[],[],{"author":124,"jobTitle":125,"quote":121,"image":126},{},{"kind":20,"lastPreviewUrl":21,"breakpoints":216,"hasAutosaves":19},{"small":17,"medium":16},[],"ce043785b71b4ece98eac811ecf4ba10",1776256974140,{"breakpoints":221,"hasAutosaves":6,"kind":20,"lastPreviewUrl":21},{"medium":16,"small":17,"xsmall":18},"inductive-automation",[],{},1776256974130,[227,231,235,239,243],{"title":228,"logo":229,"createdDate":230},"SOC2","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fb6727a5e00004d6e9e69fc3068b8b64c",1784291539953,{"title":232,"logo":233,"createdDate":234},"GDPR","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Ffe49f53211674deaa5a6640d929cdf42?format=webp",1784291672535,{"title":236,"logo":237,"createdDate":238},"Cyber essentials","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F53558c1045a342a7a28def960cd54ae7?format=webp",1784291702710,{"title":240,"logo":241,"createdDate":242},"ISO IEC 27001","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2F578a404a61cf45db951a41fe3554d12d",1784291766222,{"title":244,"logo":245,"createdDate":246},"ISO IEC 27701","https:\u002F\u002Fcdn.builder.io\u002Fapi\u002Fv1\u002Fimage\u002Fassets%2Ff3a1111ff5be48cdbb123cd9f5795a05%2Fbe219844b13242fbba531959579a753c",1784291858848,[248,317,362],{"id":249,"label":250,"text":21,"navIcon":251,"items":252},"stop-browser-based-attacks","Stop browser-based attacks","solid:faShieldHalved",[253,258,263,268,273,278,283,288,293,297,302,307,312],{"title":254,"text":255,"url":256,"navIcon":257},"Phishing","Detect phishing behaviorally in the browser, regardless of the payload or delivery channel.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fzero-day-phishing","sharp-regular:faFishingRod",{"title":259,"text":260,"url":261,"navIcon":262},"Adversary-in-the-Middle","Detect and block MFA-bypassing AiTM phishing pages in real-time.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fadversary-in-the-middle-attacks","solid:faUserSecret",{"title":264,"text":265,"url":266,"navIcon":267},"ClickFix (and variants)","Intercept malicious copy and paste attacks at the point of interaction.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fclickfix-fix-variants","sharp-regular:faLaptopCode",{"title":269,"text":270,"url":271,"navIcon":272},"Device code phishing","Detect and block device code phishing kits designed to get around passkeys.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fdevice-code-phishing","solid:faTabletScreenButton",{"title":274,"text":275,"url":276,"navIcon":277},"Consent phishing","Detect and block malicious OAuth consent grants before access is authorized.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fconsent-phishing","solid:faThumbsUp",{"title":279,"text":280,"url":281,"navIcon":282},"Malicious OAuth integrations","Detect and block the root cause of SaaS supply chain attacks.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fmalicious-oauth-integrations","solid:faPlugCircleXmark",{"title":284,"text":285,"url":286,"navIcon":287},"Malicious browser extensions","Inventory, monitor, and block risky browser extensions.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fmalicious-browser-extensions","sharp-regular:faPuzzlePiece",{"title":289,"text":290,"url":291,"navIcon":292},"Malicious file downloads","Control which files users can download by type, source, and user group.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fmalicious-file-downloads","solid:faFileCircleXmark",{"title":294,"text":295,"url":296,"navIcon":292},"Infostealers","Detect infostealer delivery and respond to a compromise.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Finfostealer-malware",{"title":298,"text":299,"url":300,"navIcon":301},"Ghost logins","Surface hidden login paths that bypass SSO and expose accounts.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fghost-logins","solid:faGhost",{"title":303,"text":304,"url":305,"navIcon":306},"Mobile phishing (QR & SMS)","Detect phishing regardless of whether it arrives via email, SMS, or QR code.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fmobile-phishing-qr-code-sms","solid:faQrcode",{"title":308,"text":309,"url":310,"navIcon":311},"Credential stuffing","Identify reused and compromised credentials across SaaS logins.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fcredential-stuffing","custom:credentialStuffing",{"title":313,"text":314,"url":315,"navIcon":316},"Session hijacking","Detect and respond to stolen session token replay with browser session markers.","\u002Fsolution\u002Fstop-browser-based-attacks\u002Fsession-hijacking","solid:faCookieBite",{"id":318,"label":319,"text":21,"navIcon":320,"items":321},"achieve-security-outcomes","Achieve security outcomes","solid:faCheckToSlot",[322,327,332,337,342,347,352,357],{"title":323,"text":324,"url":325,"navIcon":326},"Stop account takeover","Stop ATO with stolen credential and compromised token detection.","\u002Fsolution\u002Fachieve-security-outcomes\u002Fstop-account-takeover","sharp-regular:faUserSecret",{"title":328,"text":329,"url":330,"navIcon":331},"Harden unmanaged identities","Harden access paths with visibility, detection, and guardrails.","\u002Fsolution\u002Fachieve-security-outcomes\u002Fharden-unmanaged-identities","sharp-regular:faRadar",{"title":333,"text":334,"url":335,"navIcon":336},"Investigate browser-related incidents","Investigate and respond faster with unique browser telemetry.","\u002Fsolution\u002Fachieve-security-outcomes\u002Finvestigate-browser-related-incidents","sharp-regular:faSatelliteDish",{"title":338,"text":339,"url":340,"navIcon":341},"Secure shadow SaaS","See and control shadow SaaS in the browser.","\u002Fsolution\u002Fachieve-security-outcomes\u002Fsecure-shadow-saas","sharp-regular:faShieldCheck",{"title":343,"text":344,"url":345,"navIcon":346},"Secure AI","See and control AI apps in the browser.","\u002Fsolution\u002Fachieve-security-outcomes\u002Fsecure-ai","sharp-regular:faBrainCircuit",{"title":348,"text":349,"url":350,"navIcon":351},"Secure BYOD","Extend consistent browser-based protection to unmanaged devices.","\u002Fsolution\u002Fachieve-security-outcomes\u002Fsecure-bring-your-own-device","solid:faMobileScreenButton",{"title":353,"text":354,"url":355,"navIcon":356},"Secure Chromebooks","Secure browser activity on Chromebooks without endpoint agents.","\u002Fsolution\u002Fachieve-security-outcomes\u002Fsecure-chromebooks","brands:faChrome",{"title":358,"text":359,"url":360,"navIcon":361},"Investigate and stop data loss","Detect and prevent data loss across AI tools, apps, and sessions.","\u002Fsolution\u002Fachieve-security-outcomes\u002Finvestigate-and-stop-data-loss","custom:investigateAndStopDataLoss",{"id":363,"label":364,"text":21,"navIcon":365,"items":366},"tool-replacements","Tool replacements","solid:faScrewdriverWrench",[367,372,377,382],{"title":368,"text":369,"url":370,"navIcon":371},"Remote browser isolation","Detect attacks that look like normal browsing.","\u002Fsolution\u002Ftool-replacements\u002Fremote-browser-isolation","solid:faDisplay",{"title":373,"text":374,"url":375,"navIcon":376},"Secure web gateways","Detect attacks inside the browser after SWGs allowed the connection.","\u002Fsolution\u002Ftool-replacements\u002Fsecure-web-gateways","solid:faFilter",{"title":378,"text":379,"url":380,"navIcon":381},"Cloud access security broker","Catch browser-based identity threats in real time, not after the fact.","\u002Fsolution\u002Ftool-replacements\u002Fcloud-access-security-broker","solid:faCloudArrowUp",{"title":383,"text":384,"url":385,"navIcon":386},"Security awareness training","Block real phishing instead of training users on simulations.","\u002Fsolution\u002Ftool-replacements\u002Fsecurity-awareness-training","custom:securityAwareness",{"w":388,"h":389,"d":390},448,512,"M284.6 0l91.4 0 0 160-48 0 0-112-36.6 0-203.4 58.1 0 181.9 40 0 0 224-128 0 0-224 40 0 0-218.1 17.4-5 224-64 3.2-.9zM80 336l-32 0 0 128 32 0 0-128zm176 8c0-76.8 64-136 96-152 32 16 96 75.2 96 152 0 32-16 80-64 112l32 40 0 16-128 0 0-16 32-40c-48-32-64-80-64-112zm128-32a24 24 0 1 0 -48 0 24 24 0 1 0 48 0z",{"w":388,"h":389,"d":392},"M171-16c-36.4 0-57.8 58.3-68.3 112L72 96c-13.3 0-24 10.7-24 24s10.7 24 24 24l24 0 0 32c0 17 3.3 33.2 9.3 48l-9.3 0 0 0-20.5 0c-15.2 0-27.5 12.3-27.5 27.5 0 3 .5 5.9 1.4 8.7l28.9 86.6C40.2 379.6 16 428.1 16 482.3 16 498.7 29.3 512 45.7 512l356.6 0c16.4 0 29.7-13.3 29.7-29.7 0-54.2-24.2-102.7-62.3-135.4l28.9-86.6c.9-2.8 1.4-5.7 1.4-8.7 0-15.2-12.3-27.5-27.5-27.5l-20.5 0 0 0-9.3 0c6-14.8 9.3-31 9.3-48l0-32 24 0c13.3 0 24-10.7 24-24s-10.7-24-24-24l-30.7 0c-10.4-53.7-31.9-112-68.3-112-9.6 0-19 3.9-27.5 8.2-8.2 4.1-18.4 7.8-25.5 7.8s-17.3-3.7-25.5-7.8C190-12.1 180.6-16 171-16zm93.7 484.4l-24.8-70.9 27.9-32.5c2.7-3.2 4.2-7.2 4.2-11.4 0-9.7-7.8-17.5-17.5-17.5l-61 0c-9.7 0-17.5 7.8-17.5 17.5 0 4.2 1.5 8.2 4.2 11.4l27.9 32.5-24.8 70.9-57-180.4 35.7 0c18.4 10.2 39.5 16 62 16s43.6-5.8 62-16l35.7 0-57 180.4zM224 256c-34.7 0-64.2-22.1-75.3-53 5.7 3.2 12.3 5 19.3 5l12.4 0c16.5 0 31.1-10.6 36.3-26.2 2.3-7 12.2-7 14.5 0 5.2 15.6 19.9 26.2 36.3 26.2l12.4 0c7 0 13.6-1.8 19.3-5-11.1 30.9-40.6 53-75.3 53z",{"w":17,"h":389,"d":394},"M112 80l416 0 0 224 48 0 0-272-512 0 0 272 48 0 0-224zM48 404.1l0-4.1 544 0 0 4.1-27.9 27.9-488.2 0-27.9-27.9zM592 352l-592 0 0 72 56 56 528 0 56-56 0-72-48 0zM281 169l17-17-33.9-33.9c-6.1 6.1-27.8 27.8-65 65l-17 17c6.1 6.1 27.8 27.8 65 65l17 17 33.9-33.9c-9-9-25-25-48-48l31-31zM393 135l-17-17-33.9 33.9c9 9 25 25 48 48-23 23-39 39-48 48L376 281.9c6.1-6.1 27.8-27.8 65-65l17-17c-6.1-6.1-27.8-27.8-65-65z",{"w":388,"h":389,"d":396},"M0 64C0 28.7 28.7 0 64 0L384 0c35.3 0 64 28.7 64 64l0 384c0 35.3-28.7 64-64 64L64 512c-35.3 0-64-28.7-64-64L0 64zM256 432a32 32 0 1 0 -64 0 32 32 0 1 0 64 0zM384 64l-320 0 0 288 320 0 0-288z",{"w":389,"h":389,"d":398},"M80 160c17.7 0 32 14.3 32 32l0 256c0 17.7-14.3 32-32 32l-48 0c-17.7 0-32-14.3-32-32L0 192c0-17.7 14.3-32 32-32l48 0zM270.6 16C297.9 16 320 38.1 320 65.4l0 4.2c0 6.8-1.3 13.6-3.8 19.9L288 160 448 160c26.5 0 48 21.5 48 48 0 19.7-11.9 36.6-28.9 44 17 7.4 28.9 24.3 28.9 44 0 23.4-16.8 42.9-39 47.1 4.4 7.3 7 15.8 7 24.9 0 22.2-15 40.8-35.4 46.3 2.2 5.5 3.4 11.5 3.4 17.7 0 26.5-21.5 48-48 48l-87.9 0c-36.3 0-71.6-12.4-99.9-35.1L184 435.2c-15.2-12.1-24-30.5-24-50l0-186.6c0-14.9 3.5-29.6 10.1-42.9L226.3 43.3C234.7 26.6 251.8 16 270.6 16z",{"w":17,"h":389,"d":400},"M192-32c17.7 0 32 14.3 32 32l0 96 128 0 0-96c0-17.7 14.3-32 32-32s32 14.3 32 32l0 96 64 0c17.7 0 32 14.3 32 32s-14.3 32-32 32l0 48.7c-98.6 8.1-176 90.7-176 191.3 0 27.3 5.7 53.3 16 76.9l0 3.1c0 17.7-14.3 32-32 32s-32-14.3-32-32l0-66.7C165.2 398.1 96 319.1 96 224l0-64c-17.7 0-32-14.3-32-32S78.3 96 96 96l64 0 0-96c0-17.7 14.3-32 32-32zM496 256a144 144 0 1 1 0 288 144 144 0 1 1 0-288zm59.3 107.3c6.2-6.2 6.2-16.4 0-22.6s-16.4-6.2-22.6 0l-36.7 36.7-36.7-36.7c-6.2-6.2-16.4-6.2-22.6 0s-6.2 16.4 0 22.6l36.7 36.7-36.7 36.7c-6.2 6.2-6.2 16.4 0 22.6s16.4 6.2 22.6 0l36.7-36.7 36.7 36.7c6.2 6.2 16.4 6.2 22.6 0s6.2-16.4 0-22.6l-36.7-36.7 36.7-36.7z",{"w":389,"h":389,"d":402},"M201.1 57.3c-7 5.3-9.1 10.7-9.1 14.7 0 4.5 2.8 11.2 12.4 16.9l11.6 7 0 48.1-168 0 0 60.5c7.4-2.9 15.5-4.5 24-4.5 43.1 0 72 39.4 72 80s-28.9 80-72 80c-8.5 0-16.6-1.6-24-4.5l0 108.5 108.5 0c-2.9-7.4-4.5-15.5-4.5-24 0-43.1 39.4-72 80-72s80 28.9 80 72c0 8.5-1.6 16.6-4.5 24l60.5 0 0-168 48.1 0 7 11.6c5.8 9.6 12.4 12.4 16.9 12.4 4 0 9.5-2.1 14.7-9.1s9.3-17.9 9.3-30.9-4-23.8-9.3-30.9-10.7-9.1-14.7-9.1c-4.5 0-11.2 2.8-16.9 12.4l-7 11.6-48.1 0 0-120-120 0 0-48.1 11.6-7c9.6-5.8 12.4-12.4 12.4-16.9 0-4-2.1-9.5-9.1-14.7S245 48 232 48 208.2 52 201.1 57.3zM172.3 18.9C188.5 6.8 209.6 0 232 0S275.5 6.8 291.7 18.9 320 49.5 320 72c0 8.6-1.8 16.7-4.9 24l100.9 0 0 100.9c7.3-3.1 15.4-4.9 24-4.9 22.5 0 41 12.2 53.1 28.3s18.9 37.3 18.9 59.7-6.8 43.5-18.9 59.7-30.6 28.3-53.1 28.3c-8.6 0-16.7-1.8-24-4.9l0 148.9-168 0 0-49.3 8.2-7.2c5.4-4.7 7.8-10.3 7.8-15.5 0-9.9-10.7-24-32-24s-32 14.1-32 24c0 5.3 2.4 10.8 7.8 15.5l8.2 7.2 0 49.3-216 0 0-216 49.3 0 7.2 8.2c4.7 5.4 10.3 7.8 15.5 7.8 9.9 0 24-10.7 24-32s-14.1-32-24-32c-5.3 0-10.8 2.4-15.5 7.8L49.3 264 0 264 0 96 148.9 96c-3.1-7.3-4.9-15.4-4.9-24 0-22.5 12.2-41 28.3-53.1z",{"w":404,"h":389,"d":405},576,"M96 0C60.7 0 32 28.7 32 64l0 384c0 35.3 28.7 64 64 64l180 0c-22.7-31.5-36-70.2-36-112 0-100.6 77.4-183.2 176-191.3l0-38.1c0-17-6.7-33.3-18.7-45.3L290.7 18.7C278.7 6.7 262.5 0 245.5 0L96 0zM357.5 176L264 176c-13.3 0-24-10.7-24-24L240 58.5 357.5 176zM432 544a144 144 0 1 0 0-288 144 144 0 1 0 0 288zm59.3-180.7l-36.7 36.7 36.7 36.7c6.2 6.2 6.2 16.4 0 22.6s-16.4 6.2-22.6 0l-36.7-36.7-36.7 36.7c-6.2 6.2-16.4 6.2-22.6 0s-6.2-16.4 0-22.6l36.7-36.7-36.7-36.7c-6.2-6.2-6.2-16.4 0-22.6s16.4-6.2 22.6 0l36.7 36.7 36.7-36.7c6.2-6.2 16.4-6.2 22.6 0s6.2 16.4 0 22.6z",{"w":407,"h":389,"d":408},384,"M40.1 467.1l-11.2 9C25.7 478.6 21.8 480 17.8 480 8 480 0 472 0 462.2L0 192C0 86 86 0 192 0S384 86 384 192l0 270.2c0 9.8-8 17.8-17.8 17.8-4 0-7.9-1.4-11.1-3.9l-11.2-9c-13.4-10.7-32.8-9-44.1 3.9L269.3 506c-3.3 3.8-8.2 6-13.3 6s-9.9-2.2-13.3-6l-26.6-30.5c-12.7-14.6-35.4-14.6-48.2 0L141.3 506c-3.3 3.8-8.2 6-13.3 6s-9.9-2.2-13.3-6L84.2 471c-11.3-12.9-30.7-14.6-44.1-3.9zM160 192a32 32 0 1 0 -64 0 32 32 0 1 0 64 0zm96 32a32 32 0 1 0 0-64 32 32 0 1 0 0 64z",{"w":388,"h":389,"d":410},"M64 160l64 0 0-64-64 0 0 64zM0 80C0 53.5 21.5 32 48 32l96 0c26.5 0 48 21.5 48 48l0 96c0 26.5-21.5 48-48 48l-96 0c-26.5 0-48-21.5-48-48L0 80zM64 416l64 0 0-64-64 0 0 64zM0 336c0-26.5 21.5-48 48-48l96 0c26.5 0 48 21.5 48 48l0 96c0 26.5-21.5 48-48 48l-96 0c-26.5 0-48-21.5-48-48l0-96zM320 96l0 64 64 0 0-64-64 0zM304 32l96 0c26.5 0 48 21.5 48 48l0 96c0 26.5-21.5 48-48 48l-96 0c-26.5 0-48-21.5-48-48l0-96c0-26.5 21.5-48 48-48zM288 352a32 32 0 1 1 0-64 32 32 0 1 1 0 64zm0 64c17.7 0 32 14.3 32 32s-14.3 32-32 32-32-14.3-32-32 14.3-32 32-32zm96 32c0-17.7 14.3-32 32-32s32 14.3 32 32-14.3 32-32 32-32-14.3-32-32zm32-96a32 32 0 1 1 0-64 32 32 0 1 1 0 64zm-32 32a32 32 0 1 1 -64 0 32 32 0 1 1 64 0z",{"w":389,"h":389,"d":412},"M257.5 27.6c-.8-5.4-4.9-9.8-10.3-10.6-22.1-3.1-44.6 .9-64.4 11.4l-74 39.5C89.1 78.4 73.2 94.9 63.4 115L26.7 190.6c-9.8 20.1-13 42.9-9.1 64.9l14.5 82.8c3.9 22.1 14.6 42.3 30.7 57.9l60.3 58.4c16.1 15.6 36.6 25.6 58.7 28.7l83 11.7c22.1 3.1 44.6-.9 64.4-11.4l74-39.5c19.7-10.5 35.6-27 45.4-47.2l36.7-75.5c9.8-20.1 13-42.9 9.1-64.9-.9-5.3-5.3-9.3-10.6-10.1-51.5-8.2-92.8-47.1-104.5-97.4-1.8-7.6-8-13.4-15.7-14.6-54.6-8.7-97.7-52-106.2-106.8zM208 144a32 32 0 1 1 0 64 32 32 0 1 1 0-64zM144 336a32 32 0 1 1 64 0 32 32 0 1 1 -64 0zm224-64a32 32 0 1 1 0 64 32 32 0 1 1 0-64z",{"w":388,"h":389,"d":414},"M144-16l-48 112-48 0 0 48 48 0 0 32c0 17 3.3 33.2 9.3 48l-73.3 0 0 32 5.3 16 26.7 80-64 160 51.7 0 56.9-142.2 6.5-16.3c-1-3.1-10.1-30.3-27.2-81.5l51.4 0c22.6 19.9 52.2 32 84.7 32s62.1-12.1 84.7-32l51.4 0c-17.1 51.2-26.1 78.4-27.2 81.5l6.5 16.3 56.9 142.2 51.7 0-64-160 26.7-80 5.3-16 0-32-73.3 0c6-14.8 9.3-31 9.3-48l0-32 48 0 0-48-48 0-48-112-32 0-48 32-48-32-32 0zm80 272c-32.8 0-61-19.7-73.3-48l57.3 0 16-40 16 40 57.3 0c-12.3 28.3-40.5 48-73.3 48zm17.5 139.6l30.5-35.6 0-24-96 0 0 24 30.5 35.6-46.5 116.4 128 0-46.5-116.4z",{"w":389,"h":389,"d":416},"M497.4 49l17-17-33.9-33.9C473.6 4.9 453.3 25.2 419.7 58.8 375.4 22.1 318.5 0 256.4 0 115.1 0 .4 114.6 .4 256s114.6 256 256 256 256-114.6 256-256l-48 0c0 114.9-93.1 208-208 208s-208-93.1-208-208 93.1-208 208-208c48.8 0 93.7 16.8 129.1 44.9l-45.7 45.7c-23.5-16.8-52.3-26.6-83.4-26.6-79.5 0-144 64.5-144 144s64.5 144 144 144 144-64.5 144-144l-48 0c0 53-43 96-96 96s-96-43-96-96 43-96 96-96c17.8 0 34.5 4.8 48.8 13.3-52 52-79.5 79.5-82.7 82.7l33.9 33.9 17-17 224-224z",{"w":389,"h":389,"d":418},"M208 0l24 0C386.6 0 512 125.4 512 280l0 24-48 0 0-24C464 151.9 360.1 48 232 48l-24 0 0-48zm24 96c101.6 0 184 82.4 184 184l0 24-48 0 0-24c0-75.1-60.9-136-136-136l-24 0 0-48 24 0zM48 256c0 114.9 93.1 208 208 208 22.9 0 45-3.7 65.6-10.5l-263-263C51.7 211 48 233.1 48 256zM0 256c0-36.5 7.6-71.3 21.4-102.7 6.7-15.3 14.9-29.9 24.4-43.5 7.7 7.7 61.5 61.5 161.2 161.2 30.5-30.5 49.5-49.5 57-57L297.9 248c-7.5 7.5-26.5 26.5-57 57 99.7 99.7 153.5 153.5 161.2 161.2-13.6 9.5-28.2 17.7-43.5 24.4-31.4 13.8-66.2 21.4-102.7 21.4-141.4 0-256-114.6-256-256z",{"w":389,"h":389,"d":420},"M267.6 4.5l207.5 80.5 19.2 7.4 1.2 20.5c2.9 50-4.9 126.3-37.3 200.9-32.7 75.2-91.1 150-189.4 192.5l-12.7 5.5-12.7-5.5C144.9 463.9 86.6 389.2 53.9 313.9 21.5 239.3 13.7 162.9 16.6 113L17.8 92.5 37 85 244.5 4.5 256 0 267.6 4.5zM64.1 126C63.1 169.5 71 232.9 97.9 294.8 126.1 359.7 175 422.4 256 459.6 337.1 422.4 385.9 359.7 414.2 294.8 441 232.9 449 169.5 448 126L256 51.5 64.1 126zm302.3 44.7L352.3 190.1 249.8 330.9 233 354c-8.8-9.1-30.9-32-66.2-68.6l-16.7-17.3 34.5-33.3c9.5 9.8 23.9 24.7 43.2 44.7l85.6-117.7 14.1-19.4 38.8 28.2z",{"w":389,"h":389,"d":422},"M192 48l40 0 0 108-12.4 0c-7.6-16.5-24.3-28-43.6-28-26.5 0-48 21.5-48 48s21.5 48 48 48c19.4 0 36.1-11.5 43.6-28l12.4 0 0 56-92 0 0 56.4c-16.5 7.6-28 24.3-28 43.6 0 26.5 21.5 48 48 48s48-21.5 48-48c0-19.4-11.5-36.1-28-43.6l0-16.4 52 0 0 172-40 0c-16.8 0-31.2-10.3-37.1-25.1l-6.4-16-17.2 1c-1.1 .1-2.2 .1-3.2 .1-30.9 0-56-25.1-56-56 0-9.5 2.4-18.5 6.5-26.3l8.7-16.2-13.4-12.6c-11-10.2-17.8-24.8-17.8-40.9 0-21.6 12.2-40.4 30.3-49.8l22.6-11.7-13.1-21.9c-5-8.4-7.9-18.1-7.9-28.6 0-30.9 25.1-56 56-56l24 0 0-32c0-13.3 10.7-24 24-24zm88 148l12.4 0c7.6 16.5 24.3 28 43.6 28 26.5 0 48-21.5 48-48s-21.5-48-48-48c-19.4 0-36.1 11.5-43.6 28l-12.4 0 0-108 40 0c13.3 0 24 10.7 24 24l0 32 24 0c30.9 0 56 25.1 56 56 0 10.5-2.9 20.3-7.9 28.6l-13.1 21.9 22.6 11.7c18 9.3 30.3 28.1 30.3 49.8 0 16.1-6.8 30.7-17.8 40.9l-13.4 12.6 8.7 16.2c4.2 7.8 6.5 16.7 6.5 26.3 0 30.9-25.1 56-56 56-1.1 0-2.2 0-3.2-.1l-17.2-1-6.4 16C351.2 453.7 336.8 464 320 464l-40 0 0-76 92 0 0-56.4c16.5-7.6 28-24.3 28-43.6 0-26.5-21.5-48-48-48s-48 21.5-48 48c0 19.4 11.5 36.1 28 43.6l0 16.4-52 0 0-152zM192 512l128 0c31.1 0 58.4-16.2 74.1-40.5 52.7-5.1 93.9-49.5 93.9-103.5 0-11.5-1.9-22.5-5.3-32.9 13.4-17.5 21.3-39.4 21.3-63.1 0-32-14.5-60.6-37.1-79.7 3.3-10.2 5.1-21.1 5.1-32.3 0-49.6-34.8-91.1-81.3-101.5-6.3-33.3-35.6-58.5-70.7-58.5L192 0c-35.1 0-64.4 25.2-70.7 58.5-46.5 10.4-81.3 51.9-81.3 101.5 0 11.3 1.8 22.2 5.1 32.3-22.7 19.1-37.1 47.7-37.1 79.7 0 23.7 8 45.6 21.3 63.1-3.5 10.4-5.3 21.4-5.3 32.9 0 54 41.2 98.5 93.9 103.5 15.6 24.3 42.9 40.5 74.1 40.5zM336 192a16 16 0 1 1 0-32 16 16 0 1 1 0 32zm32 96a16 16 0 1 1 -32 0 16 16 0 1 1 32 0zM176 352a16 16 0 1 1 -32 0 16 16 0 1 1 32 0zm16-176a16 16 0 1 1 -32 0 16 16 0 1 1 32 0z",{"w":407,"h":389,"d":424},"M16 64C16 28.7 44.7 0 80 0L304 0c35.3 0 64 28.7 64 64l0 384c0 35.3-28.7 64-64 64L80 512c-35.3 0-64-28.7-64-64L16 64zm64 0l0 304 224 0 0-304-224 0zM192 472c17.7 0 32-14.3 32-32s-14.3-32-32-32-32 14.3-32 32 14.3 32 32 32z",{"w":389,"h":389,"d":426},"M0 256c0-46.6 12.5-90.4 34.3-128.9L144.1 318.3c21.9 39.2 63.8 65.7 111.9 65.7 14.3 0 27.1-2.3 40.8-6.6L220.5 509.6C95.9 492.3 0 385.3 0 256zm365.1 65.6c12.3-19.2 18.9-42.5 18.9-65.6 0-38.2-16.8-72.5-43.3-96l152.7 0c12 29.6 18.6 62.1 18.6 96 0 141.4-114.6 255.1-256 256L365.1 321.6zM477.8 128L256 128c-62.9 0-113.7 44.1-125.5 102.7L54.2 98.5C101 38.5 174 0 256 0 350.8 0 433.5 51.5 477.8 128zM344 256a88 88 0 1 1 -176 0 88 88 0 1 1 176 0z",{"w":389,"h":389,"d":428},"M448 96l0 256-384 0 0-256 384 0zM64 32C28.7 32 0 60.7 0 96L0 352c0 35.3 28.7 64 64 64l144 0-16 48-72 0c-13.3 0-24 10.7-24 24s10.7 24 24 24l272 0c13.3 0 24-10.7 24-24s-10.7-24-24-24l-72 0-16-48 144 0c35.3 0 64-28.7 64-64l0-256c0-35.3-28.7-64-64-64L64 32z",{"w":389,"h":389,"d":430},"M32 64C19.1 64 7.4 71.8 2.4 83.8S.2 109.5 9.4 118.6L192 301.3 192 416c0 8.5 3.4 16.6 9.4 22.6l64 64c9.2 9.2 22.9 11.9 34.9 6.9S320 492.9 320 480l0-178.7 182.6-182.6c9.2-9.2 11.9-22.9 6.9-34.9S492.9 64 480 64L32 64z",{"w":404,"h":389,"d":432},"M144 480c-79.5 0-144-64.5-144-144 0-63.4 41-117.2 97.9-136.5-1.3-7.7-1.9-15.5-1.9-23.5 0-79.5 64.5-144 144-144 55.4 0 103.5 31.3 127.6 77.1 14.2-8.3 30.8-13.1 48.4-13.1 53 0 96 43 96 96 0 15.7-3.8 30.6-10.5 43.7 44 20.3 74.5 64.7 74.5 116.3 0 70.7-57.3 128-128 128l-304 0zM305 191c-9.4-9.4-24.6-9.4-33.9 0l-72 72c-9.4 9.4-9.4 24.6 0 33.9s24.6 9.4 33.9 0l31-31 0 102.1c0 13.3 10.7 24 24 24s24-10.7 24-24l0-102.1 31 31c9.4 9.4 24.6 9.4 33.9 0s9.4-24.6 0-33.9l-72-72z",{"id":434,"title":435,"authorsCollection":436,"content":444,"extension":858,"faqItemsCollection":859,"faqTitle":59,"featured":6,"hashTags":59,"meta":861,"metaTitle":862,"ogImage":59,"postType":863,"publishedDate":864,"relatedBlogPostsCollection":865,"slug":1677,"stem":1678,"subtitle":59,"summary":1679,"synopsis":1690,"sys":1691,"tagsCollection":1694,"topicsCollection":1698,"__hash__":1720},"blog\u002Fblog\u002Fproduct-release-july-2026.json","Product release: July 2026",{"items":437},[438],{"fullName":439,"firstName":440,"jobTitle":441,"socialLinks":59,"profilePicture":442},"Andy Waugh","Andy","VP Product",{"url":443},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F3Rf76rJn6S9inMb4dUnAIJ\u002F0a787f8141d05b95300e2fe77c4493fa\u002FDSC_6868.jpg",{"json":445,"links":789},{"data":446,"content":447,"nodeType":788},{},[448,457,503,510,526,533,542,549,569,576,591,598,604,626,644,651,676,683,689,710,728,735,742,748,769],{"data":449,"content":450,"nodeType":456},{},[451],{"data":452,"marks":453,"value":454,"nodeType":455},{},[],"What’s new this month","text","heading-1",{"data":458,"content":459,"nodeType":502},{},[460,472,482,492],{"data":461,"content":462,"nodeType":471},{},[463],{"data":464,"content":465,"nodeType":470},{},[466],{"data":467,"marks":468,"value":469,"nodeType":455},{},[],"Clipboard blocking","paragraph","list-item",{"data":473,"content":474,"nodeType":471},{},[475],{"data":476,"content":477,"nodeType":470},{},[478],{"data":479,"marks":480,"value":481,"nodeType":455},{},[],"File download blocking",{"data":483,"content":484,"nodeType":471},{},[485],{"data":486,"content":487,"nodeType":470},{},[488],{"data":489,"marks":490,"value":491,"nodeType":455},{},[],"File upload blocking & telemetry",{"data":493,"content":494,"nodeType":471},{},[495],{"data":496,"content":497,"nodeType":470},{},[498],{"data":499,"marks":500,"value":501,"nodeType":455},{},[],"App categorization","unordered-list",{"data":504,"content":505,"nodeType":456},{},[506],{"data":507,"marks":508,"value":509,"nodeType":455},{},[],"Prevent sensitive data from being copied and pasted",{"data":511,"content":512,"nodeType":470},{},[513,517,522],{"data":514,"marks":515,"value":516,"nodeType":455},{},[],"You can now block clipboard copy and paste operations containing content that is unauthorized, sensitive, or that doesn’t conform to your security policies using Push’s new ",{"data":518,"marks":519,"value":469,"nodeType":455},{},[520],{"type":521},"bold",{"data":523,"marks":524,"value":525,"nodeType":455},{},[]," control.",{"data":527,"content":528,"nodeType":470},{},[529],{"data":530,"marks":531,"value":532,"nodeType":455},{},[],"Push provides content patterns for common data types like API keys, personal access tokens, PII, and other sensitive information you may wish to monitor, warn, or block on. You can also define your own content patterns, or warn or block all clipboard actions for a given URL pattern.",{"data":534,"content":540,"nodeType":541},{"target":535},{"sys":536},{"id":537,"type":538,"linkType":539},"7aIWluJBmyEwqbyJIyj4yc","Link","Entry",[],"embedded-entry-block",{"data":543,"content":544,"nodeType":470},{},[545],{"data":546,"marks":547,"value":548,"nodeType":455},{},[],"Clipboard events matching your configured rules can be sent to your SIEM or other downstream tool using custom webhook.",{"data":550,"content":551,"nodeType":470},{},[552,555,566],{"data":553,"marks":554,"value":21,"nodeType":455},{},[],{"data":556,"content":560,"nodeType":565},{"target":557},{"sys":558},{"id":559,"type":538,"linkType":539},"1uLNsRZsrUu6zAIs1fKjAg",[561],{"data":562,"marks":563,"value":564,"nodeType":455},{},[],"Learn more","entry-hyperlink",{"data":567,"marks":568,"value":21,"nodeType":455},{},[],{"data":570,"content":571,"nodeType":456},{},[572],{"data":573,"marks":574,"value":575,"nodeType":455},{},[],"Block unauthorized or risky file downloads",{"data":577,"content":578,"nodeType":470},{},[579,583,587],{"data":580,"marks":581,"value":582,"nodeType":455},{},[],"Push can now block unpermitted or risky file downloads. Configure the ",{"data":584,"marks":585,"value":481,"nodeType":455},{},[586],{"type":521},{"data":588,"marks":589,"value":590,"nodeType":455},{},[]," control to enforce your security policy around when users are permitted to download specific file types or from specific destinations.",{"data":592,"content":593,"nodeType":470},{},[594],{"data":595,"marks":596,"value":597,"nodeType":455},{},[],"You can also use this capability to block downloads of unwanted AI tools.",{"data":599,"content":603,"nodeType":541},{"target":600},{"sys":601},{"id":602,"type":538,"linkType":539},"6CiB7JH42atcn7yQ6c3g6W",[],{"data":605,"content":606,"nodeType":470},{},[607,611,622],{"data":608,"marks":609,"value":610,"nodeType":455},{},[],"This feature complements the ",{"data":612,"content":616,"nodeType":565},{"target":613},{"sys":614},{"id":615,"type":538,"linkType":539},"2gzIJQtEn6hEzpGlpyVg2m",[617],{"data":618,"marks":619,"value":621,"nodeType":455},{},[620],{"type":521},"File download telemetry",{"data":623,"marks":624,"value":625,"nodeType":455},{},[]," feed, which allows you to capture all file download events in your environment.",{"data":627,"content":628,"nodeType":470},{},[629,632,641],{"data":630,"marks":631,"value":21,"nodeType":455},{},[],{"data":633,"content":637,"nodeType":565},{"target":634},{"sys":635},{"id":636,"type":538,"linkType":539},"4mYt4biAhBS6uEBoinYoQf",[638],{"data":639,"marks":640,"value":564,"nodeType":455},{},[],{"data":642,"marks":643,"value":21,"nodeType":455},{},[],{"data":645,"content":646,"nodeType":456},{},[647],{"data":648,"marks":649,"value":650,"nodeType":455},{},[],"Block file uploads and alert on file upload activity",{"data":652,"content":653,"nodeType":470},{},[654,658,663,667,672],{"data":655,"marks":656,"value":657,"nodeType":455},{},[],"You can also block file uploads using the new ",{"data":659,"marks":660,"value":662,"nodeType":455},{},[661],{"type":521},"File upload blocking",{"data":664,"marks":665,"value":666,"nodeType":455},{},[]," control, and consume a telemetry feed of all file upload events in your environment using ",{"data":668,"marks":669,"value":671,"nodeType":455},{},[670],{"type":521},"File upload telemetry",{"data":673,"marks":674,"value":675,"nodeType":455},{},[],".",{"data":677,"content":678,"nodeType":470},{},[679],{"data":680,"marks":681,"value":682,"nodeType":455},{},[],"For example, you may wish to block or warn users when they attempt to upload files that could contain sensitive information, or stop them from uploading files to AI apps that pose a risk for data loss or security incidents.",{"data":684,"content":688,"nodeType":541},{"target":685},{"sys":686},{"id":687,"type":538,"linkType":539},"7Ep9Jpd9eYkIXMjA4CDRpC",[],{"data":690,"content":691,"nodeType":470},{},[692,696,706],{"data":693,"marks":694,"value":695,"nodeType":455},{},[],"The complementary telemetry stream for this control allows you to consume events for ",{"data":697,"content":701,"nodeType":565},{"target":698},{"sys":699},{"id":700,"type":538,"linkType":539},"11Rc2WDooPUQzLR3gYz2KY",[702],{"data":703,"marks":704,"value":705,"nodeType":455},{},[],"all file uploads",{"data":707,"marks":708,"value":709,"nodeType":455},{},[]," in your environment.",{"data":711,"content":712,"nodeType":470},{},[713,716,725],{"data":714,"marks":715,"value":21,"nodeType":455},{},[],{"data":717,"content":721,"nodeType":565},{"target":718},{"sys":719},{"id":720,"type":538,"linkType":539},"5J29qC6WfSUOPwzTLmwiF5",[722],{"data":723,"marks":724,"value":564,"nodeType":455},{},[],{"data":726,"marks":727,"value":21,"nodeType":455},{},[],{"data":729,"content":730,"nodeType":456},{},[731],{"data":732,"marks":733,"value":734,"nodeType":455},{},[],"App categories now automatically applied",{"data":736,"content":737,"nodeType":470},{},[738],{"data":739,"marks":740,"value":741,"nodeType":455},{},[],"Push now automatically categorizes the apps in your inventory and new apps it observes. ",{"data":743,"content":747,"nodeType":541},{"target":744},{"sys":745},{"id":746,"type":538,"linkType":539},"5jebrzsn65MokK2rBst80",[],{"data":749,"content":750,"nodeType":470},{},[751,755,765],{"data":752,"marks":753,"value":754,"nodeType":455},{},[],"You can also use these categories to power ",{"data":756,"content":760,"nodeType":565},{"target":757},{"sys":758},{"id":759,"type":538,"linkType":539},"2ti5f4Eh4teqnVkKDgztcm",[761],{"data":762,"marks":763,"value":764,"nodeType":455},{},[],"App banner rules",{"data":766,"marks":767,"value":768,"nodeType":455},{},[],". For example, you may wish to block all file-sharing or AI apps except the ones you allow. ",{"data":770,"content":771,"nodeType":470},{},[772,775,784],{"data":773,"marks":774,"value":21,"nodeType":455},{},[],{"data":776,"content":780,"nodeType":565},{"target":777},{"sys":778},{"id":779,"type":538,"linkType":539},"2fdBRTkqFvlnmN5RnaBUj6",[781],{"data":782,"marks":783,"value":564,"nodeType":455},{},[],{"data":785,"marks":786,"value":787,"nodeType":455},{},[],"\n\n\n\n","document",{"entries":790},{"inline":791,"hyperlink":792,"block":829},[],[793,799,804,809,814,819,824],{"sys":794,"__typename":795,"title":796,"slug":797,"articleId":798},{"id":559},"HelpArticle","Can Push block clipboard actions?","can-push-block-clipboard-actions",10157,{"sys":800,"__typename":795,"title":801,"slug":802,"articleId":803},{"id":615},"Can Push detect and alert on file downloads?","can-push-detect-and-alert-on-file-downloads",10153,{"sys":805,"__typename":795,"title":806,"slug":807,"articleId":808},{"id":636},"Can Push block file downloads?","can-push-block-file-downloads",10158,{"sys":810,"__typename":795,"title":811,"slug":812,"articleId":813},{"id":700},"Can Push detect and alert on file uploads?","can-push-detect-and-alert-on-file-uploads",10154,{"sys":815,"__typename":795,"title":816,"slug":817,"articleId":818},{"id":720},"Can Push block file uploads?","can-push-block-file-uploads",10159,{"sys":820,"__typename":795,"title":821,"slug":822,"articleId":823},{"id":759},"How to create a rule for app banners","how-to-create-a-configuration-rule-for-app-banners",10125,{"sys":825,"__typename":795,"title":826,"slug":827,"articleId":828},{"id":779},"Does Push automatically categorize apps it discovers?","does-push-automatically-categorize-apps-it-discovers",10160,[830,838,845,851],{"sys":831,"__typename":832,"title":833,"caption":59,"layoutMode":59,"file":834},{"id":537},"Image","Clipboard warn example - release notes - July 2026",{"url":835,"width":836,"height":837},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F4NoWZp6WCmn6Zu6WNzcxxb\u002Fc723babb880e180adc67a0321738ea95\u002Fclipboard_warn_example.png",3420,2214,{"sys":839,"__typename":832,"title":840,"caption":59,"layoutMode":59,"file":841},{"id":602},"File download blocked banner - KB 10158",{"url":842,"width":843,"height":844},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002FD8ah4yuOUEGg0Oye7ty96\u002F4d4cec338176fc2b0cfd63f4c6fa7b74\u002Ffile_download_block_banner_20260609.png",1999,1096,{"sys":846,"__typename":832,"title":847,"caption":59,"layoutMode":59,"file":848},{"id":687},"File upload blocking example - KB 10159",{"url":849,"width":843,"height":850},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F6LLIBdYQ5D7bG7X6btlr27\u002F38f407c82af9d6c113f609a1f0a5e151\u002Ffile_upload_block_example_20260610.png",1072,{"sys":852,"__typename":832,"title":853,"caption":59,"layoutMode":59,"file":854},{"id":746},"App inventory - app categories - KB 10160",{"url":855,"width":856,"height":857},"https:\u002F\u002Fimages.ctfassets.net\u002Fy1cdw1ablpvd\u002F2PGW4nGLQvuz6HMakwp36p\u002F3f98e6964577f3abc8e624736d44a6e4\u002Fapp_categories_20260604.png",3012,1714,"json",{"items":860},[],{},"Push Security new product features for July 2026","release-notes","2026-07-20T00:00:00.000Z",{"items":866},[867,1162],{"__typename":868,"sys":869,"content":871,"title":1148,"synopsis":1149,"hashTags":59,"publishedDate":1150,"slug":1151,"tagsCollection":1152,"authorsCollection":1158},"BlogPosts",{"id":870},"4CnX1gLNvcwsbed1q4kTEj",{"json":872},{"data":873,"content":874,"nodeType":788},{},[875,881,923,930,937,944,951,994,1011,1018,1025,1032,1048,1055,1072,1078,1085,1103,1109,1127,1134,1141],{"data":876,"content":877,"nodeType":456},{},[878],{"data":879,"marks":880,"value":454,"nodeType":455},{},[],{"data":882,"content":883,"nodeType":502},{},[884,894,903,913],{"data":885,"content":886,"nodeType":471},{},[887],{"data":888,"content":889,"nodeType":470},{},[890],{"data":891,"marks":892,"value":893,"nodeType":455},{},[],"Custom detections",{"data":895,"content":896,"nodeType":471},{},[897],{"data":898,"content":899,"nodeType":470},{},[900],{"data":901,"marks":902,"value":621,"nodeType":455},{},[],{"data":904,"content":905,"nodeType":471},{},[906],{"data":907,"content":908,"nodeType":470},{},[909],{"data":910,"marks":911,"value":912,"nodeType":455},{},[],"Prevent password entry into non-password fields",{"data":914,"content":915,"nodeType":471},{},[916],{"data":917,"content":918,"nodeType":470},{},[919],{"data":920,"marks":921,"value":922,"nodeType":455},{},[],"Expansion of Events window to 30 days",{"data":924,"content":925,"nodeType":456},{},[926],{"data":927,"marks":928,"value":929,"nodeType":455},{},[],"Create your own custom detections",{"data":931,"content":932,"nodeType":470},{},[933],{"data":934,"marks":935,"value":936,"nodeType":455},{},[],"You can now write your own detections using Push’s real-time detection engine to target specific elements of the page DOM, web requests and responses, HTTP headers such as cookies, and a lot more.",{"data":938,"content":939,"nodeType":470},{},[940],{"data":941,"marks":942,"value":943,"nodeType":455},{},[],"Rules are written in YAML in the Push admin console. You can define a response action (e.g. Warn or Block) and customize the end-user message, similar to other Push controls.",{"data":945,"content":946,"nodeType":470},{},[947],{"data":948,"marks":949,"value":950,"nodeType":455},{},[],"Example use cases:",{"data":952,"content":953,"nodeType":502},{},[954,964,974,984],{"data":955,"content":956,"nodeType":471},{},[957],{"data":958,"content":959,"nodeType":470},{},[960],{"data":961,"marks":962,"value":963,"nodeType":455},{},[],"Detect a specific IOC or TTP for campaigns targeting your organization.",{"data":965,"content":966,"nodeType":471},{},[967],{"data":968,"content":969,"nodeType":470},{},[970],{"data":971,"marks":972,"value":973,"nodeType":455},{},[],"Partner with your red team to detect custom tooling during pen testing.",{"data":975,"content":976,"nodeType":471},{},[977],{"data":978,"content":979,"nodeType":470},{},[980],{"data":981,"marks":982,"value":983,"nodeType":455},{},[],"Alert on specific user behaviors on webpages that point to risk or violate policy.",{"data":985,"content":986,"nodeType":471},{},[987],{"data":988,"content":989,"nodeType":470},{},[990],{"data":991,"marks":992,"value":993,"nodeType":455},{},[],"Block unauthorized MCP connections.",{"data":995,"content":996,"nodeType":470},{},[997,1000,1008],{"data":998,"marks":999,"value":21,"nodeType":455},{},[],{"data":1001,"content":1003,"nodeType":1007},{"uri":1002},"https:\u002F\u002Fpushsecurity.com\u002Fhelp\u002Faudience\u002Fengineering\u002Fresources\u002Fcustom-detections",[1004],{"data":1005,"marks":1006,"value":564,"nodeType":455},{},[],"hyperlink",{"data":1009,"marks":1010,"value":21,"nodeType":455},{},[],{"data":1012,"content":1013,"nodeType":456},{},[1014],{"data":1015,"marks":1016,"value":1017,"nodeType":455},{},[],"Stream telemetry on file download events",{"data":1019,"content":1020,"nodeType":470},{},[1021],{"data":1022,"marks":1023,"value":1024,"nodeType":455},{},[],"You can now consume a feed of file download events into your SIEM or SOAR. These events report file metadata, such as file name, download URLs, and MIME type, as well as whether the download was considered unsafe.",{"data":1026,"content":1027,"nodeType":470},{},[1028],{"data":1029,"marks":1030,"value":1031,"nodeType":455},{},[],"Events are generated for traditional network-based downloads, but also downloads of files constructed in the browser, such as those via blob or data URLs.",{"data":1033,"content":1034,"nodeType":470},{},[1035,1039,1044],{"data":1036,"marks":1037,"value":1038,"nodeType":455},{},[],"You can enable this feed for all employees, employee groups, or specific individuals; and for all profiles, profiles logged in with a company domain, or profiles logged in with a non-company domain. Go to ",{"data":1040,"marks":1041,"value":1043,"nodeType":455},{},[1042],{"type":521},"Settings > Telemetry > File downloads",{"data":1045,"marks":1046,"value":1047,"nodeType":455},{},[]," to configure it.",{"data":1049,"content":1050,"nodeType":470},{},[1051],{"data":1052,"marks":1053,"value":1054,"nodeType":455},{},[],"Next, we’ll be adding a control that allows you implement a policy around which downloads are permitted from where, so you can block unwanted or potentially malicious files directly at the point of download.",{"data":1056,"content":1057,"nodeType":470},{},[1058,1061,1069],{"data":1059,"marks":1060,"value":21,"nodeType":455},{},[],{"data":1062,"content":1065,"nodeType":565},{"target":1063},{"sys":1064},{"id":615,"type":538,"linkType":539},[1066],{"data":1067,"marks":1068,"value":564,"nodeType":455},{},[],{"data":1070,"marks":1071,"value":21,"nodeType":455},{},[],{"data":1073,"content":1074,"nodeType":456},{},[1075],{"data":1076,"marks":1077,"value":912,"nodeType":455},{},[],{"data":1079,"content":1080,"nodeType":470},{},[1081],{"data":1082,"marks":1083,"value":1084,"nodeType":455},{},[],"You can prevent users from mistakenly entering their password into non-password fields such as username or email fields when they’re signing in to the app that password is associated with.",{"data":1086,"content":1087,"nodeType":470},{},[1088,1092,1100],{"data":1089,"marks":1090,"value":1091,"nodeType":455},{},[],"You may wish to prevent the entry of passwords into non-password fields particularly for core applications like your identity provider. By blocking incorrect password entry, you can avoid inadvertently recording passwords in your app logs, which can ",{"data":1093,"content":1095,"nodeType":1007},{"uri":1094},"https:\u002F\u002Fattack.mitre.org\u002Ftechniques\u002FT1552\u002F001\u002F",[1096],{"data":1097,"marks":1098,"value":1099,"nodeType":455},{},[],"introduce security risk",{"data":1101,"marks":1102,"value":675,"nodeType":455},{},[],{"data":1104,"content":1108,"nodeType":541},{"target":1105},{"sys":1106},{"id":1107,"type":538,"linkType":539},"1utNf3bb143PvfGS0BvDUK",[],{"data":1110,"content":1111,"nodeType":470},{},[1112,1115,1124],{"data":1113,"marks":1114,"value":21,"nodeType":455},{},[],{"data":1116,"content":1120,"nodeType":565},{"target":1117},{"sys":1118},{"id":1119,"type":538,"linkType":539},"2h2EfKDrmw2ZsXFQuBZmS4",[1121],{"data":1122,"marks":1123,"value":564,"nodeType":455},{},[],{"data":1125,"marks":1126,"value":21,"nodeType":455},{},[],{"data":1128,"content":1129,"nodeType":456},{},[1130],{"data":1131,"marks":1132,"value":1133,"nodeType":455},{},[],"Events page now displays up to 30 days of data",{"data":1135,"content":1136,"nodeType":470},{},[1137],{"data":1138,"marks":1139,"value":1140,"nodeType":455},{},[],"We’ve expanded the storage window for events viewable on the Push admin console Events page to assist with quick triage. It is now 30 days, instead of 7.",{"data":1142,"content":1143,"nodeType":470},{},[1144],{"data":1145,"marks":1146,"value":1147,"nodeType":455},{},[],"As before, we recommend ingesting Push events into your SIEM for longer-term storage, querying, and correlation.\n","Product release: May 2026","Here’s what’s new on the Push platform for May 2026.","2026-05-29T00:00:00.000Z","product-release-may-2026",{"items":1153},[1154],{"sys":1155,"name":1157},{"id":1156},"5jk0kqjSdSK2L0YiistQjY","Release notes",{"items":1159},[1160],{"fullName":439,"firstName":440,"jobTitle":441,"profilePicture":1161},{"url":443},{"__typename":868,"sys":1163,"content":1165,"title":1665,"synopsis":1666,"hashTags":59,"publishedDate":1667,"slug":1668,"tagsCollection":1669,"authorsCollection":1673},{"id":1164},"3Yw48rVLntipUijLR0CYf2",{"json":1166},{"data":1167,"content":1168,"nodeType":788},{},[1169,1176,1239,1246,1253,1269,1285,1291,1309,1315,1330,1337,1343,1361,1367,1388,1422,1440,1446,1453,1468,1474,1492,1498,1505,1529,1554,1572,1579,1586,1659],{"data":1170,"content":1171,"nodeType":456},{},[1172],{"data":1173,"marks":1174,"value":1175,"nodeType":455},{},[],"What's new this month:",{"data":1177,"content":1178,"nodeType":502},{},[1179,1189,1199,1209,1219,1229],{"data":1180,"content":1181,"nodeType":471},{},[1182],{"data":1183,"content":1184,"nodeType":470},{},[1185],{"data":1186,"marks":1187,"value":1188,"nodeType":455},{},[],"Detect malicious browser extensions",{"data":1190,"content":1191,"nodeType":471},{},[1192],{"data":1193,"content":1194,"nodeType":470},{},[1195],{"data":1196,"marks":1197,"value":1198,"nodeType":455},{},[],"Create a blocklist or allowlist for browser extensions",{"data":1200,"content":1201,"nodeType":471},{},[1202],{"data":1203,"content":1204,"nodeType":470},{},[1205],{"data":1206,"marks":1207,"value":1208,"nodeType":455},{},[],"Block ClickFix-style attacks and collect payloads for investigation",{"data":1210,"content":1211,"nodeType":471},{},[1212],{"data":1213,"content":1214,"nodeType":470},{},[1215],{"data":1216,"marks":1217,"value":1218,"nodeType":455},{},[],"Custom branding for employee-facing banners and block pages",{"data":1220,"content":1221,"nodeType":471},{},[1222],{"data":1223,"content":1224,"nodeType":470},{},[1225],{"data":1226,"marks":1227,"value":1228,"nodeType":455},{},[],"Collect additional metadata to support threat detection",{"data":1230,"content":1231,"nodeType":471},{},[1232],{"data":1233,"content":1234,"nodeType":470},{},[1235],{"data":1236,"marks":1237,"value":1238,"nodeType":455},{},[],"And a few other things … ",{"data":1240,"content":1241,"nodeType":456},{},[1242],{"data":1243,"marks":1244,"value":1245,"nodeType":455},{},[],"Detect malicious extensions",{"data":1247,"content":1248,"nodeType":470},{},[1249],{"data":1250,"marks":1251,"value":1252,"nodeType":455},{},[],"Push can now detect and block malicious browser extensions found in your environment. ",{"data":1254,"content":1255,"nodeType":470},{},[1256,1260,1265],{"data":1257,"marks":1258,"value":1259,"nodeType":455},{},[],"Push maintains a global list of malicious extensions based on our own threat research and publicly available threat intelligence. When an extension in your environment matches a malicious extension ID, Push will raise a detection on the ",{"data":1261,"marks":1262,"value":1264,"nodeType":455},{},[1263],{"type":521},"Detections",{"data":1266,"marks":1267,"value":1268,"nodeType":455},{},[]," page of the Push admin console. You can also configure the control to warn or block users automatically.",{"data":1270,"content":1271,"nodeType":470},{},[1272,1276,1281],{"data":1273,"marks":1274,"value":1275,"nodeType":455},{},[],"To enable malicious extension detection, go to the ",{"data":1277,"marks":1278,"value":1280,"nodeType":455},{},[1279],{"type":521},"Controls",{"data":1282,"marks":1283,"value":1284,"nodeType":455},{},[]," page in the Push admin console. ",{"data":1286,"content":1290,"nodeType":541},{"target":1287},{"sys":1288},{"id":1289,"type":538,"linkType":539},"1QV5UQ04MYLpWY7jTocvO4",[],{"data":1292,"content":1293,"nodeType":470},{},[1294,1297,1306],{"data":1295,"marks":1296,"value":21,"nodeType":455},{},[],{"data":1298,"content":1302,"nodeType":565},{"target":1299},{"sys":1300},{"id":1301,"type":538,"linkType":539},"5NyiWgjMDwk16XZ0S681JK",[1303],{"data":1304,"marks":1305,"value":564,"nodeType":455},{},[],{"data":1307,"marks":1308,"value":21,"nodeType":455},{},[],{"data":1310,"content":1311,"nodeType":456},{},[1312],{"data":1313,"marks":1314,"value":1198,"nodeType":455},{},[],{"data":1316,"content":1317,"nodeType":470},{},[1318,1322,1327],{"data":1319,"marks":1320,"value":1321,"nodeType":455},{},[],"You can also block unwanted extensions or allowlist only the extensions you want in your environment, using Push’s ",{"data":1323,"marks":1324,"value":1326,"nodeType":455},{},[1325],{"type":521},"Browser extension blocking",{"data":1328,"marks":1329,"value":525,"nodeType":455},{},[],{"data":1331,"content":1332,"nodeType":470},{},[1333],{"data":1334,"marks":1335,"value":1336,"nodeType":455},{},[],"End-users will see a block page if they attempt to enable a blocked extension or install one via the Chrome or Microsoft extension stores.",{"data":1338,"content":1342,"nodeType":541},{"target":1339},{"sys":1340},{"id":1341,"type":538,"linkType":539},"3OCdGfsyNTLXQx77dwzY9L",[],{"data":1344,"content":1345,"nodeType":470},{},[1346,1349,1358],{"data":1347,"marks":1348,"value":21,"nodeType":455},{},[],{"data":1350,"content":1354,"nodeType":565},{"target":1351},{"sys":1352},{"id":1353,"type":538,"linkType":539},"3ibVBa6u0XfcXXDVtON5th",[1355],{"data":1356,"marks":1357,"value":564,"nodeType":455},{},[],{"data":1359,"marks":1360,"value":21,"nodeType":455},{},[],{"data":1362,"content":1363,"nodeType":456},{},[1364],{"data":1365,"marks":1366,"value":1208,"nodeType":455},{},[],{"data":1368,"content":1369,"nodeType":470},{},[1370,1374,1384],{"data":1371,"marks":1372,"value":1373,"nodeType":455},{},[],"You can now block ClickFix-style malicious copy and paste attacks using Push. These are one of the ",{"data":1375,"content":1379,"nodeType":565},{"target":1376},{"sys":1377},{"id":1378,"type":538,"linkType":539},"1u8RJxC00HbBhCBVxcDnkK",[1380],{"data":1381,"marks":1382,"value":1383,"nodeType":455},{},[],"fastest-growing",{"data":1385,"marks":1386,"value":1387,"nodeType":455},{},[]," browser-based attacks. You can also choose to collect the payload for your security team to investigate.",{"data":1389,"content":1390,"nodeType":470},{},[1391,1395,1400,1404,1409,1413,1418],{"data":1392,"marks":1393,"value":1394,"nodeType":455},{},[],"From the Push admin console, go to ",{"data":1396,"marks":1397,"value":1399,"nodeType":455},{},[1398],{"type":521},"Controls > Malicious copy and paste detection",{"data":1401,"marks":1402,"value":1403,"nodeType":455},{},[],". Then create a configuration rule to select the ",{"data":1405,"marks":1406,"value":1408,"nodeType":455},{},[1407],{"type":521},"Mode",{"data":1410,"marks":1411,"value":1412,"nodeType":455},{},[]," and ",{"data":1414,"marks":1415,"value":1417,"nodeType":455},{},[1416],{"type":521},"Scope",{"data":1419,"marks":1420,"value":1421,"nodeType":455},{},[],". If you’ve enabled payload collection, Push will collect the malicious payload and include it in the detection event.",{"data":1423,"content":1424,"nodeType":470},{},[1425,1428,1437],{"data":1426,"marks":1427,"value":21,"nodeType":455},{},[],{"data":1429,"content":1433,"nodeType":565},{"target":1430},{"sys":1431},{"id":1432,"type":538,"linkType":539},"7jygmadjoz0asAHv7e5PuK",[1434],{"data":1435,"marks":1436,"value":564,"nodeType":455},{},[],{"data":1438,"marks":1439,"value":21,"nodeType":455},{},[],{"data":1441,"content":1442,"nodeType":456},{},[1443],{"data":1444,"marks":1445,"value":1218,"nodeType":455},{},[],{"data":1447,"content":1448,"nodeType":470},{},[1449],{"data":1450,"marks":1451,"value":1452,"nodeType":455},{},[],"Customize the look and feel of employee-facing banners and warn or block pages by adding your company logo, accent color, and choice of light or dark mode themes. ",{"data":1454,"content":1455,"nodeType":470},{},[1456,1460,1465],{"data":1457,"marks":1458,"value":1459,"nodeType":455},{},[],"To add your brand elements, go to ",{"data":1461,"marks":1462,"value":1464,"nodeType":455},{},[1463],{"type":521},"Settings > Branding",{"data":1466,"marks":1467,"value":675,"nodeType":455},{},[],{"data":1469,"content":1473,"nodeType":541},{"target":1470},{"sys":1471},{"id":1472,"type":538,"linkType":539},"3Jawd7IBSA3GF2XBHARsn",[],{"data":1475,"content":1476,"nodeType":470},{},[1477,1480,1489],{"data":1478,"marks":1479,"value":21,"nodeType":455},{},[],{"data":1481,"content":1485,"nodeType":565},{"target":1482},{"sys":1483},{"id":1484,"type":538,"linkType":539},"4i1KWgBfYqtFYlUFRYiGdW",[1486],{"data":1487,"marks":1488,"value":564,"nodeType":455},{},[],{"data":1490,"marks":1491,"value":21,"nodeType":455},{},[],{"data":1493,"content":1494,"nodeType":456},{},[1495],{"data":1496,"marks":1497,"value":1228,"nodeType":455},{},[],{"data":1499,"content":1500,"nodeType":470},{},[1501],{"data":1502,"marks":1503,"value":1504,"nodeType":455},{},[],"The Push browser extension can now collect additional metadata and store it locally for up to 30 days, powering more diverse and precise detections, including for emerging threats. ",{"data":1506,"content":1507,"nodeType":470},{},[1508,1512,1516,1520,1525],{"data":1509,"marks":1510,"value":1511,"nodeType":455},{},[],"Detections informed by this metadata will be raised on the ",{"data":1513,"marks":1514,"value":1264,"nodeType":455},{},[1515],{"type":521},{"data":1517,"marks":1518,"value":1519,"nodeType":455},{},[]," page. Note that these detections do not block end-user activity and are ",{"data":1521,"marks":1522,"value":1524,"nodeType":455},{},[1523],{"type":521},"Monitor",{"data":1526,"marks":1527,"value":1528,"nodeType":455},{},[]," mode only.",{"data":1530,"content":1531,"nodeType":470},{},[1532,1536,1541,1545,1550],{"data":1533,"marks":1534,"value":1535,"nodeType":455},{},[],"We recommend you enable ",{"data":1537,"marks":1538,"value":1540,"nodeType":455},{},[1539],{"type":521},"Browser event storage",{"data":1542,"marks":1543,"value":1544,"nodeType":455},{},[]," to take advantage of this capability. Go to ",{"data":1546,"marks":1547,"value":1549,"nodeType":455},{},[1548],{"type":521},"Settings > Telemetry > Browser event storage",{"data":1551,"marks":1552,"value":1553,"nodeType":455},{},[]," in the admin console.",{"data":1555,"content":1556,"nodeType":470},{},[1557,1560,1569],{"data":1558,"marks":1559,"value":21,"nodeType":455},{},[],{"data":1561,"content":1565,"nodeType":565},{"target":1562},{"sys":1563},{"id":1564,"type":538,"linkType":539},"1x69JxXcDWEDIzYXUM8nGb",[1566],{"data":1567,"marks":1568,"value":564,"nodeType":455},{},[],{"data":1570,"marks":1571,"value":21,"nodeType":455},{},[],{"data":1573,"content":1574,"nodeType":456},{},[1575],{"data":1576,"marks":1577,"value":1578,"nodeType":455},{},[],"And a few other things ...",{"data":1580,"content":1581,"nodeType":470},{},[1582],{"data":1583,"marks":1584,"value":1585,"nodeType":455},{},[],"Other new features or improvements to the platform include:",{"data":1587,"content":1588,"nodeType":502},{},[1589,1609,1619,1639],{"data":1590,"content":1591,"nodeType":471},{},[1592],{"data":1593,"content":1594,"nodeType":470},{},[1595,1599,1606],{"data":1596,"marks":1597,"value":1598,"nodeType":455},{},[],"You can now configure the frequency with which app banners will be displayed: either per-tab or per-browser. ",{"data":1600,"content":1602,"nodeType":1007},{"uri":1601},"\u002Fhelp\u002F10125#frequency",[1603],{"data":1604,"marks":1605,"value":564,"nodeType":455},{},[],{"data":1607,"marks":1608,"value":21,"nodeType":455},{},[],{"data":1610,"content":1611,"nodeType":471},{},[1612],{"data":1613,"content":1614,"nodeType":470},{},[1615],{"data":1616,"marks":1617,"value":1618,"nodeType":455},{},[],"You can now define an Owner role as part of Push’s RBAC options. Only Owners can edit roles, delete your team (e.g. tenant), change default SAML roles, or update your team name.",{"data":1620,"content":1621,"nodeType":471},{},[1622],{"data":1623,"content":1624,"nodeType":470},{},[1625,1629,1636],{"data":1626,"marks":1627,"value":1628,"nodeType":455},{},[],"Webhook events now include detection details, for greater context. ",{"data":1630,"content":1632,"nodeType":1007},{"uri":1631},"https:\u002F\u002Fpushsecurity.com\u002Fhelp\u002Faudience\u002Fengineering\u002Fwebhooks-v1\u002Fdetections",[1633],{"data":1634,"marks":1635,"value":564,"nodeType":455},{},[],{"data":1637,"marks":1638,"value":21,"nodeType":455},{},[],{"data":1640,"content":1641,"nodeType":471},{},[1642],{"data":1643,"content":1644,"nodeType":470},{},[1645,1649,1656],{"data":1646,"marks":1647,"value":1648,"nodeType":455},{},[],"Push now uses static IP addresses to emit webhook events. These IP addresses are in the same range we previously used, but if you wish to update your network filtering to these new, narrower IP addresses, you can. ",{"data":1650,"content":1652,"nodeType":1007},{"uri":1651},"https:\u002F\u002Fpushsecurity.com\u002Fhelp\u002Faudience\u002Fengineering\u002Fwebhooks-v1\u002Fsection\u002Fip-addresses",[1653],{"data":1654,"marks":1655,"value":564,"nodeType":455},{},[],{"data":1657,"marks":1658,"value":21,"nodeType":455},{},[],{"data":1660,"content":1661,"nodeType":470},{},[1662],{"data":1663,"marks":1664,"value":21,"nodeType":455},{},[],"Product release: March 2026","Here’s what’s new on the Push platform for March 2026.","2026-03-10T00:00:00.000Z","product-release-march-2026",{"items":1670},[1671],{"sys":1672,"name":1157},{"id":1156},{"items":1674},[1675],{"fullName":439,"firstName":440,"jobTitle":441,"profilePicture":1676},{"url":443},"product-release-july-2026","blog\u002Fproduct-release-july-2026",{"json":1680},{"data":1681,"content":1682,"nodeType":788},{},[1683],{"data":1684,"content":1685,"nodeType":470},{},[1686],{"data":1687,"marks":1688,"value":1689,"nodeType":455},{},[],"Clipboard blocking, file download blocking, app categorization, and more","Here’s what’s new on the Push platform for July 2026.",{"id":1692,"publishedAt":1693},"76c5Oo3kktjFa1oUQoCYSu","2026-08-12T11:52:39.380Z",{"items":1695},[1696],{"sys":1697,"name":1157},{"id":1156},{"items":1699},[1700,1705,1710,1715],{"sys":1701,"name":1703,"slug":1704,"tier":31},{"id":1702},"topic-browser-security","Browser security","browser-security",{"sys":1706,"name":1708,"slug":1709,"tier":45},{"id":1707},"topic-dlp","DLP","dlp",{"sys":1711,"name":1713,"slug":1714,"tier":45},{"id":1712},"topic-shadow-saas","Shadow SaaS","shadow-saas",{"sys":1716,"name":1718,"slug":1719,"tier":45},{"id":1717},"topic-shadow-ai","Shadow AI","shadow-ai","KqgkacUcUOlS0kauLuxOpwFUea0oLkCATd3yAMW2cVs",{"id":1722,"extension":858,"items":1723,"meta":2131,"stem":2132,"__hash__":2133},"blogTopics\u002Fblogtopics.json",[1724,1733,1742,1751,1760,1769,1778,1787,1793,1802,1811,1820,1828,1837,1846,1854,1860,1869,1878,1886,1895,1904,1913,1922,1930,1939,1948,1957,1966,1975,1983,1992,2001,2009,2018,2026,2035,2043,2052,2060,2066,2071,2079,2087,2095,2104,2113,2122],{"sys":1725,"faqItemsCollection":1727,"name":1729,"slug":1730,"tier":31,"intro":1731,"faqTitle":59,"postCount":1732,"hasPage":19},{"id":1726},"topic-ai",{"items":1728},[],"AI","ai","AI is reshaping both sides of the security equation: employees adopt AI tools faster than security teams can track them, while attackers use AI to scale and automate campaigns. Shadow AI adoption may now outpace wider shadow SaaS, and attackers are already turning AI chatbot platforms into malware delivery channels. Push has researched the offensive potential of computer-using agents and now applies AI agents to its own threat hunting. This hub covers AI as risk, target, and defensive tool.",22,{"sys":1734,"faqItemsCollection":1736,"name":1738,"slug":1739,"tier":45,"intro":1740,"faqTitle":59,"postCount":1741,"hasPage":19},{"id":1735},"topic-ai-attacks",{"items":1737},[],"AI attacks","ai-attacks","AI attacks run in both directions: attackers using AI to scale phishing, malware delivery, and identity attacks, and AI platforms themselves becoming the attack surface. Push has researched how computer-using agents can automate identity attacks, and has seen the poisoned tenant technique it coined used against its own employees in the wild.",23,{"sys":1743,"faqItemsCollection":1745,"name":1747,"slug":1748,"tier":45,"intro":1749,"faqTitle":59,"postCount":1750,"hasPage":19},{"id":1744},"topic-ai-governance",{"items":1746},[],"AI governance","ai-governance","AI governance is how organizations set and enforce rules for workplace AI use — which tools are allowed, what data can enter them, and how to evidence it to regulators. With US, EU, and UK AI regulations converging on obligations most organizations can’t yet meet, Push’s research makes the case that enforcement starts in the browser, where AI tools are actually used.",9,{"sys":1752,"faqItemsCollection":1754,"name":1756,"slug":1757,"tier":45,"intro":1758,"faqTitle":59,"postCount":1759,"hasPage":19},{"id":1753},"topic-aitm",{"items":1755},[],"AiTM phishing","aitm","Adversary-in-the-middle (AiTM) phishing proxies a real login page through an attacker-controlled site, capturing credentials, MFA codes, and session tokens in real time to bypass multi-factor authentication. Push’s research into kits like Evilginx and Sneaky2FA documents how they evade URL- and signature-based detection — and why analyzing toolkit behavior in the browser catches attacks that blocklists miss.",78,{"sys":1761,"faqItemsCollection":1763,"name":1765,"slug":1766,"tier":45,"intro":1767,"faqTitle":59,"postCount":1768,"hasPage":6},{"id":1762},"topic-bec",{"items":1764},[],"BEC","bec","Business email compromise (BEC) turns a hijacked mailbox into a fraud tool: attackers use mail rules, auto-forwarding, and payment redirection to steal money while staying invisible to the account owner. Alongside a first-hand case study of a BEC attack that nearly cost an engineering firm millions, Push breaks down these mailbox persistence tricks and how to detect them.",4,{"sys":1770,"faqItemsCollection":1772,"name":1774,"slug":1775,"tier":31,"intro":1776,"faqTitle":59,"postCount":1777,"hasPage":19},{"id":1771},"topic-browser-attacks",{"items":1773},[],"Browser attacks","browser-attacks","Browser attacks target users through the web pages, sessions, and extensions they rely on every day — bypassing endpoint and network defenses that never see inside the browser. Techniques like AiTM phishing kits, ClickFix-style copy-paste attacks, OAuth consent abuse, malvertising, and browser sync abuse have become a leading path to account takeover. Push researchers analyze these attacks in the wild, from infiltrating criminal phishing panels to dissecting toolkits like ConsentFix and Sneaky2FA. Use this hub to track how the techniques evolve and how to defend against them.",122,{"sys":1779,"faqItemsCollection":1781,"name":1783,"slug":1784,"tier":45,"intro":1785,"faqTitle":59,"postCount":1786,"hasPage":19},{"id":1780},"topic-browser-extensions",{"items":1782},[],"Browser extensions","browser-extensions","Browser extensions cut both ways for security teams: malicious or compromised extensions are a growing attack vector, while an extension is also the lightest-weight way to deploy security controls into the browsers employees already use. These posts cover both sides — extension-borne risks like browser sync attacks and the limits of risk scoring, and how Push uses its extension to detect threats and block risky extensions.",31,{"sys":1788,"faqItemsCollection":1789,"name":1703,"slug":1704,"tier":31,"intro":1791,"faqTitle":59,"postCount":1792,"hasPage":19},{"id":1702},{"items":1790},[],"Work now happens in the browser, making browser security — visibility and control at the point where users meet the web — a core layer of enterprise defense. Endpoint, network, and email tools miss attacks that unfold inside the browser session, from AiTM phishing to risky extensions and shadow SaaS. Push has published extensively on choosing between enterprise browsers and browser extensions, using browser telemetry, and making the business case for browser security. Start here for both strategy and hands-on guidance.",129,{"sys":1794,"faqItemsCollection":1796,"name":1798,"slug":1799,"tier":45,"intro":1800,"faqTitle":59,"postCount":1801,"hasPage":19},{"id":1795},"topic-casb",{"items":1797},[],"CASB","casb","Cloud access security brokers (CASBs) govern cloud app usage through API integrations and network proxies — an approach that works for sanctioned apps but struggles with the long tail of shadow SaaS employees adopt on their own. Because every SaaS signup happens in a browser, Push captures that adoption in real time at the point of login, and these posts cover what proxy-based discovery misses.",12,{"sys":1803,"faqItemsCollection":1805,"name":1807,"slug":1808,"tier":45,"intro":1809,"faqTitle":59,"postCount":1810,"hasPage":19},{"id":1804},"topic-clickfix",{"items":1806},[],"ClickFix","clickfix","ClickFix attacks trick users into copying and running malicious commands themselves — typically through fake CAPTCHA, error, or fix-it prompts — so malware executes without a download for security tools to scan. Push researchers track the technique’s evolution in the wild and identified the ConsentFix and InstallFix variants, which extend it to OAuth consent grants and fake install guides.",40,{"sys":1812,"faqItemsCollection":1814,"name":1816,"slug":1817,"tier":45,"intro":1818,"faqTitle":59,"postCount":1819,"hasPage":19},{"id":1813},"topic-credential-phishing",{"items":1815},[],"Credential phishing","credential-phishing","Credential phishing steals usernames and passwords through fake login pages impersonating the services employees use, handing attackers direct access to corporate accounts. Attackers don’t hack in — they log in. Push’s browser extension analyzes login pages as users actually see them, blocking cloned pages and stopping employees from entering company passwords on lookalike sites.",90,{"sys":1821,"faqItemsCollection":1823,"name":308,"slug":1825,"tier":45,"intro":1826,"faqTitle":59,"postCount":1827,"hasPage":19},{"id":1822},"topic-credential-stuffing",{"items":1824},[],"credential-stuffing","Credential stuffing is an attack where criminals replay username-password pairs stolen from one breach against other services, exploiting password reuse to take over accounts. Major breaches have shown how far a single set of stolen credentials can travel. Push detects verified stolen credentials by comparing employee passwords against breach datasets and dark-web threat intelligence, eliminating false positives.",64,{"sys":1829,"faqItemsCollection":1831,"name":1833,"slug":1834,"tier":31,"intro":1835,"faqTitle":59,"postCount":1836,"hasPage":19},{"id":1830},"topic-detection-and-response",{"items":1832},[],"Detection & response","detection-and-response","Detection and response is being reshaped as attacks move into the browser, where EDR, SIEM, and network tools have limited visibility. Modern phishing kits evade signature-based detection, and most malicious pages have never been seen before — so technique-level, in-browser detection matters more than known-bad indicators. Push’s work here spans high-fidelity browser telemetry, session token theft detection, and agentic threat hunting, plus practical IR guidance for compromised SaaS accounts and malicious OAuth apps. These posts cover both the philosophy and the workflows.",102,{"sys":1838,"faqItemsCollection":1840,"name":1842,"slug":1843,"tier":45,"intro":1844,"faqTitle":59,"postCount":1845,"hasPage":19},{"id":1839},"topic-detection-engineering",{"items":1841},[],"Detection engineering","detection-engineering","Detection engineering turns threat research into reliable, high-fidelity detections — and as AI accelerates the churn of attacker infrastructure, indicator-based detection is collapsing in favor of technique-level approaches. Here you’ll find teardowns of AiTM kits, ClickFix pages, and malvertising campaigns, alongside Push’s own account of building an agentic threat hunting pipeline that turns hunts into shipped detections.",43,{"sys":1847,"faqItemsCollection":1849,"name":269,"slug":1851,"tier":45,"intro":1852,"faqTitle":59,"postCount":1853,"hasPage":19},{"id":1848},"topic-device-code-phishing",{"items":1850},[],"device-code-phishing","Device code phishing abuses the OAuth device authorization flow: attackers generate a legitimate sign-in code, trick the victim into entering it on the vendor’s real login page, and walk away with access tokens — no fake site or password capture required. Push research tracked a sharp spike in adoption during 2026 as attackers use the technique to sidestep standard access controls.",24,{"sys":1855,"faqItemsCollection":1856,"name":1708,"slug":1709,"tier":45,"intro":1858,"faqTitle":59,"postCount":1859,"hasPage":19},{"id":1707},{"items":1857},[],"Data loss prevention (DLP) is the practice of stopping sensitive data from leaving your control — a problem that has shifted from email and endpoints to the browser, where employees move data into SaaS and AI tools. Push applies controls at that point of use, from keeping corporate credentials out of personal password managers to governing what flows into unsanctioned apps.",15,{"sys":1861,"faqItemsCollection":1863,"name":1865,"slug":1866,"tier":45,"intro":1867,"faqTitle":59,"postCount":1868,"hasPage":19},{"id":1862},"topic-edr",{"items":1864},[],"EDR","edr","Endpoint detection and response (EDR) watches processes, files, and memory on the device — a vantage point that never sees the phishing pages, stolen sessions, and identity attacks playing out inside the browser. That’s not an EDR failure; attackers have simply moved where it can’t follow. These posts map that gap and show how Push pairs browser-level detection and response with endpoint security to close it.",25,{"sys":1870,"faqItemsCollection":1872,"name":1874,"slug":1875,"tier":45,"intro":1876,"faqTitle":59,"postCount":1877,"hasPage":19},{"id":1871},"topic-enterprise-browser",{"items":1873},[],"Enterprise browser","enterprise-browser","An enterprise browser is a standalone, security-hardened browser that organizations deploy in place of Chrome, Edge, or other defaults. The real buying question is whether replacing the browser beats securing the browsers employees already use — a trade-off these posts examine directly, alongside analysis of Omdia’s secure enterprise browser market report and Push’s framework for weighing full browsers against extension-based deployment.",8,{"sys":1879,"faqItemsCollection":1881,"name":298,"slug":1883,"tier":45,"intro":1884,"faqTitle":59,"postCount":1885,"hasPage":19},{"id":1880},"topic-ghost-logins",{"items":1882},[],"ghost-logins","Ghost logins are overlooked authentication routes into an account — like a password login lingering behind SSO, or a forgotten secondary auth method — that attackers exploit for account takeover and persistence. Push coined the term after research showing how these forgotten login paths let attackers sidestep the MFA and SSO controls guarding an account’s primary sign-in method.",48,{"sys":1887,"faqItemsCollection":1889,"name":1891,"slug":1892,"tier":45,"intro":1893,"faqTitle":59,"postCount":1894,"hasPage":19},{"id":1888},"topic-identity-attacks",{"items":1890},[],"Identity attacks","identity-attacks","Identity attacks target user accounts rather than infrastructure — phishing credentials, stealing sessions, abusing OAuth grants — because logging in is easier than hacking in. Identity-based techniques are now the leading cause of breaches. Push’s offensive research maps these techniques continuously, coining attacks like SAMLjacking and the poisoned tenant before they appeared in the wild.",58,{"sys":1896,"faqItemsCollection":1898,"name":1900,"slug":1901,"tier":31,"intro":1902,"faqTitle":59,"postCount":1903,"hasPage":19},{"id":1897},"topic-identity-security",{"items":1899},[],"Identity security","identity-security","Identity security is the practice of protecting workforce accounts, credentials, and sessions — the primary route attackers now use to breach organizations. Instead of hacking in, attackers log in: through phished credentials, stolen session tokens, MFA bypass, and forgotten ghost logins. Push’s research team documents these techniques continuously, from cross-IdP impersonation and SAMLjacking to analyses of major identity-driven breaches. This hub collects that research alongside practical guidance on MFA, SSO, and stopping account takeover.",154,{"sys":1905,"faqItemsCollection":1907,"name":1909,"slug":1910,"tier":45,"intro":1911,"faqTitle":59,"postCount":1912,"hasPage":19},{"id":1906},"topic-infostealer",{"items":1908},[],"Infostealer","infostealer","Infostealers are malware built to harvest saved passwords, cookies, and session tokens from infected devices, supplying the stolen credentials behind some of the most consequential breaches of recent years. Push traces the ecosystem trading this data and checks employee passwords against threat intel feeds, flagging verified stolen credentials before attackers can log in with them.",53,{"sys":1914,"faqItemsCollection":1916,"name":1918,"slug":1919,"tier":45,"intro":1920,"faqTitle":59,"postCount":1921,"hasPage":19},{"id":1915},"topic-legitimate-service-abuse",{"items":1917},[],"Legitimate service abuse","legitimate-service-abuse","Legitimate service abuse means staging attacks on trusted platforms — Google Ads, AI chatbot share pages, office.com links, Slack, SaaS tenants — so malicious content inherits the reputation of the service hosting it. Push research has documented the pattern repeatedly, from malvertising run through hijacked Google Ad Manager accounts to phishing links generated by Active Directory Federation Services.",29,{"sys":1923,"faqItemsCollection":1925,"name":1927,"slug":1928,"tier":45,"intro":1929,"faqTitle":59,"postCount":1786,"hasPage":19},{"id":1924},"topic-malvertising",{"items":1926},[],"Malvertising","malvertising","Malvertising uses paid search and display ads to put phishing pages and malware in front of users, often by impersonating trusted brands at the top of Google results. Push tracks these campaigns continuously — intercepting live attacks spoofing well-known brands — and has documented how criminals hijack Google Ads accounts to fund and run them.",{"sys":1931,"faqItemsCollection":1933,"name":1935,"slug":1936,"tier":45,"intro":1937,"faqTitle":59,"postCount":1938,"hasPage":19},{"id":1932},"topic-malware-delivery",{"items":1934},[],"Malware delivery","malware-delivery","Malware delivery has moved into the browser: rather than email attachments, attackers now rely on malvertising, fake install guides, and ClickFix-style copy-paste lures to get code running on endpoints. Push research on techniques like InstallFix maps the playbook, and in-browser detection of malicious copy and paste blocks these attacks before commands reach the endpoint.",14,{"sys":1940,"faqItemsCollection":1942,"name":1944,"slug":1945,"tier":45,"intro":1946,"faqTitle":59,"postCount":1947,"hasPage":19},{"id":1941},"topic-mfa",{"items":1943},[],"MFA","mfa","Multi-factor authentication (MFA) requires a second proof of identity beyond a password, and it remains one of the most effective controls against account takeover. Regulators from Cyber Essentials to NYDFS now mandate it across cloud services. Push enforces MFA in the browser on third-party apps — even those with no native enforcement option — and shows security teams where coverage gaps remain.",83,{"sys":1949,"faqItemsCollection":1951,"name":1953,"slug":1954,"tier":45,"intro":1955,"faqTitle":59,"postCount":1956,"hasPage":19},{"id":1950},"topic-mfa-bypass",{"items":1952},[],"MFA bypass","mfa-bypass","MFA bypass covers the techniques attackers use to defeat multi-factor authentication — AiTM phishing kits, consent phishing, device code phishing, and MFA downgrade attacks among them. None of these break the second factor; they route around it. Push researchers regularly get hands-on with phishing kits like Evilginx and Sneaky2FA, analyzing how these attacks work in the wild and how they evolve.",60,{"sys":1958,"faqItemsCollection":1960,"name":1962,"slug":1963,"tier":45,"intro":1964,"faqTitle":59,"postCount":1965,"hasPage":19},{"id":1959},"topic-non-email-phishing",{"items":1961},[],"Non-email phishing","non-email-phishing","Non-email phishing delivers malicious links through channels your secure email gateway never sees — social media messages, IM apps like Slack and Teams, search ads, and SMS. Push has intercepted live campaigns arriving via LinkedIn DMs, malvertising, and messaging platforms, which is why it detects phishing pages in the browser at the point of click, regardless of delivery channel.",52,{"sys":1967,"faqItemsCollection":1969,"name":1971,"slug":1972,"tier":45,"intro":1973,"faqTitle":59,"postCount":1974,"hasPage":19},{"id":1968},"topic-oauth-abuse",{"items":1970},[],"OAuth abuse","oauth-abuse","OAuth abuse is attackers exploiting app-to-app authorization — consent phishing, malicious OAuth apps, stolen tokens, and device code flows — to gain persistent access to cloud tenants without touching a password or MFA prompt. Push tracks these techniques continuously and discovered ConsentFix, a browser-native attack in the wild that pairs OAuth consent phishing with a ClickFix-style prompt.",70,{"sys":1976,"faqItemsCollection":1978,"name":1980,"slug":1981,"tier":45,"intro":1982,"faqTitle":59,"postCount":1741,"hasPage":19},{"id":1977},"topic-passkeys",{"items":1979},[],"Passkeys","passkeys","Passkeys are phishing-resistant credentials that replace passwords with cryptographic key pairs bound to a user’s device. They defeat conventional credential phishing, but attackers adapt: Push research has documented MFA downgrade, app-specific password phishing, and device code phishing being used in the wild to route around passkey-protected accounts. Deploying passkeys is step one; closing those fallback paths is step two.",{"sys":1984,"faqItemsCollection":1986,"name":1988,"slug":1989,"tier":45,"intro":1990,"faqTitle":59,"postCount":1991,"hasPage":19},{"id":1985},"topic-password-security",{"items":1987},[],"Password security","password-security","Password security is the practice of keeping workforce credentials strong, unique, and out of attackers’ hands — still a frontline defense while most SaaS logins depend on passwords. Expiration policies don’t fix weak or reused passwords; visibility does. Push observes real logins in the browser to flag weak, reused, and breached passwords and guide employees to reset them on any app.",80,{"sys":1993,"faqItemsCollection":1995,"name":1997,"slug":1998,"tier":45,"intro":1999,"faqTitle":59,"postCount":2000,"hasPage":19},{"id":1994},"topic-phaas",{"items":1996},[],"PhaaS","phaas","Phishing-as-a-service (PhaaS) platforms sell ready-made phishing kits, hosted infrastructure, and management panels on subscription, letting low-skill criminals run MFA-bypassing campaigns at scale. Kits like Evilginx, Tycoon2FA, Sneaky2FA, FlowerStorm, and EvilTokens each add their own evasion and session-theft capabilities, and new entrants appear regularly. Push researchers continuously get hands-on with these tools — investigating attacks in the wild, reverse-engineering kit behavior, and turning that research into detections.",41,{"sys":2002,"faqItemsCollection":2004,"name":254,"slug":2006,"tier":31,"intro":2007,"faqTitle":59,"postCount":2008,"hasPage":19},{"id":2003},"topic-phishing",{"items":2005},[],"phishing","Phishing remains the most common way attackers compromise business accounts — and it has moved far beyond suspicious emails. Modern campaigns use AiTM toolkits that bypass MFA, consent phishing against OAuth, device code phishing, and lures delivered through malvertising, LinkedIn, and Slack. Push detects and blocks these attacks in the browser, and its researchers publish teardowns of live campaigns and kits like Evilginx and Sneaky2FA. Read on for how phishing actually works today and what stops it.",93,{"sys":2010,"faqItemsCollection":2012,"name":2014,"slug":2015,"tier":45,"intro":2016,"faqTitle":59,"postCount":2017,"hasPage":19},{"id":2011},"topic-public-breach",{"items":2013},[],"Public breach","public-breach","Public breaches are the disclosed incidents that show how attacks actually unfold once the headlines fade. Push’s breach analyses keep finding identity at the entry point: stolen credentials, OAuth abuse, and missing MFA recur across the incidents analyzed here.",30,{"sys":2019,"faqItemsCollection":2021,"name":2023,"slug":2024,"tier":45,"intro":2025,"faqTitle":59,"postCount":1938,"hasPage":19},{"id":2020},"topic-ransomware",{"items":2022},[],"Ransomware","ransomware","Ransomware attacks increasingly begin with an identity, not an exploit: stolen credentials, MFA bypass, and help desk scams give operators their initial foothold. The analysis here follows that front end of the kill chain — how identity compromise leads to ransomware deployment, and the breaches driving regulators toward tighter MFA requirements.",{"sys":2027,"faqItemsCollection":2029,"name":2031,"slug":2032,"tier":31,"intro":2033,"faqTitle":59,"postCount":2034,"hasPage":19},{"id":2028},"topic-saas-security",{"items":2030},[],"SaaS security","saas-security","SaaS security means protecting the sprawl of cloud apps, accounts, and integrations your employees adopt — often without IT ever knowing. Shadow SaaS, risky OAuth grants, ghost logins, and unmanaged third-party access create attack paths traditional controls can’t see, as recent high-profile breaches have demonstrated. Building on the original SaaS attack matrix, Push continues to map SaaS-native attack techniques alongside practical guides for discovering and securing unsanctioned apps, and this hub gathers all of it.",97,{"sys":2036,"faqItemsCollection":2038,"name":2040,"slug":2041,"tier":45,"intro":2042,"faqTitle":59,"postCount":1768,"hasPage":6},{"id":2037},"topic-security-training",{"items":2039},[],"Security training","security-training","Security training aims to teach employees to recognize and avoid attacks — yet modern phishing routinely fools even seasoned security professionals. Push argues that training budgets work harder as real-time, in-browser intervention: guardrails and warnings at the moment of risk, rather than lessons employees must recall under pressure.",{"sys":2044,"faqItemsCollection":2046,"name":2048,"slug":2049,"tier":45,"intro":2050,"faqTitle":59,"postCount":2051,"hasPage":19},{"id":2045},"topic-seo-poisoning",{"items":2047},[],"SEO poisoning","seo-poisoning","SEO poisoning manipulates search engine results so malicious pages rank prominently for the software, tools, or services users are actively searching for, turning a routine search into an infection vector. It often pairs with malvertising and ClickFix-style payloads — Push has documented attackers abusing shared pages on legitimate AI chatbot domains to deliver malware from trusted infrastructure.",7,{"sys":2053,"faqItemsCollection":2055,"name":313,"slug":2057,"tier":45,"intro":2058,"faqTitle":59,"postCount":2059,"hasPage":19},{"id":2054},"topic-session-hijacking",{"items":2056},[],"session-hijacking","Session hijacking is the theft of an authenticated session — usually via stolen session cookies or tokens — letting attackers walk past passwords and MFA into a live account. AiTM phishing kits and infostealers have made it a mainstream attack technique across both criminal and targeted intrusions. Push’s browser agent detects session token theft by adding telemetry to the user agent string, creating a high-fidelity signal for security teams.",75,{"sys":2061,"faqItemsCollection":2062,"name":1718,"slug":1719,"tier":45,"intro":2064,"faqTitle":59,"postCount":2065,"hasPage":19},{"id":1717},{"items":2063},[],"Shadow AI is employees’ unsanctioned use of AI tools at work, putting corporate data into chatbots and assistants that security teams never approved and can’t see. Push’s own browser telemetry shows AI adoption acting as a force multiplier for shadow IT — potentially now outscaling shadow SaaS — and this hub tracks that research, real-world breach examples, and practical controls.",20,{"sys":2067,"faqItemsCollection":2068,"name":1713,"slug":1714,"tier":45,"intro":2070,"faqTitle":59,"postCount":2059,"hasPage":19},{"id":1712},{"items":2069},[],"Shadow SaaS is the cloud applications employees adopt for work without IT approval, each one creating unmanaged accounts, identities, and data outside your security controls. Push covers the problem end to end — from browser-based SaaS discovery to in-browser app banners and MFA enforcement — alongside breach analyses that show where unmanaged accounts lead.",{"sys":2072,"faqItemsCollection":2074,"name":2076,"slug":2077,"tier":45,"intro":2078,"faqTitle":59,"postCount":2065,"hasPage":19},{"id":2073},"topic-siem",{"items":2075},[],"SIEM","siem","A SIEM is only as good as the telemetry feeding it, and most log sources never see what happens inside the browser — where phishing, session token theft, and account takeover actually play out. Push streams browser-level detections and identity telemetry into SIEMs, and these posts show how that data improves detection fidelity and cuts alert fatigue.",{"sys":2080,"faqItemsCollection":2082,"name":2084,"slug":2085,"tier":45,"intro":2086,"faqTitle":59,"postCount":1956,"hasPage":19},{"id":2081},"topic-social-engineering",{"items":2083},[],"Social engineering","social-engineering","Social engineering is the manipulation of people — through phishing pages, help desk impersonation, vishing calls, and poisoned tenant invites — into handing over access that no exploit could take. Coverage here tracks how threat actors run these plays — drawing on Push’s ongoing investigation of live phishing infrastructure and criminal tooling.",{"sys":2088,"faqItemsCollection":2090,"name":2092,"slug":2093,"tier":31,"intro":2094,"faqTitle":59,"postCount":1768,"hasPage":6},{"id":2089},"topic-supply-chain-security",{"items":2091},[],"Supply chain security","supply-chain-security","Supply chain security extends beyond your own perimeter to the vendors, platforms, and browser extensions your organization depends on. A compromised third party can hand attackers legitimate access — as recent campaigns against SaaS providers have shown. Push’s research examines the browser-extension supply chain in particular: why extension risk scores fail to predict compromise, and how developers can harden extensions against takeover. These posts frame supply chain risk through a browser and identity lens.",{"sys":2096,"faqItemsCollection":2098,"name":2100,"slug":2101,"tier":45,"intro":2102,"faqTitle":59,"postCount":2103,"hasPage":19},{"id":2097},"topic-swg",{"items":2099},[],"SWG","swg","A secure web gateway (SWG) filters and inspects web traffic in transit, sitting in the network path between users and the internet. That position shows you the packet but not the session: Push’s research on AitM phishing kits documents how attackers break the signatures proxies rely on, and these posts explain why phishing detection is moving from the network path into the browser itself.",18,{"sys":2105,"faqItemsCollection":2107,"name":2109,"slug":2110,"tier":45,"intro":2111,"faqTitle":59,"postCount":2112,"hasPage":19},{"id":2106},"topic-third-party-risk",{"items":2108},[],"Third-party risk","third-party-risk","Third-party risk is the exposure your organization inherits from vendors, SaaS providers, and integrations that hold your data or access your tenants — a chain now extended one employee sign-up at a time. This hub collects Push’s breach analyses and guides for assessing OAuth integrations, managing browser extensions, and responding when a supplier is compromised.",44,{"sys":2114,"faqItemsCollection":2116,"name":2118,"slug":2119,"tier":31,"intro":2120,"faqTitle":59,"postCount":2121,"hasPage":19},{"id":2115},"topic-threat-landscape",{"items":2117},[],"Threat landscape","threat-landscape","The enterprise threat landscape is now defined by identity attacks: criminals log in with phished, stolen, or stuffed credentials rather than breaking infrastructure. Threat actors keep proving how effective help desk scams, MFA bypass, and session theft are against well-defended organizations. Drawing on breach analyses, annual phishing trend reviews, and in-the-wild campaign tracking, Push documents how attacker TTPs are shifting. This hub is where to follow those changes.",49,{"sys":2123,"faqItemsCollection":2125,"name":2127,"slug":2128,"tier":45,"intro":2129,"faqTitle":59,"postCount":2130,"hasPage":19},{"id":2124},"topic-vishing",{"items":2126},[],"Vishing","vishing","Vishing — voice phishing — uses phone calls to impersonate IT support, help desks, or employees, talking targets into password resets, MFA approvals, or opening attacker-controlled pages. Threat actors now routinely pair calls with AiTM phishing to hijack SSO accounts, a chain Push has analyzed across campaigns targeting hundreds of organizations.",16,{},"blogtopics","9aR-7_LhDkRRXRaED83WYgKvhxkN_ODLJNuDH339OG0",1789500292142]